Tagged “cve.org”
CVEs tagged cve.org, newest first.
15461 CVEsRSS
CVE-2026-97064Critical· 9.1X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emai…
CVE-2026-97060High· 7.2X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords …
CVE-2026-100192Medium· 6.5X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering
X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send ar…
CVE-2026-84460Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag names for the given ticket, regardless of whether they have …
CVE-2026-63205Medium· 5.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img t…
CVE-2026-84463Medium· 6.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a specially crafted value. When the answer i…
CVE-2026-63206Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email views, can be bypassed using a shortened URL format that omits the doubl…
CVE-2026-63216Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, t…
CVE-2026-84465High· 7.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it onl…
CVE-2026-63207Medium· 6.9Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses d…
CVE-2026-63006Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer using path traversal sequences. When an authenticated agent vi…
CVE-2026-49469Medium· 4.6GLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter…
CVE-2026-97896Low· 3.5A vulnerability was identified in krayin laravel-crm up to 2.2.5
A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Function…
CVE-2026-53628Medium· 5.9GLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable two-factor…
CVE-2026-45801Medium· 5.3GLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the privilege bou…
CVE-2026-55214High· 8.5GLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored …
CVE-2026-53610High· 7.5GLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL …
CVE-2026-49470High· 7.7GLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentic…
CVE-2026-53626High· 7.1GLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can …
CVE-2026-48482Critical· 9.4GLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The i…
CVE-2026-97895Medium· 6.3PoCA vulnerability was determined in krayin laravel-crm up to 2.2.5
A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing a manipulation …
CVE-2026-97063Critical· 9.1PoCX-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners
X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobil…
CVE-2026-53629High· 7.1PoCGLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This…
CVE-2026-97897Low· 3.5A security flaw has been discovered in Krayin laravel-crm up to 2.2.5
A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The atta…
CVE-2026-84461Medium· 6.9Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The…
CVE-2026-63204Low· 2.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identifier to the ticket summarize endpoint and receive the AI prov…
CVE-2026-63208Medium· 5.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the mailbox. The system attempts to hide th…
CVE-2026-100304Medium· 5.3TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions
TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphane…
CVE-2026-100303Medium· 5.4TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories
TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms o…
CVE-2026-84464High· 7.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a speci…