Products: 2
    Vulnerabilities: 68
    Known Exploited: 5
    18
    Critical Level Threats
    28
    High Level Threats
    19
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-66141

    Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

    Last Modified: Aug 03, 2026
    Published: Jul 24, 2026

    CVE-2026-66140

    Directory Traversal Exploiting Queue-Name Argument in Exim

    Last Modified: Jul 26, 2026
    Published: Jul 24, 2026

    CVE-2026-48840

    Exim Proxy Misconfiguration Causes Uninitialized Memory Disclosure

    Last Modified: Jun 05, 2026
    Published: May 30, 2026

    CVE-2026-45185

    Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

    Last Modified: Jun 18, 2026
    Published: May 12, 2026

    CVE-2026-40687

    Out‑of‑Bounds Write and Data Disclosure via Exim SPA Authentication Driver

    Last Modified: May 01, 2026
    Published: Apr 30, 2026
    Items Per Page