Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c4e18e9c by security tracker role at 2026-09-09T07:12:53+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,1175 @@
+CVE-2026-8615 (The Reviso Exporter for WooCommerce plugin for WordPress is
vulnerable ...)
+ TODO: check
+CVE-2026-87747 (The Enterprise Cloud Database developed by Ragic has an
Arbitrary File ...)
+ TODO: check
+CVE-2026-87737 (An issue was discovered in the mirage-crypto-ec package before
2.4.0 f ...)
+ TODO: check
+CVE-2026-87736 (An issue was discovered in the mirage-crypto-ec package before
2.3.0 f ...)
+ TODO: check
+CVE-2026-87735 (An issue was discovered in the mirage-crypto-pk package before
2.3.0 f ...)
+ TODO: check
+CVE-2026-87734 (An issue was discovered in the utcp package before 0.0.6 for
OCaml. Ou ...)
+ TODO: check
+CVE-2026-87733 (An issue was discovered in the mirage-crypto-ec function
before 2.2.0 ...)
+ TODO: check
+CVE-2026-87732 (An issue was discovered in the mirage-crypto package before
2.2.0 for ...)
+ TODO: check
+CVE-2026-87724 (Tor before 0.4.9.12 interprets the CC_RESPONSE extension even
when CC_ ...)
+ TODO: check
+CVE-2026-87658 (Information leak in Extensions in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87657 (Use after free in V8 in Google Chrome prior to 153.0.8010.36
allowed a ...)
+ TODO: check
+CVE-2026-87656 (Improper state validation in Safebrowsing in Google Chrome
prior to 15 ...)
+ TODO: check
+CVE-2026-87655 (Clickjacking in Downloads in Google Chrome prior to
153.0.8010.36 allo ...)
+ TODO: check
+CVE-2026-87654 (Buffer overflow in ANGLE in Google Chrome on on Windows prior
to 153.0 ...)
+ TODO: check
+CVE-2026-87653 (UI misrepresentation in FullScreen in Google Chrome on on
Windows prio ...)
+ TODO: check
+CVE-2026-87652 (Incorrect authorization in PushAPI in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87651 (Incorrect authorization in Paint in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87650 (Out of bounds read in WebGL in Google Chrome prior to
153.0.8010.36 al ...)
+ TODO: check
+CVE-2026-87649 (UI misrepresentation in Downloads in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87648 (Use after free in ANGLE in Google Chrome on on Windows prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87647 (Uninitialized resource in GPU in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87646 (Use after free in Web Authentication in Google Chrome prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87645 (Improper state validation in Safebrowsing in Google Chrome
prior to 15 ...)
+ TODO: check
+CVE-2026-87644 (Incorrect authorization in Views in Google Chrome on on
Windows prior ...)
+ TODO: check
+CVE-2026-87643 (Integer overflow in GPU in Google Chrome on on Android prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87642 (Uninitialized resource in WebGL in Google Chrome prior to
153.0.8010.3 ...)
+ TODO: check
+CVE-2026-87641 (Race condition in Browser in Google Chrome prior to
153.0.8010.36 allo ...)
+ TODO: check
+CVE-2026-87640 (Out of bounds read in WebView in Google Chrome on on Android
prior to ...)
+ TODO: check
+CVE-2026-87639 (Use after free in WebPackaging in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87638 (Out of bounds write in Media in Google Chrome prior to
153.0.8010.36 a ...)
+ TODO: check
+CVE-2026-87637 (Use after free in Extensions in Google Chrome on on Mac prior
to 153.0 ...)
+ TODO: check
+CVE-2026-87636 (Type confusion in XML in Google Chrome prior to 153.0.8010.36
allowed ...)
+ TODO: check
+CVE-2026-87635 (UI misrepresentation in Payments in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87634 (Use after free in WebPackaging in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87633 (Use after free in Views in Google Chrome prior to
153.0.8010.36 allowe ...)
+ TODO: check
+CVE-2026-87632 (Cross-site scripting in SanitizerAPI in Google Chrome prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87631 (Missing authorization in DOM in Google Chrome prior to
153.0.8010.36 a ...)
+ TODO: check
+CVE-2026-87630 (Integer overflow in WebRTC in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87629 (Incorrect authorization in Sources in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87628 (Use after free in Cast in Google Chrome prior to 153.0.8010.36
allowed ...)
+ TODO: check
+CVE-2026-87627 (Interpretation conflict in Safebrowsing in Google Chrome on on
Mac pri ...)
+ TODO: check
+CVE-2026-87626 (Incorrect authorization in DeviceBoundSessionCredentials in
Google Chr ...)
+ TODO: check
+CVE-2026-87625 (Use after free in V8 in Google Chrome prior to 153.0.8010.36
allowed a ...)
+ TODO: check
+CVE-2026-87624 (UI misrepresentation in Passwords in Google Chrome on on
Android prior ...)
+ TODO: check
+CVE-2026-87623 (Observable discrepancy in DOM in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87622 (Missing authorization in FedCM in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87621 (Out of bounds write in ANGLE in Google Chrome on on Windows
prior to 1 ...)
+ TODO: check
+CVE-2026-87620 (Observable discrepancy in SVG in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87619 (Observable discrepancy in Prefetch in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87618 (Incorrect reference resolution in Storage in Google Chrome on
on Windo ...)
+ TODO: check
+CVE-2026-87617 (Use after free in DevTools in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87616 (Improper initialization in Views in Google Chrome on on
Windows prior ...)
+ TODO: check
+CVE-2026-87615 (Race condition in Payments in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87614 (Incorrect authorization in ServiceWorker in Google Chrome
prior to 153 ...)
+ TODO: check
+CVE-2026-87613 (Incorrect reference resolution in Extensions in Google Chrome
prior to ...)
+ TODO: check
+CVE-2026-87612 (Type confusion in V8 in Google Chrome prior to 153.0.8010.36
allowed a ...)
+ TODO: check
+CVE-2026-87611 (Missing authorization in FileSystem in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87610 (Incorrect authorization in Omnibox in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87609 (Use after free in Sharing in Google Chrome on on iOS prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87608 (Improper certificate validation in FedCM in Google Chrome
prior to 153 ...)
+ TODO: check
+CVE-2026-87607 (Use after free in Device in Google Chrome on on Mac prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87606 (Missing authorization in SiteIsolation in Google Chrome prior
to 153.0 ...)
+ TODO: check
+CVE-2026-87605 (Missing authorization in Contacts in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87604 (Out of bounds read in ANGLE in Google Chrome prior to
153.0.8010.36 al ...)
+ TODO: check
+CVE-2026-87603 (Missing authorization in FileSystem in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87602 (Out of bounds read in ANGLE in Google Chrome on on Windows
prior to 15 ...)
+ TODO: check
+CVE-2026-87601 (Race condition in V8 in Google Chrome prior to 153.0.8010.36
allowed a ...)
+ TODO: check
+CVE-2026-87600 (Improper input validation in Safebrowsing in Google Chrome on
on Andro ...)
+ TODO: check
+CVE-2026-87599 (Improper input validation in Interstitials in Google Chrome
prior to 1 ...)
+ TODO: check
+CVE-2026-87598 (Incorrect authorization in ServiceWorker in Google Chrome
prior to 153 ...)
+ TODO: check
+CVE-2026-87597 (UI misrepresentation in CustomTabs in Google Chrome on on
Android prio ...)
+ TODO: check
+CVE-2026-87596 (Out of bounds read in ANGLE in Google Chrome prior to
153.0.8010.36 al ...)
+ TODO: check
+CVE-2026-87595 (Server-side request forgery in Mobile in Google Chrome prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87594 (Incorrect authorization in DataTransfer in Google Chrome prior
to 153. ...)
+ TODO: check
+CVE-2026-87593 (Information leak in Editing in Google Chrome prior to
153.0.8010.36 al ...)
+ TODO: check
+CVE-2026-87592 (Out of bounds read in Tint in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87591 (Incorrect authorization in Extensions in Google Chrome prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87590 (Improper input validation in Passwords in Google Chrome prior
to 153.0 ...)
+ TODO: check
+CVE-2026-87589 (Incorrect authorization in SiteIsolation in Google Chrome
prior to 153 ...)
+ TODO: check
+CVE-2026-87588 (Use after free in Chromecast in Google Chrome prior to
153.0.8010.36 a ...)
+ TODO: check
+CVE-2026-87587 (Use after free in V8 in Google Chrome prior to 153.0.8010.36
allowed a ...)
+ TODO: check
+CVE-2026-87586 (Out of bounds read in ANGLE in Google Chrome prior to
153.0.8010.36 al ...)
+ TODO: check
+CVE-2026-87585 (Double free in PDFium in Google Chrome on on Windows prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87584 (Incorrect authorization in WebUI in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87583 (UI misrepresentation in Passwords in Google Chrome on on
Android prior ...)
+ TODO: check
+CVE-2026-87582 (Confused deputy in DataTransfer in Google Chrome prior to
153.0.8010.3 ...)
+ TODO: check
+CVE-2026-87581 (Use after free in Payments in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87580 (Incorrect authorization in WebAppInstalls in Google Chrome
prior to 15 ...)
+ TODO: check
+CVE-2026-87579 (Buffer overflow in WebRTC in Google Chrome prior to
153.0.8010.36 allo ...)
+ TODO: check
+CVE-2026-87578 (Use after free in Receiver in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87577 (Incorrect authorization in Isolated in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87576 (Uninitialized resource in GPU in Google Chrome on on Android
prior to ...)
+ TODO: check
+CVE-2026-87575 (Incorrect authorization in Loader in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87574 (Information leak in ServiceWorker in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87573 (Improper input validation in Network in Google Chrome prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87572 (Injection in DevTools in Google Chrome prior to 153.0.8010.36
allowed ...)
+ TODO: check
+CVE-2026-87571 (Improper certificate validation in Loader in Google Chrome
prior to 15 ...)
+ TODO: check
+CVE-2026-87570 (Incorrect authorization in SiteIsolation in Google Chrome
prior to 153 ...)
+ TODO: check
+CVE-2026-87569 (Missing authorization in Views in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87568 (Improper input validation in Chromium in Google Chrome prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87567 (UI misrepresentation in UrlFormatting in Google Chrome prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87566 (Observable discrepancy in Layout in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87565 (Information leak in Passwords in Google Chrome on on Android
prior to ...)
+ TODO: check
+CVE-2026-87564 (Type confusion in V8 in Google Chrome prior to 153.0.8010.36
allowed a ...)
+ TODO: check
+CVE-2026-87563 (Origin validation error in Paint in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87562 (Incorrect reference resolution in Accessibility in Google
Chrome on on ...)
+ TODO: check
+CVE-2026-87561 (Incorrect authorization in Web Authentication in Google Chrome
prior t ...)
+ TODO: check
+CVE-2026-87560 (Missing authorization in Browser in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87559 (UI misrepresentation in UI in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87558 (Use after free in Payments in Google Chrome on on Mac prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87557 (Missing authorization in LocalNetworkAccess in Google Chrome
prior to ...)
+ TODO: check
+CVE-2026-87556 (Missing authorization in Browser in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87555 (Uninitialized resource in GPU in Google Chrome on on Android
prior to ...)
+ TODO: check
+CVE-2026-87554 (Race condition in Chromoting in Google Chrome on on Windows
prior to 1 ...)
+ TODO: check
+CVE-2026-87553 (Improper input validation in SiteIsolation in Google Chrome
prior to 1 ...)
+ TODO: check
+CVE-2026-87552 (Missing authorization in TrustedWebActivities in Google Chrome
on on A ...)
+ TODO: check
+CVE-2026-87551 (Improper certificate validation in CORS in Google Chrome prior
to 153. ...)
+ TODO: check
+CVE-2026-87550 (Improper encoding or escaping of output in CSS in Google
Chrome prior ...)
+ TODO: check
+CVE-2026-87549 (Incomplete cleanup in Downloads in Google Chrome prior to
153.0.8010.3 ...)
+ TODO: check
+CVE-2026-87548 (Improper state validation in Installer in Google Chrome prior
to 153.0 ...)
+ TODO: check
+CVE-2026-87547 (Incorrect reference resolution in FileSystem in Google Chrome
prior to ...)
+ TODO: check
+CVE-2026-87546 (Incorrect type conversion or cast in Safebrowsing in Google
Chrome on ...)
+ TODO: check
+CVE-2026-87545 (Information leak in Mobile in Google Chrome on on iOS prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87544 (Incorrect authorization in Extensions in Google Chrome prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87543 (Missing authorization in Core in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87542 (Use after free in Input in Google Chrome prior to
153.0.8010.36 allowe ...)
+ TODO: check
+CVE-2026-87541 (Information leak in Navigation in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87540 (Incorrect authorization in Isolated in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87539 (Observable discrepancy in Network in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87538 (Clickjacking in Input in Google Chrome prior to 153.0.8010.36
allowed ...)
+ TODO: check
+CVE-2026-87537 (Missing authorization in Extensions in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87536 (Use after free in V8 in Google Chrome prior to 153.0.8010.36
allowed a ...)
+ TODO: check
+CVE-2026-87535 (Information loss or omission in Safebrowsing in Google Chrome
on on Ma ...)
+ TODO: check
+CVE-2026-87534 (Missing authorization in WebView in Google Chrome on on
Android prior ...)
+ TODO: check
+CVE-2026-87533 (Use after free in DevTools in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87532 (Improper state validation in Safebrowsing in Google Chrome
prior to 15 ...)
+ TODO: check
+CVE-2026-87531 (Information leak in CORS in Google Chrome prior to
153.0.8010.36 allow ...)
+ TODO: check
+CVE-2026-87530 (Uncontrolled search path element in CredentialProvider in
Google Chrom ...)
+ TODO: check
+CVE-2026-87529 (Numeric truncation error in Media in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87528 (Type confusion in Rust in Google Chrome on on Windows prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87527 (Buffer overflow in WebGL in Google Chrome prior to
153.0.8010.36 allow ...)
+ TODO: check
+CVE-2026-87526 (Use after free in Passwords in Google Chrome prior to
153.0.8010.36 al ...)
+ TODO: check
+CVE-2026-87525 (Out of bounds read in Chromoting in Google Chrome on on
Windows prior ...)
+ TODO: check
+CVE-2026-87524 (Use after free in Core in Google Chrome on on Windows prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87523 (Race condition in DataTransfer in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87522 (Missing authorization in WebView in Google Chrome on on
Android prior ...)
+ TODO: check
+CVE-2026-87521 (Information leak in WebMCP in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87520 (Use after free in Dawn in Google Chrome on on Android prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87519 (Incorrect authorization in Safebrowsing in Google Chrome prior
to 153. ...)
+ TODO: check
+CVE-2026-87518 (Observable discrepancy in Safebrowsing in Google Chrome on on
iOS prio ...)
+ TODO: check
+CVE-2026-87517 (Race condition in Mobile in Google Chrome on on iOS prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87516 (Observable discrepancy in Navigation in Google Chrome prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87515 (Incorrect authorization in FileAPI in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87514 (Use after free in Views in Google Chrome prior to
153.0.8010.36 allowe ...)
+ TODO: check
+CVE-2026-87513 (Missing authorization in ControlledFrame in Google Chrome
prior to 153 ...)
+ TODO: check
+CVE-2026-87512 (Use after free in ANGLE in Google Chrome on on Windows prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87511 (Missing authorization in DevTools in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87510 (Improper input validation in FileAPI in Google Chrome prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87509 (Incorrect authorization in Updater in Google Chrome on on
Windows prio ...)
+ TODO: check
+CVE-2026-87508 (Incorrect authorization in Loader in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87507 (UI misrepresentation in Downloads in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87506 (Privilege elevation in WebUI in Google Chrome prior to
153.0.8010.36 a ...)
+ TODO: check
+CVE-2026-87505 (Incorrect authorization in FileSystem in Google Chrome prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87504 (Use after free in Core in Google Chrome prior to 153.0.8010.36
allowed ...)
+ TODO: check
+CVE-2026-87503 (Inappropriate implementation in Downloads in Google Chrome on
on Andro ...)
+ TODO: check
+CVE-2026-87502 (Confused deputy in Fullscreen in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87501 (UI misrepresentation in Passwords in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87500 (Improper validation of array index in ANGLE in Google Chrome
prior to ...)
+ TODO: check
+CVE-2026-87499 (Incorrect authorization in Network in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87498 (Missing authorization in WebUI in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87497 (Uninitialized resource in Codecs in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87496 (UI misrepresentation in Browser in Google Chrome prior to
153.0.8010.3 ...)
+ TODO: check
+CVE-2026-87495 (Information leak in Scroll in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87494 (Use after free in Browser in Google Chrome on on Windows prior
to 153. ...)
+ TODO: check
+CVE-2026-87493 (Missing authorization in FileSystem in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87492 (Incorrect authorization in DevTools in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87491 (Out of bounds write in V8 in Google Chrome prior to
153.0.8010.36 allo ...)
+ TODO: check
+CVE-2026-87490 (Information leak in Transactions Platform in Google Chrome
prior to 15 ...)
+ TODO: check
+CVE-2026-87489 (Memory corruption in V8 in Google Chrome prior to
153.0.8010.36 allowe ...)
+ TODO: check
+CVE-2026-87488 (Use after free in WebGL in Google Chrome on on Android prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87487 (Missing authorization in FileSystem in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87486 (Clickjacking in TrustedWebActivities in Google Chrome on on
Android pr ...)
+ TODO: check
+CVE-2026-87485 (Incorrect authorization in CORS in Google Chrome prior to
153.0.8010.3 ...)
+ TODO: check
+CVE-2026-87484 (UI misrepresentation in Geometry in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87483 (Incorrect authorization in Browser in Google Chrome on on
Android prio ...)
+ TODO: check
+CVE-2026-87482 (Cleartext transmission of sensitive data in HttpsUpgrades in
Google Ch ...)
+ TODO: check
+CVE-2026-87481 (Incorrect authorization in WebView in Google Chrome on on
Android prio ...)
+ TODO: check
+CVE-2026-87480 (Use after free in Printing in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87479 (Insufficient policy enforcement in Extensions in Google Chrome
prior t ...)
+ TODO: check
+CVE-2026-87478 (Observable discrepancy in Autofill in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87477 (Information leak in Core in Google Chrome prior to
153.0.8010.36 allow ...)
+ TODO: check
+CVE-2026-87476 (Incorrect authorization in Loader in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87475 (Missing authorization in Omnibox in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87474 (Use after free in Payments in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87473 (Incorrect authorization in FileHandling in Google Chrome prior
to 153. ...)
+ TODO: check
+CVE-2026-87472 (Improper input validation in FedCM in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87471 (Incorrect authorization in ServiceWorker in Google Chrome
prior to 153 ...)
+ TODO: check
+CVE-2026-87470 (Improper quantity validation in Tint in Google Chrome on on
Mac prior ...)
+ TODO: check
+CVE-2026-87469 (Improper input validation in Extensions in Google Chrome prior
to 153. ...)
+ TODO: check
+CVE-2026-87468 (Incorrect authorization in Isolated in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87467 (Race condition in Updater in Google Chrome on on Windows prior
to 153. ...)
+ TODO: check
+CVE-2026-87466 (Incorrect authorization in Workers in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87465 (Incorrect authorization in Downloads in Google Chrome prior to
153.0.8 ...)
+ TODO: check
+CVE-2026-87464 (Use after free in WebGL in Google Chrome prior to
153.0.8010.36 allowe ...)
+ TODO: check
+CVE-2026-87463 (Incorrect authorization in Certificate in Google Chrome on on
Android ...)
+ TODO: check
+CVE-2026-87462 (UI misrepresentation in FedCM in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87461 (Information leak in Core in Google Chrome prior to
153.0.8010.36 allow ...)
+ TODO: check
+CVE-2026-87460 (Use after free in Platform in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87459 (Observable discrepancy in Select in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87458 (UI misrepresentation in Geometry in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87457 (Race condition in Updater in Google Chrome on on Windows prior
to 153. ...)
+ TODO: check
+CVE-2026-87456 (Uninitialized resource in Media in Google Chrome prior to
153.0.8010.3 ...)
+ TODO: check
+CVE-2026-87455 (Use after free in Aura in Google Chrome prior to 153.0.8010.36
allowed ...)
+ TODO: check
+CVE-2026-87454 (Information leak in Enterprise in Google Chrome on on Windows
prior to ...)
+ TODO: check
+CVE-2026-87453 (Confused deputy in BackgroundFetch in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87452 (Incorrect authorization in GPU in Google Chrome on on Mac
prior to 153 ...)
+ TODO: check
+CVE-2026-87451 (Information leak in Downloads in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87450 (Incorrect authorization in Permissions in Google Chrome prior
to 153.0 ...)
+ TODO: check
+CVE-2026-87449 (Cross-site request forgery in DeviceBoundSessionCredentials in
Google ...)
+ TODO: check
+CVE-2026-87448 (Use after free in DevTools in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87447 (Incorrect authorization in Network in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87446 (Incomplete cleanup in Extensions in Google Chrome prior to
153.0.8010. ...)
+ TODO: check
+CVE-2026-87445 (UI misrepresentation in Session in Google Chrome prior to
153.0.8010.3 ...)
+ TODO: check
+CVE-2026-87444 (Memory corruption in Codecs in Google Chrome prior to
153.0.8010.36 al ...)
+ TODO: check
+CVE-2026-87443 (Missing authorization in Actor in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87442 (Confused deputy in Prerender in Google Chrome prior to
153.0.8010.36 a ...)
+ TODO: check
+CVE-2026-87441 (Missing authorization in Downloads in Google Chrome prior to
153.0.801 ...)
+ TODO: check
+CVE-2026-87440 (Out of bounds read in Media in Google Chrome prior to
153.0.8010.36 al ...)
+ TODO: check
+CVE-2026-87439 (Information leak in ServiceWorker in Google Chrome prior to
153.0.8010 ...)
+ TODO: check
+CVE-2026-87438 (Out of bounds write in WebGL in Google Chrome on on Android
prior to 1 ...)
+ TODO: check
+CVE-2026-87437 (Information leak in Frames in Google Chrome prior to
153.0.8010.36 all ...)
+ TODO: check
+CVE-2026-87436 (Incomplete cleanup in Browser in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87435 (Information leak in ControlledFrame in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87434 (Missing authorization in CORS in Google Chrome prior to
153.0.8010.36 ...)
+ TODO: check
+CVE-2026-87433 (Race condition in FileAPI in Google Chrome prior to
153.0.8010.36 allo ...)
+ TODO: check
+CVE-2026-87432 (Incorrect authorization in Navigation in Google Chrome prior
to 153.0. ...)
+ TODO: check
+CVE-2026-87431 (Missing authorization in Extensions in Google Chrome prior to
153.0.80 ...)
+ TODO: check
+CVE-2026-87430 (Buffer overflow in WebRTC in Google Chrome prior to
153.0.8010.36 allo ...)
+ TODO: check
+CVE-2026-87429 (Missing authorization in ServiceWorker in Google Chrome prior
to 153.0 ...)
+ TODO: check
+CVE-2026-87088 (Tanium addressed an unauthorized code execution vulnerability
in Enfor ...)
+ TODO: check
+CVE-2026-87084 (Tanium addressed a server-side request forgery vulnerability
in Enforc ...)
+ TODO: check
+CVE-2026-87083 (A weakness has been identified in tile-ai tilelang up to
0.1.14. This ...)
+ TODO: check
+CVE-2026-87075 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87073 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87072 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87048 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87047 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87046 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87037 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87036 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87035 (Tanium addressed an information disclosure vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87034 (Tanium addressed a SQL injection vulnerability in Comply.)
+ TODO: check
+CVE-2026-87033 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87032 (Tanium addressed an information disclosure vulnerability in
Tanium Ser ...)
+ TODO: check
+CVE-2026-87030 (Tanium addressed a path traversal vulnerability in Comply.)
+ TODO: check
+CVE-2026-87025 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-87023 (Tanium addressed a path traversal vulnerability in Comply.)
+ TODO: check
+CVE-2026-87021 (Tanium addressed an unauthorized code execution vulnerability
in Compl ...)
+ TODO: check
+CVE-2026-87019 (Tanium addressed an improper access controls vulnerability in
Comply.)
+ TODO: check
+CVE-2026-86996 (n8n is an open source workflow automation platform. Prior to
2.37.7 an ...)
+ TODO: check
+CVE-2026-86995 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86994 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86993 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86819 (Waves Central for macOS contains a local privilege escalation
in the p ...)
+ TODO: check
+CVE-2026-86810 (A vulnerability was detected in Open-Web-Analytics up to
1.9.1. The im ...)
+ TODO: check
+CVE-2026-86808 (A security vulnerability has been detected in moltis-org
moltis up to ...)
+ TODO: check
+CVE-2026-86806 (A weakness has been identified in opengeos GeoLibre up to
2.3.0. Impac ...)
+ TODO: check
+CVE-2026-86464 (In the current development version of Eclipse aeriOS, for
which no off ...)
+ TODO: check
+CVE-2026-86085 (n8n is an open source workflow automation platform. Prior to
2.37.7 an ...)
+ TODO: check
+CVE-2026-86084 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86083 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86082 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86081 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86080 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86079 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86078 (n8n is an open source workflow automation platform. Prior to
2.37.7 an ...)
+ TODO: check
+CVE-2026-86077 (n8n is an open source workflow automation platform. Prior to
2.37.7 an ...)
+ TODO: check
+CVE-2026-86076 (n8n is an open source workflow automation platform. Prior to
1.123.76, ...)
+ TODO: check
+CVE-2026-86075 (n8n is an open source workflow automation platform. Prior to
2.37.7 an ...)
+ TODO: check
+CVE-2026-85983 (The Auth0 AD/LDAP Connector improperly processes a
configuration value ...)
+ TODO: check
+CVE-2026-85982 (The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-85981 (The administrative panel of the Auth0 AD/LDAP Connector
(versions 6.5. ...)
+ TODO: check
+CVE-2026-85418 (The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie
Notice, ...)
+ TODO: check
+CVE-2026-85133 (The WPLP Cookie Consent WordPress plugin before 4.4.2 does
not perfor ...)
+ TODO: check
+CVE-2026-85132 (The WPLP Cookie Consent WordPress plugin before 4.4.2 does
not perfor ...)
+ TODO: check
+CVE-2026-85117 (The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs
the shor ...)
+ TODO: check
+CVE-2026-85037 (The Sunshine Photo Cart WordPress plugin before 3.7 does not
validate ...)
+ TODO: check
+CVE-2026-84942 (Improper input validation in the Vega expression function
implementati ...)
+ TODO: check
+CVE-2026-84908 (The WPFunnels plugin for WordPress is vulnerable to Missing
Authorizat ...)
+ TODO: check
+CVE-2026-84869 (A condition in the ScreenConnect client may allow files to be
transfer ...)
+ TODO: check
+CVE-2026-84685 (The react-native-auth0 SDK's web platform implementation does
not scop ...)
+ TODO: check
+CVE-2026-84293 (The Repeater Fields for Gravity Forms plugin for WordPress is
vulnerab ...)
+ TODO: check
+CVE-2026-84222 (The Kirki WordPress plugin before 6.3.0 does not check
whether the re ...)
+ TODO: check
+CVE-2026-84197 (In Eclipse Ditto's Node.js JavaScript client, all released
versions of ...)
+ TODO: check
+CVE-2026-84113 (The Quentn WP WordPress plugin before 1.2.15 does not properly
sanitis ...)
+ TODO: check
+CVE-2026-84068 (The Quentn WP WordPress plugin before 1.2.15 does not
adequately escap ...)
+ TODO: check
+CVE-2026-83593 (The WPBot \u2013 AI ChatBot for Live Support, Lead Generation,
AI Serv ...)
+ TODO: check
+CVE-2026-83541 (The Sina Extension for Elementor WordPress plugin before
3.10.4 does n ...)
+ TODO: check
+CVE-2026-83537 (The WP Express Checkout WordPress plugin before 2.5.0 does not
verify ...)
+ TODO: check
+CVE-2026-82848 (The Masteriyo LMS WordPress plugin before 3.4.0 does not
perform any ...)
+ TODO: check
+CVE-2026-82185 (The WPLP Cookie Consent WordPress plugin before 4.4.2 does
not have c ...)
+ TODO: check
+CVE-2026-82184 (The WPLP Cookie Consent WordPress plugin before 4.4.2 does
not have a ...)
+ TODO: check
+CVE-2026-82007 (Photoshop Desktop is affected by an Integer Overflow or
Wraparound vul ...)
+ TODO: check
+CVE-2026-82006 (Photoshop Desktop is affected by a Heap-based Buffer Overflow
vulnerab ...)
+ TODO: check
+CVE-2026-82005 (Photoshop Desktop is affected by an out-of-bounds write
vulnerability ...)
+ TODO: check
+CVE-2026-82001 (Acrobat Reader is affected by an Uncontrolled Resource
Consumption vul ...)
+ TODO: check
+CVE-2026-81997 (Acrobat Reader is affected by an Incorrect Authorization
vulnerability ...)
+ TODO: check
+CVE-2026-81996 (Acrobat Reader is affected by an Incorrect Authorization
vulnerability ...)
+ TODO: check
+CVE-2026-81994 (Acrobat Reader is affected by an Improperly Controlled
Modification of ...)
+ TODO: check
+CVE-2026-81993 (Acrobat Reader is affected by a Heap-based Buffer Overflow
vulnerabili ...)
+ TODO: check
+CVE-2026-81992 (Acrobat Reader is affected by a Heap-based Buffer Overflow
vulnerabili ...)
+ TODO: check
+CVE-2026-81991 (Acrobat Reader is affected by an out-of-bounds read
vulnerability that ...)
+ TODO: check
+CVE-2026-81990 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-81989 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-81988 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-81987 (Acrobat Reader is affected by an Integer Overflow or
Wraparound vulner ...)
+ TODO: check
+CVE-2026-81986 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-81985 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-81984 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-81983 (Acrobat Reader is affected by an out-of-bounds write
vulnerability tha ...)
+ TODO: check
+CVE-2026-81982 (Acrobat Reader is affected by an out-of-bounds read
vulnerability that ...)
+ TODO: check
+CVE-2026-81981 (Acrobat Reader is affected by an out-of-bounds write
vulnerability tha ...)
+ TODO: check
+CVE-2026-81980 (Acrobat Reader is affected by an out-of-bounds write
vulnerability tha ...)
+ TODO: check
+CVE-2026-81979 (Acrobat Reader is affected by an out-of-bounds write
vulnerability tha ...)
+ TODO: check
+CVE-2026-81978 (Acrobat Reader is affected by an out-of-bounds read
vulnerability that ...)
+ TODO: check
+CVE-2026-81977 (Acrobat Reader is affected by an Integer Underflow (Wrap or
Wraparound ...)
+ TODO: check
+CVE-2026-81976 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-81975 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-81973 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-81904 (Concrete CMS below 9.5.3 registered view assets for every
sub-block of ...)
+ TODO: check
+CVE-2026-81741 (The Groundhogg \u2014 CRM, Newsletters, and Marketing
Automation WordP ...)
+ TODO: check
+CVE-2026-81647 (Out-of-bounds read vulnerability in the graphics module.
Impact: Succe ...)
+ TODO: check
+CVE-2026-81646 (Out-of-bounds read vulnerability in the graphics module.
Impact: Succe ...)
+ TODO: check
+CVE-2026-81644 (DoS vulnerability in the preview service module. Impact:
Successful ex ...)
+ TODO: check
+CVE-2026-81192 (`OpenTelemetry.Resources.Host` NuGet package, which provides
OpenTelem ...)
+ TODO: check
+CVE-2026-81022 (The SupportCandy WordPress plugin before 3.5.3 does not
validate a su ...)
+ TODO: check
+CVE-2026-81021 (The SupportCandy WordPress plugin before 3.5.3 does not
perform an au ...)
+ TODO: check
+CVE-2026-80440 (The Hustle WordPress plugin before 7.8.14.2 does not prevent
shortcode ...)
+ TODO: check
+CVE-2026-80341 (The Payment Plugins for PayPal WooCommerce WordPress plugin
before 2.0 ...)
+ TODO: check
+CVE-2026-80340 (The Payment Plugins for PayPal WooCommerce WordPress plugin
before 2.0 ...)
+ TODO: check
+CVE-2026-80339 (The Payment Plugins for Stripe WooCommerce WordPress plugin
before 4.0 ...)
+ TODO: check
+CVE-2026-80162 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-80161 (Acrobat Reader is affected by an Access of Resource Using
Incompatible ...)
+ TODO: check
+CVE-2026-80160 (Acrobat Reader is affected by an out-of-bounds read
vulnerability that ...)
+ TODO: check
+CVE-2026-80159 (Acrobat Reader is affected by an Untrusted Search Path
vulnerability t ...)
+ TODO: check
+CVE-2026-7809
+ REJECTED
+CVE-2026-7804 (The Product Filter for WooCommerce by WBW plugin for WordPress
is vuln ...)
+ TODO: check
+CVE-2026-79910 (Acrobat Reader is affected by an out-of-bounds read
vulnerability that ...)
+ TODO: check
+CVE-2026-79909 (Acrobat Reader is affected by a Use After Free vulnerability
that coul ...)
+ TODO: check
+CVE-2026-79908 (Acrobat Reader is affected by an out-of-bounds write
vulnerability tha ...)
+ TODO: check
+CVE-2026-79907 (Acrobat Reader is affected by a Double Free vulnerability that
could r ...)
+ TODO: check
+CVE-2026-79905 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-79588 (U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext
transmissi ...)
+ TODO: check
+CVE-2026-78971 (In Halo <= 2.25.4, the plugin management feature allows users
to insta ...)
+ TODO: check
+CVE-2026-78834 (A code execution vulnerability exists in CMSimple 5.22 in the
CoAuthor ...)
+ TODO: check
+CVE-2026-78742 (Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting
(XSS) vi ...)
+ TODO: check
+CVE-2026-78741 (Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting
(XSS) in ...)
+ TODO: check
+CVE-2026-78738 (Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting
(XSS) via ...)
+ TODO: check
+CVE-2026-78635 (The Okta Privileged Access client URL handler does not insert
an optio ...)
+ TODO: check
+CVE-2026-78631 (The Okta Hyperdrive Agent writes the decoded SAML bearer
assertion to ...)
+ TODO: check
+CVE-2026-78630 (The Okta Access Gateway does not neutralize shell
metacharacters in SN ...)
+ TODO: check
+CVE-2026-78629 (The Okta Hyperdrive agent plugin returns a success response
without a ...)
+ TODO: check
+CVE-2026-78627 (The Okta Hyperdrive Integration installer does not mask the
OAuth clie ...)
+ TODO: check
+CVE-2026-78626 (The Okta Access Gateway improperly handles input sanitization
and regu ...)
+ TODO: check
+CVE-2026-78625 (The Okta Access Gateway does not sanitize dashboard label
values befor ...)
+ TODO: check
+CVE-2026-78624 (The Okta Access Gateway backup restore function does not
validate the ...)
+ TODO: check
+CVE-2026-78623 (The Okta Access Gateway does not sanitize SAML assertion
values before ...)
+ TODO: check
+CVE-2026-78622 (The Okta Verify for Windows uninstaller does not verify
whether the us ...)
+ TODO: check
+CVE-2026-78620 (The Okta Access Gateway Kerberos configuration handler does
not valida ...)
+ TODO: check
+CVE-2026-78579 (The Okta Access Gateway does not sanitize SAML assertion
attribute val ...)
+ TODO: check
+CVE-2026-78574 (The Okta Hyperdrive Integration plugin resolves a required
assembly us ...)
+ TODO: check
+CVE-2026-78560 (The Okta Access Gateway includes an optional pass-through
authenticati ...)
+ TODO: check
+CVE-2026-78552 (The Okta Access Gateway does not apply its Lua directive
restriction t ...)
+ TODO: check
+CVE-2026-78550 (The Okta Access Gateway management console passes
user-supplied input ...)
+ TODO: check
+CVE-2026-78545 (The Okta Access Gateway does not sanitize the application
label field ...)
+ TODO: check
+CVE-2026-77827 (Maono Link 3.8.13 MaonoAiServices Windows service allows local
privile ...)
+ TODO: check
+CVE-2026-77187 (The My Calendar \u2013 Accessible Event Manager plugin for
WordPress i ...)
+ TODO: check
+CVE-2026-77186 (The My Calendar \u2013 Accessible Event Manager plugin for
WordPress i ...)
+ TODO: check
+CVE-2026-76801 (The FireBox \u2013 WooCommerce Popup Builder, Exit Intent
Popup, Email ...)
+ TODO: check
+CVE-2026-76199 (Photoshop Desktop is affected by an Uncontrolled Search Path
Element v ...)
+ TODO: check
+CVE-2026-76190 (ColdFusion is affected by an Improper Neutralization of
Directives in ...)
+ TODO: check
+CVE-2026-76009 (The Next-Cart Store to WooCommerce Migration plugin for
WordPress is v ...)
+ TODO: check
+CVE-2026-76002 (ColdFusion is affected by a reflected Cross-Site Scripting
(XSS) vulne ...)
+ TODO: check
+CVE-2026-76000 (ColdFusion is affected by an Uncontrolled Resource Consumption
vulnera ...)
+ TODO: check
+CVE-2026-75999 (ColdFusion is affected by an Improper Input Validation
vulnerability t ...)
+ TODO: check
+CVE-2026-75998 (ColdFusion is affected by an Improper Access Control
vulnerability tha ...)
+ TODO: check
+CVE-2026-75993 (ColdFusion is affected by a reflected Cross-Site Scripting
(XSS) vulne ...)
+ TODO: check
+CVE-2026-75992 (Illustrator is affected by an out-of-bounds write
vulnerability that c ...)
+ TODO: check
+CVE-2026-75991 (Illustrator is affected by an Improper Input Validation
vulnerability ...)
+ TODO: check
+CVE-2026-75990 (Illustrator is affected by an Incorrect Authorization
vulnerability th ...)
+ TODO: check
+CVE-2026-75966 (The Podlove Podcast Publisher plugin for WordPress is
vulnerable to St ...)
+ TODO: check
+CVE-2026-75905 (The WP Recipe Maker plugin for WordPress is vulnerable to
authorizatio ...)
+ TODO: check
+CVE-2026-75863 (Photoshop Desktop is affected by an Integer Overflow or
Wraparound vul ...)
+ TODO: check
+CVE-2026-75862 (Photoshop Desktop is affected by an Integer Overflow or
Wraparound vul ...)
+ TODO: check
+CVE-2026-75861 (The Ultimate Gift Cards for WooCommerce WordPress plugin
before 3.2.10 ...)
+ TODO: check
+CVE-2026-75771 (Photoshop Desktop is affected by an Integer Overflow or
Wraparound vul ...)
+ TODO: check
+CVE-2026-75746 (ColdFusion is affected by an Improper Neutralization of
Special Elemen ...)
+ TODO: check
+CVE-2026-75742 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75741 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75740 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75739 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75738 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75737 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75736 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75735 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75734 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75733 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75731 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75730 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75729 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75727 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75726 (Adobe Experience Manager is affected by an Improper Input
Validation v ...)
+ TODO: check
+CVE-2026-75725 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75724 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75722 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75720 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75719 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75718 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75717 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75716 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75715 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75714 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75713 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75712 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75711 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75710 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75709 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75708 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75707 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75706 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75705 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75704 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75702 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75701 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75700 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75696 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75695 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75694 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75693 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75692 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75691 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75690 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75687 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75685 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75683 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75681 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75680 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75679 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75678 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75677 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75675 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75674 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75672 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75671 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75670 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75669 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75668 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75667 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75666 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75661 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75660 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75659 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75657 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75652 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75651 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75647 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75646 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75644 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75643 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75642 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-75640 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75639 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75637 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75636 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75635 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-75631 (Photoshop Desktop is affected by an out-of-bounds write
vulnerability ...)
+ TODO: check
+CVE-2026-75629 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-72627 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-72626 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-71565 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-71440 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-71388 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-71357 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-71356 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-6485 (UEFI BIOS embedded Shell could be used to bypass Secure Boot
via shell ...)
+ TODO: check
+CVE-2026-55250 (Maravel, a PHP framework oriented towards dependency
injection, prior ...)
+ TODO: check
+CVE-2026-53939 (OpenIDC/cjose is a C library implementing the Javascript
Object Signin ...)
+ TODO: check
+CVE-2026-53938 (OpenIDC/cjose is a C library implementing the Javascript
Object Signin ...)
+ TODO: check
+CVE-2026-53937 (MCP Kotlin SDK is the Kotlin Multiplatform software
development kit fo ...)
+ TODO: check
+CVE-2026-53933 (Maravel, a PHP framework oriented towards dependency
injection, prior ...)
+ TODO: check
+CVE-2026-53639 (Sylius is an Open Source eCommerce Framework on Symfony.
Starting in v ...)
+ TODO: check
+CVE-2026-53638 (Sylius is an Open Source eCommerce Framework on Symfony.
Starting in v ...)
+ TODO: check
+CVE-2026-53637 (Sylius is an Open Source eCommerce Framework on Symfony.
Versions 2.0. ...)
+ TODO: check
+CVE-2026-53581 (OPNsense is a FreeBSD based firewall and routing platform.
Prior to ve ...)
+ TODO: check
+CVE-2026-52486 (An issue in OpenDDS 3.33.x allows a local attacker to cause a
denial o ...)
+ TODO: check
+CVE-2026-49883 (In checkReadPermission of PermissionsManager.java, there is a
possible ...)
+ TODO: check
+CVE-2026-49315 (DoS vulnerability in the input device module. Impact:
Successful explo ...)
+ TODO: check
+CVE-2026-49314 (OOB write vulnerability in the rendering and composition
module. Impac ...)
+ TODO: check
+CVE-2026-49313 (Permission control vulnerability in the app lock module.
Impact: Succe ...)
+ TODO: check
+CVE-2026-49312 (Permission control vulnerability in the window module. Impact:
Success ...)
+ TODO: check
+CVE-2026-49311 (Permission control vulnerability in the event notification
module.Impa ...)
+ TODO: check
+CVE-2026-49310 (Permission control vulnerability in the event notification
module. Imp ...)
+ TODO: check
+CVE-2026-49309 (Permission control vulnerability in the Settings module.
Impact: Succe ...)
+ TODO: check
+CVE-2026-49156
+ REJECTED
+CVE-2026-49155
+ REJECTED
+CVE-2026-49154
+ REJECTED
+CVE-2026-49153
+ REJECTED
+CVE-2026-48273 (ColdFusion is affected by an Improper Neutralization of
Directives in ...)
+ TODO: check
+CVE-2026-47680 (The source-controller is a Kubernetes operator, specialised in
artifac ...)
+ TODO: check
+CVE-2026-45220
+ REJECTED
+CVE-2026-45219
+ REJECTED
+CVE-2026-41987 (Permission control vulnerability in the app management module.
Impact: ...)
+ TODO: check
+CVE-2026-30754 (A memory corruption vulnerability exists in FFmpeg before 8.1.
The RTP ...)
+ TODO: check
+CVE-2026-28659 (In MicroXR Blobstore, there is a possible way to access other
app's fi ...)
+ TODO: check
+CVE-2026-27227 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2026-21113 (Improper export of android application components in Visual
Voicemail ...)
+ TODO: check
+CVE-2026-21112 (Improper input validation in Samsung Tips prior to Android 17
allows l ...)
+ TODO: check
+CVE-2026-21111 (Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows
local a ...)
+ TODO: check
+CVE-2026-21110 (Out-of-bounds write in libsavscmn.so prior to One UI 8.5
allows local ...)
+ TODO: check
+CVE-2026-21109 (Improper access control in Watch Plugin prior to Android Watch
17 allo ...)
+ TODO: check
+CVE-2026-21108 (Improper export of android application components in Bixby
Touch prior ...)
+ TODO: check
+CVE-2026-21107 (Out-of-bounds write in Samsung Notes prior to version 4.4.45.5
allows ...)
+ TODO: check
+CVE-2026-21106 (Improper verification of intent by broadcast receiver in
Samsung Cloud ...)
+ TODO: check
+CVE-2026-21105 (Improper access control in Collection prior to version
1.0.1.14 in And ...)
+ TODO: check
+CVE-2026-21104 (Heap-based buffer overflow in KnoxVault trustlet prior to SMR
Sep-2026 ...)
+ TODO: check
+CVE-2026-21103 (Path traversal in GalaxyDiagnostics prior to SMR Sep-2026
Release 1 al ...)
+ TODO: check
+CVE-2026-21102 (Use after free in DualDAR prior to SMR Sep-2026 Release 1
allows local ...)
+ TODO: check
+CVE-2026-21101 (Improper input validation in DualDAR driver prior to SMR
Sep-2026 Rele ...)
+ TODO: check
+CVE-2026-21100 (Improper access control in SystemUI prior to SMR Sep-2026
Release 1 al ...)
+ TODO: check
+CVE-2026-21099 (Improper access control in SettingsProvider prior to SMR
Sep-2026 Rele ...)
+ TODO: check
+CVE-2026-21098 (Improper access control in Link to Windows prior to SMR
Sep-2026 Relea ...)
+ TODO: check
+CVE-2026-21097 (Improper authentication in ActivityTaskManagerService prior to
SMR Sep ...)
+ TODO: check
+CVE-2026-21096 (Heap-based buffer overflow in JPEG decoder of
libimagecodec.quram.so p ...)
+ TODO: check
+CVE-2026-21095 (Heap-based buffer overflow in DNG decoder of
libimagecodec.quram.so pr ...)
+ TODO: check
+CVE-2026-21094 (Improper input validation in wpa_supplicant prior to SMR
Sep-2026 Rele ...)
+ TODO: check
+CVE-2026-21093 (Stack-based buffer overflow in PROCA trustlet prior to SMR
Sep-2026 Re ...)
+ TODO: check
+CVE-2026-21092 (Path traversal in ImsService prior to SMR Sep-2026 Release 1
allows re ...)
+ TODO: check
+CVE-2026-21091 (Out-of-bounds write in libcodec2secevrcdec.so prior to SMR
Sep-2026 Re ...)
+ TODO: check
+CVE-2026-21090 (Out-of-bounds write in libsaviextractor.so prior to SMR
Sep-2026 Relea ...)
+ TODO: check
+CVE-2026-21089 (Improper input validation in removing style tag in
libsubextractor.so ...)
+ TODO: check
+CVE-2026-21088 (Improper input validation in loading a subtitle frame in
libsubextract ...)
+ TODO: check
+CVE-2026-21087 (Out-of-bounds write in libmdnie.so prior to SMR Sep-2026
Release 1 all ...)
+ TODO: check
+CVE-2026-21086 (Improper authorization in ProxyHandler prior to SMR Aug-2026
Release 1 ...)
+ TODO: check
+CVE-2026-21085 (Out-of-bounds write in Keymaster trustlet prior to SMR
Sep-2026 Releas ...)
+ TODO: check
+CVE-2026-19946 (The Awesome Support plugin for WordPress is vulnerable to
Missing Auth ...)
+ TODO: check
+CVE-2026-19945 (The WP Crowdfunding plugin for WordPress is vulnerable to
Stored Cross ...)
+ TODO: check
+CVE-2026-19944 (The WP Crowdfunding plugin for WordPress is vulnerable to
generic SQL ...)
+ TODO: check
+CVE-2026-19855 (The CleanTalk WordPress plugin before 6.87 does not prevent
unauthenti ...)
+ TODO: check
+CVE-2026-19802 (The Checkout Custom Fields Builder for WooCommerce plugin for
WordPres ...)
+ TODO: check
+CVE-2026-19800 (The Mail Mint \u2013 Email Marketing, Newsletter, Email
Automation & W ...)
+ TODO: check
+CVE-2026-19797 (The User Access Manager plugin for WordPress is vulnerable to
Reflecte ...)
+ TODO: check
+CVE-2026-19713 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-19644 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-19612 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-19479 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2026-19232 (Adobe Experience Manager is affected by an Incorrect
Authorization vul ...)
+ TODO: check
+CVE-2026-19201 (An uncontrolled recursion vulnerability in the Windows SIPA
event log ...)
+ TODO: check
+CVE-2026-18042 (The WP Travel WordPress plugin before 12.0.2 does not verify
that the ...)
+ TODO: check
+CVE-2026-17553 (The WP EasyCart plugin for WordPress is vulnerable to
privilege escala ...)
+ TODO: check
+CVE-2026-16960 (The Loops & Logic WordPress plugin before 4.3.0 does not
restrict its ...)
+ TODO: check
+CVE-2026-15667 (The Eventin \u2013 Event Calendar, Event Registration, Tickets
& Booki ...)
+ TODO: check
+CVE-2026-15406 (The Eventin \u2013 Event Calendar, Event Registration, Tickets
& Booki ...)
+ TODO: check
+CVE-2026-14962 (The ELEX WooCommerce Request a Quote WordPress plugin before
2.4.1 doe ...)
+ TODO: check
+CVE-2026-14892 (Tanium addressed an improper access controls vulnerability in
Tanium S ...)
+ TODO: check
+CVE-2026-14505 (Tanium addressed a path traversal vulnerability in Tanium Data
Service ...)
+ TODO: check
+CVE-2026-13709 (The Graphina \u2013 Charts and Graphs For Elementor plugin for
WordPre ...)
+ TODO: check
+CVE-2026-13359 (The Contact Form to DB by BestWebSoft \u2013 Messages Database
Plugin ...)
+ TODO: check
+CVE-2026-13146 (The WP Travel WordPress plugin before 12.0.2 does not
properly verify ...)
+ TODO: check
+CVE-2026-13144 (The WP Travel WordPress plugin before 12.0.2 does not
properly verify ...)
+ TODO: check
+CVE-2026-12956 (The WP Event Solution (Eventin) plugin for WordPress is
vulnerable to ...)
+ TODO: check
+CVE-2026-12855 (Unvalidated memory boundary could result in arbitrary code
execution. ...)
+ TODO: check
+CVE-2026-11821 (The Eventin \u2013 Event Calendar, Event Registration, Tickets
& Booki ...)
+ TODO: check
+CVE-2026-11363 (The Ninja Forms \u2013 The Contact Form Builder That Grows
With You pl ...)
+ TODO: check
+CVE-2025-7062 (A stored cross-site scripting (XSS) vulnerability has been
identified ...)
+ TODO: check
+CVE-2025-64868 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64866 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64854 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64838 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64830 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64618 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64610 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64589 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64588 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64584 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
+ TODO: check
+CVE-2025-64542 (Adobe Experience Manager is affected by a DOM-based Cross-Site
Scripti ...)
+ TODO: check
+CVE-2025-15690 (The Content Mask WordPress plugin before 1.8.5.6 does not
properly san ...)
+ TODO: check
CVE-2026-87065
NOT-FOR-US: konflux-operator-tasks
CVE-2026-87064
@@ -32,25 +1204,25 @@ CVE-2026-87050
NOT-FOR-US: operator-foundry
CVE-2026-87049
NOT-FOR-US: operator-foundry
-CVE-2026-86564
+CVE-2026-86564 (A flaw was found in DPDK lib/vhost. Missing length validation
before r ...)
- dpdk <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2529682
-CVE-2026-85630
+CVE-2026-85630 (HTML::FormHandler versions before 0.410002 for Perl render
field attri ...)
- libhtml-formhandler-perl <unfixed>
[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43387553/
NOTE: Fixed by:
https://github.com/gshank/html-formhandler/commit/a887271e91d755e6486a9f433ae932deb1d2c4a6
(0.410002)
-CVE-2026-85485
+CVE-2026-85485 (HTML::FormHandler versions before 0.410002 for Perl render
some error ...)
- libhtml-formhandler-perl <unfixed>
[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43387537/
NOTE: Fixed by:
https://github.com/gshank/html-formhandler/commit/2ea9e138dbfe231e317c13936abe6583217c807f
(0.410002)
-CVE-2026-85484
+CVE-2026-85484 (HTML::FormHandler versions before 0.410002 for Perl render
option grou ...)
- libhtml-formhandler-perl <unfixed>
[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43387507/
NOTE: Fixed by:
https://github.com/gshank/html-formhandler/commit/49b562e0fed5146fc1a372c5fa8a879876b8841d
(0.410002)
-CVE-2026-19872
+CVE-2026-19872 (HTML::FormHandler versions before 0.410000 for Perl allow
cross-site s ...)
- libhtml-formhandler-perl <unfixed>
[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43387502/
@@ -2664,7 +3836,7 @@ CVE-2026-0054 (In isCallerAllowed of
WalletContextualLocationsService.kt, there
NOT-FOR-US: Android
CVE-2026-0001 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel
Driver, Arm ...)
NOT-FOR-US: ARM
-CVE-2026-18090
+CVE-2026-18090 (A flaw was found in gdk-pixbuf. This vulnerability allows a
remote att ...)
- gdk-pixbuf <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517751
CVE-2026-86544 (knowns versions before 0.30.0 contain an authorization bypass
vulnerab ...)
@@ -6593,24 +7765,31 @@ CVE-2026-XXXX [Out-of-bounds read in RGB-YCbCr
identity-matrix colour conversion
- libheif 1.23.3-1
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-9rj8-5mp5-26c9
CVE-2026-65107 [Fix sbcast shared objects skipping credential verification,
Fix possible slurmd crash on invalid sbcast filenames]
+ {DSA-6491-1}
- slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65108 [Fix a slurmstepd stack overflow when a job environment
contains an oversized SPANK option variable]
+ {DSA-6491-1}
- slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65109 [Fix slurmstepd removing files outside the container spool
directory when cleaning up an OCI containe, Fix slurmstepd leaving OCI
container spool directories behind when ContainerPath contains a task id
pattern]
+ {DSA-6491-1}
- slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65138 [Fix heap over-read when unpacking a malformed forward data RPC
in slurmd. Fix a slurmd crash when handling a malformed forward data RPC with a
missing socket address]
+ {DSA-6491-1}
- slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65139 [Fix various issues in unsafe operation/queries to the slurmdbd]
+ {DSA-6491-1}
- slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65140 [Fix a privilege escalation where an operator could alter
Administrator accounts through the accounting database]
+ {DSA-6491-1}
- slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65165 [Fix various issues around job steps and node count
discrepancies]
+ {DSA-6491-1}
- slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-76642 (util-linux versions through 2.41.5 and 2.42.2 fail to check
mount help ...)
@@ -7725,9 +8904,9 @@ CVE-2026-77849
NOT-FOR-US: grafana-global-hub
CVE-2026-75762
NOT-FOR-US: multicluster-global-hub
-CVE-2026-19625
+CVE-2026-19625 (When a Quarkus application has multiple endpoints secured by
individua ...)
NOT-FOR-US: Quarkus OIDC
-CVE-2026-19651
+CVE-2026-19651 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and
3.33.1 thro ...)
NOT-FOR-US: Quarkus
CVE-2026-48521
- envoyproxy <itp> (bug #987544)
@@ -13087,7 +14266,7 @@ CVE-2026-19715 (The WP OAuth Server ( Login with
WordPress ) WordPress plugin be
NOT-FOR-US: WordPress plugin
CVE-2026-19454 (The JetBackup WordPress plugin before 3.1.23.5 does not
perform its m ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-19398 (\u201cunsupported-when-assigned.\u201d An out-of-bounds write
in the S ...)
+CVE-2026-19398 (An out-of-bounds write in the SmiFlash SMM module of ASUS
FA507NU and ...)
NOT-FOR-US: ASUS
CVE-2026-19225 (The Defender Security WordPress plugin before 6.2.0 does not
restrict ...)
NOT-FOR-US: WordPress plugin
@@ -18515,6 +19694,7 @@ CVE-2026-53527 (LeafWiki is a self-hosted wiki.
Versions 0.1.0 through 0.10.0 ha
CVE-2026-53509 (CKAN MCP Server is a tool for querying CKAN open data portals.
A known ...)
NOT-FOR-US: CKAN MCP Server
CVE-2026-53499 (FORT Validator is a Resource Public Key Infrastructure (RPKI)
relying- ...)
+ {DSA-6490-1}
- fort-validator 1.6.8-1
NOTE:
https://github.com/NICMx/FORT-validator/security/advisories/GHSA-qfm3-577x-rh54
NOTE: Fixed by:
https://github.com/NICMx/FORT-validator/commit/284023585ea74d64175c5e25ec674a563aa9e81c
(1.6.8)
@@ -32670,7 +33850,7 @@ CVE-2024-58374 (Hongjing e-HR contains an
unauthenticated SQL injection vulnerab
NOT-FOR-US: Hongjing e-HR
CVE-2019-25765 (ASP-CMS contains a SQL injection vulnerability in the
commentList.asp ...)
NOT-FOR-US: ASP-CMS
-CVE-2022-4993 (HTML::FormHandler versions through 0.40068 for Perl allow
attacker sel ...)
+CVE-2022-4993 (HTML::FormHandler versions before 0.410000 for Perl allow
attacker sel ...)
- libhtml-formhandler-perl 0.40068-3
[trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue; will be
fixed via point release)
[bookworm] - libhtml-formhandler-perl <postponed> (Minor issue; will be
fixed via point release)
@@ -35927,7 +37107,7 @@ CVE-2026-21279 (is affected by an Improper Input
Validation vulnerability that c
NOT-FOR-US: Adobe
CVE-2026-21273 (is affected by an Improper Input Validation vulnerability that
could r ...)
NOT-FOR-US: Adobe
-CVE-2026-21269 (is affected by a stored Cross-Site Scripting (XSS)
vulnerability that ...)
+CVE-2026-21269 (ColdFusion is affected by a stored Cross-Site Scripting (XSS)
vulnerab ...)
NOT-FOR-US: Adobe
CVE-2026-20913 (Improper input validation for some Intel(R) Neural Compressor
software ...)
NOT-FOR-US: Intel
@@ -65392,7 +66572,7 @@ CVE-2026-57433 (Storable versions before 3.41 for Perl
have a signed integer ove
- libstorable-perl <removed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780100/
NOTE: Fixed by:
https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7
(v5.43.11)
-CVE-2026-57432 (Perl versions through 5.43.10 have an integer overflow in
S_measure_st ...)
+CVE-2026-57432 (Perl versions before 5.40.5-RC1, from 5.41.0 before
5.42.3-RC1, from 5 ...)
- perl 5.40.1-8 (bug #1138905; bug #1142036)
[trixie] - perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780102/
@@ -65613,7 +66793,7 @@ CVE-2026-14453 (This vulnerability is a critical
Server-Side Template Injection
NOT-FOR-US: Centreon
CVE-2026-14165 (An Authorization Bypass Through User-Controlled Key
vulnerability affe ...)
NOT-FOR-US: Dassault Systemes
-CVE-2026-13221 (Perl versions through 5.43.9 produce silently incorrect
regular expres ...)
+CVE-2026-13221 (Perl versions before 5.40.5-RC1, from 5.41.0 before
5.42.3-RC1, from 5 ...)
[experimental] - perl 5.44.0-1
- perl 5.42.3-1 (bug #1142037)
[trixie] - perl <no-dsa> (Minor issue)
@@ -67410,7 +68590,7 @@ CVE-2026-0279 (Multiple cross site scripting
vulnerabilities in the User-ID\u212
NOT-FOR-US: Palo Alto Networks
CVE-2025-63579 (Unauthorized use of Kyocera printers, allows all information
stored in ...)
NOT-FOR-US: Kyocera
-CVE-2026-57825
+CVE-2026-57825 (In the opam package before 2.5.2 for OCaml, the sandbox
protection mec ...)
{DSA-6386-1 DLA-4684-1}
- opam 2.5.2-1
NOTE:
https://github.com/ocaml/security-advisories/blob/main/advisories/2026/OSEC-2026-10.md
@@ -103664,7 +104844,7 @@ CVE-2026-5091 (Catalyst::Plugin::Authentication
versions through 0.10024 for Per
[bullseye] - libcatalyst-plugin-authentication-perl <postponed> (Minor
issue, side channel)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40281889/
NOTE:
https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b0515f492257438cf07082acf1e10d06e8088a5e
(v0.10_025)
-CVE-2026-8376 (Perl versions through 5.43.10 have a heap buffer overflow when
compili ...)
+CVE-2026-8376 (Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1,
from 5 ...)
- perl 5.40.1-8 (bug #1137345)
[trixie] - perl <no-dsa> (Minor issue; can be fixed in point release)
[bookworm] - perl <no-dsa> (Minor issue; can be fixed in point release)
@@ -126603,7 +127783,7 @@ CVE-2026-27287 (InCopy versions 20.5.2, 21.2 and
earlier are affected by an out-
NOT-FOR-US: Adobe
CVE-2026-27282 (ColdFusion versions 2023.18, 2025.6 and earlier are affected
by an Imp ...)
NOT-FOR-US: Adobe
-CVE-2026-27222 (Bridge versions 16.0.2, 15.1.4 and earlier are affected by a
Divide By ...)
+CVE-2026-27222 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
NOT-FOR-US: Adobe
CVE-2026-26291 (Stored cross-site scripting vulnerability exists in GROWI
v7.4.6 and e ...)
NOT-FOR-US: GROWI
@@ -127022,7 +128202,7 @@ CVE-2026-27284 (InDesign Desktop versions 20.5.2,
21.2 and earlier are affected
NOT-FOR-US: Adobe
CVE-2026-27283 (InDesign Desktop versions 20.5.2, 21.2 and earlier are
affected by a U ...)
NOT-FOR-US: Adobe
-CVE-2026-27258 (DNG SDK versions 1.7.1 2502 and earlier are affected by an
out-of-boun ...)
+CVE-2026-27258 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
NOT-FOR-US: Adobe
CVE-2026-27246 (Adobe Connect versions 2025.3, 12.10 and earlier are affected
by a DOM ...)
NOT-FOR-US: Adobe
@@ -127030,7 +128210,7 @@ CVE-2026-27245 (Adobe Connect versions 2025.3, 12.10
and earlier are affected by
NOT-FOR-US: Adobe
CVE-2026-27243 (Adobe Connect versions 2025.3, 12.10 and earlier are affected
by a ref ...)
NOT-FOR-US: Adobe
-CVE-2026-27238 (InDesign Desktop versions 20.5.2, 21.2 and earlier are
affected by a H ...)
+CVE-2026-27238 (Adobe Experience Manager is affected by a stored Cross-Site
Scripting ...)
NOT-FOR-US: Adobe
CVE-2026-26184 (Buffer over-read in Windows Projected File System allows an
authorized ...)
NOT-FOR-US: Microsoft
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c4e18e9c361afd4b99caef6c18d13f15eba7aacd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c4e18e9c361afd4b99caef6c18d13f15eba7aacd
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits