CVE tracker
332 subscribers
4.61K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-8176 - LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset

CVE ID :CVE-2026-8176
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible for authenticated attackers, with Agent access and above, to elevate their privileges to Administrator.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8442 - WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' Parameter

CVE ID :CVE-2026-8442
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected prefix but fails to sanitize path traversal sequences in the remaining relative path before passing it to unlink(). This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12309 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12309
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12310 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12310
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12311 - Information disclosure, sandbox escape in the Security: Process Sandboxing component

CVE ID :CVE-2026-12311
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12312 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12312
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12313 - Information disclosure, sandbox escape in the Security: Process Sandboxing component

CVE ID :CVE-2026-12313
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12314 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12314
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12315 - Mitigation bypass in the DOM: Security component

CVE ID :CVE-2026-12315
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12316 - Mitigation bypass in the DOM: Security component

CVE ID :CVE-2026-12316
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12317 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12317
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12318 - Incorrect boundary conditions in the Libraries component in NSS

CVE ID :CVE-2026-12318
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12319 - Denial-of-service in the Audio/Video: Playback component

CVE ID :CVE-2026-12319
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12320 - Information disclosure in the Password Manager component

CVE ID :CVE-2026-12320
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12321 - JIT miscompilation in the JavaScript: WebAssembly component

CVE ID :CVE-2026-12321
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12322 - Clickjacking issue in the Widget: Gtk component

CVE ID :CVE-2026-12322
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12323 - Spoofing issue in the DOM: Core & HTML component

CVE ID :CVE-2026-12323
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12324 - Incorrect boundary conditions in the Graphics: CanvasWebGL component

CVE ID :CVE-2026-12324
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12325 - Denial-of-service in the Graphics: ImageLib component

CVE ID :CVE-2026-12325
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12326 - Memory safety bugs fixed in Firefox 152 and Thunderbird 152

CVE ID :CVE-2026-12326
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12327 - Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152

CVE ID :CVE-2026-12327
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...