CVE tracker
369 subscribers
5.06K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-38446 - osTicket Stored Cross-Site Scripting

CVE ID :CVE-2026-38446
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by submitting a crafted ticket reply or email with a malicious subject line.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-38447 - osTicket API Key Cryptographic Weakness

CVE ID :CVE-2026-38447
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59912 - Dell Display and Peripheral Manager Improper Access Control Vulnerability

CVE ID :CVE-2026-59912
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59913 - Dell Display and Peripheral Manager Privilege Escalation Vulnerability

CVE ID :CVE-2026-59913
Published : Aug. 3, 2026, 7:16 p.m. | 43 minutes ago
Description :Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18632 - langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine

CVE ID :CVE-2026-18632
Published : Aug. 3, 2026, 7:30 p.m. | 30 minutes ago
Description :A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of special elements used in a template engine. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66312 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE ID :CVE-2026-66312
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66313 - Microsoft Edge (Chromium-based) Tampering Vulnerability

CVE ID :CVE-2026-66313
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66314 - Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVE ID :CVE-2026-66314
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66315 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE ID :CVE-2026-66315
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66316 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE ID :CVE-2026-66316
Published : Aug. 3, 2026, 10:53 p.m. | 1 hour, 7 minutes ago
Description :None
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65802 - Microsoft Edge for Android Information Disclosure Vulnerability

CVE ID :CVE-2026-65802
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65804 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE ID :CVE-2026-65804
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66311 - Microsoft Edge (Chromium-based) Tampering Vulnerability

CVE ID :CVE-2026-66311
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66317 - Microsoft Edge (Chromium-based) Tampering Vulnerability

CVE ID :CVE-2026-66317
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66322 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE ID :CVE-2026-66322
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66325 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE ID :CVE-2026-66325
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66326 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE ID :CVE-2026-66326
Published : Aug. 3, 2026, 10:58 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-62870 - Microsoft Excel Remote Code Execution Vulnerability

CVE ID :CVE-2026-62870
Published : Aug. 3, 2026, 10:58 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18685 - GL.iNet GL-MT3000 modem.so glc set_upgrade command injection

CVE ID :CVE-2026-18685
Published : Aug. 3, 2026, 11:15 p.m. | 45 minutes ago
Description :A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18667 - Sensor Proxy Version 1.4.2 Fixes One Vulnerability

CVE ID :CVE-2026-18667
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18684 - GL.iNet GL-MT3000 modem.so glc remove_profile command injection

CVE ID :CVE-2026-18684
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...