Vulnerabilities
359 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-24782 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuilder role to retrieve information on or modify other users' form definitions and some global configuration parameters. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2026-44314 | Traccar is an open source GPS tracking system. Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into mediaManager.createFileStream(...). Unlike the generic mutation path in BaseObjectResource.update and the explicit device mutation handler updateAccumulators, this route never invokes permissionsService.checkEdit(getUserId(), Device.class, false, false). The skipped guard is exactly where Traccar enforces readonly and deviceReadonly restrictions for non-admin users. An unauthorized user can replace a device’s stored image file under the server media directory. This allows modification of UI-visible device media and any downstream workflows that rely on the persisted image, despite other device update paths correctly rejecting the same identity. This vulnerability is fixed in 6.13.0. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-27644 | Traccar is an open source GPS tracking system. Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fields. When a manager or administrator opens the exported CSV file in spreadsheet software, this can cause formula execution and lead to command execution or data exfiltration. This has been patched in version 6.13.0. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2026-29092 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorized access to continue until the session naturally expires. Upgrade Kiteworks to version 9.2.1 or later to receive a patch. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2026-27895 +1 in the same advisory: …27894 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2026-28270 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch for the issue. NVD description · AI analysis pending | 7.2 group max | 2% |
| — | ||
| CVE-2026-28269 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Version 9.2.0 contains a patch. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2026-25648 | Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in t Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The application accepts SVG file uploads without sanitization and serves them with the `image/svg+xml` Content-Type, allowing embedded JavaScript to execute when victims view the image. As of time of publication, it is unclear whether a fix is available. NVD description · AI analysis pending | 8.7 group max | <1% | PoC |
| — | |
| CVE-2025-60534 | Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate f Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-53939 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly elevate another user's permissions on the share. This issue has been patched in version 9.1.0. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-53900 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could lead to unexpected escalation of privileges for authorized users. This issue has been patched in version 9.1.0. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2025-12599 | Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12553 | Email Server Certificate Verification Disabled.This issue affects BLU-IC2: Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12516 +1 in the same advisory: …12517 | Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12515 | Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2025-10928 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.5. NVD description · AI analysis pending | 6.3 | <1% |
| — | ||
| CVE-2025-12477 | Server Version Disclosure.This issue affects BLU-IC2: Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . NVD description · AI analysis pending | 10.0 | <1% |
| — |