CVE tracker
386 subscribers
5.43K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-18710 - Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization

CVE ID :CVE-2026-18710
Published : Aug. 11, 2026, 10:17 p.m. | 1 hour, 15 minutes ago
Description :A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and requires no special privileges to trigger. A party able to read the affected application's logs or downstream log-aggregation storage could recover the credential and reuse it to authenticate to the associated network infrastructure. This issue affects confidentiality only.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19556 - Google Chrome V8 Use-After-Free Vulnerability

CVE ID :CVE-2026-19556
Published : Aug. 11, 2026, 10:17 p.m. | 1 hour, 15 minutes ago
Description :Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19557 - Google Chrome TabStrip Use-After-Free Sandbox Escape

CVE ID :CVE-2026-19557
Published : Aug. 11, 2026, 10:17 p.m. | 1 hour, 15 minutes ago
Description :Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19558 - Google Chrome Extensions Use-After-Free Vulnerability

CVE ID :CVE-2026-19558
Published : Aug. 11, 2026, 10:17 p.m. | 1 hour, 15 minutes ago
Description :Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19559 - Google Chrome HTML Use-After-Free Vulnerability

CVE ID :CVE-2026-19559
Published : Aug. 11, 2026, 10:17 p.m. | 1 hour, 15 minutes ago
Description :Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19560 - Google Chrome Blink Use After Free

CVE ID :CVE-2026-19560
Published : Aug. 11, 2026, 10:17 p.m. | 1 hour, 15 minutes ago
Description :Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-29036 - cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding

CVE ID :CVE-2026-29036
Published : Aug. 11, 2026, 10:17 p.m. | 1 hour, 15 minutes ago
Description :cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-5917 - libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend

CVE ID :CVE-2026-5917
Published : Aug. 11, 2026, 10:17 p.m. | 1 hour, 15 minutes ago
Description :libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64934 - Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision

CVE ID :CVE-2026-64934
Published : Aug. 11, 2026, 10:18 p.m. | 1 hour, 14 minutes ago
Description :The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66098 - Mira Hormone Monitor, Mira Android App Missing authentication for critical function

CVE ID :CVE-2026-66098
Published : Aug. 11, 2026, 10:18 p.m. | 1 hour, 13 minutes ago
Description :The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66340 - Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts

CVE ID :CVE-2026-66340
Published : Aug. 11, 2026, 10:18 p.m. | 1 hour, 13 minutes ago
Description :The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66875 - Mira Hormone Monitor, Mira Android App Missing authentication for critical function

CVE ID :CVE-2026-66875
Published : Aug. 11, 2026, 10:18 p.m. | 1 hour, 13 minutes ago
Description :In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67558 - Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing

CVE ID :CVE-2026-67558
Published : Aug. 11, 2026, 10:18 p.m. | 1 hour, 13 minutes ago
Description :The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67568 - Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials

CVE ID :CVE-2026-67568
Published : Aug. 11, 2026, 10:18 p.m. | 1 hour, 13 minutes ago
Description :The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68067 - Mira Hormone Monitor, Mira Android App Weak Authentication

CVE ID :CVE-2026-68067
Published : Aug. 11, 2026, 10:18 p.m. | 1 hour, 13 minutes ago
Description :The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73245 - Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth

CVE ID :CVE-2026-73245
Published : Aug. 11, 2026, 10:19 p.m. | 1 hour, 13 minutes ago
Description :Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /api/v1/** on port 8080, allowing unauthenticated GET /env requests to disclose resolved configuration and POST /loggers/{name} requests to change runtime log levels. This issue is fixed in 2.0.0-rc6.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73246 - Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials

CVE ID :CVE-2026-73246
Published : Aug. 11, 2026, 10:19 p.m. | 1 hour, 13 minutes ago
Description :Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, which can expose commands, environment variables, HTTP headers, connection details, plaintext credentials, and execution identifiers while the main API on port 8080 remains protected. This issue is fixed in 2.0.0-rc6.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73247 - Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata

CVE ID :CVE-2026-73247
Published : Aug. 11, 2026, 10:19 p.m. | 1 hour, 13 minutes ago
Description :Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting private, loopback, or link-local destinations, allowing an unauthenticated attacker to import and execute a flow that accesses internal services or cloud metadata.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73248 - calibre: Bypass of Python template restrictions via nested `template()` leading to RCE

CVE ID :CVE-2026-73248
Published : Aug. 11, 2026, 10:19 p.m. | 1 hour, 13 minutes ago
Description :calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allow_python_templates=False, allowing a nested python: template to reach compile_python_template and execute arbitrary Python code when the file is opened or imported. This issue is fixed in version 9.12.0.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73249 - calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification

CVE ID :CVE-2026-73249
Published : Aug. 11, 2026, 10:19 p.m. | 1 hour, 13 minutes ago
Description :calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_write_access() before update_annotations() passes attacker-controlled JSON to db.merge_annotations_for_book(), which allows a readonly user or an anonymous user on an unauthenticated deployment to persist unauthorized book annotation changes. This issue is fixed in version 9.12.0.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-14043 - Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow

CVE ID :CVE-2024-14043
Published : Aug. 11, 2026, 11:15 p.m. | 17 minutes ago
Description :A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data_from_avp of the file src/mme/mme-fd-path.c of the component Diameter S6a Interface. Executing a manipulation of the argument msisdn_len can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.7.2 is able to resolve this issue. This patch is called 7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304. Upgrading the affected component is recommended.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...