Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial Of Service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Prompt Leakage Llm Sensitive Information Disclosure Malware Missing Update Privilege Escalation SSRF Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-19206) CVE-2018-19206 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-12625) CVE-2020-12625 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-13964) CVE-2020-13964 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-13965) CVE-2020-13965 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-15562) CVE-2020-15562 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-16145) CVE-2020-16145 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-18670) CVE-2020-18670 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-18671) CVE-2020-18671 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-35730) CVE-2020-35730 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-26925) CVE-2021-26925 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-44025) CVE-2021-44025 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-46144) CVE-2021-46144 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-5631) CVE-2023-5631 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-43770) CVE-2023-43770 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-47272) CVE-2023-47272 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-37383) CVE-2024-37383 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-37384) CVE-2024-37384 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-42008) CVE-2024-42008 CWE-707 CWE-707 Critical Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-42009) CVE-2024-42009 CWE-707 CWE-707 Critical Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-68461) CVE-2025-68461 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-35539) CVE-2026-35539 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Vulnerability (CVE-2024-57004) CVE-2024-57004 CWE-707 CWE-707 Medium Roundcube Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2024-37385) CVE-2024-37385 CWE-138 CWE-138 Critical Roundcube Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2013-6172) CVE-2013-6172 CWE-138 CWE-138 High Roundcube Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-44026) CVE-2021-44026 CWE-138 CWE-138 Critical Roundcube Improper Privilege Management Vulnerability (CVE-2017-8114) CVE-2017-8114 CWE-269 CWE-269 High Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35540) CVE-2026-35540 CWE-669 CWE-669 Medium Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35542) CVE-2026-35542 CWE-669 CWE-669 Medium Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35543) CVE-2026-35543 CWE-669 CWE-669 Medium Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35544) CVE-2026-35544 CWE-669 CWE-669 Medium Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35545) CVE-2026-35545 CWE-669 CWE-669 High Roundcube Multiple Buffer Overflow Vulnerabilities (CVE-2015-2181) CVE-2015-2181 High Roundcube Multiple Cross-site Request Forgery (CSRF) Vulnerabilities (CVE-2014-9587) CVE-2014-9587 Medium Roundcube Resource Management Errors Vulnerability (CVE-2008-5620) CVE-2008-5620 High Roundcube Resource Management Errors Vulnerability (CVE-2011-4078) CVE-2011-4078 Medium Roundcube security updates 0.8.6 and 0.7.3 CVE-2013-1904 CWE-22 CWE-22 High Roundcube Unspesificed Vulnerability (CVE-2018-9846) CVE-2018-9846 High Roundcube Unspesificed Vulnerability (CVE-2018-1000071) CVE-2018-1000071 High Roundcube Unspesificed Vulnerability (CVE-2019-10740) CVE-2019-10740 Medium Roundcube Unspesificed Vulnerability (CVE-2019-15237) CVE-2019-15237 High RSA Private Key Detected CWE-200 CWE-200 High Ruby 7PK - Security Features Vulnerability (CVE-2015-3900) CVE-2015-3900 Medium Ruby Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2026-46727) CVE-2026-46727 CWE-362 CWE-362 High Ruby Cryptographic Issues Vulnerability (CVE-2011-2686) CVE-2011-2686 Medium Ruby Cryptographic Issues Vulnerability (CVE-2012-5371) CVE-2012-5371 Medium Ruby Cryptographic Issues Vulnerability (CVE-2013-4073) CVE-2013-4073 Medium Ruby Cryptographic Issues Vulnerability (CVE-2013-4287) CVE-2013-4287 Medium Ruby Cryptographic Issues Vulnerability (CVE-2013-4363) CVE-2013-4363 Medium Ruby CVE-2018-16395 Vulnerability (CVE-2018-16395) CVE-2018-16395 Critical Ruby CVE-2018-16396 Vulnerability (CVE-2018-16396) CVE-2018-16396 High Ruby CVE-2019-15845 Vulnerability (CVE-2019-15845) CVE-2019-15845 Medium Ruby CVE-2021-41819 Vulnerability (CVE-2021-41819) CVE-2021-41819 High Ruby Double Free Vulnerability (CVE-2022-28738) CVE-2022-28738 CWE-415 CWE-415 Critical Ruby Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-31810) CVE-2021-31810 CWE-668 CWE-668 Medium Ruby Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-10933) CVE-2020-10933 CWE-200 CWE-200 Medium Ruby framework weak secret key CWE-693 CWE-693 High RubyGems 7PK - Security Features Vulnerability (CVE-2015-3900) CVE-2015-3900 Medium RubyGems Cryptographic Issues Vulnerability (CVE-2012-2126) CVE-2012-2126 Medium RubyGems Cryptographic Issues Vulnerability (CVE-2013-4287) CVE-2013-4287 Medium RubyGems Cryptographic Issues Vulnerability (CVE-2013-4363) CVE-2013-4363 Medium RubyGems Deserialization of Untrusted Data Vulnerability (CVE-2017-0903) CVE-2017-0903 CWE-502 CWE-502 Critical RubyGems Deserialization of Untrusted Data Vulnerability (CVE-2018-1000074) CVE-2018-1000074 CWE-502 CWE-502 High RubyGems Improper Authentication Vulnerability (CVE-2022-36073) CVE-2022-36073 CWE-287 CWE-287 High RubyGems Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-0899) CVE-2017-0899 CWE-94 CWE-94 Critical RubyGems Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-8324) CVE-2019-8324 CWE-94 CWE-94 High RubyGems Improper Input Validation Vulnerability (CVE-2015-4020) CVE-2015-4020 CWE-20 CWE-20 Medium RubyGems Improper Input Validation Vulnerability (CVE-2017-0900) CVE-2017-0900 CWE-20 CWE-20 High RubyGems Improper Input Validation Vulnerability (CVE-2017-0901) CVE-2017-0901 CWE-20 CWE-20 High RubyGems Improper Input Validation Vulnerability (CVE-2018-1000077) CVE-2018-1000077 CWE-20 CWE-20 Medium RubyGems Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-1000079) CVE-2018-1000079 CWE-22 CWE-22 Medium RubyGems Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-8320) CVE-2019-8320 CWE-22 CWE-22 High RubyGems Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2018-1000073) CVE-2018-1000073 CWE-59 CWE-59 High RubyGems Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') Vulnerability (CVE-2019-8321) CVE-2019-8321 CWE-707 CWE-707 High RubyGems Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-1000078) CVE-2018-1000078 CWE-707 CWE-707 Medium RubyGems Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2019-8322) CVE-2019-8322 CWE-138 CWE-138 High 1...175176177178...327 176 / 327