CVE tracker
394 subscribers
5.73K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-97322 - YunaiV/zhijiantianya ruoyi-vue-pro File Upload FileController.java cross site scripting

CVE ID :CVE-2026-97322
Published : Sept. 24, 2026, 6:45 p.m. | 37 minutes ago
Description :A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the component File Upload. Performing a manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13016 - Unauthenticated SQL Injection in ServiceNow AI Platform

CVE ID :CVE-2026-13016
Published : Sept. 24, 2026, 6:48 p.m. | 33 minutes ago
Description :ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86859 - Unauthenticated Arbitrary Record Disclosure in ServiceNow AI Platform

CVE ID :CVE-2026-86859
Published : Sept. 24, 2026, 6:52 p.m. | 29 minutes ago
Description :ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling further unintended access. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81473 - Dell Rugged Control Center Improper Authorization Elevation of Privilege

CVE ID :CVE-2026-81473
Published : Sept. 24, 2026, 6:53 p.m. | 29 minutes ago
Description :Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-56792 - Dell Rugged Control Center Improper Authorization Elevation of Privilege

CVE ID :CVE-2026-56792
Published : Sept. 24, 2026, 6:56 p.m. | 25 minutes ago
Description :Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86860 - Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform

CVE ID :CVE-2026-86860
Published : Sept. 24, 2026, 6:56 p.m. | 25 minutes ago
Description :ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89325 - Rapid7 Insight Agent: Uncontrolled search path element in InsightVM assessment content leads to local privilege escalation

CVE ID :CVE-2026-89325
Published : Sept. 24, 2026, 6:58 p.m. | 24 minutes ago
Description :An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Assessment content at or below version 0.0.261.0 included a check that invoked the `code` command without a fully qualified path from a process running as SYSTEM. The command was resolved against the machine PATH environment variable at execution time. Where the machine PATH contained a directory writable by non-administrative users and ordered ahead of the legitimate Visual Studio Code installation, a local user could place an executable named `code` in that directory and cause the agent to execute it with SYSTEM privileges. The version range above refers to InsightVM assessment content versions, not Insight Agent versions. All Insight Agent versions were affected while running assessment content at or below 0.0.261.0. Assessment content is delivered to all Insight Agents via the Rapid7 Insight Platform independently of the Insight Agent version and is not customer-managed. This issue was resolved in assessment content version 0.0.269.0, which was made generally available on September 15, 2026. Remediation was deployed automatically and no customer action is required.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97323 - YunaiV/zhijiantianya ruoyi-vue-pro File Upload MpMaterialServiceImpl.java getOriginalFilename path traversal

CVE ID :CVE-2026-97323
Published : Sept. 24, 2026, 7 p.m. | 22 minutes ago
Description :A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java of the component File Upload. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14441 - Logic flaw in SANnav Java cache key handling object comparison handling

CVE ID :CVE-2026-14441
Published : Sept. 24, 2026, 9:17 p.m. | 2 hours, 6 minutes ago
Description :A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by updating the internal comparison routines to ensure accurate object evaluation and prevent potential identity mismatch conditions.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14442 - Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a

CVE ID :CVE-2026-14442
Published : Sept. 24, 2026, 9:17 p.m. | 2 hours, 6 minutes ago
Description :An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters including external server passwords and archive protection keys are logged without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, potentially leading to unauthorized access to remote backup targets or protected archives.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14443 - Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1a

CVE ID :CVE-2026-14443
Published : Sept. 24, 2026, 9:17 p.m. | 2 hours, 6 minutes ago
Description :Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75558 - Botslab G980H Dashcams Use of Hard-coded Cryptographic Key

CVE ID :CVE-2026-75558
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79959 - Botslab G980H Dashcams Use of Hard-coded Credentials

CVE ID :CVE-2026-79959
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81630 - Botslab G980H Dashcams Insufficient Verification of Data Authenticity

CVE ID :CVE-2026-81630
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82585 - Botslab G980H Dashcams Cleartext Transmission of Sensitive Information

CVE ID :CVE-2026-82585
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82708 - Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory

CVE ID :CVE-2026-82708
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82716 - Botslab G980H Dashcams Insertion of Sensitive Information into Log File

CVE ID :CVE-2026-82716
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84403 - Botslab G980H Dashcams Missing Authentication for Critical Function

CVE ID :CVE-2026-84403
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87118 - Botslab G980H Dashcams Out-of-bounds Write

CVE ID :CVE-2026-87118
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88386 - libsndfile Memory Misalignment Denial of Service

CVE ID :CVE-2026-88386
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cast an unaligned destination address to unsigned int * and perform a 4-byte store. This results in undefined behavior leading to denial of service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88387 - LibRaw Incorrect Numeric Conversion Denial of Service Vulnerability

CVE ID :CVE-2026-88387
Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 4 minutes ago
Description :LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can supply an attacker-controlled NewSubfileType value outside the range of a signed int. The parser converts this value and narrows it to int without performing range validation. This out-of-range conversion triggers undefined behavior, resulting in process termination and denial of service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...