Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54449
Total
4308
Critical
16178
High
15893
Medium
CVE ID Severity Score Description Published
CVE-2026-97895 MEDIUM 6.3 A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing … Sep 25, 2026
CVE-2026-97064 CRITICAL 9.1 X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as … Sep 25, 2026
CVE-2026-97063 CRITICAL 9.1 X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers … Sep 25, 2026
CVE-2026-97060 HIGH 7.2 X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can … Sep 25, 2026
CVE-2026-84465 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it … Sep 25, 2026
CVE-2026-84464 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an … Sep 25, 2026
CVE-2026-84463 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed … Sep 25, 2026
CVE-2026-84461 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for … Sep 25, 2026
CVE-2026-84460 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag … Sep 25, 2026
CVE-2026-84458 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad … Sep 25, 2026
CVE-2026-63216 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents … Sep 25, 2026
CVE-2026-63208 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the … Sep 25, 2026
CVE-2026-63207 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through … Sep 25, 2026
CVE-2026-63206 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email … Sep 25, 2026
CVE-2026-63205 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced … Sep 25, 2026
CVE-2026-63204 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics … Sep 25, 2026
CVE-2026-63006 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL … Sep 25, 2026
CVE-2026-61855 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark … Sep 25, 2026
CVE-2026-55217 UNKNOWN — GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete … Sep 25, 2026
CVE-2026-55214 UNKNOWN — GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. … Sep 25, 2026
CVE-2026-53629 UNKNOWN — GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can … Sep 25, 2026
CVE-2026-53628 UNKNOWN — GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or … Sep 25, 2026
CVE-2026-53627 UNKNOWN — GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to … Sep 25, 2026
CVE-2026-53626 UNKNOWN — GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document … Sep 25, 2026
CVE-2026-53625 UNKNOWN — GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the … Sep 25, 2026