Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.29%—Magicwinmail Winmail Server18/12/202417/6/2026
Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).
AnalizadaAlta (8.8)0.84%—Winmail9/3/202417/6/2026
An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.
ModificadaAlta (7.5)0.79%—Winmail Project Winmail26/1/202117/6/2026
A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the server to send a request to a specific URL. An attacker can modify the request header 'HOST' value to cause the server to send the request.
ModificadaMedia (6.1)0.60%—Winmail Project Winmail26/1/202117/6/2026
A reflected XSS vulnerability exists in tohtml/convert.php of Winmail 6.5, which can cause JavaScript code to be executed.
ModificadaAlta (8.8)3.3%—Magicwinmail Winmail Server14/1/201817/6/2026
Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php copy_folder_file call (in inc/class.ftpfolder.php) to move a .php file from the FTP folder into a web folder.
ModificadaAlta (8.8)2.8%—Magicwinmail Winmail Server24/6/201717/6/2026
Winmail Server 6.1 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php move_folder_file call to move a .php file from the FTP folder into a web folder.
ModificadaAlta (10)1.6%—Amax Information Technologies Winmail19/3/200616/6/2026
Unspecified vulnerability in the Webmail module in Winmail before 4.3 has unknown impact and unknown remote attack vectors.
ModificadaMedia (5)7.3%—Amax Information Technologies Magic Winmail Server25/11/200516/6/2026
Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session information via the sid parameter.
ModificadaMedia (4.3)2.1%—Amax Information Technologies Magic Winmail Server19/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML mail attachments.
ModificadaMedia (4.3)1.2%—Magicwinmail Winmail ServerAI27/1/200516/6/2026
Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.
ModificadaMedia (4.6)0.75%—Amax Information Technologies Magic Winmail Server27/1/200516/6/2026
The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.
ModificadaAlta (7.5)3.4%—Amax Information Technologies Magic Winmail Server27/1/200516/6/2026
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary…
ModificadaMedia (5)1.7%—Amax Information Technologies Magic Winmail Server31/12/200416/6/2026
AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails,…
ModificadaAlta (7.5)3.5%—Amax Information Technologies Magic Winmail Server2/7/200316/6/2026
Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.