Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
19d0c9f7 by security tracker role at 2026-06-20T19:13:37+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,75 @@
+CVE-2026-5366 (Prefect version 3.6.23 is vulnerable to remote code execution 
due to i ...)
+       TODO: check
+CVE-2026-56347 (AVideo TopMenu plugin through version 26.0 contains a stored 
cross-sit ...)
+       TODO: check
+CVE-2026-56346 (AVideo through version 25.0 contains an authentication bypass 
vulnerab ...)
+       TODO: check
+CVE-2026-56345 (AVideo through 29.0 contains an authorization bypass 
vulnerability in  ...)
+       TODO: check
+CVE-2026-56342 (AVideo through version 27.0 contains a server-side request 
forgery vul ...)
+       TODO: check
+CVE-2026-56341 (AVideo through version 26.0 contains multiple unauthenticated 
list.jso ...)
+       TODO: check
+CVE-2026-56340 (vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor 
validat ...)
+       TODO: check
+CVE-2026-56332 (Capgo before 12.128.2 contains an open redirect vulnerability 
in the c ...)
+       TODO: check
+CVE-2026-56330 (Capgo before 12.128.2 contains an open redirect vulnerability 
in strip ...)
+       TODO: check
+CVE-2026-56325 (Capgo before 12.128.2 uses ILIKE pattern matching instead of 
exact mat ...)
+       TODO: check
+CVE-2026-56319 (Capgo before 12.128.2 contains an information disclosure 
vulnerability ...)
+       TODO: check
+CVE-2026-56317 (Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains 
a cross- ...)
+       TODO: check
+CVE-2026-56307 (Cap-go before 12.128.12 contains a broken cursor pagination 
vulnerabil ...)
+       TODO: check
+CVE-2026-56304 (picklescan before 1.0.1 contains an unsafe pickle 
deserialization vuln ...)
+       TODO: check
+CVE-2026-56295 (Capgo before 12.128.2 contains an authorization bypass 
vulnerability i ...)
+       TODO: check
+CVE-2026-56294 (capacitor-native-biometric before 12.128.2 contains an 
authentication  ...)
+       TODO: check
+CVE-2026-56282 (Capgo before 12.128.2 contains an information disclosure 
vulnerability ...)
+       TODO: check
+CVE-2026-56276 (Flowise before 3.1.2 contains a mass assignment vulnerability 
in the P ...)
+       TODO: check
+CVE-2026-56267 (Flowise before 3.0.13 contains an information exposure 
vulnerability i ...)
+       TODO: check
+CVE-2026-56235 (Cap-go capgo before 12.128.2 contains an authorization bypass 
in sever ...)
+       TODO: check
+CVE-2026-56228 (Capgo before 12.128.2 fails to enforce a maximum value on the 
minimum  ...)
+       TODO: check
+CVE-2026-56227 (Capgo before 12.128.2 contains a server-side request forgery 
vulnerabi ...)
+       TODO: check
+CVE-2026-56218 (Capgo before 12.128.2 fails to strip EXIF metadata including 
GPS geolo ...)
+       TODO: check
+CVE-2026-48939 (A vulnerability in the iCagenda extension for Joomla allows 
the upload ...)
+       TODO: check
+CVE-2026-48909 (SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes 
user-controlled  ...)
+       TODO: check
+CVE-2026-48908 (A vulnerability in the SP Page Builder for Joomla allows the 
upload of ...)
+       TODO: check
+CVE-2026-12673 (Liquidfiles versions before 4.2.12 are affected by a broken 
access con ...)
+       TODO: check
+CVE-2026-12119 (The Simple File List plugin for WordPress is vulnerable to 
unauthorize ...)
+       TODO: check
+CVE-2026-11912 (The Simple File List plugin for WordPress is vulnerable to 
arbitrary f ...)
+       TODO: check
+CVE-2026-11911 (The Simple File List plugin for WordPress is vulnerable to 
arbitrary f ...)
+       TODO: check
+CVE-2025-71379 (vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular 
expression ...)
+       TODO: check
+CVE-2025-71331 (Flowise before 3.0.8 contains a cross-site scripting (XSS) 
vulnerabili ...)
+       TODO: check
+CVE-2024-58351 (Flowise before 2.1.4 allows configuration to be injected into 
the Chai ...)
+       TODO: check
+CVE-2022-50972 (WooCommerce 7.1.0 contains a remote code execution 
vulnerability that  ...)
+       TODO: check
+CVE-2020-37255 (WordPress Time Capsule Plugin 1.21.16 contains an 
authentication bypas ...)
+       TODO: check
+CVE-2019-25763 (WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains 
an authe ...)
+       TODO: check
 CVE-2026-9843 (The Database for Contact Form 7, WPforms, Elementor forms 
plugin for W ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-9375 (urllib3 version 2.6.3 is vulnerable to a decompression bomb 
bypass in  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/19d0c9f7e68befc2008875581d93ec50d46a77fb

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/19d0c9f7e68befc2008875581d93ec50d46a77fb
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to