CVE tracker
386 subscribers
5.41K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-73049 - SiYuan before v3.7.4 Information Disclosure via getAttributeViewBacklinks

CVE ID :CVE-2026-73049
Published : Aug. 14, 2026, 12:16 p.m. | 1 hour, 27 minutes ago
Description :SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden access list instead of the visibility list when filtering backlinks. Anonymous readers can supply a publicly visible database row identifier to discover hidden-tier documents that reference it, receiving the database name, row title, and document path of hidden documents.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73051 - actix-http before 3.12.1 HTTP Request Smuggling via CL.TE

CVE ID :CVE-2026-73051
Published : Aug. 14, 2026, 12:16 p.m. | 1 hour, 27 minutes ago
Description :actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73630 - SiYuan before v3.7.4 Information Disclosure via authFilePublishAccess

CVE ID :CVE-2026-73630
Published : Aug. 14, 2026, 12:16 p.m. | 1 hour, 27 minutes ago
Description :SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with CheckAuth only and is reachable anonymously. The endpoint never sets a failure code, so its outcome is signalled entirely by the response message and by the presence of a Set-Cookie header, and these signals differ across access tiers. By submitting requests with an empty password for a candidate document identifier, an anonymous attacker can distinguish whether a document is public/nonexistent, password-protected, or exists at the hidden or forbidden tier, thereby confirming the existence of documents they are not permitted to access. Because hidden and forbidden entries store an empty password, such requests also cause the server to issue a publish-auth cookie for forbidden documents.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19823 - Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow

CVE ID :CVE-2026-19823
Published : Aug. 14, 2026, 1:17 p.m. | 26 minutes ago
Description :A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19824 - Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow

CVE ID :CVE-2026-19824
Published : Aug. 14, 2026, 1:17 p.m. | 26 minutes ago
Description :A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19825 - SourceCodester Simple Client Management System Master.php save_service sql injection

CVE ID :CVE-2026-19825
Published : Aug. 14, 2026, 1:17 p.m. | 26 minutes ago
Description :A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19826 - alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization

CVE ID :CVE-2026-19826
Published : Aug. 14, 2026, 1:17 p.m. | 26 minutes ago
Description :A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19870 - IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation

CVE ID :CVE-2026-19870
Published : Aug. 14, 2026, 1:17 p.m. | 26 minutes ago
Description :Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73673 - Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication

CVE ID :CVE-2026-73673
Published : Aug. 14, 2026, 1:19 p.m. | 25 minutes ago
Description :Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing '.cgi' regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler, which accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature, potentially enabling persistent router compromise.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19631 - SQL Injection

CVE ID :CVE-2026-19631
Published : Aug. 14, 2026, 5:08 p.m. | 36 minutes ago
Description :A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19635 - Local Privilege Escalation

CVE ID :CVE-2026-19635
Published : Aug. 14, 2026, 5:12 p.m. | 32 minutes ago
Description :A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19846 - TOTOLINK A800R firewall.so cstecgi.cgi setUrlFilterRules stack-based overflow

CVE ID :CVE-2026-19846
Published : Aug. 14, 2026, 5:15 p.m. | 29 minutes ago
Description :A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-7347 - Rejected reason: This CVE ID has been rejected or

CVE ID :CVE-2023-7347
Published : Aug. 14, 2026, 5:17 p.m. | 27 minutes ago
Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19626 - Remote Code Execution

CVE ID :CVE-2026-19626
Published : Aug. 14, 2026, 5:17 p.m. | 27 minutes ago
Description :A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19628 - Remote Code Execution

CVE ID :CVE-2026-19628
Published : Aug. 14, 2026, 5:17 p.m. | 27 minutes ago
Description :A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19838 - Webkul Bagisto Backend Reporting Endpoint sales authorization

CVE ID :CVE-2026-19838
Published : Aug. 14, 2026, 5:17 p.m. | 27 minutes ago
Description :A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19839 - SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload

CVE ID :CVE-2026-19839
Published : Aug. 14, 2026, 5:17 p.m. | 27 minutes ago
Description :A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19841 - TRENDNET TEW-813DRU vsftpd vsftpd.conf default permission

CVE ID :CVE-2026-19841
Published : Aug. 14, 2026, 5:17 p.m. | 27 minutes ago
Description :A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19844 - TOTOLINK A800R ipv6.so cstecgi.cgi setRadvdCfg stack-based overflow

CVE ID :CVE-2026-19844
Published : Aug. 14, 2026, 5:17 p.m. | 27 minutes ago
Description :A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19845 - TOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow

CVE ID :CVE-2026-19845
Published : Aug. 14, 2026, 5:17 p.m. | 27 minutes ago
Description :A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-46380 - compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem

CVE ID :CVE-2026-46380
Published : Aug. 14, 2026, 5:18 p.m. | 26 minutes ago
Description :compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgery, targeting internal services or cloud metadata endpoints. Versions 3.12.2 and 4.0.3 fix the issue.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...