Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54449
Total
4308
Critical
16178
High
15893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56734 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity … | Sep 25, 2026 |
| CVE-2026-56733 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the … | Sep 25, 2026 |
| CVE-2026-56732 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into … | Sep 25, 2026 |
| CVE-2026-56731 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event … | Sep 25, 2026 |
| CVE-2026-56730 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to … | Sep 25, 2026 |
| CVE-2026-56728 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vulnerability exists in Zammad's GraphQL API. An authenticated … | Sep 25, 2026 |
| CVE-2026-56727 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP email processing, the return value of the … | Sep 25, 2026 |
| CVE-2026-56726 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation boundaries between agents. Any authenticated agent, … | Sep 25, 2026 |
| CVE-2026-56725 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST /api/v1/import/otrs/import_check blocks a Zammad request worker … | Sep 25, 2026 |
| CVE-2026-97879 | MEDIUM | 5.3 | A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the … | Sep 25, 2026 |
| CVE-2026-97878 | HIGH | 7.3 | A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such … | Sep 25, 2026 |
| CVE-2026-97877 | HIGH | 7.3 | A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token … | Sep 25, 2026 |
| CVE-2026-97871 | HIGH | 7.3 | A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. … | Sep 25, 2026 |
| CVE-2026-95835 | UNKNOWN | — | Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal … | Sep 25, 2026 |
| CVE-2026-95834 | UNKNOWN | — | Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to … | Sep 25, 2026 |
| CVE-2026-94445 | HIGH | 8.8 | A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible … | Sep 25, 2026 |
| CVE-2026-93365 | MEDIUM | 6.5 | Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of … | Sep 25, 2026 |
| CVE-2026-93364 | MEDIUM | 4.3 | Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators … | Sep 25, 2026 |
| CVE-2026-93363 | MEDIUM | 4.3 | The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route … | Sep 25, 2026 |
| CVE-2026-91837 | HIGH | 7.8 | A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting … | Sep 25, 2026 |
| CVE-2026-89032 | HIGH | 7.7 | BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses … | Sep 25, 2026 |
| CVE-2026-80432 | UNKNOWN | — | Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the … | Sep 25, 2026 |
| CVE-2026-67421 | UNKNOWN | — | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an … | Sep 25, 2026 |
| CVE-2026-67420 | UNKNOWN | — | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAuth credential refresh retains revoked runtime tags. when … | Sep 25, 2026 |
| CVE-2026-67419 | UNKNOWN | — | RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to … | Sep 25, 2026 |