Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
–

53 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.39%—Zbateson Mail Mime ParserAI24/9/202630/9/2026
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrolled resource consumption / algorithmic complexity vulnerability (CWE-400) affects…
AplazadaAlta (7.2)0.18%—Zbateson Mail Mime ParserAI24/9/20265/10/2026
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF (carriage-return / line-feed) header injection (CWE-93) affecting any application that uses this library to build or…
Pendiente de análisisAlta (8.9)0.51%—LaravelAISymfony MailerAISymfony MimeAI4/9/202610/9/2026
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in…
Pendiente de análisisAlta (7.1)0.28%—XdgmimeAI17/7/20266/10/2026
A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application…
Pendiente de análisisMedia (4.5)0.12%—Mimecast IncydrAI5/6/202623/7/2026
In Mimecast Incydr before 2.6.0, arbitrary file access can occur.
AplazadaAlta (8.3)0.32%—Mimetypes Link IconsAI21/3/202617/6/2026
The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is enabled. This makes it possible for…
AnalizadaMedia (6.9)1.2%—Jstedfast Mimekit6/3/202617/6/2026
MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \r\n into the SMTP envelope address…
AplazadaAlta (7.1)0.15%—Ldrumm Unsafe-mimetypesAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ldrumm Unsafe Mimetypes unsafe-mimetypes allows Stored XSS.This issue affects Unsafe Mimetypes: from n/a through <= 0.1.4.
AnalizadaCrítica (9.8)0.75%—Ctan Mimetex22/4/202517/6/2026
An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script
AnalizadaAlta (7.3)0.62%—Ctan Mimetex22/4/202517/6/2026
A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths.
AplazadaAlta (7.1)0.42%—Kailey More Mime Type FiltersAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey (trepmal) More Mime Type Filters more-mime-type-filters allows Stored XSS.This issue affects More Mime Type Filters: from n/a through <= 0.3.
AplazadaAlta (7.1)0.15%—Jinhan Park Rocket Media Library Mime TypeAI23/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in JinHan Park Rocket Media Library Mime Type rocket-media-library-mime-type allows Stored XSS.This issue affects Rocket Media Library Mime Type: from n/a through <= 2.1.0.
AplazadaMedia (6.4)0.33%—PJW Mime ConfigAI16/11/202417/6/2026
The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary…
AnalizadaMedia (5.5)0.35%—Staude Mime Types Extended25/6/202417/6/2026
The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
AnalizadaAlta (7.5)1.1%—Rjbs Email-mimeFedoraproject Fedora2/5/202417/6/2026
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
AplazadaAlta (7.4)0.83%—AmavisAIMime-toolsAI18/3/202417/6/2026
Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.
ModificadaMedia (5.3)1.1%—Apache James Mime4j27/2/202417/6/2026
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.
ModificadaAlta (8.8)0.33%—Cyberwire PRO Mime Types9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions.
ModificadaMedia (4.9)0.81%—Mimecast Email Security16/3/202217/6/2026
Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature. (The domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.)
ModificadaMedia (5.4)1.1%—Horde Mime ViewerDebian Linux11/3/202217/6/2026
lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.
ModificadaMedia (5.4)0.62%—Mimetic Books16/8/202117/6/2026
The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in the "Default Publisher ID" field on the plugin's settings page.
ModificadaAlta (8.8)1.8%—Silverstripe MimevalidatorSilverstripe Recipe15/7/202017/6/2026
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the file contents. Uploads stored as…
ModificadaAlta (7.5)2.2%—Mime Project Mime7/6/201817/6/2026
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
ModificadaAlta (7.8)0.37%—Mimedefang1/9/201717/6/2026
MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by the…
ModificadaAlta (7.5)11%—Libmimedir Project Libmimedir16/6/201517/6/2026
libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, related to "free" function calls in the "lexer's memory clean-up procedure."