Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2533▼ 411 respecto a la semana anterior
Críticas / altas1305▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)2.6%—Hgiga IsherlockAI16/4/202617/6/2026
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
AplazadaCrítica (9.3)1.8%—Hgiga IsherlockAI17/10/202517/6/2026
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AplazadaCrítica (9.3)1.4%—Hgiga IsherlockAI14/7/202517/6/2026
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately.
AplazadaCrítica (9.8)1.3%—Hgiga IsherlockAI8/4/202517/6/2026
The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AplazadaCrítica (9.8)1.3%—Hgiga IsherlockAI8/4/202517/6/2026
The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AplazadaCrítica (9.8)1.3%—Hgiga IsherlockAI8/4/202517/6/2026
The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AnalizadaAlta (7.2)2.1%—Hgiga Isherlock29/4/202417/6/2026
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of…
AnalizadaAlta (7.2)2.1%—Hgiga Isherlock29/4/202417/6/2026
The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary…
AnalizadaMedia (4.9)0.67%—Hgiga Isherlock29/4/202417/6/2026
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
AnalizadaMedia (4.9)0.67%—Hgiga Isherlock29/4/202417/6/2026
The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
ModificadaCrítica (9.8)1.3%—Hgiga Isherlock21/7/202317/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before…
ModificadaCrítica (9.8)0.98%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user18/3/202117/6/2026
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
ModificadaCrítica (9.8)1.8%—Hgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.
ModificadaAlta (7.6)0.61%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
ModificadaAlta (7.6)0.61%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
ModificadaMedia (6.1)0.62%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
ModificadaMedia (6.1)0.62%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
ModificadaAlta (7.5)1.1%—Hgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-user31/12/202017/6/2026
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
ModificadaCrítica (9.8)1.7%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-auditHgiga Msr45 Isherlock-baseHgiga Msr45 Isherlock-user+631/12/202017/6/2026
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
ModificadaAlta (8.8)0.67%—Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+43/6/201917/6/2026
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes.
ModificadaAlta (8.8)0.67%—Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+43/6/201917/6/2026
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&new=hacker@socialengineering.com&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes.