|
5041
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information di…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2026-48846
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5042
|
3.7 |
LOW
Network
|
-
|
-
|
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2026-48847
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5043
|
7.2 |
HIGH
Network
|
-
|
-
|
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48848
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5044
|
4.4 |
MEDIUM
Network
|
-
|
-
|
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
|
CWE-79
Cross-site Scripting
|
CVE-2026-48849
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5045
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
Insufficient Validation of Autoprimary SOA Queries
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42001
|
2026-05-27 04:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5046
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
Concurrency and locking defects in GSS-TSIG
|
CWE-364
Signal Handler Race Condition
|
CVE-2026-42002
|
2026-05-27 04:23 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5047
|
6.5 |
MEDIUM
Network
|
powerdns
|
authoritative
|
Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
|
CWE-94
Code Injection
|
CVE-2026-42396
|
2026-05-27 04:19 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5048
|
- |
|
-
|
-
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1…
|
CWE-862
Missing Authorization
|
CVE-2026-33137
|
2026-05-27 04:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5049
|
- |
|
-
|
-
|
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator passwor…
|
CWE-20
Improper Input Validation
|
CVE-2026-3294
|
2026-05-27 04:08 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5050
|
- |
|
-
|
-
|
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, thi…
|
CWE-22 CWE-269 CWE-284 CWE-732
Path Traversal Improper Privilege Management Improper Access Control Incorrect Permission Assignment for Critical Resource
|
CVE-2026-9489
|
2026-05-27 04:05 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|