Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2024-28063 Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS. Totemomail after 7.0.0 Fix from $1,6002024-05-18 MEDIUM 5.4 CVE-2020-7918 An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of… Totemomail Mitigation only Fix from $1,6002020-03-27 MEDIUM 5.4 CVE-2019-17189 totemodata 3.0.0_b936 has XSS via a folder name. Totemodata No fix yet Fix from $1,6002019-10-22 MEDIUM 6.1 CVE-2018-15510 Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web s… Totemomail Mitigation only Fix from $1,6002019-08-30 MEDIUM 6.1 CVE-2018-15511 Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbit… Totemomail Mitigation only Fix from $1,6002019-08-30 MEDIUM 6.1 CVE-2018-15512 Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbit… Totemomail Mitigation only Fix from $1,6002019-08-30 MEDIUM 5.3 CVE-2018-15513 Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role. Totemomail Mitigation only Fix from $1,6002019-08-30 HIGH 8.8 CVE-2018-6563 Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack t… Encryption Gateway after 6.0.0 Fix from $1,9502018-06-20 HIGH 7.5 CVE-2018-6562 totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material… Totemomail Encryption Gateway 6.0.0_b567+ Fix from $1,9502018-05-18