CVE tracker
369 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-18436 - MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Modification via REST API Endpoint

CVE ID :CVE-2026-18436
Published : July 31, 2026, 10:16 a.m. | 1 hour, 37 minutes ago
Description :The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign//restore-revision/). The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign's content_html with any prior revision. This makes it possible for unauthenticated attackers to modify campaign content by restoring an arbitrary revision.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18437 - MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates

CVE ID :CVE-2026-18437
Published : July 31, 2026, 10:16 a.m. | 1 hour, 37 minutes ago
Description :The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16843 - Hikvision Wireless Access Point Authenticated Command Injection

CVE ID :CVE-2026-16843
Published : July 31, 2026, 11:17 a.m. | 37 minutes ago
Description :Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17567 - Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter

CVE ID :CVE-2026-17567
Published : July 31, 2026, 11:17 a.m. | 37 minutes ago
Description :The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to brute-force valid transaction hashes and view sensitive payment receipt data including customer name, email address, billing address, order items, payment method, and payment status belonging to other users. Because submission ID, form ID, and transaction creation time are either observable or guessable by an attacker, the effective brute-force space is bounded to approximately 900 candidates per second per (submission, form) pair, making exploitation practical without any prior authentication or account.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44615 - Path traversal in NotebookRepo note and folder path composition

CVE ID :CVE-2026-44615
Published : July 31, 2026, 11:17 a.m. | 37 minutes ago
Description :Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths.                   Zeppelin composed these values into filesystem paths using the server's filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory. This could allow notebook files or directories to be moved,                   written, or deleted outside the notebook root. This issue affects Apache Zeppelin versions 0.9.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-62391 - Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases

CVE ID :CVE-2026-62391
Published : July 31, 2026, 11:17 a.m. | 37 minutes ago
Description :The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64607 - Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

CVE ID :CVE-2026-64607
Published : July 31, 2026, 11:17 a.m. | 37 minutes ago
Description :HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51256 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51256
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51257 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51257
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51258 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51258
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51262 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51262
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51264 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51264
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51265 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51265
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51276 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51276
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51277 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51277
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51278 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51278
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51279 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51279
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51280 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51280
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51281 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51281
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51282 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51282
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51283 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51283
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...