7.5

CVSS3.1

CVE-2026-33616 - MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the mb24api Endpoint

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

๐Ÿ“… Published: April 2, 2026, 8:59 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:41 p.m.

9.1

CVSS3.1

CVE-2026-33615 - MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the setinfo Endpoint

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total loss of integrity and availability.

๐Ÿ“… Published: April 2, 2026, 8:59 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:45 p.m.

7.5

CVSS3.1

CVE-2026-33614 - MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the getinfo endpoint

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

๐Ÿ“… Published: April 2, 2026, 8:59 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:45 p.m.

7.2

CVSS3.1

CVE-2026-33613 - MB connect line mbCONNECT24 vulnerable to RCE in generateSrpArray

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise. This vulnerability can only be attacked if the attacker has some other way to write arbitrary data โ€ฆ

๐Ÿ“… Published: April 2, 2026, 8:59 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:49 p.m.

5.3

CVSS4.0

CVE-2026-29136 - CA Notification HTML Injection

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates.

๐Ÿ“… Published: April 2, 2026, 8:53 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:02 p.m.

7.8

CVSS4.0

CVE-2026-29139 - GINA State Confusion Account Takeover

SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.

๐Ÿ“… Published: April 2, 2026, 8:52 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7 p.m.

7.8

CVSS4.0

CVE-2026-29144 - Unicode Subject Tags

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters.

๐Ÿ“… Published: April 2, 2026, 8:50 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7 p.m.

7.8

CVSS4.0

CVE-2026-29143 - S/MIME Decryption Impersonation

SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.

๐Ÿ“… Published: April 2, 2026, 8:49 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:58 p.m.

7.8

CVSS3.1

CVE-2026-0634 - Code Execution in AssistFeedbackService on TECNO Pova7 Pro 5G

Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as system via command injection.

๐Ÿ“… Published: April 2, 2026, 8:48 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

6.3

CVSS4.0

CVE-2026-29138 - PGP Decryption Sender LDAP Injection

SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.

๐Ÿ“… Published: April 2, 2026, 8:47 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:01 p.m.
Total resulsts: 349182
Page 738 of 34,919
ยซ previous page ยป next page
Filters