Total
9866 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-84470 | 2026-09-04 | N/A | 6.4 MEDIUM | ||
| A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A principal that holds read (but not use) permission on an instance group -- for example the built-in read-only System Auditor role -- together with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use, bypassing execution-placement isolation. | |||||
| CVE-2026-32480 | 2026-09-04 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11. | |||||
| CVE-2026-27347 | 2026-09-04 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2. | |||||
| CVE-2026-85605 | 2026-09-04 | N/A | 5.3 MEDIUM | ||
| Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks. | |||||
| CVE-2026-85512 | 2026-09-04 | 7.5 HIGH | 7.3 HIGH | ||
| A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. | |||||
| CVE-2026-85306 | 2026-09-04 | N/A | 6.5 MEDIUM | ||
| Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5. | |||||
| CVE-2026-84754 | 2026-09-04 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | |||||
| CVE-2026-71962 | 1 Flowiseai | 1 Flowise | 2026-09-04 | N/A | 7.5 HIGH |
| Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication whitelist, which bypasses all session and API key verification. Attackers can supply valid chatflowId, chatId, and fileName identifiers to retrieve files from any chatflow on the instance, including private chatflows belonging to other workspaces or organizations. | |||||
| CVE-2026-20696 | 1 Apple | 1 Macos | 2026-09-04 | N/A | 5.5 MEDIUM |
| An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.4. An app may be able to access sensitive user data. | |||||
| CVE-2026-84794 | 2026-09-04 | N/A | 7.1 HIGH | ||
| Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement. | |||||
| CVE-2026-72681 | 1 Elastic | 1 Kibana | 2026-09-03 | N/A | 6.5 MEDIUM |
| Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read. | |||||
| CVE-2026-85304 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17. | |||||
| CVE-2026-84779 | 2026-09-03 | N/A | 8.1 HIGH | ||
| Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions. | |||||
| CVE-2026-84757 | 2026-09-03 | N/A | 8.2 HIGH | ||
| Unauthenticated Settings Change in WP Compress <= 7.21.28 versions. | |||||
| CVE-2026-84755 | 2026-09-03 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. | |||||
| CVE-2026-84215 | 2026-09-03 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. | |||||
| CVE-2026-17563 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers. | |||||
| CVE-2026-81427 | 2026-09-03 | N/A | 4.3 MEDIUM | ||
| The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email. | |||||
| CVE-2026-77787 | 2026-09-03 | N/A | 2.7 LOW | ||
| The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users. | |||||
| CVE-2025-15485 | 2026-09-03 | N/A | 8.2 HIGH | ||
| The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | |||||
