Hgiga
Hgiga Isherlock: vulnerabilidades y CVE
Hgiga Isherlock tiene 11 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses2
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6349 | Crítica (9.3) | 2.6% | — | 16 abr 2026 | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server. |
| CVE-2025-11900 | Crítica (9.3) | 1.8% | — | 17 oct 2025 | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. |
| CVE-2025-7451 | Crítica (9.3) | 1.4% | — | 14 jul 2025 | The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been… |
| CVE-2025-3363 | Crítica (9.8) | 1.3% | — | 8 abr 2025 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. |
| CVE-2025-3362 | Crítica (9.8) | 1.3% | — | 8 abr 2025 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. |
| CVE-2025-3361 | Crítica (9.8) | 1.3% | — | 8 abr 2025 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. |
| CVE-2024-4299 | Alta (7.2) | 2.1% | — | 29 abr 2024 | The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative… |
| CVE-2024-4298 | Alta (7.2) | 2.1% | — | 29 abr 2024 | The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative… |
| CVE-2024-4297 | Media (4.9) | 0.67% | — | 29 abr 2024 | The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with… |
| CVE-2024-4296 | Media (4.9) | 0.67% | — | 29 abr 2024 | The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative… |
| CVE-2023-37292 | Crítica (9.8) | 1.3% | — | 21 jul 2023 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.