Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.96% | — | Icewarp Mail Server | 30/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Alta (7.5) | 58% | 💥 Exploit | Icewarp Mail Server | 8/5/2018 | 17/6/2026 | Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to… | |
| Modificada | Alta (8.8) | 3.3% | — | Magicwinmail Winmail Server | 14/1/2018 | 17/6/2026 | Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php copy_folder_file call (in inc/class.ftpfolder.php) to move a .php file from the FTP folder into a web folder. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Codecrafters Ability Mail Server | 20/12/2017 | 17/6/2026 | Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4. | |
| Modificada | Media (5.3) | 4.5% | 💥 Exploit | Argosoft Mini Mail Server | 24/10/2017 | 17/6/2026 | Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite loop. | |
| Modificada | Media (5.4) | 1.6% | — | Axigen Mail Server | 23/10/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email attachment. | |
| Modificada | Crítica (9.8) | 2.5% | — | Ipswitch Imail Server | 3/10/2017 | 17/6/2026 | Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vectors in IMmailSrv, aka ETRE or ETCTERARED. | |
| Modificada | Crítica (9.8) | 2.5% | — | Ipswitch Imail Server | 3/10/2017 | 17/6/2026 | Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vectors in IMmailSrv, aka ETBL or ETCETERABLUE. | |
| Modificada | Media (4.8) | 0.78% | — | Icewarp Mail Server | 23/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted user name. | |
| Modificada | Alta (8.8) | 2.8% | — | Magicwinmail Winmail Server | 24/6/2017 | 17/6/2026 | Winmail Server 6.1 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php move_folder_file call to move a .php file from the FTP folder into a web folder. | |
| Modificada | Media (5.5) | 0.40% | — | Avast Business SecurityAvast Free AntivirusAvast Internet SecurityAvast Premier+7 | 3/11/2016 | 17/6/2026 | Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Emailarchitect Email Server | 20/6/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an email. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Axigen Mail Server | 18/6/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Ipswitch Imail Server | 5/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact action in the Contacts section or unspecified vectors in (2) an… | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Code-crafters Ability Mail Server | 21/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email. | |
| Modificada | Media (6.4) | 85% | 💥 Exploit | Gecad Axigen Free Mail Server | 31/10/2012 | 16/6/2026 | Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in (2) an edit action… | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Winwebmail Server | 12/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an… | |
| Modificada | Media (5) | 1.6% | — | Icewarp Mail Server | 30/9/2011 | 16/6/2026 | IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function. | |
| Modificada | Media (6.4) | 4.8% | 💥 Exploit | Icewarp Mail Server | 30/9/2011 | 16/6/2026 | server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference. | |
| Modificada | Media (5) | 8.4% | 💥 Exploit | Gecad Axigen Mail Server | 17/9/2010 | 16/6/2026 | Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL. | |
| Modificada | Media (4.3) | 1.3% | — | Gecad Axigen Mail Server | 17/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Ajax WebMail interface in AXIGEN Mail Server before 7.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.2% | — | Code-crafters Ability Mail Server | 28/9/2009 | 16/6/2026 | Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Pablosoftwaresolutions Quick'n Easy Mail Server | 11/5/2009 | 16/6/2026 | Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outage or CPU consumption) via multiple long SMTP commands, as demonstrated by HELO commands. | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Icewarp Email ServerIcewarp Webmail Server | 5/5/2009 | 16/6/2026 | CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as… | |
| Modificada | Media (6.5) | 1.9% | 💥 Exploit | Icewarp Email ServerIcewarp Webmail Server | 5/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query. |