Export limit exceeded: 10273 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10273 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73788 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-09-10 | 6.5 Medium |
| A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially unauthorized operation of the vulnerable system. | ||||
| CVE-2026-87998 | 1 Open-webui | 1 Open-webui | 2026-09-10 | 7.1 High |
| Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge base but then removed its administrator-owned external connection without a separate administrator check or a check for other dependent knowledge bases. A non-administrator with write access to one external knowledge base could delete shared instance configuration and make every other knowledge base using that connection unavailable. This issue is fixed in version 0.11.1. | ||||
| CVE-2026-84042 | 1 Redhat | 1 Hummingbird | 2026-09-10 | 7.8 High |
| A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29 | ||||
| CVE-2026-81805 | 2026-09-10 | 8.1 High | ||
| Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions. | ||||
| CVE-2026-88863 | 2026-09-10 | 8.1 High | ||
| capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /private/invite_new_user_to_org endpoint only requires the org.update_user_roles permission for org_super_admin invitations, so an authenticated user holding only the org.invite_user permission (e.g., an org_member) can invite an external user as org_admin or org_billing_admin. When the invited account accepts the invitation via POST /private/accept_invitation, ensureOrgMembership creates the role binding using the Supabase service-role key, which bypasses the prevent_role_binding_priority_escalation and check_org_user_privileges database triggers. This allows privilege escalation resulting in full administrative control over the organization's apps, channels, members, and billing. The issue is addressed by pull request #3096, which compares the inviter's rank before permitting elevated invitations. | ||||
| CVE-2026-49310 | 1 Huawei | 1 Harmonyos | 2026-09-10 | 8.6 High |
| Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2026-81431 | 2026-09-10 | 7.2 High | ||
| The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can therefore register a new account with an arbitrary role, including Administrator, leading to full site takeover. This is an incomplete fix of CVE-2026-54807. | ||||
| CVE-2026-49312 | 1 Huawei | 1 Harmonyos | 2026-09-10 | 4 Medium |
| Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2026-81644 | 1 Huawei | 1 Harmonyos | 2026-09-10 | 4.3 Medium |
| DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-49315 | 1 Huawei | 2 Emui, Harmonyos | 2026-09-10 | 7.1 High |
| DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-41987 | 1 Huawei | 2 Emui, Harmonyos | 2026-09-10 | 6.2 Medium |
| Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-49313 | 1 Huawei | 1 Harmonyos | 2026-09-10 | 5.5 Medium |
| Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2026-88891 | 1 Openpanel | 1 Openpanel | 2026-09-10 | 8.3 High |
| OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers. | ||||
| CVE-2026-28659 | 1 Google | 1 Android Xr | 2026-09-10 | N/A |
| In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-80921 | 1 Linux | 1 Linux Kernel | 2026-09-10 | 8.8 High |
| In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits. | ||||
| CVE-2026-75166 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-10 | 8.8 High |
| Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution. | ||||
| CVE-2026-71625 | 1 Slimkit | 1 Thinksns+ | 2026-09-10 | 9.8 Critical |
| An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component | ||||
| CVE-2026-66818 | 1 Microsoft | 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more | 2026-09-09 | 8.8 High |
| Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-86512 | 1 Java-json-tools | 1 Json-patch | 2026-09-09 | 6.3 Medium |
| A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-86746 | 1 Snipeitapp | 1 Snipe-it | 2026-09-09 | 6.4 Medium |
| Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid authenticated session can replay signed component snapshots via POST /livewire/update to invoke protected methods and escalate privileges, including creating OAuth clients, minting personal access tokens, and accessing sensitive admin data. | ||||