Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2024-28063
Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.
Totemomail
after 7.0.0
MEDIUM 5.4
CVE-2020-7918
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of…
Totemomail
Mitigation only
MEDIUM 5.4
CVE-2019-17189
totemodata 3.0.0_b936 has XSS via a folder name.
Totemodata
No fix yet
MEDIUM 6.1
CVE-2018-15510
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web s…
Totemomail
Mitigation only
MEDIUM 6.1
CVE-2018-15511
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbit…
Totemomail
Mitigation only
MEDIUM 6.1
CVE-2018-15512
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbit…
Totemomail
Mitigation only
MEDIUM 5.3
CVE-2018-15513
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
Totemomail
Mitigation only
HIGH 8.8
CVE-2018-6563
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack t…
Encryption Gateway
after 6.0.0
HIGH 7.5
CVE-2018-6562
totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material…
Totemomail Encryption Gateway
6.0.0_b567+