24h | 7d | 30d

Overview

  • Roundcube
  • Webmail

18 Dec 2025
Published
18 Dec 2025
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.06%

KEV

Description

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Statistics

  • 2 Posts

Last activity: 6 hours ago

Bluesky

Profile picture
URGENT: #Fedora 43 Roundcube Webmail security patch is live. Patches CVE-2025-68461 (XSS via SVG) & CVE-2025-68460 (Info Disclosure). Remote exploitation risk is high. Read more: 👉 tinyurl.com/3xkhyk9h #Security
  • 0
  • 0
  • 0
  • 8h ago
Profile picture
URGENT: #Fedora 42 admins must patch RoundcubeMail to v1.6.12 immediately! Fixes CVE-2025-68461 (SVG XSS) & CVE-2025-68460 (info disclosure). Read more: 👉 tinyurl.com/3783kcme #Security
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • 7-Zip
  • 7-Zip

19 Nov 2025
Published
21 Nov 2025
Updated

CVSS v3.0
HIGH (7.0)
EPSS
0.31%

KEV

Description

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. Was ZDI-CAN-26753.

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture
Critical update for RetroArch on #Fedora 43. Patches RCE and buffer overflow flaws (CVE-2025-11001, CVE-2025-53816, etc.). Your retro gaming setup could be a backdoor. Patch NOW: Read more: 👉 tinyurl.com/3zzb9ad3 #Security
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Roundcube
  • Webmail

18 Dec 2025
Published
18 Dec 2025
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.05%

KEV

Description

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

Statistics

  • 2 Posts

Last activity: 6 hours ago

Bluesky

Profile picture
URGENT: #Fedora 43 Roundcube Webmail security patch is live. Patches CVE-2025-68461 (XSS via SVG) & CVE-2025-68460 (Info Disclosure). Remote exploitation risk is high. Read more: 👉 tinyurl.com/3xkhyk9h #Security
  • 0
  • 0
  • 0
  • 8h ago
Profile picture
URGENT: #Fedora 42 admins must patch RoundcubeMail to v1.6.12 immediately! Fixes CVE-2025-68461 (SVG XSS) & CVE-2025-68460 (info disclosure). Read more: 👉 tinyurl.com/3783kcme #Security
  • 0
  • 0
  • 0
  • 6h ago
Showing 21 to 23 of 23 CVEs