Show filters
95 Total Results
Displaying 1-10 of 95
Sort by:
Attacker Value
Unknown

CVE-2020-11022

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Attacker Value
High

Zimbra Collaboration Suite ProxyServlet SSRF

Disclosure Date: April 30, 2019 (last updated October 06, 2023)
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
0
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2019-8947

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS.
Attacker Value
Unknown

CVE-2015-2249

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Zimbra Collaboration before 8.6.0 patch5 has XSS.
Attacker Value
Unknown

CVE-2014-8563

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.
Attacker Value
Unknown

CVE-2019-15313

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.
Attacker Value
Unknown

CVE-2019-8945

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.
Attacker Value
Unknown

CVE-2014-5500

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Synacor Zimbra Collaboration before 8.0.8 has XSS.
Attacker Value
Unknown

CVE-2019-8946

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.