CVE tracker
383 subscribers
5.36K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-78637 - Fdawgs node-poppler Argument Injection index.js pdfUnite argument injection

CVE ID :CVE-2026-78637
Published : Aug. 25, 2026, 5:17 a.m. | 1 hour, 35 minutes ago
Description :A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument Injection Handler. Performing a manipulation of the argument file_path results in argument injection. The attack may be initiated remotely. The patch is named db6e3f79d3beb20601be7e59669c39811ae3c330. It is recommended to apply a patch to fix this issue.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78656 - itsourcecode Sales and Inventory System cust_del.php sql injection

CVE ID :CVE-2026-78656
Published : Aug. 25, 2026, 6:15 a.m. | 37 minutes ago
Description :A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_del.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41741 - Rejected reason: This CVE ID has been rejected or

CVE ID :CVE-2025-41741
Published : Aug. 25, 2026, 6:18 a.m. | 34 minutes ago
Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78466 - Fluent Boards Pro <= 2.0.11 - Authenticated (Subscriber+) Insecure Direct Object Reference

CVE ID :CVE-2026-78466
Published : Aug. 25, 2026, 6:19 a.m. | 34 minutes ago
Description :The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.11 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78467 - Fluent Support Pro <= 2.3.1 - Missing Authorization

CVE ID :CVE-2026-78467
Published : Aug. 25, 2026, 6:19 a.m. | 34 minutes ago
Description :The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78470 - WP Project Manager Pro <= 4.0.1 - Authenticated (Subscriber+) SQL Injection

CVE ID :CVE-2026-78470
Published : Aug. 25, 2026, 6:19 a.m. | 34 minutes ago
Description :The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78477 - Jawn <= 1.4.2 - Unauthenticated Privilege Escalation

CVE ID :CVE-2026-78477
Published : Aug. 25, 2026, 6:19 a.m. | 34 minutes ago
Description :The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78478 - Måne <= 1.7 - Unauthenticated Local File Inclusion

CVE ID :CVE-2026-78478
Published : Aug. 25, 2026, 6:19 a.m. | 34 minutes ago
Description :The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78638 - peerigon unzip-crx/unzip-crx-3 Archive Extraction index.js unzip path traversal

CVE ID :CVE-2026-78638
Published : Aug. 25, 2026, 6:19 a.m. | 34 minutes ago
Description :A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component Archive Extraction. Executing a manipulation of the argument destination can lead to path traversal. The attack can only be executed locally. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78654 - cleverbrush framework/deep deepExtend.ts deepExtend prototype pollution

CVE ID :CVE-2026-78654
Published : Aug. 25, 2026, 6:19 a.m. | 34 minutes ago
Description :A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.1 will fix this issue. The identifier of the patch is 810398c1308c500c3b8b6af380b5a89371389327. You should upgrade the affected component.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-69665 - SKYSEA Client View and SKYMEC IT Manager Improper Default Permissions Vulnerability

CVE ID :CVE-2026-69665
Published : Aug. 25, 2026, 6:27 a.m. | 25 minutes ago
Description :SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68960 - SKYSEA Client View and SKYMEC IT Manager Stack-Based Buffer Overflow

CVE ID :CVE-2026-68960
Published : Aug. 25, 2026, 6:27 a.m. | 25 minutes ago
Description :A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product installed and can receive UDP packets from that system.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66109 - SKYSEA Client View and SKYMEC IT Manager Missing Authorization Vulnerability

CVE ID :CVE-2026-66109
Published : Aug. 25, 2026, 6:27 a.m. | 25 minutes ago
Description :A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68062 - SKYSEA Client View and SKYMEC IT Manager Path Traversal Vulnerability

CVE ID :CVE-2026-68062
Published : Aug. 25, 2026, 6:27 a.m. | 25 minutes ago
Description :SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68959 - SKYSEA Client View and SKYMEC IT Manager Path Traversal Vulnerability

CVE ID :CVE-2026-68959
Published : Aug. 25, 2026, 6:27 a.m. | 25 minutes ago
Description :SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77138 - Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)

CVE ID :CVE-2026-77138
Published : Aug. 25, 2026, 9:17 a.m. | 1 hour, 35 minutes ago
Description :The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77139 - Path Traversal in extension "Mask" (mask)

CVE ID :CVE-2026-77139
Published : Aug. 25, 2026, 9:17 a.m. | 1 hour, 35 minutes ago
Description :The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An authenticated backend user with access to the Mask module can supply a key containing path traversal sequences to create or delete .html files outside the configured template directory.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77140 - Broken Access Control in extension "Telephone Directory" (telephonedirectory)

CVE ID :CVE-2026-77140
Published : Aug. 25, 2026, 9:17 a.m. | 1 hour, 35 minutes ago
Description :The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update action and overwrite that record without a valid edit link or any ownership check.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77141 - Broken Access Control in extension "Club Directory" (clubdirectory)

CVE ID :CVE-2026-77141
Published : Aug. 25, 2026, 9:17 a.m. | 1 hour, 35 minutes ago
Description :The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check in any of them. An unauthenticated visitor who knows the UID of a club record can send a direct request to the update or activate action and overwrite that record, or publish one still awaiting approval, without owning it.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77142 - Broken Access Control in extension "Industry Directory" (yellowpages2)

CVE ID :CVE-2026-77142
Published : Aug. 25, 2026, 9:17 a.m. | 1 hour, 35 minutes ago
Description :The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor who knows the identifier of a company record from the public directory can submit a modified update request for that record directly and overwrite its data, without the application ever confirming that the visitor owns it.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77143 - Broken Access Control in extension "Forum" (pforum)

CVE ID :CVE-2026-77143
Published : Aug. 25, 2026, 9:17 a.m. | 1 hour, 35 minutes ago
Description :The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a visitor who knows the identifier of a topic from the public forum can submit a modified update request for that topic directly and overwrite its content, without the application confirming ownership. Topic identifiers are visible in the public forum listing, and exploitation requires no privileged access or non-default configuration.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...