SEPPmail kayıtları
seppmail üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-295 Improper Certificate Validation2
- CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-347 Improper Verification of Cryptographic Signature2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2026-2743İstismar yok | SEPPmail User Web Interface Arbitrary File Write to RCEseppmail · seppmail · CWE-22 | Kritik10,0 | — | %1,0 | 5 Mar 2026 |
38İzleyin | CVE-2026-27441İstismar yok | SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.seppmail · seppmail · CWE-78 | Kritik9,5 | — | %0,5 | 4 Mar 2026 |
37İzleyin | CVE-2026-27442İstismar yok | zip_attachments Path Traversalseppmail · seppmail · CWE-22 | Kritik9,3 | — | %0,5 | 4 Mar 2026 |
35İzleyin | CVE-2022-41871İstismar yok | SEPPmail through 12.1.17 allows command injection within the Admin Portal.seppmail · seppmail · CWE-78 | Yüksek8,8 | — | %1,1 | 28 Nis 2025 |
32İzleyin | CVE-2026-27443İstismar yok | S/MIME Decryption Tag Sanitization Bypassseppmail · seppmail · CWE-20 | Yüksek8,2 | — | %0,4 | 4 Mar 2026 |
31İzleyin | CVE-2026-29139İstismar yok | GINA State Confusion Account Takeoverseppmail · secure email gateway · CWE-288 | Yüksek7,8 | — | %0,5 | 2 Nis 2026 |
31İzleyin | CVE-2026-29143İstismar yok | S/MIME Decryption Impersonationseppmail · secure email gateway · CWE-20 | Yüksek7,8 | — | %0,4 | 2 Nis 2026 |
31İzleyin | CVE-2026-27444İstismar yok | Header Email Address Parsingseppmail · seppmail · CWE-436 | Yüksek7,8 | — | %0,4 | 4 Mar 2026 |
31İzleyin | CVE-2026-29144İstismar yok | Unicode Subject Tagsseppmail · secure email gateway · CWE-20 | Yüksek7,8 | — | %0,3 | 2 Nis 2026 |
31İzleyin | CVE-2026-2748İstismar yok | S/MIME Certificate Subject Whitespaceseppmail · seppmail · CWE-295 | Yüksek7,8 | — | %0,2 | 4 Mar 2026 |
30İzleyin | CVE-2026-29141İstismar yok | Bounded Subject Tag Sanitizationseppmail · secure email gateway · CWE-20 | Yüksek7,7 | — | %0,3 | 2 Nis 2026 |
30İzleyin | CVE-2026-29140İstismar yok | S/MIME Signature Additional Certificateseppmail · secure email gateway · CWE-295 | Yüksek7,7 | — | %0,2 | 2 Nis 2026 |
27İzleyin | CVE-2026-2747İstismar yok | PGP Mixed Plaintext and Encrypted Contentseppmail · seppmail · CWE-200 | Orta6,9 | — | %0,4 | 4 Mar 2026 |
27İzleyin | CVE-2026-27445İstismar yok | PGP Signature Reflectionseppmail · seppmail · CWE-347 | Orta6,9 | — | %0,2 | 4 Mar 2026 |
27İzleyin | CVE-2026-2746İstismar yok | Missing PGP Signature Tagseppmail · seppmail · CWE-347 | Orta6,9 | — | %0,2 | 4 Mar 2026 |
25İzleyin | CVE-2026-29132İstismar yok | ESWmail-Verify Bypassseppmail · secure email gateway · CWE-306 | Orta6,3 | — | %0,4 | 2 Nis 2026 |
25İzleyin | CVE-2026-29138İstismar yok | PGP Decryption Sender LDAP Injectionseppmail · secure email gateway · CWE-90 | Orta6,3 | — | %0,4 | 2 Nis 2026 |
25İzleyin | CVE-2026-29142İstismar yok | Plaintext secure-mail.htmlseppmail · secure email gateway · CWE-325 | Orta6,3 | — | %0,2 | 2 Nis 2026 |
24İzleyin | CVE-2021-31739İstismar yok | The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly encoded in HTML attriseppmail · seppmail · CWE-79 | Orta6,1 | — | %0,4 | 18 Kas 2022 |
24İzleyin | CVE-2021-31740İstismar yok | SEPPMail's web frontend, user input is not embedded correctly in the web page and therefore leads to cross-site scripting vulnerabilities (Xseppmail · seppmail · CWE-79 | Orta6,1 | — | %0,4 | 30 Kas 2022 |
21İzleyin | CVE-2026-29135İstismar yok | Webmail Password Tag Sanitization Bypassseppmail · secure email gateway · CWE-20 | Orta5,3 | — | %0,4 | 2 Nis 2026 |
21İzleyin | CVE-2026-29133İstismar yok | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.seppmail · secure email gateway · CWE-20 | Orta5,3 | — | %0,4 | 2 Nis 2026 |
21İzleyin | CVE-2026-29134İstismar yok | SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictseppmail · secure email gateway · CWE-807 | Orta5,3 | — | %0,4 | 2 Nis 2026 |
21İzleyin | CVE-2026-29137İstismar yok | Long Subject Untaggingseppmail · secure email gateway · CWE-20 | Orta5,3 | — | %0,3 | 2 Nis 2026 |
21İzleyin | CVE-2026-29136İstismar yok | CA Notification HTML Injectionseppmail · secure email gateway · CWE-79 | Orta5,3 | — | %0,2 | 2 Nis 2026 |
- CVE-2026-274340Planlayın
SEPPmail User Web Interface Arbitrary File Write to RCE
KritikCVSS 10,0İstismar yokEPSS %1seppmail · seppmail5 Mar 2026
- CVE-2026-2744138İzleyin
SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.
KritikCVSS 9,5İstismar yokEPSS %1seppmail · seppmail4 Mar 2026
- CVE-2026-2744237İzleyin
zip_attachments Path Traversal
KritikCVSS 9,3İstismar yokEPSS %0seppmail · seppmail4 Mar 2026
- CVE-2022-4187135İzleyin
SEPPmail through 12.1.17 allows command injection within the Admin Portal.
YüksekCVSS 8,8İstismar yokEPSS %1seppmail · seppmail28 Nis 2025
- CVE-2026-2744332İzleyin
S/MIME Decryption Tag Sanitization Bypass
YüksekCVSS 8,2İstismar yokEPSS %0seppmail · seppmail4 Mar 2026
- CVE-2026-2913931İzleyin
GINA State Confusion Account Takeover
YüksekCVSS 7,8İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-2914331İzleyin
S/MIME Decryption Impersonation
YüksekCVSS 7,8İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-2744431İzleyin
Header Email Address Parsing
YüksekCVSS 7,8İstismar yokEPSS %0seppmail · seppmail4 Mar 2026
- CVE-2026-2914431İzleyin
Unicode Subject Tags
YüksekCVSS 7,8İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-274831İzleyin
S/MIME Certificate Subject Whitespace
YüksekCVSS 7,8İstismar yokEPSS %0seppmail · seppmail4 Mar 2026
- CVE-2026-2914130İzleyin
Bounded Subject Tag Sanitization
YüksekCVSS 7,7İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-2914030İzleyin
S/MIME Signature Additional Certificate
YüksekCVSS 7,7İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-274727İzleyin
PGP Mixed Plaintext and Encrypted Content
OrtaCVSS 6,9İstismar yokEPSS %0seppmail · seppmail4 Mar 2026
- CVE-2026-2744527İzleyin
PGP Signature Reflection
OrtaCVSS 6,9İstismar yokEPSS %0seppmail · seppmail4 Mar 2026
- CVE-2026-274627İzleyin
Missing PGP Signature Tag
OrtaCVSS 6,9İstismar yokEPSS %0seppmail · seppmail4 Mar 2026
- CVE-2026-2913225İzleyin
ESWmail-Verify Bypass
OrtaCVSS 6,3İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-2913825İzleyin
PGP Decryption Sender LDAP Injection
OrtaCVSS 6,3İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-2914225İzleyin
Plaintext secure-mail.html
OrtaCVSS 6,3İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2021-3173924İzleyin
The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly encoded in HTML attri
OrtaCVSS 6,1İstismar yokEPSS %0seppmail · seppmail18 Kas 2022
- CVE-2021-3174024İzleyin
SEPPMail's web frontend, user input is not embedded correctly in the web page and therefore leads to cross-site scripting vulnerabilities (X
OrtaCVSS 6,1İstismar yokEPSS %0seppmail · seppmail30 Kas 2022
- CVE-2026-2913521İzleyin
Webmail Password Tag Sanitization Bypass
OrtaCVSS 5,3İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-2913321İzleyin
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.
OrtaCVSS 5,3İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-2913421İzleyin
SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrict
OrtaCVSS 5,3İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-2913721İzleyin
Long Subject Untagging
OrtaCVSS 5,3İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026
- CVE-2026-2913621İzleyin
CA Notification HTML Injection
OrtaCVSS 5,3İstismar yokEPSS %0seppmail · secure email gateway2 Nis 2026