Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
92b774ba by security tracker role at 2026-02-02T08:13:13+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,57 @@
+CVE-2026-25253 (OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a
gatewayU ...)
+ TODO: check
+CVE-2026-25202 (The database account and password are hardcoded, allowing
login with t ...)
+ TODO: check
+CVE-2026-25201 (An unauthenticated user can upload arbitrary files to execute
remote c ...)
+ TODO: check
+CVE-2026-25200 (A vulnerability in MagicInfo9 Server allows authorized users
to upload ...)
+ TODO: check
+CVE-2026-24788 (RaspAP raspap-webgui versions prior to 3.3.6 contain an OS
command inj ...)
+ TODO: check
+CVE-2026-22888 (Improper input verification issue exists in Cybozu Garoon
5.0.0 to 6.0 ...)
+ TODO: check
+CVE-2026-22881 (Cross-site scripting vulnerability exists in Message function
of Cyboz ...)
+ TODO: check
+CVE-2026-20711 (Cross-site scripting vulnerability exists in E-mail function
of Cybozu ...)
+ TODO: check
+CVE-2026-1746 (A vulnerability was identified in JeecgBoot 3.9.0. This
vulnerability ...)
+ TODO: check
+CVE-2026-1745 (A vulnerability was determined in SourceCodester Medical
Certificate G ...)
+ TODO: check
+CVE-2026-1744 (A vulnerability was found in D-Link DSL-6641K
N8.TR069.20131126. Affec ...)
+ TODO: check
+CVE-2026-1743 (A vulnerability has been found in DJI Mavic Mini, Air, Spark
and Mini ...)
+ TODO: check
+CVE-2026-1742 (A vulnerability was identified in EFM ipTIME A8004T 14.18.2.
Affected ...)
+ TODO: check
+CVE-2026-1741 (A vulnerability was determined in EFM ipTIME A8004T 14.18.2.
Affected ...)
+ TODO: check
+CVE-2026-1740 (A vulnerability was found in EFM ipTIME A8004T 14.18.2. This
impacts t ...)
+ TODO: check
+CVE-2026-1739 (A vulnerability has been found in Free5GC pcf up to 1.4.1. This
affect ...)
+ TODO: check
+CVE-2026-1738 (A flaw has been found in Open5GS up to 2.7.6. The impacted
element is ...)
+ TODO: check
+CVE-2026-1737 (A vulnerability was detected in Open5GS up to 2.7.6. The
affected elem ...)
+ TODO: check
+CVE-2026-1736 (A security vulnerability has been detected in Open5GS up to
2.7.6. Imp ...)
+ TODO: check
+CVE-2026-1735 (A weakness has been identified in Yealink MeetingBar A30
133.321.0.3. ...)
+ TODO: check
+CVE-2026-1734 (A security flaw has been discovered in Zhong Bang CRMEB up to
5.6.3. T ...)
+ TODO: check
+CVE-2026-1733 (A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3.
This a ...)
+ TODO: check
+CVE-2026-1518 (A flaw was found in Keycloak\u2019s CIBA feature where
insufficient va ...)
+ TODO: check
+CVE-2026-0658 (The Five Star Restaurant Reservations WordPress plugin before
2.7.9 d ...)
+ TODO: check
+CVE-2025-15396 (The Library Viewer WordPress plugin before 3.2.0 does not
sanitise and ...)
+ TODO: check
+CVE-2025-15030 (The User Profile Builder WordPress plugin before 3.15.2 does
not have ...)
+ TODO: check
+CVE-2025-13348 (An improper access control vulnerability exists in ASUS Secure
Delete ...)
+ TODO: check
CVE-2023-54343 (QWE DL 2.0.1 mobile web application contains a persistent
input valida ...)
NOT-FOR-US: QWE DL
CVE-2022-50952 (Banco Guayaquil 8.0.0 mobile iOS application contains a
persistent cro ...)
@@ -26,7 +80,8 @@ CVE-2021-47918 (Simple CMS 2.1 contains a remote SQL
injection vulnerability tha
NOT-FOR-US: Simple CMS
CVE-2021-47917 (Simple CMS 2.1 contains a persistent cross-site scripting
vulnerabilit ...)
NOT-FOR-US: Simple CMS
-CVE-2021-47916 (Simple CMS 2.1 contains a remote SQL injection vulnerability
that allo ...)
+CVE-2021-47916
+ REJECTED
NOT-FOR-US: Simple CMS
CVE-2021-47915 (PHP Melody version 3.0 contains a remote SQL injection
vulnerability i ...)
NOT-FOR-US: PHP Melody
@@ -874,9 +929,9 @@ CVE-2025-15344 (Tanium addressed a SQL injection
vulnerability in Asset.)
NOT-FOR-US: Tanium
CVE-2025-14975 (The Custom Login Page Customizer WordPress plugin before 2.5.4
does no ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-1531
+CVE-2026-1531 (A flaw was found in foreman_kubevirt. When configuring the
connection ...)
NOT-FOR-US: foreman-kubevirt
-CVE-2026-1530
+CVE-2026-1530 (A flaw was found in fog-kubevirt. This vulnerability allows a
remote a ...)
NOT-FOR-US: fog-kubevirt
CVE-2026-24775 (OpenProject is an open-source, web-based project management
software. ...)
NOT-FOR-US: OpenProject
@@ -1332,7 +1387,7 @@ CVE-2026-XXXX [RUSTSEC-2025-0143]
[bookworm] - rust-capnp <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0143.html
NOTE: https://github.com/capnproto/capnproto-rust/issues/605
-CVE-2025-13881
+CVE-2025-13881 (A flaw was found in Keycloak Admin API. This vulnerability
allows an a ...)
- keycloak <itp> (bug #1088287)
CVE-2026-24875 (Integer Overflow or Wraparound vulnerability in yoyofr
modizer.This is ...)
NOT-FOR-US: yoyofr modizer
@@ -10392,9 +10447,11 @@ CVE-2025-15449 (A vulnerability was determined in
cld378632668 JavaMall up to 99
NOT-FOR-US: JavaMall
CVE-2025-15448 (A vulnerability was found in cld378632668 JavaMall up to
994f1e2b01937 ...)
NOT-FOR-US: JavaMall
-CVE-2025-15447 (A vulnerability has been found in Seeyon Zhiyuan OA Web
Application Sy ...)
+CVE-2025-15447
+ REJECTED
NOT-FOR-US: OA Web Application System
-CVE-2025-15446 (A flaw has been found in Seeyon Zhiyuan OA Web Application
System up t ...)
+CVE-2025-15446
+ REJECTED
NOT-FOR-US: OA Web Application System
CVE-2025-15238 (QOCA aim AI Medical Cloud Platform developed by Quanta
Computer has a ...)
NOT-FOR-US: QOCA aim AI Medical Cloud Platform
@@ -11876,7 +11933,8 @@ CVE-2025-15429 (A security vulnerability has been
detected in UTT \u8fdb\u53d6 5
NOT-FOR-US: UTT
CVE-2025-15428 (A weakness has been identified in UTT \u8fdb\u53d6 512W
1.7.7-171114. ...)
NOT-FOR-US: UTT
-CVE-2025-15427 (A security flaw has been discovered in Seeyon Zhiyuan OA Web
Applicati ...)
+CVE-2025-15427
+ REJECTED
NOT-FOR-US: Seeyon Zhiyuan OA Web Application System
CVE-2025-15426 (A vulnerability was identified in jackying H-ui.admin up to
3.1. This ...)
NOT-FOR-US: jackying H-ui.admin
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/92b774baed086af2ab59f5a68601553715d597af
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/92b774baed086af2ab59f5a68601553715d597af
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits