Show filters
63 Total Results
Displaying 21-30 of 63
Sort by:
Attacker Value
Unknown

CVE-2022-37238

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.
Attacker Value
Unknown

CVE-2022-37245

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.
Attacker Value
Unknown

CVE-2022-37244

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.
Attacker Value
Unknown

CVE-2022-37243

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
Attacker Value
Unknown

CVE-2022-37242

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
Attacker Value
Unknown

CVE-2022-37241

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.
Attacker Value
Unknown

CVE-2022-37240

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
Attacker Value
Unknown

CVE-2022-37239

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
Attacker Value
Unknown

CVE-2021-44750

Disclosure Date: March 10, 2022 (last updated October 07, 2023)
An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands.
Attacker Value
Unknown

CVE-2021-45105

Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.