Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.49%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conducting a reflected XSS attack.
ModificadaMedia (6.1)0.85%—Sherlockim29/3/202117/6/2026
Sherlock SherlockIM through 2021-03-29 allows Cross Site Scripting (XSS) by leveraging the api/Files/Attachment URI to attack help-desk staff via the chatbot feature.
ModificadaCrítica (9.8)0.98%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user18/3/202117/6/2026
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
ModificadaCrítica (9.8)1.8%—Hgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.
ModificadaAlta (7.6)0.61%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
ModificadaAlta (7.6)0.61%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
ModificadaMedia (6.1)0.62%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
ModificadaMedia (6.1)0.62%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
ModificadaAlta (7.5)1.1%—Hgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-user31/12/202017/6/2026
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
ModificadaCrítica (9.8)1.7%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-auditHgiga Msr45 Isherlock-baseHgiga Msr45 Isherlock-user+631/12/202017/6/2026
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
ModificadaAlta (8.8)0.67%—Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+43/6/201917/6/2026
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes.
ModificadaAlta (8.8)0.67%—Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+43/6/201917/6/2026
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&new=hacker@socialengineering.com&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes.
ModificadaMedia (5.3)1.2%—Hgiga Oaklouds Mailsherlock11/2/201917/6/2026
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.
ModificadaCrítica (9.8)7.3%—Teledynedalsa Sherlock28/11/201817/6/2026
A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, which may allow remote code execution.