CVE tracker
387 subscribers
5.44K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-15413 - Link Factory - Backdoor

CVE ID :CVE-2026-15413
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16458 - Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto

CVE ID :CVE-2026-16458
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16459 - Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto

CVE ID :CVE-2026-16459
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19481 - @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header

CVE ID :CVE-2026-19481
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19694 - Heap-based Buffer Overflow in Wireshark

CVE ID :CVE-2026-19694
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19695 - Stack-based Buffer Overflow in Wireshark

CVE ID :CVE-2026-19695
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19696 - Out-of-bounds Write in Wireshark

CVE ID :CVE-2026-19696
Published : Aug. 13, 2026, 9:17 a.m. | 23 minutes ago
Description :Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59500 - Priority - CWE-287: Improper Authentication

CVE ID :CVE-2026-59500
Published : Aug. 13, 2026, 9:18 a.m. | 22 minutes ago
Description :CWE-287: Improper Authentication
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11970 - Forcepoint One Endpoint Safari Extension Disablement and DLP Bypass

CVE ID :CVE-2026-11970
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59501 - Priority – CWE-284: Improper Access Control

CVE ID :CVE-2026-59501
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59502 - Priority - CWE-203: Observable Discrepancy

CVE ID :CVE-2026-59502
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-203: Observable Discrepancy
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59503 - Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor

CVE ID :CVE-2026-59503
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59504 - Priority – CWE-602: Client-Side Enforcement of Server-Side Security

CVE ID :CVE-2026-59504
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-602: Client-Side Enforcement of Server-Side Security
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59505 - Priority - CWE-284: Improper Access Control

CVE ID :CVE-2026-59505
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-284: Improper Access Control
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59506 - Priority – CWE-306: Missing Authentication for Critical Function

CVE ID :CVE-2026-59506
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-306: Missing Authentication for Critical Function
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59507 - Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

CVE ID :CVE-2026-59507
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45819 - baseline-browser-mapping Denial of Service Vulnerability

CVE ID :CVE-2026-45819
Published : Aug. 13, 2026, 11:03 a.m. | 37 minutes ago
Description :baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12263 - Authentication Bypass

CVE ID :CVE-2026-12263
Published : Aug. 13, 2026, 11:17 a.m. | 23 minutes ago
Description :Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16455 - Local privilege escalation via improper input sanitization in execl() call

CVE ID :CVE-2026-16455
Published : Aug. 13, 2026, 11:17 a.m. | 23 minutes ago
Description :In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18368 - Heap buffer overflow in Modbusgwd

CVE ID :CVE-2026-18368
Published : Aug. 13, 2026, 11:17 a.m. | 23 minutes ago
Description :In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthenticated attacker with access to the affected service could trigger a heap-based buffer overflow, resulting in a denial of service.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68453 - s390/zcrypt: Fix buffer over-read in cca_cipher2protkey

CVE ID :CVE-2026-68453
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read. So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of sizeof key token struct ... key buf length
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...