CVE tracker
395 subscribers
5.73K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-101059 - utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass

CVE ID :CVE-2026-101059
Published : Sept. 27, 2026, 6:16 p.m. | 3 hours, 9 minutes ago
Description :utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library POSTs the victim's client_id and client_secret to the attacker-supplied token endpoint without URL validation.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101060 - python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects

CVE ID :CVE-2026-101060
Published : Sept. 27, 2026, 6:16 p.m. | 3 hours, 9 minutes ago
Description :python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and return their response bodies to the caller.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101061 - utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass

CVE ID :CVE-2026-101061
Published : Sept. 27, 2026, 6:16 p.m. | 3 hours, 9 minutes ago
Description :utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin performs no URL validation despite documented security requirements. Attackers can force connections to internal services and cloud metadata endpoints by supplying malicious tool URLs in call templates, and receive configured API keys and OAuth tokens sent to attacker-controlled hosts.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100873 - mathurvishal CloudClassroom-PHP-Project cross-site request forgery

CVE ID :CVE-2026-100873
Published : Sept. 27, 2026, 7:16 p.m. | 2 hours, 9 minutes ago
Description :A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100874 - mathurvishal CloudClassroom-PHP-Project addnewstudent.php sql injection

CVE ID :CVE-2026-100874
Published : Sept. 27, 2026, 7:16 p.m. | 2 hours, 9 minutes ago
Description :A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file addnewstudent.php. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100875 - mathurvishal CloudClassroom-PHP-Project updatedetailsfromfaculty.php sql injection

CVE ID :CVE-2026-100875
Published : Sept. 27, 2026, 7:16 p.m. | 2 hours, 9 minutes ago
Description :A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromfaculty.php. Such manipulation of the argument myfid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100877 - mathurvishal CloudClassroom-PHP-Project registrationform.php cross site scripting

CVE ID :CVE-2026-100877
Published : Sept. 27, 2026, 8:15 p.m. | 1 hour, 11 minutes ago
Description :A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file registrationform.php. Executing a manipulation of the argument FName/LName/Addrs can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100876 - mathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authentication

CVE ID :CVE-2026-100876
Published : Sept. 27, 2026, 8:16 p.m. | 1 hour, 9 minutes ago
Description :A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument umail results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96279 - Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks

CVE ID :CVE-2026-96279
Published : Sept. 27, 2026, 8:16 p.m. | 1 hour, 9 minutes ago
Description :A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96280 - Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

CVE ID :CVE-2026-96280
Published : Sept. 27, 2026, 8:19 p.m. | 1 hour, 7 minutes ago
Description :The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100881 - zhistaredu StarTraining application.yml cross site scripting

CVE ID :CVE-2026-100881
Published : Sept. 27, 2026, 10:17 p.m. | 3 hours, 9 minutes ago
Description :A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross site scripting. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. Not independently exploitable: a defense-in-depth absence that amplifies CVE-2026-100880. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 2.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100882 - Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting

CVE ID :CVE-2026-100882
Published : Sept. 27, 2026, 10:17 p.m. | 3 hours, 9 minutes ago
Description :A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96282 - Flatpak: flatpak: extension metadata path traversal file existence oracle

CVE ID :CVE-2026-96282
Published : Sept. 27, 2026, 10:17 p.m. | 3 hours, 9 minutes ago
Description :A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96283 - Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull

CVE ID :CVE-2026-96283
Published : Sept. 27, 2026, 10:17 p.m. | 3 hours, 9 minutes ago
Description :By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100883 - Krayin laravel-crm acl.php access control

CVE ID :CVE-2026-100883
Published : Sept. 27, 2026, 11:16 p.m. | 2 hours, 9 minutes ago
Description :A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been published and may be used. Upgrading to version 2.2.6 is sufficient to fix this issue. This patch is called a399404a388d8ad2700a01349d0d98069c8e85a4. The affected component should be upgraded.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100884 - Krayin laravel-crm attachment-download Endpoint acl.php resource injection

CVE ID :CVE-2026-100884
Published : Sept. 27, 2026, 11:16 p.m. | 2 hours, 9 minutes ago
Description :A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100885 - Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization

CVE ID :CVE-2026-100885
Published : Sept. 27, 2026, 11:16 p.m. | 2 hours, 9 minutes ago
Description :A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this issue. The patch is identified as 89f2916b6a46ff91bd1999ce38158fa0de8b9490. Upgrading the affected component is recommended.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100886 - Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication

CVE ID :CVE-2026-100886
Published : Sept. 27, 2026, 11:16 p.m. | 2 hours, 9 minutes ago
Description :A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96284 - Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following

CVE ID :CVE-2026-96284
Published : Sept. 27, 2026, 11:17 p.m. | 2 hours, 9 minutes ago
Description :A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
Severity: 2.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100890 - Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode null pointer dereference

CVE ID :CVE-2026-100890
Published : Sept. 28, 2026, midnight | 1 hour, 26 minutes ago
Description :A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100891 - Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmarc_policy_query_dmarc encoding error

CVE ID :CVE-2026-100891
Published : Sept. 28, 2026, 12:15 a.m. | 1 hour, 11 minutes ago
Description :A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...