Export limit exceeded: 11060 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (11060 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-24546 2 Ruben Garcia, Wordpress 2 Gamipress, Wordpress 2026-05-26 5.3 Medium
Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3.
CVE-2026-24586 2 Themeansar, Wordpress 2 Newses, Wordpress 2026-05-26 5.4 Medium
Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Newses: from n/a through 2.0.0.77.
CVE-2026-27398 2 Wordpress, Wpchill 2 Wordpress, Rsvp And Event Management 2026-05-26 5.3 Medium
Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16.
CVE-2026-24545 2 Nikki Blight, Wordpress 2 Qr Redirector, Wordpress 2026-05-26 4.3 Medium
Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.
CVE-2026-24582 2 Wordpress, Wppool 2 Wordpress, Flextable 2026-05-26 4.3 Medium
Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexTable: from n/a through 3.24.0.
CVE-2026-24592 2 Lucian Apostol, Wordpress 2 Auto Affiliate Links, Wordpress 2026-05-26 5.3 Medium
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3.
CVE-2026-24527 2 Patterns In The Cloud, Wordpress 2 Autoship Cloud For Woocommerce Subscription Products, Wordpress 2026-05-26 4.3 Medium
Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0.
CVE-2026-45209 2 Edward Plainview, Wordpress 2 Mycryptocheckout, Wordpress 2026-05-26 7.5 High
Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.
CVE-2026-42763 2 Sepay Team, Wordpress 2 Sepay Gateway, Wordpress 2026-05-26 6.5 Medium
Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue affects SePay Gateway: from n/a through 1.1.20.
CVE-2026-32389 2 Linethemes, Wordpress 2 Nanocare, Wordpress 2026-05-26 5.4 Medium
Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects NanoCare: from n/a before 1.2.2.
CVE-2026-24638 2 Webful Creations, Wordpress 2 Repairbuddy, Wordpress 2026-05-26 4.3 Medium
Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.
CVE-2026-24590 2 Videowhisper.com, Wordpress 2 Paid Videochat Turnkey Site, Wordpress 2026-05-26 5.3 Medium
Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.
CVE-2026-5146 1 Devolutions 2 Devolutions Server, Server 2026-05-26 4.3 Medium
Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.15.0 * Devolutions Server 2025.3.19.0 and earlier
CVE-2026-9486 1 Sourcecodester 1 Student Grades Management System 2026-05-26 4.3 Medium
A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-20238 1 Splunk 2 Ai Toolkit, Splunk Ai Toolkit 2026-05-26 6.5 Medium
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the `OR` SPL operator, the injected filter overrides more restrictive filters on child roles.
CVE-2026-8407 1 Devolutions 2 Devolutions Server, Server 2026-05-26 4.3 Medium
Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.11.0 * Devolutions Server 2025.3.16.0 and earlier
CVE-2026-42432 1 Openclaw 1 Openclaw 2026-05-26 7.8 High
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without the operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.
CVE-2026-42429 1 Openclaw 1 Openclaw 2026-05-26 7.1 High
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that escalates identity-bearing operator.read requests to runtime operator.write permissions. Attackers can exploit this by sending read-scoped requests through the gateway auth route to gain unauthorized write access to runtime operations.
CVE-2026-32067 1 Openclaw 1 Openclaw 2026-05-26 3.7 Low
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple accounts. An attacker approved as a sender in one account can be automatically accepted in another account in multi-account deployments without explicit approval, bypassing authorization boundaries.
CVE-2026-27357 2 Cornelraiu, Wordpress 2 Wp Search Analytics, Wordpress 2026-05-26 5.3 Medium
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Search Analytics: from n/a before 1.5.0.