Common Vulnerabilities and Exposures (CVE)

CVE-2026-90959

Sep 25, 2026 17:47:42 UTC

A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validatio...

CVE-2026-67410

Sep 25, 2026 17:46:42 UTC

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint (CWE-200). when OAuth2 authentication is enabled for the RabbitMQ Management UI and the con...

CVE-2026-56724

Sep 25, 2026 17:45:13 UTC

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area has been identified. Under certain conditions, data validation for linked item...

CVE-2026-97885

Sep 25, 2026 17:45:06 UTC

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument fid causes sql injection. The ...

CVE-2026-56723

Sep 25, 2026 17:44:24 UTC

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who can view a ticket cannot see internal ticket articles through the article listing API. However, the same customer can directly request an att...

CVE-2026-93364

Sep 25, 2026 17:42:59 UTC

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save reques...

CVE-2026-56727

Sep 25, 2026 17:42:09 UTC

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP email processing, the return value of the gpg verification call was silently discarded. Regardless of whether gpg reported a...

CVE-2026-56732

Sep 25, 2026 17:41:20 UTC

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into ticket bodies. When another user views the crafted ticket, the i...

CVE-2026-61525

Sep 25, 2026 17:31:01 UTC

Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the cl...

CVE-2026-97884

Sep 25, 2026 17:30:10 UTC

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestudent.php of the component Student Update Functionality. The manipu...

CVE-2026-84462

Sep 25, 2026 17:29:15 UTC

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An admi...

CVE-2026-65828

Sep 25, 2026 17:28:13 UTC

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-supplied form_id without verifying that the...

CVE-2026-97883

Sep 25, 2026 17:27:48 UTC

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The manipulation of the argument gid leads t...

CVE-2026-32157

Sep 25, 2026 17:26:30 UTC

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-26174

Sep 25, 2026 17:26:29 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.