CVE tracker
369 subscribers
5.03K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-16969 - DFIR-IRIS Stored XSS in Assets

CVE ID :CVE-2026-16969
Published : July 30, 2026, 10:16 a.m. | 1 hour, 32 minutes ago
Description :The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16970 - DFIR-IRIS Insufficient Logout Implementation

CVE ID :CVE-2026-16970
Published : July 30, 2026, 10:16 a.m. | 1 hour, 32 minutes ago
Description :The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16971 - DFIR-IRIS Missing Brute Force Protection in OTP Validation

CVE ID :CVE-2026-16971
Published : July 30, 2026, 10:16 a.m. | 1 hour, 32 minutes ago
Description :The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18360 - DFIR-IRIS Stored XSS in Custom Attributes

CVE ID :CVE-2026-18360
Published : July 30, 2026, 10:16 a.m. | 1 hour, 32 minutes ago
Description :The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18361 - DFIR-IRIS Stored XSS in Datastore Upload

CVE ID :CVE-2026-18361
Published : July 30, 2026, 10:16 a.m. | 1 hour, 32 minutes ago
Description :The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18362 - DFIR-IRIS Missing Brute Force Protection in User Authentication

CVE ID :CVE-2026-18362
Published : July 30, 2026, 10:16 a.m. | 1 hour, 32 minutes ago
Description :The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15397 - Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation via wps_sfw_install_plugin_configuration AJAX Action

CVE ID :CVE-2026-15397
Published : July 30, 2026, 11:03 a.m. | 46 minutes ago
Description :The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install and activate arbitrary WordPress.org plugins.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18363 - Weak password recovery mechanism in osTicket by Enhancesoft LLC

CVE ID :CVE-2026-18363
Published : July 30, 2026, 11:16 a.m. | 33 minutes ago
Description :A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tokens with an existing timestamp to bypass the intended expiry validation. Therefore, an attacker able to obtain a valid password reset token could reuse it to perform an unauthorised password reset and compromise the affected account.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18369 - Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirects

CVE ID :CVE-2026-18369
Published : July 30, 2026, 11:16 a.m. | 33 minutes ago
Description :A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22620 - Eaton Tripp Lite PADM Authentication Bypass Vulnerability

CVE ID :CVE-2026-22620
Published : July 30, 2026, 11:16 a.m. | 33 minutes ago
Description :Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22621 - Eaton Tripp Lite Series PADM OS Command Injection

CVE ID :CVE-2026-22621
Published : July 30, 2026, 11:16 a.m. | 33 minutes ago
Description :Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22622 - Eaton Tripp Lite PADM Improper Input Validation Privilege Escalation

CVE ID :CVE-2026-22622
Published : July 30, 2026, 11:16 a.m. | 33 minutes ago
Description :Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17543 - SQL injection in ext-pgsql via E'...' backslash breakout

CVE ID :CVE-2026-17543
Published : July 30, 2026, 11:22 a.m. | 27 minutes ago
Description :Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17544 - Out-of-bounds write in bccomp() via crafted operand and scale

CVE ID :CVE-2026-17544
Published : July 30, 2026, 11:22 a.m. | 27 minutes ago
Description :Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-7260 - Stack overflow in phar with circular symlinks

CVE ID :CVE-2026-7260
Published : July 30, 2026, 11:22 a.m. | 26 minutes ago
Description :Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11897 - IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/2

CVE ID :CVE-2026-11897
Published : July 30, 2026, 3:16 p.m. | 33 minutes ago
Description :IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11980 - Code execution in IBM Desktop App

CVE ID :CVE-2026-11980
Published : July 30, 2026, 3:16 p.m. | 33 minutes ago
Description :IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12947 - IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Connector nodes

CVE ID :CVE-2026-12947
Published : July 30, 2026, 3:16 p.m. | 33 minutes ago
Description :IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14519 - IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings

CVE ID :CVE-2026-14519
Published : July 30, 2026, 3:16 p.m. | 33 minutes ago
Description :IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14522 - IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings

CVE ID :CVE-2026-14522
Published : July 30, 2026, 3:16 p.m. | 33 minutes ago
Description :IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14980 - IBM WebSphere Application Server Liberty is affected by a cross-site request forgery

CVE ID :CVE-2026-14980
Published : July 30, 2026, 3:16 p.m. | 33 minutes ago
Description :IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...