Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2020-18985
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their c…
Zimbra Collaboration Suite
Mitigation only
MEDIUM 6.1
CVE-2020-13653
An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable…
Zimbra Collaboration Suite
8.8.15+
HIGH 8.0
CVE-2020-12846
Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is potential abuse of /service/uplo…
Zimbra Collaboration Suite
8.8.15+
CRITICAL 9.8
CVE-2020-7796 KEVEPSS 84%
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
Zimbra Collaboration Suite
8.8.15+
MEDIUM 5.3
CVE-2020-8633
An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calendar in Outlook, the calendar s…
Zimbra Collaboration Suite
8.8.15+
CRITICAL 9.8
CVE-2014-8563
Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.
Zimbra Collaboration Server
8.0.9+
MEDIUM 6.1
CVE-2014-5500
Synacor Zimbra Collaboration before 8.0.8 has XSS.
Zimbra Collaboration Server
8.0.8+
MEDIUM 5.4
CVE-2015-2249
Zimbra Collaboration before 8.6.0 patch5 has XSS.
Zimbra Collaboration Server
after 8.5.1
MEDIUM 5.4
CVE-2019-11318
Zimbra Collaboration before 8.8.12 Patch 1 has persistent XSS.
Zimbra Collaboration Server
after 8.8.12
MEDIUM 6.1
CVE-2015-2230
Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console.
Zimbra Collaboration Server
8.7.0+
MEDIUM 6.1
CVE-2015-7609
Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra.
Zimbra Collaboration Suite
No fix yet
MEDIUM 6.1
CVE-2018-14425
There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8…
Zimbra Collaboration Suite
8.8.8+
MEDIUM 5.3
CVE-2018-15131
An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, a…
Zimbra Collaboration Suite
8.7.11 / 8.8.8+
CRITICAL 9.8
CVE-2018-20160
ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XX…
Zimbra Collaboration Suite
8.7.11 / 8.8.9+
CRITICAL 9.8
CVE-2019-6980
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
Zimbra Collaboration Suite
8.7.11 / 8.8.9+
CRITICAL 9.8
CVE-2019-9670 KEVEPSS 100%
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstr…
Zimbra Collaboration Suite
8.7.11+
MEDIUM 6.5
CVE-2019-6981
Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component.
Zimbra Collaboration Suite
8.7.11 / 8.8.9+
MEDIUM 6.1
CVE-2018-18631
mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 has Persistent XSS.
Zimbra Collaboration Suite
8.7.11 / 8.8.9+
MEDIUM 6.1
CVE-2018-14013EPSS 7%
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
Zimbra Collaboration Suite
8.7.11 / 8.8.9+
HIGH 7.5
CVE-2019-9621 KEVEPSS 81%
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows S…
Zimbra Collaboration Suite
8.6.0 / 8.7.11+
MEDIUM 5.3
CVE-2018-17938
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
Zimbra Collaboration Suite
8.8.10+
HIGH 8.8
CVE-2015-7610
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 …
Zimbra Collaboration Suite
after 8.8.8
MEDIUM 6.1
CVE-2018-10939
Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.
Zimbra Collaboration Suite
after 8.8.8
MEDIUM 6.5
CVE-2018-10951
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read acces…
Zimbra Collaboration Suite
8.8.8+
MEDIUM 5.3
CVE-2018-10949
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy bet…
Zimbra Collaboration Suite
8.8.8+
MEDIUM 5.3
CVE-2018-10950
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through V…
Zimbra Collaboration Suite
8.7.11 / 8.8.8+
MEDIUM 6.1
CVE-2018-6882 KEVEPSS 25%
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 a…
Zimbra Collaboration Suite
8.7.0+
MEDIUM 6.1
CVE-2017-17703
Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.
Zimbra Collaboration Suite
8.8.3+
MEDIUM 5.4
CVE-2017-8783
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.
Zimbra Collaboration Suite
8.7.10+
CRITICAL 9.8
CVE-2017-6813
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.
Zimbra Collaboration Suite
after 8.7.5