Export limit exceeded: 10037 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10037 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-70475 | 1 Flowiseai | 1 Flowise | 2026-09-11 | 6.5 Medium |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects other execution endpoints. Any authenticated user, regardless of assigned permissions, can modify execution state, data, and metadata of any execution in their workspace, enabling privilege escalation and manipulation of workflow execution results. This issue is fixed in 3.1.3. | ||||
| CVE-2026-70473 | 1 Flowiseai | 1 Flowise | 2026-09-11 | 8.5 High |
| Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL and collection name. The observed behavior indicates missing or insufficient authorization checks, workspace/project/tenant isolation, and pagination or limits, exposing integration parameters and infrastructure details that may enable further targeted attacks. This issue is fixed in version 3.1.3. | ||||
| CVE-2026-8304 | 1 Tubitak Bilgem Software Technologies Research Institute | 1 Pardus About | 2026-09-11 | 5.5 Medium |
| Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus About: from 1.2.1 before 1.2.5. | ||||
| CVE-2026-84869 | 1 Connectwise | 1 Screenconnect | 2026-09-11 | 9.9 Critical |
| A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. | ||||
| CVE-2026-87493 | 1 Google | 1 Chrome | 2026-09-11 | 6.5 Medium |
| Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87522 | 1 Google | 2 Android, Chrome | 2026-09-11 | 6.5 Medium |
| Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low) | ||||
| CVE-2026-69107 | 1 Jfrog | 1 Artifactory | 2026-09-11 | 5.9 Medium |
| An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | ||||
| CVE-2026-70547 | 1 Jfrog | 1 Artifactory | 2026-09-11 | 4.3 Medium |
| An authenticated user without repository read permission may access package metadata under specific conditions. | ||||
| CVE-2026-86815 | 2 Backwpup, Wordpress | 2 Backwpup, Wordpress | 2026-09-11 | 5.5 Medium |
| The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.5-defined, administrator-assigned limited role to create and run backup jobs and exfiltrate a full database backup to an attacker-controlled destination. | ||||
| CVE-2024-12145 | 2 Buddypress, Wordpress | 2 Buddypress, Wordpress | 2026-09-11 | 4.3 Medium |
| The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete/mark as read/mark as unread notifications of other users. | ||||
| CVE-2026-63300 | 1 Canonical | 1 Lxd | 2026-09-11 | 9.9 Critical |
| An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project. | ||||
| CVE-2026-18121 | 1 Concretecms | 1 Concrete Cms | 2026-09-11 | N/A |
| Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns the requested event occurrence. The controller loads the occurrence directly from an attacker‑supplied, sequential identifier without confirming that it belongs to the calendar configured on the referenced block. An unauthenticated visitor who can render any public calendar block with lightbox properties enabled could therefore supply an arbitrary occurrence identifier and disclose event metadata — title, date, description, page link, and configured event attributes — from calendars they are not permitted to view. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting. | ||||
| CVE-2026-77106 | 1 Commvault | 1 Commvault | 2026-09-11 | 8.8 High |
| Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. | ||||
| CVE-2026-87603 | 1 Google | 1 Chrome | 2026-09-11 | 6.5 Medium |
| Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87606 | 1 Google | 1 Chrome | 2026-09-11 | 8.1 High |
| Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-41870 | 1 Apache | 1 Nutch | 2026-09-11 | 8.8 High |
| Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.11 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ . | ||||
| CVE-2026-86779 | 2026-09-11 | 2.7 Low | ||
| The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators. | ||||
| CVE-2026-81785 | 2 Themekraft, Wordpress | 2 Buddyforms, Wordpress | 2026-09-11 | 6.5 Medium |
| Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. | ||||
| CVE-2026-81788 | 2 Idxbroker, Wordpress | 2 Impress For Idx Broker, Wordpress | 2026-09-11 | 6.3 Medium |
| Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions. | ||||
| CVE-2026-81793 | 2 Dimitri Grassi, Wordpress | 2 Salon Booking System, Wordpress | 2026-09-11 | 6.5 Medium |
| Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. | ||||