CVE tracker
386 subscribers
5.48K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-20504 - Modem System Denial of Service Vulnerability

CVE ID :CVE-2026-20504
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20506 - Audio HAL Use-After-Free Privilege Escalation

CVE ID :CVE-2026-20506
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9126.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20507 - Audio HAL Use-After-Free Privilege Escalation

CVE ID :CVE-2026-20507
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9125.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20508 - Power HAL Type Confusion Vulnerability

CVE ID :CVE-2026-20508
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9012.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20509 - Power HAL Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20509
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9011.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20510 - Camera Middleware Double Free Privilege Escalation

CVE ID :CVE-2026-20510
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11134622; Issue ID: MSV-8894.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20511 - SurfaceFlinger Use-After-Free Vulnerability

CVE ID :CVE-2026-20511
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID: MSV-8890.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20512 - Audio HAL Improper Input Validation Privilege Escalation

CVE ID :CVE-2026-20512
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20513 - Audio HAL Information Disclosure Vulnerability

CVE ID :CVE-2026-20513
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533; Issue ID: MSV-8245.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20514 - Audio HAL Information Disclosure

CVE ID :CVE-2026-20514
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087632; Issue ID: MSV-8244.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20515 - GPU Use-After-Free Vulnerability

CVE ID :CVE-2026-20515
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20516 - MiracastService Privilege Escalation

CVE ID :CVE-2026-20516
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20517 - Geniezone Use-After-Free Privilege Escalation

CVE ID :CVE-2026-20517
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID: MSV-6781.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20518 - Geniezone Information Disclosure Vulnerability

CVE ID :CVE-2026-20518
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10867524 / ALPS10876355; Issue ID: MSV-6674.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86239 - liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload

CVE ID :CVE-2026-86239
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86240 - liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery

CVE ID :CVE-2026-86240
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. The manipulation of the argument source[] results in server-side request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86241 - liufee FeehiCMS Cookie Validation main-local.php hard-coded key

CVE ID :CVE-2026-86241
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the argument cookieValidationKey causes use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86244 - FastAdmin User Controller User.php login cross site scripting

CVE ID :CVE-2026-86244
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. Such manipulation of the argument url leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 1.2.1.20210731_beta is able to address this issue. The name of the patch is b3d32e2bf3637488cfe2fc58a27a9d2475b2b51b. It is recommended to upgrade the affected component.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86245 - itsourcecode Sales and Inventory System sup_transac.php sql injection

CVE ID :CVE-2026-86245
Published : Sept. 7, 2026, 2:17 a.m. | 1 hour, 4 minutes ago
Description :A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument companyname results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86314 - Samsung Walrus Integer Overflow Vulnerability

CVE ID :CVE-2026-86314
Published : Sept. 7, 2026, 2:22 a.m. | 59 minutes ago
Description :Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check. This issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86262 - sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization

CVE ID :CVE-2026-86262
Published : Sept. 7, 2026, 2:30 a.m. | 51 minutes ago
Description :A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler. The manipulation of the argument userID/id leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...