Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.4%—Zimbra Collaboration Server27/1/202017/6/2026
Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS.
ModificadaMedia (6.1)1.4%—Zimbra Collaboration Server27/1/202017/6/2026
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.
ModificadaMedia (6.1)1.4%—Zimbra Collaboration Server27/1/202017/6/2026
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.
ModificadaMedia (6.1)0.97%—Zimbra Collaboration Server27/1/202017/6/2026
In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.
ModificadaMedia (4.8)1.0%—Zimbra Collaboration Server27/1/202017/6/2026
Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.
ModificadaMedia (5.4)1.1%—Synacor Zimbra Collaboration Server27/1/202017/6/2026
Zimbra Collaboration before 8.8.12 Patch 1 has persistent XSS.
ModificadaMedia (5.4)0.69%—Synacor Zimbra Collaboration Server27/1/202017/6/2026
Zimbra Collaboration before 8.6.0 patch5 has XSS.
ModificadaCrítica (9.8)2.5%—Synacor Zimbra Collaboration Server27/1/202017/6/2026
Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.
ModificadaMedia (6.1)0.83%—Synacor Zimbra Collaboration Server27/1/202017/6/2026
Synacor Zimbra Collaboration before 8.0.8 has XSS.
ModificadaMedia (6.1)0.81%—Synacor Zimbra Collaboration Server30/5/201917/6/2026
Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console.
ModificadaMedia (6.1)1.1%—Zimbra Collaboration Server29/8/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)3.0%—Zimbra Collaboration Server8/4/201617/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that change account preferences via a SOAP request to service/soap/BatchRequest.
ModificadaMedia (6.3)1.1%—IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management19/7/201417/6/2026
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter.
ModificadaBaja (3.5)0.77%—IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management19/7/201417/6/2026
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links via unspecified vectors.
ModificadaBaja (3.5)0.76%—IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management19/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or…
ModificadaBaja (3.5)0.76%—IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management19/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or…
ModificadaMedia (6.8)0.57%—IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management4/2/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users.
ModificadaAlta (10)3.0%—Zimbra Collaboration Server26/12/201317/6/2026
Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vectors, a different vulnerability than CVE-2013-7091.
ModificadaMedia (4.9)0.50%—IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management19/12/201316/6/2026
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors.
ModificadaBaja (3.5)0.76%—IBM Infosphere Master Data Management Server FOR Product Information ManagementIBM Infosphere Master Data Management Collaboration Server27/11/201316/6/2026
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script…
ModificadaBaja (3.5)0.76%—IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management21/2/201316/6/2026
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified…
ModificadaMedia (6)0.93%—IBM Infosphere Master Data Management Collaboration ServerIBM Infosphere Master Data Management Server FOR Product Information Management21/2/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing…
ModificadaMedia (5)7.7%—Cisco Collaboration Server17/2/201016/6/2026
Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension, as demonstrated by (1) changing .jhtml to %2Ejhtml, (2) changing .jhtml to .jhtm%6C, (3) appending %00 after .jhtml, and (4) appending %c0%80 after .jhtml, related to…
ModificadaMedia (4.3)3.2%—Cisco Collaboration Server17/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to inject arbitrary web script or HTML via the dest parameter.
ModificadaAlta (7.5)2.0%—Ventia Desknow Mail AND Collaboration Server2/5/200516/6/2026
Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to…