Search Results (42550 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-34836 1 Combodo 1 Itop 2026-08-25 6.5 Medium
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.
CVE-2026-32554 2026-08-25 9.3 Critical
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
CVE-2026-27364 2 Analogwp, Wordpress 2 Style Kits, Wordpress 2026-08-25 6.5 Medium
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
CVE-2026-19755 1 Nosleep 1 Nosleep 2026-08-25 N/A
NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.
CVE-2026-17548 1 Checkmk 1 Checkmk 2026-08-25 N/A
Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.
CVE-2026-78266 2 Ruben Garcia, Wordpress 2 Automatorwp, Wordpress 2026-08-25 6.5 Medium
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
CVE-2026-55528 1 Mervinpraison 2 Praisonai, Praisonaiagents 2026-08-25 8.2 High
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or X-Auth-Token even when authentication is configured. This issue is fixed in version 1.6.58.
CVE-2026-75497 1 Webkul 1 Qloapps 2026-08-25 7.2 High
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c.
CVE-2026-75498 1 Webkul 1 Qloapps 2026-08-25 7.2 High
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'Address.php' file. Fixed in 123c97c.
CVE-2026-18840 1 Ibm 3 Aix, Powervm Vios, Vios 2026-08-25 8.2 High
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.
CVE-2026-78887 1 Liketrek 1 Trek 2026-08-25 3.7 Low
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. Upgrading to version 3.1.0 will fix this issue. You should upgrade the affected component.
CVE-2026-76876 1 Puemos 1 Craftplan 2026-08-25 5.9 Medium
Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the Settings resource. Attackers can send a GET request to the settings API endpoint with a valid record ID to retrieve decrypted SMTP passwords, email API keys, and email API secrets due to the read policy using an always-allow authorization check that bypasses all identity verification.
CVE-2026-75908 2 Contrid, Wordpress 2 Newsletters, Wordpress 2026-08-25 4.3 Medium
The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to send arbitrary newsletter emails to users of any WordPress role, including administrators, by forging POST fields during a normal post submission. This allows an attacker-supplied role slug via the newsletters_mailinglistsroles POST field to be passed directly to get_users(), enabling unauthorized mass-mailing and potential phishing against privileged site users through the site's own outbound email channel.
CVE-2026-69104 1 Jfrog 1 Artifactory 2026-08-25 7.6 High
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
CVE-2026-53572 1 Kedacore 1 Keda 2026-08-25 5.9 Medium
KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password values, while escapePostgreConnectionParameter() only quotes values containing a literal space. Tabs, newlines, carriage returns, form feeds, vertical tabs, quotes, and backslashes can therefore create additional key-value tokens when pgx parses the string. An attacker able to create or modify a TriggerAuthentication or ScaledObject can inject host or sslmode parameters, redirect the database connection to an attacker-controlled server, expose credentials, or disable intended TLS protection. This issue is fixed in version 2.20.0.
CVE-2023-4010 2026-08-25 4.6 Medium
Rejected because the CVE description attributes a vulnerability to a non-existent Linux kernel function (usb_giveback_urb()) and the reported issue cannot be mapped to any valid codebase.
CVE-2026-19442 1 Ibm 3 Aix, Powervm Vios, Vios 2026-08-25 8.2 High
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
CVE-2026-55530 1 Mervinpraison 2 Praisonai, Praisonaiagents 2026-08-25 6.1 Medium
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools. With dry_run=False, an agent-controlled call can pass --update-all and a broad path to rewrite matching files without the expected authorization gate. This issue is fixed in version 1.6.58.
CVE-2026-53487 1 Kite 1 Kite 2026-08-25 4.3 Medium
Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before `middleware.RBACMiddleware()` and `GetOverview` only checks `len(user.Roles) > 0`, so it returns aggregate Kubernetes inventory and capacity data from unauthorized clusters. Version 0.12.3 fixes the issue.
CVE-2026-9127 1 Rockwellautomation 1 Studio 5000 Logix Designer 2026-08-25 7.5 High
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.