Export limit exceeded: 393030 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 393030 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 11635 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (11635 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-68852 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-10 | 5.5 Medium |
| Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-21108 | 1 Samsung Mobile | 1 Bixby | 2026-09-10 | N/A |
| Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information. | ||||
| CVE-2026-81021 | 2 Supportcandy, Wordpress | 2 Supportcandy, Wordpress | 2026-09-10 | 5.3 Medium |
| The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket attachment download paths, allowing unauthenticated attackers to read protected customer-uploaded attachments by enumerating sequential attachment identifiers. | ||||
| CVE-2026-84222 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-09-10 | 5.3 Medium |
| The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the content of pages that are not publicly available, such as private, draft, pending and trashed ones. | ||||
| CVE-2026-87035 | 1 Tanium | 1 Comply | 2026-09-10 | 4.3 Medium |
| Tanium addressed an information disclosure vulnerability in Comply. | ||||
| CVE-2026-69806 | 1 Microsoft | 3 .net, Visual Studio 2022, Visual Studio 2026 | 2026-09-10 | 7 High |
| Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-0860 | 1 Arm | 2 Arm 5th Gen Gpu Architecture Kernel Driver, Valhall Gpu Kernel Driver | 2026-09-10 | 7.5 High |
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to sensitive kernel information. This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0. | ||||
| CVE-2026-87541 | 1 Google | 1 Chrome | 2026-09-10 | 6.5 Medium |
| Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87017 | 1 Open-webui | 1 Open-webui | 2026-09-10 | 4.3 Medium |
| Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filter, but the search methods in eleven shipped vector backends ignored that filter. An authenticated user on an affected backend could enumerate the identifiers, names, and descriptions of inaccessible knowledge bases from the shared collection, although the associated document text remained in separate collections. This issue is fixed in version 0.11.1. | ||||
| CVE-2026-79323 | 1 Mageplaza | 1 Magefan Blog | 2026-09-10 | 7.5 High |
| Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql. | ||||
| CVE-2026-19439 | 2026-09-10 | 7.5 High | ||
| The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend. Versions from 3.0.3 to 3.2.8 disclose the same data without the redemption code. | ||||
| CVE-2026-81022 | 2 Supportcandy, Wordpress | 2 Supportcandy, Wordpress | 2026-09-10 | 5.3 Medium |
| The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket. | ||||
| CVE-2026-84195 | 1 Kyverno | 1 Kyverno | 2026-09-10 | 7.7 High |
| Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources. | ||||
| CVE-2026-86767 | 2 Grokability, Snipeitapp | 2 Snipe-it, Snipe-it | 2026-09-10 | 5 Medium |
| Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can retrieve cross-tenant data including requested asset names, requester display names and profile links, locations, and expected check-in dates without parameter manipulation. | ||||
| CVE-2026-88893 | 1 Openpanel | 1 Openpanel | 2026-09-10 | 7.5 High |
| OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown dimensions for offline password cracking and business intelligence theft. | ||||
| CVE-2026-88874 | 1 Wwbn | 1 Avideo | 2026-09-10 | 7.5 High |
| AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password-protected transmission's RTMP stream key, its isPasswordProtected flag, and its HLS (m3u8) URL to unauthenticated callers, in both the public applications list and the hidden_applications branch used when canSeeLiveFromLiveKey() fails. Separately, the shipped NGINX configuration (deploy/nginx/nginx.conf) serves the .m3u8 playlist, the AES-128 key, and the transport-stream segments from the /live location without any auth_request (the auth_key_check directive in the .key location is commented out). A remote, unauthenticated attacker can therefore retrieve the stream key and decryption key and watch a password-protected live transmission without supplying the configured password. No patched version was available at the time of the advisory. | ||||
| CVE-2026-0305 | 1 Palo Alto Networks | 1 Prisma Access Agent | 2026-09-10 | N/A |
| An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected. | ||||
| CVE-2026-75162 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-10 | 6.5 Medium |
| An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via the JSON API response. | ||||
| CVE-2026-71626 | 1 Invoiceninja | 1 Invoice Ninja | 2026-09-10 | 7.5 High |
| An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components | ||||
| CVE-2026-87495 | 1 Google | 1 Chrome | 2026-09-09 | 4.3 Medium |
| Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||