Total
9864 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-81801 | 2026-09-10 | N/A | 8.1 HIGH | ||
| Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. | |||||
| CVE-2026-81794 | 2026-09-10 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions. | |||||
| CVE-2026-79324 | 1 Mageplaza | 1 Gdpr | 2026-09-10 | N/A | 7.5 HIGH |
| Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so no authentication, ownership or form key check is enforced. | |||||
| CVE-2026-88898 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs. | |||||
| CVE-2026-87569 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 8.8 HIGH |
| Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87557 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 4.3 MEDIUM |
| Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87552 | 1 Google | 2 Android, Chrome | 2026-09-10 | N/A | 5.5 MEDIUM |
| Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High) | |||||
| CVE-2026-86438 | 2026-09-10 | N/A | 7.2 HIGH | ||
| Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution. | |||||
| CVE-2026-85669 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes. | |||||
| CVE-2026-85651 | 2026-09-10 | N/A | 8.5 HIGH | ||
| Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history. | |||||
| CVE-2026-81799 | 2026-09-10 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. | |||||
| CVE-2026-81785 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. | |||||
| CVE-2026-78536 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | |||||
| CVE-2026-85210 | 2026-09-10 | N/A | 4.3 MEDIUM | ||
| Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific roles, banned flags, and managed topic identifiers without authorization. | |||||
| CVE-2026-82633 | 2026-09-10 | N/A | 4.3 MEDIUM | ||
| Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers to access group names, entity associations, and private notes across tenant boundaries. | |||||
| CVE-2026-86777 | 2026-09-10 | N/A | 5.3 MEDIUM | ||
| AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URLs from all sites and languages. | |||||
| CVE-2026-85390 | 2026-09-10 | N/A | 7.1 HIGH | ||
| Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and delete monitor check history to erase incident evidence. | |||||
| CVE-2026-85212 | 2026-09-10 | N/A | 8.3 HIGH | ||
| CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests. | |||||
| CVE-2026-85213 | 2026-09-10 | N/A | 7.6 HIGH | ||
| Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation. | |||||
| CVE-2026-82475 | 2026-09-10 | N/A | 8.1 HIGH | ||
| iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions. | |||||
