Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.5%—Mailenable EnterpriseMailenable Professional5/12/200516/6/2026
Multiple unspecified vulnerabilities in MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allow attackers to cause a denial of service (crash) via invalid IMAP commands.
ModificadaMedia (4)3.6%💥 ExploitMailenable EnterpriseMailenable Professional26/11/200516/6/2026
IMAP service (meimaps.exe) of MailEnable Professional 1.7 and Enterprise 1.1 allows remote authenticated attackers to cause a denial of service (application crash) by using RENAME with a non-existent mailbox, a different vulnerability than CVE-2005-3690.
ModificadaMedia (5)1.9%—Mailenable ProfessionalAIMailenable EnterpriseAI19/11/200516/6/2026
Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.
ModificadaAlta (7.5)5.2%—Mailenable EnterpriseMailenable Professional19/11/200516/6/2026
Stack-based buffer overflow in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to execute arbitrary code via a long mailbox name in the (1) select, (2) create, (3) delete, (4) rename, (5) subscribe, or (6) unsubscribe commands.
ModificadaAlta (7.5)64%💥 ExploitMailenable EnterpriseMailenable Professional5/10/200516/6/2026
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.
ModificadaMedia (6.4)1.3%—Omnipilot Software Lasso Professional Server17/8/200516/6/2026
Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.
ModificadaAlta (7.2)85%💥 ExploitMailenable Professional18/7/200516/6/2026
Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.
ModificadaMedia (5)51%—Mailenable ProfessionalMailenable Standard12/7/200516/6/2026
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.
ModificadaAlta (10)1.4%—Mailenable Professional12/7/200516/6/2026
Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.
ModificadaMedia (5)1.8%—Mailenable EnterpriseMailenable Professional31/5/200516/6/2026
Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).
ModificadaMedia (5)3.7%💥 ExploitRaiden Professional Servers Raidenftpd11/5/200516/6/2026
Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a "..\\" (dot dot backslash) in the urlget site command.
ModificadaAlta (7.5)1.0%💥 ExploitEcomm Professional Guestbook3/5/200516/6/2026
SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.
ModificadaAlta (7.5)4.2%💥 ExploitMnet Soft Factory Nodemanager Professional2/5/200516/6/2026
Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.
ModificadaAlta (7.5)73%💥 ExploitMailenable EnterpriseMailenable Professional2/5/200516/6/2026
Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorization header.
ModificadaAlta (7.5)4.9%—Mailenable EnterpriseMailenable Professional2/5/200516/6/2026
Buffer overflow in the IMAP service for MailEnable Enterprise 1.04 and earlier and Professional 1.54 allows remote attackers to execute arbitrary code via a long AUTHENTICATE command.
ModificadaMedia (5)5.7%💥 ExploitMailenable EnterpriseMailenable Professional2/5/200516/6/2026
The SMTP service in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to cause a denial of service (server crash) via an EHLO command with a Unicode string.
ModificadaAlta (7.5)14%💥 ExploitMailenable EnterpriseMailenable Professional31/12/200416/6/2026
Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command string or (2) a long string to the MEIMAP service and then terminating the connection.
ModificadaMedia (5)2.1%—Mailenable EnterpriseMailenable Professional31/12/200416/6/2026
MailEnable Professional Edition before 1.53 and Enterprise Edition before 1.02 allows remote attackers to cause a denial of service (crash) via malformed (1) SMTP or (2) IMAP commands.
ModificadaMedia (5)3.4%💥 ExploitLoom Software Surfnow ProfessionalLoom Software Surfnow Standard31/12/200416/6/2026
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.
ModificadaAlta (7.5)1.3%💥 ExploitPhprofession31/12/200416/6/2026
SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.
ModificadaMedia (5)3.3%💥 ExploitPhprofession31/12/200416/6/2026
phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.
ModificadaAlta (10)63%💥 ExploitProxy-pro Professional Gatekeeper23/11/200416/6/2026
Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.
ModificadaAlta (7.5)2.9%💥 ExploitSitecubed Mailworks Professional2/9/200416/6/2026
MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."
ModificadaMedia (4.3)1.9%💥 ExploitPhprofession21/4/200416/6/2026
Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.
ModificadaMedia (4.3)1.4%—Jshop E-commerce Jshop ProfessionalJshop E-commerce Jshop Server7/2/200416/6/2026
Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.
Orbitaley — Vulnerabilidades