Export limit exceeded: 16579 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16579 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100830 | 1 Mozilla | 1 Firefox | 2026-10-01 | 8.1 High |
| Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-2340 | 2 Redhat, Samba | 10 Enterprise Linux, Enterprise Linux Eus, Openshift and 7 more | 2026-10-01 | 6.5 Medium |
| A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file. | ||||
| CVE-2026-103651 | 1 Misp | 1 Misp | 2026-10-01 | N/A |
| MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a counter value that was cached in the user's session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state. Preconditions: - The target user has HOTP (paper token) second-factor authentication enabled. - The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending). - The attacker has access to at least one HOTP token value (e.g., a paper token list). Security impact: - Bypass of the second authentication factor, allowing unauthorized access to a user's MISP account. - Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays. Affected versions: <2.5.48. | ||||
| CVE-2026-103659 | 1 Misp | 1 Misp | 2026-10-01 | N/A |
| MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes. As a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user's organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data. A secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate. Preconditions: - An authenticated user with access to a community-distributed event - The event contains at least one object with a distribution level or sharing group that restricts access beyond the event's own distribution Impact: - Unauthorized disclosure of attributes belonging to restricted objects - Potential exposure of organisation-specific threat intelligence to other organisations Affected versions: <2.5.48 | ||||
| CVE-2026-102245 | 1 Modsetter | 1 Surfsense | 2026-10-01 | 7.3 High |
| A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101281 | 1 Trusted Domain Project | 1 Opendmarc | 2026-10-01 | 7.3 High |
| A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c758677fc5272a73eff15ffdbf8afda1a6. Applying a patch is the recommended action to fix this issue. | ||||
| CVE-2026-100808 | 1 Mozilla | 1 Firefox | 2026-10-01 | 8.8 High |
| Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100787 | 1 Mozilla | 1 Firefox | 2026-10-01 | 9.6 Critical |
| Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-90972 | 1 Wordpress-extensions | 1 Wp Fusion Lite | 2026-10-01 | 5.4 Medium |
| The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync. | ||||
| CVE-2026-47603 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-10-01 | 5.5 Medium |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-90974 | 1 Wordpress-extensions | 1 Wp Fusion Lite | 2026-10-01 | 6.5 Medium |
| The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host. | ||||
| CVE-2026-75957 | 2 Superdav42, Wordpress-extensions | 2 Ultimate Multisite, Ultimate Multisite | 2026-10-01 | 9.8 Critical |
| The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible `wu_ajax_nopriv_wu_validate_form` AJAX handler accepting a freely obtainable checkout nonce, and the `checkout_form=wu-finish-checkout` parameter causing `get_validation_rules()` to discard all validation rules while `finish_checkout_form_fields()` returns an empty step list — forcing `is_last_step()` to return true and routing the request directly into full order processing — after which `maybe_create_customer()` resolves the attacker-supplied `email_address` to an existing WordPress user ID without any authentication or ownership verification, and `login_customer_after_checkout()` calls `wp_set_auth_cookie()` for that user ID via a passwordless code path. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including a Network Super Admin — simply by knowing their email address. Exploitation requires that the targeted user account has no pre-existing Ultimate Multisite customer record; accounts such as a Network Super Admin on a fresh Multisite install, or any administrator or editor added before Ultimate Multisite was configured, satisfy this condition and are therefore exploitable. | ||||
| CVE-2026-94276 | 1 Apache | 1 Apisix | 2026-10-01 | N/A |
| Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affects Apache APISIX: from 3.12.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue. | ||||
| CVE-2026-102128 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 7.5 High |
| An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account. | ||||
| CVE-2026-102106 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 9.1 Critical |
| Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authenticating; deleting a managed domain also removes its user accounts and could lock administrators out of the gateway. | ||||
| CVE-2026-81703 | 1 Jahlives | 1 Openssl Encrypt | 2026-10-01 | 5.5 Medium |
| openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification. | ||||
| CVE-2026-74894 | 1 Jahlives | 1 Openssl Encrypt | 2026-10-01 | 9.8 Critical |
| openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header. | ||||
| CVE-2026-103858 | 1 Misp | 1 Misp | 2026-10-01 | N/A |
| MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility. As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could: - Read the thread title and the content of the quoted post - Submit a new post into the discussion thread This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in). Affected: <2.5.48 | ||||
| CVE-2026-103541 | 1 Form Tools | 1 Form Tools | 2026-10-01 | 6.3 Medium |
| A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax Handler. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-103538 | 1 Zongxr | 1 Supermarket | 2026-10-01 | 6.5 Medium |
| A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||