CVE tracker
383 subscribers
5.37K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-62986 - OpenEXR: PyOpenEXR deep prefixed RGB stale lane disclosure

CVE ID :CVE-2026-62986
Published : Aug. 25, 2026, 6:27 p.m. | 25 minutes ago
Description :OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR that uses layer-prefixed RGB channels. With the default channel coalescing (separate_channels=False), the wrapper groups channels such as left.R, left.G, and left.B into a single RGB sample array, but the lane-offset calculation in PyPart::setDeepSliceData() only recognizes the exact unprefixed names G, B, and A. As a result, prefixed channels like left.G and left.B are decoded into lane 0 while lanes 1 and 2 are left uninitialized and returned to Python. A Python application that reads untrusted deep EXR files through the default OpenEXR.File API and then logs, serializes, previews, or otherwise processes the resulting NumPy sample arrays may expose uninitialized same-process heap contents, in addition to receiving incorrect green and blue channel data. This issue is fixed in versions 3.3.13 and 3.4.14.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79804 - SililaWijesinghe Food Ordering System search.php sql injection

CVE ID :CVE-2026-79804
Published : Aug. 25, 2026, 10:17 p.m. | 36 minutes ago
Description :A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument search_box results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79845 - code-projects Simple Inventory System edit.php sql injection

CVE ID :CVE-2026-79845
Published : Aug. 25, 2026, 10:17 p.m. | 36 minutes ago
Description :A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80182 - OpenStack Keystone Improper Authorization of Delegated Tokens

CVE ID :CVE-2026-80182
Published : Aug. 25, 2026, 10:17 p.m. | 36 minutes ago
Description :In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80184 - OpenStack Keystone Token Scope Escalation Vulnerability

CVE ID :CVE-2026-80184
Published : Aug. 25, 2026, 10:17 p.m. | 36 minutes ago
Description :In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an application credential token was presented with no explicit scope, Keystone would issue a new token scoped to the credential owner's default project rather than the project for which the credential was issued, bypassing the intended project boundary. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80185 - Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root

CVE ID :CVE-2026-80185
Published : Aug. 25, 2026, 10:17 p.m. | 36 minutes ago
Description :BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80186 - Bluez: stack overflow in name2utf8 causes dos and potential code execution

CVE ID :CVE-2026-80186
Published : Aug. 25, 2026, 10:17 p.m. | 36 minutes ago
Description :A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18985 - Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093

CVE ID :CVE-2026-18985
Published : Aug. 25, 2026, 10:19 p.m. | 33 minutes ago
Description :Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18261 - Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092

CVE ID :CVE-2026-18261
Published : Aug. 25, 2026, 10:21 p.m. | 31 minutes ago
Description :Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18260 - Disable Login Page - Critical - Unsupported - SA-CONTRIB-2026-091

CVE ID :CVE-2026-18260
Published : Aug. 25, 2026, 10:21 p.m. | 31 minutes ago
Description :Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18259 - Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090

CVE ID :CVE-2026-18259
Published : Aug. 25, 2026, 10:21 p.m. | 31 minutes ago
Description :Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15088 - Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089

CVE ID :CVE-2026-15088
Published : Aug. 25, 2026, 10:21 p.m. | 31 minutes ago
Description :Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16645 - PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access bypass - SA-CONTRIB-2026-088

CVE ID :CVE-2026-16645
Published : Aug. 25, 2026, 10:21 p.m. | 31 minutes ago
Description :Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16644 - Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087

CVE ID :CVE-2026-16644
Published : Aug. 25, 2026, 10:21 p.m. | 31 minutes ago
Description :Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16643 - Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086

CVE ID :CVE-2026-16643
Published : Aug. 25, 2026, 10:21 p.m. | 31 minutes ago
Description :Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16642 - Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085

CVE ID :CVE-2026-16642
Published : Aug. 25, 2026, 10:21 p.m. | 31 minutes ago
Description :Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16641 - Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084

CVE ID :CVE-2026-16641
Published : Aug. 25, 2026, 10:22 p.m. | 31 minutes ago
Description :Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16646 - PanKM - Critical - Unsupported - SA-CONTRIB-2026-083

CVE ID :CVE-2026-16646
Published : Aug. 25, 2026, 10:22 p.m. | 31 minutes ago
Description :Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16640 - Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082

CVE ID :CVE-2026-16640
Published : Aug. 25, 2026, 10:22 p.m. | 31 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16639 - Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081

CVE ID :CVE-2026-16639
Published : Aug. 25, 2026, 10:22 p.m. | 31 minutes ago
Description :Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16638 - Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080

CVE ID :CVE-2026-16638
Published : Aug. 25, 2026, 10:22 p.m. | 31 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...