Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2963▼ 120 respecto a la semana anterior
Críticas / altas1404▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Horde Groupware | 11/10/2017 | 17/6/2026 | The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename. | |
| Modificada | Alta (8.1) | 4.0% | — | Horde Image API | 21/9/2017 | 17/6/2026 | A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" utility. It's not exploitable through any Horde application, because the code path to the vulnerability is not used by any Horde code. Custom applications using the… | |
| Modificada | Alta (8.8) | 2.4% | — | Horde Image API | 21/6/2017 | 17/6/2026 | Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication. | |
| Modificada | Media (5.7) | 0.85% | — | Horde Image | 21/6/2017 | 17/6/2026 | Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver. | |
| Modificada | Alta (7.5) | 1.2% | — | Horde Groupware | 4/4/2017 | 17/6/2026 | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?" preference. To exploit this vulnerability,… | |
| Modificada | Alta (8.8) | 40% | — | Horde Groupware | 4/4/2017 | 17/6/2026 | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an email addressed to a maliciously crafted email address. | |
| Modificada | Media (6.1) | 1.5% | — | Horde Groupware | 20/12/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Horde Text Filter API in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows remote attackers to inject arbitrary web script or HTML via crafted data:text/html content in a form (1) action or (2) xlink attribute. | |
| Modificada | Media (6.1) | 1.9% | — | Debian LinuxHorde GroupwareHorde GroupwareFedoraproject Fedora | 13/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated by a request to… | |
| Modificada | Media (6.1) | 2.1% | — | Fedoraproject FedoraHorde GroupwareDebian Linux | 13/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric… | |
| Modificada | Media (6.8) | 4.1% | 💥 Exploit | Horde GroupwareHorde Application FrameworkDebian Linux | 19/11/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1) commands via the cmd parameter to… | |
| Modificada | Media (4.3) | 1.3% | — | Horde GroupwareHorde Internet Mail Program | 14/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via (1) unspecified flags or (2) a mailbox name in the dynamic mailbox view. | |
| Modificada | Media (4.3) | 1.3% | — | Horde GroupwareHorde Internet Mail Program | 14/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via an unspecified flag in the basic (1) mailbox or (2) message view. | |
| Modificada | Media (4.3) | 1.8% | — | Horde GroupwareHorde IMP | 5/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde Internet Mail Program (IMP) before 5.0.22, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted SVG image attachment, a different vulnerability than CVE-2012-5565. | |
| Modificada | Media (4.3) | 2.5% | — | Horde GroupwareHorde Kronolith H4 | 5/4/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject arbitrary web script or HTML via crafted event location parameters in the (1) month, (2) monthlist, or (3)… | |
| Modificada | Media (4.3) | 2.5% | — | Horde Kronolith H4Horde Groupware | 5/4/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in Horde Groupware Webmail Edition before 4.0.8, allow remote attackers to inject arbitrary web script or HTML via the (1) tasks view or (2) search view. | |
| Modificada | Media (4.3) | 1.8% | — | Horde IMPHorde Groupware | 5/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view. | |
| Modificada | Alta (7.5) | 43% | 💥 Exploit | Horde Application Framework | 1/4/2014 | 17/6/2026 | The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form. | |
| Modificada | Media (4.3) | 2.1% | — | Horde Kronolith H4 | 16/1/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the (1) tasks and (2) search views in Horde Kronolith H4 before 3.0.17 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Horde GroupwareHorde | 25/9/2012 | 16/6/2026 | Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code. | |
| Modificada | Media (4.3) | 1.8% | — | Horde Groupware Webmail Edition | 24/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 2.3% | — | Horde Dynamic IMPHorde IMPHorde Groupware Webmail Edition | 24/1/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts… | |
| Modificada | Media (4.3) | 0.90% | — | Horde IMPHorde Groupware | 4/4/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka fmusername), (2) password (aka fmpassword), or (3) server (aka fmserver) field… | |
| Modificada | Media (4.3) | 2.6% | — | Horde GroupwareHorde Dynamic IMP | 4/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via vectors related to displaying mailbox names. | |
| Modificada | Media (4.3) | 1.8% | — | Horde Gollem | 4/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view.php in the file viewer in Horde Gollem before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the file parameter in a view_file action. | |
| Modificada | Media (4.3) | 5.0% | 💥 Exploit | Horde IMPHorde Groupware | 31/3/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save action, related to the Fetchmail configuration. |