Export limit exceeded: 15283 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 16716 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16716 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104678 | 1 Wordpress-extensions | 1 Cp Media Player | 2026-10-09 | 2.7 Low |
| The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access. | ||||
| CVE-2026-86816 | 1 Wordpress-extensions | 1 Wpcafe | 2026-10-09 | 5.3 Medium |
| The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication. | ||||
| CVE-2026-87782 | 1 Wordpress-extensions | 1 Koinonia Link | 2026-10-09 | 8.8 High |
| The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role. | ||||
| CVE-2026-102781 | 1 Ordasoft.com | 1 Touch Slider Extension For Joomla | 2026-10-09 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path. | ||||
| CVE-2026-76463 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76463 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. | ||||
| CVE-2026-103309 | 1 Wordpress-extensions | 1 Gptranslate | 2026-10-09 | 7.5 High |
| The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled. | ||||
| CVE-2026-103646 | 1 Wordpress-extensions | 1 Ultimate Multisite | 2026-10-09 | 9.8 Critical |
| The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know. This bypass is not addressed by the 2.15.1 fix for CVE-2026-75957 and remains exploitable in all versions up to and including 2.16.1, the releases that fix was expected to cover. Exploitation requires a checkout form configured without a password field (auto-generated password) and a target account that has no existing customer record in the Ultimate Multisite WordPress plugin before 2.17.0. | ||||
| CVE-2026-105196 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 3.3 Low |
| The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled. | ||||
| CVE-2026-94275 | 1 Wordpress-extensions | 1 Track Orders For Woocommerce | 2026-10-09 | 5.3 Medium |
| The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address. | ||||
| CVE-2026-104671 | 1 Wordpress-extensions | 1 Tutorsstarter | 2026-10-09 | 5.3 Medium |
| The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled. | ||||
| CVE-2026-105190 | 1 Wordpress-extensions | 1 Easy Digital Downloads | 2026-10-09 | 5.3 Medium |
| The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role. | ||||
| CVE-2026-104075 | 1 Tvu Networks | 1 Tvu Receiver / Transceiver | 2026-10-09 | 9.8 Critical |
| TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive a valid session cookie regardless of the password value and gain full administrative control of the device's web management interface. | ||||
| CVE-2026-105672 | 1 Tp-link | 1 Tapo C325wb V2 | 2026-10-09 | N/A |
| TP-Link Tapo C325WB V2 contains an unauthenticated authorization bypass vulnerability in the HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network can append an onboarding-scoped object to a JSON request to bypass session verification and invoke privileged actions without authentication. Successful exploitation may allow an unauthenticated adjacent-network attacker to access live video and audio, modify device settings, and obtain sensitive device information or secrets. | ||||
| CVE-2026-95263 | 1 Liufee | 1 Feehicms | 2026-10-09 | 7.2 High |
| Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password. | ||||
| CVE-2026-59358 | 1 Cloudfoundry | 2 Cf-deployment, Uaa | 2026-10-09 | N/A |
| Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated attacker holding a valid user access token to obtain a fully-privileged client_credentials token for the OAuth client that issued it, by presenting the user token as an OAuth 2.0 Bearer credential on a client_credentials grant request in place of the client’s configured secret. UAA’s client_credentials handling does not verify that the Bearer credential supplied for client authentication is actually a client credential (a client secret or a valid configured client authentication method); it accepts any valid access token whose client_id matches the request. A token obtained by a normal end user through a public authorization_code + PKCE flow — scoped only to uaa.user, carrying a user_id, and recording client_auth_method=none — satisfies this check. That user token cannot itself administer OAuth clients (POST /oauth/clients correctly returns 403), but when replayed as Bearer authentication on a client_credentials request for the same client, UAA issues a new client-only token carrying the client’s full authorities, such as clients.write. An attacker can use that token to create arbitrary new OAuth clients, including clients with attacker-chosen authorities, without ever possessing the client’s actual secret. Exploitation requires a valid user access token (the attacker’s own) for a client that is configured to support both a public, user-facing authorization flow and the client_credentials grant type on the same client_id — a non-default combination. Practical impact scales with the authorities assigned to that client. | ||||
| CVE-2026-76498 | 1 Cisco | 1 Application Policy Infrastructure Controller (apic) | 2026-10-09 | 9.8 Critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76498 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. | ||||
| CVE-2026-107228 | 1 Asynchttpclient Project | 1 Async-http-client | 2026-10-09 | 6.8 Medium |
| The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14. | ||||
| CVE-2026-107361 | 1 Cisagov | 1 Malcolm | 2026-10-09 | 4.2 Medium |
| The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from any IP address (userAuthIps=::,0.0.0.0/0) and auto-creates users with full access. The passwordSecret is hardcoded to the public value "Malcolm". A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header. | ||||
| CVE-2026-107510 | 1 Infoblox | 1 Nios | 2026-10-09 | 9.1 Critical |
| An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation. | ||||
| CVE-2026-107910 | 1 Falkordb | 1 Falkordb | 2026-10-09 | 8.1 High |
| An improper authentication vulnerability in the is_authenticated function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to execute graph queries without credentials through the Bolt endpoint. The function decides whether a password is required by issuing an empty AUTH command to Redis and treats only a WRONGPASS error as meaning that a password is required; any other error, such as LOADING while a dataset is being loaded, MASTERDOWN during replication failover, or OOM under memory pressure, causes the client to be treated as authenticated. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected. | ||||