Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-66376 KEVEPSS 22% Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives… Zimbra Collaboration Suite 10.0.18 / 10.1.13+ Fix from $1,6002026-01-05 HIGH 8.8 CVE-2025-68645 KEVEPSS 34% A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling … Zimbra Collaboration Suite 10.0.18 / 10.1.13+ Fix from $1,9502025-12-22 MEDIUM 6.1 CVE-2025-48700 KEV An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Clas… Zimbra Collaboration Suite 10.0.12 / 10.1.4+ Fix from $1,6002025-06-23 MEDIUM 5.4 CVE-2025-27915 KEV An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic … Zimbra Collaboration Suite 10.0.13 / 10.1.5+ Fix from $1,6002025-03-12 CRITICAL 9.8 CVE-2024-45519 KEVEPSS 100% The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 somet… Zimbra Collaboration Suite 8.8.15 / 10.0.9+ Fix from $2,3002024-10-02 MEDIUM 6.1 CVE-2023-37580 KEVEPSS 47% Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. Zimbra Collaboration Suite 8.8.15+ Fix from $1,6002023-07-31 CRITICAL 9.0 CVE-2023-34192 KEVEPSS 77% Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to th… Zimbra Collaboration Suite Mitigation only Fix from $2,3002023-07-06 CRITICAL 9.8 CVE-2022-41352 KEVEPSS 95% An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extr… Zimbra Collaboration Suite Patch available Fix from $2,3002022-09-26 CRITICAL 9.8 CVE-2022-37042 KEVEPSS 92% Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing aut… Zimbra Collaboration Suite Patch available Fix from $2,3002022-08-12 HIGH 7.5 CVE-2022-27924 KEVEPSS 85% Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. Thes… Zimbra Collaboration Suite Mitigation only Fix from $1,9502022-04-21 HIGH 7.2 CVE-2022-27925 KEVEPSS 99% Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated u… Zimbra Collaboration Suite Mitigation only Fix from $1,9502022-04-21 MEDIUM 6.1 CVE-2022-27926 KEVEPSS 18% A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauth… Zimbra Collaboration Suite Mitigation only Fix from $1,6002022-04-21 MEDIUM 6.1 CVE-2022-24682 KEVEPSS 31% An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild start… Zimbra Collaboration Suite 8.8.15+ Fix from $1,6002022-02-09 CRITICAL 9.8 CVE-2020-7796 KEVEPSS 84% Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. Zimbra Collaboration Suite 8.8.15+ Fix from $2,3002020-02-18 CRITICAL 9.8 CVE-2019-9670 KEVEPSS 100% mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstr… Zimbra Collaboration Suite 8.7.11+ Fix from $2,3002019-05-29 HIGH 7.5 CVE-2019-9621 KEVEPSS 81% Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows S… Zimbra Collaboration Suite 8.6.0 / 8.7.11+ Fix from $1,9502019-04-30 MEDIUM 6.1 CVE-2018-6882 KEVEPSS 25% Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 a… Zimbra Collaboration Suite 8.7.0+ Fix from $1,6002018-03-27