CVE tracker
394 subscribers
5.74K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-88259 - CareCam CM2507 Missing Authentication for Critical Function

CVE ID :CVE-2026-88259
Published : Sept. 18, 2026, 4:05 p.m. | 17 minutes ago
Description :CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10841 - Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.

CVE ID :CVE-2026-10841
Published : Sept. 18, 2026, 4:06 p.m. | 16 minutes ago
Description :IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68914 - Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data

CVE ID :CVE-2026-68914
Published : Sept. 18, 2026, 4:07 p.m. | 15 minutes ago
Description :Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable or MOJO_NO_JSON_XS is enabled. An attacker who can supply untrusted JSON to decode_json, from_json, or j can submit deeply nested arrays or objects, causing unbounded recursion, memory exhaustion, and a process crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in version 9.47.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10853 - IBM MQ queue manager is vulnerable to remote code execution

CVE ID :CVE-2026-10853
Published : Sept. 18, 2026, 4:07 p.m. | 15 minutes ago
Description :IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84398 - CareCam CM2507 Empty Password in Configuration File

CVE ID :CVE-2026-84398
Published : Sept. 18, 2026, 4:07 p.m. | 15 minutes ago
Description :CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10858 - IBM MQ for HPE NonStop is vulnerable to a denial of service attack

CVE ID :CVE-2026-10858
Published : Sept. 18, 2026, 4:08 p.m. | 14 minutes ago
Description :IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77568 - Mojolicious: CSRF tokens are vulnerable to BREACH attacks

CVE ID :CVE-2026-77568
Published : Sept. 18, 2026, 4:08 p.m. | 14 minutes ago
Description :Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, and csrf_protect reuse an unchanged per-session token in rendered HTML. When response compression is enabled and attacker-influenced content is reflected in the same response, an unauthenticated attacker who can induce many victim requests and observe response sizes can use a BREACH compression side channel to recover the token and forge cross-site requests. API-only deployments that never render the token in HTML are not affected. This issue is fixed in version 9.48.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11375 - IBM MQ queue manager is vulnerable to remote code execution

CVE ID :CVE-2026-11375
Published : Sept. 18, 2026, 4:09 p.m. | 13 minutes ago
Description :IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61682 - Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes

CVE ID :CVE-2025-61682
Published : Sept. 18, 2026, 4:09 p.m. | 13 minutes ago
Description :Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11378 - IBM MQ queue manager is vulnerable to remote code execution

CVE ID :CVE-2026-11378
Published : Sept. 18, 2026, 4:09 p.m. | 13 minutes ago
Description :IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11381 - IBM MQ for HPE NonStop is vulnerable to a denial of service issue

CVE ID :CVE-2026-11381
Published : Sept. 18, 2026, 4:09 p.m. | 13 minutes ago
Description :IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54148 - http4k: `DigestAuthProvider.verify` did not bind to request URI

CVE ID :CVE-2026-54148
Published : Sept. 18, 2026, 4:09 p.m. | 13 minutes ago
Description :http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication response can replay it against another URL served by the same realm, bypassing the per-request-URI binding and potentially gaining unauthorized read or write access. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84400 - CareCam CM2507 Missing Authentication for Critical Function

CVE ID :CVE-2026-84400
Published : Sept. 18, 2026, 4:10 p.m. | 12 minutes ago
Description :CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11537 - IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities

CVE ID :CVE-2026-11537
Published : Sept. 18, 2026, 4:10 p.m. | 12 minutes ago
Description :IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54147 - http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI

CVE ID :CVE-2026-54147
Published : Sept. 18, 2026, 4:10 p.m. | 12 minutes ago
Description :http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker MD5-based verification, exposing Digest authentication to collision-related attack paths that depend on the hash function's collision resistance. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-61682 - kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace

CVE ID :CVE-2026-61682
Published : Sept. 18, 2026, 4:11 p.m. | 11 minutes ago
Description :kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81305 - CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere

CVE ID :CVE-2026-81305
Published : Sept. 18, 2026, 4:12 p.m. | 10 minutes ago
Description :CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected device.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84106 - IBM Guardium Data Protection is affected by multiple vulnerabilities.

CVE ID :CVE-2026-84106
Published : Sept. 18, 2026, 7:52 p.m. | 30 minutes ago
Description :IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Severity: 8.9 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84108 - IBM Guardium Data Protection is affected by multiple vulnerabilities.

CVE ID :CVE-2026-84108
Published : Sept. 18, 2026, 7:52 p.m. | 30 minutes ago
Description :IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84241 - IBM Guardium Data Protection is affected by multiple vulnerabilities.

CVE ID :CVE-2026-84241
Published : Sept. 18, 2026, 7:53 p.m. | 30 minutes ago
Description :IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63647 - CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`

CVE ID :CVE-2026-63647
Published : Sept. 18, 2026, 7:53 p.m. | 29 minutes ago
Description :CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...