CVE tracker
378 subscribers
5.27K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-46334 - OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning

CVE ID :CVE-2026-46334
Published : Aug. 5, 2026, 12:17 a.m. | 3 hours, 44 minutes ago
Description :OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed session-level SDP bandwidth line missing the required colon delimiter can corrupt parsed SDP bandwidth metadata. When a route or module subsequently clones the corrupted SDP state, as occurs with dialog and QoS processing, the OpenSIPS worker process crashes. An unauthenticated remote attacker can therefore trigger a crash in any configuration whose routing script parses attacker-controlled SDP and applies dialog/QoS processing. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18856 - Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery

CVE ID :CVE-2026-18856
Published : Aug. 5, 2026, 1:16 a.m. | 2 hours, 44 minutes ago
Description :A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.1.34 will fix this issue. It is recommended to upgrade the affected component.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18859 - ESAFENET CDG usbkey;logindojojs sql injection

CVE ID :CVE-2026-18859
Published : Aug. 5, 2026, 1:16 a.m. | 2 hours, 44 minutes ago
Description :A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18895 - UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow

CVE ID :CVE-2026-18895
Published : Aug. 5, 2026, 2:16 a.m. | 1 hour, 44 minutes ago
Description :A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18896 - lavkush-maurya Student-Registration-System changepass.php sql injection

CVE ID :CVE-2026-18896
Published : Aug. 5, 2026, 2:16 a.m. | 1 hour, 44 minutes ago
Description :A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument oldpass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18897 - UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow

CVE ID :CVE-2026-18897
Published : Aug. 5, 2026, 2:16 a.m. | 1 hour, 44 minutes ago
Description :A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18907 - PathTravelsal Vulnerability in com.talpa.hibrowser

CVE ID :CVE-2026-18907
Published : Aug. 5, 2026, 2:16 a.m. | 1 hour, 44 minutes ago
Description :Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18898 - UTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflow

CVE ID :CVE-2026-18898
Published : Aug. 5, 2026, 3 a.m. | 1 hour, 1 minute ago
Description :A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16942 - WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS

CVE ID :CVE-2026-16942
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to users allowed to post unfiltered HTML, allowing users with the Author role to store JavaScript that is served unescaped at a public URL and executes for any visitor, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16968 - GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users

CVE ID :CVE-2026-16968
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16981 - DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR

CVE ID :CVE-2026-16981
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16993 - DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory

CVE ID :CVE-2026-16993
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17515 - MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item

CVE ID :CVE-2026-17515
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4's import log file as well as import-related metadata belonging to arbitrary posts.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49004 - PostgreSQL Misconfiguration and Command Injection Vulnerability in ZTE NX799J (Red Magic 11 Air) Product

CVE ID :CVE-2026-49004
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66274 - Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow

CVE ID :CVE-2026-66274
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66275 - Apache Qpid Proton-J: Incoming session flow control window can be exceeded

CVE ID :CVE-2026-66275
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66276 - Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service

CVE ID :CVE-2026-66276
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66277 - Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery

CVE ID :CVE-2026-66277
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67552 - Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow

CVE ID :CVE-2026-67552
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67553 - Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded

CVE ID :CVE-2026-67553
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67554 - Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service

CVE ID :CVE-2026-67554
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...