CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-102490 CRITICAL

Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha

CVSS 9.4 EPSS 0.32% Sep 30, 2026
CVE-2026-102489 CRITICAL

Undisclosed RCE in Zammad v6.3 and higher

CVSS 9.4 EPSS 0.71% Sep 30, 2026
CVE-2026-63208 MEDIUM

Zammad: Microsoft Graph error logs expose partially masked OAuth access tokens

CVSS 5.1 EPSS 0.31% Sep 25, 2026
CVE-2026-63006 MEDIUM

Zammad: HTML sanitizer API path allowlist bypass via interior path traversal in img src/srcset

CVSS 5.3 EPSS 0.48% Sep 25, 2026
CVE-2026-63204 LOW

Zammad: Authenticated agents can read AI summary error messages from inaccessible tickets

CVSS 2.3 EPSS 0.29% Sep 25, 2026
CVE-2026-61855 MEDIUM

Zammad: Invalid PGP Detached Signatures Reported as Good Signature on Inbound Mail

CVSS 5.3 EPSS 0.21% Sep 25, 2026
CVE-2026-84461 MEDIUM

Zammad: Missing rate limiting allows password brute-forcing during two-factor login

CVSS 6.9 EPSS 0.32% Sep 25, 2026
CVE-2026-63207 MEDIUM

Zammad: Sensitive Information Exposure in Integration Administration API

CVSS 6.9 EPSS 0.17% Sep 25, 2026
CVE-2026-84465 HIGH

Zammad: S/MIME signature verification allows forged sender impersonation

CVSS 7.1 EPSS 0.12% Sep 25, 2026
CVE-2026-84463 MEDIUM

Zammad: Stored HTML injection in Knowledge Base video widget enables forced session switching via unescaped iframe attribute

CVSS 6.3 EPSS 0.15% Sep 25, 2026
CVE-2026-84464 HIGH

Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organization data

CVSS 7.1 EPSS 0.29% Sep 25, 2026
CVE-2026-63216 MEDIUM

Zammad: Stored XSS via unescaped option labels in the object attribute options context UI

CVSS 5.3 EPSS 0.24% Sep 25, 2026
CVE-2026-84458 CRITICAL

Zammad: Account takeover via unverified email matching during SSO auto-link

CVSS 9.1 EPSS 0.36% Sep 25, 2026
CVE-2026-84460 MEDIUM

Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag Enumeration

CVSS 5.3 EPSS 0.26% Sep 25, 2026
CVE-2026-63206 MEDIUM

Zammad: Remote image tracking bypass via shortened URL scheme

CVSS 5.3 EPSS 0.28% Sep 25, 2026
CVE-2026-63205 MEDIUM

Zammad: Channel admins can read unauthorized attachments via signature rich-text body

CVSS 5.1 EPSS 0.32% Sep 25, 2026
CVE-2026-84462 HIGH

Zammad: AI Agent template sanitizer bypass leads to remote code execution

CVSS 8.6 EPSS 0.28% Sep 25, 2026
CVE-2026-65828 LOW

Zammad: Pending upload deletion bypass via legacy attachment endpoint

CVSS 2.3 EPSS 0.20% Sep 25, 2026
CVE-2026-61525 HIGH

Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller

CVSS 8.8 EPSS 0.36% Sep 25, 2026
CVE-2026-56728 MEDIUM

Zammad: Cross-User Taskbar Item Access Control Vulnerability

CVSS 5.3 EPSS 0.33% Sep 25, 2026
CVE-2026-56725 HIGH

Zammad: Denial of Service via OTRS Import Controller

CVSS 8.7 EPSS 0.41% Sep 25, 2026
CVE-2026-56732 MEDIUM

Zammad: Malicious input in Ticket Body Enables Session Termination

CVSS 5.3 EPSS 0.20% Sep 25, 2026
CVE-2026-56730 LOW

Zammad: Missing authorization in GraphQL mutation for suggesting knowledge base answers

CVSS 2.1 EPSS 0.35% Sep 25, 2026
CVE-2026-56733 HIGH

Zammad: Incorrect Authorization and Improper Privilege Management

CVSS 8.7 EPSS 0.27% Sep 25, 2026
CVE-2026-56731 HIGH

Zammad: Cross-Site Scripting in Ticket Notifications

CVSS 8.4 EPSS 0.24% Sep 25, 2026

Showing 1 to 25 CVEs · page 1 (more available)