Export limit exceeded: 20496 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 385664 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (9513 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-27391 | 2 Stylemixthemes, Wordpress | 2 Ulisting, Wordpress | 2026-08-02 | 5.4 Medium |
| Subscriber Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-27392 | 2 Stylemixthemes, Wordpress | 2 Ulisting, Wordpress | 2026-08-02 | 4.3 Medium |
| Contributor Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-27423 | 2 Rolandbarkerxnauwebdesign, Wordpress | 2 Participants Database, Wordpress | 2026-08-02 | 4.3 Medium |
| Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | ||||
| CVE-2026-57367 | 2 Wordpress, Wpbookingsystem | 2 Wordpress, Wp Booking System | 2026-08-02 | 7.1 High |
| Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | ||||
| CVE-2026-57717 | 2 Knit Pay, Wordpress | 2 Knit Pay, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. | ||||
| CVE-2026-61943 | 2 Shahjada, Wordpress | 2 Wpdm Premium Packages, Wordpress | 2026-08-02 | 7.5 High |
| Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. | ||||
| CVE-2026-65468 | 2 Crocoblock, Wordpress | 2 Jetbooking, Wordpress | 2026-08-02 | 5.3 Medium |
| Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. | ||||
| CVE-2026-65469 | 2 Strategy11, Wordpress | 2 Awp Classifieds, Wordpress | 2026-08-02 | 5.3 Medium |
| Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. | ||||
| CVE-2026-65478 | 2 Cridio, Wordpress | 2 Listingpro, Wordpress | 2026-08-02 | 5.4 Medium |
| Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. | ||||
| CVE-2026-65499 | 2 Peprodev, Wordpress | 2 Peprodev Ultimate Invoice, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-65506 | 2 Sonaar, Wordpress | 2 Mp3 Audio Player For Music, Radio & Podcast, Wordpress | 2026-08-02 | 5.3 Medium |
| Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | ||||
| CVE-2026-18214 | 1 Redhat | 8 Build Keycloak, Build Of Keycloak, Data Grid and 5 more | 2026-08-02 | 6.8 Medium |
| Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm. | ||||
| CVE-2026-15227 | 1 Checkmk | 1 Checkmk | 2026-07-31 | N/A |
| Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users. | ||||
| CVE-2026-14930 | 2026-07-31 | 7.5 High | ||
| The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets. | ||||
| CVE-2026-67527 | 1 Opf | 1 Openproject | 2026-07-31 | 7.6 High |
| OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with edit_work_packages but without manage_file_links to resolve Storages::FileLink records by raw id, detach or hard-delete existing FileLinks, and re-parent FileLinks from other projects to an attacker-controlled work package, exposing origin filename, origin id, and MIME type metadata. This issue is fixed in 17.6.0. | ||||
| CVE-2026-67529 | 1 Opf | 1 Openproject | 2026-07-31 | 4.3 Medium |
| OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _links.workPackage.href through associated_resource in modules/costs/lib/api/v3/time_entries/time_entry_representer.rb and modules/costs/lib/api/v3/cost_entries/cost_entry_representer.rb without checking WorkPackage.visible or view_work_packages, allowing users with view_time_entries or view_cost_entries to read private work package subjects and ids. This issue is fixed in 17.6.0. | ||||
| CVE-2026-35552 | 2026-07-31 | 8.1 High | ||
| In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license. | ||||
| CVE-2026-59796 | 1 Jetbrains | 1 Teamcity | 2026-07-31 | 8.1 High |
| In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | ||||
| CVE-2026-18201 | 1 Redhat | 7 Build Keycloak, Build Of Keycloak, Data Grid and 4 more | 2026-07-30 | 5.5 Medium |
| Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations. | ||||
| CVE-2026-47755 | 1 Itflow | 1 Itflow | 2026-07-30 | 6.5 Medium |
| ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue. | ||||