Search Results (14751 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100270 1 Jetbrains 1 Youtrack 2026-10-02 3.3 Low
In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations
CVE-2026-100271 1 Jetbrains 1 Youtrack 2026-10-02 2.7 Low
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects
CVE-2026-100273 1 Jetbrains 1 Youtrack 2026-10-02 8.2 High
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
CVE-2026-39717 2026-10-02 4.3 Medium
Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1.
CVE-2026-39439 2026-10-02 6.5 Medium
Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebSamurai: from n/a through 1.0.7.
CVE-2026-104467 1 Yeswiki 1 Yeswiki 2026-10-02 8.1 High
YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list, download, or delete backup archives.
CVE-2026-104438 1 Yeswiki 1 Yeswiki 2026-10-02 5.3 Medium
YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and body-derived titles of ACL-restricted pages.
CVE-2026-100276 1 Jetbrains 1 Youtrack 2026-10-02 5.9 Medium
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVE-2026-100277 1 Jetbrains 1 Youtrack 2026-10-02 8.9 High
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVE-2026-100278 1 Jetbrains 1 Youtrack 2026-10-02 4.9 Medium
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
CVE-2026-100280 1 Jetbrains 1 Youtrack 2026-10-02 3.1 Low
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
CVE-2026-104472 1 Yeswiki 1 Yeswiki 2026-10-02 7.5 High
YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter to retrieve confidential attachments from read-restricted pages.
CVE-2026-95374 1 Google 1 Chrome 2026-10-02 6.5 Medium
Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-91023 1 Wordpress-extensions 1 Motors 2026-10-02 3.1 Low
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
CVE-2026-80337 1 Havelsan 1 Sef - Ai Chatbot Platform 2026-10-02 5.3 Medium
Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
CVE-2026-78210 1 Octopus 1 Octopus Server 2026-10-02 N/A
In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization.
CVE-2026-104443 1 Yeswiki 1 Yeswiki 2026-10-02 8.1 High
YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout.
CVE-2026-93379 1 Google 1 Chrome 2026-10-01 4.3 Medium
Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-97395 1 Apache 1 Polaris 2026-10-01 8.1 High
Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation. This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints.
CVE-2026-93832 1 Motorola 1 Setup App 2026-10-01 4.4 Medium
A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.