Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2025-2150
The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails contai…
C\&cm\@il
Mitigation only
HIGH 7.2
CVE-2024-4299
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in cert…
Isherlock
4.5-147 / 5.5-147+
HIGH 7.2
CVE-2024-4298
The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain func…
Isherlock
4.5-188 / 5.5-188+
CRITICAL 9.8
CVE-2024-26261
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put fi…
Oaklouds Organization 2.0
188 / 1051+
CRITICAL 9.8
CVE-2024-26260
The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inj…
Oaklouds Organization 2.0
188 / 1051+
CRITICAL 9.8
CVE-2023-37292
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modul…
Isherlock
4.5-174 / 5.5-174+
CRITICAL 9.8
CVE-2023-25909
HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vuln…
Oaklouds Portal
2.0-10 / 3.0-10+
HIGH 7.2
CVE-2023-24840
HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrat…
Oaklouds Mailsherlock
Mitigation only
HIGH 7.2
CVE-2023-24841
HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker w…
Oaklouds Mailsherlock
Mitigation only
MEDIUM 5.3
CVE-2023-24842
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial …
Oaklouds Mailsherlock
Mitigation only
CRITICAL 9.8
CVE-2023-24838
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the admini…
Powerstation Firmware
Mitigation only
HIGH 8.8
CVE-2023-24837
HGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege…
Powerstation Firmware
Mitigation only
MEDIUM 6.1
CVE-2023-24839
HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability t…
Oaklouds Mailsherlock
Mitigation only
HIGH 8.8
CVE-2022-38118
OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-inje…
Oaklouds Portal
after 3.0-163
CRITICAL 9.8
CVE-2021-37913
The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote …
Oaklouds Portal
after 3.0-2
CRITICAL 9.8
CVE-2021-37912
The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remo…
Oaklouds Portal
after 3.0-2
CRITICAL 9.8
CVE-2021-22848
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages withou…
Msr45 Isherlock Antispam
4.5-120 / 4.5-133+
CRITICAL 9.8
CVE-2021-22850
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.
Oaklouds Portal
Mitigation only
CRITICAL 9.8
CVE-2021-22851
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to o…
Oaklouds Openid
2.0-54 / 3.0-54+
HIGH 8.8
CVE-2021-22852
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain…
Oaklouds Openid
2.0-54 / 3.0-54+
CRITICAL 9.8
CVE-2020-25848
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
Msr45 Isherlock Antispam
4.5-114 / 4.5-122+
CRITICAL 9.8
CVE-2020-35851
HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and …
Msr45 Isherlock User
4.5-115+
HIGH 7.6
CVE-2020-35742
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
Msr45 Isherlock Antispam
4.5-120 / 4.5-133+
HIGH 7.6
CVE-2020-35743
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
Msr45 Isherlock Antispam
4.5-120 / 4.5-133+
HIGH 7.5
CVE-2020-25850
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbit…
Msr45 Isherlock User
4.5-117+
MEDIUM 6.1
CVE-2020-35740
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
Msr45 Isherlock Antispam
4.5-120 / 4.5-133+
MEDIUM 6.1
CVE-2020-35741
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS…
Msr45 Isherlock Antispam
4.5-120 / 4.5-133+
CRITICAL 9.8
CVE-2020-10511
HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can…
Oaklouds Ccm\@il
No fix yet
HIGH 8.8
CVE-2020-10512
HGiga C&Cmail CCMAILQ before olln-calendar-6.0-100.i386.rpm and CCMAILN before olln-calendar-5.0-100.i386.rpm contains a SQL Injection vulnerability …
Oaklouds Ccm\@il
Mitigation only
HIGH 8.8
CVE-2019-9882
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user…
Msr35 Isherlock Base
1.5.127 / 1.5.196+