Vulnerabilities

Summary — last 7 days

New vulnerabilities2,587▼ 296 vs. last week
Critical / high1,355▲ 100 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
–

7 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.5)0.75%—Nodemailer Smtp ServerAI5/15/20266/17/2026
An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components
ModifiedHigh (7.8)1.6%—Qksoft QK Smtp Server 312/28/20076/16/2026
QK SMTP Server 3 allows remote attackers to cause a denial of service (daemon crash) via a long (1) HELO, (2) MAIL FROM, or (3) RCPT TO command; or (4) a long string in the message sent after the DATA command; possibly a related issue to CVE-2006-5551.
ModifiedHigh (7.5)4.8%—BL4 Smtp Server4/29/20066/16/2026
Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the (1) EHLO, (2) MAIL FROM, and (3) RCPT TO commands.
ModifiedHigh (7.5)4.6%—E-post Corporation Mail ServerE-post Corporation Smtp ServerE-post Corporation Spa-pro Mail Atsolomon1/27/20066/16/2026
Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3…
ModifiedHigh (7.5)2.6%—Softstack Free Smtp Server9/8/20056/16/2026
Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy).
ModifiedHigh (7.5)3.1%—Goodtech Systems Goodtech Smtp Server7/27/20056/16/2026
Multiple stack-based buffer overflows in GoodTech SMTP server 5.16 allow remote attackers to execute arbitrary code via (1) a RCPT TO command with a long DNS name, or (2) a large number of RCPT TO commands with a long e-mail name arugment in the last command.
ModifiedMedium (5)2.5%—Goodtech Systems Goodtech Smtp Server7/5/20056/16/2026
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.