Export limit exceeded: 16305 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 14778 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14778 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103274 | 1 Ghost | 1 Ghost | 2026-10-01 | 5.3 Medium |
| Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings. | ||||
| CVE-2026-103269 | 1 Ghost | 1 Ghost | 2026-10-01 | 5.3 Medium |
| Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content). | ||||
| CVE-2026-103265 | 1 Fleetdm | 1 Fleet | 2026-10-01 | 4.3 Medium |
| Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses. | ||||
| CVE-2026-101006 | 1 Frappe | 1 Hr | 2026-10-01 | 4.3 Medium |
| A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it." | ||||
| CVE-2026-101000 | 1 Netcore | 1 Nbr100v2 | 2026-10-01 | 10 Critical |
| A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-95290 | 1 Google | 1 Chrome | 2026-10-01 | 5.4 Medium |
| Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95297 | 1 Google | 1 Chrome | 2026-10-01 | 6.5 Medium |
| Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95300 | 1 Google | 1 Chrome | 2026-10-01 | 4.8 Medium |
| Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-95301 | 1 Google | 1 Chrome | 2026-10-01 | 8.1 High |
| Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-95340 | 1 Google | 1 Chrome | 2026-10-01 | 4.3 Medium |
| Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-95342 | 1 Google | 1 Chrome | 2026-10-01 | 4.3 Medium |
| Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-103495 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs | ||||
| CVE-2026-103341 | 2026-10-01 | 5.3 Medium | ||
| Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-103284 | 1 Ghost | 1 Ghost | 2026-10-01 | 4.3 Medium |
| Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks. | ||||
| CVE-2026-103273 | 1 Ghost | 1 Ghost | 2026-10-01 | 4.3 Medium |
| Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level. | ||||
| CVE-2026-103268 | 1 Ghost | 1 Ghost | 2026-10-01 | 8.8 High |
| Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges. | ||||
| CVE-2026-103260 | 1 N8n | 1 N8n | 2026-10-01 | 4 Medium |
| n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode. Attackers can submit resume requests without verification of the requester's identity or approval permissions, allowing unauthenticated users to advance waiting executions and trigger guarded actions. | ||||
| CVE-2026-95375 | 1 Google | 1 Chrome | 2026-10-01 | 6.3 Medium |
| Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95368 | 1 Google | 1 Chrome | 2026-10-01 | 4.3 Medium |
| Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-81158 | 2 Drupal, Entity Api Project | 2 Entity Api, Entity Api | 2026-10-01 | 5.3 Medium |
| Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0. | ||||