CVE tracker
394 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-90516 - SourceCodester School Registration and Fee System pay_report.php sql injection

CVE ID :CVE-2026-90516
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90517 - PHPGurukul Bank Locker Management System view-assign-locker.php authorization

CVE ID :CVE-2026-90517
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90518 - PHPGurukul Bank Locker Management System sidebar.php access control

CVE ID :CVE-2026-90518
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90775 - PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule Weight

CVE ID :CVE-2026-90775
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90776 - Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing

CVE ID :CVE-2026-90776
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90777 - ESPnet before 202609 Remote Code Execution via Unsafe Deserialization

CVE ID :CVE-2026-90777
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90778 - SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag

CVE ID :CVE-2026-90778
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90779 - SIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm Parameter

CVE ID :CVE-2026-90779
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90780 - SIPp through 3.7.7 Buffer Overflow via Oversized SIP Header Content

CVE ID :CVE-2026-90780
Published : Sept. 13, 2026, 12:17 p.m. | 1 hour, 41 minutes ago
Description :SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90523 - jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges management

CVE ID :CVE-2026-90523
Published : Sept. 13, 2026, 1:15 p.m. | 43 minutes ago
Description :A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90519 - PHPGurukul Bank Locker Management System add-locker-form.php unrestricted upload

CVE ID :CVE-2026-90519
Published : Sept. 13, 2026, 1:16 p.m. | 42 minutes ago
Description :A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90520 - jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationInterceptor.java improper authorization

CVE ID :CVE-2026-90520
Published : Sept. 13, 2026, 1:16 p.m. | 42 minutes ago
Description :A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90521 - jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization

CVE ID :CVE-2026-90521
Published : Sept. 13, 2026, 1:16 p.m. | 42 minutes ago
Description :A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The patch is identified as d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. It is best practice to apply a patch to resolve this issue.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90522 - jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass password recovery

CVE ID :CVE-2026-90522
Published : Sept. 13, 2026, 1:16 p.m. | 42 minutes ago
Description :A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90781 - alsa-lib through 1.2.16.1 Off-by-One Stack Buffer Overflow in __snd_ctl_ascii_elem_id_parse()

CVE ID :CVE-2026-90781
Published : Sept. 13, 2026, 1:16 p.m. | 42 minutes ago
Description :alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90782 - S2OPC through 1.7.3 NULL Pointer Dereference in alloc_notification_message_items()

CVE ID :CVE-2026-90782
Published : Sept. 13, 2026, 1:16 p.m. | 42 minutes ago
Description :S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90783 - MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound

CVE ID :CVE-2026-90783
Published : Sept. 13, 2026, 1:16 p.m. | 42 minutes ago
Description :MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90524 - jaychouchannel Tourism-Management-System Update Endpoint missing authentication

CVE ID :CVE-2026-90524
Published : Sept. 13, 2026, 1:30 p.m. | 28 minutes ago
Description :A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 84d8ec384f669df3985293dab293bb7b477efa64. It is suggested to install a patch to address this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90525 - itsourcecode Sales and Inventory System cust_pos_trans.php sql injection

CVE ID :CVE-2026-90525
Published : Sept. 13, 2026, 2:16 p.m. | 3 hours, 42 minutes ago
Description :A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90526 - SourceCodester School Registration and Fee System save_class.php sql injection

CVE ID :CVE-2026-90526
Published : Sept. 13, 2026, 2:16 p.m. | 3 hours, 42 minutes ago
Description :A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90527 - quequnlong shiyi-blog Add Message API index.vue cross site scripting

CVE ID :CVE-2026-90527
Published : Sept. 13, 2026, 3:16 p.m. | 2 hours, 42 minutes ago
Description :A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...