synacor kayıtları
synacor üreticisine ait 94 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 18 · %19,1
- Silahlaştırılmış
- 20 · %21,3
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 110 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')41
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-611 Improper Restriction of XML External Entity Reference4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
94 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2019-9670Silahlaştırılmış | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, assynacor · zimbra collaboration suite · CWE-611 | Kritik9,8 | KEV | %100,0 | 29 May 2019 |
99Hemen | CVE-2024-45519Silahlaştırılmış | The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.synacor · zimbra collaboration suite · CWE-78 | Kritik9,8 | KEV | %99,9 | 2 Eki 2024 |
98Hemen | CVE-2022-41352Silahlaştırılmış | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.synacor · zimbra collaboration suite · CWE-22 | Kritik9,8 | KEV | %95,5 | 25 Eyl 2022 |
97Hemen | CVE-2022-37042Silahlaştırılmış | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.synacor · zimbra collaboration suite · CWE-22 | Kritik9,8 | KEV | %91,9 | 12 Ağu 2022 |
94Hemen | CVE-2020-7796Silahlaştırılmış | Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.synacor · zimbra collaboration suite · CWE-918 | Kritik9,8 | KEV | %84,4 | 18 Şub 2020 |
89Hemen | CVE-2023-34192Silahlaştırılmış | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scrsynacor · zimbra collaboration suite · CWE-79 | Kritik9,0 | KEV | %77,3 | 6 Tem 2023 |
88Hemen | CVE-2022-27925Silahlaştırılmış | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.synacor · zimbra collaboration suite · CWE-22 | Yüksek7,2 | KEV | %98,7 | 20 Nis 2022 |
86Hemen | CVE-2022-27924Silahlaştırılmış | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instasynacor · zimbra collaboration suite · CWE-74 | Yüksek7,5 | KEV | %85,4 | 20 Nis 2022 |
84Hemen | CVE-2019-9621Silahlaştırılmış | Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3synacor · zimbra collaboration suite · CWE-918 | Yüksek7,5 | KEV | %81,0 | 30 Nis 2019 |
80Hemen | CVE-2025-68645Silahlaştırılmış | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper synacor · zimbra collaboration suite · CWE-98 | Yüksek8,8 | KEV | %48,9 | 22 Ara 2025 |
69Bu hafta | CVE-2023-37580Silahlaştırılmış | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.synacor · zimbra collaboration suite · CWE-79 | Orta6,1 | KEV | %49,1 | 31 Tem 2023 |
69Bu hafta | CVE-2026-73570Silahlaştırılmış | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installedsynacor · zimbra collaboration suite · CWE-78 | Yüksek8,9 | KEV | %11,7 | 13 Ağu 2026 |
63Bu hafta | CVE-2022-24682Silahlaştırılmış | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wsynacor · zimbra collaboration suite · CWE-116 | Orta6,1 | KEV | %30,9 | 9 Şub 2022 |
63Bu hafta | CVE-2018-6882Silahlaştırılmış | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 synacor · zimbra collaboration suite · CWE-79 | Orta6,1 | KEV | %29,8 | 27 Mar 2018 |
60Bu hafta | CVE-2025-66376Silahlaştırılmış | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import dsynacor · zimbra collaboration suite · CWE-79 | Orta6,1 | KEV | %19,6 | 5 Oca 2026 |
59Planlayın | CVE-2022-27926Silahlaştırılmış | A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allosynacor · zimbra collaboration suite · CWE-79 | Orta6,1 | KEV | %17,6 | 20 Nis 2022 |
55Planlayın | CVE-2025-48700Silahlaştırılmış | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1.synacor · zimbra collaboration suite · CWE-79 | Orta6,1 | KEV | %1,7 | 23 Haz 2025 |
52Planlayın | CVE-2025-27915Silahlaştırılmış | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1.synacor · zimbra collaboration suite · CWE-79 | Orta5,4 | KEV | %4,0 | 12 Mar 2025 |
46Planlayın | CVE-2013-7091Silahlaştırılmış | Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 synacor · zimbra collaboration suite · CWE-22 | Orta5,0 | — | %86,3 | 13 Ara 2013 |
46Planlayın | CVE-2025-25064Kavram kanıtı | SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 dsynacor · zimbra collaboration suite · CWE-89 | Yüksek8,8 | — | %36,7 | 3 Şub 2025 |
42Planlayın | CVE-2024-50599İstismar yok | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the wesynacor · zimbra collaboration suite · CWE-79 | Orta6,1 | — | %61,4 | 7 Kas 2024 |
40Planlayın | CVE-2019-6980İstismar yok | Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.synacor · zimbra collaboration suite · CWE-502 | Kritik9,8 | — | %3,8 | 29 May 2019 |
40Planlayın | CVE-2017-6821İstismar yok | Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknosynacor · zimbra collaboration suite · CWE-22 | Kritik9,8 | — | %3,8 | 23 May 2017 |
40Planlayın | CVE-2016-9924İstismar yok | Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.synacor · zimbra collaboration suite · CWE-611 | Kritik9,8 | — | %2,9 | 29 Mar 2017 |
40Planlayın | CVE-2017-6813İstismar yok | A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested opesynacor · zimbra collaboration suite | Kritik9,8 | — | %2,6 | 23 May 2017 |
- CVE-2019-967099Hemen
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100synacor · zimbra collaboration suite29 May 2019
- CVE-2024-4551999Hemen
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100synacor · zimbra collaboration suite2 Eki 2024
- CVE-2022-4135298Hemen
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95synacor · zimbra collaboration suite25 Eyl 2022
- CVE-2022-3704297Hemen
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92synacor · zimbra collaboration suite12 Ağu 2022
- CVE-2020-779694Hemen
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84synacor · zimbra collaboration suite18 Şub 2020
- CVE-2023-3419289Hemen
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scr
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %77synacor · zimbra collaboration suite6 Tem 2023
- CVE-2022-2792588Hemen
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %99synacor · zimbra collaboration suite20 Nis 2022
- CVE-2022-2792486Hemen
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted insta
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %85synacor · zimbra collaboration suite20 Nis 2022
- CVE-2019-962184Hemen
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %81synacor · zimbra collaboration suite30 Nis 2019
- CVE-2025-6864580Hemen
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %49synacor · zimbra collaboration suite22 Ara 2025
- CVE-2023-3758069Bu hafta
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %49synacor · zimbra collaboration suite31 Tem 2023
- CVE-2026-7357069Bu hafta
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed
YüksekCVSS 8,9KEVSilahlaştırılmışEPSS %12synacor · zimbra collaboration suite13 Ağu 2026
- CVE-2022-2468263Bu hafta
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the w
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %31synacor · zimbra collaboration suite9 Şub 2022
- CVE-2018-688263Bu hafta
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %30synacor · zimbra collaboration suite27 Mar 2018
- CVE-2025-6637660Bu hafta
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import d
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %20synacor · zimbra collaboration suite5 Oca 2026
- CVE-2022-2792659Planlayın
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allo
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %18synacor · zimbra collaboration suite20 Nis 2022
- CVE-2025-4870055Planlayın
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %2synacor · zimbra collaboration suite23 Haz 2025
- CVE-2025-2791552Planlayın
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1.
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %4synacor · zimbra collaboration suite12 Mar 2025
- CVE-2013-709146Planlayın
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2
OrtaCVSS 5,0SilahlaştırılmışEPSS %86synacor · zimbra collaboration suite13 Ara 2013
- CVE-2025-2506446Planlayın
SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 d
YüksekCVSS 8,8Kavram kanıtıEPSS %37synacor · zimbra collaboration suite3 Şub 2025
- CVE-2024-5059942Planlayın
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the we
OrtaCVSS 6,1İstismar yokEPSS %61synacor · zimbra collaboration suite7 Kas 2024
- CVE-2019-698040Planlayın
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
KritikCVSS 9,8İstismar yokEPSS %4synacor · zimbra collaboration suite29 May 2019
- CVE-2017-682140Planlayın
Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unkno
KritikCVSS 9,8İstismar yokEPSS %4synacor · zimbra collaboration suite23 May 2017
- CVE-2016-992440Planlayın
Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
KritikCVSS 9,8İstismar yokEPSS %3synacor · zimbra collaboration suite29 Mar 2017
- CVE-2017-681340Planlayın
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested ope
KritikCVSS 9,8İstismar yokEPSS %3synacor · zimbra collaboration suite23 May 2017