Total
3969 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-58566 | 2026-09-04 | N/A | 8.8 HIGH | ||
| Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |||||
| CVE-2026-72633 | 1 Elastic | 1 Kibana | 2026-09-04 | N/A | 4.3 MEDIUM |
| Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators. | |||||
| CVE-2026-47841 | 1 Vmware | 1 Spring Security | 2026-09-04 | N/A | 7.4 HIGH |
| An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 | |||||
| CVE-2026-85697 | 2026-09-04 | N/A | 6.5 MEDIUM | ||
| Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers. | |||||
| CVE-2026-78609 | 1 Elastic | 1 Elastic Cloud On Kubernetes | 2026-09-04 | N/A | 5.4 MEDIUM |
| Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace. | |||||
| CVE-2026-85512 | 2026-09-04 | 7.5 HIGH | 7.3 HIGH | ||
| A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. | |||||
| CVE-2026-56152 | 1 Elastic | 1 Endpoint Security | 2026-09-04 | N/A | 5.3 MEDIUM |
| Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view. | |||||
| CVE-2026-78587 | 1 Elastic | 1 Fleet Server | 2026-09-03 | N/A | 3.1 LOW |
| Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents. | |||||
| CVE-2026-72643 | 1 Elastic | 1 Kibana | 2026-09-03 | N/A | 7.1 HIGH |
| Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in different realms are treated as the same owner. This discloses the configuration and instructions of an agent the caller does not own, and allows that agent to be altered or removed. | |||||
| CVE-2024-21262 | 2 Netapp, Oracle | 2 Oncommand Insight, Mysql Connector\/odbc | 2026-09-03 | N/A | 6.5 MEDIUM |
| Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L). | |||||
| CVE-2026-80184 | 2026-09-03 | N/A | N/A | ||
| In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an application credential token was presented with no explicit scope, Keystone would issue a new token scoped to the credential owner's default project rather than the project for which the credential was issued, bypassing the intended project boundary. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected. | |||||
| CVE-2026-82293 | 2026-09-03 | N/A | 4.3 MEDIUM | ||
| Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization scope, consuming cluster resources they should not be able to reach. | |||||
| CVE-2025-8945 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API. | |||||
| CVE-2025-15489 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content | |||||
| CVE-2025-15490 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs | |||||
| CVE-2026-78153 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users. | |||||
| CVE-2026-2688 | 2026-09-03 | N/A | 6.5 MEDIUM | ||
| The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints. | |||||
| CVE-2026-84354 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 9.6 CRITICAL |
| Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-84355 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 3.1 LOW |
| Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-84331 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 3.1 LOW |
| Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | |||||
