CVE tracker
363 subscribers
4.98K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-16336 - trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect

CVE ID :CVE-2026-16336
Published : July 21, 2026, 2:30 a.m. | 1 hour, 30 minutes ago
Description :A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59776 - FeliCa IC Chips Missing Cryptographic Step Vulnerability

CVE ID :CVE-2026-59776
Published : July 21, 2026, 3:06 a.m. | 53 minutes ago
Description :Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16332 - D-Link DNS-320 multi_uploadify.php unrestricted upload

CVE ID :CVE-2026-16332
Published : July 21, 2026, 3:16 a.m. | 43 minutes ago
Description :A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16334 - itsourcecode Hospital Management System prescriptionorder.php sql injection

CVE ID :CVE-2026-16334
Published : July 21, 2026, 3:16 a.m. | 43 minutes ago
Description :A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63729 - TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File

CVE ID :CVE-2026-63729
Published : July 21, 2026, 3:16 a.m. | 43 minutes ago
Description :The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-6952 - Zyxel AX7501-B1 Command Injection Vulnerability

CVE ID :CVE-2026-6952
Published : July 21, 2026, 3:16 a.m. | 43 minutes ago
Description :A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-37508 - HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability

CVE ID :CVE-2023-37508
Published : July 21, 2026, 5:16 a.m. | 2 hours, 43 minutes ago
Description :HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15156 - Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings

CVE ID :CVE-2026-15156
Published : July 21, 2026, 5:16 a.m. | 2 hours, 43 minutes ago
Description :The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-37507 - An information disclosure vulnerability affects HCL DevOps Plan

CVE ID :CVE-2023-37507
Published : July 21, 2026, 6:16 a.m. | 1 hour, 43 minutes ago
Description :HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13439 - Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint

CVE ID :CVE-2026-13439
Published : July 21, 2026, 6:16 a.m. | 1 hour, 43 minutes ago
Description :The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/refresh) that issues valid WordPress REST nonces to unauthenticated visitors. This makes it possible for unauthenticated attackers to reset the password of any WordPress user — including administrators — by scraping the public sid from a published login form page, submitting a recovery request for any known user email via Emsfb/v1/forms/message/add, and then calling Emsfb/v1/forms/recovery/efb_set_password with the known sid to set an arbitrary new password and gain full administrator access.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15782 - WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content

CVE ID :CVE-2026-15782
Published : July 21, 2026, 6:16 a.m. | 1 hour, 43 minutes ago
Description :The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15811 - Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes

CVE ID :CVE-2026-15811
Published : July 21, 2026, 6:16 a.m. | 1 hour, 43 minutes ago
Description :A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15812 - Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links

CVE ID :CVE-2026-15812
Published : July 21, 2026, 6:16 a.m. | 1 hour, 43 minutes ago
Description :A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15927 - Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation

CVE ID :CVE-2026-15927
Published : July 21, 2026, 6:16 a.m. | 1 hour, 43 minutes ago
Description :A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16266 - mongo-object Prototype Pollution Vulnerability

CVE ID :CVE-2026-16266
Published : July 21, 2026, 6:16 a.m. | 1 hour, 43 minutes ago
Description :Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-3182 - Sensitive Data Exposure

CVE ID :CVE-2026-3182
Published : July 21, 2026, 6:16 a.m. | 1 hour, 43 minutes ago
Description :Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-3183 - Multi Factor Auth Bypass

CVE ID :CVE-2026-3183
Published : July 21, 2026, 6:58 a.m. | 1 hour, 1 minute ago
Description :Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11767 - CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form

CVE ID :CVE-2026-11767
Published : July 21, 2026, 7:16 a.m. | 43 minutes ago
Description :The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form submissions.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13693 - Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal

CVE ID :CVE-2026-13693
Published : July 21, 2026, 7:16 a.m. | 43 minutes ago
Description :The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13694 - Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass

CVE ID :CVE-2026-13694
Published : July 21, 2026, 7:16 a.m. | 43 minutes ago
Description :The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14183 - Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR

CVE ID :CVE-2026-14183
Published : July 21, 2026, 7:16 a.m. | 43 minutes ago
Description :The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...