Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-97883 — mathurvishal CloudClassroom-PHP-Project updatequery.php sql injection

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The…

Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-97882 — mathurvishal CloudClassroom-PHP-Project Faculty Authentication loginlinkfaculty.php sql i…

A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php …

Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.4 MEDIUM
CVE-2026-93366 — Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endpoints

Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other use…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.8 HIGH
CVE-2026-91841 — Networkmanager-vpnc: networkmanager-vpnc: incomplete fix for cve-2018-10900 allows root p…

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipul…

| Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.8 HIGH
CVE-2026-91840 — Networkmanager-vpnc: networkmanager-vpnc: local privilege escalation to root via newline …

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker …

| Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.8 HIGH
CVE-2026-91839 — Networkmanager-fortisslvpn: networkmanager-fortisslvpn: local privilege escalation to roo…

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection…

| Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.8 HIGH
CVE-2026-91838 — Networkmanager-sstp: networkmanager-sstp: local privilege escalation to root via shell in…

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacter…

| Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.6 HIGH
CVE-2026-84462 — Zammad: AI Agent template sanitizer bypass leads to remote code execution

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text …

Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
2.3 LOW
CVE-2026-65828 — Zammad: Pending upload deletion bypass via legacy attachment endpoint

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-su…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.8 HIGH
CVE-2026-61525 — Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Contro…

Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attac…

Remote | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-56735 — Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammad

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in to prevent remote content loadin…

Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-56734 — Zammad: Avatar Image URL Server-Side Request Forwarding

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity provider is fetch…

Remote | Server-Side Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.7 HIGH
CVE-2026-56733 — Zammad: Incorrect Authorization and Improper Privilege Management

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determi…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-56732 — Zammad: Malicious input in Ticket Body Enables Session Termination

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into ticket bodies. When ano…

Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.4 HIGH
CVE-2026-56731 — Zammad: Cross-Site Scripting in Ticket Notifications

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event handlers, into a ti…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
2.1 LOW
CVE-2026-56730 — Zammad: Missing authorization in GraphQL mutation for suggesting knowledge base answers

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer co…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-56728 — Zammad: Cross-User Taskbar Item Access Control Vulnerability

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vulnerability exists in Zammad's GraphQL API. An authenticated user can access taskbar item…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.1 HIGH
CVE-2026-56727 — Zammad: PGP signature spoofing via unvalidated verification return

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP email processing, the return value of the gpg verification call was silently discar…

Remote | Cryptography
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-56726 — Zammad: Missing authorization check in GitHub + GitLab integration allows cross-ticket da…

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation boundaries between agents. Any authenticated agent, even one with…

Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.7 HIGH
CVE-2026-56725 — Zammad: Denial of Service via OTRS Import Controller

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST /api/v1/import/otrs/import_check blocks a Zammad request worker for roug…

Remote | Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14494 Results