Total
9902 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-63092 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The plugin's activate dialog handler in lib/areas.php returns the complete key via ModulesLicense::readKey() without performing an administrator check, as the dialog is gated only by the access.system permission which defaults to true for all non-admin roles, enabling attackers to use the disclosed key to activate the plugin on arbitrary third-party installations. | |||||
| CVE-2026-11876 | 2026-07-23 | N/A | 5.0 MEDIUM | ||
| In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all users and tenants. This includes stack component details, service connector information, and user IDs of stack owners. The vulnerability arises from two issues: missing endpoint-level RBAC checks and the use of a server-side `Client()` that bypasses the RBAC enforcement layer by directly accessing the database through `SqlZenStore`. This exposes sensitive information such as infrastructure topology, service connector details, stack ownership, and deployment metadata, potentially enabling cross-tenant reconnaissance and further attacks in multi-tenant ZenML Pro/Cloud deployments. | |||||
| CVE-2026-55518 | 2026-07-23 | N/A | 9.6 CRITICAL | ||
| Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new path, but the actual write endpoint, POST /resources/:resource/:id/:related, does not run the same authorization check before mutating the association through Avo::AssociationsController#create. An authenticated low-privileged Avo user can bypass hidden or disabled attach controls and directly attach related records to a parent record by sending a crafted POST request, which can lead to privilege escalation and cross-tenant data exposure where associations represent authorization-bearing relationships. This issue is fixed in versions 3.32.1 and 4.0.0.beta.51. | |||||
| CVE-2026-65537 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | |||||
| CVE-2026-65531 | 2026-07-23 | N/A | 4.8 MEDIUM | ||
| Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. | |||||
| CVE-2026-65525 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. | |||||
| CVE-2026-65506 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | |||||
| CVE-2026-65491 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions. | |||||
| CVE-2026-65486 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. | |||||
| CVE-2026-65485 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | |||||
| CVE-2026-65479 | 2026-07-23 | N/A | 5.4 MEDIUM | ||
| Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. | |||||
| CVE-2026-59547 | 2026-07-23 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. | |||||
| CVE-2026-59522 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. | |||||
| CVE-2026-57830 | 1 Ollyo | 1 Helix Ultimate | 2026-07-23 | N/A | 9.1 CRITICAL |
| Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. | |||||
| CVE-2026-57808 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. | |||||
| CVE-2026-57717 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. | |||||
| CVE-2026-27422 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions. | |||||
| CVE-2026-27418 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. | |||||
| CVE-2026-27399 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. | |||||
| CVE-2026-27377 | 2026-07-23 | N/A | 6.7 MEDIUM | ||
| Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | |||||
