Export limit exceeded: 13905 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (13905 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15594 | 1 Waooai | 1 Waoowaoo | 2026-07-15 | 3.7 Low |
| A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-50130 | 1 Pi-hole | 1 Pi-hole | 2026-07-15 | 8.8 High |
| Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3. | ||||
| CVE-2026-12112 | 1 Redhat | 1 Satellite | 2026-07-15 | 7.8 High |
| A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code execution. | ||||
| CVE-2026-15542 | 1 Will-moss | 1 Isaiah | 2026-07-15 | 7.3 High |
| A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack can be initiated remotely. The pull request to fix this issue awaits acceptance. | ||||
| CVE-2026-55014 | 1 Microsoft | 1 Windows-remote-help | 2026-07-15 | 7.8 High |
| Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50335 | 1 Microsoft | 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more | 2026-07-15 | 7.8 High |
| Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50418 | 1 Microsoft | 5 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 2 more | 2026-07-15 | 5.1 Medium |
| Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. | ||||
| CVE-2026-50344 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-07-15 | 7.8 High |
| Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50495 | 1 Microsoft | 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more | 2026-07-15 | 6.1 Medium |
| Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||||
| CVE-2026-15089 | 1 Drupal | 1 Commerce Guest Registration | 2026-07-15 | 9.1 Critical |
| vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*. | ||||
| CVE-2026-50423 | 1 Microsoft | 7 Windows 10 21h2, Windows 10 22h2, Windows 11 24h2 and 4 more | 2026-07-15 | 7.8 High |
| Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-49170 | 1 Microsoft | 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more | 2026-07-15 | 7.8 High |
| Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50373 | 1 Microsoft | 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more | 2026-07-15 | 7.8 High |
| Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-56169 | 1 Microsoft | 1 Windows Admin Center | 2026-07-15 | 8.1 High |
| Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-57107 | 1 Microsoft | 1 Windows Admin Center | 2026-07-15 | 7.8 High |
| Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-54121 | 1 Microsoft | 8 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 5 more | 2026-07-15 | 8.8 High |
| Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2020-37255 | 2 Wordpress, Wptimecapsule | 2 Wordpress, Wp Time Capsule | 2026-07-15 | 7.5 High |
| WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the WordPress dashboard without providing credentials. | ||||
| CVE-2019-25763 | 3 Brainstormforce, Ultimatebeaver, Wordpress | 3 Ultimate Addons For Beaver Builder, Ultimate Addons For Beaver Builder, Wordpress | 2026-07-15 | 9.8 Critical |
| WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and authenticate as that user. | ||||
| CVE-2018-25236 | 1 Belden | 2 Hirschmann Hios, Hirschmann Hisecos | 2026-07-15 | 9.8 Critical |
| Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attackers can exploit improper authentication handling to obtain the authentication status and privileges of a previously authenticated user without providing valid credentials. | ||||
| CVE-2026-20744 | 1 Hydro-québec | 1 Le Circuit Electrique Charging Station Backend | 2026-07-15 | 9.8 Critical |
| The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation. | ||||