Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-100306 — TDuck survey form through 6.0 Write Password Bypass via Client-Side Enforcement

TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit form entries directly t…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-100305 — TDuck survey form through 6.0 Fill-In Restriction Bypass via Authenticated Submission End…

TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a form's key can submit…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.0 MEDIUM
CVE-2026-100304 — TDuck survey form 6.0 Information Disclosure via Fail-Open Form Ownership Check

TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form s…

Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.4 MEDIUM
CVE-2026-100303 — TDuck survey form through 6.0 Missing Authorization in Form Theme Management Endpoints

TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes …

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-97897 — Krayin laravel-crm TinyMCE Media Upload Sanitizer.php cross site scripting

A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation res…

| Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-53629 — GLPI: SQL injection in history tab

GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-control…

glpi | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-53626 — GLPI: Arbitrary Document Read via Form Context Authorization Bypass

GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is li…

glpi | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-48482 — GLPI: RCE via Form import

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the …

glpi | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-53625 — GLPI: Privilege Escalation via authtype API manipulation

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication met…

glpi | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-53610 — GLPI: Reflected XSS in dashboards

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encod…

glpi | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-47679 — GLPI: arbitrary file deletion

GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to r…

glpi | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-55214 — GLPI: Stored XSS in suppliers

GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item…

glpi | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-49470 — GLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover via Brute F…

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who h…

glpi | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-97896 — krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross site scripting

A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationFor…

| Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-55217 — GLPI: Unallowed modfication of knowbase items comments and translations

GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations…

glpi | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-53628 — GLPI: Unallowed authentication method update by administrator

GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authen…

glpi | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-45801 — GLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation)

GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting upd…

glpi | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-53627 — GLPI: Unexpected access to update operations through the API

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is norm…

glpi | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-49469 — GLPI: LDAP filter injection in user import feature

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to byp…

glpi | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-63208 — Zammad: Microsoft Graph error logs expose partially masked OAuth access tokens

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the m…

| Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14512 Results