CVE Search

IDDescriptionSeverityUpdated
CVE-2025-49113Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
high
Vulnerability of Interest
CVE-2026-20896Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
critical
Vulnerability of Interest
CVE-2026-2699Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
critical
Vulnerability Being Monitored
CVE-2026-45659Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high
Vulnerability of Interest
CVE-2026-2701Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
high
Vulnerability Being Monitored
CVE-2026-48282ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
critical
Vulnerability of Interest
CVE-2024-42009A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
critical
Vulnerability of Interest
CVE-2026-50746A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
critical
Vulnerability Being Monitored
CVE-2026-8451Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
high
Vulnerability of Interest