Vulnerabilities
Summary — last 7 days
New vulnerabilities2,587▼ 296 vs. last week
Critical / high1,355▲ 100 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
7 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.5) | 0.75% | — | Nodemailer Smtp ServerAI | 5/15/2026 | 6/17/2026 | An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components | |
| Modified | High (7.8) | 1.6% | — | Qksoft QK Smtp Server 3 | 12/28/2007 | 6/16/2026 | QK SMTP Server 3 allows remote attackers to cause a denial of service (daemon crash) via a long (1) HELO, (2) MAIL FROM, or (3) RCPT TO command; or (4) a long string in the message sent after the DATA command; possibly a related issue to CVE-2006-5551. | |
| Modified | High (7.5) | 4.8% | — | BL4 Smtp Server | 4/29/2006 | 6/16/2026 | Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the (1) EHLO, (2) MAIL FROM, and (3) RCPT TO commands. | |
| Modified | High (7.5) | 4.6% | — | E-post Corporation Mail ServerE-post Corporation Smtp ServerE-post Corporation Spa-pro Mail Atsolomon | 1/27/2006 | 6/16/2026 | Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3… | |
| Modified | High (7.5) | 2.6% | — | Softstack Free Smtp Server | 9/8/2005 | 6/16/2026 | Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy). | |
| Modified | High (7.5) | 3.1% | — | Goodtech Systems Goodtech Smtp Server | 7/27/2005 | 6/16/2026 | Multiple stack-based buffer overflows in GoodTech SMTP server 5.16 allow remote attackers to execute arbitrary code via (1) a RCPT TO command with a long DNS name, or (2) a large number of RCPT TO commands with a long e-mail name arugment in the last command. | |
| Modified | Medium (5) | 2.5% | — | Goodtech Systems Goodtech Smtp Server | 7/5/2005 | 6/16/2026 | GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character. |