Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.26% | — | Cyrus Imap | 9/9/2026 | 16/9/2026 | An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be… | |
| Analizada | Media (4.3) | 0.22% | — | Cyrus Imap | 9/9/2026 | 16/9/2026 | An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery. | |
| Analizada | Media (5) | 0.19% | — | Cyrus Imap | 9/9/2026 | 16/9/2026 | An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the… | |
| Analizada | Media (4.3) | 0.20% | — | Cyrus Imap | 9/9/2026 | 16/9/2026 | An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget… | |
| Analizada | Media (6.5) | 0.22% | — | Cyrus Imap | 9/9/2026 | 16/9/2026 | An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing… | |
| Aplazada | Media (4.3) | 0.21% | — | Cyrus ImapAI | 9/9/2026 | 14/9/2026 | An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no… | |
| Aplazada | Media (4.3) | 0.27% | — | ImapAI | 28/8/2026 | 3/9/2026 | An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the client, which may include sensitive data. Disable the IMAP URLAUTH functionality. Update to… | |
| Aplazada | Baja (3.7) | 0.26% | — | ImapAI | 28/8/2026 | 3/9/2026 | When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the… | |
| Aplazada | Media (6.5) | 0.33% | — | ImapAI | 28/8/2026 | 3/9/2026 | An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not addressed by that fix. Whenever a mail… | |
| Aplazada | Media (4.3) | 0.55% | — | Imap-hibernateAI | 28/8/2026 | 3/9/2026 | An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for… | |
| Aplazada | Media (6.5) | 0.33% | — | ImapAI | 28/8/2026 | 3/9/2026 | An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU… | |
| Aplazada | Alta (7.1) | 0.55% | — | Courier ImapAICourier Mail ServerAI | 29/7/2026 | 30/7/2026 | Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with… | |
| Aplazada | Media (4.3) | 0.28% | — | Cyrus-imapdAI | 16/7/2026 | 17/7/2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin… | |
| Aplazada | Baja (3.1) | 0.27% | — | Cyrus ImapdAI | 16/7/2026 | 17/7/2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory,… | |
| Aplazada | Baja (3.5) | 0.29% | — | Cyrus ImapdAI | 16/7/2026 | 17/7/2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked. | |
| Aplazada | Baja (3.5) | 0.27% | — | Cyrus ImapdAI | 16/7/2026 | 17/7/2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no… | |
| Aplazada | Media (4) | 0.30% | — | Cyrus ImapdAI | 16/7/2026 | 17/7/2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a… | |
| Aplazada | Media (6.5) | 0.35% | — | Cyrus ImapdAI | 16/7/2026 | 17/7/2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions. | |
| Aplazada | Media (4.3) | 0.31% | — | Cyrus-imapdAI | 16/7/2026 | 17/7/2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content… | |
| Aplazada | Media (5.4) | 0.30% | — | Cyrus ImapdAI | 16/7/2026 | 17/7/2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to save a copy of the sent message) could deliver vacation auto-reply copies into any mailbox the script could name, regardless of whether the… | |
| Aplazada | Baja (3.1) | 0.24% | — | Cyrus ImapdAI | 16/7/2026 | 17/7/2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification… | |
| Aplazada | Media (5.8) | 0.18% | — | Ruby NET ImapAI | 22/6/2026 | 23/6/2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While… | |
| Aplazada | Baja (2.1) | 0.38% | — | Ruby NET ImapAI | 22/6/2026 | 23/6/2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated to prevent CRLF injection and then sent verbatim. If this string is derived from user-controlled input, an attacker can… | |
| Aplazada | Media (5.8) | 0.83% | — | Ruby NET ImapAI | 22/6/2026 | 23/6/2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a "raw data" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may… | |
| Aplazada | Media (6.5) | 0.19% | — | OfflineimapAI | 8/6/2026 | 23/7/2026 | OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext. |