Total
9866 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-66378 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 4.3 MEDIUM |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | |||||
| CVE-2026-66379 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 4.3 MEDIUM |
| An authenticated user may view private Puppet module metadata without repository read access. | |||||
| CVE-2026-66380 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 4.3 MEDIUM |
| An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | |||||
| CVE-2026-68753 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 5.3 MEDIUM |
| An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | |||||
| CVE-2026-68754 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 6.5 MEDIUM |
| A repository publisher without delete permission may modify protected package content under specific conditions. | |||||
| CVE-2026-68758 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 6.5 MEDIUM |
| A low-privileged authenticated user may access restricted support information under specific conditions. | |||||
| CVE-2026-18544 | 1 Ibm | 1 Portieris | 2026-09-02 | N/A | 8.1 HIGH |
| IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references. | |||||
| CVE-2026-78597 | 1 Elastic | 1 Kibana | 2026-09-02 | N/A | 4.3 MEDIUM |
| Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an administrative operation that creates and persists Elasticsearch API keys under the caller's identity, bypassing the elevated cluster and Kibana privileges that the documented Entity Store setup flow requires. | |||||
| CVE-2026-78607 | 1 Elastic | 1 Elasticsearch | 2026-09-02 | N/A | 5.4 MEDIUM |
| Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed. | |||||
| CVE-2026-65938 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 4.3 MEDIUM |
| In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. | |||||
| CVE-2026-65675 | 1 Microsoft | 2 Github Copilot Chat, Visual Studio Code | 2026-09-02 | N/A | 7.1 HIGH |
| No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. | |||||
| CVE-2026-59113 | 1 Microsoft | 1 Visual Studio Code | 2026-09-02 | N/A | 8.8 HIGH |
| Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-84801 | 2026-09-02 | N/A | 8.8 HIGH | ||
| Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via actionSetPassword, which validates only the verification code without checking the caller's session, enabling complete control-panel takeover. | |||||
| CVE-2026-84798 | 2026-09-02 | N/A | 7.1 HIGH | ||
| Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs the deletion authorization check against the user's own provisional draft (which only verifies draft ownership), then propagates the deletion to the canonical element without re-checking permissions. As a result, an authenticated user who has viewEntries, viewPeerEntries, saveEntries, savePeerEntries, and editSite permissions but lacks the deleteEntriesForSite permission can hard-delete a canonical entry's site record (and, for single-site entries, the full element and content), which is irrecoverable via Craft's recycle bin. | |||||
| CVE-2026-82223 | 2026-09-02 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions. | |||||
| CVE-2026-14357 | 2026-09-02 | N/A | 8.8 HIGH | ||
| The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary theme ZIP packages containing PHP files that are extracted into the web-accessible wp-content/themes/ directory, which may make remote code execution possible. | |||||
| CVE-2026-78608 | 1 Elastic | 1 Kibana | 2026-09-02 | N/A | 6.5 MEDIUM |
| Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any authenticated Kibana user to read APM server credentials that should be restricted to users holding APM or Fleet administrative privileges. | |||||
| CVE-2026-78603 | 1 Elastic | 1 Kibana | 2026-09-02 | N/A | 4.3 MEDIUM |
| Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space. | |||||
| CVE-2026-84805 | 2026-09-02 | N/A | 4.3 MEDIUM | ||
| Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates these employment-contract fields behind the contract_other_profile admin permission, the WorkContractPreferenceSubscriber (introduced in 2.61.0) registers the preferences as enabled without a permission check, so an authenticated regular user can use the API to modify their own admin-only work-contract data. The issue is fixed in 2.63.0 by applying the same permission check to the API endpoint. | |||||
| CVE-2026-84800 | 2026-09-02 | N/A | 7.1 HIGH | ||
| Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the permission checks execute, so the replacePeerFiles permission is never enforced. An authenticated low-privilege author with only the replaceFiles permission on a shared folder can overwrite the content of a peer's asset file (located in the same folder) with attacker-controlled bytes. Fixed in 5.10.11. | |||||
