CVE tracker
386 subscribers
5.43K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-84329 - Google Chrome CredentialProvider Confused Deputy Vulnerability

CVE ID :CVE-2026-84329
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84356 - Google Chrome FullScreen UI Spoofing Vulnerability

CVE ID :CVE-2026-84356
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84350 - Google Chrome TabStrip Use-After-Free Vulnerability

CVE ID :CVE-2026-84350
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84331 - Google Chrome Actor Web Origin Policy Bypass

CVE ID :CVE-2026-84331
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84425 - zhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service

CVE ID :CVE-2026-84425
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84427 - zhayujie CowAgent Bash Tool bash.py denial of service

CVE ID :CVE-2026-84427
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84430 - gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes

CVE ID :CVE-2026-84430
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upgrading the affected component is advised.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84694 - Coolify before 4.2.0 Remote Code Execution via Environment Variable Key

CVE ID :CVE-2026-84694
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84695 - BookStack before 26.05.4 Stored XSS via Drawing Upload

CVE ID :CVE-2026-84695
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84696 - Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands

CVE ID :CVE-2026-84696
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84697 - Mailpit SSRF Deny List Bypass via Azure Metadata and IPv6 Prefix

CVE ID :CVE-2026-84697
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in message content to reach the link check API and proxy endpoint for accessing internal resources.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84698 - PX4 Autopilot sd_bench Heap Buffer Overflow via Block Size

CVE ID :CVE-2026-84698
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially execute code or crash the system.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84699 - Team Password Manager before 14.184.308 Authentication Bypass in Password Reset

CVE ID :CVE-2026-84699
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84700 - Pika Unauthenticated Replication Access via Internal Protobuf Port

CVE ID :CVE-2026-84700
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates it; the frame dispatcher (DealMessage) does not require a completed or attempted MetaSync before routing other message types to their handlers. As a result, an unauthenticated remote attacker can connect directly to the replication port and issue TrySync, DBSync, BinlogSync, and RemoveSlaveNode requests, obtaining the full-sync snapshot and live write stream and removing replica nodes, even when requirepass is configured.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84701 - NocoBase Rich Text Field Stored Cross-Site Scripting via API

CVE ID :CVE-2026-84701
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers of all users viewing the affected record.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84702 - facefusion before 3.7.0 Path Traversal via Job Identifier

CVE ID :CVE-2026-84702
Published : Sept. 2, 2026, 1:17 a.m. | 2 hours, 52 minutes ago
Description :facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82968 - Keycloak-services: keycloak-services: cross-session email verification proof not bound to upstream identity for social providers

CVE ID :CVE-2026-82968
Published : Sept. 2, 2026, 2:17 a.m. | 1 hour, 53 minutes ago
Description :A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84431 - AirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRealPath path traversal

CVE ID :CVE-2026-84431
Published : Sept. 2, 2026, 2:17 a.m. | 1 hour, 52 minutes ago
Description :A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84437 - OpenCart Autocomplete Workflow address.php cross site scripting

CVE ID :CVE-2026-84437
Published : Sept. 2, 2026, 2:17 a.m. | 1 hour, 52 minutes ago
Description :A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manipulation of the argument address_1 results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84438 - OpenCart Autocomplete Workflow edit.php cross site scripting

CVE ID :CVE-2026-84438
Published : Sept. 2, 2026, 2:17 a.m. | 1 hour, 52 minutes ago
Description :A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete Workflow. This manipulation of the argument firstname causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84484 - ION-DTN before 4.2.0 Out-of-Bounds Read via decodeSdnv

CVE ID :CVE-2026-84484
Published : Sept. 2, 2026, 2:17 a.m. | 1 hour, 52 minutes ago
Description :ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...