Search Results (14480 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-32220 1 Salonbookingsystem 1 Salon Booking System 2026-10-02 5.4 Medium
Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.8.
CVE-2026-85209 2026-10-02 6.5 Medium
Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18.
CVE-2025-58222 1 Wordpress 1 Wordpress 2026-10-02 5.3 Medium
Missing Authorization vulnerability in Dynamic Web Lab Team Manager wp-team-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Manager: from n/a through 2.6.7.
CVE-2026-93379 1 Google 1 Chrome 2026-10-01 4.3 Medium
Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-97395 1 Apache 1 Polaris 2026-10-01 8.1 High
Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation. This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints.
CVE-2026-93832 1 Motorola 1 Setup App 2026-10-01 4.4 Medium
A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.
CVE-2026-97280 2 Mamunur Rashid, Wordpress-extensions 2 Review Schema, Review Schema 2026-10-01 6.5 Medium
Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0.
CVE-2026-97277 2026-10-01 7.6 High
Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
CVE-2026-103259 1 N8n 1 N8n 2026-10-01 7.6 High
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access.
CVE-2026-103251 1 N8n 1 N8n 2026-10-01 7.1 High
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without authentication.
CVE-2026-102397 2 Supsystic, Wordpress-extensions 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic 2026-10-01 6.5 Medium
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
CVE-2026-102375 2 Optimole, Wordpress-extensions 2 Optimole, Optimole 2026-10-01 6.5 Medium
Subscriber Broken Access Control in Optimole <= 4.2.14 versions.
CVE-2026-76143 1 Genians 1 Genian Ssl Pns (frodo-core) 2026-10-01 N/A
A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter.
CVE-2026-76147 1 Genians 2 Genian Nac, Genian Ztna 2026-10-01 N/A
A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code
CVE-2026-103340 2 Geminilabs, Wordpress-extensions 2 Site Reviews, Site Reviews 2026-10-01 5.3 Medium
Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2.
CVE-2026-102381 2 Ahmad, Wordpress-extensions 2 Majestic Support, Majestic Support 2026-10-01 5.3 Medium
Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
CVE-2026-102390 2 Villatheme, Wordpress-extensions 2 Affi – Affiliate Marketing For Woocommerce, Affi - Affiliate Marketing For Woocommerce 2026-10-01 5.3 Medium
Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9.
CVE-2026-62073 2 Themeisle, Wordpress-extensions 2 Wp Full Stripe Free, Wp Full Stripe Free 2026-10-01 7.5 High
Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.
CVE-2026-77087 1 Paperclip 1 Paperclipai 2026-10-01 9.6 Critical
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.
CVE-2026-43643 1 Softaculous 1 Virtualizor 2026-10-01 7.5 High
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafted act and from_billing_module parameters to the admin panel dispatcher. Attackers can send a POST request with arbitrary uid and balance values in the billing_data field to trigger an unauthenticated parameterized UPDATE against the users table, enabling account balance manipulation and potential automated service suspension for targeted accounts.