Export limit exceeded: 16028 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 13815 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (13815 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-62927 | 1 Eclipse | 1 Milo | 2026-08-04 | 7.5 High |
| In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method. | ||||
| CVE-2026-58080 | 1 Eclipse | 1 Milo | 2026-08-04 | 8.2 High |
| In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted to read role-permission metadata, invoke protected methods, or delete protected nodes. | ||||
| CVE-2026-63248 | 1 Eclipse | 1 Milo | 2026-08-04 | 6.5 Medium |
| In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates. | ||||
| CVE-2026-64630 | 1 Veeam | 1 One | 2026-08-04 | N/A |
| A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. | ||||
| CVE-2026-62354 | 1 Apache | 1 Nifi | 2026-08-04 | 4.3 Medium |
| Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests. | ||||
| CVE-2026-18650 | 1 Havelsan | 1 Liman Mys | 2026-08-04 | 8.8 High |
| Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | ||||
| CVE-2026-16057 | 2 Contest-gallery, Wordpress | 2 Contest Gallery, Wordpress | 2026-08-04 | 6.5 Medium |
| The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own. | ||||
| CVE-2026-16274 | 2026-08-04 | 2.7 Low | ||
| The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership. | ||||
| CVE-2023-4853 | 2 Quarkus, Redhat | 21 Quarkus, Build Of Optaplanner, Build Of Quarkus and 18 more | 2026-08-04 | 8.1 High |
| A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service. | ||||
| CVE-2026-48113 | 1 Jpillora | 1 Chisel | 2026-08-04 | N/A |
| Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial handshake against declared remotes, but never on subsequent SSH channels that carry actual traffic. A malicious client can authenticate with a permitted remote, then open channels to any host:port it wants. This issue has been fixed in version 1.11.5. | ||||
| CVE-2026-60784 | 1 Oracle | 1 Trading Community | 2026-08-04 | 8.1 High |
| Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trading Community accessible data as well as unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-17070 | 1 Havelsan | 1 Liman Mys | 2026-08-04 | 8.8 High |
| Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | ||||
| CVE-2026-18773 | 1 Nousresearch | 1 Hermes-agent | 2026-08-04 | 6.3 Medium |
| A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-66311 | 1 Microsoft | 1 Edge Chromium | 2026-08-04 | 6.2 Medium |
| Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | ||||
| CVE-2026-66326 | 1 Microsoft | 1 Edge Chromium | 2026-08-04 | 6.5 Medium |
| Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-16546 | 2026-08-04 | 4.3 Medium | ||
| The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer opportunity. | ||||
| CVE-2026-43672 | 1 Apple | 1 Macos | 2026-08-04 | 7.1 High |
| An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences. | ||||
| CVE-2026-43665 | 1 Apple | 1 Macos | 2026-08-04 | 5.5 Medium |
| This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing. | ||||
| CVE-2026-14862 | 2026-08-04 | 3.7 Low | ||
| The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments. | ||||
| CVE-2026-46730 | 1 Dell | 2 Data Domain Operating System, Powerprotect Data Domain | 2026-08-04 | 4.2 Medium |
| Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution. | ||||