Export limit exceeded: 398253 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 398253 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 25019 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 10191 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10191 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-72675 | 1 Elastic | 1 Kibana | 2026-09-02 | 7.1 High |
| Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment. | ||||
| CVE-2026-74927 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-09-02 | 5.3 Medium |
| The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications. | ||||
| CVE-2026-81427 | 2026-09-02 | 4.3 Medium | ||
| The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email. | ||||
| CVE-2026-84802 | 1 Craftcms | 1 Craft Cms | 2026-09-02 | 4.3 Medium |
| Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and total storage size for volumes they cannot access. | ||||
| CVE-2026-84797 | 1 Craftcms | 1 Craft Cms | 2026-09-02 | 6.3 Medium |
| Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the deleteProvisionalDraft parameter to delete another user's unsaved draft without proper authorization checks, gaining access to the victim's in-progress content. | ||||
| CVE-2026-84792 | 1 Craftcms | 1 Craft Cms | 2026-09-02 | 4.3 Medium |
| Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation. | ||||
| CVE-2026-84760 | 2 Wordpress, Wpswings | 2 Wordpress, Ultimate Gift Cards For Woocommerce | 2026-09-02 | 5.3 Medium |
| Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. | ||||
| CVE-2026-77787 | 2 Rank Math Seo, Wordpress | 2 Rank Math Seo, Wordpress | 2026-09-02 | 2.7 Low |
| The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users. | ||||
| CVE-2026-14215 | 2026-09-02 | 6.5 Medium | ||
| The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier. | ||||
| CVE-2026-82746 | 1 Ash-project | 1 Ash | 2026-09-01 | N/A |
| Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic path of Ash.update_many/4. Ash.update_many/4 runs as a single atomic statement (a data-layer update_many, for example a SQL MERGE) whenever an atomic strategy is used and the data layer supports it. Ash.Actions.Update.UpdateMany (lib/ash/actions/update/update_many.ex) took that path even under authorize?: true without applying the resource's policies, so the statement updated every row matched by primary key regardless of the policy filter that authorization would impose. An actor could therefore update records the policies forbid, such as rows belonging to another actor or tenant. The fix restricts the atomic path to data layers supporting changeset filters when authorizing, authorizes each changeset, and merges the resulting policy filter into each changeset so the statement only touches authorized rows. This issue affects ash: from 3.29.0 before 3.32.2. | ||||
| CVE-2026-13611 | 2 Kivicare, Wordpress | 2 Kivicare, Wordpress | 2026-09-01 | 5.3 Medium |
| The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key. | ||||
| CVE-2026-81278 | 2 Wordpress, Wpexperts | 2 Wordpress, Post Smtp | 2026-09-01 | 5.4 Medium |
| Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1. | ||||
| CVE-2026-81758 | 2 Ownerrez, Wordpress | 2 Ownerrez Api, Wordpress | 2026-09-01 | 6.3 Medium |
| Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions. | ||||
| CVE-2026-19948 | 2 Cozythemes, Wordpress | 2 Cozy Blocks – Page Builder For Gutenberg Editor & Fse With 600+ Patterns, 58 Blocks & Templates, Wordpress | 2026-09-01 | 5.3 Medium |
| The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve the name, price, short description, image URL, permalink, stock status, and product type of draft, pending, private, and catalog-hidden WooCommerce products not intended to be publicly visible. The sidebarNonce value is emitted unconditionally into public page HTML by multiple block renderers with no login gate, allowing unauthenticated visitors to harvest a valid nonce and pass the only authentication check in the handler. | ||||
| CVE-2026-77966 | 1 Ebyte | 1 Ebyte Na111-m Firmware | 2026-09-01 | 8.8 High |
| The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity, or availability of the device. | ||||
| CVE-2026-50152 | 1 Ceph | 1 Ceph | 2026-09-01 | 9.1 Critical |
| Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6 | ||||
| CVE-2026-24369 | 2 Theme-one, Wordpress | 2 The Grid, Wordpress | 2026-09-01 | 7.1 High |
| Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0. | ||||
| CVE-2026-24368 | 1 Wordpress | 1 Wordpress | 2026-09-01 | 5.3 Medium |
| Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0. | ||||
| CVE-2026-75798 | 2 Ai Engine Project, Wordpress | 2 Ai Engine, Wordpress | 2026-09-01 | 5.3 Medium |
| The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account. | ||||
| CVE-2026-18431 | 2 Themefusion, Wordpress | 3 Avada | Website Builder For Wordpress & Woocommerce, Fusion Builder, Wordpress | 2026-09-01 | 9.8 Critical |
| The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present. | ||||