Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e9540cfc by security tracker role at 2026-08-28T07:13:42+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,408 @@
-CVE-2026-81893
+CVE-2026-82090 (Pocket through 8.33.0.0 allows XSS because "Save to Pocket" 
injects ex ...)
+       TODO: check
+CVE-2026-82089 (The wallabag (aka fr.gaulupeau.apps.InThePoche) application 
through 2. ...)
+       TODO: check
+CVE-2026-82082 (NUMail developed by Green-Computing has an OS Command 
Injection vulner ...)
+       TODO: check
+CVE-2026-82081 (wallabag 2 through 2.6.14 allows SSRF because a crafted title 
or conte ...)
+       TODO: check
+CVE-2026-82072 (Out of bounds read in V8 in Google Chrome prior to 
151.0.7922.72 allow ...)
+       TODO: check
+CVE-2026-81934 (Redis contains a use-after-free vulnerability in the 
'tlsProcessPendin ...)
+       TODO: check
+CVE-2026-81931 (Unrestricted Upload of File with Dangerous Type in the product 
photo u ...)
+       TODO: check
+CVE-2026-81851 (A heap-based buffer overflow vulnerability in Fireware OS's 
iked proce ...)
+       TODO: check
+CVE-2026-81848 (A vulnerability was determined in cyberchitta 
scrapling-fetch-mcp up t ...)
+       TODO: check
+CVE-2026-81847 (A vulnerability was found in MAA-AI MaaMCP up to 
1.1.1.dev6+g2e4a41287 ...)
+       TODO: check
+CVE-2026-81845 (A vulnerability has been found in arben-adm 
mcp-sequential-thinking up ...)
+       TODO: check
+CVE-2026-81838 (A relative path traversal issue in the zip extraction 
functionality in ...)
+       TODO: check
+CVE-2026-81837 (A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. 
This issue  ...)
+       TODO: check
+CVE-2026-81836 (A vulnerability was detected in RooCodeInc Roo-Code up to 
3.51.1. This ...)
+       TODO: check
+CVE-2026-81835 (A security vulnerability has been detected in RooCodeInc 
Roo-Code up t ...)
+       TODO: check
+CVE-2026-81834 (A weakness has been identified in RooCodeInc Roo-Code up to 
3.51.1. Af ...)
+       TODO: check
+CVE-2026-81833 (A security flaw has been discovered in RooCodeInc Roo-Code up 
to 3.51. ...)
+       TODO: check
+CVE-2026-81731 (Frappe 15.11.0 through 16.32.0 stores and renders the 
workspace card d ...)
+       TODO: check
+CVE-2026-81730 (Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments 
under th ...)
+       TODO: check
+CVE-2026-81729 (Dolibarr before 23.0.4 authorizes REST API document deletion 
against t ...)
+       TODO: check
+CVE-2026-81728 (Dolibarr before 24.0.0 contains a SQL injection in its CSV and 
XLSX im ...)
+       TODO: check
+CVE-2026-81530 (A weakness in the client-side encryption configuration surface 
of the  ...)
+       TODO: check
+CVE-2026-81529 (Improper neutralization of delimiters in connection-URL 
construction a ...)
+       TODO: check
+CVE-2026-81528 (A MongoDB C# driver document-replacement code path omits the 
element-n ...)
+       TODO: check
+CVE-2026-81527 (A NoSQL/expression injection weakness exists in the 
LINQ-to-aggregatio ...)
+       TODO: check
+CVE-2026-81526 (The MongoDB Rust Driver does not neutralize special characters 
in a ca ...)
+       TODO: check
+CVE-2026-81525 (The MongoDB client library for PHP does not sufficiently 
sanitize spec ...)
+       TODO: check
+CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in 
caller-s ...)
+       TODO: check
+CVE-2026-81523 (A missing input-validation issue in MongoDB libmongocrypt's 
automatic- ...)
+       TODO: check
+CVE-2026-81522 (A weakness in the MongoDB C++ Driver's handling of 
caller-supplied nam ...)
+       TODO: check
+CVE-2026-81521 (The MongoDB Go Driver's client-level bulk write operation may 
accept a ...)
+       TODO: check
+CVE-2026-78618 (A business logic flaw in WatchGuard Dimension allows an 
authenticated  ...)
+       TODO: check
+CVE-2026-78617 (WatchGuard Dimension's web login endpoint does not enforce 
effective r ...)
+       TODO: check
+CVE-2026-78616 (A Stored Cross-Site Scripting (XSS) vulnerability in 
WatchGuard Dimens ...)
+       TODO: check
+CVE-2026-78615 (A Reflected Cross-Site Scripting (XSS) vulnerability in 
WatchGuard Dim ...)
+       TODO: check
+CVE-2026-78614 (WatchGuard Dimension contains an authenticated SQL injection 
vulnerabi ...)
+       TODO: check
+CVE-2026-78613 (WatchGuard Dimension contains an authenticated SQL injection 
vulnerabi ...)
+       TODO: check
+CVE-2026-78612 (WatchGuard Dimension contains an authenticated SQL injection 
vulnerabi ...)
+       TODO: check
+CVE-2026-78610 (WatchGuard Dimension's Web UI exposes an administrator 
passphrase chan ...)
+       TODO: check
+CVE-2026-78500 (A blind server-side request forgery (SSRF) vulnerability 
WatchGuard Di ...)
+       TODO: check
+CVE-2026-78499 (A server-side request forgery (SSRF) vulnerability WatchGuard 
Dimensio ...)
+       TODO: check
+CVE-2026-78498 (A server-side request forgery (SSRF) vulnerability WatchGuard 
Dimensio ...)
+       TODO: check
+CVE-2026-78495 (A server-side request forgery (SSRF) vulnerability WatchGuard 
Dimensio ...)
+       TODO: check
+CVE-2026-78239 (Xiiaozet LK100W exposes a critical management function that 
can be  in ...)
+       TODO: check
+CVE-2026-78195 (A Cross-Site Scripting (XSS) vulnerability in the WatchGuard 
Dimension ...)
+       TODO: check
+CVE-2026-78174 (WatchGuard Dimension records unredacted session identifiers 
for logged ...)
+       TODO: check
+CVE-2026-78103 (WatchGuard Dimension provides a client-side lock/unlock UI 
control for ...)
+       TODO: check
+CVE-2026-78047 (A stored cross-site scripting (XSS) vulnerability in 
WatchGuard Dimens ...)
+       TODO: check
+CVE-2026-78037 (Xiiaozet LK100W is vulnerable to OS command injection through 
its  web ...)
+       TODO: check
+CVE-2026-78011 (An integer underflow vulnerability in the WatchGuard Fireware 
OS iked  ...)
+       TODO: check
+CVE-2026-78010 (A stack-based buffer overflow vulnerability in the WatchGuard 
Fireware ...)
+       TODO: check
+CVE-2026-78009 (An out-of-bounds read vulnerability in the WatchGuard Fireware 
OS iked ...)
+       TODO: check
+CVE-2026-78008 (A buffer overflow vulnerability in the WatchGuard Fireware OS 
Manageme ...)
+       TODO: check
+CVE-2026-77977 (Ebyte gateway product's vendor configuration utility does not 
require  ...)
+       TODO: check
+CVE-2026-77438 (Trilium is an open-source hierarchical note-taking 
application. In ver ...)
+       TODO: check
+CVE-2026-77365 (The Optimole \u2013 Optimize Images | Convert WebP & AVIF | 
CDN & Lazy ...)
+       TODO: check
+CVE-2026-77358 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In 
versions 0.33. ...)
+       TODO: check
+CVE-2026-77341 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In 
version 0.49.0 ...)
+       TODO: check
+CVE-2026-76945 (The affected Ebyte device relies on client-managed 
authentication toke ...)
+       TODO: check
+CVE-2026-76943 (Xiiaozet LK100Wt contains an authentication weakness within an 
 admini ...)
+       TODO: check
+CVE-2026-76940 (The affected Ebyte device does not restrict repeated 
authentication  a ...)
+       TODO: check
+CVE-2026-76640 (Unitree G1 EDU firmware through 1.5.2 contains multiple 
chained vulner ...)
+       TODO: check
+CVE-2026-76639 (Unitree G1 EDU firmware through 1.5.2 contains an 
unauthenticated remo ...)
+       TODO: check
+CVE-2026-76179 (An improper protection of authentication tokens vulnerability 
exists i ...)
+       TODO: check
+CVE-2026-76060 (An authenticated OS command injection vulnerability exists in 
ZoneMind ...)
+       TODO: check
+CVE-2026-76053 (The TranslatePress \u2013 Translate Multilingual sites with AI 
Transla ...)
+       TODO: check
+CVE-2026-75889 (Grafana Alloy\u2019s prometheus.operator.servicemonitors 
component all ...)
+       TODO: check
+CVE-2026-75814 (The Ebyte device does not adequately verify the origin or 
authenticity ...)
+       TODO: check
+CVE-2026-75813 (Certain configuration endpoints may lack proper server-side  
authoriza ...)
+       TODO: check
+CVE-2026-75548 (The affected Ebyte device web management interface does not 
restrict t ...)
+       TODO: check
+CVE-2026-75419 (go-wind-cms (GoWind) before 1.0.0 has a missing authorization 
vulnerab ...)
+       TODO: check
+CVE-2026-75418 (A path traversal vulnerability exists in the built-in 
preview/developm ...)
+       TODO: check
+CVE-2026-75417 (A SQL injection vulnerability was found in YzmCMS 7.5. The 
issue occur ...)
+       TODO: check
+CVE-2026-75339 (The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are 
missing ...)
+       TODO: check
+CVE-2026-75337 (The static resource interface /api/static/{deployKey}/ of Yu 
AI Code M ...)
+       TODO: check
+CVE-2026-74820 (ServiceNow has remediated a SQL injection vulnerability that 
was ident ...)
+       TODO: check
+CVE-2026-73839 (Administrative credentials may be exposed in plaintext within 
the Ebyt ...)
+       TODO: check
+CVE-2026-73809 (A cleartext transmission of sensitive information 
vulnerability exists ...)
+       TODO: check
+CVE-2026-73125 (Ebyte device web management interface does not consistently 
enforce  a ...)
+       TODO: check
+CVE-2026-71396 (Bendix EC80 Brake ECUuses hard-coded credentials, which could 
allow an ...)
+       TODO: check
+CVE-2026-71187 (The Ebyte device relies on client side authentication logic 
that can b ...)
+       TODO: check
+CVE-2026-6876 (ServiceNow has remediated a sandbox escape security issue that 
was ide ...)
+       TODO: check
+CVE-2026-69658 (MQTT credentials and control traffic are transmitted in 
cleartext,  ex ...)
+       TODO: check
+CVE-2026-68967 (Bendix EC80 Brake ECUis vulnerable to an out-of-bounds write, 
which co ...)
+       TODO: check
+CVE-2026-68929 (FastGPT is an open-source LLM platform for building AI 
applications on ...)
+       TODO: check
+CVE-2026-67560 (Bendix EC80 Brake ECU  is vulnerable to a stack-based buffer 
overflow, ...)
+       TODO: check
+CVE-2026-66353 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
+       TODO: check
+CVE-2026-65931 (LimeSurvey Community Edition 7.0.5 contains an authenticated 
improper  ...)
+       TODO: check
+CVE-2026-61802 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
+       TODO: check
+CVE-2026-61800 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
+       TODO: check
+CVE-2026-61783 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
+       TODO: check
+CVE-2026-5706 (In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended 
advertisem ...)
+       TODO: check
+CVE-2026-59324 (When an IntegrationFlow uses .fluxTransform() with an 
asynchronous/reo ...)
+       TODO: check
+CVE-2026-59322 (The EmbeddedHeadersJsonMessageMapper defaults to an overly 
permissive  ...)
+       TODO: check
+CVE-2026-59321 (A single ScriptEngine instance is reused for every message on 
a script ...)
+       TODO: check
+CVE-2026-59320 (When a container-level ErrorHandler is configured (the 
mitigation for  ...)
+       TODO: check
+CVE-2026-59319 (RedisChatMemoryRepository.findByMetadata() builds RediSearch 
tag and t ...)
+       TODO: check
+CVE-2026-59317 (DeadLetterPublishingRecovererFactory reads the 
retry_topic-original-ti ...)
+       TODO: check
+CVE-2026-59316 (Spring Authorization Server's default consent page renders 
user-contro ...)
+       TODO: check
+CVE-2026-59315 (The Spring Cloud Config Monitor is susceptible to Denial of 
Service at ...)
+       TODO: check
+CVE-2026-59314 (Applications that build a Content-Disposition header value 
from untrus ...)
+       TODO: check
+CVE-2026-59313 (Spring MVC applications using the functional web framework are 
vulnera ...)
+       TODO: check
+CVE-2026-59311 (A local unprivileged user on the same host can redirect all 
Zip/UnZip  ...)
+       TODO: check
+CVE-2026-59307 (An operator who calls JdbcMessageStore.addAllowedPatterns(...) 
to rest ...)
+       TODO: check
+CVE-2026-59306 (Potential for deserialization of untrusted types in Spring 
Cloud Strea ...)
+       TODO: check
+CVE-2026-59305 (Partition interceptor may be improperly added while sending 
message. S ...)
+       TODO: check
+CVE-2026-59304 (Improper caching of the original content type in Spring Cloud 
Stream A ...)
+       TODO: check
+CVE-2026-59303 (Dynamic destination cache size is not properly bound in Spring 
Cloud S ...)
+       TODO: check
+CVE-2026-59302 (Potential for logging sensitive data in Spring Cloud Stream. 
Spring Cl ...)
+       TODO: check
+CVE-2026-59301 (Potential for logging sensitive data in Spring Cloud Function 
Azure. S ...)
+       TODO: check
+CVE-2026-59300 (Potential for logging sensitive data in Spring Cloud Function 
AWS. Spr ...)
+       TODO: check
+CVE-2026-59299 (Composition lookup can potentially poison base function in 
Spring Clou ...)
+       TODO: check
+CVE-2026-59298 (Potential for improper filtering of HTTP headers in Spring 
Cloud Funct ...)
+       TODO: check
+CVE-2026-59297 (Implementation of isSecure() call of 
ServerlessHttpServletRequest does ...)
+       TODO: check
+CVE-2026-59294 (ResourceCacheService.getCacheName() builds the on-disk 
filename by app ...)
+       TODO: check
+CVE-2026-59293 (Unless the application explicitly raises smbMinVersion, the 
jCIFS clie ...)
+       TODO: check
+CVE-2026-59292 (PropertiesPersistingMetadataStore, the default file-based 
ConcurrentMe ...)
+       TODO: check
+CVE-2026-59291 (Potential arbitrary file read and SSRF vulnerability in Spring 
Cloud F ...)
+       TODO: check
+CVE-2026-59289 (Spring for GraphQL's Spring Data pagination support resolves 
arguments ...)
+       TODO: check
+CVE-2026-59288 (The GraphiQL page bundled with Spring for GraphQL sends 
requests to th ...)
+       TODO: check
+CVE-2026-59287 (Spring for GraphQL is vulnerable to Denial of Service attacks 
when usi ...)
+       TODO: check
+CVE-2026-59286 (The GraphiQL page bundled with Spring for GraphQL loads 
JavaScript lib ...)
+       TODO: check
+CVE-2026-59285 (Spring for GraphQL applications are vulnerable to Unsafe 
Deserializati ...)
+       TODO: check
+CVE-2026-59284 (There is no allow list for property keys when Spring Cloud 
Commons wri ...)
+       TODO: check
+CVE-2026-59283 (Applications that evaluate Spring Expression Language (SpEL) 
expressio ...)
+       TODO: check
+CVE-2026-59282 (Spring Framework applications that use Spring's data binding 
infrastru ...)
+       TODO: check
+CVE-2026-59281 (Spring MVC and WebFlux applications that obtain a data-binding 
Errors  ...)
+       TODO: check
+CVE-2026-59277 (Spring Security's InetAddressMatchers utility provides 
matchInternal() ...)
+       TODO: check
+CVE-2026-59276 (Several components in Spring Security compare 
security-sensitive value ...)
+       TODO: check
+CVE-2026-55758 (CC: Tweaked is a mod for Minecraft which adds programmable 
computers,  ...)
+       TODO: check
+CVE-2026-54732 (libreoffice-convert is a Node.js module for converting office 
document ...)
+       TODO: check
+CVE-2026-54721 (Silverstripe UserForms provides a visual form builder for the 
Silverst ...)
+       TODO: check
+CVE-2026-54718 (Silverstripe Advanced Workflow is a highly configurable 
step-based wor ...)
+       TODO: check
+CVE-2026-54713 (CakePHP Queue is a queue-interop compatible queueing library. 
From 0.1 ...)
+       TODO: check
+CVE-2026-54687 (n8n-nodes-sqlite3 is a node for operating a local SQLite 
database from ...)
+       TODO: check
+CVE-2026-54085 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
+       TODO: check
+CVE-2026-54084 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
+       TODO: check
+CVE-2026-54083 (Wazuh is an open-source security platform providing unified 
XDR and SI ...)
+       TODO: check
+CVE-2026-53580 (Trilium is an open-source hierarchical note-taking 
application. In ver ...)
+       TODO: check
+CVE-2026-53579 (Trilium is an open-source hierarchical note-taking 
application. In ver ...)
+       TODO: check
+CVE-2026-53578 (Trilium is an open-source hierarchical note-taking 
application. In ver ...)
+       TODO: check
+CVE-2026-48996 (Trilium is an open-source hierarchical note-taking 
application. In ver ...)
+       TODO: check
+CVE-2026-47727 (Trilium is an open-source hierarchical note-taking 
application. In ver ...)
+       TODO: check
+CVE-2026-44629 (Improper access control to the Synergis Softwire installation 
folder.  ...)
+       TODO: check
+CVE-2026-3129 (The LiteSpeed Cache plugin for WordPress is vulnerable to 
Stored Cross ...)
+       TODO: check
+CVE-2026-38822 (In openNDS before 11.0.0, the client_params.sh script, invoked 
by the  ...)
+       TODO: check
+CVE-2026-38821 (A heap-based buffer overflow vulnerability exists in openNDS 
before 11 ...)
+       TODO: check
+CVE-2026-38820 (openNDS before 11.0.0 is susceptible to unauthenticated OS 
command exe ...)
+       TODO: check
+CVE-2026-38819 (Multiple memory leaks in openNDS before 11.0.0 allow an 
unauthenticate ...)
+       TODO: check
+CVE-2026-38350 (An integer overflow in the target_sws_fuzzer() function 
(libswscale/ou ...)
+       TODO: check
+CVE-2026-38349 (An integer overflow in the hScale16To19_c() function 
(libswscale/outpu ...)
+       TODO: check
+CVE-2026-38348 (An integer overflow in the libswscale/utils.c component of 
FFmpeg N-12 ...)
+       TODO: check
+CVE-2026-38347 (A heap overflow in the ff_sws_alphablendaway function 
(libswscale/alph ...)
+       TODO: check
+CVE-2026-38346 (An integer overflow in the yuv2planeX_8_c() function 
(libswscale/outpu ...)
+       TODO: check
+CVE-2026-38345 (A Division-by-Zero vulnerability in the 
ff_sws_init_single_context fun ...)
+       TODO: check
+CVE-2026-38344 (A NULL pointer dereference in the get_min_buffer_size function 
(/libsw ...)
+       TODO: check
+CVE-2026-38343 (An integer overflow in the libavfilter/vf_scale.c component of 
FFmpeg  ...)
+       TODO: check
+CVE-2026-37198 (An integer overflow in the SMF component of Open5GS v2.7.6 
allows atta ...)
+       TODO: check
+CVE-2026-37073 (Incorrect access control in /vfm-admin/ajax/sendfiles.php in 
Veno File ...)
+       TODO: check
+CVE-2026-37072 (Veno File Manager Project Veno File Manager Project 4.4.9 is 
vulnerabl ...)
+       TODO: check
+CVE-2026-37071 (Arbitrary File Rename Leading to Privilege Escalation in 
Actions::rena ...)
+       TODO: check
+CVE-2026-37070 (Incorrect access control in /vfm-admin/ajax/streamvid.php in 
Veno File ...)
+       TODO: check
+CVE-2026-37069 (Absolute Path Disclosure in 
/vfm-admin/assets/zipstream/grandt/relativ ...)
+       TODO: check
+CVE-2026-37068 (Arbitrary file write in 
/vfm-admin/index.php?section=translations&acti ...)
+       TODO: check
+CVE-2026-37067 (Incorrect access control in 
/vfm-admin/admin-panel/view/save-cvs.php i ...)
+       TODO: check
+CVE-2026-37066 (Path traversal leading to Arbitrary File Read in 
/vfm-admin/index.php  ...)
+       TODO: check
+CVE-2026-37065 (Veno File Manager Project 4.4.9 is vulnerable to Arbitrary 
File Deleti ...)
+       TODO: check
+CVE-2026-37064 (User enumeration in /vfm-admin/ajax/usr-check.php in Veno File 
Manager ...)
+       TODO: check
+CVE-2026-37012 (A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 
1.0.0 all ...)
+       TODO: check
+CVE-2026-37009 (A SQL injection vulnerability in NL2SQLTool in crewai-tools 
v1.10.2rc1 ...)
+       TODO: check
+CVE-2026-37007 (A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 
allows  ...)
+       TODO: check
+CVE-2026-37006 (A vulnerability in the WebSocket endpoint of gpt-researcher 
v0.14.7 an ...)
+       TODO: check
+CVE-2026-37004 (BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template 
Injecti ...)
+       TODO: check
+CVE-2026-37003 (Agno up to and including 2.5.8 is vulnerable to Remote Code 
Execution  ...)
+       TODO: check
+CVE-2026-36102 (An issue in the inviteController.js component in Bluewave Labs 
Checkma ...)
+       TODO: check
+CVE-2026-35869 (A Command Injection vulnerability exists in the 
bs_SetLimitCli_info fu ...)
+       TODO: check
+CVE-2026-35868 (A Command Injection vulnerability exists in the 
bs_SetLimitCli_info fu ...)
+       TODO: check
+CVE-2026-34620 (DNG SDK versions 1.7.1 2502 and earlier are affected by an 
out-of-boun ...)
+       TODO: check
+CVE-2026-34616 (DNG SDK versions 1.7.1 2502 and earlier are affected by an 
out-of-boun ...)
+       TODO: check
+CVE-2026-30612 (An issue in Time4 Popcorn for Windows <= 6.2.1.18 and 
Time4Popcorn for ...)
+       TODO: check
+CVE-2026-25250 (EAZ EazyFix 12.9 allows a Security Feature Bypass related to a 
"Missin ...)
+       TODO: check
+CVE-2026-19318 (A stack-based buffer overflow vulnerability in the WatchGuard 
Fireware ...)
+       TODO: check
+CVE-2026-19317 (An out-of-bounds read vulnerability in the WatchGuard Fireware 
OS iked ...)
+       TODO: check
+CVE-2026-19316 (A double-free vulnerability in the WatchGuard Fireware OS iked 
process ...)
+       TODO: check
+CVE-2026-19315 (A type confusion vulnerability in the iked process of 
WatchGuard Firew ...)
+       TODO: check
+CVE-2026-19314 (An integer underflow vulnerability in the WatchGuard Fireware 
OS iked  ...)
+       TODO: check
+CVE-2026-19313 (An heap overflow vulnerability in the WatchGuard Fireware OS 
iked proc ...)
+       TODO: check
+CVE-2026-19092 (The Tutor LMS WordPress plugin before 4.0.6 does not prevent 
request d ...)
+       TODO: check
+CVE-2026-18983 (The One User Avatar | User Profile Picture plugin for 
WordPress is vul ...)
+       TODO: check
+CVE-2026-18978 (The LiteSpeed Cache plugin for WordPress is vulnerable to 
Stored Cross ...)
+       TODO: check
+CVE-2026-18965 (PayRange APIis missing proper authorization on management 
endpoints, w ...)
+       TODO: check
+CVE-2026-18886 (ServiceNow has remediated an improper access control 
vulnerability tha ...)
+       TODO: check
+CVE-2026-18885 (ServiceNow has remediated a code injection vulnerability that 
was iden ...)
+       TODO: check
+CVE-2026-18717 (ASE2000 2.35 through 2.37 is vulnerable to an improper 
certificate val ...)
+       TODO: check
+CVE-2026-18324 (The Forminator Forms \u2013 Contact Form, Payment Form & 
Custom Form B ...)
+       TODO: check
+CVE-2026-17610 (In SiSDK v2026.6.0 and earlier, high network traffic loads can 
cause a ...)
+       TODO: check
+CVE-2026-16759 (The Tutor LMS \u2013 eLearning and online course solution 
plugin for W ...)
+       TODO: check
+CVE-2026-16654 (The Avada (Fusion) Builder plugin for WordPress is vulnerable 
to Store ...)
+       TODO: check
+CVE-2026-15798 (The Smart Slider 3 plugin for WordPress is vulnerable to 
Stored Cross- ...)
+       TODO: check
+CVE-2026-13108 (WatchGuard Dimension is susceptible to a denial-of-service 
condition w ...)
+       TODO: check
+CVE-2026-13086 (A stack-based buffer overflow in the epm (Endpoint Protection 
Manager) ...)
+       TODO: check
+CVE-2026-10036 (SpeechBrain before 1.1.1 contains an arbitrary code execution 
vulnerab ...)
+       TODO: check
+CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially 
crafted JPEG  ...)
        - gdk-pixbuf <unfixed>
        NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278
        NOTE: Introduced with: 
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/4af78023ce7d3b5e3cec422a59bb4f48fa4f5886
 (2.43.4)
@@ -9,7 +413,7 @@ CVE-2026-80489
        [trixie] - glibc <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524870
        NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34568
-CVE-2026-80179
+CVE-2026-80179 (A flaw was found in jwcrypto. A remote attacker can send a 
specially c ...)
        - python-jwcrypto <unfixed>
        NOTE: 
https://github.com/latchset/jwcrypto/security/advisories/GHSA-96rv-c4vc-h4f4
 CVE-2026-81501
@@ -20,7 +424,7 @@ CVE-2026-81500
        - incus 7.0.1-3
        [trixie] - incus <no-dsa> (Minor issue)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-9pqw-c7m4-xvg7
-CVE-2026-18374
+CVE-2026-18374 (Passing an effectively empty string to the `,ccs=` syntax 
extension of ...)
        - glibc <unfixed>
        NOTE: NOTE: 
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015
 CVE-2026-81827 (Affected versions of Flowintel incorrectly attempted to 
validate login ...)
@@ -4664,7 +5068,7 @@ CVE-2026-59564 (An authentication bypass issue exists in 
communications between
        NOT-FOR-US: Zscaler
 CVE-2026-59561 (Sakura Editor provided by Sakura Editor Development Community 
contains ...)
        NOT-FOR-US: Sakura Editor
-CVE-2026-59295 (Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) 
usage via  ...)
+CVE-2026-59295 (It is possible for outbound HTTP requests using a 
Micrometer-instrumen ...)
        NOT-FOR-US: io.micrometer:micrometer-core
 CVE-2026-59230 (Improper input validation vulnerability in Apache Camel.    
This issue ...)
        NOT-FOR-US: Apache software not packaged in Debian
@@ -6112,31 +6516,31 @@ CVE-2026-76137 (Missing authentication for critical 
function vulnerability exist
 CVE-2026-76131 (Use of hard-coded credentials issue exists in VOCALOID6 , 
which may al ...)
        NOT-FOR-US: VOCALOID6
 CVE-2026-76023 (Improper resource control in Linux Toolkit Theming in Google 
Chrome pr ...)
-       {DSA-6476-1}
+       {DSA-6476-1 DLA-4758-1}
        - chromium 151.0.7922.173-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76022 (Buffer overflow in Network in Google Chrome prior to 
151.0.7922.173 al ...)
-       {DSA-6476-1}
+       {DSA-6476-1 DLA-4758-1}
        - chromium 151.0.7922.173-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76021 (Use after free in DOM in Google Chrome prior to 151.0.7922.173 
allowed ...)
-       {DSA-6476-1}
+       {DSA-6476-1 DLA-4758-1}
        - chromium 151.0.7922.173-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76020 (Race condition in V8 in Google Chrome prior to 151.0.7922.173 
allowed  ...)
-       {DSA-6476-1}
+       {DSA-6476-1 DLA-4758-1}
        - chromium 151.0.7922.173-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76019 (Incorrect authorization in Workers in Google Chrome prior to 
151.0.792 ...)
-       {DSA-6476-1}
+       {DSA-6476-1 DLA-4758-1}
        - chromium 151.0.7922.173-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76018 (Privilege elevation in Import in Google Chrome prior to 
151.0.7922.173 ...)
-       {DSA-6476-1}
+       {DSA-6476-1 DLA-4758-1}
        - chromium 151.0.7922.173-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-76017 (Use after free in Chromoting in Google Chrome prior to 
151.0.7922.173  ...)
-       {DSA-6476-1}
+       {DSA-6476-1 DLA-4758-1}
        - chromium 151.0.7922.173-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-75946 (A potential security vulnerability has been identified in the 
OMEN Gam ...)
@@ -8273,19 +8677,19 @@ CVE-2026-XXXX [arbitrary code execution upon opening 
file]
        NOTE: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=80574#227
        NOTE: Mitigated by: 
https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-31&id=8466eb44991707d128110bdc549fad14c8e1d61e
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=c1337758a6c00e22e2a685e0556068fd73fa9a54
-CVE-2025-30156
+CVE-2025-30156 (Ceph is an open-source distributed storage platform providing 
object,  ...)
        - ceph 20.2.4+ds-1 (bug #1144947)
        NOTE: 
https://github.com/ceph/ceph/security/advisories/GHSA-7q3q-3975-qw3q
        NOTE: https://docs.ceph.com/en/latest/security/CVE-2025-30156/
-CVE-2026-54330
+CVE-2026-54330 (Ceph is an open-source distributed storage platform providing 
object,  ...)
        - ceph 20.2.4+ds-1 (bug #1144947)
        NOTE: 
https://github.com/ceph/ceph/security/advisories/GHSA-rmjq-ffrm-j6vj
        NOTE: https://docs.ceph.com/en/latest/security/CVE-2026-54330/
-CVE-2026-50152
+CVE-2026-50152 (Ceph is an open-source distributed storage platform providing 
object,  ...)
        - ceph 20.2.4+ds-1 (bug #1144947)
        NOTE: 
https://github.com/ceph/ceph/security/advisories/GHSA-rg9p-5xcp-wm8h
        NOTE: https://docs.ceph.com/en/latest/security/CVE-2026-50152/
-CVE-2026-39944
+CVE-2026-39944 (Ceph is an open-source distributed storage platform providing 
object,  ...)
        - ceph 20.2.4+ds-1 (bug #1144947)
        NOTE: 
https://github.com/ceph/ceph/security/advisories/GHSA-j73r-qrgx-jvq2
        NOTE: https://docs.ceph.com/en/latest/security/CVE-2026-39944/
@@ -11084,7 +11488,7 @@ CVE-2026-15421 (The Speed Optimizer \u2013 The 
All-In-One Performance-Boosting P
        NOT-FOR-US: WordPress plugin
 CVE-2026-15316 (An improper input validation vulnerability in the 
configuration servic ...)
        NOT-FOR-US: TPLink
-CVE-2026-15315 (Tapo C200 v5 contains an improper authentication vulnerability 
within  ...)
+CVE-2026-15315 (Tapo C120 v1 and C200 v5 contain an improper authentication 
vulnerabil ...)
        NOT-FOR-US: TPLink
 CVE-2026-15253 (The Easy Media Replace WordPress plugin through 0.2.0 does not 
sanitis ...)
        NOT-FOR-US: WordPress plugin
@@ -32116,10 +32520,12 @@ CVE-2026-81499 [GHSA-6v6x-387m-rj4w: Project 
restriction bypass on network addre
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-6v6x-387m-rj4w
        NOTE: https://github.com/lxc/incus/pull/3750
 CVE-2026-81495 [GHSA-67qw-68v3-36h6: Arbitrary file write on host via path 
traversal in custom volume import]
+       {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-67qw-68v3-36h6
        NOTE: https://github.com/lxc/incus/pull/3750
 CVE-2026-81496 [GHSA-26gp-p5fw-3r2h: Arbitrary file write on host via path 
traversal in instance backup import]
+       {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-26gp-p5fw-3r2h
        NOTE: https://github.com/lxc/incus/pull/3750
@@ -32129,10 +32535,12 @@ CVE-2026-81494 [GHSA-7fj9-65v4-rp7h: Arbitrary file 
write on host via image-plan
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-7fj9-65v4-rp7h
        NOTE: https://github.com/lxc/incus/pull/3750
 CVE-2026-81497 [GHSA-4qxq-p5hm-3q3p: Arbitrary host file read+write via VM 
template path traversal]
+       {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-4qxq-p5hm-3q3p
        NOTE: https://github.com/lxc/incus/pull/3750
 CVE-2026-81493 [GHSA-p2v3-6wvc-cv3p: Arbitrary file write on host via image 
fingerprint path traversal]
+       {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-p2v3-6wvc-cv3p
        NOTE: https://github.com/lxc/incus/pull/3750
@@ -32147,6 +32555,7 @@ CVE-2026-63125 (Incus is a system container and virtual 
machine manager. Prior t
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-6rqx-22hc-qm36
        NOTE: https://github.com/lxc/incus/pull/3750
 CVE-2026-81498 [GHSA-m3j6-p3v3-qmjv: Container configuration newline injection 
through nvidia.driver.capabilities]
+       {DSA-6407-1}
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-m3j6-p3v3-qmjv
        NOTE: https://github.com/lxc/incus/pull/3750
@@ -116847,8 +117256,8 @@ CVE-2026-4429 (The OSM \u2013 OpenStreetMap plugin 
for WordPress is vulnerable t
        NOT-FOR-US: WordPress plugin
 CVE-2026-4402
        REJECTED
-CVE-2026-4398
-       REJECTED
+CVE-2026-4398 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
 CVE-2026-4336 (The Ultimate FAQ Accordion plugin for WordPress is vulnerable 
to Store ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-4332 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
@@ -168053,7 +168462,7 @@ CVE-2025-13999 (The HTML5 Audio Player \u2013 The 
Ultimate No-Code Podcast, MP3
        NOT-FOR-US: WordPress plugin
 CVE-2025-13941 (A local privilege escalation vulnerability exists in the Foxit 
PDF Rea ...)
        NOT-FOR-US: Foxit
-CVE-2025-13911 (The vulnerability affects Ignition SCADA applications where 
Python  sc ...)
+CVE-2025-13911 (Ignition by Inductive Automation, when installed with default 
OS servi ...)
        NOT-FOR-US: Ignition SCADA
 CVE-2025-13754 (The Appointment Booking Calendar \u2014 Simply Schedule 
Appointments B ...)
        NOT-FOR-US: WordPress plugin



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9540cfc988d8580243d4cb6cf9f67f4072f7a5a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9540cfc988d8580243d4cb6cf9f67f4072f7a5a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to