CVE tracker
341 subscribers
4.65K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-45174 - Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initialization

CVE ID :CVE-2026-45174
Published : June 11, 2026, 10:16 p.m. | 3 hours, 13 minutes ago
Description :Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49060 - WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability

CVE ID :CVE-2026-49060
Published : June 11, 2026, 10:16 p.m. | 3 hours, 13 minutes ago
Description :Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-6250 - Authenticated Format String Injection on TP-Link Tapo C110

CVE ID :CVE-2026-6250
Published : June 11, 2026, 10:16 p.m. | 3 hours, 13 minutes ago
Description :An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-42846 - ClipBucket: Remote Play URL Command Injection

CVE ID :CVE-2026-42846
Published : June 11, 2026, 11:16 p.m. | 2 hours, 14 minutes ago
Description :ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated directly into shell commands without escaping then executed, so any shell metacharacter in the URL is interpreted. This results in arbitrary command execution. This issue has been patched in version 5.5.3 - #140.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45060 - ClipBucket: Blind SQL Injection in progress_video.php

CVE ID :CVE-2026-45060
Published : June 11, 2026, 11:16 p.m. | 2 hours, 14 minutes ago
Description :ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #129.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45418 - ClipBucket: Blind SQL Injection in subtitle_edit.php

CVE ID :CVE-2026-45418
Published : June 11, 2026, 11:16 p.m. | 2 hours, 14 minutes ago
Description :ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their title (English, Spanish...). The POST /actions/subtitle_edit.php request used to change their title includes a number parameter which is vulnerable to SQL Injection. A boolean-based blind SQL injection can be used to exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #132.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47238 - ClipBucket: IDOR in videos subtitle editor

CVE ID :CVE-2026-47238
Published : June 11, 2026, 11:16 p.m. | 2 hours, 14 minutes ago
Description :ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can upload subtitles, edit their name or delete them. This issue has been patched in version 5.5.3 - #133.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45170 - Idira Privilege Cloud Connector: Potential Security Bypass due to Incomplete TLS Certificate Validation

CVE ID :CVE-2026-45170
Published : June 12, 2026, 12:05 a.m. | 1 hour, 24 minutes ago
Description :Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10676 - Rejected reason: This CVE Record has been rejected

CVE ID :CVE-2026-10676
Published : June 12, 2026, 12:16 a.m. | 1 hour, 14 minutes ago
Description :Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis determined that the addressed defect is not reachable in any released version of Zephyr: on every supported release branch the affected value is corrected before it is used, and the change that exposes the defect exists only in unreleased development code. As no released version is affected, this identifier is withdrawn.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49482 - ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite

CVE ID :CVE-2026-49482
Published : June 12, 2026, 12:16 a.m. | 1 hour, 14 minutes ago
Description :ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle editing endpoint. An authenticated user can send a % character as the number parameter to overwrite all subtitle titles of any video they own in a single HTTP request. This issue has been patched in version 5.5.3 - #141.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11933 - Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion

CVE ID :CVE-2026-11933
Published : June 12, 2026, 2:16 a.m. | 3 hours, 14 minutes ago
Description :A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9125 - The Ultimate Video Player For WordPress <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode Attribute

CVE ID :CVE-2026-9125
Published : June 12, 2026, 2:16 a.m. | 3 hours, 13 minutes ago
Description :The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url shortcode attribute directly into the overlay configuration without scheme validation, allowing javascript: URIs to survive and be rendered as the href of a clickable anchor element by the presto-dynamic-overlay-ui web component. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20746 - PingDirectory copying of virtual attributes leads to memory exhaustion

CVE ID :CVE-2026-20746
Published : June 12, 2026, 4:17 a.m. | 1 hour, 13 minutes ago
Description :Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47365 - WordPress Toolkit Argument Injection

CVE ID :CVE-2026-47365
Published : June 12, 2026, 4:17 a.m. | 1 hour, 13 minutes ago
Description :Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47366 - PHPGraffiti ACP Privilege Escalation

CVE ID :CVE-2026-47366
Published : June 12, 2026, 4:17 a.m. | 1 hour, 13 minutes ago
Description :Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47367 - UID Enterprise Agent Command Injection

CVE ID :CVE-2026-47367
Published : June 12, 2026, 4:17 a.m. | 1 hour, 13 minutes ago
Description :A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47368 - UniFi OS Path Traversal

CVE ID :CVE-2026-47368
Published : June 12, 2026, 4:17 a.m. | 1 hour, 13 minutes ago
Description :A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47369 - UniFi OS Improper Input Validation Privilege Escalation

CVE ID :CVE-2026-47369
Published : June 12, 2026, 4:17 a.m. | 1 hour, 13 minutes ago
Description :A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47370 - UniFi OS Command Injection

CVE ID :CVE-2026-47370
Published : June 12, 2026, 4:17 a.m. | 1 hour, 13 minutes ago
Description :A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48610 - UniFi OS Improper Access Control Vulnerability

CVE ID :CVE-2026-48610
Published : June 12, 2026, 4:17 a.m. | 1 hour, 13 minutes ago
Description :Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48611 - Google OAuth Account Hijacking Vulnerability

CVE ID :CVE-2026-48611
Published : June 12, 2026, 4:17 a.m. | 1 hour, 13 minutes ago
Description :Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...