[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 18 08:12:58 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5f93d258 by security tracker role at 2026-08-18T07:12:52+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,293 @@
+CVE-2026-9859 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
+ TODO: check
+CVE-2026-9816 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
+ TODO: check
+CVE-2026-9693 (Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost f ...)
+ TODO: check
+CVE-2026-75587 (Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-a ...)
+ TODO: check
+CVE-2026-75531 (Pandora contains a stored cross-site scripting (XSS) vulnerability in ...)
+ TODO: check
+CVE-2026-75529 (Pandora is affected by a stored cross-site scripting vulnerability in ...)
+ TODO: check
+CVE-2026-75483 (powerlevel10k fails to neutralize control characters in the package.js ...)
+ TODO: check
+CVE-2026-75482 (SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1 ...)
+ TODO: check
+CVE-2026-75481 (SkyPilot fails to validate that authenticated users are entitled to gr ...)
+ TODO: check
+CVE-2026-75480 (OpenViking debug vector scroll and count endpoints apply only account- ...)
+ TODO: check
+CVE-2026-75479 (JimuReport contains an authentication bypass vulnerability in the repo ...)
+ TODO: check
+CVE-2026-75151 (A vulnerability has been found in SourceCodester Onlne Examination & L ...)
+ TODO: check
+CVE-2026-75111 (Evidently UI fails to properly validate the filename parameter in the ...)
+ TODO: check
+CVE-2026-75110 (MemOS is a memory operating system for LLMs and AI agents. In deployme ...)
+ TODO: check
+CVE-2026-75109 (Determined fails to authorize requests on the generic task kill, pause ...)
+ TODO: check
+CVE-2026-75108 (Next Terminal fails to enforce per-asset authorization checks on the p ...)
+ TODO: check
+CVE-2026-75106 (OpnForm derives editable-submission secrets from sequential row identi ...)
+ TODO: check
+CVE-2026-75105 (phpIPAM through 1.8.1 fails to verify that a requested IP address belo ...)
+ TODO: check
+CVE-2026-75104 (Hugging Face Transformers fails to validate shard filenames in checkpo ...)
+ TODO: check
+CVE-2026-75103 (Crawlab fails to verify user ownership or administrative role on the p ...)
+ TODO: check
+CVE-2026-75094 (A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the fun ...)
+ TODO: check
+CVE-2026-75093 (A security vulnerability has been detected in sonos tract up to 0.23.4 ...)
+ TODO: check
+CVE-2026-75091 (The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes p ...)
+ TODO: check
+CVE-2026-75090 (A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. ...)
+ TODO: check
+CVE-2026-75089 (A weakness has been identified in PHPGurukul Complaint Management Syst ...)
+ TODO: check
+CVE-2026-75088 (A vulnerability was determined in itsourcecode Hospital Management Sys ...)
+ TODO: check
+CVE-2026-75087 (A vulnerability was found in itsourcecode Hospital Management System 1 ...)
+ TODO: check
+CVE-2026-75086 (A vulnerability has been found in itsourcecode Hospital Management Sys ...)
+ TODO: check
+CVE-2026-75082 (A flaw has been found in Webkul Bagisto up to 2.4.4. The affected elem ...)
+ TODO: check
+CVE-2026-75081 (A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted i ...)
+ TODO: check
+CVE-2026-75080 (A security vulnerability has been detected in SourceCodester Class and ...)
+ TODO: check
+CVE-2026-75079 (A weakness has been identified in SourceCodester Class and Exam Timeta ...)
+ TODO: check
+CVE-2026-75078 (A security flaw has been discovered in SourceCodester Class and Exam T ...)
+ TODO: check
+CVE-2026-75077 (A vulnerability was identified in SourceCodester Class and Exam Timeta ...)
+ TODO: check
+CVE-2026-75014 (A flaw has been found in SourceCodester Pet Grooming Management Softwa ...)
+ TODO: check
+CVE-2026-75013 (A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023 ...)
+ TODO: check
+CVE-2026-75012 (A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u. ...)
+ TODO: check
+CVE-2026-74234 (Legora before 2026-08-14 contains a cross-site scripting vulnerability ...)
+ TODO: check
+CVE-2026-73560 (vLLM is an inference and serving engine for large language models. Pri ...)
+ TODO: check
+CVE-2026-73410 (Budibase is an open-source low-code platform. Prior to 3.40.0, package ...)
+ TODO: check
+CVE-2026-71858 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
+ TODO: check
+CVE-2026-71553 (ApostropheCMS is an open-source Node.js content management system. In ...)
+ TODO: check
+CVE-2026-71518 (Typemill before 2.26.0 contains an authorization bypass vulnerability ...)
+ TODO: check
+CVE-2026-71486 (vLLM is an inference and serving engine for large language models. Pri ...)
+ TODO: check
+CVE-2026-71472 (A flaw was found in acm-search-v2-rhel9. This vulnerability allows an ...)
+ TODO: check
+CVE-2026-71424 (Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0 ...)
+ TODO: check
+CVE-2026-70495 (A flaw was found in search-v2-operator. This component's `search-servi ...)
+ TODO: check
+CVE-2026-69148 (MLflow is an open source AI engineering platform for agents, large lan ...)
+ TODO: check
+CVE-2026-69146 (MLflow is an open source AI engineering platform for agents, large lan ...)
+ TODO: check
+CVE-2026-68765 (hashcat master branch builds after v7.1.2 contain a heap buffer overfl ...)
+ TODO: check
+CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to ...)
+ TODO: check
+CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remo ...)
+ TODO: check
+CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an ...)
+ TODO: check
+CVE-2026-67966 (Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthentic ...)
+ TODO: check
+CVE-2026-67965 (An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to e ...)
+ TODO: check
+CVE-2026-67961 (An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary ...)
+ TODO: check
+CVE-2026-67960 (An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary ...)
+ TODO: check
+CVE-2026-67926 (An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbi ...)
+ TODO: check
+CVE-2026-67925 (Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remot ...)
+ TODO: check
+CVE-2026-67919 (An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary ...)
+ TODO: check
+CVE-2026-67918 (Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a r ...)
+ TODO: check
+CVE-2026-67917 (zuraCast versions up to and including 0.23.7 contain a SQL injection v ...)
+ TODO: check
+CVE-2026-67868 (A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 i ...)
+ TODO: check
+CVE-2026-67854 (SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker t ...)
+ TODO: check
+CVE-2026-67678 (File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a ...)
+ TODO: check
+CVE-2026-66795 (A flaw was found in the managedcluster-import-controller. The Certific ...)
+ TODO: check
+CVE-2026-65976 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 until contin ...)
+ TODO: check
+CVE-2026-65974 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
+ TODO: check
+CVE-2026-65832 (Deskflow is a keyboard and mouse sharing app. Prior to continuous buil ...)
+ TODO: check
+CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
+ TODO: check
+CVE-2026-65640 (WordPress is vulnerable to a remote code execution vulnerability via m ...)
+ TODO: check
+CVE-2026-65351 (This issue was addressed through improved state management. This issue ...)
+ TODO: check
+CVE-2026-65349 (An out-of-bounds read was addressed with improved input validation. Th ...)
+ TODO: check
+CVE-2026-65347 (The issue was addressed with improved checks. This issue is fixed in i ...)
+ TODO: check
+CVE-2026-65346 (An integer overflow was addressed with improved input validation. This ...)
+ TODO: check
+CVE-2026-65343 (A use after free issue was addressed with improved memory management. ...)
+ TODO: check
+CVE-2026-65341 (The issue was addressed with improved memory handling. This issue is f ...)
+ TODO: check
+CVE-2026-65340 (This issue was addressed through improved state management. This issue ...)
+ TODO: check
+CVE-2026-65339 (A logic issue was addressed with improved checks. This issue is fixed ...)
+ TODO: check
+CVE-2026-65338 (The issue was addressed with improved memory handling. This issue is f ...)
+ TODO: check
+CVE-2026-65337 (This issue was addressed through improved state management. This issue ...)
+ TODO: check
+CVE-2026-65336 (This issue was addressed through improved state management. This issue ...)
+ TODO: check
+CVE-2026-65335 (This issue was addressed through improved state management. This issue ...)
+ TODO: check
+CVE-2026-65334 (A memory corruption issue was addressed with improved state management ...)
+ TODO: check
+CVE-2026-65333 (This issue was addressed through improved state management. This issue ...)
+ TODO: check
+CVE-2026-65332 (This issue was addressed through improved state management. This issue ...)
+ TODO: check
+CVE-2026-65331 (This issue was addressed through improved state management. This issue ...)
+ TODO: check
+CVE-2026-65330 (The issue was addressed with improved memory handling. This issue is f ...)
+ TODO: check
+CVE-2026-65329 (An authentication issue was addressed with improved state management. ...)
+ TODO: check
+CVE-2026-64849 (MLflow is an open source AI engineering platform for agents, large lan ...)
+ TODO: check
+CVE-2026-64788 (The issue was addressed with improved memory handling. This issue is f ...)
+ TODO: check
+CVE-2026-64787 (A use-after-free issue was addressed with improved memory management. ...)
+ TODO: check
+CVE-2026-64784 (An out-of-bounds access issue was addressed with improved bounds check ...)
+ TODO: check
+CVE-2026-64782 (A memory corruption vulnerability was addressed with improved locking. ...)
+ TODO: check
+CVE-2026-64781 (The issue was addressed with improved input validation. This issue is ...)
+ TODO: check
+CVE-2026-64780 (The issue was addressed with improved checks. This issue is fixed in i ...)
+ TODO: check
+CVE-2026-64779 (A memory corruption vulnerability was addressed with improved locking. ...)
+ TODO: check
+CVE-2026-64778 (The issue was addressed with improved checks. This issue is fixed in i ...)
+ TODO: check
+CVE-2026-64760 (An information leakage was addressed with additional validation. This ...)
+ TODO: check
+CVE-2026-64715 (A use-after-free issue was addressed with improved memory management. ...)
+ TODO: check
+CVE-2026-64657 (Budibase is an open-source low-code platform. Prior to 3.39.19, the Po ...)
+ TODO: check
+CVE-2026-63670 (ApostropheCMS is an open-source Node.js content management system. Pri ...)
+ TODO: check
+CVE-2026-63669 (ApostropheCMS is an open-source Node.js content management system. Pri ...)
+ TODO: check
+CVE-2026-63667 (ApostropheCMS is an open-source Node.js content management system. Pri ...)
+ TODO: check
+CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 until contin ...)
+ TODO: check
+CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Ed ...)
+ TODO: check
+CVE-2026-57485 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
+ TODO: check
+CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
+ TODO: check
+CVE-2026-56677 (9Router is an AI router & token saver. In 0.5.4 and earlier, the POST ...)
+ TODO: check
+CVE-2026-54758 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
+ TODO: check
+CVE-2026-54385
+ REJECTED
+CVE-2026-54356 (Budibase is an open-source low-code platform. Prior to 3.41.3, POST /a ...)
+ TODO: check
+CVE-2026-54336 (JumpServer is an open source bastion host and an operation and mainten ...)
+ TODO: check
+CVE-2026-52886 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
+ TODO: check
+CVE-2026-51977 (An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Ve ...)
+ TODO: check
+CVE-2026-47698 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bri ...)
+ TODO: check
+CVE-2026-47686 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleE ...)
+ TODO: check
+CVE-2026-47683 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the buf ...)
+ TODO: check
+CVE-2026-45791 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+ TODO: check
+CVE-2026-45790 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+ TODO: check
+CVE-2026-44846 (JumpServer is an open source bastion host and an operation and mainten ...)
+ TODO: check
+CVE-2026-44845 (JumpServer is an open source bastion host and an operation and mainten ...)
+ TODO: check
+CVE-2026-43795 (The issue was addressed with improved memory handling. This issue is f ...)
+ TODO: check
+CVE-2026-43794 (A memory corruption issue was addressed with improved memory handling. ...)
+ TODO: check
+CVE-2026-43667 (A reachable assertion was addressed with improved input validation. Th ...)
+ TODO: check
+CVE-2026-42164 (Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/sect ...)
+ TODO: check
+CVE-2026-42163 (Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access ...)
+ TODO: check
+CVE-2026-42162 (Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being acc ...)
+ TODO: check
+CVE-2026-40506 (OpenEMR before 8.2.0 contains a path traversal vulnerability in the st ...)
+ TODO: check
+CVE-2026-39255 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ...)
+ TODO: check
+CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ...)
+ TODO: check
+CVE-2026-38165 (A Server-Side Template Injection (SSTI) vulnerability in the Velocity ...)
+ TODO: check
+CVE-2026-35219 (Budibase is an open-source low-code platform. Prior to 3.41.3, automat ...)
+ TODO: check
+CVE-2026-34789 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
+ TODO: check
+CVE-2026-34399 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
+ TODO: check
+CVE-2026-34398 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
+ TODO: check
+CVE-2026-28984 (The issue was addressed with improved memory handling. This issue is f ...)
+ TODO: check
+CVE-2026-19650 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
+ TODO: check
+CVE-2026-19589 (Packer up to 1.15.4 is vulnerable to an issue in the third-party plugi ...)
+ TODO: check
+CVE-2026-19478 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
+ TODO: check
+CVE-2026-15748 (The Forminator Forms plugin for WordPress is vulnerable to Arbitrary F ...)
+ TODO: check
+CVE-2026-15371 (Velociraptor's web GUI allows specifying a custom type for columns in ...)
+ TODO: check
+CVE-2026-11817 (This vulnerability only affects Grafana stacks configured with multipl ...)
+ TODO: check
+CVE-2026-11801 (The WPAdverts \u2013 Classifieds Plugin plugin for WordPress is vulner ...)
+ TODO: check
+CVE-2026-10080 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
+ TODO: check
CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy() in dri ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was possible via u ...)
@@ -13329,6 +13619,7 @@ CVE-2026-XXXX [Neutron sub-resource APIs do not verify parent ownership]
NOTE: https://review.opendev.org/c/openstack/neutron/+/989624/
NOTE: https://review.opendev.org/c/openstack/neutron/+/991586
CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant infinite ...)
+ {DSA-6446-1}
- expat 2.8.3-1 (bug #1144064)
NOTE: https://github.com/libexpat/libexpat/pull/1296
NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
@@ -42233,6 +42524,7 @@ CVE-2026-53730 (DataEase is an open source data visualization and analysis tool.
CVE-2026-53729 (DataEase is an open source data visualization and analysis tool. Prior ...)
NOT-FOR-US: DataEase
CVE-2026-53511 (calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, ...)
+ {DLA-4744-1}
- calibre 9.10.0+ds+~0.10.6-1
[trixie] - calibre <no-dsa> (Minor issue)
[bullseye] - calibre <not-affected> (Vulnerable code introduced later)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f93d25814ebdffbfbe93eddbf7ce78c2beb2f7b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f93d25814ebdffbfbe93eddbf7ce78c2beb2f7b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/7c470188/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list