CVE tracker
370 subscribers
5.05K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-14539 - Denial of Service via Unrestricted Payload Buffering in MCP Toolbox

CVE ID :CVE-2026-14539
Published : July 31, 2026, 2:16 a.m. | 1 hour, 33 minutes ago
Description :An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted buffer loop (io.ReadAll) without applying defensive constraints such as http.MaxBytesReader or pre-read Content-Length enforcement. By submitting a single, massive HTTP request body, an attacker can linearly consume available host memory until the runtime process is terminated by an Out-Of-Memory (OOM) error.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14540 - Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox

CVE ID :CVE-2026-14540
Published : July 31, 2026, 2:16 a.m. | 1 hour, 33 minutes ago
Description :A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection boundaries. Specifically, the client is initialized without a restrictive CheckRedirect policy hook and lacks target IP validation. An attacker or a malicious data-driven prompt can supply a crafted path parameter that triggers an open redirect or a direct destination swap on the target backend, coercing the mcp-toolbox into blindly following the redirection and making unauthorized requests to internal or arbitrary external endpoints.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14541 - Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider

CVE ID :CVE-2026-14541
Published : July 31, 2026, 3:16 a.m. | 33 minutes ago
Description :An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18157 - Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection

CVE ID :CVE-2026-18157
Published : July 31, 2026, 3:16 a.m. | 33 minutes ago
Description :A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-6889 - Denial of service vulnerability

CVE ID :CVE-2026-6889
Published : July 31, 2026, 3:16 a.m. | 33 minutes ago
Description :A denial of service vulnerability in the Advantech ECU-1251D allows a network-adjacent attacker to send a DNP3 signal to the Digital Output address of the device, causing the DNP3Daemon to invoke a non-existent system file and enter an indefinite restart loop. While the device remains partially accessible via its web panel or direct signals, an operator using SCADA TelWin is unable to reconnect until the device is manually restarted.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-6890 - Use of default credentials vulnerability

CVE ID :CVE-2026-6890
Published : July 31, 2026, 3:16 a.m. | 33 minutes ago
Description :A use of default credentials vulnerability in the Advantech ECU-1251D allows a remote attacker to gain unauthorised access to the device via SSH using the default root account with no password, as documented in the device manual. No prompt or guidance to change these credentials is provided during device configuration, increasing the risk of exploitation.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14554 - Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters

CVE ID :CVE-2026-14554
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14830 - FlxWoo < 3.1.1 - Unauthenticated Payment Bypass

CVE ID :CVE-2026-14830
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14833 - Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute

CVE ID :CVE-2026-14833
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption in the browser, allowing users with author-level access and above (who lack the unfiltered_html capability) to store JavaScript that runs when a visitor or administrator opens the lightbox.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14834 - Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX

CVE ID :CVE-2026-14834
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14843 - Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR

CVE ID :CVE-2026-14843
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14845 - NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget

CVE ID :CVE-2026-14845
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in one of its widgets, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against users viewing the affected widget.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14847 - Paid Member Subscriptions < 3.0.7 - Subscriber+ Payment Data Disclosure via IDOR

CVE ID :CVE-2026-14847
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14849 - Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exposure via Residual Export Files

CVE ID :CVE-2026-14849
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14862 - Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via Missing Authorization

CVE ID :CVE-2026-14862
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14919 - ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute

CVE ID :CVE-2026-14919
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14921 - Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS via ult_buttons Shortcode

CVE ID :CVE-2026-14921
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(),
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14922 - WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment

CVE ID :CVE-2026-14922
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by `wp_strip_all_tags()` (`wppa-functions.php:2623-2624`). Because `wp_strip_all_tags()` only removes *real* tags, an attacker who submits a **double HTML-entity-encoded** payload (e.g. `&lt;img src=... onload=...&gt;`) passes the write filters as harmless entity text and is stored one decode-level down (`<img ... onload=...>`).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14927 - FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes

CVE ID :CVE-2026-14927
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14928 - JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject

CVE ID :CVE-2026-14928
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14929 - JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR

CVE ID :CVE-2026-14929
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...