Export limit exceeded: 10357 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10357 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-90441 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request. | ||||
| CVE-2026-86136 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request. | ||||
| CVE-2026-95320 | 1 Google | 1 Chrome | 2026-09-30 | 5.4 Medium |
| Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-100855 | 1 Azuracast | 1 Azuracast | 2026-09-30 | 6.5 Medium |
| AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media files using sequential IDs and exfiltrate the complete media library of stations they lack permissions for. | ||||
| CVE-2026-100744 | 1 Coollabsio | 1 Coolify | 2026-09-30 | 7.3 High |
| A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 4.2.0 is sufficient to fix this issue. This patch is called 39ae16de4248075de8c08f3259114e064b20d52d. It is advisable to upgrade the affected component. | ||||
| CVE-2026-101047 | 1 Fleetdm | 1 Fleet | 2026-09-30 | 5.3 Medium |
| Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot rely on session-based authentication, and the missing token allows an unauthenticated attacker with network access to the Fleet server to download in-house IPA binaries and their metadata (bundle identifier, version, and name) by guessing sequential title identifiers. The impact is limited to read-only disclosure; there is no privilege escalation or write access, and the free tier is unaffected (it returns fleet.ErrMissingLicense). | ||||
| CVE-2026-65489 | 2 Lastudio, Wordpress | 2 La-studio Element Kit For Elementor, Wordpress | 2026-09-30 | 5.3 Medium |
| Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. | ||||
| CVE-2026-66651 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-09-30 | 6.5 Medium |
| Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through 5.0.19. | ||||
| CVE-2026-97267 | 2026-09-30 | 4.3 Medium | ||
| Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. | ||||
| CVE-2026-97247 | 2026-09-30 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. | ||||
| CVE-2026-97243 | 2026-09-30 | 5.4 Medium | ||
| Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions. | ||||
| CVE-2026-97239 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | ||||
| CVE-2026-97197 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | ||||
| CVE-2026-96834 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. | ||||
| CVE-2026-96823 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | ||||
| CVE-2026-96818 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. | ||||
| CVE-2026-96817 | 2026-09-30 | 8.2 High | ||
| Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. | ||||
| CVE-2026-96348 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Bookly <= 28.2 versions. | ||||
| CVE-2026-95587 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. | ||||
| CVE-2026-94499 | 2026-09-30 | 7.1 High | ||
| Subscriber Broken Access Control in FormGent <= 1.12.2 versions. | ||||