Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 33% | ⚠ Explotación activa💥 PoC | Roundcube WebmailFedoraproject FedoraDebian Linux | 28/12/2020 | 17/6/2026 | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php. | |
| Modificada | Media (6.1) | 2.1% | — | Roundcube WebmailFedoraproject Fedora | 12/8/2020 | 17/6/2026 | Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15. | |
| Modificada | Crítica (9.8) | 33% | 💥 Exploit | Superwebmailer | 14/7/2020 | 17/6/2026 | SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection. | |
| Modificada | Media (6.1) | 2.1% | — | Roundcube WebmailDebian Linux | 6/7/2020 | 17/6/2026 | An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists. | |
| Modificada | Media (5.9) | 0.97% | — | Ciphermail GatewayCiphermail Webmail Messenger | 11/6/2020 | 17/6/2026 | An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger Virtual Appliances 1.1.1 through 3.1.1-0. A Diffie-Hellman parameter of insufficient size could allow man-in-the-middle… | |
| Modificada | Alta (7.2) | 2.6% | — | Ciphermail GatewayCiphermail Webmail Messenger | 11/6/2020 | 17/6/2026 | An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges to the Unix root account. | |
| Analizada | Media (6.1) | 77% | ⚠ Explotación activa💥 PoC | Roundcube WebmailDebian LinuxFedoraproject Fedora | 9/6/2020 | 17/6/2026 | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. | |
| Modificada | Media (6.1) | 1.0% | — | Roundcube WebmailFedoraproject FedoraDebian Linux | 9/6/2020 | 17/6/2026 | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object. | |
| Analizada | Crítica (9.8) | 84% | ⚠ Explotación activa💥 Exploit | Roundcube WebmailOpensuse Backports SLEOpensuse Leap | 4/5/2020 | 17/6/2026 | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | |
| Modificada | Crítica (9.8) | 6.7% | 💥 PoC | Roundcube WebmailOpensuse Backports SLEOpensuse Leap | 4/5/2020 | 17/6/2026 | Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php. | |
| Modificada | Media (6.5) | 2.0% | — | Roundcube WebmailDebian Linux | 4/5/2020 | 17/6/2026 | An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered. | |
| Modificada | Media (6.1) | 2.8% | 💥 PoC | Roundcube WebmailDebian LinuxOpensuse Backports SLEOpensuse Leap | 4/5/2020 | 17/6/2026 | An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message. | |
| Modificada | Media (6.1) | 0.87% | — | Rainloop Webmail | 20/3/2020 | 17/6/2026 | RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header. | |
| Modificada | Media (4.3) | 1.1% | — | Basic Webmail Project Basic Webmail | 8/2/2020 | 16/6/2026 | The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses. | |
| Modificada | Media (6.1) | 0.80% | — | Afterlogic AuroraAfterlogic Webmail PRO | 26/11/2019 | 17/6/2026 | Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name. | |
| Modificada | Alta (7.4) | 1.0% | — | Roundcube WebmailFedoraproject Fedora | 20/8/2019 | 17/6/2026 | Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. | |
| Modificada | Alta (8.8) | 1.0% | — | Altn Mdaemon Webmail | 19/7/2019 | 17/6/2026 | MDaemon Webmail (formerly WorldClient) has CSRF. | |
| Modificada | Media (4.3) | 0.77% | — | Roundcube WebmailFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 7/4/2019 | 17/6/2026 | In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the… | |
| Modificada | Media (6.1) | 0.99% | — | Mailtraq Webmail | 12/3/2019 | 17/6/2026 | Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe. | |
| Modificada | Media (6.1) | 56% | — | Roundcube WebmailDebian Linux | 12/11/2018 | 17/6/2026 | steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment. | |
| Modificada | Alta (7.5) | 1.6% | — | Roundcube Webmail | 12/11/2018 | 17/6/2026 | Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php. | |
| Modificada | Media (5.9) | 5.5% | — | Apple MailBloop AirmailEmclientFlipdogsolutions Maildroid+7 | 16/5/2018 | 17/6/2026 | The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a… | |
| Modificada | Alta (8.8) | 2.3% | — | Roundcube WebmailDebian Linux | 7/4/2018 | 17/6/2026 | In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after… | |
| Modificada | Alta (7.5) | 1.7% | — | Roundcube Webmail | 13/3/2018 | 17/6/2026 | roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity. | |
| Analizada | Alta (7.8) | 46% | ⚠ Explotación activa💥 PoC | Roundcube WebmailDebian Linux | 9/11/2017 | 17/6/2026 | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as… |