Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | V-webmail | 19/2/2006 | 16/6/2026 | help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | V-webmail | 19/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the newid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 1.4% | — | V-webmail | 19/2/2006 | 16/6/2026 | frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 1.4% | — | Roundcube Webmail | 20/12/2005 | 16/6/2026 | roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message. | |
| Modificada | Media (4.3) | 1.2% | — | Open Webmail | 8/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in openwebmail-main.pl in OpenWebMail 2.41 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter. | |
| Modificada | Media (4.3) | 2.2% | — | Inter7 Sqwebmail | 7/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]". | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | Inter7 Sqwebmail | 2/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail. | |
| Modificada | Media (4.3) | 1.8% | — | Inter7 Sqwebmail | 30/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been disputed by the developer. | |
| Modificada | Media (4.3) | 0.94% | — | Nikosoft Webmail | 1/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NikoSoft WebMail before 0.11.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Open Webmail | 3/5/2005 | 16/6/2026 | Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename. | |
| Modificada | Media (4.3) | 1.3% | — | Open Webmail | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page. | |
| Modificada | Media (5) | 1.5% | — | Captaris Infinite Mobile Delivery Webmail | 2/5/2005 | 16/6/2026 | Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 1.3% | — | Captaris Infinite Mobile Delivery Webmail | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Inter7 Sqwebmail | 15/4/2005 | 16/6/2026 | SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Netwin SurgemailNetwin Webmail | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the… | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Emumail EMU Webmail | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-encoded value to the variable parameter in emumail.fcgi, (2) the folder parameter in emumail.fcgi, or Javascript in the (3) username or (4) password field in the login… | |
| Modificada | Media (4.3) | 1.4% | — | Calacode AT Mail Webmail System | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for Windows allow remote attackers to inject arbitrary web script or HTML via (1) the Displayed Name attribute in util.pl and (2) the Folder attribute in showmail.pl. | |
| Modificada | Media (5) | 1.6% | — | Inter7 Sqwebmail | 31/12/2004 | 16/6/2026 | Inter7 SqWebMail 3.4.1 through 3.6.1 generates different error messages for incorrect passwords versus correct passwords on non-mail-enabled accounts (such as root), which allows remote attackers to guess the root password via brute force attacks. | |
| Modificada | Baja (2.6) | 3.1% | 💥 Exploit | Netwin SurgemailNetwin Webmail | 31/12/2004 | 16/6/2026 | NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message. | |
| Modificada | Alta (10) | 3.4% | — | Open Webmail | 31/12/2004 | 16/6/2026 | The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument. | |
| Modificada | Media (5) | 1.9% | — | Calacode AT Mail Webmail System | 31/12/2004 | 16/6/2026 | @Mail 3.64 for Windows allows remote attackers to cause a denial of service ("unusable" server) via a large number of POP3 connections to the server. | |
| Modificada | Media (5) | 6.7% | 💥 Exploit | Emumail EMU Webmail | 31/12/2004 | 16/6/2026 | EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu. | |
| Modificada | Media (5) | 1.4% | — | Open Webmail | 31/12/2004 | 16/6/2026 | Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories. | |
| Modificada | Media (6.8) | 7.1% | 💥 Exploit | Open WebmailSGI PropackSquirrelmail | 18/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php. | |
| Modificada | Media (6.8) | 6.0% | 💥 Exploit | Open WebmailSGI PropackSquirrelmail | 6/8/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable… |