Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5f93d258 by security tracker role at 2026-08-18T07:12:52+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,293 @@
+CVE-2026-9859 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21,
11.8.x <= 1 ...)
+ TODO: check
+CVE-2026-9816 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21,
11.8.x <= 1 ...)
+ TODO: check
+CVE-2026-9693 (Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5
Mattermost f ...)
+ TODO: check
+CVE-2026-75587 (Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact
the pre-a ...)
+ TODO: check
+CVE-2026-75531 (Pandora contains a stored cross-site scripting (XSS)
vulnerability in ...)
+ TODO: check
+CVE-2026-75529 (Pandora is affected by a stored cross-site scripting
vulnerability in ...)
+ TODO: check
+CVE-2026-75483 (powerlevel10k fails to neutralize control characters in the
package.js ...)
+ TODO: check
+CVE-2026-75482 (SWE-agent's trajectory inspector (sweagent inspector),
confirmed in v1 ...)
+ TODO: check
+CVE-2026-75481 (SkyPilot fails to validate that authenticated users are
entitled to gr ...)
+ TODO: check
+CVE-2026-75480 (OpenViking debug vector scroll and count endpoints apply only
account- ...)
+ TODO: check
+CVE-2026-75479 (JimuReport contains an authentication bypass vulnerability in
the repo ...)
+ TODO: check
+CVE-2026-75151 (A vulnerability has been found in SourceCodester Onlne
Examination & L ...)
+ TODO: check
+CVE-2026-75111 (Evidently UI fails to properly validate the filename parameter
in the ...)
+ TODO: check
+CVE-2026-75110 (MemOS is a memory operating system for LLMs and AI agents. In
deployme ...)
+ TODO: check
+CVE-2026-75109 (Determined fails to authorize requests on the generic task
kill, pause ...)
+ TODO: check
+CVE-2026-75108 (Next Terminal fails to enforce per-asset authorization checks
on the p ...)
+ TODO: check
+CVE-2026-75106 (OpnForm derives editable-submission secrets from sequential
row identi ...)
+ TODO: check
+CVE-2026-75105 (phpIPAM through 1.8.1 fails to verify that a requested IP
address belo ...)
+ TODO: check
+CVE-2026-75104 (Hugging Face Transformers fails to validate shard filenames in
checkpo ...)
+ TODO: check
+CVE-2026-75103 (Crawlab fails to verify user ownership or administrative role
on the p ...)
+ TODO: check
+CVE-2026-75094 (A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts
the fun ...)
+ TODO: check
+CVE-2026-75093 (A security vulnerability has been detected in sonos tract up
to 0.23.4 ...)
+ TODO: check
+CVE-2026-75091 (The Quill Forms | Conversational Multi Step Forms, Surveys &
quizzes p ...)
+ TODO: check
+CVE-2026-75090 (A vulnerability was detected in EricLBuehler Mistral.rs up to
0.8.22. ...)
+ TODO: check
+CVE-2026-75089 (A weakness has been identified in PHPGurukul Complaint
Management Syst ...)
+ TODO: check
+CVE-2026-75088 (A vulnerability was determined in itsourcecode Hospital
Management Sys ...)
+ TODO: check
+CVE-2026-75087 (A vulnerability was found in itsourcecode Hospital Management
System 1 ...)
+ TODO: check
+CVE-2026-75086 (A vulnerability has been found in itsourcecode Hospital
Management Sys ...)
+ TODO: check
+CVE-2026-75082 (A flaw has been found in Webkul Bagisto up to 2.4.4. The
affected elem ...)
+ TODO: check
+CVE-2026-75081 (A vulnerability was detected in Webkul Bagisto up to 2.4.4.
Impacted i ...)
+ TODO: check
+CVE-2026-75080 (A security vulnerability has been detected in SourceCodester
Class and ...)
+ TODO: check
+CVE-2026-75079 (A weakness has been identified in SourceCodester Class and
Exam Timeta ...)
+ TODO: check
+CVE-2026-75078 (A security flaw has been discovered in SourceCodester Class
and Exam T ...)
+ TODO: check
+CVE-2026-75077 (A vulnerability was identified in SourceCodester Class and
Exam Timeta ...)
+ TODO: check
+CVE-2026-75014 (A flaw has been found in SourceCodester Pet Grooming
Management Softwa ...)
+ TODO: check
+CVE-2026-75013 (A vulnerability was detected in TOTOLINK EX1200L
9.3.5u.6146_B20201023 ...)
+ TODO: check
+CVE-2026-75012 (A security vulnerability has been detected in TOTOLINK EX1200L
9.3.5u. ...)
+ TODO: check
+CVE-2026-74234 (Legora before 2026-08-14 contains a cross-site scripting
vulnerability ...)
+ TODO: check
+CVE-2026-73560 (vLLM is an inference and serving engine for large language
models. Pri ...)
+ TODO: check
+CVE-2026-73410 (Budibase is an open-source low-code platform. Prior to 3.40.0,
package ...)
+ TODO: check
+CVE-2026-71858 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.7 ...)
+ TODO: check
+CVE-2026-71553 (ApostropheCMS is an open-source Node.js content management
system. In ...)
+ TODO: check
+CVE-2026-71518 (Typemill before 2.26.0 contains an authorization bypass
vulnerability ...)
+ TODO: check
+CVE-2026-71486 (vLLM is an inference and serving engine for large language
models. Pri ...)
+ TODO: check
+CVE-2026-71472 (A flaw was found in acm-search-v2-rhel9. This vulnerability
allows an ...)
+ TODO: check
+CVE-2026-71424 (Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14,
and 4.0.0 ...)
+ TODO: check
+CVE-2026-70495 (A flaw was found in search-v2-operator. This component's
`search-servi ...)
+ TODO: check
+CVE-2026-69148 (MLflow is an open source AI engineering platform for agents,
large lan ...)
+ TODO: check
+CVE-2026-69146 (MLflow is an open source AI engineering platform for agents,
large lan ...)
+ TODO: check
+CVE-2026-68765 (hashcat master branch builds after v7.1.2 contain a heap
buffer overfl ...)
+ TODO: check
+CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote
attacker to ...)
+ TODO: check
+CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213
allows a remo ...)
+ TODO: check
+CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782)
allows an ...)
+ TODO: check
+CVE-2026-67966 (Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows
unauthentic ...)
+ TODO: check
+CVE-2026-67965 (An issue in Tneda W20E v.16.01.0.6(2782) allows a remote
attacker to e ...)
+ TODO: check
+CVE-2026-67961 (An issue in O2OA v.10.0.2 allows a local attacker to execute
arbitrary ...)
+ TODO: check
+CVE-2026-67960 (An issue in PbootCMS v.3.2.15 allows an attacker to execute
arbitrary ...)
+ TODO: check
+CVE-2026-67926 (An issue in JeecgBoot v.3.9.2 allows a remote attacker to
execute arbi ...)
+ TODO: check
+CVE-2026-67925 (Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows
a remot ...)
+ TODO: check
+CVE-2026-67919 (An issue in Halo 2.25.4 allows a remote attacker to execute
arbitrary ...)
+ TODO: check
+CVE-2026-67918 (Directory Traversal vulnerability in hermes-studio v.0.6.26
allows a r ...)
+ TODO: check
+CVE-2026-67917 (zuraCast versions up to and including 0.23.7 contain a SQL
injection v ...)
+ TODO: check
+CVE-2026-67868 (A heap-based out-of-bounds write vulnerability exists in S2OPC
1.7.3 i ...)
+ TODO: check
+CVE-2026-67854 (SQL Injection vulnerability in Qcms v.6.0.6 allows a remote
attacker t ...)
+ TODO: check
+CVE-2026-67678 (File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80
allows a ...)
+ TODO: check
+CVE-2026-66795 (A flaw was found in the managedcluster-import-controller. The
Certific ...)
+ TODO: check
+CVE-2026-65976 (Deskflow is a keyboard and mouse sharing app. From 1.17.0
until contin ...)
+ TODO: check
+CVE-2026-65974 (ERPNext is a free and open source Enterprise Resource Planning
tool. P ...)
+ TODO: check
+CVE-2026-65832 (Deskflow is a keyboard and mouse sharing app. Prior to
continuous buil ...)
+ TODO: check
+CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning
tool. P ...)
+ TODO: check
+CVE-2026-65640 (WordPress is vulnerable to a remote code execution
vulnerability via m ...)
+ TODO: check
+CVE-2026-65351 (This issue was addressed through improved state management.
This issue ...)
+ TODO: check
+CVE-2026-65349 (An out-of-bounds read was addressed with improved input
validation. Th ...)
+ TODO: check
+CVE-2026-65347 (The issue was addressed with improved checks. This issue is
fixed in i ...)
+ TODO: check
+CVE-2026-65346 (An integer overflow was addressed with improved input
validation. This ...)
+ TODO: check
+CVE-2026-65343 (A use after free issue was addressed with improved memory
management. ...)
+ TODO: check
+CVE-2026-65341 (The issue was addressed with improved memory handling. This
issue is f ...)
+ TODO: check
+CVE-2026-65340 (This issue was addressed through improved state management.
This issue ...)
+ TODO: check
+CVE-2026-65339 (A logic issue was addressed with improved checks. This issue
is fixed ...)
+ TODO: check
+CVE-2026-65338 (The issue was addressed with improved memory handling. This
issue is f ...)
+ TODO: check
+CVE-2026-65337 (This issue was addressed through improved state management.
This issue ...)
+ TODO: check
+CVE-2026-65336 (This issue was addressed through improved state management.
This issue ...)
+ TODO: check
+CVE-2026-65335 (This issue was addressed through improved state management.
This issue ...)
+ TODO: check
+CVE-2026-65334 (A memory corruption issue was addressed with improved state
management ...)
+ TODO: check
+CVE-2026-65333 (This issue was addressed through improved state management.
This issue ...)
+ TODO: check
+CVE-2026-65332 (This issue was addressed through improved state management.
This issue ...)
+ TODO: check
+CVE-2026-65331 (This issue was addressed through improved state management.
This issue ...)
+ TODO: check
+CVE-2026-65330 (The issue was addressed with improved memory handling. This
issue is f ...)
+ TODO: check
+CVE-2026-65329 (An authentication issue was addressed with improved state
management. ...)
+ TODO: check
+CVE-2026-64849 (MLflow is an open source AI engineering platform for agents,
large lan ...)
+ TODO: check
+CVE-2026-64788 (The issue was addressed with improved memory handling. This
issue is f ...)
+ TODO: check
+CVE-2026-64787 (A use-after-free issue was addressed with improved memory
management. ...)
+ TODO: check
+CVE-2026-64784 (An out-of-bounds access issue was addressed with improved
bounds check ...)
+ TODO: check
+CVE-2026-64782 (A memory corruption vulnerability was addressed with improved
locking. ...)
+ TODO: check
+CVE-2026-64781 (The issue was addressed with improved input validation. This
issue is ...)
+ TODO: check
+CVE-2026-64780 (The issue was addressed with improved checks. This issue is
fixed in i ...)
+ TODO: check
+CVE-2026-64779 (A memory corruption vulnerability was addressed with improved
locking. ...)
+ TODO: check
+CVE-2026-64778 (The issue was addressed with improved checks. This issue is
fixed in i ...)
+ TODO: check
+CVE-2026-64760 (An information leakage was addressed with additional
validation. This ...)
+ TODO: check
+CVE-2026-64715 (A use-after-free issue was addressed with improved memory
management. ...)
+ TODO: check
+CVE-2026-64657 (Budibase is an open-source low-code platform. Prior to
3.39.19, the Po ...)
+ TODO: check
+CVE-2026-63670 (ApostropheCMS is an open-source Node.js content management
system. Pri ...)
+ TODO: check
+CVE-2026-63669 (ApostropheCMS is an open-source Node.js content management
system. Pri ...)
+ TODO: check
+CVE-2026-63667 (ApostropheCMS is an open-source Node.js content management
system. Pri ...)
+ TODO: check
+CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0
until contin ...)
+ TODO: check
+CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx
Enterprise Ed ...)
+ TODO: check
+CVE-2026-57485 (Stirling-PDF is a locally hosted web application that
facilitates vari ...)
+ TODO: check
+CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.7 ...)
+ TODO: check
+CVE-2026-56677 (9Router is an AI router & token saver. In 0.5.4 and earlier,
the POST ...)
+ TODO: check
+CVE-2026-54758 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.7 ...)
+ TODO: check
+CVE-2026-54385
+ REJECTED
+CVE-2026-54356 (Budibase is an open-source low-code platform. Prior to 3.41.3,
POST /a ...)
+ TODO: check
+CVE-2026-54336 (JumpServer is an open source bastion host and an operation and
mainten ...)
+ TODO: check
+CVE-2026-52886 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.7 ...)
+ TODO: check
+CVE-2026-51977 (An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security
Camera Ve ...)
+ TODO: check
+CVE-2026-47698 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6,
lib/bri ...)
+ TODO: check
+CVE-2026-47686 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6,
handleE ...)
+ TODO: check
+CVE-2026-47683 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6,
the buf ...)
+ TODO: check
+CVE-2026-45791 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-45790 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
+ TODO: check
+CVE-2026-44846 (JumpServer is an open source bastion host and an operation and
mainten ...)
+ TODO: check
+CVE-2026-44845 (JumpServer is an open source bastion host and an operation and
mainten ...)
+ TODO: check
+CVE-2026-43795 (The issue was addressed with improved memory handling. This
issue is f ...)
+ TODO: check
+CVE-2026-43794 (A memory corruption issue was addressed with improved memory
handling. ...)
+ TODO: check
+CVE-2026-43667 (A reachable assertion was addressed with improved input
validation. Th ...)
+ TODO: check
+CVE-2026-42164 (Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text
block/sect ...)
+ TODO: check
+CVE-2026-42163 (Mahara before 25.04.5 and 26.04.0 is vulnerable to
unauthorized access ...)
+ TODO: check
+CVE-2026-42162 (Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts
being acc ...)
+ TODO: check
+CVE-2026-40506 (OpenEMR before 8.2.0 contains a path traversal vulnerability
in the st ...)
+ TODO: check
+CVE-2026-39255 (Buffer Overflow vulnerability in SteelSeries GG (macOS)
v.107.0.0 allo ...)
+ TODO: check
+CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS)
v.107.0.0 allo ...)
+ TODO: check
+CVE-2026-38165 (A Server-Side Template Injection (SSTI) vulnerability in the
Velocity ...)
+ TODO: check
+CVE-2026-35219 (Budibase is an open-source low-code platform. Prior to 3.41.3,
automat ...)
+ TODO: check
+CVE-2026-34789 (FreeCAD is a free and open-source multiplatform 3D parametric
modeler. ...)
+ TODO: check
+CVE-2026-34399 (FreeCAD is a free and open-source multiplatform 3D parametric
modeler. ...)
+ TODO: check
+CVE-2026-34398 (FreeCAD is a free and open-source multiplatform 3D parametric
modeler. ...)
+ TODO: check
+CVE-2026-28984 (The issue was addressed with improved memory handling. This
issue is f ...)
+ TODO: check
+CVE-2026-19650 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
+ TODO: check
+CVE-2026-19589 (Packer up to 1.15.4 is vulnerable to an issue in the
third-party plugi ...)
+ TODO: check
+CVE-2026-19478 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
+ TODO: check
+CVE-2026-15748 (The Forminator Forms plugin for WordPress is vulnerable to
Arbitrary F ...)
+ TODO: check
+CVE-2026-15371 (Velociraptor's web GUI allows specifying a custom type for
columns in ...)
+ TODO: check
+CVE-2026-11817 (This vulnerability only affects Grafana stacks configured with
multipl ...)
+ TODO: check
+CVE-2026-11801 (The WPAdverts \u2013 Classifieds Plugin plugin for WordPress
is vulner ...)
+ TODO: check
+CVE-2026-10080 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21,
11.8.x <= 1 ...)
+ TODO: check
CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy()
in dri ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was
possible via u ...)
@@ -13329,6 +13619,7 @@ CVE-2026-XXXX [Neutron sub-resource APIs do not verify
parent ownership]
NOTE: https://review.opendev.org/c/openstack/neutron/+/989624/
NOTE: https://review.opendev.org/c/openstack/neutron/+/991586
CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant
infinite ...)
+ {DSA-6446-1}
- expat 2.8.3-1 (bug #1144064)
NOTE: https://github.com/libexpat/libexpat/pull/1296
NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
@@ -42233,6 +42524,7 @@ CVE-2026-53730 (DataEase is an open source data
visualization and analysis tool.
CVE-2026-53729 (DataEase is an open source data visualization and analysis
tool. Prior ...)
NOT-FOR-US: DataEase
CVE-2026-53511 (calibre is an e-book manager. Prior to 9.10.0, a malicious
EPUB, OPF, ...)
+ {DLA-4744-1}
- calibre 9.10.0+ds+~0.10.6-1
[trixie] - calibre <no-dsa> (Minor issue)
[bullseye] - calibre <not-affected> (Vulnerable code introduced later)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f93d25814ebdffbfbe93eddbf7ce78c2beb2f7b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f93d25814ebdffbfbe93eddbf7ce78c2beb2f7b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits