Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8f1651e2 by security tracker role at 2026-09-08T07:12:49+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,125 @@
+CVE-2026-86544 (knowns versions before 0.30.0 contain an authorization bypass 
vulnerab ...)
+       TODO: check
+CVE-2026-86543 (knowns versions before 0.30.0 serve the management API without 
authent ...)
+       TODO: check
+CVE-2026-86542 (knowns before 0.30.0 fails to validate import names in the 
import rout ...)
+       TODO: check
+CVE-2026-86541 (knowns versions before 0.30.0 contain a path traversal 
vulnerability i ...)
+       TODO: check
+CVE-2026-86540 (knowns versions before 0.30.0 fail to validate the 
settings.lsp.langua ...)
+       TODO: check
+CVE-2026-86539 (knowns through 0.33.0 contains a server-side request forgery 
vulnerabi ...)
+       TODO: check
+CVE-2026-86538 (knowns versions before 0.30.0 contain a path traversal 
vulnerability i ...)
+       TODO: check
+CVE-2026-86519 (A vulnerability was found in code-projects Student Crud 
Operation 1.0. ...)
+       TODO: check
+CVE-2026-86518 (A vulnerability has been found in code-projects Student Crud 
Operation ...)
+       TODO: check
+CVE-2026-86517 (A flaw has been found in itsourcecode Sales and Inventory 
System 1.0.  ...)
+       TODO: check
+CVE-2026-86516 (A vulnerability was detected in elenavanengelenmaslova 
mocknest-server ...)
+       TODO: check
+CVE-2026-86515 (A security vulnerability has been detected in vgmstream up to 
r2117. I ...)
+       TODO: check
+CVE-2026-86514 (A weakness has been identified in vgmstream up to r2117. This 
issue af ...)
+       TODO: check
+CVE-2026-86513 (A security flaw has been discovered in java-json-tools 
jackson-coreuti ...)
+       TODO: check
+CVE-2026-86512 (A vulnerability was identified in java-json-tools json-patch 
up to 1.1 ...)
+       TODO: check
+CVE-2026-86511 (A vulnerability was found in java-json-tools jackson-coreutils 
2.0. Af ...)
+       TODO: check
+CVE-2026-86510 (A vulnerability has been found in D-Link DIR-822A A_101. 
Affected is t ...)
+       TODO: check
+CVE-2026-86509 (A flaw has been found in D-Link DIR-895L A1_102b07. This 
impacts the f ...)
+       TODO: check
+CVE-2026-86439 (knowns versions before 0.30.0 fail to validate filesystem 
paths in MCP ...)
+       TODO: check
+CVE-2026-86438 (Lara Dashboard before 1.3.2 fails to authorize the 
MarketplaceModuleBr ...)
+       TODO: check
+CVE-2026-86437 (Lara Dashboard before 1.3.2 authorizes the POST 
/admin/settings/core-u ...)
+       TODO: check
+CVE-2026-86436 (Lara Dashboard before 1.3.2 fails to authorize access to the 
post-buil ...)
+       TODO: check
+CVE-2026-82758 (Improper Authentication vulnerability in ash-project 
ash_authenticatio ...)
+       TODO: check
+CVE-2026-82757 (Server-Side Request Forgery (SSRF) vulnerability in 
ash-project ash_au ...)
+       TODO: check
+CVE-2026-82756 (Improper Encoding or Escaping of Output vulnerability in 
ash-project a ...)
+       TODO: check
+CVE-2026-82755 (Use of Cache Containing Sensitive Information vulnerability in 
ash-pro ...)
+       TODO: check
+CVE-2026-82754 (Improper Protection of Alternate Path vulnerability in 
ash-project ash ...)
+       TODO: check
+CVE-2026-82753 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
+       TODO: check
+CVE-2026-82710 (Improper Neutralization of Escape, Meta, or Control Sequences 
vulnerab ...)
+       TODO: check
+CVE-2026-82586 (Improper Protection of Alternate Path vulnerability in 
ash-project ash ...)
+       TODO: check
+CVE-2026-82584 (Improper Neutralization of Escape, Meta, or Control Sequences 
vulnerab ...)
+       TODO: check
+CVE-2026-81638 (Improper Handling of Alternate Encoding vulnerability in 
ash-project a ...)
+       TODO: check
+CVE-2026-76977 (SAP UI5 does not sufficiently validate the parent frame's 
origin again ...)
+       TODO: check
+CVE-2026-76971 (Due to a Server-Side Request Forgery (SSRF) vulnerability in 
SAP Manuf ...)
+       TODO: check
+CVE-2026-76969 (@sap/cds-mtxs NPM library does not perform sufficient checks 
on certai ...)
+       TODO: check
+CVE-2026-76968 (SAP Web Dispatcher, Internet Communication Manager and SAP 
Content Ser ...)
+       TODO: check
+CVE-2026-76967 (SAP NetWeaver Business Client does not perform sufficient 
validation w ...)
+       TODO: check
+CVE-2026-76963 (Due to a missing authorization check in Application Server 
ABAP of SAP ...)
+       TODO: check
+CVE-2026-76962 (SAP S/4HANA (Manage Bank Chains app) does not perform 
sufficient autho ...)
+       TODO: check
+CVE-2026-76961 (SAP S/4HANA Finance (Advanced Payment Management) does not 
perform suf ...)
+       TODO: check
+CVE-2026-76960 (SAP S/4HANA Finance (Advanced Payment Management) does not 
perform suf ...)
+       TODO: check
+CVE-2026-76959 (SAP S/4HANA Finance (Advanced Payment Management) does not 
perform suf ...)
+       TODO: check
+CVE-2026-76958 (SAP Integration Suite does not sufficiently validate XML 
documents acc ...)
+       TODO: check
+CVE-2026-75811 (Improper Restriction of Software Interfaces to Hardware 
Features in AS ...)
+       TODO: check
+CVE-2026-75810 (Exposed Dangerous Method or Function in ASUSArmoury Crate 
allow a loca ...)
+       TODO: check
+CVE-2026-75809 (Exposed IOCTL with insufficient access control in ASUSArmoury 
Crate al ...)
+       TODO: check
+CVE-2026-75808 (Allocation of Resources Without Limits or Throttling in 
ASUSArmoury Cr ...)
+       TODO: check
+CVE-2026-75650 (Adobe Commerce is affected by an Improper Neutralization of 
Special El ...)
+       TODO: check
+CVE-2026-66768 (SAP GUI for Java does not correctly enforce the trust level 
policy for ...)
+       TODO: check
+CVE-2026-66767 (SAP NetWeaver Application Server for ABAP and ABAP Platform 
allows an  ...)
+       TODO: check
+CVE-2026-58240 (SAP NetWeaver Message Server does not sufficiently validate 
the authen ...)
+       TODO: check
+CVE-2026-58234 (SAP Process Integration (SOAP Adapter) allows a privileged 
user to sen ...)
+       TODO: check
+CVE-2026-44766 (SAP S/4HANA (Intercompany Matching and Reconciliation) allows 
a low-pr ...)
+       TODO: check
+CVE-2026-44756 (A memory safety vulnerability exists in the Extended Passport 
Protocol ...)
+       TODO: check
+CVE-2026-19397 (Missing authentication for a critical function in ASUS Control 
Center  ...)
+       TODO: check
+CVE-2026-18023 (Sensitive Information in Resource Not Removed Before Reuse in 
ASUS Arm ...)
+       TODO: check
+CVE-2026-16006 (Exposure of Sensitive System Information to an Unauthorized 
Control Sp ...)
+       TODO: check
+CVE-2026-16005 (Release of Invalid Pointer or Reference in Armoury Crate 
driver allows ...)
+       TODO: check
+CVE-2026-16004 (Exposed IOCTL with Insufficient Access Control in Armoury 
Crate driver ...)
+       TODO: check
+CVE-2026-16003 (Exposed IOCTL with Insufficient Access Control in Armoury 
Crate driver ...)
+       TODO: check
+CVE-2026-12962 (A Permissive Cross-domain Security Policy with Untrusted 
Domains in Ar ...)
+       TODO: check
 CVE-2026-8279 (The Masteriyo LMS plugin for WordPress is vulnerable to 
unauthorized d ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-86506 (In JetBrains GoLand before 2026.2.2.1 missing authentication 
on the Go ...)
@@ -21672,7 +21794,7 @@ CVE-2026-66633 (Unauthenticated Cross Site Scripting 
(XSS) in Fluent Forms Pro A
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66629 (Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 
versions.)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-66627 (Contributor Arbitrary File Upload in GP Premium <= 2.5.5 
versions.)
+CVE-2026-66627 (Unrestricted Upload of File with Dangerous Type vulnerability 
in EDGE2 ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66622 (Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 
versions.)
        NOT-FOR-US: WordPress plugin or theme



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8f1651e2b40d394d823999e69b649c0ca433274f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8f1651e2b40d394d823999e69b649c0ca433274f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to