Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
032290e3 by security tracker role at 2026-07-24T07:12:54+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,8 +1,184 @@
+CVE-2026-6924 (A bug in the entropy initialization for SiWx917 causes the DRBG
to use ...)
+ TODO: check
+CVE-2026-6454 (The Firelight Lightbox plugin for WordPress is vulnerable to
Stored DO ...)
+ TODO: check
+CVE-2026-66141 (Exim before 4.99.5 allows .forward privilege escalation
because force_ ...)
+ TODO: check
+CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files
outside ...)
+ TODO: check
+CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass
via an EXT ...)
+ TODO: check
+CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0,
aproject-scoped user ...)
+ TODO: check
+CVE-2026-65706 (FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds
write vulne ...)
+ TODO: check
+CVE-2026-65705 (FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds
write vulne ...)
+ TODO: check
+CVE-2026-65704 (FFmpeg through 8.1.2 contains an out-of-bounds write
vulnerability tha ...)
+ TODO: check
+CVE-2026-65703 (FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds
write vulne ...)
+ TODO: check
+CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path traversal
vulnerability ...)
+ TODO: check
+CVE-2026-65604 (Skipper contains an incomplete fix for CVE-2026-50197 in which
oversiz ...)
+ TODO: check
+CVE-2026-64785 (SwiftNIO HTTP/2 was missing validation on inbound HEADERS
frames that ...)
+ TODO: check
+CVE-2026-63732 (9router 0.4.59 (fixed in 0.4.60) contains a chain of
vulnerabilities: ...)
+ TODO: check
+CVE-2026-63359 (The Appriss Insights (Equifax) Victim Information Notification
Exchang ...)
+ TODO: check
+CVE-2026-63313 (9Router before 0.4.72 contains a server-side request forgery
(SSRF) vu ...)
+ TODO: check
+CVE-2026-62825 (Improper authentication in Azure Key Vault allows an
unauthorized atta ...)
+ TODO: check
+CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains
a code ...)
+ TODO: check
+CVE-2026-58275 (Missing authorization in Azure DNS allows an unauthorized
attacker to ...)
+ TODO: check
+CVE-2026-56191 (Improper authentication in Microsoft Exchange Online allows an
unautho ...)
+ TODO: check
+CVE-2026-56167 (Server-side request forgery (ssrf) in Azure AI Search allows
an author ...)
+ TODO: check
+CVE-2026-56165 (Heap-based buffer overflow in Microsoft Account allows an
unauthorized ...)
+ TODO: check
+CVE-2026-56160 (Improper authorization in Azure Red Hat OpenShift (ARO) allows
an auth ...)
+ TODO: check
+CVE-2026-54120 (Improper input validation in Microsoft Surface allows an
authorized at ...)
+ TODO: check
+CVE-2026-52439 (An issue in xiandafu beetl 3.20.2 allows a remote attacker to
execute ...)
+ TODO: check
+CVE-2026-50517 (Deserialization of untrusted data in M365 Copilot allows an
authorized ...)
+ TODO: check
+CVE-2026-50103 (A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared
parser, ...)
+ TODO: check
+CVE-2026-50044 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an
inadequate encr ...)
+ TODO: check
+CVE-2026-50039 (The affected product is vulnerable to a stack-based buffer
overflow, w ...)
+ TODO: check
+CVE-2026-50032 (A NULL pointer dereference in the MMS Write Named Variable
List handle ...)
+ TODO: check
+CVE-2026-49159 (Exposure of sensitive information to an unauthorized actor in
Microsof ...)
+ TODO: check
+CVE-2026-49035 (The affected product is vulnerable to a heap-based buffer
overflow via ...)
+ TODO: check
+CVE-2026-48013 (Shopware is an open commerce platform. Prior to 6.6.10.18 and
6.7.10.1 ...)
+ TODO: check
+CVE-2026-48012 (Shopware is an open commerce platform. Versions 6.7.3.0
through 6.7.10 ...)
+ TODO: check
+CVE-2026-47724 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh virtu ...)
+ TODO: check
+CVE-2026-47723 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh virtu ...)
+ TODO: check
+CVE-2026-47722 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh virtu ...)
+ TODO: check
+CVE-2026-47670 (DbGate is cross-platform database manager. Versions 7.1.8 and
prior ar ...)
+ TODO: check
+CVE-2026-47669 (DbGate is cross-platform database manager. In versions 7.1.8
and prior ...)
+ TODO: check
+CVE-2026-44955 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an
exposure of sen ...)
+ TODO: check
+CVE-2026-42933 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an
unintended prox ...)
+ TODO: check
+CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a
plaintext storag ...)
+ TODO: check
+CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a
vulnerability ...)
+ TODO: check
+CVE-2026-38764 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4
allows a l ...)
+ TODO: check
+CVE-2026-35425 (Improper access control in Azure API Management (APIM) allows
an autho ...)
+ TODO: check
+CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on
Windows allows ...)
+ TODO: check
+CVE-2026-28698 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an
exposure of sen ...)
+ TODO: check
+CVE-2026-25800 (Quinn is a pure-Rust, async-compatible implementation of the
IETF QUIC ...)
+ TODO: check
+CVE-2026-21655 (Deserialization of untrusted data vulnerability in Johnson
Control vic ...)
+ TODO: check
+CVE-2026-21653 (Victor SSRF vulnerability in Johnson Controls CCure 9000 and
victor ap ...)
+ TODO: check
+CVE-2026-16870 (Multiple security vulnerabilities in Snowflake
libsnowflakeclient vers ...)
+ TODO: check
+CVE-2026-16807 (Out of bounds write in Codecs in Google Chrome prior to
150.0.7871.186 ...)
+ TODO: check
+CVE-2026-16806 (Use after free in WebMCP in Google Chrome prior to
150.0.7871.186 allo ...)
+ TODO: check
+CVE-2026-16805 (Use after free in Blink in Google Chrome prior to
150.0.7871.186 allow ...)
+ TODO: check
+CVE-2026-16804 (Use after free in Input in Google Chrome prior to
150.0.7871.186 allow ...)
+ TODO: check
+CVE-2026-16796 (Improper neutralization of argument delimiters in the
install_packages ...)
+ TODO: check
+CVE-2026-16767 (A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2.
This affe ...)
+ TODO: check
+CVE-2026-16765 (A vulnerability was determined in CodeAstro Online Classroom
1.0. Affe ...)
+ TODO: check
+CVE-2026-16764 (A vulnerability was identified in OWASP DefectDojo 2.59.0.
This issue ...)
+ TODO: check
+CVE-2026-16763 (A vulnerability was identified in localstack
serverless-localstack up ...)
+ TODO: check
+CVE-2026-16002 (The affected product is vulnerable to an Out-of-bounds read,
which may ...)
+ TODO: check
+CVE-2026-15981 (The SAML Single Sign On \u2013 SSO Login plugin for WordPress
is vulne ...)
+ TODO: check
+CVE-2026-15968 (Improper neutralization of input during web page generation
('cross-si ...)
+ TODO: check
+CVE-2026-15967 (Insufficient session expiration vulnerability in Progress
MOVEit Trans ...)
+ TODO: check
+CVE-2026-15966 (Permissive cross-domain security policy with untrusted domains
vulnera ...)
+ TODO: check
+CVE-2026-15630 (A non-global organization admin in one tenant can bypass
tenant bounda ...)
+ TODO: check
+CVE-2026-15420 (The Nexter Blocks \u2013 Gutenberg Blocks, Page Builder & AI
Website B ...)
+ TODO: check
+CVE-2026-15212 (The WPO365 | Login plugin for WordPress is vulnerable to
Cross-Site Re ...)
+ TODO: check
+CVE-2026-15100 (The Post Grid Gutenberg Blocks \u2013 PostX plugin for
WordPress is vu ...)
+ TODO: check
+CVE-2026-14603 (The WowOptin: Next-Gen Popup Maker WordPress plugin before
1.4.38 doe ...)
+ TODO: check
+CVE-2026-14172 (Rapid7 InsightVM, Nexpose, and the Insight Agent execute
discovered ex ...)
+ TODO: check
+CVE-2026-13464 (The Kirki \u2013 Freeform Page Builder, Website Builder &
Customizer p ...)
+ TODO: check
+CVE-2026-12981 (The CAFEHAUS API WordPress plugin through 1.0.0 does not have
any auth ...)
+ TODO: check
+CVE-2026-12877 (The Project Management, Bug and Issue Tracking Plugin
WordPress plugi ...)
+ TODO: check
+CVE-2026-12736 (The Wpify Woo plugin for WordPress is vulnerable to Privilege
Escalati ...)
+ TODO: check
+CVE-2026-12690 (The ProfileGrid WordPress plugin before 5.9.9.7 does not
perform a ca ...)
+ TODO: check
+CVE-2026-12689 (The ProfileGrid WordPress plugin before 5.9.9.7 does not
perform any ...)
+ TODO: check
+CVE-2026-12688 (The ProfileGrid WordPress plugin before 5.9.9.7 does not
verify PayPa ...)
+ TODO: check
+CVE-2026-12497 (The Paid Membership Plugin, Ecommerce, User Registration Form,
Login F ...)
+ TODO: check
+CVE-2026-12353 (An unauthenticated attacker could trigger an Out of Memory
condition t ...)
+ TODO: check
+CVE-2026-11922 (A vulnerability in zenml-io/zenml versions 0.57.0 through
0.94.2 allow ...)
+ TODO: check
+CVE-2026-11354 (The Participants Database plugin for WordPress is vulnerable
to Sensit ...)
+ TODO: check
+CVE-2026-10697 (Improper Authentication vulnerability in Progress MOVEit
Transfer. Th ...)
+ TODO: check
+CVE-2025-9205 (The MapSVG plugin for WordPress is vulnerable to Stored
Cross-Site Scr ...)
+ TODO: check
+CVE-2025-71389 (Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to
unauthenticated ...)
+ TODO: check
+CVE-2024-58355 (Cal.com (calcom/cal.diy) versions through 4.7.15 contain a
stored cros ...)
+ TODO: check
+CVE-2024-58354 (cal.com (calcom repository, later renamed cal.diy) is affected
by a re ...)
+ TODO: check
+CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is
vulnerabl ...)
+ TODO: check
CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
- knot-resolver 6.4.1-1
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
NOTE:
https://lists.nic.cz/hyperkitty/list/[email protected]/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
-CVE-2026-54422
+CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious
bootc cont ...)
- ironic-python-agent <unfixed>
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
@@ -558,7 +734,7 @@ CVE-2026-27422 (Unauthenticated Broken Access Control in YT
Player <= 2.0.9 vers
NOT-FOR-US: WordPress plugin or theme
CVE-2026-27418 (Unauthenticated Broken Access Control in WP Fast Total Search
<= 1.81. ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-27403 (Contributor Cross Site Scripting (XSS) in Hubbub Lite <=
1.36.3 versio ...)
+CVE-2026-27403 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-27399 (Unauthenticated Broken Access Control in MarketKing <= 2.1.40
versions ...)
NOT-FOR-US: WordPress plugin or theme
@@ -7771,6 +7947,7 @@ CVE-2026-63030 (WordPress 6.9.x before 6.9.5 and 7.0.x
before 7.0.2 is affected
NOTE:
https://github.com/WordPress/wordpress-develop/commit/6f2074dda61864a03f334d70414d1690ce7e5c79
(6.9.5)
NOTE: The error handling in the problematic function is different in
6.8 and below.
CVE-2026-60137 (WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x
before 7.0 ...)
+ {DSA-6399-1}
- wordpress 7.0.2+dfsg1-1 (bug #1142510)
[bookworm] - wordpress <not-affected> (Vulnerable is_array-gated
author__not_in handling introduced in 6.8; shipped version applies absint
unconditionally)
[bullseye] - wordpress <not-affected> (Vulnerable is_array-gated
author__not_in handling introduced in 6.8; shipped version applies absint
unconditionally)
@@ -23351,7 +23528,7 @@ CVE-2026-8720 (wc_Blake2bHmacFinal and
wc_Blake2sHmacFinal discard the message w
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10447 (v5.9.2-stable)
-CVE-2026-8661 (Server-Side Cross-Site Scripting and Server-Side Request
Forgery vulne ...)
+CVE-2026-8661 (Server-Side Request Forgery in the markdown_to_pdf action of
Rapid7 In ...)
NOT-FOR-US: Rapid7
CVE-2026-8380 (The Frontend File Manager Plugin WordPress plugin through 23.6
does no ...)
NOT-FOR-US: WordPress plugin
@@ -33599,14 +33776,14 @@ CVE-2017-20240 (Crypt::PBKDF2 versions before
0.261630 for Perl are vulnerable t
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40929601/
NOTE: Fixed by:
https://github.com/arodland/Crypt-PBKDF2/commit/ac5aac7c8c0e411165a6665a9c1f449b745f2629
(0.261630)
CVE-2026-50012 (Squid is a caching proxy for the Web. Prior to 7.6, due to an
improper ...)
- {DSA-6360-1}
+ {DSA-6360-1 DLA-4697-1}
- squid 7.6-1
NOTE: https://www.openwall.com/lists/oss-security/2026/06/12/1
NOTE: Fixed by:
https://github.com/squid-cache/squid/commit/19fcfe922717c8b255270c032dcde4071c003bcd
(SQUID_7_6)
NOTE: Follow-up:
https://github.com/squid-cache/squid/commit/c9c9a06be6fb21f400014dcb0ec7e6d573167a5d
(SQUID_7_6)
NOTE:
https://github.com/squid-cache/squid/security/advisories/GHSA-5vmx-9x64-9284
CVE-2026-47729 (Squid is a caching proxy for the Web. Prior to 7.6, due to an
improper ...)
- {DSA-6360-1}
+ {DSA-6360-1 DLA-4697-1}
- squid 7.6-1
NOTE: https://www.openwall.com/lists/oss-security/2026/06/12/1
NOTE: https://blog.calif.io/p/squidbleed-cve-2026-47729
@@ -35988,7 +36165,7 @@ CVE-2025-55657 (A NULL pointer dereference in the
gf_odf_vvc_cfg_write_bs functi
CVE-2025-55651 (A NULL pointer dereference in the gf_isom_get_user_data_count
function ...)
- gpac <removed>
[bullseye] - gpac <end-of-life> (EOL in bullseye LTS)
-CVE-2025-54509 (Improper access control for register interface in the
input-output mem ...)
+CVE-2025-54509 (Improper access control for register interface in the
Input-Output Mem ...)
NOT-FOR-US: AMD
CVE-2025-52293 (A segmentation violaton in the gf_hevc_read_sps_bs_internal
function ( ...)
- gpac <removed>
@@ -84519,7 +84696,7 @@ CVE-2026-3608 (Sending a maliciously crafted message to
the kea-ctrl-agent, kea-
[trixie] - isc-kea 2.6.3-1+deb13u1
NOTE: https://kb.isc.org/docs/cve-2026-3608
CVE-2026-33515 (Squid is a caching proxy for the Web. Prior to version 7.5,
due to imp ...)
- {DSA-6360-1}
+ {DSA-6360-1 DLA-4697-1}
- squid 7.5-1
NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/4
NOTE: Fxied by:
https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165
(SQUID_7_5)
@@ -84531,7 +84708,7 @@ CVE-2026-32748 (Squid is a caching proxy for the Web.
Prior to version 7.5, due
NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/3
NOTE: Fixed by:
https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b
(SQUID_7_5)
CVE-2026-33526 (Squid is a caching proxy for the Web. Prior to version 7.5,
due to hea ...)
- {DSA-6360-1}
+ {DSA-6360-1 DLA-4697-1}
- squid 7.5-1
NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/2
NOTE: Fixed by:
https://github.com/squid-cache/squid/commit/8a7d42f9d44befb8fcbbb619505587c8de6a1e91
(SQUID_7_5)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/032290e3941895795a6b5531276b3f45bac32de7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/032290e3941895795a6b5531276b3f45bac32de7
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits