Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
60a0fffa by security tracker role at 2026-07-23T19:13:49+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,603 @@
+CVE-2026-9729 (The Webpushr Push Notifications plugin for WordPress is
vulnerable to ...)
+ TODO: check
+CVE-2026-9713 (The Lumise Product Designer for WooCommerce plugin for
WordPress is vu ...)
+ TODO: check
+CVE-2026-9635 (The WP Shortcode by MyThemeShop plugin for WordPress is
vulnerable to ...)
+ TODO: check
+CVE-2026-8287 (Allocation of resources without limits or throttling
vulnerability in ...)
+ TODO: check
+CVE-2026-6516 (Zohocorp ManageEngine ADAudit Plus versionsbefore 8606 are
affected by ...)
+ TODO: check
+CVE-2026-65920 (Diffusers through 0.39.0, fixed in commit cee298c, contains a
path tra ...)
+ TODO: check
+CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary
file read ...)
+ TODO: check
+CVE-2026-65918 (PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2,
contains ...)
+ TODO: check
+CVE-2026-65917 (CyberPanel through 1.9.1, fixed in commit b198460, contains an
insecur ...)
+ TODO: check
+CVE-2026-65916 (CyberPanel through 1.9.1, fixed in commit b198460, contains a
missing ...)
+ TODO: check
+CVE-2026-65914 (DOMPurify before 3.3.2 contains a mutation-XSS vulnerability
when sani ...)
+ TODO: check
+CVE-2026-65913 (DOMPurify before 3.3.2 contains a prototype pollution
vulnerability in ...)
+ TODO: check
+CVE-2026-65912 (DOMPurify before 3.3.2 contains a URI validation bypass
vulnerability ...)
+ TODO: check
+CVE-2026-65911 (In DOMPurify through 3.3.3, function predicates supplied via
ADD_ATTR ...)
+ TODO: check
+CVE-2026-65908 (In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code
execution ...)
+ TODO: check
+CVE-2026-65907 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 code
execution in Git ...)
+ TODO: check
+CVE-2026-65906 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 \u0441ode
execution v ...)
+ TODO: check
+CVE-2026-65904 (DOMPurify through 3.3.3 fails to sanitize DOM elements passed
via IN_P ...)
+ TODO: check
+CVE-2026-65903 (DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS
function ...)
+ TODO: check
+CVE-2026-65902 (DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes
direct refe ...)
+ TODO: check
+CVE-2026-65901 (DOMPurify through 3.4.6 contains a cross-site scripting
vulnerability ...)
+ TODO: check
+CVE-2026-65900 (DOMPurify versions >=3.0.0 and before 3.4.8, when configured
with SAFE ...)
+ TODO: check
+CVE-2026-65899 (DOMPurify 3.0.0 before 3.4.9 does not reset the retained
Trusted Types ...)
+ TODO: check
+CVE-2026-65898 (DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR
allowlist when ...)
+ TODO: check
+CVE-2026-65897 (Grav API Plugin versions before 1.0.10 fail to validate the
groups fie ...)
+ TODO: check
+CVE-2026-65896 (Grav API Plugin (Composer package getgrav/grav-plugin-api)
before 1.0. ...)
+ TODO: check
+CVE-2026-65895 (Grav API Plugin versions before 1.0.10 fail to restrict write
access t ...)
+ TODO: check
+CVE-2026-65763 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in
Phoca Map ...)
+ TODO: check
+CVE-2026-65762 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in
Phoca Gue ...)
+ TODO: check
+CVE-2026-65761 (Joomla Extension - joomshaper.com - Unauthenticated SQL
injection in E ...)
+ TODO: check
+CVE-2026-65760 (Joomla Extension - joomshaper.com - cross-customer order and
personal ...)
+ TODO: check
+CVE-2026-65759 (Joomla Extension - joomshaper.com - unauthenticated
payment/order forg ...)
+ TODO: check
+CVE-2026-65758 (Joomla Extension - tassos.gr - Sensitive data exposure in
Convert Form ...)
+ TODO: check
+CVE-2026-65757 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
+ TODO: check
+CVE-2026-65756 (Joomla Extension - regularlabs.com - XSS vector in Keyboard
Shortcuts ...)
+ TODO: check
+CVE-2026-65755 (Joomla Extension - regularlabs.com - Date-sensitive
query-cache leakag ...)
+ TODO: check
+CVE-2026-65754 (Joomla Extension - regularlabs.com - Insecure path handling in
ReRepla ...)
+ TODO: check
+CVE-2026-65713 (Joomla Extension - regularlabs.com - Insecure path handling in
Modals ...)
+ TODO: check
+CVE-2026-65712 (Joomla Extension - regularlabs.com - Insecure path handling in
CDN for ...)
+ TODO: check
+CVE-2026-65702 (Vanna through 2.0.2 contains a path traversal vulnerability in
the Fil ...)
+ TODO: check
+CVE-2026-65701 (SoftVC VITS Singing Voice Conversion through commit 730930d
contains a ...)
+ TODO: check
+CVE-2026-65700 (h2oGPT through 0.2.1 contains a path traversal vulnerability
in the Op ...)
+ TODO: check
+CVE-2026-65699 (AgentGPT through 1.0.0 contains an authorization bypass
through user-c ...)
+ TODO: check
+CVE-2026-65698 (Void through 1.3.4 contains a path traversal vulnerability in
the AI a ...)
+ TODO: check
+CVE-2026-65697 (Fathom Lite through 1.3.1 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-65696 (Overseerr through 1.35.0 contains an authorization bypass
through user ...)
+ TODO: check
+CVE-2026-65695 (Office-Word-MCP-Server through 1.1.11 contains a path
traversal vulner ...)
+ TODO: check
+CVE-2026-65690 (Bold Reports Standalone Report Designer before 14.1.12
contains a miss ...)
+ TODO: check
+CVE-2026-65689 (Bold Reports Standalone Report Designer before 14.1.12
contains a miss ...)
+ TODO: check
+CVE-2026-65688 (Bold Reports Standalone Report Designer before 14.1.12
contains a miss ...)
+ TODO: check
+CVE-2026-65687 (Bold Reports Standalone Report Designer before 14.1.12
contains a miss ...)
+ TODO: check
+CVE-2026-65608 (Grav versions >= 1.7.0 and before 2.0.9 contain a remote code
executio ...)
+ TODO: check
+CVE-2026-65607 (SiYuan before v3.7.2 contains a path traversal vulnerability
in the /e ...)
+ TODO: check
+CVE-2026-65606 (SiYuan before v3.7.2 contains a cross-site scripting
vulnerability in ...)
+ TODO: check
+CVE-2026-65605 (SiYuan before v3.7.2 contains a stored cross-site scripting
vulnerabil ...)
+ TODO: check
+CVE-2026-65550 (Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5
versions.)
+ TODO: check
+CVE-2026-65540 (Unauthenticated Cross Site Request Forgery (CSRF) in Popup for
CF7 wit ...)
+ TODO: check
+CVE-2026-65539 (Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy
HTML Sitema ...)
+ TODO: check
+CVE-2026-65538 (Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.)
+ TODO: check
+CVE-2026-65537 (Subscriber Broken Access Control in Cyr to Lat reloaded \u2013
transli ...)
+ TODO: check
+CVE-2026-65536 (Unauthenticated Cross Site Request Forgery (CSRF) in
\u0627\u0641\u063 ...)
+ TODO: check
+CVE-2026-65535 (Contributor Sensitive Data Exposure in TinyMCE Templates <=
4.8.1 vers ...)
+ TODO: check
+CVE-2026-65534 (Author Cross Site Scripting (XSS) in Custom links in Elementor
Image C ...)
+ TODO: check
+CVE-2026-65533 (Contributor Cross Site Scripting (XSS) in Smart SEO Tool <=
4.1.2 vers ...)
+ TODO: check
+CVE-2026-65532 (Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2
version ...)
+ TODO: check
+CVE-2026-65531 (Unauthenticated Broken Access Control in Qubely <= 1.8.14
versions.)
+ TODO: check
+CVE-2026-65530 (Subscriber Broken Access Control in TemplateSpare <= 4.2.2
versions.)
+ TODO: check
+CVE-2026-65529 (Unauthenticated Broken Access Control in Graphina <= 3.1.12
versions.)
+ TODO: check
+CVE-2026-65528 (Contributor Cross Site Scripting (XSS) in BSK PDF Manager <=
3.8 versi ...)
+ TODO: check
+CVE-2026-65527 (Contributor Cross Site Scripting (XSS) in LIQUID SPEECH
BALLOON <= 1.2 ...)
+ TODO: check
+CVE-2026-65526 (Contributor SQL Injection in Visualizer <= 4.0.6 versions.)
+ TODO: check
+CVE-2026-65525 (Unauthenticated Broken Access Control in Civi Framework <=
2.2.0 versi ...)
+ TODO: check
+CVE-2026-65524 (Contributor Broken Access Control in Avada Custom Branding <=
1.2 vers ...)
+ TODO: check
+CVE-2026-65522 (Contributor Cross Site Scripting (XSS) in Manual -
Documentation, Know ...)
+ TODO: check
+CVE-2026-65521 (Unauthenticated Sensitive Data Exposure in WP Social Ninja <=
4.3.0 ve ...)
+ TODO: check
+CVE-2026-65519 (Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29
version ...)
+ TODO: check
+CVE-2026-65518 (Contributor Cross Site Scripting (XSS) in Accept Donations
with PayPal ...)
+ TODO: check
+CVE-2026-65516 (Unauthenticated Server Side Request Forgery (SSRF) in PeproDev
Ultimat ...)
+ TODO: check
+CVE-2026-65514 (Contributor Cross Site Scripting (XSS) in Appointment Hour
Booking <= ...)
+ TODO: check
+CVE-2026-65512 (Unauthenticated Cross Site Request Forgery (CSRF) in WP
Activity Log < ...)
+ TODO: check
+CVE-2026-65511 (Unauthenticated Cross Site Scripting (XSS) in Manual -
Documentation, ...)
+ TODO: check
+CVE-2026-65510 (Unauthenticated Cross Site Scripting (XSS) in PeproDev
Ultimate Invoic ...)
+ TODO: check
+CVE-2026-65506 (Unauthenticated Broken Access Control in MP3 Audio Player for
Music, R ...)
+ TODO: check
+CVE-2026-65505 (Unauthenticated Sensitive Data Exposure in Ultimate Store Kit
Elemento ...)
+ TODO: check
+CVE-2026-65503 (Contributor Cross Site Scripting (XSS) in Ultimate Store Kit
Elementor ...)
+ TODO: check
+CVE-2026-65501 (Unauthenticated Insecure Direct Object References (IDOR) in
Shiptastic ...)
+ TODO: check
+CVE-2026-65500 (Unauthenticated Broken Access Control in Manual -
Documentation, Knowl ...)
+ TODO: check
+CVE-2026-65499 (Unauthenticated Broken Access Control in PeproDev Ultimate
Invoice <= ...)
+ TODO: check
+CVE-2026-65498 (Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0
versions ...)
+ TODO: check
+CVE-2026-65497 (Administrator PHP Object Injection in Complianz <= 7.5.0
versions.)
+ TODO: check
+CVE-2026-65496 (Author Server Side Request Forgery (SSRF) in Complianz <=
7.5.0 versio ...)
+ TODO: check
+CVE-2026-65495 (Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3
versions.)
+ TODO: check
+CVE-2026-65494 (Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.)
+ TODO: check
+CVE-2026-65493 (Subscriber PHP Object Injection in Dokan Pro <= 5.0.2
versions.)
+ TODO: check
+CVE-2026-65492 (Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <=
5.0.0 versi ...)
+ TODO: check
+CVE-2026-65491 (Subscriber Broken Access Control in Query Wrangler <= 1.5.57
versions.)
+ TODO: check
+CVE-2026-65490 (Unauthenticated Sensitive Data Exposure in Create by Mediavine
<= 2.5. ...)
+ TODO: check
+CVE-2026-65489 (Unauthenticated Broken Access Control in LA-Studio Element Kit
for Ele ...)
+ TODO: check
+CVE-2026-65488 (Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio
Element ...)
+ TODO: check
+CVE-2026-65487 (Unauthenticated Broken Access Control in Photography <= 7.7.6
versions ...)
+ TODO: check
+CVE-2026-65486 (Unauthenticated Broken Access Control in Event post <= 6.0.1
versions.)
+ TODO: check
+CVE-2026-65485 (Unauthenticated Broken Access Control in Content Control <=
2.6.5 vers ...)
+ TODO: check
+CVE-2026-65484 (Contributor Broken Access Control in Style Kits <= 2.6.5
versions.)
+ TODO: check
+CVE-2026-65483 (Author Cross Site Scripting (XSS) in HashThemes Demo Importer
<= 1.4.2 ...)
+ TODO: check
+CVE-2026-65482 (Contributor Cross Site Scripting (XSS) in LA-Studio Element
Kit for El ...)
+ TODO: check
+CVE-2026-65481 (Contributor Local File Inclusion in Vino <= 1.9 versions.)
+ TODO: check
+CVE-2026-65480 (Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1
versions.)
+ TODO: check
+CVE-2026-65479 (Subscriber Broken Access Control in Reviewer <= 3.14.2
versions.)
+ TODO: check
+CVE-2026-65478 (Subscriber Broken Access Control in ListingPro <= 2.9.10
versions.)
+ TODO: check
+CVE-2026-65477 (Contributor Local File Inclusion in Tonda Core <= 2.1.2
versions.)
+ TODO: check
+CVE-2026-65476 (Unauthenticated Broken Access Control in Civi <= 2.2.4
versions.)
+ TODO: check
+CVE-2026-65475 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
+ TODO: check
+CVE-2026-65474 (Unauthenticated Sensitive Data Exposure in Ninja Tables <=
5.2.10 vers ...)
+ TODO: check
+CVE-2026-65473 (Contributor Cross Site Scripting (XSS) in
Virtue/Ascend/Pinnacle Toolk ...)
+ TODO: check
+CVE-2026-65472 (Unauthenticated Broken Access Control in Kit (formerly
ConvertKit) <= ...)
+ TODO: check
+CVE-2026-65471 (Unauthenticated Cross Site Request Forgery (CSRF) in Avada
Core <= 5.1 ...)
+ TODO: check
+CVE-2026-65470 (Contributor Cross Site Scripting (XSS) in Fluent Support <=
2.3.0 vers ...)
+ TODO: check
+CVE-2026-65469 (Unauthenticated Broken Access Control in AWP Classifieds <=
4.4.7 vers ...)
+ TODO: check
+CVE-2026-65468 (Unauthenticated Broken Access Control in JetBooking <= 4.1.2
versions.)
+ TODO: check
+CVE-2026-65467 (Contributor Server Side Request Forgery (SSRF) in JetEngine <=
3.8.11 ...)
+ TODO: check
+CVE-2026-65466 (Custom role Server Side Request Forgery (SSRF) in JetBooking
<= 4.1.2 ...)
+ TODO: check
+CVE-2026-65465 (Contributor Cross Site Scripting (XSS) in JetElements For
Elementor <= ...)
+ TODO: check
+CVE-2026-65464 (Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <=
4.16.3 ...)
+ TODO: check
+CVE-2026-65463 (Subscriber Insecure Direct Object References (IDOR) in
Masteriyo - LMS ...)
+ TODO: check
+CVE-2026-65462 (Administrator SQL Injection in Uncanny Automator <= 7.3.2
versions.)
+ TODO: check
+CVE-2026-65461 (Administrator Arbitrary File Upload in Really Simple CSV
Importer <= 1 ...)
+ TODO: check
+CVE-2026-65460 (Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal
Gateway ...)
+ TODO: check
+CVE-2026-65458 (Contributor Sensitive Data Exposure in Polylang <= 3.8.5
versions.)
+ TODO: check
+CVE-2026-65457 (Subscriber Broken Access Control in \u042eKassa
\u0434\u043b\u044f Woo ...)
+ TODO: check
+CVE-2026-65456 (Contributor Insecure Direct Object References (IDOR) in
Product Slider ...)
+ TODO: check
+CVE-2026-65455 (Administrator Arbitrary File Upload in MapSVG <= 8.14.0
versions.)
+ TODO: check
+CVE-2026-65454 (Contributor SQL Injection in Quiz And Survey Master <= 11.2.0
versions ...)
+ TODO: check
+CVE-2026-65453 (Unauthenticated Broken Access Control in Ebook Store <= 6.19
versions.)
+ TODO: check
+CVE-2026-65452 (Unauthenticated Broken Access Control in Ebook Store <= 6.19
versions.)
+ TODO: check
+CVE-2026-65451 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
+ TODO: check
+CVE-2026-65450 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
+ TODO: check
+CVE-2026-65449 (Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0
versions.)
+ TODO: check
+CVE-2026-65431 (Joomla Extension - regularlabs.com - Zipslip in GeoIP
extension - Geo ...)
+ TODO: check
+CVE-2026-65430 (Joomla Extension - regularlabs.com - MaxMind Credential
leakage in Geo ...)
+ TODO: check
+CVE-2026-65010 (Datasets through 5.00, fixed in commit ad2d853, contains a
symlink-fol ...)
+ TODO: check
+CVE-2026-64876 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
+ TODO: check
+CVE-2026-64875 (Joomla Extension - regularlabs.com - IP spoofing vulnerability
in GeoI ...)
+ TODO: check
+CVE-2026-64874 (Joomla Extension - regularlabs.com - CDN Credential leakage
Cache Clea ...)
+ TODO: check
+CVE-2026-64873 (Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro
extensi ...)
+ TODO: check
+CVE-2026-64872 (Joomla Extension - regularlabs.com - Path traversal in Cache
Cleaner P ...)
+ TODO: check
+CVE-2026-64871 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
+ TODO: check
+CVE-2026-64815 (In JetBrains IntelliJ IDEA before 2026.2 arbitrary code
injection was ...)
+ TODO: check
+CVE-2026-64814 (In JetBrains IntelliJ IDEA before 2026.2 unauthorized file
access was ...)
+ TODO: check
+CVE-2026-64813 (In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings
modific ...)
+ TODO: check
+CVE-2026-64812 (In JetBrains IntelliJ IDEA before 2026.2 unauthorized input
injection ...)
+ TODO: check
+CVE-2026-64811 (In JetBrains IntelliJ IDEA before 2026.2 arbitrary code
execution was ...)
+ TODO: check
+CVE-2026-64810 (In JetBrains IntelliJ IDEA before 2026.2 hTML injection was
possible i ...)
+ TODO: check
+CVE-2026-64809 (In JetBrains PhpStorm before 2026.2 arbitrary code execution
was possi ...)
+ TODO: check
+CVE-2026-64808 (In JetBrains PhpStorm before 2026.2 arbitrary code execution
was possi ...)
+ TODO: check
+CVE-2026-64807 (In JetBrains WebStorm before 2026.2 arbitrary code execution
was possi ...)
+ TODO: check
+CVE-2026-64806 (In JetBrains WebStorm before 2026.2 arbitrary code execution
was possi ...)
+ TODO: check
+CVE-2026-64805 (In JetBrains WebStorm before 2026.2 arbitrary code execution
was possi ...)
+ TODO: check
+CVE-2026-64804 (In JetBrains WebStorm before 2026.2 arbitrary code execution
was possi ...)
+ TODO: check
+CVE-2026-64803 (In JetBrains GoLand before 2026.2 arbitrary code execution was
possibl ...)
+ TODO: check
+CVE-2026-64802 (In JetBrains GoLand before 2026.2 arbitrary code execution was
possibl ...)
+ TODO: check
+CVE-2026-64800 (In JetBrains GoLand before 2026.2 sensitive configuration
values writt ...)
+ TODO: check
+CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF via remote image
downloads i ...)
+ TODO: check
+CVE-2026-64611 (A flaw was found in libcupsfilters. The
cfIEEE1284NormalizeMakeModel() ...)
+ TODO: check
+CVE-2026-63765 (Chatwoot before 4.16.0 contains an authentication bypass
vulnerability ...)
+ TODO: check
+CVE-2026-61981 (Unauthenticated Cross Site Request Forgery (CSRF) in Simple
Link Direc ...)
+ TODO: check
+CVE-2026-61973 (Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5
versions.)
+ TODO: check
+CVE-2026-61972 (Unauthenticated Broken Access Control in ShopLentor Pro <=
2.8.5 versi ...)
+ TODO: check
+CVE-2026-61954 (Unauthenticated Broken Access Control in PayU India <= 3.8.9
versions.)
+ TODO: check
+CVE-2026-61951 (Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3
versions.)
+ TODO: check
+CVE-2026-61950 (Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.)
+ TODO: check
+CVE-2026-61949 (Unauthenticated SQL Injection in Bookly <= 27.7 versions.)
+ TODO: check
+CVE-2026-61948 (Unauthenticated SQL Injection in WPDM \u2013 Premium Packages
<= 6.2.0 ...)
+ TODO: check
+CVE-2026-61947 (Unauthenticated Cross Site Scripting (XSS) in Form Vibes
\u2013 Databa ...)
+ TODO: check
+CVE-2026-61946 (Unauthenticated Insecure Direct Object References (IDOR) in
Easy Appoi ...)
+ TODO: check
+CVE-2026-61945 (Exposure of Sensitive System Information to an Unauthorized
Control Sp ...)
+ TODO: check
+CVE-2026-61944 (Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7
versions.)
+ TODO: check
+CVE-2026-61943 (Unauthenticated Broken Access Control in WPDM \u2013 Premium
Packages ...)
+ TODO: check
+CVE-2026-59678 (An Incorrect Authorization vulnerability in Linux-Gaming
PortProtonQt ...)
+ TODO: check
+CVE-2026-59677 (A Missing Authorization vulnerability in selinux
policycoreutils seuns ...)
+ TODO: check
+CVE-2026-59555 (Unauthenticated Arbitrary File Deletion in Participants
Database <= 2. ...)
+ TODO: check
+CVE-2026-59554 (Unauthenticated Broken Authentication in Ziina <= 1.2.21
versions.)
+ TODO: check
+CVE-2026-59547 (Unauthenticated Broken Access Control in Payment Gateway for
PayPal on ...)
+ TODO: check
+CVE-2026-59545 (Unauthenticated Broken Authentication in miniOrange Discord
Integratio ...)
+ TODO: check
+CVE-2026-59544 (Unauthenticated PHP Object Injection in Thrive Quiz Builder <=
10.9.3. ...)
+ TODO: check
+CVE-2026-59543 (Subscriber Remote Code Execution (RCE) in Advanced Views <=
3.8.11 ver ...)
+ TODO: check
+CVE-2026-59542 (Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18
versions.)
+ TODO: check
+CVE-2026-59541 (Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1
versions.)
+ TODO: check
+CVE-2026-59540 (Unauthenticated Privilege Escalation in SMS Alert Order
Notifications ...)
+ TODO: check
+CVE-2026-59526 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
+ TODO: check
+CVE-2026-59525 (Unauthenticated SQL Injection in Participants Database <=
2.7.8.3 vers ...)
+ TODO: check
+CVE-2026-59524 (Unauthenticated Broken Authentication in Easy Digital
Downloads <= 3.6 ...)
+ TODO: check
+CVE-2026-59522 (Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.)
+ TODO: check
+CVE-2026-59517 (Unauthenticated Cross Site Scripting (XSS) in Easy Form
Builder <= 4.0 ...)
+ TODO: check
+CVE-2026-59514 (Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5
versions.)
+ TODO: check
+CVE-2026-59513 (Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <=
2.3.0 vers ...)
+ TODO: check
+CVE-2026-59512 (Unauthenticated Cross Site Scripting (XSS) in Product Enquiry
for WooC ...)
+ TODO: check
+CVE-2026-57809 (Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <=
2.34.0 ve ...)
+ TODO: check
+CVE-2026-57808 (Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0
versions.)
+ TODO: check
+CVE-2026-57785 (Unauthenticated Cross Site Request Forgery (CSRF) in
ApusListing <= 1. ...)
+ TODO: check
+CVE-2026-57784 (Unauthenticated Cross Site Request Forgery (CSRF) in Ninja
Forms File ...)
+ TODO: check
+CVE-2026-57769 (Unauthenticated Cross Site Scripting (XSS) in Grand
Photography <= 5.7 ...)
+ TODO: check
+CVE-2026-57767 (Unauthenticated Cross Site Scripting (XSS) in WP Google Maps
Pro <= 10 ...)
+ TODO: check
+CVE-2026-57735 (Unauthenticated Cross Site Scripting (XSS) in Breakdance <=
2.7.1 vers ...)
+ TODO: check
+CVE-2026-57717 (Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0
versions.)
+ TODO: check
+CVE-2026-57716 (Unauthenticated Arbitrary File Deletion in Broadcast Live
Video <= 7.2 ...)
+ TODO: check
+CVE-2026-57704 (Unauthenticated Cross Site Scripting (XSS) in Smart Manager <=
8.90.0 ...)
+ TODO: check
+CVE-2026-57703 (Subscriber Broken Access Control in Sunshine Photo Cart <=
3.6.10.1 ve ...)
+ TODO: check
+CVE-2026-57701 (Unauthenticated Cross Site Scripting (XSS) in Real Estate
Manager Pro ...)
+ TODO: check
+CVE-2026-57699 (Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13
versions ...)
+ TODO: check
+CVE-2026-57696 (Contributor Arbitrary File Deletion in Picture Gallery <=
1.6.5 versio ...)
+ TODO: check
+CVE-2026-57626 (Cross-Site Request Forgery (CSRF) vulnerability in MailPoet
allows Cro ...)
+ TODO: check
+CVE-2026-57428 (Unauthenticated Cross Site Scripting (XSS) in Sprout Clients
<= 3.2.3 ...)
+ TODO: check
+CVE-2026-57427 (Unauthenticated Cross Site Scripting (XSS) in Download Monitor
- WPFor ...)
+ TODO: check
+CVE-2026-57425 (Unauthenticated Broken Access Control in Autopay dla
WooCommerce <= 2. ...)
+ TODO: check
+CVE-2026-57397 (Unauthenticated Cross Site Scripting (XSS) in Coaching <=
3.9.2 versio ...)
+ TODO: check
+CVE-2026-57384 (Subscriber Cross Site Scripting (XSS) in WishList Member X <=
3.32.0 v ...)
+ TODO: check
+CVE-2026-57374 (Unauthenticated Cross Site Scripting (XSS) in Funnel Kit
Funnel Builde ...)
+ TODO: check
+CVE-2026-57373 (Customer Cross Site Scripting (XSS) in Funnel Kit Funnel
Builder PRO < ...)
+ TODO: check
+CVE-2026-57370 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic
Real Tim ...)
+ TODO: check
+CVE-2026-57367 (Subscriber Broken Access Control in WP Booking System <
5.12.8.1 versi ...)
+ TODO: check
+CVE-2026-52684 (If the auth responds very slowly and the records expire in
between, th ...)
+ TODO: check
+CVE-2026-48539 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-48538 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-48537 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-48536 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-48535 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-48534 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-48533
+ REJECTED
+CVE-2026-48532 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-48531 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-48530 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
+ TODO: check
+CVE-2026-47769 (APIFold reads an OpenAPI 3.x or Swagger 2.x specification and
generate ...)
+ TODO: check
+CVE-2026-47755 (ITFlow provides an IT documentation, ticketing and accounting
system f ...)
+ TODO: check
+CVE-2026-47752 (Tugtainer is a self-hosted app for automating updates of
Docker contai ...)
+ TODO: check
+CVE-2026-47743 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0,
three re ...)
+ TODO: check
+CVE-2026-47668 (DbGate is cross-platform database manager. In versions 7.1.8
and prior ...)
+ TODO: check
+CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection
mechanism in its ...)
+ TODO: check
+CVE-2026-44210 (Kata Containers is an open source project focusing on a
standard imple ...)
+ TODO: check
+CVE-2026-43823 (When initializing an RSA public key from DER or PEM bytes
throws an er ...)
+ TODO: check
+CVE-2026-43820 (NIOSSLCertificate._subjectAlternativeNames provides access to
the raw ...)
+ TODO: check
+CVE-2026-27423 (Subscriber Broken Access Control in Participants Database <=
2.7.8.4 v ...)
+ TODO: check
+CVE-2026-27422 (Unauthenticated Broken Access Control in YT Player <= 2.0.9
versions.)
+ TODO: check
+CVE-2026-27418 (Unauthenticated Broken Access Control in WP Fast Total Search
<= 1.81. ...)
+ TODO: check
+CVE-2026-27403 (Contributor Cross Site Scripting (XSS) in Hubbub Lite <=
1.36.3 versio ...)
+ TODO: check
+CVE-2026-27399 (Unauthenticated Broken Access Control in MarketKing <= 2.1.40
versions ...)
+ TODO: check
+CVE-2026-27392 (Contributor Broken Access Control in uListing <= 2.2.0
versions.)
+ TODO: check
+CVE-2026-27391 (Subscriber Broken Access Control in uListing <= 2.2.0
versions.)
+ TODO: check
+CVE-2026-27377 (Booking Agent Broken Access Control in QuickCal - Appointment
Booking ...)
+ TODO: check
+CVE-2026-27372 (Unauthenticated Sensitive Data Exposure in PeproDev Ultimate
Invoice < ...)
+ TODO: check
+CVE-2026-27355 (Unauthenticated Broken Access Control in Ditty <= 3.1.66
versions.)
+ TODO: check
+CVE-2026-27064 (Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.)
+ TODO: check
+CVE-2026-25466 (Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04
version ...)
+ TODO: check
+CVE-2026-25427 (Subscriber Broken Access Control in eRoom <= 1.7.1 versions.)
+ TODO: check
+CVE-2026-25424 (Contributor Broken Access Control in Mediavine Control Panel
<= 2.10.1 ...)
+ TODO: check
+CVE-2026-25405 (Contributor SQL Injection in eRoom <= 1.7.1 versions.)
+ TODO: check
+CVE-2026-24639 (Author Server Side Request Forgery (SSRF) in Photo Block <=
1.7.1 vers ...)
+ TODO: check
+CVE-2026-24628 (Administrator Cross Site Scripting (XSS) in Photo Gallery by
Supsystic ...)
+ TODO: check
+CVE-2026-24552 (Contributor SQL Injection in Create by Mediavine <= 2.5.3
versions.)
+ TODO: check
+CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP
Accessibility ...)
+ TODO: check
+CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially
crafted ICO f ...)
+ TODO: check
+CVE-2026-16756 (Missing connection and header-read timeouts and the absence of
a concu ...)
+ TODO: check
+CVE-2026-16745 (A flaw was found in odh-dashboard, the web console component
of Red Ha ...)
+ TODO: check
+CVE-2026-16735 (A security vulnerability has been detected in release-it
conventional- ...)
+ TODO: check
+CVE-2026-16733 (A weakness has been identified in bahmutov find-cypress-specs
up to 1. ...)
+ TODO: check
+CVE-2026-16723 (A remote code execution (RCE) vulnerability exists in fastjson
1.2.68 ...)
+ TODO: check
+CVE-2026-16584 (Improper handling of an initialization failure in AWS API MCP
Server f ...)
+ TODO: check
+CVE-2026-16287 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-16078 (The WCPOS \u2013 Point of Sale (POS) plugin for WooCommerce
plugin for ...)
+ TODO: check
+CVE-2026-15906 (The Premium Packages \u2013 Sell Digital Products Securely
plugin for ...)
+ TODO: check
+CVE-2026-15827 (The GutenKit Blocks plugin for WordPress is vulnerable to
unauthorized ...)
+ TODO: check
+CVE-2026-15794 (The Grid/List View for WooCommerce plugin for WordPress is
vulnerable ...)
+ TODO: check
+CVE-2026-15786 (The WP Encryption \u2013 One Click Free SSL Certificate & SSL
/ HTTPS ...)
+ TODO: check
+CVE-2026-15761 (The Tickera \u2013 Sell Tickets & Manage Events plugin for
WordPress i ...)
+ TODO: check
+CVE-2026-15687 (A security issue was discovered in the Kubernetes Java client
library ...)
+ TODO: check
+CVE-2026-15647 (The Brands for WooCommerce plugin for WordPress is vulnerable
to Store ...)
+ TODO: check
+CVE-2026-15646 (The Brands for WooCommerce plugin for WordPress is vulnerable
to Store ...)
+ TODO: check
+CVE-2026-15617 (Logto performs principal lookup without normalizing email and
identifi ...)
+ TODO: check
+CVE-2026-15616 (Logto does not enforce locally configured MFA during SSO
authenticatio ...)
+ TODO: check
+CVE-2026-15615 (Logto omits validation of the SAML <Conditions> element,
enabling atta ...)
+ TODO: check
+CVE-2026-15614 (Logto silently fails to delete IdP-initiated SAML sessions,
enabling s ...)
+ TODO: check
+CVE-2026-15612 (Logto bypasses OIDC nonce validation when the nonce claim is
absent fr ...)
+ TODO: check
+CVE-2026-15611 (Logto allows unverified email-based SSO account linking,
enabling an a ...)
+ TODO: check
+CVE-2026-15448 (The Tickera \u2013 Sell Tickets & Manage Events plugin for
WordPress i ...)
+ TODO: check
+CVE-2026-15404 (The Lpagery plugin for WordPress is vulnerable to Stored
Cross-Site Sc ...)
+ TODO: check
+CVE-2026-15394 (The Header Footer Script Adder \u2013 Insert Code in Header,
Body & Fo ...)
+ TODO: check
+CVE-2026-15348 (The Premium Packages \u2013 Sell Digital Products Securely
plugin for ...)
+ TODO: check
+CVE-2026-15037 (Improper output neutralization (XML injection) in QDom
comment, CDATA, ...)
+ TODO: check
+CVE-2026-15017 (The MDJM Event Management plugin for WordPress is vulnerable
to Privil ...)
+ TODO: check
+CVE-2026-15015 (The MountDev AI MCP Connector for WordPress plugin for
WordPress is vu ...)
+ TODO: check
+CVE-2026-15011 (The Customer Support Ticket System & Helpdesk plugin for
WordPress is ...)
+ TODO: check
+CVE-2026-14481 (The Equalize Digital Accessibility Checker \u2013 WCAG, ADA,
EAA and S ...)
+ TODO: check
+CVE-2026-14282 (The GoDAM \u2013 Organize WordPress Media Library & File
Manager with ...)
+ TODO: check
+CVE-2026-14257 (brace-expansion through 5.0.7 is vulnerable to denial of
service via m ...)
+ TODO: check
+CVE-2026-13119 (The Registrations For The Events Calendar plugin for WordPress
is vuln ...)
+ TODO: check
+CVE-2026-13009 (The AI Copilot \u2013 Content Generator plugin for WordPress
is vulner ...)
+ TODO: check
+CVE-2026-12421 (The ARforms plugin for WordPress is vulnerable to Stored
Cross-Site Sc ...)
+ TODO: check
+CVE-2026-11804 (Improper handling of insufficient permissions or privileges
vulnerabil ...)
+ TODO: check
+CVE-2025-68081 (Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3
version ...)
+ TODO: check
+CVE-2024-58330 (A missing authentication check in Bosch IP cameras of families
CPP13 a ...)
+ TODO: check
+CVE-2024-58023 (Information disclosure in Bosch Configuration Manager in
Version 7.72. ...)
+ TODO: check
CVE-2026-9737 (During query planning when reading the sort pattern in raw
BSONObj for ...)
- mongodb <removed>
NOTE: https://jira.mongodb.org/browse/SERVER-128341
@@ -17,33 +617,33 @@ CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer
error message handlin
TODO: check upstream status
CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation
vulnerab ...)
NOT-FOR-US: Question2Answer
-CVE-2026-64798 (Persistent URL login keys were also generated using a
non-cryptographi ...)
+CVE-2026-64798 (Joomla Extension - regularlabs.com - Insecure login URL keys
in IP log ...)
NOT-FOR-US: Joomla
-CVE-2026-64797 (IP Login trusted forwarded client-IP headers without requiring
a confi ...)
+CVE-2026-64797 (Joomla Extension - regularlabs.com - IP spoofing vulnerability
in IP l ...)
NOT-FOR-US: Joomla
-CVE-2026-64796 (Free did not require both the article creator and last
modifier to be ...)
+CVE-2026-64796 (Joomla Extension - regularlabs.com - various code injection
vectors in ...)
NOT-FOR-US: Joomla
-CVE-2026-64795 (Tag-provided custom HTML, module content/title overrides and
decoded m ...)
+CVE-2026-64795 (Joomla Extension - regularlabs.com - XSS vectors in
tag-provided input ...)
NOT-FOR-US: Joomla
-CVE-2026-64794 (User tags, filters and conditions allowed access to
insufficiently res ...)
+CVE-2026-64794 (Joomla Extension - regularlabs.com - restricted user-data
exposure in ...)
NOT-FOR-US: Joomla
-CVE-2026-64793 (Content tags could use ignore flags or property overrides to
render re ...)
+CVE-2026-64793 (Joomla Extension - regularlabs.com - Content access and
publication by ...)
NOT-FOR-US: Joomla
-CVE-2026-64792 (Smart Search indexing could render generated content using the
indexin ...)
+CVE-2026-64792 (Joomla Extension - regularlabs.com - disclosure of restricted
content ...)
NOT-FOR-US: Joomla
-CVE-2026-64791 (Administrator routes and install/update/uninstall processing
did not c ...)
+CVE-2026-64791 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
NOT-FOR-US: Joomla
-CVE-2026-63685 (Administrator routes and replacement requests did not
consistently req ...)
+CVE-2026-63685 (Joomla Extension - regularlabs.com - Authorization bypass in
DB Replac ...)
NOT-FOR-US: Joomla
-CVE-2026-63684 (Administrator actions, editor popups and import/export
requests lacked ...)
+CVE-2026-63684 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
NOT-FOR-US: Joomla
-CVE-2026-63683 (IP and GeoIP conditions trusted spoofable forwarded headers,
allowing ...)
+CVE-2026-63683 (Joomla Extension - regularlabs.com - Client IP spoofing
vulnerability ...)
NOT-FOR-US: Joomla
-CVE-2026-63281 (Stored condition values could also execute HTML/JavaScript in
administ ...)
+CVE-2026-63281 (Joomla Extension - regularlabs.com - XSS vulnerability in
Regular Labs ...)
NOT-FOR-US: Joomla
-CVE-2026-63280 (Conditions administration did not consistently enforce tokens
and comp ...)
+CVE-2026-63280 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
NOT-FOR-US: Joomla
-CVE-2026-63265 (Privileged Regular Labs AJAX endpoints did not consistently
require va ...)
+CVE-2026-63265 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
NOT-FOR-US: Joomla
CVE-2026-63226 (Printers and Multifunction Printers (MFPs) provided by Ricoh
Company, ...)
NOT-FOR-US: Ricoh
@@ -251,11 +851,11 @@ CVE-2026-64830 (FFmpeg versions 2.1 through 8.1.2
contains a heap buffer overflo
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951
CVE-2026-64828 (Froiden TableTrack through 1.3.10 contains a stored cross-site
scripti ...)
NOT-FOR-US: Froiden TableTrack
-CVE-2026-63264 (The Joomla extension JoomShopping is vulnerable to an
reflected XSS vu ...)
+CVE-2026-63264 (Joomla Extension - joomshopping.com - Reflective XSS in
JoomShopping < ...)
NOT-FOR-US: Joomla
-CVE-2026-63048 (The Joomla extension Page Builder CK is vulnerable to an
authenticated ...)
+CVE-2026-63048 (Joomla Extension - joomlack.fr - Improper access control in
Page Build ...)
NOT-FOR-US: Joomla
-CVE-2026-63047 (The Joomla extension Events Booking prior version 5.0-5.8.1
did not pr ...)
+CVE-2026-63047 (Joomla Extension - joomdonation.com - Invoice data
exfiltration via in ...)
NOT-FOR-US: Joomla
CVE-2026-62145 (A vulnerability in Check Point Gaia Portal allows an
authenticated att ...)
NOT-FOR-US: Check Point Gaia Portal
@@ -322,7 +922,8 @@ CVE-2026-16606 (A vulnerability in Fujitsu Software Linux
openFT andFujitsu Soft
CVE-2026-16560 (A heap-buffer-overflow flaw was found in Directory Server
(389-ds-base ...)
- 389-ds-base <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506102
-CVE-2026-16552 (A flaw was found in systemd-tmpfiles. When processing a
tmpfiles.d con ...)
+CVE-2026-16552
+ REJECTED
- systemd <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506073
CVE-2026-16551 (Denial-of-Service in Thinkst Applied Research OpenCanary
(MongoDB modu ...)
@@ -485,13 +1086,13 @@ CVE-2026-13321 (The BIND resolver accepts validly-signed
NSEC records where the
{DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-13321
-CVE-2026-52688
+CVE-2026-52688 (RRSIGs with too few labels can lead to bypass of DNSSEC
wildcard valid ...)
{DSA-6397-1}
- pdns-recursor 5.4.4-1
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
[bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
NOTE:
https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-10.html
-CVE-2026-52686
+CVE-2026-52686 (The issue is a DNSSEC validation bypass where wildcard
expansion proof ...)
{DSA-6397-1}
- pdns-recursor 5.4.4-1
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
@@ -575,7 +1176,7 @@ CVE-2026-64614 (Data::Deque::Shared versions before 0.06
for Perl create a world
NOT-FOR-US: Data::Deque::Shared Perl module
CVE-2026-64613 (Data::Buffer::Shared versions before 0.05 for Perl create a
world-read ...)
NOT-FOR-US: Data::Buffer::Shared Perl module
-CVE-2026-63764 (lmdeploy's OpenAI-compatible API server contains a server-side
request ...)
+CVE-2026-63764 (LMDeploy through 0.14.0, fixed in commit 03c3130, contains a
server-si ...)
NOT-FOR-US: lmdeploy
CVE-2026-63358 (FileGator accepts arbitrary Unix permission values via the
'/chmoditem ...)
NOT-FOR-US: FileGator
@@ -3194,7 +3795,7 @@ CVE-2026-63454 (An authenticated path traversal
vulnerability exists in AOS-CX.
NOT-FOR-US: HPE
CVE-2026-63453 (Buffer overflow vulnerabilities exist in the command line
interface of ...)
NOT-FOR-US: HPE
-CVE-2026-62415 (The Joomla extension Membership Pro prior version 4.6.2 did by
default ...)
+CVE-2026-62415 (Joomla Extension - joomdonation.com - Insecure default
configuration M ...)
NOT-FOR-US: Joomla
CVE-2026-60080 (Use After Free vulnerability in the Rust deserialization logic
of Apac ...)
NOT-FOR-US: Apache software not packaged in Debian
@@ -3423,19 +4024,19 @@ CVE-2026-16361 (Memory safety bugs present in
Thunderbird ESR 140.12. Some of th
{DSA-6394-1 DLA-4695-1}
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
-CVE-2026-16360 (Memory safety bugs present in Thunderbird ESR 140.12 and
Thunderbird 1 ...)
+CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR
140.12 a ...)
{DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
-CVE-2026-16412 (Memory safety bugs present in Thunderbird ESR 140.12 and
Thunderbird 1 ...)
+CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox
152. Some ...)
{DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
-CVE-2026-16411 (Memory safety bugs present in Thunderbird 152. Some of these
bugs show ...)
+CVE-2026-16411 (Memory safety bugs present in Firefox 152. Some of these bugs
showed e ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16411
CVE-2026-16410 (JIT miscompilation in the JavaScript Engine: JIT component.
This vulne ...)
@@ -3816,15 +4417,15 @@ CVE-2026-63729 (The SyncTeX parser (synctex_parser.c)
shipped with TeX Live and
NOTE:
https://fatihhcelik.github.io/posts/evince-synctex-heap-use-after-free/
CVE-2026-63728 (Gitleaks prior to 8.30.1 contains a template injection
vulnerability t ...)
NOT-FOR-US: Gitleaks
-CVE-2026-62414 (The Joomla extension Page Builder CK does not properly apply
access co ...)
+CVE-2026-62414 (Joomla Extension - joomlack.fr - Improper access control in
Page Build ...)
NOT-FOR-US: Joomla
-CVE-2026-61901 (The Joomla extension Hikashop is vulnerable to an open
redirect.)
+CVE-2026-61901 (Joomla Extension - hikashop.com - Open redirect in Hikashop <
6.5.2 - ...)
NOT-FOR-US: Joomla
-CVE-2026-61900 (The Joomla extension JDownloads is vulnerable to an
unauthenticated fi ...)
+CVE-2026-61900 (Joomla Extension - dj-extensions.com - Unauthenticated
arbitrary file ...)
NOT-FOR-US: Joomla
-CVE-2026-61425 (The Joomla extension Gridbox is vulnerable an authenticated
bypass, po ...)
+CVE-2026-61425 (Joomla Extension - balbooa.com - Authentication bypass in
Gridbox < 1. ...)
NOT-FOR-US: Joomla
-CVE-2026-61424 (The Joomla extension DJ-Classifieds is vulnerable to an
unauthenticate ...)
+CVE-2026-61424 (Joomla Extension - dj-extensions.com - Unauthenticated
arbitrary file ...)
NOT-FOR-US: Joomla
CVE-2026-59776 (Missing Cryptographic Step (CWE-325) vulnerability exists in
certain F ...)
NOT-FOR-US: FeliCa IC chips issues
@@ -4112,23 +4713,23 @@ CVE-2026-62418 (Low-privileged authenticated
Server-Side Request Forgery (SSRF)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-62183 (Improper Privilege Management vulnerability in Apache Syncope.
When: ...)
NOT-FOR-US: Apache software not packaged in Debian
-CVE-2026-60034 (The Joomla extension JMedia is vulnerable to a stored XSS
vulnerabilit ...)
+CVE-2026-60034 (Joomla Extension - themexpert.com - Authenticated stored XSS
in JMedia ...)
NOT-FOR-US: Joomla
-CVE-2026-60033 (The Joomla extension JMedia is vulnerable to an SSRF
vulnerability. Re ...)
+CVE-2026-60033 (Joomla Extension - themexpert.com - SSRF via remote download
in JMedia ...)
NOT-FOR-US: Joomla
-CVE-2026-60032 (The Joomla extension JMedia is vulnerable to an authenticated
arbitrar ...)
+CVE-2026-60032 (Joomla Extension - themexpert.com - Authenticated arbitrary
file uploa ...)
NOT-FOR-US: Joomla
-CVE-2026-60031 (The Joomla extension Quix Page Builder Pro is vulnerable to an
informa ...)
+CVE-2026-60031 (Joomla Extension - themexpert.com - Information disclosure in
Quix Pag ...)
NOT-FOR-US: Joomla
-CVE-2026-60030 (The Joomla extension Quix Page Builder Pro is vulnerable to an
imprope ...)
+CVE-2026-60030 (Joomla Extension - themexpert.com - Broken Access Control for
media ma ...)
NOT-FOR-US: Joomla
-CVE-2026-60029 (The Joomla extension Quix Page Builder Pro is vulnerable to an
authent ...)
+CVE-2026-60029 (Joomla Extension - themexpert.com - Authenticated stored XSS
in Quix P ...)
NOT-FOR-US: Joomla
-CVE-2026-60028 (The Joomla extension Quix Page Builder Pro is vulnerable to an
authent ...)
+CVE-2026-60028 (Joomla Extension - themexpert.com - Authenticated stored XSS
in Quix P ...)
NOT-FOR-US: Joomla
-CVE-2026-60027 (The Joomla extension Quix Page Builder Pro is vulnerable to a
unauthen ...)
+CVE-2026-60027 (Joomla Extension - themexpert.com - Unauthenticated path
traversal / f ...)
NOT-FOR-US: Joomla
-CVE-2026-60026 (The Joomla extension Quix Page Builder Pro is vulnerable to an
authent ...)
+CVE-2026-60026 (Joomla Extension - themexpert.com - Authenticated PHP code
execution i ...)
NOT-FOR-US: Joomla
CVE-2026-59238 (Stored Cross-site Scripting (CWE-79) in the client-side report
renderi ...)
NOT-FOR-US: maalfer Pentestify
@@ -7394,9 +7995,9 @@ CVE-2026-63093 (Cursor for Windows version 3.2.16
contains a binary planting vul
NOT-FOR-US: Cursor
CVE-2026-62764 (Improper Handling of Insufficient Privileges vulnerability in
Apache A ...)
NOT-FOR-US: Apache software not packaged in Debian
-CVE-2026-60025 (The Joomla extension Events Booking prior version 5.8.0 had an
fronten ...)
+CVE-2026-60025 (Joomla Extension - joomdonation.com - User enumeration in
Events Booki ...)
NOT-FOR-US: Joomla
-CVE-2026-60024 (The Joomla extension Events Booking prior version 5.8.0 did by
default ...)
+CVE-2026-60024 (Joomla Extension - joomdonation.com - Insecure default
configuration E ...)
NOT-FOR-US: Joomla
CVE-2026-59695 (Improper Validation of Specified Quantity in Input in ZenHive
mpp allo ...)
NOT-FOR-US: ZenHive mpp
@@ -7406,9 +8007,9 @@ CVE-2026-59252 (Improper Validation of Specified Quantity
in Input in ZenHive mp
NOT-FOR-US: ZenHive mpp
CVE-2026-58195 (Agentic-Flow is an AI agent orchestration platform. Prior to
2.0.14, a ...)
NOT-FOR-US: Agentic-Flow
-CVE-2026-58149 (The Joomla extension Events Booking is vulnerable to an
unauthenticate ...)
+CVE-2026-58149 (Joomla Extension - joomdonation.com - User enumeration in
Events Booki ...)
NOT-FOR-US: Joomla
-CVE-2026-58148 (The Joomla extension ChronoForms is vulnerable to an
unauthenticated s ...)
+CVE-2026-58148 (Joomla Extension - chronoengine.com - Stored XSS in
ChronoForms extens ...)
NOT-FOR-US: Joomla
CVE-2026-57860 (ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI,
automati ...)
NOT-FOR-US: ForgeCode
@@ -7824,7 +8425,7 @@ CVE-2026-58598 (Concurrent execution using shared
resource with improper synchro
NOT-FOR-US: Microsoft
CVE-2026-58317 (Unsigned to Signed Conversion Error (CWE-196) vulnerability
exists in ...)
NOT-FOR-US: Tera Term
-CVE-2026-58078 (The Joomla extension Quix Page Builder Pro is vulnerable to an
unauthe ...)
+CVE-2026-58078 (Joomla Extension - themexpert.com - Unauthenticated SQL
injection in Q ...)
NOT-FOR-US: Joomla
CVE-2026-57896 (An out-of-bounds read vulnerability in the Productivity Suite
allows a ...)
NOT-FOR-US: Productivity Suite
@@ -8568,6 +9169,7 @@ CVE-2026-62164
CVE-2026-61873 (Grav before 9.1.8 contains an arbitrary file write
vulnerability in th ...)
NOT-FOR-US: Grav CMS
CVE-2026-61872 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h5r4-w88w-7ccr
@@ -8583,12 +9185,14 @@ CVE-2026-61871 (ImageMagick before 7.1.2-26 and
6.9.13-51 contains a memory leak
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/e4b68bfb6a9541a9c3a4af81a21bf0c253661083
(6.9.13-51)
NOTE: Introduced by:
https://github.com/ImageMagick/ImageMagick6/commit/24397534f7c5694840bd6b70bf2d16efe7382b5c
(6.9.13-11)
CVE-2026-61869 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r628-69v2-2f9c
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/b2dc602e175ee07b0794f3e31f1a29ae6b7267d1
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/ca6c9da425880fde937da41d59666dedf5e719e1
(6.9.13-51)
CVE-2026-61868 (ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51
contains a memo ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h7f2-f9cc-h2gv
@@ -8603,12 +9207,14 @@ CVE-2026-61867 (ImageMagick before 7.1.2-26 contains a
memory leak vulnerability
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/f34065ecd9512df16cb10083c8b4b46b5cd09b30
(7.1.2-26)
NOTE: Introduced by
https://github.com/ImageMagick/ImageMagick/commit/14c08dcd1910ecd8360f51d13885b2c9c39b655d
(7.0.1-0)
CVE-2026-61866 (ImageMagick before 7.1.2-26 contains a memory leak
vulnerability in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/0bb3578ee087f3c4f14bbf1d8883ae456fc99092
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/353e2604d1983b6d8ec4c04f4f38bbd4668ba0e1
(6.9.13-51)
CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x
@@ -8616,6 +9222,7 @@ CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51
contains a memory leak
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8
(6.9.13-52)
NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862,
CVE-2026-61864, CVE-2026-61863
CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in co ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq
@@ -8623,6 +9230,7 @@ CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51
contains a memory leak
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8
(6.9.13-52)
NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862,
CVE-2026-61861, CVE-2026-61865
CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51)
contains a memo ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9
@@ -8630,6 +9238,7 @@ CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x
before 6.9.13-51) contains
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8
(6.9.13-52)
NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862,
CVE-2026-61864, CVE-2026-61865
CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an
information disc ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx
@@ -8637,12 +9246,14 @@ CVE-2026-61862 (ImageMagick before 7.1.2-26 and
6.9.13-51 contains an informatio
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8
(6.9.13-52)
NOTE: For imagemagick 6 patch include fix for CVE-2026-61863,
CVE-2026-61864
CVE-2026-61860 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a
use-after-free vu ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/3fc646a498eecda9163164046189f90dc677ae64
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/eed471c1286aa27c076348b453b35a2e962967bc
(6.9.13-51)
CVE-2026-61859 (ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51
contains a p ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398
@@ -8681,6 +9292,7 @@ CVE-2026-61606
CVE-2026-61605
REJECTED
CVE-2026-61464 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a
heap-based buffer ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr
@@ -8780,15 +9392,15 @@ CVE-2026-58550 (Out-of-bounds read vulnerability in the
image codec module. Impa
NOT-FOR-US: Huawei
CVE-2026-58549 (Out-of-bounds read vulnerability in the image codec module.
Impact: Su ...)
NOT-FOR-US: Huawei
-CVE-2026-58077 (The Joomla extension 4Analytics is vulnerable to an
unauthenticated st ...)
+CVE-2026-58077 (Joomla Extension - weeblr.com - Unauthenticated stored XSS in
4Analyti ...)
NOT-FOR-US: Joomla
CVE-2026-57996 (phpMyFAQ before 4.1.5 contains a privilege escalation
vulnerability in ...)
NOT-FOR-US: phpMyFAQ
-CVE-2026-57833 (The Joomla extension 4Analytics is vulnerable to an
unauthenticated st ...)
+CVE-2026-57833 (Joomla Extension - weeblr.com - Unauthenticated stored XSS in
4Analyti ...)
NOT-FOR-US: Joomla
-CVE-2026-57832 (The Joomla extension EDocman is vulnerable to an
unauthenticated SQL i ...)
+CVE-2026-57832 (Joomla Extension - joomdonation.com - Unauthenticated blind
SQL inject ...)
NOT-FOR-US: Joomla
-CVE-2026-57831 (The Joomla extension DP Calendar is vulnerable to an
unauthenticated S ...)
+CVE-2026-57831 (Joomla Extension - digital-peak.com - Unauthenticated blind
SQL inject ...)
NOT-FOR-US: Joomla
CVE-2026-57821 (A SQL Injection vulnerability exists in Apache Fineract's
Office Searc ...)
NOT-FOR-US: Apache software not packaged in Debian
@@ -11364,9 +11976,9 @@ CVE-2026-58228 (Cross-site scripting vulnerability in
phoenixframework phoenix_l
NOT-FOR-US: phoenixframework phoenix_live_view
CVE-2026-58065 (The Apache Airflow Git provider runs its git-over-SSH
operations with ...)
NOT-FOR-US: Apache Airflow Git provider
-CVE-2026-57830 (The Joomla extension Helix Ultimate is vulnerable to an
unauthenticate ...)
+CVE-2026-57830 (Joomla Extension - joomshaper.com - Unauthenticated arbitrary
file del ...)
NOT-FOR-US: Joomla
-CVE-2026-57829 (The Joomla extension Helix Ultimate is vulnerable to an
unauthenticate ...)
+CVE-2026-57829 (Joomla Extension - joomshaper.com - Unauthenticated stored XSS
in Heli ...)
NOT-FOR-US: Joomla
CVE-2026-57816 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
@@ -11972,6 +12584,7 @@ CVE-2026-15471 (A vulnerability was found in Eleveo
Call Recording Software 9.7.
CVE-2026-15470 (A vulnerability has been found in Eleveo Call Recording
Software 9.7.0 ...)
NOT-FOR-US: Eleveo Call Recording Software
CVE-2026-61870 (ImageMagick before 7.1.2-26 contains a memory leak
vulnerability in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m596-67p7-69wh
@@ -11987,18 +12600,21 @@ CVE-2026-61861 (ImageMagick before 7.1.2-26 contains
a use-after-free vulnerabil
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/0091f38a106601893c77c2d298708048cd2930f5
(6.9.13-51)
NOTE: Introduced by
https://github.com/ImageMagick/ImageMagick6/commit/1d597191bd1f45d05ff041c89b7e3f8759e9eaf5
(6.9.12-24)
CVE-2026-61858 (ImageMagick before 7.1.2-26 contains a policy bypass
vulnerability in ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/19c11cb0aefbd627c95c4c08c44722e660025aa1
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/5fbcfe76fd8be554e30ec1d8723c00ae8b68f470
(6.9.13-51)
CVE-2026-61857 (ImageMagick before 7.1.2-26 contains a heap use-after-free
vulnerabili ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh5g-q395-cx4j
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/150c9852402ac1aa1f223e5bf5109e3a2022ebbc
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/e1d94d92d985f8c0bb648ddbcd70ba3362a84674
(6.9.13-51)
CVE-2026-61465 (ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check
for the a ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvhp-75f6-9jqh
@@ -12028,9 +12644,9 @@ CVE-2026-60090 (PraisonAI before 4.6.78 fails to
validate the caller-controlled
NOT-FOR-US: PraisonAI
CVE-2026-60088 (PraisonAI before 4.6.78 fails to validate file path references
in cust ...)
NOT-FOR-US: PraisonAI
-CVE-2026-57828 (The Joomla extension Phoca Downloads is vulnerable to an
authenticated ...)
+CVE-2026-57828 (Joomla Extension - phoca.cz - Authenticated file upload in
RSFiles com ...)
NOT-FOR-US: Joomla
-CVE-2026-57827 (The Joomla extension RSFiles is vulnerable to an
unauthenticated arbit ...)
+CVE-2026-57827 (Joomla Extension - rsjoomla.com - Unauthenticated file upload
in RSFil ...)
NOT-FOR-US: Joomla
CVE-2026-56763 (Hono before 4.12.7 allows __proto__ key in parseBody with dot
option e ...)
NOT-FOR-US: Hono
@@ -13284,9 +13900,9 @@ CVE-2026-56459 (HCL DevOps Deploy / HCL Launch is
susceptible to sensitive infor
NOT-FOR-US: HCL
CVE-2026-56458 (HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS)
which coul ...)
NOT-FOR-US: HCL
-CVE-2026-56292 (A SQLi vulnerability in AcyMailing component < 10.11.1 for
Joomla was ...)
+CVE-2026-56292 (Joomla Extension - acymailing.com - SQL Injection in
AcyMailing extens ...)
NOT-FOR-US: Joomla
-CVE-2026-56291 (The Joomla extension Balbooa Forms is vulnerable to an
unauthenticated ...)
+CVE-2026-56291 (Joomla Extension - balbooa.com - Unauthenticated file upload
in Balboo ...)
NOT-FOR-US: Joomla
CVE-2026-56289 (GNU patch is vulnerable to a denial of service (DoS) due to
improper v ...)
- patch <unfixed> (unimportant)
@@ -20659,6 +21275,7 @@ CVE-2026-51218 (A heap buffer overflow in the
TS7Worker::PerformFunctionWrite()
CVE-2026-43746 (A use-after-free issue was addressed with improved memory
management. ...)
NOT-FOR-US: Apple
CVE-2026-43745 (An out-of-bounds write issue was addressed with improved input
validat ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20670,6 +21287,7 @@ CVE-2026-43745 (An out-of-bounds write issue was
addressed with improved input v
CVE-2026-43743 (A race condition was addressed with improved state handling.
This issu ...)
NOT-FOR-US: Apple
CVE-2026-43742 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20679,6 +21297,7 @@ CVE-2026-43742 (A use-after-free issue was addressed
with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43740 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20690,6 +21309,7 @@ CVE-2026-43740 (The issue was addressed with improved
memory handling. This issu
CVE-2026-43735 (The issue was addressed with improved checks. This issue is
fixed in S ...)
NOT-FOR-US: Apple
CVE-2026-43734 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20699,6 +21319,7 @@ CVE-2026-43734 (A use-after-free issue was addressed
with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43732 (A path handling issue was addressed with improved validation.
This iss ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20708,6 +21329,7 @@ CVE-2026-43732 (A path handling issue was addressed
with improved validation. Th
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43731 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20717,6 +21339,7 @@ CVE-2026-43731 (A use-after-free issue was addressed
with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43727 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20726,6 +21349,7 @@ CVE-2026-43727 (A use-after-free issue was addressed
with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43726 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20735,6 +21359,7 @@ CVE-2026-43726 (A use-after-free issue was addressed
with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43725 (The issue was addressed with improved input validation. This
issue is ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20748,6 +21373,7 @@ CVE-2026-43724 (The issue was addressed with improved
input sanitization. This i
CVE-2026-43722 (The issue was addressed with improved input sanitization. This
issue i ...)
NOT-FOR-US: Apple
CVE-2026-43721 (This issue was addressed through improved state management.
This issue ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20757,6 +21383,7 @@ CVE-2026-43721 (This issue was addressed through
improved state management. This
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43720 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20770,6 +21397,7 @@ CVE-2026-43718 (A stack overflow was addressed with
improved input validation. T
CVE-2026-43717 (A use-after-free issue was addressed with improved memory
management. ...)
NOT-FOR-US: Apple
CVE-2026-43716 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20779,6 +21407,7 @@ CVE-2026-43716 (The issue was addressed with improved
memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43715 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20788,6 +21417,7 @@ CVE-2026-43715 (A use-after-free issue was addressed
with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43713 (A permissions issue was addressed with additional
restrictions. This i ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20797,6 +21427,7 @@ CVE-2026-43713 (A permissions issue was addressed with
additional restrictions.
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43712 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20810,6 +21441,7 @@ CVE-2026-43709 (A use-after-free issue was addressed
with improved memory manage
CVE-2026-43708 (The issue was addressed with improved input validation. This
issue is ...)
NOT-FOR-US: Apple
CVE-2026-43707 (A memory corruption issue was addressed with improved memory
handling. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20821,6 +21453,7 @@ CVE-2026-43707 (A memory corruption issue was addressed
with improved memory han
CVE-2026-43706 (A double free issue was addressed with improved memory
management. Thi ...)
NOT-FOR-US: Apple
CVE-2026-43705 (A type confusion issue was addressed with improved checks.
This issue ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20834,6 +21467,7 @@ CVE-2026-43704 (A use-after-free issue was addressed
with improved memory manage
CVE-2026-43703 (The issue was addressed with improved memory handling. This
issue is f ...)
NOT-FOR-US: Apple
CVE-2026-43701 (The issue was addressed with improved checks. This issue is
fixed in S ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20845,6 +21479,7 @@ CVE-2026-43701 (The issue was addressed with improved
checks. This issue is fixe
CVE-2026-43700 (A cross-origin issue was addressed with improved tracking of
security ...)
NOT-FOR-US: Apple
CVE-2026-43699 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20854,6 +21489,7 @@ CVE-2026-43699 (A use-after-free issue was addressed
with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0002.html
CVE-2026-43676 (An out-of-bounds access issue was addressed with improved
bounds check ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20863,6 +21499,7 @@ CVE-2026-43676 (An out-of-bounds access issue was
addressed with improved bounds
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0002.html
CVE-2026-43663 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20874,6 +21511,7 @@ CVE-2026-43663 (The issue was addressed with improved
memory handling. This issu
CVE-2026-41896 (Coolify is an open-source and self-hostable tool for managing
servers, ...)
NOT-FOR-US: Coolify
CVE-2026-39872 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -21115,7 +21753,7 @@ CVE-2026-56780 (Modoboa before 2.9.0 contains an
insecure direct object referenc
NOT-FOR-US: Modoboa
CVE-2026-56457 (HCL DevOps Deploy / HCL Launch is susceptible to an exposure
of sensit ...)
NOT-FOR-US: HCL
-CVE-2026-56290 (The Joomla extension Page Builder CK is vulnerable to an
unauthenticat ...)
+CVE-2026-56290 (Joomla Extension - joomlack.fr - Unauthenticated file upload
in Page B ...)
NOT-FOR-US: Joomla
CVE-2026-56285 (Nitter's /video media proxy endpoint fails to validate target
URLs aga ...)
NOT-FOR-US: Nitter
@@ -48098,7 +48736,7 @@ CVE-2026-9274 (This vulnerability exists in CP Plus
Wi-Fi Camera due to improper
NOT-FOR-US: CP Plus Wi-Fi Camera
CVE-2026-9078 (Firefox for iOS displayed specially crafted right-to-left (RTL)
and in ...)
NOT-FOR-US: Firefox for iOS
-CVE-2026-9058 (Szafir SDK returns a success status code from the cryptographic
digita ...)
+CVE-2026-9058 (For untrusted certificates that contain the "Authority
Information Acc ...)
NOT-FOR-US: Szafir SDK
CVE-2026-7766 (Kenik Camera management Panel is vulnerable to Path Traversal
vulnerab ...)
NOT-FOR-US: Kenik Camera management Panel
@@ -55162,6 +55800,7 @@ CVE-2026-43666 (An out-of-bounds write issue was
addressed with improved bounds
CVE-2026-43661 (A buffer overflow issue was addressed with improved memory
handling. T ...)
NOT-FOR-US: Apple
CVE-2026-43660 (A validation issue was addressed with improved logic. This
issue is fi ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55173,6 +55812,7 @@ CVE-2026-43660 (A validation issue was addressed with
improved logic. This issue
CVE-2026-43659 (A race condition was addressed with additional validation.
This issue ...)
NOT-FOR-US: Apple
CVE-2026-43658 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55342,6 +55982,7 @@ CVE-2026-28961 (This issue was addressed with improved
checks. This issue is fix
CVE-2026-28959 (A buffer overflow was addressed with improved bounds checking.
This is ...)
NOT-FOR-US: Apple
CVE-2026-28958 (This issue was addressed with improved data protection. This
issue is ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55355,6 +55996,7 @@ CVE-2026-28957 (An issue with app access to camera
metadata was addressed with i
CVE-2026-28956 (A memory corruption issue was addressed with improved input
validation ...)
NOT-FOR-US: Apple
CVE-2026-28955 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55366,6 +56008,7 @@ CVE-2026-28955 (The issue was addressed with improved
memory handling. This issu
CVE-2026-28954 (A file quarantine bypass was addressed with additional checks.
This is ...)
NOT-FOR-US: Apple
CVE-2026-28953 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55379,6 +56022,7 @@ CVE-2026-28952 (An integer overflow was addressed with
improved input validation
CVE-2026-28951 (An authorization issue was addressed with improved state
management. T ...)
NOT-FOR-US: Apple
CVE-2026-28947 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55388,6 +56032,7 @@ CVE-2026-28947 (A use-after-free issue was addressed
with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28946 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55401,6 +56046,7 @@ CVE-2026-28944 (The issue was addressed with improved
memory handling. This issu
CVE-2026-28943 (A logging issue was addressed with improved data redaction.
This issue ...)
NOT-FOR-US: Apple
CVE-2026-28942 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55446,6 +56092,7 @@ CVE-2026-28910 (This issue was addressed with improved
permissions checking. Thi
CVE-2026-28908 (A denial of service issue was addressed by removing the
vulnerable cod ...)
NOT-FOR-US: Apple
CVE-2026-28907 (The issue was addressed with improved input validation. This
issue is ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55457,6 +56104,7 @@ CVE-2026-28907 (The issue was addressed with improved
input validation. This iss
CVE-2026-28906 (This issue was addressed through improved state management.
This issue ...)
NOT-FOR-US: Apple
CVE-2026-28905 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55466,6 +56114,7 @@ CVE-2026-28905 (The issue was addressed with improved
memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28904 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55475,6 +56124,7 @@ CVE-2026-28904 (The issue was addressed with improved
memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28903 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55484,6 +56134,7 @@ CVE-2026-28903 (The issue was addressed with improved
memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28902 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55493,6 +56144,7 @@ CVE-2026-28902 (The issue was addressed with improved
memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28901 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55504,6 +56156,7 @@ CVE-2026-28901 (The issue was addressed with improved
memory handling. This issu
CVE-2026-28897 (A buffer overflow was addressed with improved input
validation. This i ...)
NOT-FOR-US: Apple
CVE-2026-28883 (A use-after-free issue was addressed with improved memory
management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55521,6 +56174,7 @@ CVE-2026-28860 (The issue was addressed with improved
input validation. This iss
CVE-2026-28848 (A buffer overflow was addressed with improved bounds checking.
This is ...)
NOT-FOR-US: Apple
CVE-2026-28847 (The issue was addressed with improved memory handling. This
issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -310383,7 +311037,7 @@ CVE-2024-4765 (Web application manifests were stored
by using an insecure MD5 ha
- firefox <not-affected> (Android-specific)
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2024-21/#CVE-2024-4765
CVE-2024-4367 (A type check was missing when handling fonts in PDF.js, which
would al ...)
- {DSA-5742-1 DSA-5693-1 DSA-5691-1 DLA-3817-1 DLA-3815-1}
+ {DSA-6398-1 DSA-5742-1 DSA-5693-1 DSA-5691-1 DLA-3817-1 DLA-3815-1}
- firefox 126.0-1
- firefox-esr 115.11.0esr-1
- thunderbird 1:115.11.0-1
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60a0fffaa57d1ebdce1d6a002f0b0a48d4a33f5a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60a0fffaa57d1ebdce1d6a002f0b0a48d4a33f5a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits