Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.38% | — | Open-xchange OX Guard | 2/11/2023 | 17/6/2026 | Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to trigger persistent code execution, allowing… | |
| Modificada | Alta (7.5) | 1.6% | — | Open-xchange OX Guard | 30/4/2021 | 17/6/2026 | OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data. | |
| Modificada | Media (5) | 1.1% | — | Open-xchange OX Guard | 15/6/2020 | 17/6/2026 | OX Guard 2.10.3 and earlier allows SSRF. | |
| Modificada | Media (6.1) | 1.2% | — | Open-xchange OX Guard | 15/6/2020 | 17/6/2026 | OX Guard 2.10.3 and earlier allows XSS. | |
| Modificada | Alta (8.8) | 0.46% | — | Open-xchange OX Guard | 3/7/2019 | 17/6/2026 | OX Guard 2.8.0 has CSRF. | |
| Modificada | Media (6.1) | 2.4% | — | Open-xchange OX Guard | 15/12/2016 | 17/6/2026 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web… | |
| Modificada | Media (6.1) | 2.4% | — | Open-xchange OX Guard | 15/12/2016 | 17/6/2026 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later on using a specific URL, such script code might get executed. In case of injecting external websites, users might get lured… | |
| Modificada | Media (6.1) | 2.6% | — | Open-xchange OX Guard | 15/12/2016 | 17/6/2026 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks against arbitrary users since no prior authentication is needed. Malicious script code can be executed within a user's… | |
| Modificada | Alta (7.5) | 0.71% | — | Open-xchange OX Guard | 15/12/2016 | 17/6/2026 | An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify and transfer guest users' credentials. The OX Guard API acts as a padding oracle by responding with different error codes depending on whether the provided token matches the encryption padding. In… | |
| Modificada | Alta (8.8) | 2.2% | — | Open-xchange OX Guard | 15/12/2016 | 17/6/2026 | An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. Clients provide the "id" and "cid" parameter to specify the current user by its user- and context-ID. The "auth" parameter… | |
| Modificada | Media (4.3) | 2.0% | — | Open-xchange OX Guard | 19/11/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard before 2.0.0-rev11 allows remote attackers to inject arbitrary web script or HTML via the uid field in a PGP public key, which is not properly handled in "Guard PGP Settings." | |
| Modificada | Media (6.5) | 1.7% | — | Open-xchange OX Guard | 28/9/2015 | 17/6/2026 | SQL injection vulnerability in the public key discovery API call in Open-Xchange OX Guard before 2.0.0-rev8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |