CVE tracker
393 subscribers
5.79K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-105486 - OSSRS srs System API api.go systemAPI.Run missing authentication

CVE ID :CVE-2026-105486
Published : Oct. 6, 2026, 2:17 a.m. | 2 hours, 28 minutes ago
Description :A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d96368b61f6e0c21df51df. The affected component should be upgraded.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105487 - yogeshojha reNgine listTargets Endpoint tasks.py subdomain_discovery os command injection

CVE ID :CVE-2026-105487
Published : Oct. 6, 2026, 2:17 a.m. | 2 hours, 28 minutes ago
Description :A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105571 - PickMall Lilishop Mobile Binding bindMobile improper authorization

CVE ID :CVE-2026-105571
Published : Oct. 6, 2026, 2:17 a.m. | 2 hours, 28 minutes ago
Description :A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105572 - PickMall Lilishop Buyer Invoice List receipt authorization

CVE ID :CVE-2026-105572
Published : Oct. 6, 2026, 3:17 a.m. | 1 hour, 28 minutes ago
Description :A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105573 - newbee-ltd newbee-mall Shopping Cart Quantity updateAccountHeadAndDetail logic error

CVE ID :CVE-2026-105573
Published : Oct. 6, 2026, 3:17 a.m. | 1 hour, 28 minutes ago
Description :A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105610 - chillzhuang SpringBlade Parameter Submit Management ParamController.java improper authorization

CVE ID :CVE-2026-105610
Published : Oct. 6, 2026, 3:17 a.m. | 1 hour, 28 minutes ago
Description :A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter Submit Management. The manipulation of the argument initPassword results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105704 - SourceCodester Drug Recommendation System Auth Guard improper authentication

CVE ID :CVE-2026-105704
Published : Oct. 6, 2026, 4:15 a.m. | 29 minutes ago
Description :A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105611 - chillzhuang SpringBlade User Detail Endpoint RoleController.java improper authorization

CVE ID :CVE-2026-105611
Published : Oct. 6, 2026, 4:17 a.m. | 27 minutes ago
Description :A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affects an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/RoleController.java of the component User Detail Endpoint. This manipulation of the argument ID causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105621 - jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDetail improper authorization

CVE ID :CVE-2026-105621
Published : Oct. 6, 2026, 4:18 a.m. | 27 minutes ago
Description :A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105703 - PHPGurukul User Registration & Login and User Management System Change Password change-password.php authorization

CVE ID :CVE-2026-105703
Published : Oct. 6, 2026, 4:18 a.m. | 27 minutes ago
Description :A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105705 - SourceCodester Drug Recommendation System add_drug.php cross site scripting

CVE ID :CVE-2026-105705
Published : Oct. 6, 2026, 4:30 a.m. | 14 minutes ago
Description :A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25291 - Use After Free in Graphics

CVE ID :CVE-2026-25291
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25302 - Improper Verification of Cryptographic Signature in Boot

CVE ID :CVE-2026-25302
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57537 - Use After Free in DSP Service

CVE ID :CVE-2026-57537
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57545 - Untrusted Pointer Dereference in Graphics

CVE ID :CVE-2026-57545
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Memory corruption when processing draw objects of incorrect type during graphics command list execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57546 - Buffer Over-read in WLAN HAL

CVE ID :CVE-2026-57546
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Transient DOS when processing a continuous receive command with a zero-sized global configuration override.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57554 - Use After Free in DSP Service

CVE ID :CVE-2026-57554
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57555 - Use After Free in DSP Service

CVE ID :CVE-2026-57555
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Memory Corruption when executing system service routines due to improper handling of user input buffers.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57559 - Use After Free in DSP_Services

CVE ID :CVE-2026-57559
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Memory corruption while processing service requests.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59357 - Self-UAA OIDC Configuration allows JWT injection to establish unauthorized sessions

CVE ID :CVE-2026-59357
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenticated external-OIDC browser session, via submitting a UAA access token or a cross-client ID token as the callback’s id_token parameter. The issue only manifests when a UAA zone is configured with an OIDC identity provider whose issuer exactly matches that zone’s own /oauth/token endpoint (a “self-UAA” OIDC configuration). In this configuration, the callback takes a supplied id_token directly instead of requiring the authorization code exchange, and does not verify that the token was actually issued as an ID token for the specific self-OIDC relying-party client. An attacker holding any valid UAA JWT for themselves — including a plain access token with only uaa.user scope, or a valid ID token issued to an unrelated client such as cf — can present it as the callback’s id_token and be authenticated into a mapped local (“shadow”) account. Because the resulting session is not verified against the originating token’s true audience or user_id, its effective privilege depends entirely on the shadow account’s group memberships, which can include administrative scopes such as clients.write. Exploitation requires a valid UAA user JWT, a valid browser login state for the target zone, and the presence of a self-referential OIDC provider configuration — this is not a pre-authentication vulnerability, and does not by itself grant privileges beyond those already held by the mapped shadow account.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59358 - UAA OAuth Token Endpoint Vulnerability allows user access token reuse for client_credentials grant type

CVE ID :CVE-2026-59358
Published : Oct. 6, 2026, 7:16 a.m. | 1 hour, 29 minutes ago
Description :Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated attacker holding a valid user access token to obtain a fully-privileged client_credentials token for the OAuth client that issued it, by presenting the user token as an OAuth 2.0 Bearer credential on a client_credentials grant request in place of the client’s configured secret. UAA’s client_credentials handling does not verify that the Bearer credential supplied for client authentication is actually a client credential (a client secret or a valid configured client authentication method); it accepts any valid access token whose client_id matches the request. A token obtained by a normal end user through a public authorization_code + PKCE flow — scoped only to uaa.user, carrying a user_id, and recording client_auth_method=none — satisfies this check. That user token cannot itself administer OAuth clients (POST /oauth/clients correctly returns 403), but when replayed as Bearer authentication on a client_credentials request for the same client, UAA issues a new client-only token carrying the client’s full authorities, such as clients.write. An attacker can use that token to create arbitrary new OAuth clients, including clients with attacker-chosen authorities, without ever possessing the client’s actual secret. Exploitation requires a valid user access token (the attacker’s own) for a client that is configured to support both a public, user-facing authorization flow and the client_credentials grant type on the same client_id — a non-default combination. Practical impact scales with the authorities assigned to that client.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...