Export limit exceeded: 400410 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10316 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97267 | 2026-09-30 | 4.3 Medium | ||
| Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. | ||||
| CVE-2026-97247 | 2026-09-30 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. | ||||
| CVE-2026-97243 | 2026-09-30 | 5.4 Medium | ||
| Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions. | ||||
| CVE-2026-97239 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | ||||
| CVE-2026-97197 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | ||||
| CVE-2026-96834 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. | ||||
| CVE-2026-96823 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | ||||
| CVE-2026-96818 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. | ||||
| CVE-2026-96817 | 2026-09-30 | 8.2 High | ||
| Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. | ||||
| CVE-2026-96348 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Bookly <= 28.2 versions. | ||||
| CVE-2026-95587 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. | ||||
| CVE-2026-94499 | 2026-09-30 | 7.1 High | ||
| Subscriber Broken Access Control in FormGent <= 1.12.2 versions. | ||||
| CVE-2026-94120 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. | ||||
| CVE-2026-94074 | 2026-09-30 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. | ||||
| CVE-2026-100634 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-30 | 4.7 Medium |
| SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any received payload to every BrowserWindow returned by BrowserWindow.getAllWindows(), including windows belonging to other opened workspaces. A renderer connected to an attacker-controlled remote kernel can therefore send {cmd: "lockscreenByMode"} and have it delivered across the workspace boundary; a sibling workspace window whose lockScreenMode is set to 1 invokes lockScreen(). Repeated messages allow the remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. No confidentiality, integrity, or code-execution impact was observed. | ||||
| CVE-2026-100617 | 1 Cap-go | 1 Cap-go | 2026-09-30 | 8.8 High |
| Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped permissions such as channel.promote_bundle to users outside the organization. | ||||
| CVE-2026-100605 | 1 Flowiseai | 1 Flowise | 2026-09-30 | 7.1 High |
| Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message routes without required flow permissions to read chat histories, prompts, model responses, and delete messages. | ||||
| CVE-2026-55483 | 2 Grokability, Snipeitapp | 2 Snipe-it, Snipe-it | 2026-09-30 | 8.8 High |
| Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php strips superuser permission but does not strip admin permission. The created account can obtain administrative privileges. This issue is fixed in version 8.6.0. | ||||
| CVE-2026-55703 | 2 Grokability, Snipeitapp | 2 Snipe-it, Snipe-it | 2026-09-30 | 4.3 Medium |
| Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController.php show() renders the record without authorize(), while company-scoped route-model binding only prevents access to other companies. Disclosed fields include asset tags, suppliers, purchase costs, notes, and dates. This issue is fixed in version 8.6.3. | ||||
| CVE-2026-97285 | 2026-09-30 | 5.4 Medium | ||
| Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. | ||||