CVE tracker
337 subscribers
4.63K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-13548 - itsourcecode Hospital Management System doctortimings.php sql injection

CVE ID :CVE-2026-13548
Published : June 29, 2026, 7:45 a.m. | 1 hour, 30 minutes ago
Description :A vulnerability was identified in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /doctortimings.php. The manipulation of the argument editid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57965 - Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow

CVE ID :CVE-2026-57965
Published : June 29, 2026, 7:53 a.m. | 1 hour, 21 minutes ago
Description :A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual machine. This issue requires the SPICE host to be untrusted or compromised for exploitation.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57966 - Spice-vdagent: path traversal in file transfer via unsanitized filename

CVE ID :CVE-2026-57966
Published : June 29, 2026, 7:53 a.m. | 1 hour, 21 minutes ago
Description :A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. This occurs because the filename provided by the SPICE host during file transfers is not properly sanitized before being used. An attacker could exploit this to write to sensitive locations with the privileges of the spice-vdagent process, typically the logged-in user. This issue requires the SPICE host to be untrusted or compromised for exploitation.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13549 - CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization

CVE ID :CVE-2026-13549
Published : June 29, 2026, 8 a.m. | 1 hour, 15 minutes ago
Description :A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22078 - O+ Connect's lack of authentication for IPC channels led to a local privilege escalation vulnerability.

CVE ID :CVE-2026-22078
Published : June 29, 2026, 8:05 a.m. | 1 hour, 9 minutes ago
Description :Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13595 - Util-linux: util-linux: heap use-after-free in libblkid nested partition probing

CVE ID :CVE-2026-13595
Published : June 29, 2026, 8:06 a.m. | 1 hour, 9 minutes ago
Description :A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9267 - tinydtls Out-of-Bounds Read in Certificate Handling

CVE ID :CVE-2026-9267
Published : June 29, 2026, 8:10 a.m. | 1 hour, 4 minutes ago
Description :Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries by crafting a Certificate handshake message with a specific fragment_length value. Attackers can exploit missing buffer length validation before uint24 reads, memcmp, and memcpy operations during DTLS epoch 0 on both client and server paths to cause denial of service on memory-constrained devices.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13550 - itsourcecode Baptism Information Management System delbaptism.php sql injection

CVE ID :CVE-2026-13550
Published : June 29, 2026, 8:15 a.m. | 1 hour ago
Description :A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57676 - WordPress Simple User Avatar plugin <= 4.9 - Insecure Direct Object References (IDOR) vulnerability

CVE ID :CVE-2026-57676
Published : June 29, 2026, 8:19 a.m. | 55 minutes ago
Description :Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13551 - itsourcecode Baptism Information Management System editBaptism.php sql injection

CVE ID :CVE-2026-13551
Published : June 29, 2026, 8:30 a.m. | 45 minutes ago
Description :A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13552 - itsourcecode Online Hotel Management System controller.php edit sql injection

CVE ID :CVE-2026-13552
Published : June 29, 2026, 8:45 a.m. | 4 hours, 30 minutes ago
Description :A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Performing a manipulation of the argument amen_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13553 - itsourcecode Online Hotel Management System controller.php add unrestricted upload

CVE ID :CVE-2026-13553
Published : June 29, 2026, 9 a.m. | 4 hours, 15 minutes ago
Description :A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13554 - itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting

CVE ID :CVE-2026-13554
Published : June 29, 2026, 9:15 a.m. | 4 hours ago
Description :A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13601 - Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications

CVE ID :CVE-2026-13601
Published : June 29, 2026, 9:20 a.m. | 3 hours, 55 minutes ago
Description :A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13555 - itsourcecode Online Hotel Management System controller.php add sql injection

CVE ID :CVE-2026-13555
Published : June 29, 2026, 9:30 a.m. | 3 hours, 45 minutes ago
Description :A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13556 - itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting

CVE ID :CVE-2026-13556
Published : June 29, 2026, 9:45 a.m. | 3 hours, 30 minutes ago
Description :A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57346 - WordPress Embed Privacy plugin <= 1.12.3 - Arbitrary File Deletion vulnerability

CVE ID :CVE-2026-57346
Published : June 29, 2026, 9:50 a.m. | 3 hours, 25 minutes ago
Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13557 - itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting

CVE ID :CVE-2026-13557
Published : June 29, 2026, 10 a.m. | 3 hours, 15 minutes ago
Description :A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25707 - Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp

CVE ID :CVE-2026-25707
Published : June 29, 2026, 10:04 a.m. | 3 hours, 10 minutes ago
Description :A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13558 - CodeAstro Complaint Management System Report addreport cross site scripting

CVE ID :CVE-2026-13558
Published : June 29, 2026, 10:15 a.m. | 3 hours ago
Description :A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-41991 - Predictable Temporary File in GNU gzip

CVE ID :CVE-2026-41991
Published : June 29, 2026, 10:15 a.m. | 3 hours ago
Description :GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269
Severity: 2.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...