Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
dce3666d by security tracker role at 2026-08-21T19:13:47+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,13 +1,659 @@
-CVE-2026-74583 [net/sched: cls_route: fix fastmap use-after-free on filter]
+CVE-2026-9324
+       REJECTED
+CVE-2026-9321
+       REJECTED
+CVE-2026-9244
+       REJECTED
+CVE-2026-9012
+       REJECTED
+CVE-2026-77815 (to_abs_path in scripts/iib/tool.py normalised the requested 
path with  ...)
+       TODO: check
+CVE-2026-77814 (is_path_trusted in scripts/iib/api.py compares the requested 
path agai ...)
+       TODO: check
+CVE-2026-77812 (DJI drones transmit DUML (DJI Universal Markup Language) 
protocol mess ...)
+       TODO: check
+CVE-2026-77806 (SPIP before 4.4.21 allows unauthenticated remote attackers to 
execute  ...)
+       TODO: check
+CVE-2026-77795 (A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 
5.6.2.  ...)
+       TODO: check
+CVE-2026-77780 (Authorization Bypass Through User-Controlled Key in the 
transaction sa ...)
+       TODO: check
+CVE-2026-77776 (Headroom's LLM proxy derives the memory owner from the 
x-headroom-user ...)
+       TODO: check
+CVE-2026-77775 (Headroom's LLM proxy lets a client choose the upstream 
destination wit ...)
+       TODO: check
+CVE-2026-77769 (The report.list procedure in 
packages/trpc/src/routers/report.ts accep ...)
+       TODO: check
+CVE-2026-77768 (The report.get procedure in 
packages/trpc/src/routers/report.ts accept ...)
+       TODO: check
+CVE-2026-77767 (Reconmap's API applies a fallback authorization policy in 
apps/api/app ...)
+       TODO: check
+CVE-2026-77763 (The filestore backend in pkg/object/file.go, used for file:// 
stores a ...)
+       TODO: check
+CVE-2026-77761 (A parser state isolation vulnerability in misp-stix could 
cause data f ...)
+       TODO: check
+CVE-2026-77759 (Authorization Bypass Through User-Controlled Key in the 
transaction AP ...)
+       TODO: check
+CVE-2026-77755 (A denial-of-service vulnerability was identified in misp-stix 
when pro ...)
+       TODO: check
+CVE-2026-77751 (A path traversal vulnerability existed in the handling of MISP 
object  ...)
+       TODO: check
+CVE-2026-77710 (A vulnerability in misp-stix could allow a crafted STIX 
document to in ...)
+       TODO: check
+CVE-2026-77686 (A weakness has been identified in Dolibarr up to 23.0.4. This 
affects  ...)
+       TODO: check
+CVE-2026-77683 (A security flaw has been discovered in Comfast CF-N1-S 
2.6.0.1. Affect ...)
+       TODO: check
+CVE-2026-77681 (A vulnerability was identified in CodeAstro Online Job Portal 
1.0. Aff ...)
+       TODO: check
+CVE-2026-77651 (The arrayref crate 0.3.10 for Rust can trigger execution of 
malicious  ...)
+       TODO: check
+CVE-2026-77650 (The append-only-vec crate 0.1.9 for Rust can trigger execution 
of mali ...)
+       TODO: check
+CVE-2026-77649 (The internment crate 0.8.7 for Rust can trigger execution of 
malicious ...)
+       TODO: check
+CVE-2026-77646 (AServer-Side Request Forgery (SSRF) vulnerability has 
beenreported in  ...)
+       TODO: check
+CVE-2026-77645 (A critical remote code execution (RCE) vulnerability has been 
reported ...)
+       TODO: check
+CVE-2026-77644 (A critical bypass access control vulnerability has been 
reported in PT ...)
+       TODO: check
+CVE-2026-77392 (A weakness has been identified in SourceCodester Dynamic Input 
Field G ...)
+       TODO: check
+CVE-2026-77391 (A security flaw has been discovered in SourceCodester Dynamic 
Input Fi ...)
+       TODO: check
+CVE-2026-77264 (The Automation Web Platform \u2013 Notifications and OTP for 
WooCommer ...)
+       TODO: check
+CVE-2026-77237 (Missing queue-set type validation in xQueueAddToSet() in the 
FreeRTOS- ...)
+       TODO: check
+CVE-2026-77236 (Missing minimum size validation in secure context allocation 
in FreeRT ...)
+       TODO: check
+CVE-2026-77235 (Missing privilege verification in the secure context cleanup 
handler i ...)
+       TODO: check
+CVE-2026-77234 (Improper input validation in FreeRTOS-Kernel before 11.3.1 
might allow ...)
+       TODO: check
+CVE-2026-77151 (A security flaw has been discovered in lin-snow Ech0 up to 
5.4.1. Affe ...)
+       TODO: check
+CVE-2026-77113 (Path traversal in apport-unpack in Canonical Apport 
before2.36.0,2.34. ...)
+       TODO: check
+CVE-2026-77087 (Paperclip before 0.3.1 in default local_trusted mode fails to 
validate ...)
+       TODO: check
+CVE-2026-77086 (SiYuan before v3.7.4 fails to validate the packageName 
parameter in Ba ...)
+       TODO: check
+CVE-2026-77029 (Joomla Extension - yootheme.com - Missing CSRF tokens on 
front-end sta ...)
+       TODO: check
+CVE-2026-77028 (Joomla Extension - yootheme.com - Reflected XSS and open 
redirect via  ...)
+       TODO: check
+CVE-2026-76613 (Joomla Extension - yootheme.com - Authenticated, privileged 
SQL inject ...)
+       TODO: check
+CVE-2026-76612 (Joomla Extension - yootheme.com - Unauthenticated stored XSS 
via user- ...)
+       TODO: check
+CVE-2026-76611 (Joomla Extension - yootheme.com - Unauthenticated arbitrary 
directory  ...)
+       TODO: check
+CVE-2026-76158 (External Control of File Name or Path in the upload API 
endpoint of Da ...)
+       TODO: check
+CVE-2026-76157 (Missing authentication for a critical function in the upload 
API endpo ...)
+       TODO: check
+CVE-2026-76156 (OS command injection in the api endpoint of Datiphy Data 
Management Ce ...)
+       TODO: check
+CVE-2026-76155 (Use of default credentials in Datiphy Data Management Center 
from v8.3 ...)
+       TODO: check
+CVE-2026-76137 (Missing authentication for critical function vulnerability 
exists in V ...)
+       TODO: check
+CVE-2026-76131 (Use of hard-coded credentials issue exists in VOCALOID6 , 
which may al ...)
+       TODO: check
+CVE-2026-76023 (Improper resource control in Linux Toolkit Theming in Google 
Chrome pr ...)
+       TODO: check
+CVE-2026-76022 (Buffer overflow in Network in Google Chrome prior to 
151.0.7922.173 al ...)
+       TODO: check
+CVE-2026-76021 (Use after free in DOM in Google Chrome prior to 151.0.7922.173 
allowed ...)
+       TODO: check
+CVE-2026-76020 (Race condition in V8 in Google Chrome prior to 151.0.7922.173 
allowed  ...)
+       TODO: check
+CVE-2026-76019 (Incorrect authorization in Workers in Google Chrome prior to 
151.0.792 ...)
+       TODO: check
+CVE-2026-76018 (Privilege elevation in Import in Google Chrome prior to 
151.0.7922.173 ...)
+       TODO: check
+CVE-2026-76017 (Use after free in Chromoting in Google Chrome prior to 
151.0.7922.173  ...)
+       TODO: check
+CVE-2026-75946 (A potential security vulnerability has been identified in the 
OMEN Gam ...)
+       TODO: check
+CVE-2026-75933 (Jet Admin allows an authenticated attacker to inject 
JavaScript via th ...)
+       TODO: check
+CVE-2026-75932 (Jet Admin allows an attacker to create a malicious app and 
connect it  ...)
+       TODO: check
+CVE-2026-75928 (The Brushfire platform's video content streaming application 
(https:// ...)
+       TODO: check
+CVE-2026-75910 (Incorrect privilege assignment in the ClickHouse connector 
deployment  ...)
+       TODO: check
+CVE-2026-75796 (The AI Engine  WordPress plugin before 3.6.1 does not verify 
that the  ...)
+       TODO: check
+CVE-2026-75501 (A vulnerability in the Calix EXOS firmware for the GS7 XGS 
(GS5239XG)  ...)
+       TODO: check
+CVE-2026-75484 (Improper Neutralization of CRLF Sequences ('CRLF Injection') 
vulnerabi ...)
+       TODO: check
+CVE-2026-75115 (Joomla Extension - yootheme.com - Authenticated, privileged 
arbitrary  ...)
+       TODO: check
+CVE-2026-74866 (@fastify/busboy is a multipart form-data parser for Node.js. 
Its multi ...)
+       TODO: check
+CVE-2026-74836 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
+       TODO: check
+CVE-2026-73537 (Cross-site scripting vulnerability exists in Miraikan Assist 
App. If t ...)
+       TODO: check
+CVE-2026-73267 (A flaw was found in the clusterclaims-controller component of 
multiclu ...)
+       TODO: check
+CVE-2026-73137 (A flaw was found in the multicloud-operators-subscription 
component of ...)
+       TODO: check
+CVE-2026-73040 (Dockge validates a stack name only on the write path. In 
backend/stack ...)
+       TODO: check
+CVE-2026-72861 (The github-issue-bot templates in appwrite/templates verify 
the GitHub ...)
+       TODO: check
+CVE-2026-72860 (The POST /api/provider-nodes/validate route in 9router takes a 
caller- ...)
+       TODO: check
+CVE-2026-72858
+       REJECTED
+CVE-2026-72848 (SitemapLoader.parse_sitemap in 
langchain_community/document_loaders/si ...)
+       TODO: check
+CVE-2026-72846 (Lightdash stores the webhook URL supplied with a scheduled 
delivery an ...)
+       TODO: check
+CVE-2026-72843 (The customer update route in EverShop is declared with 
"access": "publ ...)
+       TODO: check
+CVE-2026-72818 (The URLS regular expression in nltk/tokenize/casual.py, 
compiled into  ...)
+       TODO: check
+CVE-2026-71862 (Checkmate is an open-source, self-hosted tool designed to 
track and mo ...)
+       TODO: check
+CVE-2026-71494 (Infracost provides cloud cost intelligence for engineers, AI 
coding ag ...)
+       TODO: check
+CVE-2026-71493 (Infracost provides cloud cost intelligence for engineers, AI 
coding ag ...)
+       TODO: check
+CVE-2026-71485 (Centrifugo is an open-source scalable real-time messaging 
server. Prio ...)
+       TODO: check
+CVE-2026-70656 (Checkmate is an open-source, self-hosted tool designed to 
track and mo ...)
+       TODO: check
+CVE-2026-70654 (libvips is a fast image processing library with low memory 
needs. Prio ...)
+       TODO: check
+CVE-2026-70653 (libvips is a fast image processing library with low memory 
needs. Prio ...)
+       TODO: check
+CVE-2026-70652 (libvips is a fast image processing library with low memory 
needs. Prio ...)
+       TODO: check
+CVE-2026-70651 (libvips is a fast image processing library with low memory 
needs. Prio ...)
+       TODO: check
+CVE-2026-70105 (Improper input validation in Microsoft Office Word allows an 
unauthori ...)
+       TODO: check
+CVE-2026-69855 (Server-side request forgery (ssrf) in Microsoft Copilot in 
Azure allow ...)
+       TODO: check
+CVE-2026-69851 (Server-side request forgery (ssrf) in Azure Active Directory 
allows an ...)
+       TODO: check
+CVE-2026-69836 (Deserialization of untrusted data in Microsoft Entra ID allows 
an unau ...)
+       TODO: check
+CVE-2026-69701
+       REJECTED
+CVE-2026-69558 (Authorization bypass through user-controlled key in Microsoft 
Partner  ...)
+       TODO: check
+CVE-2026-69555 (Incorrect authorization in Azure Arc allows an unauthorized 
attacker t ...)
+       TODO: check
+CVE-2026-69543 (Server-side request forgery (ssrf) in Azure Virtual Machines 
allows an ...)
+       TODO: check
+CVE-2026-69519 (Observable response discrepancy in Azure Stack HCI allows an 
unauthori ...)
+       TODO: check
+CVE-2026-69502 (Server-side request forgery (ssrf) in Azure SQL Database 
allows an una ...)
+       TODO: check
+CVE-2026-69419 (Integer overflow or wraparound in Azure Data Manager for 
Energy allows ...)
+       TODO: check
+CVE-2026-69400 (Improper limitation of a pathname to a restricted directory 
('path tra ...)
+       TODO: check
+CVE-2026-69242 (libvips is a fast image processing library with low memory 
needs. Prio ...)
+       TODO: check
+CVE-2026-69099
+       REJECTED
+CVE-2026-68921 (DiceBear is an avatar library for designers and developers. 
Prior to 9 ...)
+       TODO: check
+CVE-2026-68789 (Improper neutralization of special elements used in an sql 
command ('s ...)
+       TODO: check
+CVE-2026-68782 (Improper neutralization of special elements used in an sql 
command ('s ...)
+       TODO: check
+CVE-2026-68745 (Certificate validation failures in SAML authentication in 
Apache Cloud ...)
+       TODO: check
+CVE-2026-67567 (A flaw was found in the multicloud-operators-subscription 
component. T ...)
+       TODO: check
+CVE-2026-67448 (Mailpit is an email testing tool and API for developers. From 
1.29.0 u ...)
+       TODO: check
+CVE-2026-67447 (Mailpit is an email testing tool and API for developers. From 
1.30.0 u ...)
+       TODO: check
+CVE-2026-67446 (Mailpit is an email testing tool and API for developers. Prior 
to 1.30 ...)
+       TODO: check
+CVE-2026-67445 (Mailpit is an email testing tool and API for developers. Prior 
to 1.30 ...)
+       TODO: check
+CVE-2026-66722 (Improper authorization for CRUD operations on Project Roles 
and Projec ...)
+       TODO: check
+CVE-2026-66721 (Missing authorization issue for domain admins in CloudStack's 
host tag ...)
+       TODO: check
+CVE-2026-66309 (Improper access control in Azure SQL Database allows an 
authorized att ...)
+       TODO: check
+CVE-2026-65816 (Use of incorrectly-resolved name or reference in Azure Arc 
allows an u ...)
+       TODO: check
+CVE-2026-65801 (Server-side request forgery (ssrf) in Microsoft Exchange 
Online allows ...)
+       TODO: check
+CVE-2026-65770 (Improper neutralization of argument delimiters in a command 
('argument ...)
+       TODO: check
+CVE-2026-65645 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 
8.4.6. 8.3. ...)
+       TODO: check
+CVE-2026-65644 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 
8.4.6, 8.3. ...)
+       TODO: check
+CVE-2026-65613 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
+       TODO: check
+CVE-2026-64773 (An attacker that can reach a container's published TCP port 
may be abl ...)
+       TODO: check
+CVE-2026-63726
+       REJECTED
+CVE-2026-63723
+       REJECTED
+CVE-2026-63509 (Relative path traversal in Microsoft Fabric allows an 
authorized attac ...)
+       TODO: check
+CVE-2026-63466 (Unleash is an open-source feature management platform. Prior 
to 8.0.3, ...)
+       TODO: check
+CVE-2026-63462 (Unleash is an open-source feature management platform. Prior 
to 7.5.2, ...)
+       TODO: check
+CVE-2026-63046 (Improper Neutralization of Argument Delimiters in a Command 
('Argument ...)
+       TODO: check
+CVE-2026-63004 (Unleash is an open-source feature management platform. Prior 
to 7.5.2, ...)
+       TODO: check
+CVE-2026-62945 (TREK is a collaborative travel planner. Prior to 3.1.3, TREK 
file uplo ...)
+       TODO: check
+CVE-2026-62834 (Improper verification of cryptographic signature in Azure Data 
Factory ...)
+       TODO: check
+CVE-2026-62677 (Omnigent is an open-source AI agent framework and meta-harness 
for orc ...)
+       TODO: check
+CVE-2026-62676 (Omnigent is an open-source AI agent framework and meta-harness 
for orc ...)
+       TODO: check
+CVE-2026-62675 (Omnigent is an open-source AI agent framework and meta-harness 
for orc ...)
+       TODO: check
+CVE-2026-62674 (Omnigent is an open-source AI agent framework and meta-harness 
for orc ...)
+       TODO: check
+CVE-2026-62440 (Improper Access Control vulnerability in Apache CloudStack's 
Kubernete ...)
+       TODO: check
+CVE-2026-61422 (Authenticated pre-validation SSRF vulnerability in Apache 
CloudStack's ...)
+       TODO: check
+CVE-2026-61400 (Improper Neutralization of Special Elements used in a Command 
('Comman ...)
+       TODO: check
+CVE-2026-61399 (Improper Encoding or Escaping of Output vulnerability in 
Apache CloudS ...)
+       TODO: check
+CVE-2026-61398 (Improper Encoding or Escaping of Output vulnerability in 
Apache CloudS ...)
+       TODO: check
+CVE-2026-61397 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
+       TODO: check
+CVE-2026-59799 (Improper Privilege Management vulnerability in Apache 
CloudStack's Two ...)
+       TODO: check
+CVE-2026-59780 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
+       TODO: check
+CVE-2026-59657 (Cleartext Storage of Sensitive Information vulnerability in 
Apache Clo ...)
+       TODO: check
+CVE-2026-59655 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
+       TODO: check
+CVE-2026-59654 (Missing Release of Resource after Effective Lifetime 
vulnerability in  ...)
+       TODO: check
+CVE-2026-59323 (An application using Micrometer Tracing with W3C baggage 
propagation i ...)
+       TODO: check
+CVE-2026-59318 (In Spring AI's tool calling support, the per-request tool list 
is adve ...)
+       TODO: check
+CVE-2026-59308 (In Spring AI's Semantic Cache support, the context hash used 
to isolat ...)
+       TODO: check
+CVE-2026-59296 (Using untrusted, non-normalized input as-is for metrics data 
(such as  ...)
+       TODO: check
+CVE-2026-59279 (The MCP Streamable HTTP server transport (WebFlux and WebMvc 
variants) ...)
+       TODO: check
+CVE-2026-59085 (Server-Side Request Forgery (SSRF) vulnerability in Apache 
CloudStack' ...)
+       TODO: check
+CVE-2026-57835
+       REJECTED
+CVE-2026-56875
+       REJECTED
+CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and 
earlier, Caps ...)
+       TODO: check
+CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and 
earlier, Caps ...)
+       TODO: check
+CVE-2026-55850 (Element Web is a Matrix web client built using the Matrix 
React SDK. P ...)
+       TODO: check
+CVE-2026-55769 (CloudNativePG is a platform designed to manage PostgreSQL 
databases wi ...)
+       TODO: check
+CVE-2026-55765 (CloudNativePG is a platform designed to manage PostgreSQL 
databases wi ...)
+       TODO: check
+CVE-2026-55491 (BigBlueButton is an open-source virtual classroom. Prior to 
3.0.29, Bi ...)
+       TODO: check
+CVE-2026-55489 (BigBlueButton is an open-source virtual classroom. Prior to 
3.0.29, Bi ...)
+       TODO: check
+CVE-2026-55241 (Checkmate is an open-source, self-hosted tool designed to 
track and mo ...)
+       TODO: check
+CVE-2026-55015 (Uncontrolled search path element in Windows Remote Help allows 
an auth ...)
+       TODO: check
+CVE-2026-55013 (Uncontrolled search path element in Windows Remote Help 
Defense allows ...)
+       TODO: check
+CVE-2026-54789 (mod_auth_openidc is an OpenID Certified authentication and 
authorizati ...)
+       TODO: check
+CVE-2026-54682 (DiscordChatExporter saves Discord chat logs to a file. Prior 
to 2.47.2 ...)
+       TODO: check
+CVE-2026-54681 (DiscordChatExporter saves Discord chat logs to a file. Prior 
to 2.47.2 ...)
+       TODO: check
+CVE-2026-54509 (TREK is a collaborative travel planner. From 3.0.0 until 
3.1.0, the GE ...)
+       TODO: check
+CVE-2026-54508 (TREK is a collaborative travel planner. Prior to 3.1.0, TREK 
validates ...)
+       TODO: check
+CVE-2026-54505 (TREK is a collaborative travel planner. Prior to 3.1.0, when 
the Journ ...)
+       TODO: check
+CVE-2026-54389 (Ghidra before 12.1.3 contains an uncontrolled resource 
consumption vul ...)
+       TODO: check
+CVE-2026-54134 (OctoPrint provides a web interface for controlling consumer 3D 
printer ...)
+       TODO: check
+CVE-2026-54073 (VeraCrypt provides disk encryption with strong security based 
on TrueC ...)
+       TODO: check
+CVE-2026-54071 (BabelDOC is a document translation tool. Prior to 0.6.3, 
BabelDOC's ve ...)
+       TODO: check
+CVE-2026-53991
+       REJECTED
+CVE-2026-53974
+       REJECTED
+CVE-2026-53804 (OTRS Community Edition contains an authenticated OS command 
injection  ...)
+       TODO: check
+CVE-2026-53762 (VeraCrypt provides disk encryption with strong security based 
on TrueC ...)
+       TODO: check
+CVE-2026-52021 (An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) 
allows a remo ...)
+       TODO: check
+CVE-2026-50278 (iccDEV provides a set of libraries and tools for working with 
ICC colo ...)
+       TODO: check
+CVE-2026-50222 (Missing Authorization, Exposure of Sensitive Information to an 
Unautho ...)
+       TODO: check
+CVE-2026-50192 (Kerberos Agent is an open source video (surveillance) 
management agent ...)
+       TODO: check
+CVE-2026-50112 (SSRF via Metalink Mirror URL Resolution:  An authenticated 
tenant can  ...)
+       TODO: check
+CVE-2026-49436 (LinkAce is a self-hosted archive to collect website links. 
Prior to ve ...)
+       TODO: check
+CVE-2026-49245 (SFTPGo is an open source, event-driven file transfer solution. 
From 2. ...)
+       TODO: check
+CVE-2026-49244 (SFTPGo is an open source, event-driven file transfer solution. 
From 2. ...)
+       TODO: check
+CVE-2026-49217 (Mailu is a mail server as a set of Docker images. Prior to 
version 202 ...)
+       TODO: check
+CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function 
builds the ex ...)
+       TODO: check
+CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder 
(XmlBuilder module ...)
+       TODO: check
+CVE-2026-47827 (Command Injection in BOSH CLI tool on windows in Cloud Foundry 
allows  ...)
+       TODO: check
+CVE-2026-47359 (Improper Neutralization of Special Elements used in an OS 
Command ('OS ...)
+       TODO: check
+CVE-2026-47080 (XML Injection vulnerability in joshnuss xml_builder 
(XmlBuilder module ...)
+       TODO: check
+CVE-2026-47079 (Inappropriate Encoding for Output Context vulnerability in 
joshnuss xm ...)
+       TODO: check
+CVE-2026-46682 (BigBlueButton is an open-source virtual classroom. Prior to 
3.0.23, Bi ...)
+       TODO: check
+CVE-2026-46355 (BigBlueButton is an open-source virtual classroom. Prior to 
3.0.23, Bi ...)
+       TODO: check
+CVE-2026-45202 (Software installed and run as a non-privileged user may 
conduct GPU sy ...)
+       TODO: check
+CVE-2026-45201 (Software installed and run as a non-privileged user may 
conduct improp ...)
+       TODO: check
+CVE-2026-45199 (Kernel software installed and running inside a Guest VM may 
post impro ...)
+       TODO: check
+CVE-2026-43798 (A single crafted SSH message gives an unauthenticated network 
attacker ...)
+       TODO: check
+CVE-2026-43679 (This issue was addressed with improved permissions checking. 
This issu ...)
+       TODO: check
+CVE-2026-41451 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 
contain a  ...)
+       TODO: check
+CVE-2026-41450 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 
contain a  ...)
+       TODO: check
+CVE-2026-41449 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 
contain a  ...)
+       TODO: check
+CVE-2026-39909 (llama.cpp before b8585 contains a use-after-free vulnerability 
in the  ...)
+       TODO: check
+CVE-2026-35163 (OctoPrint provides a web interface for controlling consumer 3D 
printer ...)
+       TODO: check
+CVE-2026-27875 (Cleartext Storage of Sensitive Information in Memory 
vulnerability in  ...)
+       TODO: check
+CVE-2026-22681 (OpenViking before 0.3.4contains a server-side request forgery 
vulnerab ...)
+       TODO: check
+CVE-2026-20679 (The issue was addressed with improved checks. This issue is 
fixed in m ...)
+       TODO: check
+CVE-2026-19848 (The ProfilePress WordPress plugin before 4.17.1 does not strip 
shortco ...)
+       TODO: check
+CVE-2026-19783 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-19755 (NoSleep 1.5.1 exposes a privileged XPC Mach service and 
accepts raw di ...)
+       TODO: check
+CVE-2026-19449 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a 
vulnerability in c ...)
+       TODO: check
+CVE-2026-19448 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory 
corruptio ...)
+       TODO: check
+CVE-2026-19446 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote 
unauthen ...)
+       TODO: check
+CVE-2026-19442 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer 
validation ...)
+       TODO: check
+CVE-2026-19441 (Missing authentication for critical function vulnerability in 
IKAS Tec ...)
+       TODO: check
+CVE-2026-19437 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-19435 (The Duplicate Post WordPress plugin before 1.5.6 does not 
check the us ...)
+       TODO: check
+CVE-2026-19085 (The Duplicate Post WordPress plugin before 1.5.6 does not 
check that a ...)
+       TODO: check
+CVE-2026-18842 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-18840 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-18835 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote aut ...)
+       TODO: check
+CVE-2026-18832 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-18828 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-18824 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote aut ...)
+       TODO: check
+CVE-2026-18822 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-18781 (The Drag and Drop Multiple File Upload for Contact Form 7 
WordPress pl ...)
+       TODO: check
+CVE-2026-18716 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote aut ...)
+       TODO: check
+CVE-2026-18670 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-18420 (Improper input validation in the Time Series Visual Builder 
(TSVB) plu ...)
+       TODO: check
+CVE-2026-18409 (The WPForms Pro plugin for WordPress is vulnerable to Stored 
Cross-Sit ...)
+       TODO: check
+CVE-2026-18356 (The Limit Login Attempts Reloaded WordPress plugin before 
3.3.5 does n ...)
+       TODO: check
+CVE-2026-17559 (The Passster WordPress plugin before 4.3.9 does not correctly 
match it ...)
+       TODO: check
+CVE-2026-17436 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17425 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17424 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17423 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17422 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-17252 (A stack-based out-of-bounds write vulnerability exists in the 
login re ...)
+       TODO: check
+CVE-2026-17251 (A NULL pointer dereference vulnerability exists in the HTTP 
request pa ...)
+       TODO: check
+CVE-2026-17250 (A stack-based buffer overflow vulnerability exists in the 
firmware upd ...)
+       TODO: check
+CVE-2026-17195 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-17171 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-17170 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17168 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote aut ...)
+       TODO: check
+CVE-2026-17165 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17163 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17160 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17159 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17157 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17152 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17145 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17142 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17141 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17138 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17136 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17124 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-17122 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17121 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17120 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17118 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17060 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17040 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17024 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17009 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-17007 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-17006 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17003 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-17000 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16997 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16996 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16991 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16989 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16980 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16973 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16972 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16964 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16962 (The Tamara Checkout WordPress plugin through 1.9.9.20 does not 
verify  ...)
+       TODO: check
+CVE-2026-16959 (The Media Library Assistant WordPress plugin before 3.40 does 
not vali ...)
+       TODO: check
+CVE-2026-16958 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16952 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16951 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local auth ...)
+       TODO: check
+CVE-2026-16946 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16945 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16944 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16943 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16937 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16936 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16935 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16934 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16650 (The Charitable WordPress plugin before 1.8.12 does not verify 
the auth ...)
+       TODO: check
+CVE-2026-16577 (The Dokan: AI Powered WooCommerce Multivendor Marketplace 
Solution  Wo ...)
+       TODO: check
+CVE-2026-16576 (The Dokan: AI Powered WooCommerce Multivendor Marketplace 
Solution  Wo ...)
+       TODO: check
+CVE-2026-16575 (The Dokan: AI Powered WooCommerce Multivendor Marketplace 
Solution  Wo ...)
+       TODO: check
+CVE-2026-16520 (Improper input validation and Exposure of sensitive 
information throug ...)
+       TODO: check
+CVE-2026-16323 (Execution after redirect (EAR) vulnerability in FuyaWeb 
Internet and I ...)
+       TODO: check
+CVE-2026-15580 (vault token disclosure via unvalidated postMessage 
vulnerability in N- ...)
+       TODO: check
+CVE-2026-15576 (Improper authentication in the agent receiver of Checkmk 
<2.5.0p10 all ...)
+       TODO: check
+CVE-2026-15150 (The myCred WordPress plugin before 3.2.5 does not verify that 
the rece ...)
+       TODO: check
+CVE-2026-15046 (The LitExtension WordPress plugin through 1.2.5 does not 
verify a nonc ...)
+       TODO: check
+CVE-2026-14601 (The Link Whisper Free WordPress plugin before 0.9.7 does not 
properly  ...)
+       TODO: check
+CVE-2026-14325 (The Drag and Drop Multiple File Upload for Contact Form 7 
WordPress pl ...)
+       TODO: check
+CVE-2026-14208 (Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL 
files in ...)
+       TODO: check
+CVE-2026-13736 (The NewPath WildApricotPress Add-on  WordPress plugin through 
1.0.0 do ...)
+       TODO: check
+CVE-2026-13176 (The Eventin WordPress plugin before 4.1.21 does not validate a 
user-su ...)
+       TODO: check
+CVE-2026-11938
+       REJECTED
+CVE-2026-11902
+       REJECTED
+CVE-2026-11830
+       REJECTED
+CVE-2026-11427
+       REJECTED
+CVE-2025-52182 (The Library Corporation LS2 Admin v5.7 to v5.8.0 was 
discovered to con ...)
+       TODO: check
+CVE-2025-3127
+       REJECTED
+CVE-2025-2795
+       REJECTED
+CVE-2025-15671 (The Welcart e-Commerce WordPress plugin before 2.12.1 does not 
regener ...)
+       TODO: check
+CVE-2023-7344
+       REJECTED
+CVE-2023-7336
+       REJECTED
+CVE-2023-7310
+       REJECTED
+CVE-2021-4482
+       REJECTED
+CVE-2021-4476
+       REJECTED
+CVE-2021-4475
+       REJECTED
+CVE-2019-25725
+       REJECTED
+CVE-2019-25715
+       REJECTED
+CVE-2017-20232
+       REJECTED
+CVE-2026-74583 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux 7.1.9-1
        NOTE: 
https://git.kernel.org/linus/47d7f7051253bdc02b1d245d87e38f16d31a74df (7.2-rc7)
-CVE-2026-74582 [packet: use consistent hard_header_len in non-ring send paths]
+CVE-2026-74582 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
        - linux 7.1.9-1
        NOTE: 
https://git.kernel.org/linus/03390aa32e669cc4ecd7d34108e2e1afc13d689d (7.2-rc7)
-CVE-2026-74581 [net: ipv6: clear suppressed fib6 rule result]
+CVE-2026-74581 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux 7.1.8-1
        NOTE: 
https://git.kernel.org/linus/6aea62e433fe1b586202a5fee8b5807ce635e1d7 (7.2-rc6)
-CVE-2026-74580 [vhost: reset the vring metadata cache on vring reconfiguration]
+CVE-2026-74580 (In the Linux kernel, the following vulnerability has been 
resolved:  v ...)
        - linux 7.1.9-1
        NOTE: 
https://git.kernel.org/linus/de845981da67a6b049080c87e605130b0c30adc5 (7.2-rc7)
 CVE-2026-19685
@@ -1550,7 +2196,7 @@ CVE-2026-76216 (Vikunja through 2.4.0 contains a 
principal-type confusion vulner
        NOT-FOR-US: Vikunja
 CVE-2026-76215 (phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility 
checks befo ...)
        NOT-FOR-US: phpMyFAQ
-CVE-2026-76214 (phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to 
persist th ...)
+CVE-2026-76214 (phpMyFAQ before 4.1.7 fails to persist the WebAuthn login 
challenge ge ...)
        NOT-FOR-US: phpMyFAQ
 CVE-2026-76213 (phpMyFAQ before 4.1.7 contains a brute-force vulnerability in 
the two- ...)
        NOT-FOR-US: phpMyFAQ
@@ -1558,7 +2204,7 @@ CVE-2026-76212 (phpMyFAQ before 4.1.7, when configured to 
use PostgreSQL via the
        NOT-FOR-US: phpMyFAQ
 CVE-2026-76211 (phpMyFAQ before 4.1.7 fails to properly enforce 
CONFIGURATION_EDIT per ...)
        NOT-FOR-US: phpMyFAQ
-CVE-2026-76210 (phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ 
answers ...)
+CVE-2026-76210 (phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ 
answers ...)
        NOT-FOR-US: phpMyFAQ
 CVE-2026-76209 (phpMyFAQ versions before v4.1.6 fail to validate the 
security.enableRe ...)
        NOT-FOR-US: phpMyFAQ
@@ -1748,7 +2394,8 @@ CVE-2026-70422 (Dell OpenManage Enterprise, versions 
prior to 4.7.0, contains an
        NOT-FOR-US: Dell / EMC
 CVE-2026-70421 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
        NOT-FOR-US: Dell / EMC
-CVE-2026-69159 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
+CVE-2026-69159
+       REJECTED
        - freerdp3 3.29.0+dfsg-1
        [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
@@ -4326,48 +4973,63 @@ CVE-2026-60589 (Vulnerability in the Oracle Java SE, 
Oracle GraalVM for JDK, Ora
        - openjdk-8 8u504-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-76034 (Buffer overflow in WebGL in Google Chrome prior to 
151.0.7922.169 allo ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76036 (Buffer overflow in Dawn in Google Chrome on on Android prior 
to 151.0. ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76033 (Inappropriate implementation in CORS in Google Chrome prior to 
151.0.7 ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76037 (Link following in CredentialProvider in Google Chrome on on 
Windows pr ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76044 (Race condition in USB in Google Chrome prior to 151.0.7922.169 
allowed ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76039 (Incorrect reference resolution in Core in Google Chrome on on 
Android  ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76040 (Use after free in Browser in Google Chrome on on Mac prior to 
151.0.79 ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76035 (Inappropriate implementation in Media in Google Chrome on on 
Mac prior ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76042 (Use of uninitialized resource in GPU in Google Chrome prior to 
151.0.7 ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76046 (Buffer overflow in ANGLE in Google Chrome on on Android prior 
to 151.0 ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76043 (Incorrect calculation in V8 in Google Chrome prior to 
151.0.7922.169 a ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76041 (Information leak in Skia in Google Chrome prior to 
151.0.7922.169 allo ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76047 (Type confusion in V8 in Google Chrome prior to 151.0.7922.169 
allowed  ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76038 (Type confusion in V8 in Google Chrome prior to 151.0.7922.169 
allowed  ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76045 (Use after free in WebGL in Google Chrome prior to 
151.0.7922.169 allow ...)
+       {DSA-6455-1 DLA-4749-1}
        - chromium 151.0.7922.169-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-75926 (Hugo 0.161.0 placed the Node asset pipelines behind the 
Node.js permis ...)
@@ -4496,7 +5158,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient 
validation of packet len
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
        NOTE: Followup: 
https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
 CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, 
Thunderbird E ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4510,7 +5172,7 @@ CVE-2026-74988 (Internally found bugs present in 
Thunderbird ESR 153.0 and Thund
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
 CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, 
Thunderbird E ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4527,7 +5189,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine 
component. This vulnerab
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
 CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This 
vulnerab ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4553,7 +5215,7 @@ CVE-2026-74977 (Integer overflow in the Graphics 
component. This vulnerability w
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
 CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. 
This vulne ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4564,7 +5226,7 @@ CVE-2026-74975 (Spoofing issue in the Downloads component 
in Firefox for Android
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
 CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. 
This vu ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4572,7 +5234,7 @@ CVE-2026-74974 (Same-origin policy bypass in the 
Graphics: ImageLib component. T
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
 CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This 
vulnera ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4580,7 +5242,7 @@ CVE-2026-74973 (Race condition, use-after-free in the 
Graphics component. This v
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
 CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions 
component. This  ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4588,7 +5250,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push 
Subscriptions component.
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
 CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling 
componen ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4599,7 +5261,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
 CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This 
vulnerabi ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4610,7 +5272,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics: 
WebRender component. This
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
 CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback 
component. This ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4621,7 +5283,7 @@ CVE-2026-74966 (Information disclosure in the Form 
Autofill component. This vuln
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
 CVE-2026-74965 (Privilege escalation in the Shell Integration component. This 
vulnerab ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4629,7 +5291,7 @@ CVE-2026-74965 (Privilege escalation in the Shell 
Integration component. This vu
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
 CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability 
was fix ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4637,7 +5299,7 @@ CVE-2026-74964 (Integer overflow in the Graphics 
component. This vulnerability w
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
 CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies 
component. This v ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4645,7 +5307,7 @@ CVE-2026-74963 (Same-origin policy bypass in the 
Networking: Cookies component.
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
 CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. 
This vulner ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4656,7 +5318,7 @@ CVE-2026-74961 (Side-channel in the Web Audio component. 
This vulnerability was
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
 CVE-2026-74960 (Site isolation issue in the WebExtensions component. This 
vulnerabilit ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4664,7 +5326,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions 
component. This vulner
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
 CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This 
vulnerabil ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4675,7 +5337,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
 CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This 
vulnerability w ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4692,7 +5354,7 @@ CVE-2026-74954 (Information disclosure due to 
side-channel in the Storage: Cache
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
 CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. 
This vulner ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4709,7 +5371,7 @@ CVE-2026-74950 (Privilege escalation in the Downloads API 
component. This vulner
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
 CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: 
Canvas2D c ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4717,7 +5379,7 @@ CVE-2026-74949 (Privilege escalation due to 
use-after-free in the Graphics: Canv
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
 CVE-2026-74948 (Information disclosure in the Graphics component. This 
vulnerability w ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4728,7 +5390,7 @@ CVE-2026-74947 (Privilege escalation due to invalid 
pointer in the Graphics comp
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
 CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4736,7 +5398,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect 
boundary conditions in the
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
 CVE-2026-74945 (Information disclosure in the Graphics: Text component. This 
vulnerabi ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4744,7 +5406,7 @@ CVE-2026-74945 (Information disclosure in the Graphics: 
Text component. This vul
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
 CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This 
vulnerability w ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4752,7 +5414,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML 
component. This vulnerabi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
 CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This 
vulnerability ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4760,7 +5422,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib 
component. This vulnera
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
 CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. 
This vul ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4768,7 +5430,7 @@ CVE-2026-74942 (Privilege escalation in the Remote 
Settings Client component. Th
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
 CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. 
This vuln ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4776,7 +5438,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics: 
CanvasWebGL component. Thi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
 CVE-2026-74940 (Use-after-free in the Graphics: Text component. This 
vulnerability was ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4784,7 +5446,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text 
component. This vulnerabili
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
 CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This 
vulnerabil ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4798,7 +5460,7 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
 CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This 
vulnerab ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4806,7 +5468,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript: 
WebAssembly component. This vu
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
 CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This 
vulnerabil ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -4814,7 +5476,7 @@ CVE-2026-74935 (Privilege escalation in the DOM: 
Networking component. This vuln
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
 CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. 
This vuln ...)
-       {DSA-6451-1}
+       {DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6329,11 +6991,11 @@ CVE-2026-13700 (The WooMS WordPress plugin through 9.14 
does not validate a user
        NOT-FOR-US: WordPress plugin
 CVE-2026-66801
        NOT-FOR-US: Red Hat cluster-backup-operator
-CVE-2026-66800
+CVE-2026-66800 (Server-side request forgery (ssrf) in Azure Data Factory 
allows an una ...)
        NOT-FOR-US: Red Hat cluster-backup-operator
 CVE-2026-66798
        NOT-FOR-US: Red Hat cluster-backup-operator
-CVE-2026-66797
+CVE-2026-66797 (Improper access control in CloudStack's annotation 
functionality allow ...)
        NOT-FOR-US: Red Hat cluster-backup-operator
 CVE-2026-18725
        - open-iscsi <unfixed> (bug #1144935)
@@ -14137,7 +14799,7 @@ CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require 
network-level access con
        NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0106
        NOTE: https://bugs.launchpad.net/ironic/+bug/2162821
        NOTE: https://bugs.launchpad.net/ironic/+bug/2162818
-CVE-2026-77648 [OSSN-0105: OpenStack Glance legacy Tasks import bypasses image 
import URI filtering]
+CVE-2026-77648 (In OpenStack Glance through 32.0.0, the /v2/tasks API accepts 
type=imp ...)
        - glance 2:32.0.0-3 (bug #1144212)
        [trixie] - glance <no-dsa> (Minor issue)
        NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0105
@@ -15281,7 +15943,7 @@ CVE-2026-65797 (Numeric truncation error in Windows DNS 
allows an authorized att
        NOT-FOR-US: Microsoft
 CVE-2026-65796 (Heap-based buffer overflow in Windows iSCSI Target Service 
allows an u ...)
        NOT-FOR-US: Microsoft
-CVE-2026-65795 (No cwe for this issue in Windows DNS allows an authorized 
attacker to  ...)
+CVE-2026-65795 (Relative path traversal in Windows DNS allows an authorized 
attacker t ...)
        NOT-FOR-US: Microsoft
 CVE-2026-65794 (Buffer over-read in Windows SMB Client allows an unauthorized 
attacker ...)
        NOT-FOR-US: Microsoft
@@ -17214,7 +17876,8 @@ CVE-2026-XXXX [RCE fixed in 4.4.21]
        - spip 4.4.21+dfsg-1
        [trixie] - spip 4.4.21+dfsg-0+deb13u1
        NOTE: 
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html
-CVE-2026-77647 [RCE fixed in 4.4.20]
+CVE-2026-77647 (SPIP before 4.4.20 allows unauthenticated remote attackers to 
execute  ...)
+       {DSA-6448-1}
        - spip 4.4.20+dfsg-1
        NOTE: 
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-20.html
 CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in 
SQLite-b ...)
@@ -25091,12 +25754,12 @@ CVE-2026-XXXX [GHSA-p2v3-6wvc-cv3p: Arbitrary file 
write on host via image finge
        [trixie] - incus 6.0.4-2+deb13u9
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-p2v3-6wvc-cv3p
        NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-63343 [Arbitrary file read+write on host via metadata.yaml symlink in 
crafted image]
+CVE-2026-63343 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-fmjx-5j3g-997p
        NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-63125 [Arbitrary file write on host via backup.yaml symlink in 
crafted image]
+CVE-2026-63125 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-6rqx-22hc-qm36
@@ -25106,22 +25769,22 @@ CVE-2026-XXXX [GHSA-m3j6-p3v3-qmjv: Container 
configuration newline injection th
        [trixie] - incus 6.0.4-2+deb13u9
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-m3j6-p3v3-qmjv
        NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62941 [Project restriction bypass via cross-project instance copy]
+CVE-2026-62941 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-mq9x-prm8-3vpw
        NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62940 [Project restriction bypass via instance migration config 
override]
+CVE-2026-62940 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-qw5c-v953-38gw
        NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62867 [Argument injection through storage volume block.create_options]
+CVE-2026-62867 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-q7xw-r4w2-2wcm
        NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62313 [Project isolation restriction bypass by omitting 
security.idmap.isolated]
+CVE-2026-62313 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-53cg-qvg7-m8vg
@@ -55592,31 +56255,38 @@ CVE-2026-XXXX [TROVE-2026-015]
        [bookworm] - tor 0.4.9.11-0+deb12u1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41261
-CVE-2026-77642 [TROVE-2026-019]
+CVE-2026-77642 (tor before 0.4.9.9 was prone to anout-of-bounds write when 
parsing a c ...)
+       {DSA-6372-1}
        - tor 0.4.9.9-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41267
-CVE-2026-77641 [TROVE-2026-017]
+CVE-2026-77641 (tor before 0.4.9.9 was prone to aNULL write after free when 
sending a  ...)
+       {DSA-6372-1}
        - tor 0.4.9.9-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41263
-CVE-2026-77639 [TROVE-2026-022]
+CVE-2026-77639 (Tor before 0.4.9.9 was prone to acompression bomb bypass where 
an atta ...)
+       {DSA-6372-1}
        - tor 0.4.9.9-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41275
-CVE-2026-77640 [TROVE-2026-021]
+CVE-2026-77640 (tor before 0.4.9.9 was prone to an infinite loop when 
decompressing a  ...)
+       {DSA-6372-1}
        - tor 0.4.9.9-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41274
-CVE-2026-77584 [TROVE-2026-025]
+CVE-2026-77584 (Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that 
arrives on ...)
+       {DSA-6372-1}
        - tor 0.4.9.11-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41258 
(private ATM)
-CVE-2026-77587 [TROVE-2026-026]
+CVE-2026-77587 (Tor before 0.4.9.11 is prone to a use-after-free (and 
potential double ...)
+       {DSA-6372-1}
        - tor 0.4.9.11-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41306
-CVE-2026-77638
+CVE-2026-77638 (Tor before 0.4.9.11 is prone to a race condition where in just 
the rig ...)
+       {DSA-6372-1}
        - tor 0.4.9.11-1
        [bullseye] - tor <end-of-life> (see DSA 5562)
        NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41297
@@ -56903,21 +57573,21 @@ CVE-2021-47986 (Parse Server before 4.10.0 contains a 
supply chain vulnerability
        NOT-FOR-US: Parse Server
 CVE-2020-37256 (Grav before 1.6.30 contains a cross-site scripting 
vulnerability in th ...)
        NOT-FOR-US: Grav CMS
-CVE-2026-48750
+CVE-2026-48750 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
        [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-73hr-m85f-64v9
        NOTE: https://github.com/canonical/lxd/pull/18590
-CVE-2026-48751
+CVE-2026-48751 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
        [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv
        NOTE: https://github.com/canonical/lxd/pull/18604
-CVE-2026-48752
+CVE-2026-48752 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
@@ -56925,7 +57595,7 @@ CVE-2026-48752
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-vxp5-584q-c479
        NOTE: 
https://github.com/lxc/incus/commit/cbefa31ae0da8fd96361178aed3a3c631e098fef 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18590
-CVE-2026-48755
+CVE-2026-48755 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
@@ -56933,7 +57603,7 @@ CVE-2026-48755
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-v6mj-8pf4-hhw4
        NOTE: 
https://github.com/lxc/incus/commit/873a032a461df6b09b7586435b592873863a4e88 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18597
-CVE-2026-48769
+CVE-2026-48769 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
@@ -56941,7 +57611,7 @@ CVE-2026-48769
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-f6m5-xw2g-xc4x
        NOTE: 
https://github.com/lxc/incus/commit/46d6ef232186df5535c49ca9f3597cab381f9b86 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18594
-CVE-2026-55621
+CVE-2026-55621 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
@@ -56949,7 +57619,7 @@ CVE-2026-55621
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-64f3-v33m-w89f
        NOTE: 
https://github.com/lxc/incus/commit/2e01078366e2653712719dec82318e51c6d21b28 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18603
-CVE-2026-55622
+CVE-2026-55622 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
@@ -56957,14 +57627,14 @@ CVE-2026-55622
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-c9f5-j9c3-mhrg
        NOTE: 
https://github.com/lxc/incus/commit/1e3ffc53a10950e55de62ac1e0d612be597b84eb 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18603
-CVE-2026-48749
+CVE-2026-48749 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
        [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-2q3f-q5pq-g8wv
        NOTE: https://github.com/canonical/lxd/pull/18590
-CVE-2026-77506 [ZSA-2026-12]
+CVE-2026-77506 (Znuny before LTS 6.5.22 allows AgentTicketEmailResend template 
XSS.)
        - znuny 6.5.22-1
        [trixie] - znuny <no-dsa> (Non-free not supported)
        [bookworm] - znuny <no-dsa> (Non-free not supported)
@@ -77618,22 +78288,22 @@ CVE-2025-14042 (The Automotive Car Dealership 
Business WordPress Theme for WordP
        NOT-FOR-US: WordPress plugin
 CVE-2025-11993 (The WooCommerce Infinite Scroll and Ajax Pagination plugin for 
WordPre ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-48756
+CVE-2026-48756 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6370-1}
        - incus 7.0.0-2
        NOTE: https://github.com/lxc/incus/pull/3425
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-xhqx-mgh3-3h7q
-CVE-2026-48754
+CVE-2026-48754 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        - incus 7.0.0-2
        [trixie] - incus <not-affected> (Vulnerable code not present)
        NOTE: https://github.com/lxc/incus/pull/3425
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-4xg6-52mh-fpw8
-CVE-2026-48753
+CVE-2026-48753 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        - incus 7.0.0-2
        [trixie] - incus <not-affected> (Vulnerable code not present)
        NOTE: https://github.com/lxc/incus/pull/3425
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-ccjc-4qc3-jxqc
-CVE-2026-47753
+CVE-2026-47753 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        - incus 7.0.0-2
        [trixie] - incus <not-affected> (Vulnerable code not present)
        NOTE: https://github.com/lxc/incus/pull/3425
@@ -792467,7 +793137,7 @@ CVE-2018-0500 (Curl_smtp_escape_eob in lib/smtp.c in 
curl 7.54.1 to and includin
        [stretch] - curl <not-affected> (Only affects 7.54.1 to 7.60.0)
        [jessie] - curl <not-affected> (Only affects 7.54.1 to 7.60.0)
        NOTE: https://curl.haxx.se/docs/adv_2018-70a2.html
-CVE-2026-77643 [missing corner-case of CVE-2018-0499]
+CVE-2026-77643 (A cross-site scripting vulnerability in  
queryparser/termgenerator_int ...)
        - xapian-core 1.4.32-1 (bug #1144490)
        [trixie] - xapian-core <no-dsa> (Minor issue)
        NOTE: 
https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dce3666d65e30af868986916156973275c05ce01

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dce3666d65e30af868986916156973275c05ce01
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to