CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-2223 - code-projects Online Reviewer System index.php sql injection

CVE ID : CVE-2026-2223
Published : Feb. 9, 2026, 8:16 a.m. | 49 minutes ago
Description : A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/take/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2234 - HGiga|C&Cm@il - Missing Authentication

CVE ID : CVE-2026-2234
Published : Feb. 9, 2026, 8:16 a.m. | 49 minutes ago
Description : C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail content.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2235 - HGiga|C&Cm@il - SQL Injection

CVE ID : CVE-2026-2235
Published : Feb. 9, 2026, 8:16 a.m. | 49 minutes ago
Description : C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2236 - HGiga|C&Cm@il - SQL Injection

CVE ID : CVE-2026-2236
Published : Feb. 9, 2026, 8:16 a.m. | 49 minutes ago
Description : C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2224 - code-projects Online Reviewer System btn_functions.php cross site scripting

CVE ID : CVE-2026-2224
Published : Feb. 9, 2026, 8:32 a.m. | 34 minutes ago
Description : A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25904 - Overly permissive Deno configuration in mcp-run-python leads to SSRF

CVE ID : CVE-2026-25904
Published : Feb. 9, 2026, 8:51 a.m. | 14 minutes ago
Description : The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25905 - Lack of isolation in mcp-run-python leads to MCP server takeover

CVE ID : CVE-2026-25905
Published : Feb. 9, 2026, 9:16 a.m. | 3 hours, 49 minutes ago
Description : The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2225 - itsourcecode News Portal Project Administrator Login index.php sql injection

CVE ID : CVE-2026-2225
Published : Feb. 9, 2026, 9:16 a.m. | 3 hours, 49 minutes ago
Description : A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-23903 - Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems

CVE ID : CVE-2026-23903
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way. Shiro 2.0.7 and later has a new parameters to remediate this issue shiro.ini: filterChainResolver.caseInsensitive = true application.propertie: shiro.caseInsensitive=true Shiro 3.0.0 and later (upcoming) makes this the default.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2226 - DouPHP ZIP File file.php unrestricted upload

CVE ID : CVE-2026-2226
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2227 - D-Link DCS-931L setSystemAdmin doSystem command injection

CVE ID : CVE-2026-2227
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22922 - Apache Airflow: Airflow externalLogUrl Permission Bypass

CVE ID : CVE-2026-22922
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24098 - Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors

CVE ID : CVE-2026-24098
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25846 - JetBrains YouTrack Mailbox Token Exposure Vulnerability

CVE ID : CVE-2026-25846
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25847 - JetBrains PyCharm DOM-based XSS Vulnerability

CVE ID : CVE-2026-25847
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25848 - JetBrains Hub Authentication Bypass Vulnerability

CVE ID : CVE-2026-25848
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10463 - Improper Authentication in Birtech Information Technologies' Sensaway

CVE ID : CVE-2025-10463
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse.This issue affects Senseway: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6830 - SQLi in Xpoda Türkiye Information Technology's Xpoda Studio

CVE ID : CVE-2025-6830
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Xpoda Studio allows SQL Injection.This issue affects Xpoda Studio: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7708 - Sensitive Data Exposure in Atlas Software's k12net

CVE ID : CVE-2025-7708
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation.This issue affects k12net: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0632 - Fluent Forms Pro Add On Pack <= 6.1.12 - Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource'

CVE ID : CVE-2026-0632
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1959 - Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes

CVE ID : CVE-2026-1959
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/jbrain/MaestraCuentasBancarias' endpoint.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...