CVE tracker
386 subscribers
5.43K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-84358 - Google Chrome Downloads Improper Privilege Management Address Bar Spoofing

CVE ID :CVE-2026-84358
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84332 - Google Chrome SiteSettings Authorization Bypass

CVE ID :CVE-2026-84332
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84330 - Google Chrome Address Bar Spoofing via Fullscreen UI Misrepresentation

CVE ID :CVE-2026-84330
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84334 - Google Chrome Chromoting Local Privilege Escalation

CVE ID :CVE-2026-84334
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84348 - Google Chrome MediaCapture Information Disclosure

CVE ID :CVE-2026-84348
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84335 - Google Chrome TabStrip Improper Authorization

CVE ID :CVE-2026-84335
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84327 - Google Chrome Autofill Improper Authorization

CVE ID :CVE-2026-84327
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84329 - Google Chrome CredentialProvider Confused Deputy Vulnerability

CVE ID :CVE-2026-84329
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84356 - Google Chrome FullScreen UI Spoofing Vulnerability

CVE ID :CVE-2026-84356
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84350 - Google Chrome TabStrip Use-After-Free Vulnerability

CVE ID :CVE-2026-84350
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84331 - Google Chrome Actor Web Origin Policy Bypass

CVE ID :CVE-2026-84331
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84425 - zhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service

CVE ID :CVE-2026-84425
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84427 - zhayujie CowAgent Bash Tool bash.py denial of service

CVE ID :CVE-2026-84427
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84430 - gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes

CVE ID :CVE-2026-84430
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upgrading the affected component is advised.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84694 - Coolify before 4.2.0 Remote Code Execution via Environment Variable Key

CVE ID :CVE-2026-84694
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84695 - BookStack before 26.05.4 Stored XSS via Drawing Upload

CVE ID :CVE-2026-84695
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84696 - Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands

CVE ID :CVE-2026-84696
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84697 - Mailpit SSRF Deny List Bypass via Azure Metadata and IPv6 Prefix

CVE ID :CVE-2026-84697
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in message content to reach the link check API and proxy endpoint for accessing internal resources.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84698 - PX4 Autopilot sd_bench Heap Buffer Overflow via Block Size

CVE ID :CVE-2026-84698
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially execute code or crash the system.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84699 - Team Password Manager before 14.184.308 Authentication Bypass in Password Reset

CVE ID :CVE-2026-84699
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84700 - Pika Unauthenticated Replication Access via Internal Protobuf Port

CVE ID :CVE-2026-84700
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates it; the frame dispatcher (DealMessage) does not require a completed or attempted MetaSync before routing other message types to their handlers. As a result, an unauthenticated remote attacker can connect directly to the replication port and issue TrySync, DBSync, BinlogSync, and RemoveSlaveNode requests, obtaining the full-sync snapshot and live write stream and removing replica nodes, even when requirepass is configured.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...