Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

C\&cm\@il MEDIUM 5.4
CVE-2025-2150

The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails contai…

Mitigation only
Fix from $1,600 2025-03-10
Isherlock HIGH 7.2
CVE-2024-4299

The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in cert…

Fix: 4.5-147 / 5.5-147+
Fix from $1,950 2024-04-29
Isherlock HIGH 7.2
CVE-2024-4298

The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain func…

Fix: 4.5-188 / 5.5-188+
Fix from $1,950 2024-04-29
Oaklouds Organization 2.0 CRITICAL 9.8
CVE-2024-26261

The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put fi…

Fix: 188 / 1051+
Fix from $2,300 2024-02-15
Oaklouds Organization 2.0 CRITICAL 9.8
CVE-2024-26260

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inj…

Fix: 188 / 1051+
Fix from $2,300 2024-02-15
Isherlock CRITICAL 9.8
CVE-2023-37292

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modul…

Fix: 4.5-174 / 5.5-174+
Fix from $2,300 2023-07-21
Oaklouds Portal CRITICAL 9.8
CVE-2023-25909

HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vuln…

Fix: 2.0-10 / 3.0-10+
Fix from $2,300 2023-03-27
Oaklouds Mailsherlock HIGH 7.2
CVE-2023-24840

HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrat…

Mitigation only
Fix from $1,950 2023-03-27
Oaklouds Mailsherlock HIGH 7.2
CVE-2023-24841

HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker w…

Mitigation only
Fix from $1,950 2023-03-27
Oaklouds Mailsherlock MEDIUM 5.3
CVE-2023-24842

HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial …

Mitigation only
Fix from $1,600 2023-03-27
Powerstation Firmware CRITICAL 9.8
CVE-2023-24838

HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the admini…

Mitigation only
Fix from $2,300 2023-03-27
Powerstation Firmware HIGH 8.8
CVE-2023-24837

HGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege…

Mitigation only
Fix from $1,950 2023-03-27
Oaklouds Mailsherlock MEDIUM 6.1
CVE-2023-24839

HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability t…

Mitigation only
Fix from $1,600 2023-03-27
Oaklouds Portal HIGH 8.8
CVE-2022-38118

OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-inje…

Fix: after 3.0-163
Fix from $1,950 2022-08-30
Oaklouds Portal CRITICAL 9.8
CVE-2021-37913

The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote …

Fix: after 3.0-2
Fix from $2,300 2021-09-15
Oaklouds Portal CRITICAL 9.8
CVE-2021-37912

The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remo…

Fix: after 3.0-2
Fix from $2,300 2021-09-15
Msr45 Isherlock Antispam CRITICAL 9.8
CVE-2021-22848

HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages withou…

Fix: 4.5-120 / 4.5-133+
Fix from $2,300 2021-03-18
Oaklouds Portal CRITICAL 9.8
CVE-2021-22850

HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.

Mitigation only
Fix from $2,300 2021-01-19
Oaklouds Openid CRITICAL 9.8
CVE-2021-22851

HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to o…

Fix: 2.0-54 / 3.0-54+
Fix from $2,300 2021-01-19
Oaklouds Openid HIGH 8.8
CVE-2021-22852

HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain…

Fix: 2.0-54 / 3.0-54+
Fix from $1,950 2021-01-19
Msr45 Isherlock Antispam CRITICAL 9.8
CVE-2020-25848

HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

Fix: 4.5-114 / 4.5-122+
Fix from $2,300 2020-12-31
Msr45 Isherlock User CRITICAL 9.8
CVE-2020-35851

HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and …

Fix: 4.5-115+
Fix from $2,300 2020-12-31
Msr45 Isherlock Antispam HIGH 7.6
CVE-2020-35742

HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.

Fix: 4.5-120 / 4.5-133+
Fix from $1,950 2020-12-31
Msr45 Isherlock Antispam HIGH 7.6
CVE-2020-35743

HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.

Fix: 4.5-120 / 4.5-133+
Fix from $1,950 2020-12-31
Msr45 Isherlock User HIGH 7.5
CVE-2020-25850

The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbit…

Fix: 4.5-117+
Fix from $1,950 2020-12-31
Msr45 Isherlock Antispam MEDIUM 6.1
CVE-2020-35740

HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.

Fix: 4.5-120 / 4.5-133+
Fix from $1,600 2020-12-31
Msr45 Isherlock Antispam MEDIUM 6.1
CVE-2020-35741

HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS…

Fix: 4.5-120 / 4.5-133+
Fix from $1,600 2020-12-31
Oaklouds Ccm\@il CRITICAL 9.8
CVE-2020-10511

HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can…

No fix yet
Fix from $2,300 2020-04-15
Oaklouds Ccm\@il HIGH 8.8
CVE-2020-10512

HGiga C&Cmail CCMAILQ before olln-calendar-6.0-100.i386.rpm and CCMAILN before olln-calendar-5.0-100.i386.rpm contains a SQL Injection vulnerability …

Mitigation only
Fix from $1,950 2020-04-15
Msr35 Isherlock Base HIGH 8.8
CVE-2019-9882

Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user…

Fix: 1.5.127 / 1.5.196+
Fix from $1,950 2019-06-03