[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 6 20:13:41 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
18943ca6 by security tracker role at 2026-08-06T19:13:34+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,403 @@
+CVE-2026-8166 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-70646 (aiosend is a synchronous and asynchronous Crypto Pay API client. Pror ...)
+ TODO: check
+CVE-2026-70637 (LightFTP through 2.4 contains multiple data race vulnerabilities in ft ...)
+ TODO: check
+CVE-2026-70556 (Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in ...)
+ TODO: check
+CVE-2026-68750 (Inefficient Algorithmic Complexity vulnerability in the traversal engi ...)
+ TODO: check
+CVE-2026-68749 (Inefficient Regular Expression Complexity vulnerability in the CSS scr ...)
+ TODO: check
+CVE-2026-68747 (Improper Neutralization of Special Elements in Output Used by a Downst ...)
+ TODO: check
+CVE-2026-68481 (In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tok ...)
+ TODO: check
+CVE-2026-68079 (In Apache CXF's DefaultEncryptingCodeDataProvider,a captured authoriza ...)
+ TODO: check
+CVE-2026-67261 (Dell Virtual Storage Integrator for VMware vSphere Client, versions pr ...)
+ TODO: check
+CVE-2026-66909 (Apache CXF's JMS transport deserializes the body of any inbound JMS Ob ...)
+ TODO: check
+CVE-2026-66843 (Inclusion of Functionality from Untrusted Control Sphere vulnerability ...)
+ TODO: check
+CVE-2026-66829 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in t ...)
+ TODO: check
+CVE-2026-66733 (Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allo ...)
+ TODO: check
+CVE-2026-66732 (Sonic 3 A.I.R. before commit 2492d18 contains a missing source address ...)
+ TODO: check
+CVE-2026-66712 (Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 ve ...)
+ TODO: check
+CVE-2026-66711 (Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Mu ...)
+ TODO: check
+CVE-2026-66710 (Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.)
+ TODO: check
+CVE-2026-66709 (Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 version ...)
+ TODO: check
+CVE-2026-66708 (Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versio ...)
+ TODO: check
+CVE-2026-66707 (Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce ...)
+ TODO: check
+CVE-2026-66706 (Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 ve ...)
+ TODO: check
+CVE-2026-66705 (Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress < ...)
+ TODO: check
+CVE-2026-66703 (Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versio ...)
+ TODO: check
+CVE-2026-66702 (Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274 ...)
+ TODO: check
+CVE-2026-66701 (Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 ver ...)
+ TODO: check
+CVE-2026-66699 (Custom role Broken Access Control in Dokan <= 5.0.10 versions.)
+ TODO: check
+CVE-2026-66696 (Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blo ...)
+ TODO: check
+CVE-2026-66695 (Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.)
+ TODO: check
+CVE-2026-66694 (Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9 ...)
+ TODO: check
+CVE-2026-66692 (Customer Insecure Direct Object References (IDOR) in Colissimo Officie ...)
+ TODO: check
+CVE-2026-66690 (Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 version ...)
+ TODO: check
+CVE-2026-66688 (Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elemento ...)
+ TODO: check
+CVE-2026-66686 (Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage C ...)
+ TODO: check
+CVE-2026-66685 (Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3. ...)
+ TODO: check
+CVE-2026-66684 (Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9. ...)
+ TODO: check
+CVE-2026-66683 (Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript < ...)
+ TODO: check
+CVE-2026-66681 (Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= ...)
+ TODO: check
+CVE-2026-66678 (Contributor Broken Access Control in Advanced Custom Fields: Font Awes ...)
+ TODO: check
+CVE-2026-66665 (Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.)
+ TODO: check
+CVE-2026-66664 (Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly S ...)
+ TODO: check
+CVE-2026-66663 (Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 ...)
+ TODO: check
+CVE-2026-66662 (Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps < ...)
+ TODO: check
+CVE-2026-66470 (Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3. ...)
+ TODO: check
+CVE-2026-66457 (Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 ...)
+ TODO: check
+CVE-2026-66452 (Unauthenticated Broken Access Control in Legal Text Connector of the I ...)
+ TODO: check
+CVE-2026-66451 (Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 ve ...)
+ TODO: check
+CVE-2026-66447 (Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versio ...)
+ TODO: check
+CVE-2026-66440 (Unauthenticated Cross Site Scripting (XSS) in WPIDE \u2013 File Manage ...)
+ TODO: check
+CVE-2026-66439 (Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Fi ...)
+ TODO: check
+CVE-2026-66425 (Unauthenticated Broken Authentication in Gutena Forms \u2013 Contact F ...)
+ TODO: check
+CVE-2026-66370 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in t ...)
+ TODO: check
+CVE-2026-65583 (Apache CXF\u2019s OIDC relying-party token validation could accept sel ...)
+ TODO: check
+CVE-2026-65581 (Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.)
+ TODO: check
+CVE-2026-65579 (Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.)
+ TODO: check
+CVE-2026-65578 (Unauthenticated PHP Object Injection in Agora <= 1.9 versions.)
+ TODO: check
+CVE-2026-65577 (Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.)
+ TODO: check
+CVE-2026-65576 (Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.)
+ TODO: check
+CVE-2026-65575 (Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.)
+ TODO: check
+CVE-2026-65574 (Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.)
+ TODO: check
+CVE-2026-65573 (Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.)
+ TODO: check
+CVE-2026-65572 (Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.)
+ TODO: check
+CVE-2026-65571 (Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versio ...)
+ TODO: check
+CVE-2026-65570 (Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8 ...)
+ TODO: check
+CVE-2026-65569 (Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.)
+ TODO: check
+CVE-2026-65565 (Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 ...)
+ TODO: check
+CVE-2026-65560 (Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= ...)
+ TODO: check
+CVE-2026-65559 (Shop manager Privilege Escalation in Order Delivery Date for WooCommer ...)
+ TODO: check
+CVE-2026-65556 (Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Sp ...)
+ TODO: check
+CVE-2026-65554 (Subscriber Broken Access Control in AnsPress \u2013 Question and answe ...)
+ TODO: check
+CVE-2026-65553 (Unauthenticated Remote Code Execution (RCE) in Spider Analyser – ...)
+ TODO: check
+CVE-2026-65552 (Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.)
+ TODO: check
+CVE-2026-65551 (Missing Authorization vulnerability in Soflyy Breakdance allows Exploi ...)
+ TODO: check
+CVE-2026-65549 (Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 version ...)
+ TODO: check
+CVE-2026-65548 (Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.)
+ TODO: check
+CVE-2026-65547 (Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.)
+ TODO: check
+CVE-2026-65546 (Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.)
+ TODO: check
+CVE-2026-65545 (Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versi ...)
+ TODO: check
+CVE-2026-65544 (Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14 ...)
+ TODO: check
+CVE-2026-65543 (Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.)
+ TODO: check
+CVE-2026-65542 (Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 ve ...)
+ TODO: check
+CVE-2026-65541 (Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versi ...)
+ TODO: check
+CVE-2026-65523 (Unauthenticated Insecure Direct Object References (IDOR) in Formidable ...)
+ TODO: check
+CVE-2026-65520 (Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.)
+ TODO: check
+CVE-2026-65517 (Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Butt ...)
+ TODO: check
+CVE-2026-65515 (Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 ve ...)
+ TODO: check
+CVE-2026-65513 (Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointm ...)
+ TODO: check
+CVE-2026-65509 (Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 ve ...)
+ TODO: check
+CVE-2026-65508 (Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.1 ...)
+ TODO: check
+CVE-2026-65507 (Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.)
+ TODO: check
+CVE-2026-65504 (Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3 ...)
+ TODO: check
+CVE-2026-65502 (Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons ...)
+ TODO: check
+CVE-2026-65432 (Apache CXF reads a top-level WSDL through its hardened StaxUtilspath, ...)
+ TODO: check
+CVE-2026-64993 (Dell RVTools versions prior to 4.8.1, contains an improper certificate ...)
+ TODO: check
+CVE-2026-64958 (An incomplete fix forCVE-2026-50645 means that it is still possible to ...)
+ TODO: check
+CVE-2026-64640 (Apache Polaris did not consistently validate storage locations supplie ...)
+ TODO: check
+CVE-2026-63687 (Apache CXF's JwtRequestCodeFilter copies all claims from a signed requ ...)
+ TODO: check
+CVE-2026-61982 (Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1 ...)
+ TODO: check
+CVE-2026-61964 (Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 ve ...)
+ TODO: check
+CVE-2026-61963 (Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant ...)
+ TODO: check
+CVE-2026-61961 (Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 vers ...)
+ TODO: check
+CVE-2026-61959 (Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 ...)
+ TODO: check
+CVE-2026-61466 (In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the autho ...)
+ TODO: check
+CVE-2026-5430 (The JWT authentication mechanism accepts tokens signed with algorithms ...)
+ TODO: check
+CVE-2026-5423 (@neo4j/graphqllibrary versions prior to 7.5.6 fail to verify the authe ...)
+ TODO: check
+CVE-2026-5391 (The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site ...)
+ TODO: check
+CVE-2026-5158 (The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites \u20 ...)
+ TODO: check
+CVE-2026-5134 (Improper neutralization of special elements used in an SQL command ('S ...)
+ TODO: check
+CVE-2026-57819 (Apache CXF allows to set a limit on the number of form parameters in a ...)
+ TODO: check
+CVE-2026-57818 (A race condition in JCacheCodeDataProvider allows an attacker to redee ...)
+ TODO: check
+CVE-2026-57817 (The OpenID Connect Core 1.0 specification mandates that the RP MUST va ...)
+ TODO: check
+CVE-2026-55980 (A denial-of-service vulnerability inCatchPulsecould allow an attacker ...)
+ TODO: check
+CVE-2026-55979 (An improper access control check inCatchPulse'snamed pipe communicatio ...)
+ TODO: check
+CVE-2026-55978 (An improper access control vulnerability inCatchPulsecould allow a non ...)
+ TODO: check
+CVE-2026-54489 (Dell Virtual Storage Integrator for VMware vSphere Client, versions pr ...)
+ TODO: check
+CVE-2026-54225 (Apache CXF allows to control the maximum attachment size via the"attac ...)
+ TODO: check
+CVE-2026-53985 (Ground Station prior to 0.6.0contains an unauthenticated denial-of-ser ...)
+ TODO: check
+CVE-2026-53977 (OpenChamber 1.11.7 contains an authentication bypass vulnerability tha ...)
+ TODO: check
+CVE-2026-53976 (OpenChamber 1.11.7 contains a path traversal vulnerability in the file ...)
+ TODO: check
+CVE-2026-53975 (OpenChamber 1.11.7 contains an unauthenticated remote code execution v ...)
+ TODO: check
+CVE-2026-43622 (llama.cpp builds b1886 through b7445 contain a double free vulnerabili ...)
+ TODO: check
+CVE-2026-3430 (The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not saniti ...)
+ TODO: check
+CVE-2026-34502 (Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ...)
+ TODO: check
+CVE-2026-34501 (Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ...)
+ TODO: check
+CVE-2026-34191 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
+ TODO: check
+CVE-2026-32548 (Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.)
+ TODO: check
+CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.)
+ TODO: check
+CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ...)
+ TODO: check
+CVE-2026-28183 (Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 ver ...)
+ TODO: check
+CVE-2026-28180 (Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pa ...)
+ TODO: check
+CVE-2026-28179 (Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versio ...)
+ TODO: check
+CVE-2026-28178 (Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.)
+ TODO: check
+CVE-2026-28177 (Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 ve ...)
+ TODO: check
+CVE-2026-28172 (Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Man ...)
+ TODO: check
+CVE-2026-28169 (Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magni ...)
+ TODO: check
+CVE-2026-28146 (Contributor Arbitrary File Download in Unlimited Elements For Elemento ...)
+ TODO: check
+CVE-2026-28143 (Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 ver ...)
+ TODO: check
+CVE-2026-28141 (Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 ...)
+ TODO: check
+CVE-2026-28140 (Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 ver ...)
+ TODO: check
+CVE-2026-28139 (Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 ver ...)
+ TODO: check
+CVE-2026-28111 (Contributor Privilege Escalation in Forminator <= 1.56.0 versions.)
+ TODO: check
+CVE-2026-28082 (Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 ve ...)
+ TODO: check
+CVE-2026-28005 (Unauthenticated Privilege Escalation in Kadence WooCommerce Email Desi ...)
+ TODO: check
+CVE-2026-25403 (Unauthenticated Broken Access Control in Ultimate Store Kit Elementor ...)
+ TODO: check
+CVE-2026-1728 (Tokens issued to a low-privileged user are not sufficiently restricted ...)
+ TODO: check
+CVE-2026-19047 (A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. T ...)
+ TODO: check
+CVE-2026-19046 (A security vulnerability has been detected in NocteDefensor LudusMCP u ...)
+ TODO: check
+CVE-2026-19045 (A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. ...)
+ TODO: check
+CVE-2026-19044 (A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this ...)
+ TODO: check
+CVE-2026-19041 (A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. T ...)
+ TODO: check
+CVE-2026-19040 (A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affect ...)
+ TODO: check
+CVE-2026-19039 (A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8 ...)
+ TODO: check
+CVE-2026-19038 (A security vulnerability has been detected in MonomythDevelopment la-f ...)
+ TODO: check
+CVE-2026-19037 (A weakness has been identified in WonderTrader up to 0.9.9. This vulne ...)
+ TODO: check
+CVE-2026-19036 (A security flaw has been discovered in Shibby Tomato 1.28.0000. This a ...)
+ TODO: check
+CVE-2026-19035 (A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by ...)
+ TODO: check
+CVE-2026-19034 (A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by ...)
+ TODO: check
+CVE-2026-19022 (A vulnerability was determined in OpenHands up to 0.62.0. The affected ...)
+ TODO: check
+CVE-2026-19021 (A security vulnerability has been detected in SourceCodester Computer ...)
+ TODO: check
+CVE-2026-19020 (A weakness has been identified in itsourcecode Hospital Management Sys ...)
+ TODO: check
+CVE-2026-19019 (A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. ...)
+ TODO: check
+CVE-2026-19011 (A vulnerability was detected in TinyAGI 0.0.20. The affected element i ...)
+ TODO: check
+CVE-2026-19010 (A security vulnerability has been detected in TinyAGI 0.0.20. Impacted ...)
+ TODO: check
+CVE-2026-19009 (A weakness has been identified in TinyAGI 0.0.20. This issue affects t ...)
+ TODO: check
+CVE-2026-19008 (A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. Thi ...)
+ TODO: check
+CVE-2026-18915 (Invocation of process using visible sensitive information vulnerabilit ...)
+ TODO: check
+CVE-2026-18649 (A flaw was found in the GStreamer gst-plugins-good package. The rtph26 ...)
+ TODO: check
+CVE-2026-18597 (The PDF creation feature of Foxit PDF Services API supports referencin ...)
+ TODO: check
+CVE-2026-18501 (The UsersWP \u2013 Front-end login form, User Registration, User Profi ...)
+ TODO: check
+CVE-2026-18427 (@fastify/static before version 10.1.3 contains an incomplete fix for a ...)
+ TODO: check
+CVE-2026-18359 (Server-side request forgery in the METS and IIIF import URI handling i ...)
+ TODO: check
+CVE-2026-18277 (Missing authorization in the OcrModelRight create and delete views in ...)
+ TODO: check
+CVE-2026-18276 (Missing authorization in the websocket consumer in Scripta eScriptoriu ...)
+ TODO: check
+CVE-2026-18275 (Authorization bypass in the process and annotation taxonomy serializer ...)
+ TODO: check
+CVE-2026-18258 (Authorization bypass in the Line, LineTranscription, VirtualCollection ...)
+ TODO: check
+CVE-2026-16731 (OMICRON StationScout before version 3.05 contains a cryptographic timi ...)
+ TODO: check
+CVE-2026-16316 (OMICRON StationGuard 4.00 contains an improper input validation vulner ...)
+ TODO: check
+CVE-2026-16315 (OMICRON StationGuard before version 4.10 contains a cryptographic timi ...)
+ TODO: check
+CVE-2026-15599 (Unverified ownership vulnerability in T\xdcB\u0130TAK B\u0130LGEM Soft ...)
+ TODO: check
+CVE-2026-15246 (The RealHomes Memberships WordPress plugin before 3.1.0 does not verif ...)
+ TODO: check
+CVE-2026-12605 (In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in Downl ...)
+ TODO: check
+CVE-2026-11983 (The Ad Inserter \u2013 Ad Manager & AdSense Ads plugin for WordPress i ...)
+ TODO: check
+CVE-2026-0673 (The Element Pack Addons for Elementor plugin for WordPress is vulnerab ...)
+ TODO: check
+CVE-2026-0637 (When an Event Publisher output adapter is configured with irrelevant p ...)
+ TODO: check
+CVE-2025-9266 (The Accelerate theme for WordPress is vulnerable to unauthorized modif ...)
+ TODO: check
+CVE-2025-49506 (APR-util versions 1.6.3 (and earlier) function apr_password_validate() ...)
+ TODO: check
+CVE-2025-15039 (The Conditional Authentication (Adaptive Authentication) script does n ...)
+ TODO: check
+CVE-2025-15028 (The FormGent \u2013 Next-Gen AI Form Builder for WordPress with Multi- ...)
+ TODO: check
+CVE-2025-14779 (The Secret Type Management REST API does not correctly isolate access ...)
+ TODO: check
+CVE-2025-13909 (The system accepts authentication requests without sufficient validati ...)
+ TODO: check
+CVE-2025-13736 (When Multi-Attribute Login is enabled, the login interface fails to co ...)
+ TODO: check
+CVE-2025-13394 (The Ajax processor within the Carbon console fails to adequately prote ...)
+ TODO: check
+CVE-2025-12627 (The user impersonation flow in WSO2 Identity Server fails to properly ...)
+ TODO: check
+CVE-2025-11850 (When secondary user stores are configured, the implicit-association re ...)
+ TODO: check
+CVE-2024-8995 (Unused authorization codes issued to deleted users are not being prope ...)
+ TODO: check
+CVE-2024-6832 (The account locking mechanism fails to trigger when secondary user sto ...)
+ TODO: check
+CVE-2024-10302 (The user self-signup flow in multiple WSO2 products fails to adequatel ...)
+ TODO: check
+CVE-2023-7355
+ REJECTED
+CVE-2023-7354
+ REJECTED
+CVE-2023-7353
+ REJECTED
CVE-2026-68480 [x86/bugs: Make Safe-RET robust against interrupt injection]
- linux <unfixed>
CVE-2026-52682 [A crafted DNS packet can cause increased memory and CPU consumption]
@@ -7,125 +407,124 @@ CVE-2026-52682 [A crafted DNS packet can cause increased memory and CPU consumpt
- pdns-recursor <unfixed>
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
[bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
- - pdns <unfixed>
- [bookworm] - pdns <end-of-life> (See #1119290)
- [bullseye] - pdns <end-of-life> (see DLA 4471)
- dnsdist <unfixed>
[bookworm] - dnsdist <end-of-life> (See #1119290)
[bullseye] - dnsdist <end-of-life> (see #1119290)
NOTE: https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-11.html
-CVE-2026-64604 [KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode]
+CVE-2026-64604 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/7ef78d71ca713d8c00f7c34ddcf276c808143f77 (7.2-rc1)
-CVE-2026-64603 [platform/x86: intel-hid: Protect ACPI notify handler against recursion]
+CVE-2026-64603 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c085d82613d5618814b84406c8b2d64f1bc305e7 (7.2-rc1)
-CVE-2026-64602 [iio: adc: spear: Initialize completion before requesting IRQ]
+CVE-2026-64602 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0 (7.2-rc3)
-CVE-2026-64601 [ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission]
+CVE-2026-64601 (In the Linux kernel, the following vulnerability has been resolved: A ...)
- linux 7.1.4-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/5cff1529a2f9b3461a7f5a6e36a86682fc290534 (7.2-rc2)
-CVE-2026-64599 [crypto: amlogic - avoid double cleanup in meson_crypto_probe()]
+CVE-2026-64599 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/6d827ade51a24e18d81afb9f32756d339520a14c (7.2-rc1)
-CVE-2026-64598 [smb/client: Fix error code in smb2_aead_req_alloc()]
+CVE-2026-64598 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/61f28012e5650c619223decdb7970e0d3162e949 (7.2-rc1)
-CVE-2026-64597 [smb: client: fix double-free in SMB2_close() replay]
+CVE-2026-64597 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f96e1cdcb63ed3321142ff2fcdf784e32cda8fee (7.2-rc1)
-CVE-2026-64596 [libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()]
+CVE-2026-64596 (In the Linux kernel, the following vulnerability has been resolved: l ...)
- linux 7.1.4-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/6de2aeffabaafaeda819e60ec8d04f199711e11a (7.2-rc1)
-CVE-2026-64595 [HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()]
+CVE-2026-64595 (In the Linux kernel, the following vulnerability has been resolved: H ...)
- linux 7.1.4-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/73fde0cbff7d9d618591774a12c23434232752c1 (7.2-rc1)
-CVE-2026-64594 [usb: gadget: f_fs: initialize reset_work at allocation time]
+CVE-2026-64594 (In the Linux kernel, the following vulnerability has been resolved: u ...)
- linux 7.1.4-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/3137b243c93982fe3460335e12f9247739766e10 (7.2-rc3)
-CVE-2026-64593 [btrfs: do not trim a device which is not writeable]
+CVE-2026-64593 (In the Linux kernel, the following vulnerability has been resolved: b ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
[bookworm] - linux 6.1.180-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/1b1937eb08f51319bf71575484cde2b8c517aedc (7.2-rc1)
-CVE-2026-64592 [riscv: mm: Unconditionally sfence.vma for spurious fault]
+CVE-2026-64592 (In the Linux kernel, the following vulnerability has been resolved: r ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/1b2c6b56a9fa0dcbef461039937de22b1cbecc7d (7.2-rc1)
-CVE-2026-64591 [iommu/vt-d: Avoid WARNING in sva unbind path]
+CVE-2026-64591 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.4-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/534b5f98ab7319d8004bbc7dab6481462243e883 (7.2-rc1)
-CVE-2026-64589 [i2c: core: fix NULL-deref on adapter registration failure]
+CVE-2026-64589 (In the Linux kernel, the following vulnerability has been resolved: i ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/2295d2bb101faa663fbc45fadbb3fec45f107441 (7.2-rc1)
-CVE-2026-64588 [fuse-uring: fix data races on ring->ready]
+CVE-2026-64588 (In the Linux kernel, the following vulnerability has been resolved: f ...)
- linux 7.1.4-1
[trixie] - linux <not-affected> (Vulnerable code not present)
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/46725a0056c884cf58a6897f222892807327d82d (7.2-rc1)
-CVE-2026-64590 [dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning]
+CVE-2026-64590 (In the Linux kernel, the following vulnerability has been resolved: d ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/504e2b4ab97a51d56d966cd36d0997ad30b65b2d (7.2-rc1)
-CVE-2026-64587 [net: ethernet: arc: emac: quiesce interrupts before requesting IRQ]
+CVE-2026-64587 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 6.19.10-1
[trixie] - linux 6.12.85-1
[bookworm] - linux 6.1.170-1
[bullseye] - linux 5.10.257-1
NOTE: https://git.kernel.org/linus/2503d08f8a2de618e5c3a8183b250ff4a2e2d52c (7.0-rc4)
-CVE-2026-64586 [wifi: brcmfmac: drain bus_reset work on device removal]
+CVE-2026-64586 (In the Linux kernel, the following vulnerability has been resolved: w ...)
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/43b25879f004c98defa2776bedc6ca4763c51945 (7.2-rc5)
-CVE-2026-64585 [can: esd_usb: kill anchored URBs before freeing netdevs]
+CVE-2026-64585 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.5-1
[trixie] - linux 6.12.100-1
[bookworm] - linux 6.1.180-1
NOTE: https://git.kernel.org/linus/c43122fef328a70045fe7621c06de6b2b8e19264 (7.2-rc4)
-CVE-2026-64584 [usb: gadget: f_midi: cancel pending IN work before freeing the midi object]
+CVE-2026-64584 (In the Linux kernel, the following vulnerability has been resolved: u ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/5650c18d93a1db7e27cb5a40b394747eb4686d5b (7.2-rc5)
-CVE-2026-64583 [usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown]
+CVE-2026-64583 (In the Linux kernel, the following vulnerability has been resolved: u ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb (7.2-rc5)
CVE-2026-71321 (Nuxt is an open-source web development framework for Vue.js. From 3.1. ...)
@@ -439,6 +838,7 @@ CVE-2026-8029 (The ZTE Smart Life app contains an SQL injection vulnerability th
CVE-2026-7869 (IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal ...)
NOT-FOR-US: IBM
CVE-2026-7867 [Local privilege escalation via as-user mount spoofing]
+ {DSA-6414-1}
- udisks2 2.11.2-1
[bookworm] - udisks2 <not-affected> (udisks2 versions < 2.10.x are not affected)
[bullseye] - udisks2 <not-affected> (udisks2 versions < 2.10.x are not affected)
@@ -992,52 +1392,65 @@ CVE-2026-64581 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/c283e9ada7fcb7dd4b10592623086b2e6d2f9925 (7.2-rc4)
CVE-2026-64580 (In the Linux kernel, the following vulnerability has been resolved: x ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/136992de9bb91871084ae52d172610541c76e4d2 (7.2-rc4)
CVE-2026-64579 (In the Linux kernel, the following vulnerability has been resolved: x ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4 (7.2-rc4)
CVE-2026-64578 (In the Linux kernel, the following vulnerability has been resolved: k ...)
+ {DSA-6415-1}
- linux 7.1.6-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/15b38176fd1530372905c602fde51fe89ec8c877 (7.2-rc4)
CVE-2026-64577 (In the Linux kernel, the following vulnerability has been resolved: g ...)
+ {DSA-6415-1}
- linux 7.1.6-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/cd170f051dba9ac146fabcd1b91726487c0cb9fa (7.2-rc5)
CVE-2026-64576 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6415-1}
- linux 7.1.6-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/6347c5314cee49f364aaf2e40ff15415a57a116e (7.2-rc5)
CVE-2026-64574 (In the Linux kernel, the following vulnerability has been resolved: w ...)
+ {DSA-6415-1}
- linux 7.1.6-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/952c02b33f56207a160421bcd61e7ac53c9c59ae (7.2-rc5)
CVE-2026-64573 (In the Linux kernel, the following vulnerability has been resolved: B ...)
+ {DSA-6415-1}
- linux 7.1.6-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c90164ca0f7036942ba088eb7ea8d3f6c2352020 (7.2-rc4)
CVE-2026-64572 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/f2f152e94a67bc746afaf05a1b2702c195553112 (7.2-rc4)
CVE-2026-64571 (In the Linux kernel, the following vulnerability has been resolved: w ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea (7.2-rc4)
CVE-2026-64570 (In the Linux kernel, the following vulnerability has been resolved: w ...)
+ {DSA-6415-1}
- linux 7.1.6-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/286e52a799fa158bdbd77da1426c4d93f9a6e7ad (7.2-rc4)
CVE-2026-64569 (In the Linux kernel, the following vulnerability has been resolved: m ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/56d96fededd61192cd7cc8d2b0f36adfd59036c3 (7.2-rc4)
CVE-2026-64568 (In the Linux kernel, the following vulnerability has been resolved: w ...)
+ {DSA-6415-1}
- linux 7.1.6-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/1d067abcd37062426c59ec73dbc4e87a63f33fea (7.2-rc4)
CVE-2026-64567 (In the Linux kernel, the following vulnerability has been resolved: b ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/a2d8d5647ed854e38f941741aea45b9eb15a6350 (7.2-rc4)
CVE-2026-9273 (The Membership Plugin \u2013 Kadence Memberships plugin for WordPress ...)
@@ -1822,19 +2235,24 @@ CVE-2026-65804 (Improper control of generation of code ('code injection') in Mic
CVE-2026-65802 (External control of file name or path in Microsoft Edge for Android al ...)
NOT-FOR-US: Microsoft
CVE-2026-64565 (In the Linux kernel, the following vulnerability has been resolved: I ...)
+ {DSA-6415-1}
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/875115b82c295277b81b6dfee7debc725f44e854 (7.1-rc1)
CVE-2026-64564 (In the Linux kernel, the following vulnerability has been resolved: s ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f (7.2-rc5)
NOTE: https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
CVE-2026-64563 (In the Linux kernel, the following vulnerability has been resolved: r ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/8173f7e2ce67e6ca1d4763f3da14e5b01ce77456 (7.2-rc5)
CVE-2026-64562 (In the Linux kernel, the following vulnerability has been resolved: K ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/622ebfac01ba4f9c0060cebd41257fe46fc4a0b3 (7.2-rc5)
CVE-2026-64561 (In the Linux kernel, the following vulnerability has been resolved: K ...)
+ {DSA-6415-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/2abd5287f08319fa35764566b15c6e22cb1068db (7.2-rc5)
NOTE: https://github.com/V4bel/Zapscape
@@ -6291,7 +6709,8 @@ CVE-2026-52791 (fuse-overlayfs is an implementation of overlayfs in FUSE for roo
- fuse-overlayfs <unfixed> (bug #1143058)
NOTE: https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h
NOTE: Fixed by: https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad724f (v1.17)
-CVE-2026-51992 (SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 ...)
+CVE-2026-51992
+ REJECTED
NOT-FOR-US: ClickHouse Server
CVE-2026-50642 (diff\u2011so\u2011fancy does not properly sanitize non\u2011SGR termin ...)
NOT-FOR-US: diff-so-fancy
@@ -9739,6 +10158,7 @@ CVE-2026-64294 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e187bc02f8fa4226d62814592cf064ee4557c470 (7.2-rc3)
CVE-2026-64290 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6415-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -9761,6 +10181,7 @@ CVE-2026-64283 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/eba85fee7fc6cf28fec38a5bf3c378bef9a79ca6 (7.2-rc1)
CVE-2026-64280 (In the Linux kernel, the following vulnerability has been resolved: f ...)
+ {DSA-6415-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27 (7.2-rc1)
CVE-2026-64279 (In the Linux kernel, the following vulnerability has been resolved: i ...)
@@ -10926,7 +11347,7 @@ CVE-2026-65461 (Administrator Arbitrary File Upload in Really Simple CSV Importe
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65460 (Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-65458 (Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.)
+CVE-2026-65458 (Exposure of Sensitive System Information to an Unauthorized Control Sp ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65457 (Subscriber Broken Access Control in \u042eKassa \u0434\u043b\u044f Woo ...)
NOT-FOR-US: WordPress plugin or theme
@@ -11203,7 +11624,7 @@ CVE-2026-24639 (Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.
NOT-FOR-US: WordPress plugin or theme
CVE-2026-24628 (Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-24552 (Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.)
+CVE-2026-24552 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility ...)
NOT-FOR-US: WordPress plugin or theme
@@ -15850,6 +16271,7 @@ CVE-2026-64206 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/2641a9e0a1dd4af2e21995470a21d55dd35e5203 (7.2-rc3)
CVE-2026-64205 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6415-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -29034,6 +29456,7 @@ CVE-2026-55791 (Craft CMS is a content management system (CMS). Versions 4.0.0-R
CVE-2026-55790 (Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55688 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
+ {DLA-4721-1}
- async-http-client <unfixed> (bug #1141445)
NOTE: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f
NOTE: https://github.com/AsyncHttpClient/async-http-client/pull/2196
@@ -29970,17 +30393,21 @@ CVE-2026-53327 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/5f41161059fd0f1bbf18c90f3180e38cc45a14eb (7.1-rc5)
CVE-2026-45382 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
+ {DSA-6413-1}
- libde265 1.1.1-1
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-hwhx-x2mq-ccr9
NOTE: https://github.com/strukturag/libde265/commit/c33b4f63ae9056b00f34a31874fed55cd0aa29c9 (v1.0.19)
CVE-2026-45383 (libde265 is an open source implementation of the h.265 video codec. Ve ...)
+ {DSA-6413-1}
- libde265 1.1.1-1
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-wg9q-ppqw-6q38
CVE-2026-54241
+ {DSA-6413-1}
- libde265 1.1.1-1
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-j2qq-x2xq-g9wr
NOTE: https://github.com/strukturag/libde265/commit/bdca87569b9c63c2a7054d90ae4462dbb78d159a (v1.1.1)
CVE-2026-54240
+ {DSA-6413-1}
- libde265 1.1.1-1
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-ccfw-29x7-rrx3
NOTE: https://github.com/strukturag/libde265/commit/bdca87569b9c63c2a7054d90ae4462dbb78d159a (v1.1.1)
@@ -37355,6 +37782,7 @@ CVE-2026-53091 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.0.10-1
NOTE: https://git.kernel.org/linus/7fb4c19670110f052c04e1ec1d2b953b9f4f57e4 (7.1-rc1)
CVE-2026-53090 (In the Linux kernel, the following vulnerability has been resolved: b ...)
+ {DSA-6415-1}
- linux 7.0.10-1
NOTE: https://git.kernel.org/linus/ee861486e377edc55361c08dcbceab3f6b6577bd (7.1-rc1)
CVE-2026-53089 (In the Linux kernel, the following vulnerability has been resolved: b ...)
@@ -37385,6 +37813,7 @@ CVE-2026-53080 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.94-1
NOTE: https://git.kernel.org/linus/65782b2db7321d5f97c16718c4c7f6c7205a56be (7.1-rc1)
CVE-2026-53078 (In the Linux kernel, the following vulnerability has been resolved: b ...)
+ {DSA-6415-1}
- linux 7.0.10-1
NOTE: https://git.kernel.org/linus/10f86a2a5c91fc4c4d001960f1c21abe52545ef6 (7.1-rc1)
CVE-2026-53077 (In the Linux kernel, the following vulnerability has been resolved: n ...)
@@ -40014,6 +40443,7 @@ CVE-2026-50559 (Quarkus is a Java framework for building cloud-native applicatio
CVE-2026-50519 (Initialization of a resource with an insecure default in GitHub Copilo ...)
NOT-FOR-US: Microsoft
CVE-2026-49346 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
+ {DSA-6413-1}
- libde265 1.1.1-1 (bug #1140431)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-vv8h-932h-7r86
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8 (v1.1.0)
@@ -40033,10 +40463,12 @@ CVE-2026-49340 (gonic is a music streaming server / free-software subsonic serve
CVE-2026-49338 (gonic is a music streaming server / free-software subsonic server API ...)
NOT-FOR-US: gonic music streaming server
CVE-2026-49337 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
+ {DSA-6413-1}
- libde265 1.1.1-1 (bug #1140431)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-g5hj-rf9f-7vxm
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/683cb9fa603e35840642f98765ab95cdb71cadf9 (v1.1.0)
CVE-2026-49295 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
+ {DSA-6413-1}
- libde265 1.1.1-1 (bug #1140431)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-g2rg-wj66-w594
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/691f3a3c55b3d32478c4a49895dee061a282652 (v1.1.0)
@@ -58835,6 +59267,7 @@ CVE-2026-45904 (In the Linux kernel, the following vulnerability has been resolv
[bookworm] - linux 6.1.170-1
NOTE: https://git.kernel.org/linus/815a8d2feb5615ae7f0b5befd206af0b0160614c (7.0-rc1)
CVE-2026-45901 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6415-1}
- linux 6.19.6-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/7f261bb906bf527c4a6e2a646e2d5f3679f2a8bc (7.0-rc1)
@@ -58844,6 +59277,7 @@ CVE-2026-45899 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.85-1
NOTE: https://git.kernel.org/linus/79b592e8f1b435796cbc2722190368e3e8ffd7a1 (7.0-rc1)
CVE-2026-45897 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6415-1}
- linux 6.19.6-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/779c60a5190c42689534172f4b49e927c9959e4e (7.0-rc1)
@@ -111133,6 +111567,7 @@ CVE-2025-63946 (A privilege escalation (PE) vulnerability in the Tencent PC Mana
CVE-2025-63945 (A privilege escalation (PE) vulnerability in the Tencent iOA app thru ...)
NOT-FOR-US: Tencent iOA app
CVE-2025-61147 (strukturag libde265 commit d9fea9d wa discovered to contain a segmenta ...)
+ {DSA-6413-1}
- libde265 1.0.18-1 (bug #1129257; unimportant)
NOTE: https://github.com/strukturag/libde265/issues/484
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/8b17e0930f77db07f55e0b89399a8f054ddbecf7
@@ -156557,6 +156992,7 @@ CVE-2025-40099 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.57-1
NOTE: https://git.kernel.org/linus/6447b0e355562a1ff748c4a2ffb89aae7e84d2c9 (6.18-rc2)
CVE-2025-40098 (In the Linux kernel, the following vulnerability has been resolved: A ...)
+ {DSA-6415-1}
- linux 6.17.6-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -164903,7 +165339,7 @@ CVE-2025-43824 (The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, an
NOT-FOR-US: Liferay
CVE-2025-34251 (Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contain ...)
NOT-FOR-US: Tesla
-CVE-2025-11362 (Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to ...)
+CVE-2025-11362 (Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-bet ...)
NOT-FOR-US: pdfmake
CVE-2025-11358 (A weakness has been identified in code-projects Simple Banking System ...)
NOT-FOR-US: code-projects
@@ -307037,12 +307473,14 @@ CVE-2024-39242 (A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allo
CVE-2024-39241 (Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attack ...)
NOT-FOR-US: skycaiji
CVE-2024-38950 (Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attacker ...)
+ {DSA-6413-1}
- libde265 1.1.1-1 (bug #1074416)
[bookworm] - libde265 <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - libde265 <no-dsa> (Minor issue)
NOTE: https://github.com/strukturag/libde265/issues/460
NOTE: https://github.com/strukturag/libde265/commit/4089de0845e0009e019be4ca5cbebaf2aee0a8ce (v1.0.19)
CVE-2024-38949 (Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attacker ...)
+ {DSA-6413-1}
- libde265 1.1.1-1 (bug #1074416)
[bookworm] - libde265 <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - libde265 <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18943ca683b5e42e1f6ae9a3ab048e44bd1a4bf5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18943ca683b5e42e1f6ae9a3ab048e44bd1a4bf5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/6eabf0ff/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list