CVE tracker
394 subscribers
5.76K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-90503 - Chengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information disclosure

CVE ID :CVE-2026-90503
Published : Sept. 13, 2026, 9:16 a.m. | 41 minutes ago
Description :A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90507 - vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control

CVE ID :CVE-2026-90507
Published : Sept. 13, 2026, 9:30 a.m. | 27 minutes ago
Description :A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90769 - Open Notebook before 1.11.0 Server-Side Request Forgery via link-source

CVE ID :CVE-2026-90769
Published : Sept. 13, 2026, 11:17 a.m. | 2 hours, 41 minutes ago
Description :Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90770 - Spug through 3.4.0 Remote Code Execution via ping_check

CVE ID :CVE-2026-90770
Published : Sept. 13, 2026, 11:17 a.m. | 2 hours, 41 minutes ago
Description :Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90771 - joi before 17.13.8 and 18.2.9 Prototype Pollution via messages

CVE ID :CVE-2026-90771
Published : Sept. 13, 2026, 11:17 a.m. | 2 hours, 41 minutes ago
Description :joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90772 - Amundsen Frontend through 4.3.0 Stored XSS via Description

CVE ID :CVE-2026-90772
Published : Sept. 13, 2026, 11:17 a.m. | 2 hours, 41 minutes ago
Description :Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90773 - procs through 0.14.12 Terminal Escape Sequence Injection via Command

CVE ID :CVE-2026-90773
Published : Sept. 13, 2026, 11:17 a.m. | 2 hours, 41 minutes ago
Description :procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to other users' terminals for interpretation by terminal emulators.
Severity: 3.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90774 - rustypaste before 0.18.1 Path Traversal via filename header

CVE ID :CVE-2026-90774
Published : Sept. 13, 2026, 11:17 a.m. | 2 hours, 41 minutes ago
Description :rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90515 - SourceCodester School Registration and Fee System delete_stud.php sql injection

CVE ID :CVE-2026-90515
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90516 - SourceCodester School Registration and Fee System pay_report.php sql injection

CVE ID :CVE-2026-90516
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90517 - PHPGurukul Bank Locker Management System view-assign-locker.php authorization

CVE ID :CVE-2026-90517
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90518 - PHPGurukul Bank Locker Management System sidebar.php access control

CVE ID :CVE-2026-90518
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90775 - PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule Weight

CVE ID :CVE-2026-90775
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90776 - Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing

CVE ID :CVE-2026-90776
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90777 - ESPnet before 202609 Remote Code Execution via Unsafe Deserialization

CVE ID :CVE-2026-90777
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90778 - SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag

CVE ID :CVE-2026-90778
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90779 - SIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm Parameter

CVE ID :CVE-2026-90779
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90780 - SIPp through 3.7.7 Buffer Overflow via Oversized SIP Header Content

CVE ID :CVE-2026-90780
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90523 - jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges management

CVE ID :CVE-2026-90523
Published : Sept. 13, 2026, 1:15 p.m. | 43 minutes ago
Description :A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90519 - PHPGurukul Bank Locker Management System add-locker-form.php unrestricted upload

CVE ID :CVE-2026-90519
Published : Sept. 13, 2026, 1:16 p.m. | 42 minutes ago
Description :A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90520 - jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationInterceptor.java improper authorization

CVE ID :CVE-2026-90520
Published : Sept. 13, 2026, 1:16 p.m. | 42 minutes ago
Description :A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...