CVE tracker
373 subscribers
5.18K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-18603 - Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure via Reorder AJAX Actions

CVE ID :CVE-2026-18603
Published : Aug. 9, 2026, 6:19 a.m. | 2 hours ago
Description :The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a logged in user's cart via a crafted link.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19335 - Jane-xiaoer skill-vision-control config.ts getSkillVersionsDir path traversal

CVE ID :CVE-2026-19335
Published : Aug. 9, 2026, 6:19 a.m. | 1 hour, 59 minutes ago
Description :A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19336 - Pimzino spec-workflow-mcp approvals.ts ApprovalStorage.createApproval path traversal

CVE ID :CVE-2026-19336
Published : Aug. 9, 2026, 6:19 a.m. | 1 hour, 59 minutes ago
Description :A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19337 - adenot mcp-google-search read_webpage index.ts server-side request forgery

CVE ID :CVE-2026-19337
Published : Aug. 9, 2026, 6:20 a.m. | 1 hour, 59 minutes ago
Description :A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called f071d491b685011ca04e8ab8d586fc65f86bcee1. It is advisable to implement a patch to correct this issue.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19338 - automateyournetwork MCPyATS generate_mermaid_markdown index.ts processGenerateRequest path traversal

CVE ID :CVE-2026-19338
Published : Aug. 9, 2026, 7:17 a.m. | 1 hour, 2 minutes ago
Description :A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried out locally.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19339 - aliyun alibabacloud-dataworks-mcp-server initResources.ts ReadResourceRequestSchema server-side request forgery

CVE ID :CVE-2026-19339
Published : Aug. 9, 2026, 7:17 a.m. | 1 hour, 2 minutes ago
Description :A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19340 - anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgery

CVE ID :CVE-2026-19340
Published : Aug. 9, 2026, 7:17 a.m. | 1 hour, 2 minutes ago
Description :A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19341 - UTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflow

CVE ID :CVE-2026-19341
Published : Aug. 9, 2026, 7:17 a.m. | 1 hour, 2 minutes ago
Description :A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19342 - code-projects Task Management System Login index.php improper authentication

CVE ID :CVE-2026-19342
Published : Aug. 9, 2026, 7:30 a.m. | 49 minutes ago
Description :A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19343 - code-projects Task Management System AdminLogin.php sql injection

CVE ID :CVE-2026-19343
Published : Aug. 9, 2026, 7:45 a.m. | 34 minutes ago
Description :A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19344 - code-projects Task Management System comment_count_user.php sql injection

CVE ID :CVE-2026-19344
Published : Aug. 9, 2026, 10:17 a.m. | 2 hours, 2 minutes ago
Description :A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19345 - code-projects Task Management System UpdateTaskStatus.php authorization

CVE ID :CVE-2026-19345
Published : Aug. 9, 2026, 10:17 a.m. | 2 hours, 2 minutes ago
Description :A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19346 - Tenda CH22 CertListInfo formCertListInfo command injection

CVE ID :CVE-2026-19346
Published : Aug. 9, 2026, 10:17 a.m. | 2 hours, 2 minutes ago
Description :A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19347 - itsourcecode Hospital Management System viewdoctor.php sql injection

CVE ID :CVE-2026-19347
Published : Aug. 9, 2026, 11:16 a.m. | 1 hour, 3 minutes ago
Description :A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19348 - Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection

CVE ID :CVE-2026-19348
Published : Aug. 9, 2026, 11:16 a.m. | 1 hour, 3 minutes ago
Description :A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19350 - Dolibarr ERP TakePOS invoice.php fail authorization

CVE ID :CVE-2026-19350
Published : Aug. 9, 2026, 11:16 a.m. | 1 hour, 3 minutes ago
Description :A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19351 - dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection

CVE ID :CVE-2026-19351
Published : Aug. 9, 2026, 11:30 a.m. | 49 minutes ago
Description :A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19352 - mifi lossless-cut Built-in HTTP API Service httpServer.ts server-side request forgery

CVE ID :CVE-2026-19352
Published : Aug. 9, 2026, 1:16 p.m. | 3 hours, 4 minutes ago
Description :A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19353 - DedeCMS Installation Wizard index.php _4_Setup file inclusion

CVE ID :CVE-2026-19353
Published : Aug. 9, 2026, 1:16 p.m. | 3 hours, 4 minutes ago
Description :A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19354 - lock-upme OPMS IN Clause message.go sql injection

CVE ID :CVE-2026-19354
Published : Aug. 9, 2026, 2:17 p.m. | 2 hours, 3 minutes ago
Description :A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql injection. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19355 - MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection

CVE ID :CVE-2026-19355
Published : Aug. 9, 2026, 2:17 p.m. | 2 hours, 3 minutes ago
Description :A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...