ZeroHour

Vulnerabilities

123 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73573
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper valid

In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.

NVD description · AI analysis pending
6.5
group max
<1%
  • synacor zimbra collaboration suite
CVE-2026-73570
Unauthenticated OS Command Injection RCE in Synacor Zimbra Collaboration Suite

CVE-2026-73570 is an OS command injection vulnerability (CWE-78) in Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20, caused by improper sanitization of untrusted input during SNMP notification processing. It is triggered when the optional zimbra-snmp package is installed and SNMP notifications are enabled: an unauthenticated attacker sends specially crafted SMTP requests that the flawed notification path turns into execution of arbitrary operating system commands. Successful exploitation runs commands as the Zimbra user, giving attackers control of the mail server's service account with high confidentiality and integrity impact across the host. Only ZCS deployments running the optional SNMP component with notifications enabled are vulnerable; other Zimbra installs are not exposed to this specific flaw. The flaw is under active exploitation: CISA added it to the KEV catalog on 2026-08-21, Poland's CERT has warned of in-the-wild attacks, unpatched Zimbra servers are reported compromised, and two public proof-of-concept exploits exist.

Do: Upgrade to Zimbra Collaboration Suite 10.1.20 or later per vendor instructions; as an interim mitigation, disable SNMP notifications or remove the zimbra-snmp package on hosts that do not need it. Federal operators must satisfy the CISA KEV/BOD 26-04 requirement, and all administrators of internet-facing Zimbra servers should hunt for signs of compromise (unexpected processes or persistence under the zimbra user) since unpatched systems are already being exploited.

8.932% KEV PoC ×4
  • Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20 (when the optional zimbra-snmp package is installed and SNMP notifications are enabled)
large≈10,000-50,000 internet-exposed ZCS servers, with only the subset running zimbra-snmp with notifications enabled actually vulnerable
CVE-2026-33373
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1.

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state transitions. Specifically, tokens generated after operations such as enabling two-factor authentication or changing a password may lack CSRF enforcement. While such a token is active, authenticated SOAP requests that trigger token generation or state changes can be performed without CSRF validation. An attacker could exploit this by inducing a victim to submit crafted requests, potentially allowing sensitive account actions such as disabling two-factor authentication. The issue is mitigated by ensuring CSRF protection is consistently enforced for all issued authentication tokens.

NVD description · AI analysis pending
8.8<1%
  • synacor zimbra collaboration suite
CVE-2026-33154
dynaconf is a configuration management tool for Python.

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.

NVD description · AI analysis pending
8.1<1% PoC
  • dynaconf dynaconf
CVE-2026-33368
+4 in the same advisory: …33370 …33372 …33371 …33369
Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest).

Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails to properly sanitize user-supplied input, allowing an unauthenticated attacker to inject malicious JavaScript into a crafted URL. When a victim user accesses the link, the injected script executes in the context of the Zimbra webmail application, which could allow the attacker to perform actions on behalf of the victim.

NVD description · AI analysis pending
6.1
group max
<1%
  • synacor zimbra collaboration suite
CVE-2026-23528
Dask distributed is a distributed task scheduler for Dask.

Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to craft a URL which will result in code being executed by Jupyter due to a cross-side-scripting (XSS) bug in the Dask dashboard. It is possible for attackers to craft a phishing URL that assumes Jupyter Lab and Dask may be running on localhost and using default ports. If a user clicks on the malicious link it will open an error page in the Dask Dashboard via the Jupyter Lab proxy which will cause code to be executed by the default Jupyter Python kernel. This vulnerability is fixed in 2026.1.0.

NVD description · AI analysis pending
5.3<1%
  • anaconda dask
CVE-2025-66376
Stored Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI

Zimbra Collaboration Suite (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 is vulnerable to stored cross-site scripting through its Classic webmail interface. An attacker sends an HTML e-mail containing a Cascading Style Sheets (CSS) @import directive, and when a recipient opens that message in Classic UI, the injected content executes as script in the victim's browser session. Successful exploitation lets an attacker run arbitrary JavaScript in the Zimbra webmail context, potentially hijacking the session, reading mail, or acting as the user, consistent with the cross-scope impact reflected in the 6.1 CVSS score. Only deployments running the affected ZCS 10/10.1 versions with the Classic UI enabled are exposed; organizations on patched releases or not using Classic UI are not impacted. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-18, confirming exploitation in the wild, and recent reporting describes Zimbra flaws being used by Russian-aligned espionage actors against Western and Ukrainian targets.

Do: Upgrade ZCS to 10.0.18 or 10.1.13 (or later) following vendor instructions, as required by CISA's BOD 22-01 KEV guidance; federal agencies and critical infrastructure should prioritize this by the catalog deadline. Until patched, filter or sanitize HTML mail containing CSS @import directives and consider restricting or disabling the Classic UI. Check mailboxes and webmail access logs for suspicious HTML messages and unexplained session activity, which may indicate exploitation.

6.120% KEV
  • Synacor Zimbra Collaboration Suite (ZCS) 10 10.x before 10.0.18
  • Synacor Zimbra Collaboration Suite (ZCS) 10.1 10.1.x before 10.1.13
largetens of thousands of internet-exposed Zimbra servers (public internet scans typically surface on the order of 50,000+ Zimbra instances), affecting an estimated…
CVE-2025-68645
PHP Remote File Inclusion in Synacor Zimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion (RFI) flaw (CWE-98) reachable through its /h/rest endpoint. By sending crafted requests to /h/rest, a remote attacker can influence the application's internal request dispatching and cause the server to include arbitrary files from the WebRoot directory, potentially exposing sensitive file content or executing attacker-influenced file content reachable there. An attacker who abuses this flaw may gain information disclosure or further compromise of the ZCS server; the available data does not specify authentication requirements or confirm full remote code execution. Any organization running Zimbra Collaboration Suite, especially internet-facing ZCS email and collaboration servers, is potentially affected, though specific affected version ranges were not provided in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-01-22, indicating confirmed exploitation in the wild, and EPSS assigns a 49.4% probability of exploitation within 30 days (99th percentile); no public proof-of-concept is known.

Do: Apply the patched ZCS release per Synacor's/Zimbra's advisory (specific patched versions were not provided in the available data) and follow CISA KEV required actions, including applicable BOD 22-01 guidance for federal agencies. Review access logs for crafted or anomalous requests to /h/rest and restrict internet exposure of ZCS endpoints until the patch is deployed. Ransomware association is unknown, so treat exploitation activity as potentially preparatory to broader compromise.

8.849% KEV
  • Synacor Zimbra Collaboration Suite (ZCS)
largetens of thousands of internet-exposed ZCS servers (order of ~50,000)
CVE-2024-46060
Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory.

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.

NVD description · AI analysis pending
7.8<1% PoC
  • anaconda anaconda3
CVE-2025-48700
Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI

Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0, 10.0, and 10.1 contain a cross-site scripting (XSS) flaw in the Classic UI caused by insufficient sanitization of HTML email content, involving crafted tag structures and attribute values that use @import directives and other script injection vectors. An attacker triggers it simply by getting a user to view a crafted email message in the Classic UI, with no additional user interaction required. Successful exploitation executes arbitrary JavaScript within the victim's session, potentially exposing sensitive mailbox information or enabling unauthorized actions under the victim's identity. Any organization running the affected ZCS branches — particularly internet-facing mail servers whose users receive untrusted email — is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, confirming active exploitation in the wild; no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at about 1.7%.

Do: Upgrade ZCS to the latest patched builds of the affected 8.8.15/9.0/10.0/10.1 branches per Synacor/Zimbra's security advisory (no specific fixed version is listed here); federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use. Because the flaw is specific to the Classic UI, having users work in the Modern UI instead of the Classic UI reduces exposure until patching is complete. Review mail server and web client logs for users who viewed suspicious HTML-formatted messages as an indicator of targeting.

6.12% KEV
  • Synacor Zimbra Collaboration Suite (ZCS) Classic UI 8.8.15, 9.0, 10.0, and 10.1
largeon the order of tens of thousands of internet-exposed Zimbra servers
CVE-2025-32798
+3 in the same advisory: …32800 …32797 …32799
Conda-build contains commands and tools to build conda packages.

Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build recipe processing logic has been found to be vulnerable to arbitrary code execution due to unsafe evaluation of recipe selectors. Currently, conda-build uses the eval function to process embedded selectors in meta.yaml files. This approach evaluates user-defined expressions without proper sanitization, which allows arbitrary code to be executed during the build process. As a result, the integrity of the build environment is compromised, and unauthorized commands or file operations may be performed. The vulnerability stems from the inherent risk of using eval() on untrusted input in a context intended to control dynamic build configurations. By directly interpreting selector expressions, conda-build creates a potential execution pathway for malicious code, violating security assumptions. This issue has been patched in version 25.4.0.

NVD description · AI analysis pending
8.2
group max
<1% PoC
  • anaconda conda-build
CVE-2024-45516
An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47.

An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, including malformed tags with embedded JavaScript. The vulnerability is triggered when a user views a specially crafted email in the Classic UI, requiring no additional user interaction.

NVD description · AI analysis pending
6.1<1%
  • synacor zimbra collaboration suite
CVE-2025-32354
In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform unauthorized GraphQL operations, such as modifying contacts, changing account settings, and accessing sensitive user data when an authenticated user visits a malicious website.

NVD description · AI analysis pending
8.8<1%
  • synacor zimbra collaboration suite
CVE-2025-27915
Stored XSS in Zimbra Collaboration Suite Classic Web Client via Malicious ICS Files

CVE-2025-27915 is a stored cross-site scripting (XSS) flaw in the Classic Web Client of Synacor Zimbra Collaboration Suite (ZCS) 9.0, 10.0, and 10.1, caused by insufficient sanitization of HTML content in ICS calendar files. It is triggered when a user views an email message containing a malicious ICS entry, at which point embedded JavaScript executes in the victim's session via an ontoggle event handler inside a tag. A successful attacker can run arbitrary JavaScript in the victim's session and perform unauthorized actions on the account, notably creating email filters that silently redirect messages to attacker-controlled addresses, enabling data exfiltration. Any organization running the affected ZCS versions whose users read mail through the Classic Web Client is exposed, since delivery of a single crafted email can compromise a session. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-10-07, and public reporting describes active zero-day attacks, including targeting of the Brazilian military via malicious ICS files.

Do: Upgrade affected ZCS 9.0, 10.0, and 10.1 deployments to the latest patched builds per Zimbra's security advisory and apply any vendor-recommended mitigations (federal agencies must act per CISA KEV/BOD 22-01 requirements). Hunt for suspicious ICS-based emails and calendar entries, and review user mail filter rules for unauthorized forwarding or redirection to attacker-controlled addresses. Consider restricting or disabling Classic Web Client access until systems are patched.

5.44% KEV PoC
  • Synacor Zimbra Collaboration Suite (ZCS) 9.0, 10.0, and 10.1 (Classic Web Client)
large≈30,000–50,000 internet-exposed Zimbra servers; total deployments including internal-only instances likely higher
CVE-2025-25064
+1 in the same advisory: …25065
Authenticated SQL Injection in Zimbra Collaboration ZimbraSync Service

CVE-2025-25064 is a SQL injection flaw in the ZimbraSync Service SOAP endpoint of Zimbra Collaboration Suite, caused by insufficient sanitization of a user-supplied parameter. An authenticated attacker triggers it by sending a crafted SOAP request with malicious content in a specific parameter, allowing arbitrary SQL queries to be injected into the backend database. Successful exploitation can let the attacker retrieve email metadata from the database, with the high CVSS 8.8 score reflecting potentially serious confidentiality, integrity and availability impact. It affects Zimbra Collaboration 10.0.x prior to 10.0.12 and 10.1.x prior to 10.1.4, so any organization running those branches with the sync service exposed is in scope. As of the advisory date there is no public proof-of-concept, it is not listed in CISA KEV, but its EPSS of 36.7% (98th percentile) indicates an elevated likelihood of exploitation attempts within 30 days, and fixes were shipped in Zimbra's recent security release alongside patches for stored XSS and SSRF issues.

Do: Upgrade Zimbra Collaboration to 10.0.12 (for the 10.0.x branch) or 10.1.4 (for the 10.1.x branch), or later, applying the current security patch release which also fixes related stored XSS and SSRF issues. Because exploitation requires authentication, review for suspicious or compromised accounts and restrict exposure of the ZimbraSync Service SOAP endpoint until patched. Monitor vendor advisories for updates on exploitation activity given the elevated EPSS score.

8.8
group max
37%
  • Synacor Zimbra Collaboration Suite (ZimbraSync Service SOAP endpoint) 10.0.x before 10.0.12
  • Synacor Zimbra Collaboration Suite (ZimbraSync Service SOAP endpoint) 10.1.x before 10.1.4
largeon the order of tens of thousands of internet-exposed Zimbra servers, of which a substantial share run the affected 10.0.x/10.1.x branches (roughly 10k+…
CVE-2024-13236
The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insuffic

The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD description · AI analysis pending
6.5<1%
  • tainacan tainacan
CVE-2024-54663
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1.

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files in the WebRoot directory. Exploitation requires a valid auth token and involves crafting a malicious request targeting specific file paths.

NVD description · AI analysis pending
7.5<1%
  • synacor zimbra collaboration suite
CVE-2024-45514
+4 in the same advisory: …45517 …45512 …45194 …45513
An issue was discovered in Zimbra Collaboration (ZCS) through v10.1.

An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the existing checks by using encoded characters, allowing the injection and execution of arbitrary JavaScript within a victim's session.

NVD description · AI analysis pending
5.4
group max
<1%
  • synacor zimbra collaboration suite
CVE-2024-45510
+1 in the same advisory: …45511
An issue was discovered in Zimbra Collaboration (ZCS) through 10.0.

An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitization of user input. This allows an attacker to inject malicious code into specific fields of an e-mail message. When the victim adds the attacker to their contacts, the malicious code is stored and executed when viewing the contact list. This can lead to unauthorized actions such as arbitrary mail sending, mailbox exfiltration, profile picture alteration, and other malicious actions. Proper sanitization and escaping of input fields are necessary to mitigate this vulnerability.

NVD description · AI analysis pending
5.4<1%
  • synacor zimbra collaboration suite
CVE-2024-50599
Reflected XSS in Zimbra Collaboration Suite 8.8.15 webmail calendar endpoint

CVE-2024-50599 is a reflected Cross-Site Scripting (XSS) flaw (CWE-79) in one of the webmail calendar endpoints of Zimbra Collaboration Suite (ZCS) 8.8.15, caused by improper handling of user-supplied input that is reflected back into the HTML response. An attacker triggers it by getting a victim to click a crafted link to the calendar endpoint; the injected code is then reflected and executed in the victim's browser. Successful exploitation lets the attacker run script in the victim's webmail session context, with potential to steal session information or act as the user (CVSS 6.1 medium, user interaction required, scope changed). Organizations running ZCS 8.8.15, particularly those exposing webmail to the internet, are affected. The flaw is not yet in the CISA KEV catalog and no public proof-of-concept is known, but the 60.7% EPSS score (99th percentile) indicates a high probability of exploitation within 30 days.

Do: Apply the latest 8.8.15 patch level published by Synacor in its security advisory, or migrate to a currently supported ZCS release, without delay given the elevated EPSS score. Restrict internet exposure of the webmail calendar endpoint where possible and review webmail access logs for anomalous requests to calendar URLs. Caution users against clicking untrusted links that point to their webmail domain, since reflected XSS requires user interaction.

6.161%
  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 (only version named in the advisory; webmail calendar endpoint)
largetens of thousands of internet-exposed Zimbra servers (roughly 30k-40k per public internet scans), with the 8.8.15 share unverified
CVE-2024-48040
+1 in the same advisory: …9221
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows SQL Injection.This issue

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows SQL Injection.This issue affects Tainacan: from n/a through <= 0.21.8.

NVD description · AI analysis pending
6.5
group max
<1%
  • tainacan tainacan
CVE-2024-45519
Unauthenticated Command Execution in Synacor Zimbra Collaboration Suite (ZCS)

CVE-2024-45519 is an access-control weakness (CWE-284) in the postjournal service of Synacor Zimbra Collaboration Suite (ZCS) that allows an unauthenticated remote attacker to execute operating-system commands on the mail server. The postjournal service handles Zimbra's email journaling, and the flaw is reached by sending crafted mail/SMTP traffic to a vulnerable server, with no credentials or user interaction required. Successful exploitation gives the attacker command execution on the ZCS host, typically a foothold for stealing mailbox data and credentials, deploying webshells, or staging broader intrusion and ransomware activity. Any organization running ZCS is in scope, especially internet-exposed mail servers operated by enterprises, hosting/ISP providers, education, and government. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2024-10-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), though no public PoC is known.

Do: Upgrade ZCS to the latest patch release per Synacor's advisory for this CVE, prioritizing internet-facing mail servers, since CISA's KEV required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. If patching cannot be done immediately, restrict untrusted network access to the postjournal/SMTP path and treat the host as presumptively compromised because exploitation is already in the wild. Check postjournal logs and unexpected child processes or dropped files on the server for signs of compromise, and re-verify after patching.

9.8100% KEV PoC
  • Synacor Zimbra Collaboration Suite (ZCS)
largetens of thousands of internet-exposed Zimbra mail servers (roughly 30,000-50,000 per public internet scans), plus many more firewalled deployments
CVE-2024-6919
+2 in the same advisory: …6921 …6920
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunication Systems Inc.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Blind SQL Injection. This issue affects NACPremium: through 01082024.

NVD description · AI analysis pending
9.3
group max
<1%
  • nac nacpremium
CVE-2024-27443
Cross-Site Scripting in Zimbra Collaboration Suite CalendarInvite (Classic Webmail)

CVE-2024-27443 is a cross-site scripting vulnerability (CWE-79) in the CalendarInvite feature of the Zimbra webmail classic user interface in Synacor Zimbra Collaboration Suite (ZCS). It is triggered when a user's browser renders an email containing a crafted calendar header, causing attacker-controlled JavaScript to execute within the webmail session. Successful exploitation allows an attacker to run arbitrary JavaScript in the victim's browser, enabling session/cookie theft and actions performed as the victim inside webmail; no public proof-of-concept is known and CVSS has not yet been scored. Organizations running ZCS where users access mail through the classic webmail UI are affected (deployments restricted to the modern UI are not impacted), though specific affected version ranges have not been published in the available data. The flaw was added to the CISA KEV catalog on 2025-05-19, confirming exploitation in the wild, and EPSS currently estimates a 23.6% probability of exploitation within 30 days (98th percentile).

Do: Update ZCS to the patched release for your branch per Synacor/Zimbra's security advisory (specific fixed version numbers are not included in the available data) and confirm whether the classic webmail UI is enabled for any users. Review webmail access logs for suspicious calendar-invite traffic, and note that federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable.

6.124% KEV
  • Synacor Zimbra Collaboration Suite (ZCS)
mass≈ mass
CVE-2024-7135
The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up t

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

NVD description · AI analysis pending
6.53%
  • tainacan tainacan
CVE-2024-30529
Missing Authorization vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan:

Missing Authorization vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.7.

NVD description · AI analysis pending
9.8<1%
  • tainacan tainacan
CVE-2024-34794
+1 in the same advisory: …34795
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan:

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.21.3.

NVD description · AI analysis pending
6.1
group max
<1%
  • tainacan tainacan
CVE-2024-3634
The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such

The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

NVD description · AI analysis pending
4.8<1% PoC
  • benaceur-php month name translation benaceur