open-xchange

272 tracked vulnerabilities.

CVE-2023-26442 LOW
Open-Xchange App Suite Cacheservice - Sproxyd Redirect Server-Side Request Forgery
Aug 02, 2023
CVSS 3.2
EPSS 0.00
CVE-2023-26441 MEDIUM
open-xchange_appsuite_office < 8.11 - Path Traversal in Cacheservice
Aug 02, 2023
CVSS 5.7
EPSS 0.00
CVE-2023-26440 HIGH
Open-Xchange AppSuite Office <= 8.11 - SQL Injection
Aug 02, 2023
CVSS 7.1
EPSS 0.00
CVE-2023-26439 HIGH
Open-Xchange AppSuite Office <= 8.11 - SQL Injection
Aug 02, 2023
CVSS 7.6
EPSS 0.00
CVE-2023-26438 MEDIUM
Open-Xchange App Suite - JDK DNS Cache Server-Side Request Forgery
Aug 02, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-26430 LOW
open-xchange_appsuite_backend - Authenticated Command Injection via SIEVE Mail-Filter Rules
Aug 02, 2023
CVSS 3.5
EPSS 0.00
CVE-2023-26436 HIGH
Open-Xchange AppSuite Backend <= 7.10.6 - Deserialization Code Injection
Jun 20, 2023
CVSS 7.1
EPSS 0.00
CVE-2023-26435 MEDIUM
open-xchange_appsuite_backend < 7.10.6 - Server-Side Request Forgery via Manipulated ODT Documents
Jun 20, 2023
CVSS 5.0
EPSS 0.00
CVE-2023-26434 MEDIUM
open-xchange_appsuite_backend < 7.10.6 - Denial of Service via POP3 Capabilities Response
Jun 20, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-26433 MEDIUM
open-xchange_appsuite_backend < 7.10.6 - Denial of Service via IMAP Capabilities Response
Jun 20, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-26432 MEDIUM
open-xchange_appsuite_backend < 7.10.6 - Denial of Service via SMTP Capabilities Response
Jun 20, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-26431 MEDIUM
Open-Xchange App Suite - IPv4-Mapped IPv6 Server-Side Request Forgery
Jun 20, 2023
CVSS 5.0
EPSS 0.00
CVE-2023-26429 LOW
Open-Xchange AppSuite Backend - Control Character Injection via User Feedback
Jun 20, 2023
CVSS 3.5
EPSS 0.00
CVE-2023-26428 MEDIUM
Open-Xchange AppSuite Backend - Information Disclosure via Snippet ID
Jun 20, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-26427 LOW
open-xchange_appsuite_backend < 7.10.6 - Unauthenticated Sensitive Information Exposure via Insecure File Permissions
Jun 20, 2023
CVSS 3.2
EPSS 0.00
CVE-2023-24605 MEDIUM
OX App Suite <7.10.6-rev37 - Info Disclosure
May 29, 2023
CVSS 4.2
EPSS 0.00
CVE-2023-24604 MEDIUM
OX App Suite <7.10.6-rev37 - Info Disclosure
May 29, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-24603 MEDIUM
OX App Suite <7.10.6-rev37 - Info Disclosure
May 29, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-24602 MEDIUM
OX App Suite < 7.10.6 - Cross-Site Scripting via Tumblr Portal Widget
May 29, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-24601 MEDIUM
OX App Suite < 7.10.6 - Cross-Site Scripting via Jslob API Registry Sub-Tree
May 29, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-24600 MEDIUM
OX App Suite <7.10.6-rev37 - Auth Bypass
May 29, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-24599 MEDIUM
OX App Suite <7.10.6-rev37 - Privilege Escalation
May 29, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-24598 MEDIUM
OX App Suite <7.10.6-rev37 - Info Disclosure
May 29, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-24597 MEDIUM
OX App Suite <7.10.6-rev24 - Info Disclosure
May 29, 2023
CVSS 5.3
EPSS 0.00
CVE-2022-37306 MEDIUM
OX App Suite < 7.10.6 - Cross-Site Scripting via Upsell Trigger
Apr 16, 2023
CVSS 6.1
EPSS 0.00