Export limit exceeded: 14267 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14267 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65380 | 1 Apple | 1 Macos | 2026-09-20 | 5.5 Medium |
| An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden Gate 27. An app may be able to access protected user data. | ||||
| CVE-2026-65381 | 1 Apple | 1 Macos | 2026-09-20 | 8.8 High |
| A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious app may be able to break out of its sandbox. | ||||
| CVE-2026-65378 | 1 Apple | 1 Macos | 2026-09-20 | 5.5 Medium |
| An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data. | ||||
| CVE-2026-84551 | 1 Apple | 6 Ios And Ipados, Ipados, Iphone Os and 3 more | 2026-09-20 | 4.4 Medium |
| A logic issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to bypass network restrictions. | ||||
| CVE-2026-65342 | 1 Apple | 1 Macos | 2026-09-20 | 5.5 Medium |
| A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data. | ||||
| CVE-2026-88617 | 2026-09-20 | 9.8 Critical | ||
| SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges. | ||||
| CVE-2026-43785 | 1 Apple | 6 Ios And Ipados, Ipados, Iphone Os and 3 more | 2026-09-20 | 5.5 Medium |
| A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to modify a file it only had permission to read. | ||||
| CVE-2026-65404 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-20 | 5.5 Medium |
| An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malicious application may be able to bypass Privacy preferences. | ||||
| CVE-2026-84601 | 1 Apple | 1 Macos | 2026-09-20 | 5.5 Medium |
| A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Apple Intelligence security prompts. | ||||
| CVE-2026-84617 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-20 | 5.5 Medium |
| An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27. An app may be able to access sensitive user data. | ||||
| CVE-2026-84569 | 1 Apple | 1 Macos | 2026-09-20 | 5.5 Medium |
| An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data. | ||||
| CVE-2026-43737 | 1 Apple | 6 Ios And Ipados, Ipados, Iphone Os and 3 more | 2026-09-20 | 5.5 Medium |
| An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access motion data from headphones without user consent. | ||||
| CVE-2026-84580 | 1 Apple | 1 Macos | 2026-09-20 | 8.4 High |
| The issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox. | ||||
| CVE-2026-84514 | 1 Apple | 1 Macos | 2026-09-20 | 5.5 Medium |
| This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system. | ||||
| CVE-2026-88616 | 1 Dromara | 1 Ruoyi-vue-plus | 2026-09-20 | 8.8 High |
| An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components | ||||
| CVE-2026-88619 | 1 1024-lab | 1 Smartadmin | 2026-09-20 | 8.1 High |
| 1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The AdminSmartJobController exposes scheduled-job management endpoints without method-level permission checks, allowing a low-privileged authenticated user to access functionality intended for authorized administrators. | ||||
| CVE-2026-92965 | 2 Tiktok, Wordpress | 2 Tiktok, Wordpress | 2026-09-20 | 3.7 Low |
| The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that merely resemble the expected one trigger it too, and the callback runs on every request to the site rather than only on the administrator's sign-in. | ||||
| CVE-2026-90971 | 1 Devolutions | 1 Server | 2026-09-20 | 6.5 Medium |
| Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery. | ||||
| CVE-2026-81178 | 1 Syslifters | 1 Sysreptor | 2026-09-20 | 3.5 Low |
| SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share consumer joins the same collaboration group as authenticated project members and forwards client information, connection, awareness, and deletion events without consistently restricting them to the shared note subtree. The disclosed metadata can identify project members through usernames and names and reveal the identifiers and live editing activity of notes that were not shared. The content of non-shared notes remains protected, and the issue does not grant write access. This issue is fixed in version 2026.55. | ||||
| CVE-2026-11899 | 2 Edgarrojas, Wordpress | 2 Pdf Builder For Woocommerce. Create Invoices,packing Slips And More, Wordpress | 2026-09-20 | 4.3 Medium |
| The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve invoice numbers, formatted invoice numbers, and creation timestamps for arbitrary WooCommerce orders by supplying any OrderNumber and InvoiceId values with a garbage nonce. | ||||