CVE tracker
393 subscribers
5.77K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-90623 - andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validation

CVE ID :CVE-2026-90623
Published : Sept. 14, 2026, 4:16 a.m. | 1 hour, 43 minutes ago
Description :A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90680 - D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow

CVE ID :CVE-2026-90680
Published : Sept. 14, 2026, 4:16 a.m. | 1 hour, 43 minutes ago
Description :A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90685 - GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion

CVE ID :CVE-2026-90685
Published : Sept. 14, 2026, 5:15 a.m. | 45 minutes ago
Description :A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 can resolve this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. The affected component should be upgraded.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24284 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24284
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24285 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24285
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24286 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24286
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24287 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24287
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24288 - Portable Puzzle Collection Denial of Service Vulnerability

CVE ID :CVE-2023-24288
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-24291 - Portable Puzzle Collection Buffer Overflow

CVE ID :CVE-2023-24291
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-28148 - Paessler PRTG Cross-Site Scripting Vulnerability

CVE ID :CVE-2023-28148
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-29377 - Softing OPC UA SDK and Secure Integration Server Path Traversal Vulnerability

CVE ID :CVE-2023-29377
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-32778 - ILIAS Remote Code Execution via ZIP Upload

CVE ID :CVE-2023-32778
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-32803 - Amazon Linux ca-certificates Improper Certificate Revocation Vulnerability

CVE ID :CVE-2023-32803
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-34854 - HotelDruid Unrestricted File Upload Vulnerability

CVE ID :CVE-2023-34854
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-37252 - MediaWiki CheckUser Extension Information Disclosure Vulnerability

CVE ID :CVE-2023-37252
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90681 - Matthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-bounds

CVE ID :CVE-2026-90681
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90682 - Matthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflow

CVE ID :CVE-2026-90682
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90683 - GPAC MP4Box base_scenegraph.c gf_node_unregister assertion

CVE ID :CVE-2026-90683
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version abi-16.23 is able to address this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component. This is not a duplicate of CVE-2021-46237 or CVE-2021-46234.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90684 - GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion

CVE ID :CVE-2026-90684
Published : Sept. 14, 2026, 5:16 a.m. | 43 minutes ago
Description :A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Severity: 2.8 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90686 - GPAC MP4Box loader_bt.c gf_bt_report memory corruption

CVE ID :CVE-2026-90686
Published : Sept. 14, 2026, 5:30 a.m. | 29 minutes ago
Description :A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version abi-16.23 is able to mitigate this issue. The patch is identified as afca1f1181668d85941d51ed1adf647807d5d975. It is suggested to upgrade the affected component.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90687 - GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after free

CVE ID :CVE-2026-90687
Published : Sept. 14, 2026, 5:45 a.m. | 15 minutes ago
Description :A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is able to resolve this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is recommended.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...