Search CVE reports


Toggle filters

121 – 130 of 43789 results

Status is adjusted based on your filters.


CVE-2026-19693

Medium priority
Needs evaluation

extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is...

1 affected package

node-extract-zip

Package 24.04 LTS
node-extract-zip Needs evaluation
Show less packages

CVE-2026-75010

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only...

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-75007

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-75006

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network...

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-75004

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances...

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-75003

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-75002

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-75000

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-74999

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-74998

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages