Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
0a87d52a by security tracker role at 2026-08-31T19:13:52+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,417 @@
+CVE-2026-83497 (Unrestricted deserialization of untrusted data in the cursor
paginatio ...)
+ TODO: check
+CVE-2026-83492 (Improper input validation vulnerability in Extend Themes Kubio
AI Webs ...)
+ TODO: check
+CVE-2026-82970 (Unrestricted Upload of File with Dangerous Type vulnerability
in WP Le ...)
+ TODO: check
+CVE-2026-82881 (Aix-DB through 1.2.4 renders markdown with raw HTML enabled
into v-htm ...)
+ TODO: check
+CVE-2026-82880 (YaCy Search Server through 1.941 contains an XML external
entity injec ...)
+ TODO: check
+CVE-2026-82879 (DataEase before 2.10.26 contains multiple access control
defects in th ...)
+ TODO: check
+CVE-2026-82878 (DataEase versions before 2.10.26 omit object-level
authorization check ...)
+ TODO: check
+CVE-2026-82877 (ILIAS versions before 9.22, 10.0 through 10.9, and 11.0
through 11.2 c ...)
+ TODO: check
+CVE-2026-82876 (Phison PS3111-S11 controller firmware verifies RSA signatures
using a ...)
+ TODO: check
+CVE-2026-82875 (ToolJet before v3.16.208 contains an authorization bypass
vulnerabilit ...)
+ TODO: check
+CVE-2026-82874 (ToolJet before v3.16.208 fails to validate that authenticated
users be ...)
+ TODO: check
+CVE-2026-82873 (ToolJet through 3.0.0-ee-beta.2 contains authorization bypass
vulnerab ...)
+ TODO: check
+CVE-2026-82872 (ToolJet before v3.16.208 fails to validate that the path
organizationI ...)
+ TODO: check
+CVE-2026-82871 (ToolJet before v3.16.208 fails to validate organization
membership in ...)
+ TODO: check
+CVE-2026-82870 (ToolJet before v3.16.208 fails to validate organizationId
ownership in ...)
+ TODO: check
+CVE-2026-82869 (ToolJet Database versions before v3.16.44 contain a privilege
escalati ...)
+ TODO: check
+CVE-2026-82868 (@pdfme/schemas before 5.5.9 contains a cross-site scripting
vulnerabil ...)
+ TODO: check
+CVE-2026-82867 (@pdfme/schemas before 5.5.9 contains a cross-site scripting
vulnerabil ...)
+ TODO: check
+CVE-2026-82866 (@pdfme/common before 5.5.10 contains a server-side request
forgery vul ...)
+ TODO: check
+CVE-2026-82865 (pdfme schemas before 5.5.10 contains a cross-site scripting
vulnerabil ...)
+ TODO: check
+CVE-2026-82864 (pdfme pdf-lib versions before 5.5.10 contain an unbounded
buffer growt ...)
+ TODO: check
+CVE-2026-82863 (@hulumi/baseline versions before 1.3.2 fail to fully detect
CloudTrail ...)
+ TODO: check
+CVE-2026-82862 (Hulumi versions before v1.3.2 resolve the threat-model helper
script f ...)
+ TODO: check
+CVE-2026-82861 (@hulumi/policies versions before 1.3.2 contain a parent spoof
bypass v ...)
+ TODO: check
+CVE-2026-82860 (@hulumi/policies versions before 1.3.2 fail to fully inspect
inline an ...)
+ TODO: check
+CVE-2026-82859 (hulumi versions before v1.3.2 contain a deployment SCP
template that a ...)
+ TODO: check
+CVE-2026-82858 (@hulumi/drift versions before 1.3.2 accept externally supplied
execute ...)
+ TODO: check
+CVE-2026-82857 (hulumi versions before v1.3.2 contain a privilege escalation
vulnerabi ...)
+ TODO: check
+CVE-2026-82856 (@hulumi/policies versions before 1.3.2 fail to properly
validate set-q ...)
+ TODO: check
+CVE-2026-82855 (@hulumi/policies versions before 1.3.2 contain an evidence
validation ...)
+ TODO: check
+CVE-2026-82854 (Nodemailer before 8.0.4 is vulnerable to SMTP command
injection throug ...)
+ TODO: check
+CVE-2026-82853 (Nodemailer versions before 8.0.5 contain an SMTP command
injection vul ...)
+ TODO: check
+CVE-2026-82838 (The default docker image shipped for Venueless did not
properly ensure ...)
+ TODO: check
+CVE-2026-82823
+ REJECTED
+CVE-2026-82821 (A vulnerability was determined in FLVMeta up to 1.2.2.
Affected by thi ...)
+ TODO: check
+CVE-2026-82820 (A vulnerability was found in FLVMeta up to 1.2.2. Affected is
the func ...)
+ TODO: check
+CVE-2026-82818 (A vulnerability was determined in dibo-software diboot 3.8.0.
This aff ...)
+ TODO: check
+CVE-2026-82817 (A vulnerability was found in dibo-software diboot 3.8.0.
Affected by t ...)
+ TODO: check
+CVE-2026-82816 (A vulnerability has been found in dibo-software diboot 3.8.0.
Affected ...)
+ TODO: check
+CVE-2026-82815 (A flaw has been found in MegaEase EaseProbe up to 2.3.0.
Affected is t ...)
+ TODO: check
+CVE-2026-82813 (A vulnerability was detected in BEN Group TubeBuddy for
YouTube Extens ...)
+ TODO: check
+CVE-2026-82811 (A security vulnerability has been detected in Toggl O\xdc
Toggl Track ...)
+ TODO: check
+CVE-2026-82810 (A weakness has been identified in extension.vn 2FA
Authenticator Exten ...)
+ TODO: check
+CVE-2026-82809 (A security flaw has been discovered in vidIQ Vision for
YouTube Extens ...)
+ TODO: check
+CVE-2026-82808 (A vulnerability was identified in Inbox Foundry ActiveInbox
Extension ...)
+ TODO: check
+CVE-2026-82807 (A vulnerability was determined in ieungSoft Ultra RAMDisk Pro
1.82. Th ...)
+ TODO: check
+CVE-2026-82805 (A vulnerability was found in Typora up to 1.13.8/1.14.6. This
vulnerab ...)
+ TODO: check
+CVE-2026-82803 (A vulnerability has been found in armink struct2json 1.0. This
affects ...)
+ TODO: check
+CVE-2026-82802 (A flaw has been found in NASA earthdata-search 1.0.0. Affected
by this ...)
+ TODO: check
+CVE-2026-82801 (A vulnerability was detected in NASA earthdata-search 1.0.0.
Affected ...)
+ TODO: check
+CVE-2026-82797 (Uncontrolled Recursion vulnerability in Samsung Open Source
rlottie al ...)
+ TODO: check
+CVE-2026-82703 (A security flaw has been discovered in Edimax BR-6214K 1.40.
This vuln ...)
+ TODO: check
+CVE-2026-82702 (A vulnerability was identified in Edimax BR-6214K 1.40. This
affects t ...)
+ TODO: check
+CVE-2026-82701 (A vulnerability was determined in code-projects Online
Shopping System ...)
+ TODO: check
+CVE-2026-82700 (A vulnerability was found in code-projects Online Shopping
System 1.0. ...)
+ TODO: check
+CVE-2026-82699 (A flaw has been found in sambitraj Student Management System
up to 56b ...)
+ TODO: check
+CVE-2026-82698 (A vulnerability was detected in sambitraj
Student-Management-System up ...)
+ TODO: check
+CVE-2026-82697 (A security vulnerability has been detected in sambitraj
Student-Manage ...)
+ TODO: check
+CVE-2026-82696 (A weakness has been identified in itsourcecode Sales and
Inventory Sys ...)
+ TODO: check
+CVE-2026-82695 (A security flaw has been discovered in Tenda AC18 15.03.05.19.
Impacte ...)
+ TODO: check
+CVE-2026-82694 (A vulnerability was identified in Tenda AC1206 15.03.06.23.
This issue ...)
+ TODO: check
+CVE-2026-82693 (A vulnerability was determined in Tenda AC1206 15.03.06.23.
This vulne ...)
+ TODO: check
+CVE-2026-82692 (A vulnerability was found in D-Link DNS-340L and DNS-345 up to
2026071 ...)
+ TODO: check
+CVE-2026-82691 (A vulnerability has been found in D-Link DNS-320L, DNS-327L,
DNS-340L ...)
+ TODO: check
+CVE-2026-82690 (A flaw has been found in D-Link DNS-327L and DNS-340L up to
20260717. ...)
+ TODO: check
+CVE-2026-82689 (A vulnerability was detected in D-Link DNS-320L, DNS-327L,
DNS-340L an ...)
+ TODO: check
+CVE-2026-82688 (A security vulnerability has been detected in D-Link DNS-340L
and DNS- ...)
+ TODO: check
+CVE-2026-82680 (A weakness has been identified in D-Link DSM-G600 1.01. This
affects a ...)
+ TODO: check
+CVE-2026-82679 (A security flaw has been discovered in diem-project diem up to
5.1.3. ...)
+ TODO: check
+CVE-2026-82678 (A vulnerability was identified in diem-project diem up to
5.1.3. The a ...)
+ TODO: check
+CVE-2026-82677 (A vulnerability was determined in valkey-io valkey 9.1.0.
Impacted is ...)
+ TODO: check
+CVE-2026-82671 (A vulnerability has been found in IObit Unlocker 1.3.0.12.
This vulner ...)
+ TODO: check
+CVE-2026-82670 (A flaw has been found in IObit Uninstaller 15.5.0.11. This
affects the ...)
+ TODO: check
+CVE-2026-82669 (A vulnerability was detected in klaussilveira GitList 2.0.0.
Affected ...)
+ TODO: check
+CVE-2026-82668 (A security vulnerability has been detected in klaussilveira
GitList 2. ...)
+ TODO: check
+CVE-2026-82667 (A vulnerability has been found in yaojingang GEOFlow up to
2.1.0. Impa ...)
+ TODO: check
+CVE-2026-82666 (A flaw has been found in yaojingang GEOFlow up to 2.1.0. This
issue af ...)
+ TODO: check
+CVE-2026-82665 (A vulnerability was detected in yaojingang GEOFlow up to
2.1.0. This v ...)
+ TODO: check
+CVE-2026-82664 (A security vulnerability has been detected in yaojingang
GEOFlow up to ...)
+ TODO: check
+CVE-2026-82662 (Nodemailer before 8.0.8 disables TLS certificate verification
in lib/f ...)
+ TODO: check
+CVE-2026-82661 (Nodemailer before 8.0.9 fails to sanitize carriage return and
line fee ...)
+ TODO: check
+CVE-2026-82660 (Nodemailer before 8.0.9 fails to enforce disableFileAccess and
disable ...)
+ TODO: check
+CVE-2026-82659 (nodemailer before 9.0.1 fails to apply disableFileAccess and
disableUr ...)
+ TODO: check
+CVE-2026-82631 (A security flaw has been discovered in valkey-io valkey 9.1.0.
The aff ...)
+ TODO: check
+CVE-2026-82630 (A vulnerability was identified in PowerJob up to 5.1.2.
Impacted is th ...)
+ TODO: check
+CVE-2026-82629 (A vulnerability was determined in jeecgboot jeewx-boot up to
641ab52c3 ...)
+ TODO: check
+CVE-2026-82217 (In Eclipse Theia versions 1.73.0 up to but not including
1.75.0, the A ...)
+ TODO: check
+CVE-2026-81624 (Undertow is a flexible performant web server used in JBoss EAP
and Wil ...)
+ TODO: check
+CVE-2026-79750 (MCPHub is a unified hub for centrally managing and dynamically
orchest ...)
+ TODO: check
+CVE-2026-79749 (MCPHub is a unified hub for centrally managing and dynamically
orchest ...)
+ TODO: check
+CVE-2026-79748 (MCPHub is a unified hub for centrally managing and dynamically
orchest ...)
+ TODO: check
+CVE-2026-79747 (MCPHub is a unified hub for centrally managing and dynamically
orchest ...)
+ TODO: check
+CVE-2026-79746 (MCPHub is a unified hub for centrally managing and dynamically
orchest ...)
+ TODO: check
+CVE-2026-79745 (MCPHub is a unified hub for centrally managing and dynamically
orchest ...)
+ TODO: check
+CVE-2026-79744 (MCPHub is a unified hub for centrally managing and dynamically
orchest ...)
+ TODO: check
+CVE-2026-79743 (MCPHub is a unified hub for centrally managing and dynamically
orchest ...)
+ TODO: check
+CVE-2026-78422 (Subject::new_for_owner() in the zbus_polkit crate encodes the
uid entr ...)
+ TODO: check
+CVE-2026-78079 (Joomla Extension - joomshaper.com - Open Redirect via Base64
Return Pa ...)
+ TODO: check
+CVE-2026-78078 (Joomla Extension - joomshaper.com - Privileged File Upload
Bypass via ...)
+ TODO: check
+CVE-2026-78077 (Joomla Extension - joomshaper.com - Stored Cross-Site
Scripting (XSS) ...)
+ TODO: check
+CVE-2026-78076 (Joomla Extension - joomshaper.com - Broken Access Control &
Missing Au ...)
+ TODO: check
+CVE-2026-78075 (Joomla Extension - joomshaper.com - Broken Object-Level
Authorization ...)
+ TODO: check
+CVE-2026-78074 (Joomla Extension - miniorgange.com - Unauthenticated arbitrary
extensi ...)
+ TODO: check
+CVE-2026-77975 (The affected Ebyte product exports administrative
credentials and ot ...)
+ TODO: check
+CVE-2026-77966 (The affectedEbyte productdoes not provide separation between
limited ...)
+ TODO: check
+CVE-2026-76986 (Improper neutralization of input during web page generation in
Apache ...)
+ TODO: check
+CVE-2026-76985 (Improper neutralization of input during web page generation in
Apache ...)
+ TODO: check
+CVE-2026-76984 (Improper neutralization of input during web page generation in
Apache ...)
+ TODO: check
+CVE-2026-76983 (Improper neutralization of input during web page generation in
Apache ...)
+ TODO: check
+CVE-2026-76982 (Improper neutralization of input during web page generation in
Apache ...)
+ TODO: check
+CVE-2026-76763 (A flaw was found in SmallRye GraphQL. The number scalar
coercion for B ...)
+ TODO: check
+CVE-2026-76133 (The affectedEbyte product uses a deprecated hashing
algorithm in an ...)
+ TODO: check
+CVE-2026-75802 (AjaxEditableChoiceLabel in wicket-extensions, when constructed
with a ...)
+ TODO: check
+CVE-2026-75133 (Keep Backup Daily plugin for WordPress before 2.1.4 contains a
sensiti ...)
+ TODO: check
+CVE-2026-75132 (WAPT Server versions 2.6.1.17834 and earlier contains a SQL
injection ...)
+ TODO: check
+CVE-2026-74010 (Missing Authorization vulnerability in John James Jacoby
bbPress allow ...)
+ TODO: check
+CVE-2026-73819 (The affectedEbyte product's vendor configuration utility
permits acc ...)
+ TODO: check
+CVE-2026-72001 (Pangolin before 1.22.0 contains an authentication bypass
vulnerability ...)
+ TODO: check
+CVE-2026-71378 (ResourceIsolationRequestCycleListener protects a Wicket
application ag ...)
+ TODO: check
+CVE-2026-71257 (Apache Wicket enforces the upload limits configured on a form
or uploa ...)
+ TODO: check
+CVE-2026-70449 (Improper validation of resource URL attributes in Apache
Wicket allows ...)
+ TODO: check
+CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2
contains ...)
+ TODO: check
+CVE-2026-63083
+ REJECTED
+CVE-2026-5956 (Improper neutralization of special elements used in an SQL
command ('S ...)
+ TODO: check
+CVE-2026-59111 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-58301 (When Apache Shiro is used with the Jakarta EE integration
module, a lo ...)
+ TODO: check
+CVE-2026-53553 (Goploy is an open-source automation deployment system. Prior
to versio ...)
+ TODO: check
+CVE-2026-53552 (Goploy is an open-source automation deployment system. In
versions 1.1 ...)
+ TODO: check
+CVE-2026-53508 (oasdiff is a command-line and Go package that compares and
detects bre ...)
+ TODO: check
+CVE-2026-53507 (oasdiff-action is a GitHub Action that detects breaking
changes in Ope ...)
+ TODO: check
+CVE-2026-51730 (Incorrect access control in the delWiFiAclRules function of
TOTOLINK T ...)
+ TODO: check
+CVE-2026-51729 (Incorrect access control in the delDevice function of TOTOLINK
T6 4.1. ...)
+ TODO: check
+CVE-2026-51728 (Incorrect access control in the UploadFirmwareFile function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51727 (Incorrect access control in the SystemSettings function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51726 (Incorrect access control in the delParentalRules function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51725 (Incorrect access control in the NTPSyncWithHost function of
TOTOLINK T ...)
+ TODO: check
+CVE-2026-51724 (Incorrect access control in the delSmartQosCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51723 (Incorrect access control in the UploadCustomModule function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51722 (Incorrect access control in the setWiFiRepeaterCfg function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51721 (Incorrect access control in the setPairCfg function of
TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51720 (Incorrect access control in the delIpPortFilterRules function
of TOTOL ...)
+ TODO: check
+CVE-2026-51719 (Incorrect access control in the delUrlFilterRules function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51718 (Incorrect access control in the delStaticDhcpRules function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51717 (Incorrect access control in the setOpModeCfg function of
TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51716 (Incorrect access control in the delPortForwardRules function
of TOTOLI ...)
+ TODO: check
+CVE-2026-51715 (Incorrect access control in the delMacFilterRules function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51714 (Incorrect access control in the setRoamingCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51713 (Incorrect access control in the setManualDialCfg function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51712 (Incorrect access control in the setApWiFiSchCfg function of
TOTOLINK T ...)
+ TODO: check
+CVE-2026-51711 (Incorrect access control in the setWiFiWpsStart function of
TOTOLINK T ...)
+ TODO: check
+CVE-2026-51710 (Incorrect access control in the setParentalRules function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51709 (Incorrect access control in the setWiFiBasicCfg function of
TOTOLINK T ...)
+ TODO: check
+CVE-2026-51708 (Incorrect access control in the setWiFiWpsCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51706 (Incorrect access control in the setSmartQosCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51705 (Incorrect access control in the setWiFiMeshName function of
TOTOLINK T ...)
+ TODO: check
+CVE-2026-51704 (Incorrect access control in the setWiFiMeshConfig function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51703 (Incorrect access control in the setWiFiScheduleCfg function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51702 (Incorrect access control in the setIpPortFilterRules function
of TOTOL ...)
+ TODO: check
+CVE-2026-51701 (Incorrect access control in the setMacFilterRules function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51700 (Incorrect access control in the setWiFiAdvancedCfg function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51699 (Incorrect access control in the setDmzCfg function of TOTOLINK
T6 4.1. ...)
+ TODO: check
+CVE-2026-51698 (Incorrect access control in the setUrlFilterRules function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51697 (Incorrect access control in the setIptvCfg function of
TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51696 (Incorrect access control in the setPortForwardRules function
of TOTOLI ...)
+ TODO: check
+CVE-2026-51695 (Incorrect access control in the setDdnsCfg function of
TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51694 (Incorrect access control in the setStaticDhcpRules function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51693 (Incorrect access control in the setVpnPassCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51692 (Incorrect access control in the setWiFiGuestCfg function of
TOTOLINK T ...)
+ TODO: check
+CVE-2026-51691 (Incorrect access control in the setUploadSetting function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51690 (Incorrect access control in the setWanCfg function of TOTOLINK
T6 4.1. ...)
+ TODO: check
+CVE-2026-51689 (Incorrect access control in the setUpgradeFW function of
TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51688 (Incorrect access control in the setWiFiSignalCfg function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51687 (Incorrect access control in the setWiFiEasyGuestCf function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51686 (Incorrect access control in the setWiFiEasyCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51684 (Incorrect access control in the setStorageCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51683 (Incorrect access control in the setLanCfg function of TOTOLINK
T6 4.1. ...)
+ TODO: check
+CVE-2026-51681 (Incorrect access control in the setRemoteCfg function of
TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51680 (Incorrect access control in the setLedCfg function of TOTOLINK
T6 4.1. ...)
+ TODO: check
+CVE-2026-51679 (Incorrect access control in the setPasswordCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51678 (Incorrect access control in the setSyslogCfg function of
TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51677 (Incorrect access control in the setUPnPCfg function of
TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51676 (Incorrect access control in the setAccessDeviceCfg function of
TOTOLIN ...)
+ TODO: check
+CVE-2026-51675 (Incorrect access control in the setWanIeCfg function of
TOTOLINK T6 4. ...)
+ TODO: check
+CVE-2026-51674 (Incorrect access control in the setScheduleCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51673 (Incorrect access control in the setNtpCfg function of TOTOLINK
T6 4.1. ...)
+ TODO: check
+CVE-2026-51672 (Incorrect access control in the getRoamingCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51671 (Incorrect access control in the getCloudDownloadStatus
function of TOT ...)
+ TODO: check
+CVE-2026-51670 (Incorrect access control in the getSlaveUpdate function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51669 (Incorrect access control in the getPairCfg function of
TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51668 (Incorrect access control in the setLanguageCfg function of
TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51667 (Incorrect access control in the getWiFiIpMacTable function of
TOTOLINK ...)
+ TODO: check
+CVE-2026-51666 (Incorrect access control in the setWizardCfg function of
TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51153 (Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in
web/hand ...)
+ TODO: check
+CVE-2026-51152 (Server-side request forgery (SSRF) in the /har/test endpoint
in QD 202 ...)
+ TODO: check
+CVE-2026-49003 (Attackers can exploit command injection vulnerabilities to
delete core ...)
+ TODO: check
+CVE-2026-21827 (HCL Connections is vulnerable to an information disclosure
vulnerabili ...)
+ TODO: check
+CVE-2026-19702 (Improper neutralization of special elements used in an OS
command ('OS ...)
+ TODO: check
+CVE-2026-19616 (Missing Authorization vulnerability in TBC Technology Inc.
KitLogistic ...)
+ TODO: check
+CVE-2026-19410 (An Incorrect Authorization vulnerability in GitHub Trigger
Comment Con ...)
+ TODO: check
+CVE-2026-17615 (A flaw was found in RESTEasy's SourceProvider. This
vulnerability allo ...)
+ TODO: check
+CVE-2026-14696 (When Ethernet bridging is enabled
(CONFIG_NET_ETHERNET_BRIDGE), eth_br ...)
+ TODO: check
+CVE-2026-14368 (The LwM2M JSON content formatter's get_string() in
subsys/net/lib/lwm2 ...)
+ TODO: check
+CVE-2026-14367 (The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out
statica ...)
+ TODO: check
+CVE-2026-14366 (The Silicon Labs SiWx917 WiFi driver's transmit callback
siwx91x_send( ...)
+ TODO: check
+CVE-2026-12894 (A flaw was found in the Qute template engine, which is used by
Quarkus ...)
+ TODO: check
+CVE-2024-58379 (nodemailer before 6.9.9 contains a regular expression denial
of servic ...)
+ TODO: check
+CVE-2023-31308 (A malicious virtual function can invoke the certain command
handlers i ...)
+ TODO: check
CVE-2026-XXXX [GHSA-fmgr-6ggq-9859: PCRE2: integer overflow in
pcre2_compile_32() causes out-of-bounds write on 32-bit systems]
- pcre2 <unfixed>
NOTE:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859
@@ -18,7 +432,7 @@ CVE-2026-XXXX [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds
read in pcre2_match() a
- pcre2 <unfixed>
NOTE:
https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x
NOTE: Fixed by:
https://github.com/PCRE2Project/pcre2/commit/f67db227af31bba7cdf2a7a00b97af91b588c2f5
pcre2-10.48-RC1)
-CVE-2026-19873
+CVE-2026-19873 (HTML::FormFu versions through 2.08 for Perl allow resource
exhaustion ...)
- libhtml-formfu-perl <unfixed> (bug #1146310)
[trixie] - libhtml-formfu-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43141785/
@@ -2439,6 +2853,7 @@ CVE-2026-38350 (An integer overflow in the
target_sws_fuzzer() function (libswsc
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20060
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aca41d3d9327be4d6ab036f494b700118fcc04e1
(n8.0)
CVE-2026-38349 (An integer overflow in the hScale16To19_c() function
(libswscale/outpu ...)
+ {DSA-6276-1 DSA-6268-1}
- ffmpeg 7:8.1-1
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21592
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22369
@@ -2446,6 +2861,7 @@ CVE-2026-38349 (An integer overflow in the
hScale16To19_c() function (libswscale
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5f9cdf11fc49e41b7a99e2c3f009ef046a9a02d2
(n7.1.4)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4425208158170180b0a574c8161247404445b45b
(n5.1.9)
CVE-2026-38348 (An integer overflow in the libswscale/utils.c component of
FFmpeg N-12 ...)
+ {DSA-6276-1 DSA-6268-1}
- ffmpeg 7:8.1-1
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21588
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22369
@@ -2453,6 +2869,7 @@ CVE-2026-38348 (An integer overflow in the
libswscale/utils.c component of FFmpe
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2e1e4706d40f94669b3812d10523f1410e9c0c10
(n7.1.4)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/35b23b73f259515592445d8cdd142d6296994417
(n5.1.9)
CVE-2026-38347 (A heap overflow in the ff_sws_alphablendaway function
(libswscale/alph ...)
+ {DSA-6361-1}
- ffmpeg 7:8.0.1-2
NOTE: https://trac.ffmpeg.org/ticket/11692
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20063
@@ -2460,6 +2877,7 @@ CVE-2026-38347 (A heap overflow in the
ff_sws_alphablendaway function (libswscal
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/bb88e295394e5db584063bde790bfbdba04d54ec
(n7.1.5)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/7ee2f9004bd292cbe98deea3664dc00223d4275c
(n5.1.10)
CVE-2026-38346 (An integer overflow in the yuv2planeX_8_c() function
(libswscale/outpu ...)
+ {DSA-6276-1 DSA-6268-1}
- ffmpeg 7:8.1-1
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21584
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22365
@@ -2475,6 +2893,7 @@ CVE-2026-38345 (A Division-by-Zero vulnerability in the
ff_sws_init_single_conte
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/21768
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/04fe98482a264117fa49a166c18227f3f93f921b
(n8.1)
CVE-2026-38344 (A NULL pointer dereference in the get_min_buffer_size function
(/libsw ...)
+ {DSA-6276-1 DSA-6268-1}
- ffmpeg 7:8.1-1
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21583
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22365
@@ -2482,6 +2901,7 @@ CVE-2026-38344 (A NULL pointer dereference in the
get_min_buffer_size function (
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/af29ae54a4c9b2d3b3ccb4963f86698c69f28091
(n7.1.4)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ea3290bf6e92b0fd905121ee6fbebf1199f8fd24
(n5.1.9)
CVE-2026-38343 (An integer overflow in the libavfilter/vf_scale.c component of
FFmpeg ...)
+ {DSA-6276-1 DSA-6268-1}
- ffmpeg 7:8.1-1
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21587
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22369
@@ -5538,7 +5958,7 @@ CVE-2026-66422 (Improper Authorization vulnerability in
Apache Tomcat cause by s
NOTE:
https://github.com/apache/tomcat/commit/bd05d5ced387da0c967bb232f7e3cd57685d2a7b
(9.0.121)
CVE-2026-66153 (The NEService auto-upgrade process insecurely handles
temporary files ...)
NOT-FOR-US: SonicWall
-CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the
SonicWall NetE ...)
+CVE-2026-66152 (A Path traversal vulnerability in the SonicWall NetExtender
Linux clie ...)
NOT-FOR-US: SonicWall
CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the
[N] flag ...)
- tomcat11 <unfixed> (bug #1145698)
@@ -6508,7 +6928,7 @@ CVE-2026-63075 (Issue summary: When OpenSSL processes
QUIC traffic from a peer t
NOTE:
https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709
(openssl-3.5.8)
NOTE:
https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393
(openssl-3.4.7)
NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-19953
+CVE-2026-19953 (URI versions before 5.36 for Perl encode non-NFC host names to
non-sta ...)
- liburi-perl 5.36-1
[trixie] - liburi-perl <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/libwww-perl/URI/commit/8c213ff92fdae45d0fabb7bc16f6a6f27e911395
(v5.36)
@@ -16207,12 +16627,12 @@ CVE-2026-15142 (The Real Estate Manager Pro plugin
for WordPress is vulnerable t
CVE-2026-12248 (The WPML Multilingual CMS plugin for WordPress is vulnerable
to SQL In ...)
NOT-FOR-US: WordPress plugin
CVE-2026-73194 (DBI versions before 1.652 for Perl allow a heap out-of-bounds
write vi ...)
- {DSA-6473-1}
+ {DSA-6473-1 DLA-4764-1}
- libdbi-perl 1.652-1 (bug #1144471)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707363/
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/29b72ae7d2a8114a734a55840bf1c45b89207809
(1.652)
CVE-2026-73193 (DBI versions before 1.652 for Perl allow a heap out-of-bounds
write on ...)
- {DSA-6473-1}
+ {DSA-6473-1 DLA-4764-1}
- libdbi-perl 1.652-1 (bug #1144470)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707360/
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/c751ae5a5a6f56c2f8284f37c1f4d43500352ef1
(1.652)
@@ -21724,7 +22144,7 @@ CVE-2026-16815 (IBM i 7.6, 7.5, 7.4, and 7.3 could
allow a remote attacker to ca
NOT-FOR-US: IBM
CVE-2026-16810 (The Bit Form \u2013 Contact Form, Payment Forms, Multi Step
Forms, Cal ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-16739 (The Epeken All Kurir for Woocommerce WordPress plugin through
2.1.2 do ...)
+CVE-2026-16739 (The Epeken All Kurir for Woocommerce WordPress plugin through
2.1.4 do ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16722 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
NOT-FOR-US: IBM
@@ -33889,7 +34309,7 @@ CVE-2026-13506 (In Bouncy Castle for Java before 1.85,
Lazy ASN.1 sequence forci
NOTE: Fixed by:
https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84
(r1rv85)
CVE-2026-13340 (The SVG Support WordPress plugin before 2.5.17 does not apply
its SVG ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-12965 (The Super Store Finder WordPress plugin through 7.8 does not
sanitize ...)
+CVE-2026-12965 (The Super Store Finder WordPress plugin before 7.11 does not
sanitize ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12872 (The Webinfos WordPress plugin through 1.2 does not validate
the type o ...)
NOT-FOR-US: WordPress plugin
@@ -38598,12 +39018,12 @@ CVE-2024-14041 (In Bouncy Castle for Java from 1.73
to before 1.78, three ML-KEM
NOTE: Fixed by:
https://github.com/bcgit/bc-java/commit/5adb2c5c5b462a332b01a012bea0784b40b904e5
(r1rv78v1)
NOTE: Fixed by:
https://github.com/bcgit/bc-java/commit/1590247178f2280defa36421475f015175dfbe9e
(r1rv78v1)
CVE-2026-59986
- {DSA-6447-1}
+ {DSA-6447-1 DLA-4763-1}
- librabbitmq 0.17.0-1
NOTE:
https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-jgjf-7fwf-f3c7
NOTE: Fixed by:
https://github.com/alanxz/rabbitmq-c/commit/1bb1b9b1b7bc69eede6295e95fa9527c731f0798
(v0.17.0)
CVE-2026-61547
- {DSA-6447-1}
+ {DSA-6447-1 DLA-4763-1}
- librabbitmq 0.17.0-1
NOTE:
https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-hfjv-vcp3-39wh
NOTE: Fixed by:
https://github.com/alanxz/rabbitmq-c/commit/02d278663f3a93db9fe4fb4e7e34dc96b83c107b
(v0.17.0)
@@ -46097,6 +46517,7 @@ CVE-2026-21954 (Vulnerability in the Oracle Retail
Xstore Point of Service produ
CVE-2026-21953 (Vulnerability in the Oracle Retail Xstore Point of Service
product of ...)
NOT-FOR-US: Oracle
CVE-2026-16517 (A signed integer overflow vulnerability was found in
libarchive's ZIP ...)
+ {DLA-4762-1}
- libarchive 3.8.9-1 (bug #1142834)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2505492
NOTE: https://github.com/libarchive/libarchive/issues/3225
@@ -54567,19 +54988,19 @@ CVE-2026-15747 (Mojolicious versions from 4.59 before
9.48 for Perl expose a sta
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41816171/
NOTE: Fixed by:
https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27
(v9.48)
CVE-2026-15392 (DBD::File versions before 1.651 for Perl do not ensure the
table file ...)
- {DSA-6473-1}
+ {DSA-6473-1 DLA-4764-1}
- libdbi-perl 1.651-1 (bug #1142072)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813967/
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mh3j-xwf4-jrqw
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/96d62dfe4528bf56fe13f413ed323d4252531728
(1.651)
CVE-2026-60082 (DBI versions before 1.651 for Perl do not enforce statement
handle con ...)
- {DSA-6473-1}
+ {DSA-6473-1 DLA-4764-1}
- libdbi-perl 1.651-1 (bug #1142072)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813803/
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2
(1.651)
CVE-2026-60081 (DBI::ProfileData versions before 1.651 for Perl do not limit
the path ...)
- {DSA-6473-1}
+ {DSA-6473-1 DLA-4764-1}
- libdbi-perl 1.651-1 (bug #1142072)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813962/
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ww49-w4mv-jrr4
@@ -56354,6 +56775,7 @@ CVE-2026-15143 (A flaw was found in the file_type
content detector of guardrails
CVE-2026-15104 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs,
Wikis, F ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15028 (A flaw was found in libarchive. This vulnerability allows a
remote att ...)
+ {DLA-4762-1}
- libarchive 3.8.9-1 (bug #1142833)
[trixie] - libarchive <no-dsa> (Minor issue)
NOTE: https://github.com/libarchive/libarchive/issues/3251
@@ -58058,7 +58480,7 @@ CVE-2026-15053 (Tanium addressed a denial of service
vulnerability in Tanium Ser
CVE-2026-15044 (A flaw was found in the TrustyAI Service Operator. When
deploying serv ...)
NOT-FOR-US: TrustyAI Service Operator
CVE-2026-15043 (DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have
inverted ...)
- {DSA-6473-1}
+ {DSA-6473-1 DLA-4764-1}
- libdbi-perl 1.651-1 (bug #1142072)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41805128/
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp
@@ -58597,18 +59019,18 @@ CVE-2026-14895 (String::Util versions before 1.36 for
Perl are susceptible to a
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625636/
NOTE: Fixed by:
https://github.com/scottchiefbaker/String-Util/commit/f8150867aaeb8f57c59601aefb2193f2caed8745
(v1.36)
CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code
injection vi ...)
- {DSA-6473-1}
+ {DSA-6473-1 DLA-4764-1}
- libdbi-perl 1.650-1 (bug #1141667)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625527/
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259
(1.650)
CVE-2026-14739 (DBI versions before 1.650 for Perl have a heap overflow when
preparsin ...)
- {DSA-6473-1}
+ {DSA-6473-1 DLA-4764-1}
- libdbi-perl 1.650-1 (bug #1141667)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625530/
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395
(1.650)
CVE-2026-14740 (DBI versions before 1.650 for Perl read one byte out-of-bounds
in prep ...)
- {DSA-6473-1}
+ {DSA-6473-1 DLA-4764-1}
- libdbi-perl 1.650-1 (bug #1141667)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625532/
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg
@@ -59389,7 +59811,7 @@ CVE-2026-14801 (A security vulnerability has been
detected in GPAC 26.03-DEV-rev
[bullseye] - gpac <end-of-life> (EOL in bullseye LTS)
CVE-2026-14800 (A weakness has been identified in imhamzaazam ecommerceFlask
up to cb7 ...)
NOT-FOR-US: ecommerceFlask
-CVE-2026-13753 (A missing authorization vulnerability exists in the embedded
webserver ...)
+CVE-2026-13753 (Certain HP DeskJet All-in-One printers may be potentially
vulnerable t ...)
NOT-FOR-US: HP
CVE-2026-12686 (An authenticated user could manipulate a company ID parameter
in a POS ...)
NOT-FOR-US: Adiss Biloop
@@ -64697,6 +65119,7 @@ CVE-2026-31016 (Cross Site Request Forgery
vulnerability in Squidex.io Squidex C
CVE-2026-28979 (An out-of-bounds access issue was addressed with improved
bounds check ...)
NOT-FOR-US: Apple
CVE-2026-14164 (A double free issue has been identified in libarchive's RAR5
reader. D ...)
+ {DLA-4762-1}
- libarchive 3.8.8-1 (bug #1141180)
[trixie] - libarchive <no-dsa> (Minor issue)
NOTE: https://github.com/libarchive/libarchive/issues/3069
@@ -237230,7 +237653,7 @@ CVE-2025-32712 (Use after free in Windows Win32K -
GRFX allows an authorized att
NOT-FOR-US: Microsoft
CVE-2025-32710 (Use after free in Windows Remote Desktop Services allows an
unauthoriz ...)
NOT-FOR-US: Microsoft
-CVE-2025-31104 (An Improper Neutralization of Special Elements used in an OS
Command ( ...)
+CVE-2025-31104 (A improper neutralization of special elements used in an os
command (' ...)
NOT-FOR-US: Fortinet
CVE-2025-30327 (InCopy versions 20.2, 19.5.3 and earlier are affected by an
Integer Ov ...)
NOT-FOR-US: Adobe
@@ -264226,7 +264649,8 @@ CVE-2024-7957 (An arbitrary file overwrite
vulnerability exists in the ZulipConn
NOT-FOR-US: danswer-ai/danswer
CVE-2024-7819 (A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows
attackers ...)
NOT-FOR-US: danswer-ai/danswer
-CVE-2024-7806 (A vulnerability in open-webui/open-webui versions <= 0.3.8
allows remo ...)
+CVE-2024-7806
+ REJECTED
NOT-FOR-US: open-webui/open-webui
CVE-2024-7804
REJECTED
@@ -471305,8 +471729,8 @@ CVE-2023-20513 (An insufficient bounds check in PMFW
(Power Management Firmware)
NOT-FOR-US: AMD
CVE-2023-20512 (A hardcoded AES key in PMFW may result in a privileged
attacker gain ...)
NOT-FOR-US: AMD
-CVE-2023-20511
- RESERVED
+CVE-2023-20511 (Release of an invalid pointer in the AMD kernel mode driver
(KMD) coul ...)
+ TODO: check
CVE-2023-20510 (An insufficient DRAM address validation in PMFW may allow a
privileged ...)
NOT-FOR-US: AMD
CVE-2023-20509 (An insufficient DRAM address validation in PMFW may allow a
privileged ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0a87d52ac0aadcec424107f99af04230a8cac110
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0a87d52ac0aadcec424107f99af04230a8cac110
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits