Export limit exceeded: 13988 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (13988 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87792 | 1 Developers Italia | 1 Design-scuole-wordpress-theme | 2026-09-15 | N/A |
| The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation. | ||||
| CVE-2026-12758 | 1 Ibm | 1 Cloud Pak For Business Automation | 2026-09-15 | 5.4 Medium |
| IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. | ||||
| CVE-2026-12742 | 1 Ibm | 1 Business Automation Workflow Containers And Traditional | 2026-09-15 | 5.4 Medium |
| IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | ||||
| CVE-2026-84653 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 3.5 Low |
| Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to. | ||||
| CVE-2026-84656 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.3 Medium |
| A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to. | ||||
| CVE-2026-84657 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.2 Medium |
| In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users. | ||||
| CVE-2026-16190 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | 3.1 Low |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability. | ||||
| CVE-2026-19816 | 2 Packagekit, Redhat | 2 Packagekit, Enterprise Linux | 2026-09-15 | 7.1 High |
| A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend. | ||||
| CVE-2026-53966 | 1 Xwiki | 1 Xwiki-platform | 2026-09-15 | N/A |
| XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing the normal document-saving authorization checks. The user can grant script right and then execute potentially dangerous Velocity scripts or send unfiltered HTML and JavaScript to clients. The same missing checks can circumvent extension security controls implemented as listeners for UserUpdatingDocumentEvent and related user document events. This issue is fixed in versions 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1. | ||||
| CVE-2026-55636 | 1 Projectcapsule | 1 Capsule | 2026-09-15 | 5.7 Medium |
| Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource name namespaces/finalize. A user with namespaces/finalize RBAC can send a PUT request to /api/v1/namespaces/{namespace}/finalize, and the singular rule never matches the plural resource, so the validating webhook is not invoked and the user can change the namespace tenant label. matchPolicy: Equivalent does not compensate because it handles API group and version equivalence rather than resource-name errors. This vulnerability is fixed in 0.13.6. | ||||
| CVE-2026-18110 | 1 Concretecms | 1 Concrete Cms | 2026-09-15 | N/A |
| Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates only a CSRF-style access token that is bound to the selector's display options rather than to the caller's identity or permissions, and that token is issued to anonymous visitors because the selector renders without an authorization check. Because an empty query resolves to a match-all filter, an unauthenticated attacker can submit an empty search and paginate the results to enumerate every backend account, disclosing the internal user ID, username, and email address of all administrative users, including the super-administrator (user ID 1). No password hashes or session material are disclosed The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 8.7 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks thirtythree and YesWeHack for reporting. | ||||
| CVE-2026-75049 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | 6.5 Medium |
| In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | ||||
| CVE-2026-75046 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | ||||
| CVE-2026-75044 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | 8.1 High |
| In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | ||||
| CVE-2026-13210 | 1 Gitlab | 1 Gitlab | 2026-09-15 | 7.7 High |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the environment scope pattern matcher. | ||||
| CVE-2026-87511 | 1 Google | 1 Chrome | 2026-09-15 | 4.3 Medium |
| Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Low) | ||||
| CVE-2026-87473 | 1 Google | 1 Chrome | 2026-09-15 | 6.5 Medium |
| Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-85025 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-09-15 | 9.8 Critical |
| IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls. | ||||
| CVE-2026-90537 | 1 Wwbn | 1 Avideo | 2026-09-15 | 8.2 High |
| WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages. | ||||
| CVE-2026-89267 | 2 Encode, Jowilf | 2 Starlette, Starlette-admin | 2026-09-15 | 4.3 Medium |
| starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns. | ||||