Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Vdesk Webmail | 17/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in printcal.pl in vDesk Webmail 4.03 allows remote attackers to inject arbitrary web script or HTML via the type parameter. | |
| Modificada | Alta (7.5) | 3.9% | — | Netwin SurgemailNetwin Webmail | 14/5/2007 | 16/6/2026 | Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string vulnerability that allows remote code execution. | |
| Modificada | Media (6.8) | 1.2% | — | Atmail Webmail | 19/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Afterlogic Mailbee Webmail | 18/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Atmail Webmail | 15/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.pl in @Mail 4.61 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Calacode Atmail Webmail System | 23/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in @Mail WebMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. | |
| Modificada | Media (6.8) | 1.2% | — | Atmail Webmail | 23/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before 4.61 allows remote attackers to inject arbitrary web script or HTML via crafted e-mail messages. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.98% | — | Atmail Webmail | 23/12/2006 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify arbitrary settings and perform unauthorized actions as an arbitrary user, as demonstrated using a settings action in the SRC attribute of an IMG element in an HTML e-mail. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Mirapoint Webmail | 4/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated using the width style for an IMG element. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Nuralstorm Webmail | 18/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DEFAULT_SKIN parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Vamp Webmail | 5/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in wamp_dir/setup/yesno.phtml in VAMP Webmail 2.0beta1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the no_url parameter. | |
| Modificada | Media (5.1) | 3.0% | 💥 Exploit | Basilix Webmail | 5/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) BSX_LIBDIR parameter in scripts in /files/ including (a) abook.php3, (b) compose-attach.php3, (c) compose-menu.php3, (d) compose-new.php3, (e) compose-send.php3, (f)… | |
| Modificada | Media (6.8) | 4.8% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users. | |
| Modificada | Alta (7.5) | 2.6% | — | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a predictable filename. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4) sortkey_desc parameters in the (b) maillist servlet. | |
| Modificada | Media (4.3) | 1.3% | — | Open Webmail | 27/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in openwebmail-read.pl in Open WebMail (OWM) 2.52, and other versions released before 06/18/2006, allows remote attackers to inject arbitrary web script or HTML via the from field. NOTE: some third party sources have mentioned the "to" and "from" fields, although CVE analysis… | |
| Modificada | Media (4.3) | 1.2% | — | Open Webmail | 27/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Open WebMail (OWM) 2.52, and other versions released before 05/12/2006, allows remote attackers to inject arbitrary web script or HTML via the (1) To and (2) From fields in openwebmail-main.pl, and possibly (3) other unspecified vectors related to "openwebmailerror calls… | |
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | V-webmail | 30/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | V-webmail | 30/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Open Webmail | 4/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ow-shared.pl in OpenWebMail (OWM) 2.51 and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter in (1) openwebmail-send.pl, (2) openwebmail-advsearch.pl, (3) openwebmail-folder.pl, (4) openwebmail-prefs.pl, (5)… | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Igenus Webmail | 7/3/2006 | 16/6/2026 | config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Calacode Atmail Webmail System | 22/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or HTML via a modified javascript: string in the SRC attribute of an IMG element in an e-mail message, as demonstrated by "java	script:." NOTE: the provenance of this information is unknown; the… |