VulnSea

synacor has 7 CVEs on record between 2018 and 2026. 1 was published in the last 90 days. The median CVSS is 7.5 (high), with 2 rated critical. 100% have been exploited in the wild — well above the 1% corpus average, so synacor flaws are worth patching on sight. The median gap from publication to a KEV listing is 65 days (6 cases). The most common weakness class is CWE-22 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
100% vs 1% corpus
Median CVSS
7.5
Publish → KEV
65 d median(6)
Last 90 days
1 prev 0

Products

  • zimbra_collaboration_suite 7
7
Total CVEs
2
Critical
7
CISA KEV
7
Exploited

synacor vulnerabilities

CVEs affecting synacor, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-73570High· 8.9CISA KEVPoC
1mo ago

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP …

Abyssalsynacor · zimbra_collaboration_suiteEPSS 32%via NVD
CVE-2022-41352Critical· 9.8CISA KEVPoC
3y ago

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to …

Hadalsynacor · zimbra_collaboration_suiteEPSS 95%via NVD
CVE-2022-37042Critical· 9.8CISA KEV0dayPoC
4y ago

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to t…

Hadalsynacor · zimbra_collaboration_suiteEPSS 92%via NVD
CVE-2022-27925High· 7.2CISA KEVPoC
4y ago

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, l…

Abyssalsynacor · zimbra_collaboration_suiteEPSS 99%via NVD
CVE-2022-27924High· 7.5CISA KEVPoC
4y ago

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

Abyssalsynacor · zimbra_collaboration_suiteEPSS 85%via NVD
CVE-2022-24682Medium· 6.1CISA KEV0dayPoC
4y ago

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript insi…

Midnightsynacor · zimbra_collaboration_suiteEPSS 31%via NVD
CVE-2018-6882Medium· 6.1CISA KEVPoC
8y ago

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…

Midnightsynacor · zimbra_collaboration_suiteEPSS 25%via NVD
synacor vulnerabilities (CVEs) · VulnSea