Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e4cb95bf by security tracker role at 2026-08-25T19:14:35+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,517 @@
+CVE-2026-80051 (github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1
does not ...)
+ TODO: check
+CVE-2026-80050 (ContiNew Admin fails to apply file-upload permission checks or
file-ty ...)
+ TODO: check
+CVE-2026-80049 (Airbyte Platform resolves the workspace used for its
authorization dec ...)
+ TODO: check
+CVE-2026-79788 (In Dradis Community Edition, the ProvidersController and
AgentsControl ...)
+ TODO: check
+CVE-2026-79787 (Alluxio's S3 REST proxy fails to verify AWS Signature Version
4 signat ...)
+ TODO: check
+CVE-2026-79786 (Coroot's unauthenticated MCP OAuth dynamic client registration
endpoin ...)
+ TODO: check
+CVE-2026-79785 (X-AnyLabeling's model downloader disabled TLS certificate
verification ...)
+ TODO: check
+CVE-2026-79784 (Vocos instantiates a class named by a configuration file
without restr ...)
+ TODO: check
+CVE-2026-79783 (rclone before 1.74.4 fails to mask special permission bits
when applyi ...)
+ TODO: check
+CVE-2026-79782 (rclone before 1.74.4 fails to strip the X-Amz-Security-Token
header wh ...)
+ TODO: check
+CVE-2026-79781 (rclone serve s3 before 1.74.4 contains a path traversal
vulnerability ...)
+ TODO: check
+CVE-2026-79780 (rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens
and SSE- ...)
+ TODO: check
+CVE-2026-79779 (rclone versions before v1.75.0 fail to reject transport
downgrades in ...)
+ TODO: check
+CVE-2026-79778 (rclone before v1.75.0 contains a denial of service
vulnerability in th ...)
+ TODO: check
+CVE-2026-79777 (rclone before v1.75.0 includes full Go stack traces in RC API
error re ...)
+ TODO: check
+CVE-2026-79776 (rclone before 1.75.0 mounts the pprof debug handler as its own
router ...)
+ TODO: check
+CVE-2026-79775 (rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0)
contain m ...)
+ TODO: check
+CVE-2026-79774 (Winter CMS versions before 1.2.13 contain an incomplete fix
for a Twig ...)
+ TODO: check
+CVE-2026-79773 (Winter CMS before 1.2.13 contains a local file inclusion
vulnerability ...)
+ TODO: check
+CVE-2026-79772 (Nokogiri versions before 1.19.1 fail to check the return value
from xm ...)
+ TODO: check
+CVE-2026-79771 (Nokogiri versions before 1.19.3 contain a memory leak in the
XSLT Styl ...)
+ TODO: check
+CVE-2026-79770 (Nokogiri versions before 1.19.3 contain regular expression
denial of s ...)
+ TODO: check
+CVE-2026-79769 (Nokogiri versions before 1.19.4 contain a possible invalid
(out-of-bou ...)
+ TODO: check
+CVE-2026-79717 (A server-side request forgery (SSRF) vulnerability was found
in galaxy ...)
+ TODO: check
+CVE-2026-79676 (NLTK versions before 3.10.3 contain a path traversal
vulnerability in ...)
+ TODO: check
+CVE-2026-79675 (NLTK before 3.10.3 fails to validate JVM options passed
through the pe ...)
+ TODO: check
+CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass
vulnerabilit ...)
+ TODO: check
+CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the
profile:rea ...)
+ TODO: check
+CVE-2026-79672 (Ech0 before 4.4.3 fails to enforce scope-based authorization
on nine c ...)
+ TODO: check
+CVE-2026-79671 (Ech0 through 4.2.1 contains a server-side request forgery
vulnerabilit ...)
+ TODO: check
+CVE-2026-79670 (Ech0 before 4.4.3 contains a stored cross-site scripting
vulnerability ...)
+ TODO: check
+CVE-2026-79669 (Ech0 before 4.4.3 lacks authorization checks on system log
endpoints a ...)
+ TODO: check
+CVE-2026-79668 (Ech0 before 4.7.3 contains an authentication bypass
vulnerability in t ...)
+ TODO: check
+CVE-2026-79667 (Ech0 version 4.3.4 and earlier fails to reliably enforce
scoped access ...)
+ TODO: check
+CVE-2026-79666 (Ech0 before 4.4.3 fails to enforce administrator authorization
on dash ...)
+ TODO: check
+CVE-2026-79665 (Ech0 before 4.5.1 contains an authorization bypass
vulnerability where ...)
+ TODO: check
+CVE-2026-79664 (Ech0 before 4.7.3 fails to properly revoke access tokens
created with ...)
+ TODO: check
+CVE-2026-79663 (Ech0 before 4.7.3 contains a stored cross-site scripting
vulnerability ...)
+ TODO: check
+CVE-2026-79662 (Ech0 through 4.5.6 contains an OAuth redirect URI validation
vulnerabi ...)
+ TODO: check
+CVE-2026-79661 (Ech0 through 4.5.6 registers the PUT /api/echo/like/:id
endpoint on th ...)
+ TODO: check
+CVE-2026-79660 (Ech0 versions before 4.7.3 expose guest commenter email
addresses thro ...)
+ TODO: check
+CVE-2026-79659 (Ech0 before 4.7.3 contains a server-side request forgery
vulnerability ...)
+ TODO: check
+CVE-2026-79658 (Ech0 before 5.0.1 does not impose any size or shape limit on
the Accep ...)
+ TODO: check
+CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution
vulnerabil ...)
+ TODO: check
+CVE-2026-79655 (A flaw was found in sos clean, a utility within the sos
package. This ...)
+ TODO: check
+CVE-2026-79652 (A flaw was found in the JWT Bearer authorization grant
implementation ...)
+ TODO: check
+CVE-2026-79623 (A security vulnerability has been detected in FishCodeTech
Muteki up t ...)
+ TODO: check
+CVE-2026-79622 (A weakness has been identified in dekdee adobe-xd-mcp 1.0.0.
Impacted ...)
+ TODO: check
+CVE-2026-79406 (A security vulnerability has been detected in macrozheng mall
up to 1. ...)
+ TODO: check
+CVE-2026-78887 (A weakness has been identified in liketrek TREK up to 3.0.22.
This imp ...)
+ TODO: check
+CVE-2026-78886 (A security flaw has been discovered in liketrek TREK up to
3.0.22. Thi ...)
+ TODO: check
+CVE-2026-78885 (A vulnerability was identified in liketrek TREK up to 3.0.22.
The impa ...)
+ TODO: check
+CVE-2026-78864 (A vulnerability was determined in liketrek TREK up to 3.0.22.
The affe ...)
+ TODO: check
+CVE-2026-78863 (A vulnerability was found in liketrek TREK up to 3.0.22.
Impacted is t ...)
+ TODO: check
+CVE-2026-78701 (A flaw was found in 389-ds-base. A remote, authenticated
attacker coul ...)
+ TODO: check
+CVE-2026-78684 (vLLM before 0.27.0 fails to properly classify DeepStream as a
GPU back ...)
+ TODO: check
+CVE-2026-78581 (Authorization Bypass Through User-Controlled Key (CWE-639) in
Kibana c ...)
+ TODO: check
+CVE-2026-78576 (The Readabler plugin for WordPress is vulnerable to SQL
Injection in a ...)
+ TODO: check
+CVE-2026-78572 (The Kalles Addons plugin for WordPress is vulnerable to PHP
Object Inj ...)
+ TODO: check
+CVE-2026-78570 (The Total Donations plugin for WordPress is vulnerable to
Privilege Es ...)
+ TODO: check
+CVE-2026-78568 (The Total Donations plugin for WordPress is vulnerable to SQL
Injectio ...)
+ TODO: check
+CVE-2026-78566 (The Shuffle theme for WordPress is vulnerable to Local File
Inclusion ...)
+ TODO: check
+CVE-2026-78563 (The NotificationX Pro plugin for WordPress is vulnerable to
Stored Cro ...)
+ TODO: check
+CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local
File Incl ...)
+ TODO: check
+CVE-2026-78468 (The FluentCRM Pro \u2013 Email Newsletter, Automation, Email
Marketing ...)
+ TODO: check
+CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the
python_ ...)
+ TODO: check
+CVE-2026-78322 (A flaw was found in file-roller. When opening or extracting a
maliciou ...)
+ TODO: check
+CVE-2026-77998 (Joomla Extension - miniorange.com - Unauthenticated
Authentication Byp ...)
+ TODO: check
+CVE-2026-77997 (Joomla Extension - yootheme.com - Authenticated, privileged
informatio ...)
+ TODO: check
+CVE-2026-77996 (Joomla Extension - yootheme.com - Authenticated, privileged
stored XSS ...)
+ TODO: check
+CVE-2026-77824 (The Media Sweep \u2013 WordPress Media Cleaner plugin for
WordPress is ...)
+ TODO: check
+CVE-2026-77146 (The extension's invitation controller fails to stop processing
after r ...)
+ TODO: check
+CVE-2026-77145 (The permission check for the frontend management update flow
verified ...)
+ TODO: check
+CVE-2026-77144 (The frontend management plugin attributed a newly created
event to the ...)
+ TODO: check
+CVE-2026-77143 (The frontend topic editing flow does not verify on the server
side tha ...)
+ TODO: check
+CVE-2026-77142 (The frontend company self-service editing feature relies on a
template ...)
+ TODO: check
+CVE-2026-77141 (The extension resolves the targeted club record from a
user-supplied r ...)
+ TODO: check
+CVE-2026-77140 (The extension validates the HMAC of a frontend employee edit
link only ...)
+ TODO: check
+CVE-2026-77139 (The extension fails to validate a client-supplied template
element key ...)
+ TODO: check
+CVE-2026-77138 (The extension fails to safely process untrusted client input
of an att ...)
+ TODO: check
+CVE-2026-77137 (The extension fails to properly sanitize user input before
using it in ...)
+ TODO: check
+CVE-2026-77136 (The extension passes the raw value of a form field configured
as "This ...)
+ TODO: check
+CVE-2026-77135 (The extension's user detail view fails to verify that a
requested user ...)
+ TODO: check
+CVE-2026-77134 (The extension fails to require the dedicated admin
confirmation token ...)
+ TODO: check
+CVE-2026-77133 (The extension fails to restrict which frontend usergroups a
logged-in ...)
+ TODO: check
+CVE-2026-77131 (When OpenSSL is unavailable on the server, the extension
transmits TYP ...)
+ TODO: check
+CVE-2026-77130 (The extension fails to properly validate the expiration of a
client-su ...)
+ TODO: check
+CVE-2026-77129 (The extension passes an editor-configurable email subject
string direc ...)
+ TODO: check
+CVE-2026-77128 (The extension fails to enforce enable-field restrictions on a
reposito ...)
+ TODO: check
+CVE-2026-77127 (The extension fails to restrict a backend AJAX endpoint for
inline edi ...)
+ TODO: check
+CVE-2026-76198 (CAI Content Credentials is affected by an Improper Input
Validation vu ...)
+ TODO: check
+CVE-2026-76197 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
+ TODO: check
+CVE-2026-76195 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
+ TODO: check
+CVE-2026-76193 (Adobe Campaign Classic (ACC) is affected by a Server-Side
Request Forg ...)
+ TODO: check
+CVE-2026-76189 (CAI Content Credentials is affected by an Integer Underflow
(Wrap or W ...)
+ TODO: check
+CVE-2026-76128 (The eCommerce Product Catalog plugin for WordPress is
vulnerable to St ...)
+ TODO: check
+CVE-2026-75971 (The ShopEngine Elementor WooCommerce Builder Addon \u2013 All
in One W ...)
+ TODO: check
+CVE-2026-75908 (The Newsletters plugin for WordPress is vulnerable to
authorization by ...)
+ TODO: check
+CVE-2026-75770 (Substance3D - Painter is affected by an out-of-bounds write
vulnerabil ...)
+ TODO: check
+CVE-2026-75769 (Substance3D - Painter is affected by a Heap-based Buffer
Overflow vuln ...)
+ TODO: check
+CVE-2026-75768 (Substance3D - Painter is affected by an Untrusted Search Path
vulnerab ...)
+ TODO: check
+CVE-2026-75767 (Substance3D - Painter is affected by a Heap-based Buffer
Overflow vuln ...)
+ TODO: check
+CVE-2026-75766 (Substance3D - Painter is affected by a Heap-based Buffer
Overflow vuln ...)
+ TODO: check
+CVE-2026-75752 (Substance3D - Painter is affected by an out-of-bounds read
vulnerabili ...)
+ TODO: check
+CVE-2026-75750 (Substance3D - Painter is affected by a Heap-based Buffer
Overflow vuln ...)
+ TODO: check
+CVE-2026-75749 (Substance3D - Painter is affected by an out-of-bounds write
vulnerabil ...)
+ TODO: check
+CVE-2026-75498 (Webkul QloApps does not validate request parameters before a
database ...)
+ TODO: check
+CVE-2026-75497 (Webkul QloApps does not validate request parameters before a
database ...)
+ TODO: check
+CVE-2026-75496 (Webkul QloApps does not perform proper validation on uploaded
file ext ...)
+ TODO: check
+CVE-2026-75038 (UNIX symbolic link (symlink) following vulnerability in
ilya-zlobintse ...)
+ TODO: check
+CVE-2026-75037 (Polkit Authentication Based on UnixProcessSubject / Peer PID
in LACT o ...)
+ TODO: check
+CVE-2026-71564 (Substance3D - Designer is affected by an out-of-bounds write
vulnerabi ...)
+ TODO: check
+CVE-2026-71444 (CAI Content Credentials is affected by an Integer Underflow
(Wrap or W ...)
+ TODO: check
+CVE-2026-71443 (CAI Content Credentials is affected by an Improper Input
Validation vu ...)
+ TODO: check
+CVE-2026-71442 (CAI Content Credentials is affected by an Integer Underflow
(Wrap or W ...)
+ TODO: check
+CVE-2026-71441 (Illustrator is affected by an out-of-bounds read vulnerability
that co ...)
+ TODO: check
+CVE-2026-71399 (Adobe XD is affected by a Buffer Overflow vulnerability that
could res ...)
+ TODO: check
+CVE-2026-71382 (Substance3D - Sampler is affected by an out-of-bounds write
vulnerabil ...)
+ TODO: check
+CVE-2026-71360 (CAI Content Credentials is affected by an Uncontrolled
Resource Consum ...)
+ TODO: check
+CVE-2026-70551 (A user who can read an existing remote VCS repository can
replace its ...)
+ TODO: check
+CVE-2026-70550 (An authorization weakness in JFrog Artifactory Composer
repository han ...)
+ TODO: check
+CVE-2026-70548 (Under specific circumstances, low-level user can run request
to remote ...)
+ TODO: check
+CVE-2026-69104 (An authenticated user may initiate repository migration
operations wit ...)
+ TODO: check
+CVE-2026-67578 (FA-50 all versions miss authentication for some configuration.
An atta ...)
+ TODO: check
+CVE-2026-66882 (Improper Neutralization of Input During Web Page Generation
(XSS) vuln ...)
+ TODO: check
+CVE-2026-65979 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-65633 (Improper Authentication vulnerability in team-alembic
AshAuthenticatio ...)
+ TODO: check
+CVE-2026-64204 (There is a memory corruption vulnerability recently discovered
in NI L ...)
+ TODO: check
+CVE-2026-64203 (There is a memory corruption vulnerability recently discovered
in NI L ...)
+ TODO: check
+CVE-2026-64202 (There is a memory corruption vulnerability recently discovered
in NI L ...)
+ TODO: check
+CVE-2026-64201 (There is a memory corruption vulnerability recently discovered
in NI L ...)
+ TODO: check
+CVE-2026-63587 (The SMS control function of IE-SR-2TX-WL-4G devices can
require a pass ...)
+ TODO: check
+CVE-2026-63586 (The web-based management interface uses a modified uhttpd
server with ...)
+ TODO: check
+CVE-2026-62986 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-61555 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-59985 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-59984 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-59983 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-59982 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-59769 (FA-50 all versions contain hard-coded credentials. An
attacker, who kn ...)
+ TODO: check
+CVE-2026-59335 (Improper handling of case sensitivity (CWE-178) in the
identity zone a ...)
+ TODO: check
+CVE-2026-59189 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-59187 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-59186 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-59184 (OpenEXR is the reference implementation and specification for
the EXR ...)
+ TODO: check
+CVE-2026-57910 (Improper authentication in the WatchGuard Agent allows an
unauthentica ...)
+ TODO: check
+CVE-2026-57909 (A path traversal vulnerability in WatchGuard Agent allows a
remote, un ...)
+ TODO: check
+CVE-2026-57863 (Crater Invoice through 6.0.6 contains a path traversal
vulnerability i ...)
+ TODO: check
+CVE-2026-56096 (The extension passes the user-supplied search query parameter
to Apach ...)
+ TODO: check
+CVE-2026-56095 (The extension's indexer passed every field value returned by
content o ...)
+ TODO: check
+CVE-2026-56094 (The extension allows a request-provided additionalFilters
parameter to ...)
+ TODO: check
+CVE-2026-56093 (The extension's frontend detail-view document lookup does not
apply th ...)
+ TODO: check
+CVE-2026-56092 (The extension forces empty frontend-group and
subpage-inheritance rest ...)
+ TODO: check
+CVE-2026-55976 (Server-Side Request Forgery (SSRF) in Avro SerDe schema
resolution in ...)
+ TODO: check
+CVE-2026-55663 (mediasoup is a WebRTC video conferencing system. From version
3.20.0 u ...)
+ TODO: check
+CVE-2026-55640 (Nextcloud MCP Server is a production-ready MCP server that
connects AI ...)
+ TODO: check
+CVE-2026-55637 (genieacs-mcp is an MCP server for GenieACS written in Go.
Prior to 0.3 ...)
+ TODO: check
+CVE-2026-55624 (MintyItanium Lost-Auction is an auction plugin for Minecraft.
Prior to ...)
+ TODO: check
+CVE-2026-55623
+ REJECTED
+CVE-2026-55620 (eml_parser serves as a python module for parsing eml files and
returni ...)
+ TODO: check
+CVE-2026-55619 (eml_parser serves as a python module for parsing eml files and
returni ...)
+ TODO: check
+CVE-2026-55618 (eml_parser serves as a python module for parsing eml files and
returni ...)
+ TODO: check
+CVE-2026-55609 (sublinear-time-solver is a Rust and WebAssembly library for
solving as ...)
+ TODO: check
+CVE-2026-55585 (QWED is open-source AI verification infrastructure for
deterministic v ...)
+ TODO: check
+CVE-2026-55582 (mcp-shell is an MCP server for running shell commands
securely, audita ...)
+ TODO: check
+CVE-2026-55581 (mcp-shell is an MCP server for running shell commands
securely, audita ...)
+ TODO: check
+CVE-2026-55580 (mcp-shell is an MCP server for running shell commands
securely, audita ...)
+ TODO: check
+CVE-2026-55571 (djust provides Phoenix LiveView-style reactive server-side
rendering f ...)
+ TODO: check
+CVE-2026-55557 (browse-mcp is a Playwright-based headless-browser MCP server
for MCP-c ...)
+ TODO: check
+CVE-2026-55553 (urllib is an HTTP client for Node.js that supports
authentication, red ...)
+ TODO: check
+CVE-2026-55546 (QWED-MCP is a deterministic verification gateway for MCP.
Prior to 0.2 ...)
+ TODO: check
+CVE-2026-55541 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, pr ...)
+ TODO: check
+CVE-2026-55540 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.51, is ...)
+ TODO: check
+CVE-2026-55539 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.51, th ...)
+ TODO: check
+CVE-2026-55538 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.51, pr ...)
+ TODO: check
+CVE-2026-55537 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, Jo ...)
+ TODO: check
+CVE-2026-55536 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, Br ...)
+ TODO: check
+CVE-2026-55535 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, th ...)
+ TODO: check
+CVE-2026-55534 (PraisonAI is a multi-agent teams system. From praisonai 4.6.34
until 4 ...)
+ TODO: check
+CVE-2026-55533 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, cr ...)
+ TODO: check
+CVE-2026-55532 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, MC ...)
+ TODO: check
+CVE-2026-55531 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, th ...)
+ TODO: check
+CVE-2026-55530 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-55529 (PraisonAI is a multi-agent teams system. Prior to praisonai
4.6.58, th ...)
+ TODO: check
+CVE-2026-55528 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-55527 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-55526 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-55525 (PraisonAI is a multi-agent teams system. Prior to
praisonaiagents 1.6. ...)
+ TODO: check
+CVE-2026-55419 (Reachy Mini is an SDK for controlling Reachy Mini robots.
Prior to 1.8 ...)
+ TODO: check
+CVE-2026-53561 (An improper authentication vulnerability in HiveServer2 SAML
bearer-to ...)
+ TODO: check
+CVE-2026-49845 (SQL injection in Hive Metastore direct SQL partition-name
resolution i ...)
+ TODO: check
+CVE-2026-48433 (Substance3D - Designer is affected by a Heap-based Buffer
Overflow vul ...)
+ TODO: check
+CVE-2026-48432 (Substance3D - Designer is affected by a Heap-based Buffer
Overflow vul ...)
+ TODO: check
+CVE-2026-48431 (Substance3D - Designer is affected by a Heap-based Buffer
Overflow vul ...)
+ TODO: check
+CVE-2026-48430 (Substance3D - Designer is affected by a Heap-based Buffer
Overflow vul ...)
+ TODO: check
+CVE-2026-48429 (Substance3D - Designer is affected by a NULL Pointer
Dereference vulne ...)
+ TODO: check
+CVE-2026-48428 (Substance3D - Designer is affected by a Heap-based Buffer
Overflow vul ...)
+ TODO: check
+CVE-2026-48427 (Substance3D - Designer is affected by an out-of-bounds write
vulnerabi ...)
+ TODO: check
+CVE-2026-48426 (Substance3D - Designer is affected by an out-of-bounds write
vulnerabi ...)
+ TODO: check
+CVE-2026-48425 (Substance3D - Sampler is affected by a Heap-based Buffer
Overflow vuln ...)
+ TODO: check
+CVE-2026-48424 (Substance3D - Sampler is affected by a Heap-based Buffer
Overflow vuln ...)
+ TODO: check
+CVE-2026-48423 (Substance3D - Sampler is affected by a Heap-based Buffer
Overflow vuln ...)
+ TODO: check
+CVE-2026-48422 (Substance3D - Sampler is affected by a Heap-based Buffer
Overflow vuln ...)
+ TODO: check
+CVE-2026-48421 (Substance3D - Sampler is affected by an out-of-bounds write
vulnerabil ...)
+ TODO: check
+CVE-2026-48420 (Substance3D - Sampler is affected by an out-of-bounds write
vulnerabil ...)
+ TODO: check
+CVE-2026-48419 (Substance3D - Sampler is affected by an out-of-bounds write
vulnerabil ...)
+ TODO: check
+CVE-2026-48418 (Substance3D - Sampler is affected by an out-of-bounds write
vulnerabil ...)
+ TODO: check
+CVE-2026-48417 (Substance3D - Sampler is affected by a Stack-based Buffer
Overflow vul ...)
+ TODO: check
+CVE-2026-47626 (NVIDIA DGX Spark contains a vulnerability in the system
firmware, wher ...)
+ TODO: check
+CVE-2026-47624 (NVIDIA DGX Spark contains a vulnerability in UEFI where a
Attacker may ...)
+ TODO: check
+CVE-2026-26211 (Ekushey Project Manager CRM stores the
administrator-configured system ...)
+ TODO: check
+CVE-2026-24263 (NVIDIA DGX Spark contains a vulnerability in the system
firmware, wher ...)
+ TODO: check
+CVE-2026-24262 (NVIDIA DGX Spark contains a vulnerability in the system
firmware, wher ...)
+ TODO: check
+CVE-2026-24225 (NVIDIA DGX Spark contains a vulnerability in the standalone MM
firmwar ...)
+ TODO: check
+CVE-2026-24170 (NVIDIA UFM Enterprise contains a vulnerability in the web
interface au ...)
+ TODO: check
+CVE-2026-24169 (NVIDIA UFM Enterprise contains a vulnerability in the plugin
managemen ...)
+ TODO: check
+CVE-2026-24168 (NVIDIA UFM Enterprise contains a vulnerability in the
IBDiagnet API wh ...)
+ TODO: check
+CVE-2026-24167 (NVIDIA UFM Enterprise contains a vulnerability in the user
management ...)
+ TODO: check
+CVE-2026-24166 (NVIDIA UFM Enterprise contains a vulnerability in the session
manageme ...)
+ TODO: check
+CVE-2026-21758 (HCL Hive is affected by an information disclosure
vulnerability, which ...)
+ TODO: check
+CVE-2026-21754 (HCL Hive is affected by multiple infrastructure and network
configurat ...)
+ TODO: check
+CVE-2026-21753 (HCL Hive is affected by weak software supply chain governance,
which c ...)
+ TODO: check
+CVE-2026-19949 (The All-in-One WP Migration and Backup plugin for WordPress is
vulnera ...)
+ TODO: check
+CVE-2026-19913 (The Kaltura HTML5 player (mwEmbed / html5lib) contains a local
file di ...)
+ TODO: check
+CVE-2026-19912 (The Kaltura HTML5 player (mwEmbed / html5lib) contains an
unauthentica ...)
+ TODO: check
+CVE-2026-19851 (A Use of Default Password vulnerability affecting Tuleap
Enterprise Ed ...)
+ TODO: check
+CVE-2026-18547 (The Ultimate Member \u2013 User Profile, Registration, Login,
Member D ...)
+ TODO: check
+CVE-2026-18512 (The TranslatePress \u2013 Translate Multilingual sites with AI
Transla ...)
+ TODO: check
+CVE-2026-18445 (There is an integer overflow vulnerability resulting in an
out-of-boun ...)
+ TODO: check
+CVE-2026-18444 (There is an integer conversion vulnerability resulting in an
out-of-bo ...)
+ TODO: check
+CVE-2026-18328 (The Forminator Forms \u2013 Contact Form, Payment Form &
Custom Form B ...)
+ TODO: check
+CVE-2026-18323 (The Forminator Forms \u2013 Contact Form, Payment Form &
Custom Form B ...)
+ TODO: check
+CVE-2026-18100 (The MetForm \u2013 Contact Form, Survey, Quiz, & Custom Form
Builder f ...)
+ TODO: check
+CVE-2026-17587 (The My Agile Privacy\xae \u2013 CMP, Cookie Consent & Privacy
Tools pl ...)
+ TODO: check
+CVE-2026-17548 (Missing authorization in Checkmk <2.5.0p12, <2.4.0p36,
<2.3.0p50 and a ...)
+ TODO: check
+CVE-2026-16601 (The CM Map Locations \u2013 Visualize and share your locations
in a fe ...)
+ TODO: check
+CVE-2026-16599 (GNU wget is vulnerable to denial of service in its FTP
OPIE/S-KEY auth ...)
+ TODO: check
+CVE-2026-16286 (Unrestricted upload of file with dangerous type vulnerability
in TRtek ...)
+ TODO: check
+CVE-2026-16234 (There is a memory corruption vulnerability recently discovered
in NI L ...)
+ TODO: check
+CVE-2026-16233 (There is a memory corruption vulnerability recently discovered
in NI L ...)
+ TODO: check
+CVE-2026-16231 (hbs is an Express view engine that wraps Handlebars. Its
registerAsync ...)
+ TODO: check
+CVE-2026-15310 (When decompressing crafted zip files using the
bzip/LZMA/Zstandard c ...)
+ TODO: check
+CVE-2026-13478 (The Zephyr ext2 filesystem driver validates the on-disk block
bitmap i ...)
+ TODO: check
+CVE-2026-13217 (The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs
a sessi ...)
+ TODO: check
+CVE-2026-13216 (The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a
device's ...)
+ TODO: check
+CVE-2026-12878 (In affected versions of the Codefresh platform an
authenticated user c ...)
+ TODO: check
+CVE-2026-12600 (Denial-of-service (DoS) vulnerability in the internal JPEG2000
(JPX) d ...)
+ TODO: check
+CVE-2025-71407 (Nokogiri before 1.18.3 contains a stack buffer overflow
vulnerability ...)
+ TODO: check
+CVE-2025-71406 (Nokogiri before 1.18.4 bundles a vulnerable version of libxslt
(prior ...)
+ TODO: check
+CVE-2025-71346 (Nokogiri before 1.18.8 packages a vulnerable version of
libxml2 (befor ...)
+ TODO: check
+CVE-2024-58378 (Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when
using the ...)
+ TODO: check
+CVE-2024-58377 (Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which
is affect ...)
+ TODO: check
+CVE-2023-54354 (Nokogiri before 1.14.3 (CRuby implementation only, when using
the pack ...)
+ TODO: check
+CVE-2022-51000 (Nokogiri before 1.13.2 (CRuby, when using packaged libraries)
ships ve ...)
+ TODO: check
+CVE-2022-50999 (Nokogiri versions before 1.13.5 contain an integer overflow
vulnerabil ...)
+ TODO: check
+CVE-2022-50998 (Nokogiri before 1.13.9 (CRuby implementation using packaged
libraries) ...)
+ TODO: check
+CVE-2021-47996 (Nokogiri before 1.11.4 (CRuby implementation only, when the
packaged/v ...)
+ TODO: check
CVE-2026-63676
- libyaml-perl 1.321-1
NOTE: Fixed by:
https://github.com/ingydotnet/yaml-pm/commit/9388c6a02a66db79f9d2b3727b5588272f612cf1
(v1.320.0)
@@ -11,7 +525,8 @@ CVE-2026-XXXX [GHSA-75g3-96fr-7p2r: SABnzbd PAR2 path
traversal enabling cross-j
NOTE:
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-75g3-96fr-7p2r
NOTE: Fixed by:
https://github.com/sabnzbd/sabnzbd/commit/6ddabb5a4599731b00f44162e62f31e291d2b2d0
(5.1.2)
NOTE: Fixed by:
https://github.com/sabnzbd/sabnzbd/commit/c57af32131216de3e1df3097a0cce06c8c99ceb8
(5.1.2)
-CVE-2026-18798
+CVE-2026-18798 (Issue summary: QUIC server may double free QRX (QUIC record
layer RX) ...)
+ {DSA-6465-1}
- openssl <unfixed>
[bookworm] - openssl <not-affected> (Vulnerable code not present)
[bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -19,21 +534,24 @@ CVE-2026-18798
NOTE:
https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af
(openssl-3.6.4)
NOTE:
https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c
(oepnssl-3.5.8)
NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63072
+CVE-2026-63072 (Issue summary: OpenSSL CMS decryption sizes the key-unwrap
output buff ...)
+ {DSA-6465-1}
- openssl <unfixed>
NOTE:
https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335
(openssl-4.0.2)
NOTE:
https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756
(openssl-3.6.4)
NOTE:
https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42
(openssl-3.5.8)
NOTE:
https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382
(openssl-3.0.22)
NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63076
+CVE-2026-63076 (Issue summary: OpenSSL CMP password based protection
verification only ...)
+ {DSA-6465-1}
- openssl <unfixed>
NOTE:
https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e
(openssl-4.0.2)
NOTE:
https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226
(openssl-3.6.4)
NOTE:
https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c
(openssl-3.5.8)
NOTE:
https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b
(openssl-3.0.22)
NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-14457
+CVE-2026-14457 (Issue summary: In a server or client configuration with
RFC7250 Raw Pu ...)
+ {DSA-6465-1}
- openssl <unfixed>
[bookworm] - openssl <not-affected> (Vulnerable code not present)
[bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -41,14 +559,16 @@ CVE-2026-14457
NOTE:
https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1
(openssl-3.6.4)
NOTE:
https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f
(openssl-3.5.8)
NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-54874
+CVE-2026-54874 (Issue summary: Receiving a DTLS record for a future epoch
while a hand ...)
+ {DSA-6465-1}
- openssl <unfixed>
NOTE:
https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107
(openssl-4.0.2)
NOTE:
https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c
(openssl-3.6.4)
NOTE:
https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23
(openssl-3.5.8)
NOTE:
https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382
(openssl-3.0.22)
NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63073
+CVE-2026-63073 (Issue summary: OpenSSL CMP response validation passed an
unexpected re ...)
+ {DSA-6465-1}
- openssl <unfixed>
[bookworm] - openssl <not-affected> (Vulnerable code not present)
[bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -56,14 +576,16 @@ CVE-2026-63073
NOTE:
https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29
(openssl-3.6.4)
NOTE:
https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca
(openssl-3.5.8)
NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63074
+CVE-2026-63074 (Issue summary: The OpenSSL Certificate Management Protocol
(CMP) cache ...)
+ {DSA-6465-1}
- openssl <unfixed>
NOTE:
https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46
(openssl-4.0.2)
NOTE:
https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7
(openssl-3.6.4)
NOTE:
https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af
(openssl-3.5.8)
NOTE:
https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f
(openssl-3.0.22)
NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63075
+CVE-2026-63075 (Issue summary: When OpenSSL processes QUIC traffic from a peer
that re ...)
+ {DSA-6465-1}
- openssl <unfixed>
[bookworm] - openssl <not-affected> (Vulnerable code not present)
[bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -565,7 +1087,8 @@ CVE-2026-78157 (A vulnerability was detected in Open5GS
2.8.0. This affects the
- open5gs <itp> (bug #1094791)
CVE-2026-78156 (A security vulnerability has been detected in Open5GS 2.8.0.
Affected ...)
- open5gs <itp> (bug #1094791)
-CVE-2026-78154 (A vulnerability was identified in the-momentum open-wearables
up to 0. ...)
+CVE-2026-78154
+ REJECTED
NOT-FOR-US: the-momentum open-wearables
CVE-2026-78148 (A vulnerability was determined in ggml-org llama.cpp
bec4772f6. This a ...)
- llama.cpp <unfixed>
@@ -592,9 +1115,9 @@ CVE-2026-77994 (Joomla Extension - joomlack.fr - Second
order SQL injection in P
NOT-FOR-US: Joomla
CVE-2026-77993 (Joomla Extension - joomlack.fr - Reflected XSS in Page Builder
CK < 3. ...)
NOT-FOR-US: Joomla
-CVE-2026-77915 (rConfig 8.0.0 before 8.2.13 contains an authentication bypass
vulnerab ...)
+CVE-2026-77915 (rConfig Core 8.0.0 before 8.2.13 contains an authentication
bypass vul ...)
NOT-FOR-US: rConfig
-CVE-2026-77914 (rConfig before 8.2.13 contains a path traversal vulnerability
that all ...)
+CVE-2026-77914 (rConfig Core 8.0.0 before 8.2.13 contains a path traversal
vulnerabili ...)
NOT-FOR-US: rConfig
CVE-2026-76848 (TypeORM's SelectQueryBuilder.distinctOn accepts an array of
strings an ...)
NOT-FOR-US: TypeORM
@@ -3527,7 +4050,8 @@ CVE-2026-XXXX [OSSN-0103]
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0103
NOTE: https://review.opendev.org/c/openstack/manila/+/998388
NOTE: https://bugs.launchpad.net/manila/+bug/2161287
-CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs]
+CVE-2026-75803 (Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with
an empty ...)
+ {DSA-6465-1}
- openssl <unfixed> (bug #1145172)
NOTE:
https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a
(openssl-4.0.2)
NOTE:
https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b
(openssl-3.6.4)
@@ -4276,7 +4800,7 @@ CVE-2025-14602 (The application generates uploaded file
names using a weak and p
NOT-FOR-US: vsDesk
CVE-2022-4996 (A flaw has been found in mruby 3.1.0. Affected is the function
udiv of ...)
TODO: check
-CVE-2026-79992 [Emacs zero-click local command execution via TRAMP]
+CVE-2026-79992 (A flaw was found in Emacs TRAMP. A local attacker could
exploit this v ...)
- emacs <unfixed> (bug #1145049)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/21/1
NOTE: Fixed by:
https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=f3e7104d05bdb8e32ba13bf75604108ad88536dc
@@ -7358,7 +7882,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient
validation of packet len
NOTE: Fixed by:
https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
NOTE: Followup:
https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
CVE-2026-74990 (Internally found bugs present in Firefox ESR 115.38, Firefox
ESR 140.1 ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7372,7 +7896,7 @@ CVE-2026-74988 (Internally found bugs present in Firefox
ESR 153.0 and Firefox 1
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
CVE-2026-74987 (Internally found bugs present in Firefox ESR 140.13, Firefox
ESR 153.0 ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7389,7 +7913,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine
component. This vulnerab
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This
vulnerab ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7415,7 +7939,7 @@ CVE-2026-74977 (Integer overflow in the Graphics
component. This vulnerability w
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component.
This vulne ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7426,7 +7950,7 @@ CVE-2026-74975 (Spoofing issue in the Downloads component
in Firefox for Android
- firefox <not-affected> (Only affects Firefox on Android)
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component.
This vu ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7434,7 +7958,7 @@ CVE-2026-74974 (Same-origin policy bypass in the
Graphics: ImageLib component. T
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This
vulnera ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7442,7 +7966,7 @@ CVE-2026-74973 (Race condition, use-after-free in the
Graphics component. This v
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions
component. This ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7450,7 +7974,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push
Subscriptions component.
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling
componen ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7461,7 +7985,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics
component. This vulnerabili
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This
vulnerabi ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7472,7 +7996,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics:
WebRender component. This
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback
component. This ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7483,7 +8007,7 @@ CVE-2026-74966 (Information disclosure in the Form
Autofill component. This vuln
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
CVE-2026-74965 (Privilege escalation in the Shell Integration component. This
vulnerab ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7491,7 +8015,7 @@ CVE-2026-74965 (Privilege escalation in the Shell
Integration component. This vu
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability
was fix ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7499,7 +8023,7 @@ CVE-2026-74964 (Integer overflow in the Graphics
component. This vulnerability w
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies
component. This v ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7507,7 +8031,7 @@ CVE-2026-74963 (Same-origin policy bypass in the
Networking: Cookies component.
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
CVE-2026-74962 (Site isolation issue in the Networking: Cookies component.
This vulner ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7518,7 +8042,7 @@ CVE-2026-74961 (Side-channel in the Web Audio component.
This vulnerability was
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
CVE-2026-74960 (Site isolation issue in the WebExtensions component. This
vulnerabilit ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7526,7 +8050,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions
component. This vulner
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This
vulnerabil ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7537,7 +8061,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC
component. This vulnerabili
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This
vulnerability w ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7554,7 +8078,7 @@ CVE-2026-74954 (Information disclosure due to
side-channel in the Storage: Cache
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
CVE-2026-74953 (Privilege escalation in the Networking: Cookies component.
This vulner ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7571,7 +8095,7 @@ CVE-2026-74950 (Privilege escalation in the Downloads API
component. This vulner
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
CVE-2026-74949 (Use-after-free in the Graphics: Canvas2D component. This
vulnerability ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7579,7 +8103,7 @@ CVE-2026-74949 (Use-after-free in the Graphics: Canvas2D
component. This vulnera
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
CVE-2026-74948 (Information disclosure in the Graphics component. This
vulnerability w ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7590,7 +8114,7 @@ CVE-2026-74947 (Privilege escalation due to invalid
pointer in the Graphics comp
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in
the Graph ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7598,7 +8122,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect
boundary conditions in the
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
CVE-2026-74945 (Information disclosure in the Graphics: Text component. This
vulnerabi ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7606,7 +8130,7 @@ CVE-2026-74945 (Information disclosure in the Graphics:
Text component. This vul
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This
vulnerability w ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7614,7 +8138,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML
component. This vulnerabi
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This
vulnerability ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7622,7 +8146,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib
component. This vulnera
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
CVE-2026-74942 (Privilege escalation in the Remote Settings Client component.
This vul ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7630,7 +8154,7 @@ CVE-2026-74942 (Privilege escalation in the Remote
Settings Client component. Th
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component.
This vuln ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7638,7 +8162,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics:
CanvasWebGL component. Thi
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
CVE-2026-74940 (Use-after-free in the Graphics: Text component. This
vulnerability was ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7646,7 +8170,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text
component. This vulnerabili
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This
vulnerabil ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7660,7 +8184,7 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC
component. This vulnerabili
- firefox 154.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This
vulnerab ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7668,7 +8192,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript:
WebAssembly component. This vu
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This
vulnerabil ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7676,7 +8200,7 @@ CVE-2026-74935 (Privilege escalation in the DOM:
Networking component. This vuln
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component.
This vuln ...)
- {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+ {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -7830,7 +8354,8 @@ CVE-2026-73336 (Joomla! Core - [20260806] - XSS through
schema.org outputs in Jo
NOT-FOR-US: Joomla
CVE-2026-73190 (Unauthenticated Cross Site Scripting (XSS) in WPDM \u2013
Premium Pack ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-73189 (Subscriber Insecure Direct Object References (IDOR) in WP
Crowdfunding ...)
+CVE-2026-73189
+ REJECTED
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73187 (Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2
versions.)
NOT-FOR-US: WordPress plugin or theme
@@ -7965,7 +8490,7 @@ CVE-2026-66627 (Contributor Arbitrary File Upload in GP
Premium <= 2.5.5 version
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66622 (Unauthenticated SQL Injection in Depicter Slider <= 4.8.0
versions.)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate
Dashboard <= 3. ...)
+CVE-2026-66621 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
NOT-FOR-US: WordPress plugin or theme
@@ -15778,6 +16303,7 @@ CVE-2026-15994 (During an internal security assessment,
an improper link followi
CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed
as a "hom ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL
object) proce ...)
+ {DSA-6465-1}
- openssl <unfixed> (bug #1144615)
NOTE: https://openssl-library.org/news/secadv/20260813.txt
NOTE:
https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139
(openssl-4.0.2)
@@ -79189,6 +79715,7 @@ CVE-2026-9334 (Cpanel::JSON::XS versions before 4.41
for Perl allow type confusi
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40653179/
NOTE: Fixed by:
https://github.com/rurban/Cpanel-JSON-XS/commit/11a7c550a0d8fac2f84414f24d5df9b2bfe346e2
(4.41)
CVE-2026-50538 (LibVNCClient is a library for easy implementation of a VNC
client. In ...)
+ {DLA-4755-1}
- libvncserver 0.9.15+dfsg-6 (bug #1138253)
[trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
@@ -82114,7 +82641,7 @@ CVE-2026-49052 (Missing Authorization vulnerability in
Wpmet ElementsKit Element
NOT-FOR-US: WordPress plugin or theme
CVE-2026-49051 (Missing Authorization vulnerability in Prasad Kirpekar WP Meta
and Dat ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-49050
+CVE-2026-49050 (General user can mint admin access tokens via /access-tokens
This i ...)
NOT-FOR-US: Apache DolphinScheduler
CVE-2026-49047 (Missing Authorization vulnerability in DearHive DearFlip
allows Exploi ...)
NOT-FOR-US: WordPress plugin or theme
@@ -82259,6 +82786,7 @@ CVE-2026-45022 (go-git is an extensible git
implementation library written in pu
[bookworm] - golang-github-go-git-go-git <postponed> (Limited support,
minor issue; signature-verification bypass)
NOTE:
https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp
CVE-2026-44988 (LibVNCClient is a library for easy implementation of a VNC
client. In ...)
+ {DLA-4755-1}
- libvncserver 0.9.15+dfsg-5 (bug #1138174)
[trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
@@ -122348,12 +122876,14 @@ CVE-2026-33157 (Craft CMS is a content management
system (CMS). From version 5.6
CVE-2026-32948 (sbt is a build tool for Scala, Java, and others. From version
0.9.5 to ...)
NOT-FOR-US: sbt
CVE-2026-32854 (LibVNCServer versions 0.9.15 and prior (fixed incommit
dc78dee) contai ...)
+ {DLA-4755-1}
- libvncserver 0.9.15+dfsg-3 (bug #1132017)
[trixie] - libvncserver 0.9.15+dfsg-1+deb13u1
[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u1
NOTE:
https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x
NOTE: Fixed by:
https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314
CVE-2026-32853 (LibVNCServer versions 0.9.15 and prior (fixed incommit
009008e) contai ...)
+ {DLA-4755-1}
- libvncserver 0.9.15+dfsg-3 (bug #1132016)
[trixie] - libvncserver 0.9.15+dfsg-1+deb13u1
[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u1
@@ -410267,7 +410797,8 @@ CVE-2023-34960 (A command injection vulnerability in
the wsConvertPpt component
NOT-FOR-US: Chamilo CMS
CVE-2023-4026
REJECTED
-CVE-2023-4010 (A flaw was found in the USB Host Controller Driver framework in
the Li ...)
+CVE-2023-4010
+ REJECTED
- linux <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2227726
NOTE: https://github.com/wanrenmi/a-usb-kernel-bug
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4cb95bf496ed793f0ce5994609d9628b4286d86
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4cb95bf496ed793f0ce5994609d9628b4286d86
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits