Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 4.1% | 💥 Exploit | Icewarp Email ServerIcewarp Webmail Server | 5/5/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2)… | |
| Modificada | Media (4.3) | 2.0% | — | Roundcube Webmail | 3/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message. | |
| Modificada | Alta (7.8) | 2.6% | — | Roundcube Webmail | 17/12/2008 | 16/6/2026 | RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of service (memory consumption) via crafted size parameters that are used to create a large quota image. | |
| Modificada | Alta (10) | 59% | 💥 Exploit | Roundcube Webmail | 17/12/2008 | 16/6/2026 | html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch. | |
| Modificada | Alta (9) | 5.5% | 💥 Exploit | Comingchina U-mail Webmail Server | 5/11/2008 | 16/6/2026 | webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root. | |
| Modificada | Media (4.3) | 1.0% | — | V-webmail | 8/10/2008 | 16/6/2026 | Open redirect vulnerability in redirect.php in V-webmail 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the to parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | V-webmail | 8/10/2008 | 16/6/2026 | SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (5) | 1.2% | — | V-webmail | 8/10/2008 | 16/6/2026 | V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error message. | |
| Modificada | Alta (9) | 1.0% | — | Horde Groupware Webmail Edition | 13/8/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unescaped output," possibly cross-site scripting (XSS), in the (1) object browser and (2) contact view. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Horde GroupwareHorde Groupware Webmail EditionHorde Kronolith | 19/6/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php, (2) workweek.php, and (3) day.php; and (4) the horde parameter in the PATH_INFO to the default URI.… | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Horde GroupwareHorde Groupware Webmail Edition | 27/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (6) | 1.7% | — | Horde GroupwareHorde Groupware Webmail EditionHorde | 11/3/2008 | 16/6/2026 | Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name. | |
| Modificada | Alta (7.5) | 7.9% | 💥 Exploit | Netwin SurgemailNetwin Webmail | 27/2/2008 | 16/6/2026 | Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter. | |
| Modificada | Media (4.9) | 1.4% | — | Horde GroupwareHorde Groupware Webmail EditionHorde Turba Contact Manager | 19/2/2008 | 16/6/2026 | lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a… | |
| Modificada | Media (5) | 12% | 💥 Exploit | Afterlogic Mailbee Webmail PRO | 17/1/2008 | 16/6/2026 | Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the temp_filename parameter. | |
| Modificada | Media (5.8) | 1.8% | — | Horde FrameworkHorde Groupware Webmail EditionHordeHorde IMP | 11/1/2008 | 16/6/2026 | IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message. | |
| Modificada | Media (6.4) | 2.1% | 💥 Exploit | Uebimiau Webmail | 10/1/2008 | 16/6/2026 | Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using… | |
| Modificada | Media (6.4) | 2.3% | 💥 Exploit | Uebimiau Webmail | 8/1/2008 | 16/6/2026 | Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the selected_theme parameter, a different vector than CVE-2007-3172. | |
| Modificada | Media (4.3) | 5.4% | 💥 Exploit | Roundcube Webmail | 12/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands. | |
| Modificada | Media (4.3) | 1.2% | — | Calacode Atmail Webmail System | 1/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail before 5.2 allows remote attackers to inject arbitrary web script or HTML via the func parameter. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Afterlogic Mailbee Webmail | 9/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMail Lite ASP before 4.0.11, and WebMail Lite PHP before 4.0.22; allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to login.php and… | |
| Modificada | Media (4.3) | 1.0% | — | Open Webmail | 7/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Open Webmail (OWM) 2.52 20060831 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) searchtype, (2) longpage, and (3) page parameters to (a) openwebmail-main.pl; the (4) prefs_caller, (5) userfirsttime, (6) page, (7) sort, (8)… | |
| Modificada | Media (6.8) | 1.5% | — | Madirish Webmail | 6/6/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Madirish Webmail 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter to (1) calendar.php, (2) compose.php, and (3) index.php, different vectors than CVE-2007-2826. NOTE: the provenance of this information is unknown;… | |
| Modificada | Media (4.3) | 1.2% | — | Atmail Webmail | 22/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ReadMsg.php in @Mail 5.02 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) links and (2) images. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Madirish Webmail | 22/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter. |