CVE tracker
380 subscribers
5.34K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-76929 - Out-of-bounds Read in Wireshark

CVE ID :CVE-2026-76929
Published : Aug. 19, 2026, 11:16 p.m. | 3 hours, 33 minutes ago
Description :Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2022-4996 - mruby bigint.c udiv floating point comparison with incorrect operator

CVE ID :CVE-2022-4996
Published : Aug. 20, 2026, 12:16 a.m. | 2 hours, 33 minutes ago
Description :A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The exploit has been published and may be used. It is best practice to apply a patch to resolve this issue.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76762 - code-projects Assessment Management welcome.php sql injection

CVE ID :CVE-2026-76762
Published : Aug. 20, 2026, 12:16 a.m. | 2 hours, 33 minutes ago
Description :A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76764 - code-projects Employee Management System Admin Login Endpoint aprocess.php sql injection

CVE ID :CVE-2026-76764
Published : Aug. 20, 2026, 12:16 a.m. | 2 hours, 33 minutes ago
Description :A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8619 - Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600

CVE ID :CVE-2026-8619
Published : Aug. 20, 2026, 12:16 a.m. | 2 hours, 33 minutes ago
Description :An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.  A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75628 - Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter

CVE ID :CVE-2026-75628
Published : Aug. 20, 2026, 1:16 a.m. | 1 hour, 33 minutes ago
Description :Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter. oauth2_login reads the return parameter from the initiation request, runs same_origin_path over it, and stores the survivor in the session flow record as the post-login redirect target. That check rejects a value that does not begin with a slash, one with a slash as its second byte, and one containing CR or LF. A backslash and a tab pass. The URL Standard treats a backslash as equivalent to a slash for special schemes, so `/\evil.example` parses with the authority `evil.example`. It also strips ASCII tab before parsing, so a tab between two leading slashes leaves `//evil.example`. A crafted link to the application's own login route lands the victim on the attacker's site after a genuine authentication. The redirect carries no authorization code or access token.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76783 - DeDeCMS advancedsearch.php sql injection

CVE ID :CVE-2026-76783
Published : Aug. 20, 2026, 1:16 a.m. | 1 hour, 33 minutes ago
Description :A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76785 - amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injection

CVE ID :CVE-2026-76785
Published : Aug. 20, 2026, 1:16 a.m. | 1 hour, 33 minutes ago
Description :A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76795 - AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery

CVE ID :CVE-2026-76795
Published : Aug. 20, 2026, 1:16 a.m. | 1 hour, 33 minutes ago
Description :A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of the file /api of the component REST API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.0 will fix this issue. The identifier of the patch is 96448894cc93ccecb0bdcbf263a9d25390a8455e. Upgrading the affected component is advised.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76800 - DeDeCMS select_media_post.php unrestricted upload

CVE ID :CVE-2026-76800
Published : Aug. 20, 2026, 2 a.m. | 49 minutes ago
Description :A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Executing a manipulation of the argument uploadfile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been published and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76799 - code-projects Login Registration System SQL Database Backup login_registration_system.sql file access

CVE ID :CVE-2026-76799
Published : Aug. 20, 2026, 2:16 a.m. | 33 minutes ago
Description :A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation causes files or directories accessible. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19582 - Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe file

CVE ID :CVE-2026-19582
Published : Aug. 20, 2026, 5:16 a.m. | 1 hour, 33 minutes ago
Description :In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unknowningly via a stack buffer overflow out of bounds write.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76956 - Libexpat Insufficient Entropy Denial of Service Vulnerability

CVE ID :CVE-2026-76956
Published : Aug. 20, 2026, 5:16 a.m. | 1 hour, 33 minutes ago
Description :In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76957 - libexpat Use-After-Free Vulnerability

CVE ID :CVE-2026-76957
Published : Aug. 20, 2026, 5:16 a.m. | 1 hour, 33 minutes ago
Description :libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13405 - Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder

CVE ID :CVE-2026-13405
Published : Aug. 20, 2026, 6:16 a.m. | 33 minutes ago
Description :The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution capabilities) to execute arbitrary PHP code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15049 - Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import

CVE ID :CVE-2026-15049
Published : Aug. 20, 2026, 6:16 a.m. | 33 minutes ago
Description :The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17153 - AI Agent by SiteGround <= 1.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint

CVE ID :CVE-2026-17153
Published : Aug. 20, 2026, 6:16 a.m. | 33 minutes ago
Description :The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to upload images to the WordPress media library, bypassing the upload_files capability restriction that Contributors are normally subject to, as authenticated attackers with Contributor-level access or above can satisfy the endpoint's nonce and permission checks. The sg_ai_studio_gutenberg_nonce required by the endpoint is emitted to any user with block editor access — including Contributors — making the absent upload_files check the sole barrier to exploitation.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19615 - Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC

CVE ID :CVE-2026-19615
Published : Aug. 20, 2026, 6:17 a.m. | 33 minutes ago
Description :The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19697 - GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload

CVE ID :CVE-2026-19697
Published : Aug. 20, 2026, 6:17 a.m. | 33 minutes ago
Description :The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19699 - GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure

CVE ID :CVE-2026-19699
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73542 - Seiko Epson Printers and Scanners Improper Certificate Validation Vulnerability

CVE ID :CVE-2026-73542
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...