Export limit exceeded: 10534 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10534 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93332 | 1 Devolutions | 1 Server | 2026-10-01 | 5.4 Medium |
| Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API request. | ||||
| CVE-2026-47493 | 1 Nvidia | 1 Virtual Gpu Manager | 2026-10-01 | 7.8 High |
| NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-95287 | 1 Google | 1 Chrome | 2026-09-30 | 5.4 Medium |
| Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-47580 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 7.3 High |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause a missing authorization issue. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | ||||
| CVE-2026-85576 | 2026-09-30 | 4.3 Medium | ||
| The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them. | ||||
| CVE-2026-93580 | 2026-09-30 | 5.3 Medium | ||
| The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed. | ||||
| CVE-2026-102310 | 1 Google | 1 Chrome | 2026-09-30 | 6.5 Medium |
| Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-94297 | 2026-09-30 | 2.7 Low | ||
| The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site. | ||||
| CVE-2026-87748 | 1 Interprobe Information Technologies Inc. | 1 Qorela Dc | 2026-09-30 | 8.8 High |
| Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2. | ||||
| CVE-2026-96342 | 2 Amauri, Wordpress-extensions | 2 Wpmobile.app, Wpmobile.app | 2026-09-30 | N/A |
| Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83. | ||||
| CVE-2026-81841 | 1 Grafana | 2 Grafana, Grafana Enterprise | 2026-09-30 | 5.3 Medium |
| Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token. | ||||
| CVE-2026-47559 | 1 Nvidia | 6 Geforce, Guest Driver, Nvs and 3 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could access memory belonging to another user's process. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-95371 | 2 Apple, Google | 2 Macos, Chrome | 2026-09-30 | 5.4 Medium |
| Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95296 | 2 Apple, Google | 2 Macos, Chrome | 2026-09-30 | 4.3 Medium |
| Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-102320 | 1 Google | 1 Chrome | 2026-09-30 | 6.5 Medium |
| Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95320 | 1 Google | 1 Chrome | 2026-09-30 | 5.4 Medium |
| Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-100855 | 1 Azuracast | 1 Azuracast | 2026-09-30 | 6.5 Medium |
| AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media files using sequential IDs and exfiltrate the complete media library of stations they lack permissions for. | ||||
| CVE-2026-101047 | 1 Fleetdm | 1 Fleet | 2026-09-30 | 5.3 Medium |
| Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot rely on session-based authentication, and the missing token allows an unauthenticated attacker with network access to the Fleet server to download in-house IPA binaries and their metadata (bundle identifier, version, and name) by guessing sequential title identifiers. The impact is limited to read-only disclosure; there is no privilege escalation or write access, and the free tier is unaffected (it returns fleet.ErrMissingLicense). | ||||
| CVE-2026-65489 | 2 Lastudio, Wordpress | 2 La-studio Element Kit For Elementor, Wordpress | 2026-09-30 | 5.3 Medium |
| Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. | ||||
| CVE-2026-66651 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-09-30 | 6.5 Medium |
| Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through 5.0.19. | ||||