CVE-2026-82973Critical· 9.4▾ MidnightImproper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP command…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100717Critical· 9.9froxlor is a server administration panel
CVE-2026-91839High· 7.8A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager
CVE-2026-91840High· 7.8A flaw was found in NetworkManager-vpnc
CVE-2026-91841High· 7.8A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager
CVE-2026-61815High· 7.2zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822
CVE-2026-90990Medium· 5.3Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions i…