Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

877 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.25%—Mailjet Email MarketingAI6/10/20266/10/2026
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
AplazadaMedia (4.3)0.25%—Omnisend Newsletters Email Marketing SMS AND PopupsAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
AplazadaAlta (7.2)0.40%—Kadencewp Kadence Woocommerce Email DesignerAI30/9/202630/9/2026
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
Pendiente de análisisAlta (8.2)0.25%—NodemailerAI26/9/202630/9/2026
Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the…
Pendiente de análisisMedia (6)0.11%—NodemailerAI26/9/202630/9/2026
Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername. When two direct TLS/SMTPS transports (secure: true) resolve the same non-IP host with different tls.servername values, the first transport's…
Pendiente de análisisAlta (8.7)0.28%—NodemailerAI26/9/202630/9/2026
nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service…
Pendiente de análisisMedia (6.9)0.19%—NodemailerAI26/9/202630/9/2026
Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string and that are followed by RFC 5322 comments, allowing trailing comment-separated domain atoms to be retained in the normalized address. For…
AplazadaAlta (7.6)0.29%—Email LOGAI23/9/202623/9/2026
Administrator SQL Injection in Email Log <= 2.63 versions.
AplazadaMedia (5.3)0.22%—Email SubscribersAI23/9/202623/9/2026
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know.
AplazadaCrítica (9.8)0.60%—Perl Email-senderAI21/9/202622/9/2026
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every recipient go into a single command string, which open() passes to a shell. Every other…
AplazadaCrítica (9.8)0.32%—Maildata Email Archiving SystemAI17/9/202622/9/2026
In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
AplazadaBaja (2.1)0.84%—Punchin-emailAICloudflare WorkersAI17/9/202630/9/2026
punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent…
Pendiente de análisisAlta (8.3)0.40%—NodemailerAI16/9/202622/9/2026
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain…
Pendiente de análisisAlta (8.3)0.38%—NodemailerAI16/9/202622/9/2026
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the…
Pendiente de análisisAlta (8.7)0.82%—NodemailerAI16/9/202622/9/2026
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for…
Pendiente de análisisMedia (6)0.29%—NodemailerAI16/9/202622/9/2026
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key,…
Pendiente de análisisCrítica (9.8)0.53%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisAlta (7.5)0.47%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202616/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisCrítica (9.8)0.53%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisCrítica (9.8)0.62%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisCrítica (9.8)0.40%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
AplazadaMedia (6.9)0.76%—Simalexan Api-lambda-send-email-sesAI13/9/202614/9/2026
A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing…
Pendiente de análisisAlta (8.7)0.68%—NodemailerAI13/9/202624/9/2026
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several…
AplazadaAlta (7.1)0.40%—Mailmunch Grow Your Email ListAI10/9/202610/9/2026
Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
Pendiente de análisisCrítica (9.9)0.86%💥 PoCCpanelAICpanel EmailtrackAI9/9/202610/9/2026
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
Orbitaley — Vulnerabilidades