Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

251 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.7)0.34%—Axigen WebmailAI1/4/202417/6/2026
WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer.
ModificadaMedia (6.1)0.19%—Axigen Mobile Webmail8/2/202417/6/2026
WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage of SSL certificates.
ModificadaMedia (6.1)0.92%💥 ExploitSuperwebmailer7/2/202417/6/2026
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
AnalizadaMedia (6.1)0.37%—Mail2world Webmail7/2/202417/6/2026
Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp.
ModificadaMedia (5.4)1.1%💥 ExploitAxigen Mobile Webmail7/2/202417/6/2026
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.
ModificadaMedia (6.1)0.64%—Roundcube WebmailFedoraproject FedoraDebian Linux6/11/202317/6/2026
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
ModificadaMedia (6.1)1.1%💥 ExploitSuperwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
ModificadaAlta (8.8)1.3%—Superwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
ModificadaMedia (6.1)1.1%💥 ExploitSuperwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.
ModificadaAlta (8.8)0.66%—Superwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.
ModificadaMedia (6.1)0.48%—Superwebmailer20/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.
AnalizadaMedia (5.4)76%⚠ Explotación activaRoundcube WebmailDebian LinuxFedoraproject Fedora18/10/202317/6/2026
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
AnalizadaMedia (6.1)64%⚠ Explotación activa💥 PoCRoundcube WebmailDebian Linux22/9/202317/6/2026
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
ModificadaMedia (5.4)1.2%—Rainloop Webmail28/7/202217/6/2026
The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
ModificadaMedia (6.1)53%💥 ExploitAxigen Mobile Webmail7/6/202217/6/2026
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.
ModificadaMedia (5.5)0.25%—Ciphermail Webmail Messenger26/4/202217/6/2026
An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).
AnalizadaCrítica (9.8)70%⚠ Explotación activa💥 PoCRoundcube WebmailFedoraproject FedoraDebian Linux19/11/202117/6/2026
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
ModificadaMedia (6.1)1.2%—Roundcube WebmailFedoraproject FedoraDebian Linux19/11/202117/6/2026
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
ModificadaMedia (5.4)0.81%—Roundcube Webmail24/6/202117/6/2026
Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.
ModificadaMedia (5.4)0.92%—Roundcube Webmail24/6/202117/6/2026
Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.
ModificadaAlta (7.5)17%💥 ExploitAfterlogic AuroraAfterlogic Webmail PRO7/3/202117/6/2026
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with…
ModificadaCrítica (9.8)7.1%—Afterlogic AuroraAfterlogic Webmail PRO4/3/202117/6/2026
An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.
ModificadaMedia (5.4)1.0%—Roundcube WebmailFedoraproject Fedora9/2/202117/6/2026
Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.
ModificadaMedia (5.4)3.2%💥 ExploitAltn Mdaemon Webmail3/2/202117/6/2026
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.
ModificadaMedia (5.4)3.8%💥 ExploitAltn Mdaemon Webmail3/2/202117/6/2026
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.
Orbitaley — Vulnerabilidades