Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
877 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 1.9% | — | Emailarchitect Email Server | 12/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and (c) /additional/regdomain_done.asp. | |
| Modificada | Baja (2.1) | 0.36% | — | Iopus Secure Email Attachments | 26/4/2006 | 16/6/2026 | iOpus Secure Email Attachments (SEA), probably 1.0, does not properly handle passwords that consist of repetitions of a substring, which allows attackers to decrypt files by entering only the substring. | |
| Modificada | Baja (1.7) | 0.79% | 💥 Exploit | OI Email Marketing System | 28/2/2006 | 16/6/2026 | Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password. | |
| Modificada | Alta (7.5) | 1.3% | — | OI Email Marketing System | 28/2/2006 | 16/6/2026 | SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | |
| Modificada | Media (6.5) | 2.7% | — | Truenorth Software IA Emailserver | 23/2/2006 | 16/6/2026 | Buffer overflow in the IMAP service of TrueNorth Internet Anywhere (IA) eMailserver 5.3.4 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long SEARCH argument. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Hivemail | 18/2/2006 | 16/6/2026 | Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters… | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Hivemail | 18/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed when accessed from the… | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Hivemail | 18/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain… | |
| Modificada | Media (5) | 1.1% | — | Tumbleweed Mailgate Email Firewall | 1/2/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message under "extremely heavy loads" and (2) cause an "increased number of missed spam" during "spam outbreaks." | |
| Modificada | Alta (7.5) | 4.6% | — | Bogofilter Email Filter | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are longer than the input buffer used by flex. | |
| Modificada | Alta (7.5) | 5.5% | — | Bogofilter Email Filter | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter… | |
| Modificada | Alta (7.5) | 2.3% | — | Libremail | 16/12/2005 | 16/6/2026 | Format string vulnerability in the lire_pop function in pop.c in libremail 1.1.0 and earlier, with compiled with the debug option, allows remote attackers to execute arbitrary code via a crafted e-mail or POP server response. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Activecampaign 1-2-all Broadcast Email | 18/11/2005 | 16/6/2026 | SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Truenorth Software IA Emailserver | 5/7/2005 | 16/6/2026 | Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument. | |
| Modificada | Media (4.3) | 0.94% | — | Netwin Surgemail | 24/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (4.3) | 1.8% | — | Netwin Surgemail | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field. | |
| Modificada | Media (5) | 1.6% | — | Netwin SurgemailAI | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter. | |
| Modificada | Alta (10) | 7.6% | 💥 Exploit | Foxmail Email Server | 2/5/2005 | 16/6/2026 | Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command. | |
| Modificada | Alta (10) | 7.4% | 💥 Exploit | Foxmail Email Server | 2/5/2005 | 16/6/2026 | Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command. | |
| Modificada | Alta (10) | 6.1% | 💥 Exploit | Foxmail Email Server | 2/3/2005 | 16/6/2026 | Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command. | |
| Modificada | Media (5) | 1.9% | — | Bogofilter Email FilterUbuntu Linux | 1/3/2005 | 16/6/2026 | The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address. | |
| Modificada | Media (5.1) | 2.6% | 💥 Exploit | Outblaze Email | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag. | |
| Modificada | Baja (2.6) | 3.1% | 💥 Exploit | Netwin SurgemailNetwin Webmail | 31/12/2004 | 16/6/2026 | NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message. | |
| Modificada | Alta (10) | 1.7% | — | Netwin Surgemail | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug." | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Netwin SurgemailNetwin Webmail | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the… |