CVE tracker
360 subscribers
4.87K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-48588 - Potential exposure of private data via cached Set-Cookie response

CVE ID :CVE-2026-48588
Published : July 7, 2026, 3:16 p.m. | 49 minutes ago
Description :An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-53877 - Heap buffer over-read in GDALRaster

CVE ID :CVE-2026-53877
Published : July 7, 2026, 3:16 p.m. | 49 minutes ago
Description :An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-53878 - Header injection possibility since DomainNameValidator accepted newlines in input

CVE ID :CVE-2026-53878
Published : July 7, 2026, 3:16 p.m. | 49 minutes ago
Description :An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59709 - Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission Check

CVE ID :CVE-2026-59709
Published : July 7, 2026, 3:16 p.m. | 49 minutes ago
Description :Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-56812 - Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff

CVE ID :CVE-2026-56812
Published : July 7, 2026, 3:22 p.m. | 43 minutes ago
Description :Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every viewer of a presence channel topic. This vulnerability is associated with program files assets/js/phoenix/presence.js and program routines Presence.syncState and Presence.syncDiff. The Phoenix JavaScript presence client checks whether a presence already exists with a bare truthiness test (state[key]) instead of an own-property check. Presence keys are attacker-controlled, because applications track presences under a username or id supplied by the client. A user who joins a channel choosing a key that is an Object.prototype member name (__proto__, constructor, toString, hasOwnProperty, and similar) makes that lookup return JavaScript's built-in Object.prototype instead of undefined. Because the prototype is truthy, the code treats it as an existing presence and reads .metas.map(...) off it, which throws an uncaught TypeError. The exception propagates out of the presence message handler, so the local state is never updated and onSync() never fires. Because the malicious key is tracked on the server, it is re-pushed on every presence update and keeps re-throwing, so presence sync stays broken for every viewer of that channel topic until the attacker leaves. Both syncState and syncDiff use the same unsafe existence-check pattern. The impact is limited to the affected topic and is a read-time confusion of the prototype object, not a mutation of Object.prototype (it is not prototype pollution). This issue affects phoenix: from 1.2.0 before 1.5.15, from 1.6.0 before 1.6.17, from 1.7.0 before 1.7.24, and from 1.8.0 before 1.8.9.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14935 - Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check

CVE ID :CVE-2026-14935
Published : July 7, 2026, 3:37 p.m. | 28 minutes ago
Description :A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14969 - 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption

CVE ID :CVE-2026-14969
Published : July 7, 2026, 3:48 p.m. | 18 minutes ago
Description :A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12799 - Jastow: jastow cross-site scripting attack due to unsanitized uri

CVE ID :CVE-2025-12799
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13019 - Missing Authentication

CVE ID :CVE-2026-13019
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13020 - Weak Password Recovery Mechanism in Portal for ArcGIS

CVE ID :CVE-2026-13020
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14904 - RES Auth.GetUserPrivateKey Arbitrary File Read

CVE ID :CVE-2026-14904
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host. Because the cluster-manager process runs as root, any file readable by root is exposed, including other users' SSH private keys and application configuration secrets. It's recommended to upgrade to RES version 2026.06.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-23697 - Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module

CVE ID :CVE-2026-23697
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, allowing unauthenticated HTTP requests to directly execute the uploaded PHP payload.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-23698 - Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload

CVE ID :CVE-2026-23698
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the application routing layer is involved, resulting in a persistent web shell independent of the originating session.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57851 - MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers

CVE ID :CVE-2026-57851
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44877 - Unauthenticated Remote Disclosure of Cryptographic Secrets

CVE ID :CVE-2026-44877
Published : July 7, 2026, 7:03 p.m. | 1 hour, 3 minutes ago
Description :An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48947 - Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints

CVE ID :CVE-2026-48947
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows privileged users to overwrite media files without editing permissions.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48948 - Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download

CVE ID :CVE-2026-48948
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48949 - Joomla! Core - [20260703] - XSS in MFA method management

CVE ID :CVE-2026-48949
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of validation leads to an XSS vulnerability in the MFA management views.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48950 - Joomla! Core - [20260704] - XSS in com_templates

CVE ID :CVE-2026-48950
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48951 - Joomla! Core - [20260705] - XSS in various modalreturn layouts

CVE ID :CVE-2026-48951
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48952 - Joomla! Core - [20260706] - XSS in com_installer

CVE ID :CVE-2026-48952
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...