Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ac210c50 by security tracker role at 2026-09-17T07:14:29+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-92839 (Canva Desktop before v1.125.0 performed double decoding in the
deeplin ...)
TODO: check
CVE-2026-92838 (A DLL hijacking vulnerability exists in the GeoVisionGV-Remote
E-Mapde ...)
- TODO: check
+ NOT-FOR-US: GeoVision
CVE-2026-92816 (ComfyUI before 0.30.0 fails to sanitize folder_name input in
dataset s ...)
TODO: check
CVE-2026-92815 (changedetection.io through 0.60.6 fails to validate the Goto
URL actio ...)
@@ -19,7 +19,7 @@ CVE-2026-92810 (PrestaShop blockwishlist through 3.0.2 fails
to validate wishlis
CVE-2026-92809 (PrestaShop psgdpr versions through 1.4.3 fail to validate that
GDPR co ...)
TODO: check
CVE-2026-92808 (A server-side request forgery (SSRF) vulnerability exists in
the Unifi ...)
- TODO: check
+ NOT-FOR-US: Altium
CVE-2026-92806 (phpList versions before 3.6.17 fail to validate cross-site
request for ...)
TODO: check
CVE-2026-92805 (UVdesk Community Skeleton through 1.1.8 fails to authenticate
or valid ...)
@@ -125,21 +125,21 @@ CVE-2026-92596 (Nodemailer before 9.1.0 contains a
quadratic time complexity vul
CVE-2026-92595 (Nodemailer (npm package `nodemailer`) versions 9.1.0 and
earlier do no ...)
TODO: check
CVE-2026-92594 (Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly
authori ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-92593 (Craft CMS versions 5.10.0 through 5.10.12 contain an
incomplete fix fo ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-92592 (Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign
an authe ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-92591 (Craft CMS 5.0.0 through 5.10.12 treats a database connection
failure a ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-92590 (Craft CMS versions from 5.7.0 before 5.10.13 contain a stored
cross-si ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-92589 (Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a
broken a ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-92588 (n8n is a workflow automation platform. In n8n versions before
1.123.76 ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-92587 (n8n is a workflow automation platform. In versions before
1.123.76, 2. ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-92586 (AVideo through 29.0 (commit
c3edcc274c389816d434acadac07ee78eaf330c1) ...)
TODO: check
CVE-2026-92585 (AVideo through 29.0 (commit
c3edcc274c389816d434acadac07ee78eaf330c1) ...)
@@ -165,7 +165,7 @@ CVE-2026-92576 (HKUDS nanobot before 0.3.0 contains a
server-side request forger
CVE-2026-92527 (A vulnerability has been found in chatwoot up to 4.17.1. This
impacts ...)
TODO: check
CVE-2026-92526 (A flaw has been found in itsourcecode Leave Management System
1.0. Thi ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-92475 (A weakness has been identified in GPAC 26.08-DEV. This impacts
the fun ...)
TODO: check
CVE-2026-92474 (A security flaw has been discovered in GPAC 26.08-DEV. This
affects th ...)
@@ -173,93 +173,93 @@ CVE-2026-92474 (A security flaw has been discovered in
GPAC 26.08-DEV. This affe
CVE-2026-92473 (A vulnerability was identified in GPAC 26.08-DEV. The impacted
element ...)
TODO: check
CVE-2026-91019 (The Event Booking Manager for WooCommerce WordPress plugin
before 5.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91017 (The Robokassa payment gateway for Woocommerce WordPress plugin
before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91016 (The Motors WordPress plugin before 1.4.121 does not verify
that a req ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91015 (The Master Addons for Elementor WordPress plugin before 3.1.9
does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91014 (The Realtyna Organic IDX plugin + WPL Real Estate WordPress
plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91011 (The EWWW Image Optimizer WordPress plugin before 8.7.7 does
not proper ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91010 (The Invisible Anti-Spam & CAPTCHA \u2014 reCAPTCHA Alternative
for All ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91009 (The Active Woot Products Tables for WooCommerce. 100% FREE
WordPress p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91008 (The Event Booking Manager for WooCommerce WordPress plugin
before 5.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90982 (@fastify/static is a Fastify plugin that serves static files
from a co ...)
TODO: check
CVE-2026-90923 (The Autopay WordPress plugin before 5.0.1 does not enforce the
signatu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90922 (The Paid Membership Subscriptions WordPress plugin before
3.0.9 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89084 (HP has identified potential security vulnerabilities in the HP
Advance ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-89083 (HP has identified potential security vulnerabilities in the HP
Advance ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-89082 (HP has identified potential security vulnerabilities in the HP
Advance ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-89064 (The All-in-One WP Migration and Backup plugin for WordPress is
vulnera ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89034 (TCH QRing smart ring model R20_B006 running firmware
RT09R20_1.00.00_2 ...)
TODO: check
CVE-2026-88904 (The PuppyFW WordPress plugin through 0.4.4 does not have
proper author ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88795 (The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4
does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88792 (The Dictionary WordPress plugin through 1.0 does not have
authorisatio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88592 (kkFileView >= 4.2.0 is vulnerable to Server-Side Request
Forgery (SSRF ...)
TODO: check
CVE-2026-87976 (Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path
manipula ...)
TODO: check
CVE-2026-87963 (The Yo WordPress plugin from 1.1 through 1.3.1 does not
sanitize or pa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87935 (The Paid Downloads plugin for WordPress is vulnerable to
Arbitrary Fil ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87836 (The Comments Import & Export WordPress plugin before 2.5.4
does not re ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87796 (The Multi Uploader for Gravity Forms plugin for WordPress is
vulnerabl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87786 (The Dewa Kirim WordPress plugin through 1.0.0 does not escape
deliver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87116 (Tanium addressed a server-side request forgery vulnerability
in Threat ...)
- TODO: check
+ NOT-FOR-US: Tanium
CVE-2026-87113 (Tanium addressed an improper access controls vulnerability in
Threat R ...)
- TODO: check
+ NOT-FOR-US: Tanium
CVE-2026-87105 (Tanium addressed a SQL injection vulnerability in Threat
Response.)
- TODO: check
+ NOT-FOR-US: Tanium
CVE-2026-87076 (Tanium addressed an information disclosure vulnerability in
Discover.)
- TODO: check
+ NOT-FOR-US: Tanium
CVE-2026-87026 (Tanium addressed an improper access controls vulnerability in
Threat R ...)
- TODO: check
+ NOT-FOR-US: Tanium
CVE-2026-87024 (Tanium addressed a SQL injection vulnerability in Asset.)
- TODO: check
+ NOT-FOR-US: Tanium
CVE-2026-86865 (Tanium addressed a SQL injection vulnerability in Asset.)
- TODO: check
+ NOT-FOR-US: Tanium
CVE-2026-86831 (Improper validation of pod identifier uniqueness in
aws-network-policy ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-86824 (The Newsletter WordPress plugin before 9.3.8 does not
generate its em ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86801 (The To Do List Member WordPress plugin from 1.4 through 1.6
ships a fi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86788 (The HT Mega Addons for Elementor WordPress plugin before
3.2.6 does n ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86710 (The Login with QR WordPress plugin through 1.0.0 does not
verify that ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86709 (The Pressengine WordPress plugin through 1.0 does not stop its
login h ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86707 (The Private Feed Key WordPress plugin through 0.1 does not
verify that ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86446 (The LearnPress WordPress plugin before 4.4.7 does not
restrict the co ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86311 (The Photo Gallery by 10Web \u2013 Mobile-Friendly Image
Gallery plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86089 (Apache NiFi 2.11.0 supports migrating the contents of a
version-contro ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-86071 (Junrar is an open source Java RAR archive library. Prior to
version 7. ...)
TODO: check
CVE-2026-85789
@@ -267,11 +267,11 @@ CVE-2026-85789
CVE-2026-85469 (A flaw was found in quay-builder-qemu. A remote attacker could
exploit ...)
TODO: check
CVE-2026-85130 (The WPLP Cookie Consent WordPress plugin before 4.4.4 does
not escape ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85128 (The Choose User Role at Registration WordPress plugin before
1.3.3 doe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82561 (Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that
replace ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-81872 (OpenTelemetry-Go is the Go implementation of OpenTelemetry.
Prior to v ...)
TODO: check
CVE-2026-81871 (OpenTelemetry-Go is the Go implementation of OpenTelemetry.
Prior to v ...)
@@ -281,7 +281,7 @@ CVE-2026-81870 (OpenTelemetry-Go is the Go implementation
of OpenTelemetry. From
CVE-2026-81869 (OpenTelemetry-Go is the Go implementation of OpenTelemetry.
From versi ...)
TODO: check
CVE-2026-81866 (Apache NiFi 2.9.0 through 2.11.0 provide Connector
configuration updat ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-81546 (The Affinity by Canva application before 3.3.0 (September 2026
release ...)
TODO: check
CVE-2026-76646 (A remote attacker could cause excessive resource consumption
by supply ...)
@@ -305,7 +305,7 @@ CVE-2026-76444 (A vulnerability in an internal service of
Cisco ISE and Cisco IS
CVE-2026-76439 (A vulnerability in the endpoint posture status reporting
functionality ...)
TODO: check
CVE-2026-76438 (A vulnerability in the web-based management interface of Cisco
BroadWo ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76434 (A vulnerability in the certificate import functionality of the
web-bas ...)
TODO: check
CVE-2026-76433 (A vulnerability in the client provisioning download feature of
Cisco I ...)
@@ -321,9 +321,9 @@ CVE-2026-76427 (A vulnerability in the offline profiler
feed service of Cisco IS
CVE-2026-76426 (A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC
could a ...)
TODO: check
CVE-2026-76425 (A vulnerability in the APIs of Cisco ISE could allow an
authenticated, ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76424 (A vulnerability in the REST API of Cisco ISE could allow an
authentica ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76423 (A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC
could a ...)
TODO: check
CVE-2026-76413 (A vulnerability in Cisco Adaptive Security Device Manager
(ASDM) singl ...)
@@ -331,15 +331,15 @@ CVE-2026-76413 (A vulnerability in Cisco Adaptive
Security Device Manager (ASDM)
CVE-2026-76412 (A vulnerability in the remote diagnostics debugger of Cisco
Secure FMC ...)
TODO: check
CVE-2026-76409 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-75513 (Marten is a .NET Transactional Document DB and Event Store on
PostgreS ...)
TODO: check
CVE-2026-73462 (On affected platforms running Arista EOS with IGMP (Internet
Group Man ...)
- TODO: check
+ NOT-FOR-US: Arista Networks
CVE-2026-70469 (Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP
requests for ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-65388 (A remote attacker who controls a container registry may be
able to dir ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64684 (RMCP is an official Rust SDK for the Model Context Protocol.
Prior to ...)
TODO: check
CVE-2026-63506 (Tina is a headless content management system. Prior to
@tinacms/auth 1 ...)
@@ -369,45 +369,45 @@ CVE-2026-61589 (djust provides Phoenix LiveView-style
reactive server-side rende
CVE-2026-61588 (djust provides Phoenix LiveView-style reactive server-side
rendering f ...)
TODO: check
CVE-2026-50604 (A vulnerability has been identified in the Acer Agent Service
componen ...)
- TODO: check
+ NOT-FOR-US: Acer
CVE-2026-50603 (A vulnerability has been identified in the Acer Agent Service
componen ...)
- TODO: check
+ NOT-FOR-US: Acer
CVE-2026-44940 (The rancher-extension-stackstate extension in SUSE
Observability expos ...)
TODO: check
CVE-2026-25294 (Transient DOS while parsing frame during channel usage.)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25290 (Memory Corruption when validating large data buffers from
external sou ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25284 (Information Disclosure when a pointer is reused after being
deallocate ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25283 (Memory Corruption when copying unverified data from an
external source ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25282 (Transient DOS when processing unverified data from a
neighboring syste ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25281 (Transient DOS when processing large or numerous request
buffers withou ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25280 (Memory corruption when processing escape handling flow with
insufficie ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25278 (Memory Corruption when processing I2C transfer requests due to
a race ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25275 (Transient DOS when processing authentication frames with
invalid FILS ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25261 (Memory corruption while processing rear sensor IOCTL calls.)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-24081 (Transient DOS when processing a channel map with insufficient
used cha ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-24075 (Memory Corruption when multiple threads issue concurrent IOCTL
request ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-24074 (Memory Corruption when processing data with large offset and
length va ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-24073 (Memory corruption when processing decode statistics due to
insufficien ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-20361 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20360 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20352 (A vulnerability in the RADIUS feature of Cisco Identity
Services Engin ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20350 (A vulnerability in the web-based management interface of Cisco
Thousan ...)
TODO: check
CVE-2026-20344 (A vulnerability in the web-based management interface of Cisco
Secure ...)
@@ -435,35 +435,35 @@ CVE-2026-20330 (As part of Cisco's ongoing commitment to
proactive security and
CVE-2026-20329 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
TODO: check
CVE-2026-20326 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20325 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20324 (A vulnerability in the sftunnel inter-device communication
protocol of ...)
TODO: check
CVE-2026-20323 (A vulnerability in the sftunnel inter-device communication
protocol of ...)
TODO: check
CVE-2026-20322 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20309 (A vulnerability in the web-based management interface of Cisco
Identit ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20300 (A vulnerability in Cisco ISE could allow an authenticated,
remote atta ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20295 (A vulnerability in the sftunnel inter-device communication
protocol of ...)
TODO: check
CVE-2026-20290 (A vulnerability in SSL/TLS certificate parsing in the Snort 2
Detectio ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20287 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
TODO: check
CVE-2026-20286 (A vulnerability in the web-based management interface of Cisco
Identif ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20285 (A vulnerability in the web-based management interface of Cisco
Identit ...)
TODO: check
CVE-2026-20284 (A vulnerability in the SXP REST API of Cisco ISE could allow
an authen ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20283 (A vulnerability in the IPsec Open API endpoint of Cisco ISE
could allo ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20282 (A vulnerability in Cisco ISE could allow an authenticated,
remote atta ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20250 (A vulnerability in Datagram TLS (DTLS) message handling of
Cisco Secur ...)
TODO: check
CVE-2026-20249 (A vulnerability in the certification authentication feature of
Interne ...)
@@ -471,27 +471,27 @@ CVE-2026-20249 (A vulnerability in the certification
authentication feature of I
CVE-2026-20248 (A vulnerability in the DNS over TCP implementation of Cisco
Secure Fir ...)
TODO: check
CVE-2026-20247 (A vulnerability in Cisco ISE could allow an unauthenticated,
remote at ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20242 (A vulnerability in the External Database Access feature of
Cisco Secur ...)
TODO: check
CVE-2026-20237 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
TODO: check
CVE-2026-20235 (A vulnerability in the API of Cisco Identity Services Engine
(ISE) cou ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20222 (A vulnerability in the EIGRP implementation in Cisco Secure
Firewall A ...)
TODO: check
CVE-2026-20211 (A vulnerability in Cisco ISE could allow an authenticated,
remote atta ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20194 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
TODO: check
CVE-2026-20192 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
TODO: check
CVE-2026-20176 (A vulnerability in Cisco ISE could allow an authenticated,
remote atta ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20154 (A vulnerability in the system rate-limiting process for syslog
message ...)
TODO: check
CVE-2026-20135 (A vulnerability in the TLS 1.3 implementation in Cisco Secure
Firewall ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20130 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
TODO: check
CVE-2026-20121 (A vulnerability in the access control list (ACL) Object Group
Search ( ...)
@@ -499,19 +499,19 @@ CVE-2026-20121 (A vulnerability in the access control
list (ACL) Object Group Se
CVE-2026-20120 (A vulnerability in the access control list (ACL) Object Group
Search ( ...)
TODO: check
CVE-2026-20072 (A vulnerability in the web-based management interface of Cisco
ISE cou ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20071 (A vulnerability in the SSID bring-your-own-device (BYOD)
onboarding wo ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2025-59607 (Memory Corruption when copying large input data exceeds normal
allocat ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2025-56566 (MikroTik firmware 7.19.4 stores sensitive authentication
credentials a ...)
- TODO: check
+ NOT-FOR-US: MikroTik
CVE-2025-56565 (DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through
v4 hardwa ...)
- TODO: check
+ NOT-FOR-US: TP-Link
CVE-2025-56563 (A Server-Side Request Forgery vulnerability exists in
sat_proxy.php in ...)
TODO: check
CVE-2025-15697 (The Dictionary WordPress plugin through 1.0 does not escape
user input ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-62846 [SQUID-2026:9]
- squid 7.7-1
TODO: check SQUID-2026:9 information not yet public
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac210c5093820990b00a8185d85e794abb279399
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac210c5093820990b00a8185d85e794abb279399
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits