Export limit exceeded: 15239 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 13663 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (13663 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-45730 | 1 Nuclio | 1 Nuclio | 2026-09-03 | 8.3 High |
| Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project) to bypass OPA authorization checks on write paths (PUT /api/projects/{id}, DELETE /api/projects) and modify or delete any project along with all its associated resources (functions, API gateways, etc.). This issue has been patched in version 1.16.0. | ||||
| CVE-2026-84204 | 1 Growi | 1 Growi | 2026-09-02 | 6.5 Medium |
| GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers. | ||||
| CVE-2026-81164 | 1 Drupal | 1 Entity Pdf | 2026-09-02 | 5.4 Medium |
| Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5. | ||||
| CVE-2026-81158 | 1 Drupal | 1 Entity Api | 2026-09-02 | 5.3 Medium |
| Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0. | ||||
| CVE-2026-73478 | 1 Drupal | 1 Diff | 2026-09-02 | 5.3 Medium |
| Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1. | ||||
| CVE-2026-73552 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73553 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73702 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 8.8 High |
| A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise. | ||||
| CVE-2026-73707 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 8.5 High |
| Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product. | ||||
| CVE-2026-73708 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 8.3 High |
| A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system. | ||||
| CVE-2026-66375 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 8.1 High |
| A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. | ||||
| CVE-2026-66377 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 5.3 Medium |
| An unauthenticated user may access restricted repository information under specific conditions. | ||||
| CVE-2026-66378 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | ||||
| CVE-2026-66379 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| An authenticated user may view private Puppet module metadata without repository read access. | ||||
| CVE-2026-66380 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | ||||
| CVE-2026-68753 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 5.3 Medium |
| An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | ||||
| CVE-2026-68754 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 6.5 Medium |
| A repository publisher without delete permission may modify protected package content under specific conditions. | ||||
| CVE-2026-68755 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| A bundle writer may create misleading release promotion information under specific conditions. | ||||
| CVE-2026-68758 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 6.5 Medium |
| A low-privileged authenticated user may access restricted support information under specific conditions. | ||||
| CVE-2026-82463 | 1 Pac4j | 1 Pac4j | 2026-09-02 | 8.1 High |
| pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks. | ||||