Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.49% | — | Hgiga Oaklouds Mailsherlock | 27/3/2023 | 17/6/2026 | HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conducting a reflected XSS attack. | |
| Modificada | Media (6.1) | 0.85% | — | Sherlockim | 29/3/2021 | 17/6/2026 | Sherlock SherlockIM through 2021-03-29 allows Cross Site Scripting (XSS) by leveraging the api/Files/Attachment URI to attack help-desk staff via the chatbot feature. | |
| Modificada | Crítica (9.8) | 0.98% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 18/3/2021 | 17/6/2026 | HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege. | |
| Modificada | Crítica (9.8) | 1.8% | — | Hgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system. | |
| Modificada | Alta (7.6) | 0.61% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages. | |
| Modificada | Alta (7.6) | 0.61% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter. | |
| Modificada | Media (6.1) | 0.62% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks. | |
| Modificada | Media (6.1) | 0.62% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks. | |
| Modificada | Alta (7.5) | 1.1% | — | Hgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-user | 31/12/2020 | 17/6/2026 | The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files. | |
| Modificada | Crítica (9.8) | 1.7% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-auditHgiga Msr45 Isherlock-baseHgiga Msr45 Isherlock-user+6 | 31/12/2020 | 17/6/2026 | HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism. | |
| Modificada | Alta (8.8) | 0.67% | — | Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+4 | 3/6/2019 | 17/6/2026 | Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes. | |
| Modificada | Alta (8.8) | 0.67% | — | Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+4 | 3/6/2019 | 17/6/2026 | Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&new=hacker@socialengineering.com&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes. | |
| Modificada | Media (5.3) | 1.2% | — | Hgiga Oaklouds Mailsherlock | 11/2/2019 | 17/6/2026 | SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request. | |
| Modificada | Crítica (9.8) | 7.3% | — | Teledynedalsa Sherlock | 28/11/2018 | 17/6/2026 | A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, which may allow remote code execution. |