Total
9879 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-70438 | 2026-08-31 | N/A | 4.3 MEDIUM | ||
| A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
| CVE-2026-70436 | 2026-08-31 | N/A | 4.3 MEDIUM | ||
| Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access. | |||||
| CVE-2026-70439 | 2026-08-31 | N/A | 6.5 MEDIUM | ||
| Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality. | |||||
| CVE-2026-70445 | 2026-08-31 | N/A | 4.3 MEDIUM | ||
| Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
| CVE-2026-70446 | 2026-08-31 | N/A | 4.3 MEDIUM | ||
| Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
| CVE-2026-70447 | 2026-08-31 | N/A | 4.3 MEDIUM | ||
| Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
| CVE-2026-18965 | 2026-08-31 | N/A | 8.8 HIGH | ||
| PayRange APIĀ is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account. | |||||
| CVE-2026-82267 | 2026-08-31 | N/A | 5.4 MEDIUM | ||
| Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers. Authenticated users can guess resource names to obtain internal identifiers and insert fraudulent audit log entries misrepresenting privileged operations. | |||||
| CVE-2026-19197 | 2026-08-31 | N/A | 6.3 MEDIUM | ||
| A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control). | |||||
| CVE-2026-12710 | 2026-08-31 | N/A | N/A | ||
| A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required. | |||||
| CVE-2026-79110 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 4.3 MEDIUM |
| Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79116 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 4.3 MEDIUM |
| Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79067 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 4.3 MEDIUM |
| Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79053 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 3.1 LOW |
| Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79058 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 9.1 CRITICAL |
| Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79099 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 6.5 MEDIUM |
| Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-78967 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 6.5 MEDIUM |
| Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79042 | 1 Google | 2 Android, Chrome | 2026-08-31 | N/A | 4.3 MEDIUM |
| Missing authorization in Payments in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-6471 | 1 Postgresql | 1 Postgresql | 2026-08-29 | N/A | 7.2 HIGH |
| Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. | |||||
| CVE-2026-6470 | 1 Postgresql | 1 Postgresql | 2026-08-29 | N/A | 4.3 MEDIUM |
| Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. | |||||
