Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Cleantalk Spam ProtectionAICleantalk AntispamAICleantalk FirewallAI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
AplazadaAlta (7.1)0.17%—Foliovision FV AntispamAI18/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7.
AplazadaMedia (5.4)0.12%—Erik Antispam Antispam FOR Contact Form 7AI16/7/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Erik AntiSpam for Contact Form 7 cf7-antispam allows Cross Site Request Forgery.This issue affects AntiSpam for Contact Form 7: from n/a through <= 0.6.3.
AplazadaAlta (8.8)0.70%—Cleantalk Spam Protection Antispam FirewallAI13/12/202417/6/2026
Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10.
AnalizadaAlta (7.5)3.7%—Cleantalk Spam Protection, Antispam, Firewall26/11/202417/6/2026
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (5.3)0.35%—Wpcerber Cerber Security Antispam & Malware Scan31/8/202417/6/2026
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP…
AplazadaMedia (5.3)0.37%—Pluginkollektiv Antispam BEEAI4/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in pluginkollektiv Antispam Bee allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Antispam Bee: from n/a through 2.11.3.
AplazadaAlta (7.1)0.33%—Codekraft Antispam FOR Contact Form 7AI17/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codekraft AntiSpam for Contact Form 7 allows Reflected XSS.This issue affects AntiSpam for Contact Form 7: from n/a through 0.6.0.
ModificadaAlta (8.8)0.23%—Cleantalk Spam Protection, Antispam, Firewall5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.
ModificadaAlta (7.2)1.1%—Cleantalk Spam Protection, Antispam, Firewall25/10/202217/6/2026
The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin
ModificadaMedia (6.1)2.9%—Cleantalk Antispam19/4/202217/6/2026
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php`
ModificadaMedia (6.1)2.4%—Cleantalk Antispam19/4/202217/6/2026
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php`
ModificadaAlta (7.5)4.7%—Cleantalk Spam Protection, Antispam, Firewall17/5/202117/6/2026
It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent…
ModificadaCrítica (9.8)0.98%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user18/3/202117/6/2026
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
ModificadaAlta (7.6)0.61%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
ModificadaAlta (7.6)0.61%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
ModificadaMedia (6.1)0.62%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
ModificadaMedia (6.1)0.62%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
ModificadaCrítica (9.8)1.7%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-auditHgiga Msr45 Isherlock-baseHgiga Msr45 Isherlock-user+631/12/202017/6/2026
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
ModificadaMedia (6.1)1.3%—Cleantalk Spam Protection, Antispam, Firewall13/11/201917/6/2026
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack…
ModificadaMedia (6.1)1.4%—Wpcerber Cerber Security Antispam & Malware Scan17/9/201917/6/2026
The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
ModificadaAlta (7.5)1.4%—Typo3 ND Antispam10/4/200916/6/2026
Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration via unknown vectors.
ModificadaAlta (9.3)6.0%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+95/10/200716/6/2026
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
ModificadaAlta (9.3)3.9%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+95/10/200716/6/2026
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
ModificadaMedia (6.9)1.1%—Symantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+215/7/200716/6/2026
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt…