[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 21 20:13:54 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
dce3666d by security tracker role at 2026-08-21T19:13:47+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,13 +1,659 @@
-CVE-2026-74583 [net/sched: cls_route: fix fastmap use-after-free on filter]
+CVE-2026-9324
+ REJECTED
+CVE-2026-9321
+ REJECTED
+CVE-2026-9244
+ REJECTED
+CVE-2026-9012
+ REJECTED
+CVE-2026-77815 (to_abs_path in scripts/iib/tool.py normalised the requested path with ...)
+ TODO: check
+CVE-2026-77814 (is_path_trusted in scripts/iib/api.py compares the requested path agai ...)
+ TODO: check
+CVE-2026-77812 (DJI drones transmit DUML (DJI Universal Markup Language) protocol mess ...)
+ TODO: check
+CVE-2026-77806 (SPIP before 4.4.21 allows unauthenticated remote attackers to execute ...)
+ TODO: check
+CVE-2026-77795 (A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. ...)
+ TODO: check
+CVE-2026-77780 (Authorization Bypass Through User-Controlled Key in the transaction sa ...)
+ TODO: check
+CVE-2026-77776 (Headroom's LLM proxy derives the memory owner from the x-headroom-user ...)
+ TODO: check
+CVE-2026-77775 (Headroom's LLM proxy lets a client choose the upstream destination wit ...)
+ TODO: check
+CVE-2026-77769 (The report.list procedure in packages/trpc/src/routers/report.ts accep ...)
+ TODO: check
+CVE-2026-77768 (The report.get procedure in packages/trpc/src/routers/report.ts accept ...)
+ TODO: check
+CVE-2026-77767 (Reconmap's API applies a fallback authorization policy in apps/api/app ...)
+ TODO: check
+CVE-2026-77763 (The filestore backend in pkg/object/file.go, used for file:// stores a ...)
+ TODO: check
+CVE-2026-77761 (A parser state isolation vulnerability in misp-stix could cause data f ...)
+ TODO: check
+CVE-2026-77759 (Authorization Bypass Through User-Controlled Key in the transaction AP ...)
+ TODO: check
+CVE-2026-77755 (A denial-of-service vulnerability was identified in misp-stix when pro ...)
+ TODO: check
+CVE-2026-77751 (A path traversal vulnerability existed in the handling of MISP object ...)
+ TODO: check
+CVE-2026-77710 (A vulnerability in misp-stix could allow a crafted STIX document to in ...)
+ TODO: check
+CVE-2026-77686 (A weakness has been identified in Dolibarr up to 23.0.4. This affects ...)
+ TODO: check
+CVE-2026-77683 (A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affect ...)
+ TODO: check
+CVE-2026-77681 (A vulnerability was identified in CodeAstro Online Job Portal 1.0. Aff ...)
+ TODO: check
+CVE-2026-77651 (The arrayref crate 0.3.10 for Rust can trigger execution of malicious ...)
+ TODO: check
+CVE-2026-77650 (The append-only-vec crate 0.1.9 for Rust can trigger execution of mali ...)
+ TODO: check
+CVE-2026-77649 (The internment crate 0.8.7 for Rust can trigger execution of malicious ...)
+ TODO: check
+CVE-2026-77646 (AServer-Side Request Forgery (SSRF) vulnerability has beenreported in ...)
+ TODO: check
+CVE-2026-77645 (A critical remote code execution (RCE) vulnerability has been reported ...)
+ TODO: check
+CVE-2026-77644 (A critical bypass access control vulnerability has been reported in PT ...)
+ TODO: check
+CVE-2026-77392 (A weakness has been identified in SourceCodester Dynamic Input Field G ...)
+ TODO: check
+CVE-2026-77391 (A security flaw has been discovered in SourceCodester Dynamic Input Fi ...)
+ TODO: check
+CVE-2026-77264 (The Automation Web Platform \u2013 Notifications and OTP for WooCommer ...)
+ TODO: check
+CVE-2026-77237 (Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS- ...)
+ TODO: check
+CVE-2026-77236 (Missing minimum size validation in secure context allocation in FreeRT ...)
+ TODO: check
+CVE-2026-77235 (Missing privilege verification in the secure context cleanup handler i ...)
+ TODO: check
+CVE-2026-77234 (Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow ...)
+ TODO: check
+CVE-2026-77151 (A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affe ...)
+ TODO: check
+CVE-2026-77113 (Path traversal in apport-unpack in Canonical Apport before2.36.0,2.34. ...)
+ TODO: check
+CVE-2026-77087 (Paperclip before 0.3.1 in default local_trusted mode fails to validate ...)
+ TODO: check
+CVE-2026-77086 (SiYuan before v3.7.4 fails to validate the packageName parameter in Ba ...)
+ TODO: check
+CVE-2026-77029 (Joomla Extension - yootheme.com - Missing CSRF tokens on front-end sta ...)
+ TODO: check
+CVE-2026-77028 (Joomla Extension - yootheme.com - Reflected XSS and open redirect via ...)
+ TODO: check
+CVE-2026-76613 (Joomla Extension - yootheme.com - Authenticated, privileged SQL inject ...)
+ TODO: check
+CVE-2026-76612 (Joomla Extension - yootheme.com - Unauthenticated stored XSS via user- ...)
+ TODO: check
+CVE-2026-76611 (Joomla Extension - yootheme.com - Unauthenticated arbitrary directory ...)
+ TODO: check
+CVE-2026-76158 (External Control of File Name or Path in the upload API endpoint of Da ...)
+ TODO: check
+CVE-2026-76157 (Missing authentication for a critical function in the upload API endpo ...)
+ TODO: check
+CVE-2026-76156 (OS command injection in the api endpoint of Datiphy Data Management Ce ...)
+ TODO: check
+CVE-2026-76155 (Use of default credentials in Datiphy Data Management Center from v8.3 ...)
+ TODO: check
+CVE-2026-76137 (Missing authentication for critical function vulnerability exists in V ...)
+ TODO: check
+CVE-2026-76131 (Use of hard-coded credentials issue exists in VOCALOID6 , which may al ...)
+ TODO: check
+CVE-2026-76023 (Improper resource control in Linux Toolkit Theming in Google Chrome pr ...)
+ TODO: check
+CVE-2026-76022 (Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 al ...)
+ TODO: check
+CVE-2026-76021 (Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed ...)
+ TODO: check
+CVE-2026-76020 (Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed ...)
+ TODO: check
+CVE-2026-76019 (Incorrect authorization in Workers in Google Chrome prior to 151.0.792 ...)
+ TODO: check
+CVE-2026-76018 (Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 ...)
+ TODO: check
+CVE-2026-76017 (Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 ...)
+ TODO: check
+CVE-2026-75946 (A potential security vulnerability has been identified in the OMEN Gam ...)
+ TODO: check
+CVE-2026-75933 (Jet Admin allows an authenticated attacker to inject JavaScript via th ...)
+ TODO: check
+CVE-2026-75932 (Jet Admin allows an attacker to create a malicious app and connect it ...)
+ TODO: check
+CVE-2026-75928 (The Brushfire platform's video content streaming application (https:// ...)
+ TODO: check
+CVE-2026-75910 (Incorrect privilege assignment in the ClickHouse connector deployment ...)
+ TODO: check
+CVE-2026-75796 (The AI Engine WordPress plugin before 3.6.1 does not verify that the ...)
+ TODO: check
+CVE-2026-75501 (A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) ...)
+ TODO: check
+CVE-2026-75484 (Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerabi ...)
+ TODO: check
+CVE-2026-75115 (Joomla Extension - yootheme.com - Authenticated, privileged arbitrary ...)
+ TODO: check
+CVE-2026-74866 (@fastify/busboy is a multipart form-data parser for Node.js. Its multi ...)
+ TODO: check
+CVE-2026-74836 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
+ TODO: check
+CVE-2026-73537 (Cross-site scripting vulnerability exists in Miraikan Assist App. If t ...)
+ TODO: check
+CVE-2026-73267 (A flaw was found in the clusterclaims-controller component of multiclu ...)
+ TODO: check
+CVE-2026-73137 (A flaw was found in the multicloud-operators-subscription component of ...)
+ TODO: check
+CVE-2026-73040 (Dockge validates a stack name only on the write path. In backend/stack ...)
+ TODO: check
+CVE-2026-72861 (The github-issue-bot templates in appwrite/templates verify the GitHub ...)
+ TODO: check
+CVE-2026-72860 (The POST /api/provider-nodes/validate route in 9router takes a caller- ...)
+ TODO: check
+CVE-2026-72858
+ REJECTED
+CVE-2026-72848 (SitemapLoader.parse_sitemap in langchain_community/document_loaders/si ...)
+ TODO: check
+CVE-2026-72846 (Lightdash stores the webhook URL supplied with a scheduled delivery an ...)
+ TODO: check
+CVE-2026-72843 (The customer update route in EverShop is declared with "access": "publ ...)
+ TODO: check
+CVE-2026-72818 (The URLS regular expression in nltk/tokenize/casual.py, compiled into ...)
+ TODO: check
+CVE-2026-71862 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
+ TODO: check
+CVE-2026-71494 (Infracost provides cloud cost intelligence for engineers, AI coding ag ...)
+ TODO: check
+CVE-2026-71493 (Infracost provides cloud cost intelligence for engineers, AI coding ag ...)
+ TODO: check
+CVE-2026-71485 (Centrifugo is an open-source scalable real-time messaging server. Prio ...)
+ TODO: check
+CVE-2026-70656 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
+ TODO: check
+CVE-2026-70654 (libvips is a fast image processing library with low memory needs. Prio ...)
+ TODO: check
+CVE-2026-70653 (libvips is a fast image processing library with low memory needs. Prio ...)
+ TODO: check
+CVE-2026-70652 (libvips is a fast image processing library with low memory needs. Prio ...)
+ TODO: check
+CVE-2026-70651 (libvips is a fast image processing library with low memory needs. Prio ...)
+ TODO: check
+CVE-2026-70105 (Improper input validation in Microsoft Office Word allows an unauthori ...)
+ TODO: check
+CVE-2026-69855 (Server-side request forgery (ssrf) in Microsoft Copilot in Azure allow ...)
+ TODO: check
+CVE-2026-69851 (Server-side request forgery (ssrf) in Azure Active Directory allows an ...)
+ TODO: check
+CVE-2026-69836 (Deserialization of untrusted data in Microsoft Entra ID allows an unau ...)
+ TODO: check
+CVE-2026-69701
+ REJECTED
+CVE-2026-69558 (Authorization bypass through user-controlled key in Microsoft Partner ...)
+ TODO: check
+CVE-2026-69555 (Incorrect authorization in Azure Arc allows an unauthorized attacker t ...)
+ TODO: check
+CVE-2026-69543 (Server-side request forgery (ssrf) in Azure Virtual Machines allows an ...)
+ TODO: check
+CVE-2026-69519 (Observable response discrepancy in Azure Stack HCI allows an unauthori ...)
+ TODO: check
+CVE-2026-69502 (Server-side request forgery (ssrf) in Azure SQL Database allows an una ...)
+ TODO: check
+CVE-2026-69419 (Integer overflow or wraparound in Azure Data Manager for Energy allows ...)
+ TODO: check
+CVE-2026-69400 (Improper limitation of a pathname to a restricted directory ('path tra ...)
+ TODO: check
+CVE-2026-69242 (libvips is a fast image processing library with low memory needs. Prio ...)
+ TODO: check
+CVE-2026-69099
+ REJECTED
+CVE-2026-68921 (DiceBear is an avatar library for designers and developers. Prior to 9 ...)
+ TODO: check
+CVE-2026-68789 (Improper neutralization of special elements used in an sql command ('s ...)
+ TODO: check
+CVE-2026-68782 (Improper neutralization of special elements used in an sql command ('s ...)
+ TODO: check
+CVE-2026-68745 (Certificate validation failures in SAML authentication in Apache Cloud ...)
+ TODO: check
+CVE-2026-67567 (A flaw was found in the multicloud-operators-subscription component. T ...)
+ TODO: check
+CVE-2026-67448 (Mailpit is an email testing tool and API for developers. From 1.29.0 u ...)
+ TODO: check
+CVE-2026-67447 (Mailpit is an email testing tool and API for developers. From 1.30.0 u ...)
+ TODO: check
+CVE-2026-67446 (Mailpit is an email testing tool and API for developers. Prior to 1.30 ...)
+ TODO: check
+CVE-2026-67445 (Mailpit is an email testing tool and API for developers. Prior to 1.30 ...)
+ TODO: check
+CVE-2026-66722 (Improper authorization for CRUD operations on Project Roles and Projec ...)
+ TODO: check
+CVE-2026-66721 (Missing authorization issue for domain admins in CloudStack's host tag ...)
+ TODO: check
+CVE-2026-66309 (Improper access control in Azure SQL Database allows an authorized att ...)
+ TODO: check
+CVE-2026-65816 (Use of incorrectly-resolved name or reference in Azure Arc allows an u ...)
+ TODO: check
+CVE-2026-65801 (Server-side request forgery (ssrf) in Microsoft Exchange Online allows ...)
+ TODO: check
+CVE-2026-65770 (Improper neutralization of argument delimiters in a command ('argument ...)
+ TODO: check
+CVE-2026-65645 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3. ...)
+ TODO: check
+CVE-2026-65644 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3. ...)
+ TODO: check
+CVE-2026-65613 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
+ TODO: check
+CVE-2026-64773 (An attacker that can reach a container's published TCP port may be abl ...)
+ TODO: check
+CVE-2026-63726
+ REJECTED
+CVE-2026-63723
+ REJECTED
+CVE-2026-63509 (Relative path traversal in Microsoft Fabric allows an authorized attac ...)
+ TODO: check
+CVE-2026-63466 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
+ TODO: check
+CVE-2026-63462 (Unleash is an open-source feature management platform. Prior to 7.5.2, ...)
+ TODO: check
+CVE-2026-63046 (Improper Neutralization of Argument Delimiters in a Command ('Argument ...)
+ TODO: check
+CVE-2026-63004 (Unleash is an open-source feature management platform. Prior to 7.5.2, ...)
+ TODO: check
+CVE-2026-62945 (TREK is a collaborative travel planner. Prior to 3.1.3, TREK file uplo ...)
+ TODO: check
+CVE-2026-62834 (Improper verification of cryptographic signature in Azure Data Factory ...)
+ TODO: check
+CVE-2026-62677 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
+ TODO: check
+CVE-2026-62676 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
+ TODO: check
+CVE-2026-62675 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
+ TODO: check
+CVE-2026-62674 (Omnigent is an open-source AI agent framework and meta-harness for orc ...)
+ TODO: check
+CVE-2026-62440 (Improper Access Control vulnerability in Apache CloudStack's Kubernete ...)
+ TODO: check
+CVE-2026-61422 (Authenticated pre-validation SSRF vulnerability in Apache CloudStack's ...)
+ TODO: check
+CVE-2026-61400 (Improper Neutralization of Special Elements used in a Command ('Comman ...)
+ TODO: check
+CVE-2026-61399 (Improper Encoding or Escaping of Output vulnerability in Apache CloudS ...)
+ TODO: check
+CVE-2026-61398 (Improper Encoding or Escaping of Output vulnerability in Apache CloudS ...)
+ TODO: check
+CVE-2026-61397 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
+ TODO: check
+CVE-2026-59799 (Improper Privilege Management vulnerability in Apache CloudStack's Two ...)
+ TODO: check
+CVE-2026-59780 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
+ TODO: check
+CVE-2026-59657 (Cleartext Storage of Sensitive Information vulnerability in Apache Clo ...)
+ TODO: check
+CVE-2026-59655 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
+ TODO: check
+CVE-2026-59654 (Missing Release of Resource after Effective Lifetime vulnerability in ...)
+ TODO: check
+CVE-2026-59323 (An application using Micrometer Tracing with W3C baggage propagation i ...)
+ TODO: check
+CVE-2026-59318 (In Spring AI's tool calling support, the per-request tool list is adve ...)
+ TODO: check
+CVE-2026-59308 (In Spring AI's Semantic Cache support, the context hash used to isolat ...)
+ TODO: check
+CVE-2026-59296 (Using untrusted, non-normalized input as-is for metrics data (such as ...)
+ TODO: check
+CVE-2026-59279 (The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) ...)
+ TODO: check
+CVE-2026-59085 (Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack' ...)
+ TODO: check
+CVE-2026-57835
+ REJECTED
+CVE-2026-56875
+ REJECTED
+CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
+ TODO: check
+CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
+ TODO: check
+CVE-2026-55850 (Element Web is a Matrix web client built using the Matrix React SDK. P ...)
+ TODO: check
+CVE-2026-55769 (CloudNativePG is a platform designed to manage PostgreSQL databases wi ...)
+ TODO: check
+CVE-2026-55765 (CloudNativePG is a platform designed to manage PostgreSQL databases wi ...)
+ TODO: check
+CVE-2026-55491 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, Bi ...)
+ TODO: check
+CVE-2026-55489 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, Bi ...)
+ TODO: check
+CVE-2026-55241 (Checkmate is an open-source, self-hosted tool designed to track and mo ...)
+ TODO: check
+CVE-2026-55015 (Uncontrolled search path element in Windows Remote Help allows an auth ...)
+ TODO: check
+CVE-2026-55013 (Uncontrolled search path element in Windows Remote Help Defense allows ...)
+ TODO: check
+CVE-2026-54789 (mod_auth_openidc is an OpenID Certified authentication and authorizati ...)
+ TODO: check
+CVE-2026-54682 (DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2 ...)
+ TODO: check
+CVE-2026-54681 (DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2 ...)
+ TODO: check
+CVE-2026-54509 (TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GE ...)
+ TODO: check
+CVE-2026-54508 (TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates ...)
+ TODO: check
+CVE-2026-54505 (TREK is a collaborative travel planner. Prior to 3.1.0, when the Journ ...)
+ TODO: check
+CVE-2026-54389 (Ghidra before 12.1.3 contains an uncontrolled resource consumption vul ...)
+ TODO: check
+CVE-2026-54134 (OctoPrint provides a web interface for controlling consumer 3D printer ...)
+ TODO: check
+CVE-2026-54073 (VeraCrypt provides disk encryption with strong security based on TrueC ...)
+ TODO: check
+CVE-2026-54071 (BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's ve ...)
+ TODO: check
+CVE-2026-53991
+ REJECTED
+CVE-2026-53974
+ REJECTED
+CVE-2026-53804 (OTRS Community Edition contains an authenticated OS command injection ...)
+ TODO: check
+CVE-2026-53762 (VeraCrypt provides disk encryption with strong security based on TrueC ...)
+ TODO: check
+CVE-2026-52021 (An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remo ...)
+ TODO: check
+CVE-2026-50278 (iccDEV provides a set of libraries and tools for working with ICC colo ...)
+ TODO: check
+CVE-2026-50222 (Missing Authorization, Exposure of Sensitive Information to an Unautho ...)
+ TODO: check
+CVE-2026-50192 (Kerberos Agent is an open source video (surveillance) management agent ...)
+ TODO: check
+CVE-2026-50112 (SSRF via Metalink Mirror URL Resolution: An authenticated tenant can ...)
+ TODO: check
+CVE-2026-49436 (LinkAce is a self-hosted archive to collect website links. Prior to ve ...)
+ TODO: check
+CVE-2026-49245 (SFTPGo is an open source, event-driven file transfer solution. From 2. ...)
+ TODO: check
+CVE-2026-49244 (SFTPGo is an open source, event-driven file transfer solution. From 2. ...)
+ TODO: check
+CVE-2026-49217 (Mailu is a mail server as a set of Docker images. Prior to version 202 ...)
+ TODO: check
+CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function builds the ex ...)
+ TODO: check
+CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
+ TODO: check
+CVE-2026-47827 (Command Injection in BOSH CLI tool on windows in Cloud Foundry allows ...)
+ TODO: check
+CVE-2026-47359 (Improper Neutralization of Special Elements used in an OS Command ('OS ...)
+ TODO: check
+CVE-2026-47080 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
+ TODO: check
+CVE-2026-47079 (Inappropriate Encoding for Output Context vulnerability in joshnuss xm ...)
+ TODO: check
+CVE-2026-46682 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, Bi ...)
+ TODO: check
+CVE-2026-46355 (BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, Bi ...)
+ TODO: check
+CVE-2026-45202 (Software installed and run as a non-privileged user may conduct GPU sy ...)
+ TODO: check
+CVE-2026-45201 (Software installed and run as a non-privileged user may conduct improp ...)
+ TODO: check
+CVE-2026-45199 (Kernel software installed and running inside a Guest VM may post impro ...)
+ TODO: check
+CVE-2026-43798 (A single crafted SSH message gives an unauthenticated network attacker ...)
+ TODO: check
+CVE-2026-43679 (This issue was addressed with improved permissions checking. This issu ...)
+ TODO: check
+CVE-2026-41451 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a ...)
+ TODO: check
+CVE-2026-41450 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a ...)
+ TODO: check
+CVE-2026-41449 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a ...)
+ TODO: check
+CVE-2026-39909 (llama.cpp before b8585 contains a use-after-free vulnerability in the ...)
+ TODO: check
+CVE-2026-35163 (OctoPrint provides a web interface for controlling consumer 3D printer ...)
+ TODO: check
+CVE-2026-27875 (Cleartext Storage of Sensitive Information in Memory vulnerability in ...)
+ TODO: check
+CVE-2026-22681 (OpenViking before 0.3.4contains a server-side request forgery vulnerab ...)
+ TODO: check
+CVE-2026-20679 (The issue was addressed with improved checks. This issue is fixed in m ...)
+ TODO: check
+CVE-2026-19848 (The ProfilePress WordPress plugin before 4.17.1 does not strip shortco ...)
+ TODO: check
+CVE-2026-19783 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-19755 (NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw di ...)
+ TODO: check
+CVE-2026-19449 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in c ...)
+ TODO: check
+CVE-2026-19448 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruptio ...)
+ TODO: check
+CVE-2026-19446 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthen ...)
+ TODO: check
+CVE-2026-19442 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation ...)
+ TODO: check
+CVE-2026-19441 (Missing authentication for critical function vulnerability in IKAS Tec ...)
+ TODO: check
+CVE-2026-19437 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-19435 (The Duplicate Post WordPress plugin before 1.5.6 does not check the us ...)
+ TODO: check
+CVE-2026-19085 (The Duplicate Post WordPress plugin before 1.5.6 does not check that a ...)
+ TODO: check
+CVE-2026-18842 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-18840 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-18835 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
+ TODO: check
+CVE-2026-18832 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-18828 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-18824 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
+ TODO: check
+CVE-2026-18822 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-18781 (The Drag and Drop Multiple File Upload for Contact Form 7 WordPress pl ...)
+ TODO: check
+CVE-2026-18716 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
+ TODO: check
+CVE-2026-18670 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-18420 (Improper input validation in the Time Series Visual Builder (TSVB) plu ...)
+ TODO: check
+CVE-2026-18409 (The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Sit ...)
+ TODO: check
+CVE-2026-18356 (The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does n ...)
+ TODO: check
+CVE-2026-17559 (The Passster WordPress plugin before 4.3.9 does not correctly match it ...)
+ TODO: check
+CVE-2026-17436 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17425 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17424 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17423 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17422 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-17252 (A stack-based out-of-bounds write vulnerability exists in the login re ...)
+ TODO: check
+CVE-2026-17251 (A NULL pointer dereference vulnerability exists in the HTTP request pa ...)
+ TODO: check
+CVE-2026-17250 (A stack-based buffer overflow vulnerability exists in the firmware upd ...)
+ TODO: check
+CVE-2026-17195 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-17171 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-17170 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17168 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
+ TODO: check
+CVE-2026-17165 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17163 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17160 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17159 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17157 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17152 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17145 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17142 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17141 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17138 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17136 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17124 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-17122 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17121 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17120 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17118 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17060 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17040 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17024 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17009 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-17007 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-17006 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17003 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-17000 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-16997 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16996 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16991 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16989 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16980 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16973 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16972 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-16964 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-16962 (The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify ...)
+ TODO: check
+CVE-2026-16959 (The Media Library Assistant WordPress plugin before 3.40 does not vali ...)
+ TODO: check
+CVE-2026-16958 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
+ TODO: check
+CVE-2026-16952 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16951 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local auth ...)
+ TODO: check
+CVE-2026-16946 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16945 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16944 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16943 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16937 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16936 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16935 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16934 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16650 (The Charitable WordPress plugin before 1.8.12 does not verify the auth ...)
+ TODO: check
+CVE-2026-16577 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Wo ...)
+ TODO: check
+CVE-2026-16576 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Wo ...)
+ TODO: check
+CVE-2026-16575 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Wo ...)
+ TODO: check
+CVE-2026-16520 (Improper input validation and Exposure of sensitive information throug ...)
+ TODO: check
+CVE-2026-16323 (Execution after redirect (EAR) vulnerability in FuyaWeb Internet and I ...)
+ TODO: check
+CVE-2026-15580 (vault token disclosure via unvalidated postMessage vulnerability in N- ...)
+ TODO: check
+CVE-2026-15576 (Improper authentication in the agent receiver of Checkmk <2.5.0p10 all ...)
+ TODO: check
+CVE-2026-15150 (The myCred WordPress plugin before 3.2.5 does not verify that the rece ...)
+ TODO: check
+CVE-2026-15046 (The LitExtension WordPress plugin through 1.2.5 does not verify a nonc ...)
+ TODO: check
+CVE-2026-14601 (The Link Whisper Free WordPress plugin before 0.9.7 does not properly ...)
+ TODO: check
+CVE-2026-14325 (The Drag and Drop Multiple File Upload for Contact Form 7 WordPress pl ...)
+ TODO: check
+CVE-2026-14208 (Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in ...)
+ TODO: check
+CVE-2026-13736 (The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 do ...)
+ TODO: check
+CVE-2026-13176 (The Eventin WordPress plugin before 4.1.21 does not validate a user-su ...)
+ TODO: check
+CVE-2026-11938
+ REJECTED
+CVE-2026-11902
+ REJECTED
+CVE-2026-11830
+ REJECTED
+CVE-2026-11427
+ REJECTED
+CVE-2025-52182 (The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to con ...)
+ TODO: check
+CVE-2025-3127
+ REJECTED
+CVE-2025-2795
+ REJECTED
+CVE-2025-15671 (The Welcart e-Commerce WordPress plugin before 2.12.1 does not regener ...)
+ TODO: check
+CVE-2023-7344
+ REJECTED
+CVE-2023-7336
+ REJECTED
+CVE-2023-7310
+ REJECTED
+CVE-2021-4482
+ REJECTED
+CVE-2021-4476
+ REJECTED
+CVE-2021-4475
+ REJECTED
+CVE-2019-25725
+ REJECTED
+CVE-2019-25715
+ REJECTED
+CVE-2017-20232
+ REJECTED
+CVE-2026-74583 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/47d7f7051253bdc02b1d245d87e38f16d31a74df (7.2-rc7)
-CVE-2026-74582 [packet: use consistent hard_header_len in non-ring send paths]
+CVE-2026-74582 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/03390aa32e669cc4ecd7d34108e2e1afc13d689d (7.2-rc7)
-CVE-2026-74581 [net: ipv6: clear suppressed fib6 rule result]
+CVE-2026-74581 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.8-1
NOTE: https://git.kernel.org/linus/6aea62e433fe1b586202a5fee8b5807ce635e1d7 (7.2-rc6)
-CVE-2026-74580 [vhost: reset the vring metadata cache on vring reconfiguration]
+CVE-2026-74580 (In the Linux kernel, the following vulnerability has been resolved: v ...)
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/de845981da67a6b049080c87e605130b0c30adc5 (7.2-rc7)
CVE-2026-19685
@@ -1550,7 +2196,7 @@ CVE-2026-76216 (Vikunja through 2.4.0 contains a principal-type confusion vulner
NOT-FOR-US: Vikunja
CVE-2026-76215 (phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks befo ...)
NOT-FOR-US: phpMyFAQ
-CVE-2026-76214 (phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist th ...)
+CVE-2026-76214 (phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge ge ...)
NOT-FOR-US: phpMyFAQ
CVE-2026-76213 (phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two- ...)
NOT-FOR-US: phpMyFAQ
@@ -1558,7 +2204,7 @@ CVE-2026-76212 (phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the
NOT-FOR-US: phpMyFAQ
CVE-2026-76211 (phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT per ...)
NOT-FOR-US: phpMyFAQ
-CVE-2026-76210 (phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ answers ...)
+CVE-2026-76210 (phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers ...)
NOT-FOR-US: phpMyFAQ
CVE-2026-76209 (phpMyFAQ versions before v4.1.6 fail to validate the security.enableRe ...)
NOT-FOR-US: phpMyFAQ
@@ -1748,7 +2394,8 @@ CVE-2026-70422 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an
NOT-FOR-US: Dell / EMC
CVE-2026-70421 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
NOT-FOR-US: Dell / EMC
-CVE-2026-69159 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
+CVE-2026-69159
+ REJECTED
- freerdp3 3.29.0+dfsg-1
[trixie] - freerdp3 <no-dsa> (Minor issue)
- freerdp2 <removed>
@@ -4326,48 +4973,63 @@ CVE-2026-60589 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
- openjdk-8 8u504-ga-1
NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
CVE-2026-76034 (Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allo ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76036 (Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0. ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76033 (Inappropriate implementation in CORS in Google Chrome prior to 151.0.7 ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76037 (Link following in CredentialProvider in Google Chrome on on Windows pr ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76044 (Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76039 (Incorrect reference resolution in Core in Google Chrome on on Android ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76040 (Use after free in Browser in Google Chrome on on Mac prior to 151.0.79 ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76035 (Inappropriate implementation in Media in Google Chrome on on Mac prior ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76042 (Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7 ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76046 (Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0 ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76043 (Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 a ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76041 (Information leak in Skia in Google Chrome prior to 151.0.7922.169 allo ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76047 (Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76038 (Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76045 (Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allow ...)
+ {DSA-6455-1 DLA-4749-1}
- chromium 151.0.7922.169-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-75926 (Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permis ...)
@@ -4496,7 +5158,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet len
NOTE: Fixed by: https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
NOTE: Followup: https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4510,7 +5172,7 @@ CVE-2026-74988 (Internally found bugs present in Thunderbird ESR 153.0 and Thund
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4527,7 +5189,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine component. This vulnerab
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This vulnerab ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4553,7 +5215,7 @@ CVE-2026-74977 (Integer overflow in the Graphics component. This vulnerability w
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4564,7 +5226,7 @@ CVE-2026-74975 (Spoofing issue in the Downloads component in Firefox for Android
- firefox <not-affected> (Only affects Firefox on Android)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. This vu ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4572,7 +5234,7 @@ CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. T
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This vulnera ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4580,7 +5242,7 @@ CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This v
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component. This ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4588,7 +5250,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component.
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling componen ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4599,7 +5261,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics component. This vulnerabili
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This vulnerabi ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4610,7 +5272,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics: WebRender component. This
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback component. This ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4621,7 +5283,7 @@ CVE-2026-74966 (Information disclosure in the Form Autofill component. This vuln
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vulnerab ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4629,7 +5291,7 @@ CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vu
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability was fix ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4637,7 +5299,7 @@ CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability w
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component. This v ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4645,7 +5307,7 @@ CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component.
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. This vulner ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4656,7 +5318,7 @@ CVE-2026-74961 (Side-channel in the Web Audio component. This vulnerability was
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulnerabilit ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4664,7 +5326,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulner
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This vulnerabil ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4675,7 +5337,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC component. This vulnerabili
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This vulnerability w ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4692,7 +5354,7 @@ CVE-2026-74954 (Information disclosure due to side-channel in the Storage: Cache
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. This vulner ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4709,7 +5371,7 @@ CVE-2026-74950 (Privilege escalation in the Downloads API component. This vulner
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canvas2D c ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4717,7 +5379,7 @@ CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canv
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
CVE-2026-74948 (Information disclosure in the Graphics component. This vulnerability w ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4728,7 +5390,7 @@ CVE-2026-74947 (Privilege escalation due to invalid pointer in the Graphics comp
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4736,7 +5398,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vulnerabi ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4744,7 +5406,7 @@ CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vul
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4752,7 +5414,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnerability ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4760,7 +5422,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnera
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. This vul ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4768,7 +5430,7 @@ CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. Th
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. This vuln ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4776,7 +5438,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. Thi
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerability was ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4784,7 +5446,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerabili
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4798,7 +5460,7 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC component. This vulnerabili
- firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4806,7 +5468,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vu
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vulnerabil ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -4814,7 +5476,7 @@ CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vuln
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. This vuln ...)
- {DSA-6451-1}
+ {DSA-6451-1 DLA-4750-1}
- firefox 154.0-1
- firefox-esr 140.14.0esr-2
- thunderbird 1:140.14.0esr-1
@@ -6329,11 +6991,11 @@ CVE-2026-13700 (The WooMS WordPress plugin through 9.14 does not validate a user
NOT-FOR-US: WordPress plugin
CVE-2026-66801
NOT-FOR-US: Red Hat cluster-backup-operator
-CVE-2026-66800
+CVE-2026-66800 (Server-side request forgery (ssrf) in Azure Data Factory allows an una ...)
NOT-FOR-US: Red Hat cluster-backup-operator
CVE-2026-66798
NOT-FOR-US: Red Hat cluster-backup-operator
-CVE-2026-66797
+CVE-2026-66797 (Improper access control in CloudStack's annotation functionality allow ...)
NOT-FOR-US: Red Hat cluster-backup-operator
CVE-2026-18725
- open-iscsi <unfixed> (bug #1144935)
@@ -14137,7 +14799,7 @@ CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require network-level access con
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0106
NOTE: https://bugs.launchpad.net/ironic/+bug/2162821
NOTE: https://bugs.launchpad.net/ironic/+bug/2162818
-CVE-2026-77648 [OSSN-0105: OpenStack Glance legacy Tasks import bypasses image import URI filtering]
+CVE-2026-77648 (In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=imp ...)
- glance 2:32.0.0-3 (bug #1144212)
[trixie] - glance <no-dsa> (Minor issue)
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0105
@@ -15281,7 +15943,7 @@ CVE-2026-65797 (Numeric truncation error in Windows DNS allows an authorized att
NOT-FOR-US: Microsoft
CVE-2026-65796 (Heap-based buffer overflow in Windows iSCSI Target Service allows an u ...)
NOT-FOR-US: Microsoft
-CVE-2026-65795 (No cwe for this issue in Windows DNS allows an authorized attacker to ...)
+CVE-2026-65795 (Relative path traversal in Windows DNS allows an authorized attacker t ...)
NOT-FOR-US: Microsoft
CVE-2026-65794 (Buffer over-read in Windows SMB Client allows an unauthorized attacker ...)
NOT-FOR-US: Microsoft
@@ -17214,7 +17876,8 @@ CVE-2026-XXXX [RCE fixed in 4.4.21]
- spip 4.4.21+dfsg-1
[trixie] - spip 4.4.21+dfsg-0+deb13u1
NOTE: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html
-CVE-2026-77647 [RCE fixed in 4.4.20]
+CVE-2026-77647 (SPIP before 4.4.20 allows unauthenticated remote attackers to execute ...)
+ {DSA-6448-1}
- spip 4.4.20+dfsg-1
NOTE: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-20.html
CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in SQLite-b ...)
@@ -25091,12 +25754,12 @@ CVE-2026-XXXX [GHSA-p2v3-6wvc-cv3p: Arbitrary file write on host via image finge
[trixie] - incus 6.0.4-2+deb13u9
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-p2v3-6wvc-cv3p
NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-63343 [Arbitrary file read+write on host via metadata.yaml symlink in crafted image]
+CVE-2026-63343 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6407-1}
- incus 7.0.1-2
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-fmjx-5j3g-997p
NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-63125 [Arbitrary file write on host via backup.yaml symlink in crafted image]
+CVE-2026-63125 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6407-1}
- incus 7.0.1-2
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-6rqx-22hc-qm36
@@ -25106,22 +25769,22 @@ CVE-2026-XXXX [GHSA-m3j6-p3v3-qmjv: Container configuration newline injection th
[trixie] - incus 6.0.4-2+deb13u9
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-m3j6-p3v3-qmjv
NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62941 [Project restriction bypass via cross-project instance copy]
+CVE-2026-62941 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6407-1}
- incus 7.0.1-2
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-mq9x-prm8-3vpw
NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62940 [Project restriction bypass via instance migration config override]
+CVE-2026-62940 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6407-1}
- incus 7.0.1-2
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-qw5c-v953-38gw
NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62867 [Argument injection through storage volume block.create_options]
+CVE-2026-62867 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6407-1}
- incus 7.0.1-2
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-q7xw-r4w2-2wcm
NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-62313 [Project isolation restriction bypass by omitting security.idmap.isolated]
+CVE-2026-62313 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6407-1}
- incus 7.0.1-2
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-53cg-qvg7-m8vg
@@ -55592,31 +56255,38 @@ CVE-2026-XXXX [TROVE-2026-015]
[bookworm] - tor 0.4.9.11-0+deb12u1
[bullseye] - tor <end-of-life> (see DSA 5562)
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41261
-CVE-2026-77642 [TROVE-2026-019]
+CVE-2026-77642 (tor before 0.4.9.9 was prone to anout-of-bounds write when parsing a c ...)
+ {DSA-6372-1}
- tor 0.4.9.9-1
[bullseye] - tor <end-of-life> (see DSA 5562)
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41267
-CVE-2026-77641 [TROVE-2026-017]
+CVE-2026-77641 (tor before 0.4.9.9 was prone to aNULL write after free when sending a ...)
+ {DSA-6372-1}
- tor 0.4.9.9-1
[bullseye] - tor <end-of-life> (see DSA 5562)
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41263
-CVE-2026-77639 [TROVE-2026-022]
+CVE-2026-77639 (Tor before 0.4.9.9 was prone to acompression bomb bypass where an atta ...)
+ {DSA-6372-1}
- tor 0.4.9.9-1
[bullseye] - tor <end-of-life> (see DSA 5562)
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41275
-CVE-2026-77640 [TROVE-2026-021]
+CVE-2026-77640 (tor before 0.4.9.9 was prone to an infinite loop when decompressing a ...)
+ {DSA-6372-1}
- tor 0.4.9.9-1
[bullseye] - tor <end-of-life> (see DSA 5562)
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41274
-CVE-2026-77584 [TROVE-2026-025]
+CVE-2026-77584 (Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on ...)
+ {DSA-6372-1}
- tor 0.4.9.11-1
[bullseye] - tor <end-of-life> (see DSA 5562)
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41258 (private ATM)
-CVE-2026-77587 [TROVE-2026-026]
+CVE-2026-77587 (Tor before 0.4.9.11 is prone to a use-after-free (and potential double ...)
+ {DSA-6372-1}
- tor 0.4.9.11-1
[bullseye] - tor <end-of-life> (see DSA 5562)
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41306
-CVE-2026-77638
+CVE-2026-77638 (Tor before 0.4.9.11 is prone to a race condition where in just the rig ...)
+ {DSA-6372-1}
- tor 0.4.9.11-1
[bullseye] - tor <end-of-life> (see DSA 5562)
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41297
@@ -56903,21 +57573,21 @@ CVE-2021-47986 (Parse Server before 4.10.0 contains a supply chain vulnerability
NOT-FOR-US: Parse Server
CVE-2020-37256 (Grav before 1.6.30 contains a cross-site scripting vulnerability in th ...)
NOT-FOR-US: Grav CMS
-CVE-2026-48750
+CVE-2026-48750 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-73hr-m85f-64v9
NOTE: https://github.com/canonical/lxd/pull/18590
-CVE-2026-48751
+CVE-2026-48751 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv
NOTE: https://github.com/canonical/lxd/pull/18604
-CVE-2026-48752
+CVE-2026-48752 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
@@ -56925,7 +57595,7 @@ CVE-2026-48752
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-vxp5-584q-c479
NOTE: https://github.com/lxc/incus/commit/cbefa31ae0da8fd96361178aed3a3c631e098fef (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18590
-CVE-2026-48755
+CVE-2026-48755 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
@@ -56933,7 +57603,7 @@ CVE-2026-48755
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-v6mj-8pf4-hhw4
NOTE: https://github.com/lxc/incus/commit/873a032a461df6b09b7586435b592873863a4e88 (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18597
-CVE-2026-48769
+CVE-2026-48769 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
@@ -56941,7 +57611,7 @@ CVE-2026-48769
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-f6m5-xw2g-xc4x
NOTE: https://github.com/lxc/incus/commit/46d6ef232186df5535c49ca9f3597cab381f9b86 (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18594
-CVE-2026-55621
+CVE-2026-55621 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
@@ -56949,7 +57619,7 @@ CVE-2026-55621
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-64f3-v33m-w89f
NOTE: https://github.com/lxc/incus/commit/2e01078366e2653712719dec82318e51c6d21b28 (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18603
-CVE-2026-55622
+CVE-2026-55622 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
@@ -56957,14 +57627,14 @@ CVE-2026-55622
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-c9f5-j9c3-mhrg
NOTE: https://github.com/lxc/incus/commit/1e3ffc53a10950e55de62ac1e0d612be597b84eb (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18603
-CVE-2026-48749
+CVE-2026-48749 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-2q3f-q5pq-g8wv
NOTE: https://github.com/canonical/lxd/pull/18590
-CVE-2026-77506 [ZSA-2026-12]
+CVE-2026-77506 (Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.)
- znuny 6.5.22-1
[trixie] - znuny <no-dsa> (Non-free not supported)
[bookworm] - znuny <no-dsa> (Non-free not supported)
@@ -77618,22 +78288,22 @@ CVE-2025-14042 (The Automotive Car Dealership Business WordPress Theme for WordP
NOT-FOR-US: WordPress plugin
CVE-2025-11993 (The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPre ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-48756
+CVE-2026-48756 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6370-1}
- incus 7.0.0-2
NOTE: https://github.com/lxc/incus/pull/3425
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-xhqx-mgh3-3h7q
-CVE-2026-48754
+CVE-2026-48754 (Incus is a system container and virtual machine manager. Prior to vers ...)
- incus 7.0.0-2
[trixie] - incus <not-affected> (Vulnerable code not present)
NOTE: https://github.com/lxc/incus/pull/3425
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-4xg6-52mh-fpw8
-CVE-2026-48753
+CVE-2026-48753 (Incus is a system container and virtual machine manager. Prior to vers ...)
- incus 7.0.0-2
[trixie] - incus <not-affected> (Vulnerable code not present)
NOTE: https://github.com/lxc/incus/pull/3425
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-ccjc-4qc3-jxqc
-CVE-2026-47753
+CVE-2026-47753 (Incus is a system container and virtual machine manager. Prior to vers ...)
- incus 7.0.0-2
[trixie] - incus <not-affected> (Vulnerable code not present)
NOTE: https://github.com/lxc/incus/pull/3425
@@ -792467,7 +793137,7 @@ CVE-2018-0500 (Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and includin
[stretch] - curl <not-affected> (Only affects 7.54.1 to 7.60.0)
[jessie] - curl <not-affected> (Only affects 7.54.1 to 7.60.0)
NOTE: https://curl.haxx.se/docs/adv_2018-70a2.html
-CVE-2026-77643 [missing corner-case of CVE-2018-0499]
+CVE-2026-77643 (A cross-site scripting vulnerability in queryparser/termgenerator_int ...)
- xapian-core 1.4.32-1 (bug #1144490)
[trixie] - xapian-core <no-dsa> (Minor issue)
NOTE: https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dce3666d65e30af868986916156973275c05ce01
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dce3666d65e30af868986916156973275c05ce01
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/8ea39110/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list