Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.44%—Watchguard Dimension Email ServerAI28/8/202628/8/2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
AnalizadaMedia (5.3)0.64%—Mdaemon Email Server29/4/202517/6/2026
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.
ModificadaMedia (5.4)0.55%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.
ModificadaMedia (5.4)0.55%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
ModificadaCrítica (9.8)1.4%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.
ModificadaCrítica (9.8)1.4%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
ModificadaMedia (5.4)0.60%—Altn Mdaemon Email Server17/12/201917/6/2026
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
ModificadaAlta (7.5)1.3%—Altn Mdaemon Email Server16/7/201917/6/2026
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a…
ModificadaMedia (5.5)0.40%—Avast Business SecurityAvast Free AntivirusAvast Internet SecurityAvast Premier+73/11/201617/6/2026
Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x…
ModificadaMedia (4.3)2.0%—Emailarchitect Email Server20/6/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an email.
ModificadaMedia (4.3)4.9%—Icewarp Email ServerIcewarp Webmail Server5/5/200916/6/2026
CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as…
ModificadaMedia (6.5)1.9%—Icewarp Email ServerIcewarp Webmail Server5/5/200916/6/2026
Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.
ModificadaMedia (4.3)4.1%—Icewarp Email ServerIcewarp Webmail Server5/5/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2)…
ModificadaAlta (7.6)2.8%—Mcafee Active Virus DefenseMcafee Active VirusscanMcafee Email GatewayMcafee Internet Security Suite+930/4/200916/6/2026
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in…
ModificadaMedia (5)2.7%—Noticeware Email Server NG19/2/200916/6/2026
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command.
ModificadaMedia (5)2.7%—Noticeware Email Server12/8/200816/6/2026
The IMAP server in NoticeWare Email Server NG 4.6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via multiple long LOGIN commands.
ModificadaMedia (5)2.6%—Noticeware Email Server9/4/200816/6/2026
MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application crash) via a long string to IMAP port (143/tcp).
ModificadaMedia (4.3)1.4%—Emailarchitect Email Server21/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in EmailArchitect Email Server 6.1 allows remote attackers to inject arbitrary Javascript via an HTML div tag with a carriage return between the onmouseover attribute and its value, which bypasses the mail filter.
ModificadaBaja (2.6)1.9%—Emailarchitect Email Server12/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and (c) /additional/regdomain_done.asp.
ModificadaAlta (10)7.4%—Foxmail Email Server2/5/200516/6/2026
Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.
ModificadaAlta (10)7.6%—Foxmail Email Server2/5/200516/6/2026
Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command.