CVE tracker
332 subscribers
4.6K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-24155 - NVIDIA NeMo Code Injection

CVE ID :CVE-2026-24155
Published : June 16, 2026, 5:16 p.m. | 43 minutes ago
Description :NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24228 - NVIDIA NeMo Framework Deserialization Vulnerability

CVE ID :CVE-2026-24228
Published : June 16, 2026, 5:16 p.m. | 43 minutes ago
Description :NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39926 - Rejected reason: This CVE ID has been rejected or

CVE ID :CVE-2026-39926
Published : June 16, 2026, 5:16 p.m. | 43 minutes ago
Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39927 - Rejected reason: This CVE ID has been rejected or

CVE ID :CVE-2026-39927
Published : June 16, 2026, 5:16 p.m. | 43 minutes ago
Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-42089 - yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation

CVE ID :CVE-2026-42089
Published : June 16, 2026, 5:16 p.m. | 43 minutes ago
Description :Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled project configuration into this path, this can result in arbitrary package installation and code execution during CLI bootstrap. The vulnerable method is installLocalGenerators(), which calls repository.install() directly without prompting the user. This issue has been fixed in version 6.0.0.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44932 - indirect remote shell command injection via unsanitized DHCP options in wicked

CVE ID :CVE-2026-44932
Published : June 16, 2026, 5:16 p.m. | 43 minutes ago
Description :Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-53776 - Perry < 0.5.1166 JWT Expiration Bypass via verify_decode

CVE ID :CVE-2026-53776
Published : June 16, 2026, 5:16 p.m. | 43 minutes ago
Description :Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a previously issued bearer token can present expired tokens to any jwt.verify() call and retain authenticated access indefinitely, bypassing force-expired sessions such as user logout or administrative revocation.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39580 - WordPress Micdrop theme <= 1.3.1 - PHP Object Injection vulnerability

CVE ID :CVE-2026-39580
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40736 - WordPress Laurits theme <= 1.5.1 - PHP Object Injection vulnerability

CVE ID :CVE-2026-40736
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40739 - WordPress LuxeDrive theme <= 1.4 - PHP Object Injection vulnerability

CVE ID :CVE-2026-40739
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40751 - WordPress Ashtanga theme <= 1.2 - PHP Object Injection vulnerability

CVE ID :CVE-2026-40751
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40754 - WordPress Roisin theme <= 1.4 - PHP Object Injection vulnerability

CVE ID :CVE-2026-40754
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40755 - WordPress TechLink theme <= 1.3 - PHP Object Injection vulnerability

CVE ID :CVE-2026-40755
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40758 - WordPress Léonie theme <= 1.2.1 - PHP Object Injection vulnerability

CVE ID :CVE-2026-40758
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40759 - WordPress Esmée theme <= 1.4 - PHP Object Injection vulnerability

CVE ID :CVE-2026-40759
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40760 - WordPress Behold theme <= 1.5 - PHP Object Injection vulnerability

CVE ID :CVE-2026-40760
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40761 - WordPress Valeska theme <= 1.2.2 - PHP Object Injection vulnerability

CVE ID :CVE-2026-40761
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48869 - WordPress Enfold theme <= 7.1.4 - Reflected Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-48869
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49057 - WordPress JobSearch plugin <= 3.2.7 - Broken Access Control vulnerability

CVE ID :CVE-2026-49057
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49080 - WordPress wpDataTables plugin <= 7.3.6 - SQL Injection vulnerability

CVE ID :CVE-2026-49080
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49113 - WordPress Cornerstone plugin < 7.8.8 - Arbitrary Code Execution vulnerability

CVE ID :CVE-2026-49113
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...