Search Results (10487 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-105706 1 Sourcecodester 1 Drug Recommendation System 2026-10-06 4.3 Medium
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVE-2026-105693 1 Penpot 1 Penpot 2026-10-06 5.3 Medium
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0.
CVE-2026-25267 2026-10-06 7.8 High
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
CVE-2025-62973 2 Themekraft, Wordpress 2 Buddyforms, Wordpress 2026-10-06 5.3 Medium
Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyForms: from n/a through 2.10.2.
CVE-2026-97309 2026-10-06 N/A
Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226.
CVE-2026-97303 2026-10-06 7.6 High
Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2.
CVE-2026-39789 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
CVE-2026-39751 2026-10-06 7.5 High
Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
CVE-2026-39749 2026-10-06 6.5 Medium
Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions.
CVE-2026-39730 2026-10-06 7.1 High
Missing Authorization vulnerability in Marcin Wise Chat wise-chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wise Chat: from n/a through 3.4.2.
CVE-2026-39723 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.
CVE-2026-39599 2026-10-06 4.3 Medium
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
CVE-2026-32582 2026-10-06 6.5 Medium
Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.
CVE-2026-32578 2026-10-06 7.1 High
Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions.
CVE-2026-25433 2026-10-06 7.1 High
Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions.
CVE-2026-105072 2026-10-06 7.5 High
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
CVE-2026-104386 2026-10-06 6.5 Medium
Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3.
CVE-2026-103337 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2.
CVE-2026-103086 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74.
CVE-2026-103762 2 B3log, Siyuan 2 Siyuan, Siyuan 2026-10-06 5.3 Medium
SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time.