CVE tracker
368 subscribers
5.07K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-66322 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE ID :CVE-2026-66322
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66325 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE ID :CVE-2026-66325
Published : Aug. 3, 2026, 10:57 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66326 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE ID :CVE-2026-66326
Published : Aug. 3, 2026, 10:58 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-62870 - Microsoft Excel Remote Code Execution Vulnerability

CVE ID :CVE-2026-62870
Published : Aug. 3, 2026, 10:58 p.m. | 1 hour, 2 minutes ago
Description :None
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18685 - GL.iNet GL-MT3000 modem.so glc set_upgrade command injection

CVE ID :CVE-2026-18685
Published : Aug. 3, 2026, 11:15 p.m. | 45 minutes ago
Description :A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18667 - Sensor Proxy Version 1.4.2 Fixes One Vulnerability

CVE ID :CVE-2026-18667
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18684 - GL.iNet GL-MT3000 modem.so glc remove_profile command injection

CVE ID :CVE-2026-18684
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48317 - Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)

CVE ID :CVE-2026-48317
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48323 - Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

CVE ID :CVE-2026-48323
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48326 - Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

CVE ID :CVE-2026-48326
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48330 - Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

CVE ID :CVE-2026-48330
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this issue does not require user interaction. Scope is changed.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48331 - Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)

CVE ID :CVE-2026-48331
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48333 - Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

CVE ID :CVE-2026-48333
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48399 - Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)

CVE ID :CVE-2026-48399
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67673 - OreSat Firmware Stack-Based Buffer Overflow

CVE ID :CVE-2026-67673
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where the argument is copied to a 64-byte stack buffer via memcpy without proper length validation. An attacker with physical access to the UART3 serial interface can exploit this vulnerability by sending a maliciously crafted command with an oversized filename parameter,
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67978 - NASA cFS SBN UDP Interface Denial of Service Vulnerability

CVE ID :CVE-2026-67978
Published : Aug. 3, 2026, 11:16 p.m. | 44 minutes ago
Description :An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66318 - Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVE ID :CVE-2026-66318
Published : Aug. 4, 2026, 12:17 a.m. | 3 hours, 43 minutes ago
Description :Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66321 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE ID :CVE-2026-66321
Published : Aug. 4, 2026, 12:17 a.m. | 3 hours, 43 minutes ago
Description :Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-56845 - CustomSounds Path Traversal Vulnerability

CVE ID :CVE-2026-56845
Published : Aug. 4, 2026, 1:16 a.m. | 2 hours, 44 minutes ago
Description :An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-56846 - Node.js HTTP/2 Denial of Service Memory Exhaustion

CVE ID :CVE-2026-56846
Published : Aug. 4, 2026, 1:16 a.m. | 2 hours, 44 minutes ago
Description :A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58041 - Node.js sqlite StatementSyncIterator Use-After-Reset Vulnerability

CVE ID :CVE-2026-58041
Published : Aug. 4, 2026, 1:16 a.m. | 2 hours, 44 minutes ago
Description :A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanism introduced for StatementSync in recent releases This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...