Export limit exceeded: 10401 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10401 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39789 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. | ||||
| CVE-2026-39723 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions. | ||||
| CVE-2026-39599 | 2026-10-06 | 4.3 Medium | ||
| Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. | ||||
| CVE-2026-32582 | 2026-10-06 | 6.5 Medium | ||
| Contributor Broken Access Control in IATO MCP <= 1.11.0 versions. | ||||
| CVE-2026-105072 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. | ||||
| CVE-2026-105706 | 1 Sourcecodester | 1 Drug Recommendation System | 2026-10-06 | 4.3 Medium |
| A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2026-103762 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-10-06 | 5.3 Medium |
| SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time. | ||||
| CVE-2026-45524 | 1 Google | 1 Android | 2026-10-06 | 8.8 High |
| In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-103433 | 2026-10-05 | N/A | ||
| Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected. | ||||
| CVE-2026-105693 | 1 Penpot | 1 Penpot | 2026-10-05 | 5.3 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105695 | 1 Penpot | 1 Penpot | 2026-10-05 | 5.9 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105696 | 1 Penpot | 1 Penpot | 2026-10-05 | 6.5 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to the link's authorized pages set. An attacker with both a valid share link and the attacker's own authenticated Penpot session can retrieve the complete shape and design data of another page in the same file when its identifier is known, because get-page requires authentication. The related get-file-fragment RPC also permits share-link access without mapping fragments to authorized pages. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105209 | 1 Zitadel | 1 Zitadel | 2026-10-05 | 9.6 Critical |
| ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account. | ||||
| CVE-2026-105698 | 2026-10-05 | 5.4 Medium | ||
| Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who knew another user's flow UUID could reach these handlers; from version 1.7.2 through 1.10.0, callers had to authenticate but needed no elevated privileges. Such a caller could cause retrieve_vertices_order to load and cache the private graph, enumerate its vertex identifiers, and use build_vertex to execute selected vertices and receive their results. build_graph_from_db_no_cache performed a primary-key lookup without an owner filter. This could disclose private flow structure, configured values, and selected outputs and could trigger victim-configured side effects and build-history records, although it did not expose the victim's variable-store credentials or permit modification of the stored flow. This issue is fixed in Langflow 1.10.1 and langflow-base 0.10.1. | ||||
| CVE-2026-104979 | 1 Makeplane | 1 Plane | 2026-10-05 | 8.7 High |
| Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \tjavascript: parser bypass and the target="_self" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0. | ||||
| CVE-2026-104968 | 1 Makeplane | 1 Plane | 2026-10-05 | N/A |
| Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a workspace member. The endpoint also exposes ProjectMember rows under the same condition. SearchEndpoint in apps/api/plane/app/views/search/base.py inherits BaseAPIView with only permission_classes = [IsAuthenticated] and performs no workspace-membership check. This issue is fixed in 1.4.0. | ||||
| CVE-2026-105635 | 1 Makeplane | 1 Plane | 2026-10-05 | 7.4 High |
| Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0. | ||||
| CVE-2026-105680 | 2026-10-05 | 6.5 Medium | ||
| Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0. | ||||
| CVE-2026-97304 | 2026-10-05 | 6.5 Medium | ||
| Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.63. | ||||
| CVE-2026-104962 | 1 Makeplane | 1 Plane | 2026-10-05 | 6.5 Medium |
| Plane is an open-source project management tool. Prior to 1.4.0, GET /api/v1/workspaces/{slug}/projects/{project_id}/members/ returns the complete project-member roster, including each member's email address, first and last name, display name, avatar, and role. ProjectMemberPermission gates the endpoint, but its SAFE_METHODS branch checks only whether the caller is an active ProjectMember of any project in the workspace and does not bind the check to view.project_id. The view then filters solely by the project_id supplied in the URL. Consequently, any authenticated user who belongs to one project in a workspace, including a Guest, can read the roster of another private project in the same workspace. This issue is fixed in 1.4.0. | ||||