CVE tracker
380 subscribers
5.35K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-77649 - Internment Rust Crate Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-77649
Published : Aug. 21, 2026, 1:17 a.m. | 1 hour, 33 minutes ago
Description :The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77650 - append-only-vec Malicious Dependency Arbitrary Code Execution

CVE ID :CVE-2026-77650
Published : Aug. 21, 2026, 1:17 a.m. | 1 hour, 33 minutes ago
Description :The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77651 - arrayref Supply Chain Compromise

CVE ID :CVE-2026-77651
Published : Aug. 21, 2026, 1:17 a.m. | 1 hour, 33 minutes ago
Description :The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76158 - Datiphy Data Management Center - External Control of File Name or Path

CVE ID :CVE-2026-76158
Published : Aug. 21, 2026, 2:02 a.m. | 48 minutes ago
Description :External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76131 - Yamaha VOCALOID6 Hard-Coded Credentials Vulnerability

CVE ID :CVE-2026-76131
Published : Aug. 21, 2026, 2:02 a.m. | 47 minutes ago
Description :Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's activation and content servers.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76137 - VOCALOID6 Local Privilege Escalation Vulnerability

CVE ID :CVE-2026-76137
Published : Aug. 21, 2026, 2:02 a.m. | 47 minutes ago
Description :Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may escalate privileges via a local named pipe.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76155 - Datiphy Data Management Center - Use of Default Credentials

CVE ID :CVE-2026-76155
Published : Aug. 21, 2026, 2:16 a.m. | 34 minutes ago
Description :Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76156 - Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command

CVE ID :CVE-2026-76156
Published : Aug. 21, 2026, 2:16 a.m. | 34 minutes ago
Description :OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76157 - Datiphy Data Management Center - Missing Authentication for Critical Function

CVE ID :CVE-2026-76157
Published : Aug. 21, 2026, 2:16 a.m. | 34 minutes ago
Description :Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77391 - SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP cross-site request forgery

CVE ID :CVE-2026-77391
Published : Aug. 21, 2026, 2:16 a.m. | 34 minutes ago
Description :A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77392 - SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.php saveUser sql injection

CVE ID :CVE-2026-77392
Published : Aug. 21, 2026, 2:16 a.m. | 34 minutes ago
Description :A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73267 - Clusterclaims-controller: clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no ownership check

CVE ID :CVE-2026-73267
Published : Aug. 21, 2026, 3:16 a.m. | 3 hours, 34 minutes ago
Description :A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's local-cluster or other tenants' clusters, due to a missing ownership check. This vulnerability can lead to a denial of service by enabling unauthorized deletion of ManagedClusters.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18409 - WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values

CVE ID :CVE-2026-18409
Published : Aug. 21, 2026, 4:18 a.m. | 2 hours, 32 minutes ago
Description :The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit relies on the plugin's own wp_kses_allowed_html filter widening the 'post' allowlist to permit iframe elements with a data-src attribute, which is not on WordPress's URI-attribute sanitization list, allowing a javascript: URI stored in data-src to survive kses processing and subsequently be promoted to a live src attribute by the bundled admin script view-entry.min.js.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45199 - GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers

CVE ID :CVE-2026-45199
Published : Aug. 21, 2026, 4:18 a.m. | 2 hours, 32 minutes ago
Description :Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45201 - GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead to OOB read and/or write of arbitrary physical memory

CVE ID :CVE-2026-45201
Published : Aug. 21, 2026, 4:18 a.m. | 2 hours, 32 minutes ago
Description :Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading to OOB read and/or write due to improper validation of the said value. Such crafted log2 page size could lead to 4K pages being treated as higher order pages and allowing read and/or write access to the memory beyond 4K threshold.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45202 - GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast`

CVE ID :CVE-2026-45202
Published : Aug. 21, 2026, 4:18 a.m. | 2 hours, 32 minutes ago
Description :Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65644 - Rocket.Chat Cross-Site Scripting Vulnerability

CVE ID :CVE-2026-65644
Published : Aug. 21, 2026, 4:18 a.m. | 2 hours, 32 minutes ago
Description :Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65645 - Rocket.Chat Insecure DDP Method Schema Validation Information Disclosure

CVE ID :CVE-2026-65645
Published : Aug. 21, 2026, 4:18 a.m. | 2 hours, 32 minutes ago
Description :Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user. The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13736 - NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API

CVE ID :CVE-2026-13736
Published : Aug. 21, 2026, 6 a.m. | 50 minutes ago
Description :The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16962 - Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation

CVE ID :CVE-2026-16962
Published : Aug. 21, 2026, 6 a.m. | 50 minutes ago
Description :The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated attacker can cancel or fail arbitrary orders store-wide by enumerating ids (triggering downstream stock-release and notification side-effects).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15671 - Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter

CVE ID :CVE-2025-15671
Published : Aug. 21, 2026, 6 a.m. | 50 minutes ago
Description :The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...