Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.0
CVE-2025-68723
Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exis…
Axigen Mail Server
10.5.57 / 10.6.26+
MEDIUM 5.4
CVE-2025-68643
Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers …
Axigen Mail Server
10.5.57 / 10.6.26+
HIGH 8.8
CVE-2025-68722
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface thro…
Axigen Mail Server
10.5.57 / 10.6.26+
HIGH 8.1
CVE-2025-68721
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero pe…
Axigen Mail Server
10.5.57 / 10.6.26+
CRITICAL 9.1
CVE-2020-26942
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminP…
Axigen Mail Server
10.3.1.27 / 10.3.3.1+
MEDIUM 6.1
CVE-2023-49101
WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling…
Axigen Mobile Webmail
10.3.3.61 / 10.4.24+
CRITICAL 9.6
CVE-2023-48974
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the s…
Axigen Mail Server
after 10.5.7
MEDIUM 5.4
CVE-2023-40355
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authen…
Axigen Mobile Webmail
10.3.3.59 / 10.4.19+
CRITICAL 9.8
CVE-2023-23566
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an acc…
Axigen Mail Server
Mitigation only
MEDIUM 6.1
CVE-2022-31470EPSS 52%
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 …
Axigen Mobile Webmail
10.2.3.12 / 10.3.3.47+
MEDIUM 5.4
CVE-2015-5379
Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inj…
Axigen Mail Server
No fix yet