Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

877 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.6)1.9%—Emailarchitect Email Server12/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and (c) /additional/regdomain_done.asp.
ModificadaBaja (2.1)0.36%—Iopus Secure Email Attachments26/4/200616/6/2026
iOpus Secure Email Attachments (SEA), probably 1.0, does not properly handle passwords that consist of repetitions of a substring, which allows attackers to decrypt files by entering only the substring.
ModificadaBaja (1.7)0.79%💥 ExploitOI Email Marketing System28/2/200616/6/2026
Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password.
ModificadaAlta (7.5)1.3%—OI Email Marketing System28/2/200616/6/2026
SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
ModificadaMedia (6.5)2.7%—Truenorth Software IA Emailserver23/2/200616/6/2026
Buffer overflow in the IMAP service of TrueNorth Internet Anywhere (IA) eMailserver 5.3.4 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long SEARCH argument.
ModificadaAlta (7.5)3.2%💥 ExploitHivemail18/2/200616/6/2026
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters…
ModificadaMedia (4.3)1.9%💥 ExploitHivemail18/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed when accessed from the…
ModificadaAlta (7.5)1.8%💥 ExploitHivemail18/2/200616/6/2026
Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain…
ModificadaMedia (5)1.1%—Tumbleweed Mailgate Email Firewall1/2/200616/6/2026
Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message under "extremely heavy loads" and (2) cause an "increased number of missed spam" during "spam outbreaks."
ModificadaAlta (7.5)4.6%—Bogofilter Email Filter31/12/200516/6/2026
Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are longer than the input buffer used by flex.
ModificadaAlta (7.5)5.5%—Bogofilter Email Filter31/12/200516/6/2026
Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter…
ModificadaAlta (7.5)2.3%—Libremail16/12/200516/6/2026
Format string vulnerability in the lire_pop function in pop.c in libremail 1.1.0 and earlier, with compiled with the debug option, allows remote attackers to execute arbitrary code via a crafted e-mail or POP server response.
ModificadaAlta (7.5)1.3%💥 ExploitActivecampaign 1-2-all Broadcast Email18/11/200516/6/2026
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.
ModificadaMedia (5)3.1%💥 ExploitTruenorth Software IA Emailserver5/7/200516/6/2026
Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.
ModificadaMedia (4.3)0.94%—Netwin Surgemail24/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaMedia (4.3)1.8%—Netwin Surgemail2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.
ModificadaMedia (5)1.6%—Netwin SurgemailAI2/5/200516/6/2026
Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.
ModificadaAlta (10)7.6%💥 ExploitFoxmail Email Server2/5/200516/6/2026
Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command.
ModificadaAlta (10)7.4%💥 ExploitFoxmail Email Server2/5/200516/6/2026
Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.
ModificadaAlta (10)6.1%💥 ExploitFoxmail Email Server2/3/200516/6/2026
Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.
ModificadaMedia (5)1.9%—Bogofilter Email FilterUbuntu Linux1/3/200516/6/2026
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
ModificadaMedia (5.1)2.6%💥 ExploitOutblaze Email31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag.
ModificadaBaja (2.6)3.1%💥 ExploitNetwin SurgemailNetwin Webmail31/12/200416/6/2026
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.
ModificadaAlta (10)1.7%—Netwin Surgemail31/12/200416/6/2026
Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."
ModificadaMedia (4.3)2.0%💥 ExploitNetwin SurgemailNetwin Webmail31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the…
Orbitaley — Vulnerabilidades