Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Cleantalk Spam ProtectionAICleantalk AntispamAICleantalk FirewallAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | |
| Aplazada | Alta (7.1) | 0.17% | — | Foliovision FV AntispamAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7. | |
| Aplazada | Media (5.4) | 0.12% | — | Erik Antispam Antispam FOR Contact Form 7AI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Erik AntiSpam for Contact Form 7 cf7-antispam allows Cross Site Request Forgery.This issue affects AntiSpam for Contact Form 7: from n/a through <= 0.6.3. | |
| Aplazada | Alta (8.8) | 0.70% | — | Cleantalk Spam Protection Antispam FirewallAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10. | |
| Analizada | Alta (7.5) | 3.7% | — | Cleantalk Spam Protection, Antispam, Firewall | 26/11/2024 | 17/6/2026 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (5.3) | 0.35% | — | Wpcerber Cerber Security Antispam & Malware Scan | 31/8/2024 | 17/6/2026 | The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP… | |
| Aplazada | Media (5.3) | 0.37% | — | Pluginkollektiv Antispam BEEAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in pluginkollektiv Antispam Bee allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Antispam Bee: from n/a through 2.11.3. | |
| Aplazada | Alta (7.1) | 0.33% | — | Codekraft Antispam FOR Contact Form 7AI | 17/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codekraft AntiSpam for Contact Form 7 allows Reflected XSS.This issue affects AntiSpam for Contact Form 7: from n/a through 0.6.0. | |
| Modificada | Alta (8.8) | 0.23% | — | Cleantalk Spam Protection, Antispam, Firewall | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20. | |
| Modificada | Alta (7.2) | 1.1% | — | Cleantalk Spam Protection, Antispam, Firewall | 25/10/2022 | 17/6/2026 | The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin | |
| Modificada | Media (6.1) | 2.9% | — | Cleantalk Antispam | 19/4/2022 | 17/6/2026 | The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php` | |
| Modificada | Media (6.1) | 2.4% | — | Cleantalk Antispam | 19/4/2022 | 17/6/2026 | The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php` | |
| Modificada | Alta (7.5) | 4.7% | — | Cleantalk Spam Protection, Antispam, Firewall | 17/5/2021 | 17/6/2026 | It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent… | |
| Modificada | Crítica (9.8) | 0.98% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 18/3/2021 | 17/6/2026 | HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege. | |
| Modificada | Alta (7.6) | 0.61% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages. | |
| Modificada | Alta (7.6) | 0.61% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter. | |
| Modificada | Media (6.1) | 0.62% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks. | |
| Modificada | Media (6.1) | 0.62% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks. | |
| Modificada | Crítica (9.8) | 1.7% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-auditHgiga Msr45 Isherlock-baseHgiga Msr45 Isherlock-user+6 | 31/12/2020 | 17/6/2026 | HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism. | |
| Modificada | Media (6.1) | 1.3% | — | Cleantalk Spam Protection, Antispam, Firewall | 13/11/2019 | 17/6/2026 | The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack… | |
| Modificada | Media (6.1) | 1.4% | — | Wpcerber Cerber Security Antispam & Malware Scan | 17/9/2019 | 17/6/2026 | The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header. | |
| Modificada | Alta (7.5) | 1.4% | — | Typo3 ND Antispam | 10/4/2009 | 16/6/2026 | Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration via unknown vectors. | |
| Modificada | Alta (9.3) | 6.0% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives. | |
| Modificada | Alta (9.3) | 3.9% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header. | |
| Modificada | Media (6.9) | 1.1% | — | Symantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+2 | 15/7/2007 | 16/6/2026 | Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt… |