Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Icewarp MEDIUM 6.1
CVE-2018-25269

ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embe…

No fix yet
Fix from $1,600 2026-04-22
Mail Server MEDIUM 6.1
CVE-2025-40631

HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrar…

Mitigation only
Fix from $1,600 2025-05-16
Mail Server MEDIUM 6.1
CVE-2025-40632

Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie wi…

Mitigation only
Fix from $1,600 2025-05-16
Mail Server MEDIUM 6.1
CVE-2025-40630

Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domai…

Mitigation only
Fix from $1,600 2025-05-16
Icewarp MEDIUM 6.1
CVE-2024-55218

IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.

No fix yet
Fix from $1,600 2025-01-07
Icewarp MEDIUM 6.1
CVE-2024-0246

A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the comp…

Mitigation only
Fix from $1,600 2024-01-05
Webclient MEDIUM 6.1
CVE-2023-43319

Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML vi…

Mitigation only
Fix from $1,600 2023-09-25
Deep Castle G2 MEDIUM 6.1
CVE-2023-40779

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

Mitigation only
Fix from $1,600 2023-09-14
Icewarp MEDIUM 6.1
CVE-2023-41013

Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.

Mitigation only
Fix from $1,600 2023-09-12
Webclient MEDIUM 6.1
CVE-2023-39598

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload…

Mitigation only
Fix from $1,600 2023-09-05
Icewarp MEDIUM 6.1
CVE-2023-39600

IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.

Mitigation only
Fix from $1,600 2023-08-25
Mail Server CRITICAL 9.8
CVE-2023-39699

IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. Thi…

No fix yet
Fix from $2,300 2023-08-25
Mail Server MEDIUM 6.1
CVE-2023-39700

IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.

No fix yet
Fix from $1,600 2023-08-25
Icewarp MEDIUM 6.1
CVE-2023-37728

IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

Mitigation only
Fix from $1,600 2023-07-20
Webclient Dc2 CRITICAL 9.8
CVE-2022-35115

IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/serv…

Mitigation only
Fix from $2,300 2022-08-23
Webclient MEDIUM 6.1
CVE-2020-25925

Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4…

No fix yet
Fix from $1,600 2021-07-07
Mail Server MEDIUM 6.1
CVE-2020-27982EPSS 5%

IceWarp 11.4.5.0 allows XSS via the language parameter.

No fix yet
Fix from $1,600 2020-11-02
Mail Server HIGH 8.8
CVE-2020-14066

IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.

Mitigation only
Fix from $1,950 2020-07-15
Mail Server MEDIUM 6.5
CVE-2020-14064

IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.

No fix yet
Fix from $1,600 2020-07-15
Mail Server MEDIUM 6.5
CVE-2020-14065

IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.

Mitigation only
Fix from $1,600 2020-07-15
Mail Server MEDIUM 6.1
CVE-2018-7475

Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script…

No fix yet
Fix from $1,600 2018-06-30
Server MEDIUM 6.1
CVE-2017-7855

In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.

Mitigation only
Fix from $1,600 2017-08-31
Merak Mail Server HIGH 7.5
CVE-2009-1516

Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependen…

No fix yet
Fix from $1,950 2009-05-04
Web Mail MEDIUM 5.0
CVE-2005-3132

MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a di…

Mitigation only
Fix from $1,600 2005-10-04
Web Mail MEDIUM 5.0
CVE-2005-3133EPSS 6%

Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote at…

No fix yet
Fix from $1,600 2005-10-04
Web Mail HIGH 7.2
CVE-2005-0322

MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, …

Mitigation only
Fix from $1,950 2005-05-02
Web Mail HIGH 7.5
CVE-2002-0258

Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers wi…

Mitigation only
Fix from $1,950 2002-05-29