CVE tracker
331 subscribers
4.6K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-12466 - Google Chrome Heap Buffer Overflow

CVE ID :CVE-2026-12466
Published : June 17, 2026, 1:38 a.m. | 22 minutes ago
Description :Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12467 - Google Chrome Use-After-Free Sandbox Escape

CVE ID :CVE-2026-12467
Published : June 17, 2026, 1:38 a.m. | 22 minutes ago
Description :Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12468 - Google Chrome Updater Sandbox Escape

CVE ID :CVE-2026-12468
Published : June 17, 2026, 1:38 a.m. | 22 minutes ago
Description :Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12469 - Google Chrome GPU Uninitialized Use Information Leak

CVE ID :CVE-2026-12469
Published : June 17, 2026, 1:38 a.m. | 22 minutes ago
Description :Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50203 - Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory allows local file write outside the destination directory via malicious server-supplied directory-entry names

CVE ID :CVE-2026-50203
Published : June 17, 2026, 1:47 a.m. | 13 minutes ago
Description :A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15642 - Netskope Client Service Insufficient Access Controls

CVE ID :CVE-2025-15642
Published : June 17, 2026, 1:48 a.m. | 12 minutes ago
Description :Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,. * Product Name: Netskope Client * Affected Platform: Windows * Affected Version: All version below R138
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12360 - JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection via Listing Grid Load More AJAX Endpoint

CVE ID :CVE-2026-12360
Published : June 17, 2026, 4:32 a.m. | 1 hour, 29 minutes ago
Description :The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row values within filtered_query are not sanitized before being merged into SQL construction. This makes it possible for unauthenticated attackers to perform time-based or boolean blind SQL injection by appending a malicious meta_query value to a Load More AJAX request captured from any public Listing Grid page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-53876 - RadiX Command Injection

CVE ID :CVE-2026-53876
Published : June 17, 2026, 4:56 a.m. | 1 hour, 5 minutes ago
Description :RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48571 - BTM SMS Interception Information Disclosure

CVE ID :CVE-2025-48571
Published : June 17, 2026, 5:53 a.m. | 7 minutes ago
Description :In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48617 - CarrierConfigLoader UID Bypass Privilege Escalation

CVE ID :CVE-2025-48617
Published : June 17, 2026, 5:53 a.m. | 7 minutes ago
Description :In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48640 - Third-Party Passkey Pairing Approval Vulnerability

CVE ID :CVE-2025-48640
Published : June 17, 2026, 5:53 a.m. | 7 minutes ago
Description :In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48643 - Citrix Gateway Privilege Escalation Vulnerability

CVE ID :CVE-2025-48643
Published : June 17, 2026, 5:53 a.m. | 7 minutes ago
Description :In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0019 - SettingsLib Local Privilege Escalation

CVE ID :CVE-2026-0019
Published : June 17, 2026, 5:53 a.m. | 7 minutes ago
Description :In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0057 - Contacts Provider Local Information Disclosure

CVE ID :CVE-2026-0057
Published : June 17, 2026, 5:53 a.m. | 7 minutes ago
Description :In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8607 - myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute

CVE ID :CVE-2026-8607
Published : June 17, 2026, 6:49 a.m. | 3 hours, 12 minutes ago
Description :The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8494 - Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title

CVE ID :CVE-2026-8494
Published : June 17, 2026, 6:49 a.m. | 3 hours, 12 minutes ago
Description :The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in the admin Permalink Manager page that will execute whenever an administrator accesses the Permalink Manager page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0092 - Package Manager Local Privilege Escalation via Device Lock Controller Bypass

CVE ID :CVE-2026-0092
Published : June 17, 2026, 6:57 a.m. | 3 hours, 4 minutes ago
Description :In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0064 - In multiple places, there is a possible persistent

CVE ID :CVE-2026-0064
Published : June 17, 2026, 6:59 a.m. | 3 hours, 2 minutes ago
Description :In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-28575 - Android PackageInstaller Denial of Service via Memory Exhaustion

CVE ID :CVE-2026-28575
Published : June 17, 2026, 7:02 a.m. | 2 hours, 59 minutes ago
Description :In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0071 - SettingsLib Local Privilege Escalation

CVE ID :CVE-2026-0071
Published : June 17, 2026, 7:09 a.m. | 2 hours, 52 minutes ago
Description :In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0081 - NFC Spoofing Leading to Local Privilege Escalation

CVE ID :CVE-2026-0081
Published : June 17, 2026, 7:12 a.m. | 2 hours, 49 minutes ago
Description :In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...