Записи zammad
90 опубликованных записей вендора zammad.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 14,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-863 Incorrect Authorization8
- CWE-862 Missing Authorization7
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-284 Improper Access Control3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
90 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-42090Эксплойта нет | An issue was discovered in Zammad before 4.1.1.zammad · zammad · CWE-502 | Критическая9,8 | — | 2,3 % | 7 окт. 2021 г. |
40В плане | CVE-2021-42094Эксплойта нет | An issue was discovered in Zammad before 4.1.1.zammad · zammad · CWE-77 | Критическая9,8 | — | 1,9 % | 7 окт. 2021 г. |
39Наблюдать | CVE-2017-5619Эксплойта нет | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1.zammad · zammad · CWE-287 | Критическая9,8 | — | 1,5 % | 13 мар. 2017 г. |
39Наблюдать | CVE-2020-26030Эксплойта нет | An issue was discovered in Zammad before 3.4.1.zammad · zammad · CWE-287 | Критическая9,8 | — | 1,4 % | 28 дек. 2020 г. |
39Наблюдать | CVE-2022-48021Эксплойта нет | A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.zammad · zammad | Критическая9,8 | — | 0,9 % | 2 февр. 2023 г. |
39Наблюдать | CVE-2022-35490Эксплойта нет | Zammad 5.2.0 is vulnerable to privilege escalation.zammad · zammad · CWE-307 | Критическая9,8 | — | 0,9 % | 8 авг. 2022 г. |
39Наблюдать | CVE-2017-6080Эксплойта нет | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involvizammad · zammad · CWE-352 | Критическая9,8 | — | 0,7 % | 13 мар. 2017 г. |
36Наблюдать | CVE-2022-27332Эксплойта нет | An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication.zammad · zammad · CWE-306 | Критическая9,1 | — | 1,1 % | 26 апр. 2022 г. |
36Наблюдать | CVE-2021-42091Эксплойта нет | An issue was discovered in Zammad before 4.1.1.zammad · zammad · CWE-918 | Критическая9,1 | — | 1,1 % | 7 окт. 2021 г. |
36Наблюдать | CVE-2024-33668Эксплойта нет | An issue was discovered in Zammad before 6.3.0.zammad · zammad · CWE-639 | Критическая9,1 | — | 0,4 % | 25 апр. 2024 г. |
35Наблюдать | CVE-2021-42086Эксплойта нет | An issue was discovered in Zammad before 4.1.1.zammad · zammad | Высокая8,8 | — | 1,1 % | 7 окт. 2021 г. |
35Наблюдать | CVE-2017-6081Эксплойта нет | A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1.zammad · zammad · CWE-352 | Высокая8,8 | — | 0,6 % | 13 мар. 2017 г. |
35Наблюдать | CVE-2025-32359Эксплойта нет | In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security.zammad · zammad · CWE-602 | Высокая8,8 | — | 0,3 % | 5 апр. 2025 г. |
34Наблюдать | CVE-2026-34723Эксплойта нет | Zammad has incorrect access control in getting_started_controllerzammad · zammad · CWE-284 | Высокая8,7 | — | 0,5 % | 8 апр. 2026 г. |
34Наблюдать | CVE-2024-33666Эксплойта нет | An issue was discovered in Zammad before 6.3.0.zammad · zammad · CWE-284 | Высокая8,6 | — | 0,5 % | 25 апр. 2024 г. |
34Наблюдать | CVE-2026-34724Proof of concept | Zammad has a server-side template injection leading to RCE via AI Agentzammad · zammad · CWE-94 | Высокая8,7 | — | 0,5 % | 8 апр. 2026 г. |
33Наблюдать | CVE-2026-34719Эксплойта нет | Zammad has a Server-side request forgery (SSRF) via webhookszammad · zammad · CWE-918 | Высокая8,3 | — | 0,3 % | 8 апр. 2026 г. |
32Наблюдать | CVE-2021-43145Эксплойта нет | With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.zammad · zammad | Высокая8,1 | — | 1,0 % | 4 февр. 2022 г. |
32Наблюдать | CVE-2025-32360Эксплойта нет | In Zammad 6.4.x before 6.4.2, there is information exposure.zammad · zammad · CWE-402 | Высокая8,1 | — | 0,2 % | 5 апр. 2025 г. |
30Наблюдать | CVE-2020-10096Эксплойта нет | An issue was discovered in Zammad 3.0 through 3.2.zammad · zammad · CWE-200 | Высокая7,5 | — | 1,1 % | 4 мар. 2020 г. |
30Наблюдать | CVE-2021-35299Эксплойта нет | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration prozammad · zammad · CWE-532 | Высокая7,5 | — | 1,1 % | 28 июн. 2021 г. |
30Наблюдать | CVE-2021-42089Эксплойта нет | An issue was discovered in Zammad before 4.1.1.zammad · zammad · CWE-200 | Высокая7,5 | — | 1,1 % | 7 окт. 2021 г. |
30Наблюдать | CVE-2020-10101Эксплойта нет | An issue was discovered in Zammad 3.0 through 3.2.zammad · zammad · CWE-20 | Высокая7,5 | — | 1,1 % | 4 мар. 2020 г. |
30Наблюдать | CVE-2020-26032Эксплойта нет | An SSRF issue was discovered in Zammad before 3.4.1.zammad · zammad · CWE-918 | Высокая7,5 | — | 1,1 % | 28 дек. 2020 г. |
30Наблюдать | CVE-2022-29701Эксплойта нет | A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests forzammad · zammad · CWE-770 | Высокая7,5 | — | 1,0 % | 26 апр. 2022 г. |
- CVE-2021-4209040В плане
An issue was discovered in Zammad before 4.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zammad · zammad7 окт. 2021 г.
- CVE-2021-4209440В плане
An issue was discovered in Zammad before 4.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zammad · zammad7 окт. 2021 г.
- CVE-2017-561939Наблюдать
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zammad · zammad13 мар. 2017 г.
- CVE-2020-2603039Наблюдать
An issue was discovered in Zammad before 3.4.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zammad · zammad28 дек. 2020 г.
- CVE-2022-4802139Наблюдать
A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zammad · zammad2 февр. 2023 г.
- CVE-2022-3549039Наблюдать
Zammad 5.2.0 is vulnerable to privilege escalation.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zammad · zammad8 авг. 2022 г.
- CVE-2017-608039Наблюдать
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involvi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zammad · zammad13 мар. 2017 г.
- CVE-2022-2733236Наблюдать
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %zammad · zammad26 апр. 2022 г.
- CVE-2021-4209136Наблюдать
An issue was discovered in Zammad before 4.1.1.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %zammad · zammad7 окт. 2021 г.
- CVE-2024-3366836Наблюдать
An issue was discovered in Zammad before 6.3.0.
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %zammad · zammad25 апр. 2024 г.
- CVE-2021-4208635Наблюдать
An issue was discovered in Zammad before 4.1.1.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %zammad · zammad7 окт. 2021 г.
- CVE-2017-608135Наблюдать
A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %zammad · zammad13 мар. 2017 г.
- CVE-2025-3235935Наблюдать
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %zammad · zammad5 апр. 2025 г.
- CVE-2026-3472334Наблюдать
Zammad has incorrect access control in getting_started_controller
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %zammad · zammad8 апр. 2026 г.
- CVE-2024-3366634Наблюдать
An issue was discovered in Zammad before 6.3.0.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %zammad · zammad25 апр. 2024 г.
- CVE-2026-3472434Наблюдать
Zammad has a server-side template injection leading to RCE via AI Agent
ВысокаяCVSS 8,7Proof of conceptEPSS 0 %zammad · zammad8 апр. 2026 г.
- CVE-2026-3471933Наблюдать
Zammad has a Server-side request forgery (SSRF) via webhooks
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %zammad · zammad8 апр. 2026 г.
- CVE-2021-4314532Наблюдать
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %zammad · zammad4 февр. 2022 г.
- CVE-2025-3236032Наблюдать
In Zammad 6.4.x before 6.4.2, there is information exposure.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %zammad · zammad5 апр. 2025 г.
- CVE-2020-1009630Наблюдать
An issue was discovered in Zammad 3.0 through 3.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zammad · zammad4 мар. 2020 г.
- CVE-2021-3529930Наблюдать
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration pro
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zammad · zammad28 июн. 2021 г.
- CVE-2021-4208930Наблюдать
An issue was discovered in Zammad before 4.1.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zammad · zammad7 окт. 2021 г.
- CVE-2020-1010130Наблюдать
An issue was discovered in Zammad 3.0 through 3.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zammad · zammad4 мар. 2020 г.
- CVE-2020-2603230Наблюдать
An SSRF issue was discovered in Zammad before 3.4.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zammad · zammad28 дек. 2020 г.
- CVE-2022-2970130Наблюдать
A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zammad · zammad26 апр. 2022 г.