CVE tracker
383 subscribers
5.36K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-9254 - Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices

CVE ID :CVE-2026-9254
Published : Aug. 24, 2026, 6:17 p.m. | 35 minutes ago
Description :An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-13081
Published : Aug. 24, 2026, 6:20 p.m. | 32 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-13047
Published : Aug. 24, 2026, 6:20 p.m. | 32 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78541 - Command Injection in Parent Control of TP-Link Archer BE3600 v1

CVE ID :CVE-2026-78541
Published : Aug. 24, 2026, 6:26 p.m. | 26 minutes ago
Description :A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78417 - Devolutions Remote Desktop Manager IronVNC Improper Authentication Verification

CVE ID :CVE-2026-78417
Published : Aug. 24, 2026, 6:26 p.m. | 26 minutes ago
Description :Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-27364 - WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability

CVE ID :CVE-2026-27364
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32554 - WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnerability

CVE ID :CVE-2026-32554
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32555 - WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability

CVE ID :CVE-2026-32555
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32556 - WordPress Boost plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-32556
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32559 - WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability

CVE ID :CVE-2026-32559
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32560 - WordPress MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator plugin <= 1.4 - Local File Inclusion vulnerability

CVE ID :CVE-2026-32560
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32561 - WordPress Booking Hub plugin <= 1.3.0 - Privilege Escalation vulnerability

CVE ID :CVE-2026-32561
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32563 - WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability

CVE ID :CVE-2026-32563
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45404 - OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access

CVE ID :CVE-2026-45404
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent SetBaggageItem and correlation.MapFromContext calls on the same hooked bridgeSpan can trigger a fatal runtime error—such as concurrent map read and map write or concurrent map iteration and map write—terminating the process and causing denial of service. This issue is fixed in version 1.45.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68516 - OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow

CVE ID :CVE-2026-68516
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77337 - CakePHP: Potential Authentication bypass with CookieAuthenticator

CVE ID :CVE-2026-77337
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77384 - libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows remote resource exhaustion

CVE ID :CVE-2026-77384
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @libp2p/circuit-relay-v2 relay servers and leading to denial of service. This issue is fixed in version 4.2.9.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78259 - WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability

CVE ID :CVE-2026-78259
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78262 - WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability

CVE ID :CVE-2026-78262
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78263 - WordPress Event Tickets plugin <= 5.29.2.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-78263
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78264 - WordPress Toolset Blocks plugin <= 1.6.26 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-78264
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...