Export limit exceeded: 401115 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (801 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87785 | 2026-09-14 | 9.1 Critical | ||
| Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and obtaining a valid JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue. | ||||
| CVE-2026-21391 | 2026-09-14 | N/A | ||
| An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation. | ||||
| CVE-2026-88879 | 1 Traefik | 1 Traefik | 2026-09-14 | 8.2 High |
| Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three distinct headers by Traefik, while backends that derive variable names from header names (CGI, WSGI, PHP, NGINX and others) collapse them into a single variable. A client can therefore smuggle a dot-form alias of a header that Traefik manages past the middleware managing it — for example supplying X.Authenticated.User alongside the canonical X-Authenticated-User written by the ForwardAuth middleware — causing such a backend to read the client-supplied value instead of the identity Traefik asserted. In the tested configuration (PHP 8.2 built-in SAPI over an HTTP/1 backend path), Go's lexical header ordering makes the attacker-supplied value win deterministically, so a client that ForwardAuth admits as a low-privilege identity can be treated by the backend as a different user or role. Any header Traefik sets is affected, not only ForwardAuth's. This is an incomplete fix for GHSA-x677-9fxg-v5c5, which blocked only the underscore form. Fixed in v2.11.56 and v3.7.12, which add the aliasHeadersStrategy entry-point option; because it defaults to 'keep' for backwards compatibility, it must be explicitly set to 'delete' or 'reject' for the fix to take effect. Unmaintained release lines will not receive a patch. | ||||
| CVE-2026-45056 | 1 Matrix-org | 1 Matrix-rust-sdk | 2026-09-14 | N/A |
| matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the `sender_device_keys` property. This could be exploited to forge an encrypted to-device event, but only if the attacker colludes with the homeserver operator. This issue is fixed in matrix-sdk-crypto 0.17.0. There are no known workarounds for the issue. | ||||
| CVE-2026-66674 | 2 Replywp, Wordpress | 2 Simple Cloudfare Turnstile, Wordpress | 2026-09-13 | 5.6 Medium |
| Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. | ||||
| CVE-2026-63427 | 1 Lenovo | 1 Software Fix | 2026-09-11 | 7.8 High |
| An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges. | ||||
| CVE-2026-77089 | 1 Commvault | 1 Commvault | 2026-09-11 | 9.8 Critical |
| Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. | ||||
| CVE-2026-82563 | 1 Softish | 2 C6 Ear Camera, Earvision Android Application | 2026-09-10 | 7.6 High |
| An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior. | ||||
| CVE-2026-0292 | 3 Microsoft, Palo Alto Networks, Paloaltonetworks | 3 Windows, Prisma Access Agent, Prisma Access Agent | 2026-09-09 | 6.0 Medium |
| An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected. | ||||
| CVE-2026-86196 | 1 Getgrav | 2 Grav, Grav-plugin-api | 2026-09-08 | N/A |
| Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts. | ||||
| CVE-2026-19538 | 1 Nlnetlabs | 1 Nsd | 2026-09-08 | 7.5 High |
| The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open. | ||||
| CVE-2026-84186 | 1 Prestashop | 1 Prestashop | 2026-09-08 | N/A |
| Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse proxy, load balancer or CDN. The application incorrectly processes the IP address string and uses the address controlled by the visitor rather than the one provided by the trusted infrastructure, allowing an unauthenticated remote attacker to cause the application to interpret their connection as originating from an arbitrary IP address. This condition allows IP-based controls, such as the maintenance mode allowlist, to be bypassed, as well as enabling the forgery of security and audit logs and the evasion of third-party mechanisms that rely on the IP address, such as geolocation checks, fraud detection or request throttling. | ||||
| CVE-2026-86478 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 9.8 Critical |
| In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | ||||
| CVE-2026-84849 | 2 Brightplugins, Wordpress | 2 Pre-orders For Woocommerce, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. | ||||
| CVE-2026-84766 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Booking | 2026-09-07 | 5.9 Medium |
| Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | ||||
| CVE-2026-85432 | 1 Themoos | 1 Core-moos | 2026-09-04 | 8.2 High |
| MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting the disconnect between authenticated connection identity and wire-supplied source attribution. | ||||
| CVE-2026-47845 | 2 Broadcom, Spring | 2 Reactor Netty, Reactor Netty | 2026-09-04 | 5.3 Medium |
| In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier | ||||
| CVE-2023-50224 | 1 Tp-link | 72 Archer C1900, Archer C1900 Firmware, Archer C5 and 69 more | 2026-09-03 | 6.5 Medium |
| TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899. | ||||
| CVE-2026-84358 | 1 Google | 1 Chrome | 2026-09-03 | 4.2 Medium |
| Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-82180 | 1 Eclipse | 1 Arrowhead | 2026-09-03 | N/A |
| In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that the client sends inside the MQTT message payload (the authentication field of MqttRequestTemplate) and treats its Subject DN as the authenticated identity. The certificate is decoded with CertificateFactory.generateCertificate() but its signature is never verified and its issuer chain is never validated against any trust store. Authorisation is reduced to two string comparisons on attacker-supplied data: the DN-qualifier must equal "sy" or "op", and the cloud-name part of the CN must match the server's. Both values are public (the cloud name is in the server's own TLS certificate). An attacker who can publish to the MQTT broker can therefore mint a self-signed certificate with CN=Sysop.<cloud>.<org>.arrowhead.eu, dnQualifier=op, send it as the authentication field, and be authenticated as the cloud's system operator with isSysOp == true. This passes the downstream ManagementServiceMqttFilter (request.isSysOp() → allowed) and gives full management access over MQTT. The HTTP CertificateFilter is not affected — it reads the certificate from jakarta.servlet.request.X509Certificate, which Tomcat populates only after a successful mTLS handshake against the configured trust store. | ||||