CVE tracker
370 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-16565 - Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API

CVE ID :CVE-2026-16565
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16572 - LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie

CVE ID :CVE-2026-16572
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18587 - Wavlink WL-NU516U1 Config Import os command injection

CVE ID :CVE-2026-18587
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18588 - Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow

CVE ID :CVE-2026-18588
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18589 - Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow

CVE ID :CVE-2026-18589
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-4793 - Synology Assistant Incorrect Default Permissions Vulnerability

CVE ID :CVE-2026-4793
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9593 - iDTM FDI Unauthorized Debug Interface Enablement

CVE ID :CVE-2026-9593
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21548 - NR Modem Improper Input Validation Vulnerability

CVE ID :CVE-2026-21548
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21549 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21549
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21550 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21550
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21551 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21551
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21552 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21552
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21553 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21553
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21554 - Modem Improper Input Validation Vulnerability

CVE ID :CVE-2026-21554
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21555 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21555
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18592 - osCommerce Email Template Configuration EmailController.php EmailController sql injection

CVE ID :CVE-2026-18592
Published : Aug. 3, 2026, 7:30 a.m. | 30 minutes ago
Description :A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18593 - vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox

CVE ID :CVE-2026-18593
Published : Aug. 3, 2026, 7:45 a.m. | 15 minutes ago
Description :A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18591 - Meesho Online Shopping App com.meesho.supply cleartext storage

CVE ID :CVE-2026-18591
Published : Aug. 3, 2026, 8:17 a.m. | 3 hours, 43 minutes ago
Description :A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-28147 - WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.15 - Broken Access Control vulnerability

CVE ID :CVE-2026-28147
Published : Aug. 3, 2026, 8:17 a.m. | 3 hours, 43 minutes ago
Description :Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8793 - PaperCut NG/MF: Insufficient brute-force protection

CVE ID :CVE-2026-8793
Published : Aug. 3, 2026, 8:17 a.m. | 3 hours, 43 minutes ago
Description :PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8794 - PaperCut NG/MF: User enumeration via timing attack

CVE ID :CVE-2026-8794
Published : Aug. 3, 2026, 8:17 a.m. | 3 hours, 43 minutes ago
Description :PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...