Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

251 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.4%—V-webmail19/2/200616/6/2026
help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.8%💥 ExploitV-webmail19/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the newid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)1.4%—V-webmail19/2/200616/6/2026
frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)1.4%—Roundcube Webmail20/12/200516/6/2026
roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message.
ModificadaMedia (4.3)1.2%—Open Webmail8/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in openwebmail-main.pl in OpenWebMail 2.41 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.
ModificadaMedia (4.3)2.2%—Inter7 Sqwebmail7/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]".
ModificadaMedia (4.3)2.7%💥 ExploitInter7 Sqwebmail2/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.
ModificadaMedia (4.3)1.8%—Inter7 Sqwebmail30/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been disputed by the developer.
ModificadaMedia (4.3)0.94%—Nikosoft Webmail1/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in NikoSoft WebMail before 0.11.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaAlta (7.5)2.1%—Open Webmail3/5/200516/6/2026
Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.
ModificadaMedia (4.3)1.3%—Open Webmail2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.
ModificadaMedia (5)1.5%—Captaris Infinite Mobile Delivery Webmail2/5/200516/6/2026
Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message.
ModificadaMedia (4.3)1.3%—Captaris Infinite Mobile Delivery Webmail2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL.
ModificadaAlta (7.5)2.3%💥 ExploitInter7 Sqwebmail15/4/200516/6/2026
SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.
ModificadaMedia (4.3)2.0%💥 ExploitNetwin SurgemailNetwin Webmail31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the…
ModificadaMedia (4.3)4.8%💥 ExploitEmumail EMU Webmail31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-encoded value to the variable parameter in emumail.fcgi, (2) the folder parameter in emumail.fcgi, or Javascript in the (3) username or (4) password field in the login…
ModificadaMedia (4.3)1.4%—Calacode AT Mail Webmail System31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for Windows allow remote attackers to inject arbitrary web script or HTML via (1) the Displayed Name attribute in util.pl and (2) the Folder attribute in showmail.pl.
ModificadaMedia (5)1.6%—Inter7 Sqwebmail31/12/200416/6/2026
Inter7 SqWebMail 3.4.1 through 3.6.1 generates different error messages for incorrect passwords versus correct passwords on non-mail-enabled accounts (such as root), which allows remote attackers to guess the root password via brute force attacks.
ModificadaBaja (2.6)3.1%💥 ExploitNetwin SurgemailNetwin Webmail31/12/200416/6/2026
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.
ModificadaAlta (10)3.4%—Open Webmail31/12/200416/6/2026
The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument.
ModificadaMedia (5)1.9%—Calacode AT Mail Webmail System31/12/200416/6/2026
@Mail 3.64 for Windows allows remote attackers to cause a denial of service ("unusable" server) via a large number of POP3 connections to the server.
ModificadaMedia (5)6.7%💥 ExploitEmumail EMU Webmail31/12/200416/6/2026
EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu.
ModificadaMedia (5)1.4%—Open Webmail31/12/200416/6/2026
Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories.
ModificadaMedia (6.8)7.1%💥 ExploitOpen WebmailSGI PropackSquirrelmail18/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.
ModificadaMedia (6.8)6.0%💥 ExploitOpen WebmailSGI PropackSquirrelmail6/8/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable…
Orbitaley — Vulnerabilidades