Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-26562 In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/s… Collaboration Mitigation only Fix from $1,6002024-02-13 HIGH 8.8 CVE-2023-34193 File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via… Collaboration Mitigation only Fix from $1,9502023-07-06 CRITICAL 9.8 CVE-2023-29381 An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the pa… Collaboration Mitigation only Fix from $2,3002023-07-06 CRITICAL 9.8 CVE-2023-29382 An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component. Collaboration Mitigation only Fix from $2,3002023-07-06 MEDIUM 6.1 CVE-2023-24030 An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an … Collaboration Mitigation only Fix from $1,6002023-06-15 MEDIUM 6.1 CVE-2023-24031 An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 8.8.15. XSS can occur, via one of attributes of the webmail /h/ endpoint, to execute ar… Collaboration Mitigation only Fix from $1,6002023-06-15 MEDIUM 6.1 CVE-2022-45911 An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the u… Collaboration Mitigation only Fix from $1,6002023-01-06 MEDIUM 6.1 CVE-2022-45913 An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via one of attributes in webmail URLs to execute arbitrary JavaScript code, … Collaboration Mitigation only Fix from $1,6002023-01-06 HIGH 7.2 CVE-2022-45912 An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admi… Collaboration Mitigation only Fix from $1,9502022-12-05 MEDIUM 6.1 CVE-2022-41348 An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, leading to information disclosu… Collaboration Mitigation only Fix from $1,6002022-10-12 MEDIUM 6.1 CVE-2022-41349 In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows exe… Collaboration Mitigation only Fix from $1,6002022-10-12 MEDIUM 6.1 CVE-2022-41350 In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. T… Collaboration Mitigation only Fix from $1,6002022-10-12 MEDIUM 6.1 CVE-2022-41351 In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing … Collaboration Mitigation only Fix from $1,6002022-10-12 MEDIUM 6.1 CVE-2020-11737 A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invit… Zimbra Mitigation only Fix from $1,6002020-05-05