Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2025-7024 — Local privilege escalation in Windows Server OS through installed Tetra Connectivity Serv…

Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a u…

| Misconfiguration
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.3 LOW
CVE-2026-5458 — Noelse Individuals & Pro App com.afone.noelse BuildConfig.java hard-coded key

A weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This impacts an unknown function of the file com/reactnative/antelop/BuildConfig.java of the component com.afone…

| Cryptography
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.3 LOW
CVE-2026-5457 — PropertyGuru AgentNet Singapore App com.allproperty.android.agentnet BuildConfig.java har…

A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to 23.7.10 on Android. This affects an unknown function of the file com/allproperty/android/agentnet/BuildConfig.java of …

| Cryptography
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.3 LOW
CVE-2026-5456 — Align Technology My Invisalign App com.aligntech.myinvisalign.emea BuildConfig.java hard-…

A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unknown function of the file com/aligntech/myinvisalign/BuildConfig.java of the comp…

| Cryptography
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.3 LOW
CVE-2026-5455 — Dialogue App ca.diagram.dialogue config.json hard-coded key

A vulnerability was determined in Dialogue App up to 4.3.2 on Android. The affected element is an unknown function of the file file res/raw/config.json of the component ca.diagram.dialogue. Executing…

| Cryptography
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
9.3 CRITICAL
CVE-2026-5463 — Metasploit Command Injection

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This break…

Remote | Injection
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.3 LOW
CVE-2026-5454 — GRID Organiser App co.gridapp.organiser app.json hard-coded key

A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file file res/raw/app.json of the component co.gridapp.organiser. Performing a manipulat…

| Cryptography
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.3 LOW
CVE-2026-5453 — Rico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-code…

A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processing of the file br/com/rico/mobile/di/SegmentSettingsModule.…

| Cryptography
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
6.5 MEDIUM
CVE-2026-35549 — MariaDB Server Caching Sha2 Password Authentication Plugin Crash Vulnerability

An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user a…

mariadb | Remote | Denial of Service
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.3 MEDIUM
CVE-2026-35545 — Roundcube Webmail SVG Animate Element Injection Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure …

webmail | Remote | Information Disclosure
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.3 MEDIUM
CVE-2026-35544 — Roundcube Webmail CSS Injection Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass vi…

webmail | Remote | Cross-Site Scripting
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.3 MEDIUM
CVE-2026-35543 — Roundcube Webmail SVG Image Injection Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead …

webmail | Remote | Information Disclosure
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.3 MEDIUM
CVE-2026-35542 — Roundcube Webmail Background Attribute Injection Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. Thi…

webmail | Remote | Information Disclosure
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
4.2 MEDIUM
CVE-2026-35541 — Roundcube Webmail Password Comparison Type Confusion Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing …

webmail | Remote | Authentication
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
5.4 MEDIUM
CVE-2026-35540 — Roundcube Webmail CSS Injection Vulnerability

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if s…

webmail | Remote | Server-Side Request Forgery
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
6.1 MEDIUM
CVE-2026-35539 — Roundcube Webmail Cross-Site Scripting Vulnerability

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

webmail | Remote | Cross-Site Scripting
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.1 LOW
CVE-2026-35538 — Roundcube Webmail IMAP Injection/CSRF Bypass

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

webmail | Remote | Injection
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.3 LOW
CVE-2026-5452 — UCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key

A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the file campusconnect/BuildConfig.java of the component campusconnect.ucc. This man…

| Cryptography
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
3.7 LOW
CVE-2026-35537 — "Roundcube Webmail Deserialization File Write Vulnerability"

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated atta…

webmail | Remote | Misconfiguration
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
7.2 HIGH
CVE-2026-35536 — Tornado Cookie Attribute Injection Vulnerability

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

tornado | Remote | Injection
Apr 03, 2026 Apr 03, 2026
Apr 03, 2026
Apr 03, 2026
Showing 20 of 6344 Results