Export limit exceeded: 11980 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 14733 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14733 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106289 | 1 Google | 1 Chrome | 2026-10-07 | N/A |
| Missing authorization in FedCM in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106355 | 1 Google | 1 Chrome | 2026-10-07 | 5.3 Medium |
| Missing authorization in Media in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106422 | 1 Google | 1 Chrome | 2026-10-07 | 4.3 Medium |
| Incorrect authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106352 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106384 | 1 Google | 1 Chrome | 2026-10-07 | 5.3 Medium |
| Missing authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106362 | 1 Google | 1 Chrome | 2026-10-07 | N/A |
| Missing authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low) | ||||
| CVE-2026-106340 | 1 Google | 1 Chrome | 2026-10-07 | 4.6 Medium |
| Missing authorization in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via physical access. (Chromium security severity: Low) | ||||
| CVE-2026-106297 | 1 Google | 1 Chrome | 2026-10-07 | N/A |
| Incorrect authorization in Scheduling in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106387 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-103007 | 1 Elastic | 1 Elasticsearch | 2026-10-07 | 7.2 High |
| Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indices. The authorization check that enforces this scoping does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly-scoped index pattern can exploit this inconsistency by updating their own assigned role to gain access to indices that should remain restricted, including internal security data. This can enable further escalation up to full administrative control of the cluster. | ||||
| CVE-2026-106350 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106492 | 2026-10-07 | 7.6 High | ||
| Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. This issue is fixed in versions 0.16.1 and 0.17.8. | ||||
| CVE-2026-106498 | 2026-10-06 | 7.7 High | ||
| Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1. | ||||
| CVE-2026-102410 | 1 Elastic | 1 Kibana | 2026-10-06 | 4.3 Medium |
| Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal API surface within the Metrics Experience feature did not enforce a Kibana-level authorization check that an equivalent, related API in the same feature did enforce. As a result, a user who held only data-store-level read access to an index, but no corresponding Kibana feature privilege, could retrieve index-derived metric data through Kibana that the properly-authorized API would otherwise have blocked. | ||||
| CVE-2026-106040 | 1 Kvcache-ai | 1 Mooncake | 2026-10-06 | 8.2 High |
| Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on disk. | ||||
| CVE-2026-102412 | 1 Elastic | 1 Kibana | 2026-10-06 | 6.5 Medium |
| Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with limited Fleet management privileges could access sensitive credential material that should be restricted to users with Fleet settings administrative access. Successful exploitation could allow an attacker to obtain private cryptographic key material configured for Fleet Server host connections, potentially enabling impersonation of trusted Fleet infrastructure components in deployments where those keys are actively used. | ||||
| CVE-2026-39762 | 2 Patterns In The Cloud, Wordpress-extensions | 2 Autoship Cloud For Woocommerce Subscription Products, Autoship Cloud For Woocommerce Subscription Products | 2026-10-06 | 6.5 Medium |
| Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1. | ||||
| CVE-2026-39787 | 2 10web, Wordpress-extensions | 2 10web Social Post Feed, 10web Social Photo Feed | 2026-10-06 | 6.5 Medium |
| Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions. | ||||
| CVE-2026-39794 | 2 Wclovers, Wordpress-extensions | 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. | ||||
| CVE-2026-39796 | 2 Flipper Code, Wordpress-extensions | 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. | ||||