Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2026-7511

2 месяца назад

PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-75032

9 дней назад

(A flaw was found in BlueZ. Insufficient validation of packet length fi ...)

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2026-75010

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2026-75007

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2026-75006

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2026-75004

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2026-75003

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2026-75002

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2026-75000

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

CVSS3: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2026-74999

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2026-74998

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

CVSS3: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2026-74997

10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-74990

9 дней назад

(Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-74989

9 дней назад

(Internally found bugs present in Thunderbird 153. Some of these bugs s ...)

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-74988

9 дней назад

(Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird ...)

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-74987

9 дней назад

(Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-74986

9 дней назад

(Site isolation issue in the CSS Parsing and Computation component. Thi ...)

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2026-74985

9 дней назад

(Privilege escalation in the Enterprise Policies component. This vulner ...)

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-74984

9 дней назад

(Race condition in the JavaScript Engine component. This vulnerability ...)

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2026-74983

9 дней назад

(Mitigation bypass in the Data Loss Prevention component. This vulnerab ...)

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-7511

PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.

CVSS3: 7.5
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-75032

(A flaw was found in BlueZ. Insufficient validation of packet length fi ...)

CVSS3: 6.3
0%
Низкий
9 дней назад
ubuntu логотип
CVE-2026-75010

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

CVSS3: 6.4
0%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-75007

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

CVSS3: 5.4
0%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-75006

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.

CVSS3: 5.8
0%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-75004

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.

CVSS3: 4.3
0%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-75003

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

CVSS3: 5.8
0%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-75002

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

CVSS3: 7.1
1%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-75000

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

CVSS3: 5.8
0%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-74999

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

CVSS3: 5.4
0%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-74998

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

CVSS3: 7.2
0%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-74997

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

CVSS3: 8.8
1%
Низкий
10 дней назад
ubuntu логотип
CVE-2026-74990

(Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)

CVSS3: 9.8
1%
Низкий
9 дней назад
ubuntu логотип
CVE-2026-74989

(Internally found bugs present in Thunderbird 153. Some of these bugs s ...)

CVSS3: 9.8
0%
Низкий
9 дней назад
ubuntu логотип
CVE-2026-74988

(Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird ...)

CVSS3: 9.8
0%
Низкий
9 дней назад
ubuntu логотип
CVE-2026-74987

(Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)

CVSS3: 9.8
1%
Низкий
9 дней назад
ubuntu логотип
CVE-2026-74986

(Site isolation issue in the CSS Parsing and Computation component. Thi ...)

CVSS3: 9.1
0%
Низкий
9 дней назад
ubuntu логотип
CVE-2026-74985

(Privilege escalation in the Enterprise Policies component. This vulner ...)

CVSS3: 9.8
0%
Низкий
9 дней назад
ubuntu логотип
CVE-2026-74984

(Race condition in the JavaScript Engine component. This vulnerability ...)

CVSS3: 6.8
0%
Низкий
9 дней назад
ubuntu логотип
CVE-2026-74983

(Mitigation bypass in the Data Loss Prevention component. This vulnerab ...)

CVSS3: 8.1
0%
Низкий
9 дней назад

Уязвимостей на страницу