Total
9903 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-4843 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's Google Sheets API token and configuration options. | |||||
| CVE-2026-8238 | 1 Concretecms | 1 Concrete Cms | 2026-07-23 | N/A | 5.3 MEDIUM |
| Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including messages from restricted pages, member-only areas, and the moderation queue. File attachments with download URLs are also exposed. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting. | |||||
| CVE-2026-45260 | 2026-07-23 | N/A | 8.1 HIGH | ||
| Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Controller/WebDavController.php, and models/Asset/WebDAV/Tree.php performs asset mutation and deletion through models/Asset.php before checking a current Pimcore user or the rename, delete, create, or publish permissions, allowing unauthorized asset deletion, moves, or overwrites. This issue is fixed in versions 11.5.17 (LTS) and 12.3.7. | |||||
| CVE-2026-47657 | 2026-07-23 | N/A | N/A | ||
| HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available. | |||||
| CVE-2026-57494 | 2026-07-23 | N/A | N/A | ||
| AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=<name>`. The returned task objects include the task IDs and payloads. The same task IDs can then be used with the capability-style task mutation endpoints (`/tasks/:id/claim`, `/tasks/:id/result`, `/tasks/:id/complete`, `/tasks/:id/fail`) to claim, complete, or fail tasks assigned to a different agent. Because ordinary authenticated agents can discover agent names through `GET /api/agenticmail/accounts/directory`, the task ID effectively stops being a secret capability. This turns the intended capability model into a cross-agent authorization bypass. Version 0.9.64 contains a fix. | |||||
| CVE-2026-44585 | 2026-07-23 | N/A | 5.4 MEDIUM | ||
| Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support tickets referencing services belonging to other accounts by modifying the service ID in the request. An attacker could modify the service ID value in the client-side request and successfully create a ticket associated with another user's service. The vulnerability requires authentication and does not provide direct access to service contents or customer data. However, referenced service information could become visible to support personnel handling the ticket. Successful exploitation could allow an authenticated user to: create support tickets referencing services belonging to other users, potentially cause support staff to interact with or review unrelated customer services. The vulnerability did not allow direct access to another user's service, modification of another user's service or retrieval of confidential service data through the vulnerable endpoint itself. This issue has been fixed in version 1.5.0. | |||||
| CVE-2026-59677 | 2026-07-23 | N/A | N/A | ||
| A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10. | |||||
| CVE-2026-65055 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data API endpoints on UserStory, Task, Issue, and Epic viewsets. Attackers can send unauthenticated GET requests to the filters_data endpoints with sequential integer project IDs to enumerate private project membership details including user IDs, full names, and gravatar hashes, bypassing the access controls that correctly restrict other project API endpoints. | |||||
| CVE-2026-65011 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them. | |||||
| CVE-2026-64622 | 2026-07-23 | N/A | 7.5 HIGH | ||
| Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read routes, so even when an operator configures a secret, unauthenticated actors can access sensitive approval request details. The GET /approvals/?status=all, GET /approvals/:id, GET /approvals/stats, and GET /approvals/sse routes disclose full ApprovalEntry content including action/target shell-command strings, file paths, justifications, and risk levels. All responses also carry a hardcoded Access-Control-Allow-Origin: * header, enabling cross-origin disclosure from any website the operator visits. This is an incomplete fix for GHSA-mxjx-28vx-xjjj. | |||||
| CVE-2026-65530 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. | |||||
| CVE-2026-65524 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. | |||||
| CVE-2026-65499 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | |||||
| CVE-2026-65487 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. | |||||
| CVE-2026-65484 | 2026-07-23 | N/A | 6.3 MEDIUM | ||
| Contributor Broken Access Control in Style Kits <= 2.6.5 versions. | |||||
| CVE-2026-65478 | 2026-07-23 | N/A | 5.4 MEDIUM | ||
| Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. | |||||
| CVE-2026-65472 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions. | |||||
| CVE-2026-65468 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. | |||||
| CVE-2026-65453 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | |||||
| CVE-2026-65452 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | |||||
