Vulnerabilidades en axllent
11 resultadosAnálisis Vexday
Axllent apresenta 11 vulnerabilidades catalogadas, com metade delas (6) divulgadas nos últimos 90 dias, indicando risco recente e ativo. Nenhuma está sob exploração documentada (KEV) e não há críticas por severidade CVSS, mas a fraqueza dominante CWE-918 (Server-Side Request Forgery) representa vetor de ataque significativo em ambiente de rede. O padrão de publicações recentes demanda monitoramento contínuo de patches.
CVE-2026-23829MEDIUMMailpit has SMTP Header Injection via Regex BypassEPSS 1.4%CVE-2026-21859MEDIUMMailpit Proxy Endpoint is Vulnerable to Server-Side Request Forgery (SSRF)EPSS 0.8%CVE-2026-27808MEDIUMMailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check APIEPSS 0.5%CVE-2026-48824MEDIUMMailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)EPSS 0.4%CVE-2026-45713HIGHMailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizesEPSS 0.4%CVE-2026-23845MEDIUMMailpit Vulnerable to Server-Side Request Forgery (SSRF) via HTML Check APIEPSS 0.4%CVE-2026-45711MEDIUMMailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDsEPSS 0.3%CVE-2026-55187MEDIUMMailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms (follow-up to CVE-2026-27808)EPSS 0.3%CVE-2026-45709MEDIUMMailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialerEPSS 0.3%CVE-2026-45712MEDIUMMailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)EPSS 0.2%CVE-2026-22689MEDIUMMailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emailsEPSS 0.2%