Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

251 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)5.0%💥 ExploitInter7 Sqwebmail6/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.
ModificadaAlta (10)4.7%—Omail Webmail4/5/200416/6/2026
The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.
ModificadaAlta (7.5)3.3%—Double Precision Incorporated Courier MTADouble Precision Incorporated SqwebmailInter7 Courier-imapGentoo Linux15/4/200416/6/2026
Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."
ModificadaAlta (10)69%💥 ExploitTruenorth Software IA Webmail Server3/11/200316/6/2026
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.
ModificadaAlta (10)3.6%—Omail Webmail19/8/200316/6/2026
The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.
ModificadaAlta (7.5)3.2%—Bvrp Software Slwebmail27/5/200316/6/2026
Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID…
ModificadaMedia (5)1.5%—Bvrp Software Slwebmail27/5/200316/6/2026
SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message.
ModificadaMedia (5)1.6%—Bvrp Software Slwebmail27/5/200316/6/2026
ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.
ModificadaMedia (5)7.5%💥 ExploitEmumail EMU Webmail2/4/200316/6/2026
emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error that includes the pathname in the resulting error message.
ModificadaMedia (4.3)3.9%💥 ExploitEmumail EMU Webmail2/4/200316/6/2026
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field.
ModificadaBaja (3.6)0.33%—Basilix Webmail31/12/200216/6/2026
The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file.
ModificadaMedia (6.8)4.3%💥 ExploitBasilix Webmail31/12/200216/6/2026
Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.
ModificadaBaja (2.1)0.35%—Basilix Webmail31/12/200216/6/2026
BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments.
ModificadaMedia (5)1.3%—Open Webmail31/12/200216/6/2026
openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.
ModificadaBaja (2.1)0.84%💥 ExploitImho Webmail31/12/200216/6/2026
The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.
ModificadaMedia (6.4)1.2%—Basilix Webmail31/12/200216/6/2026
SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.
ModificadaAlta (7.2)0.41%—Open Webmail26/12/200216/6/2026
openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuration file that specifies additional code to be executed.
ModificadaMedia (5)2.2%—Endymion Mailman Webmail12/8/200216/6/2026
Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.
ModificadaAlta (7.5)7.9%💥 ExploitIMP Webmail6/12/200116/6/2026
Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.
ModificadaMedia (5)3.8%💥 ExploitBasilix Webmail6/7/200116/6/2026
Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter.
ModificadaMedia (5)8.1%💥 ExploitCobalt QubeCobalt Webmail5/7/200116/6/2026
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter.
ModificadaAlta (10)13%💥 ExploitEndymion Mailman Webmail16/2/200116/6/2026
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.
ModificadaAlta (7.5)6.9%💥 ExploitBasilix Webmail11/1/200116/6/2026
Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.
ModificadaAlta (7.5)5.7%💥 ExploitTrlinux Postaci Webmail9/1/200116/6/2026
The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.
ModificadaMedia (5)7.3%💥 ExploitConcatus Imate Webmail Server1/6/200016/6/2026
Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.