Export limit exceeded: 402913 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 10788 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 10496 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10496 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100592 | 1 Openclaw | 1 Openclaw | 2026-10-05 | 6.3 Medium |
| OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue the persistent '/dreaming on' and '/dreaming off' commands to enable or disable the Gateway's Memory Core dreaming behavior, disabling background memory processing or re-enabling durable memory promotion where the owner expected it to remain disabled; the practical confidentiality, integrity, and availability impact depends on stored conversation material and subsequent memory use. Read-only status and help commands remain governed by normal command policy. The issue is fixed in version 2026.7.1. As a workaround, disable dreaming commands in external channels or restrict channel command access to owners. | ||||
| CVE-2026-105055 | 2026-10-05 | 5.3 Medium | ||
| Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0. | ||||
| CVE-2026-104675 | 2026-10-05 | 4.3 Medium | ||
| Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. | ||||
| CVE-2026-104388 | 2026-10-05 | 5.3 Medium | ||
| Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9. | ||||
| CVE-2026-20535 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In aidl, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185216; Issue ID: MSV-9039. | ||||
| CVE-2026-103490 | 1 Jetbrains | 1 Youtrack | 2026-10-05 | 7.2 High |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links | ||||
| CVE-2025-58222 | 1 Wordpress | 1 Wordpress | 2026-10-05 | 5.3 Medium |
| Missing Authorization vulnerability in Dynamic Web Lab Team Manager wp-team-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Manager: from n/a through 2.6.8. | ||||
| CVE-2025-53345 | 2 Thimpress, Wordpress | 2 Thim Core, Wordpress | 2026-10-05 | 8.8 High |
| Missing Authorization vulnerability in ThimPress Thim Core thim-core.This issue affects Thim Core: from n/a through 2.3.3. | ||||
| CVE-2025-32220 | 1 Salonbookingsystem | 1 Salon Booking System | 2026-10-05 | 5.4 Medium |
| Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9. | ||||
| CVE-2026-81793 | 2 Dimitri Grassi, Wordpress | 2 Salon Booking System, Wordpress | 2026-10-05 | 6.5 Medium |
| Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9. | ||||
| CVE-2026-79618 | 1 Wordpress-extensions | 1 Wp User Frontend | 2026-10-04 | 4.3 Medium |
| The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers. | ||||
| CVE-2026-85005 | 1 Wordpress-extensions | 1 Popup Maker Wp | 2026-10-04 | 5.4 Medium |
| The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service. | ||||
| CVE-2026-90952 | 1 Wordpress-extensions | 1 Wp Edit Password Protected | 2026-10-04 | 5.3 Medium |
| The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide. | ||||
| CVE-2026-97219 | 2 Mstore, Wordpress-extensions | 2 Mstore Api, Mstore Api | 2026-10-04 | 4.3 Medium |
| The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying. | ||||
| CVE-2026-85209 | 1 Avez Electronics | 1 Learning Management System (lms) | 2026-10-04 | 6.5 Medium |
| Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18. | ||||
| CVE-2026-101104 | 1 Meari | 1 Iot Cloud Platform Openapi Service | 2026-10-04 | 7.7 High |
| The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions. | ||||
| CVE-2026-96613 | 1 Meari | 1 Iot Cloud Platform Openapi Service | 2026-10-04 | 6.5 Medium |
| The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship between the requester and the target device. | ||||
| CVE-2026-97337 | 2 Wordpress-extensions, Wpinsider-1 | 2 Simple Membership, Simple Membership | 2026-10-04 | 7.5 High |
| The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST['email'] parameter (overriding the member's registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member's activation email — and the follow-up 'registration complete' email containing the member's username and plaintext password — to an attacker-chosen address, and to then activate that member's account without their consent. | ||||
| CVE-2026-101923 | 2 Villatheme, Wordpress-extensions | 2 Photo Reviews For Woocommerce, Photo Reviews For Woocommerce | 2026-10-04 | 8.1 High |
| The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the delete_reviews_image() handler unconditionally calling wp_delete_post( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker's review (or when WordPress's built-in wp_scheduled_delete cron empties the comment trash after 30 days). | ||||
| CVE-2026-92437 | 1 Wordpress-extensions | 1 Mailchimp For Woocommerce | 2026-10-04 | 5.3 Medium |
| The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart. | ||||