CVE tracker
389 subscribers
5.51K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-82483 - coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cross site scripting

CVE ID :CVE-2026-82483
Published : Aug. 30, 2026, 8:16 a.m. | 3 hours, 42 minutes ago
Description :A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.6.29 will fix this issue. It is recommended to upgrade the affected component.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82484 - itsourcecode Sales and Inventory System emp_searchfrm.php sql injection

CVE ID :CVE-2026-82484
Published : Aug. 30, 2026, 9:16 a.m. | 2 hours, 42 minutes ago
Description :A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82485 - itsourcecode Sales and Inventory System pro_edit.php sql injection

CVE ID :CVE-2026-82485
Published : Aug. 30, 2026, 9:16 a.m. | 2 hours, 42 minutes ago
Description :A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82486 - SiteServer SSCMS Agent Installation Workflow access control

CVE ID :CVE-2026-82486
Published : Aug. 30, 2026, 10:17 a.m. | 1 hour, 41 minutes ago
Description :A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82487 - Beetel 450TC3 password recovery

CVE ID :CVE-2026-82487
Published : Aug. 30, 2026, 10:17 a.m. | 1 hour, 41 minutes ago
Description :A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82540 - itsourcecode Sales and Inventory System cust_searchfrm.php sql injection

CVE ID :CVE-2026-82540
Published : Aug. 30, 2026, 11:15 a.m. | 44 minutes ago
Description :A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82488 - Beetel 450TC3 User Management cross site scripting

CVE ID :CVE-2026-82488
Published : Aug. 30, 2026, 11:17 a.m. | 41 minutes ago
Description :A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82539 - TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption

CVE ID :CVE-2026-82539
Published : Aug. 30, 2026, 11:17 a.m. | 41 minutes ago
Description :A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82639 - NextChat 2.15.8 through 2.16.1 OpenAI API Key Disclosure

CVE ID :CVE-2026-82639
Published : Aug. 30, 2026, 2:17 p.m. | 1 hour, 42 minutes ago
Description :NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82640 - browser-use web-ui 2.0.0 through 3.0.0 Cleartext API Key Storage

CVE ID :CVE-2026-82640
Published : Aug. 30, 2026, 2:17 p.m. | 1 hour, 42 minutes ago
Description :browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82641 - keploy 3.1.0 through 3.6.25 Unauthenticated TLS Key Exposure

CVE ID :CVE-2026-82641
Published : Aug. 30, 2026, 2:17 p.m. | 1 hour, 42 minutes ago
Description :keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/stop and /agent/storemocks to manipulate recording sessions.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82642 - Readest: unsanitized iframe srcdoc attribute in the EPUB sanitizer can lead to arbitrary code execution

CVE ID :CVE-2026-82642
Published : Aug. 30, 2026, 2:17 p.m. | 1 hour, 42 minutes ago
Description :Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the
CVE-2026-78699 - rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres

CVE ID :CVE-2026-78699
Published : Aug. 30, 2026, 3:13 p.m. | 46 minutes ago
Description :Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data. AshPostgres.MultiTenancy.rename_tenant/3 issues the ALTER SCHEMA ... RENAME TO ... with the non-raising Ecto.Adapters.SQL.query/2, discards its {:ok, _} | {:error, _} result, and unconditionally returns :ok. PostgreSQL rejects the rename when the target schema already exists (and on insufficient privilege or lock timeout), but that failure never reaches the caller. The calling manage_tenant update action therefore sees success and commits the tenant row with the new name, which is the schema of a different existing tenant, so subsequent reads and writes for that tenant run against the other tenant's data. This issue affects ash_postgres: from 0.25.0 before 2.13.0.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82545 - itsourcecode Sales and Inventory System sup_searchfrm.php sql injection

CVE ID :CVE-2026-82545
Published : Aug. 30, 2026, 3:16 p.m. | 43 minutes ago
Description :A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82547 - Linux Foundation Magma Registration Complete Message amf_fsm.cpp improper authentication

CVE ID :CVE-2026-82547
Published : Aug. 30, 2026, 3:16 p.m. | 43 minutes ago
Description :A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authentication. The attack can be launched remotely. The exploit has been made public and could be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82548 - Linux Foundation Magma InitialUEMessage information disclosure

CVE ID :CVE-2026-82548
Published : Aug. 30, 2026, 3:16 p.m. | 43 minutes ago
Description :A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82643 - WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.php

CVE ID :CVE-2026-82643
Published : Aug. 30, 2026, 3:16 p.m. | 43 minutes ago
Description :WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to trigger uncapped two-factor confirmation emails and perform sustained password guessing attacks against user accounts.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82644 - WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-Agent

CVE ID :CVE-2026-82644
Published : Aug. 30, 2026, 3:16 p.m. | 43 minutes ago
Description :WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlobal) that silently discards writes for any client identified as a bot by isBot(). Because isBot() treats a missing User-Agent header as a bot by default — and also matches common bot identifiers such as 'curl', 'bot', 'crawler', and 'spider' — the counter never increments for such clients, so the rate limit never fires. An unauthenticated attacker can therefore submit unlimited login attempts (e.g., by omitting the User-Agent header or using curl's default User-Agent), enabling unrestricted password-guessing attacks.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82645 - AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token

CVE ID :CVE-2026-82645
Published : Aug. 30, 2026, 3:16 p.m. | 43 minutes ago
Description :AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's stream_key and stream_url (credentials for external platforms such as YouTube, Facebook, and Twitch) without authentication. The token is merely encryptString() of an integer id with no user binding, expiry, or authentication tag. Because encryption uses AES-256-CBC with a deterministic IV and no MAC, and because intval() accepts any string beginning with a digit, an unauthenticated attacker can forge valid tokens using the public encryption oracle in view/url2Embed.json.php, disclosing arbitrary users' stream credentials.
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82646 - WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php

CVE ID :CVE-2026-82646
Published : Aug. 30, 2026, 3:16 p.m. | 43 minutes ago
Description :WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an encrypted evideo payload containing unescaped markup, then deliver it as a legitimate-looking link on the site's own domain to execute JavaScript in victims' sessions and steal cookies or CSRF tokens.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82647 - WWBN AVideo Cross-Site Request Forgery via sendEmail.json.php

CVE ID :CVE-2026-82647
Published : Aug. 30, 2026, 3:16 p.m. | 43 minutes ago
Description :WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends emails with attacker-controlled subject and body to arbitrary recipients, passing SPF/DKIM/DMARC validation for phishing and brand impersonation attacks.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...