CVE tracker
393 subscribers
5.77K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-77807 - AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter

CVE ID :CVE-2026-77807
Published : Sept. 10, 2026, 11:27 p.m. | 19 minutes ago
Description :The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires "Embed images" option in AcyMailing configuration being enabled.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84941 - Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read

CVE ID :CVE-2026-84941
Published : Sept. 10, 2026, 11:35 p.m. | 10 minutes ago
Description :An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78123 - strongSwan OpenSSL Plugin PKCS#7 Expired Pointer Dereference

CVE ID :CVE-2026-78123
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78124 - strongSwan OpenSSL Plugin Memory Leak Vulnerability

CVE ID :CVE-2026-78124
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78126 - strongSwan EAP-AKA Plugin NULL Pointer Dereference

CVE ID :CVE-2026-78126
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78127 - strongSwan libcharon Memory Leak

CVE ID :CVE-2026-78127
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78129 - strongSwan PKCS#5 Decryption Infinite Loop Denial of Service

CVE ID :CVE-2026-78129
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78130 - strongSwan X.509 Attribute Certificate Parser NULL Pointer Dereference

CVE ID :CVE-2026-78130
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78131 - strongSwan X.509 Plugin Memory Leak

CVE ID :CVE-2026-78131
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78132 - strongSwan x509 Plugin Infinite Loop Vulnerability

CVE ID :CVE-2026-78132
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78133 - strongSwan libcharon Use-After-Free Vulnerability

CVE ID :CVE-2026-78133
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78134 - strongSwan EAP-TTLS and EAP-PEAP Incorrect Access Control

CVE ID :CVE-2026-78134
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88914 - Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser

CVE ID :CVE-2026-88914
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89092 - Stack overflow in nscd due to unbounded alloca use

CVE ID :CVE-2026-89092
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name resolution, with the compromised DNS server being capable of processing records large enough to result in a stack overflow in an nscd thread stack.  During experimentation, bind 9 was unable to handle large records, but that could change in future or with a different name server.  In typical installations, nscd is executed in an isolated context as its own user without a shell, due to which any compromise of that service is isolated. There is a remote possibility of nscd cache corruption if an attacker manages to get the stack pointer into a desired point in the heap, potentially resulting in other caches in nscd being overwritten with corrupt data through the stack overflow, until the buggy code path eventually results in a crash. Finally, a crash in nscd may result in performance degradation when resolving names, but it does not result in a denial of service.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89145 - Flextype CMS 0.9.9 through 1.0.0-alpha.3 Stored XSS via Plugin Directory

CVE ID :CVE-2026-89145
Published : Sept. 11, 2026, 2:18 a.m. | 1 hour, 28 minutes ago
Description :Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers when dependency validation fails.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78135 - strongSwan libcharon IKEv2 Authentication Bypass

CVE ID :CVE-2026-78135
Published : Sept. 11, 2026, 3:16 a.m. | 30 minutes ago
Description :libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88260 - Brainzcompany Zenius EMS Authentication Bypass and Remote Code Inclusion

CVE ID :CVE-2026-88260
Published : Sept. 11, 2026, 3:16 a.m. | 30 minutes ago
Description :Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89151 - Forgejo API Token Unauthorized Privilege Escalation

CVE ID :CVE-2026-89151
Published : Sept. 11, 2026, 3:16 a.m. | 30 minutes ago
Description :Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73784 - HPE IceWall products, Remote Bypass of Security Restrictions

CVE ID :CVE-2026-73784
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73785 - HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability

CVE ID :CVE-2026-73785
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...