Search CVE reports


Toggle filters

201 – 210 of 33539 results

Status is adjusted based on your filters.


CVE-2026-35540

Medium priority
Needs evaluation

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local...

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-35539

Medium priority
Needs evaluation

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-35538

Medium priority
Needs evaluation

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-35537

Medium priority
Needs evaluation

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-35536

Medium priority
Needs evaluation

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

1 affected package

python-tornado

Package 24.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-35535

High priority
Fixed

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

1 affected package

sudo

Package 24.04 LTS
sudo Fixed
Show less packages

CVE-2026-27456

Medium priority
Needs evaluation

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when...

1 affected package

util-linux

Package 24.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-35414

Medium priority
Needs evaluation

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS
openssh Needs evaluation
openssh-ssh1 Ignored
Show less packages

CVE-2026-34835

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted...

1 affected package

ruby-rack

Package 24.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-34827

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition:...

1 affected package

ruby-rack

Package 24.04 LTS
ruby-rack Needs evaluation
Show less packages