Search Results (10496 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100271 1 Jetbrains 1 Youtrack 2026-10-02 2.7 Low
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects
CVE-2026-39717 2026-10-02 4.3 Medium
Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1.
CVE-2026-39439 2026-10-02 6.5 Medium
Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebSamurai: from n/a through 1.0.7.
CVE-2026-104467 1 Yeswiki 1 Yeswiki 2026-10-02 8.1 High
YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list, download, or delete backup archives.
CVE-2026-104438 1 Yeswiki 1 Yeswiki 2026-10-02 5.3 Medium
YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and body-derived titles of ACL-restricted pages.
CVE-2026-100280 1 Jetbrains 1 Youtrack 2026-10-02 3.1 Low
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
CVE-2026-104472 1 Yeswiki 1 Yeswiki 2026-10-02 7.5 High
YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter to retrieve confidential attachments from read-restricted pages.
CVE-2026-91023 1 Wordpress-extensions 1 Motors 2026-10-02 3.1 Low
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
CVE-2026-80337 1 Havelsan 1 Sef - Ai Chatbot Platform 2026-10-02 5.3 Medium
Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
CVE-2026-97395 1 Apache 1 Polaris 2026-10-01 8.1 High
Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation. This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints.
CVE-2026-93832 1 Motorola 1 Setup App 2026-10-01 4.4 Medium
A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.
CVE-2026-97277 2026-10-01 7.6 High
Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
CVE-2026-97280 2 Mamunur Rashid, Wordpress-extensions 2 Review Schema, Review Schema 2026-10-01 6.5 Medium
Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0.
CVE-2026-103251 1 N8n 1 N8n 2026-10-01 7.1 High
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without authentication.
CVE-2026-102397 2 Supsystic, Wordpress-extensions 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic 2026-10-01 6.5 Medium
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
CVE-2026-76143 1 Genians 1 Genian Ssl Pns (frodo-core) 2026-10-01 N/A
A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter.
CVE-2026-76147 1 Genians 2 Genian Nac, Genian Ztna 2026-10-01 N/A
A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code
CVE-2026-103340 2 Geminilabs, Wordpress-extensions 2 Site Reviews, Site Reviews 2026-10-01 5.3 Medium
Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2.
CVE-2026-102381 2 Ahmad, Wordpress-extensions 2 Majestic Support, Majestic Support 2026-10-01 5.3 Medium
Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
CVE-2026-102390 2 Villatheme, Wordpress-extensions 2 Affi – Affiliate Marketing For Woocommerce, Affi - Affiliate Marketing For Woocommerce 2026-10-01 5.3 Medium
Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9.