Export limit exceeded: 14805 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14805 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-50055 | 1 Zimbra | 1 Zimbra Collaboration Suite | 2026-10-08 | 6.5 Medium |
| A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify action to send copies of email content and headers to an arbitrary address. | ||||
| CVE-2026-86101 | 1 Watchguard | 2 Fireware, Fireware Os | 2026-10-08 | 6.5 Medium |
| An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request. | ||||
| CVE-2026-39678 | 2 Dotonpaper, Wordpress | 2 Pinpoint Booking System, Wordpress | 2026-10-08 | 5.3 Medium |
| Missing Authorization vulnerability in Pinpoint Booking System Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through 2.9.9.7.2. | ||||
| CVE-2026-106363 | 1 Google | 1 Chrome | 2026-10-08 | 8.3 High |
| Missing authorization in FullScreen in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-105888 | 2026-10-08 | 5.4 Medium | ||
| Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.1. | ||||
| CVE-2026-103072 | 2026-10-08 | 4.3 Medium | ||
| Missing Authorization vulnerability in VillaTheme VillaTheme Core villatheme-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VillaTheme Core: from n/a through 1.0.5. | ||||
| CVE-2026-106288 | 1 Google | 1 Chrome | 2026-10-08 | 5.4 Medium |
| Missing authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106259 | 1 Google | 1 Chrome | 2026-10-08 | 5.4 Medium |
| Incorrect authorization in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106271 | 1 Google | 1 Chrome | 2026-10-08 | 8.1 High |
| Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium) | ||||
| CVE-2026-105878 | 2026-10-08 | 5.3 Medium | ||
| Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Bundles: from n/a through 2.29.0. | ||||
| CVE-2026-105886 | 2026-10-08 | 6.5 Medium | ||
| Missing Authorization vulnerability in BdThemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Post Kit: from n/a through 4.5.5. | ||||
| CVE-2026-106196 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-08 | 7.6 High |
| Missing authorization in Navigation in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106387 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-08 | 8.8 High |
| Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-67411 | 2 Broadcom, Rabbitmq | 2 Rabbitmq Server, Rabbitmq-server | 2026-10-08 | 7.1 High |
| RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT and MQTT over WebSocket behind a trusted PROXY Protocol frontend could lose the proxy-derived client address before the MQTT authentication path checked loopback_users, causing the frontend-to-broker address to be treated as loopback. An attacker who can reach the trusted frontend and has valid credentials for a loopback-restricted account can therefore bypass the source-address restriction; the issue does not bypass password authentication. This issue is fixed in versions 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3. | ||||
| CVE-2026-67412 | 2 Broadcom, Rabbitmq | 2 Rabbitmq Server, Rabbitmq-server | 2026-10-08 | 7.1 High |
| RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policymaker on one vhost reads and drains messages out of another vhost it has no permission on. With the default ack-mode the source messages are consumed (deleted), not copied. Why that should not 1. Federation validates the upstream URI without any vhost-access Cross-vhost message read/drain from a per-vhost policymaker, breaking vhost tenancy This issue is fixed in versions 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18. | ||||
| CVE-2026-39723 | 2026-10-08 | 7.5 High | ||
| Missing Authorization vulnerability in Green Invoice Morning for WooCommerce wc-gateway-greeninvoice allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Morning for WooCommerce: from n/a through 2.4.1. | ||||
| CVE-2026-82239 | 1 Budibase | 2 Budibase, Server | 2026-10-08 | 8.1 High |
| Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data. | ||||
| CVE-2026-106324 | 1 Google | 2 Android, Chrome | 2026-10-08 | 6.1 Medium |
| Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106198 | 1 Google | 1 Chrome | 2026-10-08 | 8.2 High |
| Missing authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-14273 | 1 Ibm | 4 Datapower Gateway 1050, Datapower Gateway 1060, Datapower Gateway 106cd and 1 more | 2026-10-08 | 6.5 Medium |
| IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a local attacker to obtain sensitive information due to improper authorization. | ||||