Total
11009 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-84135 | 1 Mozilla | 1 Firefox Mobile | 2026-09-03 | N/A | 9.8 CRITICAL |
| Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. | |||||
| CVE-2026-42392 | 2026-09-03 | N/A | 4.3 MEDIUM | ||
| An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the client, which may include sensitive data. Disable the IMAP URLAUTH functionality. Update to non-vulnerable version. No publicly available exploits are known. | |||||
| CVE-2026-40203 | 2026-09-03 | N/A | 3.7 LOW | ||
| When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known. | |||||
| CVE-2026-42393 | 2026-09-03 | N/A | 3.1 LOW | ||
| The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known. | |||||
| CVE-2026-52021 | 2026-09-03 | N/A | 7.5 HIGH | ||
| An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitive information via the src/middleware.ts, and src/app/api/mobile/search/route.ts components. | |||||
| CVE-2026-72549 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function performs no authentication before resolving and returning the internal identifier. An attacker can use this to enumerate user accounts and target subsequent attacks. | |||||
| CVE-2026-72548 | 2026-09-03 | N/A | 7.5 HIGH | ||
| An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant record without authentication or authorization checks. An attacker can enumerate and disclose tenant configuration data for any organisation in the system. | |||||
| CVE-2026-81195 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user. | |||||
| CVE-2026-77782 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts. | |||||
| CVE-2026-81197 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses. | |||||
| CVE-2026-81199 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user. | |||||
| CVE-2026-78151 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms. | |||||
| CVE-2026-19251 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting moderation. | |||||
| CVE-2026-16983 | 2026-09-03 | N/A | 4.3 MEDIUM | ||
| The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST endpoints, exposing the plaintext passwords of password-protected posts to any authenticated user with at least the Subscriber role. | |||||
| CVE-2026-72539 | 2026-09-03 | N/A | 6.5 MEDIUM | ||
| An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource credentials. Drafts with a null owner email bypass ACL enforcement and are returned to any workspace member who queries the drafts endpoint. Sensitive credentials stored in these drafts are exposed across ACL boundaries. | |||||
| CVE-2026-16966 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress would otherwise not serve. | |||||
| CVE-2025-61164 | 2026-09-03 | N/A | 7.5 HIGH | ||
| Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. | |||||
| CVE-2026-84348 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 6.5 MEDIUM |
| Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-84359 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 3.1 LOW |
| Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-84658 | 2026-09-03 | N/A | 4.3 MEDIUM | ||
| Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration. | |||||
