CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-2225 - itsourcecode News Portal Project Administrator Login index.php sql injection

CVE ID : CVE-2026-2225
Published : Feb. 9, 2026, 9:16 a.m. | 3 hours, 49 minutes ago
Description : A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-23903 - Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems

CVE ID : CVE-2026-23903
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way. Shiro 2.0.7 and later has a new parameters to remediate this issue shiro.ini: filterChainResolver.caseInsensitive = true application.propertie: shiro.caseInsensitive=true Shiro 3.0.0 and later (upcoming) makes this the default.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2226 - DouPHP ZIP File file.php unrestricted upload

CVE ID : CVE-2026-2226
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2227 - D-Link DCS-931L setSystemAdmin doSystem command injection

CVE ID : CVE-2026-2227
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22922 - Apache Airflow: Airflow externalLogUrl Permission Bypass

CVE ID : CVE-2026-22922
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24098 - Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors

CVE ID : CVE-2026-24098
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25846 - JetBrains YouTrack Mailbox Token Exposure Vulnerability

CVE ID : CVE-2026-25846
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25847 - JetBrains PyCharm DOM-based XSS Vulnerability

CVE ID : CVE-2026-25847
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25848 - JetBrains Hub Authentication Bypass Vulnerability

CVE ID : CVE-2026-25848
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10463 - Improper Authentication in Birtech Information Technologies' Sensaway

CVE ID : CVE-2025-10463
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse.This issue affects Senseway: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6830 - SQLi in Xpoda Türkiye Information Technology's Xpoda Studio

CVE ID : CVE-2025-6830
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Xpoda Studio allows SQL Injection.This issue affects Xpoda Studio: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7708 - Sensitive Data Exposure in Atlas Software's k12net

CVE ID : CVE-2025-7708
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation.This issue affects k12net: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0632 - Fluent Forms Pro Add On Pack <= 6.1.12 - Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource'

CVE ID : CVE-2026-0632
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1959 - Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes

CVE ID : CVE-2026-1959
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/jbrain/MaestraCuentasBancarias' endpoint.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1960 - Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes

CVE ID : CVE-2026-1960
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'Facebook' parameter in '/loggrodemo/jbrain/ConsultaTerceros' endpoint.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10464 - Cleartext password storage in Birtech Information Technologies' Sensaway

CVE ID : CVE-2025-10464
Published : Feb. 9, 2026, 12:49 p.m. | 17 minutes ago
Description : Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data.This issue affects Senseway: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10465 - Unrestricted File Upload in Birtech Information Technologies' Sensaway

CVE ID : CVE-2025-10465
Published : Feb. 9, 2026, 2:16 p.m. | 51 minutes ago
Description : Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server.This issue affects Sensaway: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0398 - Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor

CVE ID : CVE-2026-0398
Published : Feb. 9, 2026, 2:20 p.m. | 46 minutes ago
Description : Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24027 - Crafted zones can lead to increased incoming network traffic

CVE ID : CVE-2026-24027
Published : Feb. 9, 2026, 2:25 p.m. | 42 minutes ago
Description : Crafted zones can lead to increased incoming network traffic.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14831 - Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification

CVE ID : CVE-2025-14831
Published : Feb. 9, 2026, 3:16 p.m. | 3 hours, 54 minutes ago
Description : A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-59023 - Crafted delegations or IP fragments can poison cached delegations in Recursor

CVE ID : CVE-2025-59023
Published : Feb. 9, 2026, 3:16 p.m. | 3 hours, 54 minutes ago
Description : Crafted delegations or IP fragments can poison cached delegations in Recursor.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...