CVE tracker
282 subscribers
3.66K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-13002 - XSS in Farktor Software's E-Commerce Package

CVE ID : CVE-2025-13002
Published : Feb. 12, 2026, 2:16 p.m. | 1 hour, 12 minutes ago
Description : Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Cross-Site Scripting (XSS).This issue affects E-Commerce Package: through 27112025.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-13004 - IDOR in Farktor Software's E-Commerce Package

CVE ID : CVE-2025-13004
Published : Feb. 12, 2026, 2:16 p.m. | 1 hour, 12 minutes ago
Description : Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Manipulating User-Controlled Variables.This issue affects E-Commerce Package: through 27112025.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1320 - Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header

CVE ID : CVE-2026-1320
Published : Feb. 12, 2026, 2:16 p.m. | 1 hour, 12 minutes ago
Description : The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTTP header in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2003 - PostgreSQL oidvector discloses a few bytes of memory

CVE ID : CVE-2026-2003
Published : Feb. 12, 2026, 2:16 p.m. | 1 hour, 12 minutes ago
Description : Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2004 - PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code

CVE ID : CVE-2026-2004
Published : Feb. 12, 2026, 2:16 p.m. | 1 hour, 12 minutes ago
Description : Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2005 - PostgreSQL pgcrypto heap buffer overflow executes arbitrary code

CVE ID : CVE-2026-2005
Published : Feb. 12, 2026, 2:16 p.m. | 1 hour, 12 minutes ago
Description : Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2006 - PostgreSQL missing validation of multibyte character length executes arbitrary code

CVE ID : CVE-2026-2006
Published : Feb. 12, 2026, 2:16 p.m. | 1 hour, 12 minutes ago
Description : Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2007 - PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

CVE ID : CVE-2026-2007
Published : Feb. 12, 2026, 2:16 p.m. | 1 hour, 12 minutes ago
Description : Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-31313 - AMD PMFW Unintended Proxy Arbitrary Code Execution

CVE ID : CVE-2023-31313
Published : Feb. 12, 2026, 2:16 p.m. | 1 hour, 11 minutes ago
Description : An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1104 - FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 - Missing Authorization to Authenticated (Contributor+) Backup Creation and Download

CVE ID : CVE-2026-1104
Published : Feb. 12, 2026, 2:25 p.m. | 1 hour, 2 minutes ago
Description : The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and download full-site backup archives containing the entire WordPress installation, including database exports and configuration files.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-69634 - Dolibarr ERP & CRM CSRF Privilege Escalation

CVE ID : CVE-2025-69634
Published : Feb. 12, 2026, 4:16 p.m. | 3 hours, 12 minutes ago
Description : Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php
Severity: 9.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-69752 - Ideagen Q-Pulse Authentication Bypass

CVE ID : CVE-2025-69752
Published : Feb. 12, 2026, 4:16 p.m. | 3 hours, 12 minutes ago
Description : An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-70886 - Halo Denial of Service (DoS) Vulnerability

CVE ID : CVE-2025-70886
Published : Feb. 12, 2026, 4:16 p.m. | 3 hours, 12 minutes ago
Description : An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-26214 - Xiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITM

CVE ID : CVE-2026-26214
Published : Feb. 12, 2026, 4:16 p.m. | 3 hours, 12 minutes ago
Description : Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default in FDSClientConfiguration, all applications using the SDK with default settings are affected. This vulnerability allows a man-in-the-middle attacker to intercept and modify SDK communications to Xiaomi FDS cloud storage endpoints, potentially exposing authentication credentials, file contents, and API responses. The XiaoMi/galaxy-fds-sdk-android open source project has reached end-of-life status.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-26216 - Crawl4AI < 0.8.0 Docker API Unauthenticated Remote Code Execution via Hooks Parameter

CVE ID : CVE-2026-26216
Published : Feb. 12, 2026, 4:16 p.m. | 3 hours, 12 minutes ago
Description : Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-26217 - Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling

CVE ID : CVE-2026-26217
Published : Feb. 12, 2026, 4:16 p.m. | 3 hours, 12 minutes ago
Description : Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54756 - BrightSign Players Use of Default Credentials

CVE ID : CVE-2025-54756
Published : Feb. 12, 2026, 5:16 p.m. | 2 hours, 12 minutes ago
Description : BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest release fixes this issue for new installations; users of old installations are encouraged to change all default passwords.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-55210 - FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes

CVE ID : CVE-2025-55210
Published : Feb. 12, 2026, 5:16 p.m. | 2 hours, 12 minutes ago
Description : FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege escalation by authenticated users with REST/GraphQL API access. This vulnerability allows an attacker to forge a valid JWT with full access to the REST and GraphQL APIs on a FreePBX that they've already connected to, possibly as a lower privileged user. The JWT is signed using the api-oauth.key private key. An attacker can generate their own token if they possess this key (e.g., by accessing an affected instance), and specify any scopes they wish (e.g., rest, gql), bypassing traditional authorization checks. However, FreePBX enforces that the jti (JWT ID) claim must exist in the database (api_access_tokens table in the asterisk MySQL database) in order for the token to be accepted. Therefore, the attacker must know a jti value that already exists on the target instance. This vulnerability is fixed in 17.0.5 and 16.0.17.
Severity: 2.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61879 - Infoblox NIOS Privilege Escalation File Write Vulnerability

CVE ID : CVE-2025-61879
Published : Feb. 12, 2026, 5:16 p.m. | 2 hours, 12 minutes ago
Description : In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61880 - Infoblox NIOS Deserialization Remote Code Execution

CVE ID : CVE-2025-61880
Published : Feb. 12, 2026, 5:16 p.m. | 2 hours, 12 minutes ago
Description : In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-20601 - Cisco RAS TA Driver Buffer Overflow

CVE ID : CVE-2023-20601
Published : Feb. 12, 2026, 6:16 p.m. | 1 hour, 12 minutes ago
Description : Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...