Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.7) | 0.34% | — | Axigen WebmailAI | 1/4/2024 | 17/6/2026 | WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer. | |
| Modificada | Media (6.1) | 0.19% | — | Axigen Mobile Webmail | 8/2/2024 | 17/6/2026 | WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage of SSL certificates. | |
| Modificada | Media (6.1) | 0.92% | 💥 Exploit | Superwebmailer | 7/2/2024 | 17/6/2026 | SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php. | |
| Analizada | Media (6.1) | 0.37% | — | Mail2world Webmail | 7/2/2024 | 17/6/2026 | Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp. | |
| Modificada | Media (5.4) | 1.1% | 💥 Exploit | Axigen Mobile Webmail | 7/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions. | |
| Modificada | Media (6.1) | 0.64% | — | Roundcube WebmailFedoraproject FedoraDebian Linux | 6/11/2023 | 17/6/2026 | Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download). | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Superwebmailer | 21/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter. | |
| Modificada | Alta (8.8) | 1.3% | — | Superwebmailer | 21/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line. | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Superwebmailer | 21/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords. | |
| Modificada | Alta (8.8) | 0.66% | — | Superwebmailer | 21/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter. | |
| Modificada | Media (6.1) | 0.48% | — | Superwebmailer | 20/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename. | |
| Analizada | Media (5.4) | 76% | ⚠ Explotación activa | Roundcube WebmailDebian LinuxFedoraproject Fedora | 18/10/2023 | 17/6/2026 | Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code. | |
| Analizada | Media (6.1) | 64% | ⚠ Explotación activa💥 PoC | Roundcube WebmailDebian Linux | 22/9/2023 | 17/6/2026 | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. | |
| Modificada | Media (5.4) | 1.2% | — | Rainloop Webmail | 28/7/2022 | 17/6/2026 | The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message. | |
| Modificada | Media (6.1) | 53% | 💥 Exploit | Axigen Mobile Webmail | 7/6/2022 | 17/6/2026 | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content. | |
| Modificada | Media (5.5) | 0.25% | — | Ciphermail Webmail Messenger | 26/4/2022 | 17/6/2026 | An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA). | |
| Analizada | Crítica (9.8) | 70% | ⚠ Explotación activa💥 PoC | Roundcube WebmailFedoraproject FedoraDebian Linux | 19/11/2021 | 17/6/2026 | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. | |
| Modificada | Media (6.1) | 1.2% | — | Roundcube WebmailFedoraproject FedoraDebian Linux | 19/11/2021 | 17/6/2026 | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message. | |
| Modificada | Media (5.4) | 0.81% | — | Roundcube Webmail | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php. | |
| Modificada | Media (5.4) | 0.92% | — | Roundcube Webmail | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php. | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Afterlogic AuroraAfterlogic Webmail PRO | 7/3/2021 | 17/6/2026 | An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with… | |
| Modificada | Crítica (9.8) | 7.1% | — | Afterlogic AuroraAfterlogic Webmail PRO | 4/3/2021 | 17/6/2026 | An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x. | |
| Modificada | Media (5.4) | 1.0% | — | Roundcube WebmailFedoraproject Fedora | 9/2/2021 | 17/6/2026 | Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering. | |
| Modificada | Media (5.4) | 3.2% | 💥 Exploit | Altn Mdaemon Webmail | 3/2/2021 | 17/6/2026 | Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list. | |
| Modificada | Media (5.4) | 3.8% | 💥 Exploit | Altn Mdaemon Webmail | 3/2/2021 | 17/6/2026 | Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities. |