Browse 179+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-53987 | GLPI 11 before 2.14.4 Tag Plugin Stored Cross-Site Scripting in Kanban Badge Rendering | Tag plugin | GLPI 11 | Medium | 6.4 | 2026-07-09 15:44:04 | Deep Dive |
| CVE-2026-13490 | glpi-project glpi Document document.send.php canViewFile authorization | glpi-project | glpi | Low | 3.7 | 2026-06-28 11:00:06 | Deep Dive |
| CVE-2026-42321 | GLPI has stored XSS in asset locks | glpi-project | glpi | - | - | 2026-06-03 15:25:18 | Deep Dive |
| CVE-2026-42320 | GLPI vulnerable to arbitrary file access | glpi-project | glpi | - | - | 2026-06-03 15:23:47 | Deep Dive |
| CVE-2026-42318 | GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint | glpi-project | glpi | - | - | 2026-06-03 15:17:17 | Deep Dive |
| CVE-2026-42317 | GLPI vulnerable to arbitrary files deletion by technician | glpi-project | glpi | 中危 | - | 2026-06-03 15:16:02 | Deep Dive |
| CVE-2026-44281 | GLPI vulnerable to unauthorized reading of a specific asset object | glpi-project | glpi | 中危 | - | 2026-06-03 14:06:12 | Deep Dive |
| CVE-2026-40108 | GLPI Vulnerable to Stored XSS in ITIL Costs | glpi-project | glpi | 中危 | - | 2026-06-02 23:02:35 | Deep Dive |
| CVE-2026-5385 | GLPI 11.0.0 - Stored XSS in knowledge base | glpi-project | glpi | 中危 | - | 2026-06-02 18:32:01 | Deep Dive |
| CVE-2026-32312 | GLPI: Unauthorized export of form structure | glpi-project | glpi | - | - | 2026-05-18 23:46:26 | Deep Dive |
| CVE-2026-29047 | GLPI has an Authenticated SQL Injection via log exports | glpi-project | glpi | High | 7.2 | 2026-04-06 14:39:16 | Deep Dive |
| CVE-2026-26263 | GLPI has an Unauthenticated SQL Injection via Search engine | glpi-project | glpi | High | 8.1 | 2026-04-06 14:36:57 | Deep Dive |
| CVE-2026-26027 | GLPI has an Unauthenticated Stored XSS via inventory | glpi-project | glpi | High | 7.5 | 2026-04-06 14:35:54 | Deep Dive |
| CVE-2026-26026 | GLPI has a Server-Side Template Injection via Double-Compilation EPSS 0.11 | glpi-project | glpi | Critical | 9.1 | 2026-04-06 14:33:05 | Deep Dive |
| CVE-2026-25932 | GLPI has Stored XSS in Supplier 'Website' field | glpi-project | glpi | High | 7.2 | 2026-04-06 14:31:02 | Deep Dive |
| CVE-2026-26001 | GLPI Inventory Plugin has SQL Injection on dropdown_calendar Report | glpi-project | glpi-inventory-plugin | High | 7.1 | 2026-03-17 23:18:01 | Deep Dive |
| CVE-2026-25937 | GLPI has a MFA bypass | glpi-project | glpi | Medium | 6.5 | 2026-03-17 23:16:38 | Deep Dive |
| CVE-2026-25936 | GLPI Vulnerable to Authenticated SQL Injection | glpi-project | glpi | Medium | 6.5 | 2026-03-17 19:41:32 | Deep Dive |
| CVE-2026-22248 | GLPI affected by Remote Code Execution via malicious upload | glpi-project | glpi | High | 8.0 | 2026-03-11 15:27:05 | Deep Dive |
| CVE-2026-25590 | GLPI Inventory Plugin has Reflected XSS in task jobs | glpi-project | glpi-inventory-plugin | Medium | 4.5 | 2026-03-03 22:14:02 | Deep Dive |