Softnext develops a focused portfolio of mail and threat-management appliances—including Mail SQR Expert, SN OS, and Spam SQR—that operate at the network perimeter and serve as centralized security gateways. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through injection and traversal weakness classes—OS command injection, code injection, path traversal, and server-side request forgery—that are characteristic of internet-facing mail and filtering middleware processing untrusted input. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Softnext over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5670CRITICAL The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject arbitrar | Jul 29, 2024 | 9.8 | 31 | NO | NO |
CVE-2022-40741CRITICAL Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system | Oct 31, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-48380HIGH Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote attacker authenticated as a loca | Dec 15, 2023 | 8.0 | 23 | NO | NO |
CVE-2023-24835HIGH Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit | Mar 27, 2023 | 7.2 | 23 | NO | NO |
CVE-2022-40742MEDIUM Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file exte | Oct 31, 2022 | 6.5 | 23 | NO | NO |
CVE-2023-48382MEDIUM Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a mail deliver-related URL. An unauthenticated remote attacker can ex | Dec 15, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-48381MEDIUM Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special URL. An unauthenticated remote attacker can exploit this vu | Dec 15, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-48378HIGH Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass auth | Dec 15, 2023 | 7.5 | 19 | NO | NO |
CVE-2023-48379MEDIUM Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker ca | Dec 15, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Softnext.
Media articles that mention a CVE ID that affects a product developed by Softnext — matched by CVE ID, not by vendor name.