Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2025-68461 | Roundcube | Webmail | RoundCube Webmail Cross-site Scripting Vulnerability RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. | 7.2 CNA | 2026-02-20 | 2026-03-13 | Unknown |
| CVE-2025-49113 | Roundcube | Webmail | RoundCube Webmail Deserialization of Untrusted Data Vulnerability RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. | 9.9 CNA | 2026-02-20 | 2026-03-13 | Unknown |
| CVE-2024-42009 | Roundcube | Webmail | RoundCube Webmail Cross-Site Scripting Vulnerability RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. | 9.3 CISA | 2025-06-09 | 2025-06-30 | Unknown |
| CVE-2024-37383 | Roundcube | Webmail | RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code. | 6.1 CISA | 2024-10-24 | 2024-11-14 | Unknown |
| CVE-2020-13965 | Roundcube | Webmail | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment. | 6.3 CISA | 2024-06-26 | 2024-07-17 | Unknown |
| CVE-2023-43770 | Roundcube | Webmail | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages. | 6.1 CISA | 2024-02-12 | 2024-03-04 | Unknown |
| CVE-2023-5631 | Roundcube | Webmail | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code. | 6.1 CNA | 2023-10-26 | 2023-11-16 | Unknown |
| CVE-2021-44026 | Roundcube | Roundcube Webmail | Roundcube Webmail SQL Injection Vulnerability Roundcube Webmail is vulnerable to SQL injection via search or search_params. | 9.8 CISA | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2020-12641 | Roundcube | Roundcube Webmail | Roundcube Webmail Remote Code Execution Vulnerability Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | 9.8 CISA | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2020-35730 | Roundcube | Roundcube Webmail | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php. | 6.1 CISA | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2017-16651 | Roundcube | Roundcube Webmail | Roundcube Webmail File Disclosure Vulnerability Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |