Перейти к содержимому
Noroxi

Записи Synacor

94 опубликованных записей вендора synacor.

Профиль для исследователя

Попали в KEV
18 · 19,1 %
С эксплойтом
20 · 21,3 %
Pre-auth RCE
9
С записью об исправлении
0 %
Медиана: публикация → KEV
110 дн.

Все записи

94 записей
  • CVE-2019-9670
    99Срочно

    mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    synacor · zimbra collaboration suite29 мая 2019 г.

  • CVE-2024-45519
    99Срочно

    The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    synacor · zimbra collaboration suite2 окт. 2024 г.

  • CVE-2022-41352
    98Срочно

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %

    synacor · zimbra collaboration suite25 сент. 2022 г.

  • CVE-2022-37042
    97Срочно

    Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %

    synacor · zimbra collaboration suite12 авг. 2022 г.

  • CVE-2020-7796
    94Срочно

    Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %

    synacor · zimbra collaboration suite18 февр. 2020 г.

  • CVE-2023-34192
    89Срочно

    Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scr

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 77 %

    synacor · zimbra collaboration suite6 июл. 2023 г.

  • CVE-2022-27925
    88Срочно

    Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 99 %

    synacor · zimbra collaboration suite20 апр. 2022 г.

  • CVE-2022-27924
    86Срочно

    Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted insta

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 85 %

    synacor · zimbra collaboration suite20 апр. 2022 г.

  • CVE-2019-9621
    84Срочно

    Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 81 %

    synacor · zimbra collaboration suite30 апр. 2019 г.

  • CVE-2025-68645
    80Срочно

    A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 49 %

    synacor · zimbra collaboration suite22 дек. 2025 г.

  • CVE-2023-37580
    69На этой неделе

    Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 49 %

    synacor · zimbra collaboration suite31 июл. 2023 г.

  • CVE-2026-73570
    69На этой неделе

    A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed

    ВысокаяCVSS 8,9KEVГотовый эксплойтEPSS 12 %

    synacor · zimbra collaboration suite13 авг. 2026 г.

  • CVE-2022-24682
    63На этой неделе

    An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the w

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 31 %

    synacor · zimbra collaboration suite9 февр. 2022 г.

  • CVE-2018-6882
    63На этой неделе

    Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 30 %

    synacor · zimbra collaboration suite27 мар. 2018 г.

  • CVE-2025-66376
    60На этой неделе

    Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import d

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 20 %

    synacor · zimbra collaboration suite5 янв. 2026 г.

  • CVE-2022-27926
    59В плане

    A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allo

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 18 %

    synacor · zimbra collaboration suite20 апр. 2022 г.

  • CVE-2025-48700
    55В плане

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1.

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 2 %

    synacor · zimbra collaboration suite23 июн. 2025 г.

  • CVE-2025-27915
    52В плане

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1.

    СредняяCVSS 5,4KEVГотовый эксплойтEPSS 4 %

    synacor · zimbra collaboration suite12 мар. 2025 г.

  • CVE-2013-7091
    46В плане

    Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2

    СредняяCVSS 5,0Готовый эксплойтEPSS 86 %

    synacor · zimbra collaboration suite13 дек. 2013 г.

  • CVE-2025-25064
    46В плане

    SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 d

    ВысокаяCVSS 8,8Proof of conceptEPSS 37 %

    synacor · zimbra collaboration suite3 февр. 2025 г.

  • CVE-2024-50599
    42В плане

    A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the we

    СредняяCVSS 6,1Эксплойта нетEPSS 61 %

    synacor · zimbra collaboration suite7 нояб. 2024 г.

  • CVE-2019-6980
    40В плане

    Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    synacor · zimbra collaboration suite29 мая 2019 г.

  • CVE-2017-6821
    40В плане

    Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unkno

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    synacor · zimbra collaboration suite23 мая 2017 г.

  • CVE-2016-9924
    40В плане

    Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    synacor · zimbra collaboration suite29 мар. 2017 г.

  • CVE-2017-6813
    40В плане

    A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested ope

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    synacor · zimbra collaboration suite23 мая 2017 г.