Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.84% | — | Zammad | 11/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc. | |
| Modificada | Crítica (9.1) | 1.1% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration. | |
| Modificada | Crítica (9.8) | 2.3% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled. | |
| Modificada | Alta (7.5) | 1.1% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information. | |
| Modificada | Media (6.1) | 0.65% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled. | |
| Modificada | Media (4.9) | 0.88% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API. | |
| Modificada | Alta (8.8) | 1.1% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request. | |
| Modificada | Media (5.4) | 0.52% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar. | |
| Modificada | Media (6.5) | 0.93% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service. | |
| Modificada | Crítica (9.8) | 1.9% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages. | |
| Modificada | Alta (7.2) | 1.3% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers. | |
| Modificada | Media (5.4) | 0.52% | — | Zammad | 7/10/2021 | 17/6/2026 | An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket. | |
| Modificada | Media (6.1) | 0.83% | — | Zammad | 28/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute. | |
| Modificada | Media (5.3) | 1.2% | — | Zammad | 28/6/2021 | 17/6/2026 | Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information. | |
| Modificada | Media (5.3) | 1.2% | — | Zammad | 28/6/2021 | 17/6/2026 | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view. | |
| Modificada | Media (4.3) | 0.89% | — | Zammad | 28/6/2021 | 17/6/2026 | Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page. | |
| Modificada | Alta (7.5) | 1.1% | — | Zammad | 28/6/2021 | 17/6/2026 | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing. | |
| Modificada | Media (6.1) | 1.5% | — | Zammad | 28/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information. | |
| Modificada | Alta (7.5) | 0.91% | — | Zammad | 28/12/2020 | 17/6/2026 | An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing. | |
| Modificada | Media (4.9) | 0.93% | — | Zammad | 28/12/2020 | 17/6/2026 | An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended. | |
| Modificada | Media (4.3) | 0.68% | — | Zammad | 28/12/2020 | 17/6/2026 | An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view. | |
| Modificada | Media (5.4) | 0.55% | — | Zammad | 28/12/2020 | 17/6/2026 | An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket. | |
| Modificada | Media (4.3) | 0.73% | — | Zammad | 28/12/2020 | 17/6/2026 | An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was recognized as associated with a valid user. | |
| Modificada | Media (5.4) | 0.36% | — | Zammad | 28/12/2020 | 17/6/2026 | An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check. | |
| Modificada | Alta (7.5) | 1.1% | — | Zammad | 28/12/2020 | 17/6/2026 | An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can use this to request any URL via a GET request from the network interface of the server. This may lead to disclosure of… |