Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
af962a33 by security tracker role at 2026-08-13T19:13:58+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,220 +1,862 @@
-CVE-2022-4993
+CVE-2026-73671 (Saurus CMS Community Edition contains an unauthenticated open 
redirect ...)
+       TODO: check
+CVE-2026-73670 (A CMS contains a SQL injection vulnerability in 
admin/db_data.php at l ...)
+       TODO: check
+CVE-2026-73653 (Vitest is a testing framework powered by Vite. Prior to 
versions 3.2.7 ...)
+       TODO: check
+CVE-2026-73652 (vantage6 is an open-source infrastructure for privacy 
preserving analy ...)
+       TODO: check
+CVE-2026-73651 (TypeORM is a TypeScript and JavaScript ORM for Node.js that 
supports P ...)
+       TODO: check
+CVE-2026-73650 (SVGO, short for SVG Optimizer, is a Node.js library and 
command-line a ...)
+       TODO: check
+CVE-2026-73649 (Velocity.js is a JavaScript implementation of the Apache 
Velocity temp ...)
+       TODO: check
+CVE-2026-73648 (rails-html-sanitizer is responsible for sanitizing HTML 
fragments in R ...)
+       TODO: check
+CVE-2026-73647 (Quasar Framework is a framework for building high-performance 
Vue.js u ...)
+       TODO: check
+CVE-2026-73645 (OpenZeppelin Confidential Contracts is an experimental library 
for dev ...)
+       TODO: check
+CVE-2026-73644 (OpenDJ is an LDAPv3 compliant directory service. Prior to 
5.1.2, the S ...)
+       TODO: check
+CVE-2026-73643 (js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 
until 5.2.2 ...)
+       TODO: check
+CVE-2026-73629 (Serendipity before 2.6.0 contains a server-side request 
forgery vulner ...)
+       TODO: check
+CVE-2026-73628 (Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected 
cross-s ...)
+       TODO: check
+CVE-2026-73627 (JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 
and >=4 ...)
+       TODO: check
+CVE-2026-73626 (JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an 
allowlist/b ...)
+       TODO: check
+CVE-2026-73625 (GitPython versions before 3.1.54 contain a remote code 
execution vulne ...)
+       TODO: check
+CVE-2026-73624 (GitPython versions before 3.1.54 contain an arbitrary file 
overwrite v ...)
+       TODO: check
+CVE-2026-73623 (GitPython before 3.1.54 contains an incomplete denylist in 
unsafe_git_ ...)
+       TODO: check
+CVE-2026-73622 (GitPython before 3.1.55 fails to disable environment variable 
expansio ...)
+       TODO: check
+CVE-2026-73621 (GitPython before 3.1.56 contains an argument injection 
vulnerability i ...)
+       TODO: check
+CVE-2026-73620 (GitPython before 3.1.57 fails to guard git option forwarding 
in IndexF ...)
+       TODO: check
+CVE-2026-73619 (GitPython before 3.1.57 contains an incomplete denylist in the 
unsafe_ ...)
+       TODO: check
+CVE-2026-73618 (Budibase Server before 3.40.0 contains a NoSQL injection 
vulnerability ...)
+       TODO: check
+CVE-2026-73617 (Budibase before 3.40.0 contains a NoSQL injection 
vulnerability in the ...)
+       TODO: check
+CVE-2026-73616 (OpenRemote notification deletion endpoints fail to enforce 
realm bound ...)
+       TODO: check
+CVE-2026-73615 (Network-AI versions before 5.15.1 contain a security matcher 
bypass vu ...)
+       TODO: check
+CVE-2026-73614 (Network-AI ClaudeHookBridge before 5.15.1 truncates the target 
string  ...)
+       TODO: check
+CVE-2026-73613 (filebrowser versions before 2.63.19 contain an out-of-scope 
file delet ...)
+       TODO: check
+CVE-2026-73612 (File Browser before v2.63.22 fails to validate access rules 
for descen ...)
+       TODO: check
+CVE-2026-73611 (File Browser versions from 2.50.0 through 2.63.21 fail to 
validate JWT ...)
+       TODO: check
+CVE-2026-73610 (SiYuan before v3.7.4 contains an information disclosure 
vulnerability  ...)
+       TODO: check
+CVE-2026-73609 (SiYuan versions before v3.7.4 contain an information 
disclosure vulner ...)
+       TODO: check
+CVE-2026-73608 (SiYuan's development branch (endpoint introduced by commit 
9b8e8956f,  ...)
+       TODO: check
+CVE-2026-73607 (SiYuan versions before v3.7.4 contain an information 
disclosure vulner ...)
+       TODO: check
+CVE-2026-73606 (SiYuan versions before v3.7.4 contain an information 
disclosure vulner ...)
+       TODO: check
+CVE-2026-73605 (SiYuan versions before v3.7.4 contain a path traversal 
vulnerability i ...)
+       TODO: check
+CVE-2026-73604 (Flowise before 3.1.3 contains an incomplete credential 
redaction vulne ...)
+       TODO: check
+CVE-2026-73603 (Flowise before 3.1.4 fails to validate chatflow visibility in 
the unau ...)
+       TODO: check
+CVE-2026-73602 (Flowise before 3.1.3 contains a sandbox escape vulnerability 
in the vm ...)
+       TODO: check
+CVE-2026-73601 (Flowise versions before 3.1.3 contain a remote code execution 
vulnerab ...)
+       TODO: check
+CVE-2026-73585 (A flaw was found in sblim-cmpi-base. Insecure temporary file 
creation  ...)
+       TODO: check
+CVE-2026-73584 (A flaw was found in sblim-sfcb. A local, low-privileged 
attacker can e ...)
+       TODO: check
+CVE-2026-73583 (A flaw was found in sblim-sfcb. A local attacker with access 
to the sy ...)
+       TODO: check
+CVE-2026-73576 (In Zimbra Collaboration (ZCS) before 10.1.17,weak 
cryptographic key ge ...)
+       TODO: check
+CVE-2026-73575 (In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site 
Request For ...)
+       TODO: check
+CVE-2026-73574 (In Zimbra Collaboration before 10.1.17, a local file inclusion 
(LFI) v ...)
+       TODO: check
+CVE-2026-73573 (In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal 
vulnera ...)
+       TODO: check
+CVE-2026-73572 (In Zimbra Collaboration (ZCS) before 10.1.17, a stored 
cross-site scri ...)
+       TODO: check
+CVE-2026-73571 (An authorization bypass vulnerability exists in Zimbra 
Collaboration ( ...)
+       TODO: check
+CVE-2026-73570 (A remote code execution vulnerability exists in Zimbra 
Collaboration ( ...)
+       TODO: check
+CVE-2026-73569 (fast-xml-parser allows users to process XML from JS object 
without C/C ...)
+       TODO: check
+CVE-2026-73568 (py-libp2p is the Python implementation of the libp2p 
networking stack. ...)
+       TODO: check
+CVE-2026-73567 (sm-crypto provides JavaScript implementations of the Chinese 
cryptogra ...)
+       TODO: check
+CVE-2026-73566 (node-tar is a tar archive manipulation library for Node.js. 
Prior to 7 ...)
+       TODO: check
+CVE-2026-73565 (@hono/node-server allows running the Hono application on 
Node.js. From ...)
+       TODO: check
+CVE-2026-73564 (frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's 
optional  ...)
+       TODO: check
+CVE-2026-73563 (Backstage is an open framework for building developer portals. 
Prior t ...)
+       TODO: check
+CVE-2026-73562 (Mongoose is a MongoDB object modeling tool designed to work in 
an asyn ...)
+       TODO: check
+CVE-2026-73561 (Hub is a Node.js WebSocket server and client with added 
features. Prio ...)
+       TODO: check
+CVE-2026-73559 (vLLM is an inference and serving engine for large language 
models. Fro ...)
+       TODO: check
+CVE-2026-73558 (vLLM is an inference and serving engine for large language 
models. Pri ...)
+       TODO: check
+CVE-2026-73557 (vLLM is an inference and serving engine for large language 
models. Fro ...)
+       TODO: check
+CVE-2026-73556 (vLLM is an inference and serving engine for large language 
models. Pri ...)
+       TODO: check
+CVE-2026-73555 (vLLM is an inference and serving engine for large language 
models. Pri ...)
+       TODO: check
+CVE-2026-73533 (Ninja Tables Pro 5.2.11 contains an embedded malicious code 
vulnerabil ...)
+       TODO: check
+CVE-2026-73532 (Fluent Forms Pro 6.2.7 contains an embedded malicious code 
vulnerabili ...)
+       TODO: check
+CVE-2026-73515 (PostGIS before 3.7.0beta2 contains an out-of-bounds read 
vulnerability ...)
+       TODO: check
+CVE-2026-73514 (The address_standardizer extension for PostGIS through 3.7.0, 
fixed in ...)
+       TODO: check
+CVE-2026-73509 (OpenList a file list program that supports multiple storage. 
Prior to  ...)
+       TODO: check
+CVE-2026-73508 (Netty is an asynchronous, event-driven network application 
framework.  ...)
+       TODO: check
+CVE-2026-73507 (Netty is an asynchronous, event-driven network application 
framework.  ...)
+       TODO: check
+CVE-2026-73506 (Oh My Posh is the most customisable and low-latency cross 
platform/she ...)
+       TODO: check
+CVE-2026-73505 (Oh My Posh is the most customisable and low-latency cross 
platform/she ...)
+       TODO: check
+CVE-2026-73488 (Flowise versions before 3.1.3 contain an insecure direct 
object refere ...)
+       TODO: check
+CVE-2026-73487 (Flowise before 3.1.3 contains a regex-based Python code 
validator bypa ...)
+       TODO: check
+CVE-2026-73486 (Flowise before 3.1.3 contains a code injection vulnerability 
in the CS ...)
+       TODO: check
+CVE-2026-73485 (Flowise before 3.1.3 contains a code injection vulnerability 
in the Ai ...)
+       TODO: check
+CVE-2026-73484 (Flowise before 3.1.3 contains a sandbox escape vulnerability 
in python ...)
+       TODO: check
+CVE-2026-73483 (Flowise (packages flowise and flowise-components) in versions 
<= 3.1.2 ...)
+       TODO: check
+CVE-2026-73482 (phpList before 3.7.0-RC5 contains a cross-site request forgery 
(CSRF)  ...)
+       TODO: check
+CVE-2026-73481 (phpList before 3.7.0-RC5 fail to enforce CSRF token validation 
on the  ...)
+       TODO: check
+CVE-2026-73403 (Unauthenticated Broken Access Control in User Registration <= 
5.2.6 ve ...)
+       TODO: check
+CVE-2026-73401 (Unauthenticated Broken Access Control in InstaWP Connect <= 
0.1.3.7 ve ...)
+       TODO: check
+CVE-2026-73357 (Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.)
+       TODO: check
+CVE-2026-73353 (Unauthenticated Broken Access Control in Revolut Gateway for 
WooCommer ...)
+       TODO: check
+CVE-2026-73349 (Unauthenticated Broken Access Control in GiveWP < 4.16.6 
versions.)
+       TODO: check
+CVE-2026-73346 (Administrator SQL Injection in MailChimp For WooCommerce < 6.2 
version ...)
+       TODO: check
+CVE-2026-73344 (Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 
versions ...)
+       TODO: check
+CVE-2026-73340 (Contributor Cross Site Scripting (XSS) in Featured Image from 
URL <= 5 ...)
+       TODO: check
+CVE-2026-73266 (A flaw was found in the clusterclaims-controller component of 
Multiclu ...)
+       TODO: check
+CVE-2026-73188 (Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 
versions.)
+       TODO: check
+CVE-2026-73038 (NodeBB before 4.15.0 contains a stored cross-site scripting 
vulnerabil ...)
+       TODO: check
+CVE-2026-73037 (Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected 
cross-site s ...)
+       TODO: check
+CVE-2026-72777 (Next AI Draw.io through 0.4.16 contains a server-side request 
forgery  ...)
+       TODO: check
+CVE-2026-72741 (Rainbond through 6.9.7 contains a broken access control 
vulnerability  ...)
+       TODO: check
+CVE-2026-6387 (A potential authentication bypass vulnerability was reported in 
Lenovo ...)
+       TODO: check
+CVE-2026-67991 (crmne/ruby_llm at commit 
fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
+       TODO: check
+CVE-2026-67990 (basecamp/upright at commit 
efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
+       TODO: check
+CVE-2026-67986 (amazing-print/amazing_print at commit 
dc890dfafdf07088ea901df53c19c271 ...)
+       TODO: check
+CVE-2026-67614 (CyberPanel before 3.0.0 contains a hard-coded JWT secret 
vulnerability ...)
+       TODO: check
+CVE-2026-67613 (CyberPanel before 3.0.0 contains a path traversal 
vulnerability that a ...)
+       TODO: check
+CVE-2026-66704 (Unauthenticated Server Side Request Forgery (SSRF) in 
Gutenverse Compa ...)
+       TODO: check
+CVE-2026-66700 (Unauthenticated Cross Site Scripting (XSS) in Smart Online 
Order for C ...)
+       TODO: check
+CVE-2026-66698 (Unauthenticated Cross Site Scripting (XSS) in SureDash <= 
1.10.1 versi ...)
+       TODO: check
+CVE-2026-66697 (Unauthenticated Cross Site Scripting (XSS) in Colissimo 
Officiel : M\x ...)
+       TODO: check
+CVE-2026-66693 (Subscriber Broken Access Control in Motors <= 1.4.113 
versions.)
+       TODO: check
+CVE-2026-66691 (Unauthenticated Broken Access Control in Nokri <= 1.6.6 
versions.)
+       TODO: check
+CVE-2026-66689 (Unauthenticated Broken Access Control in Anti Spam and list 
cleaner &# ...)
+       TODO: check
+CVE-2026-66687 (Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 
versions.)
+       TODO: check
+CVE-2026-66661 (Subscriber Privilege Escalation in Directories Pro <= 2.0.5 
versions.)
+       TODO: check
+CVE-2026-66660 (Unauthenticated Broken Access Control in Contact Form 7 \u2013 
PayPal  ...)
+       TODO: check
+CVE-2026-66658 (Subscriber SQL Injection in Reviewer <= 3.14.2 versions.)
+       TODO: check
+CVE-2026-66657 (Unauthenticated Local File Inclusion in Biagiotti Core <= 
2.1.1 versio ...)
+       TODO: check
+CVE-2026-66656 (Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 
versions.)
+       TODO: check
+CVE-2026-66655 (Unauthenticated Cross Site Scripting (XSS) in MultiParcels 
Shipping Fo ...)
+       TODO: check
+CVE-2026-66654 (Subscriber Server Side Request Forgery (SSRF) in Vehica Core 
<= 1.0.10 ...)
+       TODO: check
+CVE-2026-66653 (Unauthenticated Local File Inclusion in Barista <= 2.5.1 
versions.)
+       TODO: check
+CVE-2026-66478 (Unauthenticated SQL Injection in Church Admin <= 5.1.1 
versions.)
+       TODO: check
+CVE-2026-66472 (Unauthenticated SQL Injection in Everest Backup <= 2.3.12 
versions.)
+       TODO: check
+CVE-2026-66471 (Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 
versions.)
+       TODO: check
+CVE-2026-66469 (Unauthenticated Broken Access Control in Arvow AI SEO Writer 
<= 1.5.3  ...)
+       TODO: check
+CVE-2026-66468 (Unauthenticated Cross Site Scripting (XSS) in Local Delivery 
Drivers f ...)
+       TODO: check
+CVE-2026-66467 (Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 
2.7.5 vers ...)
+       TODO: check
+CVE-2026-66466 (Unauthenticated Broken Access Control in StoreGrowth: Smart 
Sales Boos ...)
+       TODO: check
+CVE-2026-66465 (Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 
versions.)
+       TODO: check
+CVE-2026-66464 (Unauthenticated Broken Access Control in Internal Link 
Optimiser <= 5. ...)
+       TODO: check
+CVE-2026-66463 (Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 
versions.)
+       TODO: check
+CVE-2026-66462 (Unauthenticated Sensitive Data Exposure in WooCommerce 
Appointments <= ...)
+       TODO: check
+CVE-2026-66461 (Unauthenticated Broken Access Control in SMEPay: UPI Gateway 
for WooCo ...)
+       TODO: check
+CVE-2026-66460 (Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 
1.18.1  ...)
+       TODO: check
+CVE-2026-66459 (Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 
versions.)
+       TODO: check
+CVE-2026-66458 (Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.)
+       TODO: check
+CVE-2026-66456 (Subscriber Cross Site Scripting (XSS) in Profile Extra Fields 
by BestW ...)
+       TODO: check
+CVE-2026-66455 (Subscriber Broken Access Control in ReactPress <= 3.4.0 
versions.)
+       TODO: check
+CVE-2026-66454 (Unauthenticated Broken Access Control in WP Social Avatar <= 
1.5 versi ...)
+       TODO: check
+CVE-2026-66453 (Unauthenticated Broken Authentication in Salon booking system 
<= 10.30 ...)
+       TODO: check
+CVE-2026-66450 (Unauthenticated Local File Inclusion in  Geo Mashup <= 1.13.18 
version ...)
+       TODO: check
+CVE-2026-66449 (Unauthenticated Cross Site Scripting (XSS) in  Geo Mashup <= 
1.13.18 v ...)
+       TODO: check
+CVE-2026-66446 (Subscriber SQL Injection in If-So Dynamic Content 
Personalization <= 1 ...)
+       TODO: check
+CVE-2026-66444 (Subscriber Sensitive Data Exposure in Payment Forms for 
Paystack <= 4. ...)
+       TODO: check
+CVE-2026-66443 (Unauthenticated Sensitive Data Exposure in REST API Log <= 
1.7.1 versi ...)
+       TODO: check
+CVE-2026-66441 (Unauthenticated Broken Access Control in MultiVendorX <= 
5.0.10 versio ...)
+       TODO: check
+CVE-2026-66436 (Unauthenticated SQL Injection in Active Products Tables for 
WooCommerc ...)
+       TODO: check
+CVE-2026-66432 (Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 
versions.)
+       TODO: check
+CVE-2026-66431 (Unauthenticated Broken Access Control in Bitcoin Lightning 
Payment Gat ...)
+       TODO: check
+CVE-2026-66430 (Subscriber SQL Injection in Visitor Traffic Real Time 
Statistics Pro < ...)
+       TODO: check
+CVE-2026-66429 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic 
Real Tim ...)
+       TODO: check
+CVE-2026-66426 (Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 
version ...)
+       TODO: check
+CVE-2026-66424 (Unauthenticated Privilege Escalation in SMS Alert Order 
Notifications  ...)
+       TODO: check
+CVE-2026-66256 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted 
Data vuln ...)
+       TODO: check
+CVE-2026-65936 (A malformed Bluetooth connection request message can cause the 
RS9116W ...)
+       TODO: check
+CVE-2026-65935 (Passkey entry Bluetooth LE legacy pairing can be bypassed in 
the RS911 ...)
+       TODO: check
+CVE-2026-65934 (An unencrypted 'pause encryption request' message causes a 
denial of s ...)
+       TODO: check
+CVE-2026-65933 (A malformed Bluetooth connection request message can cause the 
BT122 t ...)
+       TODO: check
+CVE-2026-65932 (The BT122 module stops advertising after receiving a plaintext 
'pause  ...)
+       TODO: check
+CVE-2026-65582 (Subscriber Arbitrary File Download in AI Hub <= 1.3.10 
versions.)
+       TODO: check
+CVE-2026-65580 (Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 
versions ...)
+       TODO: check
+CVE-2026-63426 (During an internal security assessment, a potential 
vulnerability was  ...)
+       TODO: check
+CVE-2026-63425 (During an internal security assessment, a potential improper 
permissio ...)
+       TODO: check
+CVE-2026-63424 (During an internal security assessment, an improperly 
protected key wa ...)
+       TODO: check
+CVE-2026-63423 (During an internal security assessment, a potential 
vulnerability was  ...)
+       TODO: check
+CVE-2026-61984 (Unauthenticated Broken Access Control in WPMobile.App <= 11.77 
version ...)
+       TODO: check
+CVE-2026-61980 (Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 
versions.)
+       TODO: check
+CVE-2026-61979 (Unauthenticated Privilege Escalation in SAML SP Single Sign On 
<= 5.4. ...)
+       TODO: check
+CVE-2026-61978 (Unauthenticated Broken Access Control in Secure Card Gateway 
for ePay  ...)
+       TODO: check
+CVE-2026-61974 (Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 
2.3.4 v ...)
+       TODO: check
+CVE-2026-61969 (Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.)
+       TODO: check
+CVE-2026-61967 (Unauthenticated Privilege Escalation in miniorange otp 
verification <= ...)
+       TODO: check
+CVE-2026-61966 (Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.)
+       TODO: check
+CVE-2026-61965 (Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 
1.2.6 versio ...)
+       TODO: check
+CVE-2026-61962 (Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 
6.3.0 v ...)
+       TODO: check
+CVE-2026-61960 (Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe 
Free <= 8 ...)
+       TODO: check
+CVE-2026-59765 (SSRF via Migration Asset Downloads Bypasses hostmatcher \u2014 
Reads I ...)
+       TODO: check
+CVE-2026-59763 (Unbounded Arch package file metadata can cause resource 
amplification  ...)
+       TODO: check
+CVE-2026-59507 (CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of 
Sensitive  ...)
+       TODO: check
+CVE-2026-59506 (CWE-306: Missing Authentication for Critical Function)
+       TODO: check
+CVE-2026-59505 (CWE-284: Improper Access Control)
+       TODO: check
+CVE-2026-59504 (CWE-602: Client-Side Enforcement of Server-Side Security)
+       TODO: check
+CVE-2026-59503 (CWE-200: Exposure of Sensitive Information to an Unauthorized 
Actor CW ...)
+       TODO: check
+CVE-2026-59502 (CWE-203: Observable Discrepancy)
+       TODO: check
+CVE-2026-59501 (CWE-284: Improper Access Control)
+       TODO: check
+CVE-2026-59500 (CWE-287: Improper Authentication)
+       TODO: check
+CVE-2026-59499 (CWE-200: Exposure of Sensitive Information to an Unauthorized 
Actor)
+       TODO: check
+CVE-2026-59109 (SQL injection in the Zalktis accounting application via 
trading-partne ...)
+       TODO: check
+CVE-2026-58511 (Webhook Authorization Header Returned in Plaintext via API)
+       TODO: check
+CVE-2026-58510 (GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API 
EditRepo p ...)
+       TODO: check
+CVE-2026-58508 (Two SSRF vulnerabilities in Gitea migration/mirror (DNS 
rebinding + mi ...)
+       TODO: check
+CVE-2026-58507 (Private Repository Existence Disclosure via go-get Meta 
Endpoint)
+       TODO: check
+CVE-2026-58445 (Cross-repository label-ID enumeration oracle via unscoped 
DeleteIssueL ...)
+       TODO: check
+CVE-2026-58444 (Personal access token scope enforcement bypass on the 
repository home  ...)
+       TODO: check
+CVE-2026-58443 (Public-only repository tokens can update private PR head 
branches)
+       TODO: check
+CVE-2026-58442 (Repository migration SSRF via multi-answer DNS allow-list 
bypass)
+       TODO: check
+CVE-2026-58441 (SSRF in restore-repo via unsanitized pull_request.yml 
Head.CloneURL)
+       TODO: check
+CVE-2026-58440 (Webhooks created by a collaborator keep firing after their 
repo access ...)
+       TODO: check
+CVE-2026-58439 (Branch Protection Bypass via PR Retargeting Preserves Stale 
`official` ...)
+       TODO: check
+CVE-2026-58438 (Cross-repository IDOR in issue-dependency removal lets an 
attacker tam ...)
+       TODO: check
+CVE-2026-58437 (Repository Visibility Manipulation via Git Push Options)
+       TODO: check
+CVE-2026-58436 (ParseAcceptLanguage quadratic-time DoS via Locale middleware 
on unauth ...)
+       TODO: check
+CVE-2026-58435 (Gitea LFS Deploy-Key Privilege Escalation)
+       TODO: check
+CVE-2026-58434 (Private Repository Metadata Remains Accessible After Access 
Revocation)
+       TODO: check
+CVE-2026-58433 (Team-repository linking endpoint bypasses the 
RepoAdminChangeTeamAcces ...)
+       TODO: check
+CVE-2026-58432 (Missing Authorization and Authorization Bypass Through 
User-Controlled ...)
+       TODO: check
+CVE-2026-58431 (Public-only API token restriction is not enforced on team API 
routes)
+       TODO: check
+CVE-2026-58429 (Public-Only Personal access tokens scope bypass in 
Organization and Pe ...)
+       TODO: check
+CVE-2026-58428 (Release attachment extension allowlist bypass via web release 
edit for ...)
+       TODO: check
+CVE-2026-58427 (Private org member list leaked via /members API endpoint 
\u2014 incomp ...)
+       TODO: check
+CVE-2026-58425 (OAuth token introspection returns metadata of tokens issued to 
other c ...)
+       TODO: check
+CVE-2026-58420 (Local File Inclusion via file:// URI in Migration Restore)
+       TODO: check
+CVE-2026-58417 (REST API exposes organization membership of private 
organizations to p ...)
+       TODO: check
+CVE-2026-58416 (Fork-PR Actions task can read a third private repository via 
the colla ...)
+       TODO: check
+CVE-2026-58314 (Two SSRF findings in Gitea 1.26.2)
+       TODO: check
+CVE-2026-57897 (Cross-Repo Information Disclosure via Org-Level Actions 
Run/Job APIs)
+       TODO: check
+CVE-2026-57894 (Repository Migration Follows Git HTTP Redirects After URL 
Allow/Block  ...)
+       TODO: check
+CVE-2026-57886 (Cross-repository issue/comment attachment re-linking can 
expose privat ...)
+       TODO: check
+CVE-2026-56755 (Denial of Service (CPU & Memory Exhaustion) via O(N^2) String 
Concaten ...)
+       TODO: check
+CVE-2026-56750 (Gitea Remember-Me Token Theft Not Invalidating Attacker 
Session)
+       TODO: check
+CVE-2026-56657 (Gitea SSH Key Parser Denial of Service)
+       TODO: check
+CVE-2026-56654 (Privilege Escalation via Access Token Scope Escalation in API)
+       TODO: check
+CVE-2026-56443 (Token public-only scope bypassed on Limited-visibility owners 
(Reposit ...)
+       TODO: check
+CVE-2026-55987 (OAuth2 sign-in reactivates an administrator-deactivated 
account on aut ...)
+       TODO: check
+CVE-2026-55986 (Email Management API Bypasses ManageCredentials Feature 
Restrictions)
+       TODO: check
+CVE-2026-55984 (Null Pointer Dereference in AddTime API Causes Authenticated 
Denial of ...)
+       TODO: check
+CVE-2026-55982 (OIDC userinfo Endpoint Returns Identity Claims Without 
Enforcing API T ...)
+       TODO: check
+CVE-2026-55402 (CVE-2026-55402 is an out of bounds read vulnerability in 
Secure Access ...)
+       TODO: check
+CVE-2026-55401 (CVE-2026-55401 is a null dereference vulnerability on the 
load-balanci ...)
+       TODO: check
+CVE-2026-55400 (CVE-2026-55400 is an integer underflow in Secure Access 
servers prior  ...)
+       TODO: check
+CVE-2026-54481 (Internal API HTTP client hardcodes InsecureSkipVerify:true 
with no con ...)
+       TODO: check
+CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only 
confinemen ...)
+       TODO: check
+CVE-2026-49857 (auth-fetch-mcp is an MCP server that lets AI assistants fetch 
content  ...)
+       TODO: check
+CVE-2026-49856 (@jshookmcp/jshook is an MCP server that gives AI agents tools 
for Java ...)
+       TODO: check
+CVE-2026-49827 (WebErpMesv2 is a Resource Management and Manufacturing 
execution syste ...)
+       TODO: check
+CVE-2026-49820 (Probo is a self-hostable governance, risk, and compliance 
(GRC) platfo ...)
+       TODO: check
+CVE-2026-45819 (baseline-browser-mapping 2.x before 2.11.0 calls 
process.exit() instea ...)
+       TODO: check
+CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag 
Endpoint)
+       TODO: check
+CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is 
vulnera ...)
+       TODO: check
+CVE-2026-28189 (Unauthenticated Arbitrary File Deletion in Participants 
Database <= 2. ...)
+       TODO: check
+CVE-2026-28188 (Unauthenticated Broken Access Control in Hydra Booking <= 
1.2.2 versio ...)
+       TODO: check
+CVE-2026-28187 (Unauthenticated Cross Site Scripting (XSS) in Knowledge Base 
for Docum ...)
+       TODO: check
+CVE-2026-28186 (Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 
version ...)
+       TODO: check
+CVE-2026-28185 (Unauthenticated Broken Authentication in Log in with Google <= 
1.4.2 v ...)
+       TODO: check
+CVE-2026-28184 (Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 
versions.)
+       TODO: check
+CVE-2026-28182 (Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP 
Newsletter <= ...)
+       TODO: check
+CVE-2026-28181 (Subscriber Broken Access Control in AcyMailing SMTP Newsletter 
<= 10.1 ...)
+       TODO: check
+CVE-2026-28176 (Unauthenticated PHP Object Injection in Booking Activities <= 
1.18.4 v ...)
+       TODO: check
+CVE-2026-28175 (Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic 
Real Ti ...)
+       TODO: check
+CVE-2026-28174 (Customer Sensitive Data Exposure in WP Event SOlution <= 
4.1.18 versio ...)
+       TODO: check
+CVE-2026-28173 (Customer Arbitrary Content Deletion in WP Event SOlution <= 
4.1.19 ver ...)
+       TODO: check
+CVE-2026-28170 (Unauthenticated Cross Site Scripting (XSS) in Blog Floating 
Button <=  ...)
+       TODO: check
+CVE-2026-28168 (Subscriber SQL Injection in CubeWP <= 1.1.30 versions.)
+       TODO: check
+CVE-2026-28161 (Subscriber Privilege Escalation in Service Finder Booking <= 
6.2 versi ...)
+       TODO: check
+CVE-2026-28159 (Subscriber Broken Access Control in Service Finder Booking <= 
6.2 vers ...)
+       TODO: check
+CVE-2026-28158 (Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 
versions ...)
+       TODO: check
+CVE-2026-28157 (Subscriber Path Traversal in Do Lasso <= 358 versions.)
+       TODO: check
+CVE-2026-28156 (Subscriber SQL Injection in Do Lasso <= 358 versions.)
+       TODO: check
+CVE-2026-28155 (Unauthenticated Insecure Direct Object References (IDOR) in Do 
Lasso < ...)
+       TODO: check
+CVE-2026-28154 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2026-28149 (Unauthenticated PHP Object Injection in Headless Single Sign 
On <= 1.6 ...)
+       TODO: check
+CVE-2026-28148 (Unauthenticated Bypass Vulnerability in Headless Single Sign 
On <= 1.6 ...)
+       TODO: check
+CVE-2026-28142 (Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 
versions ...)
+       TODO: check
+CVE-2026-28008 (Unauthenticated Broken Authentication in OAuth Single Sign On 
\u2013 S ...)
+       TODO: check
+CVE-2026-28004 (Unauthenticated Cross Site Scripting (XSS) in Business 
Directory <= 6. ...)
+       TODO: check
+CVE-2026-28003 (Unauthenticated Cross Site Scripting (XSS) in Maspik \u2013 
Spam black ...)
+       TODO: check
+CVE-2026-28002 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
+       TODO: check
+CVE-2026-28001 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 
versions.)
+       TODO: check
+CVE-2026-27999 (Subscriber Broken Access Control in Tourfic <= 2.23.1 
versions.)
+       TODO: check
+CVE-2026-27544 (Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 
5.2.0.0 ...)
+       TODO: check
+CVE-2026-27543 (Unauthenticated Privilege Escalation in MStore API <= 4.20.0 
versions.)
+       TODO: check
+CVE-2026-27539 (Unauthenticated Cross Site Scripting (XSS) in Welcart 
e-Commerce <= 2. ...)
+       TODO: check
+CVE-2026-27538 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 
versions.)
+       TODO: check
+CVE-2026-27537 (Unauthenticated Cross Site Scripting (XSS) in Popup by 
Supsystic <= 1. ...)
+       TODO: check
+CVE-2026-27536 (Unauthenticated Cross Site Scripting (XSS) in MailChimp 
Subscribe Form ...)
+       TODO: check
+CVE-2026-27535 (Subscriber Broken Access Control in Solace Extra <= 1.6.0 
versions.)
+       TODO: check
+CVE-2026-27380 (Editor PHP Object Injection in Car Rental Manager <= 1.3.9 
versions.)
+       TODO: check
+CVE-2026-27345 (Unauthenticated Broken Access Control in Taxi Booking Manager 
for WooC ...)
+       TODO: check
+CVE-2026-24791 (Public-only tokens bypass private-resource restrictions on 
`/api/v1/us ...)
+       TODO: check
+CVE-2026-24059 (The GET /api/v1/user/actions/runners/registration-token 
endpoint (and  ...)
+       TODO: check
+CVE-2026-23603 (Blind SSRF in OAuth2 avatar synchronization via unvalidated 
OIDC pictu ...)
+       TODO: check
+CVE-2026-21832 (HCL AION is affected by a vulnerability where indirect prompt 
injectio ...)
+       TODO: check
+CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer 
Pentestify be ...)
+       TODO: check
+CVE-2026-19734 (Missing Authorization and Authorization Bypass Through 
User-Controlled ...)
+       TODO: check
+CVE-2026-19730 (The 'podman quadlet install --replace' command opens the 
existing dest ...)
+       TODO: check
+CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management 
component  ...)
+       TODO: check
+CVE-2026-19710 (A vulnerability was found in SourceCodester Simple Student 
Information ...)
+       TODO: check
+CVE-2026-19696 (Ixia IxVeriWave and Vector Informatik BLF file parser crashes 
in 4.6.0 ...)
+       TODO: check
+CVE-2026-19695 (Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows 
denial of  ...)
+       TODO: check
+CVE-2026-19694 (TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial 
of servic ...)
+       TODO: check
+CVE-2026-19487 (Perl versions from 5.9.4 before 5.41.9 produce incorrect 
regular expre ...)
+       TODO: check
+CVE-2026-19484 (@fastify/busboy is a multipart form-data parser. In versions 
3.1.0 thr ...)
+       TODO: check
+CVE-2026-19481 (@fastify/busboy is a multipart form-data parser. In versions 
1.0.0 thr ...)
+       TODO: check
+CVE-2026-19293 (SMP security request (from peripheral)does not include the 
maximum enc ...)
+       TODO: check
+CVE-2026-19292 (Re-pairing with a legitimate device can use a lower security 
level tha ...)
+       TODO: check
+CVE-2026-19291 (Bluetooth re-pairing with an existing device can use a lower 
security  ...)
+       TODO: check
+CVE-2026-18622 (Foxit PDF Editor/Reader inconsistently alerts users when 
signature fie ...)
+       TODO: check
+CVE-2026-18428 (A SQL query validation bypass in the Flint extension query 
handler in  ...)
+       TODO: check
+CVE-2026-18368 (In Teltonika Networks RUTOS devices, a vulnerability exists in 
modbusg ...)
+       TODO: check
+CVE-2026-18071 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
gain elev ...)
+       TODO: check
+CVE-2026-17220 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
+       TODO: check
+CVE-2026-17197 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
bypass s ...)
+       TODO: check
+CVE-2026-16459 (Padding oracle attack vulnerability in Oberon microsystem 
AG\u2019s Ob ...)
+       TODO: check
+CVE-2026-16458 (Padding oracle attack vulnerability in Oberon microsystem 
AG\u2019s oc ...)
+       TODO: check
+CVE-2026-16455 (In Teltonika Networks RUTOS devices running versions 7.07.1 
through 7. ...)
+       TODO: check
+CVE-2026-16101 (Spoofing an already bonded device can force either RS9116W or 
SiWx917  ...)
+       TODO: check
+CVE-2026-15994 (During an internal security assessment, an improper link 
following vul ...)
+       TODO: check
+CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed 
as a "hom ...)
+       TODO: check
+CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL 
object) proce ...)
+       TODO: check
+CVE-2026-14332 (The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress 
plugin befor ...)
+       TODO: check
+CVE-2026-14298 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x 
<= 11.7 ...)
+       TODO: check
+CVE-2026-14256 (ELAN reported a potential out-of-bounds write vulnerability in 
the ELA ...)
+       TODO: check
+CVE-2026-12908
+       REJECTED
+CVE-2026-12263 (Zohocorp ManageEngine Password Manager Pro versions before 
13232 and P ...)
+       TODO: check
+CVE-2026-12236 (The Bluetooth host GATT client function 
parse_read_std_char_desc() in  ...)
+       TODO: check
+CVE-2026-12036 (An improper link following vulnerability was reported in the 
VantageCo ...)
+       TODO: check
+CVE-2026-11970 (This vulnerability allows a normal (non-admin) user to disable 
the For ...)
+       TODO: check
+CVE-2026-11840 (Zohocorp ManageEngine Password Manager Pro versions before 
13232 and M ...)
+       TODO: check
+CVE-2025-62318 (HCL AION is affected by a vulnerability where JavaScript 
responses con ...)
+       TODO: check
+CVE-2025-62315 (HCL AION is affected by a vulnerability where certain input 
fields do  ...)
+       TODO: check
+CVE-2025-62314 (HCL AION is affected by a vulnerability where certain 
endpoints lack s ...)
+       TODO: check
+CVE-2025-52640 (HCL AION is affected by a vulnerability where the shared 
storage used  ...)
+       TODO: check
+CVE-2024-58374 (Hongjing e-HR contains an unauthenticated SQL injection 
vulnerability  ...)
+       TODO: check
+CVE-2019-25765 (ASP-CMS contains a SQL injection vulnerability in the 
commentList.asp  ...)
+       TODO: check
+CVE-2022-4993 (HTML::FormHandler versions through 0.40068 for Perl allow 
attacker sel ...)
        - libhtml-formhandler-perl <unfixed>
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42659947/
        NOTE: 
https://security.metacpan.org/patches/H/HTML-FormHandler/0.40068/CVE-2022-4993-r2.patch
-CVE-2026-13048
+CVE-2026-13048 (Data::MuForm::Localizer versions through 0.05 for Perl execute 
Perl fr ...)
        NOT-FOR-US: Data::MuForm Perl module
-CVE-2026-13051
+CVE-2026-13051 (Form::Processor::Field::HtmlArea versions from 0.06 through 
1.162360 f ...)
        NOT-FOR-US: Form::Processor Perl module
-CVE-2026-6464
+CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a 
server ad ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-6464/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-6469
+CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER 
TYPE co ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-6469/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-6470
+CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an 
object crea ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-6470/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-6471
+CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a 
non-supe ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-6471/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14662
+CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data 
type functi ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14662/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14663
+CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers 
allows a use ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14663/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14664
+CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query 
author to e ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14664/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14666
+CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role 
membership, role  ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14666/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14668
+CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type 
selectivit ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14668/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14669
+CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows 
the par ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14669/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14670
+CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied 
hash allows ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14670/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14671
+CVE-2026-14671 (Type confusion in PostgreSQL module "refint" allows an object 
creator  ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14671/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14672
+CVE-2026-14672 (Observable response discrepancy in PostgreSQL SCRAM 
authentication all ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <not-affected> ((Vulnerable code not present)
        - postgresql-13 <not-affected> ((Vulnerable code not present)
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14672/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14673
+CVE-2026-14673 (Untrusted search path in PostgreSQL amcheck allows a grantee 
of amchec ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14673/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14676
+CVE-2026-14676 (Heap buffer overflow in PostgreSQL pg_stat_statements allows 
the query ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <not-affected> (Vulnerable code not present)
        - postgresql-15 <not-affected> (Vulnerable code not present)
        - postgresql-13 <not-affected> (Vulnerable code not present)
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14676/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14677
+CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and 
plperl all ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14677/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14678
+CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit 
function reads  ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14678/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14679
+CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching 
allows an o ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14679/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14680
+CVE-2026-14680 (Type confusion with PostgreSQL "internal" data type arguments 
allows a ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14680/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-14681
+CVE-2026-14681 (Improper enforcement of message integrity in PostgreSQL GSSAPI 
support ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <not-affected> (Vulnerable code not present)
        - postgresql-13 <not-affected> (Vulnerable code not present)
        NOTE: https://www.postgresql.org/support/security/CVE-2026-14681/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-15741
+CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object 
owner t ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-15741/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-15742
+CVE-2026-15742 (Integer wraparound in PostgreSQL fuzzystrmatch allows a user 
to direct ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-15742/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-16238
+CVE-2026-16238 (Type confusion in PostgreSQL pg_restore_attribute_stats() 
allows an ob ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <not-affected> (Vulnerable code not present)
        - postgresql-15 <not-affected> (Vulnerable code not present)
        - postgresql-13 <not-affected> (Vulnerable code not present)
        NOTE: https://www.postgresql.org/support/security/CVE-2026-16238/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-16239
+CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows 
a user t ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-16239/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-16241
+CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server 
administ ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-16241/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-18024
+CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a 
user to d ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-18024/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-18408
+CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a 
malicious s ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-18408/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-19385
+CVE-2026-19385 (Heap buffer overflow in PostgreSQL pg_dump of long function 
transform  ...)
        - postgresql-18 <unfixed>
        - postgresql-17 <removed>
        - postgresql-15 <removed>
        - postgresql-13 <unfixed>
        NOTE: https://www.postgresql.org/support/security/CVE-2026-19385/
        NOTE: 
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-CVE-2026-68454 [KVM: s390: pci: Fix handling of AIF enable without AISB]
+CVE-2026-68454 (In the Linux kernel, the following vulnerability has been 
resolved:  K ...)
        - linux 7.1.5-1
        [trixie] - linux 6.12.100-1
        [bookworm] - linux 6.1.180-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/3e3aa6da87d30a0064a17b836685cd43c90a3572 (7.2-rc4)
-CVE-2026-68453 [s390/zcrypt: Fix buffer over-read in cca_cipher2protkey]
+CVE-2026-68453 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
        - linux 7.1.8-1
        NOTE: 
https://git.kernel.org/linus/36b230835b8a008266aad22168ca52afacc8a58d (7.2-rc6)
-CVE-2026-68452 [s390/zcrypt: Validate length for CCA AES cipher key requests]
+CVE-2026-68452 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
        - linux 7.1.8-1
        NOTE: 
https://git.kernel.org/linus/06afe425d5283b9764303de47f554da5a808ce8a (7.2-rc6)
-CVE-2026-68451 [s390/zcrypt: Validate length for CCA ECC private key requests]
+CVE-2026-68451 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
        - linux 7.1.8-1
        NOTE: 
https://git.kernel.org/linus/a9ae0f6dd45c3ccc1d69363f7aea8af179122730 (7.2-rc6)
 CVE-2026-7366 (IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM 
DataPower Gate ...)
@@ -628,103 +1270,103 @@ CVE-2025-9486 (GitLab has remediated an issue in 
GitLab EE affecting all version
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2024-27253 (IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow 
an auth ...)
        NOT-FOR-US: IBM
-CVE-2026-53802
+CVE-2026-53802 (rsync before 3.5.0 contains an arbitrary file read 
vulnerability that  ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53803
+CVE-2026-53803 (rsync before 3.5.0 contains a symlink following vulnerability 
that all ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53785
+CVE-2026-53785 (rsyncbefore 3.5.0contains a path traversal vulnerability that 
allows a ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53784
+CVE-2026-53784 (rsync before 3.5.0contains a path traversal vulnerability that 
allows  ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53793
+CVE-2026-53793 (rsync before 3.5.0contains a path confinement bypass 
vulnerability tha ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53795
+CVE-2026-53795 (rsync before 3.5.0contains an arbitrary file write 
vulnerability that  ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53796
+CVE-2026-53796 (rsync before 3.5.0contains a time-of-check to time-of-use 
(TOCTOU) rac ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53797
+CVE-2026-53797 (rsync before 3.5.0contains a symlink race condition 
vulnerability in t ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53799
+CVE-2026-53799 (rsync before 3.5.0contains a symlink race condition 
vulnerability that ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53800
+CVE-2026-53800 (rsync before 3.5.0contains a symlink race condition 
vulnerability in t ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53801
+CVE-2026-53801 (rsync before 3.5.0contains a symlink race condition 
vulnerability in t ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53783
+CVE-2026-53783 (rsync before3.5.0 contains a time-of-check to time-of-use 
(TOCTOU) rac ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53786
+CVE-2026-53786 (rsyncbefore 3.5.0contains a filter rule bypass vulnerability 
that allo ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53798
+CVE-2026-53798 (rsync tbefore 3.5.0contains a privilege confusion 
vulnerability in the ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53788
+CVE-2026-53788 (rsync before 3.5.0contains a newline injection vulnerability 
in the na ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53789
+CVE-2026-53789 (rsync before 3.5.0contains an improper path handling 
vulnerability tha ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53791
+CVE-2026-53791 (rsync daemon before 3.5.0contains an IP address spoofing 
vulnerability ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53790
+CVE-2026-53790 (rsync before 3.5.0contains multiple command and argument 
injection vul ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53792
+CVE-2026-53792 (rsyncbefore 3.5.0contains an out-of-bounds read vulnerability 
in the s ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53794
+CVE-2026-53794 (rsync before 3.5.0contains a logic error in --max-alloc 
handling that  ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70461
+CVE-2026-70461 (rsync 3.2.5 before 3.5.0contains a heap out-of-bounds write 
vulnerabil ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70458
+CVE-2026-70458 (rsync 3.0.0 before 3.5.0 contains an out-of-bounds write 
vulnerability ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70456
+CVE-2026-70456 (rsync 3.0.1 before 3.5.0contains an out-of-bounds write 
vulnerability  ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70457
+CVE-2026-70457 (rsync 3.2.3before 3.5.0contains an out-of-bounds write in 
parse_size_a ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70459
+CVE-2026-70459 (rsync 3.0.0 before 3.5.0contains a null pointer dereference 
vulnerabil ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70464
+CVE-2026-70464 (rsync daemon 2.0.0 before 3.5.0contains a denial of service 
vulnerabil ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70455
+CVE-2026-70455 (rsync 3.4.2 before 3.5.0contains a denial of service 
vulnerability tha ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70453
+CVE-2026-70453 (rsync before 3.5.0contains an algorithmic complexity 
vulnerability in  ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70452
+CVE-2026-70452 (rsync 3.1.0 before 3.5.0 contains an access control bypass 
vulnerabili ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70463
+CVE-2026-70463 (rsync 3.1.0 before 3.5.0contains an authorization bypass in 
auth users ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70460
+CVE-2026-70460 (rsync 2.3.3 before 3.5.0contains a path traversal 
vulnerability that a ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70462
+CVE-2026-70462 (rsync 3.1.0 before 3.5.0contains a signed integer overflow 
vulnerabili ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-70454
+CVE-2026-70454 (rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 
3.4.4 ( ...)
        - rsync <unfixed>
        NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
 CVE-2026-17431 (PDF::WebKit versions through 1.2 for Perl allow OS command 
injection v ...)
@@ -1642,18 +2284,23 @@ CVE-2026-68430 (In the Linux kernel, the following 
vulnerability has been resolv
        [trixie] - linux 6.12.101-1
        NOTE: 
https://git.kernel.org/linus/84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5 (7.2-rc2)
 CVE-2026-19556 (Use after free in V8 in Google Chrome prior to 151.0.7922.137 
allowed  ...)
+       {DSA-6436-1 DLA-4739-1}
        - chromium 151.0.7922.137-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19557 (Use after free in TabStrip in Google Chrome on Mac prior to 
151.0.7922 ...)
+       {DSA-6436-1 DLA-4739-1}
        - chromium 151.0.7922.137-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19558 (Use after free in Extensions in Google Chrome prior to 
151.0.7922.137  ...)
+       {DSA-6436-1 DLA-4739-1}
        - chromium 151.0.7922.137-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19559 (Use after free in HTML in Google Chrome prior to 
151.0.7922.137 allowe ...)
+       {DSA-6436-1 DLA-4739-1}
        - chromium 151.0.7922.137-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19560 (Use after free in Blink in Google Chrome prior to 
151.0.7922.137 allow ...)
+       {DSA-6436-1 DLA-4739-1}
        - chromium 151.0.7922.137-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-9214 (Insufficient input validation vulnerability in the NETGEAR 
R7000 model ...)
@@ -2831,7 +3478,7 @@ CVE-2026-59119 (Incorrect default permissions in 
Microsoft PowerShell allows an
        NOT-FOR-US: Microsoft
 CVE-2026-59113 (Missing authorization in Visual Studio Code allows an 
unauthorized att ...)
        NOT-FOR-US: Microsoft
-CVE-2026-59086 (A vulnerability has been identified in Simcenter Nastran (All 
versions ...)
+CVE-2026-59086 (A vulnerability has been identified in Simcenter Femap (All 
versions < ...)
        NOT-FOR-US: Siemens
 CVE-2026-58651 (Heap-based buffer overflow in Microsoft Office Word allows an 
unauthor ...)
        NOT-FOR-US: Microsoft
@@ -4399,7 +5046,8 @@ CVE-2026-21058 (Improper input validation in Samsung 
Contacts prior to SMR Aug-2
        NOT-FOR-US: Samsung Mobile
 CVE-2026-19433 (Authorization Bypass Through User-Controlled Key in the 
contact manage ...)
        TODO: check
-CVE-2026-19429 (Jenkins FilePath.untarFrom() does not validate symlink targets 
in extr ...)
+CVE-2026-19429
+       REJECTED
        NOTE: bogus assignment outside of Jenkins CNA scope, being sorted out 
with MITRE
 CVE-2026-19404 (A flaw was found in 389 Directory Server. The CleanAllRUV and 
Abort Cl ...)
        - 389-ds-base <unfixed>
@@ -6218,11 +6866,11 @@ CVE-2026-17519
        REJECTED
 CVE-2026-17023 (The Salon Booking System  WordPress plugin through 10.30.33 
does not p ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-17022 (The Salon Booking System  WordPress plugin through 10.30.33 
does not p ...)
+CVE-2026-17022 (The Salon Booking System  WordPress plugin before 10.30.34 
does not pr ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-17021 (The Salon Booking System  WordPress plugin through 10.30.33 
does not p ...)
+CVE-2026-17021 (The Salon Booking System WordPress plugin before 10.30.34 does 
not pro ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-17020 (The Salon Booking System  WordPress plugin through 10.30.33 
does not v ...)
+CVE-2026-17020 (The Salon Booking System  WordPress plugin through 10.31.0 
does not ve ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-17019 (The JetEngine WordPress plugin before 3.8.13.1 does not 
sanitise uploa ...)
        NOT-FOR-US: WordPress plugin
@@ -7962,10 +8610,12 @@ CVE-2026-43622 (llama.cpp builds b1886 through b7445 
contain a double free vulne
 CVE-2026-3430 (The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not 
saniti ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-34502 (Heap-based Buffer Overflow vulnerability in Apache Portable 
Runtime Ut ...)
+       {DSA-6437-1}
        - apr-util 1.6.4-1 (bug #1143837)
        NOTE: https://lists.apache.org/thread/spk5643m4vq0mb8h5b9hz9gkp57ombl8
        NOTE: Fixed by: 
https://github.com/apache/apr-util/commit/f1c98dd0847c43375daf3789c936685adbc6d872
 (1.6.4-rc1-candidate)
 CVE-2026-34501 (Heap-based Buffer Overflow vulnerability in Apache Portable 
Runtime Ut ...)
+       {DSA-6437-1}
        - apr-util 1.6.4-1 (bug #1143837)
        NOTE: https://lists.apache.org/thread/o8h6c7cq86fplxlnry6c3rn9x0ovq8mv
        NOTE: Fixed by: 
https://github.com/apache/apr-util/commit/e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2
 (1.6.4-rc1-candidate)
@@ -7980,6 +8630,7 @@ CVE-2026-32548 (Unauthenticated Broken Access Control in 
SureCart <= 4.6.2 versi
 CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 
versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack 
recursion ...)
+       {DSA-6437-1}
        - apr-util 1.6.4-1 (bug #1143837)
        NOTE: https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1
        NOTE: Fixed by: 
https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8
 (1.6.4-rc1-candidate)
@@ -8103,6 +8754,7 @@ CVE-2026-0637 (When an Event Publisher output adapter is 
configured with irrelev
 CVE-2025-9266 (The Accelerate theme for WordPress is vulnerable to 
unauthorized modif ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-49506 (APR-util versions 1.6.3 (and earlier) function 
apr_password_validate() ...)
+       {DSA-6437-1}
        - apr-util 1.6.4-1 (bug #1143837)
        NOTE: https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5
        NOTE: Fixed by: 
https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e
 (1.6.4-rc1-candidate)
@@ -16554,12 +17206,12 @@ CVE-2026-64531 (In the Linux kernel, the following 
vulnerability has been resolv
        NOTE: 
https://git.kernel.org/linus/3f1f755366687d051174739fb99f7d560202f60b (7.2-rc4)
        NOTE: https://heyitsas.im/posts/ovswrap
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/28/8
-CVE-2026-49478
+CVE-2026-49478 (Fulcio is a certificate authority for issuing code signing 
certificate ...)
        - golang-github-sigstore-fulcio 1.8.7-1
        [trixie] - golang-github-sigstore-fulcio <no-dsa> (Minor issue)
        NOTE: https://github.com/sigstore/fulcio/pull/2354
        NOTE: Fixed by: 
https://github.com/sigstore/fulcio/commit/378c654f48c3bafdced04ead7010aab2cb4c6ca1
 (v1.8.6)
-CVE-2026-48702
+CVE-2026-48702 (Rekor is a software supply chain transparency log. Starting in 
version ...)
        - rekor 1.5.2-1
        [trixie] - rekor <no-dsa> (Minor issue)
        NOTE: https://github.com/sigstore/rekor/pull/2831
@@ -48582,7 +49234,8 @@ CVE-2019-25763 (WordPress Ultimate Addons for Beaver 
Builder 1.2.4.1 contains an
        NOT-FOR-US: WordPress plugin
 CVE-2026-9843 (The Database for Contact Form 7, WPforms, Elementor forms 
plugin for W ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-9375 (urllib3 version 2.6.3 is vulnerable to a decompression bomb 
bypass in  ...)
+CVE-2026-9375
+       REJECTED
        - python-urllib3 2.7.0-1 (bug #1140427)
        [trixie] - python-urllib3 <ignored> (Intrusive to backport; requires 
update for src:brotli for effective fix)
        [bookworm] - python-urllib3 <ignored> (Intrusive to backport; requires 
update for src:brotli for effective fix)
@@ -95483,7 +96136,7 @@ CVE-2026-5437 (An out-of-bounds read vulnerability 
exists in `DicomStreamReader`
        NOTE: https://orthanc.uclouvain.be/hg/orthanc/rev/5ce108190752
 CVE-2026-5329 (Rapid7 Velociraptor versions prior to 0.76.2contain an improper 
input  ...)
        NOT-FOR-US: Rapid7 Velociraptor
-CVE-2026-4901 (Hydrosystem Control System saves sensitive information into a 
log file ...)
+CVE-2026-4901 (AlanWeb SCADA saves sensitive information into a log file. 
Critically, ...)
        NOT-FOR-US: Hydrosystem Control System
 CVE-2026-4660 (HashiCorp\u2019s go-getter library up to v1.8.5 may allow 
arbitrary fi ...)
        - golang-github-hashicorp-go-getter <removed>
@@ -95652,9 +96305,9 @@ CVE-2026-34538 (Apache Airflow versions 3.0.0 through 
3.1.8 DagRun wait endpoint
        - airflow <itp> (bug #819700)
        NOTE: https://github.com/apache/airflow/pull/64415
        NOTE: https://www.openwall.com/lists/oss-security/2026/04/09/9
-CVE-2026-34185 (Hydrosystem Control System is vulnerable to SQL Injection 
across most  ...)
+CVE-2026-34185 (AlanWeb SCADA is vulnerable to SQL Injection across most 
scripts and i ...)
        NOT-FOR-US: Hydrosystem Control System
-CVE-2026-34184 (Hydrosystem Control System does not enforce authorization for 
some dir ...)
+CVE-2026-34184 (AlanWeb SCADA does not enforce authorization for some 
directories. Thi ...)
        NOT-FOR-US: Hydrosystem Control System
 CVE-2026-34179 (In Canonical LXD versions 4.12 through 6.7, the 
doCertificateUpdate fu ...)
        {DSA-6213-1 DSA-6212-1}
@@ -240705,7 +241358,8 @@ CVE-2024-8062 (A vulnerability in the typeahead 
endpoint of h2oai/h2o-3 version
        NOT-FOR-US: h2oai/h2o-3
 CVE-2024-8061 (In version 3.23.0 of aimhubio/aim, certain methods that request 
data f ...)
        NOT-FOR-US: aimhubio/aim
-CVE-2024-8060 (OpenWebUI version 0.3.0 contains a vulnerability in the audio 
API endp ...)
+CVE-2024-8060
+       REJECTED
        NOT-FOR-US: OpenWebUI
 CVE-2024-8057 (In version 0.4.1 of danswer-ai/danswer, a vulnerability exists 
where a ...)
        NOT-FOR-US: danswer-ai/danswer
@@ -240735,7 +241389,8 @@ CVE-2024-8017 (An XSS vulnerability exists in 
open-webui/open-webui versions <=
        NOT-FOR-US: open-webui/open-webui
 CVE-2024-7999
        REJECTED
-CVE-2024-7990 (A stored cross-site scripting (XSS) vulnerability exists in 
open-webui ...)
+CVE-2024-7990
+       REJECTED
        NOT-FOR-US: open-webui/open-webui
 CVE-2024-7983 (In version 0.3.8 of open-webui, an endpoint for converting 
markdown to ...)
        NOT-FOR-US: open-webui/open-webui
@@ -240785,11 +241440,14 @@ CVE-2024-7476 (A broken access control 
vulnerability exists in lunary-ai/lunary
        NOT-FOR-US: lunary-ai/lunary
 CVE-2024-7058 (A vulnerability in the sanitize_path function in 
parisneo/lollms-webui ...)
        NOT-FOR-US: parisneo/lollms-webui
-CVE-2024-7053 (A vulnerability in open-webui/open-webui version 0.3.8 allows 
an attac ...)
+CVE-2024-7053
+       REJECTED
        NOT-FOR-US: open-webui/open-webui
-CVE-2024-7046 (An improper access control vulnerability in 
open-webui/open-webui v0.3 ...)
+CVE-2024-7046
+       REJECTED
        NOT-FOR-US: open-webui/open-webui
-CVE-2024-7045 (In version v0.3.8 of open-webui/open-webui, improper access 
control vu ...)
+CVE-2024-7045
+       REJECTED
        NOT-FOR-US: open-webui/open-webui
 CVE-2024-7044 (A Stored Cross-Site Scripting (XSS) vulnerability exists in the 
chat f ...)
        NOT-FOR-US: open-webui/open-webui
@@ -240799,7 +241457,8 @@ CVE-2024-7040
        REJECTED
 CVE-2024-7039
        REJECTED
-CVE-2024-7036 (A vulnerability in open-webui/open-webui v0.3.8 allows an 
unauthentica ...)
+CVE-2024-7036
+       REJECTED
        NOT-FOR-US: open-webui/open-webui
 CVE-2024-7035 (In version v0.3.8 of open-webui/open-webui, sensitive actions 
such as  ...)
        NOT-FOR-US: open-webui/open-webui
@@ -240937,9 +241596,11 @@ CVE-2024-12704 (A vulnerability in the LangChainLLM 
class of the run-llama/llama
        NOT-FOR-US: run-llama/llama_index
 CVE-2024-12580 (A vulnerability in danny-avila/librechat prior to version 
0.7.6 allows ...)
        NOT-FOR-US: danny-avila/librechat
-CVE-2024-12537 (In version 0.3.32 of open-webui/open-webui, the absence of 
authenticat ...)
+CVE-2024-12537
+       REJECTED
        NOT-FOR-US: open-webui/open-webui
-CVE-2024-12534 (In version v0.3.32 of open-webui/open-webui, the application 
allows us ...)
+CVE-2024-12534
+       REJECTED
        NOT-FOR-US: open-webui/open-webui
 CVE-2024-12450 (In infiniflow/ragflow versions 0.12.0, the `web_crawl` 
function in `do ...)
        NOT-FOR-US: infiniflow/ragflow
@@ -291351,7 +292012,8 @@ CVE-2024-7041 (An Insecure Direct Object Reference 
(IDOR) vulnerability exists i
        NOT-FOR-US: open-webui
 CVE-2024-7038
        REJECTED
-CVE-2024-7037 (In version v0.3.8 of open-webui/open-webui, the endpoint 
/api/pipeline ...)
+CVE-2024-7037
+       REJECTED
        NOT-FOR-US: open-webui
 CVE-2024-5968 (The Photo Gallery by 10Web  WordPress plugin before 1.8.28 does 
not pr ...)
        NOT-FOR-US: WordPress plugin



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/af962a3316f1f9f2e94d64cae5e6e87cf5e1e893

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/af962a3316f1f9f2e94d64cae5e6e87cf5e1e893
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to