Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.38%—SogoAI30/9/202630/9/2026
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was…
AplazadaCrítica (9.3)0.41%—Sogo YHNAI30/9/202630/9/2026
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged…
AplazadaAlta (8.7)0.49%—SogoAI17/9/202622/9/2026
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens…
AplazadaCrítica (9.8)0.93%—Sogou Input MethodAI16/9/202622/9/2026
An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component
AplazadaMedia (6.8)0.23%—Sogo ADD Script TO Individual Pages Header FooterAI30/8/202631/8/2026
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store…
AplazadaMedia (6.3)0.27%—SogoAI8/7/20269/7/2026
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.
AplazadaMedia (6.3)0.27%—SogoAI8/7/20269/7/2026
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.
AplazadaAlta (8.6)0.42%—SogoAI18/5/202623/7/2026
SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inject malicious SQL…
AplazadaAlta (7.1)0.37%—SogoAIPostgresqlAIMariadbAI14/5/202617/6/2026
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
AplazadaAlta (7.1)0.37%—SogoAIPostgresqlAI14/5/202617/6/2026
SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.
AplazadaMedia (6.1)0.51%—Alinto SogoAI13/5/20266/8/2026
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the description field of an ICS file, with an…
AnalizadaBaja (2.6)0.21%—Alinto Sogo22/3/202617/6/2026
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
AnalizadaMedia (6.1)0.14%—Alinto Sogo22/3/202617/6/2026
SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
AnalizadaBaja (2.1)0.47%—Alinto Sogo24/2/202617/6/2026
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not…
AnalizadaMedia (6.1)0.30%—Alinto Sogo4/12/202517/6/2026
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
AnalizadaMedia (6.1)0.29%—Alinto SogoDebian Linux24/11/202517/6/2026
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
AplazadaMedia (4.3)0.34%—Sogo WebmailAI4/8/202517/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized…
AplazadaAlta (7.5)0.69%—Alinto SopeAIAlinto SogoAI5/7/202517/6/2026
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.
AplazadaMedia (6.5)0.32%—Beijing Sogou Technology Development CO LTD Sogou Input IOSAI27/1/202517/6/2026
An issue in Beijing Sogou Technology Development Co., Ltd Sogou Input iOS 12.2.0 allows attackers to access sensitive user information via supplying a crafted link.
AnalizadaMedia (6.1)0.48%—Alinto Sogo9/9/202417/6/2026
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.
AnalizadaMedia (6.1)0.35%—Alinto Sogo4/5/202417/6/2026
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
ModificadaMedia (6.1)1.0%—Alinto Sogo16/1/202417/6/2026
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
ModificadaMedia (6.1)0.38%—Alinto Sogo WEB Mail14/6/202317/6/2026
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code.
ModificadaAlta (8.8)0.83%—Sogou C++ Workflow6/6/202317/6/2026
In Sogou Workflow v0.10.6, memcpy a negtive size in URIParser::parse , may cause buffer-overflow and crash.
ModificadaAlta (7.5)0.34%—Touki-kyoutaku-online Shinseiyo Sogo Soft10/5/202317/6/2026
Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.