Total
9757 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87606 | 2026-09-10 | 8.1 High | ||
| Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87569 | 1 Google | 1 Chrome | 2026-09-10 | 8.8 High |
| Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87557 | 1 Google | 1 Chrome | 2026-09-10 | 4.3 Medium |
| Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87552 | 1 Google | 2 Android, Chrome | 2026-09-10 | 5.5 Medium |
| Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High) | ||||
| CVE-2026-85669 | 1 Potpie-ai | 1 Potpie | 2026-09-10 | 6.5 Medium |
| potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes. | ||||
| CVE-2026-85651 | 1 Triggerdotdev | 1 Trigger.dev | 2026-09-10 | 8.5 High |
| Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history. | ||||
| CVE-2026-81799 | 2026-09-10 | 7.5 High | ||
| Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. | ||||
| CVE-2026-81785 | 2026-09-10 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. | ||||
| CVE-2026-78536 | 2026-09-10 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | ||||
| CVE-2026-87543 | 1 Google | 1 Chrome | 2026-09-10 | 4.3 Medium |
| Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-88959 | 1 Anchorcms | 1 Anchor Cms | 2026-09-10 | 8.8 High |
| Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify existing ones. Attackers with editor or user roles can POST directly to admin/users/add or admin/users/edit endpoints to create new administrator accounts or change the existing administrator's password, gaining full administrative access. | ||||
| CVE-2026-4129 | 1 Ni | 2 Systemlink, Systemlink Server | 2026-09-10 | 8.1 High |
| There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions. | ||||
| CVE-2026-88898 | 2026-09-10 | 6.5 Medium | ||
| AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs. | ||||
| CVE-2026-87441 | 2026-09-10 | 6.5 Medium | ||
| Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium) | ||||
| CVE-2026-86762 | 1 Snipeitapp | 1 Snipe-it | 2026-09-10 | 8.1 High |
| Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens. As a result, although a deactivated account is correctly refused at web login, its existing API token continues to authenticate and to grant read and write access to the REST API (assets, users, licenses, etc.) at the account's prior permission level until the token expires. A deactivated account that retains user-management permissions can re-activate itself through the API, permanently defeating the deactivation control. | ||||
| CVE-2026-86757 | 1 Snipeitapp | 1 Snipe-it | 2026-09-10 | 6.5 Medium |
| Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checkin, assets.checkout, or assets.audit permissions can read plaintext encrypted custom field values by opening asset forms, bypassing the assets.view.encrypted_custom_fields permission check. | ||||
| CVE-2026-84821 | 2026-09-10 | 7.5 High | ||
| Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions. | ||||
| CVE-2026-81904 | 2026-09-10 | N/A | ||
| Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration values emitted by a restricted sub-block's asset registration — such as a site's configured Google Maps API key — from any public page embedding an affected Stack, Container, or layout area, despite the block-level permission restriction. Any sub-block type whose asset or header hooks output configuration values is affected. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting. | ||||
| CVE-2026-81788 | 2026-09-10 | 6.3 Medium | ||
| Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions. | ||||
| CVE-2026-28611 | 1 Google | 1 Android | 2026-09-10 | 7.8 High |
| In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||