Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

123 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.84%—Zammad11/10/202117/6/2026
An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc.
ModificadaCrítica (9.1)1.1%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
ModificadaCrítica (9.8)2.3%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
ModificadaAlta (7.5)1.1%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.
ModificadaMedia (6.1)0.65%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.
ModificadaMedia (4.9)0.88%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
ModificadaAlta (8.8)1.1%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.
ModificadaMedia (5.4)0.52%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
ModificadaMedia (6.5)0.93%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.
ModificadaCrítica (9.8)1.9%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
ModificadaAlta (7.2)1.3%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.
ModificadaMedia (5.4)0.52%—Zammad7/10/202117/6/2026
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.
ModificadaMedia (6.1)0.83%—Zammad28/6/202117/6/2026
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute.
ModificadaMedia (5.3)1.2%—Zammad28/6/202117/6/2026
Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.
ModificadaMedia (5.3)1.2%—Zammad28/6/202117/6/2026
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.
ModificadaMedia (4.3)0.89%—Zammad28/6/202117/6/2026
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.
ModificadaAlta (7.5)1.1%—Zammad28/6/202117/6/2026
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
ModificadaMedia (6.1)1.5%—Zammad28/6/202117/6/2026
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.
ModificadaAlta (7.5)0.91%—Zammad28/12/202017/6/2026
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.
ModificadaMedia (4.9)0.93%—Zammad28/12/202017/6/2026
An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.
ModificadaMedia (4.3)0.68%—Zammad28/12/202017/6/2026
An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.
ModificadaMedia (5.4)0.55%—Zammad28/12/202017/6/2026
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
ModificadaMedia (4.3)0.73%—Zammad28/12/202017/6/2026
An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was recognized as associated with a valid user.
ModificadaMedia (5.4)0.36%—Zammad28/12/202017/6/2026
An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.
ModificadaAlta (7.5)1.1%—Zammad28/12/202017/6/2026
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can use this to request any URL via a GET request from the network interface of the server. This may lead to disclosure of…