Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Winwebmail Server | 12/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an… | |
| Modificada | Media (4.3) | 4.9% | — | Icewarp Email ServerIcewarp Webmail Server | 5/5/2009 | 16/6/2026 | CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as… | |
| Modificada | Media (6.5) | 1.9% | — | Icewarp Email ServerIcewarp Webmail Server | 5/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query. | |
| Modificada | Media (4.3) | 4.1% | — | Icewarp Email ServerIcewarp Webmail Server | 5/5/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2)… | |
| Modificada | Alta (9) | 5.5% | — | Comingchina U-mail Webmail Server | 5/11/2008 | 16/6/2026 | webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root. | |
| Modificada | Alta (10) | 69% | — | Truenorth Software IA Webmail Server | 3/11/2003 | 16/6/2026 | Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request. | |
| Modificada | Media (5) | 7.3% | — | Concatus Imate Webmail Server | 1/6/2000 | 16/6/2026 | Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command. |