Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-35545 — Roundcube Webmail SVG Animate Element Injection Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure …

webmail | Remote | Information Disclosure
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.3 MEDIUM
CVE-2026-35544 — Roundcube Webmail CSS Injection Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass vi…

webmail | Remote | Cross-Site Scripting
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.3 MEDIUM
CVE-2026-35543 — Roundcube Webmail SVG Image Injection Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead …

webmail | Remote | Information Disclosure
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.3 MEDIUM
CVE-2026-35542 — Roundcube Webmail Background Attribute Injection Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. Thi…

webmail | Remote | Information Disclosure
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
4.2 MEDIUM
CVE-2026-35541 — Roundcube Webmail Password Comparison Type Confusion Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing …

webmail | Remote | Authentication
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.4 MEDIUM
CVE-2026-35540 — Roundcube Webmail CSS Injection Vulnerability

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if s…

webmail | Remote | Server-Side Request Forgery
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
6.1 MEDIUM
CVE-2026-35539 — Roundcube Webmail Cross-Site Scripting Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

webmail | Remote | Cross-Site Scripting
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.1 LOW
CVE-2026-35538 — Roundcube Webmail IMAP Injection/CSRF Bypass

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

webmail | Remote | Injection
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.3 LOW
CVE-2026-5452 — UCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key

A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the file campusconnect/BuildConfig.java of the component campusconnect.ucc. This man…

| Cryptography
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.7 LOW
CVE-2026-35537 — "Roundcube Webmail Deserialization File Write Vulnerability"

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated atta…

webmail | Remote | Misconfiguration
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
7.2 HIGH
CVE-2026-35536 — Tornado Cookie Attribute Injection Vulnerability

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

tornado | Remote | Injection
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
7.4 HIGH
CVE-2026-35535 — Sudo Privilege Escalation Vulnerability

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

sudo | Authorization
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
7.5 HIGH
CVE-2026-28815 — Apple Swift-Crypto Out-of-Bounds Read

A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime …

macos | Remote | Memory Corruption
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.4 MEDIUM
CVE-2026-35508 — Shynet XSS Vulnerability in urldisplay and iconify Template Filters

Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters,

Remote | Cross-Site Scripting
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
6.4 MEDIUM
CVE-2026-35507 — Shynet Host Header Injection Vulnerability

Shynet before 0.14.0 allows Host header injection in the password reset flow.

Remote | Misconfiguration
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
10.0 CRITICAL
CVE-2026-33107 — Azure Databricks Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
10.0 CRITICAL
CVE-2026-33105 — Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
10.0 CRITICAL
CVE-2026-32213 — Azure AI Foundry Elevation of Privilege Vulnerability

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
9.1 CRITICAL
CVE-2026-32211 — Azure MCP Server Information Disclosure Vulnerability

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.

Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
8.6 HIGH
CVE-2026-32173 — Azure SRE Agent Information Disclosure Vulnerability

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
Showing 20 of 6335 Results