Export limit exceeded: 14168 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14168 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84204 | 1 Growi | 1 Growi | 2026-09-02 | 6.5 Medium |
| GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers. | ||||
| CVE-2026-81164 | 1 Drupal | 1 Entity Pdf | 2026-09-02 | 5.4 Medium |
| Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5. | ||||
| CVE-2026-81158 | 1 Drupal | 1 Entity Api | 2026-09-02 | 5.3 Medium |
| Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0. | ||||
| CVE-2026-73702 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 8.8 High |
| A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise. | ||||
| CVE-2026-73707 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 8.5 High |
| Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product. | ||||
| CVE-2026-73708 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 8.3 High |
| A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system. | ||||
| CVE-2026-66375 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 8.1 High |
| A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. | ||||
| CVE-2026-66377 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 5.3 Medium |
| An unauthenticated user may access restricted repository information under specific conditions. | ||||
| CVE-2026-66378 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | ||||
| CVE-2026-66379 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| An authenticated user may view private Puppet module metadata without repository read access. | ||||
| CVE-2026-66380 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | ||||
| CVE-2026-68753 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 5.3 Medium |
| An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | ||||
| CVE-2026-68754 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 6.5 Medium |
| A repository publisher without delete permission may modify protected package content under specific conditions. | ||||
| CVE-2026-68755 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| A bundle writer may create misleading release promotion information under specific conditions. | ||||
| CVE-2026-68758 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 6.5 Medium |
| A low-privileged authenticated user may access restricted support information under specific conditions. | ||||
| CVE-2026-82463 | 1 Pac4j | 1 Pac4j | 2026-09-02 | 8.1 High |
| pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks. | ||||
| CVE-2026-18544 | 1 Ibm | 1 Portieris | 2026-09-02 | 8.1 High |
| IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references. | ||||
| CVE-2026-78597 | 1 Elastic | 1 Kibana | 2026-09-02 | 4.3 Medium |
| Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an administrative operation that creates and persists Elasticsearch API keys under the caller's identity, bypassing the elevated cluster and Kibana privileges that the documented Entity Store setup flow requires. | ||||
| CVE-2026-78607 | 1 Elastic | 1 Elasticsearch | 2026-09-02 | 5.4 Medium |
| Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed. | ||||
| CVE-2026-72630 | 1 Elastic | 1 Kibana | 2026-09-02 | 7.1 High |
| Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was evaluated against the integration recorded on the stored policy rather than against the replacement integration supplied with the update. An authenticated user holding only the Elastic Defend endpoint policy management privilege was therefore able to convert an endpoint policy they administer into a policy for a different integration, and to supply that integration's configuration at the same time. | ||||