Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.9% | 💥 PoC | Synacor Zimbra Collaboration Suite | 30/5/2019 | 17/6/2026 | An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enumeration is possible via inconsistent responses for specific types of authentication requests. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Synacor Zimbra Collaboration Suite | 29/5/2019 | 17/6/2026 | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml. | |
| Modificada | Media (6.5) | 1.2% | — | Synacor Zimbra Collaboration Suite | 29/5/2019 | 17/6/2026 | Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component. | |
| Modificada | Crítica (9.8) | 3.8% | — | Synacor Zimbra Collaboration Suite | 29/5/2019 | 17/6/2026 | Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component. | |
| Modificada | Crítica (9.8) | 2.2% | — | Synacor Zimbra Collaboration Suite | 29/5/2019 | 17/6/2026 | ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd. | |
| Modificada | Media (6.1) | 0.99% | — | Synacor Zimbra Collaboration Suite | 29/5/2019 | 17/6/2026 | mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 has Persistent XSS. | |
| Modificada | Media (6.1) | 7.4% | 💥 Exploit | Synacor Zimbra Collaboration Suite | 29/5/2019 | 17/6/2026 | Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients. | |
| Analizada | Alta (7.5) | 81% | ⚠ Explotación activa💥 Exploit | Synacor Zimbra Collaboration Suite | 30/4/2019 | 17/6/2026 | Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component. | |
| Modificada | Media (5.3) | 0.61% | — | Synacor Zimbra Collaboration Suite | 3/10/2018 | 17/6/2026 | Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value. | |
| Modificada | Media (6.1) | 1.4% | — | Synacor Zimbra Collaboration SuiteZimbra Collaboration Suite | 30/5/2018 | 17/6/2026 | Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group. | |
| Modificada | Alta (8.8) | 1.2% | — | Synacor Zimbra Collaboration SuiteZimbra Collaboration Suite | 30/5/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token. | |
| Analizada | Media (6.5) | 1.3% | — | Synacor Zimbra Collaboration Suite | 10/5/2018 | 17/6/2026 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API. | |
| Modificada | Media (5.3) | 1.4% | — | Synacor Zimbra Collaboration Suite | 10/5/2018 | 17/6/2026 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full user-context dump. | |
| Modificada | Media (5.3) | 2.4% | 💥 PoC | Synacor Zimbra Collaboration Suite | 10/5/2018 | 17/6/2026 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors. | |
| Analizada | Media (6.1) | 30% | ⚠ Explotación activa💥 Exploit | Synacor Zimbra Collaboration Suite | 27/3/2018 | 1/10/2026 | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment. | |
| Modificada | Media (5.4) | 0.90% | — | Synacor Zimbra Collaboration Suite | 4/2/2018 | 17/6/2026 | Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS. | |
| Modificada | Media (6.1) | 1.0% | — | Synacor Zimbra Collaboration Suite | 4/2/2018 | 17/6/2026 | Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS. | |
| Modificada | Media (5.4) | 1.3% | 💥 PoC | Synocor Zimbra Collaboration Suite | 16/1/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the "Show Snippet" functionality. | |
| Modificada | Media (6.1) | 1.7% | — | Synacor Zimbra Collaboration Suite | 23/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.8% | — | Synacor Zimbra Collaboration Suite | 23/5/2017 | 17/6/2026 | Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Crítica (9.8) | 2.6% | — | Synacor Zimbra Collaboration Suite | 23/5/2017 | 17/6/2026 | A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations. | |
| Modificada | Alta (8.8) | 1.4% | — | Synacor Zimbra Collaboration Suite | 17/5/2017 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove accounts by leveraging failure to use of a CSRF token and perform… | |
| Modificada | Crítica (9.8) | 2.9% | — | Synacor Zimbra Collaboration Suite | 29/3/2017 | 17/6/2026 | Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks. | |
| Modificada | Alta (7.5) | 2.0% | — | Synacor Zimbra Collaboration Suite | 18/1/2017 | 17/6/2026 | Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect integrity via unknown vectors, aka bug 104477. | |
| Modificada | Media (6.1) | 1.5% | — | Synacor Zimbra Collaboration Suite | 18/1/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703. |