Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

251 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)33%⚠ Explotación activa💥 PoCRoundcube WebmailFedoraproject FedoraDebian Linux28/12/202017/6/2026
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
ModificadaMedia (6.1)2.1%—Roundcube WebmailFedoraproject Fedora12/8/202017/6/2026
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
ModificadaCrítica (9.8)33%💥 ExploitSuperwebmailer14/7/202017/6/2026
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.
ModificadaMedia (6.1)2.1%—Roundcube WebmailDebian Linux6/7/202017/6/2026
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.
ModificadaMedia (5.9)0.97%—Ciphermail GatewayCiphermail Webmail Messenger11/6/202017/6/2026
An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger Virtual Appliances 1.1.1 through 3.1.1-0. A Diffie-Hellman parameter of insufficient size could allow man-in-the-middle…
ModificadaAlta (7.2)2.6%—Ciphermail GatewayCiphermail Webmail Messenger11/6/202017/6/2026
An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges to the Unix root account.
AnalizadaMedia (6.1)77%⚠ Explotación activa💥 PoCRoundcube WebmailDebian LinuxFedoraproject Fedora9/6/202017/6/2026
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
ModificadaMedia (6.1)1.0%—Roundcube WebmailFedoraproject FedoraDebian Linux9/6/202017/6/2026
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
AnalizadaCrítica (9.8)84%⚠ Explotación activa💥 ExploitRoundcube WebmailOpensuse Backports SLEOpensuse Leap4/5/202017/6/2026
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
ModificadaCrítica (9.8)6.7%💥 PoCRoundcube WebmailOpensuse Backports SLEOpensuse Leap4/5/202017/6/2026
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
ModificadaMedia (6.5)2.0%—Roundcube WebmailDebian Linux4/5/202017/6/2026
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
ModificadaMedia (6.1)2.8%💥 PoCRoundcube WebmailDebian LinuxOpensuse Backports SLEOpensuse Leap4/5/202017/6/2026
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
ModificadaMedia (6.1)0.87%—Rainloop Webmail20/3/202017/6/2026
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
ModificadaMedia (4.3)1.1%—Basic Webmail Project Basic Webmail8/2/202016/6/2026
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
ModificadaMedia (6.1)0.80%—Afterlogic AuroraAfterlogic Webmail PRO26/11/201917/6/2026
Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.
ModificadaAlta (7.4)1.0%—Roundcube WebmailFedoraproject Fedora20/8/201917/6/2026
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
ModificadaAlta (8.8)1.0%—Altn Mdaemon Webmail19/7/201917/6/2026
MDaemon Webmail (formerly WorldClient) has CSRF.
ModificadaMedia (4.3)0.77%—Roundcube WebmailFedoraproject FedoraOpensuse Backports SLEOpensuse Leap7/4/201917/6/2026
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the…
ModificadaMedia (6.1)0.99%—Mailtraq Webmail12/3/201917/6/2026
Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.
ModificadaMedia (6.1)56%—Roundcube WebmailDebian Linux12/11/201817/6/2026
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
ModificadaAlta (7.5)1.6%—Roundcube Webmail12/11/201817/6/2026
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.
ModificadaMedia (5.9)5.5%—Apple MailBloop AirmailEmclientFlipdogsolutions Maildroid+716/5/201817/6/2026
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a…
ModificadaAlta (8.8)2.3%—Roundcube WebmailDebian Linux7/4/201817/6/2026
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after…
ModificadaAlta (7.5)1.7%—Roundcube Webmail13/3/201817/6/2026
roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.
AnalizadaAlta (7.8)46%⚠ Explotación activa💥 PoCRoundcube WebmailDebian Linux9/11/201717/6/2026
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as…
Orbitaley — Vulnerabilidades