Export limit exceeded: 10703 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10703 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108616 | 2 Jeecg, Jeecgboot | 3 Jeecg-boot, Jeecg Boot, Jeecgboot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController deleteBatch handler that allows any authenticated user to delete AI evaluator records. Low-privileged attackers can send comma-separated ids to DELETE /airag/extData/deleteBatch, which lacks owner or tenant checks, deleting other users' evaluator and test-tracking records. | ||||
| CVE-2026-108679 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the sendBusAnnouncement handler of SystemApiController that allows any authenticated user to send announcements without the required permissions. Low-privileged attackers can POST crafted bodies to /sys/api/sendBusAnnouncement with forged sender, recipients, title and content to deliver spoofed admin or system messages for phishing. | ||||
| CVE-2026-108674 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OpenApiController queryById handler that allows low-privileged authenticated users to read OpenAPI definitions without openapi permissions. Attackers can request GET /openapi/queryById with an entry id to obtain internal origin URLs, virtual paths, IP whitelists, and header and parameter templates. | ||||
| CVE-2026-108621 | 1 Jeecg | 1 Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController edit handler that allows any authenticated user to modify organizational positions. Low-privileged attackers can obtain position ids from the unguarded list endpoint and send PUT or POST requests to /sys/position/edit to alter position names, codes, and ranks. | ||||
| CVE-2026-105989 | 2026-10-10 | 5.3 Medium | ||
| The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts. | ||||
| CVE-2026-108165 | 1 Futo | 1 Immich | 2026-10-10 | 4.3 Medium |
| Immich through 3.3.1 contains a missing authorization vulnerability in the partner synchronization stream that allows authenticated partners to read Locked Folder asset metadata because sync queries do not exclude Locked visibility. Attackers with an active partner relationship can call POST /api/sync/stream with PartnerAssetsV2 and PartnerAssetExifsV1 types to obtain GPS coordinates, capture times, descriptions and camera details. | ||||
| CVE-2026-62128 | 2 Creator Lms, Wordpress-extensions | 2 Creator Lms, Creator Lms | 2026-10-10 | 5.3 Medium |
| Missing Authorization vulnerability in Creator LMS Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through 1.2.21. | ||||
| CVE-2026-105891 | 2026-10-10 | 4.3 Medium | ||
| Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.1. | ||||
| CVE-2026-106418 | 1 Google | 1 Chrome | 2026-10-10 | 6.5 Medium |
| Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low) | ||||
| CVE-2026-106365 | 1 Google | 1 Chrome | 2026-10-09 | 6.5 Medium |
| Missing authorization in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106267 | 1 Google | 1 Chrome | 2026-10-09 | 6.5 Medium |
| Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106362 | 1 Google | 1 Chrome | 2026-10-09 | 6.5 Medium |
| Missing authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low) | ||||
| CVE-2026-107850 | 1 Contao | 1 Contao | 2026-10-09 | 4.3 Medium |
| Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter although the shipped class is PreviewVoter. Symfony therefore omits voter autoconfiguration and removes the private service, so PreviewVoter::hasAccess() never enforces ownership. A non-admin backend user with the preview_link module can list every tl_preview_link record, obtain signed share URLs created by other users, and use them to view unpublished pages with showUnpublished despite lacking page permission. The advisory does not establish editing or deletion of foreign links. This issue is fixed in version 5.7.12. | ||||
| CVE-2026-96461 | 2026-10-09 | 7.5 High | ||
| Missing Authorization vulnerability in TMS Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through 2.4.10. | ||||
| CVE-2026-95589 | 2026-10-09 | 6.5 Medium | ||
| Missing Authorization vulnerability in Magepeople inc. Deposits and Partial Payments for WooCommerce advanced-partial-payment-or-deposit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Deposits and Partial Payments for WooCommerce: from n/a through 4.0.1. | ||||
| CVE-2026-62042 | 2026-10-09 | 5.3 Medium | ||
| Missing Authorization vulnerability in unFocus Projects Scripts n Styles scripts-n-styles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scripts n Styles: from n/a through 3.5.8. | ||||
| CVE-2026-105883 | 2026-10-09 | 7.1 High | ||
| Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Th Shop Mania: from n/a through 1.9.1. | ||||
| CVE-2026-73665 | 2 Freepbx, Sangoma | 2 Ucp, Freepbx | 2026-10-09 | 9.8 Critical |
| FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth in node/lib/auth.js and send crafted event values containing carriage-return or newline characters through the Asterisk Manager Interface action path patched by node/lib/asterisk-manager-patch.js, allowing arbitrary commands to execute as the asterisk service user. This issue is fixed in version 17.0.9. | ||||
| CVE-2026-79842 | 1 Hewlett Packard Enterprise(hpe) | 1 Intelligent Management Center | 2026-10-09 | 9.1 Critical |
| An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713 | ||||
| CVE-2026-97075 | 2026-10-09 | 6.5 Medium | ||
| Missing Authorization vulnerability in WP Media WP Rocket wp-rocket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rocket: from n/a before 3.23.5. | ||||