Known vulnerabilities in roundcube (Debian package) - page 2

Vendor: Debian
Software CPE: cpe:2.3:o:debian:roundcube_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 30
Public exploits: 7
Known exploited (KEV): 8
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting roundcube (Debian package) roundcube (Debian package) is affected by 30 known vulnerabilities: 1 critical, 5 high, 15 medium, 9 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU59318 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-46144
CWE-79 Medium
No
No
1.3.17+dfsg.1-1~deb10u2, 1.4.13+dfsg.1-1~deb11u1 09.01.2022 SB2022010901
SB2022010902
#VU58394 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2021-44026
CWE-89 High
Available
Exploited
1.3.17+dfsg.1-1~deb10u1, 1.4.12+dfsg.1-1~deb11u1 27.11.2021 SB2021112701
SB2021112702
SB2021111516
and 2 more
#VU58393 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-44025
CWE-79 Medium
No
No
1.3.17+dfsg.1-1~deb10u1, 1.4.12+dfsg.1-1~deb11u1 27.11.2021 SB2021112701
SB2021112702
SB2021111516
and 2 more
#VU49153 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-35730
CWE-79 High
No
Exploited
1.3.16+dfsg.1-1~deb10u1 28.12.2020 SB2020122805
SB2020122812
SB2021010410
and 2 more
#VU45648 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-16145
CWE-79 Low
No
No
1.3.15+dfsg.1-1~deb10u1 12.08.2020 SB2020081262
SB2020081270
SB2020092414
and 2 more
#VU29609 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-15562
CWE-79 Medium
No
No
1.3.14+dfsg.1-1~deb10u1 09.07.2020 SB2020070909
SB2020070910
SB2020092414
#VU28979 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-13965
CWE-79 Medium
No
Exploited
1.2.3+dfsg.1-4+deb9u5, 1.3.13+dfsg.1-1~deb10u1 11.06.2020 SB2020061115
SB2020061116
SB2020060828
and 1 more
#VU28978 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-13964
CWE-79 Medium
No
No
1.2.3+dfsg.1-4+deb9u5, 1.3.13+dfsg.1-1~deb10u1 11.06.2020 SB2020061115
SB2020061116
SB2020060828
and 1 more
#VU27500 - Cross-Site Request Forgery (CSRF)
CVE-2020-12626
CWE-352 Low
No
No
1.2.3+dfsg.1-4+deb9u4, 1.3.11+dfsg.1-1~deb10u1, 1.4.4+dfsg.1-1, 1.4.4+dfsg.1-1~bpo10+1 04.05.2020 SB2020050420
SB2020050615
SB2020072722
#VU27498 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-12625
CWE-79 Low
No
No
1.2.3+dfsg.1-4+deb9u4, 1.3.11+dfsg.1-1~deb10u1, 1.4.4+dfsg.1-1, 1.4.4+dfsg.1-1~bpo10+1 04.05.2020 SB2020050420
SB2020050615
SB2020072722
and 1 more


Showing elements 21 - 40 out of 30