Where
-Infinity
0

SmarterTools SmarterMailSmarterTools SmarterMail < Build 9560 Server Local File Inclusion via the /api/v1/report/summary/{type} API

Risk 56
Severity
8.7
EPSS
0.01%
First published (updated )

SmarterTools SmarterMailSmarterTools SmarterMail < Build 9610 Cryptographic Weakness via Weak RNG

Risk 43
Severity
8.2
First published (updated )

BleepingComputerTelegram channels expose rapid weaponization of SmarterMail flaws

First published (updated )

SmarterTools SmarterMailXSS

Risk 31
Severity
7.2
EPSS
0.04%
First published (updated )

BleepingComputerCISA warns of SmarterMail RCE flaw used in ransomware attacks

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SmarterTools SmarterMailSmarterTools SmarterMail < Build 9518 Unauthenticated background-of-the-day Path Coercion

Risk 23
Severity
6.9
EPSS
0.03%
First published (updated )

SmarterTools SmarterMailSmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

Risk 88
Severity
9.8
EPSS
22.65%
First published (updated )

BleepingComputerSmarterMail auth bypass flaw now exploited to hijack admin accounts

First published (updated )

SmarterTools SmarterMailSmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability

Risk 98
Severity
9.8
EPSS
55.52%
First published (updated )

SmarterTools SmarterMailSmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability

Risk 100
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

The RegisterApache warns of 10.0-rated flaw in Tika metadata toolkit

First published (updated )

The RegisterWeaponized file name flaw allows RCE through glob

First published (updated )

The RegisterTwin Google flaws allowed researcher to get from YouTube ID to Gmail address in a few easy steps

First published (updated )

The RegisterMicrosoft waited 6 months to patch actively exploited admin-to-kernel vulnerability

First published (updated )

SmarterTools SmarterMailXSS

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SmarterTools SmarterMailPath Traversal

Risk 26
Severity
5
First published (updated )

SmarterTools SmarterMailXSS

Risk 22
Severity
4.3
First published (updated )

SmarterTools SmarterMailSMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a de…

Risk 44
Severity
7.8
First published (updated )

SmarterTools SmarterMailBuffer Overflow

Risk 26
Severity
5
First published (updated )

SmarterTools SmarterMailDirectory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and …

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SmarterTools SmarterMailfrmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated user…

Risk 21
Severity
4
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203