|
2001
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information discl…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2026-48845
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2002
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information di…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2026-48846
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2003
|
3.7 |
LOW
Network
|
-
|
-
|
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2026-48847
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2004
|
7.2 |
HIGH
Network
|
-
|
-
|
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48848
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2005
|
4.4 |
MEDIUM
Network
|
-
|
-
|
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
|
CWE-79
Cross-site Scripting
|
CVE-2026-48849
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2006
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
Insufficient Validation of Autoprimary SOA Queries
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42001
|
2026-05-27 04:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2007
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
Concurrency and locking defects in GSS-TSIG
|
CWE-364
Signal Handler Race Condition
|
CVE-2026-42002
|
2026-05-27 04:23 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2008
|
6.5 |
MEDIUM
Network
|
powerdns
|
authoritative
|
Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
|
CWE-94
Code Injection
|
CVE-2026-42396
|
2026-05-27 04:19 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2009
|
- |
|
-
|
-
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1…
|
CWE-862
Missing Authorization
|
CVE-2026-33137
|
2026-05-27 04:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2010
|
- |
|
-
|
-
|
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator passwor…
|
CWE-20
Improper Input Validation
|
CVE-2026-3294
|
2026-05-27 04:08 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|