Vulnerability index

Browse CVEs

51 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Icewarp MEDIUM 6.1
CVE-2018-25269

ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embe…

No fix yet
Fix from $1,600 2026-04-22
Mail Server MEDIUM 6.1
CVE-2025-40631

HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrar…

Mitigation only
Fix from $1,600 2025-05-16
Mail Server MEDIUM 6.1
CVE-2025-40632

Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie wi…

Mitigation only
Fix from $1,600 2025-05-16
Mail Server MEDIUM 6.1
CVE-2025-40630

Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domai…

Mitigation only
Fix from $1,600 2025-05-16
Icewarp MEDIUM 6.1
CVE-2024-55218

IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.

No fix yet
Fix from $1,600 2025-01-07
Icewarp MEDIUM 6.1
CVE-2024-0246

A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the comp…

Mitigation only
Fix from $1,600 2024-01-05
Webclient MEDIUM 6.1
CVE-2023-43319

Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML vi…

Mitigation only
Fix from $1,600 2023-09-25
Deep Castle G2 MEDIUM 6.1
CVE-2023-40779

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

Mitigation only
Fix from $1,600 2023-09-14
Icewarp MEDIUM 6.1
CVE-2023-41013

Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.

Mitigation only
Fix from $1,600 2023-09-12
Webclient MEDIUM 6.1
CVE-2023-39598

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload…

Mitigation only
Fix from $1,600 2023-09-05
Icewarp MEDIUM 6.1
CVE-2023-39600

IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.

Mitigation only
Fix from $1,600 2023-08-25
Mail Server CRITICAL 9.8
CVE-2023-39699

IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. Thi…

No fix yet
Fix from $2,300 2023-08-25
Mail Server MEDIUM 6.1
CVE-2023-39700

IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.

No fix yet
Fix from $1,600 2023-08-25
Icewarp Server MEDIUM 6.1
CVE-2021-36580

Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.

Fix: 13.0.1.2+
Fix from $1,600 2023-07-27
Icewarp MEDIUM 6.1
CVE-2023-37728

IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

Mitigation only
Fix from $1,600 2023-07-20
Webclient Dc2 CRITICAL 9.8
CVE-2022-35115

IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/serv…

Mitigation only
Fix from $2,300 2022-08-23
Webclient MEDIUM 6.1
CVE-2020-25925

Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4…

No fix yet
Fix from $1,600 2021-07-07
Mail Server MEDIUM 6.1
CVE-2020-27982EPSS 5%

IceWarp 11.4.5.0 allows XSS via the language parameter.

No fix yet
Fix from $1,600 2020-11-02
Mail Server HIGH 8.8
CVE-2020-14066

IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.

Mitigation only
Fix from $1,950 2020-07-15
Mail Server MEDIUM 6.5
CVE-2020-14064

IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.

No fix yet
Fix from $1,600 2020-07-15
Mail Server MEDIUM 6.5
CVE-2020-14065

IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.

Mitigation only
Fix from $1,600 2020-07-15
Icewarp Server MEDIUM 6.1
CVE-2020-8512EPSS 15%

In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.

Fix: after 11.4.4.1
Fix from $1,600 2020-02-01
Mail Server MEDIUM 6.1
CVE-2019-19265

IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.

Fix: 12.2.1.1+
Fix from $1,600 2020-01-06
Mail Server MEDIUM 5.4
CVE-2019-19266

IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.

Fix: 12.2.1.1+
Fix from $1,600 2020-01-06
Webclient HIGH 7.5
CVE-2010-5335

IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the o…

Fix: 10.2.1+
Fix from $1,950 2019-10-11
Webclient MEDIUM 6.1
CVE-2010-5336

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0.

Fix: 10.2.1+
Fix from $1,600 2019-10-11
Webclient MEDIUM 6.1
CVE-2010-5337

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10…

Fix: 10.2.1+
Fix from $1,600 2019-10-11
Webclient MEDIUM 6.1
CVE-2010-5338

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3…

Fix: 10.2.1+
Fix from $1,600 2019-10-11
Webclient MEDIUM 6.1
CVE-2010-5339

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 an…

Fix: 10.2.1+
Fix from $1,600 2019-10-11
Webclient MEDIUM 6.1
CVE-2010-5340

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.

Fix: 10.2.1+
Fix from $1,600 2019-10-11