| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Review Schema: 3.1.0. |
| A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores. |
| A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access. |
| Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards. |
| A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database. |
| A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior. |
| Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. |
| Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. |
| Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. |
| Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions. |
| Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. |
| Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
| A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data. |
| In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues |
| In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration |
| In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs |