Export limit exceeded: 396426 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 10091 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10091 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-56829 | 1 Shopperlabs | 1 Shopper | 2026-09-15 | 8.1 High |
| Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user, including staff with only browse_products, can select an arbitrary product variant and inventory location through component state, then submit a positive or negative quantity adjustment. This permits browse-only staff to inflate stock, reduce stock, or force out-of-stock states for variants outside the current page. This issue is fixed in version 2.9.2. | ||||
| CVE-2026-90535 | 1 Flowiseai | 1 Flowise | 2026-09-15 | 7.5 High |
| Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption. | ||||
| CVE-2026-90533 | 1 Flowiseai | 1 Flowise | 2026-09-15 | 6.5 Medium |
| Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain the owner's credential hash for offline cracking, enabling account takeover of the highest-privileged account. | ||||
| CVE-2026-87792 | 1 Developers Italia | 1 Design-scuole-wordpress-theme | 2026-09-15 | N/A |
| The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/ further facilitates exploitation. | ||||
| CVE-2026-12758 | 1 Ibm | 1 Cloud Pak For Business Automation | 2026-09-15 | 5.4 Medium |
| IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. | ||||
| CVE-2026-12742 | 1 Ibm | 1 Business Automation Workflow Containers And Traditional | 2026-09-15 | 5.4 Medium |
| IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | ||||
| CVE-2026-84653 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 3.5 Low |
| Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to. | ||||
| CVE-2026-84656 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.3 Medium |
| A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to. | ||||
| CVE-2026-84657 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.2 Medium |
| In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users. | ||||
| CVE-2026-16190 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | 3.1 Low |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability. | ||||
| CVE-2026-53966 | 1 Xwiki | 1 Xwiki-platform | 2026-09-15 | N/A |
| XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing the normal document-saving authorization checks. The user can grant script right and then execute potentially dangerous Velocity scripts or send unfiltered HTML and JavaScript to clients. The same missing checks can circumvent extension security controls implemented as listeners for UserUpdatingDocumentEvent and related user document events. This issue is fixed in versions 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1. | ||||
| CVE-2026-75049 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | 6.5 Medium |
| In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | ||||
| CVE-2026-75046 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | ||||
| CVE-2026-75044 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | 8.1 High |
| In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | ||||
| CVE-2026-87511 | 1 Google | 1 Chrome | 2026-09-15 | 4.3 Medium |
| Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Low) | ||||
| CVE-2026-90537 | 1 Wwbn | 1 Avideo | 2026-09-15 | 8.2 High |
| WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages. | ||||
| CVE-2026-90547 | 1 Wwbn | 1 Avideo | 2026-09-15 | 5.3 Medium |
| WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected videos. Attackers can query the endpoint with a video ID parameter to retrieve sensitive chapter metadata without authentication or password verification. | ||||
| CVE-2026-61549 | 1 Woodpecker-ci | 1 Woodpecker | 2026-09-15 | N/A |
| Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization. Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions. When a privileged ServiceAccount is reachable, the attacker can exfiltrate secrets such as database credentials, API keys, and TLS certificates and may take over the cluster. This issue is fixed in version 3.16.0. | ||||
| CVE-2026-91929 | 1 Flowiseai | 1 Flowise | 2026-09-15 | 7.1 High |
| Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets. | ||||
| CVE-2026-75051 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | 8.1 High |
| In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | ||||