CVE tracker
394 subscribers
5.73K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-96279 - Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks

CVE ID :CVE-2026-96279
Published : Sept. 27, 2026, 8:16 p.m. | 1 hour, 9 minutes ago
Description :A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96280 - Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

CVE ID :CVE-2026-96280
Published : Sept. 27, 2026, 8:19 p.m. | 1 hour, 7 minutes ago
Description :The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100881 - zhistaredu StarTraining application.yml cross site scripting

CVE ID :CVE-2026-100881
Published : Sept. 27, 2026, 10:17 p.m. | 3 hours, 9 minutes ago
Description :A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross site scripting. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. Not independently exploitable: a defense-in-depth absence that amplifies CVE-2026-100880. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 2.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100882 - Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting

CVE ID :CVE-2026-100882
Published : Sept. 27, 2026, 10:17 p.m. | 3 hours, 9 minutes ago
Description :A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96282 - Flatpak: flatpak: extension metadata path traversal file existence oracle

CVE ID :CVE-2026-96282
Published : Sept. 27, 2026, 10:17 p.m. | 3 hours, 9 minutes ago
Description :A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96283 - Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull

CVE ID :CVE-2026-96283
Published : Sept. 27, 2026, 10:17 p.m. | 3 hours, 9 minutes ago
Description :By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100883 - Krayin laravel-crm acl.php access control

CVE ID :CVE-2026-100883
Published : Sept. 27, 2026, 11:16 p.m. | 2 hours, 9 minutes ago
Description :A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been published and may be used. Upgrading to version 2.2.6 is sufficient to fix this issue. This patch is called a399404a388d8ad2700a01349d0d98069c8e85a4. The affected component should be upgraded.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100884 - Krayin laravel-crm attachment-download Endpoint acl.php resource injection

CVE ID :CVE-2026-100884
Published : Sept. 27, 2026, 11:16 p.m. | 2 hours, 9 minutes ago
Description :A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100885 - Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization

CVE ID :CVE-2026-100885
Published : Sept. 27, 2026, 11:16 p.m. | 2 hours, 9 minutes ago
Description :A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this issue. The patch is identified as 89f2916b6a46ff91bd1999ce38158fa0de8b9490. Upgrading the affected component is recommended.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100886 - Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication

CVE ID :CVE-2026-100886
Published : Sept. 27, 2026, 11:16 p.m. | 2 hours, 9 minutes ago
Description :A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96284 - Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following

CVE ID :CVE-2026-96284
Published : Sept. 27, 2026, 11:17 p.m. | 2 hours, 9 minutes ago
Description :A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
Severity: 2.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100890 - Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode null pointer dereference

CVE ID :CVE-2026-100890
Published : Sept. 28, 2026, midnight | 1 hour, 26 minutes ago
Description :A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100891 - Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmarc_policy_query_dmarc encoding error

CVE ID :CVE-2026-100891
Published : Sept. 28, 2026, 12:15 a.m. | 1 hour, 11 minutes ago
Description :A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100887 - amirsanni Mini-Inventory-and-Sales-Management-System Database Query Builder DB_query_builder.php order_by sql injection

CVE ID :CVE-2026-100887
Published : Sept. 28, 2026, 12:16 a.m. | 1 hour, 9 minutes ago
Description :A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder. Performing a manipulation of the argument orderBy results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project maintainer confirms: "I stopped maintaining that project for a while now, so I'm not sure it's worth fixing." This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100888 - Trusted Domain Project OpenDKIM DKIM Signature Header Selection dkim-canon.c dkim_canon_selecthdrs out-of-bounds write

CVE ID :CVE-2026-100888
Published : Sept. 28, 2026, 12:16 a.m. | 1 hour, 9 minutes ago
Description :A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100889 - Trusted Domain Project OpenDKIM Decoder util.c dkim_qp_decode off-by-one

CVE ID :CVE-2026-100889
Published : Sept. 28, 2026, 12:16 a.m. | 1 hour, 9 minutes ago
Description :A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100892 - aligungr UERANSIM nr-gnb handler.cpp ULInformationTransfer memory corruption

CVE ID :CVE-2026-100892
Published : Sept. 28, 2026, 12:30 a.m. | 56 minutes ago
Description :A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a manipulation of the argument dedicatedNASMessage results in memory corruption. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100893 - Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery

CVE ID :CVE-2026-100893
Published : Sept. 28, 2026, 2:17 a.m. | 3 hours, 9 minutes ago
Description :A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100894 - mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection

CVE ID :CVE-2026-100894
Published : Sept. 28, 2026, 2:17 a.m. | 3 hours, 9 minutes ago
Description :A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100895 - Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereference

CVE ID :CVE-2026-100895
Published : Sept. 28, 2026, 2:17 a.m. | 3 hours, 9 minutes ago
Description :A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100896 - TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection

CVE ID :CVE-2026-100896
Published : Sept. 28, 2026, 2:17 a.m. | 3 hours, 9 minutes ago
Description :A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...