Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.39% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver. | |
| Analizada | Alta (8.8) | 0.50% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation. | |
| Analizada | Media (5.8) | 0.56% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540,… | |
| Analizada | Media (4.3) | 0.37% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin. | |
| Analizada | Crítica (9.8) | 0.58% | — | Roundcube Webmail | 17/8/2026 | 10/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. | |
| Analizada | Alta (7.1) | 2.3% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection. | |
| Analizada | Media (5.8) | 0.47% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation. | |
| Analizada | Media (5.4) | 0.30% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | |
| Analizada | Alta (7.2) | 0.44% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing. | |
| Analizada | Alta (8.8) | 1.1% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver. | |
| Analizada | Crítica (10) | 0.31% | — | Roundcube Webmail | 14/7/2026 | 17/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click). | |
| Pendiente de análisis | Media (4.7) | 0.21% | — | Roundcube WebmailAI | 14/7/2026 | 15/7/2026 | Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page. | |
| Analizada | Crítica (9.8) | 0.50% | — | Roundcube Webmail | 14/7/2026 | 20/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover. | |
| Analizada | Crítica (10) | 0.44% | — | Roundcube Webmail | 14/7/2026 | 20/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and… | |
| Analizada | Media (6.5) | 0.52% | — | Roundcube Webmail | 14/7/2026 | 20/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment. | |
| Analizada | Media (6.5) | 0.47% | — | Roundcube Webmail | 14/7/2026 | 20/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size. | |
| Aplazada | Media (4.4) | 0.26% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes. | |
| Aplazada | Alta (7.2) | 0.45% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute. | |
| Aplazada | Baja (3.7) | 0.54% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. | |
| Aplazada | Media (6.5) | 0.48% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass. | |
| Aplazada | Media (6.5) | 0.45% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message. | |
| Aplazada | Alta (7.5) | 0.51% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.) | |
| Aplazada | Alta (7.2) | 0.46% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540. | |
| Aplazada | Alta (8.1) | 0.89% | — | Roundcube WebmailAI | 25/5/2026 | 25/9/2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. | |
| Analizada | Alta (8.7) | 0.19% | — | Bulwarkmail Webmail | 6/4/2026 | 24/7/2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by the client. An attacker could forge their source IP address to bypass IP-based… |