Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Gateway For Email Servers MEDIUM 5.4
CVE-2022-37238

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.

No fix yet
Fix from $1,600 2022-08-25
Security Gateway For Email Servers MEDIUM 5.4
CVE-2022-37244

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to …

No fix yet
Fix from $1,600 2022-08-25
Security Gateway For Email Servers MEDIUM 5.4
CVE-2022-37245

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.

No fix yet
Fix from $1,600 2022-08-25
Security Gateway For Email Servers CRITICAL 9.8
CVE-2022-37240

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.

No fix yet
Fix from $2,300 2022-08-25
Security Gateway For Email Servers CRITICAL 9.8
CVE-2022-37242

MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.

No fix yet
Fix from $2,300 2022-08-25
Security Gateway For Email Servers MEDIUM 5.4
CVE-2022-37239

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.

No fix yet
Fix from $1,600 2022-08-25
Security Gateway For Email Servers MEDIUM 5.4
CVE-2022-37241

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.

No fix yet
Fix from $1,600 2022-08-25
Security Gateway For Email Servers MEDIUM 5.4
CVE-2022-37243

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.

No fix yet
Fix from $1,600 2022-08-25
Mdaemon MEDIUM 5.4
CVE-2022-29975

An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .

Fix: 22.0.0+
Fix from $1,600 2022-05-11
Mdaemon MEDIUM 5.4
CVE-2022-29976

An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .

Fix: 22.0.0+
Fix from $1,600 2022-05-11
Securitygateway MEDIUM 5.3
CVE-2022-25356EPSS 6%

Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.

Fix: after 8.5.0
Fix from $1,600 2022-04-05
Mdaemon HIGH 8.8
CVE-2021-27181

An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to …

Fix: 20.0.4+
Fix from $1,950 2021-04-14
Mdaemon HIGH 8.8
CVE-2021-27182

An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an…

Fix: 20.0.4+
Fix from $1,950 2021-04-14
Mdaemon HIGH 7.2
CVE-2021-27183

An issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An a…

Fix: 20.0.4+
Fix from $1,950 2021-04-14
Mdaemon MEDIUM 6.1
CVE-2021-27180

An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allo…

Fix: 20.0.4+
Fix from $1,600 2021-04-14
Mdaemon Webmail MEDIUM 5.4
CVE-2020-18723

Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side w…

Fix: 20.0.1+
Fix from $1,600 2021-02-03
Mdaemon Webmail MEDIUM 5.4
CVE-2020-18724

Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to ex…

Fix: 20.0.1+
Fix from $1,600 2021-02-03
Mdaemon Email Server MEDIUM 5.4
CVE-2019-19497

MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.

No fix yet
Fix from $1,600 2019-12-17
Mdaemon Webmail HIGH 8.8
CVE-2018-17792

MDaemon Webmail (formerly WorldClient) has CSRF.

No fix yet
Fix from $1,950 2019-07-19
Mdaemon Email Server HIGH 7.5
CVE-2019-13612

MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even wit…

Mitigation only
Fix from $1,950 2019-07-16
Mdaemon MEDIUM 6.1
CVE-2019-8983

MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).

Fix: 18.5.2+
Fix from $1,600 2019-02-21
Mdaemon MEDIUM 6.1
CVE-2019-8984

MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).

Fix: 18.5.2+
Fix from $1,600 2019-02-21
Mdaemon MEDIUM 5.0
CVE-2008-2631EPSS 23%

The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and appli…

Fix: after 9.6.5
Fix from $1,600 2008-06-10
Mdaemon MEDIUM 6.5
CVE-2008-1358EPSS 57%

Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a …

No fix yet
Fix from $1,600 2008-03-17