VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25132 CVEsRSS

CVE-2026-56733High· 8.7
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determined that the system-level enforcement …

▾ Twilightzammad · zammadEPSS 0.27%via NVD
CVE-2026-56726Medium· 5.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation boundaries between agents. Any authenticated agent, even one with no active tickets assigned to them, c…

▾ Sunlitzammad · zammadEPSS 0.34%via NVD
CVE-2026-56735Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in to prevent remote content loading, but the srcset attribute, also allo…

▾ Sunlitzammad · zammadEPSS 0.42%via NVD
CVE-2026-56731High· 8.4
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event handlers, into a ticket title via the standard ticket cre…

▾ Twilightzammad · zammadEPSS 0.24%via NVD
CVE-2026-56730Low· 2.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to acces…

▾ Sunlitzammad · zammadEPSS 0.35%via NVD
CVE-2026-56728Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vulnerability exists in Zammad's GraphQL API. An authenticated user can access taskbar item data belonging to another user by cra…

▾ Sunlitzammad · zammadEPSS 0.33%via NVD
CVE-2026-56725High· 8.7
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST /api/v1/import/otrs/import_check blocks a Zammad request worker for roughly two minutes. The import_check and …

▾ Twilightzammad · zammadEPSS 0.41%via NVD
CVE-2026-97883High· 7.3PoC
2d ago

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The manipulation of the argument gid lead…

▾ Midnightmathurvishal · CloudClassroom-PHP-ProjectEPSS 0.31%via NVD
CVE-2026-84462High· 8.6
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An a…

▾ Twilightzammad · zammadEPSS 0.28%via NVD
CVE-2026-65828Low· 2.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-supplied form_id without verifying that …

▾ Sunlitzammad · zammadEPSS 0.20%via NVD
CVE-2026-97884Medium· 6.3PoC
2d ago

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestudent.php of the component Student Update Functionality. The man…

▾ Twilightmathurvishal · CloudClassroom-PHP-ProjectEPSS 0.19%via NVD
CVE-2026-61525High· 8.8
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the…

▾ Twilightzammad · zammadEPSS 0.36%via NVD
CVE-2026-56732Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into ticket bodies. When another user views the crafted ticket, th…

▾ Sunlitzammad · zammadEPSS 0.20%via NVD
CVE-2026-56727High· 7.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP email processing, the return value of the gpg verification call was silently discarded. Regardless of whether gpg reporte…

▾ Twilightzammad · zammadEPSS 0.25%via NVD
CVE-2026-91839High· 7.8PoC
2d ago

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivil…

▾ MidnightGNOME · network-manager-fortisslvpnEPSS 0.20%via NVD
CVE-2026-91838High· 7.8
2d ago

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields …

▾ TwilightGNOME · network-manager-sstpEPSS 0.10%via NVD
CVE-2026-91841High· 7.8PoC
2d ago

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbit…

▾ MidnightGNOME · network-manager-vpncEPSS 0.19%via NVD
CVE-2026-91840High· 7.8PoC
2d ago

A flaw was found in NetworkManager-vpnc

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration …

▾ MidnightGNOME · network-manager-vpncEPSS 0.19%via NVD
CVE-2026-97886Medium· 6.3
2d ago

A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file managevideos2.php. Such manipulation of the …

▾ Sunlitmathurvishal · CloudClassroom-PHP-ProjectEPSS 0.30%via NVD
CVE-2026-97885High· 7.3PoC
2d ago

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument fid causes sql injection. T…

▾ Midnightmathurvishal · CloudClassroom-PHP-ProjectEPSS 0.26%via NVD
CVE-2026-67222Medium· 5.9
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, mechanisms/1 applied list_to_atom/1 to every colon-delimited token in an attacker-controlled auth_mechanism value, permanently consuming …

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.31%via NVD
CVE-2026-89032High· 7.7
2d ago

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_s…

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_s…

▾ TwilightBerriAI · litellmEPSS 0.27%via NVD
CVE-2026-67234Low· 2.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, get_auth_mechanism/1 used term_to_binary/1 on the strict_auth_mechanism or preferred_auth_mechanism atom when clearing the corresponding cookie, producing a …

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.56%via NVD
CVE-2026-67230Medium· 6.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the Web STOMP WebSocket handler enforced neither max_frame_size nor login_timeout before authentication, allowing an unauthenticated clie…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.47%via NVD
CVE-2026-67237High· 7.5
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a bearer token from the Authorization header or access_token cookie into OAuth bootstrap JavaScript without escaping, allowing atta…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.48%via NVD
CVE-2026-66078Low· 2.1
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, protected tag bypass via bulk-delete. dELETE /api/users/:name refuses to delete users tagged protected (rabbitmgmtwmuser:deleteresou…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.36%via NVD
CVE-2026-66071Medium· 6.0
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom exhaustion: OAuth2 JWT tag: scope values. extractscopes/1 parses scopes of the form .tag: and calls rabbitdatacoercio…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.34%via NVD
CVE-2026-100248High· 8.4
2d ago

The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.

The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.

▾ TwilightRattadan · Cosmowarp ContractEPSS 0.40%via NVD
CVE-2026-67241Medium· 4.8
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, AMQP 1.0 management exchange.declare skips alternate-exchange permission check. pUT /exchanges/:name (lines 192-240) checks only configure on the declared ex…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVE-2026-67223Medium· 6.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance lines but contains conflicting first-fixed versions for the 3.13, 4.0, and 4.1 lines. fill/2 substitutes ${username}…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVEs tagged “nvd” — page 17 · VulnSea