Vulnerabilities
Summary — last 7 days
New vulnerabilities2,851▼ 221 vs. last week
Critical / high1,332▼ 167 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)222▼ 99 vs. last week
877 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (4.8) | 0.08% | — | Samsung Visual Voicemail | 9/9/2026 | 9/23/2026 | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission. | |
| Deferred | Medium (6.5) | 0.33% | — | Blog Studio Email Subscribers AND NewslettersAI | 9/7/2026 | 9/8/2026 | The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly… | |
| Deferred | High (8.6) | 0.64% | — | Seppmail Secure Email GatewayAI | 9/3/2026 | 9/4/2026 | SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges. | |
| Deferred | High (7.7) | 0.47% | — | Seppmail Secure Email GatewayAI | 9/3/2026 | 9/3/2026 | SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor. | |
| Deferred | High (8.6) | 1.2% | — | Seppmail Secure Email GatewayAI | 9/3/2026 | 9/3/2026 | SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges. | |
| Awaiting Analysis | Medium (5.9) | 0.16% | — | Cisco Secure EmailAI | 9/2/2026 | 9/2/2026 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An… | |
| Awaiting Analysis | Medium (5.9) | 0.16% | — | Cisco Secure EmailAI | 9/2/2026 | 9/2/2026 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An… | |
| Deferred | High (7.1) | 0.25% | — | Email EssentialsAI | 8/31/2026 | 9/1/2026 | Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | |
| Deferred | High (7.1) | 0.25% | — | Email Subscribers AND NewslettersAI | 8/31/2026 | 9/1/2026 | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | |
| Awaiting Analysis | Medium (6.9) | 1.0% | — | NodemailerAI | 8/31/2026 | 9/10/2026 | Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for… | |
| Awaiting Analysis | High (8.3) | 0.19% | — | NodemailerAI | 8/31/2026 | 9/10/2026 | Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised… | |
| Awaiting Analysis | Medium (5.3) | 0.26% | — | NodemailerAI | 8/31/2026 | 9/10/2026 | Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail… | |
| Awaiting Analysis | Medium (5.3) | 0.26% | — | NodemailerAI | 8/31/2026 | 9/10/2026 | Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls. | |
| Awaiting Analysis | High (7.1) | 0.35% | — | NodemailerAI | 8/31/2026 | 9/10/2026 | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or… | |
| Awaiting Analysis | Medium (6.9) | 0.30% | — | NodemailerAI | 8/31/2026 | 9/10/2026 | nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny… | |
| Awaiting Analysis | Critical (9.3) | 2.0% | — | NodemailerAI | 8/31/2026 | 10/8/2026 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without… | |
| Deferred | Medium (5.1) | 0.44% | — | Watchguard Dimension Email ServerAI | 8/28/2026 | 8/28/2026 | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. | |
| Awaiting Analysis | Medium (5.7) | 0.19% | — | Drupal Email Login OTPAI | 8/25/2026 | 8/28/2026 | Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | |
| Deferred | High (8.7) | 0.66% | — | Getgrav Grav-plugin-emailAI | 8/25/2026 | 8/31/2026 | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and… | |
| Analyzed | High (8.2) | 0.32% | — | Oracle Email Center | 8/18/2026 | 8/31/2026 | Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Component). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks… | |
| Deferred | Critical (9.8) | 0.50% | — | Wpfactory Customer Email Verification FOR WoocommerceAI | 8/13/2026 | 8/26/2026 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered… | |
| Awaiting Analysis | High (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 8/11/2026 | 8/28/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. | |
| Awaiting Analysis | High (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 8/11/2026 | 8/28/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask. | |
| Deferred | Critical (9.8) | 0.48% | — | Kadence Woocommerce Email DesignerAI | 8/6/2026 | 8/12/2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | |
| Deferred | Low (1.9) | 0.21% | — | Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI | 8/3/2026 | 8/12/2026 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with… |