CVE tracker
386 subscribers
5.45K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-14832 - ShopSmart Loyalty for WooCommerce <= 1.0.0 - Unauthenticated Sensitive Information Disclosure via shopsmart_check_phone

CVE ID :CVE-2026-14832
Published : Aug. 17, 2026, 6:17 a.m. | 1 hour, 39 minutes ago
Description :The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthenticated users, allowing anyone who knows a customer's phone number to retrieve that customer's loyalty profile, including name, email, and account balance.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19992 - Orange View Limited DualSafe Password Manager & Digital Vault Extension postMessage-based Bridge information disclosure

CVE ID :CVE-2026-19992
Published : Aug. 17, 2026, 6:17 a.m. | 1 hour, 39 minutes ago
Description :A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19993 - Webkul Bagisto RMA State Validation update-status behavioral workflow

CVE ID :CVE-2026-19993
Published : Aug. 17, 2026, 6:17 a.m. | 1 hour, 39 minutes ago
Description :A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19998 - code-projects Online Shopping System offersmail.php cross site scripting

CVE ID :CVE-2026-19998
Published : Aug. 17, 2026, 7:15 a.m. | 41 minutes ago
Description :A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument email can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15623 - Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service

CVE ID :CVE-2026-15623
Published : Aug. 17, 2026, 7:17 a.m. | 39 minutes ago
Description :A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no customer action is needed.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19994 - Webkul Bagisto Configuration Management execute authorization

CVE ID :CVE-2026-19994
Published : Aug. 17, 2026, 7:17 a.m. | 39 minutes ago
Description :A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19995 - Webkul Bagisto RMA Message send-message cross site scripting

CVE ID :CVE-2026-19995
Published : Aug. 17, 2026, 7:17 a.m. | 39 minutes ago
Description :A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19996 - Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges management

CVE ID :CVE-2026-19996
Published : Aug. 17, 2026, 7:17 a.m. | 39 minutes ago
Description :A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19997 - Webkul Bagisto Backend Sales RMA Endpoint requests authorization

CVE ID :CVE-2026-19997
Published : Aug. 17, 2026, 7:17 a.m. | 39 minutes ago
Description :A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22072 - Arbitrary URL Loading in WebView Leading to Token Leakage Risk

CVE ID :CVE-2026-22072
Published : Aug. 17, 2026, 7:17 a.m. | 39 minutes ago
Description :Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74875 - openssl_encrypt before 1.4.0 Schema Validation Bypass

CVE ID :CVE-2026-74875
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74876 - openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption

CVE ID :CVE-2026-74876
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74877 - openssl_encrypt before 1.4.0 Missing Ownership Verification via revoke_key

CVE ID :CVE-2026-74877
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74878 - openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass

CVE ID :CVE-2026-74878
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74879 - openssl_encrypt before 1.4.0 Information Disclosure via /ready endpoint

CVE ID :CVE-2026-74879
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74880 - openssl_encrypt before 1.4.0 Token Leakage via Query Parameters

CVE ID :CVE-2026-74880
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74881 - openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins

CVE ID :CVE-2026-74881
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74882 - openssl_encrypt before 1.4.0 Insecure Default Configuration

CVE ID :CVE-2026-74882
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74883 - openssl_encrypt before 1.4.0 Sandbox Bypass via pathlib and io

CVE ID :CVE-2026-74883
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74884 - openssl_encrypt before 1.4.0 Path Traversal via plugin_id

CVE ID :CVE-2026-74884
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to access arbitrary directories outside the intended plugin directory.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74885 - openssl_encrypt before 1.4.0 Logging Bug and Race Condition

CVE ID :CVE-2026-74885
Published : Aug. 17, 2026, 11:16 a.m. | 41 minutes ago
Description :openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...