Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-26846 An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata. Znuny after 7.1.3 Fix from $2,3002025-05-12 CRITICAL 9.8 CVE-2025-26845 An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command e… Znuny after 7.1.3 Fix from $2,3002025-05-08 HIGH 7.5 CVE-2025-26847 An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked. Znuny after 7.1.6 Fix from $1,9502025-05-08 MEDIUM 6.1 CVE-2025-43926 An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subaction can be used to … Znuny after 7.1.6 Fix from $1,6002025-05-08 CRITICAL 9.8 CVE-2025-26844 An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag. Znuny after 7.1.3 Fix from $2,3002025-05-08 HIGH 7.5 CVE-2025-26842 An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to use… Znuny after 7.1.3 Fix from $1,9502025-05-08 HIGH 7.5 CVE-2024-48938 Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied fr… Znuny 6.1.0+ Fix from $1,9502024-10-11 MEDIUM 6.1 CVE-2024-48937 Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dial… Znuny 6.1.0+ Fix from $1,6002024-10-11 CRITICAL 9.8 CVE-2024-32491 An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a ma… Znuny after 7.0.16 Fix from $2,3002024-04-29 HIGH 8.8 CVE-2024-32493 An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft fo… Znuny after 7.0.16 Fix from $1,9502024-04-29 HIGH 7.1 CVE-2024-32492 An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript. Znuny after 7.0.16 Fix from $1,9502024-04-29