[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 20:14:42 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e4cb95bf by security tracker role at 2026-08-25T19:14:35+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,517 @@
+CVE-2026-80051 (github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not  ...)
+	TODO: check
+CVE-2026-80050 (ContiNew Admin fails to apply file-upload permission checks or file-ty ...)
+	TODO: check
+CVE-2026-80049 (Airbyte Platform resolves the workspace used for its authorization dec ...)
+	TODO: check
+CVE-2026-79788 (In Dradis Community Edition, the ProvidersController and AgentsControl ...)
+	TODO: check
+CVE-2026-79787 (Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signat ...)
+	TODO: check
+CVE-2026-79786 (Coroot's unauthenticated MCP OAuth dynamic client registration endpoin ...)
+	TODO: check
+CVE-2026-79785 (X-AnyLabeling's model downloader disabled TLS certificate verification ...)
+	TODO: check
+CVE-2026-79784 (Vocos instantiates a class named by a configuration file without restr ...)
+	TODO: check
+CVE-2026-79783 (rclone before 1.74.4 fails to mask special permission bits when applyi ...)
+	TODO: check
+CVE-2026-79782 (rclone before 1.74.4 fails to strip the X-Amz-Security-Token header wh ...)
+	TODO: check
+CVE-2026-79781 (rclone serve s3 before 1.74.4 contains a path traversal vulnerability  ...)
+	TODO: check
+CVE-2026-79780 (rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE- ...)
+	TODO: check
+CVE-2026-79779 (rclone versions before v1.75.0 fail to reject transport downgrades in  ...)
+	TODO: check
+CVE-2026-79778 (rclone before v1.75.0 contains a denial of service vulnerability in th ...)
+	TODO: check
+CVE-2026-79777 (rclone before v1.75.0 includes full Go stack traces in RC API error re ...)
+	TODO: check
+CVE-2026-79776 (rclone before 1.75.0 mounts the pprof debug handler as its own router  ...)
+	TODO: check
+CVE-2026-79775 (rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain m ...)
+	TODO: check
+CVE-2026-79774 (Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig ...)
+	TODO: check
+CVE-2026-79773 (Winter CMS before 1.2.13 contains a local file inclusion vulnerability ...)
+	TODO: check
+CVE-2026-79772 (Nokogiri versions before 1.19.1 fail to check the return value from xm ...)
+	TODO: check
+CVE-2026-79771 (Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Styl ...)
+	TODO: check
+CVE-2026-79770 (Nokogiri versions before 1.19.3 contain regular expression denial of s ...)
+	TODO: check
+CVE-2026-79769 (Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bou ...)
+	TODO: check
+CVE-2026-79717 (A server-side request forgery (SSRF) vulnerability was found in galaxy ...)
+	TODO: check
+CVE-2026-79676 (NLTK versions before 3.10.3 contain a path traversal vulnerability in  ...)
+	TODO: check
+CVE-2026-79675 (NLTK before 3.10.3 fails to validate JVM options passed through the pe ...)
+	TODO: check
+CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass vulnerabilit ...)
+	TODO: check
+CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:rea ...)
+	TODO: check
+CVE-2026-79672 (Ech0 before 4.4.3 fails to enforce scope-based authorization on nine c ...)
+	TODO: check
+CVE-2026-79671 (Ech0 through 4.2.1 contains a server-side request forgery vulnerabilit ...)
+	TODO: check
+CVE-2026-79670 (Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability ...)
+	TODO: check
+CVE-2026-79669 (Ech0 before 4.4.3 lacks authorization checks on system log endpoints a ...)
+	TODO: check
+CVE-2026-79668 (Ech0 before 4.7.3 contains an authentication bypass vulnerability in t ...)
+	TODO: check
+CVE-2026-79667 (Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access ...)
+	TODO: check
+CVE-2026-79666 (Ech0 before 4.4.3 fails to enforce administrator authorization on dash ...)
+	TODO: check
+CVE-2026-79665 (Ech0 before 4.5.1 contains an authorization bypass vulnerability where ...)
+	TODO: check
+CVE-2026-79664 (Ech0 before 4.7.3 fails to properly revoke access tokens created with  ...)
+	TODO: check
+CVE-2026-79663 (Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability ...)
+	TODO: check
+CVE-2026-79662 (Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerabi ...)
+	TODO: check
+CVE-2026-79661 (Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on th ...)
+	TODO: check
+CVE-2026-79660 (Ech0 versions before 4.7.3 expose guest commenter email addresses thro ...)
+	TODO: check
+CVE-2026-79659 (Ech0 before 4.7.3 contains a server-side request forgery vulnerability ...)
+	TODO: check
+CVE-2026-79658 (Ech0 before 5.0.1 does not impose any size or shape limit on the Accep ...)
+	TODO: check
+CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution vulnerabil ...)
+	TODO: check
+CVE-2026-79655 (A flaw was found in sos clean, a utility within the sos package. This  ...)
+	TODO: check
+CVE-2026-79652 (A flaw was found in the JWT Bearer authorization grant implementation  ...)
+	TODO: check
+CVE-2026-79623 (A security vulnerability has been detected in FishCodeTech Muteki up t ...)
+	TODO: check
+CVE-2026-79622 (A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted  ...)
+	TODO: check
+CVE-2026-79406 (A security vulnerability has been detected in macrozheng mall up to 1. ...)
+	TODO: check
+CVE-2026-78887 (A weakness has been identified in liketrek TREK up to 3.0.22. This imp ...)
+	TODO: check
+CVE-2026-78886 (A security flaw has been discovered in liketrek TREK up to 3.0.22. Thi ...)
+	TODO: check
+CVE-2026-78885 (A vulnerability was identified in liketrek TREK up to 3.0.22. The impa ...)
+	TODO: check
+CVE-2026-78864 (A vulnerability was determined in liketrek TREK up to 3.0.22. The affe ...)
+	TODO: check
+CVE-2026-78863 (A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is t ...)
+	TODO: check
+CVE-2026-78701 (A flaw was found in 389-ds-base. A remote, authenticated attacker coul ...)
+	TODO: check
+CVE-2026-78684 (vLLM before 0.27.0 fails to properly classify DeepStream as a GPU back ...)
+	TODO: check
+CVE-2026-78581 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
+	TODO: check
+CVE-2026-78576 (The Readabler plugin for WordPress is vulnerable to SQL Injection in a ...)
+	TODO: check
+CVE-2026-78572 (The Kalles Addons plugin for WordPress is vulnerable to PHP Object Inj ...)
+	TODO: check
+CVE-2026-78570 (The Total Donations plugin for WordPress is vulnerable to Privilege Es ...)
+	TODO: check
+CVE-2026-78568 (The Total Donations plugin for WordPress is vulnerable to SQL Injectio ...)
+	TODO: check
+CVE-2026-78566 (The Shuffle theme for WordPress is vulnerable to Local File Inclusion  ...)
+	TODO: check
+CVE-2026-78563 (The NotificationX Pro plugin for WordPress is vulnerable to Stored Cro ...)
+	TODO: check
+CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local File Incl ...)
+	TODO: check
+CVE-2026-78468 (The FluentCRM Pro \u2013 Email Newsletter, Automation, Email Marketing ...)
+	TODO: check
+CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the python_ ...)
+	TODO: check
+CVE-2026-78322 (A flaw was found in file-roller. When opening or extracting a maliciou ...)
+	TODO: check
+CVE-2026-77998 (Joomla Extension - miniorange.com - Unauthenticated Authentication Byp ...)
+	TODO: check
+CVE-2026-77997 (Joomla Extension - yootheme.com - Authenticated, privileged informatio ...)
+	TODO: check
+CVE-2026-77996 (Joomla Extension - yootheme.com - Authenticated, privileged stored XSS ...)
+	TODO: check
+CVE-2026-77824 (The Media Sweep \u2013 WordPress Media Cleaner plugin for WordPress is ...)
+	TODO: check
+CVE-2026-77146 (The extension's invitation controller fails to stop processing after r ...)
+	TODO: check
+CVE-2026-77145 (The permission check for the frontend management update flow verified  ...)
+	TODO: check
+CVE-2026-77144 (The frontend management plugin attributed a newly created event to the ...)
+	TODO: check
+CVE-2026-77143 (The frontend topic editing flow does not verify on the server side tha ...)
+	TODO: check
+CVE-2026-77142 (The frontend company self-service editing feature relies on a template ...)
+	TODO: check
+CVE-2026-77141 (The extension resolves the targeted club record from a user-supplied r ...)
+	TODO: check
+CVE-2026-77140 (The extension validates the HMAC of a frontend employee edit link only ...)
+	TODO: check
+CVE-2026-77139 (The extension fails to validate a client-supplied template element key ...)
+	TODO: check
+CVE-2026-77138 (The extension fails to safely process untrusted client input of an att ...)
+	TODO: check
+CVE-2026-77137 (The extension fails to properly sanitize user input before using it in ...)
+	TODO: check
+CVE-2026-77136 (The extension passes the raw value of a form field configured as "This ...)
+	TODO: check
+CVE-2026-77135 (The extension's user detail view fails to verify that a requested user ...)
+	TODO: check
+CVE-2026-77134 (The extension fails to require the dedicated admin confirmation token  ...)
+	TODO: check
+CVE-2026-77133 (The extension fails to restrict which frontend usergroups a logged-in  ...)
+	TODO: check
+CVE-2026-77131 (When OpenSSL is unavailable on the server, the extension transmits TYP ...)
+	TODO: check
+CVE-2026-77130 (The extension fails to properly validate the expiration of a client-su ...)
+	TODO: check
+CVE-2026-77129 (The extension passes an editor-configurable email subject string direc ...)
+	TODO: check
+CVE-2026-77128 (The extension fails to enforce enable-field restrictions on a reposito ...)
+	TODO: check
+CVE-2026-77127 (The extension fails to restrict a backend AJAX endpoint for inline edi ...)
+	TODO: check
+CVE-2026-76198 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
+	TODO: check
+CVE-2026-76197 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
+	TODO: check
+CVE-2026-76195 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
+	TODO: check
+CVE-2026-76193 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
+	TODO: check
+CVE-2026-76189 (CAI Content Credentials is affected by an Integer Underflow (Wrap or W ...)
+	TODO: check
+CVE-2026-76128 (The eCommerce Product Catalog plugin for WordPress is vulnerable to St ...)
+	TODO: check
+CVE-2026-75971 (The ShopEngine Elementor WooCommerce Builder Addon \u2013 All in One W ...)
+	TODO: check
+CVE-2026-75908 (The Newsletters plugin for WordPress is vulnerable to authorization by ...)
+	TODO: check
+CVE-2026-75770 (Substance3D - Painter is affected by an out-of-bounds write vulnerabil ...)
+	TODO: check
+CVE-2026-75769 (Substance3D - Painter is affected by a Heap-based Buffer Overflow vuln ...)
+	TODO: check
+CVE-2026-75768 (Substance3D - Painter is affected by an Untrusted Search Path vulnerab ...)
+	TODO: check
+CVE-2026-75767 (Substance3D - Painter is affected by a Heap-based Buffer Overflow vuln ...)
+	TODO: check
+CVE-2026-75766 (Substance3D - Painter is affected by a Heap-based Buffer Overflow vuln ...)
+	TODO: check
+CVE-2026-75752 (Substance3D - Painter is affected by an out-of-bounds read vulnerabili ...)
+	TODO: check
+CVE-2026-75750 (Substance3D - Painter is affected by a Heap-based Buffer Overflow vuln ...)
+	TODO: check
+CVE-2026-75749 (Substance3D - Painter is affected by an out-of-bounds write vulnerabil ...)
+	TODO: check
+CVE-2026-75498 (Webkul QloApps does not validate request parameters before a database  ...)
+	TODO: check
+CVE-2026-75497 (Webkul QloApps does not validate request parameters before a database  ...)
+	TODO: check
+CVE-2026-75496 (Webkul QloApps does not perform proper validation on uploaded file ext ...)
+	TODO: check
+CVE-2026-75038 (UNIX symbolic link (symlink) following vulnerability in ilya-zlobintse ...)
+	TODO: check
+CVE-2026-75037 (Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT o ...)
+	TODO: check
+CVE-2026-71564 (Substance3D - Designer is affected by an out-of-bounds write vulnerabi ...)
+	TODO: check
+CVE-2026-71444 (CAI Content Credentials is affected by an Integer Underflow (Wrap or W ...)
+	TODO: check
+CVE-2026-71443 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
+	TODO: check
+CVE-2026-71442 (CAI Content Credentials is affected by an Integer Underflow (Wrap or W ...)
+	TODO: check
+CVE-2026-71441 (Illustrator is affected by an out-of-bounds read vulnerability that co ...)
+	TODO: check
+CVE-2026-71399 (Adobe XD is affected by a Buffer Overflow vulnerability that could res ...)
+	TODO: check
+CVE-2026-71382 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
+	TODO: check
+CVE-2026-71360 (CAI Content Credentials is affected by an Uncontrolled Resource Consum ...)
+	TODO: check
+CVE-2026-70551 (A user who can read an existing remote VCS repository can replace its  ...)
+	TODO: check
+CVE-2026-70550 (An authorization weakness in JFrog Artifactory Composer repository han ...)
+	TODO: check
+CVE-2026-70548 (Under specific circumstances, low-level user can run request to remote ...)
+	TODO: check
+CVE-2026-69104 (An authenticated user may initiate repository migration operations wit ...)
+	TODO: check
+CVE-2026-67578 (FA-50 all versions miss authentication for some configuration. An atta ...)
+	TODO: check
+CVE-2026-66882 (Improper Neutralization of Input During Web Page Generation (XSS) vuln ...)
+	TODO: check
+CVE-2026-65979 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-65633 (Improper Authentication vulnerability in team-alembic AshAuthenticatio ...)
+	TODO: check
+CVE-2026-64204 (There is a memory corruption vulnerability recently discovered in NI L ...)
+	TODO: check
+CVE-2026-64203 (There is a memory corruption vulnerability recently discovered in NI L ...)
+	TODO: check
+CVE-2026-64202 (There is a memory corruption vulnerability recently discovered in NI L ...)
+	TODO: check
+CVE-2026-64201 (There is a memory corruption vulnerability recently discovered in NI L ...)
+	TODO: check
+CVE-2026-63587 (The SMS control function of IE-SR-2TX-WL-4G devices can require a pass ...)
+	TODO: check
+CVE-2026-63586 (The web-based management interface uses a modified uhttpd server with  ...)
+	TODO: check
+CVE-2026-62986 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-61555 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-59985 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-59984 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-59983 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-59982 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-59769 (FA-50 all versions contain hard-coded credentials. An attacker, who kn ...)
+	TODO: check
+CVE-2026-59335 (Improper handling of case sensitivity (CWE-178) in the identity zone a ...)
+	TODO: check
+CVE-2026-59189 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-59187 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-59186 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-59184 (OpenEXR is the reference implementation and specification for the EXR  ...)
+	TODO: check
+CVE-2026-57910 (Improper authentication in the WatchGuard Agent allows an unauthentica ...)
+	TODO: check
+CVE-2026-57909 (A path traversal vulnerability in WatchGuard Agent allows a remote, un ...)
+	TODO: check
+CVE-2026-57863 (Crater Invoice through 6.0.6 contains a path traversal vulnerability i ...)
+	TODO: check
+CVE-2026-56096 (The extension passes the user-supplied search query parameter to Apach ...)
+	TODO: check
+CVE-2026-56095 (The extension's indexer passed every field value returned by content o ...)
+	TODO: check
+CVE-2026-56094 (The extension allows a request-provided additionalFilters parameter to ...)
+	TODO: check
+CVE-2026-56093 (The extension's frontend detail-view document lookup does not apply th ...)
+	TODO: check
+CVE-2026-56092 (The extension forces empty frontend-group and subpage-inheritance rest ...)
+	TODO: check
+CVE-2026-55976 (Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in  ...)
+	TODO: check
+CVE-2026-55663 (mediasoup is a WebRTC video conferencing system. From version 3.20.0 u ...)
+	TODO: check
+CVE-2026-55640 (Nextcloud MCP Server is a production-ready MCP server that connects AI ...)
+	TODO: check
+CVE-2026-55637 (genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3 ...)
+	TODO: check
+CVE-2026-55624 (MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to ...)
+	TODO: check
+CVE-2026-55623
+	REJECTED
+CVE-2026-55620 (eml_parser serves as a python module for parsing eml files and returni ...)
+	TODO: check
+CVE-2026-55619 (eml_parser serves as a python module for parsing eml files and returni ...)
+	TODO: check
+CVE-2026-55618 (eml_parser serves as a python module for parsing eml files and returni ...)
+	TODO: check
+CVE-2026-55609 (sublinear-time-solver is a Rust and WebAssembly library for solving as ...)
+	TODO: check
+CVE-2026-55585 (QWED is open-source AI verification infrastructure for deterministic v ...)
+	TODO: check
+CVE-2026-55582 (mcp-shell is an MCP server for running shell commands securely, audita ...)
+	TODO: check
+CVE-2026-55581 (mcp-shell is an MCP server for running shell commands securely, audita ...)
+	TODO: check
+CVE-2026-55580 (mcp-shell is an MCP server for running shell commands securely, audita ...)
+	TODO: check
+CVE-2026-55571 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
+	TODO: check
+CVE-2026-55557 (browse-mcp is a Playwright-based headless-browser MCP server for MCP-c ...)
+	TODO: check
+CVE-2026-55553 (urllib is an HTTP client for Node.js that supports authentication, red ...)
+	TODO: check
+CVE-2026-55546 (QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2 ...)
+	TODO: check
+CVE-2026-55541 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, pr ...)
+	TODO: check
+CVE-2026-55540 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is ...)
+	TODO: check
+CVE-2026-55539 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, th ...)
+	TODO: check
+CVE-2026-55538 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, pr ...)
+	TODO: check
+CVE-2026-55537 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Jo ...)
+	TODO: check
+CVE-2026-55536 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Br ...)
+	TODO: check
+CVE-2026-55535 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, th ...)
+	TODO: check
+CVE-2026-55534 (PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4 ...)
+	TODO: check
+CVE-2026-55533 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, cr ...)
+	TODO: check
+CVE-2026-55532 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MC ...)
+	TODO: check
+CVE-2026-55531 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, th ...)
+	TODO: check
+CVE-2026-55530 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
+	TODO: check
+CVE-2026-55529 (PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, th ...)
+	TODO: check
+CVE-2026-55528 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
+	TODO: check
+CVE-2026-55527 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
+	TODO: check
+CVE-2026-55526 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
+	TODO: check
+CVE-2026-55525 (PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6. ...)
+	TODO: check
+CVE-2026-55419 (Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8 ...)
+	TODO: check
+CVE-2026-53561 (An improper authentication vulnerability in HiveServer2 SAML bearer-to ...)
+	TODO: check
+CVE-2026-49845 (SQL injection in Hive Metastore direct SQL partition-name resolution i ...)
+	TODO: check
+CVE-2026-48433 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
+	TODO: check
+CVE-2026-48432 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
+	TODO: check
+CVE-2026-48431 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
+	TODO: check
+CVE-2026-48430 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
+	TODO: check
+CVE-2026-48429 (Substance3D - Designer is affected by a NULL Pointer Dereference vulne ...)
+	TODO: check
+CVE-2026-48428 (Substance3D - Designer is affected by a Heap-based Buffer Overflow vul ...)
+	TODO: check
+CVE-2026-48427 (Substance3D - Designer is affected by an out-of-bounds write vulnerabi ...)
+	TODO: check
+CVE-2026-48426 (Substance3D - Designer is affected by an out-of-bounds write vulnerabi ...)
+	TODO: check
+CVE-2026-48425 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
+	TODO: check
+CVE-2026-48424 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
+	TODO: check
+CVE-2026-48423 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
+	TODO: check
+CVE-2026-48422 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
+	TODO: check
+CVE-2026-48421 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
+	TODO: check
+CVE-2026-48420 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
+	TODO: check
+CVE-2026-48419 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
+	TODO: check
+CVE-2026-48418 (Substance3D - Sampler is affected by an out-of-bounds write vulnerabil ...)
+	TODO: check
+CVE-2026-48417 (Substance3D - Sampler is affected by a Stack-based Buffer Overflow vul ...)
+	TODO: check
+CVE-2026-47626 (NVIDIA DGX Spark contains a vulnerability in the system firmware, wher ...)
+	TODO: check
+CVE-2026-47624 (NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may ...)
+	TODO: check
+CVE-2026-26211 (Ekushey Project Manager CRM stores the administrator-configured system ...)
+	TODO: check
+CVE-2026-24263 (NVIDIA DGX Spark contains a vulnerability in the system firmware, wher ...)
+	TODO: check
+CVE-2026-24262 (NVIDIA DGX Spark contains a vulnerability in the system firmware, wher ...)
+	TODO: check
+CVE-2026-24225 (NVIDIA DGX Spark contains a vulnerability in the standalone MM firmwar ...)
+	TODO: check
+CVE-2026-24170 (NVIDIA UFM Enterprise contains a vulnerability in the web interface au ...)
+	TODO: check
+CVE-2026-24169 (NVIDIA UFM Enterprise contains a vulnerability in the plugin managemen ...)
+	TODO: check
+CVE-2026-24168 (NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API wh ...)
+	TODO: check
+CVE-2026-24167 (NVIDIA UFM Enterprise contains a vulnerability in the user management  ...)
+	TODO: check
+CVE-2026-24166 (NVIDIA UFM Enterprise contains a vulnerability in the session manageme ...)
+	TODO: check
+CVE-2026-21758 (HCL Hive is affected by an information disclosure vulnerability, which ...)
+	TODO: check
+CVE-2026-21754 (HCL Hive is affected by multiple infrastructure and network configurat ...)
+	TODO: check
+CVE-2026-21753 (HCL Hive is affected by weak software supply chain governance, which c ...)
+	TODO: check
+CVE-2026-19949 (The All-in-One WP Migration and Backup plugin for WordPress is vulnera ...)
+	TODO: check
+CVE-2026-19913 (The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file di ...)
+	TODO: check
+CVE-2026-19912 (The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthentica ...)
+	TODO: check
+CVE-2026-19851 (A Use of Default Password vulnerability affecting Tuleap Enterprise Ed ...)
+	TODO: check
+CVE-2026-18547 (The Ultimate Member \u2013 User Profile, Registration, Login, Member D ...)
+	TODO: check
+CVE-2026-18512 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
+	TODO: check
+CVE-2026-18445 (There is an integer overflow vulnerability resulting in an out-of-boun ...)
+	TODO: check
+CVE-2026-18444 (There is an integer conversion vulnerability resulting in an out-of-bo ...)
+	TODO: check
+CVE-2026-18328 (The Forminator Forms \u2013 Contact Form, Payment Form & Custom Form B ...)
+	TODO: check
+CVE-2026-18323 (The Forminator Forms \u2013 Contact Form, Payment Form & Custom Form B ...)
+	TODO: check
+CVE-2026-18100 (The MetForm \u2013 Contact Form, Survey, Quiz, & Custom Form Builder f ...)
+	TODO: check
+CVE-2026-17587 (The My Agile Privacy\xae \u2013 CMP, Cookie Consent & Privacy Tools pl ...)
+	TODO: check
+CVE-2026-17548 (Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and a ...)
+	TODO: check
+CVE-2026-16601 (The CM Map Locations \u2013 Visualize and share your locations in a fe ...)
+	TODO: check
+CVE-2026-16599 (GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY auth ...)
+	TODO: check
+CVE-2026-16286 (Unrestricted upload of file with dangerous type vulnerability in TRtek ...)
+	TODO: check
+CVE-2026-16234 (There is a memory corruption vulnerability recently discovered in NI L ...)
+	TODO: check
+CVE-2026-16233 (There is a memory corruption vulnerability recently discovered in NI L ...)
+	TODO: check
+CVE-2026-16231 (hbs is an Express view engine that wraps Handlebars. Its registerAsync ...)
+	TODO: check
+CVE-2026-15310 (When decompressing crafted zip files using the bzip/LZMA/Zstandard   c ...)
+	TODO: check
+CVE-2026-13478 (The Zephyr ext2 filesystem driver validates the on-disk block bitmap i ...)
+	TODO: check
+CVE-2026-13217 (The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a sessi ...)
+	TODO: check
+CVE-2026-13216 (The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's  ...)
+	TODO: check
+CVE-2026-12878 (In affected versions of the Codefresh platform an authenticated user c ...)
+	TODO: check
+CVE-2026-12600 (Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) d ...)
+	TODO: check
+CVE-2025-71407 (Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability  ...)
+	TODO: check
+CVE-2025-71406 (Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior  ...)
+	TODO: check
+CVE-2025-71346 (Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (befor ...)
+	TODO: check
+CVE-2024-58378 (Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the ...)
+	TODO: check
+CVE-2024-58377 (Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affect ...)
+	TODO: check
+CVE-2023-54354 (Nokogiri before 1.14.3 (CRuby implementation only, when using the pack ...)
+	TODO: check
+CVE-2022-51000 (Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships ve ...)
+	TODO: check
+CVE-2022-50999 (Nokogiri versions before 1.13.5 contain an integer overflow vulnerabil ...)
+	TODO: check
+CVE-2022-50998 (Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) ...)
+	TODO: check
+CVE-2021-47996 (Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/v ...)
+	TODO: check
 CVE-2026-63676
 	- libyaml-perl 1.321-1
 	NOTE: Fixed by: https://github.com/ingydotnet/yaml-pm/commit/9388c6a02a66db79f9d2b3727b5588272f612cf1 (v1.320.0)
@@ -11,7 +525,8 @@ CVE-2026-XXXX [GHSA-75g3-96fr-7p2r: SABnzbd PAR2 path traversal enabling cross-j
 	NOTE: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-75g3-96fr-7p2r
 	NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/6ddabb5a4599731b00f44162e62f31e291d2b2d0 (5.1.2)
 	NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/c57af32131216de3e1df3097a0cce06c8c99ceb8 (5.1.2)
-CVE-2026-18798
+CVE-2026-18798 (Issue summary: QUIC server may double free QRX (QUIC record layer RX)  ...)
+	{DSA-6465-1}
 	- openssl <unfixed>
 	[bookworm] - openssl <not-affected> (Vulnerable code not present)
 	[bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -19,21 +534,24 @@ CVE-2026-18798
 	NOTE: https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af (openssl-3.6.4)
 	NOTE: https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c (oepnssl-3.5.8)
 	NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63072
+CVE-2026-63072 (Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buff ...)
+	{DSA-6465-1}
 	- openssl <unfixed>
 	NOTE: https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335 (openssl-4.0.2)
 	NOTE: https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756 (openssl-3.6.4)
 	NOTE: https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42 (openssl-3.5.8)
 	NOTE: https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382 (openssl-3.0.22)
 	NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63076
+CVE-2026-63076 (Issue summary: OpenSSL CMP password based protection verification only ...)
+	{DSA-6465-1}
 	- openssl <unfixed>
 	NOTE: https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e (openssl-4.0.2)
 	NOTE: https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226 (openssl-3.6.4)
 	NOTE: https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c (openssl-3.5.8)
 	NOTE: https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b (openssl-3.0.22)
 	NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-14457
+CVE-2026-14457 (Issue summary: In a server or client configuration with RFC7250 Raw Pu ...)
+	{DSA-6465-1}
 	- openssl <unfixed>
 	[bookworm] - openssl <not-affected> (Vulnerable code not present)
 	[bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -41,14 +559,16 @@ CVE-2026-14457
 	NOTE: https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1 (openssl-3.6.4)
 	NOTE: https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f (openssl-3.5.8)
 	NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-54874
+CVE-2026-54874 (Issue summary: Receiving a DTLS record for a future epoch while a hand ...)
+	{DSA-6465-1}
 	- openssl <unfixed>
 	NOTE: https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107 (openssl-4.0.2)
 	NOTE: https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c (openssl-3.6.4)
 	NOTE: https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23 (openssl-3.5.8)
 	NOTE: https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382 (openssl-3.0.22)
 	NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63073
+CVE-2026-63073 (Issue summary: OpenSSL CMP response validation passed an unexpected re ...)
+	{DSA-6465-1}
 	- openssl <unfixed>
 	[bookworm] - openssl <not-affected> (Vulnerable code not present)
 	[bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -56,14 +576,16 @@ CVE-2026-63073
 	NOTE: https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29 (openssl-3.6.4)
 	NOTE: https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca (openssl-3.5.8)
 	NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63074
+CVE-2026-63074 (Issue summary: The OpenSSL Certificate Management Protocol (CMP) cache ...)
+	{DSA-6465-1}
 	- openssl <unfixed>
 	NOTE: https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46 (openssl-4.0.2)
 	NOTE: https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7 (openssl-3.6.4)
 	NOTE: https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af (openssl-3.5.8)
 	NOTE: https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f (openssl-3.0.22)
 	NOTE: https://openssl-library.org/news/secadv/20260825.txt
-CVE-2026-63075
+CVE-2026-63075 (Issue summary: When OpenSSL processes QUIC traffic from a peer that re ...)
+	{DSA-6465-1}
 	- openssl <unfixed>
 	[bookworm] - openssl <not-affected> (Vulnerable code not present)
 	[bullseye] - openssl <not-affected> (Vulnerable code not present)
@@ -565,7 +1087,8 @@ CVE-2026-78157 (A vulnerability was detected in Open5GS 2.8.0. This affects the
 	- open5gs <itp> (bug #1094791)
 CVE-2026-78156 (A security vulnerability has been detected in Open5GS 2.8.0. Affected  ...)
 	- open5gs <itp> (bug #1094791)
-CVE-2026-78154 (A vulnerability was identified in the-momentum open-wearables up to 0. ...)
+CVE-2026-78154
+	REJECTED
 	NOT-FOR-US: the-momentum open-wearables
 CVE-2026-78148 (A vulnerability was determined in ggml-org llama.cpp bec4772f6. This a ...)
 	- llama.cpp <unfixed>
@@ -592,9 +1115,9 @@ CVE-2026-77994 (Joomla Extension - joomlack.fr - Second order SQL injection in P
 	NOT-FOR-US: Joomla
 CVE-2026-77993 (Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3. ...)
 	NOT-FOR-US: Joomla
-CVE-2026-77915 (rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerab ...)
+CVE-2026-77915 (rConfig Core 8.0.0 before 8.2.13 contains an authentication bypass vul ...)
 	NOT-FOR-US: rConfig
-CVE-2026-77914 (rConfig before 8.2.13 contains a path traversal vulnerability that all ...)
+CVE-2026-77914 (rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerabili ...)
 	NOT-FOR-US: rConfig
 CVE-2026-76848 (TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings an ...)
 	NOT-FOR-US: TypeORM
@@ -3527,7 +4050,8 @@ CVE-2026-XXXX [OSSN-0103]
 	NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0103
 	NOTE: https://review.opendev.org/c/openstack/manila/+/998388
 	NOTE: https://bugs.launchpad.net/manila/+bug/2161287
-CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs]
+CVE-2026-75803 (Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty  ...)
+	{DSA-6465-1}
 	- openssl <unfixed> (bug #1145172)
 	NOTE: https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a (openssl-4.0.2)
 	NOTE: https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b (openssl-3.6.4)
@@ -4276,7 +4800,7 @@ CVE-2025-14602 (The application generates uploaded file names using a weak and p
 	NOT-FOR-US: vsDesk
 CVE-2022-4996 (A flaw has been found in mruby 3.1.0. Affected is the function udiv of ...)
 	TODO: check
-CVE-2026-79992 [Emacs zero-click local command execution via TRAMP]
+CVE-2026-79992 (A flaw was found in Emacs TRAMP. A local attacker could exploit this v ...)
 	- emacs <unfixed> (bug #1145049)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/21/1
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=f3e7104d05bdb8e32ba13bf75604108ad88536dc
@@ -7358,7 +7882,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet len
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
 	NOTE: Followup: https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
 CVE-2026-74990 (Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.1 ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7372,7 +7896,7 @@ CVE-2026-74988 (Internally found bugs present in Firefox ESR 153.0 and Firefox 1
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
 CVE-2026-74987 (Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7389,7 +7913,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine component. This vulnerab
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
 CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This vulnerab ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7415,7 +7939,7 @@ CVE-2026-74977 (Integer overflow in the Graphics component. This vulnerability w
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
 CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7426,7 +7950,7 @@ CVE-2026-74975 (Spoofing issue in the Downloads component in Firefox for Android
 	- firefox <not-affected> (Only affects Firefox on Android)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
 CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. This vu ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7434,7 +7958,7 @@ CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. T
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
 CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This vulnera ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7442,7 +7966,7 @@ CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This v
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
 CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component. This  ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7450,7 +7974,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component.
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
 CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling componen ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7461,7 +7985,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics component. This vulnerabili
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
 CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This vulnerabi ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7472,7 +7996,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics: WebRender component. This
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
 CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback component. This ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7483,7 +8007,7 @@ CVE-2026-74966 (Information disclosure in the Form Autofill component. This vuln
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
 CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vulnerab ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7491,7 +8015,7 @@ CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vu
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
 CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability was fix ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7499,7 +8023,7 @@ CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability w
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
 CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component. This v ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7507,7 +8031,7 @@ CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component.
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
 CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. This vulner ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7518,7 +8042,7 @@ CVE-2026-74961 (Side-channel in the Web Audio component. This vulnerability was
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
 CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulnerabilit ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7526,7 +8050,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulner
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
 CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This vulnerabil ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7537,7 +8061,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC component. This vulnerabili
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
 CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This vulnerability w ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7554,7 +8078,7 @@ CVE-2026-74954 (Information disclosure due to side-channel in the Storage: Cache
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
 CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. This vulner ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7571,7 +8095,7 @@ CVE-2026-74950 (Privilege escalation in the Downloads API component. This vulner
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
 CVE-2026-74949 (Use-after-free in the Graphics: Canvas2D component. This vulnerability ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7579,7 +8103,7 @@ CVE-2026-74949 (Use-after-free in the Graphics: Canvas2D component. This vulnera
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
 CVE-2026-74948 (Information disclosure in the Graphics component. This vulnerability w ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7590,7 +8114,7 @@ CVE-2026-74947 (Privilege escalation due to invalid pointer in the Graphics comp
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
 CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7598,7 +8122,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
 CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vulnerabi ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7606,7 +8130,7 @@ CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vul
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
 CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7614,7 +8138,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
 CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnerability ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7622,7 +8146,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnera
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
 CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. This vul ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7630,7 +8154,7 @@ CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. Th
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
 CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. This vuln ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7638,7 +8162,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. Thi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
 CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerability was ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7646,7 +8170,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerabili
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
 CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7660,7 +8184,7 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC component. This vulnerabili
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
 CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7668,7 +8192,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vu
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
 CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vulnerabil ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7676,7 +8200,7 @@ CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vuln
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
 CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. This vuln ...)
-	{DSA-6461-1 DSA-6451-1 DLA-4750-1}
+	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
 	- thunderbird 1:140.14.0esr-1
@@ -7830,7 +8354,8 @@ CVE-2026-73336 (Joomla! Core - [20260806] - XSS through schema.org outputs in Jo
 	NOT-FOR-US: Joomla
 CVE-2026-73190 (Unauthenticated Cross Site Scripting (XSS) in WPDM \u2013 Premium Pack ...)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-73189 (Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding ...)
+CVE-2026-73189
+	REJECTED
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73187 (Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.)
 	NOT-FOR-US: WordPress plugin or theme
@@ -7965,7 +8490,7 @@ CVE-2026-66627 (Contributor Arbitrary File Upload in GP Premium <= 2.5.5 version
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66622 (Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3. ...)
+CVE-2026-66621 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
 	NOT-FOR-US: WordPress plugin or theme
@@ -15778,6 +16303,7 @@ CVE-2026-15994 (During an internal security assessment, an improper link followi
 CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed as a "hom ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL object) proce ...)
+	{DSA-6465-1}
 	- openssl <unfixed> (bug #1144615)
 	NOTE: https://openssl-library.org/news/secadv/20260813.txt
 	NOTE: https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139 (openssl-4.0.2)
@@ -79189,6 +79715,7 @@ CVE-2026-9334 (Cpanel::JSON::XS versions before 4.41 for Perl allow type confusi
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40653179/
 	NOTE: Fixed by: https://github.com/rurban/Cpanel-JSON-XS/commit/11a7c550a0d8fac2f84414f24d5df9b2bfe346e2 (4.41)
 CVE-2026-50538 (LibVNCClient is a library for easy implementation of a VNC client. In  ...)
+	{DLA-4755-1}
 	- libvncserver 0.9.15+dfsg-6 (bug #1138253)
 	[trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
 	[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
@@ -82114,7 +82641,7 @@ CVE-2026-49052 (Missing Authorization vulnerability in Wpmet ElementsKit Element
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-49051 (Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Dat ...)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-49050
+CVE-2026-49050 (General user can mint admin access tokens via /access-tokens    This i ...)
 	NOT-FOR-US: Apache DolphinScheduler
 CVE-2026-49047 (Missing Authorization vulnerability in DearHive DearFlip allows Exploi ...)
 	NOT-FOR-US: WordPress plugin or theme
@@ -82259,6 +82786,7 @@ CVE-2026-45022 (go-git is an extensible git implementation library written in pu
 	[bookworm] - golang-github-go-git-go-git <postponed> (Limited support, minor issue; signature-verification bypass)
 	NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp
 CVE-2026-44988 (LibVNCClient is a library for easy implementation of a VNC client. In  ...)
+	{DLA-4755-1}
 	- libvncserver 0.9.15+dfsg-5 (bug #1138174)
 	[trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
 	[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
@@ -122348,12 +122876,14 @@ CVE-2026-33157 (Craft CMS is a content management system (CMS). From version 5.6
 CVE-2026-32948 (sbt is a build tool for Scala, Java, and others. From version 0.9.5 to ...)
 	NOT-FOR-US: sbt
 CVE-2026-32854 (LibVNCServer versions 0.9.15 and prior (fixed incommit dc78dee) contai ...)
+	{DLA-4755-1}
 	- libvncserver 0.9.15+dfsg-3 (bug #1132017)
 	[trixie] - libvncserver 0.9.15+dfsg-1+deb13u1
 	[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u1
 	NOTE: https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x
 	NOTE: Fixed by: https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314
 CVE-2026-32853 (LibVNCServer versions 0.9.15 and prior (fixed incommit 009008e) contai ...)
+	{DLA-4755-1}
 	- libvncserver 0.9.15+dfsg-3 (bug #1132016)
 	[trixie] - libvncserver 0.9.15+dfsg-1+deb13u1
 	[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u1
@@ -410267,7 +410797,8 @@ CVE-2023-34960 (A command injection vulnerability in the wsConvertPpt component
 	NOT-FOR-US: Chamilo CMS
 CVE-2023-4026
 	REJECTED
-CVE-2023-4010 (A flaw was found in the USB Host Controller Driver framework in the Li ...)
+CVE-2023-4010
+	REJECTED
 	- linux <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2227726
 	NOTE: https://github.com/wanrenmi/a-usb-kernel-bug



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4cb95bf496ed793f0ce5994609d9628b4286d86

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4cb95bf496ed793f0ce5994609d9628b4286d86
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/96d867fe/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list