[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 19 20:14:32 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ccc60041 by security tracker role at 2026-08-19T19:14:25+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,591 @@
+CVE-2026-76614 (OpenEMR before 8.3.0 contains a path traversal vulnerability in the ED ...)
+	TODO: check
+CVE-2026-76245 (stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestam ...)
+	TODO: check
+CVE-2026-76244 (stigmem-node contains an insecure default configuration vulnerability  ...)
+	TODO: check
+CVE-2026-76243 (stigmem versions before 0.9.0a2 allow unauthenticated access when auth ...)
+	TODO: check
+CVE-2026-76242 (stigmem-node 0.9.0a1 accepts federation peer key material during peer  ...)
+	TODO: check
+CVE-2026-76241 (stigmem-node 0.9.0a1 allows plugin signature enforcement to be disable ...)
+	TODO: check
+CVE-2026-76240 (stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers  ...)
+	TODO: check
+CVE-2026-76239 (Stigmem before 0.9.0a11 fails to validate the delivery_address paramet ...)
+	TODO: check
+CVE-2026-76238 (stigmem versions before 0.9.0a12 contain a broken object level authori ...)
+	TODO: check
+CVE-2026-76237 (stigmem-node before 0.9.0a12 contains a broken object level authorizat ...)
+	TODO: check
+CVE-2026-76236 (stigmem-node before 0.9.0a12 contains a cross-tenant broken object lev ...)
+	TODO: check
+CVE-2026-76235 (A memory leak flaw was found in cockpit-ws. The login page handler lea ...)
+	TODO: check
+CVE-2026-76234 (libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before  ...)
+	TODO: check
+CVE-2026-76233 (Renovate versions from 39.53.0 before 40.33.0 contain a command inject ...)
+	TODO: check
+CVE-2026-76232 (Renovate versions from 31.51.0 before 40.33.0 contain a command inject ...)
+	TODO: check
+CVE-2026-76231 (Renovate versions from 32.135.0 before 40.33.0 contain a command injec ...)
+	TODO: check
+CVE-2026-76230 (Renovate versions from 35.63.0 before 40.33.0 contain a command inject ...)
+	TODO: check
+CVE-2026-76229 (Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary co ...)
+	TODO: check
+CVE-2026-76228 (Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/ ...)
+	TODO: check
+CVE-2026-76227 (Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before ...)
+	TODO: check
+CVE-2026-76226 (Renovate versions from 43.65.0 before 43.102.11 contain a remote code  ...)
+	TODO: check
+CVE-2026-76225 (ArcadeDB before 26.8.1 contains a server-side request forgery vulnerab ...)
+	TODO: check
+CVE-2026-76224 (ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains ...)
+	TODO: check
+CVE-2026-76223 (ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce th ...)
+	TODO: check
+CVE-2026-76222 (GitPython before 3.1.58 fails to validate submodule names from .gitmod ...)
+	TODO: check
+CVE-2026-76221 (GitPython before 3.1.58 contains a config-name injection vulnerability ...)
+	TODO: check
+CVE-2026-76220 (GitPython before 3.1.58 contains a command execution vulnerability in  ...)
+	TODO: check
+CVE-2026-76219 (GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...)
+	TODO: check
+CVE-2026-76218 (GitPython before 3.1.58 contains a remote code execution vulnerability ...)
+	TODO: check
+CVE-2026-76217 (GitPython versions before 3.1.58 fail to validate options passed to gi ...)
+	TODO: check
+CVE-2026-76216 (Vikunja through 2.4.0 contains a principal-type confusion vulnerabilit ...)
+	TODO: check
+CVE-2026-76215 (phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks befo ...)
+	TODO: check
+CVE-2026-76214 (phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist th ...)
+	TODO: check
+CVE-2026-76213 (phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two- ...)
+	TODO: check
+CVE-2026-76212 (phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the nativ ...)
+	TODO: check
+CVE-2026-76211 (phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT per ...)
+	TODO: check
+CVE-2026-76210 (phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ answers ...)
+	TODO: check
+CVE-2026-76209 (phpMyFAQ versions before v4.1.6 fail to validate the security.enableRe ...)
+	TODO: check
+CVE-2026-76208 (phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass ...)
+	TODO: check
+CVE-2026-76207 (phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vuln ...)
+	TODO: check
+CVE-2026-76206 (phpMyFAQ versions before 4.1.7 fail to validate active status in the P ...)
+	TODO: check
+CVE-2026-76205 (phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the gl ...)
+	TODO: check
+CVE-2026-76203 (Incorrect Behavior Order: Validate Before Canonicalize in the report t ...)
+	TODO: check
+CVE-2026-76166 (A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.mod ...)
+	TODO: check
+CVE-2026-76164 (AIL Framework contains a server-side request forgery (SSRF) vulnerabil ...)
+	TODO: check
+CVE-2026-75956 (Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter  ...)
+	TODO: check
+CVE-2026-75955 (Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J- ...)
+	TODO: check
+CVE-2026-75954 (Joomla Extension - cmsjunkie.com -  SQL injection in trips search in J ...)
+	TODO: check
+CVE-2026-75953 (Joomla Extension - cmsjunkie.com -  Open mail relay in J-BusinessDirec ...)
+	TODO: check
+CVE-2026-75952 (Joomla Extension - cmsjunkie.com -  Cross-site request forgery in J-Bu ...)
+	TODO: check
+CVE-2026-75951 (Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (m ...)
+	TODO: check
+CVE-2026-75950 (Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership t ...)
+	TODO: check
+CVE-2026-75949 (Joomla Extension - cmsjunkie.com -  Arbitrary file upload / deletion ( ...)
+	TODO: check
+CVE-2026-75920 (phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-a ...)
+	TODO: check
+CVE-2026-75919 (phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability  ...)
+	TODO: check
+CVE-2026-75918 (phpMyFAQ before 4.1.7 stores password reset tokens in a publicly acces ...)
+	TODO: check
+CVE-2026-75917 (SiYuan before v3.7.4 contains a cross-site scripting vulnerability in  ...)
+	TODO: check
+CVE-2026-75916 (SiYuan through 3.7.3 contains a cross-site scripting vulnerability in  ...)
+	TODO: check
+CVE-2026-75619 (Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability  ...)
+	TODO: check
+CVE-2026-75618 (Tapo C100/C101 V5 contains a null pointer dereference vulnerability in ...)
+	TODO: check
+CVE-2026-75583 (keeper.sh's calendar module version prior to 2.18.14 contains a server ...)
+	TODO: check
+CVE-2026-75149 (marimo before 0.23.15 contains a code injection vulnerability in the n ...)
+	TODO: check
+CVE-2026-75148 (cgltf through 1.15 contains an integer overflow vulnerability in the n ...)
+	TODO: check
+CVE-2026-75147 (FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 ...)
+	TODO: check
+CVE-2026-75146 (FFmpeg before commit 65b0dab contains an out-of-bounds read in the DAS ...)
+	TODO: check
+CVE-2026-75145 (FFmpeg before commit b4c199c contains an incorrect integer narrowing c ...)
+	TODO: check
+CVE-2026-75144 (FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerabi ...)
+	TODO: check
+CVE-2026-75143 (FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RI ...)
+	TODO: check
+CVE-2026-75142 (FFmpeg before commit 9d786e4 contains a stack buffer overflow in the M ...)
+	TODO: check
+CVE-2026-75141 (FFmpeg before commit acf5d7c contains a heap buffer overflow in the hv ...)
+	TODO: check
+CVE-2026-75114 (Joomla Extension - yootheme.com - Open redirect in CommentController:: ...)
+	TODO: check
+CVE-2026-74804 (Joomla Extension - yootheme.com - Unauthenticated SQL injection in Ite ...)
+	TODO: check
+CVE-2026-74803 (Joomla Extension - yootheme.com - Unauthenticated arbitrary file uploa ...)
+	TODO: check
+CVE-2026-73829 (Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allow ...)
+	TODO: check
+CVE-2026-73541 (Allocation of Resources Without Limits or Throttling in ZenHive mpp al ...)
+	TODO: check
+CVE-2026-73394 (Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versi ...)
+	TODO: check
+CVE-2026-73391 (Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.)
+	TODO: check
+CVE-2026-73390 (Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versi ...)
+	TODO: check
+CVE-2026-73389 (Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 version ...)
+	TODO: check
+CVE-2026-73388 (Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.)
+	TODO: check
+CVE-2026-73387 (Unauthenticated Local File Inclusion in Resido <= 1.5 versions.)
+	TODO: check
+CVE-2026-73386 (Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users  ...)
+	TODO: check
+CVE-2026-73385 (Unauthenticated Broken Access Control in Outranking Plugin Options <=  ...)
+	TODO: check
+CVE-2026-73384 (Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <=  ...)
+	TODO: check
+CVE-2026-73364 (Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versi ...)
+	TODO: check
+CVE-2026-73363 (Unauthenticated Broken Access Control in Taxi Booking Manager for WooC ...)
+	TODO: check
+CVE-2026-73354 (Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate I ...)
+	TODO: check
+CVE-2026-73347 (Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.)
+	TODO: check
+CVE-2026-73185 (Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versio ...)
+	TODO: check
+CVE-2026-73184 (Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 ...)
+	TODO: check
+CVE-2026-73183 (Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.)
+	TODO: check
+CVE-2026-73182 (Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.)
+	TODO: check
+CVE-2026-73136 (Authentication Bypass by Capture-replay in ZenHive mpp allows an unaut ...)
+	TODO: check
+CVE-2026-72717 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-72716 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-72530 (A remote unauthorized attacker with network access via port 4307/TCP t ...)
+	TODO: check
+CVE-2026-72529 (A remote unauthorized attacker with network access via port 4307/TCP t ...)
+	TODO: check
+CVE-2026-71961 (Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command  ...)
+	TODO: check
+CVE-2026-71960 (Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded J ...)
+	TODO: check
+CVE-2026-71871 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-71869 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-71868 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-71867 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-71866 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-71865 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-71864 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-71694 (An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchm ...)
+	TODO: check
+CVE-2026-71470 (A flaw was found in the search-v2-operator. This vulnerability allows  ...)
+	TODO: check
+CVE-2026-71176 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
+	TODO: check
+CVE-2026-70496 (A flaw was found in search-v2-operator. The operator's ClusterRole has ...)
+	TODO: check
+CVE-2026-70424 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
+	TODO: check
+CVE-2026-70423 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
+	TODO: check
+CVE-2026-70422 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
+	TODO: check
+CVE-2026-70421 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
+	TODO: check
+CVE-2026-69159 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
+	TODO: check
+CVE-2026-67581 (Authentication Bypass by Capture-replay in ZenHive mpp allows an unaut ...)
+	TODO: check
+CVE-2026-67364 (Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balboo ...)
+	TODO: check
+CVE-2026-67363 (Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in  ...)
+	TODO: check
+CVE-2026-67268 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Imprope ...)
+	TODO: check
+CVE-2026-67267 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposur ...)
+	TODO: check
+CVE-2026-67266 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorre ...)
+	TODO: check
+CVE-2026-66794 (A flaw was found in the `cluster-proxy-addon` component of Multicluste ...)
+	TODO: check
+CVE-2026-66668 (Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.)
+	TODO: check
+CVE-2026-66613 (Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 ver ...)
+	TODO: check
+CVE-2026-66596 (Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 vers ...)
+	TODO: check
+CVE-2026-65612 (nnn does not sanitize the filename variable. An attacker can place a f ...)
+	TODO: check
+CVE-2026-65611 (nnn does not sanitize the path variable. An attacker can createa direc ...)
+	TODO: check
+CVE-2026-65610 (nnn stores homelen variable as uchar_t, which can only represent value ...)
+	TODO: check
+CVE-2026-65609 (nnn is vulnerable to Out-of-Bound write vulnerability.Due to lack of v ...)
+	TODO: check
+CVE-2026-64852 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
+	TODO: check
+CVE-2026-64851 (Grav Shortcode Core Plugin allows for the development shortcode plugin ...)
+	TODO: check
+CVE-2026-64850 (Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dyn ...)
+	TODO: check
+CVE-2026-63652 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
+	TODO: check
+CVE-2026-63633 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
+	TODO: check
+CVE-2026-63408 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
+	TODO: check
+CVE-2026-63407 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
+	TODO: check
+CVE-2026-63117 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
+	TODO: check
+CVE-2026-62682 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-62681 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-62680 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
+	TODO: check
+CVE-2026-62673 (Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess  ...)
+	TODO: check
+CVE-2026-62672 (Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the ...)
+	TODO: check
+CVE-2026-62671 (Grav Login Plugin adds login, basic ACL, and session wide messages to  ...)
+	TODO: check
+CVE-2026-62670 (Grav Flex Objects Plugin allows you to build custom collections of obj ...)
+	TODO: check
+CVE-2026-62669 (Grav Login Plugin adds login, basic ACL, and session wide messages to  ...)
+	TODO: check
+CVE-2026-62668 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
+	TODO: check
+CVE-2026-62667 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
+	TODO: check
+CVE-2026-62666 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
+	TODO: check
+CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0. ...)
+	TODO: check
+CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig conte ...)
+	TODO: check
+CVE-2026-61807 (Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a s ...)
+	TODO: check
+CVE-2026-61690 (Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::e ...)
+	TODO: check
+CVE-2026-61607 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
+	TODO: check
+CVE-2026-61518 (ISPConfig contains an authenticated SQL injection vulnerability in the ...)
+	TODO: check
+CVE-2026-58565 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing  ...)
+	TODO: check
+CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorre ...)
+	TODO: check
+CVE-2026-58562 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing  ...)
+	TODO: check
+CVE-2026-58088 (The ELF core dump code counted the number of dumpable VM map entries,  ...)
+	TODO: check
+CVE-2026-58087 (The GETALL and SETALL commands in semctl(2) recorded the number of sem ...)
+	TODO: check
+CVE-2026-58086 (As an inadvertent side effect of an unrelated code change, PRIV_KTRACE ...)
+	TODO: check
+CVE-2026-58085 (After dispatching a decrypt operation to OCF and receiving the result, ...)
+	TODO: check
+CVE-2026-58084 (To retrieve the previous timer value, the kernel calls realtimer_getti ...)
+	TODO: check
+CVE-2026-58083 (While the kernel was copying knotes during fork, a knote with a timer- ...)
+	TODO: check
+CVE-2026-58082 (The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX ( ...)
+	TODO: check
+CVE-2026-58081 (Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not p ...)
+	TODO: check
+CVE-2026-56797 (Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Ti ...)
+	TODO: check
+CVE-2026-56796 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Imprope ...)
+	TODO: check
+CVE-2026-56088 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
+	TODO: check
+CVE-2026-55703 (Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any ...)
+	TODO: check
+CVE-2026-55694 (Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a r ...)
+	TODO: check
+CVE-2026-55643 (Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a c ...)
+	TODO: check
+CVE-2026-55519 (Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an  ...)
+	TODO: check
+CVE-2026-55483 (Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an  ...)
+	TODO: check
+CVE-2026-55482 (Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a n ...)
+	TODO: check
+CVE-2026-54796 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
+	TODO: check
+CVE-2026-54795 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
+	TODO: check
+CVE-2026-54794 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server ...)
+	TODO: check
+CVE-2026-54793 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
+	TODO: check
+CVE-2026-53654 (Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin tw ...)
+	TODO: check
+CVE-2026-53477 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of- ...)
+	TODO: check
+CVE-2026-53452 (Ground Station is a browser-based suite for satellite tracking, SDR re ...)
+	TODO: check
+CVE-2026-53451 (Ground Station is a browser-based suite for satellite tracking, SDR re ...)
+	TODO: check
+CVE-2026-52889 (Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Form ...)
+	TODO: check
+CVE-2026-52834 (jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to ...)
+	TODO: check
+CVE-2026-52792 (Algernon is a small self-contained pure-Go web server. Prior to 1.17.9 ...)
+	TODO: check
+CVE-2026-51367 (An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote  ...)
+	TODO: check
+CVE-2026-51366 (SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2 ...)
+	TODO: check
+CVE-2026-50720 (The Ingenic T31 SoC boot ROM flash-boot verification path compares onl ...)
+	TODO: check
+CVE-2026-50719 (The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs pars ...)
+	TODO: check
+CVE-2026-50550 (Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a u ...)
+	TODO: check
+CVE-2026-50173 (Flow-Like is a platform for building end-to-end use cases. Prior to ve ...)
+	TODO: check
+CVE-2026-49976 (Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a u ...)
+	TODO: check
+CVE-2026-49870 (Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POS ...)
+	TODO: check
+CVE-2026-49817 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserial ...)
+	TODO: check
+CVE-2026-49816 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserial ...)
+	TODO: check
+CVE-2026-49441 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-49425 (The compat32 kevent() handler translates a 64-bit kevent struct into a ...)
+	TODO: check
+CVE-2026-49424 (The Linux waitid() implementation translates a FreeBSD siginfo_t struc ...)
+	TODO: check
+CVE-2026-49392 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-49289 (The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...)
+	TODO: check
+CVE-2026-49283 (The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...)
+	TODO: check
+CVE-2026-49255 (electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VN ...)
+	TODO: check
+CVE-2026-49253 (electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VN ...)
+	TODO: check
+CVE-2026-48162 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-48024 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-46343 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-45798 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-45742 (Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 ...)
+	TODO: check
+CVE-2026-45741 (Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 a ...)
+	TODO: check
+CVE-2026-45274 (MyBooks is anebook management web server also known as Talebook. In 3. ...)
+	TODO: check
+CVE-2026-45273 (MyBooks is an ebook management web server also known as Talebook. In 3 ...)
+	TODO: check
+CVE-2026-45272 (MyBooks is an enhanced and easy-to-use personal ebook management web s ...)
+	TODO: check
+CVE-2026-44901 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-44829 (Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 a ...)
+	TODO: check
+CVE-2026-44256 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-44255 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-44254 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-44253 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-44252 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-41424 (Wazuh is a free and open source platform used for threat prevention, d ...)
+	TODO: check
+CVE-2026-40509 (OpenEMR before 8.3.0 contains a cross-site request forgery vulnerabili ...)
+	TODO: check
+CVE-2026-40508 (OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerabil ...)
+	TODO: check
+CVE-2026-40507 (OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnera ...)
+	TODO: check
+CVE-2026-32802 (Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper P ...)
+	TODO: check
+CVE-2026-32552 (Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.3 ...)
+	TODO: check
+CVE-2026-32475 (Unrestricted Upload of File with Dangerous Type vulnerability in Eleme ...)
+	TODO: check
+CVE-2026-23501 (Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Imp ...)
+	TODO: check
+CVE-2026-20359 (As part of Cisco's ongoing commitment to proactive security and produc ...)
+	TODO: check
+CVE-2026-20358 (As part of Cisco's ongoing commitment to proactive security and produc ...)
+	TODO: check
+CVE-2026-20357 (As part of Cisco's ongoing commitment to proactive security and produc ...)
+	TODO: check
+CVE-2026-20327 (A vulnerability in the web-based management interface of Cisco Unified ...)
+	TODO: check
+CVE-2026-20320 (A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco ...)
+	TODO: check
+CVE-2026-20319 (As part of Cisco's ongoing commitment to proactive security and produc ...)
+	TODO: check
+CVE-2026-20318 (As part of Cisco's ongoing commitment to proactive security and produc ...)
+	TODO: check
+CVE-2026-20317 (As part of Cisco's ongoing commitment to proactive security and produc ...)
+	TODO: check
+CVE-2026-20315 (As part of Cisco's ongoing commitment to proactive security and produc ...)
+	TODO: check
+CVE-2026-20314 (A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged  ...)
+	TODO: check
+CVE-2026-20302 (A vulnerability in the USB driver of Cisco RoomOS could allow an unaut ...)
+	TODO: check
+CVE-2026-20232 (A vulnerability in the web-based management interface of Cisco Industr ...)
+	TODO: check
+CVE-2026-20231 (As part of Cisco's ongoing commitment to proactive security and produc ...)
+	TODO: check
+CVE-2026-20177 (A vulnerability in the handling of management plane packets by Cisco I ...)
+	TODO: check
+CVE-2026-20030 (As part of Cisco's ongoing commitment to proactive security and produc ...)
+	TODO: check
+CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to ...)
+	TODO: check
+CVE-2026-19672 (The tarfile module's tar and data  extraction filters created director ...)
+	TODO: check
+CVE-2026-19653 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-19490 (Vulnerability in NetScaler ADC and NetScaler Gateway.  This issue affe ...)
+	TODO: check
+CVE-2026-19489 (Vulnerability in NetScaler ADC and NetScaler Gateway.  This issue affe ...)
+	TODO: check
+CVE-2026-19321 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1 ...)
+	TODO: check
+CVE-2026-19234 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1 ...)
+	TODO: check
+CVE-2026-19198 (Akaunting 3.1.21 contains an authenticated improper authorization vuln ...)
+	TODO: check
+CVE-2026-18874 (A flaw was found in volsync-addon-controller. This vulnerability allow ...)
+	TODO: check
+CVE-2026-18848 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
+	TODO: check
+CVE-2026-18756 (HumHub Community Edition 1.18.4 contains a reflected cross-site script ...)
+	TODO: check
+CVE-2026-18681 (IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00  ...)
+	TODO: check
+CVE-2026-18526 (HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross- ...)
+	TODO: check
+CVE-2026-18430 (HumHub 1.18.4 contains a stored cross-site scripting vulnerability in  ...)
+	TODO: check
+CVE-2026-18372 (CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows  ...)
+	TODO: check
+CVE-2026-18371 (HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows ...)
+	TODO: check
+CVE-2026-18315 (The TrueBooker \u2013 Appointment Booking and Scheduler System plugin  ...)
+	TODO: check
+CVE-2026-17494 (IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30  ...)
+	TODO: check
+CVE-2026-17429 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
+	TODO: check
+CVE-2026-17183 (An authenticated user with permission to create or edit alert rules ca ...)
+	TODO: check
+CVE-2026-17100 (Power Systems FirmwareFW1120.00, FW1110.00 through FW1110.30, FW1060.0 ...)
+	TODO: check
+CVE-2026-17093 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
+	TODO: check
+CVE-2026-16938 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
+	TODO: check
+CVE-2026-16930 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and ...)
+	TODO: check
+CVE-2026-16835 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
+	TODO: check
+CVE-2026-16832 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
+	TODO: check
+CVE-2026-16828 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
+	TODO: check
+CVE-2026-16819 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16818 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16817 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16816 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
+	TODO: check
+CVE-2026-16814 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16706 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16703 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+	TODO: check
+CVE-2026-16690 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16687 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
+	TODO: check
+CVE-2026-16686 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16656 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+	TODO: check
+CVE-2026-16440 (In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deep ...)
+	TODO: check
+CVE-2026-16019 (Improper neutralization of special elements used in an SQL command ('S ...)
+	TODO: check
+CVE-2026-15961 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1 ...)
+	TODO: check
+CVE-2026-15078 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote ...)
+	TODO: check
+CVE-2026-15068 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote ...)
+	TODO: check
+CVE-2026-15065 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote ...)
+	TODO: check
+CVE-2026-15061 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration  ...)
+	TODO: check
+CVE-2026-14970 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is cr ...)
+	TODO: check
+CVE-2025-14603 (The application component processes user-supplied parameters insecurel ...)
+	TODO: check
+CVE-2025-14600 (An insecure deserialization vulnerability in vsDesk allows a remote at ...)
+	TODO: check
+CVE-2024-58376 (Renovate versions 37.158.0 before 37.199.0 contain a command injection ...)
+	TODO: check
+CVE-2024-13942 (Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time ...)
+	TODO: check
+CVE-2020-37267 (Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps ...)
+	TODO: check
+CVE-2019-25766 (Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository  ...)
+	TODO: check
 CVE-2026-73639
 	- libimager-perl 1.035+dfsg-1
 	[trixie] - libimager-perl <no-dsa> (Minor issue)
@@ -12,12 +600,12 @@ CVE-2026-XXXX [GHSA-xrfq-jhgh-wqch: Authentication bypass in the web interface]
 	- sabnzbdplus <unfixed> (bug #1144839)
 	NOTE: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch
 	NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5 (5.1.1)
-CVE-2026-72889
+CVE-2026-72889 (Net::OAuth versions before 0.33 for Perl allow the sender to choose th ...)
 	- libnet-oauth-perl 0.33-1 (bug #1144854)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42818761/
 	NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-c8rm-g5cm-4pf5
 	NOTE: Fixed by: https://github.com/vurtdev/Net-OAuth/commit/c467adf45c8d77ac4b92ad78b3eebf949252ba7f
-CVE-2026-75589
+CVE-2026-75589 (Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256  ...)
 	- libnet-oauth-perl 0.33-1 (bug #1144855)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42818763/
 	NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-g8xr-69p3-gw56
@@ -2148,7 +2736,7 @@ CVE-2025-11729 (The PPWP: Password Protect Pages, Posts & Full or Partial Conten
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15571 (A flaw was found in the legacy client-initiated account-linking endpoi ...)
 	- keycloak <itp> (bug #1088287)
-CVE-2026-75900
+CVE-2026-75900 (An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_C ...)
 	- swtpm <unfixed> (bug #1144810)
 	NOTE: https://github.com/stefanberger/swtpm/pull/1155
 	NOTE: Fixed by: https://github.com/stefanberger/swtpm/commit/dc5f5ee3d8261a4d9814ad5da69164a118822401 (master)
@@ -2355,6 +2943,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet len
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517490
 	TODO: check, Red Hat bugzilla entry (only source) contains no information
 CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2368,6 +2957,7 @@ CVE-2026-74988 (Internally found bugs present in Thunderbird ESR 153.0 and Thund
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
 CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2384,6 +2974,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine component. This vulnerab
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
 CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This vulnerab ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2409,6 +3000,7 @@ CVE-2026-74977 (Integer overflow in the Graphics component. This vulnerability w
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
 CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2419,6 +3011,7 @@ CVE-2026-74975 (Spoofing issue in the Downloads component in Firefox for Android
 	- firefox <not-affected> (Only affects Firefox on Android)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
 CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. This vu ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2426,6 +3019,7 @@ CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. T
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
 CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This vulnera ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2433,6 +3027,7 @@ CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This v
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
 CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component. This  ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2440,6 +3035,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component.
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
 CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling componen ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2450,6 +3046,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics component. This vulnerabili
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
 CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This vulnerabi ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2460,6 +3057,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics: WebRender component. This
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
 CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback component. This ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2470,6 +3068,7 @@ CVE-2026-74966 (Information disclosure in the Form Autofill component. This vuln
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
 CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vulnerab ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2477,6 +3076,7 @@ CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vu
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
 CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability was fix ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2484,6 +3084,7 @@ CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability w
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
 CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component. This v ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2491,6 +3092,7 @@ CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component.
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
 CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. This vulner ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2501,6 +3103,7 @@ CVE-2026-74961 (Side-channel in the Web Audio component. This vulnerability was
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
 CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulnerabilit ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2508,6 +3111,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulner
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
 CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This vulnerabil ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2518,6 +3122,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC component. This vulnerabili
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
 CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This vulnerability w ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2534,6 +3139,7 @@ CVE-2026-74954 (Information disclosure due to side-channel in the Storage: Cache
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
 CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. This vulner ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2550,6 +3156,7 @@ CVE-2026-74950 (Privilege escalation in the Downloads API component. This vulner
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
 CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canvas2D c ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2557,6 +3164,7 @@ CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canv
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
 CVE-2026-74948 (Information disclosure in the Graphics component. This vulnerability w ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2567,6 +3175,7 @@ CVE-2026-74947 (Privilege escalation due to invalid pointer in the Graphics comp
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
 CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2574,6 +3183,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
 CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vulnerabi ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2581,6 +3191,7 @@ CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vul
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
 CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2588,6 +3199,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
 CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnerability ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2595,6 +3207,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnera
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
 CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. This vul ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2602,6 +3215,7 @@ CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. Th
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
 CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. This vuln ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2609,6 +3223,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. Thi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
 CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerability was ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2616,6 +3231,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerabili
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
 CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2629,6 +3245,7 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC component. This vulnerabili
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
 CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2636,6 +3253,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vu
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
 CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vulnerabil ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -2643,6 +3261,7 @@ CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vuln
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
 CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. This vuln ...)
+	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
@@ -5002,7 +5621,8 @@ CVE-2026-74240 (A flaw was found in Red Hat Quay's JWT (JSON Web Token) validati
 	NOT-FOR-US: Red Hat Quay
 CVE-2026-73683 (Laravel Socialite's Facebook provider contains an authentication bypas ...)
 	NOT-FOR-US: Laravel Socialite's Facebook provider
-CVE-2026-73682 (Semaphore versions prior to 2.18.20 contain an OS command injection (a ...)
+CVE-2026-73682
+	REJECTED
 	NOT-FOR-US: Semaphore UI
 CVE-2026-73680 (Cockpit CMS 2.14.0 and prior contains a command injection vulnerabilit ...)
 	NOT-FOR-US: Cockpit CMS
@@ -27864,7 +28484,7 @@ CVE-2026-48702 (Rekor is a software supply chain transparency log. Starting in v
 	NOTE: Fixed by: https://github.com/sigstore/rekor/commit/759b98e2a7c39ea9779b6a51299c5f0f987f8802 (v1.5.2)
 CVE-2026-50540 (Kata Containers is an open source project focusing on a standard imple ...)
 	NOT-FOR-US: Kata Containers
-CVE-2026-50149
+CVE-2026-50149 (Contour is a Kubernetes ingress controller using Envoy proxy. In versi ...)
 	NOT-FOR-US: Contour
 CVE-2026-47701
 	NOT-FOR-US: OpenTelemetry Operator
@@ -43568,7 +44188,7 @@ CVE-2026-60090 (PraisonAI before 4.6.78 fails to validate the caller-controlled
 	NOT-FOR-US: PraisonAI
 CVE-2026-60088 (PraisonAI before 4.6.78 fails to validate file path references in cust ...)
 	NOT-FOR-US: PraisonAI
-CVE-2026-57828 (Joomla Extension - phoca.cz - Authenticated file upload in RSFiles com ...)
+CVE-2026-57828 (Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downl ...)
 	NOT-FOR-US: Joomla
 CVE-2026-57827 (Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFil ...)
 	NOT-FOR-US: Joomla
@@ -46665,32 +47285,32 @@ CVE-2026-55827 (FreeRDP is a free implementation of the Remote Desktop Protocol.
 	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c495-h83v-3prp
-CVE-2026-55564
+CVE-2026-55564 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.27.0+dfsg-1
 	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6xmj-pr98-cx4c
-CVE-2026-55648
+CVE-2026-55648 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.27.0+dfsg-1
 	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5c5v-f78v-h2f6
-CVE-2026-55194
+CVE-2026-55194 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.27.0+dfsg-1
 	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9gxm-3mf5-f5cx
-CVE-2026-55193
+CVE-2026-55193 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.27.0+dfsg-1
 	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7rp4-66mc-j9vx
-CVE-2026-55192
+CVE-2026-55192 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.27.0+dfsg-1
 	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mmf-qh4f-frm6
-CVE-2026-55191
+CVE-2026-55191 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.27.0+dfsg-1
 	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
@@ -73953,7 +74573,7 @@ CVE-2026-8594 (Text::LineFold versions through 2019.001 for Perl duplicate the o
 	[bullseye] - libunicode-linebreak-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40542383/
 	NOTE: Patch: https://security.metacpan.org/patches/U/Unicode-LineBreak/2019.001/CVE-2026-8594-r1.patch
-CVE-2026-48711
+CVE-2026-48711 (SSHFS is a network filesystem client for connecting to SSH servers. Fr ...)
 	- sshfs-fuse 3.7.3-1.2 (bug #1138293)
 	[trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
 	[bookworm] - sshfs-fuse 3.7.3-1.2~deb12u1
@@ -73962,7 +74582,7 @@ CVE-2026-48711
 	NOTE: https://github.com/libfuse/sshfs/security/advisories/GHSA-mm85-q63v-4476
 	NOTE: https://github.com/libfuse/sshfs/pull/362
 	NOTE: Fixed by: https://github.com/libfuse/sshfs/commit/6678accb85ea4aec15dae9961b92af8d12501a66 (sshfs-3.7.6)
-CVE-2026-47187
+CVE-2026-47187 (SSHFS is a network filesystem client for connecting to SSH servers. Pr ...)
 	- sshfs-fuse 3.7.3-1.2 (bug #1138293)
 	[trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
 	[bookworm] - sshfs-fuse 3.7.3-1.2~deb12u1
@@ -84640,7 +85260,7 @@ CVE-2026-8587 (Use after free in Extensions in Google Chrome on Mac prior to 148
 	{DSA-6273-1}
 	- chromium 148.0.7778.167-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-43961
+CVE-2026-43961 (A flaw was found in Vim's netrw plugin. A crafted filename containing  ...)
 	- vim 2:9.2.0524-1 (bug #1136828)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/05/14/7
 	NOTE: https://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3
@@ -138691,7 +139311,7 @@ CVE-2020-37118 (P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request for
 	NOT-FOR-US: P5
 CVE-2020-37117 (jizhiCMS 1.6.7 contains a file download vulnerability in the admin plu ...)
 	NOT-FOR-US: jizhiCMS
-CVE-2026-21727 (--- title: Cross-Tenant Legacy Correlation Disclosure and Deletion dra ...)
+CVE-2026-21727 (A cross-tenant isolation vulnerability was found in Grafana\u2019s Cor ...)
 	- grafana <removed>
 CVE-2026-25585 (iccDEV provides a set of libraries and tools that allow for the intera ...)
 	NOT-FOR-US: iccDEV
@@ -579373,7 +579993,7 @@ CVE-2021-26889 (Windows Update Stack Elevation of Privilege Vulnerability)
 	NOT-FOR-US: Microsoft
 CVE-2021-26888
 	RESERVED
-CVE-2021-26887 (<p>An elevation of privilege vulnerability exists in Microsoft Windows ...)
+CVE-2021-26887 (An elevation of privilege vulnerability exists in Microsoft Windows wh ...)
 	NOT-FOR-US: Microsoft
 CVE-2021-26886 (User Profile Service Denial of Service Vulnerability)
 	NOT-FOR-US: Microsoft
@@ -579387,7 +580007,7 @@ CVE-2021-26882 (Remote Access API Elevation of Privilege Vulnerability)
 	NOT-FOR-US: Microsoft
 CVE-2021-26881 (Microsoft Windows Media Foundation Remote Code Execution Vulnerability)
 	NOT-FOR-US: Microsoft
-CVE-2021-26880 (Storage Spaces Controller Elevation of Privilege Vulnerability)
+CVE-2021-26880 (Windows Storage Spaces Controller Elevation of Privilege Vulnerability)
 	NOT-FOR-US: Microsoft
 CVE-2021-26879 (Windows Network Address Translation (NAT) Denial of Service Vulnerabil ...)
 	NOT-FOR-US: Microsoft



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ccc60041fdc5e152420ec0f74e6c37a8dd694107

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ccc60041fdc5e152420ec0f74e6c37a8dd694107
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/59c99df5/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list