Export limit exceeded: 16712 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 10780 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 14792 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (14792 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106246 1 Google 1 Chrome 2026-10-07 5.4 Medium
Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106249 1 Google 2 Android, Chrome 2026-10-07 8.8 High
Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106328 1 Google 2 Android, Chrome 2026-10-07 5.9 Medium
Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
CVE-2026-106329 1 Google 1 Chrome 2026-10-07 9.6 Critical
Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106253 1 Google 1 Chrome 2026-10-07 4.3 Medium
Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-45524 1 Google 1 Android 2026-10-07 8.8 High
In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-18177 2 Ibm, Redhat 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift 2026-10-07 7.1 High
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
CVE-2026-18179 2 Ibm, Redhat 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift 2026-10-07 6.5 Medium
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.
CVE-2026-93026 1 Veeam 1 Backup And Replication 2026-10-07 N/A
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials.
CVE-2026-89182 1 Gitea 1 Gitea 2026-10-07 5.4 Medium
With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.
CVE-2026-27434 2026-10-07 5.3 Medium
Missing Authorization vulnerability in sc Internet Vivoo WP Rentals wprentals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rentals: from n/a through 3.14.2.
CVE-2026-105876 2026-10-07 5.3 Medium
Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Retrieve Embedded Sensitive Data.This issue affects Modula Image Gallery: from n/a through 3.0.11.
CVE-2026-104390 2026-10-07 4.3 Medium
Missing Authorization vulnerability in Arraytics Booktics booktics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booktics: from n/a through 1.0.27.
CVE-2026-103075 2026-10-07 4.3 Medium
Missing Authorization vulnerability in WPMU DEV Hustle wordpress-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hustle: from n/a through 7.8.14.2.
CVE-2026-106041 1 Kvcache-ai 1 Mooncake 2026-10-07 6.5 Medium
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence.
CVE-2026-42638 2 Syed Balkhi, Wordpress-extensions 2 Easy Digital Downloads, Easy Digital Downloads 2026-10-07 7.5 High
Missing Authorization vulnerability in Awesomemotive Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.7.1.
CVE-2026-102375 2 Optimole, Wordpress-extensions 2 Optimole, Optimole 2026-10-07 6.5 Medium
Missing Authorization vulnerability in Optimole Optimole optimole-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Optimole: from n/a through 4.2.14.
CVE-2026-106039 1 Kvcache-ai 1 Mooncake 2026-10-07 6.5 Medium
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client UUIDs disclosed by QueryTask to hijack task queues and record replication that never occurred.
CVE-2026-105797 1 Microsoft 1 Simplechat 2026-10-07 8.8 High
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-privileged user to omit the top-level MCP type so that _reject_non_admin_mcp_stdio skips inspection before the type is restored from metadata. The stored personal action can then reach McpPluginFactory.create_connector, and MCPStdioPlugin.connect starts the attacker-selected operating-system process under the application service identity when the action tool is invoked. Exploitation requires personal plugins to be enabled and governance to permit MCP actions, and it can expose or modify secrets and data available to the service or disrupt the service. This issue is fixed in version 0.261.031.
CVE-2026-105805 1 Payloadcms 1 Payload 2026-10-07 N/A
Payload is a free and open source headless content management system. In versions before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query a readable collection, control its sorting, and select a protected field as the sort parameter can infer limited information about field values the user cannot read. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.