Search Results (1386 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93540 1 Suse 2 Rancher, Rancher Fleet 2026-10-07 6.5 Medium
A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace. This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.
CVE-2026-106250 1 Google 1 Chrome 2026-10-07 5.4 Medium
Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-39761 2 Elightup, Wordpress-extensions 2 Meta Box Aio, Meta Box Aio 2026-10-06 9.8 Critical
Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions.
CVE-2026-39765 2 Webappick, Wordpress-extensions 2 Challan, Challan 2026-10-06 7.2 High
Shop Manager Privilege Escalation in Challan <= 3.7.88 versions.
CVE-2026-39773 2 Amentotech, Wordpress-extensions 2 Doctreat Core, Doctreat Core 2026-10-06 10 Critical
Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.
CVE-2026-39774 2 Tourfic Ai Studio, Wordpress-extensions 2 Tourfic Pro, Tourfic Pro 2026-10-06 8.8 High
Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions.
CVE-2026-39775 2 Dexignzone, Wordpress-extensions 2 Jobzilla - Job Board Wordpress Theme, Jobzilla 2026-10-06 8.8 High
Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions.
CVE-2026-48197 2 Publishpress, Wordpress-extensions 2 Capabilities, Publishpress Capabilities 2026-10-06 7.2 High
Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.
CVE-2026-95594 2 Cozy Vision Technologies Pvt. Ltd., Wordpress-extensions 2 Sms Alert Order Notifications, Sms Alert Order Notifications 2026-10-06 8.1 High
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.
CVE-2026-104405 2 Nexcess, Wordpress-extensions 2 Givewp, Givewp 2026-10-06 8.1 High
Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions.
CVE-2026-104757 2 Carazo, Wordpress-extensions 2 Import And Export Users And Customers, Import And Export Users And Customers 2026-10-06 7.2 High
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
CVE-2026-105058 2 John James Jacoby, Wordpress-extensions 2 Wp User Profiles, Wp User Profiles 2026-10-06 8.8 High
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
CVE-2026-105070 2 Dimitri Grassi, Wordpress-extensions 2 Salon Booking System, Salon Booking System 2026-10-06 8.8 High
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.
CVE-2026-105571 2 Pickmall, Pickmall Lilishop 2 Lilishop, Pickmall Lilishop 2026-10-06 7.3 High
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-92012 1 Mozilla 2 Firefox, Thunderbird 2026-10-06 8.8 High
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-92015 1 Mozilla 2 Firefox, Thunderbird 2026-10-06 8.8 High
Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-92017 1 Mozilla 2 Firefox, Thunderbird 2026-10-06 8.8 High
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-105621 1 Jishenghua 1 Jsherp 2026-10-06 5.4 Medium
A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-105610 1 Chillzhuang 1 Springblade 2026-10-06 4.7 Medium
A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter Submit Management. The manipulation of the argument initPassword results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-39753 2026-10-06 9.8 Critical
Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions.