Search Results (14486 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100744 1 Coollabsio 1 Coolify 2026-09-30 7.3 High
A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 4.2.0 is sufficient to fix this issue. This patch is called 39ae16de4248075de8c08f3259114e064b20d52d. It is advisable to upgrade the affected component.
CVE-2026-101047 1 Fleetdm 1 Fleet 2026-09-30 5.3 Medium
Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot rely on session-based authentication, and the missing token allows an unauthenticated attacker with network access to the Fleet server to download in-house IPA binaries and their metadata (bundle identifier, version, and name) by guessing sequential title identifiers. The impact is limited to read-only disclosure; there is no privilege escalation or write access, and the free tier is unaffected (it returns fleet.ErrMissingLicense).
CVE-2026-95302 1 Google 2 Android, Chrome 2026-09-30 2.9 Low
Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
CVE-2026-65489 2 Lastudio, Wordpress 2 La-studio Element Kit For Elementor, Wordpress 2026-09-30 5.3 Medium
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
CVE-2026-80110 1 Redhat 3 Certificate System, Dogtag Certificate System, Enterprise Linux 2026-09-30 8.1 High
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended to require Administrator-level profiles.create permission -- to instead be authorized under the lower-privileged profiles.approve permission held by the default Certificate Manager Agents group. The highest threat from this vulnerability is to confidentiality and integrity of the certificate authority's issuance policy.
CVE-2026-66651 2 Multivendorx, Wordpress 2 Multivendorx, Wordpress 2026-09-30 6.5 Medium
Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through 5.0.19.
CVE-2026-97267 2026-09-30 4.3 Medium
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
CVE-2026-97247 2026-09-30 6.5 Medium
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
CVE-2026-97243 2026-09-30 5.4 Medium
Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.
CVE-2026-97239 2026-09-30 6.5 Medium
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
CVE-2026-97197 2026-09-30 7.5 High
Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
CVE-2026-96834 2026-09-30 6.5 Medium
Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
CVE-2026-96823 2026-09-30 7.5 High
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
CVE-2026-96818 2026-09-30 7.5 High
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
CVE-2026-96817 2026-09-30 8.2 High
Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
CVE-2026-96348 2026-09-30 7.5 High
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
CVE-2026-95587 2026-09-30 7.5 High
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
CVE-2026-94499 2026-09-30 7.1 High
Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
CVE-2026-94120 2026-09-30 7.5 High
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
CVE-2026-94074 2026-09-30 6.5 Medium
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.