4.8

CVSS4.0

CVE-2026-5453 - Rico sรณ vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded key

A vulnerability has been found in Rico sรณ vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processing of the file br/com/rico/mobile/di/SegmentSettingsModule.java of the component br.com.rico.mobile. Such manipulation of the argument SEGMENT_WRITE_KEY leads โ€ฆ

๐Ÿ“… Published: April 3, 2026, 4:30 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 5:16 a.m.

5.3

CVSS3.1

CVE-2026-35545 -

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.

๐Ÿ“… Published: April 3, 2026, 4:02 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 5:16 a.m.

5.3

CVSS3.1

CVE-2026-35544 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.

๐Ÿ“… Published: April 3, 2026, 3:59 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 5:16 a.m.

5.3

CVSS3.1

CVE-2026-35543 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

๐Ÿ“… Published: April 3, 2026, 3:57 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 5:16 a.m.

5.3

CVSS3.1

CVE-2026-35542 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.

๐Ÿ“… Published: April 3, 2026, 3:54 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 5:16 a.m.

4.2

CVSS3.1

CVE-2026-35541 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

๐Ÿ“… Published: April 3, 2026, 3:50 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 5:16 a.m.

5.4

CVSS3.1

CVE-2026-35540 -

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.

๐Ÿ“… Published: April 3, 2026, 3:47 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 5:16 a.m.

6.1

CVSS3.1

CVE-2026-35539 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

๐Ÿ“… Published: April 3, 2026, 3:39 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 5:16 a.m.

3.1

CVSS3.1

CVE-2026-35538 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

๐Ÿ“… Published: April 3, 2026, 3:35 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 5:16 a.m.

3.7

CVSS3.1

CVE-2026-35537 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

๐Ÿ“… Published: April 3, 2026, 3:28 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:17 a.m.
Total resulsts: 341964
Page 2 of 34,197
ยซ previous page ยป next page
Filters