Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 5.0% | 💥 Exploit | Inter7 Sqwebmail | 6/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type. | |
| Modificada | Alta (10) | 4.7% | — | Omail Webmail | 4/5/2004 | 16/6/2026 | The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password. | |
| Modificada | Alta (7.5) | 3.3% | — | Double Precision Incorporated Courier MTADouble Precision Incorporated SqwebmailInter7 Courier-imapGentoo Linux | 15/4/2004 | 16/6/2026 | Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range." | |
| Modificada | Alta (10) | 69% | 💥 Exploit | Truenorth Software IA Webmail Server | 3/11/2003 | 16/6/2026 | Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request. | |
| Modificada | Alta (10) | 3.6% | — | Omail Webmail | 19/8/2003 | 16/6/2026 | The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username. | |
| Modificada | Alta (7.5) | 3.2% | — | Bvrp Software Slwebmail | 27/5/2003 | 16/6/2026 | Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID… | |
| Modificada | Media (5) | 1.5% | — | Bvrp Software Slwebmail | 27/5/2003 | 16/6/2026 | SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message. | |
| Modificada | Media (5) | 1.6% | — | Bvrp Software Slwebmail | 27/5/2003 | 16/6/2026 | ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Emumail EMU Webmail | 2/4/2003 | 16/6/2026 | emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error that includes the pathname in the resulting error message. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Emumail EMU Webmail | 2/4/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field. | |
| Modificada | Baja (3.6) | 0.33% | — | Basilix Webmail | 31/12/2002 | 16/6/2026 | The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file. | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | Basilix Webmail | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields. | |
| Modificada | Baja (2.1) | 0.35% | — | Basilix Webmail | 31/12/2002 | 16/6/2026 | BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments. | |
| Modificada | Media (5) | 1.3% | — | Open Webmail | 31/12/2002 | 16/6/2026 | openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information. | |
| Modificada | Baja (2.1) | 0.84% | 💥 Exploit | Imho Webmail | 31/12/2002 | 16/6/2026 | The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox. | |
| Modificada | Media (6.4) | 1.2% | — | Basilix Webmail | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable. | |
| Modificada | Alta (7.2) | 0.41% | — | Open Webmail | 26/12/2002 | 16/6/2026 | openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuration file that specifies additional code to be executed. | |
| Modificada | Media (5) | 2.2% | — | Endymion Mailman Webmail | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs. | |
| Modificada | Alta (7.5) | 7.9% | 💥 Exploit | IMP Webmail | 6/12/2001 | 16/6/2026 | Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Basilix Webmail | 6/7/2001 | 16/6/2026 | Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Cobalt QubeCobalt Webmail | 5/7/2001 | 16/6/2026 | Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Endymion Mailman Webmail | 16/2/2001 | 16/6/2026 | MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Basilix Webmail | 11/1/2001 | 16/6/2026 | Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file. | |
| Modificada | Alta (7.5) | 5.7% | 💥 Exploit | Trlinux Postaci Webmail | 9/1/2001 | 16/6/2026 | The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request. | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | Concatus Imate Webmail Server | 1/6/2000 | 16/6/2026 | Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command. |