Export limit exceeded: 386138 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 386138 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (386138 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-72666 | 1 Elastic | 1 Kibana | 2026-09-02 | 6.8 Medium |
| Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery live queries in one space can have a query carried out on hosts belonging to another space, resulting in disclosure of information from those hosts to the Osquery results data stream. | ||||
| CVE-2026-33465 | 1 Elastic | 1 Kibana | 2026-09-02 | 6.5 Medium |
| Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level permissions could submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable. | ||||
| CVE-2026-78581 | 1 Elastic | 1 Kibana | 2026-09-02 | 4.2 Medium |
| Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify a conversation they do not own. Successful exploitation requires knowledge of a hard-to-guess identifier. | ||||
| CVE-2026-72677 | 1 Elastic | 1 Kibana | 2026-09-02 | 7.3 High |
| Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed. | ||||
| CVE-2026-72674 | 1 Elastic | 1 Kibana | 2026-09-02 | 6.5 Medium |
| Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated before it was used to assemble the response for each matching document. A single crafted request could therefore make Kibana build a response far larger than the data it was derived from, and the resulting processing and memory pressure exhausts the resources of the Kibana instance. | ||||
| CVE-2026-34884 | 1 Apache | 1 Skywalking Mcp | 2026-09-02 | 9.8 Critical |
| SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | ||||
| CVE-2026-84353 | 1 Google | 1 Chrome | 2026-09-02 | 9.6 Critical |
| Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-84352 | 1 Google | 1 Chrome | 2026-09-02 | 9.6 Critical |
| Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-84354 | 1 Google | 1 Chrome | 2026-09-02 | 9.6 Critical |
| Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-84324 | 1 Google | 1 Chrome | 2026-09-02 | 9 Critical |
| Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | ||||
| CVE-2026-84350 | 1 Google | 1 Chrome | 2026-09-02 | 8.8 High |
| Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low) | ||||
| CVE-2026-74927 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-09-02 | 5.3 Medium |
| The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications. | ||||
| CVE-2026-84430 | 1 Gouguoa | 1 Gouguoa | 2026-09-02 | 6.3 Medium |
| A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upgrading the affected component is advised. | ||||
| CVE-2026-83562 | 2 Wclovers, Wordpress | 2 Wcfm Marketplace, Wordpress | 2026-09-02 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions. | ||||
| CVE-2026-84326 | 1 Google | 1 Chrome | 2026-09-02 | 8.8 High |
| Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-84335 | 1 Google | 1 Chrome | 2026-09-02 | 8.3 High |
| Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-84327 | 1 Google | 1 Chrome | 2026-09-02 | 6.5 Medium |
| Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-84331 | 1 Google | 1 Chrome | 2026-09-02 | 3.1 Low |
| Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-12526 | 2026-09-02 | 8.1 High | ||
| The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a publicly reachable front-end form whose user-update action targets an existing administrator (a fixed target, or one mapped to a visitor-submitted field) and maps the password to a visitor-submitted field, an unauthenticated visitor can overwrite that administrator's password and take over the account. The default target is the submitting user, so exploitation depends on the form being configured to target another account. | ||||
| CVE-2026-81583 | 2026-09-02 | 5.4 Medium | ||
| The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them. | ||||