CVE tracker
393 subscribers
5.79K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-105073 - WordPress WP Event Solution plugin <= 4.1.25 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-105073
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105307 - Casdoor API Endpoint authz_filter.go ApiFilter missing authentication

CVE ID :CVE-2026-105307
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105396 - Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header

CVE ID :CVE-2026-105396
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39783 - WordPress Polylang plugin <= 3.8.7 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-39783
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63266 - Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality

CVE ID :CVE-2026-63266
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63267 - LFI and GET SSRF via calcext:data-mappings and csv provider

CVE ID :CVE-2026-63267
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63268 - LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href

CVE ID :CVE-2026-63268
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text file into the sheet. In fixed versions only the csv, html and xml data providers are restored when a document is loaded.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63269 - LFI and GET SSRF via GStreamer and HLS playlists

CVE ID :CVE-2026-63269
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the document loaded, and their contents could end up in the document. In fixed versions LibreOffice does not follow playlists that name further resources, and linked media is under link update control.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63270 - Environment/ini-file leaks

CVE ID :CVE-2026-63270
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and the Calc csv and sql data providers still reached the expansion. In fixed versions these places refuse URLs with internal schemes when the URL comes from the document.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63277 - RCE via calcext:data-mappings, sql provider and jdbc connector

CVE ID :CVE-2026-63277
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92931 - CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK

CVE ID :CVE-2026-92931
Published : Oct. 5, 2026, 1:06 p.m. | 1 hour, 7 minutes ago
Description :CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105315 - django-haystack more_like_this Template Tag elasticsearch_backend.py _to_python eval injection

CVE ID :CVE-2026-105315
Published : Oct. 5, 2026, 1:16 p.m. | 56 minutes ago
Description :A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of the argument result_class leads to improper neutralization of directives in dynamically evaluated code. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.4.0 is able to address this issue. The name of the patch is eb05f193c9771a68dcc8cfac6674a0d48a52ee9d. It is suggested to upgrade the affected component.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77802 - HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic

CVE ID :CVE-2026-77802
Published : Oct. 5, 2026, 1:16 p.m. | 56 minutes ago
Description :In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request body using only the first Content-Length value. A local threat actor with low privileges who is able to send requests through the same Fiddler proxy instance as another user can exploit this desynchronization against a non-RFC-9110-compliant origin server that keeps the connection alive to smuggle an additional request. Because Fiddler returns the server connection to its pipe pool after reading only the first response, the unread smuggled response remains buffered on the socket and is served to the next session that reuses that connection, allowing the attacker to poison responses delivered to other users and to obtain responses intended for them.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77803 - Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic

CVE ID :CVE-2026-77803
Published : Oct. 5, 2026, 1:16 p.m. | 56 minutes ago
Description :In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server.
Severity: 3.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77804 - Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Progress® Telerik® Fiddler® Classic

CVE ID :CVE-2026-77804
Published : Oct. 5, 2026, 1:16 p.m. | 56 minutes ago
Description :In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a user-writable location and then launches the external TrustCert helper application, which elevates and imports the certificate from that file. A local threat actor with low privileges who replaces the temporary file between the time it is written and the time the elevated helper reads it can cause an attacker-supplied root certificate to be installed in the Local Computer Trusted Root Certification Authorities store, enabling subsequent interception and modification of TLS-protected traffic on the machine. Successful exploitation requires the user to initiate the certificate trust operation and approve the elevation prompt.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77805 - Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fiddler® Classic

CVE ID :CVE-2026-77805
Published : Oct. 5, 2026, 1:16 p.m. | 56 minutes ago
Description :In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose certificate subject name matches a broad allow list of publisher name fragments, rather than verifying that the file is the specific executable shipped with that version of the product. A local threat actor with low privileges who replaces one of these helper executables with any other validly signed binary from an allow-listed publisher can cause the substituted binary to be executed by the application, including with Administrator privileges for the tools that request elevation, resulting in privilege escalation and execution of unintended code. Successful exploitation requires the user to launch the affected external tool and to approve the elevation prompt without noticing that it refers to a different executable.
Severity: 7.9 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15643 - WordPress Adsmonetizer plugin <= 3.2.4 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2025-15643
Published : Oct. 5, 2026, 5:24 p.m. | 49 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101919 - Hypershift: hypershift: unsanitized kubeconfig passthrough from tenant namespace to control plane

CVE ID :CVE-2026-101919
Published : Oct. 5, 2026, 5:33 p.m. | 40 minutes ago
Description :A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When downstream controllers consume this configuration, an attacker can achieve arbitrary code execution within the control plane.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104905 - FacturaScripts < 2026.7 PHP Object Injection via WidgetSelect

CVE ID :CVE-2026-104905
Published : Oct. 5, 2026, 5:34 p.m. | 40 minutes ago
Description :FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104973 - Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery

CVE ID :CVE-2026-104973
Published : Oct. 5, 2026, 5:41 p.m. | 32 minutes ago
Description :Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhook_task.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypass the SSRF protection. This issue is fixed in 1.4.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93316 - Starting daemon with --cdi-disabled flag can lead to panic on specific builds

CVE ID :CVE-2026-93316
Published : Oct. 5, 2026, 5:42 p.m. | 32 minutes ago
Description :If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...