Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.55% | — | Altn Security Gateway FOR Email Servers | 25/8/2022 | 17/6/2026 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter. | |
| Modificada | Media (5.4) | 0.61% | — | Altn Security Gateway FOR Email Servers | 25/8/2022 | 17/6/2026 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint. | |
| Modificada | Media (5.4) | 0.55% | — | Altn Security Gateway FOR Email Servers | 25/8/2022 | 17/6/2026 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection. | |
| Modificada | Media (5.4) | 0.61% | — | Altn Security Gateway FOR Email Servers | 25/8/2022 | 17/6/2026 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint. | |
| Modificada | Crítica (9.8) | 1.4% | — | Altn Security Gateway FOR Email Servers | 25/8/2022 | 17/6/2026 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter. | |
| Modificada | Media (5.4) | 0.61% | — | Altn Security Gateway FOR Email Servers | 25/8/2022 | 17/6/2026 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint. | |
| Modificada | Crítica (9.8) | 1.4% | — | Altn Security Gateway FOR Email Servers | 25/8/2022 | 17/6/2026 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter. | |
| Modificada | Media (5.4) | 0.61% | — | Altn Security Gateway FOR Email Servers | 25/8/2022 | 17/6/2026 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint. | |
| Modificada | Media (5.4) | 0.58% | — | Rumble Mail Server Project Rumble Mail Server | 4/4/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter. | |
| Modificada | Media (5.4) | 0.58% | — | Rumble Mail Server Project Rumble Mail Server | 4/4/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter. | |
| Modificada | Media (5.4) | 0.58% | — | Rumble Mail Server Project Rumble Mail Server | 4/4/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters. | |
| Modificada | Alta (7.8) | 0.45% | — | Rumble Mail Server Project Rumble Mail Server | 4/4/2022 | 17/6/2026 | An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path. | |
| Modificada | Alta (8.1) | 1.4% | — | Courier-mta Courier Mail Server | 3/8/2021 | 17/6/2026 | An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the POP3 STLS command, injecting plaintext commands into an encrypted user session. | |
| Modificada | Media (6.1) | 5.3% | — | Icewarp Mail Server | 2/11/2020 | 17/6/2026 | IceWarp 11.4.5.0 allows XSS via the language parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Argosoft Mail Server | 11/9/2020 | 17/6/2026 | ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will run the CSRF. | |
| Modificada | Alta (8.8) | 1.8% | — | Icewarp Mail Server | 15/7/2020 | 17/6/2026 | IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access. | |
| Modificada | Media (6.5) | 1.5% | — | Icewarp Mail Server | 15/7/2020 | 17/6/2026 | IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space. | |
| Modificada | Media (6.5) | 0.97% | — | Icewarp Mail Server | 15/7/2020 | 17/6/2026 | IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts. | |
| Modificada | Media (6.1) | 1.0% | — | Icewarp Mail Server | 6/1/2020 | 17/6/2026 | IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts. | |
| Modificada | Media (5.4) | 0.72% | — | Icewarp Mail Server | 6/1/2020 | 17/6/2026 | IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects. | |
| Modificada | Media (5.4) | 0.60% | — | Altn Mdaemon Email Server | 17/12/2019 | 17/6/2026 | MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message. | |
| Modificada | Alta (7.5) | 1.3% | — | Altn Mdaemon Email Server | 16/7/2019 | 17/6/2026 | MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a… | |
| Modificada | Alta (7.5) | 41% | — | Icewarp Mail Server | 3/6/2019 | 17/6/2026 | IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal. | |
| Modificada | Media (6.1) | 0.98% | — | Codecrafters Ability Mail Server | 12/3/2019 | 17/6/2026 | Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe. | |
| Modificada | Media (6.1) | 1.1% | — | Icewarp Mail Server | 1/9/2018 | 17/6/2026 | In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field. |