[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 8 08:13:56 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e41f5938 by security tracker role at 2026-08-08T07:13:50+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,8 +1,170 @@
+CVE-2026-9031 (An input validation vulnerability exists in the HTTP-WRITEOEM handler ...)
+ TODO: check
+CVE-2026-9030 (A denial-of-service vulnerability exists in httpd service on Archer A6 ...)
+ TODO: check
+CVE-2026-8798 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the nati ...)
+ TODO: check
+CVE-2026-71381 (Adobe Genuine Software Integrity Service was affected by an Incorrect ...)
+ TODO: check
+CVE-2026-70624
+ REJECTED
+CVE-2026-70623
+ REJECTED
+CVE-2026-69207 (Hono is a Web application framework that provides support for any Java ...)
+ TODO: check
+CVE-2026-66151 (SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnera ...)
+ TODO: check
+CVE-2026-66061 (Home Assistant is open source home automation software focused on loca ...)
+ TODO: check
+CVE-2026-66060 (Home Assistant is open source home automation software focused on loca ...)
+ TODO: check
+CVE-2026-65819 (gopacket provides packet processing capabilities for Go. Through versi ...)
+ TODO: check
+CVE-2026-64676 (Kata Containers is an open source implementation of lightweight Virtua ...)
+ TODO: check
+CVE-2026-62296 (HAPI FHIR is a complete implementation of the HL7 FHIR standard for he ...)
+ TODO: check
+CVE-2026-62295 (HAPI FHIR is a complete implementation of the HL7 FHIR standard for he ...)
+ TODO: check
+CVE-2026-62293 (HAPI FHIR is a complete implementation of the HL7 FHIR standard for he ...)
+ TODO: check
+CVE-2026-61808 (LightRAG provides simple and fast retrieval-augmented generation. Thro ...)
+ TODO: check
+CVE-2026-59717 (Home Assistant is open source home automation software focused on loca ...)
+ TODO: check
+CVE-2026-58262 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-54338 (JupyterHub is software that allows users to create a multi-user server ...)
+ TODO: check
+CVE-2026-52880 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-52879 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-52878 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-49343 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-48170 (`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 ...)
+ TODO: check
+CVE-2026-48169 (PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of th ...)
+ TODO: check
+CVE-2026-48122 (Ruby LSP is an implementation of the language server protocol for Ruby ...)
+ TODO: check
+CVE-2026-48120 (Kakoune is a code editor. Prior to version 2026.05.21, the bundled, en ...)
+ TODO: check
+CVE-2026-48047 (XWiki Platform WebJars API is a package for XWiki, a generic wiki plat ...)
+ TODO: check
+CVE-2026-48039 (Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI ass ...)
+ TODO: check
+CVE-2026-48026 (lakeFS is an open-source tool that transforms object storage into a Gi ...)
+ TODO: check
+CVE-2026-48007 (Element Call is a native Matrix video conferencing application. Versio ...)
+ TODO: check
+CVE-2026-47664 (Pathling is a set of tools that make it easier to use FHIR and clinica ...)
+ TODO: check
+CVE-2026-47663 (Pathling is a set of tools that make it easier to use FHIR and clinica ...)
+ TODO: check
+CVE-2026-47662 (Pathling is a set of tools that make it easier to use FHIR and clinica ...)
+ TODO: check
+CVE-2026-47661 (Pathling is a set of tools that make it easier to use FHIR and clinica ...)
+ TODO: check
+CVE-2026-47660 (Pathling is a set of tools that make it easier to use FHIR and clinica ...)
+ TODO: check
+CVE-2026-47659 (Pathling is a set of tools that make it easier to use FHIR and clinica ...)
+ TODO: check
+CVE-2026-47249 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-47127 (Ghostfolio is an open source wealth management software. Prior to vers ...)
+ TODO: check
+CVE-2026-46409 (OpenYak is a local-first agent runtime for reliable tool-using models, ...)
+ TODO: check
+CVE-2026-46405 (OpenBao is an open source identity-based secrets management system. Pr ...)
+ TODO: check
+CVE-2026-46358 (OpenBao is an open source identity-based secrets management system. Pr ...)
+ TODO: check
+CVE-2026-45808 (OpenBao is an open source identity-based secrets management system. Pr ...)
+ TODO: check
+CVE-2026-19263 (A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1 ...)
+ TODO: check
+CVE-2026-19259 (A vulnerability has been found in MZ Automation libiec61850 up to 1.6. ...)
+ TODO: check
+CVE-2026-19246 (A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affe ...)
+ TODO: check
+CVE-2026-19245 (A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted eleme ...)
+ TODO: check
+CVE-2026-19244 (A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affecte ...)
+ TODO: check
+CVE-2026-19243 (A security vulnerability has been detected in HKUDS nanobot up to 0.2. ...)
+ TODO: check
+CVE-2026-19113 (Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are ...)
+ TODO: check
+CVE-2026-19017 (Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 a ...)
+ TODO: check
+CVE-2026-19016 (Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 di ...)
+ TODO: check
+CVE-2026-19015 (Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are ...)
+ TODO: check
+CVE-2026-19014 (Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 ar ...)
+ TODO: check
+CVE-2026-19012 (Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 ar ...)
+ TODO: check
+CVE-2026-18988 (The Easy Accordion plugin for WordPress is vulnerable to Stored Cross- ...)
+ TODO: check
+CVE-2026-16955 (The AI Engine WordPress plugin before 3.6.6 does not confine a caller ...)
+ TODO: check
+CVE-2026-16953 (The AI Engine WordPress plugin before 3.6.4 does not verify ownership ...)
+ TODO: check
+CVE-2026-16948 (The Solace Extra WordPress plugin before 1.6.1 does not perform capabi ...)
+ TODO: check
+CVE-2026-16608 (The Download Monitor WordPress plugin before 5.2.6 does not perform au ...)
+ TODO: check
+CVE-2026-16595 (The WP Directory Kit WordPress plugin before 1.5.5 does not perform au ...)
+ TODO: check
+CVE-2026-16594 (The WP Directory Kit WordPress plugin before 1.5.5 does not perform au ...)
+ TODO: check
+CVE-2026-16590 (The WP Directory Kit WordPress plugin before 1.5.5 does not perform au ...)
+ TODO: check
+CVE-2026-16589 (The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize a ...)
+ TODO: check
+CVE-2026-16578 (The Admin Safety Guard \u2014 Login Security, Limit Logins, 2FA & Brut ...)
+ TODO: check
+CVE-2026-16574 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Wo ...)
+ TODO: check
+CVE-2026-16562 (The WP Statistics WordPress plugin before 14.16.10 does not perform a ...)
+ TODO: check
+CVE-2026-16559 (The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG fi ...)
+ TODO: check
+CVE-2026-16558 (The YMC Filter WordPress plugin before 3.12.8 does not sanitize and es ...)
+ TODO: check
+CVE-2026-16535 (The Link Library WordPress plugin before 7.9.4 does not sanitise and e ...)
+ TODO: check
+CVE-2026-16282 (The Appointment Hour Booking WordPress plugin before 1.5.88 does not ...)
+ TODO: check
+CVE-2026-16269 (The Newsletters WordPress plugin before 4.16 does not strictly compare ...)
+ TODO: check
+CVE-2026-16267 (The Newsletters WordPress plugin before 4.16 does not restrict the cla ...)
+ TODO: check
+CVE-2026-15972 (Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 ar ...)
+ TODO: check
+CVE-2026-15970 (Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 ar ...)
+ TODO: check
+CVE-2026-14526 (The AI Copilot \u2013 Content Generator plugin for WordPress is vulner ...)
+ TODO: check
+CVE-2026-13505 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X ...)
+ TODO: check
+CVE-2026-11743 (The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_q ...)
+ TODO: check
+CVE-2026-11742 (The kernel queue helper z_queue_node_peek() in kernel/queue.c derefere ...)
+ TODO: check
+CVE-2026-11425 (Domoticz versions prior to 2026.3 contains a stored cross-site scripti ...)
+ TODO: check
+CVE-2025-4438
+ REJECTED
CVE-2026-66808
NOT-FOR-US: hypershift-addon-operator
CVE-2026-9169 (DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on ...)
NOT-FOR-US: LUCID Vision Labs Arena SDK
-CVE-2026-71870
+CVE-2026-71870 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
- pypdf <unfixed>
- pypdf2 <removed>
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3f-mc75-235c
@@ -141,17 +303,17 @@ CVE-2026-48094 (The ShareOpenly WordPress plugin prior to version 1.2.1 contains
NOT-FOR-US: WordPress plugin
CVE-2026-48093 (The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable t ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-47364 (On every successful login, the Datadog Android application calls Fireb ...)
+CVE-2026-47364 (In versions of the Datadog Android application prior to v545-5.9.2, th ...)
NOT-FOR-US: Datadog Android application
-CVE-2026-47363 (The launcher activity AppActivity in the Datadog Android application i ...)
+CVE-2026-47363 (In versions of the Datadog Android application prior to v541-5.9.2, th ...)
NOT-FOR-US: Datadog Android application
-CVE-2026-47362 (The Datadog Android application stores operationally sensitive content ...)
+CVE-2026-47362 (In versions of the Datadog Android application prior to v554-5.9.4, tw ...)
NOT-FOR-US: Datadog Android application
-CVE-2026-47361 (BubbleChatActivity in the Datadog Android application is declared andr ...)
+CVE-2026-47361 (In versions of the Datadog Android application prior to v541-5.9.2, Bu ...)
NOT-FOR-US: Datadog Android application
-CVE-2026-44965 (Six Android App Widget configuration activities in the Datadog Android ...)
+CVE-2026-44965 (In versions of the Datadog Android application prior to v545-5.9.2, si ...)
NOT-FOR-US: Datadog Android application
-CVE-2026-44964 (The OnCallNotificationActivity in the Datadog Android application is d ...)
+CVE-2026-44964 (In versions of the Datadog Android application prior to v545-5.9.2, On ...)
NOT-FOR-US: Datadog Android application
CVE-2026-37171 (A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0. ...)
NOT-FOR-US: SuperTokens
@@ -9594,7 +9756,7 @@ CVE-2026-48702
- rekor 1.5.2-1
NOTE: https://github.com/sigstore/rekor/pull/2831
NOTE: Fixed by: https://github.com/sigstore/rekor/commit/759b98e2a7c39ea9779b6a51299c5f0f987f8802 (v1.5.2)
-CVE-2026-50540
+CVE-2026-50540 (Kata Containers is an open source project focusing on a standard imple ...)
NOT-FOR-US: Kata Containers
CVE-2026-50149
NOT-FOR-US: Contour
@@ -62903,7 +63065,7 @@ CVE-2026-43495 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.88-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/0e7c074cfcd9bd93765505f9eb8b42f03ed2a744 (7.1-rc3)
-CVE-2026-47243
+CVE-2026-47243 (Kata Containers is an open source project focusing on a standard imple ...)
NOT-FOR-US: Kata Containers
CVE-2026-45250 (The setcred(2) system call is only available to privileged users. How ...)
NOT-FOR-US: FreeBSD
@@ -148101,7 +148263,7 @@ CVE-2020-36877 (ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthent
NOT-FOR-US: ReQuest Serious Play F3 Media Server
CVE-2020-36876 (ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2. ...)
NOT-FOR-US: ReQuest Serious Play F3 Media Server
-CVE-2025-6946 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
+CVE-2025-6946 (A stored cross-site scripting (XSS) vulnerability exists in the manage ...)
NOT-FOR-US: WatchGuard
CVE-2025-66576 (Remote Keyboard Desktop 1.0.1 enables remote attackers to execute syst ...)
NOT-FOR-US: Remote Keyboard Desktop
@@ -175245,7 +175407,7 @@ CVE-2025-9808 (The The Events Calendar plugin for WordPress is vulnerable to Inf
NOT-FOR-US: WordPress plugin
CVE-2025-6999 (An HTTP Request Smuggling [CWE-444] vulnerability in the Authenticatio ...)
NOT-FOR-US: WatchGuard
-CVE-2025-6947 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
+CVE-2025-6947 (A stored cross-site scripting (XSS) vulnerability exists in the manage ...)
NOT-FOR-US: WatchGuard
CVE-2025-5518 (Authorization Bypass Through User-Controlled Key vulnerability with us ...)
NOT-FOR-US: ArgusTech BILGER
@@ -212858,7 +213020,7 @@ CVE-2025-4811 (A vulnerability was found in CodeAstro Pharmacy Management System
NOT-FOR-US: CodeAstro
CVE-2025-4810 (A vulnerability was found in Tenda AC7 15.03.06.44. It has been declar ...)
NOT-FOR-US: Tenda
-CVE-2025-4805 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
+CVE-2025-4805 (A stored cross-site scripting (XSS) vulnerability exists in the manage ...)
NOT-FOR-US: WatchGuard
CVE-2025-4804 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
NOT-FOR-US: WatchGuard
@@ -245680,9 +245842,9 @@ CVE-2025-22702 (Missing Authorization vulnerability in ThemeGoods Photography ph
NOT-FOR-US: WordPress plugin
CVE-2025-22698 (Missing Authorization vulnerability in Ability, Inc Accessibility Suit ...)
NOT-FOR-US: WordPress plugin
-CVE-2025-1239 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
+CVE-2025-1239 (A stored cross-site scripting (XSS) vulnerability exists in the manage ...)
NOT-FOR-US: WatchGuard Fireware OS
-CVE-2025-1071 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
+CVE-2025-1071 (A stored cross-site scripting (XSS) vulnerability exists in the manage ...)
NOT-FOR-US: WatchGuard Fireware OS
CVE-2025-0867 (The standard user uses the run as function to start the MEAC applicati ...)
NOT-FOR-US: SICK
@@ -245690,7 +245852,7 @@ CVE-2025-0821 (Bit Assist plugin for WordPress is vulnerable to time-based SQL I
NOT-FOR-US: WordPress plugin
CVE-2025-0503 (Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the d ...)
- mattermost-server <itp> (bug #823556)
-CVE-2025-0178 (Improper Input Validation vulnerability in WatchGuard Fireware OS allo ...)
+CVE-2025-0178 (An Improper Input Validation vulnerability in WatchGuard Fireware OS a ...)
NOT-FOR-US: WatchGuard Fireware OS
CVE-2024-8893 (Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co. ...)
NOT-FOR-US: GoodWe Technologies
@@ -287184,7 +287346,7 @@ CVE-2024-6594 (Improper Handling of Exceptional Conditions vulnerability in the
NOT-FOR-US: WatchGuard Single Sign-On Client on Windows
CVE-2024-6593 (Incorrect Authorization vulnerability in WatchGuard Authentication Gat ...)
NOT-FOR-US: WatchGuard
-CVE-2024-6592 (Incorrect Authorization vulnerability in the protocol communication be ...)
+CVE-2024-6592 (An incorrect authorization vulnerability in the protocol communication ...)
NOT-FOR-US: WatchGuard
CVE-2024-6512 (Authorization bypass in thePAM access request approval mechanism in De ...)
NOT-FOR-US: Devolutions Server
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e41f593860c1eb78e5a2eee1c04a174a50a2b947
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e41f593860c1eb78e5a2eee1c04a174a50a2b947
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/8a8e2d2e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list