Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Cybonet Pineapp Mail Secure | 8/5/2023 | 17/6/2026 | Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using an unspecified endpoint. | |
| Modificada | Crítica (9.8) | 1.0% | — | Cybonet Pineapp Mail Secure | 24/2/2022 | 17/6/2026 | Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 and… | |
| Modificada | Alta (7.5) | 0.69% | — | Cybonet Pineapp Mail Secure | 24/2/2022 | 17/6/2026 | Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server. | |
| Modificada | Media (6.1) | 0.58% | — | Pineapp Mail Secure | 8/12/2021 | 17/6/2026 | PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies . | |
| Modificada | Alta (8.8) | 1.1% | — | Cybonet Mail Secure | 8/12/2021 | 17/6/2026 | PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code. | |
| Modificada | Alta (7.2) | 1.0% | — | Pineapp Mail-secure 5099sk | 20/11/2013 | 17/6/2026 | PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account. | |
| Modificada | Alta (7.5) | 8.9% | — | Pineapp Mail-secure 5099sk | 20/11/2013 | 17/6/2026 | admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary commands via shell metacharacters in the nsserver parameter during an nslookup operation. | |
| Modificada | Alta (7.5) | 80% | — | Pineapp Mail-secure | 20/11/2013 | 17/6/2026 | admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation. | |
| Modificada | Media (6.4) | 1.3% | — | Pineapp Mail-secure | 20/11/2013 | 17/6/2026 | admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the it parameter. | |
| Modificada | Media (5) | 1.4% | — | Pineapp Mail-secure | 20/11/2013 | 17/6/2026 | Absolute path traversal vulnerability in admin/viewmsg.php in PineApp Mail-SeCure allows remote attackers to read arbitrary files via a full pathname in the msg parameter. | |
| Modificada | Alta (8.5) | 2.6% | — | Pineapp Mail-secure | 8/11/2013 | 16/6/2026 | PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters in a "system ping" command. | |
| Modificada | Alta (7.5) | 61% | — | Ipswitch Imail PlusIpswitch Imail Secure ServerIpswitch Collaboration Suite | 8/9/2006 | 16/6/2026 | Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character. |