5.4
CVE-2025-63260 - Stored XSS in SyncFusion Document Editor 30.1.37 via Comment and Chat Fields
SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.
5.4
CVE-2026-33372 - CrossβSite Request Forgery in Zimbra Webmail
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF tokens. The application accepts CSRF tokens supplied within the request body instead of requiring them through the expecβ¦
7.8
CVE-2025-63261 - Command Injection in AWStats via Open Function
AWStats 8.0 is vulnerable to Command Injection via the open function
4.3
CVE-2026-30580 - Directory Traversal via Create Folder from URL in File Thingie 2.5.7
File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" functionality of the application to read arbitrary files on the target system.
4.3
CVE-2026-33371 - XML External Entity Vulnerability in Zimbra Collaboration 10.0/10.1 EWS SOAP Interface
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML paβ¦
6.1
CVE-2026-33368 - Zimbra Collaboration Suite Reflected XSS in Classic Webmail REST Interface
Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails to properly sanitize user-supplied input, allowing an unauthenticated attacker to inject malicious JavaScript into a crβ¦
6.1
CVE-2026-33370 -
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient sanitization of specific uploaded file types. When a user opens a publicly shared Briefcase file containing malicious scrβ¦
4.3
CVE-2026-33369 - LDAP Injection in Zimbra Collaboration Mailbox SOAP Service
Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-supplied input before incorporating it into an LDAP search filter. An authenticated attacker can exploit thiβ¦
6.5
CVE-2026-30579 - CrossβSite Scripting via Uploaded File Name in File Thingie 2.5.7
File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a crafted file name used to trigger a Javascript payload.
5.5
CVE-2026-23278 - netfilter: nf_tables: always walk all pending catchall elements
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always walk all pending catchall elements During transaction processing we might have more than one catchall element: 1 live catchall element and 1 pending element that is coming as part of the new batch. Iβ¦