CVE tracker
394 subscribers
5.76K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-23787 - Samsung Exynos DRM HDR Driver Use-After-Free Vulnerability

CVE ID :CVE-2026-23787
Published : Sept. 14, 2026, 1:16 a.m. | 43 minutes ago
Description :An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90607 - Totolink A3002MU boa formNewSchedule buffer overflow

CVE ID :CVE-2026-90607
Published : Sept. 14, 2026, 1:16 a.m. | 43 minutes ago
Description :A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90608 - Totolink A3002MU boa formPortFw buffer overflow

CVE ID :CVE-2026-90608
Published : Sept. 14, 2026, 1:16 a.m. | 43 minutes ago
Description :A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90609 - GPAC MP4Box vrml_tools.c null pointer dereference

CVE ID :CVE-2026-90609
Published : Sept. 14, 2026, 1:16 a.m. | 43 minutes ago
Description :A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrml_tools.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90613 - GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion

CVE ID :CVE-2026-90613
Published : Sept. 14, 2026, 1:30 a.m. | 29 minutes ago
Description :A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24283 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24283
Published : Sept. 14, 2026, 4:16 a.m. | 1 hour, 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90621 - ipa-lab HackingBuddyGPT ssh_run_command.py ssh_run_command os command injection

CVE ID :CVE-2026-90621
Published : Sept. 14, 2026, 4:16 a.m. | 1 hour, 43 minutes ago
Description :A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90622 - GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference

CVE ID :CVE-2026-90622
Published : Sept. 14, 2026, 4:16 a.m. | 1 hour, 43 minutes ago
Description :A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.14 will fix this issue. The patch is named f5b548c4c1697d66c3dabd0f6a49280a14365a3a. The affected component should be upgraded. The FIELD_HANDLE macro itself is NULL-safe (emits null_handle) - only the two raw zeroing assignments added by 27118c40 ("encode: also disable LAYER.material") dereferenced a NULL material handle; the fix restores the file's existing if (_obj->style) guard convention for material.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90623 - andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validation

CVE ID :CVE-2026-90623
Published : Sept. 14, 2026, 4:16 a.m. | 1 hour, 43 minutes ago
Description :A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90680 - D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow

CVE ID :CVE-2026-90680
Published : Sept. 14, 2026, 4:16 a.m. | 1 hour, 43 minutes ago
Description :A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90685 - GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion

CVE ID :CVE-2026-90685
Published : Sept. 14, 2026, 5:15 a.m. | 45 minutes ago
Description :A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 can resolve this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. The affected component should be upgraded.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24284 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24284
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24285 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24285
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24286 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24286
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24287 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24287
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24288 - Portable Puzzle Collection Denial of Service Vulnerability

CVE ID :CVE-2023-24288
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24291 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24291
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-28148 - Paessler PRTG Cross-Site Scripting Vulnerability

CVE ID :CVE-2023-28148
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-29377 - Softing OPC UA SDK and Secure Integration Server Path Traversal Vulnerability

CVE ID :CVE-2023-29377
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-32778 - ILIAS Remote Code Execution via ZIP Upload

CVE ID :CVE-2023-32778
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-32803 - Amazon Linux ca-certificates Improper Certificate Revocation Vulnerability

CVE ID :CVE-2023-32803
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...