Export limit exceeded: 15062 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15062 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76470 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682. | ||||
| CVE-2026-76467 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 7.5 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76467 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. | ||||
| CVE-2026-17538 | 2 Latepoint, Wordpress-extensions | 2 Latepoint, Latepoint | 2026-10-09 | 5.4 Medium |
| The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This is due to the process_step_customer() function using is_user_logged_in() as the sole gate before merging POSTed customer data into an existing LatePoint customer, without any ownership checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the personal information (first name, last name, email, phone, notes) of arbitrary LatePoint customers, and, when the contact_merge setting is 'phone', to overwrite the victim's email address and take over the account via a password reset. | ||||
| CVE-2026-107444 | 2 Katello, Redhat | 4 Katello, Hardened Images, Hummingbird and 1 more | 2026-10-09 | 4.3 Medium |
| A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries. | ||||
| CVE-2026-107445 | 2 Katello, Redhat | 4 Katello, Hardened Images, Hummingbird and 1 more | 2026-10-09 | 5.4 Medium |
| A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier. An authenticated user with permission to view flatpak remotes in one organization may be able to access flatpak remote repository information belonging to another organization. The same unscoped lookup is used by the mirror action, which may allow creating a repository in a product the user can edit that is configured with another organization's flatpak remote URL and stored remote credentials. | ||||
| CVE-2026-104645 | 1 Wordpress-extensions | 1 Image Photo Gallery Final Tiles Grid | 2026-10-09 | 2.7 Low |
| The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not properly verify authorization on several of its gallery and image management actions, checking ownership against a different object than the one being acted on, or omitting the check entirely, allowing any authenticated user with contributor-level access or above to clone, modify and reorder galleries and images belonging to other users and to write Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 metadata onto arbitrary posts they do not own. | ||||
| CVE-2026-105196 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 3.3 Low |
| The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled. | ||||
| CVE-2026-105197 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 2.7 Low |
| The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope. | ||||
| CVE-2026-105198 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 5.3 Medium |
| The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id. | ||||
| CVE-2026-94245 | 1 Wordpress-extensions | 1 Wallet System For Woocommerce | 2026-10-09 | 6.5 Medium |
| The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control. | ||||
| CVE-2026-94246 | 1 Wordpress-extensions | 1 Wallet System For Woocommerce | 2026-10-09 | 6.3 Medium |
| The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own. | ||||
| CVE-2026-104671 | 1 Wordpress-extensions | 1 Tutorsstarter | 2026-10-09 | 5.3 Medium |
| The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled. | ||||
| CVE-2026-107275 | 1 Fastify | 1 Fastify/jwt | 2026-10-09 | 6.8 Medium |
| @fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it. | ||||
| CVE-2026-19083 | 1 Akin | 1 Octocloud | 2026-10-09 | 8.8 High |
| Authorization bypass through User-Controlled key vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. OctoCloud allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects OctoCloud: from 1.12.06 before 1.12.07. | ||||
| CVE-2026-19218 | 1 Akin | 1 Myrezzta | 2026-10-09 | 9.1 Critical |
| Weak Password Recovery Mechanism for Forgotten Password vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. MyRezzta allows Password Recovery Exploitation. This issue affects MyRezzta: from 2.06.03 before 2.07.01. | ||||
| CVE-2026-107640 | 1 Integrics | 1 Enswitch | 2026-10-09 | 9.1 Critical |
| Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames. | ||||
| CVE-2026-107298 | 1 Mcollina | 1 Msgpack5 | 2026-10-09 | 5.3 Medium |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0. | ||||
| CVE-2026-107300 | 1 Mcollina | 1 Msgpack5 | 2026-10-09 | 7.5 High |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0. | ||||
| CVE-2026-107793 | 1 Banq | 1 Jivejdon | 2026-10-09 | 4.3 Medium |
| Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another user's subscriptionId to remove their thread, forum, tag or account subscriptions. | ||||
| CVE-2026-105643 | 1 Ghost | 1 Ghost | 2026-10-09 | 7.3 High |
| Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s admin session. Self-hosted sites should leave the new security.embedPreviewUrl configuration option at its default value. This issue is fixed in version 6.67.0. | ||||