VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15461 CVEsRSS

CVE-2026-55217Medium· 5.3
2d ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization fo…

▾ Sunlitglpi-project · glpiEPSS 0.31%via NVD
CVE-2026-53627Medium· 6.0
2d ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform through the …

▾ Sunlitglpi-project · glpiEPSS 0.31%via NVD
CVE-2026-84458Critical· 9.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account b…

▾ Midnightzammad · zammadEPSS 0.36%via NVD
CVE-2026-47679High· 8.5
2d ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of an attacker-selecte…

▾ Twilightglpi-project · glpiEPSS 0.32%via NVD
CVE-2026-100306Medium· 5.3
2d ago

TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end

TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit form entries directly to public submission APIs without provi…

▾ SunlitTDuckCloud · tduck-survey-formEPSS 0.39%via NVD
CVE-2026-61855Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a regi…

▾ Sunlitzammad · zammadEPSS 0.21%via NVD
CVE-2026-53625High· 7.5PoC
2d ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the le…

▾ Midnightglpi-project · glpiEPSS 0.57%via NVD
CVE-2026-100305Medium· 4.3PoC
2d ago

TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create

TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a form's key can submit unlimited entries to any form, bypass…

▾ TwilightTDuckCloud · tduck-survey-formEPSS 0.27%via NVD
CVE-2026-97882High· 7.3
2d ago

A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php of the component Faculty Authenticatio…

▾ Twilightmathurvishal · CloudClassroom-PHP-ProjectEPSS 0.51%via NVD
CVE-2026-93366Medium· 5.4
2d ago

Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other users, including administrators, by suppl…

Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other users, including administrators, by suppl…

▾ SunlitBludit · Bludit CMSEPSS 0.19%via NVD
CVE-2026-56734Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity provider is fetched without verifying the target addres…

▾ Sunlitzammad · zammadEPSS 0.40%via NVD
CVE-2026-56733High· 8.7
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determined that the system-level enforcement …

▾ Twilightzammad · zammadEPSS 0.27%via NVD
CVE-2026-56726Medium· 5.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation boundaries between agents. Any authenticated agent, even one with no active tickets assigned to them, c…

▾ Sunlitzammad · zammadEPSS 0.34%via NVD
CVE-2026-56735Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in to prevent remote content loading, but the srcset attribute, also allo…

▾ Sunlitzammad · zammadEPSS 0.42%via NVD
CVE-2026-56731High· 8.4
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event handlers, into a ticket title via the standard ticket cre…

▾ Twilightzammad · zammadEPSS 0.24%via NVD
CVE-2026-56730Low· 2.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to acces…

▾ Sunlitzammad · zammadEPSS 0.35%via NVD
CVE-2026-56728Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vulnerability exists in Zammad's GraphQL API. An authenticated user can access taskbar item data belonging to another user by cra…

▾ Sunlitzammad · zammadEPSS 0.33%via NVD
CVE-2026-56725High· 8.7
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST /api/v1/import/otrs/import_check blocks a Zammad request worker for roughly two minutes. The import_check and …

▾ Twilightzammad · zammadEPSS 0.41%via NVD
CVE-2026-97883High· 7.3PoC
2d ago

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The manipulation of the argument gid lead…

▾ Midnightmathurvishal · CloudClassroom-PHP-ProjectEPSS 0.31%via NVD
CVE-2026-84462High· 8.6
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An a…

▾ Twilightzammad · zammadEPSS 0.28%via NVD
CVE-2026-65828Low· 2.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-supplied form_id without verifying that …

▾ Sunlitzammad · zammadEPSS 0.20%via NVD
CVE-2026-97884Medium· 6.3PoC
2d ago

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestudent.php of the component Student Update Functionality. The man…

▾ Twilightmathurvishal · CloudClassroom-PHP-ProjectEPSS 0.19%via NVD
CVE-2026-61525High· 8.8
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the…

▾ Twilightzammad · zammadEPSS 0.36%via NVD
CVE-2026-56732Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into ticket bodies. When another user views the crafted ticket, th…

▾ Sunlitzammad · zammadEPSS 0.20%via NVD
CVE-2026-56727High· 7.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP email processing, the return value of the gpg verification call was silently discarded. Regardless of whether gpg reporte…

▾ Twilightzammad · zammadEPSS 0.25%via NVD
CVE-2026-91839High· 7.8PoC
2d ago

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivil…

▾ MidnightGNOME · network-manager-fortisslvpnEPSS 0.20%via NVD
CVE-2026-91838High· 7.8
2d ago

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields …

▾ TwilightGNOME · network-manager-sstpEPSS 0.10%via NVD
CVE-2026-91841High· 7.8PoC
2d ago

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbit…

▾ MidnightGNOME · network-manager-vpncEPSS 0.19%via NVD
CVE-2026-91840High· 7.8PoC
2d ago

A flaw was found in NetworkManager-vpnc

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration …

▾ MidnightGNOME · network-manager-vpncEPSS 0.19%via NVD
CVE-2026-97886Medium· 6.3
2d ago

A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file managevideos2.php. Such manipulation of the …

▾ Sunlitmathurvishal · CloudClassroom-PHP-ProjectEPSS 0.30%via NVD
CVEs tagged “cve.org” — page 16 · VulnSea