Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Icewarp WEB MailMerak Mail Server | 12/10/2004 | 16/6/2026 | viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary files via the originalfolder parameter or (2) move arbitrary files via the messageid parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Icewarp WEB Mail | 12/10/2004 | 16/6/2026 | accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text files with arbitrary content via the accountid parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Icewarp WEB Mail | 12/10/2004 | 16/6/2026 | attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attachments by specifying the username and message ID in an HTTP request. | |
| Modificada | Media (4.3) | 1.2% | — | Icewarp WEB MailMerak Mail Server | 10/9/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html. | |
| Modificada | Alta (7.5) | 1.8% | — | Icewarp WEB MailMerak Mail Server | 10/9/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ....// (doubled dot dot) in the… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Pscs Vpop3 WEB Mail Server | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page. | |
| Modificada | Media (4.3) | 1.3% | — | Icewarp WEB Mail | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IceWarp Web Mail 3.3.3 and 3.4.5 allows remote attackers to inject arbitrary web script or HTML via the "Full Name" (addressname) parameter. | |
| Modificada | Alta (10) | 2.7% | — | Instant WEB Mail | 12/8/2002 | 16/6/2026 | Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain mail message headers via numerous parameters in write.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Icewarp WEB MailMerak Mail Server | 29/5/2002 | 16/6/2026 | Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or forward URLs. |