Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
1338801a by Salvatore Bonaccorso at 2026-07-14T21:41:38+02:00
Process some NFUs
- - - - -
52503715 by Salvatore Bonaccorso at 2026-07-14T21:41:39+02:00
Add CVE-2026-15685/ollama
- - - - -
8628e9ee by Salvatore Bonaccorso at 2026-07-14T21:41:39+02:00
Add CVE-2026-14461/mtr
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -97,7 +97,7 @@ CVE-2026-57856 (Cockpit CMS contains a path traversal
vulnerability in the Bucke
CVE-2026-57855 (Cockpit CMS contains a missing authorization vulnerability in
the Buck ...)
NOT-FOR-US: Cockpit CMS
CVE-2026-56877 (The SCORM lab launch endpoint in Skillable
(scorm.skillable.com) throu ...)
- TODO: check
+ NOT-FOR-US: SCORM lab launch endpoint in Skillable
CVE-2026-55773 (CedarJava is an open source Java implementation of the Cedar
policy la ...)
NOT-FOR-US: CedarJava
CVE-2026-55771 (CedarJava is an open source Java implementation of the Cedar
policy la ...)
@@ -151,59 +151,59 @@ CVE-2026-39042 (An issue in MikroTIk (SIA Mikrotikls,
Latvia) RouterOS 7.21.x be
CVE-2026-27690 (Due to an HTTP Request Smuggling vulnerability in SAP
Approuter, an un ...)
NOT-FOR-US: SAP
CVE-2026-15685 (Ollama downloadBlob Improper Validation of Array Index
Denial-of-Servi ...)
- TODO: check
+ - ollama <itp> (bug #1094806)
CVE-2026-15684 (Glarysoft Glary Utilities Link Following Local Privilege
Escalation Vu ...)
- TODO: check
+ NOT-FOR-US: Glarysoft
CVE-2026-15683 (Lorex 2K Indoor Wi-Fi Security Camera Device Management Server
Imprope ...)
- TODO: check
+ NOT-FOR-US: Lorex
CVE-2026-15682 (AnyDesk Support Information Link Following Denial-of-Service
Vulnerabi ...)
- TODO: check
+ NOT-FOR-US: AnyDesk
CVE-2026-15681 (AnyDesk Screen Recording Link Following Denial-of-Service
Vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: AnyDesk
CVE-2026-15680 (Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format
String Re ...)
- TODO: check
+ NOT-FOR-US: Lorex
CVE-2026-15678 (A security vulnerability has been detected in code-projects
Online Job ...)
NOT-FOR-US: code-projects
CVE-2026-15677 (A weakness has been identified in code-projects Online Job
Portal 1.0. ...)
- TODO: check
+ NOT-FOR-US: code-projects Online Job Portal
CVE-2026-15676 (A security flaw has been discovered in code-projects Online
Job Portal ...)
- TODO: check
+ NOT-FOR-US: code-projects Online Job Portal
CVE-2026-15675 (A vulnerability was identified in code-projects Online Job
Portal 1.0. ...)
- TODO: check
+ NOT-FOR-US: code-projects Online Job Portal
CVE-2026-15672 (A vulnerability was determined in itsourcecode Electronic
Judging Syst ...)
NOT-FOR-US: itsourcecode System
CVE-2026-15669 (A vulnerability was found in louisho5 picobot up to 0.2.0.
This issue ...)
- TODO: check
+ NOT-FOR-US: louisho5 picobot
CVE-2026-15668 (A vulnerability has been found in louisho5 picobot up to
0.2.0. This v ...)
- TODO: check
+ NOT-FOR-US: louisho5 picobot
CVE-2026-15629 (A weakness has been identified in louisho5 picobot up to
0.2.0. Impact ...)
- TODO: check
+ NOT-FOR-US: louisho5 picobot
CVE-2026-15628 (A security flaw has been discovered in zhayujie
chatgpt-on-wechat CowA ...)
- TODO: check
+ NOT-FOR-US: zhayujie chatgpt-on-wechat CowAgent
CVE-2026-15627 (A vulnerability was identified in nextlevelbuilder GoClaw up
to 3.13.3 ...)
- TODO: check
+ NOT-FOR-US: nextlevelbuilder GoClaw
CVE-2026-15626 (A vulnerability was determined in nextlevelbuilder GoClaw
3.13.3-beta. ...)
- TODO: check
+ NOT-FOR-US: nextlevelbuilder GoClaw
CVE-2026-15625 (A vulnerability was found in nextlevelbuilder GoClaw 3.11.3.
Affected ...)
- TODO: check
+ NOT-FOR-US: nextlevelbuilder GoClaw
CVE-2026-15624 (A vulnerability has been found in nextlevelbuilder GoClaw
3.13.3-beta. ...)
- TODO: check
+ NOT-FOR-US: nextlevelbuilder GoClaw
CVE-2026-15622 (A flaw has been found in poco-ai poco-claw up to 0.5.4.
Affected is th ...)
- TODO: check
+ NOT-FOR-US: poco-ai poco-claw
CVE-2026-15621 (A vulnerability was detected in mosaxiv clawlet up to 0.2.10.
This imp ...)
- TODO: check
+ NOT-FOR-US: mosaxiv clawlet
CVE-2026-15620 (A security vulnerability has been detected in mosaxiv clawlet
up to 0. ...)
- TODO: check
+ NOT-FOR-US: mosaxiv clawlet
CVE-2026-15619 (A weakness has been identified in mosaxiv clawlet up to
0.2.10. The im ...)
- TODO: check
+ NOT-FOR-US: mosaxiv clawlet
CVE-2026-15618 (A security flaw has been discovered in mosaxiv clawlet up to
0.2.10. T ...)
- TODO: check
+ NOT-FOR-US: mosaxiv clawlet
CVE-2026-15607 (A vulnerability was detected in tanstack db up to 0.6.8.
Affected by t ...)
- TODO: check
+ NOT-FOR-US: tanstack db
CVE-2026-15605 (A security vulnerability has been detected in wandb
0.25.2.dev1. Affec ...)
- TODO: check
+ NOT-FOR-US: wandb
CVE-2026-15598 (A weakness has been identified in antv layout 2.0.0. This
impacts the ...)
- TODO: check
+ NOT-FOR-US: antv layout
CVE-2026-15597 (A security flaw has been discovered in SourceCodester Class
and Exam T ...)
NOT-FOR-US: SourceCodester
CVE-2026-15596 (A vulnerability was identified in SourceCodester Class and
Exam Timeta ...)
@@ -211,7 +211,7 @@ CVE-2026-15596 (A vulnerability was identified in
SourceCodester Class and Exam
CVE-2026-15595 (A vulnerability was determined in SourceCodester Class and
Exam Timeta ...)
NOT-FOR-US: SourceCodester
CVE-2026-15594 (A vulnerability was found in waooAI waoowaoo up to 0.4.1.
Impacted is ...)
- TODO: check
+ NOT-FOR-US: waooAI waoowaoo
CVE-2026-12988 (The WP 2FA WordPress plugin before 3.1.1.2 does not verify
that the e ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12583 (The Newsletters WordPress plugin before 4.15 does not prevent
deserial ...)
@@ -709,7 +709,7 @@ CVE-2026-15541 (A flaw has been found in will-moss Isaiah
up to 1.36.9. The impa
CVE-2026-15540 (A vulnerability was detected in SourceCodester Online Book
Store Syste ...)
NOT-FOR-US: SourceCodester
CVE-2026-14934 (A Missing Authorization vulnerability in the repository
creation funct ...)
- TODO: check
+ NOT-FOR-US: Google Cloud BigQuery, Dataform and Colab Enterprise
CVE-2026-14906 (Pages with malicious titles could potentially allow saved PDF
content ...)
TODO: check
CVE-2026-14846 (In version 8.2.1 of PrestaShop, there is a vulnerability
relating to t ...)
@@ -1699,7 +1699,9 @@ CVE-2026-15026 (The Import and export users and customers
plugin for WordPress i
CVE-2026-14475 (The Cookie Banner for GDPR / CCPA \u2013 WPLP Cookie Consent
plugin fo ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14461 (mtr is vulnerable to Out-of-bound read vulnerability in
ipinfo_lookup( ...)
- TODO: check
+ - mtr <unfixed>
+ [trixie] - mtr <no-dsa> (Minor issue)
+ NOTE: Fixed by:
https://github.com/traviscross/mtr/commit/48e1794414d338ce47abc0f27c25ade8788af9c3
CVE-2026-13710 (The Jeg Kit for Elementor \u2013 Powerful Addons for
Elementor, Widget ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13347 (The Hide My WP Lite plugin for WordPress is vulnerable to
Arbitrary Fi ...)
@@ -2734,7 +2736,7 @@ CVE-2026-14891 (HashiCorp Nomad and Nomad Enterprise are
vulnerable to a sandbox
CVE-2026-14373 (HashiCorp Nomad and Nomad Enterprise did not enforce the
allow_privile ...)
- nomad <removed>
CVE-2026-14361 (The consul-template library before version 0.42.1 is
vulnerable to a p ...)
- TODO: check
+ NOT-FOR-US: consul-template library
CVE-2026-13320 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-13151 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
@@ -3286,11 +3288,11 @@ CVE-2026-15034 (A vulnerability has been found in
flask-dashboard Flask-Monitori
CVE-2026-15033 (A flaw has been found in christopherthielen
check-peer-dependencies up ...)
NOT-FOR-US: christopherthielen check-peer-dependencies
CVE-2026-14967 (BBOT's `github_workflows` module could be induced to write a
downloade ...)
- TODO: check
+ NOT-FOR-US: BBOT
CVE-2026-14966 (BBOT's unarchive module rejects archives containing symlink
entries be ...)
- TODO: check
+ NOT-FOR-US: BBOT
CVE-2026-14362 (HashiCorp memberlist before version 0.6.0 is vulnerable to a
denial-of ...)
- TODO: check
+ NOT-FOR-US: HashiCorp memberlist
CVE-2026-14250 (The Themehunk Login Registration plugin for WordPress is
vulnerable to ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13129 (When the application opens a PDF file, JavaScript uses the
damaged fie ...)
@@ -3707,7 +3709,7 @@ CVE-2026-14244 (The Jssor Slider by jssor.com plugin for
WordPress is vulnerable
CVE-2026-14158 (The Widget Logic Visual plugin for WordPress is vulnerable to
Remote C ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13696 (Improper neutralization of special elements used in an LDAP
query ('LD ...)
- TODO: check
+ NOT-FOR-US: Liman MYS
CVE-2026-13199 (EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices
produce ...)
NOT-FOR-US: Raspberry Pi
CVE-2026-13020 (A Weak Password Recovery Mechanism for Forgotten Password
exists in Es ...)
@@ -9299,7 +9301,7 @@ CVE-2026-14241 (Memory safety bugs present in Firefox
152.0.3. Some of these bug
CVE-2026-14209 (A vulnerability was discovered in Keycloak's Admin UI
extension that a ...)
- keycloak <itp> (bug #1088287)
CVE-2026-14178 (openGauss \u5728\u5904\u7406\u5e26 NLS \u53c2\u6570\u7684
to_timestamp ...)
- TODO: check
+ NOT-FOR-US: openGauss
CVE-2026-14162 (Hospital Queuing Management developed by Advantech has a
Sensitive Dat ...)
NOT-FOR-US: Advantech
CVE-2026-14161 (Hospital Quening Management developed by Advantech has a
Sensitive Dat ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/477d4235cf69823ee527ce78678eaabbc45f6ff7...8628e9eeef6d8898003d9ae8c6e1ca77fd72b09c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/477d4235cf69823ee527ce78678eaabbc45f6ff7...8628e9eeef6d8898003d9ae8c6e1ca77fd72b09c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits