CVE tracker
394 subscribers
5.76K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-51897 - RAGFlow Improper Access Control Leading to Remote Code Execution

CVE ID :CVE-2026-51897
Published : Oct. 1, 2026, 10:17 p.m. | 3 hours, 24 minutes ago
Description :RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64892 - Johnson Controls Easy IO Neo Sensitive Information Exposure

CVE ID :CVE-2026-64892
Published : Oct. 1, 2026, 10:17 p.m. | 3 hours, 24 minutes ago
Description :- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64893 - Johnson Controls EasyIO NEO Cleartext Transmission of Sensitive Information

CVE ID :CVE-2026-64893
Published : Oct. 1, 2026, 10:17 p.m. | 3 hours, 24 minutes ago
Description :- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86344 - 389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue

CVE ID :CVE-2026-86344
Published : Oct. 1, 2026, 10:17 p.m. | 3 hours, 24 minutes ago
Description :A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-71427 - Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_image

CVE ID :CVE-2025-71427
Published : Oct. 1, 2026, 11:16 p.m. | 2 hours, 25 minutes ago
Description :Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103760 - Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write

CVE ID :CVE-2026-103760
Published : Oct. 1, 2026, 11:16 p.m. | 2 hours, 25 minutes ago
Description :Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103761 - Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue

CVE ID :CVE-2026-103761
Published : Oct. 1, 2026, 11:16 p.m. | 2 hours, 25 minutes ago
Description :Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103764 - Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport

CVE ID :CVE-2026-103764
Published : Oct. 2, 2026, 12:16 a.m. | 1 hour, 24 minutes ago
Description :Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103765 - Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server

CVE ID :CVE-2026-103765
Published : Oct. 2, 2026, 12:16 a.m. | 1 hour, 24 minutes ago
Description :Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103766 - ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter

CVE ID :CVE-2026-103766
Published : Oct. 2, 2026, 12:16 a.m. | 1 hour, 24 minutes ago
Description :ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-based blind payloads concatenated into AdsManager::DeleteAd queries to extract user credentials and emails or modify and delete arbitrary records.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86345 - 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result

CVE ID :CVE-2026-86345
Published : Oct. 2, 2026, 12:17 a.m. | 1 hour, 24 minutes ago
Description :A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Severity: 9.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104480 - Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership

CVE ID :CVE-2026-104480
Published : Oct. 2, 2026, 12:57 a.m. | 43 minutes ago
Description :Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104052 - itsourcecode Pet Shop Management System admin_reject_completed.php sql injection

CVE ID :CVE-2026-104052
Published : Oct. 2, 2026, 1 a.m. | 41 minutes ago
Description :A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21140 - ManagedProvisioning Improper Access Control Vulnerability

CVE ID :CVE-2026-21140
Published : Oct. 2, 2026, 1:05 a.m. | 36 minutes ago
Description :Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104053 - itsourcecode Pet Shop Management System admin_reservefilter.php sql injection

CVE ID :CVE-2026-104053
Published : Oct. 2, 2026, 1:15 a.m. | 26 minutes ago
Description :A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103096 - GV-Eye Hardcoded API Key Vulnerability

CVE ID :CVE-2026-103096
Published : Oct. 2, 2026, 1:16 a.m. | 25 minutes ago
Description :API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103097 - GV-Eye Relay Payment API Key Vulnerability

CVE ID :CVE-2026-103097
Published : Oct. 2, 2026, 1:16 a.m. | 25 minutes ago
Description :An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103098 - GV-Eye Sensitive information exposure in URL query parameter Vulnerability

CVE ID :CVE-2026-103098
Published : Oct. 2, 2026, 1:16 a.m. | 25 minutes ago
Description :Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104054 - calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization

CVE ID :CVE-2026-104054
Published : Oct. 2, 2026, 2:17 a.m. | 3 hours, 25 minutes ago
Description :A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104120 - modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery

CVE ID :CVE-2026-104120
Published : Oct. 2, 2026, 3:16 a.m. | 2 hours, 26 minutes ago
Description :A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104123 - SourceCodester Online Reviewer Management System btn_functions.php activity sql injection

CVE ID :CVE-2026-104123
Published : Oct. 2, 2026, 3:16 a.m. | 2 hours, 26 minutes ago
Description :A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...