CVE tracker
335 subscribers
4.63K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-50698 - Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering

CVE ID :CVE-2026-50698
Published : June 24, 2026, 2:17 p.m. | 2 hours, 22 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50699 - Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule rendering

CVE ID :CVE-2026-50699
Published : June 24, 2026, 2:20 p.m. | 2 hours, 18 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50700 - Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image rendering

CVE ID :CVE-2026-50700
Published : June 24, 2026, 2:27 p.m. | 2 hours, 12 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-56111 - Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler

CVE ID :CVE-2026-56111
Published : June 24, 2026, 2:31 p.m. | 2 hours, 8 minutes ago
Description :Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handler that allows attackers to corrupt firmware memory by supplying out-of-range X and Y grid indices. Attackers can send a single crafted G-code command via USB serial, network interface, or malicious gcode file to write an attacker-controlled 32-bit float value past the z_values array bounds, corrupting adjacent firmware variables and causing denial of service or firmware state corruption.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50701 - Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb rendering

CVE ID :CVE-2026-50701
Published : June 24, 2026, 2:33 p.m. | 2 hours, 6 minutes ago
Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50703 - Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label rendering

CVE ID :CVE-2026-50703
Published : June 24, 2026, 2:42 p.m. | 1 hour, 57 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50704 - Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs rendering

CVE ID :CVE-2026-50704
Published : June 24, 2026, 2:46 p.m. | 1 hour, 52 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-56121 - Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization

CVE ID :CVE-2026-56121
Published : June 24, 2026, 2:49 p.m. | 1 hour, 50 minutes ago
Description :Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an OnDemandFeatureView spec is decoded from base64 and passed to dill.loads() before any authorization check is performed, enabling attackers to embed a malicious serialized Python object with an arbitrary __reduce__ method to execute OS commands as the feast service account.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50705 - Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering

CVE ID :CVE-2026-50705
Published : June 24, 2026, 2:51 p.m. | 1 hour, 48 minutes ago
Description :A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50708 - Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering

CVE ID :CVE-2026-50708
Published : June 24, 2026, 2:58 p.m. | 1 hour, 40 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55488 - motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

CVE ID :CVE-2026-55488
Published : June 24, 2026, 3:03 p.m. | 1 hour, 36 minutes ago
Description :motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path traversal vulnerability in multiple media file handlers that allows an attacker to read arbitrary files from the filesystem. The affected handlers accept a user-controlled filename parameter and construct filesystem paths using `os.path.join()`. When an absolute path is supplied, Python discards the configured media directory and returns the attacker-supplied path directly. The application then bypasses Tornado's built-in path validation by overriding the relevant safety checks. As a result, an attacker can access files outside of the configured camera media directory, subject to the permissions of the motionEye process. Version 0.44.0 fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50709 - Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering

CVE ID :CVE-2026-50709
Published : June 24, 2026, 3:04 p.m. | 1 hour, 34 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50710 - Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config

CVE ID :CVE-2026-50710
Published : June 24, 2026, 3:08 p.m. | 1 hour, 30 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-56118
Published : June 24, 2026, 3:11 p.m. | 1 hour, 27 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-56119
Published : June 24, 2026, 3:12 p.m. | 1 hour, 27 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50711 - Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering

CVE ID :CVE-2026-50711
Published : June 24, 2026, 3:18 p.m. | 1 hour, 20 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50712 - Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering

CVE ID :CVE-2026-50712
Published : June 24, 2026, 3:26 p.m. | 1 hour, 12 minutes ago
Description :A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13164 - Unauthenticated self-registration in MailerUp allows access to stored email data

CVE ID :CVE-2026-13164
Published : June 24, 2026, 3:37 p.m. | 1 hour, 2 minutes ago
Description :Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp <1 .0.1
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54905 - concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

CVE ID :CVE-2026-54905
Published : June 24, 2026, 3:42 p.m. | 56 minutes ago
Description :concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lock 32,768 times. The lock stores a thread's local read and write hold counts in one integer. The low 15 bits are used for the read hold count, and bit 15 is used as WRITE_LOCK_HELD. After 32,768 reentrant read acquisitions, the local read count crosses into the write-lock bit. try_write_lock then treats the thread as already holding a write lock and returns true without setting the global RUNNING_WRITER bit. This breaks the core mutual-exclusion guarantee: the caller is told it has a write lock, but other threads can still hold or acquire read locks at the same time. This vulnerability is fixed in 1.3.7.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54904 - concurrent-ruby: `AtomicReference#update` livelocks when the stored value is `Float::NAN`

CVE ID :CVE-2026-54904
Published : June 24, 2026, 3:44 p.m. | 55 minutes ago
Description :concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when the current value is Float::NAN. The issue is caused by the interaction between AtomicReference#update, which retries until compare_and_set(old_value, new_value) succeeds; Numeric compare_and_set, which checks old == old_value before attempting the underlying atomic swap.; and Ruby NaN semantics, where Float::NAN == Float::NAN is always false. As a result, once an AtomicReference contains Float::NAN, calling #update repeatedly evaluates the caller's block and never returns. In services that store externally derived numeric values in an AtomicReference, this can cause CPU exhaustion or permanent request/job hangs. This vulnerability is fixed in 1.3.7.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54906 - concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption

CVE ID :CVE-2026-54906
Published : June 24, 2026, 3:46 p.m. | 53 minutes ago
Description :concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a fresh lock changes the counter from 0 to -1, after which normal read acquisition raises Concurrent::ResourceLimitError. This is a synchronization correctness issue in the public Concurrent::ReadWriteLock API. This vulnerability is fixed in 1.3.7.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...