Export limit exceeded: 14781 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14781 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102310 | 1 Google | 1 Chrome | 2026-09-30 | 6.5 Medium |
| Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-94297 | 2026-09-30 | 2.7 Low | ||
| The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site. | ||||
| CVE-2026-103547 | 1 Openbsd | 1 Openbsd | 2026-09-30 | N/A |
| In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.) | ||||
| CVE-2026-87748 | 1 Interprobe Information Technologies Inc. | 1 Qorela Dc | 2026-09-30 | 8.8 High |
| Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2. | ||||
| CVE-2026-102568 | 1 Pardus | 1 Pardus-parental-control | 2026-09-30 | 5.5 Medium |
| Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and application limits without authentication. | ||||
| CVE-2026-61519 | 1 Liberu Software | 1 Liberu Crm | 2026-09-30 | 8.8 High |
| Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can send a POST request to the team-invitations route specifying the admin role for a second account, bypassing privilege-level validation in InviteTeamMember, causing the second account upon invitation acceptance to be attached to the team with full admin-level create, read, update, and delete access over all team-scoped data. | ||||
| CVE-2026-96342 | 2 Amauri, Wordpress-extensions | 2 Wpmobile.app, Wpmobile.app | 2026-09-30 | N/A |
| Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83. | ||||
| CVE-2026-81841 | 1 Grafana | 2 Grafana, Grafana Enterprise | 2026-09-30 | 5.3 Medium |
| Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token. | ||||
| CVE-2026-81842 | 1 Grafana | 2 Grafana, Grafana Enterprise | 2026-09-30 | 4.3 Medium |
| An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed. | ||||
| CVE-2026-47559 | 1 Nvidia | 6 Geforce, Guest Driver, Nvs and 3 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could access memory belonging to another user's process. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-95371 | 2 Apple, Google | 2 Macos, Chrome | 2026-09-30 | 5.4 Medium |
| Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-76111 | 1 Dell | 13 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 10 more | 2026-09-30 | 8.8 High |
| Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation. | ||||
| CVE-2026-13719 | 1 Grafana | 2 Grafana, Grafana Enterprise | 2026-09-30 | 4.3 Medium |
| An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed. | ||||
| CVE-2026-95296 | 2 Apple, Google | 2 Macos, Chrome | 2026-09-30 | 4.3 Medium |
| Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-102320 | 1 Google | 1 Chrome | 2026-09-30 | 6.5 Medium |
| Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-102330 | 1 Google | 1 Chrome | 2026-09-30 | 6.5 Medium |
| Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-100685 | 1 Budibase | 1 Server | 2026-09-30 | 7.7 High |
| Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to access. | ||||
| CVE-2026-103396 | 1 Bbs-go Project | 1 Bbs-go | 2026-09-30 | 4.3 Medium |
| bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the synccount endpoint to trigger expensive full-table user recounts and cache invalidations, causing denial of service through repeated concurrent database operations. | ||||
| CVE-2026-95289 | 1 Google | 1 Chrome | 2026-09-30 | 4.3 Medium |
| Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95317 | 1 Google | 1 Chrome | 2026-09-30 | 3.1 Low |
| Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium) | ||||