Search Results (10502 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102320 1 Google 1 Chrome 2026-09-30 6.5 Medium
Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95320 1 Google 1 Chrome 2026-09-30 5.4 Medium
Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-101047 1 Fleetdm 1 Fleet 2026-09-30 5.3 Medium
Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot rely on session-based authentication, and the missing token allows an unauthenticated attacker with network access to the Fleet server to download in-house IPA binaries and their metadata (bundle identifier, version, and name) by guessing sequential title identifiers. The impact is limited to read-only disclosure; there is no privilege escalation or write access, and the free tier is unaffected (it returns fleet.ErrMissingLicense).
CVE-2026-65489 2 Lastudio, Wordpress 2 La-studio Element Kit For Elementor, Wordpress 2026-09-30 5.3 Medium
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
CVE-2026-66651 2 Multivendorx, Wordpress 2 Multivendorx, Wordpress 2026-09-30 6.5 Medium
Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through 5.0.19.
CVE-2026-97267 2026-09-30 4.3 Medium
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
CVE-2026-97247 2026-09-30 6.5 Medium
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
CVE-2026-97243 2026-09-30 5.4 Medium
Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.
CVE-2026-97239 2026-09-30 6.5 Medium
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
CVE-2026-97197 2026-09-30 7.5 High
Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
CVE-2026-96834 2026-09-30 6.5 Medium
Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
CVE-2026-96823 2026-09-30 7.5 High
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
CVE-2026-96818 2026-09-30 7.5 High
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
CVE-2026-96817 2026-09-30 8.2 High
Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
CVE-2026-96348 2026-09-30 7.5 High
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
CVE-2026-95587 2026-09-30 7.5 High
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
CVE-2026-94499 2026-09-30 7.1 High
Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
CVE-2026-94120 2026-09-30 7.5 High
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
CVE-2026-94074 2026-09-30 6.5 Medium
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
CVE-2026-100634 2 B3log, Siyuan 2 Siyuan, Siyuan 2026-09-30 4.7 Medium
SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any received payload to every BrowserWindow returned by BrowserWindow.getAllWindows(), including windows belonging to other opened workspaces. A renderer connected to an attacker-controlled remote kernel can therefore send {cmd: "lockscreenByMode"} and have it delivered across the workspace boundary; a sibling workspace window whose lockScreenMode is set to 1 invokes lockScreen(). Repeated messages allow the remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. No confidentiality, integrity, or code-execution impact was observed.