Search Results (12878 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65055 1 Taiga 1 Taiga 2026-07-27 5.3 Medium
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data API endpoints on UserStory, Task, Issue, and Epic viewsets. Attackers can send unauthenticated GET requests to the filters_data endpoints with sequential integer project IDs to enumerate private project membership details including user IDs, full names, and gravatar hashes, bypassing the access controls that correctly restrict other project API endpoints.
CVE-2026-59536 2 Cocart Headless, Wordpress 2 Cocart – Headless Ecommerce, Wordpress 2026-07-27 7.5 High
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
CVE-2026-59557 2 Franky, Wordpress 2 Events Made Easy, Wordpress 2026-07-27 6.5 Medium
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
CVE-2026-65433 2 Themewant, Wordpress 2 Rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg, Wordpress 2026-07-27 6.5 Medium
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.
CVE-2026-65435 2 Thrive Themes Coupon, Wordpress 2 Thrive Leads Version, Wordpress 2026-07-27 6.5 Medium
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
CVE-2026-65567 2 Nexcess, Wordpress 2 Event Tickets, Wordpress 2026-07-27 5.3 Medium
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
CVE-2026-66442 2 Wordpress, Yaycommerce 2 Wordpress, Yaypricing 2026-07-27 5.4 Medium
Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
CVE-2026-17530 1 Astrbot 1 Astrbot 2026-07-27 6.3 Medium
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as d23011262e8e75e1ec41b0f1f0091493a022327e. A patch should be applied to remediate this issue.
CVE-2026-59529 2 Motovnet, Wordpress 2 Ebook Store, Wordpress 2026-07-27 7.5 High
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-17529 1 Astrbot 1 Astrbot 2026-07-27 6.3 Medium
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is d23011262e8e75e1ec41b0f1f0091493a022327e. It is suggested to install a patch to address this issue.
CVE-2026-59560 2 Roxnor, Wordpress 2 Fundengine, Wordpress 2026-07-27 6.5 Medium
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
CVE-2026-59534 2 Aurovrata Venet, Wordpress 2 Post My Cf7 Form, Wordpress 2026-07-27 7.5 High
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
CVE-2026-59530 2 Paymentplugins, Wordpress 2 Stripe For Woocommerce, Wordpress 2026-07-27 7.5 High
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
CVE-2026-57705 2 Nexcess, Wordpress 2 Event Tickets, Wordpress 2026-07-27 7.5 High
Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.
CVE-2026-49326 1 Apache 1 Hbase 2026-07-27 6.5 Medium
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for identifying the scanner instances stored at server side. We missed the owner check in fetch and close steps which means a user can fetch rows from the scanner which is opened by other users, and close scanners which belongs to other users. This issue affects Apache HBase:from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, through 2.4.*. Users are recommended to upgrade to version 3.0.0-beta-2, 2.6.6 and 2.5.15, which fixes the issue.
CVE-2026-59535 2 Thrive Themes Coupon, Wordpress 2 Thrive Product Manager, Wordpress 2026-07-27 7.3 High
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
CVE-2026-44770 1 Sap Se 1 Sap S/4 Hana (create Single Payment) 2026-07-27 4.3 Medium
SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.
CVE-2026-44771 1 Sap Se 1 Sap S/4hana (draft Operation) 2026-07-27 4.3 Medium
SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
CVE-2026-11802 2 Themelooks, Wordpress 2 Foodbook Lite – Online Food Ordering System, Wordpress 2026-07-27 5.3 Medium
The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.6. The registration() function, accessible via the wp_ajax_nopriv_registration_action AJAX action, lacks any nonce verification or capability check, and does not check the WordPress users_can_register option before calling wp_insert_user(). This makes it possible for unauthenticated attackers to create new user accounts with the 'customer' role and receive authentication cookies, even when the site administrator has explicitly disabled user registration.
CVE-2026-45075 2 Sensiolabs, Symfony 4 Symfony, Http-kernel, Security-http and 1 more 2026-07-27 8.2 High
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12.