Export limit exceeded: 14765 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14765 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104079 | 2026-10-09 | 4.3 Medium | ||
| Envira Gallery Lite before 1.16.2 contains a missing authorization vulnerability in its gallery conversion REST endpoint that allows lower-privileged authenticated users to create and publish Envira galleries without the required capabilities, because the endpoint only checks edit permissions on the source post and uses a hard-coded publish status. Attackers can also supply arbitrary caller-controlled image IDs without ownership verification to publish unauthorized content using attachments they are not authorized to use. | ||||
| CVE-2026-103007 | 1 Elastic | 1 Elasticsearch | 2026-10-09 | 7.2 High |
| Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indices. The authorization check that enforces this scoping does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly-scoped index pattern can exploit this inconsistency by updating their own assigned role to gain access to indices that should remain restricted, including internal security data. This can enable further escalation up to full administrative control of the cluster. | ||||
| CVE-2026-105403 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 6.2 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-93860 | 1 Openstack | 1 Mistral | 2026-10-09 | 6.5 Medium |
| In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned role, can read and change the service's cluster-wide maintenance state. Setting the state to PAUSED stops processing of new workflow and execution objects across all tenant projects until an operator restores it. | ||||
| CVE-2026-107395 | 1 Indico | 1 Indico | 2026-10-09 | 4.3 Medium |
| Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, an authenticated user can misuse the legacy session export API to retrieve details for a restricted session without access to that session, as long as the containing event is accessible. The missing access check can disclose session metadata such as the title, description, and conveners. This issue is fixed in version 3.3.13. | ||||
| CVE-2026-62028 | 2026-10-09 | 5.4 Medium | ||
| Missing Authorization vulnerability in bPlugins Before After Image Comparison – Image comparison for WP before-after-image-compare allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Before After Image Comparison – Image comparison for WP: from n/a through 1.1.21. | ||||
| CVE-2026-105883 | 2026-10-09 | 7.1 High | ||
| Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Th Shop Mania: from n/a through 1.9.1. | ||||
| CVE-2026-106397 | 1 Google | 1 Chrome | 2026-10-09 | 6.1 Medium |
| Incorrect authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-39779 | 2026-10-09 | 4.3 Medium | ||
| Missing Authorization vulnerability in Asgaros Asgaros Forum asgaros-forum allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asgaros Forum: from n/a through 3.4.0. | ||||
| CVE-2026-62040 | 2026-10-09 | 5.3 Medium | ||
| Missing Authorization vulnerability in DEV Institute Restrict User Access – Membership Plugin with Force restrict-user-access allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through 2.8.1. | ||||
| CVE-2026-62041 | 2026-10-09 | 5.4 Medium | ||
| Missing Authorization vulnerability in Ashok Dudhat WP Event Manager wp-event-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Manager: from n/a through 3.4.1. | ||||
| CVE-2026-62042 | 2026-10-09 | 5.3 Medium | ||
| Missing Authorization vulnerability in unFocus Projects Scripts n Styles scripts-n-styles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scripts n Styles: from n/a through 3.5.8. | ||||
| CVE-2026-39717 | 2026-10-09 | 4.3 Medium | ||
| Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.10. | ||||
| CVE-2026-107419 | 2026-10-09 | 5.4 Medium | ||
| Missing Authorization vulnerability in Cool Plugins AI Translation for Polylang automatic-translations-for-polylang allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Translation for Polylang: from n/a through 1.6.2. | ||||
| CVE-2026-78341 | 2026-10-09 | 6.5 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access. | ||||
| CVE-2026-96334 | 2026-10-09 | 5.6 Medium | ||
| Missing Authorization vulnerability in ThemeGrill User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 5.2.7. | ||||
| CVE-2026-95589 | 2026-10-09 | 6.5 Medium | ||
| Missing Authorization vulnerability in Magepeople inc. Deposits and Partial Payments for WooCommerce advanced-partial-payment-or-deposit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Deposits and Partial Payments for WooCommerce: from n/a through 4.0.1. | ||||
| CVE-2026-95597 | 2026-10-09 | 6.5 Medium | ||
| Missing Authorization vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 워드프레스 결제 심플페이: from n/a through 5.5.17. | ||||
| CVE-2026-96461 | 2026-10-09 | 7.5 High | ||
| Missing Authorization vulnerability in TMS Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through 2.4.10. | ||||
| CVE-2026-96337 | 2026-10-09 | 6.5 Medium | ||
| Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3. | ||||