Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

176 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.34%—Acymailing Smtp NewsletterAI1/10/20261/10/2026
Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.
AplazadaCrítica (9)0.46%—Acymailing Smtp NewsletterAI30/9/202630/9/2026
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Pendiente de análisisAlta (7.5)0.27%—Netty-codec-smtpAI18/9/202625/9/2026
A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this field, can embed CR/LF characters to inject arbitrary SMTP commands. This can…
AplazadaMedia (6.3)0.39%—AiosmtplibAI12/9/202623/9/2026
aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope…
AplazadaMedia (5.4)0.29%—Wpexperts Post SmtpAI31/8/20261/9/2026
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.
AplazadaMedia (5.9)0.40%—AiosmtplibAI20/8/202618/9/2026
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP response lines after the…
AplazadaAlta (7.1)0.25%—SmartsmtpAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
AplazadaMedia (6.9)0.53%—AiosmtplibAI18/8/202618/9/2026
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is framed as additional standalone SMTP command lines, allowing an attacker who…
AplazadaMedia (6.5)0.22%—Acymailing Smtp NewsletterAI13/8/202614/8/2026
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
AplazadaMedia (6.5)0.34%—Acymailing Smtp NewsletterAI13/8/202614/8/2026
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
AplazadaAlta (7.2)0.53%—Wpmanageninja FluentsmtpAI6/8/202612/8/2026
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output…
AplazadaAlta (7.1)0.25%—Acymailing Newsletter Team Acymailing Smtp NewsletterAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
AplazadaAlta (7.1)0.32%—Acymailing Smtp NewsletterAI13/7/202613/7/2026
Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.
AplazadaCrítica (9.3)0.40%—Acymailing Smtp NewsletterAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
AplazadaMedia (6.1)0.36%—Brevo Newsletter Smtp Email Marketing Subscribe FormsAI10/7/202610/7/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (4.3)0.14%—Gmail SmtpAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.
AplazadaAlta (7.1)0.25%—Wpexperts Post SmtpAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.
AplazadaMedia (4.3)0.43%—Smtp2goAI28/5/202617/6/2026
The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.16.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level…
AplazadaAlta (7.5)0.75%—Nodemailer Smtp ServerAI15/5/202617/6/2026
An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components
AplazadaAlta (7.1)0.35%—Gravity SmtpAI10/4/202617/6/2026
The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to uninstall…
AplazadaAlta (7.5)2.2%—Gravity SmtpAI31/3/202617/6/2026
The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor…
AplazadaAlta (7.5)0.42%—Noor Alam Smtp MailerAI25/3/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Noor Alam SMTP Mailer smtp-mailer allows Retrieve Embedded Sensitive Data.This issue affects SMTP Mailer: from n/a through <= 1.1.24.
AplazadaCrítica (9)0.37%—Bitapps BIT SmtpAI25/3/202617/6/2026
Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2.
AplazadaAlta (7.2)0.39%—Wpexperts Post SmtpAI18/3/202617/6/2026
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This…
AplazadaMedia (5.3)0.34%—Wpexperts Post SmtpAI18/3/202617/6/2026
The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or…