4.9

CVSS4.0

CVE-2026-29131 - PGP Decryption Recipient LDAP Injection

SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users.

๐Ÿ“… Published: April 2, 2026, 8:46 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:07 p.m.

6.3

CVSS4.0

CVE-2026-29142 - Plaintext secure-mail.html

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.

๐Ÿ“… Published: April 2, 2026, 8:44 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7 p.m.

5.3

CVSS4.0

CVE-2026-29137 - Long Subject Untagging

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.

๐Ÿ“… Published: April 2, 2026, 8:42 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:01 p.m.

7.7

CVSS4.0

CVE-2026-29141 - Bounded Subject Tag Sanitization

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].

๐Ÿ“… Published: April 2, 2026, 8:34 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7 p.m.

5.3

CVSS4.0

CVE-2026-29135 - Webmail Password Tag Sanitization Bypass

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.

๐Ÿ“… Published: April 2, 2026, 8:31 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:03 p.m.

5.3

CVSS4.0

CVE-2026-29134 - GINA Domain Switch

SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions.

๐Ÿ“… Published: April 2, 2026, 8:29 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:03 p.m.

7.7

CVSS4.0

CVE-2026-29140 - S/MIME Signature Additional Certificate

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.

๐Ÿ“… Published: April 2, 2026, 8:27 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7 p.m.

5.3

CVSS4.0

CVE-2026-29133 - UID Regex Bypass

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.

๐Ÿ“… Published: April 2, 2026, 8:26 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:06 p.m.

6.3

CVSS4.0

CVE-2026-29132 - ESWmail-Verify Bypass

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails.

๐Ÿ“… Published: April 2, 2026, 8:25 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:07 p.m.

6.9

CVSS4.0

CVE-2026-5244 - Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: April 2, 2026, 8 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.
Total resulsts: 349182
Page 739 of 34,919
ยซ previous page ยป next page
Filters