5.4
CVE-2026-35540 - Roundcube Webmail CSS Sanitization Issue Allows SSRF and Information Disclosure
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
6.1
CVE-2026-35539 -
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
3.1
CVE-2026-35538 -
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
3.7
CVE-2026-35537 -
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
4.8
CVE-2026-5452 - UCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key
A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the file campusconnect/BuildConfig.java of the component campusconnect.ucc. This manipulation causes use of hard-coded cryptographic key . The attack can only be executed locally. Theβ¦
7.2
CVE-2026-35536 - tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
7.4
CVE-2026-35535 - sudo: Sudo: Privilege escalation due to failure in privilege drop calls
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
7.5
CVE-2026-28815 - Out-of-Bounds Read in HPKE Decapsulation Leading to Potential Memory Disclosure
A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1.
5.4
CVE-2026-35508 - CrossβSite Scripting via urldisplay and iconify Filters in Shynet before v0.14.0
Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters,
6.4
CVE-2026-35507 - Host Header Injection in Shynet Password Reset Flow
Shynet before 0.14.0 allows Host header injection in the password reset flow.