Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Fatpipeinc Ipvpn FirmwareFatpipeinc Mpvpn FirmwareFatpipeinc Warp Firmware | 15/12/2021 | 17/6/2026 | A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges. Older versions of FatPipe software may… | |
| Modificada | Media (5.3) | 2.7% | 💥 Exploit | Fatpipeinc Ipvpn FirmwareFatpipeinc Mpvpn FirmwareFatpipeinc Warp Firmware | 15/12/2021 | 17/6/2026 | A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some violation of confidentiality. Older versions… | |
| Modificada | Alta (7.5) | 1.8% | — | Fatpipeinc Ipvpn FirmwareFatpipeinc Mpvpn FirmwareFatpipeinc Warp Firmware | 15/12/2021 | 17/6/2026 | A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly guess the hostname of the target system… | |
| Modificada | Crítica (9.8) | 5.6% | 💥 Exploit | Fatpipeinc Ipvpn FirmwareFatpipeinc Mpvpn FirmwareFatpipeinc Warp Firmware | 15/12/2021 | 17/6/2026 | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002. | |
| Modificada | Alta (8.8) | 1.6% | — | Fatpipeinc Ipvpn FirmwareFatpipeinc Warp FirmwareFatpipeinc Mpvpn Firmware | 15/12/2021 | 17/6/2026 | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privileges to grant themselves administrative privileges. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is… | |
| Analizada | Alta (8.8) | 40% | ⚠ Explotación activa | Fatpipeinc Ipvpn FirmwareFatpipeinc Warp FirmwareFatpipeinc Mpvpn Firmware | 8/12/2021 | 17/6/2026 | A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006. | |
| Modificada | Media (6.1) | 1.0% | — | Icewarp Webclient | 7/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4" field. | |
| Modificada | Alta (7.8) | 0.27% | — | Cloudflare Warp | 3/2/2021 | 17/6/2026 | Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process running with non-administrative privileges can become an administrator by abusing the unquoted service path issue. Since version 1.2.2695.1, the vulnerability was fixed by adding quotes around the… | |
| Modificada | Media (6.1) | 5.3% | 💥 Exploit | Icewarp Mail Server | 2/11/2020 | 17/6/2026 | IceWarp 11.4.5.0 allows XSS via the language parameter. | |
| Modificada | Alta (8.8) | 1.8% | 💥 PoC | Icewarp Mail Server | 15/7/2020 | 17/6/2026 | IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access. | |
| Modificada | Media (6.5) | 1.5% | 💥 PoC | Icewarp Mail Server | 15/7/2020 | 17/6/2026 | IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space. | |
| Modificada | Media (6.5) | 0.97% | 💥 PoC | Icewarp Mail Server | 15/7/2020 | 17/6/2026 | IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts. | |
| Modificada | Media (6.1) | 15% | 💥 Exploit | Icewarp Server | 1/2/2020 | 17/6/2026 | In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Icewarp Mail Server | 6/1/2020 | 17/6/2026 | IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts. | |
| Modificada | Media (5.4) | 0.72% | — | Icewarp Mail Server | 6/1/2020 | 17/6/2026 | IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects. | |
| Modificada | Media (6.1) | 0.84% | — | Icewarp Webclient | 11/10/2019 | 16/6/2026 | IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0. | |
| Modificada | Media (6.1) | 0.84% | — | Icewarp Webclient | 11/10/2019 | 16/6/2026 | IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0. | |
| Modificada | Media (6.1) | 0.84% | — | Icewarp Webclient | 11/10/2019 | 16/6/2026 | IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3 and 10.2.0. | |
| Modificada | Media (6.1) | 0.84% | — | Icewarp Webclient | 11/10/2019 | 16/6/2026 | IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0. | |
| Modificada | Media (6.1) | 0.84% | — | Icewarp Webclient | 11/10/2019 | 16/6/2026 | IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0. | |
| Modificada | Alta (7.5) | 2.8% | — | Icewarp Webclient | 11/10/2019 | 16/6/2026 | IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can therefore be exploited to browse the… | |
| Modificada | Alta (7.5) | 2.6% | — | Icewarp Webclient | 11/10/2019 | 16/6/2026 | IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be exploited to browse the partition where… | |
| Modificada | Alta (7.5) | 41% | 💥 Exploit | Icewarp Mail Server | 3/6/2019 | 17/6/2026 | IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal. | |
| Modificada | Media (6.1) | 1.1% | — | Icewarp Mail Server | 1/9/2018 | 17/6/2026 | In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field. | |
| Modificada | Media (6.1) | 0.96% | — | Icewarp Mail Server | 30/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML. |