Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

204 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)4.1%💥 ExploitIcewarp Email ServerIcewarp Webmail Server5/5/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2)…
ModificadaAlta (7.5)3.2%💥 ExploitIcewarp Merak Mail Server4/5/200916/6/2026
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts…
ModificadaAlta (7.6)2.8%—Mcafee Active Virus DefenseMcafee Active VirusscanMcafee Email GatewayMcafee Internet Security Suite+930/4/200916/6/2026
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in…
ModificadaMedia (4.3)1.3%—Gecad Axigen Mail Server29/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in the web mail interface feature in AXIGEN Mail Server 6.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving e-mail messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaMedia (5)2.7%💥 ExploitNoticeware Email Server NG19/2/200916/6/2026
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command.
ModificadaMedia (4.3)1.1%—Icewarp Merak Mail Server26/12/200816/6/2026
Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message.
ModificadaAlta (9)5.5%💥 ExploitComingchina U-mail Webmail Server5/11/200816/6/2026
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.
ModificadaMedia (4)2.3%💥 ExploitSoftalk Mail Server11/9/200816/6/2026
The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource consumption and daemon crash) via a long IMAP APPEND command with certain repeated parameters.
ModificadaMedia (5)2.7%💥 ExploitNoticeware Email Server12/8/200816/6/2026
The IMAP server in NoticeWare Email Server NG 4.6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via multiple long LOGIN commands.
ModificadaMedia (4.3)1.3%—E-post Corporation Mail Server1/5/200816/6/2026
The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account, which displays the password in a POP3 error message.
ModificadaMedia (5)2.6%💥 ExploitNoticeware Email Server9/4/200816/6/2026
MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application crash) via a long string to IMAP port (143/tcp).
ModificadaAlta (7.5)4.0%—Kerio MailserverVisnetic Antivirus Plug-in FOR Mail Server21/2/200816/6/2026
Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)10%💥 ExploitGecad Technologies Axigen Mail Server23/1/200816/6/2026
Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.
ModificadaMedia (4.3)3.0%💥 ExploitMerak Icewarp Mail Server10/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4)1.4%—Code-crafters Ability Mail Server23/11/200716/6/2026
Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and possibly (2) a blank string in unspecified messages.
ModificadaAlta (7.5)3.2%—Ipswitch Imail ClientIpswitch Imail Server31/10/200716/6/2026
Buffer overflow in IMail Client 9.22, as shipped with IPSwitch IMail Server 2006.22, allows remote attackers to execute arbitrary code via a long boundary parameter in a multipart MIME e-mail message.
ModificadaMedia (4.3)1.1%—Icewarp Merak Mail Server24/9/200716/6/2026
Cross-site scripting (XSS) vulnerability in the Webmail interface for IceWarp Merak Mail Server before 9.0.0 allows remote attackers to inject arbitrary JavaScript via a javascript: URI in an attribute of an element in an email message body, as demonstrated by the onload attribute in a BODY element.
ModificadaAlta (10)16%💥 ExploitHexamail Server31/8/200716/6/2026
Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command.
ModificadaAlta (10)22%💥 ExploitIpswitch Imail ServerIpswitch Collaboration Suite21/7/200716/6/2026
Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to "subscribe."
ModificadaAlta (7.8)2.9%—Ipswitch Imail Server21/7/200716/6/2026
Ipswitch IMail Server 2006 before 2006.21 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving an "overwritten destructor."
ModificadaMedia (6.5)85%💥 ExploitIpswitch Imail ServerIpswitch Collaboration Suite21/7/200716/6/2026
Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.
ModificadaAlta (10)8.7%💥 ExploitGecad Technologies Axigen Mail Server12/2/200716/6/2026
Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an integer overflow.
ModificadaAlta (7.8)10%💥 ExploitGecad Technologies Axigen Mail Server12/2/200716/6/2026
axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp).
ModificadaMedia (4)2.1%—Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server21/7/200616/6/2026
Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer before 8.5.0.5 allows remote authenticated users to include arbitrary files via a modified language parameter and a full Windows or UNC pathname in the…
ModificadaMedia (5)5.7%—Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server21/7/200616/6/2026
Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php…