CVE tracker
394 subscribers
5.73K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-93308 - O-RAN-SC SMO OAM VES Collector allocation of resources

CVE ID :CVE-2026-93308
Published : Sept. 18, 2026, 12:17 a.m. | 2 hours, 2 minutes ago
Description :A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through a bug report but has not responded yet.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93309 - O-RAN-SC SMO OAM VES Collector allocation of resources

CVE ID :CVE-2026-93309
Published : Sept. 18, 2026, 12:17 a.m. | 2 hours, 2 minutes ago
Description :A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93450 - go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal

CVE ID :CVE-2026-93450
Published : Sept. 18, 2026, 12:17 a.m. | 2 hours, 2 minutes ago
Description :go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93451 - snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods

CVE ID :CVE-2026-93451
Published : Sept. 18, 2026, 12:17 a.m. | 2 hours, 2 minutes ago
Description :snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Attackers controlling compressed input can cause misaligned length values to write past array bounds with attacker-controlled bytes, corrupting heap memory.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93452 - snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress

CVE ID :CVE-2026-93452
Published : Sept. 18, 2026, 12:17 a.m. | 2 hours, 2 minutes ago
Description :snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93453 - SOGo before 5.12.11 Password Reset Token Interception via Origin Header

CVE ID :CVE-2026-93453
Published : Sept. 18, 2026, 12:17 a.m. | 2 hours, 2 minutes ago
Description :SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93454 - Aureus ERP through 1.6.0 Stored XSS via Payment Term Note

CVE ID :CVE-2026-93454
Published : Sept. 18, 2026, 12:17 a.m. | 2 hours, 2 minutes ago
Description :Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93313 - Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow

CVE ID :CVE-2026-93313
Published : Sept. 18, 2026, 1:15 a.m. | 1 hour, 4 minutes ago
Description :A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named eb87cf711563894649bd0c365baa479401dc6d51. To fix this issue, it is recommended to deploy a patch.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79954 - NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID

CVE ID :CVE-2026-79954
Published : Sept. 18, 2026, 1:16 a.m. | 1 hour, 3 minutes ago
Description :NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93310 - O-RAN-SC SMO OAM VES Collector allocation of resources

CVE ID :CVE-2026-93310
Published : Sept. 18, 2026, 1:16 a.m. | 1 hour, 3 minutes ago
Description :A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through a bug report but has not responded yet.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93311 - Freedesktop Poppler SampledFunction Function.cc integer overflow

CVE ID :CVE-2026-93311
Published : Sept. 18, 2026, 1:16 a.m. | 1 hour, 3 minutes ago
Description :A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSample results in integer overflow. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93312 - Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference

CVE ID :CVE-2026-93312
Published : Sept. 18, 2026, 1:16 a.m. | 1 hour, 3 minutes ago
Description :A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93455 - django-page-cms through 2.0.13 Unauthorized Content Access via Staff Account

CVE ID :CVE-2026-93455
Published : Sept. 18, 2026, 1:24 a.m. | 55 minutes ago
Description :django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumerate content identifiers and access unpublished drafts, page listings, and file paths without proper authorization checks.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93456 - django-page-cms through 2.0.13 CSRF via admin mutation views

CVE ID :CVE-2026-93456
Published : Sept. 18, 2026, 1:24 a.m. | 55 minutes ago
Description :django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82980 - Nextcloud DAV Plugin Improper Authorization Vulnerability

CVE ID :CVE-2026-82980
Published : Sept. 18, 2026, 1:26 a.m. | 53 minutes ago
Description :Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authenticated session user. This enables: Cross-user manual locks : attacker locks a victim's files, blocking writes (PUT/MOVE/DELETE, editor saves). Lock-token disclosure: the app returns the lock token to unauthorized callers, enabling them to remove token-based locks (client locks) of other users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77169 - Nextcloud Team Folders Authorization Bypass

CVE ID :CVE-2026-77169
Published : Sept. 18, 2026, 1:26 a.m. | 53 minutes ago
Description :A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82982 - Approval App Insecure Direct Object Reference Vulnerability

CVE ID :CVE-2026-82982
Published : Sept. 18, 2026, 1:26 a.m. | 53 minutes ago
Description :The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An attacker able to intercept and modify the approval request could omit the etag field entirely, bypassing the freshness check and approving or rejecting a file version they never reviewed.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77170 - Deck API Unauthorized Configuration Modification Vulnerability

CVE ID :CVE-2026-77170
Published : Sept. 18, 2026, 1:26 a.m. | 53 minutes ago
Description :The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77164 - Nextcloud Circles Server-Side Request Forgery

CVE ID :CVE-2026-77164
Published : Sept. 18, 2026, 1:26 a.m. | 53 minutes ago
Description :Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. The public, unauthenticated endpoints POST /apps/circles/event/ and POST /apps/circles/incoming/ reach this code path, allowing any unauthenticated user to force the server to issue a GET request to an internal address. The response body of the internal request is never returned to the requester, so this is blind SSRF: an attacker can determine whether an internal service is reachable, but cannot read its response contents through this endpoint alone.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82985 - Photos App Improper Access Control via Smart Album Metadata Disclosure

CVE ID :CVE-2026-82985
Published : Sept. 18, 2026, 1:26 a.m. | 53 minutes ago
Description :The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with another user, that user's own folder configuration is used to determine which of the owner's files are searched — allowing them to discover files (name, file ID, and other metadata) in folders the album owner never intended to include in the shared album. This requires the album owner to have shared a filter-based smart album with the attacker; it does not allow access to arbitrary users' files without such a share.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68493 - Insecure Direct Object Reference in Membership Retrieval

CVE ID :CVE-2026-68493
Published : Sept. 18, 2026, 1:26 a.m. | 53 minutes ago
Description :After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...