Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7cce2d77 by security tracker role at 2026-09-10T19:14:09+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,477 @@
+CVE-2026-9338 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to 
a denia ...)
+       TODO: check
+CVE-2026-9336 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to 
a denia ...)
+       TODO: check
+CVE-2026-9166 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
+       TODO: check
+CVE-2026-9163 (Improper neutralization of special elements used in an SQL 
command ('S ...)
+       TODO: check
+CVE-2026-9161 (Observable response discrepancy vulnerability in DernekPlus 
Website Te ...)
+       TODO: check
+CVE-2026-8323 (URL redirection to untrusted site ('open redirect') 
vulnerability in A ...)
+       TODO: check
+CVE-2026-89049 (A server-side request forgery issue due to improper validation 
of equi ...)
+       TODO: check
+CVE-2026-89046 (zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an 
out-of-bounds re ...)
+       TODO: check
+CVE-2026-89045 (zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate 
negative l ...)
+       TODO: check
+CVE-2026-89044 (Netty versions 4.1.133.Final through 4.1.137.Final and 
4.2.13.Final th ...)
+       TODO: check
+CVE-2026-89043 (passport-saml-encrypted through 0.1.13 contains an XML 
signature wrapp ...)
+       TODO: check
+CVE-2026-89042 (passport-saml-encrypted through 0.1.13 makes SAML signature 
verificati ...)
+       TODO: check
+CVE-2026-88959 (Anchor CMS through 0.12.7 fails to enforce role-based access 
control i ...)
+       TODO: check
+CVE-2026-88940 (knowns through 0.33.0 fails to validate the path query 
parameter in th ...)
+       TODO: check
+CVE-2026-88939 (knowns through 0.33.0 exempts the project.set action from 
permission g ...)
+       TODO: check
+CVE-2026-88938 (knowns through 0.33.0 fails to confine the path argument of 
the code.f ...)
+       TODO: check
+CVE-2026-88937 (knowns through 0.33.0 fails to properly validate template 
destination  ...)
+       TODO: check
+CVE-2026-88924 (A flaw was found in the admin backend of gvfs. The privileged 
gvfsd-ad ...)
+       TODO: check
+CVE-2026-88921 (MISP contains an HTML injection vulnerability in the 
MISPElementHTMLFo ...)
+       TODO: check
+CVE-2026-88915 (Affected versions of MISP do not consistently enforce the 
acting user' ...)
+       TODO: check
+CVE-2026-88899 (knowns versions before 0.31.0 fail to properly validate the 
x-opencode ...)
+       TODO: check
+CVE-2026-88898 (AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize 
callers ...)
+       TODO: check
+CVE-2026-88897 (Flextype CMS through 1.0.0-alpha.3 accepts API authentication 
credenti ...)
+       TODO: check
+CVE-2026-88896 (EspoCRM before 10.0.4 is vulnerable to server-side request 
forgery. Ho ...)
+       TODO: check
+CVE-2026-88895 (CyberPanel before 3.0.5 fails to enforce two-factor 
authentication on  ...)
+       TODO: check
+CVE-2026-88894 (Snipe-IT's predefined kit checkout path does not enforce Full 
Multiple ...)
+       TODO: check
+CVE-2026-88893 (OpenPanel share lookup procedures fail to validate access 
controls and ...)
+       TODO: check
+CVE-2026-88892 (OpenPanel is an analytics platform. In all versions (no 
patched releas ...)
+       TODO: check
+CVE-2026-88891 (OpenPanel fails to enforce read-only project access level on 
26 of 29  ...)
+       TODO: check
+CVE-2026-88890 (OpenPanel through commit cd24bb8 contains an SQL injection 
vulnerabili ...)
+       TODO: check
+CVE-2026-88889 (Renovate before 44.14.7 contains a command injection 
vulnerability in  ...)
+       TODO: check
+CVE-2026-88888 (Renovate before 44.14.7 contains a command injection 
vulnerability in  ...)
+       TODO: check
+CVE-2026-88887 (Renovate is a dependency update automation tool. When listing 
tags/dig ...)
+       TODO: check
+CVE-2026-88886 (Renovate is a dependency update automation tool. In versions 
before 44 ...)
+       TODO: check
+CVE-2026-88885 (Renovate before 44.14.7 contains a command injection 
vulnerability in  ...)
+       TODO: check
+CVE-2026-88884 (Renovate is a dependency update automation tool. In versions 
before 44 ...)
+       TODO: check
+CVE-2026-88883 (Renovate is an automated dependency update tool. In versions 
before 44 ...)
+       TODO: check
+CVE-2026-88882 (Renovate is a dependency update automation tool. In versions 
before 44 ...)
+       TODO: check
+CVE-2026-88881 (Renovate, a dependency update tool, follows pagination links 
supplied  ...)
+       TODO: check
+CVE-2026-88880 (Renovate before 44.11.3 fails to validate Link header 
destinations whe ...)
+       TODO: check
+CVE-2026-88879 (Traefik is an HTTP reverse proxy and load balancer. In Traefik 
v1.x, v ...)
+       TODO: check
+CVE-2026-88878 (Traefik is an HTTP reverse proxy and load balancer. In 
versions >= v2. ...)
+       TODO: check
+CVE-2026-88877 (Traefik is a HTTP reverse proxy and load balancer. In versions 
>= v3.7 ...)
+       TODO: check
+CVE-2026-88876 (AVideo through revision 
c3edcc274c389816d434acadac07ee78eaf330c1 conta ...)
+       TODO: check
+CVE-2026-88875 (AVideo through revision 
c3edcc274c389816d434acadac07ee78eaf330c1 (mast ...)
+       TODO: check
+CVE-2026-88874 (AVideo through revision 
c3edcc274c389816d434acadac07ee78eaf330c1 (mast ...)
+       TODO: check
+CVE-2026-88873 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+       TODO: check
+CVE-2026-88872 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
contain ...)
+       TODO: check
+CVE-2026-88871 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 (m ...)
+       TODO: check
+CVE-2026-88870 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+       TODO: check
+CVE-2026-88869 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
contain ...)
+       TODO: check
+CVE-2026-88868 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
contain ...)
+       TODO: check
+CVE-2026-88867 (WWBN AVideo, in versions up to and including commit 
c3edcc274c389816d4 ...)
+       TODO: check
+CVE-2026-88866 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
+       TODO: check
+CVE-2026-88865 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
fails t ...)
+       TODO: check
+CVE-2026-88864 (Capgo (capgo.app) fails to restrict direct write access to the 
public. ...)
+       TODO: check
+CVE-2026-88863 (capgo.app (npm package `capgo`) through version 12.207.1 does 
not comp ...)
+       TODO: check
+CVE-2026-88862 (Capgo (capgo.app) backend through 12.242.4 does not validate 
parent-ch ...)
+       TODO: check
+CVE-2026-88861 (Capgo (Cap-go/capgo.app) contains an authentication bypass 
affecting a ...)
+       TODO: check
+CVE-2026-88860 (Capgo fails to clean up channel permission overrides when a 
user's las ...)
+       TODO: check
+CVE-2026-88859 (A flaw was found in Evolution. A remote attacker can exploit 
this vuln ...)
+       TODO: check
+CVE-2026-88790 (A security vulnerability has been detected in proma-ai Proma 
up to 0.1 ...)
+       TODO: check
+CVE-2026-88770 (A flaw was found in the Device Authorization Grant flow of 
Keycloak, a ...)
+       TODO: check
+CVE-2026-88763 (A flaw was found in the skupper-router component of Red Hat 
Service In ...)
+       TODO: check
+CVE-2026-88290 (GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated 
clients to  ...)
+       TODO: check
+CVE-2026-88289 (GeoVision GV-LPC2211 V1.14 (260903) fails to validate 
attacker-control ...)
+       TODO: check
+CVE-2026-88288 (GeoVision GV-LPC2211 V1.13 fails to restrict the filename 
supplied to  ...)
+       TODO: check
+CVE-2026-88287 (GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes 
tokens  ...)
+       TODO: check
+CVE-2026-88286 (GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection 
state, al ...)
+       TODO: check
+CVE-2026-88285 (GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ 
control se ...)
+       TODO: check
+CVE-2026-88284 (GeoVision GV-LPC2211 V1.13 fails to limit repeated User 
elements in ON ...)
+       TODO: check
+CVE-2026-88283 (GeoVision GV-LPC2211 V1.13 fails to limit repeated User 
elements in ON ...)
+       TODO: check
+CVE-2026-88282 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled 
FTP user ...)
+       TODO: check
+CVE-2026-88281 (GeoVision GV-LPC2211 V1.13 fails to limit repeated Username 
elements i ...)
+       TODO: check
+CVE-2026-88280 (GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser 
password  ...)
+       TODO: check
+CVE-2026-88279 (GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers 
username ...)
+       TODO: check
+CVE-2026-88278 (GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security 
UsernameToken  ...)
+       TODO: check
+CVE-2026-88277 (GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user 
to injec ...)
+       TODO: check
+CVE-2026-88276 (GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP 
key val ...)
+       TODO: check
+CVE-2026-88275 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled 
WPA-PSK  ...)
+       TODO: check
+CVE-2026-88274 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled 
wireless ...)
+       TODO: check
+CVE-2026-88273 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled 
PPPoE us ...)
+       TODO: check
+CVE-2026-88272 (GeoVision GV-LPC2211 V1.13 allows an administrator-controlled 
username ...)
+       TODO: check
+CVE-2026-88271 (GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite 
device con ...)
+       TODO: check
+CVE-2026-88270 (GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR 
firmware- ...)
+       TODO: check
+CVE-2026-88269 (GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve 
persistent  ...)
+       TODO: check
+CVE-2026-88268 (GeoVision GV-LPC2211 V1.13 contains an authenticated stack 
buffer over ...)
+       TODO: check
+CVE-2026-88265 (A flaw was found in crun. After pivot_root, reopening 
/dev/null for st ...)
+       TODO: check
+CVE-2026-88264 (A flaw was found in crun. When the container configuration 
does not gi ...)
+       TODO: check
+CVE-2026-88060 (Angular is a development platform for building mobile and 
desktop web  ...)
+       TODO: check
+CVE-2026-88059 (Angular is a development platform for building mobile and 
desktop web  ...)
+       TODO: check
+CVE-2026-88058 (Angular is a development platform for building mobile and 
desktop web  ...)
+       TODO: check
+CVE-2026-88057 (Angular is a development platform for building mobile and 
desktop web  ...)
+       TODO: check
+CVE-2026-88056 (Angular is a development platform for building mobile and 
desktop web  ...)
+       TODO: check
+CVE-2026-88055 (AnythingLLM is an application that turns pieces of content 
into contex ...)
+       TODO: check
+CVE-2026-88054 (Tesseract is an open source OCR engine. In version 5.5.3 and 
earlier,  ...)
+       TODO: check
+CVE-2026-88053 (Tesseract is an open source OCR engine. In version 5.5.3 and 
earlier,  ...)
+       TODO: check
+CVE-2026-88052 (Tesseract is an open source OCR engine. In version 5.5.3 and 
earlier,  ...)
+       TODO: check
+CVE-2026-88051 (Tesseract is an open source OCR engine. In version 5.5.3 and 
earlier,  ...)
+       TODO: check
+CVE-2026-88050 (Tesseract is an open source OCR engine. In version 5.5.3 and 
earlier,  ...)
+       TODO: check
+CVE-2026-88049 (Tesseract is an open source OCR engine. In version 5.5.3 and 
earlier,  ...)
+       TODO: check
+CVE-2026-88048 (Tesseract is an open source OCR engine. In version 5.5.3 and 
earlier,  ...)
+       TODO: check
+CVE-2026-88047 (Tesseract is an open source OCR engine. In version 5.5.3 and 
earlier,  ...)
+       TODO: check
+CVE-2026-88046 (rclone is a command-line program to sync files and directories 
to and  ...)
+       TODO: check
+CVE-2026-88045 (rclone is a command-line program to sync files and directories 
to and  ...)
+       TODO: check
+CVE-2026-88044 (rclone is a command-line program to sync files and directories 
to and  ...)
+       TODO: check
+CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP 
cookies, use ...)
+       TODO: check
+CVE-2026-88036 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88035 (A size check in the client-side authentication path of the 
MongoDB C D ...)
+       TODO: check
+CVE-2026-88034 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88033 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88032 (A use-after-free in the reactive client-side encryption 
component of t ...)
+       TODO: check
+CVE-2026-88031 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88030 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88029 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88028 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88027 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88026 (Improper neutralization of regular-expression metacharacters 
in the LI ...)
+       TODO: check
+CVE-2026-88025 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88024 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88023 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88022 (Improper neutralization of special elements in data query 
logic in the ...)
+       TODO: check
+CVE-2026-88021 (Consul and Consul Enterprise are vulnerable to an 
authorization bypass ...)
+       TODO: check
+CVE-2026-88018 (rclone is a command-line program to sync files and directories 
to and  ...)
+       TODO: check
+CVE-2026-88017 (rclone is a command-line program to sync files and directories 
to and  ...)
+       TODO: check
+CVE-2026-88016 (rclone is a command-line program to sync files and directories 
to and  ...)
+       TODO: check
+CVE-2026-88015 (rclone is a command-line program to sync files and directories 
to and  ...)
+       TODO: check
+CVE-2026-88014 (rclone is a command-line program to sync files and directories 
to and  ...)
+       TODO: check
+CVE-2026-88013 (rclone is a command-line program to sync files and directories 
to and  ...)
+       TODO: check
+CVE-2026-88012 (Traefik is an open source HTTP reverse proxy and load 
balancer. From 2 ...)
+       TODO: check
+CVE-2026-88011 (Traefik is an open source HTTP reverse proxy and load 
balancer. Prior  ...)
+       TODO: check
+CVE-2026-88009 (Traefik is an open source HTTP reverse proxy and load 
balancer. Prior  ...)
+       TODO: check
+CVE-2026-88008 (Traefik is an open source HTTP reverse proxy and load 
balancer. From 2 ...)
+       TODO: check
+CVE-2026-88007 (Traefik is an open source HTTP reverse proxy and load 
balancer. From 2 ...)
+       TODO: check
+CVE-2026-88006 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-88005 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-88004 (Traefik is an open source HTTP reverse proxy and load 
balancer. From 3 ...)
+       TODO: check
+CVE-2026-87993 (The consul-template library is vulnerable to an information 
disclosure ...)
+       TODO: check
+CVE-2026-87962 (t-digest versions 3.1 through 3.3 contain a denial of service 
vulnerab ...)
+       TODO: check
+CVE-2026-87961 (ESP32-audioI2S versions 3.4.4 through 4.0.0 contain a 
heap-based out-o ...)
+       TODO: check
+CVE-2026-87913 (A missing S3 bucket ownership verification in the AWS Security 
Agent M ...)
+       TODO: check
+CVE-2026-87912 (A missing S3 bucket ownership verification in the AWS Security 
Agent p ...)
+       TODO: check
+CVE-2026-87803 (An authorization bypass vulnerability exists in the Countly 
Server DBV ...)
+       TODO: check
+CVE-2026-87107 (Consul and Consul Enterprise are vulnerable to an 
authorization bypass ...)
+       TODO: check
+CVE-2026-87106 (Consul and Consul Enterprise are vulnerable to a denial of 
service in  ...)
+       TODO: check
+CVE-2026-87090 (Consul and Consul Enterprise are vulnerable to an 
authorization bypass ...)
+       TODO: check
+CVE-2026-85545 (There is an Vulnerability in some HikCentral Access Control 
versions.  ...)
+       TODO: check
+CVE-2026-85544 (There is an Improper Encryption Configuration Vulnerability in 
some Hi ...)
+       TODO: check
+CVE-2026-85543 (Some Wi-Fi series camera products have insufficient permission 
validat ...)
+       TODO: check
+CVE-2026-85310 (import_contacts Path Traversal in Groundhogg <= 4.7.1 
versions.)
+       TODO: check
+CVE-2026-85228 (An integer overflow in the tensor buffer validation component 
in Amazo ...)
+       TODO: check
+CVE-2026-85217 (A maliciously crafted add-in, when installed and executed in 
Autodesk  ...)
+       TODO: check
+CVE-2026-84828 (A flaw was found in PCS (Pacemaker Configuration System). A 
local atta ...)
+       TODO: check
+CVE-2026-84821 (Unauthenticated Broken Access Control in WP Fast Total Search 
<= 1.82. ...)
+       TODO: check
+CVE-2026-84819 (Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 
2.3.3 versi ...)
+       TODO: check
+CVE-2026-84816 (Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 
versions.)
+       TODO: check
+CVE-2026-84042 (A flaw was found in crun. When crun is built with libkrun and 
a contai ...)
+       TODO: check
+CVE-2026-81805 (Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 
versions.)
+       TODO: check
+CVE-2026-81804 (Unauthenticated Sensitive Data Exposure in ZHBackup \u2013 
Backup, Res ...)
+       TODO: check
+CVE-2026-81803 (Subscriber Remote Code Execution (RCE) in RepairBuddy <= 
4.1224 versio ...)
+       TODO: check
+CVE-2026-81801 (Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.)
+       TODO: check
+CVE-2026-81800 (Unauthenticated SQL Injection in Verified Reviews (Avis 
V\xe9rifi\xe9s ...)
+       TODO: check
+CVE-2026-81799 (Unauthenticated Broken Access Control in Return Refund and 
Exchange Fo ...)
+       TODO: check
+CVE-2026-81796 (Unauthenticated Broken Authentication in WP Travel <= 12.0.3 
versions.)
+       TODO: check
+CVE-2026-81795 (Unauthenticated Cross Site Scripting (XSS) in Page Visits 
Counter &#82 ...)
+       TODO: check
+CVE-2026-81794 (Unauthenticated Broken Access Control in Shirt Product 
Designer for Wo ...)
+       TODO: check
+CVE-2026-81793 (Unauthenticated Broken Access Control in Salon booking system 
<= 10.31 ...)
+       TODO: check
+CVE-2026-81791 (Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 
versions.)
+       TODO: check
+CVE-2026-81789 (Unauthenticated Arbitrary File Deletion in Advanced Product 
Fields Ext ...)
+       TODO: check
+CVE-2026-81788 (Subscriber Broken Access Control in IMPress for IDX Broker <= 
3.3.0 ve ...)
+       TODO: check
+CVE-2026-81787 (Unauthenticated Broken Authentication in IMPress for IDX 
Broker <= 3.3 ...)
+       TODO: check
+CVE-2026-81786 (Unauthenticated Broken Access Control in Thank You Page 
Customizer for ...)
+       TODO: check
+CVE-2026-81785 (Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 
versions.)
+       TODO: check
+CVE-2026-81784 (Unauthenticated PHP Object Injection in Wise Chat <= 3.4 
versions.)
+       TODO: check
+CVE-2026-81783 (Subscriber Broken Authentication in MailMunch \u2013 Grow your 
Email L ...)
+       TODO: check
+CVE-2026-81782 (Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 
versions.)
+       TODO: check
+CVE-2026-81468 (Dell ThinOS 10, versions prior to 2605_10. 2616, contains an 
Improper  ...)
+       TODO: check
+CVE-2026-81467 (Dell ThinOS 10, versions prior to 2605_10. 2616, contains an 
Improper  ...)
+       TODO: check
+CVE-2026-81275 (Subscriber Arbitrary File Download in Youzify <= 1.3.7 
versions.)
+       TODO: check
+CVE-2026-81052 (Dell ThinOS 10, versions prior to 2605_10.2616, contain a 
Download of  ...)
+       TODO: check
+CVE-2026-81051 (Dell ThinOS 10, versions prior to 2605_10.2616, contain a 
Security Ver ...)
+       TODO: check
+CVE-2026-81049 (Dell ThinOS 10, versions prior to 2605_10.2616, contain a 
Missing Supp ...)
+       TODO: check
+CVE-2026-81048 (Dell ThinOS 10, versions prior to 2605_10.2616, contain an 
Improper Ne ...)
+       TODO: check
+CVE-2026-81046 (Dell ThinOS 10, versions prior to 2605_10.2616, contain a 
Protection M ...)
+       TODO: check
+CVE-2026-80354 (Authorization bypass through User-Controlled key vulnerability 
in Apac ...)
+       TODO: check
+CVE-2026-80352 (Improper Control of Generation of Code ('Code Injection') 
vulnerabilit ...)
+       TODO: check
+CVE-2026-80351 (Improper neutralization of directives in dynamically evaluated 
code (' ...)
+       TODO: check
+CVE-2026-7188 (Improper neutralization of special elements used in an SQL 
command ('S ...)
+       TODO: check
+CVE-2026-79987 (A remote, authenticated, non-admin Craft CMS Control Panel 
user with o ...)
+       TODO: check
+CVE-2026-78536 (Unauthenticated Broken Access Control in Robokassa payment 
gateway for ...)
+       TODO: check
+CVE-2026-78374 (Joomla Extension - joomlart.com - Open mail relay via contact 
AJAX end ...)
+       TODO: check
+CVE-2026-78303 (Joomla Extension - joomshaper.com - Unvalidated Email 
Destination & Fo ...)
+       TODO: check
+CVE-2026-78302 (Joomla Extension - joomshaper.com - Unauthenticated Stored 
Cross-Site  ...)
+       TODO: check
+CVE-2026-78085 (Joomla Extension - joomshaper.com - Path Traversal in Gallery 
Image Ma ...)
+       TODO: check
+CVE-2026-78084 (Joomla Extension - joomshaper.com - Missing Access Control in 
Gallery  ...)
+       TODO: check
+CVE-2026-78083 (Joomla Extension - joomshaper.com - Missing CSRF Token 
Verification in ...)
+       TODO: check
+CVE-2026-78082 (Joomla Extension - joomshaper.com - Unauthenticated SQL 
Injection in P ...)
+       TODO: check
+CVE-2026-75584 (ION-DTN before 4.2.1-a.1 contains a denial of service 
vulnerability th ...)
+       TODO: check
+CVE-2026-73699 (FileRun before 2026.3.0 contains a PHP object injection 
vulnerability  ...)
+       TODO: check
+CVE-2026-73698 (FileRun before 2026.3.0 contains a SQL injection vulnerability 
that al ...)
+       TODO: check
+CVE-2026-73694 (FileRun before 2026.3.0 contains an OS command injection 
vulnerability ...)
+       TODO: check
+CVE-2026-73693 (FileRun before 2026.3.0 contains an OS command injection 
vulnerability ...)
+       TODO: check
+CVE-2026-6285 (Weak Password Recovery Mechanism for Forgotten Password 
vulnerability  ...)
+       TODO: check
+CVE-2026-68527 (Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an 
authori ...)
+       TODO: check
+CVE-2026-68488 (A Time-of-check Time-of-use (TOCTOU) race condition leading to 
insecur ...)
+       TODO: check
+CVE-2026-68487 (Path traversal in Plesk's Backup Manager causes arbitrary file 
write a ...)
+       TODO: check
+CVE-2026-68006 (An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker 
to exec ...)
+       TODO: check
+CVE-2026-66674 (Unauthenticated Bypass Vulnerability in Simple Cloudflare 
Turnstile <= ...)
+       TODO: check
+CVE-2026-66632 (Unauthenticated Content Injection in Simple Cloudflare 
Turnstile <= 1. ...)
+       TODO: check
+CVE-2026-65639 (OS command injection in the advanced-rule parser of 
ConfigServer Secur ...)
+       TODO: check
+CVE-2026-65638 (Improper escaping of a request URL in  ConfigServer Security & 
Firewal ...)
+       TODO: check
+CVE-2026-64838 (ICEcoder versions through 8.1 fail to properly validate the 
oldFileNam ...)
+       TODO: check
+CVE-2026-64837 (ICEcoder through 8.1 passes an unescaped filesystem path into 
a shell  ...)
+       TODO: check
+CVE-2026-64836 (ICEcoder versions through 8.1 contain a path traversal 
vulnerability i ...)
+       TODO: check
+CVE-2026-5399 (The Redux Framework plugin for WordPress is vulnerable to 
Stored Cross ...)
+       TODO: check
+CVE-2026-52098 (An issue in Flowise 3.1.2 allows a remote attacker to execute 
arbitrar ...)
+       TODO: check
+CVE-2026-52097 (An issue in AppFlowy 0.11.8 allows a remote attacker to 
execute arbitr ...)
+       TODO: check
+CVE-2026-4130 (There is a storage of sensitive information in cleartext 
vulnerability ...)
+       TODO: check
+CVE-2026-4129 (There is an improper access control vulnerability in NI 
SystemLink tha ...)
+       TODO: check
+CVE-2026-46387 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45763 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-45747 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
+       TODO: check
+CVE-2026-42808 (An issue was discovered in Bosch Sensortec COINES_SDK versions 
2.0 thr ...)
+       TODO: check
+CVE-2026-42807 (A heap-based buffer overflow vulnerability in the PC bridge 
protocol d ...)
+       TODO: check
+CVE-2026-42806 (An out-of-bounds read vulnerability was discovered in the 
Bosch BME690 ...)
+       TODO: check
+CVE-2026-42805 (A stack-based buffer overflow vulnerability exists in the 
Bosch Sensor ...)
+       TODO: check
+CVE-2026-42804 (A stack-based buffer overflow vulnerability exists in the 
Bosch Sensor ...)
+       TODO: check
+CVE-2026-38626 (Garlic-Hub v1.0.1 is vulnerable to SQL Injection in 
src/Modules/Items/ ...)
+       TODO: check
+CVE-2026-17038 (DrEryk Gabinet before 11.5.0uses hard-coded API credentials in 
its tic ...)
+       TODO: check
+CVE-2026-15889 (The Aruba HiSpeed Cache plugin for WordPress is vulnerable to 
Stored C ...)
+       TODO: check
+CVE-2026-15461 (The Sierra Wireless HL78xx modem GNSS driver 
(drivers/modem/hl78xx/, l ...)
+       TODO: check
+CVE-2026-15419 (In the silabser.sys driver for CP210x devices v11.5.0 and 
earlier, a l ...)
+       TODO: check
+CVE-2026-15418 (In the silabser.sys driver for CP210x devices v11.5.0 and 
earlier, a l ...)
+       TODO: check
+CVE-2026-15417 (In the silabser.sys Windows 8 driver for CP210x devices, a 
local unpri ...)
+       TODO: check
+CVE-2026-13745 (A vulnerability in the Gemini CLI and associated GitHub Action 
allowed ...)
+       TODO: check
+CVE-2026-12683 (Improper neutralization of input during web page generation 
('cross-si ...)
+       TODO: check
+CVE-2026-12682 (Improper neutralization of input during web page generation 
('cross-si ...)
+       TODO: check
 CVE-2026-88069 (Pandora contains a path traversal vulnerability in its archive 
extract ...)
        NOT-FOR-US: Pandora
 CVE-2026-88002 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
@@ -44894,12 +45368,12 @@ CVE-2026-42170 (A heap-based buffer overflow 
vulnerability exists in the GIMP DD
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16161
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2758
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/7dff816fbd58fe17456405f19db332ef5d2a44a0
 (GIMP_3_2_4)
-CVE-2026-44950 [Font Server Client Cumulative Glyph Data Heap Buffer Overflow]
+CVE-2026-44950 (fs_read_glyphs() in the libXfont2 font-server client 
(src/fc/fserve.c) ...)
        - libxfont 1:2.0.9-1 (unimportant)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/05/1
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/c2d222bb22c623d8a40f3275077fc7e6617f2c8a
 (libXfont2-2.0.9)
        NOTE: Disabled support to connect to font server since 1:1.4.7-1
-CVE-2026-59679 [Font Server Client encoding Out-Of-Bounds Read/Write]
+CVE-2026-59679 (fs_read_glyphs() in the libXfont2 font-server client 
(src/fc/fserve.c) ...)
        - libxfont 1:2.0.9-1 (unimportant)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/05/1
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/668fea81f40bcb48ec67fb55d0b851049d265290
 (libXfont2-2.0.9)
@@ -305714,11 +306188,13 @@ CVE-2024-48943
        NOTE: https://nicmx.github.io/FORT-validator/CVE.html
        NOTE: 
https://github.com/NICMx/FORT-validator/commit/4ee88d1c3fa7df763dd52312134cd93c1ce50870
 (1.6.4)
 CVE-2024-56170 (A validation integrity issue was discovered in Fort through 
1.6.4 befo ...)
+       {DSA-6490-1}
        - fort-validator <unfixed> (bug #1090916)
        [bookworm] - fort-validator <postponed> (Minor issue, revisit when 
fixed upstream)
        [bullseye] - fort-validator <postponed> (Minor issue, wait until it's 
fixed upstream)
        NOTE: https://github.com/NICMx/FORT-validator/issues/82
 CVE-2024-56169 (A validation integrity issue was discovered in Fort through 
1.6.4 befo ...)
+       {DSA-6490-1}
        - fort-validator <unfixed> (bug #1090916)
        [bookworm] - fort-validator <postponed> (Minor issue, revisit when 
fixed upstream)
        [bullseye] - fort-validator <postponed> (Minor issue, wait until it's 
fixed upstream)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cce2d774864a3f032ce78351a1879ebea900cf2

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cce2d774864a3f032ce78351a1879ebea900cf2
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to