Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e4cb95bf by security tracker role at 2026-08-25T19:14:35+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,517 @@
+CVE-2026-80051 (github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 
does not  ...)
+       TODO: check
+CVE-2026-80050 (ContiNew Admin fails to apply file-upload permission checks or 
file-ty ...)
+       TODO: check
+CVE-2026-80049 (Airbyte Platform resolves the workspace used for its 
authorization dec ...)
+       TODO: check
+CVE-2026-79788 (In Dradis Community Edition, the ProvidersController and 
AgentsControl ...)
+       TODO: check
+CVE-2026-79787 (Alluxio's S3 REST proxy fails to verify AWS Signature Version 
4 signat ...)
+       TODO: check
+CVE-2026-79786 (Coroot's unauthenticated MCP OAuth dynamic client registration 
endpoin ...)
+       TODO: check
+CVE-2026-79785 (X-AnyLabeling's model downloader disabled TLS certificate 
verification ...)
+       TODO: check
+CVE-2026-79784 (Vocos instantiates a class named by a configuration file 
without restr ...)
+       TODO: check
+CVE-2026-79783 (rclone before 1.74.4 fails to mask special permission bits 
when applyi ...)
+       TODO: check
+CVE-2026-79782 (rclone before 1.74.4 fails to strip the X-Amz-Security-Token 
header wh ...)
+       TODO: check
+CVE-2026-79781 (rclone serve s3 before 1.74.4 contains a path traversal 
vulnerability  ...)
+       TODO: check
+CVE-2026-79780 (rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens 
and SSE- ...)
+       TODO: check
+CVE-2026-79779 (rclone versions before v1.75.0 fail to reject transport 
downgrades in  ...)
+       TODO: check
+CVE-2026-79778 (rclone before v1.75.0 contains a denial of service 
vulnerability in th ...)
+       TODO: check
+CVE-2026-79777 (rclone before v1.75.0 includes full Go stack traces in RC API 
error re ...)
+       TODO: check
+CVE-2026-79776 (rclone before 1.75.0 mounts the pprof debug handler as its own 
router  ...)
+       TODO: check
+CVE-2026-79775 (rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) 
contain m ...)
+       TODO: check
+CVE-2026-79774 (Winter CMS versions before 1.2.13 contain an incomplete fix 
for a Twig ...)
+       TODO: check
+CVE-2026-79773 (Winter CMS before 1.2.13 contains a local file inclusion 
vulnerability ...)
+       TODO: check
+CVE-2026-79772 (Nokogiri versions before 1.19.1 fail to check the return value 
from xm ...)
+       TODO: check
+CVE-2026-79771 (Nokogiri versions before 1.19.3 contain a memory leak in the 
XSLT Styl ...)
+       TODO: check
+CVE-2026-79770 (Nokogiri versions before 1.19.3 contain regular expression 
denial of s ...)
+       TODO: check
+CVE-2026-79769 (Nokogiri versions before 1.19.4 contain a possible invalid 
(out-of-bou ...)
+       TODO: check
+CVE-2026-79717 (A server-side request forgery (SSRF) vulnerability was found 
in galaxy ...)
+       TODO: check
+CVE-2026-79676 (NLTK versions before 3.10.3 contain a path traversal 
vulnerability in  ...)
+       TODO: check
+CVE-2026-79675 (NLTK before 3.10.3 fails to validate JVM options passed 
through the pe ...)
+       TODO: check
+CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass 
vulnerabilit ...)
+       TODO: check
+CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the 
profile:rea ...)
+       TODO: check
+CVE-2026-79672 (Ech0 before 4.4.3 fails to enforce scope-based authorization 
on nine c ...)
+       TODO: check
+CVE-2026-79671 (Ech0 through 4.2.1 contains a server-side request forgery 
vulnerabilit ...)
+       TODO: check
+CVE-2026-79670 (Ech0 before 4.4.3 contains a stored cross-site scripting 
vulnerability ...)
+       TODO: check
+CVE-2026-79669 (Ech0 before 4.4.3 lacks authorization checks on system log 
endpoints a ...)
+       TODO: check
+CVE-2026-79668 (Ech0 before 4.7.3 contains an authentication bypass 
vulnerability in t ...)
+       TODO: check
+CVE-2026-79667 (Ech0 version 4.3.4 and earlier fails to reliably enforce 
scoped access ...)
+       TODO: check
+CVE-2026-79666 (Ech0 before 4.4.3 fails to enforce administrator authorization 
on dash ...)
+       TODO: check
+CVE-2026-79665 (Ech0 before 4.5.1 contains an authorization bypass 
vulnerability where ...)
+       TODO: check
+CVE-2026-79664 (Ech0 before 4.7.3 fails to properly revoke access tokens 
created with  ...)
+       TODO: check
+CVE-2026-79663 (Ech0 before 4.7.3 contains a stored cross-site scripting 
vulnerability ...)
+       TODO: check
+CVE-2026-79662 (Ech0 through 4.5.6 contains an OAuth redirect URI validation 
vulnerabi ...)
+       TODO: check
+CVE-2026-79661 (Ech0 through 4.5.6 registers the PUT /api/echo/like/:id 
endpoint on th ...)
+       TODO: check
+CVE-2026-79660 (Ech0 versions before 4.7.3 expose guest commenter email 
addresses thro ...)
+       TODO: check
+CVE-2026-79659 (Ech0 before 4.7.3 contains a server-side request forgery 
vulnerability ...)
+       TODO: check
+CVE-2026-79658 (Ech0 before 5.0.1 does not impose any size or shape limit on 
the Accep ...)
+       TODO: check
+CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution 
vulnerabil ...)
+       TODO: check
+CVE-2026-79655 (A flaw was found in sos clean, a utility within the sos 
package. This  ...)
+       TODO: check
+CVE-2026-79652 (A flaw was found in the JWT Bearer authorization grant 
implementation  ...)
+       TODO: check
+CVE-2026-79623 (A security vulnerability has been detected in FishCodeTech 
Muteki up t ...)
+       TODO: check
+CVE-2026-79622 (A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. 
Impacted  ...)
+       TODO: check
+CVE-2026-79406 (A security vulnerability has been detected in macrozheng mall 
up to 1. ...)
+       TODO: check
+CVE-2026-78887 (A weakness has been identified in liketrek TREK up to 3.0.22. 
This imp ...)
+       TODO: check
+CVE-2026-78886 (A security flaw has been discovered in liketrek TREK up to 
3.0.22. Thi ...)
+       TODO: check
+CVE-2026-78885 (A vulnerability was identified in liketrek TREK up to 3.0.22. 
The impa ...)
+       TODO: check
+CVE-2026-78864 (A vulnerability was determined in liketrek TREK up to 3.0.22. 
The affe ...)
+       TODO: check
+CVE-2026-78863 (A vulnerability was found in liketrek TREK up to 3.0.22. 
Impacted is t ...)
+       TODO: check
+CVE-2026-78701 (A flaw was found in 389-ds-base. A remote, authenticated 
attacker coul ...)
+       TODO: check
+CVE-2026-78684 (vLLM before 0.27.0 fails to properly classify DeepStream as a 
GPU back ...)
+       TODO: check
+CVE-2026-78581 (Authorization Bypass Through User-Controlled Key (CWE-639) in 
Kibana c ...)
+       TODO: check
+CVE-2026-78576 (The Readabler plugin for WordPress is vulnerable to SQL 
Injection in a ...)
+       TODO: check
+CVE-2026-78572 (The Kalles Addons plugin for WordPress is vulnerable to PHP 
Object Inj ...)
+       TODO: check
+CVE-2026-78570 (The Total Donations plugin for WordPress is vulnerable to 
Privilege Es ...)
+       TODO: check
+CVE-2026-78568 (The Total Donations plugin for WordPress is vulnerable to SQL 
Injectio ...)
+       TODO: check
+CVE-2026-78566 (The Shuffle theme for WordPress is vulnerable to Local File 
Inclusion  ...)
+       TODO: check
+CVE-2026-78563 (The NotificationX Pro plugin for WordPress is vulnerable to 
Stored Cro ...)
+       TODO: check
+CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local 
File Incl ...)
+       TODO: check
+CVE-2026-78468 (The FluentCRM Pro \u2013 Email Newsletter, Automation, Email 
Marketing ...)
+       TODO: check
+CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the 
python_ ...)
+       TODO: check
+CVE-2026-78322 (A flaw was found in file-roller. When opening or extracting a 
maliciou ...)
+       TODO: check
+CVE-2026-77998 (Joomla Extension - miniorange.com - Unauthenticated 
Authentication Byp ...)
+       TODO: check
+CVE-2026-77997 (Joomla Extension - yootheme.com - Authenticated, privileged 
informatio ...)
+       TODO: check
+CVE-2026-77996 (Joomla Extension - yootheme.com - Authenticated, privileged 
stored XSS ...)
+       TODO: check
+CVE-2026-77824 (The Media Sweep \u2013 WordPress Media Cleaner plugin for 
WordPress is ...)
+       TODO: check
+CVE-2026-77146 (The extension's invitation controller fails to stop processing 
after r ...)
+       TODO: check
+CVE-2026-77145 (The permission check for the frontend management update flow 
verified  ...)
+       TODO: check
+CVE-2026-77144 (The frontend management plugin attributed a newly created 
event to the ...)
+       TODO: check
+CVE-2026-77143 (The frontend topic editing flow does not verify on the server 
side tha ...)
+       TODO: check
+CVE-2026-77142 (The frontend company self-service editing feature relies on a 
template ...)
+       TODO: check
+CVE-2026-77141 (The extension resolves the targeted club record from a 
user-supplied r ...)
+       TODO: check
+CVE-2026-77140 (The extension validates the HMAC of a frontend employee edit 
link only ...)
+       TODO: check
+CVE-2026-77139 (The extension fails to validate a client-supplied template 
element key ...)
+       TODO: check
+CVE-2026-77138 (The extension fails to safely process untrusted client input 
of an att ...)
+       TODO: check
+CVE-2026-77137 (The extension fails to properly sanitize user input before 
using it in ...)
+       TODO: check
+CVE-2026-77136 (The extension passes the raw value of a form field configured 
as "This ...)
+       TODO: check
+CVE-2026-77135 (The extension's user detail view fails to verify that a 
requested user ...)
+       TODO: check
+CVE-2026-77134 (The extension fails to require the dedicated admin 
confirmation token  ...)
+       TODO: check
+CVE-2026-77133 (The extension fails to restrict which frontend usergroups a 
logged-in  ...)
+       TODO: check
+CVE-2026-77131 (When OpenSSL is unavailable on the server, the extension 
transmits TYP ...)
+       TODO: check
+CVE-2026-77130 (The extension fails to properly validate the expiration of a 
client-su ...)
+       TODO: check
+CVE-2026-77129 (The extension passes an editor-configurable email subject 
string direc ...)
+       TODO: check
+CVE-2026-77128 (The extension fails to enforce enable-field restrictions on a 
reposito ...)
+       TODO: check
+CVE-2026-77127 (The extension fails to restrict a backend AJAX endpoint for 
inline edi ...)
+       TODO: check
+CVE-2026-76198 (CAI Content Credentials is affected by an Improper Input 
Validation vu ...)
+       TODO: check
+CVE-2026-76197 (Adobe Campaign Classic (ACC) is affected by an Improper 
Neutralization ...)
+       TODO: check
+CVE-2026-76195 (Adobe Campaign Classic (ACC) is affected by an Improper 
Neutralization ...)
+       TODO: check
+CVE-2026-76193 (Adobe Campaign Classic (ACC) is affected by a Server-Side 
Request Forg ...)
+       TODO: check
+CVE-2026-76189 (CAI Content Credentials is affected by an Integer Underflow 
(Wrap or W ...)
+       TODO: check
+CVE-2026-76128 (The eCommerce Product Catalog plugin for WordPress is 
vulnerable to St ...)
+       TODO: check
+CVE-2026-75971 (The ShopEngine Elementor WooCommerce Builder Addon \u2013 All 
in One W ...)
+       TODO: check
+CVE-2026-75908 (The Newsletters plugin for WordPress is vulnerable to 
authorization by ...)
+       TODO: check
+CVE-2026-75770 (Substance3D - Painter is affected by an out-of-bounds write 
vulnerabil ...)
+       TODO: check
+CVE-2026-75769 (Substance3D - Painter is affected by a Heap-based Buffer 
Overflow vuln ...)
+       TODO: check
+CVE-2026-75768 (Substance3D - Painter is affected by an Untrusted Search Path 
vulnerab ...)
+       TODO: check
+CVE-2026-75767 (Substance3D - Painter is affected by a Heap-based Buffer 
Overflow vuln ...)
+       TODO: check
+CVE-2026-75766 (Substance3D - Painter is affected by a Heap-based Buffer 
Overflow vuln ...)
+       TODO: check
+CVE-2026-75752 (Substance3D - Painter is affected by an out-of-bounds read 
vulnerabili ...)
+       TODO: check
+CVE-2026-75750 (Substance3D - Painter is affected by a Heap-based Buffer 
Overflow vuln ...)
+       TODO: check
+CVE-2026-75749 (Substance3D - Painter is affected by an out-of-bounds write 
vulnerabil ...)
+       TODO: check
+CVE-2026-75498 (Webkul QloApps does not validate request parameters before a 
database  ...)
+       TODO: check
+CVE-2026-75497 (Webkul QloApps does not validate request parameters before a 
database  ...)
+       TODO: check
+CVE-2026-75496 (Webkul QloApps does not perform proper validation on uploaded 
file ext ...)
+       TODO: check
+CVE-2026-75038 (UNIX symbolic link (symlink) following vulnerability in 
ilya-zlobintse ...)
+       TODO: check
+CVE-2026-75037 (Polkit Authentication Based on UnixProcessSubject / Peer PID 
in LACT o ...)
+       TODO: check
+CVE-2026-71564 (Substance3D - Designer is affected by an out-of-bounds write 
vulnerabi ...)
+       TODO: check
+CVE-2026-71444 (CAI Content Credentials is affected by an Integer Underflow 
(Wrap or W ...)
+       TODO: check
+CVE-2026-71443 (CAI Content Credentials is affected by an Improper Input 
Validation vu ...)
+       TODO: check
+CVE-2026-71442 (CAI Content Credentials is affected by an Integer Underflow 
(Wrap or W ...)
+       TODO: check
+CVE-2026-71441 (Illustrator is affected by an out-of-bounds read vulnerability 
that co ...)
+       TODO: check
+CVE-2026-71399 (Adobe XD is affected by a Buffer Overflow vulnerability that 
could res ...)
+       TODO: check
+CVE-2026-71382 (Substance3D - Sampler is affected by an out-of-bounds write 
vulnerabil ...)
+       TODO: check
+CVE-2026-71360 (CAI Content Credentials is affected by an Uncontrolled 
Resource Consum ...)
+       TODO: check
+CVE-2026-70551 (A user who can read an existing remote VCS repository can 
replace its  ...)
+       TODO: check
+CVE-2026-70550 (An authorization weakness in JFrog Artifactory Composer 
repository han ...)
+       TODO: check
+CVE-2026-70548 (Under specific circumstances, low-level user can run request 
to remote ...)
+       TODO: check
+CVE-2026-69104 (An authenticated user may initiate repository migration 
operations wit ...)
+       TODO: check
+CVE-2026-67578 (FA-50 all versions miss authentication for some configuration. 
An atta ...)
+       TODO: check
+CVE-2026-66882 (Improper Neutralization of Input During Web Page Generation 
(XSS) vuln ...)
+       TODO: check
+CVE-2026-65979 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-65633 (Improper Authentication vulnerability in team-alembic 
AshAuthenticatio ...)
+       TODO: check
+CVE-2026-64204 (There is a memory corruption vulnerability recently discovered 
in NI L ...)
+       TODO: check
+CVE-2026-64203 (There is a memory corruption vulnerability recently discovered 
in NI L ...)
+       TODO: check
+CVE-2026-64202 (There is a memory corruption vulnerability recently discovered 
in NI L ...)
+       TODO: check
+CVE-2026-64201 (There is a memory corruption vulnerability recently discovered 
in NI L ...)
+       TODO: check
+CVE-2026-63587 (The SMS control function of IE-SR-2TX-WL-4G devices can 
require a pass ...)
+       TODO: check
+CVE-2026-63586 (The web-based management interface uses a modified uhttpd 
server with  ...)
+       TODO: check
+CVE-2026-62986 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-61555 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-59985 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-59984 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-59983 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-59982 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-59769 (FA-50 all versions contain hard-coded credentials. An 
attacker, who kn ...)
+       TODO: check
+CVE-2026-59335 (Improper handling of case sensitivity (CWE-178) in the 
identity zone a ...)
+       TODO: check
+CVE-2026-59189 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-59187 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-59186 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-59184 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
+       TODO: check
+CVE-2026-57910 (Improper authentication in the WatchGuard Agent allows an 
unauthentica ...)
+       TODO: check
+CVE-2026-57909 (A path traversal vulnerability in WatchGuard Agent allows a 
remote, un ...)
+       TODO: check
+CVE-2026-57863 (Crater Invoice through 6.0.6 contains a path traversal 
vulnerability i ...)
+       TODO: check
+CVE-2026-56096 (The extension passes the user-supplied search query parameter 
to Apach ...)
+       TODO: check
+CVE-2026-56095 (The extension's indexer passed every field value returned by 
content o ...)
+       TODO: check
+CVE-2026-56094 (The extension allows a request-provided additionalFilters 
parameter to ...)
+       TODO: check
+CVE-2026-56093 (The extension's frontend detail-view document lookup does not 
apply th ...)
+       TODO: check
+CVE-2026-56092 (The extension forces empty frontend-group and 
subpage-inheritance rest ...)
+       TODO: check
+CVE-2026-55976 (Server-Side Request Forgery (SSRF) in Avro SerDe schema 
resolution in  ...)
+       TODO: check
+CVE-2026-55663 (mediasoup is a WebRTC video conferencing system. From version 
3.20.0 u ...)
+       TODO: check
+CVE-2026-55640 (Nextcloud MCP Server is a production-ready MCP server that 
connects AI ...)
+       TODO: check
+CVE-2026-55637 (genieacs-mcp is an MCP server for GenieACS written in Go. 
Prior to 0.3 ...)
+       TODO: check
+CVE-2026-55624 (MintyItanium Lost-Auction is an auction plugin for Minecraft. 
Prior to ...)
+       TODO: check
+CVE-2026-55623
+       REJECTED
+CVE-2026-55620 (eml_parser serves as a python module for parsing eml files and 
returni ...)
+       TODO: check
+CVE-2026-55619 (eml_parser serves as a python module for parsing eml files and 
returni ...)
+       TODO: check
+CVE-2026-55618 (eml_parser serves as a python module for parsing eml files and 
returni ...)
+       TODO: check
+CVE-2026-55609 (sublinear-time-solver is a Rust and WebAssembly library for 
solving as ...)
+       TODO: check
+CVE-2026-55585 (QWED is open-source AI verification infrastructure for 
deterministic v ...)
+       TODO: check
+CVE-2026-55582 (mcp-shell is an MCP server for running shell commands 
securely, audita ...)
+       TODO: check
+CVE-2026-55581 (mcp-shell is an MCP server for running shell commands 
securely, audita ...)
+       TODO: check
+CVE-2026-55580 (mcp-shell is an MCP server for running shell commands 
securely, audita ...)
+       TODO: check
+CVE-2026-55571 (djust provides Phoenix LiveView-style reactive server-side 
rendering f ...)
+       TODO: check
+CVE-2026-55557 (browse-mcp is a Playwright-based headless-browser MCP server 
for MCP-c ...)
+       TODO: check
+CVE-2026-55553 (urllib is an HTTP client for Node.js that supports 
authentication, red ...)
+       TODO: check
+CVE-2026-55546 (QWED-MCP is a deterministic verification gateway for MCP. 
Prior to 0.2 ...)
+       TODO: check
+CVE-2026-55541 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.58, pr ...)
+       TODO: check
+CVE-2026-55540 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.51, is ...)
+       TODO: check
+CVE-2026-55539 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.51, th ...)
+       TODO: check
+CVE-2026-55538 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.51, pr ...)
+       TODO: check
+CVE-2026-55537 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.58, Jo ...)
+       TODO: check
+CVE-2026-55536 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.58, Br ...)
+       TODO: check
+CVE-2026-55535 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.58, th ...)
+       TODO: check
+CVE-2026-55534 (PraisonAI is a multi-agent teams system. From praisonai 4.6.34 
until 4 ...)
+       TODO: check
+CVE-2026-55533 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.58, cr ...)
+       TODO: check
+CVE-2026-55532 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.58, MC ...)
+       TODO: check
+CVE-2026-55531 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.58, th ...)
+       TODO: check
+CVE-2026-55530 (PraisonAI is a multi-agent teams system. Prior to 
praisonaiagents 1.6. ...)
+       TODO: check
+CVE-2026-55529 (PraisonAI is a multi-agent teams system. Prior to praisonai 
4.6.58, th ...)
+       TODO: check
+CVE-2026-55528 (PraisonAI is a multi-agent teams system. Prior to 
praisonaiagents 1.6. ...)
+       TODO: check
+CVE-2026-55527 (PraisonAI is a multi-agent teams system. Prior to 
praisonaiagents 1.6. ...)
+       TODO: check
+CVE-2026-55526 (PraisonAI is a multi-agent teams system. Prior to 
praisonaiagents 1.6. ...)
+       TODO: check
+CVE-2026-55525 (PraisonAI is a multi-agent teams system. Prior to 
praisonaiagents 1.6. ...)
+       TODO: check
+CVE-2026-55419 (Reachy Mini is an SDK for controlling Reachy Mini robots. 
Prior to 1.8 ...)
+       TODO: check
+CVE-2026-53561 (An improper authentication vulnerability in HiveServer2 SAML 
bearer-to ...)
+       TODO: check
+CVE-2026-49845 (SQL injection in Hive Metastore direct SQL partition-name 
resolution i ...)
+       TODO: check
+CVE-2026-48433 (Substance3D - Designer is affected by a Heap-based Buffer 
Overflow vul ...)
+       TODO: check
+CVE-2026-48432 (Substance3D - Designer is affected by a Heap-based Buffer 
Overflow vul ...)
+       TODO: check
+CVE-2026-48431 (Substance3D - Designer is affected by a Heap-based Buffer 
Overflow vul ...)
+       TODO: check
+CVE-2026-48430 (Substance3D - Designer is affected by a Heap-based Buffer 
Overflow vul ...)
+       TODO: check
+CVE-2026-48429 (Substance3D - Designer is affected by a NULL Pointer 
Dereference vulne ...)
+       TODO: check
+CVE-2026-48428 (Substance3D - Designer is affected by a Heap-based Buffer 
Overflow vul ...)
+       TODO: check
+CVE-2026-48427 (Substance3D - Designer is affected by an out-of-bounds write 
vulnerabi ...)
+       TODO: check
+CVE-2026-48426 (Substance3D - Designer is affected by an out-of-bounds write 
vulnerabi ...)
+       TODO: check
+CVE-2026-48425 (Substance3D - Sampler is affected by a Heap-based Buffer 
Overflow vuln ...)
+       TODO: check
+CVE-2026-48424 (Substance3D - Sampler is affected by a Heap-based Buffer 
Overflow vuln ...)
+       TODO: check
+CVE-2026-48423 (Substance3D - Sampler is affected by a Heap-based Buffer 
Overflow vuln ...)
+       TODO: check
+CVE-2026-48422 (Substance3D - Sampler is affected by a Heap-based Buffer 
Overflow vuln ...)
+       TODO: check
+CVE-2026-48421 (Substance3D - Sampler is affected by an out-of-bounds write 
vulnerabil ...)
+       TODO: check
+CVE-2026-48420 (Substance3D - Sampler is affected by an out-of-bounds write 
vulnerabil ...)
+       TODO: check
+CVE-2026-48419 (Substance3D - Sampler is affected by an out-of-bounds write 
vulnerabil ...)
+       TODO: check
+CVE-2026-48418 (Substance3D - Sampler is affected by an out-of-bounds write 
vulnerabil ...)
+       TODO: check
+CVE-2026-48417 (Substance3D - Sampler is affected by a Stack-based Buffer 
Overflow vul ...)
+       TODO: check
+CVE-2026-47626 (NVIDIA DGX Spark contains a vulnerability in the system 
firmware, wher ...)
+       TODO: check
+CVE-2026-47624 (NVIDIA DGX Spark contains a vulnerability in UEFI where a 
Attacker may ...)
+       TODO: check
+CVE-2026-26211 (Ekushey Project Manager CRM stores the 
administrator-configured system ...)
+       TODO: check
+CVE-2026-24263 (NVIDIA DGX Spark contains a vulnerability in the system 
firmware, wher ...)
+       TODO: check
+CVE-2026-24262 (NVIDIA DGX Spark contains a vulnerability in the system 
firmware, wher ...)
+       TODO: check
+CVE-2026-24225 (NVIDIA DGX Spark contains a vulnerability in the standalone MM 
firmwar ...)
+       TODO: check
+CVE-2026-24170 (NVIDIA UFM Enterprise contains a vulnerability in the web 
interface au ...)
+       TODO: check
+CVE-2026-24169 (NVIDIA UFM Enterprise contains a vulnerability in the plugin 
managemen ...)
+       TODO: check
+CVE-2026-24168 (NVIDIA UFM Enterprise contains a vulnerability in the 
IBDiagnet API wh ...)
+       TODO: check
+CVE-2026-24167 (NVIDIA UFM Enterprise contains a vulnerability in the user 
management  ...)
+       TODO: check
+CVE-2026-24166 (NVIDIA UFM Enterprise contains a vulnerability in the session 
manageme ...)
+       TODO: check
+CVE-2026-21758 (HCL Hive is affected by an information disclosure 
vulnerability, which ...)
+       TODO: check
+CVE-2026-21754 (HCL Hive is affected by multiple infrastructure and network 
configurat ...)
+       TODO: check
+CVE-2026-21753 (HCL Hive is affected by weak software supply chain governance, 
which c ...)
+       TODO: check
+CVE-2026-19949 (The All-in-One WP Migration and Backup plugin for WordPress is 
vulnera ...)
+       TODO: check
+CVE-2026-19913 (The Kaltura HTML5 player (mwEmbed / html5lib) contains a local 
file di ...)
+       TODO: check
+CVE-2026-19912 (The Kaltura HTML5 player (mwEmbed / html5lib) contains an 
unauthentica ...)
+       TODO: check
+CVE-2026-19851 (A Use of Default Password vulnerability affecting Tuleap 
Enterprise Ed ...)
+       TODO: check
+CVE-2026-18547 (The Ultimate Member \u2013 User Profile, Registration, Login, 
Member D ...)
+       TODO: check
+CVE-2026-18512 (The TranslatePress \u2013 Translate Multilingual sites with AI 
Transla ...)
+       TODO: check
+CVE-2026-18445 (There is an integer overflow vulnerability resulting in an 
out-of-boun ...)
+       TODO: check
+CVE-2026-18444 (There is an integer conversion vulnerability resulting in an 
out-of-bo ...)
+       TODO: check
+CVE-2026-18328 (The Forminator Forms \u2013 Contact Form, Payment Form & 
Custom Form B ...)
+       TODO: check
+CVE-2026-18323 (The Forminator Forms \u2013 Contact Form, Payment Form & 
Custom Form B ...)
+       TODO: check
+CVE-2026-18100 (The MetForm \u2013 Contact Form, Survey, Quiz, & Custom Form 
Builder f ...)
+       TODO: check
+CVE-2026-17587 (The My Agile Privacy\xae \u2013 CMP, Cookie Consent & Privacy 
Tools pl ...)
+       TODO: check
+CVE-2026-17548 (Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, 
<2.3.0p50 and a ...)
+       TODO: check
+CVE-2026-16601 (The CM Map Locations \u2013 Visualize and share your locations 
in a fe ...)
+       TODO: check
+CVE-2026-16599 (GNU wget is vulnerable to denial of service in its FTP 
OPIE/S-KEY auth ...)
+       TODO: check
+CVE-2026-16286 (Unrestricted upload of file with dangerous type vulnerability 
in TRtek ...)
+       TODO: check
+CVE-2026-16234 (There is a memory corruption vulnerability recently discovered 
in NI L ...)
+       TODO: check
+CVE-2026-16233 (There is a memory corruption vulnerability recently discovered 
in NI L ...)
+       TODO: check
+CVE-2026-16231 (hbs is an Express view engine that wraps Handlebars. Its 
registerAsync ...)
+       TODO: check
+CVE-2026-15310 (When decompressing crafted zip files using the 
bzip/LZMA/Zstandard   c ...)
+       TODO: check
+CVE-2026-13478 (The Zephyr ext2 filesystem driver validates the on-disk block 
bitmap i ...)
+       TODO: check
+CVE-2026-13217 (The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs 
a sessi ...)
+       TODO: check
+CVE-2026-13216 (The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a 
device's  ...)
+       TODO: check
+CVE-2026-12878 (In affected versions of the Codefresh platform an 
authenticated user c ...)
+       TODO: check
+CVE-2026-12600 (Denial-of-service (DoS) vulnerability in the internal JPEG2000 
(JPX) d ...)
+       TODO: check
+CVE-2025-71407 (Nokogiri before 1.18.3 contains a stack buffer overflow 
vulnerability  ...)
+       TODO: check
+CVE-2025-71406 (Nokogiri before 1.18.4 bundles a vulnerable version of libxslt 
(prior  ...)
+       TODO: check
+CVE-2025-71346 (Nokogiri before 1.18.8 packages a vulnerable version of 
libxml2 (befor ...)
+       TODO: check
+CVE-2024-58378 (Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when 
using the ...)
+       TODO: check
+CVE-2024-58377 (Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which 
is affect ...)
+       TODO: check
+CVE-2023-54354 (Nokogiri before 1.14.3 (CRuby implementation only, when using 
the pack ...)
+       TODO: check
+CVE-2022-51000 (Nokogiri before 1.13.2 (CRuby, when using packaged libraries) 
ships ve ...)
+       TODO: check
+CVE-2022-50999 (Nokogiri versions before 1.13.5 contain an integer overflow 
vulnerabil ...)
+       TODO: check
+CVE-2022-50998 (Nokogiri before 1.13.9 (CRuby implementation using packaged 
libraries) ...)
+       TODO: check
+CVE-2021-47996 (Nokogiri before 1.11.4 (CRuby implementation only, when the 
packaged/v ...)
+       TODO: check
 CVE-2026-63676
        - libyaml-perl 1.321-1
        NOTE: Fixed by: 
https://github.com/ingydotnet/yaml-pm/commit/9388c6a02a66db79f9d2b3727b5588272f612cf1
 (v1.320.0)
@@ -11,7 +525,8 @@ CVE-2026-XXXX [GHSA-75g3-96fr-7p2r: SABnzbd PAR2 path 
traversal enabling cross-j
        NOTE: 
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-75g3-96fr-7p2r
        NOTE: Fixed by: 
https://github.com/sabnzbd/sabnzbd/commit/6ddabb5a4599731b00f44162e62f31e291d2b2d0
 (5.1.2)
        NOTE: Fixed by: 
https://github.com/sabnzbd/sabnzbd/commit/c57af32131216de3e1df3097a0cce06c8c99ceb8
 (5.1.2)
-CVE-2026-18798
+CVE-2026-18798 (Issue summary: QUIC server may double free QRX (QUIC record 
layer RX)  ...)
+       {DSA-6465-1}
        - openssl <unfixed>
        [bookworm] - openssl <not-affected> (Vulnerable code not present)
        [bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -19,21 +534,24 @@ CVE-2026-18798
        NOTE: 
https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af
 (openssl-3.6.4)
        NOTE: 
https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c
 (oepnssl-3.5.8)
        NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63072
+CVE-2026-63072 (Issue summary: OpenSSL CMS decryption sizes the key-unwrap 
output buff ...)
+       {DSA-6465-1}
        - openssl <unfixed>
        NOTE: 
https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335
 (openssl-4.0.2)
        NOTE: 
https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756
 (openssl-3.6.4)
        NOTE: 
https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42
 (openssl-3.5.8)
        NOTE: 
https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382
 (openssl-3.0.22)
        NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63076
+CVE-2026-63076 (Issue summary: OpenSSL CMP password based protection 
verification only ...)
+       {DSA-6465-1}
        - openssl <unfixed>
        NOTE: 
https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e
 (openssl-4.0.2)
        NOTE: 
https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226
 (openssl-3.6.4)
        NOTE: 
https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c
 (openssl-3.5.8)
        NOTE: 
https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b
 (openssl-3.0.22)
        NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-14457
+CVE-2026-14457 (Issue summary: In a server or client configuration with 
RFC7250 Raw Pu ...)
+       {DSA-6465-1}
        - openssl <unfixed>
        [bookworm] - openssl <not-affected> (Vulnerable code not present)
        [bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -41,14 +559,16 @@ CVE-2026-14457
        NOTE: 
https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1
 (openssl-3.6.4)
        NOTE: 
https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f
 (openssl-3.5.8)
        NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-54874
+CVE-2026-54874 (Issue summary: Receiving a DTLS record for a future epoch 
while a hand ...)
+       {DSA-6465-1}
        - openssl <unfixed>
        NOTE: 
https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107
 (openssl-4.0.2)
        NOTE: 
https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c
 (openssl-3.6.4)
        NOTE: 
https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23
 (openssl-3.5.8)
        NOTE: 
https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382
 (openssl-3.0.22)
        NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63073
+CVE-2026-63073 (Issue summary: OpenSSL CMP response validation passed an 
unexpected re ...)
+       {DSA-6465-1}
        - openssl <unfixed>
        [bookworm] - openssl <not-affected> (Vulnerable code not present)
        [bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -56,14 +576,16 @@ CVE-2026-63073
        NOTE: 
https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29
 (openssl-3.6.4)
        NOTE: 
https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca
 (openssl-3.5.8)
        NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63074
+CVE-2026-63074 (Issue summary: The OpenSSL Certificate Management Protocol 
(CMP) cache ...)
+       {DSA-6465-1}
        - openssl <unfixed>
        NOTE: 
https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46
 (openssl-4.0.2)
        NOTE: 
https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7
 (openssl-3.6.4)
        NOTE: 
https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af
 (openssl-3.5.8)
        NOTE: 
https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f
 (openssl-3.0.22)
        NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63075
+CVE-2026-63075 (Issue summary: When OpenSSL processes QUIC traffic from a peer 
that re ...)
+       {DSA-6465-1}
        - openssl <unfixed>
        [bookworm] - openssl <not-affected> (Vulnerable code not present)
        [bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -565,7 +1087,8 @@ CVE-2026-78157 (A vulnerability was detected in Open5GS 
2.8.0. This affects the
        - open5gs <itp> (bug #1094791)
 CVE-2026-78156 (A security vulnerability has been detected in Open5GS 2.8.0. 
Affected  ...)
        - open5gs <itp> (bug #1094791)
-CVE-2026-78154 (A vulnerability was identified in the-momentum open-wearables 
up to 0. ...)
+CVE-2026-78154
+       REJECTED
        NOT-FOR-US: the-momentum open-wearables
 CVE-2026-78148 (A vulnerability was determined in ggml-org llama.cpp 
bec4772f6. This a ...)
        - llama.cpp <unfixed>
@@ -592,9 +1115,9 @@ CVE-2026-77994 (Joomla Extension - joomlack.fr - Second 
order SQL injection in P
        NOT-FOR-US: Joomla
 CVE-2026-77993 (Joomla Extension - joomlack.fr - Reflected XSS in Page Builder 
CK < 3. ...)
        NOT-FOR-US: Joomla
-CVE-2026-77915 (rConfig 8.0.0 before 8.2.13 contains an authentication bypass 
vulnerab ...)
+CVE-2026-77915 (rConfig Core 8.0.0 before 8.2.13 contains an authentication 
bypass vul ...)
        NOT-FOR-US: rConfig
-CVE-2026-77914 (rConfig before 8.2.13 contains a path traversal vulnerability 
that all ...)
+CVE-2026-77914 (rConfig Core 8.0.0 before 8.2.13 contains a path traversal 
vulnerabili ...)
        NOT-FOR-US: rConfig
 CVE-2026-76848 (TypeORM's SelectQueryBuilder.distinctOn accepts an array of 
strings an ...)
        NOT-FOR-US: TypeORM
@@ -3527,7 +4050,8 @@ CVE-2026-XXXX [OSSN-0103]
        NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0103
        NOTE: https://review.opendev.org/c/openstack/manila/+/998388
        NOTE: https://bugs.launchpad.net/manila/+bug/2161287
-CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs]
+CVE-2026-75803 (Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with 
an empty  ...)
+       {DSA-6465-1}
        - openssl <unfixed> (bug #1145172)
        NOTE: 
https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a
 (openssl-4.0.2)
        NOTE: 
https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b
 (openssl-3.6.4)
@@ -4276,7 +4800,7 @@ CVE-2025-14602 (The application generates uploaded file 
names using a weak and p
        NOT-FOR-US: vsDesk
 CVE-2022-4996 (A flaw has been found in mruby 3.1.0. Affected is the function 
udiv of ...)
        TODO: check
-CVE-2026-79992 [Emacs zero-click local command execution via TRAMP]
+CVE-2026-79992 (A flaw was found in Emacs TRAMP. A local attacker could 
exploit this v ...)
        - emacs <unfixed> (bug #1145049)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/21/1
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=f3e7104d05bdb8e32ba13bf75604108ad88536dc
@@ -7358,7 +7882,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient 
validation of packet len
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
        NOTE: Followup: 
https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
 CVE-2026-74990 (Internally found bugs present in Firefox ESR 115.38, Firefox 
ESR 140.1 ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7372,7 +7896,7 @@ CVE-2026-74988 (Internally found bugs present in Firefox 
ESR 153.0 and Firefox 1
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
 CVE-2026-74987 (Internally found bugs present in Firefox ESR 140.13, Firefox 
ESR 153.0 ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7389,7 +7913,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine 
component. This vulnerab
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
 CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This 
vulnerab ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7415,7 +7939,7 @@ CVE-2026-74977 (Integer overflow in the Graphics 
component. This vulnerability w
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
 CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. 
This vulne ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7426,7 +7950,7 @@ CVE-2026-74975 (Spoofing issue in the Downloads component 
in Firefox for Android
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
 CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. 
This vu ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7434,7 +7958,7 @@ CVE-2026-74974 (Same-origin policy bypass in the 
Graphics: ImageLib component. T
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
 CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This 
vulnera ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7442,7 +7966,7 @@ CVE-2026-74973 (Race condition, use-after-free in the 
Graphics component. This v
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
 CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions 
component. This  ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7450,7 +7974,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push 
Subscriptions component.
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
 CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling 
componen ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7461,7 +7985,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
 CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This 
vulnerabi ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7472,7 +7996,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics: 
WebRender component. This
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
 CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback 
component. This ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7483,7 +8007,7 @@ CVE-2026-74966 (Information disclosure in the Form 
Autofill component. This vuln
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
 CVE-2026-74965 (Privilege escalation in the Shell Integration component. This 
vulnerab ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7491,7 +8015,7 @@ CVE-2026-74965 (Privilege escalation in the Shell 
Integration component. This vu
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
 CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability 
was fix ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7499,7 +8023,7 @@ CVE-2026-74964 (Integer overflow in the Graphics 
component. This vulnerability w
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
 CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies 
component. This v ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7507,7 +8031,7 @@ CVE-2026-74963 (Same-origin policy bypass in the 
Networking: Cookies component.
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
 CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. 
This vulner ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7518,7 +8042,7 @@ CVE-2026-74961 (Side-channel in the Web Audio component. 
This vulnerability was
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
 CVE-2026-74960 (Site isolation issue in the WebExtensions component. This 
vulnerabilit ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7526,7 +8050,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions 
component. This vulner
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
 CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This 
vulnerabil ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7537,7 +8061,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
 CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This 
vulnerability w ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7554,7 +8078,7 @@ CVE-2026-74954 (Information disclosure due to 
side-channel in the Storage: Cache
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
 CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. 
This vulner ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7571,7 +8095,7 @@ CVE-2026-74950 (Privilege escalation in the Downloads API 
component. This vulner
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
 CVE-2026-74949 (Use-after-free in the Graphics: Canvas2D component. This 
vulnerability ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7579,7 +8103,7 @@ CVE-2026-74949 (Use-after-free in the Graphics: Canvas2D 
component. This vulnera
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
 CVE-2026-74948 (Information disclosure in the Graphics component. This 
vulnerability w ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7590,7 +8114,7 @@ CVE-2026-74947 (Privilege escalation due to invalid 
pointer in the Graphics comp
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
 CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7598,7 +8122,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect 
boundary conditions in the
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
 CVE-2026-74945 (Information disclosure in the Graphics: Text component. This 
vulnerabi ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7606,7 +8130,7 @@ CVE-2026-74945 (Information disclosure in the Graphics: 
Text component. This vul
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
 CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This 
vulnerability w ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7614,7 +8138,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML 
component. This vulnerabi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
 CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This 
vulnerability ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7622,7 +8146,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib 
component. This vulnera
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
 CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. 
This vul ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7630,7 +8154,7 @@ CVE-2026-74942 (Privilege escalation in the Remote 
Settings Client component. Th
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
 CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. 
This vuln ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7638,7 +8162,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics: 
CanvasWebGL component. Thi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
 CVE-2026-74940 (Use-after-free in the Graphics: Text component. This 
vulnerability was ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7646,7 +8170,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text 
component. This vulnerabili
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
 CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This 
vulnerabil ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7660,7 +8184,7 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
 CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This 
vulnerab ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7668,7 +8192,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript: 
WebAssembly component. This vu
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
 CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This 
vulnerabil ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7676,7 +8200,7 @@ CVE-2026-74935 (Privilege escalation in the DOM: 
Networking component. This vuln
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
 CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. 
This vuln ...)
-       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -7830,7 +8354,8 @@ CVE-2026-73336 (Joomla! Core - [20260806] - XSS through 
schema.org outputs in Jo
        NOT-FOR-US: Joomla
 CVE-2026-73190 (Unauthenticated Cross Site Scripting (XSS) in WPDM \u2013 
Premium Pack ...)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-73189 (Subscriber Insecure Direct Object References (IDOR) in WP 
Crowdfunding ...)
+CVE-2026-73189
+       REJECTED
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73187 (Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 
versions.)
        NOT-FOR-US: WordPress plugin or theme
@@ -7965,7 +8490,7 @@ CVE-2026-66627 (Contributor Arbitrary File Upload in GP 
Premium <= 2.5.5 version
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66622 (Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 
versions.)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate 
Dashboard <= 3. ...)
+CVE-2026-66621 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
        NOT-FOR-US: WordPress plugin or theme
@@ -15778,6 +16303,7 @@ CVE-2026-15994 (During an internal security assessment, 
an improper link followi
 CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed 
as a "hom ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL 
object) proce ...)
+       {DSA-6465-1}
        - openssl <unfixed> (bug #1144615)
        NOTE: https://openssl-library.org/news/secadv/20260813.txt
        NOTE: 
https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139
 (openssl-4.0.2)
@@ -79189,6 +79715,7 @@ CVE-2026-9334 (Cpanel::JSON::XS versions before 4.41 
for Perl allow type confusi
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/40653179/
        NOTE: Fixed by: 
https://github.com/rurban/Cpanel-JSON-XS/commit/11a7c550a0d8fac2f84414f24d5df9b2bfe346e2
 (4.41)
 CVE-2026-50538 (LibVNCClient is a library for easy implementation of a VNC 
client. In  ...)
+       {DLA-4755-1}
        - libvncserver 0.9.15+dfsg-6 (bug #1138253)
        [trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
        [bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
@@ -82114,7 +82641,7 @@ CVE-2026-49052 (Missing Authorization vulnerability in 
Wpmet ElementsKit Element
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-49051 (Missing Authorization vulnerability in Prasad Kirpekar WP Meta 
and Dat ...)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-49050
+CVE-2026-49050 (General user can mint admin access tokens via /access-tokens   
 This i ...)
        NOT-FOR-US: Apache DolphinScheduler
 CVE-2026-49047 (Missing Authorization vulnerability in DearHive DearFlip 
allows Exploi ...)
        NOT-FOR-US: WordPress plugin or theme
@@ -82259,6 +82786,7 @@ CVE-2026-45022 (go-git is an extensible git 
implementation library written in pu
        [bookworm] - golang-github-go-git-go-git <postponed> (Limited support, 
minor issue; signature-verification bypass)
        NOTE: 
https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp
 CVE-2026-44988 (LibVNCClient is a library for easy implementation of a VNC 
client. In  ...)
+       {DLA-4755-1}
        - libvncserver 0.9.15+dfsg-5 (bug #1138174)
        [trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
        [bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
@@ -122348,12 +122876,14 @@ CVE-2026-33157 (Craft CMS is a content management 
system (CMS). From version 5.6
 CVE-2026-32948 (sbt is a build tool for Scala, Java, and others. From version 
0.9.5 to ...)
        NOT-FOR-US: sbt
 CVE-2026-32854 (LibVNCServer versions 0.9.15 and prior (fixed incommit 
dc78dee) contai ...)
+       {DLA-4755-1}
        - libvncserver 0.9.15+dfsg-3 (bug #1132017)
        [trixie] - libvncserver 0.9.15+dfsg-1+deb13u1
        [bookworm] - libvncserver 0.9.14+dfsg-1+deb12u1
        NOTE: 
https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x
        NOTE: Fixed by: 
https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314
 CVE-2026-32853 (LibVNCServer versions 0.9.15 and prior (fixed incommit 
009008e) contai ...)
+       {DLA-4755-1}
        - libvncserver 0.9.15+dfsg-3 (bug #1132016)
        [trixie] - libvncserver 0.9.15+dfsg-1+deb13u1
        [bookworm] - libvncserver 0.9.14+dfsg-1+deb12u1
@@ -410267,7 +410797,8 @@ CVE-2023-34960 (A command injection vulnerability in 
the wsConvertPpt component
        NOT-FOR-US: Chamilo CMS
 CVE-2023-4026
        REJECTED
-CVE-2023-4010 (A flaw was found in the USB Host Controller Driver framework in 
the Li ...)
+CVE-2023-4010
+       REJECTED
        - linux <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2227726
        NOTE: https://github.com/wanrenmi/a-usb-kernel-bug



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4cb95bf496ed793f0ce5994609d9628b4286d86

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4cb95bf496ed793f0ce5994609d9628b4286d86
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to