Export limit exceeded: 10686 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10686 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39773 | 2 Amentotech, Wordpress-extensions | 2 Doctreat Core, Doctreat Core | 2026-10-06 | 10 Critical |
| Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. | ||||
| CVE-2026-39774 | 2 Tourfic Ai Studio, Wordpress-extensions | 2 Tourfic Pro, Tourfic Pro | 2026-10-06 | 8.8 High |
| Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions. | ||||
| CVE-2026-39775 | 2 Dexignzone, Wordpress-extensions | 2 Jobzilla - Job Board Wordpress Theme, Jobzilla | 2026-10-06 | 8.8 High |
| Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions. | ||||
| CVE-2026-48197 | 2 Publishpress, Wordpress-extensions | 2 Capabilities, Publishpress Capabilities | 2026-10-06 | 7.2 High |
| Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0. | ||||
| CVE-2026-95594 | 2 Cozy Vision Technologies Pvt. Ltd., Wordpress-extensions | 2 Sms Alert Order Notifications, Sms Alert Order Notifications | 2026-10-06 | 8.1 High |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions. | ||||
| CVE-2026-104405 | 2 Nexcess, Wordpress-extensions | 2 Givewp, Givewp | 2026-10-06 | 8.1 High |
| Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions. | ||||
| CVE-2026-104757 | 2 Carazo, Wordpress-extensions | 2 Import And Export Users And Customers, Import And Export Users And Customers | 2026-10-06 | 7.2 High |
| Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions. | ||||
| CVE-2026-105058 | 2 John James Jacoby, Wordpress-extensions | 2 Wp User Profiles, Wp User Profiles | 2026-10-06 | 8.8 High |
| Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions. | ||||
| CVE-2026-105070 | 2 Dimitri Grassi, Wordpress-extensions | 2 Salon Booking System, Salon Booking System | 2026-10-06 | 8.8 High |
| Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions. | ||||
| CVE-2026-67269 | 2026-10-06 | 9.9 Critical | ||
| Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes. | ||||
| CVE-2026-81445 | 1 Dell | 6 Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4, Dell Openmanage Server Administrator Managed Node For Sles 15 and 3 more | 2026-10-06 | 7.2 High |
| Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||||
| CVE-2026-81442 | 1 Dell | 6 Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4, Dell Openmanage Server Administrator Managed Node For Sles 15 and 3 more | 2026-10-06 | 8.1 High |
| Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access. | ||||
| CVE-2026-105687 | 1 Penpot | 1 Penpot | 2026-10-06 | 4.9 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner's team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105634 | 1 Makeplane | 1 Plane | 2026-10-06 | 8.1 High |
| Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0. | ||||
| CVE-2026-92012 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-06 | 8.8 High |
| Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. | ||||
| CVE-2026-92015 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-06 | 8.8 High |
| Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. | ||||
| CVE-2026-92017 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-06 | 8.8 High |
| Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. | ||||
| CVE-2026-105688 | 1 Penpot | 1 Penpot | 2026-10-06 | 6.7 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105621 | 1 Jishenghua | 1 Jsherp | 2026-10-06 | 5.4 Medium |
| A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105610 | 1 Chillzhuang | 1 Springblade | 2026-10-06 | 4.7 Medium |
| A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter Submit Management. The manipulation of the argument initPassword results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||