Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a0715c8c by security tracker role at 2026-09-02T19:14:52+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,477 @@
+CVE-2026-8151 (The Simple Membership MailChimp Integration WordPress plugin
before 1. ...)
+ TODO: check
+CVE-2026-84841 (A security flaw has been discovered in tsi-coop tsi-dpdp-cms
up to 0.5 ...)
+ TODO: check
+CVE-2026-84840 (A vulnerability was identified in tsi-coop tsi-dpdp-cms up to
0.5.0. T ...)
+ TODO: check
+CVE-2026-84839 (A vulnerability was determined in tsi-coop tsi-dpdp-cms up to
0.5.0. A ...)
+ TODO: check
+CVE-2026-84838 (A flaw was found in rpmuncompress. This command injection
vulnerabilit ...)
+ TODO: check
+CVE-2026-84837 (A flaw was found in rpm. An attacker can exploit a command
injection v ...)
+ TODO: check
+CVE-2026-84835 (Missing Authorization vulnerability in DimaFreund Rentsyst
allows Expl ...)
+ TODO: check
+CVE-2026-84833 (A vulnerability was found in ntegrals openbrowser up to
067fc45d649baa ...)
+ TODO: check
+CVE-2026-84811 (agentverus-scanner fails to analyze compiled Python bytecode
files in ...)
+ TODO: check
+CVE-2026-84810 (claude-skill-antivirus fails to analyze executable files when
scanning ...)
+ TODO: check
+CVE-2026-84809 (Tencent AI-Infra-Guard's skill-scan component excludes
compiled Python ...)
+ TODO: check
+CVE-2026-84808 (Kimai versions before 2.65.0 contain an authorization bypass
vulnerabi ...)
+ TODO: check
+CVE-2026-84807 (Kimai (kimai/kimai) through 2.65.0 contains a business logic /
imprope ...)
+ TODO: check
+CVE-2026-84806 (Kimai before 2.63.0 contains an improper authorization
vulnerability i ...)
+ TODO: check
+CVE-2026-84805 (Kimai versions from 2.61.0 before 2.63.0 fail to disable
admin-only wo ...)
+ TODO: check
+CVE-2026-84804 (Kimai before 2.65.0 fails to properly validate permissions
when removi ...)
+ TODO: check
+CVE-2026-84803 (SiYuan before v3.8.2 contains a stored cross-site scripting
vulnerabil ...)
+ TODO: check
+CVE-2026-84802 (Craft CMS versions from 5.7.0 before 5.10.12 contain an
information di ...)
+ TODO: check
+CVE-2026-84801 (Craft CMS versions before 5.10.11 fail to validate admin
status in the ...)
+ TODO: check
+CVE-2026-84800 (Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a
missing author ...)
+ TODO: check
+CVE-2026-84799 (Craft CMS before 5.11.0 fails to enforce user-group scope
filters on n ...)
+ TODO: check
+CVE-2026-84798 (Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform
an indep ...)
+ TODO: check
+CVE-2026-84797 (Craft CMS versions before 5.10.11 contain an authorization
bypass vuln ...)
+ TODO: check
+CVE-2026-84796 (Craft CMS versions before 5.10.11 contain a site scope bypass
vulnerab ...)
+ TODO: check
+CVE-2026-84795 (Craft CMS before 5.10.11 fails to validate the admin flag
during user ...)
+ TODO: check
+CVE-2026-84794 (Craft CMS versions before 5.10.11 lack authorization checks in
the ass ...)
+ TODO: check
+CVE-2026-84793 (Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a
stored cros ...)
+ TODO: check
+CVE-2026-84792 (Craft CMS versions before 5.10.11 contain a broken access
control vuln ...)
+ TODO: check
+CVE-2026-84781 (Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks
<= 1.3.4 ...)
+ TODO: check
+CVE-2026-84780 (Unauthenticated Denial of Service Attack in WP Go Maps <=
10.1.08 vers ...)
+ TODO: check
+CVE-2026-84775 (Unauthenticated Denial of Service Attack in Really Simple SSL
<= 9.8.0 ...)
+ TODO: check
+CVE-2026-84772 (Editor Server Side Request Forgery (SSRF) in Broken Link
Checker <= 2. ...)
+ TODO: check
+CVE-2026-84771 (Unauthenticated Insecure Direct Object References (IDOR) in
PublishPre ...)
+ TODO: check
+CVE-2026-84770 (Unauthenticated Cross Site Request Forgery (CSRF) in Mang
Board WP <= ...)
+ TODO: check
+CVE-2026-84764 (Unauthenticated Cross Site Request Forgery (CSRF) in Simply
Schedule A ...)
+ TODO: check
+CVE-2026-84760 (Unauthenticated Broken Access Control in Ultimate Gift Cards
For WooCo ...)
+ TODO: check
+CVE-2026-84759 (Unauthenticated Cross Site Request Forgery (CSRF) in Activity
Log <= 2 ...)
+ TODO: check
+CVE-2026-84677 (Jenkins update-center2 3.18.3 and earlier does not escape
plugin-provi ...)
+ TODO: check
+CVE-2026-84676 (Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier
stores t ...)
+ TODO: check
+CVE-2026-84675 (OS command injection vulnerability in Jenkins TICS Plugin
2025.1.1 and ...)
+ TODO: check
+CVE-2026-84674 (Missing permission checks in Jenkins XebiaLabs XL Deploy
Plugin 26.1.0 ...)
+ TODO: check
+CVE-2026-84673 (Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and
earlier al ...)
+ TODO: check
+CVE-2026-84672 (Jenkins Microsoft Entra ID (previously Azure AD) Plugin
710.v0b_ff8e9c ...)
+ TODO: check
+CVE-2026-84671 (Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier
allows w ...)
+ TODO: check
+CVE-2026-84670 (Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier
does not r ...)
+ TODO: check
+CVE-2026-84669 (A path traversal vulnerability in Jenkins Allure Plugin 2.35.2
and ear ...)
+ TODO: check
+CVE-2026-84668 (Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows
overwriti ...)
+ TODO: check
+CVE-2026-84667 (Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting
the plu ...)
+ TODO: check
+CVE-2026-84666 (Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc
and earl ...)
+ TODO: check
+CVE-2026-84665 (Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not
limit URL ...)
+ TODO: check
+CVE-2026-84664 (Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting
the global ...)
+ TODO: check
+CVE-2026-84663 (A cross-site request forgery (CSRF) vulnerability in Jenkins
Pipeline: ...)
+ TODO: check
+CVE-2026-84662 (Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows
connecti ...)
+ TODO: check
+CVE-2026-84661 (A missing permission check in Jenkins Pipeline: Build Step
Plugin 599. ...)
+ TODO: check
+CVE-2026-84660 (A missing permission check in Jenkins Pipeline: Build Step
Plugin 599. ...)
+ TODO: check
+CVE-2026-84659 (Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier
does no ...)
+ TODO: check
+CVE-2026-84658 (Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier
uses th ...)
+ TODO: check
+CVE-2026-84657 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the
build CLI c ...)
+ TODO: check
+CVE-2026-84656 (A missing permission check in Jenkins 2.579 and earlier, LTS
2.568.2 a ...)
+ TODO: check
+CVE-2026-84655 (Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not
escape map ...)
+ TODO: check
+CVE-2026-84654 (In Stapler 2107.v8dfcb_e8ed317 and earlier, except
2088.2093.vd7c3e580 ...)
+ TODO: check
+CVE-2026-84653 (Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1
through 2.56 ...)
+ TODO: check
+CVE-2026-84652 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins
does no ...)
+ TODO: check
+CVE-2026-84651 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the
REST API an ...)
+ TODO: check
+CVE-2026-84650 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier,
transient field ...)
+ TODO: check
+CVE-2026-84649 (In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317
(both inc ...)
+ TODO: check
+CVE-2026-84648 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the
system log ...)
+ TODO: check
+CVE-2026-84647 (In Stapler 2107.v8dfcb_e8ed317 and earlier, except
2088.2093.vd7c3e580 ...)
+ TODO: check
+CVE-2026-84646 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user
objects ca ...)
+ TODO: check
+CVE-2026-84645 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects
of type ...)
+ TODO: check
+CVE-2026-84382 (HTTPX2 is a next generation HTTP client for Python. Prior to
2.12.0, t ...)
+ TODO: check
+CVE-2026-84381 (HTTPX2 is a next generation HTTP client for Python. Prior to
2.10.0, h ...)
+ TODO: check
+CVE-2026-84380 (HTTPX2 is a next generation HTTP client for Python. Prior to
2.11.0, R ...)
+ TODO: check
+CVE-2026-84379 (HTTPX2 is a next generation HTTP client for Python. Prior to
2.11.0, F ...)
+ TODO: check
+CVE-2026-84378 (HTTPX2 is a next generation HTTP client for Python. From 2.5.0
until 2 ...)
+ TODO: check
+CVE-2026-84377 (LiteLLM is a proxy server (AI Gateway) to call LLM APIs in
OpenAI (or ...)
+ TODO: check
+CVE-2026-84376 (Astro is a web framework for content-driven websites. Prior to
7.2.4, ...)
+ TODO: check
+CVE-2026-84217 (Missing Authorization vulnerability in Mamunur Rashid
Classified Listi ...)
+ TODO: check
+CVE-2026-84175 (In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service
fetches W ...)
+ TODO: check
+CVE-2026-83562 (Contributor Cross Site Scripting (XSS) in WCFM Marketplace <=
3.8.2 ve ...)
+ TODO: check
+CVE-2026-83547 (The Xpro Addons WordPress plugin before 1.7.4 does not
properly escape ...)
+ TODO: check
+CVE-2026-83533 (The WP Express Checkout WordPress plugin before 2.4.9 does not
verify ...)
+ TODO: check
+CVE-2026-82958 (In Eclipse Ditto versions [1.3.0, 3.9.6], the
ImplicitThingCreationMes ...)
+ TODO: check
+CVE-2026-82955 (In the current development version of Eclipse aeriOS, which
has not ye ...)
+ TODO: check
+CVE-2026-82884 (The All in One SEO WordPress plugin before 5.0.0.1 does not
sanitise a ...)
+ TODO: check
+CVE-2026-82522 (libjxl before 0.12 contains an integer underflow vulnerability
in the ...)
+ TODO: check
+CVE-2026-82404 (TOON is a compact, human-readable serialization of JSON data
for LLM p ...)
+ TODO: check
+CVE-2026-82293 (Incorrect Authorization (CWE-863) in the Kibana machine
learning featu ...)
+ TODO: check
+CVE-2026-82223 (Unauthenticated Broken Access Control in WP Event SOlution <=
4.1.22 v ...)
+ TODO: check
+CVE-2026-81775 (Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4
version ...)
+ TODO: check
+CVE-2026-81774 (Unauthenticated Sensitive Data Exposure in WooCommerce Product
Attachm ...)
+ TODO: check
+CVE-2026-81772 (Unauthenticated PHP Object Injection in Ninja Forms - Layout &
Styles ...)
+ TODO: check
+CVE-2026-81771 (Unauthenticated Cross Site Scripting (XSS) in TrustedSite <=
1.2.5 ver ...)
+ TODO: check
+CVE-2026-81770 (Unauthenticated Cross Site Scripting (XSS) in Interactive Geo
Maps <= ...)
+ TODO: check
+CVE-2026-81769 (Incorrect Privilege Assignment vulnerability in LiquidThemes
Booking H ...)
+ TODO: check
+CVE-2026-81571 (The Brave WordPress plugin before 0.8.8 does not prevent a URL
paramet ...)
+ TODO: check
+CVE-2026-81294 (Unauthenticated Privilege Escalation in Authorizer <= 3.15.1
versions.)
+ TODO: check
+CVE-2026-81289 (Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player
for Mus ...)
+ TODO: check
+CVE-2026-81288 (Unauthenticated Cross Site Scripting (XSS) in Upsell Order
Bump Offer ...)
+ TODO: check
+CVE-2026-81286 (Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1
versions.)
+ TODO: check
+CVE-2026-81283 (Subscriber PHP Object Injection in WP User Frontend <= 4.3.10
versions ...)
+ TODO: check
+CVE-2026-81269 (Missing Authorization vulnerability in Drupal Data field
allows Forcef ...)
+ TODO: check
+CVE-2026-81205 (Improper Neutralization of Special Elements used in an LDAP
Query ('LD ...)
+ TODO: check
+CVE-2026-81201 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
+ TODO: check
+CVE-2026-81168 (Authentication Bypass Using an Alternate Path or Channel
vulnerability ...)
+ TODO: check
+CVE-2026-81167 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
+ TODO: check
+CVE-2026-81166 (Missing Authorization vulnerability in Drupal Digital Signage
Framewor ...)
+ TODO: check
+CVE-2026-81165 (Incorrect Authorization vulnerability in Drupal Blazy allows
Forceful ...)
+ TODO: check
+CVE-2026-81164 (Missing Authorization vulnerability in Drupal Entity PDF
allows Forcef ...)
+ TODO: check
+CVE-2026-81162 (Insertion of Sensitive Information Into Sent Data
vulnerability in Dru ...)
+ TODO: check
+CVE-2026-81161 (Privilege Defined With Unsafe Actions vulnerability in Drupal
Content ...)
+ TODO: check
+CVE-2026-81160 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
+ TODO: check
+CVE-2026-81159 (Observable Timing Discrepancy vulnerability in Drupal Commerce
CyberSo ...)
+ TODO: check
+CVE-2026-81158 (Incorrect Authorization vulnerability in Drupal Entity API
allows Forc ...)
+ TODO: check
+CVE-2026-79991 (Craft CMS GraphQL entry mutation resolvers
(saveEntry,deleteEntry) rea ...)
+ TODO: check
+CVE-2026-79990 (Craft CMS GraphQL entry mutation resolvers
(saveEntry,deleteEntry) rea ...)
+ TODO: check
+CVE-2026-79989 (The vulnerability allows any authenticated user to change
their own pa ...)
+ TODO: check
+CVE-2026-79756 (Nuclio is a "Serverless" framework for Real-Time Events and
Data Proce ...)
+ TODO: check
+CVE-2026-79755 (Nuclio is a "Serverless" framework for Real-Time Events and
Data Proce ...)
+ TODO: check
+CVE-2026-79754 (Nuclio is a "Serverless" framework for Real-Time Events and
Data Proce ...)
+ TODO: check
+CVE-2026-78689 (Description NGINX JavaScript (njs) has a vulnerability in
the XML mo ...)
+ TODO: check
+CVE-2026-78609 (Incorrect Authorization (CWE-863) in Elastic Cloud on
Kubernetes (ECK) ...)
+ TODO: check
+CVE-2026-78604 (Incorrect Permission Assignment for Critical Resource
(CWE-732) in Ela ...)
+ TODO: check
+CVE-2026-78602 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
+ TODO: check
+CVE-2026-78601 (Missing Authorization (CWE-862) in Kibana can lead to
information disc ...)
+ TODO: check
+CVE-2026-78600 (Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes
(ECK) can ...)
+ TODO: check
+CVE-2026-78599 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
+ TODO: check
+CVE-2026-78598 (Incorrect Authorization (CWE-863) in the Kibana machine
learning featu ...)
+ TODO: check
+CVE-2026-78594 (Improper Handling of Highly Compressed Data (CWE-409) in APM
Server ca ...)
+ TODO: check
+CVE-2026-78591 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
+ TODO: check
+CVE-2026-78590 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
+ TODO: check
+CVE-2026-78588 (Allocation of Resources Without Limits or Throttling (CWE-770)
in File ...)
+ TODO: check
+CVE-2026-78587 (Incorrect Authorization (CWE-863) in Fleet Server can lead to
a denial ...)
+ TODO: check
+CVE-2026-78586 (Allocation of Resources Without Limits or Throttling (CWE-770)
in Kiba ...)
+ TODO: check
+CVE-2026-78584 (Observable Response Discrepancy (CWE-204) in the Kibana
Osquery featur ...)
+ TODO: check
+CVE-2026-78410 (A flaw was found in util-linux. Restricted bind mounts take
the source ...)
+ TODO: check
+CVE-2026-78409 (The X-mount.subdir option uses a detached-tree fast path on
Linux 6.15 ...)
+ TODO: check
+CVE-2026-78408 (The nsenter --join-cgroup option opens the target cgroup.procs
file as ...)
+ TODO: check
+CVE-2026-78222 (A vulnerability exists in NGINX JavaScript where a malformed
HTTP resp ...)
+ TODO: check
+CVE-2026-78153 (The Restrict User Access WordPress plugin before 2.8.1 does
not normal ...)
+ TODO: check
+CVE-2026-77794 (The RegistrationMagic WordPress plugin before 6.0.9.9 does not
validat ...)
+ TODO: check
+CVE-2026-77793 (The RegistrationMagic WordPress plugin before 6.0.9.9 does not
validat ...)
+ TODO: check
+CVE-2026-77180 (When NGINX Ingress Controller is configured with Ingress
annotations, ...)
+ TODO: check
+CVE-2026-77125 (A vulnerability was identified in Sonatype Nexus Repository 3
in which ...)
+ TODO: check
+CVE-2026-77124 (In affected versions of Nexus Repository 3, the script
execution endpo ...)
+ TODO: check
+CVE-2026-77123 (Nexus Repository 3 contains a sensitive information disclosure
vulnera ...)
+ TODO: check
+CVE-2026-77122 (An authorization flaw in the REST API repository details
endpoint (GET ...)
+ TODO: check
+CVE-2026-77121 (A user account with permission to deploy artifacts to a hosted
Maven r ...)
+ TODO: check
+CVE-2026-77009 (The WatchMan-Site7 WordPress plugin through 4.2.0 does not
restrict ac ...)
+ TODO: check
+CVE-2026-76782 (Vulnerability in Drupal Screenshot. This issue affects
Screenshot vers ...)
+ TODO: check
+CVE-2026-76759 (Vulnerability in Drupal Screenshot. This issue affects
Screenshot vers ...)
+ TODO: check
+CVE-2026-76758 (Vulnerability in Drupal Link content parser. This issue
affects Link c ...)
+ TODO: check
+CVE-2026-76757 (Vulnerability in Drupal Gammu SMS Daemon. This issue affects
Gammu SMS ...)
+ TODO: check
+CVE-2026-76756 (Vulnerability in Drupal Gammu SMS Daemon. This issue affects
Gammu SMS ...)
+ TODO: check
+CVE-2026-76755 (Vulnerability in Drupal Gammu SMS Daemon. This issue affects
Gammu SMS ...)
+ TODO: check
+CVE-2026-75528 (The Broken Link Checker plugin for WordPress is vulnerable to
Stored C ...)
+ TODO: check
+CVE-2026-73478 (Incorrect Authorization vulnerability in Drupal Diff allows
Forceful B ...)
+ TODO: check
+CVE-2026-73477 (Incorrect Authorization vulnerability in Drupal Quick Tabs
allows Forc ...)
+ TODO: check
+CVE-2026-73476 (Improper Handling of Case Sensitivity vulnerability in Drupal
External ...)
+ TODO: check
+CVE-2026-73475 (Incorrect Authorization vulnerability in Drupal Commerce
PayPal allows ...)
+ TODO: check
+CVE-2026-73474 (Server-Side Request Forgery (SSRF) vulnerability in Drupal
Entity Shar ...)
+ TODO: check
+CVE-2026-66842 (BIG-IP has a vulnerability where an authenticated user of any
role may ...)
+ TODO: check
+CVE-2026-66652 (Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods
Grand To ...)
+ TODO: check
+CVE-2026-66362 (Description: When NGINX Plus is configured as the data plane
for NGINX ...)
+ TODO: check
+CVE-2026-63020 (A vulnerability exists in an undisclosed BIG-IP Configuration
utility ...)
+ TODO: check
+CVE-2026-55421 (Open edX Platform enables the authoring and delivery of online
learnin ...)
+ TODO: check
+CVE-2026-55221 (Boruta is a standalone authorization server that aims to
implement OAu ...)
+ TODO: check
+CVE-2026-53706 (PREVAIL is a Polynomial-Runtime EBPF Verifier using an
Abstract Interp ...)
+ TODO: check
+CVE-2026-53683 (reset_password.html parses query string parameters and uses
the 'url' ...)
+ TODO: check
+CVE-2026-53671 (PREVAIL is a Polynomial-Runtime EBPF Verifier using an
Abstract Interp ...)
+ TODO: check
+CVE-2026-53670 (PREVAIL is a Polynomial-Runtime EBPF Verifier using an
Abstract Interp ...)
+ TODO: check
+CVE-2026-53649 (Joro is a web exploitation framework. Prior to version 1.1.1,
Joro's d ...)
+ TODO: check
+CVE-2026-53636 (Open edX Platform enables the authoring and delivery of online
learnin ...)
+ TODO: check
+CVE-2026-53635 (Open edX Platform enables the authoring and delivery of online
learnin ...)
+ TODO: check
+CVE-2026-53611 (Looking Glass is a modern, stateless network-diagnostic
platform \u201 ...)
+ TODO: check
+CVE-2026-53600 (async-tar is a tar archive reading/writing library for async
Rust. Pri ...)
+ TODO: check
+CVE-2026-52833 (Nuclio is a "Serverless" framework for Real-Time Events and
Data Proce ...)
+ TODO: check
+CVE-2026-52832 (Nuclio is a "Serverless" framework for Real-Time Events and
Data Proce ...)
+ TODO: check
+CVE-2026-52831 (Nuclio is a "Serverless" framework for Real-Time Events and
Data Proce ...)
+ TODO: check
+CVE-2026-4357 (The Embed HTML5 Game WordPress plugin through 1.3 does not
properly re ...)
+ TODO: check
+CVE-2026-49833 (DSpace open source software is a repository application which
provides ...)
+ TODO: check
+CVE-2026-49832 (DSpace open source software is a repository application which
provides ...)
+ TODO: check
+CVE-2026-49831 (DSpace open source software is a repository application which
provides ...)
+ TODO: check
+CVE-2026-49830 (DSpace open source software is a repository application which
provides ...)
+ TODO: check
+CVE-2026-49249 (Boruta is a standalone authorization server that aims to
implement OAu ...)
+ TODO: check
+CVE-2026-45730 (Nuclio is a "Serverless" framework for Real-Time Events and
Data Proce ...)
+ TODO: check
+CVE-2026-32773 (There is a lack of XSS escaping in the Spark History Server
prior to 3 ...)
+ TODO: check
+CVE-2026-2811 (The Ajaxify Comments WordPress plugin before 3.2 is vulnerable
to HTTP ...)
+ TODO: check
+CVE-2026-2688 (The HIPAA FORMS WordPress plugin before 3.2.0 contains a
hardcoded aut ...)
+ TODO: check
+CVE-2026-23591
+ REJECTED
+CVE-2026-23590
+ REJECTED
+CVE-2026-23589
+ REJECTED
+CVE-2026-23588
+ REJECTED
+CVE-2026-23587
+ REJECTED
+CVE-2026-23586
+ REJECTED
+CVE-2026-23585
+ REJECTED
+CVE-2026-23584
+ REJECTED
+CVE-2026-23583
+ REJECTED
+CVE-2026-20355 (Multiple vulnerabilities in the Secure/Multipurpose Internet
Mail Exte ...)
+ TODO: check
+CVE-2026-20354 (Multiple vulnerabilities in the Secure/Multipurpose Internet
Mail Exte ...)
+ TODO: check
+CVE-2026-20281 (A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP
Phone 7800 a ...)
+ TODO: check
+CVE-2026-20280 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-20279 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-20278 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-20277 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-20276 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-20275 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-20274 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
+ TODO: check
+CVE-2026-20212 (A vulnerability in the Silicon One integration for Cisco Nexus
9000 Se ...)
+ TODO: check
+CVE-2026-19698 (The GutenKit WordPress plugin before 2.5.1 does not validate
or escape ...)
+ TODO: check
+CVE-2026-19475 (An authenticated user with permission to query a SQL data
source can b ...)
+ TODO: check
+CVE-2026-19219 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812,
insuffic ...)
+ TODO: check
+CVE-2026-19117 (Under specific conditions, an attacker can register an
attacker-contro ...)
+ TODO: check
+CVE-2026-18986 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
+ TODO: check
+CVE-2026-18672 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812,
insuffic ...)
+ TODO: check
+CVE-2026-18329 (Description NGINX JavaScript (njs)and QuickJS (qjs)
engineshave a vul ...)
+ TODO: check
+CVE-2026-18058 (The mobile Smart Connect dashboard UI was subject to
manipulation by 3 ...)
+ TODO: check
+CVE-2026-17563 (The User Frontend WordPress plugin before 4.3.11 does not
enforce its ...)
+ TODO: check
+CVE-2026-16647 (Authentication Bypass Using an Alternate Path or Channel
vulnerability ...)
+ TODO: check
+CVE-2026-14828 (Zohocorp ManageEngine Password Manager Pro versions before
13235, PAM3 ...)
+ TODO: check
+CVE-2026-14326 (The Timetics WordPress plugin through 1.0.61 does not enforce
per-obje ...)
+ TODO: check
+CVE-2026-14255 (A maliciously crafted IFC file, when parsed through certain
Autodesk p ...)
+ TODO: check
+CVE-2026-14199 (Only self-managed Grafana instances with Auth Proxy
authentication and ...)
+ TODO: check
+CVE-2026-12704 (When SAML IdP-initiated login is enabled in Grafana
Enterprise, the SA ...)
+ TODO: check
+CVE-2026-10821 (The Yoast SEO Premium WordPress plugin before 27.6.1 does not
sanitize ...)
+ TODO: check
+CVE-2025-9314 (The Developer Tools WordPress plugin through 1.1.3 contains an
unauthe ...)
+ TODO: check
+CVE-2025-8945 (The Wp Edit Password Protected WordPress plugin before 1.3.5
allows pr ...)
+ TODO: check
+CVE-2025-7963 (The Easy Waveform Player plugin for WordPress is vulnerable to
Stored ...)
+ TODO: check
+CVE-2025-15692 (The Icegram Express WordPress plugin before 5.8.6 does not
properly es ...)
+ TODO: check
+CVE-2025-15490 (The Passster WordPress plugin before 4.2.26 has a flaw in its
global p ...)
+ TODO: check
+CVE-2025-15489 (The Passster WordPress plugin before 4.2.24 does not handle
input prop ...)
+ TODO: check
+CVE-2025-15485 (The Auto x LINE WordPress plugin through 1.0.0 does not have
authoriza ...)
+ TODO: check
+CVE-2025-15481 (The Notification Bar for WordPress plugin through 1.1.8
exposes an una ...)
+ TODO: check
+CVE-2025-13398
+ REJECTED
+CVE-2024-7956 (A vulnerability exists in the affected products that allows a
threat a ...)
+ TODO: check
+CVE-2024-3773 (The LiveJournal Shortcode WordPress plugin through 1.1.1 does
not vali ...)
+ TODO: check
+CVE-2023-3360 (The Weaver Show Posts WordPress plugin before 1.8.1
unserialises the c ...)
+ TODO: check
CVE-2026-9055 (The Booking for Appointments and Events Calendar \u2013 Amelia
(Premiu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84715 (FeatherPanel versions before 1.3.7.10 fail to validate
permissions in ...)
@@ -1008,6 +1482,7 @@ CVE-2026-53682 (An unauthenticated client can query the
Security Domain hosts in
- dogtag-pki <removed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2487511
CVE-2026-52295 (Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows
an atta ...)
+ {DSA-6268-1}
- ffmpeg 7:8.1.1-1
[bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988
@@ -2124,7 +2599,7 @@ CVE-2026-82643 (WWBN AVideo contains an unauthenticated
credential submission vu
NOT-FOR-US: WWBN AVideo
CVE-2026-82642 (Readest is an open-source e-book reader built on Tauri. In
versions pr ...)
- readest <itp> (bug #1107071)
-CVE-2026-82641 (keploy versions 3.1.0 through 3.6.25 bind the agent
control-plane HTTP ...)
+CVE-2026-82641 (Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind
the agent ...)
NOT-FOR-US: keploy
CVE-2026-82640 (browser-use web-ui versions 2.0.0 through 3.0.0 write
configured LLM A ...)
NOT-FOR-US: browser-use web-ui
@@ -5326,7 +5801,7 @@ CVE-2026-81203 (A vulnerability has been found in
SourceCodester Simple Online F
CVE-2026-81202 (A flaw has been found in itsourcecode Payroll System 1.0. The
impacted ...)
NOT-FOR-US: itsourcecode System
CVE-2026-80183 (In OpenStack Keystone before 29.0.3, any authenticated user
holding ro ...)
- {DSA-6480-1}
+ {DSA-6480-1 DLA-4767-1}
- keystone 2:29.0.2-2 (bug #1145816)
NOTE: https://launchpad.net/bugs/2154645
CVE-2026-79939 (Dell PowerProtect Cyber Recovery, versions Prior to 20.3,
contain an U ...)
@@ -7826,7 +8301,7 @@ CVE-2026-18331 (The Formidable Forms \u2013 WordPress
Form Builder for Contact F
NOT-FOR-US: WordPress plugin
CVE-2026-18261 (Vulnerability in Drupal Powerful Surveys. This issue affects
Powerful ...)
NOT-FOR-US: Drupal core and addons
-CVE-2026-18260 (Vulnerability in Drupal Disable Login Page. This issue affects
Disable ...)
+CVE-2026-18260 (Improper Restriction of Excessive Authentication Attempts
vulnerabilit ...)
NOT-FOR-US: Drupal core and addons
CVE-2026-18259 (Observable Timing Discrepancy vulnerability in Drupal Token
Content Ac ...)
NOT-FOR-US: Drupal core and addons
@@ -7877,12 +8352,12 @@ CVE-2026-13404 (The Royal Addons for Elementor
WordPress plugin before 1.7.1066
CVE-2026-13172 (The Eventin WordPress plugin before 4.1.22 does not restrict
access t ...)
NOT-FOR-US: WordPress plugin
CVE-2026-80184 (In OpenStack Keystone before 29.0.3, tokens obtained via
delegated aut ...)
- {DSA-6480-1}
+ {DSA-6480-1 DLA-4767-1}
- keystone 2:29.0.2-1 (bug #1145669)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/25/9
NOTE: https://bugs.launchpad.net/keystone/+bug/2158538
CVE-2026-80182 (In OpenStack Keystone before 29.0.3, tokens obtained via
OAuth1 access ...)
- {DSA-6480-1}
+ {DSA-6480-1 DLA-4767-1}
- keystone 2:29.0.2-1 (bug #1145669)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/25/9
NOTE: https://bugs.launchpad.net/keystone/+bug/2153453
@@ -10480,7 +10955,7 @@ CVE-2026-77682 [Use a user message to trigger form
autofill]
[trixie] - epiphany-browser <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/2147
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/epiphany/-/commit/e85444e03490cff1584251028a11d5dfeb3accac
(50.6)
-CVE-2026-66786
+CVE-2026-66786 (A flaw was found in submariner. In cert-auth mode, the
connection conf ...)
NOT-FOR-US: Submariner
CVE-2026-9052
REJECTED
@@ -11107,6 +11582,7 @@ CVE-2026-55015 (Uncontrolled search path element in
Windows Remote Help allows a
CVE-2026-55013 (Uncontrolled search path element in Windows Remote Help
Defense allows ...)
NOT-FOR-US: Microsoft
CVE-2026-54789 (mod_auth_openidc is an OpenID Certified authentication and
authorizati ...)
+ {DLA-4768-1}
- libapache2-mod-auth-openidc 2.4.19.4-1
NOTE:
https://github.com/OpenIDC/mod_auth_openidc/security/advisories/GHSA-vgr5-qcpp-x2pr
NOTE: Fixed by:
https://github.com/OpenIDC/mod_auth_openidc/commit/8017478471cc071c49aa073c5c9be652a73a8630
(v2.4.19.4)
@@ -37585,14 +38061,14 @@ CVE-2024-40683 (IBM Operations Analytics - Log
Analysis 1.3.5.0, 1.3.5.1, 1.3.5.
NOT-FOR-US: IBM
CVE-2024-25039 (IBM Engineering Requirements Management DOORS and DOORS Web
Access 9.7 ...)
NOT-FOR-US: IBM
-CVE-2026-60075 (Date::Manip versions through 6.99 for Perl allow CPU
exhaustion via qu ...)
+CVE-2026-60075 (Date::Manip versions through 7.00 for Perl allow CPU
exhaustion via qu ...)
- libdate-manip-perl 6.99-2 (bug #1143125)
[trixie] - libdate-manip-perl <no-dsa> (Minor issue)
[bookworm] - libdate-manip-perl <postponed> (Minor issue)
[bullseye] - libdate-manip-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42266599/
NOTE:
https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60075-r1.patch
-CVE-2026-60074 (Date::Manip versions through 6.99 for Perl return corrupted
dates via ...)
+CVE-2026-60074 (Date::Manip versions through 7.00 for Perl return corrupted
dates via ...)
- libdate-manip-perl 6.99-2 (bug #1143125)
[trixie] - libdate-manip-perl <no-dsa> (Minor issue)
[bookworm] - libdate-manip-perl <postponed> (Minor issue)
@@ -67657,6 +68133,7 @@ CVE-2026-61626 [GHSA-5gf7-wjfm-vmvm: Out-of-bounds bit
clears for negative Matro
NOTE: Fixed with:
https://github.com/libass/libass/commit/23da65a130bb8c5b2cf0c7df0dd7d424607f98f1
(0.17.5)
NOTE: https://github.com/libass/libass/issues/937
CVE-2026-61627 [GHSA-pjjp-65r7-ppgm: Out-of-bounds read and write in
wrap_lines_measure]
+ {DLA-4769-1}
- libass 1:0.17.5-1
[trixie] - libass 1:0.17.3-1+deb13u1
NOTE:
https://github.com/libass/libass/security/advisories/GHSA-pjjp-65r7-ppgm
@@ -138563,7 +139040,7 @@ CVE-2026-29173 (Craft Commerce is an ecommerce
platform for Craft CMS. Prior to
NOT-FOR-US: Craft Commerce
CVE-2026-29172 (Craft Commerce is an ecommerce platform for Craft CMS. Prior
to 4.10.2 ...)
NOT-FOR-US: Craft Commerce
-CVE-2026-29113 (Craft is a content management system (CMS). Prior to 4.17.4
and 5.9.7, ...)
+CVE-2026-29113 (Craft is a content management system (CMS). Prior to 4.17.3
and 5.9.7, ...)
NOT-FOR-US: Craft CMS
CVE-2026-28495 (GetSimple CMS is a content management system. The massiveAdmin
plugin ...)
NOT-FOR-US: GetSimple CMS
@@ -157839,11 +158316,14 @@ CVE-2026-0769 (Langflow eval_custom_component_code
Eval Injection Remote Code Ex
NOT-FOR-US: Langflow
CVE-2026-0768 (Langflow code Code Injection Remote Code Execution
Vulnerability. This ...)
NOT-FOR-US: Langflow
-CVE-2026-0767 (Open WebUI Cleartext Transmission of Credentials Information
Disclosur ...)
+CVE-2026-0767
+ REJECTED
NOT-FOR-US: Open WebUI
-CVE-2026-0766 (Open WebUI load_tool_module_by_id Command Injection Remote Code
Execut ...)
+CVE-2026-0766
+ REJECTED
NOT-FOR-US: Open WebUI
-CVE-2026-0765 (Open WebUI PIP install_frontmatter_requirements Command
Injection Remo ...)
+CVE-2026-0765
+ REJECTED
NOT-FOR-US: Open WebUI
CVE-2026-0764 (GPT Academic upload Deserialization of Untrusted Data Remote
Code Exec ...)
NOT-FOR-US: GPT Academic
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0715c8cf0a0d8fd06f8dbcdcbe0560a61e956fd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0715c8cf0a0d8fd06f8dbcdcbe0560a61e956fd
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits