Export limit exceeded: 14480 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14480 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-32220 | 1 Salonbookingsystem | 1 Salon Booking System | 2026-10-02 | 5.4 Medium |
| Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.8. | ||||
| CVE-2026-85209 | 2026-10-02 | 6.5 Medium | ||
| Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18. | ||||
| CVE-2025-58222 | 1 Wordpress | 1 Wordpress | 2026-10-02 | 5.3 Medium |
| Missing Authorization vulnerability in Dynamic Web Lab Team Manager wp-team-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Manager: from n/a through 2.6.7. | ||||
| CVE-2026-93379 | 1 Google | 1 Chrome | 2026-10-01 | 4.3 Medium |
| Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-97395 | 1 Apache | 1 Polaris | 2026-10-01 | 8.1 High |
| Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation. This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints. | ||||
| CVE-2026-93832 | 1 Motorola | 1 Setup App | 2026-10-01 | 4.4 Medium |
| A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps. | ||||
| CVE-2026-97280 | 2 Mamunur Rashid, Wordpress-extensions | 2 Review Schema, Review Schema | 2026-10-01 | 6.5 Medium |
| Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0. | ||||
| CVE-2026-97277 | 2026-10-01 | 7.6 High | ||
| Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | ||||
| CVE-2026-103259 | 1 N8n | 1 N8n | 2026-10-01 | 7.6 High |
| n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access. | ||||
| CVE-2026-103251 | 1 N8n | 1 N8n | 2026-10-01 | 7.1 High |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without authentication. | ||||
| CVE-2026-102397 | 2 Supsystic, Wordpress-extensions | 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic | 2026-10-01 | 6.5 Medium |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-102375 | 2 Optimole, Wordpress-extensions | 2 Optimole, Optimole | 2026-10-01 | 6.5 Medium |
| Subscriber Broken Access Control in Optimole <= 4.2.14 versions. | ||||
| CVE-2026-76143 | 1 Genians | 1 Genian Ssl Pns (frodo-core) | 2026-10-01 | N/A |
| A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. | ||||
| CVE-2026-76147 | 1 Genians | 2 Genian Nac, Genian Ztna | 2026-10-01 | N/A |
| A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code | ||||
| CVE-2026-103340 | 2 Geminilabs, Wordpress-extensions | 2 Site Reviews, Site Reviews | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2. | ||||
| CVE-2026-102381 | 2 Ahmad, Wordpress-extensions | 2 Majestic Support, Majestic Support | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0. | ||||
| CVE-2026-102390 | 2 Villatheme, Wordpress-extensions | 2 Affi – Affiliate Marketing For Woocommerce, Affi - Affiliate Marketing For Woocommerce | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9. | ||||
| CVE-2026-62073 | 2 Themeisle, Wordpress-extensions | 2 Wp Full Stripe Free, Wp Full Stripe Free | 2026-10-01 | 7.5 High |
| Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | ||||
| CVE-2026-77087 | 1 Paperclip | 1 Paperclipai | 2026-10-01 | 9.6 Critical |
| Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter. | ||||
| CVE-2026-43643 | 1 Softaculous | 1 Virtualizor | 2026-10-01 | 7.5 High |
| Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafted act and from_billing_module parameters to the admin panel dispatcher. Attackers can send a POST request with arbitrary uid and balance values in the billing_data field to trigger an unauthenticated parameterized UPDATE against the users table, enabling account balance manipulation and potential automated service suspension for targeted accounts. | ||||