CVE tracker
378 subscribers
5.29K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-19074 - Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom Field Disclosure

CVE ID :CVE-2026-19074
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19075 - All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter

CVE ID :CVE-2026-19075
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19077 - Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization

CVE ID :CVE-2026-19077
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19089 - Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload

CVE ID :CVE-2026-19089
Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 7 minutes ago
Description :The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21058 - Samsung Contacts Arbitrary File Deletion Vulnerability

CVE ID :CVE-2026-21058
Published : Aug. 10, 2026, 7:39 a.m. | 44 minutes ago
Description :Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21059 - Samsung Contacts Improper Component Export Arbitrary File Deletion Vulnerability

CVE ID :CVE-2026-21059
Published : Aug. 10, 2026, 7:39 a.m. | 44 minutes ago
Description :Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21060 - Samsung Contacts Cross-Profile Data Access Vulnerability

CVE ID :CVE-2026-21060
Published : Aug. 10, 2026, 7:39 a.m. | 44 minutes ago
Description :Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21061 - Samsung Dialer Improper Input Validation Vulnerability

CVE ID :CVE-2026-21061
Published : Aug. 10, 2026, 7:40 a.m. | 43 minutes ago
Description :Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21062 - SemClipboardService Authorization Bypass

CVE ID :CVE-2026-21062
Published : Aug. 10, 2026, 7:40 a.m. | 43 minutes ago
Description :Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72580 - duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints

CVE ID :CVE-2026-72580
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on Xiaomi smart speakers running the patch. The /mute and /unmute endpoint handlers in api/main.py pass the user-supplied silent query parameter directly to os.system() without sanitization, enabling command injection via shell metacharacters.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72581 - duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint

CVE ID :CVE-2026-72581
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in api/main.py uses the user-supplied url POST parameter to redirect to a Home Assistant instance without validating the destination URL, enabling internal network scanning and access to internal services.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72582 - fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery Endpoint

CVE ID :CVE-2026-72582
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The sendOTPEmail function in pkg/auth/local.go dereferences a pointer obtained from an unchecked error path without validating it is non-nil, causing a fatal panic that terminates the entire server when a recovery request is sent to the /api/auth/local/recover endpoint.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72583 - fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload

CVE ID :CVE-2026-72583
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated user to upload an SVG file containing malicious JavaScript by bypassing the MIME type allow-list check. The pkg/rclonefs/base.go PutMultipart function validates the Content-Type header supplied by the client rather than inspecting the actual file content, enabling an attacker to rename a file to .jpg while specifying image/svg+xml to bypass the filter and store a script-bearing SVG in the web root.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72584 - fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Recovery

CVE ID :CVE-2026-72584
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attacker to bypass the OTP attempt limit on the account recovery flow, enabling brute-force attacks on 6-digit OTP codes. The verifyOTPSession function in pkg/auth/local.go reads and increments the attempt counter in separate non-atomic operations, allowing concurrent requests to observe the same attempt count below the threshold and proceed past the limit check before any update is committed.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72585 - Grafana - Incomplete Fix for CVE-2026-21724 Allows Editor Role to Delete Protected Contact Points

CVE ID :CVE-2026-72585
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission. The fix for CVE-2026-21724 addressed only the UPDATE code path in both pkg/services/ngalert/provisioning/contactpoints.go and pkg/services/ngalert/notifier/receiver_svc.go, but the DELETE path in both receiver services was not updated with the protected-field check, leaving deletion operations unguarded.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72586 - frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler

CVE ID :CVE-2026-72586
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other sensitive Socket.IO events (DEVICE_BROWSE, HOST_INTERFACES, DEVICE_TAGS_REQUEST, etc.) call isSocketAdminAuthorized() to verify the connection token, but the DAQ_QUERY handler in server/runtime/index.js lacks this check entirely.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72587 - Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint

CVE ID :CVE-2026-72587
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/ server island endpoint. The originating-page URL supplied in u seeds the route template frame used for rendering, and the result is stored in a shared cache keyed only on nodeId, enabling an attacker to inject a crafted route that causes all subsequent visitors to receive malformed or attacker-controlled fragment content.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72588 - bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password Recovery

CVE ID :CVE-2026-72588
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered ones, enabling attackers to enumerate valid user accounts.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72589 - alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field

CVE ID :CVE-2026-72589
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a crafted crontab database file. The POST /import endpoint accepts arbitrary .db files and overwrites the application database without validation. The hook field value is embedded directly into a shell command by crontab.js makeCommand() without sanitization, so a malicious hook value in the imported file results in command execution on the next cron execution cycle.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72590 - alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter

CVE ID :CVE-2026-72590
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /crontab with URL-encoded newlines in the env_vars parameter. The handler appends the env_vars value directly to the crontab file string as '${envVars}\n' without stripping newline characters, enabling an attacker to insert arbitrary cron expressions that execute attacker-controlled commands.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72591 - Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter

CVE ID :CVE-2026-72591
Published : Aug. 10, 2026, 11:17 a.m. | 1 hour, 6 minutes ago
Description :A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or external hosts by supplying a crafted image_url value in the PATCH /apis/web/v1/album/{id}/image endpoint. The application fetches the supplied URL server-side without validating the destination host or blocking access to private, loopback, link-local, or internal addresses.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...