CVE tracker
367 subscribers
5.03K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-51287 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51287
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51288 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51288
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51289 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51289
Published : July 31, 2026, 3:16 p.m. | 39 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51299 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51299
Published : July 31, 2026, 3:17 p.m. | 38 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51301 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-51301
Published : July 31, 2026, 3:17 p.m. | 38 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67350 - Serendipity < 2.6.1 Open Redirect via exit.php

CVE ID :CVE-2026-67350
Published : July 31, 2026, 3:18 p.m. | 37 minutes ago
Description :Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16503 - VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities

CVE ID :CVE-2026-16503
Published : July 31, 2026, 3:18 p.m. | 37 minutes ago
Description :Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16504 - VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities

CVE ID :CVE-2026-16504
Published : July 31, 2026, 3:19 p.m. | 36 minutes ago
Description :Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-34490 - XAAP Android Data Stored in Unencrypted Database

CVE ID :CVE-2026-34490
Published : July 31, 2026, 6:17 p.m. | 1 hour, 40 minutes ago
Description :Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-34495 - FMS Employee vulnerable to XSS

CVE ID :CVE-2026-34495
Published : July 31, 2026, 6:17 p.m. | 1 hour, 40 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-34497 - FMS Employee Vulnerable to HTML Injection

CVE ID :CVE-2026-34497
Published : July 31, 2026, 6:17 p.m. | 1 hour, 40 minutes ago
Description :Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54725 - vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

CVE ID :CVE-2026-54725
Published : July 31, 2026, 6:17 p.m. | 1 hour, 40 minutes ago
Description :vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in version 1.23.1.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54729 - dssrf: any users using 1.1.1.1 DNS is impacted by SSRF

CVE ID :CVE-2026-54729
Published : July 31, 2026, 6:17 p.m. | 1 hour, 40 minutes ago
Description :DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery. This issue is fixed in version 1.0.5.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54737 - @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

CVE ID :CVE-2026-54737
Published : July 31, 2026, 6:17 p.m. | 1 hour, 40 minutes ago
Description :@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype. This issue is fixed in version 2.0.5.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55100 - hashi-vault-js has a path traversal and query parameter injection

CVE ID :CVE-2026-55100
Published : July 31, 2026, 6:17 p.m. | 1 hour, 40 minutes ago
Description :hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using encodeURIComponent() and URLSearchParams, allowing path traversal and query parameter injection. This issue is fixed in version 0.5.2.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55825 - Contao: Possible path traversal in job download URIs

CVE ID :CVE-2026-55825
Published : July 31, 2026, 7:07 p.m. | 50 minutes ago
Description :Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attachment download endpoint read a file from another job directory inside var/job-attachments. The controller authorizes only the jobUuid route parameter. The later attachment lookup joins that authorized job UUID with the attacker-controlled identifier, then passes the combined path to the virtual filesystem. VirtualFilesystem::resolve() canonicalizes the whole path and only rejects paths that escape the filesystem mount, so authorized-job/../victim-job/debug_log.csv becomes victim-job/debug_log.csv. This is a cross-job authorization bypass for known job attachment paths. It is not a practical brute-force against unknown jobs because job directories are UUID v4 values.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-62324 - Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS

CVE ID :CVE-2026-62324
Published : July 31, 2026, 7:08 p.m. | 49 minutes ago
Description :Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case variants, control-byte prefixes, and embedded tabs or newlines to bypass filtering and execute attacker-controlled script when a victim clicks a stored link rendered by an application. This issue is fixed in version 4.12.31.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65841 - Jodit has cross-site scripting (XSS) via

CVE ID :CVE-2026-65841
Published : July 31, 2026, 7:16 p.m. | 41 minutes ago
Description :Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18321 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec

CVE ID :CVE-2026-18321
Published : July 31, 2026, 7:17 p.m. | 40 minutes ago
Description :Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18481 - Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft

CVE ID :CVE-2026-18481
Published : July 31, 2026, 7:17 p.m. | 40 minutes ago
Description :Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25552 - Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header

CVE ID :CVE-2026-25552
Published : July 31, 2026, 7:17 p.m. | 40 minutes ago
Description :Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy_add_x_forwarded_for directive to present an arbitrary IP address, circumventing Ghost's rate-limiting mechanisms on self-hosted instances.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...