Vulnerabilities
Vulnerable Software
Security Vulnerabilities
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total loss of integrity and availability.
CVSS Score
9.1
EPSS Score
0.001
Published
2026-04-02
Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise. This vulnerability can only be attacked if the attacker has some other way to write arbitrary data to the user table.
CVSS Score
7.2
EPSS Score
0.001
Published
2026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.
CVSS Score
5.3
EPSS Score
0.001
Published
2026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.
CVSS Score
6.3
EPSS Score
0.0
Published
2026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.
CVSS Score
7.7
EPSS Score
0.0
Published
2026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].
CVSS Score
7.7
EPSS Score
0.001
Published
2026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
CVSS Score
6.3
EPSS Score
0.0
Published
2026-04-02


Contact Us

Shodan ® - All rights reserved