Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
708c96e2 by security tracker role at 2026-09-10T07:12:49+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,217 @@
+CVE-2026-88069 (Pandora contains a path traversal vulnerability in its archive 
extract ...)
+       TODO: check
+CVE-2026-88002 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-88001 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-88000 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87999 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87998 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87997 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87996 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87995 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87994 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87933 (A vulnerability was found in DaveGamble cJSON up to 1.7.19. 
The affect ...)
+       TODO: check
+CVE-2026-87931 (A vulnerability has been found in Behavioral Technology Group 
Pavlok B ...)
+       TODO: check
+CVE-2026-87926 (A flaw has been found in Rizwan17 inventory-management-system 
up to bf ...)
+       TODO: check
+CVE-2026-87925 (A vulnerability was detected in Rizwan17 
inventory-management-system u ...)
+       TODO: check
+CVE-2026-87924 (A security vulnerability has been detected in Rizwan17 
inventory-manag ...)
+       TODO: check
+CVE-2026-87923 (A weakness has been identified in Rizwan17 
inventory-management-system ...)
+       TODO: check
+CVE-2026-87922 (A security flaw has been discovered in Rizwan17 
inventory-management-s ...)
+       TODO: check
+CVE-2026-87921 (A vulnerability was identified in Rizwan17 
inventory-management-system ...)
+       TODO: check
+CVE-2026-87911 (An OS command injection weakness in the read-only enforcement 
of the S ...)
+       TODO: check
+CVE-2026-87870 (The Ninja Forms - Scheduled Exports plugin for WordPress is 
vulnerable ...)
+       TODO: check
+CVE-2026-87804
+       REJECTED
+CVE-2026-87017 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87016 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87015 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87014 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87013 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87012 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-87011 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-85645 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop 
Contact For ...)
+       TODO: check
+CVE-2026-84939 (Path traversal vulnerability in Apache FreeMarker template 
loading mec ...)
+       TODO: check
+CVE-2026-84063 (BurgerEditor 3.2.0 through 3.4.0 contains an issue with 
unrestricted u ...)
+       TODO: check
+CVE-2026-84062 (BurgerEditor 3.0.0 through 3.4.0 contains an issue with 
authorization  ...)
+       TODO: check
+CVE-2026-82925 (The Site Reviews WordPress plugin before 8.3.0 does not 
prevent reques ...)
+       TODO: check
+CVE-2026-82582 (An authorization bypass vulnerability exists in SHIRASAGI 
through a us ...)
+       TODO: check
+CVE-2026-82079 (A stack-based buffer overflow vulnerability in the Nintendo 
Switch loc ...)
+       TODO: check
+CVE-2026-81635 (A cross-site scripting vulnerability exists in SHIRASAGI, 
which may al ...)
+       TODO: check
+CVE-2026-81431 (The Registration Form for WooCommerce WordPress plugin before 
1.1.3 do ...)
+       TODO: check
+CVE-2026-79522 (An out-of-bounds read in the gf_dm_get_chunk_data function 
(src/utils/ ...)
+       TODO: check
+CVE-2026-79516 (An out-of-bounds read in the stbsp_vsnprintf function 
(stb_sprintf.h)  ...)
+       TODO: check
+CVE-2026-79515 (An out-of-bounds read in the stbtt_GetGlyphShape component of 
nothings ...)
+       TODO: check
+CVE-2026-79514 (An out-of-bounds read in the gf_dm_data_received function 
(downloader. ...)
+       TODO: check
+CVE-2026-79513 (A divide-by-zero vulnerability in the 
gf_dash_get_timeline_duration fu ...)
+       TODO: check
+CVE-2026-79387 (SQL injection vulnerability in PbootCMS versions 3.2.0 through 
3.2.5 a ...)
+       TODO: check
+CVE-2026-79324 (Missing authorization in the Address Delete controller in 
Mageplaza GD ...)
+       TODO: check
+CVE-2026-78361 (The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress 
plugin  ...)
+       TODO: check
+CVE-2026-77771 (The miniOrange 2FA  WordPress plugin before 6.3.1, miniOrange 
2FA  Wor ...)
+       TODO: check
+CVE-2026-77770 (The miniOrange 2FA  WordPress plugin before 6.3.1, miniOrange 
2FA  Wor ...)
+       TODO: check
+CVE-2026-76562 (The Sidebar Manager Light plugin for WordPress is vulnerable 
to Stored ...)
+       TODO: check
+CVE-2026-75880 (An authenticated client could attach a consumer with a 
selector contai ...)
+       TODO: check
+CVE-2026-75308 (yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). 
The file  ...)
+       TODO: check
+CVE-2026-75307 (zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS) 
via SVG f ...)
+       TODO: check
+CVE-2026-73789 (A vulnerability in the web-based management interface of CPPM 
guest ac ...)
+       TODO: check
+CVE-2026-73788 (A vulnerability in the ClearPass OnGuard agent could allow an 
authenti ...)
+       TODO: check
+CVE-2026-73787 (A vulnerability in the CPPM web interface could allow an 
authenticated ...)
+       TODO: check
+CVE-2026-73786 (A vulnerability in the web-based management interface of CPPM 
could al ...)
+       TODO: check
+CVE-2026-73769 (A vulnerability in the web-based management interface of 
vulnerable CP ...)
+       TODO: check
+CVE-2026-71809 (Authentication Bypass via Hardcoded Master Verification Code 
vulnerabi ...)
+       TODO: check
+CVE-2026-71808 (A SQL Injection vulnerability in Siam Ordering (siam-server) 
1.0.0 all ...)
+       TODO: check
+CVE-2026-71807 (In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, 
multiple co ...)
+       TODO: check
+CVE-2026-71805 (An arbitrary file upload and path traversal vulnerability 
exists in LZ ...)
+       TODO: check
+CVE-2026-71803 (money-pos 1.0 contains a stored Cross-Site Scripting (XSS) 
vulnerabili ...)
+       TODO: check
+CVE-2026-71802 (A stored Cross-Site Scripting (XSS) vulnerability exists in 
the announ ...)
+       TODO: check
+CVE-2026-71801 (An issue was discovered in s-pms SPMS-Server through v1.0. The 
applica ...)
+       TODO: check
+CVE-2026-71616 (An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 
allows an at ...)
+       TODO: check
+CVE-2026-71614 (An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 
allows an at ...)
+       TODO: check
+CVE-2026-71613 (Buffer Overflow vulnerability in GPAC 
c2dee3aff638cd96f9617ac5b17dc286 ...)
+       TODO: check
+CVE-2026-71612 (Buffer Overflow vulnerability in GPAC 
c2dee3aff638cd96f9617ac5b17dc286 ...)
+       TODO: check
+CVE-2026-67593 (A remote attacker can craft an Openwire RemoveSubscriptionInfo 
command ...)
+       TODO: check
+CVE-2026-61915 (An issue was discovered in Cyrus IMAP before 3.12.4. There is 
a VPATCH ...)
+       TODO: check
+CVE-2026-61911 (An issue was discovered in Cyrus IMAP before 3.12.4. There is 
a Sieve  ...)
+       TODO: check
+CVE-2026-61910 (An issue was discovered in Cyrus IMAP before 3.12.4. 
Mailbox/set let a ...)
+       TODO: check
+CVE-2026-61909 (An issue was discovered in Cyrus IMAP before 3.12.4. 
CalDAV/CardDAV mu ...)
+       TODO: check
+CVE-2026-61908 (An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP 
email-head ...)
+       TODO: check
+CVE-2026-57967 (An unauthenticated remote attacker can craft a CORE protocol 
SESSION_R ...)
+       TODO: check
+CVE-2026-57822 (When the broker is processing message-based management 
requests, sent  ...)
+       TODO: check
+CVE-2026-53956 (Rattler is a library that provides common functionality used 
within th ...)
+       TODO: check
+CVE-2026-50165 (alf.io is an open source ticket reservation system for 
conferences, tr ...)
+       TODO: check
+CVE-2026-4657 (The Easy Google Fonts plugin for WordPress is vulnerable to 
Stored Cro ...)
+       TODO: check
+CVE-2026-49364 (An unauthenticated network-adjacent attacker can leverage 
discovery to ...)
+       TODO: check
+CVE-2026-49363 (An unauthenticated remote attacker connecting with the CORE 
protocol c ...)
+       TODO: check
+CVE-2026-49362 (An unauthenticated remote attacker can create arbitrary 
durable queues ...)
+       TODO: check
+CVE-2026-38998 (A use-after-free in the SocketDescriptor::tcpReadHandler1 
function (li ...)
+       TODO: check
+CVE-2026-36433 (An issue in Actions Semiconductor Co. Ltd Tool- Media Player 
Utilities ...)
+       TODO: check
+CVE-2026-19840 (The Notiqoo  WordPress plugin before 1.4.14 does not have 
capability c ...)
+       TODO: check
+CVE-2026-19584 (Velociraptor allows for the creation of notebook backups in 
its defaul ...)
+       TODO: check
+CVE-2026-19583 (Velociraptor allows some sensitive artifacts to be gated by 
additional ...)
+       TODO: check
+CVE-2026-19439 (The Ultimate Gift Cards for WooCommerce WordPress plugin 
before 3.2.10 ...)
+       TODO: check
+CVE-2026-19436 (The Ultimate Gift Cards for WooCommerce WordPress plugin 
before 3.2.10 ...)
+       TODO: check
+CVE-2026-18594 (The Advanced Contact form 7 DB plugin for WordPress is 
vulnerable to a ...)
+       TODO: check
+CVE-2026-18386 (The WP BackItUp Community Edition plugin for WordPress is 
vulnerable t ...)
+       TODO: check
+CVE-2026-18351 (The Drag and Drop File Upload for Elementor Forms plugin for 
WordPress ...)
+       TODO: check
+CVE-2026-15913 (In versions prior to 7.10.2 a path traversal vulnerability in 
the/atta ...)
+       TODO: check
+CVE-2026-15823 (The Builderall Cheetah For Wp plugin for WordPress is 
vulnerable to un ...)
+       TODO: check
+CVE-2026-15820 (The Builderall for WordPress plugin for WordPress is 
vulnerable to Sto ...)
+       TODO: check
+CVE-2026-15796 (The Builderall for WordPress plugin for WordPress is 
vulnerable to Sto ...)
+       TODO: check
+CVE-2026-15460 (The Bluetooth Classic (BR/EDR) L2CAP receive handler 
bt_l2cap_br_recv( ...)
+       TODO: check
+CVE-2026-15019 (The Direct Download for WooCommerce plugin for WordPress is 
vulnerable ...)
+       TODO: check
+CVE-2026-14873 (The Bulk Password Reset plugin for WordPress is vulnerable to 
privileg ...)
+       TODO: check
+CVE-2026-0310 (A buffer overflow vulnerability in the XML processing 
functionality of ...)
+       TODO: check
+CVE-2026-0309 (A command injection vulnerability in Palo Alto Networks 
PAN-OS\xae sof ...)
+       TODO: check
+CVE-2026-0308 (A stored cross-site scripting (XSS) vulnerability in Palo Alto 
Network ...)
+       TODO: check
+CVE-2026-0307 (Multiple local privilege escalation vulnerabilities in the Palo 
Alto N ...)
+       TODO: check
+CVE-2026-0306 (A vulnerability in the EndPoint Data Loss Prevention (DLP) 
enforcement ...)
+       TODO: check
+CVE-2026-0305 (An information disclosure vulnerability in the Palo Alto 
Networks Pris ...)
+       TODO: check
+CVE-2026-0304 (A privilege escalation vulnerability in Palo Alto Networks 
Cortex XDR  ...)
+       TODO: check
+CVE-2026-0303 (A code execution vulnerability in Palo Alto Networks Checkov by 
Prisma ...)
+       TODO: check
+CVE-2026-0302 (An OS command injection vulnerability in Palo Alto Networks 
Checkov by ...)
+       TODO: check
 CVE-2026-19816
        - packagekit 1.4.0-1
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2515940
@@ -64667,16 +64881,19 @@ CVE-2026-59888 (jackson-databind contains the 
general-purpose data-binding funct
        NOTE: https://github.com/FasterXML/jackson-databind/pull/5974
        NOTE: Fixed by: 
https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d
 (jackson-databind-2.18.8)
 CVE-2026-59886 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, 
the univ ...)
+       {DLA-4778-1}
        - pyasn1 0.6.4-1 (bug #1142388)
        [trixie] - pyasn1 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r
        NOTE: Fixed by: 
https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886
 (v0.6.4)
 CVE-2026-59885 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, 
the BER, ...)
+       {DLA-4778-1}
        - pyasn1 0.6.4-1 (bug #1142388)
        [trixie] - pyasn1 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj
        NOTE: Fixed by: 
https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9
 (v0.6.4)
 CVE-2026-59884 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, 
the BER  ...)
+       {DLA-4778-1}
        - pyasn1 0.6.4-1 (bug #1142388)
        [trixie] - pyasn1 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/708c96e2f2b1685871c45808abfe6548c840fd2f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/708c96e2f2b1685871c45808abfe6548c840fd2f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to