Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.62% | — | Open-xchange Appsuite | 31/8/2020 | 17/6/2026 | OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address. | |
| Modificada | Media (6.5) | 1.1% | — | Open-xchange Appsuite | 16/6/2020 | 17/6/2026 | OX App Suite through 7.10.3 allows SSRF. | |
| Modificada | Alta (7.5) | 2.0% | — | Open-xchange Appsuite | 16/6/2020 | 17/6/2026 | OX App Suite through 7.10.3 has Improper Input Validation. | |
| Modificada | Media (5.4) | 1.2% | — | Open-xchange Appsuite | 16/6/2020 | 17/6/2026 | OX App Suite through 7.10.3 allows XSS. | |
| Modificada | Media (6.5) | 1.0% | — | Open-xchange Appsuite | 16/6/2020 | 17/6/2026 | OX App Suite through 7.10.3 allows XXE attacks. | |
| Modificada | Media (5) | 0.92% | — | Open-xchange Appsuite | 21/2/2020 | 17/6/2026 | OX App Suite through 7.10.2 allows SSRF. | |
| Modificada | Alta (7.5) | 3.8% | — | Open-xchange Appsuite | 31/1/2020 | 17/6/2026 | Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file. | |
| Modificada | Alta (7.8) | 1.9% | — | Open-xchange Appsuite | 14/1/2020 | 17/6/2026 | XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document. | |
| Modificada | Media (6.1) | 1.5% | — | Open-xchange Appsuite | 6/1/2020 | 17/6/2026 | OX App Suite through 7.10.2 has XSS. | |
| Modificada | Media (6.6) | 1.7% | — | Open-xchange Appsuite | 6/1/2020 | 17/6/2026 | OX App Suite through 7.10.2 has Incorrect Access Control. | |
| Modificada | Media (6.1) | 1.6% | — | Open-xchange Appsuite | 2/1/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of… | |
| Modificada | Media (6.1) | 1.8% | — | Open-xchange Appsuite | 2/1/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message. NOTE: this vulnerability was SPLIT from… | |
| Modificada | Media (6.1) | 1.6% | — | Open-xchange Appsuite | 2/1/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the body of the email and the publication name… | |
| Modificada | Media (6.1) | 1.00% | — | Open-xchange Appsuite | 14/10/2019 | 17/6/2026 | OX App Suite 7.10.1 and 7.10.2 allows XSS. | |
| Modificada | Alta (8.1) | 1.2% | — | Open-xchange Appsuite | 14/10/2019 | 17/6/2026 | OX App Suite through 7.10.2 has Insecure Permissions. | |
| Modificada | Media (5.4) | 0.70% | — | Open-xchange Appsuite | 14/10/2019 | 17/6/2026 | OX App Suite 7.10.1 and 7.10.2 allows SSRF. | |
| Modificada | Baja (3.3) | 0.39% | — | Open-xchange Appsuite | 20/8/2019 | 17/6/2026 | OX App Suite 7.10.1 and earlier has Insecure Permissions. | |
| Modificada | Media (5.4) | 0.72% | — | Open-xchange Appsuite | 20/8/2019 | 17/6/2026 | OX App Suite 7.10.0 to 7.10.2 allows XSS. | |
| Modificada | Alta (8.1) | 1.7% | — | Open-xchange Appsuite | 20/8/2019 | 17/6/2026 | OX App Suite 7.10.1 allows Content Spoofing. | |
| Modificada | Alta (7.5) | 1.6% | — | Open-xchange Appsuite | 18/6/2019 | 17/6/2026 | OX App Suite 7.10.1 and earlier allows Information Exposure. | |
| Modificada | Crítica (9.8) | 1.5% | — | Open-xchange Appsuite | 17/6/2019 | 17/6/2026 | OX App Suite 7.10.0 and earlier has Incorrect Access Control. | |
| Modificada | Crítica (9.9) | 0.89% | — | Open-xchange Appsuite | 23/5/2019 | 17/6/2026 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF. | |
| Modificada | Media (5.4) | 0.53% | — | Open-xchange Appsuite | 23/5/2019 | 17/6/2026 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). | |
| Modificada | Media (6.1) | 0.86% | — | Open-xchange Appsuite | 23/5/2019 | 17/6/2026 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 1.4% | — | Open-xchange Appsuite | 23/5/2019 | 17/6/2026 | Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control. |