← Back

Zendesk

zendesk

3 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Samlr
samlr
Enc Datavault
enc_datavault
Enc Vaultapi
enc_vaultapi

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Sandisk
Zendesk
3Enc Datavault
Enc VaultapiSecureaccess
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
1Zendesk
1Samlr
Nov 21, 2024
Jul 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.
1Zendesk
1Zendesk Feedback Tab
May 6, 2026
Sep 11, 2015
N/A· v4
N/A· v3
2.6 LOW· v2
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web scri...Show more
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.Show less