CVE tracker
369 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-20496 - Geniezone Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-20496
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20497 - Geniezone Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20497
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20498 - Geniezone Privilege Escalation Vulnerability

CVE ID :CVE-2026-20498
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58059 - Quadratic-time escaping when stringifying X.500 distinguished names

CVE ID :CVE-2026-58059
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58060 - HSS public-key level count unbounded, enabling huge allocation on verify

CVE ID :CVE-2026-58060
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check

CVE ID :CVE-2026-58061
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate

CVE ID :CVE-2026-58062
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58063 - BCFKS keystore load honours unbounded KDF cost from untrusted file

CVE ID :CVE-2026-58063
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16289 - ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group

CVE ID :CVE-2026-16289
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16297 - Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import

CVE ID :CVE-2026-16297
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16300 - Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset

CVE ID :CVE-2026-16300
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16532 - Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form

CVE ID :CVE-2026-16532
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16534 - Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import

CVE ID :CVE-2026-16534
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16539 - SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication

CVE ID :CVE-2026-16539
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16563 - Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint

CVE ID :CVE-2026-16563
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16564 - Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint

CVE ID :CVE-2026-16564
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16565 - Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API

CVE ID :CVE-2026-16565
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16572 - LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie

CVE ID :CVE-2026-16572
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18587 - Wavlink WL-NU516U1 Config Import os command injection

CVE ID :CVE-2026-18587
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18588 - Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow

CVE ID :CVE-2026-18588
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18589 - Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow

CVE ID :CVE-2026-18589
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...