Записи Synacor
94 опубликованных записей вендора synacor.
Профиль для исследователя
- Попали в KEV
- 18 · 19,1 %
- С эксплойтом
- 20 · 21,3 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 110 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')41
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-611 Improper Restriction of XML External Entity Reference4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
94 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2019-9670Готовый эксплойт | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, assynacor · zimbra collaboration suite · CWE-611 | Критическая9,8 | KEV | 100,0 % | 29 мая 2019 г. |
99Срочно | CVE-2024-45519Готовый эксплойт | The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.synacor · zimbra collaboration suite · CWE-78 | Критическая9,8 | KEV | 99,9 % | 2 окт. 2024 г. |
98Срочно | CVE-2022-41352Готовый эксплойт | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.synacor · zimbra collaboration suite · CWE-22 | Критическая9,8 | KEV | 95,5 % | 25 сент. 2022 г. |
97Срочно | CVE-2022-37042Готовый эксплойт | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.synacor · zimbra collaboration suite · CWE-22 | Критическая9,8 | KEV | 91,9 % | 12 авг. 2022 г. |
94Срочно | CVE-2020-7796Готовый эксплойт | Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.synacor · zimbra collaboration suite · CWE-918 | Критическая9,8 | KEV | 84,4 % | 18 февр. 2020 г. |
89Срочно | CVE-2023-34192Готовый эксплойт | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scrsynacor · zimbra collaboration suite · CWE-79 | Критическая9,0 | KEV | 77,3 % | 6 июл. 2023 г. |
88Срочно | CVE-2022-27925Готовый эксплойт | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.synacor · zimbra collaboration suite · CWE-22 | Высокая7,2 | KEV | 98,7 % | 20 апр. 2022 г. |
86Срочно | CVE-2022-27924Готовый эксплойт | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instasynacor · zimbra collaboration suite · CWE-74 | Высокая7,5 | KEV | 85,4 % | 20 апр. 2022 г. |
84Срочно | CVE-2019-9621Готовый эксплойт | Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3synacor · zimbra collaboration suite · CWE-918 | Высокая7,5 | KEV | 81,0 % | 30 апр. 2019 г. |
80Срочно | CVE-2025-68645Готовый эксплойт | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper synacor · zimbra collaboration suite · CWE-98 | Высокая8,8 | KEV | 48,9 % | 22 дек. 2025 г. |
69На этой неделе | CVE-2023-37580Готовый эксплойт | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.synacor · zimbra collaboration suite · CWE-79 | Средняя6,1 | KEV | 49,1 % | 31 июл. 2023 г. |
69На этой неделе | CVE-2026-73570Готовый эксплойт | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installedsynacor · zimbra collaboration suite · CWE-78 | Высокая8,9 | KEV | 11,7 % | 13 авг. 2026 г. |
63На этой неделе | CVE-2022-24682Готовый эксплойт | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wsynacor · zimbra collaboration suite · CWE-116 | Средняя6,1 | KEV | 30,9 % | 9 февр. 2022 г. |
63На этой неделе | CVE-2018-6882Готовый эксплойт | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 synacor · zimbra collaboration suite · CWE-79 | Средняя6,1 | KEV | 29,8 % | 27 мар. 2018 г. |
60На этой неделе | CVE-2025-66376Готовый эксплойт | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import dsynacor · zimbra collaboration suite · CWE-79 | Средняя6,1 | KEV | 19,6 % | 5 янв. 2026 г. |
59В плане | CVE-2022-27926Готовый эксплойт | A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allosynacor · zimbra collaboration suite · CWE-79 | Средняя6,1 | KEV | 17,6 % | 20 апр. 2022 г. |
55В плане | CVE-2025-48700Готовый эксплойт | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1.synacor · zimbra collaboration suite · CWE-79 | Средняя6,1 | KEV | 1,7 % | 23 июн. 2025 г. |
52В плане | CVE-2025-27915Готовый эксплойт | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1.synacor · zimbra collaboration suite · CWE-79 | Средняя5,4 | KEV | 4,0 % | 12 мар. 2025 г. |
46В плане | CVE-2013-7091Готовый эксплойт | Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 synacor · zimbra collaboration suite · CWE-22 | Средняя5,0 | — | 86,3 % | 13 дек. 2013 г. |
46В плане | CVE-2025-25064Proof of concept | SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 dsynacor · zimbra collaboration suite · CWE-89 | Высокая8,8 | — | 36,7 % | 3 февр. 2025 г. |
42В плане | CVE-2024-50599Эксплойта нет | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the wesynacor · zimbra collaboration suite · CWE-79 | Средняя6,1 | — | 61,4 % | 7 нояб. 2024 г. |
40В плане | CVE-2019-6980Эксплойта нет | Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.synacor · zimbra collaboration suite · CWE-502 | Критическая9,8 | — | 3,8 % | 29 мая 2019 г. |
40В плане | CVE-2017-6821Эксплойта нет | Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknosynacor · zimbra collaboration suite · CWE-22 | Критическая9,8 | — | 3,8 % | 23 мая 2017 г. |
40В плане | CVE-2016-9924Эксплойта нет | Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.synacor · zimbra collaboration suite · CWE-611 | Критическая9,8 | — | 2,9 % | 29 мар. 2017 г. |
40В плане | CVE-2017-6813Эксплойта нет | A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested opesynacor · zimbra collaboration suite | Критическая9,8 | — | 2,6 % | 23 мая 2017 г. |
- CVE-2019-967099Срочно
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %synacor · zimbra collaboration suite29 мая 2019 г.
- CVE-2024-4551999Срочно
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %synacor · zimbra collaboration suite2 окт. 2024 г.
- CVE-2022-4135298Срочно
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %synacor · zimbra collaboration suite25 сент. 2022 г.
- CVE-2022-3704297Срочно
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %synacor · zimbra collaboration suite12 авг. 2022 г.
- CVE-2020-779694Срочно
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %synacor · zimbra collaboration suite18 февр. 2020 г.
- CVE-2023-3419289Срочно
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scr
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 77 %synacor · zimbra collaboration suite6 июл. 2023 г.
- CVE-2022-2792588Срочно
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 99 %synacor · zimbra collaboration suite20 апр. 2022 г.
- CVE-2022-2792486Срочно
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted insta
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 85 %synacor · zimbra collaboration suite20 апр. 2022 г.
- CVE-2019-962184Срочно
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 81 %synacor · zimbra collaboration suite30 апр. 2019 г.
- CVE-2025-6864580Срочно
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 49 %synacor · zimbra collaboration suite22 дек. 2025 г.
- CVE-2023-3758069На этой неделе
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 49 %synacor · zimbra collaboration suite31 июл. 2023 г.
- CVE-2026-7357069На этой неделе
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed
ВысокаяCVSS 8,9KEVГотовый эксплойтEPSS 12 %synacor · zimbra collaboration suite13 авг. 2026 г.
- CVE-2022-2468263На этой неделе
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the w
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 31 %synacor · zimbra collaboration suite9 февр. 2022 г.
- CVE-2018-688263На этой неделе
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 30 %synacor · zimbra collaboration suite27 мар. 2018 г.
- CVE-2025-6637660На этой неделе
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import d
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 20 %synacor · zimbra collaboration suite5 янв. 2026 г.
- CVE-2022-2792659В плане
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allo
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 18 %synacor · zimbra collaboration suite20 апр. 2022 г.
- CVE-2025-4870055В плане
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1.
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 2 %synacor · zimbra collaboration suite23 июн. 2025 г.
- CVE-2025-2791552В плане
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1.
СредняяCVSS 5,4KEVГотовый эксплойтEPSS 4 %synacor · zimbra collaboration suite12 мар. 2025 г.
- CVE-2013-709146В плане
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2
СредняяCVSS 5,0Готовый эксплойтEPSS 86 %synacor · zimbra collaboration suite13 дек. 2013 г.
- CVE-2025-2506446В плане
SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 d
ВысокаяCVSS 8,8Proof of conceptEPSS 37 %synacor · zimbra collaboration suite3 февр. 2025 г.
- CVE-2024-5059942В плане
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the we
СредняяCVSS 6,1Эксплойта нетEPSS 61 %synacor · zimbra collaboration suite7 нояб. 2024 г.
- CVE-2019-698040В плане
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %synacor · zimbra collaboration suite29 мая 2019 г.
- CVE-2017-682140В плане
Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unkno
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %synacor · zimbra collaboration suite23 мая 2017 г.
- CVE-2016-992440В плане
Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %synacor · zimbra collaboration suite29 мар. 2017 г.
- CVE-2017-681340В плане
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested ope
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %synacor · zimbra collaboration suite23 мая 2017 г.