Total
9895 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-74869 | 2026-08-17 | N/A | 7.7 HIGH | ||
| stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership. Attackers can subscribe to any server's member-update topic by sending a Subscribe message with an arbitrary server ID, receiving live UserUpdate events including display names, avatars, and status changes for members they should not have access to. | |||||
| CVE-2026-53960 | 2026-08-17 | N/A | 5.3 MEDIUM | ||
| Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data, exposing it to any unauthenticated visitor and to search-engine crawlers. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. | |||||
| CVE-2026-11719 | 1 Google | 1 Mcp Toolbox For Databases | 2026-08-17 | N/A | 8.1 HIGH |
| An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol versions (2025-06-18, 2025-03-26, and 2024-11-05) omit this check. An authenticated client with low-privilege tokens (e.g., read) can bypass the intended per-tool scope restrictions and execute high-privilege tools (e.g., admin) simply by specifying an older protocol version in the MCP-Protocol-Version header, or by omitting the header entirely (which causes the server to default to the vulnerable 2024-11-05 handler). | |||||
| CVE-2026-61936 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-08-16 | N/A | 5.5 MEDIUM |
| Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. | |||||
| CVE-2026-69113 | 2026-08-14 | N/A | 5.4 MEDIUM | ||
| Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on any private video without permission by supplying an arbitrary videoId in the request body. Attackers can inject comments into private video recordings belonging to other users, trigger comment notification emails to the video owner, and enumerate valid video IDs through response differences. | |||||
| CVE-2026-73656 | 2026-08-14 | N/A | 9.9 CRITICAL | ||
| Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWorkerV4.server.ts, where workerDeployment.findFirst() selects a deployment by friendlyId without an environmentId predicate. A caller with a valid API key for one project can submit another project's deployment identifier, link an attacker-owned background worker to the victim deployment, and move the victim deployment from BUILDING to DEPLOYING. This issue is fixed in version 4.5.6. | |||||
| CVE-2026-5488 | 2026-08-14 | N/A | 5.3 MEDIUM | ||
| The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin pages (including profile.php which subscribers can access), and while other similar AJAX endpoints in the same class properly check for the exactmetrics_save_settings capability, these two endpoints only verify the nonce. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve valid Google Ads access tokens and reset Google Ads integration settings. | |||||
| CVE-2026-59714 | 2026-08-14 | N/A | 7.1 HIGH | ||
| Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a channel:-prefixed chat_id and a target message_id. The channel: path routes pipeline output through _make_channel_emitter, which writes to the Messages table using the caller-supplied message_id without binding it to the channel. This issue is fixed in version 0.10.0. | |||||
| CVE-2026-19786 | 2026-08-14 | 5.0 MEDIUM | 4.3 MEDIUM | ||
| A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. Upgrading to version 12.9 is capable of addressing this issue. The patch is named 801a71272c82cf4bf695fdc5ed42a9b7511d124d. It is recommended to upgrade the affected component. | |||||
| CVE-2026-66693 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in Motors <= 1.4.113 versions. | |||||
| CVE-2026-66660 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. | |||||
| CVE-2026-73403 | 2026-08-14 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. | |||||
| CVE-2026-73349 | 2026-08-14 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | |||||
| CVE-2026-66469 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | |||||
| CVE-2026-66466 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. | |||||
| CVE-2026-73353 | 2026-08-14 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | |||||
| CVE-2026-66689 | 2026-08-14 | N/A | 6.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions. | |||||
| CVE-2026-73401 | 2026-08-14 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | |||||
| CVE-2026-66464 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. | |||||
| CVE-2026-66454 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. | |||||
