Export limit exceeded: 10487 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (10487 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102410 1 Elastic 1 Kibana 2026-10-06 4.3 Medium
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal API surface within the Metrics Experience feature did not enforce a Kibana-level authorization check that an equivalent, related API in the same feature did enforce. As a result, a user who held only data-store-level read access to an index, but no corresponding Kibana feature privilege, could retrieve index-derived metric data through Kibana that the properly-authorized API would otherwise have blocked.
CVE-2026-106040 1 Kvcache-ai 1 Mooncake 2026-10-06 8.2 High
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on disk.
CVE-2026-39762 2 Patterns In The Cloud, Wordpress-extensions 2 Autoship Cloud For Woocommerce Subscription Products, Autoship Cloud For Woocommerce Subscription Products 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1.
CVE-2026-39787 2 10web, Wordpress-extensions 2 10web Social Post Feed, 10web Social Photo Feed 2026-10-06 6.5 Medium
Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions.
CVE-2026-39794 2 Wclovers, Wordpress-extensions 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.
CVE-2026-39796 2 Flipper Code, Wordpress-extensions 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.
CVE-2026-39798 2 Themetechmount, Wordpress-extensions 2 Truebooker, Truebooker 2026-10-06 6.5 Medium
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
CVE-2026-41560 2 Wordpress-extensions, Wxdlabs 2 Wxd Backup Lite, Wxd Backup Lite 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.
CVE-2026-105306 1 Redhat 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more 2026-10-06 6.5 Medium
A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm.
CVE-2026-39763 2 Deepak Anand, Wordpress-extensions 2 Wp Dummy Content Generator, Wp Dummy Content Generator 2026-10-06 4.3 Medium
Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
CVE-2026-94669 2 Wordpress-extensions, Wpmanageninja 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack 2026-10-06 5.3 Medium
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
CVE-2026-103684 2 Arraytics, Wordpress-extensions 2 Wp Event Solution, Wp Event Solution 2026-10-06 5.3 Medium
Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.
CVE-2026-39783 2 Wordpress-extensions, Wp Syntex 2 Polylang, Polylang 2026-10-06 4.3 Medium
Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
CVE-2026-105421 2 Nathanbarry, Wordpress-extensions 2 Kit (formerly Convertkit) For Woocommerce, Kit (formerly Convertkit) For Woocommerce 2026-10-06 5.3 Medium
Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0.
CVE-2026-102780 1 Joomlafry.com 1 Tf Content For Joomla 2026-10-06 N/A
Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the request-selected existing record ID, and saves it without filtering submitted properties through the configured form. A Guest can obtain a valid token from Joomla's public login form and modify any TF Content row, including mass-assigning `published`, `access`, and `created_by`.
CVE-2026-102779 1 Joomlafry.com 1 Tf Content For Joomla 2026-10-06 N/A
Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of any published TF Content task and make the component dispatch its configured executor immediately.
CVE-2026-103433 1 Docker 1 Buildx 2026-10-06 N/A
Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected.
CVE-2026-42637 2 Payplug, Wordpress-extensions 2 Payplug For Woocommerce (official), Payplug For Woocommerce (official) 2026-10-06 6.5 Medium
Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
CVE-2026-48199 2 Beplusthemes, Wordpress-extensions 2 Sermon'e, Sermon'e 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions.
CVE-2026-62072 2 Progress Planner, Wordpress-extensions 2 Progress Planner, Progress Planner 2026-10-06 8.8 High
Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions.