Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

90 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitSynacor Zimbra Collaboration Suite29/5/201917/6/2026
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
ModificadaMedia (6.5)1.2%—Synacor Zimbra Collaboration Suite29/5/201917/6/2026
Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component.
ModificadaCrítica (9.8)3.8%—Synacor Zimbra Collaboration Suite29/5/201917/6/2026
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
ModificadaCrítica (9.8)2.2%—Synacor Zimbra Collaboration Suite29/5/201917/6/2026
ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd.
ModificadaMedia (6.1)0.99%—Synacor Zimbra Collaboration Suite29/5/201917/6/2026
mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 has Persistent XSS.
ModificadaMedia (6.1)7.4%💥 ExploitSynacor Zimbra Collaboration Suite29/5/201917/6/2026
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
AnalizadaAlta (7.5)81%⚠ Explotación activa💥 ExploitSynacor Zimbra Collaboration Suite30/4/201917/6/2026
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
ModificadaMedia (5.3)0.61%—Synacor Zimbra Collaboration Suite3/10/201817/6/2026
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
ModificadaMedia (6.1)1.4%—Synacor Zimbra Collaboration SuiteZimbra Collaboration Suite30/5/201817/6/2026
Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.
ModificadaAlta (8.8)1.2%—Synacor Zimbra Collaboration SuiteZimbra Collaboration Suite30/5/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.
AnalizadaMedia (6.5)1.3%—Synacor Zimbra Collaboration Suite10/5/201817/6/2026
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API.
ModificadaMedia (5.3)1.4%—Synacor Zimbra Collaboration Suite10/5/201817/6/2026
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full user-context dump.
ModificadaMedia (5.3)2.4%💥 PoCSynacor Zimbra Collaboration Suite10/5/201817/6/2026
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.
AnalizadaMedia (6.1)30%⚠ Explotación activa💥 ExploitSynacor Zimbra Collaboration Suite27/3/20181/10/2026
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
ModificadaMedia (5.4)0.90%—Synacor Zimbra Collaboration Suite4/2/201817/6/2026
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.
ModificadaMedia (6.1)1.0%—Synacor Zimbra Collaboration Suite4/2/201817/6/2026
Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.
ModificadaMedia (5.4)1.3%💥 PoCSynocor Zimbra Collaboration Suite16/1/201817/6/2026
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the "Show Snippet" functionality.
ModificadaMedia (6.1)1.7%—Synacor Zimbra Collaboration Suite23/5/201717/6/2026
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)3.8%—Synacor Zimbra Collaboration Suite23/5/201717/6/2026
Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors.
ModificadaCrítica (9.8)2.6%—Synacor Zimbra Collaboration Suite23/5/201717/6/2026
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.
ModificadaAlta (8.8)1.4%—Synacor Zimbra Collaboration Suite17/5/201717/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove accounts by leveraging failure to use of a CSRF token and perform…
ModificadaCrítica (9.8)2.9%—Synacor Zimbra Collaboration Suite29/3/201717/6/2026
Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
ModificadaAlta (7.5)2.0%—Synacor Zimbra Collaboration Suite18/1/201717/6/2026
Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect integrity via unknown vectors, aka bug 104477.
ModificadaMedia (6.1)1.5%—Synacor Zimbra Collaboration Suite18/1/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703.
ModificadaCrítica (9.1)2.5%—Synacor Zimbra Collaboration Suite18/1/201717/6/2026
Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.
Orbitaley — Vulnerabilidades