Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54449
Total
4308
Critical
16178
High
15893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53610 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects … | Sep 25, 2026 |
| CVE-2026-49470 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions … | Sep 25, 2026 |
| CVE-2026-49469 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria … | Sep 25, 2026 |
| CVE-2026-48482 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration … | Sep 25, 2026 |
| CVE-2026-47679 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation … | Sep 25, 2026 |
| CVE-2026-45801 | UNKNOWN | — | GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable … | Sep 25, 2026 |
| CVE-2026-100306 | MEDIUM | 5.3 | TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can … | Sep 25, 2026 |
| CVE-2026-100305 | MEDIUM | 4.3 | TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a form's key … | Sep 25, 2026 |
| CVE-2026-100304 | MEDIUM | 5.3 | TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access … | Sep 25, 2026 |
| CVE-2026-100303 | MEDIUM | 5.4 | TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or … | Sep 25, 2026 |
| CVE-2026-100192 | MEDIUM | 6.5 | X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and … | Sep 25, 2026 |
| CVE-2026-97886 | MEDIUM | 6.3 | A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file managevideos2.php. Such manipulation … | Sep 25, 2026 |
| CVE-2026-97885 | HIGH | 7.3 | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument … | Sep 25, 2026 |
| CVE-2026-97884 | MEDIUM | 6.3 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestudent.php of the component Student Update Functionality. … | Sep 25, 2026 |
| CVE-2026-97883 | HIGH | 7.3 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The manipulation of the … | Sep 25, 2026 |
| CVE-2026-97882 | HIGH | 7.3 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php of the component … | Sep 25, 2026 |
| CVE-2026-93366 | MEDIUM | 5.4 | Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to … | Sep 25, 2026 |
| CVE-2026-91841 | HIGH | 7.8 | A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into … | Sep 25, 2026 |
| CVE-2026-91840 | HIGH | 7.8 | A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the … | Sep 25, 2026 |
| CVE-2026-91839 | HIGH | 7.8 | A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local … | Sep 25, 2026 |
| CVE-2026-91838 | HIGH | 7.8 | A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known … | Sep 25, 2026 |
| CVE-2026-84462 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed … | Sep 25, 2026 |
| CVE-2026-65828 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely … | Sep 25, 2026 |
| CVE-2026-61525 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to … | Sep 25, 2026 |
| CVE-2026-56735 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in to prevent … | Sep 25, 2026 |