Export limit exceeded: 13617 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (13617 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18255 | 1 Redhat | 2 Quay, Quay 3 | 2026-09-10 | 7.2 High |
| A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account. | ||||
| CVE-2026-81211 | 1 Ibm | 1 Langflow Oss | 2026-09-10 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows. | ||||
| CVE-2026-73014 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-10 | 7.8 High |
| Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-28611 | 1 Google | 1 Android | 2026-09-10 | 7.8 High |
| In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-69377 | 1 Microsoft | 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more | 2026-09-10 | 7.8 High |
| Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69553 | 1 Microsoft | 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more | 2026-09-10 | 7.1 High |
| Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-70283 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-10 | 7 High |
| Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-86085 | 1 N8n | 1 N8n | 2026-09-10 | 4.9 Medium |
| n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. A caller with role:manageProject could name a project the caller could not list and obtain member names and email addresses. The affected controller is packages/cli/src/controllers/role.controller.ts, which omitted the project:list scope check. This issue is fixed in versions 2.37.7 and 2.38.2. | ||||
| CVE-2026-83942 | 1 Microsoft | 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more | 2026-09-10 | 7.8 High |
| Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-86993 | 1 N8n | 1 N8n | 2026-09-10 | 4.9 Medium |
| n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check. A user with a custom global role carrying Log Streaming scopes could select a credential belonging to another project and send its decrypted secret to an attacker-controlled endpoint. The affected authorization boundary is packages/cli/src/modules/log-streaming.ee/destinations/destination-credentials-access.ts and the credential:read scope. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2. | ||||
| CVE-2026-86994 | 1 N8n | 1 N8n | 2026-09-10 | 4.3 Medium |
| n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, deactivation, and publication push events were also broadcast to clients that could not access the affected workflow, disclosing workflow IDs, version IDs, and activation error details. The affected paths include packages/cli/src/services/active-workflows.service.ts and packages/cli/src/workflows/workflow-push-notifier.service.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2. | ||||
| CVE-2026-85025 | 1 Ibm | 1 Langflow Oss | 2026-09-10 | 9.8 Critical |
| IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls. | ||||
| CVE-2026-86996 | 1 N8n | 1 N8n | 2026-09-10 | 5.4 Medium |
| n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool. A user able to build an Agent could invoke a restricted workflow and read its returned data. The affected path is packages/cli/src/modules/agents/tools/workflow-tool-factory.ts, where executeWorkflow omitted SubworkflowPolicyChecker.checkForProject. This issue is fixed in versions 2.37.7 and 2.38.2. | ||||
| CVE-2026-72966 | 1 Microsoft | 24 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 21 more | 2026-09-10 | 5.5 Medium |
| Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally. | ||||
| CVE-2026-87471 | 1 Google | 1 Chrome | 2026-09-10 | 8.1 High |
| Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87475 | 1 Google | 1 Chrome | 2026-09-10 | 6.5 Medium |
| Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87037 | 1 Tanium | 1 Comply | 2026-09-10 | 5.4 Medium |
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87513 | 1 Google | 1 Chrome | 2026-09-10 | 6.5 Medium |
| Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-79324 | 1 Mageplaza | 2 Gdpr, Module-gdpr | 2026-09-10 | 7.5 High |
| Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so no authentication, ownership or form key check is enforced. | ||||
| CVE-2026-87073 | 1 Tanium | 1 Comply | 2026-09-10 | 6.5 Medium |
| Tanium addressed an improper access controls vulnerability in Comply. | ||||