Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2024-6741
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability…
Mail2000
No fix yet
MEDIUM 6.1
CVE-2024-6740
Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attac…
Mail2000
No fix yet
MEDIUM 6.1
CVE-2024-6739
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal t…
Mailaudit
6.1.7.040+
HIGH 8.8
CVE-2024-5400
Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to exe…
Mail2000
Mitigation only
HIGH 7.2
CVE-2024-5399
Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability…
Mail2000
Mitigation only
MEDIUM 6.1
CVE-2023-28705
Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit thi…
Mail2000
8.0+
MEDIUM 5.4
CVE-2023-22902
Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can…
Mail2000
Mitigation only
HIGH 8.8
CVE-2020-25849
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after…
Mailaudit
Mitigation only
HIGH 7.2
CVE-2020-12776
Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the adminis…
Mail2000
Mitigation only
CRITICAL 9.8
CVE-2020-12782
Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be trigg…
Mailaudit
Mitigation only
MEDIUM 6.1
CVE-2019-15073
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authenticati…
Mail2000
after 7.0
MEDIUM 6.1
CVE-2019-15072
The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of …
Mail2000
after 7.0
MEDIUM 6.1
CVE-2019-15071
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code v…
Mail2000
after 7.0
MEDIUM 6.1
CVE-2019-9763
An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message …
Mail2000
No fix yet