CVE tracker
385 subscribers
5.43K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-85092 - LiME Arbitrary File Overwrite Vulnerability

CVE ID :CVE-2026-85092
Published : Sept. 3, 2026, 2:20 a.m. | 1 hour, 54 minutes ago
Description :LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged local users to overwrite arbitrary root-owned files. An attacker who controls the output directory can create a symbolic link with the expected filename pointing to any root-owned file, and when the acquisition runs in kernel context, LiME follows the link and truncates the target file with the memory acquisition stream.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85093 - Cheshire Cat AI Memory Access Control Bypass

CVE ID :CVE-2026-85093
Published : Sept. 3, 2026, 2:20 a.m. | 1 hour, 54 minutes ago
Description :Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by paginating through the collection using the offset cursor.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2021-43614 - UEFI PlatformLangCodes Buffer Overflow

CVE ID :CVE-2021-43614
Published : Sept. 3, 2026, 3:35 a.m. | 39 minutes ago
Description :Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2021-43613 - Insyde InsydeH2O SysPasswordDxe Information Disclosure Vulnerability

CVE ID :CVE-2021-43613
Published : Sept. 3, 2026, 3:35 a.m. | 39 minutes ago
Description :An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85031 - TOTOLINK CP450 Buffer Overflow Vulnerability

CVE ID :CVE-2026-85031
Published : Sept. 3, 2026, 3:35 a.m. | 39 minutes ago
Description :A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2021-38489 - UEFI Firmware HDD Password Plaintext Exposure

CVE ID :CVE-2021-38489
Published : Sept. 3, 2026, 3:35 a.m. | 39 minutes ago
Description :HDD password plaintext is stored in a UEFI variable.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85040 - ZhongBangKeJi CRMEB OS Command Injection Vulnerability

CVE ID :CVE-2026-85040
Published : Sept. 3, 2026, 3:35 a.m. | 39 minutes ago
Description :A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval of the file /adminapi/system/crontab/save of the component Custom Scheduled Task Feature. This manipulation of the argument customCode causes os command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Vendor documents this as deliberate debug-only behavior. But isSafePhpCode blacklist offers no real RCE containment.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2573 - GutenKit <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss'

CVE ID :CVE-2026-2573
Published : Sept. 3, 2026, 4:29 a.m. | 3 hours, 46 minutes ago
Description :The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postBodyCss’ parameter in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85156 - WWBN AVideo Broken Access Control via Channel Page

CVE ID :CVE-2026-85156
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can access the channel endpoint to retrieve sensitive video content that should be hidden, including full URLs to unlisted videos and thumbnails of member-only content, regardless of the operator's hidePrivateVideos setting.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85157 - WWBN AVideo Broken Access Control via feed/index.php program_id

CVE ID :CVE-2026-85157
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers can enumerate playlist identifiers and retrieve unlisted and group-restricted videos by requesting the RSS feed with any visible playlist id, including empty playlists that return the entire site's hidden video catalogue.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85158 - AVideo Reflected XSS via videoEmbeded.php link parameter

CVE ID :CVE-2026-85158
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero escaping. Attackers can close the comment with --> and inject arbitrary JavaScript that executes when victims visit the crafted embed URL.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85159 - AVideo Reflected XSS via cancelUri in userLogin.php

CVE ID :CVE-2026-85159
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unauthenticated attackers can inject event handlers via relative URLs with embedded quotes to execute arbitrary JavaScript when users interact with the Cancel button.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85160 - AVideo through c91b5975d CSRF and Path Traversal via stopLive.php

CVE ID :CVE-2026-85160
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visits a malicious page.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85161 - AVideo removePoster.php Cross-Site Request Forgery File Deletion

CVE ID :CVE-2026-85161
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster and thumbnail files via GET requests.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85162 - AVideo through c91b5975d CSRF via saveLive.php

CVE ID :CVE-2026-85162
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft malicious image tags to overwrite authenticated streamers' RTMP keys, passwords, and titles, hijacking live broadcasts.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85163 - AVideo Server-Side Request Forgery via epg_link parameter

CVE ID :CVE-2026-85163
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter during video upload, which is validated only for syntax and later fetched server-side during EPG generation without SSRF protection checks.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85164 - WWBN AVideo Server-Side Request Forgery via set_api_userImages

CVE ID :CVE-2026-85164
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply internal URLs to fetch cloud metadata or internal services, with responses written to publicly accessible web paths for retrieval.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85165 - n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement

CVE ID :CVE-2026-85165
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85166 - n8n before 2.36.2 Credential Exfiltration via Workflow Tool Node

CVE ID :CVE-2026-85166
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/updating a workflow via the REST API, Public API, or MCP, can persist a node referencing a credential they do not own. When the workflow is later executed under an identity that holds the credential, the inline sub-workflow resolves the secret and can send it to an attacker-controlled endpoint, resulting in credential exfiltration.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85167 - n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes

CVE ID :CVE-2026-85167
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression values directly into the query string before parsing. A value containing quote and brace characters can close the intended field and introduce new query operators, turning an intended single-document lookup into a full-collection read.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85168 - n8n before 1.123.73 Remote Code Execution via Git Node

CVE ID :CVE-2026-85168
Published : Sept. 3, 2026, 11:22 a.m. | 54 minutes ago
Description :n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the content-filter and merge-driver key families. A repository with local configuration setting one of those keys together with a matching attribute pattern causes git to execute the configured command during an ordinary Add, Commit, Checkout, or Pull operation. The command runs as the n8n process user.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...