4.8

CVSS4.0

CVE-2026-5454 - GRID Organiser App co.gridapp.organiser app.json hard-coded key

A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file fileΒ res/raw/app.json of the component co.gridapp.organiser. Performing a manipulation of the argument SegmentWriteKey results in use of hard-coded cryptographic key . The attack is …

πŸ“… Published: April 3, 2026, 4:45 a.m. πŸ”„ Last Modified: April 3, 2026, 8:01 p.m.

9.3

CVSS4.0

CVE-2026-5463 - Command Injection in pymetasploit3 Enables Arbitrary Command Execution

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended …

πŸ“… Published: April 3, 2026, 4:32 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

4.8

CVSS4.0

CVE-2026-5453 - Rico sΓ³ vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded key

A vulnerability has been found in Rico sΓ³ vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processing of the file br/com/rico/mobile/di/SegmentSettingsModule.java of the component br.com.rico.mobile. Such manipulation of the argument SEGMENT_WRITE_KEY leads …

πŸ“… Published: April 3, 2026, 4:30 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS3.1

CVE-2026-35545 - SVG Bypass of Remote Image Blocking in Roundcube Webmail

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.

πŸ“… Published: April 3, 2026, 4:02 a.m. πŸ”„ Last Modified: April 7, 2026, 8:37 p.m.

5.3

CVSS3.1

CVE-2026-35544 - Fixed-Position Mitigation Bypass via CSS Injection in Roundcube Webmail

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.

πŸ“… Published: April 3, 2026, 3:59 a.m. πŸ”„ Last Modified: April 9, 2026, 1:09 a.m.

5.3

CVSS3.1

CVE-2026-35543 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

πŸ“… Published: April 3, 2026, 3:57 a.m. πŸ”„ Last Modified: April 8, 2026, 7:54 p.m.

5.3

CVSS3.1

CVE-2026-35542 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.

πŸ“… Published: April 3, 2026, 3:54 a.m. πŸ”„ Last Modified: April 8, 2026, 7:54 p.m.

4.2

CVSS3.1

CVE-2026-35541 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

πŸ“… Published: April 3, 2026, 3:50 a.m. πŸ”„ Last Modified: April 8, 2026, 7:54 p.m.

5.4

CVSS3.1

CVE-2026-35540 - Roundcube Webmail CSS Sanitization Issue Allows SSRF and Information Disclosure

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.

πŸ“… Published: April 3, 2026, 3:47 a.m. πŸ”„ Last Modified: April 7, 2026, 8:52 p.m.

6.1

CVSS3.1

CVE-2026-35539 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

πŸ“… Published: April 3, 2026, 3:39 a.m. πŸ”„ Last Modified: April 8, 2026, 7:54 p.m.
Total resulsts: 343970
Page 190 of 34,397
Β« previous page Β» next page
Filters