Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54449
Total
4308
Critical
16178
High
15893
Medium
CVE ID Severity Score Description Published
CVE-2026-53610 UNKNOWN — GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects … Sep 25, 2026
CVE-2026-49470 UNKNOWN — GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions … Sep 25, 2026
CVE-2026-49469 UNKNOWN — GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria … Sep 25, 2026
CVE-2026-48482 UNKNOWN — GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration … Sep 25, 2026
CVE-2026-47679 UNKNOWN — GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation … Sep 25, 2026
CVE-2026-45801 UNKNOWN — GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable … Sep 25, 2026
CVE-2026-100306 MEDIUM 5.3 TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can … Sep 25, 2026
CVE-2026-100305 MEDIUM 4.3 TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a form's key … Sep 25, 2026
CVE-2026-100304 MEDIUM 5.3 TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access … Sep 25, 2026
CVE-2026-100303 MEDIUM 5.4 TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or … Sep 25, 2026
CVE-2026-100192 MEDIUM 6.5 X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and … Sep 25, 2026
CVE-2026-97886 MEDIUM 6.3 A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file managevideos2.php. Such manipulation … Sep 25, 2026
CVE-2026-97885 HIGH 7.3 A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument … Sep 25, 2026
CVE-2026-97884 MEDIUM 6.3 A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestudent.php of the component Student Update Functionality. … Sep 25, 2026
CVE-2026-97883 HIGH 7.3 A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The manipulation of the … Sep 25, 2026
CVE-2026-97882 HIGH 7.3 A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php of the component … Sep 25, 2026
CVE-2026-93366 MEDIUM 5.4 Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to … Sep 25, 2026
CVE-2026-91841 HIGH 7.8 A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into … Sep 25, 2026
CVE-2026-91840 HIGH 7.8 A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the … Sep 25, 2026
CVE-2026-91839 HIGH 7.8 A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local … Sep 25, 2026
CVE-2026-91838 HIGH 7.8 A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known … Sep 25, 2026
CVE-2026-84462 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed … Sep 25, 2026
CVE-2026-65828 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely … Sep 25, 2026
CVE-2026-61525 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to … Sep 25, 2026
CVE-2026-56735 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in to prevent … Sep 25, 2026