Export limit exceeded: 396031 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (10062 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-24369 2 Theme-one, Wordpress 2 The Grid, Wordpress 2026-09-01 7.1 High
Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0.
CVE-2026-24368 1 Wordpress 1 Wordpress 2026-09-01 5.3 Medium
Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0.
CVE-2026-75798 2 Ai Engine Project, Wordpress 2 Ai Engine, Wordpress 2026-09-01 5.3 Medium
The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.
CVE-2026-18431 2 Themefusion, Wordpress 3 Avada | Website Builder For Wordpress & Woocommerce, Fusion Builder, Wordpress 2026-09-01 9.8 Critical
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.
CVE-2026-19197 1 Grafana 2 Grafana, Grafana Enterprise 2026-09-01 6.3 Medium
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
CVE-2026-77507 1 Weblate 1 Weblate 2026-09-01 5.3 Medium
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users to read change-history metadata from private projects and restricted components. On installations that permit anonymous access, this metadata can be retrieved without any authentication. The exposed information can include project and component identities, contributor usernames and full names, action types, timestamps, and translation or unit links, though translated-string content is not included in the feed. Installations using private projects or restricted components are affected. This issue is fixed in version 2026.8.
CVE-2026-18965 1 Payrange 1 Payrange 2026-09-01 8.8 High
PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
CVE-2026-81762 2 Magepeople, Wordpress 2 Booking & Rental Manager, Wordpress 2026-09-01 6.5 Medium
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
CVE-2026-81296 2 Wordpress, Wpmanageninja 2 Wordpress, Fluent Forms Pro Add On Pack 2026-09-01 7.5 High
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
CVE-2026-81346 2 Dynamiapps, Wordpress 2 Frontend Admin By Dynamiapps, Wordpress 2026-09-01 4.3 Medium
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
CVE-2026-81759 2 Magepeopleteam, Wordpress 2 Wpevently, Wordpress 2026-09-01 5.4 Medium
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
CVE-2026-81761 2 Magepeopleteam, Wordpress 2 Wpevently, Wordpress 2026-09-01 4.3 Medium
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
CVE-2026-56100 1 Springblade Project 1 Springblade 2026-09-01 8.1 High
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Attackers can exploit the gateway's authentication filter, which only validates JWT parsing without verifying user roles or caller identity, and leverage a hardcoded JWT signing key embedded in publicly available JARs to forge tokens and escalate privileges from a low-privilege user to administrator, enabling cross-tenant data pollution and persistent backdoor access.
CVE-2026-18233 2 Mstore, Wordpress 2 Mstore Api, Wordpress 2026-09-01 6.5 Medium
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made.
CVE-2026-18234 2 Mstore, Wordpress 2 Mstore Api, Wordpress 2026-09-01 6.5 Medium
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment being taken.
CVE-2026-82475 1 Iflytek 1 Astron-agent 2026-09-01 8.1 High
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
CVE-2026-82544 1 Wger-project 1 Wger 2026-08-31 4.3 Medium
A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. This patch is called 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314. It is advisable to implement a patch to correct this issue.
CVE-2026-19616 1 Tbc Technology 1 Kitlogistic 2026-08-31 7.5 High
Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects KitLogistic: before v2.2.2.
CVE-2026-79748 1 Samanhappy 1 Mcphub 2026-08-31 9.9 Critical
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP server configurations and then immediately spawn the configured stdio process via child_process.spawn. Authentication is required, but there is no authorization check restricting these endpoints to admins, and there is no allowlist/sanitization on the command and args fields. As a result, any authenticated non-admin user can submit a server configuration with command:"/bin/sh" (or any other binary) and arbitrary args, causing MCPHub to execute the attacker-controlled process as the MCPHub server's OS user (commonly root in the published Docker image and in npx/systemd deployments). This issue has been patched in version 0.12.15.
CVE-2026-79744 1 Samanhappy 1 Mcphub 2026-08-31 8.8 High
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config endpoint (handler updateSystemConfig) performs no authorization check. It is protected only by the app-wide authentication middleware and a rate limiter — it never inspects req.user.isAdmin. This issue has been patched in version 1.0.29.