Export limit exceeded: 10867 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 10558 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10558 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-38056 | 1 St Engineering Idirect | 3 3315-series Terminals, 9-series Terminals, Evolution Iq‑series Terminals | 2026-09-13 | 8.8 High |
| A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced. | ||||
| CVE-2026-89265 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 4.3 Medium |
| MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve restricted image-category records including metadata such as name, cover file uid, sort order and timestamps. | ||||
| CVE-2026-27378 | 2 Magepeopleteam, Wordpress | 2 Deposits And Partial Payments For Woocommerce, Wordpress | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. | ||||
| CVE-2026-62136 | 2 Wordpress, Wpdesk | 2 Wordpress, Flexible Quantity – Measurement Price Calculator For Woocommerce | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions. | ||||
| CVE-2026-62089 | 2 Pixar Labs, Wordpress | 2 Master Addons For Elementor, Wordpress | 2026-09-13 | 7.1 High |
| Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2. | ||||
| CVE-2026-15398 | 2 Arraytics, Wordpress | 2 Eventin – Event Calendar, Event Registration, Tickets & Booking (ai Powered), Wordpress | 2026-09-13 | 4.3 Medium |
| The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to bypass payment for paid events, fraudulently mark orders as completed, deplete ticket inventory, and trigger confirmation emails for tickets never purchased. This is exploitable by unauthenticated attackers because the wp_rest nonce is publicly emitted on every frontend page, and the order creation endpoint mints and returns an order_access_token to any caller possessing that nonce — giving unauthenticated users all credentials required to reach the privileged update_booking_status branch. | ||||
| CVE-2026-11446 | 2 Arraytics, Wordpress | 2 Booktics – Booking Calendar For Appointments And Service Businesses, Wordpress | 2026-09-13 | 5.3 Medium |
| The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23. This is due to the create_order_permission() permission callback on the POST /wp-json/booktics/v1/orders REST route unconditionally returning true, combined with find_and_update_guest() overwriting an existing customer record's stored name, phone, and wp_user_id whenever the caller-supplied email matches, with no proof of ownership. This makes it possible for unauthenticated attackers to overwrite the contact details (name and phone) of any existing customer whose email address they know, poisoning downstream reminder emails, SMS, calendar invites, and CRM data. | ||||
| CVE-2026-62114 | 2 Wordpress, Wpchill | 2 Wordpress, Passster | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Passster <= 4.3.13 versions. | ||||
| CVE-2026-62132 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-09-13 | 5.3 Medium |
| Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. | ||||
| CVE-2026-18122 | 1 Concretecms | 1 Concrete Cms | 2026-09-13 | N/A |
| Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with read scope for an Express entity could enumerate entries that its user context lacked permission to view, disclosing each entry's public identifier, URL, label, dates, and any attribute or associated-entry data requested via the includes parameter. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting. | ||||
| CVE-2026-81909 | 1 Concretecms | 1 Concrete Cms | 2026-09-13 | N/A |
| Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, nor that the caller holds any permission over the source block. A user granted only an area-scoped add_block_to_area delegation on their own page can therefore pass any block ID on the site: the source block's content is duplicated into an area the rogue editor controls, disclosing that content, and the original block is then force-deleted in the same request, destroying arbitrary site content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting. | ||||
| CVE-2026-62135 | 2 Arraytics, Wordpress | 2 Booktics, Wordpress | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions. | ||||
| CVE-2026-81908 | 1 Concretecms | 1 Concrete Cms | 2026-09-12 | N/A |
| Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns true, so no per-object (tree node) authorization is enforced when the group collection is returned. An authenticated user whose API token carries the groups:read scope can call GET /ccm/api/1.0/groups and receive every group on the site regardless of the view permissions on those groups, disclosing the organization's group structure, roles, and access hierarchy. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting. | ||||
| CVE-2026-87797 | 2026-09-12 | 4.3 Medium | ||
| The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users. | ||||
| CVE-2026-62137 | 2 John James Jacoby, Wordpress | 2 Bbpress, Wordpress | 2026-09-12 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. | ||||
| CVE-2026-87919 | 2026-09-12 | 4.9 Medium | ||
| The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode. | ||||
| CVE-2026-61410 | 1 Dell | 3 Secure Connect Gateway, Secure Connect Gateway Appliance, Secure Connect Gateway Application | 2026-09-11 | 9.4 Critical |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system by sending a specially crafted request to the application, bypassing intended restrictions on code execution.Dell recommends customers to upgrade at the earliest opportunity. | ||||
| CVE-2026-88959 | 1 Anchorcms | 1 Anchor Cms | 2026-09-11 | 8.8 High |
| Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify existing ones. Attackers with editor or user roles can POST directly to admin/users/add or admin/users/edit endpoints to create new administrator accounts or change the existing administrator's password, gaining full administrative access. | ||||
| CVE-2026-86281 | 1 Sourcecodester | 1 Syllabus-aligned Learning Management Examination System | 2026-09-11 | 4.3 Medium |
| A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. | ||||
| CVE-2026-81786 | 2 Villatheme, Wordpress | 2 Thank You Page Customizer For Woocommerce, Wordpress | 2026-09-11 | 7.5 High |
| Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. | ||||