CVE tracker
370 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-21551 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21551
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21552 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21552
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21553 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21553
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21554 - Modem Improper Input Validation Vulnerability

CVE ID :CVE-2026-21554
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21555 - Modem Improper Input Validation Denial of Service

CVE ID :CVE-2026-21555
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18592 - osCommerce Email Template Configuration EmailController.php EmailController sql injection

CVE ID :CVE-2026-18592
Published : Aug. 3, 2026, 7:30 a.m. | 30 minutes ago
Description :A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18593 - vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox

CVE ID :CVE-2026-18593
Published : Aug. 3, 2026, 7:45 a.m. | 15 minutes ago
Description :A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18591 - Meesho Online Shopping App com.meesho.supply cleartext storage

CVE ID :CVE-2026-18591
Published : Aug. 3, 2026, 8:17 a.m. | 3 hours, 43 minutes ago
Description :A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-28147 - WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.15 - Broken Access Control vulnerability

CVE ID :CVE-2026-28147
Published : Aug. 3, 2026, 8:17 a.m. | 3 hours, 43 minutes ago
Description :Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8793 - PaperCut NG/MF: Insufficient brute-force protection

CVE ID :CVE-2026-8793
Published : Aug. 3, 2026, 8:17 a.m. | 3 hours, 43 minutes ago
Description :PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8794 - PaperCut NG/MF: User enumeration via timing attack

CVE ID :CVE-2026-8794
Published : Aug. 3, 2026, 8:17 a.m. | 3 hours, 43 minutes ago
Description :PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-60011 - Sharp and Toshiba Tec MFPs Unauthorized Image Data Access Vulnerability

CVE ID :CVE-2026-60011
Published : Aug. 3, 2026, 9:17 a.m. | 2 hours, 43 minutes ago
Description :Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-62416 - Sharp Corporation Network Scanner Tool Unauthenticated Arbitrary File Upload and Denial of Service Vulnerability

CVE ID :CVE-2026-62416
Published : Aug. 3, 2026, 9:17 a.m. | 2 hours, 43 minutes ago
Description :Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63545 - Sharp and Toshiba Tec MFPs Sensitive Data Exposure via Insecure Cache Persistence

CVE ID :CVE-2026-63545
Published : Aug. 3, 2026, 9:17 a.m. | 2 hours, 43 minutes ago
Description :Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.
Severity: 2.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63563 - Sharp and Toshiba Tec MFPs Unauthorized Access Vulnerability

CVE ID :CVE-2026-63563
Published : Aug. 3, 2026, 9:17 a.m. | 2 hours, 43 minutes ago
Description :Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication. Products intended for the Japanese market are not affected.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-69075 - Stored Cross-Site Scripting via Vue Template Injection in FlowIntel

CVE ID :CVE-2026-69075
Published : Aug. 3, 2026, 9:17 a.m. | 2 hours, 43 minutes ago
Description :FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted values—including case titles, ticket identifiers, recurring-case information, user profile attributes, organisation names, and role names—were rendered inside DOM elements subsequently compiled by Vue. Although normal HTML escaping could neutralize direct HTML markup, it did not prevent an attacker from injecting Vue interpolation expressions using the configured [[ ... ]] delimiters. An authenticated attacker able to modify one of the affected fields could store a malicious Vue expression. When another user viewed an affected case, report, profile, recurring-case page, or navigation component, Vue could evaluate the injected expression in the context of the FlowIntel application. Successful exploitation could allow arbitrary JavaScript execution in the victim’s browser under the FlowIntel origin. This could expose information available to the victim, perform actions using the victim’s authenticated session, or modify application data within the victim’s privileges. The patch introduces a dedicated vue_escape filter that escapes HTML-sensitive characters and breaks Vue interpolation delimiters before the values are rendered. The filter is applied to the affected case, account, organisation, role, configuration, and navigation fields.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0392 - eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update

CVE ID :CVE-2026-0392
Published : Aug. 3, 2026, 10:16 a.m. | 1 hour, 44 minutes ago
Description :eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch the application fetches an update descriptor (XML) over TLS but accepts any TLS certificate (a permissive TrustManager and a HostnameVerifier that always returns true), does not verify any digital signature on the update descriptor, and does not verify the Authenticode signature or a checksum of the downloaded installer before running it. A man-in-the-middle attacker able to redirect www.eparaksts.lv can serve a crafted update descriptor pointing to an attacker-controlled executable, which the client downloads and executes, resulting in arbitrary code execution on the victim host.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-33591 - Authentication bypass on WaptServer

CVE ID :CVE-2026-33591
Published : Aug. 3, 2026, 10:16 a.m. | 1 hour, 44 minutes ago
Description :A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68742 - Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr

CVE ID :CVE-2026-68742
Published : Aug. 3, 2026, 10:16 a.m. | 1 hour, 44 minutes ago
Description :A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-69078 - Server-Side Request Forgery and Local File Disclosure in CTI-Transmute Evaluation PDF Rendering

CVE ID :CVE-2026-69078
Published : Aug. 3, 2026, 10:16 a.m. | 1 hour, 44 minutes ago
Description :CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions, and comments, is converted from Markdown to HTML and rendered as a PDF using WeasyPrint. Before the patch, the renderer used WeasyPrint’s default URL-fetching behavior without restricting the protocols or destinations that could be referenced by the generated HTML. An attacker able to supply content included in an evaluation report could inject crafted resource references using schemes such as http://, https://, or file://. When the report was rendered, CTI-Transmute could fetch these resources using the application server’s network connectivity and filesystem privileges. Successful exploitation could allow an attacker to: * access services available only from the CTI-Transmute server or its internal network; * probe internal hosts and service endpoints; * retrieve local files readable by the application process; and * expose fetched content through the generated PDF, depending on the referenced resource type and rendering context. The vulnerability is corrected by providing WeasyPrint with a restrictive URL fetcher that permits only self-contained data: URIs. The externally hosted Google Fonts stylesheet was also removed so that PDF generation performs no intentional network or filesystem fetches.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-69079 - Unauthenticated Denial of Service via Unbounded Activity-Timeline Range in CTI-Transmute

CVE ID :CVE-2026-69079
Published : Aug. 3, 2026, 10:16 a.m. | 1 hour, 44 minutes ago
Description :CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range. A remote, unauthenticated attacker could submit an excessively large value for this parameter, causing the application to retrieve and process activity data over an arbitrarily large period. This could consume excessive database, CPU, or memory resources, delay the processing of concurrent requests, or trigger an internal server error. Repeated requests could further degrade the availability of the CTI-Transmute website. The vulnerability is corrected by clamping the requested timeline range to a minimum of one day and a maximum of 1,095 days.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...