5.3

CVSS4.0

CVE-2026-29137 - Long Subject Untagging

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.

πŸ“… Published: April 2, 2026, 8:42 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.7

CVSS4.0

CVE-2026-29141 - Bounded Subject Tag Sanitization

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].

πŸ“… Published: April 2, 2026, 8:34 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS4.0

CVE-2026-29135 - Webmail Password Tag Sanitization Bypass

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.

πŸ“… Published: April 2, 2026, 8:31 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS4.0

CVE-2026-29134 - GINA Domain Switch

SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions.

πŸ“… Published: April 2, 2026, 8:29 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.7

CVSS4.0

CVE-2026-29140 - S/MIME Signature Additional Certificate

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.

πŸ“… Published: April 2, 2026, 8:27 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS4.0

CVE-2026-29133 - UID Regex Bypass

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.

πŸ“… Published: April 2, 2026, 8:26 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

6.3

CVSS4.0

CVE-2026-29132 - ESWmail-Verify Bypass

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails.

πŸ“… Published: April 2, 2026, 8:25 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

6.9

CVSS4.0

CVE-2026-5244 - Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been …

πŸ“… Published: April 2, 2026, 8 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.5

CVSS3.1

CVE-2026-5032 - W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header

The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which causes raw mfunc/m…

πŸ“… Published: April 2, 2026, 7:39 a.m. πŸ”„ Last Modified: April 8, 2026, 8:02 p.m.

7.2

CVSS3.1

CVE-2026-0686 - Webmention <= 5.6.2 - Unauthenticated Blind Server-Side Request Forgery

The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 in the 'MF2::parse_authorpage' function via the 'Receiver::post' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations or…

πŸ“… Published: April 2, 2026, 7:39 a.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.
Total resulsts: 343942
Page 219 of 34,395
Β« previous page Β» next page
Filters