Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b6abaef0 by security tracker role at 2026-09-15T19:14:11+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,220 +1,1152 @@
-CVE-2026-92079
+CVE-2026-92180 (pdfforge PDF Architect activation-service Update Service 
Uncontrolled  ...)
+       TODO: check
+CVE-2026-92179 (pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write 
Remote Cod ...)
+       TODO: check
+CVE-2026-92178 (pdfforge PDF Architect PDF File Parsing Memory Corruption 
Remote Code  ...)
+       TODO: check
+CVE-2026-92177 (pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write 
Remote Cod ...)
+       TODO: check
+CVE-2026-92176 (pdfforge PDF Architect App Object Out-Of-Bounds Read Remote 
Code Execu ...)
+       TODO: check
+CVE-2026-92082 (By default, Payara Server does not limit the number of failed 
login at ...)
+       TODO: check
+CVE-2026-92021 (Use-after-free in the JavaScript Engine: JIT component. This 
vulnerabi ...)
+       TODO: check
+CVE-2026-92014 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
+       TODO: check
+CVE-2026-92003 (Affected versions of MISP do not consistently apply the 
existing authe ...)
+       TODO: check
+CVE-2026-92002 (Affected versions of MISP use Redis to throttle repeated 
authenticatio ...)
+       TODO: check
+CVE-2026-91998 (Casdoor through 4.4.0 contains an authorization bypass 
vulnerability i ...)
+       TODO: check
+CVE-2026-91997 (evolution-api through 2.3.7 contains an incorrect array 
comparison in  ...)
+       TODO: check
+CVE-2026-91996 (lamp-cloud through 5.10.0 whitelists the path pattern 
/*/anno/** for a ...)
+       TODO: check
+CVE-2026-91995 (pig before 4.1.0 contains an authentication bypass 
vulnerability in th ...)
+       TODO: check
+CVE-2026-91994 (Semaphore UI through 2.19.12 exempts GET and HEAD requests 
from projec ...)
+       TODO: check
+CVE-2026-91993 (Jpom through 2.11.12 fails to validate workspace ownership 
when resolv ...)
+       TODO: check
+CVE-2026-91992 (Tornado before 6.5.7 contains a credential leak vulnerability 
in CurlA ...)
+       TODO: check
+CVE-2026-91991 (Tornado before 6.5.8 contains an incomplete fix for cookie 
attribute i ...)
+       TODO: check
+CVE-2026-91990 (Tornado before 6.5.8 contains a memory amplification 
vulnerability in  ...)
+       TODO: check
+CVE-2026-91989 (atomic-agents-stack before 1.1.0 contains a path traversal 
vulnerabili ...)
+       TODO: check
+CVE-2026-91988 (atomic-agents-stack before 1.1.0 accepts cleartext HTTP 
schemes in the ...)
+       TODO: check
+CVE-2026-91987 (atomic-agents-stack before 1.1.0 contains a cost-guardrail 
bypass in t ...)
+       TODO: check
+CVE-2026-91986 (gitoxide gix-transport before 0.59.2 fails to filter control 
character ...)
+       TODO: check
+CVE-2026-91985 (Vikunja before 2.6.0 fails to properly restrict access to the 
link-sha ...)
+       TODO: check
+CVE-2026-91984 (Vikunja before 2.6.0 fails to validate that user-supplied 
project_view ...)
+       TODO: check
+CVE-2026-91983 (Vikunja before 2.6.0 contains an API token scope bypass 
vulnerability  ...)
+       TODO: check
+CVE-2026-91982 (Vikunja before 2.6.0 continues to expose the raw TOTP shared 
secret af ...)
+       TODO: check
+CVE-2026-91981 (Vikunja versions before 2.6.0 fail to properly validate 
link-share tok ...)
+       TODO: check
+CVE-2026-91980 (vikunja before 2.6.0 fails to validate team access when 
attaching team ...)
+       TODO: check
+CVE-2026-91979 (Vikunja before 2.6.0 fails to limit archive expansion during 
data impo ...)
+       TODO: check
+CVE-2026-91973 (Vikunja before 2.6.0 contains an authentication bypass 
vulnerability i ...)
+       TODO: check
+CVE-2026-91972 (Vikunja versions before 2.6.0 fail to apply rate limiting to 
/api/v2 p ...)
+       TODO: check
+CVE-2026-91971 (Vikunja before 2.6.0 fails to apply pixel decode limits to 
avatar and  ...)
+       TODO: check
+CVE-2026-91970 (Vikunja versions before 2.6.0 contain a resource exhaustion 
vulnerabil ...)
+       TODO: check
+CVE-2026-91969 (vikunja versions before 2.6.0 contain a resource exhaustion 
vulnerabil ...)
+       TODO: check
+CVE-2026-91968 (vikunja versions before 2.6.0 contain a resource exhaustion 
vulnerabil ...)
+       TODO: check
+CVE-2026-91967 (AVideo through 29.0 contains a blind server-side request 
forgery vulne ...)
+       TODO: check
+CVE-2026-91966 (AVideo through 29.0 contains an unauthenticated server-side 
request fo ...)
+       TODO: check
+CVE-2026-91965 (WWBN AVideo through 29.0 fails to enforce user-group 
restrictions in t ...)
+       TODO: check
+CVE-2026-91964 (FreeRDP versions before 3.31.0 contain a heap-based buffer 
overflow in ...)
+       TODO: check
+CVE-2026-91963 (FreeRDP versions before 3.31.0 contain an uninitialized heap 
memory di ...)
+       TODO: check
+CVE-2026-91962 (FreeRDP before 3.31.0 contains an integer overflow in the 
audin Apple  ...)
+       TODO: check
+CVE-2026-91961 (FreeRDP before 3.31.0 contains a denial-of-service 
vulnerability in th ...)
+       TODO: check
+CVE-2026-91960 (FreeRDP versions before 3.31.0 contain an integer overflow in 
WinPR's  ...)
+       TODO: check
+CVE-2026-91959 (FreeRDP before 3.31.0 contains a buffer over-read 
vulnerability in the ...)
+       TODO: check
+CVE-2026-91958 (FreeRDP versions before 3.31.0 fail to validate MonitorIds 
array value ...)
+       TODO: check
+CVE-2026-91957 (FreeRDP before 3.31.0 contains a use-after-free vulnerability 
in the s ...)
+       TODO: check
+CVE-2026-91956 (FreeRDP before 3.31.0 contains an out-of-bounds read 
vulnerability in  ...)
+       TODO: check
+CVE-2026-91955 (FreeRDP before 3.31.0 fails to validate client-supplied 
DesktopWidth a ...)
+       TODO: check
+CVE-2026-91954 (FreeRDP before 3.31.0 contains a null pointer dereference 
vulnerabilit ...)
+       TODO: check
+CVE-2026-91953 (FreeRDP versions before 3.31.0 contain a heap buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-91952 (FreeRDP versions before 3.31.0 contain an infinite-loop denial 
of serv ...)
+       TODO: check
+CVE-2026-91951 (FreeRDP versions before 3.31.0 contain an out-of-bounds write 
vulnerab ...)
+       TODO: check
+CVE-2026-91950 (FreeRDP before 3.31.0 contains an out-of-bounds read 
vulnerability in  ...)
+       TODO: check
+CVE-2026-91949 (FreeRDP server versions before 3.31.0 contain a protocol 
negotiation b ...)
+       TODO: check
+CVE-2026-91948 (FreeRDP versions before 3.31.0 contain an out-of-bounds write 
vulnerab ...)
+       TODO: check
+CVE-2026-91947 (FreeRDP server versions before 3.31.0 contain a use-after-free 
vulnera ...)
+       TODO: check
+CVE-2026-91946 (FreeRDP versions before 3.31.0 contain an information 
disclosure vulne ...)
+       TODO: check
+CVE-2026-91945 (FreeRDP versions before 3.31.0 contain an out-of-bounds read 
vulnerabi ...)
+       TODO: check
+CVE-2026-91944 (crawl4ai versions before 0.9.3 contain a DOM-based cross-site 
scriptin ...)
+       TODO: check
+CVE-2026-91943 (Crawl4AI before 0.9.3 contains a server-side request forgery 
vulnerabi ...)
+       TODO: check
+CVE-2026-91942 (crawl4ai before 0.9.3 contains a DOM-based cross-site 
scripting vulner ...)
+       TODO: check
+CVE-2026-91941 (Crawl4AI before 0.9.3 contains an uncontrolled resource 
consumption vu ...)
+       TODO: check
+CVE-2026-91940 (crawl4ai before 0.9.3 contains an arbitrary file write 
vulnerability i ...)
+       TODO: check
+CVE-2026-91938 (Flowise versions before 3.1.4 contain a server-side request 
forgery vu ...)
+       TODO: check
+CVE-2026-91937 (Flowise before 3.1.4 fails to sanitize the 
overrideConfig.sessionId pa ...)
+       TODO: check
+CVE-2026-91936 (Flowise versions before 3.1.4 contain a script injection 
vulnerability ...)
+       TODO: check
+CVE-2026-91935 (Flowise before 3.1.4 fails to validate baseURL parameters in 
chat-mode ...)
+       TODO: check
+CVE-2026-91934 (Flowise versions before 3.1.4 fail to validate file paths in 
the SQL D ...)
+       TODO: check
+CVE-2026-91933 (Flowise before 3.1.4 fails to enforce workspace-level 
authorization ch ...)
+       TODO: check
+CVE-2026-91932 (Flowise before 3.1.4 contains a validation bypass 
vulnerability in MCP ...)
+       TODO: check
+CVE-2026-91931 (Flowise before 3.1.4 contains a remote code execution 
vulnerability in ...)
+       TODO: check
+CVE-2026-91930 (Flowise before 3.1.4 fails to scope enterprise organization 
and worksp ...)
+       TODO: check
+CVE-2026-91929 (Flowise versions before 3.1.4 contain cross-tenant 
authorization gaps  ...)
+       TODO: check
+CVE-2026-91926 (A flaw was found in gss-ntlmssp. A memory leak occurs in the 
NTLM targ ...)
+       TODO: check
+CVE-2026-91925 (Polyaxon through 2.16.4 renders operation specification fields 
with an ...)
+       TODO: check
+CVE-2026-91924 (pgweb through 0.17.0 leaves the POST /api/connect endpoint 
unguarded w ...)
+       TODO: check
+CVE-2026-91923 (KubeSphere through 4.1.3 contains a server-side request 
forgery vulner ...)
+       TODO: check
+CVE-2026-91922 (Steedos Platform through 3.0.15-beta.47 contains a reflected 
cross-sit ...)
+       TODO: check
+CVE-2026-91859 (Affected versions of MISP can record incorrect access-log data 
for req ...)
+       TODO: check
+CVE-2026-91857 (Affected versions of MISP expose several state-changing 
controller act ...)
+       TODO: check
+CVE-2026-91855 (A security flaw has been discovered in Open5GS up to 2.7.7. 
Affected b ...)
+       TODO: check
+CVE-2026-91854 (A vulnerability was identified in code-projects Record 
Management Syst ...)
+       TODO: check
+CVE-2026-91853 (A vulnerability has been found in TOTOLINK X5000R 
9.1.0cu.2089_B202112 ...)
+       TODO: check
+CVE-2026-91851 (Affected versions of MISP incorrectly filter dashboard 
templates that  ...)
+       TODO: check
+CVE-2026-91849 (A security flaw has been discovered in WuzhiCMS up to 4.1.0. 
This affe ...)
+       TODO: check
+CVE-2026-91848 (A vulnerability was identified in WuzhiCMS up to 4.1.0. 
Affected by th ...)
+       TODO: check
+CVE-2026-91846 (Affected versions of MISP allow a collection element to be 
created fro ...)
+       TODO: check
+CVE-2026-91842 (A vulnerability has been found in OpenBankProject OBP-API up 
to 1.10.1 ...)
+       TODO: check
+CVE-2026-91836 (A flaw has been found in OpenClaw ClawScan up to 0.1.6. This 
affects a ...)
+       TODO: check
+CVE-2026-91835 (A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. 
The imp ...)
+       TODO: check
+CVE-2026-91826 (Stack-based buffer overflow vulnerability in Samsung 
Opensource rLotti ...)
+       TODO: check
+CVE-2026-91825 (Affected versions of MISP fail to authorize a submitted 
sharing group  ...)
+       TODO: check
+CVE-2026-91819 (Affected versions of MISP rely on CakePHP request-method 
override proc ...)
+       TODO: check
+CVE-2026-91786 (A flaw was found in GNOME Shell. When processing icons from a 
remote s ...)
+       TODO: check
+CVE-2026-91782 (A vulnerability was detected in GNU Binutils 2.47. Affected by 
this vu ...)
+       TODO: check
+CVE-2026-91781 (A security vulnerability has been detected in GNU Binutils 
2.47. Affec ...)
+       TODO: check
+CVE-2026-91780 (A weakness has been identified in GNU Binutils 2.47. This 
impacts the  ...)
+       TODO: check
+CVE-2026-91779 (A security flaw has been discovered in GNU Binutils 2.47. This 
affects ...)
+       TODO: check
+CVE-2026-91778 (In affected versions of Octopus Server, users with certain 
scoped perm ...)
+       TODO: check
+CVE-2026-91091 (A vulnerability was identified in GPAC up to f1219cde. The 
impacted el ...)
+       TODO: check
+CVE-2026-91090 (A vulnerability was determined in GPAC up to f1219cde. The 
affected el ...)
+       TODO: check
+CVE-2026-91089 (A vulnerability was found in GPAC up to f1219cde. Impacted is 
the func ...)
+       TODO: check
+CVE-2026-90650 (The MotoPress Hotel Booking plugin for WordPress is vulnerable 
to Stor ...)
+       TODO: check
+CVE-2026-90439 (NGINX Plus and NGINX Open Source have a vulnerability in the 
ngx_http_ ...)
+       TODO: check
+CVE-2026-89308 (An unauthenticated OS command injection vulnerability exists 
in thepin ...)
+       TODO: check
+CVE-2026-89307 (The "Firma Circolare" feature in the "Design Scuole Italia" 
WordPress  ...)
+       TODO: check
+CVE-2026-89026 (The Issabel Framework, the web framework supporting Issabel 
PBX softwa ...)
+       TODO: check
+CVE-2026-89025 (Hirschmann HiOS Switch Platform devices contain a 
denial-of-service vu ...)
+       TODO: check
+CVE-2026-89022 (BookStack before 26.05.5 contains an authentication bypass 
vulnerabili ...)
+       TODO: check
+CVE-2026-88765 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-88621 (OneNav v1.2.4 contains an authenticated arbitrary file 
deletion vulner ...)
+       TODO: check
+CVE-2026-88620 (SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an 
improper  ...)
+       TODO: check
+CVE-2026-88619 (1024-lab SmartAdmin v3.30.0 contains a missing authorization 
vulnerabi ...)
+       TODO: check
+CVE-2026-88618 (1024-lab SmartAdmin v3.30.0 contains a stored cross-site 
scripting vul ...)
+       TODO: check
+CVE-2026-88617 (SmartAdmin v3.30.0 contains an authorization flaw in the 
configuration ...)
+       TODO: check
+CVE-2026-88616 (An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to 
execute a ...)
+       TODO: check
+CVE-2026-87793 (The "Design Scuole Italia" WordPress theme is affected by a 
Reflected  ...)
+       TODO: check
+CVE-2026-87792 (The "Design Scuole Italia" WordPress theme is affected by 
multiple Aut ...)
+       TODO: check
+CVE-2026-87791 (A path traversal vulnerability exists in the 
reserved_file_check funct ...)
+       TODO: check
+CVE-2026-87730
+       REJECTED
+CVE-2026-86818 (fast-uri is a dependency-free RFC 3986 URI parser for Node.js, 
used by ...)
+       TODO: check
+CVE-2026-86472 (fast-uri is a dependency-free RFC 3986 URI parser for Node.js, 
used by ...)
+       TODO: check
+CVE-2026-85234 (A flaw was found in tftp-hpa. When the `in.tftpd` remap engine 
process ...)
+       TODO: check
+CVE-2026-82837 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-82191 (Joomla Extension - j2commerce.com - Unescaped request data 
reflected i ...)
+       TODO: check
+CVE-2026-82190 (Joomla Extension - j2commerce.com - Predictable/forgeable 
order access ...)
+       TODO: check
+CVE-2026-82189 (Joomla Extension - j2commerce.com - Any order can be marked 
Failed by  ...)
+       TODO: check
+CVE-2026-81924 (Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request 
Forgery  ...)
+       TODO: check
+CVE-2026-81923 (In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags 
editor did ...)
+       TODO: check
+CVE-2026-81922 (Concrete CMS before 9.5.3 did not enforce a per-page 
authorization che ...)
+       TODO: check
+CVE-2026-81921 (Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 
refresh-token g ...)
+       TODO: check
+CVE-2026-81920 (Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request 
Forgery  ...)
+       TODO: check
+CVE-2026-81919 (Concrete CMS below 9.5.3 did not validate an anti-CSRF token 
on the bl ...)
+       TODO: check
+CVE-2026-81899 (Concrete CMS 9.0.0 to 9.5.2 stored group folder names without 
sanitiza ...)
+       TODO: check
+CVE-2026-81898 (In Concrete CMS below version 9.5.3, the Address attribute's 
country-l ...)
+       TODO: check
+CVE-2026-81897 (In Concrete CMS below CMS 9.5.3, the save_control action in 
the Expres ...)
+       TODO: check
+CVE-2026-81896 (Concrete CMS before 9.5.3 does not apply HTML entity encoding 
to user- ...)
+       TODO: check
+CVE-2026-81895 (In Concrete CMS before 9.5.3, the Document Library block 
stored the fi ...)
+       TODO: check
+CVE-2026-81894 (Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based 
Cross-s ...)
+       TODO: check
+CVE-2026-81568 (Joomla Extension - j2commerce.com - Arbitrary file read via 
`task=down ...)
+       TODO: check
+CVE-2026-81567 (Joomla Extension - j2commerce.com - Unauthenticated blind SQL 
injectio ...)
+       TODO: check
+CVE-2026-81240 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, 
contain an ...)
+       TODO: check
+CVE-2026-81239 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, 
contain an ...)
+       TODO: check
+CVE-2026-81238 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, 
contain a  ...)
+       TODO: check
+CVE-2026-81237 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, 
contain an ...)
+       TODO: check
+CVE-2026-81236 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, 
contain an ...)
+       TODO: check
+CVE-2026-81235 (Dell Wyse Management Suite, versions prior to 2605.0.3.683, 
contain a  ...)
+       TODO: check
+CVE-2026-80217 (Hidden functionality issue exists in FF-RFI079I4 and 
FF-RFI078I4, whic ...)
+       TODO: check
+CVE-2026-79705 (A flaw was found in the buildah/copier Go package. When used 
outside o ...)
+       TODO: check
+CVE-2026-79699 (A flaw was found in the containers/storage library. A crafted 
tar arch ...)
+       TODO: check
+CVE-2026-79551 (Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was 
discovered to ...)
+       TODO: check
+CVE-2026-79425 (An authenticated Server-Side Request Forgery (SSRF) in the 
/adminapi/f ...)
+       TODO: check
+CVE-2026-79411 (Incorrect privilege assignment in the admin user-management 
component  ...)
+       TODO: check
+CVE-2026-79410 (Improper validation of the quantity parameter in the 
add-to-cart path  ...)
+       TODO: check
+CVE-2026-79409 (An issue in Webkul Bagisto 2.4.9 allows a remote attacker to 
obtain se ...)
+       TODO: check
+CVE-2026-79303 (kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL 
Injecti ...)
+       TODO: check
+CVE-2026-78081 (Joomla Extension - j2commerce.com - Missing CSRF protection on 
cart, c ...)
+       TODO: check
+CVE-2026-77972 (Time-of-check Time-of-use (TOCTOU) Race Condition in Slab 
safeurl allo ...)
+       TODO: check
+CVE-2026-77866 (Server-Side Request Forgery (SSRF) vulnerability in Slab 
safeurl allow ...)
+       TODO: check
+CVE-2026-77853 (Improper neutralization of special elements used in an OS 
command ('OS ...)
+       TODO: check
+CVE-2026-77179 (On macOS, the virtio-fs host server used by Docker Sandboxes 
improperl ...)
+       TODO: check
+CVE-2026-76159 (Incorrect Permission Assignment for Critical Resource in the  
configur ...)
+       TODO: check
+CVE-2026-75092 (A privilege escalation flaw was found in the scan_mysql actor 
of leapp ...)
+       TODO: check
+CVE-2026-73467 (On affected platforms running Arista EOS, under certain 
circumstances  ...)
+       TODO: check
+CVE-2026-73466 (On affected platforms running Arista EOS, under certain 
circumstances  ...)
+       TODO: check
+CVE-2026-73465 (On affected platforms running Arista EOS, under certain 
circumstances  ...)
+       TODO: check
+CVE-2026-73451 (On affected platforms running Arista EOS with dual switch 
cards and wi ...)
+       TODO: check
+CVE-2026-69211 (Http4s is a Scala interface for HTTP services. Prior to 
0.23.35 and 1. ...)
+       TODO: check
+CVE-2026-69209 (Http4s is a Scala interface for HTTP services. Prior to 
0.23.35 and 1. ...)
+       TODO: check
+CVE-2026-69208 (Http4s is a Scala interface for HTTP services. Prior to 
0.23.35 and 1. ...)
+       TODO: check
+CVE-2026-69204 (Http4s is a Scala interface for HTTP services. Prior to 
0.23.35 and 1. ...)
+       TODO: check
+CVE-2026-68534 (Concrete CMS before 9.5.3 rendered Express entry labels as raw 
HTML wh ...)
+       TODO: check
+CVE-2026-68533 (Concrete CMS below 9.5.3 conversation attachment uploaded 
endpoint imp ...)
+       TODO: check
+CVE-2026-68532 (Concrete CMS 9.0.0 to dashboard group type controller did not 
validate ...)
+       TODO: check
+CVE-2026-65831 (ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role 
user ca ...)
+       TODO: check
+CVE-2026-63696 (Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, 
contains a ...)
+       TODO: check
+CVE-2026-63695 (Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, 
contains a ...)
+       TODO: check
+CVE-2026-63443 (Coder allows organizations to provision remote development 
environment ...)
+       TODO: check
+CVE-2026-62379 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-62280 (Open Access Management (OpenAM) is an access management 
solution. From ...)
+       TODO: check
+CVE-2026-62263 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-61668 (DIRAC is an interware, meaning a software framework for 
distributed co ...)
+       TODO: check
+CVE-2026-61667 (DIRAC is an interware, meaning a software framework for 
distributed co ...)
+       TODO: check
+CVE-2026-61549 (Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, 
pipeline/backen ...)
+       TODO: check
+CVE-2026-59973 (FrontMCP is a TypeScript-first framework for the Model Context 
Protoco ...)
+       TODO: check
+CVE-2026-59971 (MySQL MCP Server is a Model Context Protocol server that 
enables secur ...)
+       TODO: check
+CVE-2026-59965 (Payload Plugins is a collection of plugins designed to enhance 
Payload ...)
+       TODO: check
+CVE-2026-59341 (A security vulnerability exists in the Sealed Secrets 
controller's una ...)
+       TODO: check
+CVE-2026-59160 (Yeger is a monorepo for npm packages maintained under the 
yeger scope. ...)
+       TODO: check
+CVE-2026-59157 (webhookd is a minimalist webhook server that triggers shell 
scripts an ...)
+       TODO: check
+CVE-2026-58773 (In link_load_gnss_image of link_device.c, there is a possible 
out-of-b ...)
+       TODO: check
+CVE-2026-58767 (In multiple functions of arm-smmu-v3.c, there is a possible 
escalation ...)
+       TODO: check
+CVE-2026-58766 (In multiple functions of arm-smmu-v3.c, there is a possible 
escalation ...)
+       TODO: check
+CVE-2026-58765 (In GPU, there is a possible permission bypass due to a logic 
error in  ...)
+       TODO: check
+CVE-2026-58755 (In smmu_install_nested_ste of arm-smmu-v3.c, there is a 
possible escal ...)
+       TODO: check
+CVE-2026-58751 (In multiple functions of arm-smmu-v3.c, there is a possible 
use-after- ...)
+       TODO: check
+CVE-2026-58747 (In smmu_detach_dev of arm-smmu-v3.c, there is a possible 
permission by ...)
+       TODO: check
+CVE-2026-58744 (In multiple locations, there is a possible escalation of 
privilege due ...)
+       TODO: check
+CVE-2026-58739 (In platform_msg_handler_init of default_msg_handlers.c, there 
is a pos ...)
+       TODO: check
+CVE-2026-58734 (In google_mba_recv_msg of google_mba_poll.c, there is a 
possible out-o ...)
+       TODO: check
+CVE-2026-58731 (In multiple functions of physmem_extmem_linux.c, there is a 
possible o ...)
+       TODO: check
+CVE-2026-58728 (In ARM64_TLBI of mmu.h, there is a possible memory corruption 
due to a ...)
+       TODO: check
+CVE-2026-58726 (In FsmReleaseKey of fsm.c, there is a possible permission 
bypass due t ...)
+       TODO: check
+CVE-2026-58724 (In multiple locations, there is a possible use-after-free due 
to a rac ...)
+       TODO: check
+CVE-2026-58721 (In multiple locations, there is a possible information 
disclosure due  ...)
+       TODO: check
+CVE-2026-58718 (In smmu_detach_dev_nested of arm-smmu-v3.c, there is a 
possible escala ...)
+       TODO: check
+CVE-2026-58716 (In multiple locations, there is a possible time-of-check to 
time-of-us ...)
+       TODO: check
+CVE-2026-58710 (In DecodeFilmGrainParams of film_grain_dec.cc, there is a 
possible out ...)
+       TODO: check
+CVE-2026-58704 (In Cellular Modem, there is a possible permission bypass due 
to a logi ...)
+       TODO: check
+CVE-2026-58701 (In trusty_dputc of generic-arm64-smcall.c, there is a possible 
out-of- ...)
+       TODO: check
+CVE-2026-58699 (In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible 
out-of-b ...)
+       TODO: check
+CVE-2026-58698 (In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a 
possible perm ...)
+       TODO: check
+CVE-2026-58695 (In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is 
a possi ...)
+       TODO: check
+CVE-2026-58691 (In FsmReleaseKey of fsm.c, there is a possible permission 
bypass due t ...)
+       TODO: check
+CVE-2026-58683 (In IP Multimedia Subsystem, there is a possible out-of-bounds 
write du ...)
+       TODO: check
+CVE-2026-58679 (In gf_ta_test_set_config of gf_ta_test.c, there is a possible 
heap buf ...)
+       TODO: check
+CVE-2026-58678 (In Bootloader, there is a possible permission bypass due to a 
logic er ...)
+       TODO: check
+CVE-2026-58502 (githubtoplanguages generates a user's top GitHub languages as 
an SVG.  ...)
+       TODO: check
+CVE-2026-58485 (mcp-searxng is a Model Context Protocol server that gives AI 
assistant ...)
+       TODO: check
+CVE-2026-58483 (mcp-searxng is a Model Context Protocol server that gives AI 
assistant ...)
+       TODO: check
+CVE-2026-58201 (Lokka is a Model Context Protocol server for Microsoft 365, 
including  ...)
+       TODO: check
+CVE-2026-58200 (Payload Plugins is a collection of plugins designed to enhance 
Payload ...)
+       TODO: check
+CVE-2026-58196 (ToolHive is a utility designed to simplify the deployment and 
manageme ...)
+       TODO: check
+CVE-2026-57586 (CodeRAG is a lightweight semantic code search and distillation 
utility ...)
+       TODO: check
+CVE-2026-57442 (MCPVault is a lightweight Model Context Protocol server for 
safe acces ...)
+       TODO: check
+CVE-2026-57441 (MCPVault is a lightweight Model Context Protocol server for 
safe acces ...)
+       TODO: check
+CVE-2026-57148 (PraisonAI is a multi-agent teams system. Prior to 0.1.6, 
praisonai_pla ...)
+       TODO: check
+CVE-2026-57147 (PraisonAI is a multi-agent teams system. Prior to 0.1.6, 
praisonai_pla ...)
+       TODO: check
+CVE-2026-57141 (PraisonAI is a multi-agent teams system. Prior to 1.7.2, the 
codeMode  ...)
+       TODO: check
+CVE-2026-57140 (PraisonAI is a multi-agent teams system. From 1.6.0 until 
1.7.2, Agent ...)
+       TODO: check
+CVE-2026-57139 (PraisonAI is a multi-agent teams system. From 1.5.0 until 
1.7.2, MCPSe ...)
+       TODO: check
+CVE-2026-57138 (PraisonAI is a multi-agent teams system. From 1.4.0 until 
1.7.2, codeM ...)
+       TODO: check
+CVE-2026-57137 (PraisonAI is a multi-agent teams system. From 1.4.0 until 
1.7.2, creat ...)
+       TODO: check
+CVE-2026-57136 (PraisonAI is a multi-agent teams system. From 1.2.3 until 
1.7.2, Comma ...)
+       TODO: check
+CVE-2026-57135 (PraisonAI is a multi-agent teams system. From 1.2.3 until 
1.7.2, Sandb ...)
+       TODO: check
+CVE-2026-57134 (PraisonAI is a multi-agent teams system. From 1.5.1 until 
1.7.2, MCPSe ...)
+       TODO: check
+CVE-2026-57133 (PraisonAI is a multi-agent teams system. From 1.5.1 until 
1.7.2, the s ...)
+       TODO: check
+CVE-2026-57112 (PraisonAI is a multi-agent teams system. From praisonaiagents 
0.6.0 un ...)
+       TODO: check
+CVE-2026-57042 (In multiple functions of DreamPickerReceiver.kt, there is a 
possible p ...)
+       TODO: check
+CVE-2026-57035 (In multiple locations, there is a possible out-of-bounds write 
due to  ...)
+       TODO: check
+CVE-2026-57014 (In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, 
there i ...)
+       TODO: check
+CVE-2026-57012 (In the Setup Wizard, there is a possible remote package 
install due to ...)
+       TODO: check
+CVE-2026-57008 (In Modem, there is a possible information disclosure due to 
improper i ...)
+       TODO: check
+CVE-2026-57006 (In acfw_ffa.c, there is a possible secret read due to a logic 
error in ...)
+       TODO: check
+CVE-2026-56997 (In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible 
out-of- ...)
+       TODO: check
+CVE-2026-56992 (In multiple files, there is a possible permission bypass due 
to a conf ...)
+       TODO: check
+CVE-2026-56989 (In multiple locations, there is a possible out-of-bounds write 
due to  ...)
+       TODO: check
+CVE-2026-56988 (In multiple functions of bluetooth_cco.cc, there is a possible 
use-aft ...)
+       TODO: check
+CVE-2026-56986 (In multiple files, there is a possible out-of-bounds read due 
to type  ...)
+       TODO: check
+CVE-2026-56985 (In multiple files, there is a possible way to obtain 
signatures due to ...)
+       TODO: check
+CVE-2026-56982 (In VPU, there is a possible permission bypass due to a missing 
permiss ...)
+       TODO: check
+CVE-2026-56979 (In multiple locations, there is a possible permission bypass 
due to a  ...)
+       TODO: check
+CVE-2026-56978 (In get_global_config_item_addr of gc.c, there is a possible 
out-of-bou ...)
+       TODO: check
+CVE-2026-56975 (In Cellular Modem, there is a possible denial of service due 
to improp ...)
+       TODO: check
+CVE-2026-56974 (In Start of AudioRtpPayloadEncoderNode.cpp, there is a 
possible out-of ...)
+       TODO: check
+CVE-2026-56973 (In multiple locations, there is a possible escalation of 
privilege due ...)
+       TODO: check
+CVE-2026-56972 (In multiple locations, there is a possible out-of-bounds write 
due to  ...)
+       TODO: check
+CVE-2026-56970 (In multiple locations, there is a possible permission bypass 
due to a  ...)
+       TODO: check
+CVE-2026-56967 (In Cellular Modem, there is a possible out-of-bounds write due 
to a he ...)
+       TODO: check
+CVE-2026-56964 (In multiple locations, there is a possible use-after-free due 
to a rac ...)
+       TODO: check
+CVE-2026-56960 (In multiple locations, there is a possible use-after-free due 
to a log ...)
+       TODO: check
+CVE-2026-56958 (In gf_algo_get_cached_dump_data of gf_algo.c, there is a 
possible out- ...)
+       TODO: check
+CVE-2026-56950 (In validate_ns_buf of mbu_class.rs, there is a possible 
information di ...)
+       TODO: check
+CVE-2026-56945 (In VPU, there is a possible out-of-bounds write due to a 
confused depu ...)
+       TODO: check
+CVE-2026-56942 (In ReadTileInfo of vp9hwd_headers.cc, there is a possible 
out-of-bound ...)
+       TODO: check
+CVE-2026-56941 (In multiple functions of fpc_tee_hal.c, there is a possible 
use-after- ...)
+       TODO: check
+CVE-2026-56932 (In Trusted Execution Environment, there is a possible memory 
corruptio ...)
+       TODO: check
+CVE-2026-56923 (In handle_unmap_req of tipc_virtio_dev.c, there is a possible 
memory c ...)
+       TODO: check
+CVE-2026-56922 (In CPM, there is a possible permission bypass due to a 
confused deputy ...)
+       TODO: check
+CVE-2026-56920 (In s_decode_vui_param of fw_hevc_dec_header.c, there is a 
possible out ...)
+       TODO: check
+CVE-2026-56915 (In bigo_worker_thread of bigo.c, there is a possible 
escalation of pri ...)
+       TODO: check
+CVE-2026-56914 (In multiple locations, there is a possible use-after-free due 
to impro ...)
+       TODO: check
+CVE-2026-56907 (In VPU, there is a possible shared memory overwrite due to 
improper in ...)
+       TODO: check
+CVE-2026-56892 (In ReadDataElement of common.c, there is a possible 
information disclo ...)
+       TODO: check
+CVE-2026-56889 (In multiple locations, there is a possible permission bypass 
due to an ...)
+       TODO: check
+CVE-2026-56888 (In multiple locations, there is a possible permission bypass 
due to si ...)
+       TODO: check
+CVE-2026-56882 (In Cellular Modem, there is a possible information disclosure 
due to a ...)
+       TODO: check
+CVE-2026-56881 (In enable_segment of remap.c, there is a possible permission 
bypass du ...)
+       TODO: check
+CVE-2026-56879 (In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory 
corrupt ...)
+       TODO: check
+CVE-2026-56831 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, 
the /cpa ...)
+       TODO: check
+CVE-2026-56830 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, 
an earli ...)
+       TODO: check
+CVE-2026-56829 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, 
packages ...)
+       TODO: check
+CVE-2026-56827 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, 
groupedB ...)
+       TODO: check
+CVE-2026-56825 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, 
packages ...)
+       TODO: check
+CVE-2026-55887 (MCP Gateway allows easy and secure running and deployment of 
MCP serve ...)
+       TODO: check
+CVE-2026-55864 (GeoNetwork is a catalog application to manage spatially 
referenced res ...)
+       TODO: check
+CVE-2026-55863 (motionEye (mEye) is an online interface for a piece of 
software called ...)
+       TODO: check
+CVE-2026-55828 (qbee transport is a remote access transport protocol 
implementation. P ...)
+       TODO: check
+CVE-2026-55776 (OpenBao is an open source identity-based secrets management 
system. Pr ...)
+       TODO: check
+CVE-2026-55775 (OpenBao is an open source identity-based secrets management 
system. Pr ...)
+       TODO: check
+CVE-2026-55774 (OpenBao is an open source identity-based secrets management 
system. Pr ...)
+       TODO: check
+CVE-2026-55770 (OpenBao is an open source identity-based secrets management 
system. Pr ...)
+       TODO: check
+CVE-2026-55701 (The OpenTelemetry Collector Contrib repository contains 
components for ...)
+       TODO: check
+CVE-2026-55692 (The EmbedVideo Extension is a MediaWiki extension which adds a 
parser  ...)
+       TODO: check
+CVE-2026-55691 (The EmbedVideo Extension is a MediaWiki extension which adds a 
parser  ...)
+       TODO: check
+CVE-2026-55690 (The EmbedVideo Extension is a MediaWiki extension which adds a 
parser  ...)
+       TODO: check
+CVE-2026-55650 (Outerbase Studio is a lightweight browser-based database GUI 
supportin ...)
+       TODO: check
+CVE-2026-55636 (Capsule is a multi-tenancy and policy-based framework for 
Kubernetes.  ...)
+       TODO: check
+CVE-2026-55630 (Kiwi TCMS is an open source test management system. Prior to 
16.1, Tes ...)
+       TODO: check
+CVE-2026-55617 (Hydro is a next-generation high-performance online judge 
platform. Fro ...)
+       TODO: check
+CVE-2026-55591 (Signal K Server is a server application that runs on a central 
hub in  ...)
+       TODO: check
+CVE-2026-55375 (canto-saas-api is a PHP library for interacting with the Canto 
SaaS AP ...)
+       TODO: check
+CVE-2026-55374 (canto-saas-api is a PHP library for interacting with the Canto 
SaaS AP ...)
+       TODO: check
+CVE-2026-55366 (In IP Multimedia Subsystem, there is a possible authentication 
bypass  ...)
+       TODO: check
+CVE-2026-55365 (In multiple functions of remap.c, there is a possible 
out-of-bounds wr ...)
+       TODO: check
+CVE-2026-55359 (In multiple locations, there is a possible permission bypass 
due to a  ...)
+       TODO: check
+CVE-2026-55351 (In VPU, there is a possible out-of-bounds write due to an 
integer over ...)
+       TODO: check
+CVE-2026-55343 (In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible 
out-of-bo ...)
+       TODO: check
+CVE-2026-55332 (In multiple locations, there is a possible out-of-bounds write 
due to  ...)
+       TODO: check
+CVE-2026-55331 (In IP Multimedia Subsystem, there is a possible out-of-bounds 
write du ...)
+       TODO: check
+CVE-2026-55323 (In gf_base_update_finger_base of gf_base.c, there is a 
possible out-of ...)
+       TODO: check
+CVE-2026-55318 (In multiple locations, there is a possible use-after-free due 
to a rac ...)
+       TODO: check
+CVE-2026-55317 (In printf of printf.c, there is a possible out-of-bounds write 
due to  ...)
+       TODO: check
+CVE-2026-55306 (In Cellular Modem, there is a possible denial of service due 
to improp ...)
+       TODO: check
+CVE-2026-55304 (In addr_remap_address_map of remap.c, there is a possible 
escalation o ...)
+       TODO: check
+CVE-2026-55302 (In multiple locations, there is a possible permission bypass 
due to a  ...)
+       TODO: check
+CVE-2026-55301 (In Wave6VpuDecFlush of wave6.c, there is a possible 
out-of-bounds writ ...)
+       TODO: check
+CVE-2026-55211 (Surfio is a library for reading and writing surface files. 
Prior to 0. ...)
+       TODO: check
+CVE-2026-55178 (GeoLens is a self-hosted geospatial data catalog with semantic 
search, ...)
+       TODO: check
+CVE-2026-55158 (Conflibot warns in advance when merging a pull request will 
cause conf ...)
+       TODO: check
+CVE-2026-55149 (Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx 
using th ...)
+       TODO: check
+CVE-2026-54724 (Kiwi TCMS is an open source test management system. Prior to 
16.1, the ...)
+       TODO: check
+CVE-2026-54689 (mcp-searxng is a Model Context Protocol server that gives AI 
assistant ...)
+       TODO: check
+CVE-2026-54688 (mcp-searxng is a Model Context Protocol server that gives AI 
assistant ...)
+       TODO: check
+CVE-2026-54637 (Dragonfly is an open source P2P-based file distribution and 
image acce ...)
+       TODO: check
+CVE-2026-54561 (MCP Memory Keeper is an MCP server for persistent context 
management i ...)
+       TODO: check
+CVE-2026-54549 (Meta Ads MCP is a Model Context Protocol (MCP) server that 
lets AI ass ...)
+       TODO: check
+CVE-2026-54547 (Meta Ads MCP is a Model Context Protocol (MCP) server that 
lets AI ass ...)
+       TODO: check
+CVE-2026-54450 (ToolHive is a utility designed to simplify the deployment and 
manageme ...)
+       TODO: check
+CVE-2026-54254 (Cyberdrop-DL is a bulk asynchronous downloader for multiple 
file hosts ...)
+       TODO: check
+CVE-2026-54251 (netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) 
gateway  ...)
+       TODO: check
+CVE-2026-54168 (Pipelines-as-Code is a CI/CD system that lets users define 
Tekton pipe ...)
+       TODO: check
+CVE-2026-54167 (Pipelines-as-Code is a CI/CD system that lets users define 
Tekton pipe ...)
+       TODO: check
+CVE-2026-54077 (ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT 
DATABASE s ...)
+       TODO: check
+CVE-2026-54076 (ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for 
CVE-2026- ...)
+       TODO: check
+CVE-2026-54050 (Sakai is a Collaboration and Learning Environment (CLE). From 
23.0 unt ...)
+       TODO: check
+CVE-2026-53966 (XWiki Platform is a generic wiki platform. From 13.4-rc-1 
until 16.10. ...)
+       TODO: check
+CVE-2026-53957 (Contentful MCP Server is a Model Context Protocol server for 
the Conte ...)
+       TODO: check
+CVE-2026-53954 (Bugsink is a self-hosted error tracking tool. Prior to version 
2.2.2,  ...)
+       TODO: check
+CVE-2026-53941 (Inspektor Gadget is a set of tools and framework for data 
collection a ...)
+       TODO: check
+CVE-2026-53710 (MCP Context Forge is an AI gateway, registry, and proxy for 
MCP, A2A,  ...)
+       TODO: check
+CVE-2026-53660 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-53658 (Fabric CA is a Certificate Authority for Hyperledger Fabric. 
Prior to  ...)
+       TODO: check
+CVE-2026-53459 (Bambuddy is a self-hosted print archive and management system 
for Bamb ...)
+       TODO: check
+CVE-2026-52828 (Kimai is an open-source time tracking application. Prior to 
2.58.0, Ex ...)
+       TODO: check
+CVE-2026-52827 (Kimai is an open-source time tracking application. Prior to 
2.59.0, th ...)
+       TODO: check
+CVE-2026-52826 (Kimai is an open-source time tracking application. Prior to 
2.57.0, GE ...)
+       TODO: check
+CVE-2026-52825 (Kimai is an open-source time tracking application. Prior to 
2.58.0, PO ...)
+       TODO: check
+CVE-2026-52824 (Kimai is an open-source time tracking application. Prior to 
2.58.0, th ...)
+       TODO: check
+CVE-2026-52823 (Kimai is an open-source time tracking application. Prior to 
2.58.0, Ti ...)
+       TODO: check
+CVE-2026-52822 (Kimai is an open-source time tracking application. Prior to 
2.58.0, PA ...)
+       TODO: check
+CVE-2026-52821 (Kimai is an open-source time tracking application. Prior to 
2.57.0, GE ...)
+       TODO: check
+CVE-2026-52820 (Kimai is an open-source time tracking application. Prior to 
2.57.0, PA ...)
+       TODO: check
+CVE-2026-52819 (Kimai is an open-source time tracking application. Prior to 
2.57.0, th ...)
+       TODO: check
+CVE-2026-52724 (Kuma is a modern Envoy-based service mesh that can run on 
every cloud  ...)
+       TODO: check
+CVE-2026-52484 (An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 
allows a ...)
+       TODO: check
+CVE-2026-50166 (Kuma is a modern Envoy-based service mesh that can run on 
every cloud  ...)
+       TODO: check
+CVE-2026-50024 (GitHacker is a tool that restores Git repositories from 
exposed .git d ...)
+       TODO: check
+CVE-2026-49446 (Cosmos provides users the ability self-host a home server by 
acting as ...)
+       TODO: check
+CVE-2026-49254 (Dragonfly is an open source P2P-based file distribution and 
image acce ...)
+       TODO: check
+CVE-2026-48987 (pyLoad is a free and open-source download manager written in 
Python. P ...)
+       TODO: check
+CVE-2026-48737 (pyLoad is a free and open-source download manager written in 
Python. P ...)
+       TODO: check
+CVE-2026-48722 (Nextflow is a DSL for data-driven computational pipelines. 
From 25.09. ...)
+       TODO: check
+CVE-2026-48717 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-47780 (free5GC is an open-source implementation of the 5G core 
network. In 4. ...)
+       TODO: check
+CVE-2026-47426 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-47424 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-46623 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-46619 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-46498 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-46495 (OpenDJ is an LDAPv3 compliant directory service. Prior to 
5.1.1, the J ...)
+       TODO: check
+CVE-2026-46488 (motionEye (mEye) is an online interface for a piece of 
software called ...)
+       TODO: check
+CVE-2026-45794 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-45579 (DIRAC is an interware, meaning a software framework for 
distributed co ...)
+       TODO: check
+CVE-2026-45052 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-45051 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-45048 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-44793 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-44778 (Inspektor Gadget is a set of tools and framework for data 
collection a ...)
+       TODO: check
+CVE-2026-44300 (OpenCost provides cost monitoring for Kubernetes workloads and 
cloud c ...)
+       TODO: check
+CVE-2026-44282 (Decidim is a participatory democracy framework. Prior to 
0.32.0, a low ...)
+       TODO: check
+CVE-2026-44203 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-44202 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-44163 (fluent-plugin-opentelemetry is a Fluentd input and output 
plugin for f ...)
+       TODO: check
+CVE-2026-41573 (Open Access Management (OpenAM) is an access management 
solution. Prio ...)
+       TODO: check
+CVE-2026-40058 (CrowdStrike released a security update to address a 
vulnerability in t ...)
+       TODO: check
+CVE-2026-39919 (Ghostscript before 10.08.0 contains a heap-based buffer 
overflow vulne ...)
+       TODO: check
+CVE-2026-39040 (BharatMLStack up to and including 1.3.0 is vulnerable to Cross 
Site Sc ...)
+       TODO: check
+CVE-2026-39039 (In BharatMLStack up to and including v1.3.0, Trufflebox UI 
stores the  ...)
+       TODO: check
+CVE-2026-39038 (BharatMLStack up to and including v1.3.0 is vulnerable to 
Cross Site S ...)
+       TODO: check
+CVE-2026-37152 (TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to 
contain a ha ...)
+       TODO: check
+CVE-2026-25827 (An issue was discovered in Keyfactor SignServer before 7.6.0. 
A number ...)
+       TODO: check
+CVE-2026-25826 (An issue was discovered in Keyfactor SignServer before 7.6.0. 
The attr ...)
+       TODO: check
+CVE-2026-25825 (An issue was discovered in Keyfactor SignServer before 7.6.0. 
The outp ...)
+       TODO: check
+CVE-2026-21588 (This High severity DoS (Denial of Service) vulnerability was 
introduce ...)
+       TODO: check
+CVE-2026-21587 (This High severity Improper Authorization vulnerability was 
introduced ...)
+       TODO: check
+CVE-2026-21586 (This High severity Improper Authorization vulnerability was 
introduced ...)
+       TODO: check
+CVE-2026-1759 (Improper handling of insufficient permissions or privileges 
vulnerabil ...)
+       TODO: check
+CVE-2026-1758 (Session fixation vulnerability in Secomea GateManager 
(webserver modul ...)
+       TODO: check
+CVE-2026-19886 (OriginLab Origin Viewer OGM File Parsing Memory Corruption 
Remote Code ...)
+       TODO: check
+CVE-2026-19885 (OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write 
Remote C ...)
+       TODO: check
+CVE-2026-19781 (Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer 
Overflow Remote ...)
+       TODO: check
+CVE-2026-19780 (Koha Eval Code Injection Remote Code Execution Vulnerability. 
This vul ...)
+       TODO: check
+CVE-2026-19774 (BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution 
Vulnerabi ...)
+       TODO: check
+CVE-2026-19773 (libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds 
Write Rem ...)
+       TODO: check
+CVE-2026-19641 (On affected platforms running Arista EOS with password 
authentication  ...)
+       TODO: check
+CVE-2026-19515 (The WSO2 Integrator MI VS Code extension fails to properly 
sanitize or ...)
+       TODO: check
+CVE-2026-19504 (Fabric.js loadFromJSON Server-Side Request Forgery 
Vulnerability. This ...)
+       TODO: check
+CVE-2026-19407 (Bucket Squatting in Google Cloud Gemini Enterprise Agent 
Platform SDK  ...)
+       TODO: check
+CVE-2026-18115 (Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field 
edit_user_proper ...)
+       TODO: check
+CVE-2026-18113 (In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did 
not HTM ...)
+       TODO: check
+CVE-2026-18111 (Concrete CMS 9 before 9.5.3 was vulnerable to stored 
cross-site script ...)
+       TODO: check
+CVE-2026-18110 (Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an 
authorization ...)
+       TODO: check
+CVE-2026-16141 (OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a 
logic fl ...)
+       TODO: check
+CVE-2026-16140 (OpenBMC's IPMI implementation, phosphor-net-ipmid, is 
vulnerable to a  ...)
+       TODO: check
+CVE-2026-15609 (The Bridge - Creative Multipurpose WordPress Theme theme for 
WordPress ...)
+       TODO: check
+CVE-2026-14805 (The Consulting theme for WordPress is vulnerable to Privilege 
Escalati ...)
+       TODO: check
+CVE-2026-13210 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-12910 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-12752 (IBM Business Automation Workflow containers and traditional is 
vulnera ...)
+       TODO: check
+CVE-2026-12751 (IBM Cloud Pak for Business Automation is vulnerable to HTML 
injection. ...)
+       TODO: check
+CVE-2026-12750 (IBM Cloud Pak for Business Automation is vulnerable to stored 
cross-si ...)
+       TODO: check
+CVE-2026-12749 (IBM Cloud Pak for Business Automation is vulnerable to stored 
cross-si ...)
+       TODO: check
+CVE-2026-12742 (IBM Business Automation Workflow containers and traditional 
could allo ...)
+       TODO: check
+CVE-2026-12728 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 
LTS, 9.3 ...)
+       TODO: check
+CVE-2026-12667 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 
LTS, 9.3 ...)
+       TODO: check
+CVE-2026-12666 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 
LTS, 9.3 ...)
+       TODO: check
+CVE-2026-12358 (IBM Verify Identity Access could allow a remote attacker to 
cause a de ...)
+       TODO: check
+CVE-2026-12355 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 
LTS, 9.3 ...)
+       TODO: check
+CVE-2026-12354 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 
LTS, 9.3 ...)
+       TODO: check
+CVE-2026-12351 (IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 
CD, 9.4.0 ...)
+       TODO: check
+CVE-2026-12150 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 
LTS, 9.3 ...)
+       TODO: check
+CVE-2026-12101 (IBM Verify Identity Access could allow an administrator to 
execute add ...)
+       TODO: check
+CVE-2026-11934 (IBM Verify Identity Access could allow an administrator to 
execute add ...)
+       TODO: check
+CVE-2026-11929 (IBM Security Verify Identity Access Reverse Proxy in certain 
configura ...)
+       TODO: check
+CVE-2026-11928 (IBM Verify Identity Access is vulnerable to a buffer overflow 
attack.)
+       TODO: check
+CVE-2026-11927 (IBM Security Verify Identity Access reverse proxy may allow 
parameters ...)
+       TODO: check
+CVE-2026-11926 (IBM Verify Identity Access could allow a remote attacker to 
cause a de ...)
+       TODO: check
+CVE-2026-11921 (IBM Verify Identity Access containers may not apply management 
passwor ...)
+       TODO: check
+CVE-2026-11918 (IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge 
could all ...)
+       TODO: check
+CVE-2026-11864 (IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 
Interim Fi ...)
+       TODO: check
+CVE-2026-11729 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 
LTS, 9.3 ...)
+       TODO: check
+CVE-2026-11728 (IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 
LTS, 9.3 ...)
+       TODO: check
+CVE-2026-0200 (In Cellular Modem, there is a possible out-of-bounds write due 
to a he ...)
+       TODO: check
+CVE-2026-0199 (In gf_ta_test_set_config of gf_ta_test.c, there is a possible 
out-of-b ...)
+       TODO: check
+CVE-2026-0197 (In VPU, there is a possible information dislclosure due to a 
logic err ...)
+       TODO: check
+CVE-2026-0194 (In multiple locations, there is a possible permission bypass 
due to an ...)
+       TODO: check
+CVE-2026-0192 (In Bootloader, there is a possible escalation of privilege due 
to a mi ...)
+       TODO: check
+CVE-2026-0189 (In ac_init_policy of init.c, there is a possible permission 
bypass due ...)
+       TODO: check
+CVE-2026-0187 (In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a 
possible esc ...)
+       TODO: check
+CVE-2026-0186 (In ac_init_one_sswrp of init.c, there is a possible escalation 
of priv ...)
+       TODO: check
+CVE-2026-0183 (In CPM, there is a possible information disclosure due to a 
confused d ...)
+       TODO: check
+CVE-2026-0179 (In Bootloader, there is a possible permission bypass due to a 
missing  ...)
+       TODO: check
+CVE-2026-0177 (In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible 
out-of-b ...)
+       TODO: check
+CVE-2026-0171 (In multiple locations, there is a possible out-of-bounds write 
due to  ...)
+       TODO: check
+CVE-2026-0170 (In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible 
out-of- ...)
+       TODO: check
+CVE-2026-0159 (In Cellular Modem, there is a possible out-of-bounds write due 
to a mi ...)
+       TODO: check
+CVE-2025-66974 (An issue in Prolink 13A Smart Plug Model Version: 
DS-3202M-UKv3 Wi-Fi  ...)
+       TODO: check
+CVE-2025-5802 (The self-registration flow accepts user-supplied input for 
usernames w ...)
+       TODO: check
+CVE-2025-13166 (The SMS OTP flow fails to adequately handle error messages, 
allowing a ...)
+       TODO: check
+CVE-2024-58385 (Yonyou U8 CRM contains an unauthenticated SQL injection 
vulnerability  ...)
+       TODO: check
+CVE-2024-58384 (Tornado before 6.4.1 contains a CRLF injection vulnerability 
in CurlAs ...)
+       TODO: check
+CVE-2024-14029 (Tornado before 6.4.1 ignores duplicate Transfer-Encoding: 
chunked head ...)
+       TODO: check
+CVE-2023-54398 (Yonyou U8 Cloud contains an unauthenticated Java 
deserialization vulne ...)
+       TODO: check
+CVE-2023-54397 (Tornado before 6.3.3 contains an HTTP request smuggling 
vulnerability  ...)
+       TODO: check
+CVE-2026-92079 (Mitigation bypass in the Widget: Win32 component. This 
vulnerability w ...)
        - firefox <not-affected> (Only affects Firefox on Windows)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92079
-CVE-2026-92078
+CVE-2026-92078 (Denial-of-service in the Security component. This 
vulnerability was fi ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92078
-CVE-2026-92077
+CVE-2026-92077 (Denial-of-service in the SVG component. This vulnerability was 
fixed i ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92077
-CVE-2026-92076
+CVE-2026-92076 (Incorrect boundary conditions in the Networking component. 
This vulner ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92076
-CVE-2026-92075
+CVE-2026-92075 (Mitigation bypass in the Networking component. This 
vulnerability was  ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92075
-CVE-2026-92074
+CVE-2026-92074 (Mitigation bypass in the Popup Blocker component. This 
vulnerability w ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92074
-CVE-2026-92073
+CVE-2026-92073 (Privilege escalation in the Enterprise Policies component. 
This vulner ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92073
-CVE-2026-92072
+CVE-2026-92072 (Incorrect boundary conditions in the Safe Browsing component. 
This vul ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92072
-CVE-2026-92071
+CVE-2026-92071 (Sandbox escape due to incorrect boundary conditions in the 
Widget: Win ...)
        - firefox <not-affected> (Only affects Firefox on Windows)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92071
-CVE-2026-92070
+CVE-2026-92070 (Information disclosure in the Networking component. This 
vulnerability ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92070
-CVE-2026-92069
+CVE-2026-92069 (Spoofing issue in the DOM: Navigation component. This 
vulnerability wa ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92069
-CVE-2026-92068
+CVE-2026-92068 (Site isolation issue in the Reader Mode component. This 
vulnerability  ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92068
-CVE-2026-92067
+CVE-2026-92067 (Use-after-free in the Widget: Gtk component. This 
vulnerability was fi ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92067
-CVE-2026-92066
+CVE-2026-92066 (Sandbox escape in the Profile Backup component. This 
vulnerability was ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92066
-CVE-2026-92065
+CVE-2026-92065 (Sandbox escape due to incorrect boundary conditions in the 
Widget: Win ...)
        - firefox <not-affected> (Only affects Firefox on Windows)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92065
-CVE-2026-92064
+CVE-2026-92064 (Sandbox escape due to incorrect boundary conditions in the 
Widget: Win ...)
        - firefox <not-affected> (Only affects Firefox on Windows)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92064
-CVE-2026-92063
+CVE-2026-92063 (Denial-of-service in the Audio/Video component. This 
vulnerability was ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92063
-CVE-2026-92062
+CVE-2026-92062 (Privilege escalation in the Session Restore component. This 
vulnerabil ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92062
-CVE-2026-92061
+CVE-2026-92061 (Incorrect boundary conditions in the Security: Process 
Sandboxing comp ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92061
-CVE-2026-92060
+CVE-2026-92060 (Use-after-free in the Internationalization component. This 
vulnerabili ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92060
-CVE-2026-92059
+CVE-2026-92059 (Incorrect boundary conditions in the DOM: Editor component. 
This vulne ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92059
-CVE-2026-92058
+CVE-2026-92058 (Use-after-free in the Graphics component. This vulnerability 
was fixed ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92058
-CVE-2026-92032
+CVE-2026-92032 (Sandbox escape due to invalid pointer in the Graphics 
component. This  ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92032
-CVE-2026-92031
+CVE-2026-92031 (Information disclosure in the Graphics: ImageLib component. 
This vulne ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92031
-CVE-2026-92057
+CVE-2026-92057 (Mitigation bypass in the Enterprise Policies component. This 
vulnerabi ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92057
-CVE-2026-92056
+CVE-2026-92056 (Use-after-free in the Graphics: Text component. This 
vulnerability was ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92056
-CVE-2026-92055
+CVE-2026-92055 (Privilege escalation in the DevTools component. This 
vulnerability was ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92055
-CVE-2026-92054
+CVE-2026-92054 (Privilege escalation in the Memory component. This 
vulnerability was f ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92054
-CVE-2026-92053
+CVE-2026-92053 (Privilege escalation in the Graphics: CanvasWebGL component. 
This vuln ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92053
-CVE-2026-92052
+CVE-2026-92052 (Privilege escalation due to uninitialized memory in the 
Graphics: Canv ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92052
-CVE-2026-92051
+CVE-2026-92051 (Spoofing issue due to invalid pointer in the Graphics 
component. This  ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92051
-CVE-2026-92050
+CVE-2026-92050 (Sandbox escape due to race condition in the XPConnect 
component. This  ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92050
-CVE-2026-92049
+CVE-2026-92049 (Use-after-free in the Widget: Win32 component. This 
vulnerability was  ...)
        - firefox <not-affected> (Only affects Firefox on Windows)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92049
-CVE-2026-92048
+CVE-2026-92048 (Sandbox escape due to incorrect boundary conditions in the 
Widget: Win ...)
        - firefox <not-affected> (Only affects Firefox on Windows)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92048
-CVE-2026-92047
+CVE-2026-92047 (Privilege escalation in the Crash Reporting component. This 
vulnerabil ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92047
-CVE-2026-92046
+CVE-2026-92046 (Use-after-free in the Graphics component. This vulnerability 
was fixed ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92046
-CVE-2026-92030
+CVE-2026-92030 (Mitigation bypass in the DOM: Copy & Paste and Drag & Drop 
component.  ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92030
-CVE-2026-92045
+CVE-2026-92045 (Sandbox escape due to incorrect boundary conditions in the 
WebRTC comp ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92045
-CVE-2026-92044
+CVE-2026-92044 (Information disclosure in the Networking: HTTP component. This 
vulnera ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92044
-CVE-2026-92043
+CVE-2026-92043 (Privilege escalation due to incorrect boundary conditions in 
the Audio ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92043
-CVE-2026-92042
+CVE-2026-92042 (Race condition in the DOM: Content Processes component. This 
vulnerabi ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92042
-CVE-2026-92041
+CVE-2026-92041 (Mitigation bypass in the DOM: Networking component. This 
vulnerability ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92041
-CVE-2026-92040
+CVE-2026-92040 (Use-after-free in the JavaScript: WebAssembly component. This 
vulnerab ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92040
-CVE-2026-92039
+CVE-2026-92039 (Mitigation bypass in the DOM: Notifications component. This 
vulnerabil ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92039
-CVE-2026-92038
+CVE-2026-92038 (Mitigation bypass in the Remote Settings Client component. 
This vulner ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92038
-CVE-2026-92037
+CVE-2026-92037 (Incorrect boundary conditions in the DOM: Animation component. 
This vu ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92037
-CVE-2026-92029
+CVE-2026-92029 (Use-after-free in the SVG component. This vulnerability was 
fixed in F ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92029
-CVE-2026-92028
+CVE-2026-92028 (Use-after-free in the DOM: Core & HTML component. This 
vulnerability w ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92028
-CVE-2026-92027
+CVE-2026-92027 (Use-after-free in the DOM: Streams component. This 
vulnerability was f ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92027
-CVE-2026-92036
+CVE-2026-92036 (Incorrect boundary conditions in the Networking: HTTP 
component. This  ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92036
-CVE-2026-92026
+CVE-2026-92026 (Use-after-free in the Networking component. This vulnerability 
was fix ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92026
-CVE-2026-92025
+CVE-2026-92025 (Use-after-free in the DOM: Navigation component. This 
vulnerability wa ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92025
-CVE-2026-92024
+CVE-2026-92024 (Use-after-free in the SVG component. This vulnerability was 
fixed in F ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92024
-CVE-2026-92023
+CVE-2026-92023 (Use-after-free in the XML component. This vulnerability was 
fixed in F ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92023
-CVE-2026-92022
+CVE-2026-92022 (Use-after-free in the DOM: HTML Parser component. This 
vulnerability w ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92022
-CVE-2026-92020
+CVE-2026-92020 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92020
-CVE-2026-92019
+CVE-2026-92019 (Mitigation bypass in the Remote Settings Client component. 
This vulner ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92019
-CVE-2026-92018
+CVE-2026-92018 (Sandbox escape in the DOM: Core & HTML component. This 
vulnerability w ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92018
-CVE-2026-92017
+CVE-2026-92017 (Privilege escalation in the DOM: Service Workers component. 
This vulne ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92017
-CVE-2026-92016
+CVE-2026-92016 (Use-after-free in the Disability Access APIs component. This 
vulnerabi ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92016
-CVE-2026-92035
+CVE-2026-92035 (Sandbox escape due to incorrect boundary conditions in the 
Graphics co ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92035
-CVE-2026-92034
+CVE-2026-92034 (Site isolation issue in the Graphics component. This 
vulnerability was ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92034
-CVE-2026-92015
+CVE-2026-92015 (Privilege escalation in the WebExtensions component. This 
vulnerabilit ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92015
-CVE-2026-92013
+CVE-2026-92013 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92013
-CVE-2026-92012
+CVE-2026-92012 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92012
-CVE-2026-92011
+CVE-2026-92011 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92011
-CVE-2026-92010
+CVE-2026-92010 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92010
-CVE-2026-92009
+CVE-2026-92009 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92009
-CVE-2026-92008
+CVE-2026-92008 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92008
-CVE-2026-92007
+CVE-2026-92007 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92007
-CVE-2026-92006
+CVE-2026-92006 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92006
-CVE-2026-92005
+CVE-2026-92005 (Use-after-free in the Audio/Video: Web Codecs component. This 
vulnerab ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92005
-CVE-2026-92033
+CVE-2026-92033 (Privilege escalation in Firefox for Android. This 
vulnerability was fi ...)
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92033
 CVE-2026-91774 (Yao through v1.0.0-rc22 authenticates but fails to authorize 
the GET / ...)
@@ -362,6 +1294,7 @@ CVE-2026-90816 (A vulnerability was found in FFmpeg 8.0.x. 
This affects the func
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21492
        NOTE: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/64fafd63f0b4ebf8dbbdbdc2296f21a03548b5fc
 (n8.1)
 CVE-2026-90815 (A vulnerability has been found in FFmpeg up to 
4.4.6/5.1.8/6.1.4/7.1.3 ...)
+       {DSA-6276-1 DSA-6268-1}
        - ffmpeg 7:8.1-1
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21487
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/8970658472d1cb62d663ece0b6cacf4a1f465da3
 (n8.1)
@@ -10798,7 +11731,7 @@ CVE-2026-20500 (In Modem, there is a possible system 
crash due to improper input
        NOT-FOR-US: MediaTek
 CVE-2026-16876 (An authentication bypass vulnerability exists in the WebGUI of 
Series  ...)
        NOT-FOR-US: NEC
-CVE-2026-85013
+CVE-2026-85013 (A flaw was found in environment-modules. A local attacker can 
exploit  ...)
        - modules 5.6.1-3
        [trixie] - modules <no-dsa> (Minor issue; will be fixed via point 
release)
        NOTE: Fixed by: 
https://github.com/envmodules/modules/commit/d401b76a863386f9064637c71b66837805f82881
 (v5.6.2)
@@ -19703,7 +20636,7 @@ CVE-2026-81893 (A flaw was found in gdk-pixbuf. When 
loading a specially crafted
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01
        NOTE: The introducing commit is the fix for CVE-2025-7345.
        NOTE: Since gdk-pixbuf >= 2.44.5+dfsg-3 gdk-pixbuf loads most image 
formats using glycin
-CVE-2026-80489
+CVE-2026-80489 (Converting crafted EUC_JISX0213 input to UCS-4 or the internal 
wide ch ...)
        - glibc 2.43-5 (bug #1145987)
        [trixie] - glibc <no-dsa> (Minor issue)
        [bookworm] - glibc <postponed> (Minor issue)
@@ -20763,7 +21696,7 @@ CVE-2026-80158 (A flaw was found in the ipa_getkeytab 
module of the community.ge
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524651
 CVE-2026-78360
        NOT-FOR-US: fedora-infra/anitya
-CVE-2026-77117
+CVE-2026-77117 (Converting crafted SHIFT_JISX0213 input to UCS-4 or the 
internal wide  ...)
        - glibc 2.43-5 (bug #1145880)
        [trixie] - glibc <no-dsa> (Minor issue)
        [bookworm] - glibc <postponed> (Minor issue)
@@ -88552,15 +89485,15 @@ CVE-2026-12064 (When a user invokes curl using a 
schemeless URL combined with `-
        NOTE: https://curl.se/docs/CVE-2026-12064.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/18270893abdb19f0ca170c118f8a2847dbd304be 
(curl-7_81_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/ab3bb8cd8be8f9d4acb97da0418abc279182041e 
(rc-8_21_0-3, curl-8_21_0)
-CVE-2026-47215
+CVE-2026-47215 (SingularityCE and SingularityPRO are open source container 
platforms.  ...)
        - singularity-container <removed>
        NOTE: 
https://github.com/sylabs/singularity/security/advisories/GHSA-wqcr-7rf3-f64m
-CVE-2026-48785
+CVE-2026-48785 (Apptainer is an open source container platform. Prior to 
version 1.5.1 ...)
        - apptainer <unfixed> (bug #1140649)
        NOTE: 
https://github.com/apptainer/apptainer/security/advisories/GHSA-cr2j-534f-mf3g
        NOTE: Fixed by: 
https://github.com/apptainer/apptainer/commit/0ff35257420e0c6cb97dac11d305749c893e5214
 (v1.5.1)
        NOTE: Fixed by: 
https://github.com/apptainer/apptainer/commit/4ce069ed6e56e1acd8cbfbfc0d57ccce3311bf92
 (v1.5.1)
-CVE-2026-54503
+CVE-2026-54503 (plone.app.textfield provides a zope.schema-style field type 
called Ric ...)
        NOT-FOR-US: Plone
 CVE-2026-55830 (RestrictedPython is a tool that helps to define a subset of 
the Python ...)
        NOT-FOR-US: Plone
@@ -89718,7 +90651,7 @@ CVE-2026-6653 (Use After Free in libxml2's 
xmlParseInternalSubset from GNOME lib
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libxml2/-/commit/463bbeeca1805b5c4828f50d0fefc4eebaf620df
 (v2.11.0)
        NOTE: Mark 2.14.5+dfsg-0.1 as the first version fixed in unstable as 
from 2.12.7+dfsg-1
        NOTE: the version was reverted back to a 2.9.14 based one.
-CVE-2026-55226
+CVE-2026-55226 (Strimzi provides a way to run an Apache Kafka cluster on 
Kubernetes or ...)
        NOT-FOR-US: Strimzi
 CVE-2026-8918 (A permissive list of allowed inputs in ASUS Armoury Crate 
allows a loc ...)
        NOT-FOR-US: ASUS
@@ -90462,7 +91395,7 @@ CVE-2026-50195 (containerd is an open-source container 
runtime. Versions prior t
        [bookworm] - containerd <not-affected> (Vulnerable code not present, 
only affects 2.x)
        [bullseye] - containerd <not-affected> (Vulnerable code not present, 
only affects 2.x)
        NOTE: 
https://github.com/containerd/containerd/security/advisories/GHSA-cvxm-645q-p574
-CVE-2026-55225
+CVE-2026-55225 (Strimzi provides a way to run an Apache Kafka cluster on 
Kubernetes or ...)
        NOT-FOR-US: Strimzi
 CVE-2026-3865
        NOT-FOR-US: Kubernetes CSI Driver for SMB



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6abaef06f49dbf2fc10b57fff2d7a34536333ce

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6abaef06f49dbf2fc10b57fff2d7a34536333ce
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to