Search Results (12174 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15829 1 Google 1 Mcp Toolbox For Databases 2026-07-23 N/A
A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via fmt.Sprintf directly into a generated AI.FORECAST table-valued SELECT statement. While MCP Toolbox utilizes an allowedDatasets mechanism to restrict queries, this defense only validates the history_data parameter; the final assembled query is executed without re-validation. An attacker can break out of the string literal fields (such as timestamp_col) to inject a valid multi-statement or cross-dataset query block. This allows an unauthorized user to bypass the operator-configured allowedDatasets boundary and read arbitrary BigQuery tables.
CVE-2026-63092 1 Medienbaecker 1 Kirby-modules 2026-07-23 4.3 Medium
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The plugin's activate dialog handler in lib/areas.php returns the complete key via ModulesLicense::readKey() without performing an administrator check, as the dialog is gated only by the access.system permission which defaults to true for all non-admin roles, enabling attackers to use the disclosed key to activate the plugin on arbitrary third-party installations.
CVE-2026-65011 1 Graylog2 1 Graylog2-server 2026-07-23 4.3 Medium
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them.
CVE-2026-59678 1 Linux-gaming 1 Portprotonqt 2026-07-23 N/A
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
CVE-2026-15827 2 Ataurr, Wordpress 2 Gutenkit – Page Builder Blocks, Patterns, And Templates For Gutenberg Block Editor, Wordpress 2026-07-23 5.3 Medium
The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12. Both endpoints are registered with permission_callback => '__return_true', and their callbacks read the site's stored Mailchimp API key from the gutenkit_settings_list option and proxy Mailchimp audience/list, merge-field, interest-category, interest-name, and subscriber-count metadata back to the caller with no login, nonce, or capability check. This makes it possible for unauthenticated attackers to retrieve private Mailchimp audience configuration information from any site that has configured the GutenKit Mailchimp integration.
CVE-2026-15015 2 Cascadiawebservices, Wordpress 2 Mountdev Ai Mcp Connector For Wordpress, Wordpress 2026-07-23 9.8 Critical
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an administrator-bound OAuth Bearer token via a self-registered client, granting full administrator-equivalent access to the plugin's MCP tool surface and all exposed WordPress content, users, and options. This is exploitable by combining the publicly accessible Dynamic Client Registration endpoint, which allows unauthenticated callers to register arbitrary OAuth clients with an attacker-controlled redirect_uri, with the unprotected authorization endpoint to complete the full OAuth flow without any administrator interaction.
CVE-2026-25427 2 Digitalme, Wordpress 2 Eroom, Wordpress 2026-07-23 5.4 Medium
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
CVE-2026-27377 2 Axiomthemes, Wordpress 2 Quickcal - Appointment Booking Calendar For Wordpress, Wordpress 2026-07-23 6.7 Medium
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
CVE-2026-27399 2 Webwizards, Wordpress 2 Marketking, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
CVE-2026-27422 2 Bplugins, Wordpress 2 Yt Player, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
CVE-2026-57425 2 Wordpress, Wpdesk 2 Wordpress, Autopay Dla Woocommerce 2026-07-23 6.5 Medium
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
CVE-2026-61954 2 Payu India, Wordpress 2 Payu India, Wordpress 2026-07-23 7.5 High
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVE-2026-61972 2 Woolentor, Wordpress 2 Shoplentor Pro, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61973 2 Woolentor, Wordpress 2 Shoplentor Pro, Wordpress 2026-07-23 4.3 Medium
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-65457 2 Wordpress, Yoomoney 2 Wordpress, Юkassa Для Woocommerce 2026-07-23 4.3 Medium
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
CVE-2026-65472 2 Kit, Wordpress 2 Kit (formerly Convertkit), Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
CVE-2026-65479 2 Mvp Themes, Wordpress 2 Reviewer, Wordpress 2026-07-23 5.4 Medium
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
CVE-2026-65485 2 Daniel Iser, Wordpress 2 Content Control, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVE-2026-65486 2 Bastien Ho, Wordpress 2 Event Post, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
CVE-2026-65500 2 Pixelacehq, Wordpress 2 Manual - Documentation, Knowledge Base & Education Wordpress Theme, Wordpress 2026-07-23 7.5 High
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.