HGiga Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with HGiga products.
Products
- iSherlock 4.59 vulnerabilities
- iSherlock 5.59 vulnerabilities
- MailSherlock MSR45/SSR458 vulnerabilities
- isherlock6 vulnerabilities
- MailSherlock4 vulnerabilities
- OAKlouds4 vulnerabilities
- PowerStation3 vulnerabilities
- C&Cm@il package olln-base2 vulnerabilities
- C&Cmail2 vulnerabilities
- OAKlouds OAKSv22 vulnerabilities
- OAKlouds OAKSv32 vulnerabilities
- C&Cm@il1 vulnerability
- C&Cm@il package olln-base1 vulnerability
- iSherlock-audit-4.51 vulnerability
- iSherlock-audit-5.51 vulnerability
- iSherlock-base-4.51 vulnerability
- iSherlock-base-5.51 vulnerability
- iSherlock-maillog-4.51 vulnerability
- iSherlock-maillog-5.51 vulnerability
- iSherlock-smtp-4.51 vulnerability
- iSherlock-smtp-5.51 vulnerability
- oaklouds-organization1 vulnerability
- oaklouds-webbase1 vulnerability
- OAKSv20 OAKlouds-document_v31 vulnerability
- OAKSv20 OAKlouds-document_v3 2.01 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-6349CRITICAL | HGiga|iSherlock - OS Command InjectionThe iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server. CWE-78Apr 16, 2026 | CVSS9.3v4.0 | EPSS2.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2236HIGH | HGiga|C&Cm@il - SQL InjectionC&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. CWE-89Feb 9, 2026 | CVSS8.7v4.0 | EPSS0.41% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2235HIGH | HGiga|C&Cm@il - SQL InjectionC&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. CWE-89Feb 9, 2026 | CVSS7.1v4.0 | EPSS0.272% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2234CRITICAL | HGiga|C&Cm@il - Missing AuthenticationC&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail content. CWE-306Feb 9, 2026 | CVSS9.3v4.0 | EPSS0.449% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11900CRITICAL | HGiga|iSherlock - OS Command InjectionThe iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. CWE-78Oct 17, 2025 | CVSS9.3v4.0 | EPSS1.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7451CRITICAL | Hgiga|iSherlock - OS Command InjectionThe iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately. CWE-78Jul 14, 2025 | CVSS9.3v4.0 | EPSS1.41% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3364MEDIUM | HGiga PowerStation - Chroot EscapeThe SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire file system. CWE-250Apr 8, 2025 | CVSS6.7v3.1 | EPSS0.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3363CRITICAL | HGiga iSherlock - OS Command InjectionThe web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. CWE-78Apr 8, 2025 | CVSS9.8v3.1 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3362CRITICAL | HGiga iSherlock - OS Command InjectionThe web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. CWE-78Apr 8, 2025 | CVSS9.8v3.1 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3361CRITICAL | HGiga iSherlock - OS Command InjectionThe web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. CWE-78Apr 8, 2025 | CVSS9.8v3.1 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2150MEDIUM | HGiga C&Cm@il - Stored Cross-Site ScriptingThe C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email. CWE-79Mar 10, 2025 | CVSS5.4v3.1 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9924CRITICAL | Hgiga OAKlouds - Arbitrary File Read And DeleteThe fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthenticated remote attackers still can download arbitrary system files, which may be deleted subsequently . CWE-36Oct 14, 2024 | CVSS9.8v3.1 | EPSS0.827% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4299HIGH | HGiga iSherlock - Command InjectionThe system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands. CWE-78Apr 29, 2024 | CVSS7.2v3.1 | EPSS2.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4298HIGH | HGiga iSherlock - Command InjectionThe email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands. CWE-78Apr 29, 2024 | CVSS7.2v3.1 | EPSS2.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4297MEDIUM | HGiga iSherlock - Arbitrary File DownloadThe system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files. CWE-22Apr 29, 2024 | CVSS4.9v3.1 | EPSS0.674% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4296MEDIUM | HGiga iSherlock - Arbitrary File DownloadThe account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files. CWE-22Apr 29, 2024 | CVSS4.9v3.1 | EPSS0.674% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-26261CRITICAL | Hgiga OAKlouds - Arbitrary File Read And DeleteThe functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded. CWE-22Feb 15, 2024 | CVSS9.8v3.1 | EPSS0.679% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-26260CRITICAL | Hgiga OAKlouds - Command InjectionThe functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission. CWE-78Feb 15, 2024 | CVSS9.8v3.1 | EPSS1.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-37292CRITICAL | HGiga iSherlock - Command InjectionImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before iSherlock-user-5.5-174. CWE-78Jul 21, 2023 | CVSS9.8v3.1 | EPSS1.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24841HIGH | HGiga MailSherlock - Command InjectionHGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service. CWE-78Mar 27, 2023 | CVSS7.2v3.1 | EPSS0.928% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24840HIGH | HGiga MailSherlock - SQL InjectionHGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database. CWE-89Mar 27, 2023 | CVSS7.2v3.1 | EPSS0.928% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24838CRITICAL | HGiga PowerStation - Information LeakageHGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerStation or Secure Shell to achieve remote code execution. | CVSS9.8v3.1 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24842MEDIUM | HGiga MailSherlock - Broken Access ControlHGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL. CWE-639Mar 27, 2023 | CVSS5.3v3.1 | EPSS0.595% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24839MEDIUM | HGiga MailSherlock - Reflected XSSHGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conducting a reflected XSS attack. CWE-79Mar 27, 2023 | CVSS6.1v3.1 | EPSS0.494% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24837HIGH | HGiga PowerStation - Command InjectionHGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service. CWE-78Mar 27, 2023 | CVSS8.8v3.1 | EPSS0.933% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |