CVE tracker
394 subscribers
5.74K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-102425 - Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4

CVE ID :CVE-2026-102425
Published : Sept. 29, 2026, 5:04 p.m. | 22 minutes ago
Description :Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component replaces each shortcode with the raw value submitted by the visitor, leading to an RCE vector. A public form must use the product's optional PHP-after-submission action and interpolate an attacker-controlled field shortcode inside a double-quoted PHP string to be vulnerable.
Severity: 9.5 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102623 - Kubevirt: kubevirt: virt-controller nil-pointer dereference via malformed ephemeral volume

CVE ID :CVE-2026-102623
Published : Sept. 29, 2026, 5:06 p.m. | 21 minutes ago
Description :A flaw was found in KubeVirt. An authenticated user with permission to create Virtual Machine Instances (VMIs) can cause a Denial of Service (DoS) by submitting a virtual machine definition with an empty ephemeral volume. The virt-controller component fails to properly validate the volume configuration, leading to an unhandled exception and application crash during processing. Because the malformed definition persists in the cluster, the controller enters a continuous crash loop, disrupting virtual machine lifecycle operations across the entire environment.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102424 - Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4

CVE ID :CVE-2026-102424
Published : Sept. 29, 2026, 5:07 p.m. | 19 minutes ago
Description :Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal “auto reply” and “attach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.
Severity: 8.9 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76735 - Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On

CVE ID :CVE-2026-76735
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.
Severity: 4.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76736 - Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On

CVE ID :CVE-2026-76736
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76737 - Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On

CVE ID :CVE-2026-76737
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
Severity: 3.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76738 - Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service

CVE ID :CVE-2026-76738
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79348 - KitchenAsty Broken Object Level Authorization Vulnerability

CVE ID :CVE-2026-79348
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79403 - Kilo Code Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-79403
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79417 - ArgusMonitor Improper Access Control Vulnerability

CVE ID :CVE-2026-79417
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79534 - mark3labs mcp-filesystem-server Directory Traversal Vulnerability

CVE ID :CVE-2026-79534
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved path, so write_file (and modify_file, copy_file, move_file, create_directory) follows a pre-existing dangling symlink located inside an allowed directory and creates a file outside the configured allowed directories.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79535 - VoiceMode OS Command Injection

CVE ID :CVE-2026-79535
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79536 - Bytebase DBHub SQL Injection Vulnerability

CVE ID :CVE-2026-79536
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79537 - MetaMCP Insecure Direct Object Reference (IDOR) Vulnerability

CVE ID :CVE-2026-79537
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id " obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs " can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79538 - MetaMCP Remote Code Execution

CVE ID :CVE-2026-79538
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94953 - TOTOLINK N150RT Stack-Based Buffer Overflow

CVE ID :CVE-2026-94953
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96274 - Uncaught exception in Baicells Nova 430H

CVE ID :CVE-2026-96274
Published : Sept. 29, 2026, 8:17 p.m. | 1 hour, 9 minutes ago
Description :In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102620 - Freedesktop Poppler FoFiTrueType.cc cvtSfnts integer overflow

CVE ID :CVE-2026-102620
Published : Sept. 29, 2026, 8:30 p.m. | 56 minutes ago
Description :A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 245d3c6823377755f2c1d5fdddd010279c6ed94d. It is suggested to install a patch to address this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81841 - Paused shared dashboard access tokens still expose data source configuration

CVE ID :CVE-2026-81841
Published : Sept. 29, 2026, 8:35 p.m. | 51 minutes ago
Description :Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94204 - Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application

CVE ID :CVE-2026-94204
Published : Sept. 29, 2026, 8:40 p.m. | 46 minutes ago
Description :The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96587 - Use of Hard-coded Credentials in Viidure Dashcam Android Application

CVE ID :CVE-2026-96587
Published : Sept. 29, 2026, 8:42 p.m. | 44 minutes ago
Description :The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...