Export limit exceeded: 10889 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 15533 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 10490 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10490 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106406 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-07 | 5.4 Medium |
| Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106410 | 1 Google | 1 Chrome | 2026-10-07 | 4.2 Medium |
| Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-45524 | 1 Google | 1 Android | 2026-10-07 | 8.8 High |
| In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-18177 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-07 | 7.1 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks. | ||||
| CVE-2026-18179 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-07 | 6.5 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization. | ||||
| CVE-2026-106224 | 1 Google | 1 Chrome | 2026-10-07 | 3.1 Low |
| Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106187 | 1 Google | 1 Chrome | 2026-10-07 | 4.2 Medium |
| Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-93026 | 1 Veeam | 1 Backup And Replication | 2026-10-07 | N/A |
| This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials. | ||||
| CVE-2026-92393 | 2026-10-07 | N/A | ||
| Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn are defined as the following Kubernetes objects: "deployments", "replicasets", "statefulsets", "daemonsets", "jobs", "cronjobs". The CREATE action correctly enforces the checks for all object types. The bypass allows any user to specify an arbitrary user info annotation. The same bypass also allows changing the application ID for the workload. The combination of the two applied in one UPDATE could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue. Users are recommended to upgrade to version 1.10.0, which fixes this issue. | ||||
| CVE-2026-82211 | 2026-10-07 | 8.2 High | ||
| The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details. | ||||
| CVE-2026-27434 | 2026-10-07 | 5.3 Medium | ||
| Missing Authorization vulnerability in sc Internet Vivoo WP Rentals wprentals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rentals: from n/a through 3.14.2. | ||||
| CVE-2026-105876 | 2026-10-07 | 5.3 Medium | ||
| Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Retrieve Embedded Sensitive Data.This issue affects Modula Image Gallery: from n/a through 3.0.11. | ||||
| CVE-2026-104390 | 2026-10-07 | 4.3 Medium | ||
| Missing Authorization vulnerability in Arraytics Booktics booktics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booktics: from n/a through 1.0.27. | ||||
| CVE-2026-103075 | 2026-10-07 | 4.3 Medium | ||
| Missing Authorization vulnerability in WPMU DEV Hustle wordpress-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hustle: from n/a through 7.8.14.2. | ||||
| CVE-2026-103323 | 2026-10-07 | 5.9 Medium | ||
| The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers. | ||||
| CVE-2026-106041 | 1 Kvcache-ai | 1 Mooncake | 2026-10-07 | 6.5 Medium |
| Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence. | ||||
| CVE-2026-42638 | 2 Syed Balkhi, Wordpress-extensions | 2 Easy Digital Downloads, Easy Digital Downloads | 2026-10-07 | 7.5 High |
| Missing Authorization vulnerability in Awesomemotive Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.7.1. | ||||
| CVE-2026-63691 | 1 Dell | 1 Container Storage Modules | 2026-10-07 | 6.1 Medium |
| Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. | ||||
| CVE-2026-89289 | 2026-10-07 | 5.3 Medium | ||
| The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id. | ||||
| CVE-2026-102375 | 2 Optimole, Wordpress-extensions | 2 Optimole, Optimole | 2026-10-07 | 6.5 Medium |
| Missing Authorization vulnerability in Optimole Optimole optimole-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Optimole: from n/a through 4.2.14. | ||||