Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: cc134b0f by security tracker role at 2025-03-19T20:12:43+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,10 +1,106 @@ +CVE-2025-30258 (In GnuPG before 2.5.5, if a user chooses to import a certificate with ...) + TODO: check +CVE-2025-30197 (Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not ...) + TODO: check +CVE-2025-30196 (Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it ...) + TODO: check +CVE-2025-30154 (reviewdog/action-setup is a GitHub action that installs reviewdog. rev ...) + TODO: check +CVE-2025-30153 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131 ...) + TODO: check +CVE-2025-30152 (The Syliud PayPal Plugin is the Sylius Core Team\u2019s plugin for the ...) + TODO: check +CVE-2025-30144 (fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5 ...) + TODO: check +CVE-2025-2536 (Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 th ...) + TODO: check +CVE-2025-2512 (The File Away plugin for WordPress is vulnerable to arbitrary file upl ...) + TODO: check +CVE-2025-2511 (The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQ ...) + TODO: check +CVE-2025-2476 (Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowe ...) + TODO: check +CVE-2025-2324 (Improper Privilege Management vulnerability for users configured as Sh ...) + TODO: check +CVE-2025-29926 (XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, ...) + TODO: check +CVE-2025-29925 (XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, ...) + TODO: check +CVE-2025-29924 (XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, ...) + TODO: check +CVE-2025-29783 (vLLM is a high-throughput and memory-efficient inference and serving e ...) + TODO: check +CVE-2025-29770 (vLLM is a high-throughput and memory-efficient inference and serving e ...) + TODO: check +CVE-2025-29405 (An arbitrary file upload vulnerability in the component /admin/templat ...) + TODO: check +CVE-2025-29401 (An arbitrary file upload vulnerability in the component /views/plugin. ...) + TODO: check +CVE-2025-29137 (Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the time ...) + TODO: check +CVE-2025-29118 (Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via ...) + TODO: check +CVE-2025-27705 (There is a cross-site scripting vulnerability in the Secure Access adm ...) + TODO: check +CVE-2025-27704 (There is a cross-site scripting vulnerability in the Secure Access adm ...) + TODO: check +CVE-2025-27415 (Nuxt is an open-source web development framework for Vue.js. Prior to ...) + TODO: check +CVE-2025-26486 (Use of a Broken or Risky Cryptographic Algorithm, Use of Password Hash ...) + TODO: check +CVE-2025-26485 (The Exposure of Sensitive Information to an Unauthorized Actor vulner ...) + TODO: check +CVE-2025-26475 (Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26 ...) + TODO: check +CVE-2025-23382 (Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26 ...) + TODO: check +CVE-2025-1758 (Improper Input Validation vulnerability in Progress LoadMaster allows ...) + TODO: check +CVE-2025-1472 (Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authoriz ...) + TODO: check +CVE-2025-0431 (Enterprise Protection contains a vulnerability in URL rewriting that a ...) + TODO: check +CVE-2024-7631 (A flaw was found in the OpenShift Console, an endpoint for plugins to ...) + TODO: check +CVE-2024-57061 (An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically ...) + TODO: check +CVE-2024-55551 (An issue was discovered in Exasol jdbc driver 24.2.0. Attackers can in ...) + TODO: check +CVE-2024-53970 (Adobe Experience Manager versions 6.5.21 and earlier are affected by a ...) + TODO: check +CVE-2024-53969 (Adobe Experience Manager versions 6.5.21 and earlier are affected by a ...) + TODO: check +CVE-2024-53968 (Adobe Experience Manager versions 6.5.21 and earlier are affected by a ...) + TODO: check +CVE-2024-53967 (Adobe Experience Manager versions 6.5.21 and earlier are affected by a ...) + TODO: check +CVE-2024-51459 (IBM InfoSphere Information Server 11.7 could allow a local user to exe ...) + TODO: check +CVE-2024-45644 (IBM Security ReaQta 3.12 allows a privileged user to upload or transfe ...) + TODO: check +CVE-2024-42176 (HCL MyXalytics is affected by concurrent login vulnerability. A concur ...) + TODO: check +CVE-2024-25132 (A flaw was found in the Hive hibernation controller component of OpenS ...) + TODO: check +CVE-2024-13933 (The FoodBakery | Delivery Restaurant Directory WordPress Theme theme f ...) + TODO: check +CVE-2024-13790 (The MinimogWP \u2013 The High Converting eCommerce WordPress Theme the ...) + TODO: check +CVE-2024-13442 (The Service Finder Bookings plugin for WordPress is vulnerable to priv ...) + TODO: check +CVE-2024-12920 (The FoodBakery | Delivery Restaurant Directory WordPress Theme theme f ...) + TODO: check +CVE-2024-12137 (Authentication Bypass by Capture-replay vulnerability in Elfatek Elekt ...) + TODO: check +CVE-2024-12136 (Missing Critical Step in Authentication vulnerability in Elfatek Elekt ...) + TODO: check CVE-2025-27888 - druid <itp> (bug #825797) CVE-2024-54016 NOT-FOR-US: Apache Seata CVE-2024-47552 NOT-FOR-US: Apache Seata -CVE-2025-27018 +CVE-2025-27018 (Improper Neutralization of Special Elements used in an SQL Command ('S ...) NOT-FOR-US: Apache Airflow MySQL Provider CVE-2025-30236 (Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authenti ...) NOT-FOR-US: Shearwater SecurEnvoy SecurAccess Enrol @@ -4817,7 +4913,7 @@ CVE-2025-27531 NOT-FOR-US: Apache InLong CVE-2025-26325 (ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.) NOT-FOR-US: ShopXO -CVE-2025-26264 (GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote ...) +CVE-2025-26264 (GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), ...) NOT-FOR-US: GeoVision GV-ASWeb CVE-2025-25730 (An issue in Motorola Mobility Droid Razr HD (Model XT926) System Versi ...) NOT-FOR-US: Motorola @@ -5860,6 +5956,7 @@ CVE-2024-49570 (In the Linux kernel, the following vulnerability has been resolv CVE-2025-26925 (Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu ...) NOT-FOR-US: WordPress plugin CVE-2025-26699 (An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, ...) + {DLA-4086-1} - python-django 3:4.2.20-1 (bug #1099682) NOTE: https://www.djangoproject.com/weblog/2025/mar/06/security-releases/ NOTE: Fixed by: https://github.com/django/django/commit/e88f7376fe68dbf4ebaf11fad1513ce700b45860 (4.2.20) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cc134b0f39cc530040c120db7caf03e91f6dd540 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cc134b0f39cc530040c120db7caf03e91f6dd540 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits