Export limit exceeded: 10008 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (10008 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-81785 2 Themekraft, Wordpress 2 Buddyforms, Wordpress 2026-09-11 6.5 Medium
Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.
CVE-2026-81788 2 Idxbroker, Wordpress 2 Impress For Idx Broker, Wordpress 2026-09-11 6.3 Medium
Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.
CVE-2026-81793 2 Dimitri Grassi, Wordpress 2 Salon Booking System, Wordpress 2026-09-11 6.5 Medium
Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
CVE-2026-84821 2 Epsiloncool, Wordpress 2 Wp Fast Total Search, Wordpress 2026-09-11 7.5 High
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
CVE-2026-88915 1 Misp 1 Misp 2026-09-11 N/A
Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value into event creation without verifying that the user instantiating the template was actually permitted to use the selected sharing group. The commit notes that Event::_add() only performed its own sharing-group authorization in another code path, leaving template instantiation able to write the identifier directly. The same instantiation path also attached template-specified tags without checking the user's normal tagging permissions. In addition, it hardcoded local => 0, meaning tags marked local_only could be attached globally and consequently propagate through synchronization or export, contrary to their intended restriction. The fix adds explicit SharingGroup::canUse() authorization for the acting user, applies the same tag-modification checks used by normal event tagging, and ensures local_only tags are attached locally. Version affected: ≤2.5.45
CVE-2026-81799 2 Wordpress, Wpswings 2 Wordpress, Return Refund And Exchange For Woocommerce 2026-09-11 7.5 High
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
CVE-2026-78536 2 Robokassa, Wordpress 2 Payment Gateway For Woocommerce, Wordpress 2026-09-11 6.5 Medium
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
CVE-2026-88898 1 Appflowy-io 1 Appflowy-cloud 2026-09-11 6.5 Medium
AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.
CVE-2026-86840 1 Bitfrost.io 1 Bifrost 2026-09-11 9.1 Critical
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.
CVE-2026-81904 1 Concretecms 1 Concrete Cms 2026-09-11 N/A
Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration values emitted by a restricted sub-block's asset registration — such as a site's configured Google Maps API key — from any public page embedding an affected Stack, Container, or layout area, despite the block-level permission restriction. Any sub-block type whose asset or header hooks output configuration values is affected.  The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
CVE-2026-87513 1 Google 1 Chrome 2026-09-11 6.5 Medium
Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87534 1 Google 2 Android, Chrome 2026-09-11 6.5 Medium
Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-84908 2 Getwpfunnels, Wordpress 2 Wpfunnels – Funnel Builder For Woocommerce With Checkout & One Click Upsell, Wordpress 2026-09-10 5.3 Medium
The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. This is due to the plugin registering the 'wpfnl_load_payment' AJAX action for both authenticated and unauthenticated (wp_ajax_nopriv_) users and the underlying add_offer_product_to_cart() function performing no nonce verification, no capability check, and no validation that the attacker-supplied product_id is the offer product actually configured on the attacker-supplied step_id. This makes it possible for unauthenticated attackers to add arbitrary WooCommerce products to a cart at any discounted price configured on any funnel step, enabling price manipulation and revenue loss at checkout.
CVE-2026-75905 2 Brechtvds, Wordpress 2 Wp Recipe Maker, Wordpress 2026-09-10 4.3 Medium
The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to take ownership of any admin-authored recipe by rewriting its post_author to the attacker's user ID, and unpublish it by overwriting its post_status with the contributor's draft or pending post status. This requires the default 'recipe_use_author' setting to be set to 'parent' for the ownership transfer to occur, though unpublishing remains possible regardless of this setting.
CVE-2026-86757 2 Grokability, Snipeitapp 2 Snipe-it, Snipe-it 2026-09-10 6.5 Medium
Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checkin, assets.checkout, or assets.audit permissions can read plaintext encrypted custom field values by opening asset forms, bypassing the assets.view.encrypted_custom_fields permission check.
CVE-2026-69377 1 Microsoft 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more 2026-09-10 7.8 High
Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
CVE-2026-69553 1 Microsoft 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more 2026-09-10 7.1 High
Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.
CVE-2026-83942 1 Microsoft 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more 2026-09-10 7.8 High
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-86993 1 N8n 1 N8n 2026-09-10 4.9 Medium
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check. A user with a custom global role carrying Log Streaming scopes could select a credential belonging to another project and send its decrypted secret to an attacker-controlled endpoint. The affected authorization boundary is packages/cli/src/modules/log-streaming.ee/destinations/destination-credentials-access.ts and the credential:read scope. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
CVE-2026-86994 1 N8n 1 N8n 2026-09-10 4.3 Medium
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, deactivation, and publication push events were also broadcast to clients that could not access the affected workflow, disclosing workflow IDs, version IDs, and activation error details. The affected paths include packages/cli/src/services/active-workflows.service.ts and packages/cli/src/workflows/workflow-push-notifier.service.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.