Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

759
Quick preset (or use dates below)
Clear Filters
Showing 61 - 80 of 212 CVEs
CVE-2026-32492 MEDIUM - 5.3

Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue affects My Tickets: from n/a through <= 2.1.1.

Vendor: Joe Dolson
Product: My Tickets
Published: Mar 25, 2026
Source: NVD
CVE-2026-4533 MEDIUM - 6.3

A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-tickets.php. The manipulation of the argument Status results in sql injection. It is possible to launch the attack remotely. The exploit is now public a...

Published: Mar 22, 2026
Source: NVD
CVE-2026-33291 MEDIUM - 5.4

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators can create Zendesk tickets for topics they do not have access to view. This affects all forums that use the Zendesk plugin. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 cont...

Vendor: discourse
Product: discourse
Published: Mar 20, 2026
Source: NVD
CVE-2026-22203 MEDIUM - 4.9

wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expose OAuth secrets by exporting plugin options as JSON. Attackers can obtain exported files containing plaintext API secrets like fbAppSecret, googleClientSecret, twitterAppSecret, a...

Vendor: gVectors
Product: wpDiscuz
Published: Mar 13, 2026
Source: NVD
CVE-2026-27406 HIGH - 7.5

Insertion of Sensitive Information Into Sent Data vulnerability in Joe Dolson My Tickets my-tickets allows Retrieve Embedded Sensitive Data.This issue affects My Tickets: from n/a through <= 2.1.0.

Vendor: Joe Dolson
Product: My Tickets
Published: Mar 05, 2026
Source: NVD
CVE-2026-2750 CRITICAL - 9.1

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.

Published: Feb 27, 2026
Source: NVD
CVE-2026-2749 CRITICAL - 9.9

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.

Published: Feb 27, 2026
Source: NVD
CVE-2026-27744 CRITICAL - 9.8

The SPIP tickets plugin versions prior toΒ 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later rendered by a template using unfiltered environment rendering ...

Vendor: SPIP
Product: tickets
Published: Feb 25, 2026
Source: NVD
CVE-2025-70141 CRITICAL - 9.4

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker ...

Vendor: oretnom23
Product: customer_support_system
Published: Feb 18, 2026
Source: NVD
CVE-2025-12356 MEDIUM - 4.3

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_change_ticket_status' AJAX endpoint in all versions up to, and including, 3.5.6.4. This makes it possible for authenticat...

Vendor: tickera
Product: Tickera – Sell Tickets & Manage Events
Published: Feb 18, 2026
Source: NVD
CVE-2026-2545 LOW - 3.5

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the pub...

Vendor: ligerosmart
Product: ligerosmart
Published: Feb 16, 2026
Source: NVD
CVE-2026-1251 MEDIUM - 5.4

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.4 via the 'add_reply' function due to missing validation on a user controlled key. This makes it possible for au...

Published: Jan 31, 2026
Source: NVD
CVE-2025-68015 CRITICAL - 9.0

Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.3.

Vendor: Vollstart
Product: Event Tickets with Ticket Scanner
Published: Jan 22, 2026
Source: NVD
CVE-2025-14507 MEDIUM - 5.3

The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.0 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive booking data including user names, ema...

Published: Jan 13, 2026
Source: NVD

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently s...

Published: Jan 12, 2026
Source: NVD
CVE-2025-14657 HIGH - 7.2

The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for u...

Published: Jan 09, 2026
Source: NVD
CVE-2025-14034 MEDIUM - 5.3

The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'delete_single_ticket_callback' and 'change_ticket_status_callback' functions in all versions up to, and including,...

Published: Jan 06, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix racy bitfield write in btrfs_clear_space_info_full() From the memory-barriers.txt document regarding memory barrier ordering guarantees: (*) These guarantees do not apply to bitfields, because compilers often gen...

Published: Dec 24, 2025
Source: NVD
CVE-2025-64641 MEDIUM - 4.1

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted...

Vendor: mattermost
Product: mattermost_server
Published: Dec 24, 2025
Source: NVD

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Notification rules, Open tickets module) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before ...

Published: Dec 22, 2025
Source: NVD