Export limit exceeded: 14760 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14760 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104472 | 1 Yeswiki | 1 Yeswiki | 2026-10-02 | 7.5 High |
| YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter to retrieve confidential attachments from read-restricted pages. | ||||
| CVE-2026-95374 | 1 Google | 1 Chrome | 2026-10-02 | 6.5 Medium |
| Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-91023 | 1 Wordpress-extensions | 1 Motors | 2026-10-02 | 3.1 Low |
| The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration. | ||||
| CVE-2026-80337 | 1 Havelsan | 1 Sef - Ai Chatbot Platform | 2026-10-02 | 5.3 Medium |
| Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-78210 | 1 Octopus | 1 Octopus Server | 2026-10-02 | N/A |
| In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization. | ||||
| CVE-2026-104443 | 1 Yeswiki | 1 Yeswiki | 2026-10-02 | 8.1 High |
| YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout. | ||||
| CVE-2026-93379 | 1 Google | 1 Chrome | 2026-10-01 | 4.3 Medium |
| Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-97395 | 1 Apache | 1 Polaris | 2026-10-01 | 8.1 High |
| Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation. This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints. | ||||
| CVE-2026-93832 | 1 Motorola | 1 Setup App | 2026-10-01 | 4.4 Medium |
| A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps. | ||||
| CVE-2026-97280 | 2 Mamunur Rashid, Wordpress-extensions | 2 Review Schema, Review Schema | 2026-10-01 | 6.5 Medium |
| Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0. | ||||
| CVE-2026-97277 | 2026-10-01 | 7.6 High | ||
| Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | ||||
| CVE-2026-103259 | 1 N8n | 1 N8n | 2026-10-01 | 7.6 High |
| n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access. | ||||
| CVE-2026-103251 | 1 N8n | 1 N8n | 2026-10-01 | 7.1 High |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without authentication. | ||||
| CVE-2026-102397 | 2 Supsystic, Wordpress-extensions | 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic | 2026-10-01 | 6.5 Medium |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-76143 | 1 Genians | 1 Genian Ssl Pns (frodo-core) | 2026-10-01 | N/A |
| A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. | ||||
| CVE-2026-76147 | 1 Genians | 2 Genian Nac, Genian Ztna | 2026-10-01 | N/A |
| A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code | ||||
| CVE-2026-103340 | 2 Geminilabs, Wordpress-extensions | 2 Site Reviews, Site Reviews | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2. | ||||
| CVE-2026-102381 | 2 Ahmad, Wordpress-extensions | 2 Majestic Support, Majestic Support | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0. | ||||
| CVE-2026-102390 | 2 Villatheme, Wordpress-extensions | 2 Affi – Affiliate Marketing For Woocommerce, Affi - Affiliate Marketing For Woocommerce | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9. | ||||
| CVE-2026-77087 | 1 Paperclip | 1 Paperclipai | 2026-10-01 | 9.6 Critical |
| Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter. | ||||