Export limit exceeded: 390028 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (390028 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-87431 1 Google 1 Chrome 2026-09-10 7.5 High
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-87429 1 Google 1 Chrome 2026-09-10 6.5 Medium
Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87107 2026-09-10 5.4 Medium
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a peered cluster without holding authority over the peer origin. This vulnerability (CVE-2026-87107) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
CVE-2026-86060 1 Mikrotik 1 Routeros 2026-09-10 N/A
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CVE-2026-84432 2026-09-10 N/A
Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action created a board_slot_proxy Block and dispatched an AddCustomSlotToBoardCommand against a board instance while gating only on the per-resource canEditBoardContents() permission, so a crafted cross-site request could cause a user holding board-edit permission with an active session to write attacker-chosen slot and template data to a board under their own authority. The state-changing database write completed before any downstream rendering, so the forged request succeeded even when the HTTP response returned a non-200 status. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
CVE-2026-67277 1 Mikrotik 1 Routeros 2026-09-10 N/A
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CVE-2026-28624 1 Google 1 Android 2026-09-10 7.8 High
In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-14892 1 Tanium 1 Tanium Server 2026-09-10 4.3 Medium
Tanium addressed an improper access controls vulnerability in Tanium Server.
CVE-2026-87033 1 Tanium 1 Comply 2026-09-10 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87035 1 Tanium 1 Comply 2026-09-10 4.3 Medium
Tanium addressed an information disclosure vulnerability in Comply.
CVE-2026-87034 1 Tanium 1 Comply 2026-09-10 8.3 High
Tanium addressed a SQL injection vulnerability in Comply.
CVE-2026-87048 1 Tanium 1 Comply 2026-09-10 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87021 1 Tanium 1 Comply 2026-09-10 7.2 High
Tanium addressed an unauthorized code execution vulnerability in Comply.
CVE-2026-87036 1 Tanium 1 Comply 2026-09-10 8.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-53956 1 Conda 2 Py-rattler, Rattler 2026-09-10 5.4 Medium
Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling package metadata from conda channels. During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a filesystem path. A malicious or untrusted channel could publish repodata with path separators or traversal components in that field, causing package contents to be written outside the configured package cache directory. The issue requires use of a malicious or otherwise untrusted conda channel. Curated channels that validate package metadata are not expected to allow malformed build strings of this form. Users should upgrade to `rattler_cache` version 0.9.0 or `py-rattler` version 0.24.0 and avoid untrusted conda channels.
CVE-2026-15796 2 Builderall, Wordpress 2 Builder For Wordpress, Wordpress 2026-09-10 6.4 Medium
The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-15823 2 Builderall, Wordpress 2 Builder For Wordpress, Wordpress 2026-09-10 4.3 Medium
The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable() function in versions up to, and including, 3.0.2. The wp_ajax_ba_cheetah_disable AJAX handler is registered without any capability or nonce verification, and the target post_id is sourced directly from user-controlled $_POST['ba_cheetah_data']['post_id']. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable the page builder layout on arbitrary posts by setting the _ba_cheetah_enabled post meta to false, including on posts owned by other users.
CVE-2026-18594 2 Vsourz, Wordpress 2 Advanced Contact Form 7 Db, Wordpress 2026-09-10 4.3 Medium
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to import forged CSV submission records into any Contact Form 7 form managed by the plugin.
CVE-2026-15820 2 Builderall, Wordpress 2 Builder For Wordpress, Wordpress 2026-09-10 6.4 Medium
The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-69854 1 Microsoft 2 Azure Spring Cloud, Spring Cloud Azure 2026-09-10 9 Critical
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.