Export limit exceeded: 381928 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15059 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-47159 | 1 Dani-garcia | 1 Vaultwarden | 2026-07-15 | N/A |
| Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the discovered identifier, enabling SSO-enabled organization enumeration and authentication workflow abuse. This issue is fixed in version 1.36.0. | ||||
| CVE-2026-44986 | 1 Penpot | 1 Penpot | 2026-07-15 | 9.9 Critical |
| Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile issue a session based on the invitation email match without password verification, allowing a registered user to take over any non-blocked profile. This issue is fixed in version 2.14.5. | ||||
| CVE-2026-61435 | 1 Praison | 1 Praisonai | 2026-07-15 | 8.2 High |
| PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the disabled-auth opt-out to localhost binding derives the bind host from request.url.hostname, which is taken from the client-controlled HTTP Host header. A remote, unauthenticated attacker who can reach the service over the network can send a spoofed 'Host: 127.0.0.1' header to bypass the localhost-only restriction and list (GET /api/v1/agents) and invoke (POST /api/v1/agents/{agent_id}/invoke) registered agents without authentication. | ||||
| CVE-2026-58617 | 1 Microsoft | 3 365 Copilot, 365 Copilot Ios, 365 Copilot Ios | 2026-07-15 | 8.1 High |
| Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-50342 | 1 Microsoft | 6 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 3 more | 2026-07-15 | 8.8 High |
| Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-56185 | 1 Microsoft | 1 Windows Admin Center | 2026-07-15 | 6.5 Medium |
| Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-15594 | 1 Waooai | 1 Waoowaoo | 2026-07-15 | 3.7 Low |
| A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-50130 | 1 Pi-hole | 1 Pi-hole | 2026-07-15 | 8.8 High |
| Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3. | ||||
| CVE-2026-12112 | 2 Redhat, Theforeman | 2 Satellite, Foreman | 2026-07-15 | 7.8 High |
| A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code execution. | ||||
| CVE-2026-15542 | 1 Will-moss | 1 Isaiah | 2026-07-15 | 7.3 High |
| A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack can be initiated remotely. The pull request to fix this issue awaits acceptance. | ||||
| CVE-2026-55014 | 1 Microsoft | 2 Remote Help, Windows-remote-help | 2026-07-15 | 7.8 High |
| Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50335 | 1 Microsoft | 14 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 11 more | 2026-07-15 | 7.8 High |
| Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50418 | 1 Microsoft | 8 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 5 more | 2026-07-15 | 5.1 Medium |
| Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. | ||||
| CVE-2026-50344 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-07-15 | 7.8 High |
| Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50495 | 1 Microsoft | 14 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 11 more | 2026-07-15 | 6.1 Medium |
| Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||||
| CVE-2026-15089 | 1 Drupal | 1 Commerce Guest Registration | 2026-07-15 | 9.1 Critical |
| vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*. | ||||
| CVE-2026-50423 | 1 Microsoft | 12 Windows 10 21h2, Windows 10 21h2, Windows 10 22h2 and 9 more | 2026-07-15 | 7.8 High |
| Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-49170 | 1 Microsoft | 14 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 11 more | 2026-07-15 | 7.8 High |
| Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50373 | 1 Microsoft | 14 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 11 more | 2026-07-15 | 7.8 High |
| Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-56169 | 1 Microsoft | 1 Windows Admin Center | 2026-07-15 | 8.1 High |
| Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | ||||