Export limit exceeded: 10509 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (10509 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94297 2026-09-30 2.7 Low
The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site.
CVE-2026-87748 1 Interprobe Information Technologies Inc. 1 Qorela Dc 2026-09-30 8.8 High
Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2.
CVE-2026-96342 2 Amauri, Wordpress-extensions 2 Wpmobile.app, Wpmobile.app 2026-09-30 N/A
Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.
CVE-2026-81841 1 Grafana 2 Grafana, Grafana Enterprise 2026-09-30 5.3 Medium
Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.
CVE-2026-47559 1 Nvidia 6 Geforce, Guest Driver, Nvs and 3 more 2026-09-30 7.8 High
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could access memory belonging to another user's process. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CVE-2026-95371 2 Apple, Google 2 Macos, Chrome 2026-09-30 5.4 Medium
Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95296 2 Apple, Google 2 Macos, Chrome 2026-09-30 4.3 Medium
Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-102320 1 Google 1 Chrome 2026-09-30 6.5 Medium
Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95320 1 Google 1 Chrome 2026-09-30 5.4 Medium
Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-101047 1 Fleetdm 1 Fleet 2026-09-30 5.3 Medium
Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot rely on session-based authentication, and the missing token allows an unauthenticated attacker with network access to the Fleet server to download in-house IPA binaries and their metadata (bundle identifier, version, and name) by guessing sequential title identifiers. The impact is limited to read-only disclosure; there is no privilege escalation or write access, and the free tier is unaffected (it returns fleet.ErrMissingLicense).
CVE-2026-65489 2 Lastudio, Wordpress 2 La-studio Element Kit For Elementor, Wordpress 2026-09-30 5.3 Medium
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
CVE-2026-66651 2 Multivendorx, Wordpress 2 Multivendorx, Wordpress 2026-09-30 6.5 Medium
Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through 5.0.19.
CVE-2026-97267 2026-09-30 4.3 Medium
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
CVE-2026-97247 2026-09-30 6.5 Medium
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
CVE-2026-97243 2026-09-30 5.4 Medium
Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.
CVE-2026-97239 2026-09-30 6.5 Medium
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
CVE-2026-97197 2026-09-30 7.5 High
Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
CVE-2026-96834 2026-09-30 6.5 Medium
Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
CVE-2026-96823 2026-09-30 7.5 High
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
CVE-2026-96818 2026-09-30 7.5 High
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.