Vulnerabilities

Summary — last 7 days

New vulnerabilities2,737▼ 82 vs. last week
Critical / high1,248▼ 291 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)249▲ 212 vs. last week
–

11 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.1)0.51%—Mubag Easymail1/30/20236/17/2026
Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.
ModifiedMedium (6.5)1.1%—Alo-easymail Project Alo-easymail9/25/20196/17/2026
The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
ModifiedHigh (9.3)10%💥 ExploitQuiksoft Easymail Objects3/3/20106/16/2026
Heap-based buffer overflow in the Quiksoft EasyMail Objects 6 ActiveX control allows remote attackers to execute arbitrary code via a long argument to the AddAttachment method.
ModifiedHigh (9.3)5.8%💥 ExploitQuiksoft Easymail Mailstore Object3/9/20096/16/2026
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a long first argument to the CreateStore method.
ModifiedHigh (10)7.0%💥 ExploitQuiksoft Easymail Messageprinter Object9/24/20076/16/2026
Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail MessagePrinter Object allows remote attackers to execute arbitrary code via a long string in the first argument to the SetFont method.
ModifiedHigh (9.3)56%💥 ExploitGate Comm Software Postcast Server PROQuicksoft Easymail Objects8/31/20076/16/2026
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029.…
ModifiedMedium (4.3)1.0%—RM Easymail Plus5/30/20076/16/2026
Cross-site scripting (XSS) vulnerability in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the title field in an email.
ModifiedMedium (4.3)1.1%—RM Easymail Plus5/22/20076/16/2026
Cross-site scripting (XSS) vulnerability in cp/ps/Main/login/Login in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the d parameter.
ModifiedHigh (7.6)7.5%💥 ExploitQuicksoft Easymail Objects2/21/20076/16/2026
Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute arbitrary code via a long host name.
ModifiedMedium (5)3.4%—Webeasymail4/11/20036/16/2026
Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests.
ModifiedMedium (5)1.8%—Webeasymail4/11/20036/16/2026
The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.
Orbitaley — Vulnerabilities