Export limit exceeded: 10514 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10514 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-62179 | 2026-10-07 | 6.5 Medium | ||
| PraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member cannot delete a dependency through the owner-created issue endpoint, but can delete the same dependency through a member-owned related issue endpoint because the route accepts either endpoint and checks delete permission only against the caller-selected URL issue. Version 0.1.9 patches the issue. | ||||
| CVE-2026-103620 | 1 Github | 1 Enterprise Server | 2026-10-07 | N/A |
| A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become the new default. In repositories that required pull-request review but did not restrict branch deletion, this bypassed the review requirement and caused fresh clones and default-branch API requests to use attacker-controlled content. This vulnerability affected supported GitHub Enterprise Server releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series and was fixed in versions 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2. This vulnerability was reported via the GitHub Bug Bounty program. | ||||
| CVE-2026-106489 | 2026-10-07 | 6.5 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper authorization enforcement for techdocs static content. An authenticated user with access to one TechDocs documentation site could craft a URL able to read documentation belonging to a different entity. This only affects deployments using the external TechDocs builder with an external storage provider (S3, GCS, etc.) and the permission framework enabled. Instances that do not use the permission framework are unaffected, since TechDocs content is visible to all authenticated users by design. This issue is fixed in version 2.2.4. | ||||
| CVE-2025-69016 | 2 Averta, Wordpress | 2 Shortcodes And Extra Features For Phlox Theme, Wordpress | 2026-10-07 | 4.3 Medium |
| Missing Authorization vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.22. | ||||
| CVE-2026-14259 | 1 Mattermost | 2 Mattermost, Mattermost Server | 2026-10-07 | 4.3 Medium |
| Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator restrictions via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00712 | ||||
| CVE-2026-14344 | 1 Mattermost | 2 Mattermost, Mattermost Server | 2026-10-07 | 4.3 Medium |
| Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-and-blocks, and archive-import endpoints.. Mattermost Advisory ID: MMSA-2026-00715 | ||||
| CVE-2026-18132 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-07 | 6.5 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization. | ||||
| CVE-2026-8821 | 1 Mattermost | 2 Mattermost, Mattermost Server | 2026-10-07 | 7.1 High |
| Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a restricted channel via the run owner field.. Mattermost Advisory ID: MMSA-2026-00677 | ||||
| CVE-2026-81164 | 2 Drupal, Entity Pdf Project | 2 Entity Pdf, Entity Pdf | 2026-10-07 | 5.4 Medium |
| Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5. | ||||
| CVE-2026-39730 | 2026-10-07 | 7.1 High | ||
| Missing Authorization vulnerability in Marcin Wise Chat wise-chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wise Chat: from n/a through 3.4.3. | ||||
| CVE-2026-106563 | 2026-10-07 | 5.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 0.21.8, the @backstage/plugin-kubernetes-backend package is affected by improper entity validation in deprecated kubernetes services endpoint. An authenticated user with Kubernetes read permissions could access Kubernetes workload data beyond their intended scope by supplying crafted entity data to the deprecated services endpoint. The exposure is limited to read-only access to Kubernetes object metadata across configured clusters. This issue is fixed in version 0.21.8. | ||||
| CVE-2026-58068 | 2026-10-07 | N/A | ||
| This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system. | ||||
| CVE-2026-106264 | 1 Google | 1 Chrome | 2026-10-07 | 5.4 Medium |
| Missing authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106312 | 1 Google | 1 Chrome | 2026-10-07 | 6.5 Medium |
| Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low) | ||||
| CVE-2026-106323 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-07 | 9.6 Critical |
| Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106388 | 1 Google | 1 Chrome | 2026-10-07 | 5.3 Medium |
| Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106406 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-07 | 5.4 Medium |
| Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106410 | 1 Google | 1 Chrome | 2026-10-07 | 4.2 Medium |
| Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-45524 | 1 Google | 1 Android | 2026-10-07 | 8.8 High |
| In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-18177 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-07 | 7.1 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks. | ||||