Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

204 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.96%—Icewarp Mail Server30/6/201817/6/2026
Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML.
ModificadaAlta (7.5)58%💥 ExploitIcewarp Mail Server8/5/201817/6/2026
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to…
ModificadaAlta (8.8)3.3%—Magicwinmail Winmail Server14/1/201817/6/2026
Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php copy_folder_file call (in inc/class.ftpfolder.php) to move a .php file from the FTP folder into a web folder.
ModificadaMedia (6.1)1.4%💥 ExploitCodecrafters Ability Mail Server20/12/201717/6/2026
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.
ModificadaMedia (5.3)4.5%💥 ExploitArgosoft Mini Mail Server24/10/201717/6/2026
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite loop.
ModificadaMedia (5.4)1.6%—Axigen Mail Server23/10/201717/6/2026
Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email attachment.
ModificadaCrítica (9.8)2.5%—Ipswitch Imail Server3/10/201717/6/2026
Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vectors in IMmailSrv, aka ETRE or ETCTERARED.
ModificadaCrítica (9.8)2.5%—Ipswitch Imail Server3/10/201717/6/2026
Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vectors in IMmailSrv, aka ETBL or ETCETERABLUE.
ModificadaMedia (4.8)0.78%—Icewarp Mail Server23/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted user name.
ModificadaAlta (8.8)2.8%—Magicwinmail Winmail Server24/6/201717/6/2026
Winmail Server 6.1 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php move_folder_file call to move a .php file from the FTP folder into a web folder.
ModificadaMedia (5.5)0.40%—Avast Business SecurityAvast Free AntivirusAvast Internet SecurityAvast Premier+73/11/201617/6/2026
Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x…
ModificadaMedia (4.3)2.0%💥 ExploitEmailarchitect Email Server20/6/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an email.
ModificadaMedia (4.3)1.8%💥 ExploitAxigen Mail Server18/6/201416/6/2026
Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.
ModificadaMedia (4.3)3.5%💥 ExploitIpswitch Imail Server5/6/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact action in the Contacts section or unspecified vectors in (2) an…
ModificadaMedia (4.3)1.4%💥 ExploitCode-crafters Ability Mail Server21/12/201317/6/2026
Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.
ModificadaMedia (6.4)85%💥 ExploitGecad Axigen Free Mail Server31/10/201216/6/2026
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in (2) an edit action…
ModificadaMedia (4.3)1.3%💥 ExploitWinwebmail Server12/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an…
ModificadaMedia (5)1.6%—Icewarp Mail Server30/9/201116/6/2026
IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function.
ModificadaMedia (6.4)4.8%💥 ExploitIcewarp Mail Server30/9/201116/6/2026
server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.
ModificadaMedia (5)8.4%💥 ExploitGecad Axigen Mail Server17/9/201016/6/2026
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.
ModificadaMedia (4.3)1.3%—Gecad Axigen Mail Server17/9/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Ajax WebMail interface in AXIGEN Mail Server before 7.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)2.2%—Code-crafters Ability Mail Server28/9/200916/6/2026
Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command.
ModificadaMedia (5)2.8%💥 ExploitPablosoftwaresolutions Quick'n Easy Mail Server11/5/200916/6/2026
Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outage or CPU consumption) via multiple long SMTP commands, as demonstrated by HELO commands.
ModificadaMedia (4.3)4.9%💥 ExploitIcewarp Email ServerIcewarp Webmail Server5/5/200916/6/2026
CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as…
ModificadaMedia (6.5)1.9%💥 ExploitIcewarp Email ServerIcewarp Webmail Server5/5/200916/6/2026
Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.