Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54449
Total
4308
Critical
16178
High
15893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97895 | MEDIUM | 6.3 | A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing … | Sep 25, 2026 |
| CVE-2026-97064 | CRITICAL | 9.1 | X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as … | Sep 25, 2026 |
| CVE-2026-97063 | CRITICAL | 9.1 | X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers … | Sep 25, 2026 |
| CVE-2026-97060 | HIGH | 7.2 | X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can … | Sep 25, 2026 |
| CVE-2026-84465 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it … | Sep 25, 2026 |
| CVE-2026-84464 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an … | Sep 25, 2026 |
| CVE-2026-84463 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed … | Sep 25, 2026 |
| CVE-2026-84461 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for … | Sep 25, 2026 |
| CVE-2026-84460 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag … | Sep 25, 2026 |
| CVE-2026-84458 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad … | Sep 25, 2026 |
| CVE-2026-63216 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents … | Sep 25, 2026 |
| CVE-2026-63208 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the … | Sep 25, 2026 |
| CVE-2026-63207 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through … | Sep 25, 2026 |
| CVE-2026-63206 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email … | Sep 25, 2026 |
| CVE-2026-63205 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced … | Sep 25, 2026 |
| CVE-2026-63204 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics … | Sep 25, 2026 |
| CVE-2026-63006 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL … | Sep 25, 2026 |
| CVE-2026-61855 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark … | Sep 25, 2026 |
| CVE-2026-55217 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete … | Sep 25, 2026 |
| CVE-2026-55214 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. … | Sep 25, 2026 |
| CVE-2026-53629 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can … | Sep 25, 2026 |
| CVE-2026-53628 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or … | Sep 25, 2026 |
| CVE-2026-53627 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to … | Sep 25, 2026 |
| CVE-2026-53626 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document … | Sep 25, 2026 |
| CVE-2026-53625 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the … | Sep 25, 2026 |