Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 17% | — | Afterlogic AuroraAfterlogic Webmail PRO | 7/3/2021 | 17/6/2026 | An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with… | |
| Modificada | Crítica (9.8) | 7.1% | — | Afterlogic AuroraAfterlogic Webmail PRO | 4/3/2021 | 17/6/2026 | An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x. | |
| Modificada | Media (4.3) | 1.1% | — | Basic Webmail Project Basic Webmail | 8/2/2020 | 16/6/2026 | The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses. | |
| Modificada | Media (6.1) | 0.80% | — | Afterlogic AuroraAfterlogic Webmail PRO | 26/11/2019 | 17/6/2026 | Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name. | |
| Modificada | Media (4.3) | 1.8% | — | Basic Webmail Project Basic WebmailJason Flatt Basic Webmail | 3/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message. | |
| Modificada | Media (4.3) | 1.5% | — | Afterlogic Webmail PRO | 26/3/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) HistoryStorageObjectName and (2) HistoryKey parameters. | |
| Modificada | Media (5) | 12% | — | Afterlogic Mailbee Webmail PRO | 17/1/2008 | 16/6/2026 | Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the temp_filename parameter. |