Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b0e38878 by security tracker role at 2026-09-01T19:13:00+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,104 +1,530 @@
-CVE-2026-84145
+CVE-2026-9637 (A denial-of-service security issue exists in the affected Logix 
platfo ...)
+       TODO: check
+CVE-2026-9634 (A security issue exists within the Redundancy Module 
Configuration Too ...)
+       TODO: check
+CVE-2026-9633 (A security issue exists within the Redundancy Module 
Configuration Too ...)
+       TODO: check
+CVE-2026-9625 (A denial-of-service security issue exists within RSLinx\xae 
Classic. A ...)
+       TODO: check
+CVE-2026-9624 (A denial-of-service security issue exists within RSLinx\xae 
Classic. A ...)
+       TODO: check
+CVE-2026-9622 (A denial-of-service security issue exists within RSLinx\xae 
Classic. A ...)
+       TODO: check
+CVE-2026-9621 (A denial-of-service security issue exists within RSLinx\xae 
Classic. T ...)
+       TODO: check
+CVE-2026-8712 (Wyoming before 1.10.2 contains a server-side request forgery 
vulnerabi ...)
+       TODO: check
+CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
+       TODO: check
+CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 
1.83.1, in ...)
+       TODO: check
+CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 
1.83.1, th ...)
+       TODO: check
+CVE-2026-84270 (A flaw was found in the MTP backend in gvfs. When reading a 
file from  ...)
+       TODO: check
+CVE-2026-84269 (A flaw was found in the AFP backend in gvfs. When mounting a 
share, a  ...)
+       TODO: check
+CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a 
share an ...)
+       TODO: check
+CVE-2026-84267 (A flaw was found in the SFTP backend in gvfs. When mounting a 
share, a ...)
+       TODO: check
+CVE-2026-84235 (A denial-of-service security issue exists in the affected 
product. The ...)
+       TODO: check
+CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a 
specially cra ...)
+       TODO: check
+CVE-2026-84232 (A flaw was found in pulpcore's content serving application. 
Files uplo ...)
+       TODO: check
+CVE-2026-84218 (A flaw was found in Jolokia's JSR-160 proxy functionality 
where insuff ...)
+       TODO: check
+CVE-2026-84207 (Heym before 0.0.98 fails to apply SSRF egress guards to 
WebSocket Send ...)
+       TODO: check
+CVE-2026-84206 (Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on 
the ass ...)
+       TODO: check
+CVE-2026-84205 (GROWI contains an access control vulnerability in the GET 
/_api/v3/rev ...)
+       TODO: check
+CVE-2026-84204 (GROWI contains an access control vulnerability in the GET 
/_api/v3/att ...)
+       TODO: check
+CVE-2026-84203 (Memos versions 0.26.0 through 0.30.0 fail to revoke refresh 
tokens whe ...)
+       TODO: check
+CVE-2026-84202 (ModelScope uses PyYAML's unsafe yaml.Loader to parse model 
configurati ...)
+       TODO: check
+CVE-2026-84201 (appium-mcp-server through 0.1.61 fails to validate or 
normalize file p ...)
+       TODO: check
+CVE-2026-84200 (Kyverno versions v1.9.0 through v1.12.7 contain a policy 
exception han ...)
+       TODO: check
+CVE-2026-84199 (Kyverno before 1.16.2 contains a server-side request forgery 
(SSRF) vu ...)
+       TODO: check
+CVE-2026-84196 (Kyverno before 1.18.0 contains a server-side request forgery 
vulnerabi ...)
+       TODO: check
+CVE-2026-84195 (Kyverno before 1.16.4 automatically attaches the admission 
controller' ...)
+       TODO: check
+CVE-2026-84194 (LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) 
contain an ...)
+       TODO: check
+CVE-2026-84193 (LibreNMS through 26.2.0 contains a stored cross-site scripting 
vulnera ...)
+       TODO: check
+CVE-2026-84192 (LibreNMS before 26.3.1 contains a stored cross-site scripting 
vulnerab ...)
+       TODO: check
+CVE-2026-84191 (LibreNMS before 26.5.0 contains stored cross-site scripting 
vulnerabil ...)
+       TODO: check
+CVE-2026-84190 (LibreNMS versions before 26.5.0 contain a remote code 
execution vulner ...)
+       TODO: check
+CVE-2026-84189 (LibreNMS through 26.4.0 renders JSON fields (name, ip, model, 
author,  ...)
+       TODO: check
+CVE-2026-84188 (LibreNMS versions <= 26.4.0 contain a stored cross-site 
scripting vuln ...)
+       TODO: check
+CVE-2026-84187 (AVideo contains a missing authentication vulnerability in 
plugin/Live/ ...)
+       TODO: check
+CVE-2026-84165 (A vulnerability relating to incorrect access control in 
OpenNebula by  ...)
+       TODO: check
+CVE-2026-84153 (A vulnerability was determined in Xinhu Rainrock RockOA up to 
2.3.2. T ...)
+       TODO: check
+CVE-2026-84149 (This vulnerability exists in the ERP system due to exposure of 
reposit ...)
+       TODO: check
+CVE-2026-84148 (This vulnerability exists in the ERP system due to improper 
authentica ...)
+       TODO: check
+CVE-2026-84147 (This vulnerability exists in the ERP system due to improper 
authentica ...)
+       TODO: check
+CVE-2026-84115 (A vulnerability was found in Cleo Harmony up to 5.8.1.10. The 
affected ...)
+       TODO: check
+CVE-2026-84114 (A vulnerability has been found in Cleo Harmony up to 5.8.1.10. 
Impacte ...)
+       TODO: check
+CVE-2026-84111 (A flaw has been found in Chanjet CRM up to 20260707. This 
issue affect ...)
+       TODO: check
+CVE-2026-84110 (A vulnerability was detected in Releasit Releasit COD Form & 
Upsells v ...)
+       TODO: check
+CVE-2026-84109 (A weakness has been identified in Xinhu Rainrock RockOA up to 
2.7.6. A ...)
+       TODO: check
+CVE-2026-84061 (A security flaw has been discovered in zhongyu09 OpenChatBI up 
to 0.3. ...)
+       TODO: check
+CVE-2026-84059 (A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 
20260704. T ...)
+       TODO: check
+CVE-2026-83619 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83618 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83617 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83616 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83615 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83614 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83613 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83612 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83611 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83610 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83609 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83608 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83607 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83606 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83605 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 
2 Core)  ...)
+       TODO: check
+CVE-2026-83595 (AVideo contains a cross-site request forgery vulnerability in 
plugin/A ...)
+       TODO: check
+CVE-2026-83557 (DefaultBaseTypeLimitingValidator is the 
PolymorphicTypeValidator appli ...)
+       TODO: check
+CVE-2026-83551 (Cleartext storage of sensitive information in the @step and 
@remote de ...)
+       TODO: check
+CVE-2026-82927 (Untrusted pointer dereference vulnerability in Samsung Open 
Source mTo ...)
+       TODO: check
+CVE-2026-82926 (NULL pointer dereference vulnerability in Samsung Open Source 
mTower a ...)
+       TODO: check
+CVE-2026-80047 (A vulnerability in Hugging Face Transformers (versions >= 
4.49.0 and < ...)
+       TODO: check
+CVE-2026-7877 (The WP Recipe Maker Premium plugin for WordPress is vulnerable 
to Stor ...)
+       TODO: check
+CVE-2026-79687 (Dell PowerStore SDNAS contains a Missing Authentication for 
Critical F ...)
+       TODO: check
+CVE-2026-79686 (Dell PowerStore contains a Protection Mechanism Failure 
vulnerability. ...)
+       TODO: check
+CVE-2026-79685 (Dell PowerStore contains an Argument Injection vulnerability. 
An authe ...)
+       TODO: check
+CVE-2026-79684 (Dell PowerStore contains a Protection Mechanism Failure 
vulnerability. ...)
+       TODO: check
+CVE-2026-79683 (Dell PowerStore contains a Protection Mechanism Failure 
vulnerability. ...)
+       TODO: check
+CVE-2026-79682 (Dell PowerStore contains a Command Injection vulnerability. An 
authent ...)
+       TODO: check
+CVE-2026-78363 (The MW WP Form WordPress plugin before 5.1.5 does not prevent 
shortcod ...)
+       TODO: check
+CVE-2026-78012 (An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 
could allow  ...)
+       TODO: check
+CVE-2026-77194 (The Simple Membership plugin for WordPress is vulnerable to 
Authentica ...)
+       TODO: check
+CVE-2026-76111 (Dell PowerStore contains an Incorrect Authorization 
vulnerability. An  ...)
+       TODO: check
+CVE-2026-75538 (An attacker that connects to an open Erlang TCP port that uses 
the ine ...)
+       TODO: check
+CVE-2026-74994 (The mod_auth module in OTP's inets httpd server, when 
configured with  ...)
+       TODO: check
+CVE-2026-74916 (The WP Fastest Cache WordPress plugin before 1.5.1 does not 
include a  ...)
+       TODO: check
+CVE-2026-74835 (The inets application HTTP server httpd fails to enforce a 
configured  ...)
+       TODO: check
+CVE-2026-73812 (httpd function check_header/3 rejects duplicate Content-Length 
(per CV ...)
+       TODO: check
+CVE-2026-73276 (Gracefulness code ignored cases that should be rejected, 
resulting in  ...)
+       TODO: check
+CVE-2026-73270 (Improper Handling of Case Sensitivity vulnerability in 
Erlang/OTP inet ...)
+       TODO: check
+CVE-2026-71562 (Improper Validation of Specified Quantity in Input 
vulnerability in Er ...)
+       TODO: check
+CVE-2026-71380 (Missing Release of Resource after Effective Lifetime 
vulnerability in  ...)
+       TODO: check
+CVE-2026-70409 (Improper Validation of Specified Quantity in Input 
vulnerability in Er ...)
+       TODO: check
+CVE-2026-70405 (Improper Validation of Specified Quantity in Input 
vulnerability in Er ...)
+       TODO: check
+CVE-2026-70399 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
+       TODO: check
+CVE-2026-69664 (Missing Release of Resource after Effective Lifetime 
vulnerability in  ...)
+       TODO: check
+CVE-2026-66835 (Path Equivalence vulnerability in Erlang/OTP inets httpd 
allows a remo ...)
+       TODO: check
+CVE-2026-66357 (httpd has never implemented obs-fold (RFC 2616 \xa72.2 / RFC 
7230 \xa7 ...)
+       TODO: check
+CVE-2026-61779 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61778 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61777 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61776 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61775 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61774 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61773 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61772 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61771 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61770 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61769 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61768 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61767 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61766 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61765 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61764 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61763 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61762 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61761 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61760 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61759 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61758 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61757 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61756 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61755 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61754 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61753 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61752 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61751 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-61750 (NVIDIA Megatron Bridge contains a vulnerability where an 
attacker coul ...)
+       TODO: check
+CVE-2026-5480
+       REJECTED
+CVE-2026-59696 (Improper Validation of Specified Quantity in Input 
vulnerability in Er ...)
+       TODO: check
+CVE-2026-59681 (A OS command injection vulnerability in yast2-auth-client 
allows an at ...)
+       TODO: check
+CVE-2026-59680 (An OS command injection vulnerability was found in 
yast2-users. When d ...)
+       TODO: check
+CVE-2026-58575 (Dell PowerStore contains an Authentication Bypass by Spoofing 
vulnerab ...)
+       TODO: check
+CVE-2026-58572 (Dell PowerStore contains a Code Injection vulnerability. An 
authentica ...)
+       TODO: check
+CVE-2026-58571 (Dell PowerStore contains an OS Command Injection 
vulnerability. An aut ...)
+       TODO: check
+CVE-2026-58569 (Dell PowerStore contains an Inclusion of Functionality from 
Untrusted  ...)
+       TODO: check
+CVE-2026-58567 (Dell PowerStore contains an OS Command Injection 
vulnerability. An aut ...)
+       TODO: check
+CVE-2026-58566 (Dell PowerStore, an Incorrect Authorization vulnerability. A 
low privi ...)
+       TODO: check
+CVE-2026-55951 (The Erlang/OTP httpc HTTP client does not enforce a limit on 
the total ...)
+       TODO: check
+CVE-2026-53682 (An unauthenticated client can query the Security Domain hosts 
inventor ...)
+       TODO: check
+CVE-2026-52295 (Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows 
an atta ...)
+       TODO: check
+CVE-2026-52132 (llama.cpp through commit 97f06e9, when started with the 
--reranking fl ...)
+       TODO: check
+CVE-2026-52131 (llama.cpp b5693 and before has a Reachable Assertion via the 
gguf_read ...)
+       TODO: check
+CVE-2026-52130 (llama.cpp b5693 and before is vulnerable to Uncontrolled 
Recursion in  ...)
+       TODO: check
+CVE-2026-52111 (An issue in fast-note-sync-service <=2.13.7 allows a remote 
attacker t ...)
+       TODO: check
+CVE-2026-52023 (An issue in kamailio v.6.1.1 and before allows a remote 
attacker to ca ...)
+       TODO: check
+CVE-2026-52022 (An issue in kamailio v.6.1.1 and before allows a remote 
attacker to ca ...)
+       TODO: check
+CVE-2026-51974 (An eval() injection vulnerability in the get_list function in 
modules/ ...)
+       TODO: check
+CVE-2026-51956 (A Broken Object Level Authorization vulnerability exists in 
Grashjs At ...)
+       TODO: check
+CVE-2026-51934 (Buffer Overflow vulnerability in Shenzhen Jixiang Tengda 
Technology Co ...)
+       TODO: check
+CVE-2026-51788 (An issue in cleverange_auth v.0.1.10 allows a remote attacker 
to cause ...)
+       TODO: check
+CVE-2026-51770 (Incorrect access control in the sendToMasterQosConfig function 
of TOTO ...)
+       TODO: check
+CVE-2026-51769 (Incorrect access control in the remoteCloudUpdateCheck 
function of TOT ...)
+       TODO: check
+CVE-2026-51768 (Incorrect access control in the setElinkQosConfig function of 
TOTOLINK ...)
+       TODO: check
+CVE-2026-51767 (Incorrect access control in the recvClearPairCfg function of 
TOTOLINK  ...)
+       TODO: check
+CVE-2026-51766 (Incorrect access control in the setDevReboot function of 
TOTOLINK T6 4 ...)
+       TODO: check
+CVE-2026-51765 (Incorrect access control in the recvIndirectMeshInfo function 
of TOTOL ...)
+       TODO: check
+CVE-2026-51764 (Incorrect access control in the recvSlaveCloudCheckStatus 
function of  ...)
+       TODO: check
+CVE-2026-51763 (Incorrect access control in the freeStaClient function of 
TOTOLINK T6  ...)
+       TODO: check
+CVE-2026-51762 (Incorrect access control in the meshInfoKick function of 
TOTOLINK T6 4 ...)
+       TODO: check
+CVE-2026-51761 (Incorrect access control in the updateLanIp function of 
TOTOLINK T6 4. ...)
+       TODO: check
+CVE-2026-51760 (Incorrect access control in the informSyncUpgfw function of 
TOTOLINK T ...)
+       TODO: check
+CVE-2026-51757 (Incorrect access control in the meshSlaveUpdate function of 
TOTOLINK T ...)
+       TODO: check
+CVE-2026-51756 (Incorrect access control in the meshSlaveUpgfw function of 
TOTOLINK T6 ...)
+       TODO: check
+CVE-2026-51754 (Incorrect access control in the updateSlaveIpList function of 
TOTOLINK ...)
+       TODO: check
+CVE-2026-51752 (Incorrect access control in the staticInfoSend function of 
TOTOLINK T6 ...)
+       TODO: check
+CVE-2026-51751 (Incorrect access control in the delSlaveDevice function of 
TOTOLINK T6 ...)
+       TODO: check
+CVE-2026-51750 (Incorrect access control in the updatePriChannel function of 
TOTOLINK  ...)
+       TODO: check
+CVE-2026-51748 (Incorrect access control in the sendStaticInfoToMaster 
function of TOT ...)
+       TODO: check
+CVE-2026-51747 (Incorrect access control in the keepAlive function of TOTOLINK 
T6 4.1. ...)
+       TODO: check
+CVE-2026-51745 (Incorrect access control in the updatePriStaList function of 
TOTOLINK  ...)
+       TODO: check
+CVE-2026-51744 (Incorrect access control in the recv_mesh_info_sync function 
of TOTOLI ...)
+       TODO: check
+CVE-2026-51743 (Incorrect access control in the guest_wifi_sync function of 
TOTOLINK T ...)
+       TODO: check
+CVE-2026-51742 (Incorrect access control in the discoverWan function of 
TOTOLINK T6 4. ...)
+       TODO: check
+CVE-2026-51741 (Incorrect access control in the clearDiagnosisLog function of 
TOTOLINK ...)
+       TODO: check
+CVE-2026-4813 (A vulnerability in the Lutece Core XSL export management module 
up to  ...)
+       TODO: check
+CVE-2026-49329 (A flaw was found in openshift/oauth-server. The OAuth login 
and error  ...)
+       TODO: check
+CVE-2026-25706 (Improper neutralization of special elements used in an OS 
command in y ...)
+       TODO: check
+CVE-2026-19914 (The Welcart e-Commerce plugin for WordPress is vulnerable to 
Stored Cr ...)
+       TODO: check
+CVE-2026-19593 (OpenAI Codex Desktop for Windows and macOS automatically 
inspected Git ...)
+       TODO: check
+CVE-2026-19592 (OpenAI Codex CLI for Windows, macOS, and Linux and Codex 
Desktop for W ...)
+       TODO: check
+CVE-2026-19591 (OpenAI Codex CLI for Windows, macOS, and Linux and Codex 
Desktop for W ...)
+       TODO: check
+CVE-2026-19590 (OpenAI Codex Desktop for Windows and macOS could execute 
attacker-cont ...)
+       TODO: check
+CVE-2026-19513 (The Gravity Forms plugin for WordPress is vulnerable to 
Arbitrary File ...)
+       TODO: check
+CVE-2026-19472 (A denial-of-service security issue exists within 
ArmorStart\xae LT. Th ...)
+       TODO: check
+CVE-2026-19471 (Multiple stored cross-site scripting security issues exist 
within Armo ...)
+       TODO: check
+CVE-2026-18931 (Use of Hard-coded Credentials vulnerability in TMT Machine 
Industry an ...)
+       TODO: check
+CVE-2026-18808 (Improper Control of Generation of Code ('Code Injection') 
vulnerabilit ...)
+       TODO: check
+CVE-2026-18780 (Cross-Site request forgery (CSRF) vulnerability in TMT Machine 
Industr ...)
+       TODO: check
+CVE-2026-18771 (Missing authentication for critical function vulnerability in 
TMT Mach ...)
+       TODO: check
+CVE-2026-18765 (Improper neutralization of special elements used in an SQL 
command ('S ...)
+       TODO: check
+CVE-2026-18630 (Improper neutralization of special elements used in an SQL 
command ('S ...)
+       TODO: check
+CVE-2026-18550 (The Nokri - Job Board WordPress Theme for WordPress is 
vulnerable to P ...)
+       TODO: check
+CVE-2026-18210 (Improper neutralization of special elements used in an SQL 
command ('S ...)
+       TODO: check
+CVE-2026-16788 (The Live Composer \u2013 Free WordPress Website Builder plugin 
for Wor ...)
+       TODO: check
+CVE-2026-16786 (The Live Composer \u2013 Free WordPress Website Builder plugin 
for Wor ...)
+       TODO: check
+CVE-2026-16675 (A privilege escalation security issue exists within 
FactoryTalk\xae Ac ...)
+       TODO: check
+CVE-2026-15101 (The WPBakery Page Builder plugin for WordPress is vulnerable 
to Stored ...)
+       TODO: check
+CVE-2026-13611 (The KiviCare WordPress plugin before 4.5.5 does not perform 
authorizat ...)
+       TODO: check
+CVE-2026-13348 (CWE-307: Improper Restriction of Excessive Authentication 
Attempts vul ...)
+       TODO: check
+CVE-2026-13337 (CWE-564: SQL Injection: Hibernate vulnerability exists that 
could allo ...)
+       TODO: check
+CVE-2026-13336 (CWE-78: Improper Neutralization of Special Elements used in an 
OS Comm ...)
+       TODO: check
+CVE-2026-12663 (A security issue exists within ControlFLASH\u2122, where the 
installer ...)
+       TODO: check
+CVE-2026-12661 (A denial-of-service security issue exists within 
FactoryTalk\xae Histo ...)
+       TODO: check
+CVE-2026-11873 (An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST 
/ca/res ...)
+       TODO: check
+CVE-2026-10420 (Untrusted pointer dereference vulnerability in Samsung Open 
Source mTo ...)
+       TODO: check
+CVE-2026-10195 (The FS-Poster plugin for WordPress is vulnerable to Remote 
Code Execut ...)
+       TODO: check
+CVE-2025-15613 (Kyverno before v1.13.4 is vulnerable to server-side request 
forgery (S ...)
+       TODO: check
+CVE-2025-12768 (A security issue exists within FactoryTalk\xae Historian 
Machine Editi ...)
+       TODO: check
+CVE-2024-7953 (A vulnerability exists in the affected products that allows a 
threat a ...)
+       TODO: check
+CVE-2024-7952 (A data exposure vulnerability exists in the affected product. 
There ar ...)
+       TODO: check
+CVE-2024-14047 (A local vulnerability in the Winlogbeat Windows installer 
caused runti ...)
+       TODO: check
+CVE-2024-10085 (CWE-770: Allocation of Resources Without Limits or 
Throttlingvulnerabi ...)
+       TODO: check
+CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES 
cipher suites ...)
+       TODO: check
+CVE-2026-84145 (Internally found bugs present in Firefox 154, Firefox ESR 
153.1, Firef ...)
        - firefox <unfixed>
        - firefox-esr <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84145
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84145
-CVE-2026-84144
+CVE-2026-84144 (Internally found bugs present in Firefox 154 and Firefox ESR 
153.1. So ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84144
-CVE-2026-84143
+CVE-2026-84143 (Internally found bugs present in Firefox 154, Firefox ESR 
153.1 and Fi ...)
        - firefox <unfixed>
        - firefox-esr <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84143
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84143
-CVE-2026-84142
+CVE-2026-84142 (Internally found bugs present in Firefox 154. Some of these 
bugs showe ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84142
-CVE-2026-84141
+CVE-2026-84141 (Integer overflow in the Graphics: ImageLib component. This 
vulnerabili ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84141
-CVE-2026-84140
+CVE-2026-84140 (Site isolation issue in the DOM: Navigation component. This 
vulnerabil ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84140
-CVE-2026-84139
+CVE-2026-84139 (Clickjacking issue in the DOM: Events component. This 
vulnerability wa ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84139
-CVE-2026-84138
+CVE-2026-84138 (Denial-of-service in the PDF Viewer component. This 
vulnerability was  ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84138
-CVE-2026-84137
+CVE-2026-84137 (Spoofing issue in the DOM: Core & HTML component. This 
vulnerability w ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84137
-CVE-2026-84136
+CVE-2026-84136 (Other issue in the DOM: Navigation component. This 
vulnerability was f ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84136
-CVE-2026-84135
+CVE-2026-84135 (Other issue in Firefox Focus for Android. This vulnerability 
was fixed ...)
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84135
-CVE-2026-84134
+CVE-2026-84134 (Other issue in the Profile Backup component. This 
vulnerability was fi ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84134
-CVE-2026-84133
+CVE-2026-84133 (Site isolation issue in the DOM: Push Subscriptions component. 
This vu ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84133
-CVE-2026-84132
+CVE-2026-84132 (Information disclosure in the Networking: HTTP component. This 
vulnera ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84132
-CVE-2026-84131
+CVE-2026-84131 (Privilege escalation due to invalid pointer in the Graphics 
component. ...)
        - firefox <unfixed>
        - firefox-esr <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84131
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84131
-CVE-2026-84130
+CVE-2026-84130 (Information disclosure in the Graphics: WebGPU component. This 
vulnera ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84130
-CVE-2026-84129
+CVE-2026-84129 (Site isolation issue in the DOM: Navigation component. This 
vulnerabil ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84129
-CVE-2026-84128
+CVE-2026-84128 (Privilege escalation in the WebDriver BiDi component. This 
vulnerabili ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84128
-CVE-2026-84127
+CVE-2026-84127 (Information disclosure in the WebExtensions component in 
Firefox for A ...)
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84127
-CVE-2026-84126
+CVE-2026-84126 (Incorrect boundary conditions in the Layout: Grid component. 
This vuln ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84126
-CVE-2026-84125
+CVE-2026-84125 (Use-after-free in the DOM: Core & HTML component. This 
vulnerability w ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84125
-CVE-2026-84124
+CVE-2026-84124 (Use-after-free in the DOM: Core & HTML component. This 
vulnerability w ...)
        - firefox <unfixed>
        - firefox-esr <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84124
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84124
-CVE-2026-84123
+CVE-2026-84123 (Privilege escalation due to use-after-free in the Graphics: 
WebGPU com ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84123
-CVE-2026-84122
+CVE-2026-84122 (Use-after-free in the Audio/Video component. This 
vulnerability was fi ...)
        - firefox <unfixed>
        - firefox-esr <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84122
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84122
-CVE-2026-84121
+CVE-2026-84121 (Sandbox escape due to use-after-free in the DOM: Security 
component. T ...)
        - firefox <unfixed>
        - firefox-esr <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84121
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84121
-CVE-2026-84120
+CVE-2026-84120 (Use-after-free in the Audio/Video component. This 
vulnerability was fi ...)
        - firefox <unfixed>
        - firefox-esr <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84120
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84120
-CVE-2026-84119
+CVE-2026-84119 (Sandbox escape due to use-after-free in the DOM: Navigation 
component. ...)
        - firefox <unfixed>
        - firefox-esr <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84119
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84119
-CVE-2026-84118
+CVE-2026-84118 (Use-after-free in the JavaScript: GC component. This 
vulnerability was ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84118
-CVE-2026-84117
+CVE-2026-84117 (Privilege escalation in Firefox for Android. This 
vulnerability was fi ...)
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84117
 CVE-2026-83772 (A vulnerability was detected in Cobham SATCOM VSAT7090 
Maritime Satell ...)
@@ -6842,19 +7268,26 @@ CVE-2026-78684 (vLLM before 0.27.0 fails to properly 
classify DeepStream as a GP
        - vllm <itp> (bug #1095237)
 CVE-2026-78581 (Authorization Bypass Through User-Controlled Key (CWE-639) in 
Kibana c ...)
        - kibana <itp> (bug #700337)
-CVE-2026-78576 (The Readabler plugin for WordPress is vulnerable to SQL 
Injection in a ...)
+CVE-2026-78576
+       REJECTED
        NOT-FOR-US: WordPress plugin
-CVE-2026-78572 (The Kalles Addons plugin for WordPress is vulnerable to PHP 
Object Inj ...)
+CVE-2026-78572
+       REJECTED
        NOT-FOR-US: WordPress plugin
-CVE-2026-78570 (The Total Donations plugin for WordPress is vulnerable to 
Privilege Es ...)
+CVE-2026-78570
+       REJECTED
        NOT-FOR-US: WordPress plugin
-CVE-2026-78568 (The Total Donations plugin for WordPress is vulnerable to SQL 
Injectio ...)
+CVE-2026-78568
+       REJECTED
        NOT-FOR-US: WordPress plugin
-CVE-2026-78566 (The Shuffle theme for WordPress is vulnerable to Local File 
Inclusion  ...)
+CVE-2026-78566
+       REJECTED
        NOT-FOR-US: WordPress plugin
-CVE-2026-78563 (The NotificationX Pro plugin for WordPress is vulnerable to 
Stored Cro ...)
+CVE-2026-78563
+       REJECTED
        NOT-FOR-US: WordPress plugin
-CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local 
File Incl ...)
+CVE-2026-78562
+       REJECTED
        NOT-FOR-US: WordPress plugin
 CVE-2026-78468
        REJECTED
@@ -7449,7 +7882,8 @@ CVE-2026-78551 (RansomLook contains multiple weaknesses 
in its authentication en
        NOT-FOR-US: RansomLook
 CVE-2026-78478 (The Mane theme for WordPress is vulnerable to Local File 
Inclusion in  ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-78477 (The Jawn theme for WordPress is vulnerable to Privilege 
Escalation in  ...)
+CVE-2026-78477
+       REJECTED
        NOT-FOR-US: WordPress plugin
 CVE-2026-78470 (The WP Project Manager Pro plugin for WordPress is vulnerable 
to SQL I ...)
        NOT-FOR-US: WordPress plugin
@@ -15811,7 +16245,7 @@ CVE-2026-28567 (Unauthenticated Broken Access Control 
in WP Sort Order <= 1.3.5
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28192 (Unauthenticated Arbitrary File Upload in Piotnet Addons For 
Elementor  ...)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-28191 (Subscriber Privilege Escalation in The Grid <= 2.7.9.1 
versions.)
+CVE-2026-28191 (Incorrect Privilege Assignment vulnerability in ThemeOne The 
Grid allo ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24301 (Improper neutralization of special elements used in a command 
('comman ...)
        NOT-FOR-US: Microsoft
@@ -52238,26 +52672,32 @@ CVE-2026-49998 (Centrifugo is an open-source scalable 
real-time messaging server
 CVE-2026-47751 (Claude Code Action is a general-purpose GitHub action that 
runs Claude ...)
        NOT-FOR-US: Claude
 CVE-2026-47089 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 
3.12.2. L ...)
+       {DLA-4766-1}
        - cyrus-imapd 3.12.3-1
        [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
        NOTE: 
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47088 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 
3.12.2. T ...)
+       {DLA-4766-1}
        - cyrus-imapd 3.12.3-1
        [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
        NOTE: 
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47087 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 
3.12.2. U ...)
+       {DLA-4766-1}
        - cyrus-imapd 3.12.3-1
        [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
        NOTE: 
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47086 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 
3.12.2. G ...)
+       {DLA-4766-1}
        - cyrus-imapd 3.12.3-1
        [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
        NOTE: 
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47085 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 
3.12.2. U ...)
+       {DLA-4766-1}
        - cyrus-imapd 3.12.3-1
        [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
        NOTE: 
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47084 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 
3.12.2. T ...)
+       {DLA-4766-1}
        - cyrus-imapd 3.12.3-1
        [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
        NOTE: 
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
@@ -52266,10 +52706,12 @@ CVE-2026-47083 (An issue was discovered in 
cyrus-imapd in Cyrus IMAP through 3.1
        [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
        NOTE: 
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47082 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 
3.12.2. T ...)
+       {DLA-4766-1}
        - cyrus-imapd 3.12.3-1
        [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
        NOTE: 
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47081 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 
3.12.2. T ...)
+       {DLA-4766-1}
        - cyrus-imapd 3.12.3-1
        [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
        NOTE: 
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
@@ -128835,7 +129277,7 @@ CVE-2026-24372 (Authentication Bypass by Spoofing 
vulnerability in WP Swings Sub
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24370 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-24369 (Missing Authorization vulnerability in Theme-one The Grid 
the-grid all ...)
+CVE-2026-24369 (Missing Authorization vulnerability in ThemeOne The Grid 
allows Exploi ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24364 (Missing Authorization vulnerability in weDevs WP User Frontend 
wp-user ...)
        NOT-FOR-US: WordPress plugin or theme
@@ -156743,7 +157185,7 @@ CVE-2026-24374 (Cross-Site Request Forgery (CSRF) 
vulnerability in Metagauss Reg
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24371 (Missing Authorization vulnerability in bookingalgorithms BA 
Book Every ...)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-24368 (Missing Authorization vulnerability in Theme-one The Grid 
the-grid all ...)
+CVE-2026-24368 (Missing Authorization vulnerability in ThemeOne The Grid 
allows Exploi ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24367 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
        NOT-FOR-US: WordPress plugin or theme



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0e3887827512e62dfacc543052ede268e782b31

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0e3887827512e62dfacc543052ede268e782b31
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to