Export limit exceeded: 14802 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14802 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106425 | 1 Google | 1 Chrome | 2026-10-07 | 6.5 Medium |
| Missing authorization in BrowserTag in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106355 | 1 Google | 1 Chrome | 2026-10-07 | 5.3 Medium |
| Missing authorization in Media in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106352 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106340 | 1 Google | 1 Chrome | 2026-10-07 | 4.6 Medium |
| Missing authorization in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via physical access. (Chromium security severity: Low) | ||||
| CVE-2026-106350 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106040 | 1 Kvcache-ai | 1 Mooncake | 2026-10-06 | 8.2 High |
| Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on disk. | ||||
| CVE-2026-39762 | 2 Patterns In The Cloud, Wordpress-extensions | 2 Autoship Cloud For Woocommerce Subscription Products, Autoship Cloud For Woocommerce Subscription Products | 2026-10-06 | 6.5 Medium |
| Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1. | ||||
| CVE-2026-39787 | 2 10web, Wordpress-extensions | 2 10web Social Post Feed, 10web Social Photo Feed | 2026-10-06 | 6.5 Medium |
| Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions. | ||||
| CVE-2026-39794 | 2 Wclovers, Wordpress-extensions | 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. | ||||
| CVE-2026-39796 | 2 Flipper Code, Wordpress-extensions | 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. | ||||
| CVE-2026-39798 | 2 Themetechmount, Wordpress-extensions | 2 Truebooker, Truebooker | 2026-10-06 | 6.5 Medium |
| Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. | ||||
| CVE-2026-41560 | 2 Wordpress-extensions, Wxdlabs | 2 Wxd Backup Lite, Wxd Backup Lite | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions. | ||||
| CVE-2026-105306 | 1 Redhat | 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more | 2026-10-06 | 6.5 Medium |
| A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm. | ||||
| CVE-2026-39763 | 2 Deepak Anand, Wordpress-extensions | 2 Wp Dummy Content Generator, Wp Dummy Content Generator | 2026-10-06 | 4.3 Medium |
| Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0. | ||||
| CVE-2026-94669 | 2 Wordpress-extensions, Wpmanageninja | 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack | 2026-10-06 | 5.3 Medium |
| Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13. | ||||
| CVE-2026-103684 | 2 Arraytics, Wordpress-extensions | 2 Wp Event Solution, Wp Event Solution | 2026-10-06 | 5.3 Medium |
| Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25. | ||||
| CVE-2026-39783 | 2 Wordpress-extensions, Wp Syntex | 2 Polylang, Polylang | 2026-10-06 | 4.3 Medium |
| Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7. | ||||
| CVE-2026-105421 | 2 Nathanbarry, Wordpress-extensions | 2 Kit (formerly Convertkit) For Woocommerce, Kit (formerly Convertkit) For Woocommerce | 2026-10-06 | 5.3 Medium |
| Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0. | ||||
| CVE-2026-104891 | 2 Douglasborthwick-crypto, Insumermodel | 3 Mppx-condition-gate, Mppx-condition-gate, Mppx-token-gate | 2026-10-06 | 7.5 High |
| mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4. | ||||
| CVE-2026-102780 | 1 Joomlafry.com | 1 Tf Content For Joomla | 2026-10-06 | N/A |
| Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the request-selected existing record ID, and saves it without filtering submitted properties through the configured form. A Guest can obtain a valid token from Joomla's public login form and modify any TF Content row, including mass-assigning `published`, `access`, and `created_by`. | ||||