Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

204 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.55%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.
ModificadaMedia (5.4)0.55%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
ModificadaCrítica (9.8)1.4%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.
ModificadaCrítica (9.8)1.4%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
ModificadaMedia (5.4)0.58%—Rumble Mail Server Project Rumble Mail Server4/4/202217/6/2026
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.
ModificadaMedia (5.4)0.58%—Rumble Mail Server Project Rumble Mail Server4/4/202217/6/2026
Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.
ModificadaMedia (5.4)0.58%—Rumble Mail Server Project Rumble Mail Server4/4/202217/6/2026
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters.
ModificadaAlta (7.8)0.45%—Rumble Mail Server Project Rumble Mail Server4/4/202217/6/2026
An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.
ModificadaAlta (8.1)1.4%—Courier-mta Courier Mail Server3/8/202117/6/2026
An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the POP3 STLS command, injecting plaintext commands into an encrypted user session.
ModificadaMedia (6.1)5.3%—Icewarp Mail Server2/11/202017/6/2026
IceWarp 11.4.5.0 allows XSS via the language parameter.
ModificadaAlta (8.8)1.2%—Argosoft Mail Server11/9/202017/6/2026
ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will run the CSRF.
ModificadaAlta (8.8)1.8%—Icewarp Mail Server15/7/202017/6/2026
IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.
ModificadaMedia (6.5)1.5%—Icewarp Mail Server15/7/202017/6/2026
IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.
ModificadaMedia (6.5)0.97%—Icewarp Mail Server15/7/202017/6/2026
IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.
ModificadaMedia (6.1)1.0%—Icewarp Mail Server6/1/202017/6/2026
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.
ModificadaMedia (5.4)0.72%—Icewarp Mail Server6/1/202017/6/2026
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.
ModificadaMedia (5.4)0.60%—Altn Mdaemon Email Server17/12/201917/6/2026
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
ModificadaAlta (7.5)1.3%—Altn Mdaemon Email Server16/7/201917/6/2026
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a…
ModificadaAlta (7.5)41%—Icewarp Mail Server3/6/201917/6/2026
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.
ModificadaMedia (6.1)0.98%—Codecrafters Ability Mail Server12/3/201917/6/2026
Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.
ModificadaMedia (6.1)1.1%—Icewarp Mail Server1/9/201817/6/2026
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.