Export limit exceeded: 403484 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403484 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (43608 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106187 | 1 Google | 1 Chrome | 2026-10-08 | 4.2 Medium |
| Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106191 | 1 Google | 1 Chrome | 2026-10-08 | 8.3 High |
| Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106183 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-10-08 | 5.9 Medium |
| Missing authorization in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-106194 | 1 Google | 1 Chrome | 2026-10-08 | 8.3 High |
| Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106306 | 1 Google | 1 Chrome | 2026-10-08 | 5.4 Medium |
| Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106307 | 1 Google | 1 Chrome | 2026-10-08 | 6.5 Medium |
| Incorrect authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106244 | 1 Google | 1 Chrome | 2026-10-08 | 6.5 Medium |
| Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-102488 | 2026-10-08 | N/A | ||
| In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them. | ||||
| CVE-2026-106205 | 1 Google | 2 Android, Chrome | 2026-10-08 | 8.1 High |
| Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-104671 | 2026-10-08 | 5.3 Medium | ||
| The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled. | ||||
| CVE-2026-105190 | 2026-10-08 | 5.3 Medium | ||
| The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role. | ||||
| CVE-2026-12260 | 1 Netboard Crm | 1 Netboard Crm Demo Platform | 2026-10-08 | N/A |
| SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or further compromise the CRM environment. | ||||
| CVE-2026-32582 | 2026-10-08 | 6.5 Medium | ||
| Missing Authorization vulnerability in iatoai IATO MCP iato-mcp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IATO MCP: from n/a through 1.12.0. | ||||
| CVE-2026-105472 | 1 Girishsaraf | 1 Online-appointment-booking-system | 2026-10-08 | 6.3 Medium |
| A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component Booking Handler. This manipulation of the argument Doctor/appointment causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105468 | 1 Girishsaraf | 1 Online-appointment-booking-system | 2026-10-08 | 7.3 High |
| A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105447 | 1 Redhat | 1 Quay | 2026-10-08 | 5.5 Medium |
| A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to retrieve these delegate tokens. This issue allows a restricted user to bypass read-only limitations and push arbitrary container images to private repositories, leading to privilege escalation. | ||||
| CVE-2026-104039 | 2 Redhat, Sssd | 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more | 2026-10-08 | 4.7 Medium |
| A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When handling Generic Security Services Application Programming Interface (GSSAPI) authentication in the Pluggable Authentication Module (PAM) responder, cached connection state is freed upon completion without clearing the reference pointer. An attacker can exploit this by sending an additional request over the same connection, causing the service to access invalid memory and unexpectedly terminate. | ||||
| CVE-2026-95386 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service | ||||
| CVE-2026-106222 | 1 Google | 1 Chrome | 2026-10-08 | 5.9 Medium |
| Incorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-106224 | 1 Google | 1 Chrome | 2026-10-08 | 3.1 Low |
| Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||