Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mailcow\ HIGH 7.2
CVE-2025-53909

mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions…

Fix: 2025-07+
Fix from $1,950 2025-07-17
Mailcow\ HIGH 8.8
CVE-2025-25198

mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset f…

Fix: 2025-01a+
Fix from $1,950 2025-02-12
Mailcow\ HIGH 7.2
CVE-2024-41958

mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2F…

Fix: 2024-07+
Fix from $1,950 2024-08-05
Mailcow\ MEDIUM 6.1
CVE-2024-41959

mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API…

Fix: 2024-07+
Fix from $1,600 2024-08-05
Mailcow\ MEDIUM 6.2
CVE-2024-30270EPSS 27%

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versio…

Fix: 2024-04+
Fix from $1,600 2024-04-04
Mailcow\ MEDIUM 6.1
CVE-2024-31204EPSS 8%

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versio…

Fix: 2024-04+
Fix from $1,600 2024-04-04
Mailcow\ HIGH 7.3
CVE-2024-24760

mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailco…

Fix: 2024-01c+
Fix from $1,950 2024-02-02
Mailcow\ MEDIUM 6.1
CVE-2023-49077

Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability has been identified within th…

Fix: 2023-11+
Fix from $1,600 2023-11-30
Mailcow\ HIGH 8.8
CVE-2023-34108

mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration…

Fix: after 2023-05
Fix from $1,950 2023-06-07
Mailcow\ HIGH 8.8
CVE-2023-26490

mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to …

Fix: 2023-03+
Fix from $1,950 2023-03-04
Mailcow\ HIGH 8.2
CVE-2022-39258

mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Author…

Fix: 2022-09+
Fix from $1,950 2022-09-27
Mailcow\ HIGH 8.8
CVE-2022-31138

mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the…

Fix: 2022-06a+
Fix from $1,950 2022-07-11
Mailcow\ HIGH 8.8
CVE-2022-31245EPSS 5%

mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in co…

Fix: 2022-05d+
Fix from $1,950 2022-05-20
Mailcow\ HIGH 8.8
CVE-2017-8928

mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.

Patch available
Fix from $1,950 2017-05-14