Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Zbateson Mail Mime ParserAI | 24/9/2026 | 30/9/2026 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrolled resource consumption / algorithmic complexity vulnerability (CWE-400) affects… | |
| Aplazada | Alta (7.2) | 0.18% | — | Zbateson Mail Mime ParserAI | 24/9/2026 | 5/10/2026 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF (carriage-return / line-feed) header injection (CWE-93) affecting any application that uses this library to build or… | |
| Pendiente de análisis | Alta (8.9) | 0.51% | — | LaravelAISymfony MailerAISymfony MimeAI | 4/9/2026 | 10/9/2026 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in… | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | XdgmimeAI | 17/7/2026 | 6/10/2026 | A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application… | |
| Pendiente de análisis | Media (4.5) | 0.12% | — | Mimecast IncydrAI | 5/6/2026 | 23/7/2026 | In Mimecast Incydr before 2.6.0, arbitrary file access can occur. | |
| Aplazada | Alta (8.3) | 0.32% | — | Mimetypes Link IconsAI | 21/3/2026 | 17/6/2026 | The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is enabled. This makes it possible for… | |
| Analizada | Media (6.9) | 1.2% | — | Jstedfast Mimekit | 6/3/2026 | 17/6/2026 | MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \r\n into the SMTP envelope address… | |
| Aplazada | Alta (7.1) | 0.15% | — | Ldrumm Unsafe-mimetypesAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ldrumm Unsafe Mimetypes unsafe-mimetypes allows Stored XSS.This issue affects Unsafe Mimetypes: from n/a through <= 0.1.4. | |
| Analizada | Crítica (9.8) | 0.75% | — | Ctan Mimetex | 22/4/2025 | 17/6/2026 | An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script | |
| Analizada | Alta (7.3) | 0.62% | — | Ctan Mimetex | 22/4/2025 | 17/6/2026 | A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths. | |
| Aplazada | Alta (7.1) | 0.42% | — | Kailey More Mime Type FiltersAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey (trepmal) More Mime Type Filters more-mime-type-filters allows Stored XSS.This issue affects More Mime Type Filters: from n/a through <= 0.3. | |
| Aplazada | Alta (7.1) | 0.15% | — | Jinhan Park Rocket Media Library Mime TypeAI | 23/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in JinHan Park Rocket Media Library Mime Type rocket-media-library-mime-type allows Stored XSS.This issue affects Rocket Media Library Mime Type: from n/a through <= 2.1.0. | |
| Aplazada | Media (6.4) | 0.33% | — | PJW Mime ConfigAI | 16/11/2024 | 17/6/2026 | The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary… | |
| Analizada | Media (5.5) | 0.35% | — | Staude Mime Types Extended | 25/6/2024 | 17/6/2026 | The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Analizada | Alta (7.5) | 1.1% | — | Rjbs Email-mimeFedoraproject Fedora | 2/5/2024 | 17/6/2026 | An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts. | |
| Aplazada | Alta (7.4) | 0.83% | — | AmavisAIMime-toolsAI | 18/3/2024 | 17/6/2026 | Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware. | |
| Modificada | Media (5.3) | 1.1% | — | Apache James Mime4j | 27/2/2024 | 17/6/2026 | Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages. | |
| Modificada | Alta (8.8) | 0.33% | — | Cyberwire PRO Mime Types | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions. | |
| Modificada | Media (4.9) | 0.81% | — | Mimecast Email Security | 16/3/2022 | 17/6/2026 | Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature. (The domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.) | |
| Modificada | Media (5.4) | 1.1% | — | Horde Mime ViewerDebian Linux | 11/3/2022 | 17/6/2026 | lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering. | |
| Modificada | Media (5.4) | 0.62% | — | Mimetic Books | 16/8/2021 | 17/6/2026 | The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in the "Default Publisher ID" field on the plugin's settings page. | |
| Modificada | Alta (8.8) | 1.8% | — | Silverstripe MimevalidatorSilverstripe Recipe | 15/7/2020 | 17/6/2026 | Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the file contents. Uploads stored as… | |
| Modificada | Alta (7.5) | 2.2% | — | Mime Project Mime | 7/6/2018 | 17/6/2026 | The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input. | |
| Modificada | Alta (7.8) | 0.37% | — | Mimedefang | 1/9/2017 | 17/6/2026 | MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by the… | |
| Modificada | Alta (7.5) | 11% | — | Libmimedir Project Libmimedir | 16/6/2015 | 17/6/2026 | libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, related to "free" function calls in the "lexer's memory clean-up procedure." |