Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zulip zulip vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2023-46723
lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publicati...
Pajip Lte-pic32-writer
7.5
CVSSv3
CVE-2016-4427
In zulip prior to 1.3.12, deactivated users could access messages if SSO was enabled.
Zulip Zulip
7.5
CVSSv3
CVE-2020-14215
Zulip Server prior to 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
Zulip Zulip Server
7.4
CVSSv3
CVE-2022-24751
Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable to a race condition during account deactivation, where a simultaneous access by the user being deactivated may, in rare cases, allow continued access by the de...
Zulip Zulip
6.5
CVSSv3
CVE-2023-32678
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete ...
Zulip Zulip Server
6.5
CVSSv3
CVE-2021-41115
Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via arbitrary regular expressions. Malicious organizatio...
Zulip Zulip
6.5
CVSSv3
CVE-2019-16215
The Markdown parser in Zulip server prior to 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message causing the server to spend an effectively arbitrary amount of CPU time and stall the processing ...
Zulip Zulip Server
6.5
CVSSv3
CVE-2017-0896
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to...
Zulip Zulip Server 1.3.11
Zulip Zulip Server 1.3.2
Zulip Zulip Server 1.3.8
Zulip Zulip Server 1.3.1
Zulip Zulip Server 1.4.0
Zulip Zulip Server 1.3.3
Zulip Zulip Server 1.3.12
Zulip Zulip Server 1.3.10
Zulip Zulip Server 1.3.6
Zulip Zulip Server 1.4.2
Zulip Zulip Server 1.3.7
Zulip Zulip Server 1.5.1
Zulip Zulip Server 1.4.3
Zulip Zulip Server 1.3.0
Zulip Zulip Server 1.3.4
Zulip Zulip Server 1.5.0
Zulip Zulip Server 1.3.13
Zulip Zulip Server 1.4.1
Zulip Zulip Server 1.3.9
6.1
CVSSv3
CVE-2023-33186
Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from May 2, 2023 and later, including beta versions 7.0-beta1 and ...
Zulip Zulip Server 7.0
6.1
CVSSv3
CVE-2020-24582
Zulip Desktop prior to 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.
Zulipchat Zulip Desktop
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
spoof
CVE-2024-34928
CVE-2024-5291
deserialization
CVE-2024-4471
CVE-2024-4956
CVE-2024-32002
CVE-2024-5227
unspecified
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »