CVE tracker
378 subscribers
5.27K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-18786 - CheckView < 2.3.2 - Administrator Account Creation via REST API Authentication Bypass

CVE ID :CVE-2026-18786
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-in administrator, such as creating a new administrator account, via a crafted link an administrator is tricked into opening.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18934 - RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation and Post Deletion

CVE ID :CVE-2026-18934
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and scheduling state, disable it, or clear its error log. One of the affected actions performs no object-type check either, so arbitrary posts and pages can also be unpublished regardless of who owns them.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18946 - Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictable Filename

CVE ID :CVE-2026-18946
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18960 - Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords

CVE ID :CVE-2026-18960
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19049 - ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'removesite' Cookie

CVE ID :CVE-2026-19049
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19053 - ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter

CVE ID :CVE-2026-19053
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19074 - Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom Field Disclosure

CVE ID :CVE-2026-19074
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19075 - All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter

CVE ID :CVE-2026-19075
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19077 - Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization

CVE ID :CVE-2026-19077
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19089 - Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload

CVE ID :CVE-2026-19089
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21058 - Samsung Contacts Arbitrary File Deletion Vulnerability

CVE ID :CVE-2026-21058
Published : Aug. 10, 2026, 7:39 a.m. | 44 minutes ago
Description :Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21059 - Samsung Contacts Improper Component Export Arbitrary File Deletion Vulnerability

CVE ID :CVE-2026-21059
Published : Aug. 10, 2026, 7:39 a.m. | 44 minutes ago
Description :Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21060 - Samsung Contacts Cross-Profile Data Access Vulnerability

CVE ID :CVE-2026-21060
Published : Aug. 10, 2026, 7:39 a.m. | 44 minutes ago
Description :Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21061 - Samsung Dialer Improper Input Validation Vulnerability

CVE ID :CVE-2026-21061
Published : Aug. 10, 2026, 7:40 a.m. | 43 minutes ago
Description :Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21062 - SemClipboardService Authorization Bypass

CVE ID :CVE-2026-21062
Published : Aug. 10, 2026, 7:40 a.m. | 43 minutes ago
Description :Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72580 - duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints

CVE ID :CVE-2026-72580
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on Xiaomi smart speakers running the patch. The /mute and /unmute endpoint handlers in api/main.py pass the user-supplied silent query parameter directly to os.system() without sanitization, enabling command injection via shell metacharacters.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72581 - duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint

CVE ID :CVE-2026-72581
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in api/main.py uses the user-supplied url POST parameter to redirect to a Home Assistant instance without validating the destination URL, enabling internal network scanning and access to internal services.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72582 - fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery Endpoint

CVE ID :CVE-2026-72582
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The sendOTPEmail function in pkg/auth/local.go dereferences a pointer obtained from an unchecked error path without validating it is non-nil, causing a fatal panic that terminates the entire server when a recovery request is sent to the /api/auth/local/recover endpoint.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72583 - fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload

CVE ID :CVE-2026-72583
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated user to upload an SVG file containing malicious JavaScript by bypassing the MIME type allow-list check. The pkg/rclonefs/base.go PutMultipart function validates the Content-Type header supplied by the client rather than inspecting the actual file content, enabling an attacker to rename a file to .jpg while specifying image/svg+xml to bypass the filter and store a script-bearing SVG in the web root.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72584 - fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Recovery

CVE ID :CVE-2026-72584
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attacker to bypass the OTP attempt limit on the account recovery flow, enabling brute-force attacks on 6-digit OTP codes. The verifyOTPSession function in pkg/auth/local.go reads and increments the attempt counter in separate non-atomic operations, allowing concurrent requests to observe the same attempt count below the threshold and proceed past the limit check before any update is committed.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72585 - Grafana - Incomplete Fix for CVE-2026-21724 Allows Editor Role to Delete Protected Contact Points

CVE ID :CVE-2026-72585
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission. The fix for CVE-2026-21724 addressed only the UPDATE code path in both pkg/services/ngalert/provisioning/contactpoints.go and pkg/services/ngalert/notifier/receiver_svc.go, but the DELETE path in both receiver services was not updated with the protected-field check, leaving deletion operations unguarded.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...