CVE tracker
378 subscribers
5.29K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2023-54386 - Rejected reason: Erroneously reserved under wrong

CVE ID :CVE-2023-54386
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54387 - Rejected reason: Erroneously reserved under wrong

CVE ID :CVE-2023-54387
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54388 - Rejected reason: Erroneously reserved under wrong

CVE ID :CVE-2023-54388
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54389 - Rejected reason: Erroneously reserved under wrong

CVE ID :CVE-2023-54389
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18970 - Rongzhitong Visual Integrated Command and Dispatch Platform findAll sql injection

CVE ID :CVE-2026-18970
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52466 - VuFind Incorrect Access Control Vulnerability

CVE ID :CVE-2026-52466
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67869 - open62541 Buffer Overflow Vulnerability

CVE ID :CVE-2026-67869
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67870 - open62541 Null Pointer Dereference Vulnerability

CVE ID :CVE-2026-67870
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67871 - Systerel S2OPC Buffer Overflow

CVE ID :CVE-2026-67871
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67872 - Systerel S2OPC Denial of Service Vulnerability

CVE ID :CVE-2026-67872
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67873 - lib60870-C Heap-Based Buffer Overflow

CVE ID :CVE-2026-67873
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18973 - heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery

CVE ID :CVE-2026-18973
Published : Aug. 6, 2026, 1:16 a.m. | 2 hours, 49 minutes ago
Description :A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18974 - heshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure

CVE ID :CVE-2026-18974
Published : Aug. 6, 2026, 1:16 a.m. | 2 hours, 49 minutes ago
Description :A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18976 - NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment

CVE ID :CVE-2026-18976
Published : Aug. 6, 2026, 2:16 a.m. | 1 hour, 49 minutes ago
Description :A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18980 - nearai ironclaw shell.rs classify_command_risk command injection

CVE ID :CVE-2026-18980
Published : Aug. 6, 2026, 2:16 a.m. | 1 hour, 49 minutes ago
Description :A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is a1d7c3ba428ed575900469b207fb5668725f9a71. Applying a patch is advised to resolve this issue.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18990 - letta-ai LettaBot API Status Route server.ts missing authentication

CVE ID :CVE-2026-18990
Published : Aug. 6, 2026, 3:16 a.m. | 49 minutes ago
Description :A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18991 - nanocoai NanoClaw send_file core.ts path traversal

CVE ID :CVE-2026-18991
Published : Aug. 6, 2026, 3:16 a.m. | 49 minutes ago
Description :A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12713 - WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number

CVE ID :CVE-2026-12713
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13153 - Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint

CVE ID :CVE-2026-13153
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13154 - Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint

CVE ID :CVE-2026-13154
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13703 - SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure

CVE ID :CVE-2026-13703
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...