Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
18943ca6 by security tracker role at 2026-08-06T19:13:34+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,403 @@
+CVE-2026-8166 (Improper neutralization of input during web page generation 
('cross-si ...)
+       TODO: check
+CVE-2026-70646 (aiosend is a synchronous and asynchronous Crypto Pay API 
client. Pror  ...)
+       TODO: check
+CVE-2026-70637 (LightFTP through 2.4 contains multiple data race 
vulnerabilities in ft ...)
+       TODO: check
+CVE-2026-70556 (Hubzilla 11.2.1 contains a cross-site request forgery 
vulnerability in ...)
+       TODO: check
+CVE-2026-68750 (Inefficient Algorithmic Complexity vulnerability in the 
traversal engi ...)
+       TODO: check
+CVE-2026-68749 (Inefficient Regular Expression Complexity vulnerability in the 
CSS scr ...)
+       TODO: check
+CVE-2026-68747 (Improper Neutralization of Special Elements in Output Used by 
a Downst ...)
+       TODO: check
+CVE-2026-68481 (In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked 
access tok ...)
+       TODO: check
+CVE-2026-68079 (In Apache CXF's DefaultEncryptingCodeDataProvider,a captured 
authoriza ...)
+       TODO: check
+CVE-2026-67261 (Dell Virtual Storage Integrator for VMware vSphere Client, 
versions pr ...)
+       TODO: check
+CVE-2026-66909 (Apache CXF's JMS transport deserializes the body of any 
inbound JMS Ob ...)
+       TODO: check
+CVE-2026-66843 (Inclusion of Functionality from Untrusted Control Sphere 
vulnerability ...)
+       TODO: check
+CVE-2026-66829 (URL Redirection to Untrusted Site ('Open Redirect') 
vulnerability in t ...)
+       TODO: check
+CVE-2026-66733 (Sonic 3 A.I.R. before commit 2492d18 contains an unbounded 
memory allo ...)
+       TODO: check
+CVE-2026-66732 (Sonic 3 A.I.R. before commit 2492d18 contains a missing source 
address ...)
+       TODO: check
+CVE-2026-66712 (Unauthenticated Broken Access Control in Simple Membership <= 
4.7.8 ve ...)
+       TODO: check
+CVE-2026-66711 (Subscriber Cross Site Scripting (XSS) in WooCommerce 
Multilingual & Mu ...)
+       TODO: check
+CVE-2026-66710 (Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 
versions.)
+       TODO: check
+CVE-2026-66709 (Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 
version ...)
+       TODO: check
+CVE-2026-66708 (Unauthenticated Broken Access Control in Total Upkeep <= 
1.17.2 versio ...)
+       TODO: check
+CVE-2026-66707 (Unauthenticated Cross Site Scripting (XSS) in Facebook for 
WooCommerce ...)
+       TODO: check
+CVE-2026-66706 (Author Cross Site Scripting (XSS) in Subscribe to Comments <= 
2.3.1 ve ...)
+       TODO: check
+CVE-2026-66705 (Unauthenticated Cross Site Scripting (XSS) in Facebook for 
WordPress < ...)
+       TODO: check
+CVE-2026-66703 (Contributor Cross Site Scripting (XSS) in MailOptin <= 
1.2.78.0 versio ...)
+       TODO: check
+CVE-2026-66702 (Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 
1.0.274 ...)
+       TODO: check
+CVE-2026-66701 (Unauthenticated Broken Access Control in Profile Builder <= 
3.16.5 ver ...)
+       TODO: check
+CVE-2026-66699 (Custom role Broken Access Control in Dokan <= 5.0.10 versions.)
+       TODO: check
+CVE-2026-66696 (Contributor Sensitive Data Exposure in Gutenberg Blocks by 
Kadence Blo ...)
+       TODO: check
+CVE-2026-66695 (Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 
versions.)
+       TODO: check
+CVE-2026-66694 (Unauthenticated Cross Site Scripting (XSS) in Thrive Architect 
<= 10.9 ...)
+       TODO: check
+CVE-2026-66692 (Customer Insecure Direct Object References (IDOR) in Colissimo 
Officie ...)
+       TODO: check
+CVE-2026-66690 (Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 
version ...)
+       TODO: check
+CVE-2026-66688 (Contributor Cross Site Scripting (XSS) in Ultimate Addons for 
Elemento ...)
+       TODO: check
+CVE-2026-66686 (Unauthenticated Cross Site Request Forgery (CSRF) in Plugins 
Garbage C ...)
+       TODO: check
+CVE-2026-66685 (Unauthenticated Sensitive Data Exposure in Featured Video Plus 
<= 2.3. ...)
+       TODO: check
+CVE-2026-66684 (Unauthenticated Sensitive Data Exposure in Export Import Menus 
<= 1.9. ...)
+       TODO: check
+CVE-2026-66683 (Unauthenticated Sensitive Data Exposure in Custom CSS and 
JavaScript < ...)
+       TODO: check
+CVE-2026-66681 (Unauthenticated Cross Site Request Forgery (CSRF) in Theme My 
Login <= ...)
+       TODO: check
+CVE-2026-66678 (Contributor Broken Access Control in Advanced Custom Fields: 
Font Awes ...)
+       TODO: check
+CVE-2026-66665 (Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 
versions.)
+       TODO: check
+CVE-2026-66664 (Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by 
Squirrly S ...)
+       TODO: check
+CVE-2026-66663 (Unauthenticated Cross Site Scripting (XSS) in WP Data Access 
<= 5.5.79 ...)
+       TODO: check
+CVE-2026-66662 (Unauthenticated Privilege Escalation in Frontend Admin by 
DynamiApps < ...)
+       TODO: check
+CVE-2026-66470 (Subscriber Broken Access Control in Frontend Admin by 
DynamiApps <= 3. ...)
+       TODO: check
+CVE-2026-66457 (Unauthenticated Cross Site Scripting (XSS) in Events Manager 
<= 7.4.1  ...)
+       TODO: check
+CVE-2026-66452 (Unauthenticated Broken Access Control in Legal Text Connector 
of the I ...)
+       TODO: check
+CVE-2026-66451 (Unauthenticated Broken Authentication in WP Event SOlution <= 
4.1.9 ve ...)
+       TODO: check
+CVE-2026-66447 (Unauthenticated SQL Injection in WordPress File Upload <= 
5.1.7 versio ...)
+       TODO: check
+CVE-2026-66440 (Unauthenticated Cross Site Scripting (XSS) in WPIDE \u2013 
File Manage ...)
+       TODO: check
+CVE-2026-66439 (Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX 
Product Fi ...)
+       TODO: check
+CVE-2026-66425 (Unauthenticated Broken Authentication in Gutena Forms \u2013 
Contact F ...)
+       TODO: check
+CVE-2026-66370 (URL Redirection to Untrusted Site ('Open Redirect') 
vulnerability in t ...)
+       TODO: check
+CVE-2026-65583 (Apache CXF\u2019s OIDC relying-party token validation could 
accept sel ...)
+       TODO: check
+CVE-2026-65581 (Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 
versions.)
+       TODO: check
+CVE-2026-65579 (Unauthenticated PHP Object Injection in Agricola <= 1.21.0 
versions.)
+       TODO: check
+CVE-2026-65578 (Unauthenticated PHP Object Injection in Agora <= 1.9 versions.)
+       TODO: check
+CVE-2026-65577 (Unauthenticated PHP Object Injection in Advice <= 1.18.0 
versions.)
+       TODO: check
+CVE-2026-65576 (Unauthenticated PHP Object Injection in Adrena <= 1.2.14 
versions.)
+       TODO: check
+CVE-2026-65575 (Unauthenticated PHP Object Injection in Accalia <= 1.5.3 
versions.)
+       TODO: check
+CVE-2026-65574 (Unauthenticated PHP Object Injection in Abogado <= 1.18 
versions.)
+       TODO: check
+CVE-2026-65573 (Unauthenticated PHP Object Injection in Abelle <= 1.22 
versions.)
+       TODO: check
+CVE-2026-65572 (Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 
versions.)
+       TODO: check
+CVE-2026-65571 (Unauthenticated PHP Object Injection in 69 Clothing <= 
1.2.11.1 versio ...)
+       TODO: check
+CVE-2026-65570 (Unauthenticated Bypass Vulnerability in Login with phone 
number <= 1.8 ...)
+       TODO: check
+CVE-2026-65569 (Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.)
+       TODO: check
+CVE-2026-65565 (Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 
5.2.3.3  ...)
+       TODO: check
+CVE-2026-65560 (Unauthenticated Cross Site Scripting (XSS) in Houzez Property 
Feed <=  ...)
+       TODO: check
+CVE-2026-65559 (Shop manager Privilege Escalation in Order Delivery Date for 
WooCommer ...)
+       TODO: check
+CVE-2026-65556 (Unauthenticated PHP Object Injection in WPBruiser {no- Captcha 
anti-Sp ...)
+       TODO: check
+CVE-2026-65554 (Subscriber Broken Access Control in AnsPress \u2013 Question 
and answe ...)
+       TODO: check
+CVE-2026-65553 (Unauthenticated Remote Code Execution (RCE) in Spider Analyser 
&#8211; ...)
+       TODO: check
+CVE-2026-65552 (Subscriber PHP Object Injection in Export User Data <= 2.2.6 
versions.)
+       TODO: check
+CVE-2026-65551 (Missing Authorization vulnerability in Soflyy Breakdance 
allows Exploi ...)
+       TODO: check
+CVE-2026-65549 (Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 
version ...)
+       TODO: check
+CVE-2026-65548 (Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 
versions.)
+       TODO: check
+CVE-2026-65547 (Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.)
+       TODO: check
+CVE-2026-65546 (Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 
versions.)
+       TODO: check
+CVE-2026-65545 (Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 
3.6.8 versi ...)
+       TODO: check
+CVE-2026-65544 (Unauthenticated Cross Site Scripting (XSS) in Super Socializer 
<= 7.14 ...)
+       TODO: check
+CVE-2026-65543 (Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.)
+       TODO: check
+CVE-2026-65542 (Unauthenticated Broken Authentication in Super Socializer <= 
7.14.5 ve ...)
+       TODO: check
+CVE-2026-65541 (Unauthenticated Broken Access Control in Staff Training <= 
1.0.7 versi ...)
+       TODO: check
+CVE-2026-65523 (Unauthenticated Insecure Direct Object References (IDOR) in 
Formidable ...)
+       TODO: check
+CVE-2026-65520 (Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 
versions.)
+       TODO: check
+CVE-2026-65517 (Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy 
Now Butt ...)
+       TODO: check
+CVE-2026-65515 (Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 
2.35.0 ve ...)
+       TODO: check
+CVE-2026-65513 (Unauthenticated Cross Site Scripting (XSS) in Simply Schedule 
Appointm ...)
+       TODO: check
+CVE-2026-65509 (Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 
7.5.1 ve ...)
+       TODO: check
+CVE-2026-65508 (Unauthenticated SQL Injection in Simply Schedule Appointments 
<= 1.6.1 ...)
+       TODO: check
+CVE-2026-65507 (Unauthenticated Privilege Escalation in AIWU <= 1.5.6 
versions.)
+       TODO: check
+CVE-2026-65504 (Unauthenticated Broken Access Control in BOX NOW Delivery 
Croatia <= 3 ...)
+       TODO: check
+CVE-2026-65502 (Unauthenticated Bypass Vulnerability in Element Pack Elementor 
Addons  ...)
+       TODO: check
+CVE-2026-65432 (Apache CXF reads a top-level WSDL through its hardened 
StaxUtilspath,  ...)
+       TODO: check
+CVE-2026-64993 (Dell RVTools versions prior to 4.8.1, contains an improper 
certificate ...)
+       TODO: check
+CVE-2026-64958 (An incomplete fix forCVE-2026-50645 means that it is still 
possible to ...)
+       TODO: check
+CVE-2026-64640 (Apache Polaris did not consistently validate storage locations 
supplie ...)
+       TODO: check
+CVE-2026-63687 (Apache CXF's JwtRequestCodeFilter copies all claims from a 
signed requ ...)
+       TODO: check
+CVE-2026-61982 (Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP 
Plugin <= 1 ...)
+       TODO: check
+CVE-2026-61964 (Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 
5.2.9 ve ...)
+       TODO: check
+CVE-2026-61963 (Unauthenticated Cross Site Scripting (XSS) in Media LIbrary 
Assistant  ...)
+       TODO: check
+CVE-2026-61961 (Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 
4.5.6 vers ...)
+       TODO: check
+CVE-2026-61959 (Subscriber Cross Site Scripting (XSS) in Business Directory <= 
6.4.24  ...)
+       TODO: check
+CVE-2026-61466 (In Apache CXF's OAuth2 Dynamic Client Registration endpoint, 
the autho ...)
+       TODO: check
+CVE-2026-5430 (The JWT authentication mechanism accepts tokens signed with 
algorithms ...)
+       TODO: check
+CVE-2026-5423 (@neo4j/graphqllibrary versions prior to 7.5.6 fail to verify 
the authe ...)
+       TODO: check
+CVE-2026-5391 (The LatePoint plugin for WordPress is vulnerable to Stored 
Cross-Site  ...)
+       TODO: check
+CVE-2026-5158 (The Post Grid Gutenberg Blocks for News, Magazines, Blog 
Websites \u20 ...)
+       TODO: check
+CVE-2026-5134 (Improper neutralization of special elements used in an SQL 
command ('S ...)
+       TODO: check
+CVE-2026-57819 (Apache CXF allows to set a limit on the number of form 
parameters in a ...)
+       TODO: check
+CVE-2026-57818 (A race condition in JCacheCodeDataProvider allows an attacker 
to redee ...)
+       TODO: check
+CVE-2026-57817 (The OpenID Connect Core 1.0 specification mandates that the RP 
MUST va ...)
+       TODO: check
+CVE-2026-55980 (A denial-of-service vulnerability inCatchPulsecould allow an 
attacker  ...)
+       TODO: check
+CVE-2026-55979 (An improper access control check inCatchPulse'snamed pipe 
communicatio ...)
+       TODO: check
+CVE-2026-55978 (An improper access control vulnerability inCatchPulsecould 
allow a non ...)
+       TODO: check
+CVE-2026-54489 (Dell Virtual Storage Integrator for VMware vSphere Client, 
versions pr ...)
+       TODO: check
+CVE-2026-54225 (Apache CXF allows to control the maximum attachment size via 
the"attac ...)
+       TODO: check
+CVE-2026-53985 (Ground Station prior to 0.6.0contains an unauthenticated 
denial-of-ser ...)
+       TODO: check
+CVE-2026-53977 (OpenChamber 1.11.7 contains an authentication bypass 
vulnerability tha ...)
+       TODO: check
+CVE-2026-53976 (OpenChamber 1.11.7 contains a path traversal vulnerability in 
the file ...)
+       TODO: check
+CVE-2026-53975 (OpenChamber 1.11.7 contains an unauthenticated remote code 
execution v ...)
+       TODO: check
+CVE-2026-43622 (llama.cpp builds b1886 through b7445 contain a double free 
vulnerabili ...)
+       TODO: check
+CVE-2026-3430 (The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not 
saniti ...)
+       TODO: check
+CVE-2026-34502 (Heap-based Buffer Overflow vulnerability in Apache Portable 
Runtime Ut ...)
+       TODO: check
+CVE-2026-34501 (Heap-based Buffer Overflow vulnerability in Apache Portable 
Runtime Ut ...)
+       TODO: check
+CVE-2026-34191 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
+       TODO: check
+CVE-2026-32548 (Unauthenticated Broken Access Control in SureCart <= 4.6.2 
versions.)
+       TODO: check
+CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 
versions.)
+       TODO: check
+CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack 
recursion ...)
+       TODO: check
+CVE-2026-28183 (Editor Privilege Escalation in PublishPress Capabilities <= 
2.45.0 ver ...)
+       TODO: check
+CVE-2026-28180 (Unauthenticated Insecure Direct Object References (IDOR) in 
Mercado Pa ...)
+       TODO: check
+CVE-2026-28179 (Shop manager Cross Site Scripting (XSS) in FiboSearch <= 
1.33.0 versio ...)
+       TODO: check
+CVE-2026-28178 (Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 
versions.)
+       TODO: check
+CVE-2026-28177 (Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 
1.23.0 ve ...)
+       TODO: check
+CVE-2026-28172 (Unauthenticated Cross Site Request Forgery (CSRF) in Tracking 
Code Man ...)
+       TODO: check
+CVE-2026-28169 (Unauthenticated Sensitive Data Exposure in YITH WooCommerce 
Zoom Magni ...)
+       TODO: check
+CVE-2026-28146 (Contributor Arbitrary File Download in Unlimited Elements For 
Elemento ...)
+       TODO: check
+CVE-2026-28143 (Unauthenticated Cross Site Scripting (XSS) in Forminator <= 
1.56.0 ver ...)
+       TODO: check
+CVE-2026-28141 (Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery 
<= 4.2.3 ...)
+       TODO: check
+CVE-2026-28140 (Unauthenticated Broken Access Control in JetFormBuilder <= 
3.6.4.1 ver ...)
+       TODO: check
+CVE-2026-28139 (Unauthenticated PHP Object Injection in Ajax Search Lite <= 
4.14.4 ver ...)
+       TODO: check
+CVE-2026-28111 (Contributor Privilege Escalation in Forminator <= 1.56.0 
versions.)
+       TODO: check
+CVE-2026-28082 (Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 
3.8.13.1 ve ...)
+       TODO: check
+CVE-2026-28005 (Unauthenticated Privilege Escalation in Kadence WooCommerce 
Email Desi ...)
+       TODO: check
+CVE-2026-25403 (Unauthenticated Broken Access Control in Ultimate Store Kit 
Elementor  ...)
+       TODO: check
+CVE-2026-1728 (Tokens issued to a low-privileged user are not sufficiently 
restricted ...)
+       TODO: check
+CVE-2026-19047 (A vulnerability was detected in NocteDefensor LudusMCP up to 
1.0.24. T ...)
+       TODO: check
+CVE-2026-19046 (A security vulnerability has been detected in NocteDefensor 
LudusMCP u ...)
+       TODO: check
+CVE-2026-19045 (A weakness has been identified in NocteDefensor LudusMCP up to 
1.0.24. ...)
+       TODO: check
+CVE-2026-19044 (A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected 
by this ...)
+       TODO: check
+CVE-2026-19041 (A vulnerability has been found in MissionSquad mcp-api up to 
1.11.8. T ...)
+       TODO: check
+CVE-2026-19040 (A flaw has been found in MissionSquad mcp-api up to 1.11.9. 
The affect ...)
+       TODO: check
+CVE-2026-19039 (A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server 
up to 8 ...)
+       TODO: check
+CVE-2026-19038 (A security vulnerability has been detected in 
MonomythDevelopment la-f ...)
+       TODO: check
+CVE-2026-19037 (A weakness has been identified in WonderTrader up to 0.9.9. 
This vulne ...)
+       TODO: check
+CVE-2026-19036 (A security flaw has been discovered in Shibby Tomato 
1.28.0000. This a ...)
+       TODO: check
+CVE-2026-19035 (A vulnerability was identified in Shibby Tomato 1.28.0000. 
Affected by ...)
+       TODO: check
+CVE-2026-19034 (A vulnerability was determined in Shibby Tomato 1.28.0000. 
Affected by ...)
+       TODO: check
+CVE-2026-19022 (A vulnerability was determined in OpenHands up to 0.62.0. The 
affected ...)
+       TODO: check
+CVE-2026-19021 (A security vulnerability has been detected in SourceCodester 
Computer  ...)
+       TODO: check
+CVE-2026-19020 (A weakness has been identified in itsourcecode Hospital 
Management Sys ...)
+       TODO: check
+CVE-2026-19019 (A security flaw has been discovered in poco-ai poco-agent up 
to 0.5.4. ...)
+       TODO: check
+CVE-2026-19011 (A vulnerability was detected in TinyAGI 0.0.20. The affected 
element i ...)
+       TODO: check
+CVE-2026-19010 (A security vulnerability has been detected in TinyAGI 0.0.20. 
Impacted ...)
+       TODO: check
+CVE-2026-19009 (A weakness has been identified in TinyAGI 0.0.20. This issue 
affects t ...)
+       TODO: check
+CVE-2026-19008 (A vulnerability was identified in mf-yang openclaw-cn up to 
0.2.1. Thi ...)
+       TODO: check
+CVE-2026-18915 (Invocation of process using visible sensitive information 
vulnerabilit ...)
+       TODO: check
+CVE-2026-18649 (A flaw was found in the GStreamer gst-plugins-good package. 
The rtph26 ...)
+       TODO: check
+CVE-2026-18597 (The PDF creation feature of Foxit PDF Services API supports 
referencin ...)
+       TODO: check
+CVE-2026-18501 (The UsersWP \u2013 Front-end login form, User Registration, 
User Profi ...)
+       TODO: check
+CVE-2026-18427 (@fastify/static before version 10.1.3 contains an incomplete 
fix for a ...)
+       TODO: check
+CVE-2026-18359 (Server-side request forgery in the METS and IIIF import URI 
handling i ...)
+       TODO: check
+CVE-2026-18277 (Missing authorization in the OcrModelRight create and delete 
views in  ...)
+       TODO: check
+CVE-2026-18276 (Missing authorization in the websocket consumer in Scripta 
eScriptoriu ...)
+       TODO: check
+CVE-2026-18275 (Authorization bypass in the process and annotation taxonomy 
serializer ...)
+       TODO: check
+CVE-2026-18258 (Authorization bypass in the Line, LineTranscription, 
VirtualCollection ...)
+       TODO: check
+CVE-2026-16731 (OMICRON StationScout before version 3.05 contains a 
cryptographic timi ...)
+       TODO: check
+CVE-2026-16316 (OMICRON StationGuard 4.00 contains an improper input 
validation vulner ...)
+       TODO: check
+CVE-2026-16315 (OMICRON StationGuard before version 4.10 contains a 
cryptographic timi ...)
+       TODO: check
+CVE-2026-15599 (Unverified ownership vulnerability in T\xdcB\u0130TAK 
B\u0130LGEM Soft ...)
+       TODO: check
+CVE-2026-15246 (The RealHomes Memberships WordPress plugin before 3.1.0 does 
not verif ...)
+       TODO: check
+CVE-2026-12605 (In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF 
in Downl ...)
+       TODO: check
+CVE-2026-11983 (The Ad Inserter \u2013 Ad Manager & AdSense Ads plugin for 
WordPress i ...)
+       TODO: check
+CVE-2026-0673 (The Element Pack Addons for Elementor plugin for WordPress is 
vulnerab ...)
+       TODO: check
+CVE-2026-0637 (When an Event Publisher output adapter is configured with 
irrelevant p ...)
+       TODO: check
+CVE-2025-9266 (The Accelerate theme for WordPress is vulnerable to 
unauthorized modif ...)
+       TODO: check
+CVE-2025-49506 (APR-util versions 1.6.3 (and earlier) function 
apr_password_validate() ...)
+       TODO: check
+CVE-2025-15039 (The Conditional Authentication (Adaptive Authentication) 
script does n ...)
+       TODO: check
+CVE-2025-15028 (The FormGent \u2013 Next-Gen AI Form Builder for WordPress 
with Multi- ...)
+       TODO: check
+CVE-2025-14779 (The Secret Type Management REST API does not correctly isolate 
access  ...)
+       TODO: check
+CVE-2025-13909 (The system accepts authentication requests without sufficient 
validati ...)
+       TODO: check
+CVE-2025-13736 (When Multi-Attribute Login is enabled, the login interface 
fails to co ...)
+       TODO: check
+CVE-2025-13394 (The Ajax processor within the Carbon console fails to 
adequately prote ...)
+       TODO: check
+CVE-2025-12627 (The user impersonation flow in WSO2 Identity Server fails to 
properly  ...)
+       TODO: check
+CVE-2025-11850 (When secondary user stores are configured, the 
implicit-association re ...)
+       TODO: check
+CVE-2024-8995 (Unused authorization codes issued to deleted users are not 
being prope ...)
+       TODO: check
+CVE-2024-6832 (The account locking mechanism fails to trigger when secondary 
user sto ...)
+       TODO: check
+CVE-2024-10302 (The user self-signup flow in multiple WSO2 products fails to 
adequatel ...)
+       TODO: check
+CVE-2023-7355
+       REJECTED
+CVE-2023-7354
+       REJECTED
+CVE-2023-7353
+       REJECTED
 CVE-2026-68480 [x86/bugs: Make Safe-RET robust against interrupt injection]
        - linux <unfixed>
 CVE-2026-52682 [A crafted DNS packet can cause increased memory and CPU 
consumption]
@@ -7,125 +407,124 @@ CVE-2026-52682 [A crafted DNS packet can cause increased 
memory and CPU consumpt
        - pdns-recursor <unfixed>
        [bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
        [bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
-       - pdns <unfixed>
-       [bookworm] - pdns <end-of-life> (See #1119290)
-       [bullseye] - pdns <end-of-life> (see DLA 4471)
        - dnsdist <unfixed>
        [bookworm] - dnsdist <end-of-life> (See #1119290)
        [bullseye] - dnsdist <end-of-life> (see #1119290)
        NOTE: 
https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-11.html
-CVE-2026-64604 [KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is 
in guest mode]
+CVE-2026-64604 (In the Linux kernel, the following vulnerability has been 
resolved:  K ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        [bookworm] - linux 6.1.180-1
        [bullseye] - linux 5.10.262-1
        NOTE: 
https://git.kernel.org/linus/7ef78d71ca713d8c00f7c34ddcf276c808143f77 (7.2-rc1)
-CVE-2026-64603 [platform/x86: intel-hid: Protect ACPI notify handler against 
recursion]
+CVE-2026-64603 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/c085d82613d5618814b84406c8b2d64f1bc305e7 (7.2-rc1)
-CVE-2026-64602 [iio: adc: spear: Initialize completion before requesting IRQ]
+CVE-2026-64602 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        [bookworm] - linux 6.1.180-1
        [bullseye] - linux 5.10.262-1
        NOTE: 
https://git.kernel.org/linus/3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0 (7.2-rc3)
-CVE-2026-64601 [ALSA: us144mkii: capture_urb_complete: redundant 
usb_anchor_urb corrupts anchor list on each resubmission]
+CVE-2026-64601 (In the Linux kernel, the following vulnerability has been 
resolved:  A ...)
        - linux 7.1.4-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/5cff1529a2f9b3461a7f5a6e36a86682fc290534 (7.2-rc2)
-CVE-2026-64599 [crypto: amlogic - avoid double cleanup in meson_crypto_probe()]
+CVE-2026-64599 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        [bookworm] - linux 6.1.180-1
        [bullseye] - linux 5.10.262-1
        NOTE: 
https://git.kernel.org/linus/6d827ade51a24e18d81afb9f32756d339520a14c (7.2-rc1)
-CVE-2026-64598 [smb/client: Fix error code in smb2_aead_req_alloc()]
+CVE-2026-64598 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/61f28012e5650c619223decdb7970e0d3162e949 (7.2-rc1)
-CVE-2026-64597 [smb: client: fix double-free in SMB2_close() replay]
+CVE-2026-64597 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/f96e1cdcb63ed3321142ff2fcdf784e32cda8fee (7.2-rc1)
-CVE-2026-64596 [libfs: set SB_I_NOEXEC and SB_I_NODEV by default in 
init_pseudo()]
+CVE-2026-64596 (In the Linux kernel, the following vulnerability has been 
resolved:  l ...)
        - linux 7.1.4-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/6de2aeffabaafaeda819e60ec8d04f199711e11a (7.2-rc1)
-CVE-2026-64595 [HID: hid-lenovo-go: cancel cfg_setup work in 
hid_go_cfg_remove()]
+CVE-2026-64595 (In the Linux kernel, the following vulnerability has been 
resolved:  H ...)
        - linux 7.1.4-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/73fde0cbff7d9d618591774a12c23434232752c1 (7.2-rc1)
-CVE-2026-64594 [usb: gadget: f_fs: initialize reset_work at allocation time]
+CVE-2026-64594 (In the Linux kernel, the following vulnerability has been 
resolved:  u ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.100-1
        [bookworm] - linux 6.1.180-1
        [bullseye] - linux 5.10.262-1
        NOTE: 
https://git.kernel.org/linus/3137b243c93982fe3460335e12f9247739766e10 (7.2-rc3)
-CVE-2026-64593 [btrfs: do not trim a device which is not writeable]
+CVE-2026-64593 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        [bookworm] - linux 6.1.180-1
        [bullseye] - linux 5.10.262-1
        NOTE: 
https://git.kernel.org/linus/1b1937eb08f51319bf71575484cde2b8c517aedc (7.2-rc1)
-CVE-2026-64592 [riscv: mm: Unconditionally sfence.vma for spurious fault]
+CVE-2026-64592 (In the Linux kernel, the following vulnerability has been 
resolved:  r ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/1b2c6b56a9fa0dcbef461039937de22b1cbecc7d (7.2-rc1)
-CVE-2026-64591 [iommu/vt-d: Avoid WARNING in sva unbind path]
+CVE-2026-64591 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
        - linux 7.1.4-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/534b5f98ab7319d8004bbc7dab6481462243e883 (7.2-rc1)
-CVE-2026-64589 [i2c: core: fix NULL-deref on adapter registration failure]
+CVE-2026-64589 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/2295d2bb101faa663fbc45fadbb3fec45f107441 (7.2-rc1)
-CVE-2026-64588 [fuse-uring: fix data races on ring->ready]
+CVE-2026-64588 (In the Linux kernel, the following vulnerability has been 
resolved:  f ...)
        - linux 7.1.4-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/46725a0056c884cf58a6897f222892807327d82d (7.2-rc1)
-CVE-2026-64590 [dma-buf/udmabuf: skip redundant cpu sync to fix cacheline 
EEXIST warning]
+CVE-2026-64590 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        NOTE: 
https://git.kernel.org/linus/504e2b4ab97a51d56d966cd36d0997ad30b65b2d (7.2-rc1)
-CVE-2026-64587 [net: ethernet: arc: emac: quiesce interrupts before requesting 
IRQ]
+CVE-2026-64587 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux 6.19.10-1
        [trixie] - linux 6.12.85-1
        [bookworm] - linux 6.1.170-1
        [bullseye] - linux 5.10.257-1
        NOTE: 
https://git.kernel.org/linus/2503d08f8a2de618e5c3a8183b250ff4a2e2d52c (7.0-rc4)
-CVE-2026-64586 [wifi: brcmfmac: drain bus_reset work on device removal]
+CVE-2026-64586 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/43b25879f004c98defa2776bedc6ca4763c51945 (7.2-rc5)
-CVE-2026-64585 [can: esd_usb: kill anchored URBs before freeing netdevs]
+CVE-2026-64585 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
        - linux 7.1.5-1
        [trixie] - linux 6.12.100-1
        [bookworm] - linux 6.1.180-1
        NOTE: 
https://git.kernel.org/linus/c43122fef328a70045fe7621c06de6b2b8e19264 (7.2-rc4)
-CVE-2026-64584 [usb: gadget: f_midi: cancel pending IN work before freeing the 
midi object]
+CVE-2026-64584 (In the Linux kernel, the following vulnerability has been 
resolved:  u ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/5650c18d93a1db7e27cb5a40b394747eb4686d5b (7.2-rc5)
-CVE-2026-64583 [usb: gadget: udc: bdc: free IRQ and drain func_wake_notify 
before teardown]
+CVE-2026-64583 (In the Linux kernel, the following vulnerability has been 
resolved:  u ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb (7.2-rc5)
 CVE-2026-71321 (Nuxt is an open-source web development framework for Vue.js. 
From 3.1. ...)
@@ -439,6 +838,7 @@ CVE-2026-8029 (The ZTE Smart Life app contains an SQL 
injection vulnerability th
 CVE-2026-7869 (IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path 
Traversal  ...)
        NOT-FOR-US: IBM
 CVE-2026-7867 [Local privilege escalation via as-user mount spoofing]
+       {DSA-6414-1}
        - udisks2 2.11.2-1
        [bookworm] - udisks2 <not-affected> (udisks2 versions < 2.10.x are not 
affected)
        [bullseye] - udisks2 <not-affected> (udisks2 versions < 2.10.x are not 
affected)
@@ -992,52 +1392,65 @@ CVE-2026-64581 (In the Linux kernel, the following 
vulnerability has been resolv
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/c283e9ada7fcb7dd4b10592623086b2e6d2f9925 (7.2-rc4)
 CVE-2026-64580 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/136992de9bb91871084ae52d172610541c76e4d2 (7.2-rc4)
 CVE-2026-64579 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4 (7.2-rc4)
 CVE-2026-64578 (In the Linux kernel, the following vulnerability has been 
resolved:  k ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/15b38176fd1530372905c602fde51fe89ec8c877 (7.2-rc4)
 CVE-2026-64577 (In the Linux kernel, the following vulnerability has been 
resolved:  g ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/cd170f051dba9ac146fabcd1b91726487c0cb9fa (7.2-rc5)
 CVE-2026-64576 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/6347c5314cee49f364aaf2e40ff15415a57a116e (7.2-rc5)
 CVE-2026-64574 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/952c02b33f56207a160421bcd61e7ac53c9c59ae (7.2-rc5)
 CVE-2026-64573 (In the Linux kernel, the following vulnerability has been 
resolved:  B ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/c90164ca0f7036942ba088eb7ea8d3f6c2352020 (7.2-rc4)
 CVE-2026-64572 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/f2f152e94a67bc746afaf05a1b2702c195553112 (7.2-rc4)
 CVE-2026-64571 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea (7.2-rc4)
 CVE-2026-64570 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/286e52a799fa158bdbd77da1426c4d93f9a6e7ad (7.2-rc4)
 CVE-2026-64569 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/56d96fededd61192cd7cc8d2b0f36adfd59036c3 (7.2-rc4)
 CVE-2026-64568 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/1d067abcd37062426c59ec73dbc4e87a63f33fea (7.2-rc4)
 CVE-2026-64567 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/a2d8d5647ed854e38f941741aea45b9eb15a6350 (7.2-rc4)
 CVE-2026-9273 (The Membership Plugin \u2013 Kadence Memberships plugin for 
WordPress  ...)
@@ -1822,19 +2235,24 @@ CVE-2026-65804 (Improper control of generation of code 
('code injection') in Mic
 CVE-2026-65802 (External control of file name or path in Microsoft Edge for 
Android al ...)
        NOT-FOR-US: Microsoft
 CVE-2026-64565 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       {DSA-6415-1}
        - linux 7.1.3-1
        NOTE: 
https://git.kernel.org/linus/875115b82c295277b81b6dfee7debc725f44e854 (7.1-rc1)
 CVE-2026-64564 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f (7.2-rc5)
        NOTE: https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
 CVE-2026-64563 (In the Linux kernel, the following vulnerability has been 
resolved:  r ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/8173f7e2ce67e6ca1d4763f3da14e5b01ce77456 (7.2-rc5)
 CVE-2026-64562 (In the Linux kernel, the following vulnerability has been 
resolved:  K ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/622ebfac01ba4f9c0060cebd41257fe46fc4a0b3 (7.2-rc5)
 CVE-2026-64561 (In the Linux kernel, the following vulnerability has been 
resolved:  K ...)
+       {DSA-6415-1}
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/2abd5287f08319fa35764566b15c6e22cb1068db (7.2-rc5)
        NOTE: https://github.com/V4bel/Zapscape
@@ -6291,7 +6709,8 @@ CVE-2026-52791 (fuse-overlayfs is an implementation of 
overlayfs in FUSE for roo
        - fuse-overlayfs <unfixed> (bug #1143058)
        NOTE: 
https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h
        NOTE: Fixed by: 
https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad724f
 (v1.17)
-CVE-2026-51992 (SQL Injection vulnerability in ClickHouse Server Versions <= 
26.3.9.8  ...)
+CVE-2026-51992
+       REJECTED
        NOT-FOR-US: ClickHouse Server
 CVE-2026-50642 (diff\u2011so\u2011fancy does not properly sanitize 
non\u2011SGR termin ...)
        NOT-FOR-US: diff-so-fancy
@@ -9739,6 +10158,7 @@ CVE-2026-64294 (In the Linux kernel, the following 
vulnerability has been resolv
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/e187bc02f8fa4226d62814592cf064ee4557c470 (7.2-rc3)
 CVE-2026-64290 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
+       {DSA-6415-1}
        - linux 7.1.4-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -9761,6 +10181,7 @@ CVE-2026-64283 (In the Linux kernel, the following 
vulnerability has been resolv
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/eba85fee7fc6cf28fec38a5bf3c378bef9a79ca6 (7.2-rc1)
 CVE-2026-64280 (In the Linux kernel, the following vulnerability has been 
resolved:  f ...)
+       {DSA-6415-1}
        - linux 7.1.4-1
        NOTE: 
https://git.kernel.org/linus/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27 (7.2-rc1)
 CVE-2026-64279 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
@@ -10926,7 +11347,7 @@ CVE-2026-65461 (Administrator Arbitrary File Upload in 
Really Simple CSV Importe
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65460 (Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal 
Gateway  ...)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-65458 (Contributor Sensitive Data Exposure in Polylang <= 3.8.5 
versions.)
+CVE-2026-65458 (Exposure of Sensitive System Information to an Unauthorized 
Control Sp ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65457 (Subscriber Broken Access Control in \u042eKassa 
\u0434\u043b\u044f Woo ...)
        NOT-FOR-US: WordPress plugin or theme
@@ -11203,7 +11624,7 @@ CVE-2026-24639 (Author Server Side Request Forgery 
(SSRF) in Photo Block <= 1.7.
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24628 (Administrator Cross Site Scripting (XSS) in Photo Gallery by 
Supsystic ...)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-24552 (Contributor SQL Injection in Create by Mediavine <= 2.5.3 
versions.)
+CVE-2026-24552 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP 
Accessibility  ...)
        NOT-FOR-US: WordPress plugin or theme
@@ -15850,6 +16271,7 @@ CVE-2026-64206 (In the Linux kernel, the following 
vulnerability has been resolv
        - linux 7.1.4-1
        NOTE: 
https://git.kernel.org/linus/2641a9e0a1dd4af2e21995470a21d55dd35e5203 (7.2-rc3)
 CVE-2026-64205 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
+       {DSA-6415-1}
        - linux 7.1.4-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -29034,6 +29456,7 @@ CVE-2026-55791 (Craft CMS is a content management 
system (CMS). Versions 4.0.0-R
 CVE-2026-55790 (Craft CMS is a content management system (CMS). In versions 
5.0.0-RC1  ...)
        NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-55688 (The AsyncHttpClient (AHC) library allows Java applications to 
easily e ...)
+       {DLA-4721-1}
        - async-http-client <unfixed> (bug #1141445)
        NOTE: 
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f
        NOTE: https://github.com/AsyncHttpClient/async-http-client/pull/2196
@@ -29970,17 +30393,21 @@ CVE-2026-53327 (In the Linux kernel, the following 
vulnerability has been resolv
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/5f41161059fd0f1bbf18c90f3180e38cc45a14eb (7.1-rc5)
 CVE-2026-45382 (libde265 is an open source implementation of the h.265 video 
codec. Pr ...)
+       {DSA-6413-1}
        - libde265 1.1.1-1
        NOTE: 
https://github.com/strukturag/libde265/security/advisories/GHSA-hwhx-x2mq-ccr9
        NOTE: 
https://github.com/strukturag/libde265/commit/c33b4f63ae9056b00f34a31874fed55cd0aa29c9
 (v1.0.19)
 CVE-2026-45383 (libde265 is an open source implementation of the h.265 video 
codec. Ve ...)
+       {DSA-6413-1}
        - libde265 1.1.1-1
        NOTE: 
https://github.com/strukturag/libde265/security/advisories/GHSA-wg9q-ppqw-6q38
 CVE-2026-54241
+       {DSA-6413-1}
        - libde265 1.1.1-1
        NOTE: 
https://github.com/strukturag/libde265/security/advisories/GHSA-j2qq-x2xq-g9wr
        NOTE: 
https://github.com/strukturag/libde265/commit/bdca87569b9c63c2a7054d90ae4462dbb78d159a
 (v1.1.1)
 CVE-2026-54240
+       {DSA-6413-1}
        - libde265 1.1.1-1
        NOTE: 
https://github.com/strukturag/libde265/security/advisories/GHSA-ccfw-29x7-rrx3
        NOTE: 
https://github.com/strukturag/libde265/commit/bdca87569b9c63c2a7054d90ae4462dbb78d159a
 (v1.1.1)
@@ -37355,6 +37782,7 @@ CVE-2026-53091 (In the Linux kernel, the following 
vulnerability has been resolv
        - linux 7.0.10-1
        NOTE: 
https://git.kernel.org/linus/7fb4c19670110f052c04e1ec1d2b953b9f4f57e4 (7.1-rc1)
 CVE-2026-53090 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
+       {DSA-6415-1}
        - linux 7.0.10-1
        NOTE: 
https://git.kernel.org/linus/ee861486e377edc55361c08dcbceab3f6b6577bd (7.1-rc1)
 CVE-2026-53089 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
@@ -37385,6 +37813,7 @@ CVE-2026-53080 (In the Linux kernel, the following 
vulnerability has been resolv
        [trixie] - linux 6.12.94-1
        NOTE: 
https://git.kernel.org/linus/65782b2db7321d5f97c16718c4c7f6c7205a56be (7.1-rc1)
 CVE-2026-53078 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
+       {DSA-6415-1}
        - linux 7.0.10-1
        NOTE: 
https://git.kernel.org/linus/10f86a2a5c91fc4c4d001960f1c21abe52545ef6 (7.1-rc1)
 CVE-2026-53077 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
@@ -40014,6 +40443,7 @@ CVE-2026-50559 (Quarkus is a Java framework for 
building cloud-native applicatio
 CVE-2026-50519 (Initialization of a resource with an insecure default in 
GitHub Copilo ...)
        NOT-FOR-US: Microsoft
 CVE-2026-49346 (libde265 is an open source implementation of the h.265 video 
codec. Pr ...)
+       {DSA-6413-1}
        - libde265 1.1.1-1 (bug #1140431)
        NOTE: 
https://github.com/strukturag/libde265/security/advisories/GHSA-vv8h-932h-7r86
        NOTE: Fixed by: 
https://github.com/strukturag/libde265/commit/8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8
 (v1.1.0)
@@ -40033,10 +40463,12 @@ CVE-2026-49340 (gonic is a music streaming server / 
free-software subsonic serve
 CVE-2026-49338 (gonic is a music streaming server / free-software subsonic 
server API  ...)
        NOT-FOR-US: gonic music streaming server
 CVE-2026-49337 (libde265 is an open source implementation of the h.265 video 
codec. Pr ...)
+       {DSA-6413-1}
        - libde265 1.1.1-1 (bug #1140431)
        NOTE: 
https://github.com/strukturag/libde265/security/advisories/GHSA-g5hj-rf9f-7vxm
        NOTE: Fixed by: 
https://github.com/strukturag/libde265/commit/683cb9fa603e35840642f98765ab95cdb71cadf9
 (v1.1.0)
 CVE-2026-49295 (libde265 is an open source implementation of the h.265 video 
codec. Pr ...)
+       {DSA-6413-1}
        - libde265 1.1.1-1 (bug #1140431)
        NOTE: 
https://github.com/strukturag/libde265/security/advisories/GHSA-g2rg-wj66-w594
        NOTE: Fixed by: 
https://github.com/strukturag/libde265/commit/691f3a3c55b3d32478c4a49895dee061a282652
 (v1.1.0)
@@ -58835,6 +59267,7 @@ CVE-2026-45904 (In the Linux kernel, the following 
vulnerability has been resolv
        [bookworm] - linux 6.1.170-1
        NOTE: 
https://git.kernel.org/linus/815a8d2feb5615ae7f0b5befd206af0b0160614c (7.0-rc1)
 CVE-2026-45901 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       {DSA-6415-1}
        - linux 6.19.6-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/7f261bb906bf527c4a6e2a646e2d5f3679f2a8bc (7.0-rc1)
@@ -58844,6 +59277,7 @@ CVE-2026-45899 (In the Linux kernel, the following 
vulnerability has been resolv
        [trixie] - linux 6.12.85-1
        NOTE: 
https://git.kernel.org/linus/79b592e8f1b435796cbc2722190368e3e8ffd7a1 (7.0-rc1)
 CVE-2026-45897 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       {DSA-6415-1}
        - linux 6.19.6-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/779c60a5190c42689534172f4b49e927c9959e4e (7.0-rc1)
@@ -111133,6 +111567,7 @@ CVE-2025-63946 (A privilege escalation (PE) 
vulnerability in the Tencent PC Mana
 CVE-2025-63945 (A privilege escalation (PE) vulnerability in the Tencent iOA 
app thru  ...)
        NOT-FOR-US: Tencent iOA app
 CVE-2025-61147 (strukturag libde265 commit d9fea9d wa discovered to contain a 
segmenta ...)
+       {DSA-6413-1}
        - libde265 1.0.18-1 (bug #1129257; unimportant)
        NOTE: https://github.com/strukturag/libde265/issues/484
        NOTE: Fixed by: 
https://github.com/strukturag/libde265/commit/8b17e0930f77db07f55e0b89399a8f054ddbecf7
@@ -156557,6 +156992,7 @@ CVE-2025-40099 (In the Linux kernel, the following 
vulnerability has been resolv
        [trixie] - linux 6.12.57-1
        NOTE: 
https://git.kernel.org/linus/6447b0e355562a1ff748c4a2ffb89aae7e84d2c9 (6.18-rc2)
 CVE-2025-40098 (In the Linux kernel, the following vulnerability has been 
resolved:  A ...)
+       {DSA-6415-1}
        - linux 6.17.6-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -164903,7 +165339,7 @@ CVE-2025-43824 (The Profile widget in Liferay Portal 
7.4.0 through 7.4.3.111, an
        NOT-FOR-US: Liferay
 CVE-2025-34251 (Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 
contain ...)
        NOT-FOR-US: Tesla
-CVE-2025-11362 (Versions of the package pdfmake before 0.3.0-beta.17 are 
vulnerable to ...)
+CVE-2025-11362 (Versions of the package pdfmake from 0.3.0-beta.1 and before 
0.3.0-bet ...)
        NOT-FOR-US: pdfmake
 CVE-2025-11358 (A weakness has been identified in code-projects Simple Banking 
System  ...)
        NOT-FOR-US: code-projects
@@ -307037,12 +307473,14 @@ CVE-2024-39242 (A cross-site scripting (XSS) 
vulnerability in skycaiji v2.8 allo
 CVE-2024-39241 (Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 
allows attack ...)
        NOT-FOR-US: skycaiji
 CVE-2024-38950 (Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows 
attacker ...)
+       {DSA-6413-1}
        - libde265 1.1.1-1 (bug #1074416)
        [bookworm] - libde265 <postponed> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - libde265 <no-dsa> (Minor issue)
        NOTE: https://github.com/strukturag/libde265/issues/460
        NOTE: 
https://github.com/strukturag/libde265/commit/4089de0845e0009e019be4ca5cbebaf2aee0a8ce
 (v1.0.19)
 CVE-2024-38949 (Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows 
attacker ...)
+       {DSA-6413-1}
        - libde265 1.1.1-1 (bug #1074416)
        [bookworm] - libde265 <postponed> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - libde265 <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18943ca683b5e42e1f6ae9a3ab048e44bd1a4bf5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18943ca683b5e42e1f6ae9a3ab048e44bd1a4bf5
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to