Total
396163 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-18994 | 2026-09-11 | N/A | 7.1 HIGH | ||
| A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application. | |||||
| CVE-2026-18121 | 2026-09-11 | N/A | N/A | ||
| Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns the requested event occurrence. The controller loads the occurrence directly from an attacker‑supplied, sequential identifier without confirming that it belongs to the calendar configured on the referenced block. An unauthenticated visitor who can render any public calendar block with lightbox properties enabled could therefore supply an arbitrary occurrence identifier and disclose event metadata — title, date, description, page link, and configured event attributes — from calendars they are not permitted to view. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting. | |||||
| CVE-2026-15462 | 2026-09-11 | N/A | 7.5 HIGH | ||
| The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to $wpdb->insert(), which wraps column identifiers in backticks without escaping them, allowing a backtick in an attacker-supplied key to break out of the column-identifier list into raw SQL; additionally, the use of filter_input() bypasses WordPress's wp_magic_quotes() protection, and the widget_id validation loop is skipped entirely when no valid widget_id is supplied, leaving $isValid at 1. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
| CVE-2026-11813 | 2026-09-11 | N/A | 7.8 HIGH | ||
| A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges. | |||||
| CVE-2026-63296 | 1 Canonical | 1 Lxd | 2026-09-11 | N/A | 9.9 CRITICAL |
| An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls. | |||||
| CVE-2026-63295 | 1 Canonical | 1 Lxd | 2026-09-11 | N/A | 4.3 MEDIUM |
| An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints. | |||||
| CVE-2026-63294 | 1 Canonical | 1 Lxd | 2026-09-11 | N/A | 9.9 CRITICAL |
| A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges. | |||||
| CVE-2026-87584 | 1 Google | 1 Chrome | 2026-09-11 | N/A | 6.5 MEDIUM |
| Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-73784 | 2026-09-11 | N/A | 8.8 HIGH | ||
| A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user. | |||||
| CVE-2026-11765 | 2026-09-11 | N/A | 3.3 LOW | ||
| Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Argument Injection. This issue affects Pardus Pen: before 4.2.1. | |||||
| CVE-2026-87580 | 1 Google | 1 Chrome | 2026-09-11 | N/A | 6.5 MEDIUM |
| Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-62420 | 1 Canonical | 1 Lxd | 2026-09-11 | N/A | 9.9 CRITICAL |
| An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project. | |||||
| CVE-2026-87589 | 1 Google | 1 Chrome | 2026-09-11 | N/A | 6.5 MEDIUM |
| Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-77106 | 1 Commvault | 1 Commvault | 2026-09-11 | N/A | 8.8 HIGH |
| Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. | |||||
| CVE-2026-77089 | 1 Commvault | 1 Commvault | 2026-09-11 | N/A | 9.8 CRITICAL |
| Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. | |||||
| CVE-2026-13738 | 1 Commvault | 1 Commvault | 2026-09-11 | N/A | 9.8 CRITICAL |
| CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. | |||||
| CVE-2026-77091 | 1 Commvault | 1 Commvault | 2026-09-11 | N/A | 7.8 HIGH |
| DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store. | |||||
| CVE-2026-77092 | 1 Commvault | 1 Commvault | 2026-09-11 | N/A | 9.8 CRITICAL |
| Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor. | |||||
| CVE-2026-77097 | 1 Commvault | 1 Commvault | 2026-09-11 | N/A | 8.2 HIGH |
| Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. | |||||
| CVE-2026-77098 | 1 Commvault | 1 Commvault | 2026-09-11 | N/A | 9.8 CRITICAL |
| Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. | |||||
