CVE tracker
393 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-51862 - DB-GPT Directory Traversal Vulnerability

CVE ID :CVE-2026-51862
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51864 - DB-GPT Directory Traversal Vulnerability

CVE ID :CVE-2026-51864
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51866 - DB-GPT Arbitrary Code Execution

CVE ID :CVE-2026-51866
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51867 - AgentGPT Incorrect Access Control Vulnerability

CVE ID :CVE-2026-51867
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51869 - DB-GPT Sandbox API Arbitrary Code Execution

CVE ID :CVE-2026-51869
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51870 - DeepTutor Command Injection Vulnerability

CVE ID :CVE-2026-51870
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51871 - Devika Code Injection Vulnerability

CVE ID :CVE-2026-51871
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-51872 - Devika Code Injection Vulnerability

CVE ID :CVE-2026-51872
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92172 - Meta Horizon OS OVRMediaService Privilege Escalation Vulnerability

CVE ID :CVE-2026-92172
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92173 - Meta Horizon OS Improper Privilege Management Vulnerability

CVE ID :CVE-2026-92173
Published : Sept. 30, 2026, 9:17 p.m. | 14 minutes ago
Description :Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101283 - iperf3 Heap Buffer Overflow

CVE ID :CVE-2026-101283
Published : Sept. 30, 2026, 10:16 p.m. | 3 hours, 20 minutes ago
Description :iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103001 - PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

CVE ID :CVE-2026-103001
Published : Sept. 30, 2026, 10:16 p.m. | 3 hours, 20 minutes ago
Description :PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47096 - AJA HELO Plus < 2.1.7 Stored XSS via System Name Parameter

CVE ID :CVE-2026-47096
Published : Sept. 30, 2026, 10:16 p.m. | 3 hours, 20 minutes ago
Description :AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw when device authentication is disabled to persistently execute arbitrary script in the browser of any administrator who opens the web management interface, enabling theft of stored secrets such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as hijacking of the authenticated session.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103584 - attacker-controlled javascript license URL via XSS

CVE ID :CVE-2026-103584
Published : Sept. 30, 2026, 11:16 p.m. | 2 hours, 20 minutes ago
Description :Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43.
Severity: 1.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103585 - attacker-controlled javascript license URL via XSS

CVE ID :CVE-2026-103585
Published : Sept. 30, 2026, 11:16 p.m. | 2 hours, 20 minutes ago
Description :Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43.
Severity: 1.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103587 - QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters

CVE ID :CVE-2026-103587
Published : Sept. 30, 2026, 11:16 p.m. | 2 hours, 20 minutes ago
Description :QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103588 - QloApps through 1.7.0 Reflected XSS via exceptions field

CVE ID :CVE-2026-103588
Published : Sept. 30, 2026, 11:16 p.m. | 2 hours, 20 minutes ago
Description :QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103589 - QloApps through 1.7.0 Reflected XSS via Room Type Editor

CVE ID :CVE-2026-103589
Published : Sept. 30, 2026, 11:16 p.m. | 2 hours, 20 minutes ago
Description :QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103590 - QloApps through 1.7.0 Reflected XSS via Length of Stay Fields

CVE ID :CVE-2026-103590
Published : Sept. 30, 2026, 11:16 p.m. | 2 hours, 20 minutes ago
Description :QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim's administrative session.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103591 - DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file

CVE ID :CVE-2026-103591
Published : Sept. 30, 2026, 11:16 p.m. | 2 hours, 20 minutes ago
Description :DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103592 - simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers

CVE ID :CVE-2026-103592
Published : Sept. 30, 2026, 11:16 p.m. | 2 hours, 20 minutes ago
Description :simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...