5.4

CVSS3.1

CVE-2026-35540 - Roundcube Webmail CSS Sanitization Issue Allows SSRF and Information Disclosure

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.

πŸ“… Published: April 3, 2026, 3:47 a.m. πŸ”„ Last Modified: April 7, 2026, 8:52 p.m.

6.1

CVSS3.1

CVE-2026-35539 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

πŸ“… Published: April 3, 2026, 3:39 a.m. πŸ”„ Last Modified: April 8, 2026, 7:54 p.m.

3.1

CVSS3.1

CVE-2026-35538 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

πŸ“… Published: April 3, 2026, 3:35 a.m. πŸ”„ Last Modified: April 8, 2026, 7:54 p.m.

3.7

CVSS3.1

CVE-2026-35537 -

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

πŸ“… Published: April 3, 2026, 3:28 a.m. πŸ”„ Last Modified: April 11, 2026, 3:16 p.m.

4.8

CVSS4.0

CVE-2026-5452 - UCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key

A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the file campusconnect/BuildConfig.java of the component campusconnect.ucc. This manipulation causes use of hard-coded cryptographic key . The attack can only be executed locally. The…

πŸ“… Published: April 3, 2026, 2:45 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.2

CVSS3.1

CVE-2026-35536 - tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

πŸ“… Published: April 3, 2026, 2:25 a.m. πŸ”„ Last Modified: April 10, 2026, 3:14 p.m.

7.4

CVSS3.1

CVE-2026-35535 - sudo: Sudo: Privilege escalation due to failure in privilege drop calls

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

πŸ“… Published: April 3, 2026, 2:21 a.m. πŸ”„ Last Modified: April 7, 2026, 7:55 a.m.

7.5

CVSS3.1

CVE-2026-28815 - Out-of-Bounds Read in HPKE Decapsulation Leading to Potential Memory Disclosure

A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1.

πŸ“… Published: April 3, 2026, 1:32 a.m. πŸ”„ Last Modified: April 7, 2026, 7:55 a.m.

5.4

CVSS3.1

CVE-2026-35508 - Cross‑Site Scripting via urldisplay and iconify Filters in Shynet before v0.14.0

Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters,

πŸ“… Published: April 3, 2026, 1:13 a.m. πŸ”„ Last Modified: April 10, 2026, 4:02 p.m.

6.4

CVSS3.1

CVE-2026-35507 - Host Header Injection in Shynet Password Reset Flow

Shynet before 0.14.0 allows Host header injection in the password reset flow.

πŸ“… Published: April 3, 2026, 1 a.m. πŸ”„ Last Modified: April 10, 2026, 2:01 a.m.
Total resulsts: 344062
Page 200 of 34,407
Β« previous page Β» next page
Filters