axigen kayıtları
axigen üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-276 Incorrect Default Permissions1
- CWE-284 Improper Access Control1
- CWE-306 Missing Authentication for Critical Function1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-31470Kavram kanıtı | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 1axigen · axigen mobile webmail · CWE-79 | Orta6,1 | — | %52,7 | 7 Haz 2022 |
39İzleyin | CVE-2023-48974Kavram kanıtı | Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted scriptaxigen · axigen mail server · CWE-79 | Kritik9,6 | — | %3,0 | 7 Şub 2024 |
39İzleyin | CVE-2023-23566İstismar yok | A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to aaxigen · axigen mail server · CWE-276 | Kritik9,8 | — | %0,9 | 13 Oca 2023 |
36İzleyin | CVE-2020-26942İstismar yok | An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a axigen · axigen mail server · CWE-306 | Kritik9,1 | — | %0,5 | 20 Mar 2024 |
36İzleyin | CVE-2025-68723Kavram kanıtı | Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface.axigen · axigen mail server · CWE-79 | Kritik9,0 | — | %0,3 | 5 Şub 2026 |
35İzleyin | CVE-2025-68722Kavram kanıtı | Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interaxigen · axigen mail server · CWE-352 | Yüksek8,8 | — | %0,3 | 5 Şub 2026 |
32İzleyin | CVE-2025-68721Kavram kanıtı | Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface.axigen · axigen mail server · CWE-284 | Yüksek8,1 | — | %0,3 | 5 Şub 2026 |
26İzleyin | CVE-2024-28589Kavram kanıtı | An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbiCWE-732 | Orta6,7 | — | %0,3 | 3 Nis 2024 |
24İzleyin | CVE-2024-50601İstismar yok | Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow CWE-79 | Orta6,1 | — | %0,2 | 11 Kas 2024 |
24İzleyin | CVE-2023-49101İstismar yok | WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of miaxigen · axigen mobile webmail · CWE-79 | Orta6,1 | — | %0,2 | 8 Şub 2024 |
21İzleyin | CVE-2015-5379İstismar yok | Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackeaxigen · axigen mail server · CWE-79 | Orta5,4 | — | %1,6 | 23 Eki 2017 |
21İzleyin | CVE-2023-40355Kavram kanıtı | Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, alloaxigen · axigen mobile webmail · CWE-79 | Orta5,4 | — | %1,1 | 7 Şub 2024 |
21İzleyin | CVE-2025-68643İstismar yok | Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter.axigen · axigen mail server · CWE-79 | Orta5,4 | — | %0,2 | 5 Şub 2026 |
18İzleyin | CVE-2012-2592Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the axigen · axigen mail server · CWE-79 | Orta4,3 | — | %1,8 | 18 Haz 2014 |
- CVE-2022-3147040Planlayın
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 1
OrtaCVSS 6,1Kavram kanıtıEPSS %53axigen · axigen mobile webmail7 Haz 2022
- CVE-2023-4897439İzleyin
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script
KritikCVSS 9,6Kavram kanıtıEPSS %3axigen · axigen mail server7 Şub 2024
- CVE-2023-2356639İzleyin
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to a
KritikCVSS 9,8İstismar yokEPSS %1axigen · axigen mail server13 Oca 2023
- CVE-2020-2694236İzleyin
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a
KritikCVSS 9,1İstismar yokEPSS %0axigen · axigen mail server20 Mar 2024
- CVE-2025-6872336İzleyin
Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface.
KritikCVSS 9,0Kavram kanıtıEPSS %0axigen · axigen mail server5 Şub 2026
- CVE-2025-6872235İzleyin
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin inter
YüksekCVSS 8,8Kavram kanıtıEPSS %0axigen · axigen mail server5 Şub 2026
- CVE-2025-6872132İzleyin
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface.
YüksekCVSS 8,1Kavram kanıtıEPSS %0axigen · axigen mail server5 Şub 2026
- CVE-2024-2858926İzleyin
An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbi
OrtaCVSS 6,7Kavram kanıtıEPSS %03 Nis 2024
- CVE-2024-5060124İzleyin
Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow
OrtaCVSS 6,1İstismar yokEPSS %011 Kas 2024
- CVE-2023-4910124İzleyin
WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mi
OrtaCVSS 6,1İstismar yokEPSS %0axigen · axigen mobile webmail8 Şub 2024
- CVE-2015-537921İzleyin
Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attacke
OrtaCVSS 5,4İstismar yokEPSS %2axigen · axigen mail server23 Eki 2017
- CVE-2023-4035521İzleyin
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allo
OrtaCVSS 5,4Kavram kanıtıEPSS %1axigen · axigen mobile webmail7 Şub 2024
- CVE-2025-6864321İzleyin
Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter.
OrtaCVSS 5,4İstismar yokEPSS %0axigen · axigen mail server5 Şub 2026
- CVE-2012-259218İzleyin
Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the
OrtaCVSS 4,3Kavram kanıtıEPSS %2axigen · axigen mail server18 Haz 2014