CVE tracker
387 subscribers
5.44K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-71693 - Rejected reason: DO NOT USE THIS CVE RECORD. Consu

CVE ID :CVE-2026-71693
Published : Aug. 17, 2026, 7:16 p.m. | 43 minutes ago
Description :Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74238 - TIER IV Nebula 1.2.0 Heap Out-of-Bounds Read via VLP32 UDP Decoder

CVE ID :CVE-2026-74238
Published : Aug. 17, 2026, 7:16 p.m. | 43 minutes ago
Description :TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. Attackers can send a malformed datagram to the Velodyne UDP sensor port, which lacks sender-address restrictions present in other drivers, causing fabricated points derived from heap memory contents to be silently published into downstream PointCloud2 messages consumed by Autoware nodes.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75011 - kylecui NetForensicMCP index.js execAsync command injection

CVE ID :CVE-2026-75011
Published : Aug. 17, 2026, 7:16 p.m. | 43 minutes ago
Description :A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argument interface/protocol can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70495 - Search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters

CVE ID :CVE-2026-70495
Published : Aug. 17, 2026, 7:28 p.m. | 31 minutes ago
Description :A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71472 - Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_mem

CVE ID :CVE-2026-71472
Published : Aug. 17, 2026, 7:28 p.m. | 31 minutes ago
Description :A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to arbitrary code execution within the privileged postgres pod, potentially compromising the system.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75013 - TOTOLINK EX1200L cstecgi.cgi setWizardCfg null pointer dereference

CVE ID :CVE-2026-75013
Published : Aug. 17, 2026, 7:30 p.m. | 30 minutes ago
Description :A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null pointer dereference. The attack can be launched remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57485 - Stirling-PDF: Internal Service Account API Key Disclosure via Pipeline Endpoint

CVE ID :CVE-2026-57485
Published : Aug. 17, 2026, 7:31 p.m. | 28 minutes ago
Description :Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java injects the STIRLING-PDF-BACKEND-API-USER API key into pipeline subrequests, allowing an authenticated ROLE_USER to retrieve the key through /api/v1/user/get-api-key, impersonate the internal service account, bypass normal rate limits, and access internal endpoints including /api/v1/info/requests/all and /api/v1/info/load/all. This issue is fixed in version 2.9.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74234 - Legora < 2026-08-14 XSS via Mermaid gray-matter JavaScript Engine

CVE ID :CVE-2026-74234
Published : Aug. 17, 2026, 7:38 p.m. | 22 minutes ago
Description :Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive, causing the front-matter parser to invoke eval() before any SVG sanitization occurs. Attackers can exploit this flaw through influenced Mermaid diagram content to execute arbitrary JavaScript in the user's browser context, with elevated impact on Word and Outlook add-in surfaces where bearer session tokens are persisted in localStorage.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63669 - ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree

CVE ID :CVE-2026-63669
Published : Aug. 17, 2026, 7:41 p.m. | 18 minutes ago
Description :ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the check for ordinary moves, allowing an authenticated editor or contributor to use _targetId and _position through the page REST update endpoint to move a controlled page into a restricted subtree and make nudgeNewPeers() updateMany re-rank protected sibling pages. This issue is fixed in version 4.32.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75014 - SourceCodester Pet Grooming Management Software get_barcode_data.php sql injection

CVE ID :CVE-2026-75014
Published : Aug. 17, 2026, 7:45 p.m. | 15 minutes ago
Description :A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63670 - ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `` solidus close

CVE ID :CVE-2026-63670
Published : Aug. 17, 2026, 7:49 p.m. | 10 minutes ago
Description :ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2 and the ontext handler emits that content without escaping, while a browser parses the following img onerror markup as active HTML. This issue is fixed in version 2.17.6.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63667 - ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal

CVE ID :CVE-2026-63667
Published : Aug. 17, 2026, 7:56 p.m. | 4 minutes ago
Description :ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and extension fields in aposAttachments.json without ensuring that the resolved path remains under the extracted attachments directory, allowing an authenticated contributor to import a crafted archive, read a host file with an allowed extension, and publish the copied file at an unauthenticated uploads URL. This issue is fixed in version 3.6.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65346 - Apple Image Processing Integer Overflow Vulnerability

CVE ID :CVE-2026-65346
Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 43 minutes ago
Description :An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to arbitrary code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65347 - Apple ImageIO Denial of Service Vulnerability

CVE ID :CVE-2026-65347
Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 43 minutes ago
Description :The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to a denial-of-service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65349 - Apple Kernel Out-of-Bounds Read

CVE ID :CVE-2026-65349
Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 43 minutes ago
Description :An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to cause unexpected system termination or read kernel memory.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65351 - Apple Safari Denial of Service Vulnerability

CVE ID :CVE-2026-65351
Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 43 minutes ago
Description :This issue was addressed through improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67854 - Qcms SQL Injection Vulnerability

CVE ID :CVE-2026-67854
Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 43 minutes ago
Description :SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67868 - S2OPC Heap-Based Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-67868
Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 43 minutes ago
Description :A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67918 - Hermes Studio Directory Traversal Vulnerability

CVE ID :CVE-2026-67918
Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 43 minutes ago
Description :Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67960 - PbootCMS Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-67960
Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 43 minutes ago
Description :An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-69146 - MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

CVE ID :CVE-2026-69146
Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 43 minutes ago
Description :MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inputs for another user's run_id and inject attacker-controlled DatasetInput records into the dataset_inputs lineage metadata without UPDATE permission. This issue is fixed in version 3.15.0.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...