Zimbra kayıtları
zimbra üreticisine ait 59 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,7
- Silahlaştırılmış
- 2 · %3,4
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %8,5
- Yayından KEV’e ortanca
- 280 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')33
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-862 Missing Authorization2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
59 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2024-27443Silahlaştırılmış | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.zimbra · collaboration · CWE-79 | Orta6,1 | KEV | %23,6 | 12 Ağu 2024 |
41Planlayın | CVE-2024-45518İstismar yok | An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Pzimbra · collaboration · CWE-918 | Yüksek8,8 | — | %20,7 | 22 Eki 2024 |
41Planlayın | CVE-2013-7217İstismar yok | Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vzimbra · collaboration server | Kritik10,0 | — | %3,0 | 26 Ara 2013 |
40Planlayın | CVE-2021-35209İstismar yok | An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9zimbra · collaboration · CWE-918 | Kritik9,8 | — | %3,0 | 2 Tem 2021 |
40Planlayın | CVE-2022-32294İstismar yok | Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command).zimbra · collaboration · CWE-863 | Kritik9,8 | — | %2,5 | 10 Tem 2022 |
39İzleyin | CVE-2023-29381İstismar yok | An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information vzimbra · collaboration · CWE-863 | Kritik9,8 | — | %1,0 | 6 Tem 2023 |
39İzleyin | CVE-2023-29382İstismar yok | An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.zimbra · collaboration · CWE-94 | Kritik9,8 | — | %1,0 | 6 Tem 2023 |
36İzleyin | CVE-2015-6541Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remotzimbra · zimbra collaboration server · CWE-352 | Yüksek8,8 | — | %3,0 | 8 Nis 2016 |
35İzleyin | CVE-2015-7610İstismar yok | Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x beforzimbra · zimbra collaboration suite · CWE-352 | Yüksek8,8 | — | %1,2 | 30 May 2018 |
35İzleyin | CVE-2023-34193İstismar yok | File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive informzimbra · collaboration · CWE-434 | Yüksek8,8 | — | %1,2 | 6 Tem 2023 |
32İzleyin | CVE-2022-37393Silahlaştırılmış | Zimbra zmslapd arbitrary module loadzimbra · collaboration · CWE-284 | Yüksek7,8 | — | %1,7 | 16 Ağu 2022 |
31İzleyin | CVE-2023-24032İstismar yok | In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commzimbra · collaboration · CWE-77 | Yüksek7,8 | — | %1,0 | 15 Haz 2023 |
31İzleyin | CVE-2022-41347İstismar yok | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15).zimbra · collaboration | Yüksek7,8 | — | %0,4 | 25 Eyl 2022 |
31İzleyin | CVE-2024-27442İstismar yok | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.zimbra · collaboration · CWE-755 | Yüksek7,8 | — | %0,3 | 12 Ağu 2024 |
30İzleyin | CVE-2023-41106İstismar yok | An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3.zimbra · collaboration | Yüksek7,5 | — | %1,0 | 7 Ara 2023 |
30İzleyin | CVE-2023-38750İstismar yok | In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be expzimbra · zimbra | Yüksek7,5 | — | %0,9 | 31 Tem 2023 |
30İzleyin | CVE-2022-37041İstismar yok | An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0.zimbra · collaboration · CWE-918 | Yüksek7,5 | — | %0,7 | 12 Ağu 2022 |
30İzleyin | CVE-2024-33535İstismar yok | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.zimbra · collaboration · CWE-22 | Yüksek7,5 | — | %0,6 | 12 Ağu 2024 |
28İzleyin | CVE-2022-45912İstismar yok | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.zimbra · collaboration · CWE-434 | Yüksek7,2 | — | %1,2 | 5 Ara 2022 |
26İzleyin | CVE-2020-35123İstismar yok | In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer stzimbra · collaboration · CWE-611 | Orta6,5 | — | %1,5 | 17 Ara 2020 |
26İzleyin | CVE-2020-10194İstismar yok | cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account.zimbra · zm-mailbox · CWE-862 | Orta6,5 | — | %1,2 | 20 Mar 2020 |
26İzleyin | CVE-2023-26562İstismar yok | In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured fzimbra · collaboration · CWE-862 | Orta6,5 | — | %0,6 | 13 Şub 2024 |
26İzleyin | CVE-2024-9665İstismar yok | Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerabilityzimbra · zimbra · CWE-352 | Orta6,5 | — | %0,5 | 22 Kas 2024 |
25İzleyin | CVE-2021-35207İstismar yok | An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16.zimbra · collaboration · CWE-79 | Orta6,1 | — | %3,3 | 2 Tem 2021 |
25İzleyin | CVE-2013-1938Kavram kanıtı | Zimbra 2013 has XSS in aspell.phpzimbra · zimbra · CWE-79 | Orta6,1 | — | %3,3 | 12 Şub 2020 |
- CVE-2024-2744361Bu hafta
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %24zimbra · collaboration12 Ağu 2024
- CVE-2024-4551841Planlayın
An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before P
YüksekCVSS 8,8İstismar yokEPSS %21zimbra · collaboration22 Eki 2024
- CVE-2013-721741Planlayın
Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified v
KritikCVSS 10,0İstismar yokEPSS %3zimbra · collaboration server26 Ara 2013
- CVE-2021-3520940Planlayın
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9
KritikCVSS 9,8İstismar yokEPSS %3zimbra · collaboration2 Tem 2021
- CVE-2022-3229440Planlayın
Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command).
KritikCVSS 9,8İstismar yokEPSS %3zimbra · collaboration10 Tem 2022
- CVE-2023-2938139İzleyin
An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information v
KritikCVSS 9,8İstismar yokEPSS %1zimbra · collaboration6 Tem 2023
- CVE-2023-2938239İzleyin
An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.
KritikCVSS 9,8İstismar yokEPSS %1zimbra · collaboration6 Tem 2023
- CVE-2015-654136İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remot
YüksekCVSS 8,8Kavram kanıtıEPSS %3zimbra · zimbra collaboration server8 Nis 2016
- CVE-2015-761035İzleyin
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x befor
YüksekCVSS 8,8İstismar yokEPSS %1zimbra · zimbra collaboration suite30 May 2018
- CVE-2023-3419335İzleyin
File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive inform
YüksekCVSS 8,8İstismar yokEPSS %1zimbra · collaboration6 Tem 2023
- CVE-2022-3739332İzleyin
Zimbra zmslapd arbitrary module load
YüksekCVSS 7,8SilahlaştırılmışEPSS %2zimbra · collaboration16 Ağu 2022
- CVE-2023-2403231İzleyin
In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute comm
YüksekCVSS 7,8İstismar yokEPSS %1zimbra · collaboration15 Haz 2023
- CVE-2022-4134731İzleyin
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15).
YüksekCVSS 7,8İstismar yokEPSS %0zimbra · collaboration25 Eyl 2022
- CVE-2024-2744231İzleyin
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.
YüksekCVSS 7,8İstismar yokEPSS %0zimbra · collaboration12 Ağu 2024
- CVE-2023-4110630İzleyin
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3.
YüksekCVSS 7,5İstismar yokEPSS %1zimbra · collaboration7 Ara 2023
- CVE-2023-3875030İzleyin
In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exp
YüksekCVSS 7,5İstismar yokEPSS %1zimbra · zimbra31 Tem 2023
- CVE-2022-3704130İzleyin
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0.
YüksekCVSS 7,5İstismar yokEPSS %1zimbra · collaboration12 Ağu 2022
- CVE-2024-3353530İzleyin
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.
YüksekCVSS 7,5İstismar yokEPSS %1zimbra · collaboration12 Ağu 2024
- CVE-2022-4591228İzleyin
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.
YüksekCVSS 7,2İstismar yokEPSS %1zimbra · collaboration5 Ara 2022
- CVE-2020-3512326İzleyin
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer st
OrtaCVSS 6,5İstismar yokEPSS %2zimbra · collaboration17 Ara 2020
- CVE-2020-1019426İzleyin
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account.
OrtaCVSS 6,5İstismar yokEPSS %1zimbra · zm-mailbox20 Mar 2020
- CVE-2023-2656226İzleyin
In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured f
OrtaCVSS 6,5İstismar yokEPSS %1zimbra · collaboration13 Şub 2024
- CVE-2024-966526İzleyin
Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0zimbra · zimbra22 Kas 2024
- CVE-2021-3520725İzleyin
An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16.
OrtaCVSS 6,1İstismar yokEPSS %3zimbra · collaboration2 Tem 2021
- CVE-2013-193825İzleyin
Zimbra 2013 has XSS in aspell.php
OrtaCVSS 6,1Kavram kanıtıEPSS %3zimbra · zimbra12 Şub 2020