[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 20:13:49 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bdc6d046 by security tracker role at 2026-08-26T19:13:42+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,453 @@
+CVE-2026-9668 (With legitimate user credentials in hand, attackers can construct mali ...)
+	TODO: check
+CVE-2026-81036 (Stalwart Mail Server does not compare an OAuth redirect target against ...)
+	TODO: check
+CVE-2026-81035 (Midday allows any member of a team to delete it. The delete procedure  ...)
+	TODO: check
+CVE-2026-81034 (Netmaker disables certificate verification on the connection to the co ...)
+	TODO: check
+CVE-2026-81033 (Automatisch reveals whether an address is registered through the respo ...)
+	TODO: check
+CVE-2026-81032 (NebulaGraph exposes its runtime configuration over an unauthenticated  ...)
+	TODO: check
+CVE-2026-81031 (IDURAR ERP CRM changes the password of whichever account a request nam ...)
+	TODO: check
+CVE-2026-81030 (Mage AI does not confine the paths accepted by its browser-items API t ...)
+	TODO: check
+CVE-2026-81029 (OpenMetadata accepts a caller-supplied post-authentication redirect ta ...)
+	TODO: check
+CVE-2026-81028 (ZLMediaKit confines the downloadFile API to a configured set of root d ...)
+	TODO: check
+CVE-2026-81027 (one-api gates one of its two channel-pinning paths and not the other.  ...)
+	TODO: check
+CVE-2026-80589 (In the Linux kernel, the following vulnerability has been resolved:  b ...)
+	TODO: check
+CVE-2026-80588 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
+	TODO: check
+CVE-2026-80587 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
+	TODO: check
+CVE-2026-80586 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
+	TODO: check
+CVE-2026-80585 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
+	TODO: check
+CVE-2026-80584 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80583 (In the Linux kernel, the following vulnerability has been resolved:  A ...)
+	TODO: check
+CVE-2026-80582 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
+	TODO: check
+CVE-2026-80581 (In the Linux kernel, the following vulnerability has been resolved:  A ...)
+	TODO: check
+CVE-2026-80580 (In the Linux kernel, the following vulnerability has been resolved:  f ...)
+	TODO: check
+CVE-2026-80579 (In the Linux kernel, the following vulnerability has been resolved:  f ...)
+	TODO: check
+CVE-2026-80578 (In the Linux kernel, the following vulnerability has been resolved:  f ...)
+	TODO: check
+CVE-2026-80577 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
+	TODO: check
+CVE-2026-80576 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
+	TODO: check
+CVE-2026-80575 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80574 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80573 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80572 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80571 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
+	TODO: check
+CVE-2026-80570 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80569 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80568 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80567 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80566 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80565 (In the Linux kernel, the following vulnerability has been resolved:  c ...)
+	TODO: check
+CVE-2026-80564 (In the Linux kernel, the following vulnerability has been resolved:  g ...)
+	TODO: check
+CVE-2026-80563 (In the Linux kernel, the following vulnerability has been resolved:  g ...)
+	TODO: check
+CVE-2026-80562 (In the Linux kernel, the following vulnerability has been resolved:  g ...)
+	TODO: check
+CVE-2026-80561 (In the Linux kernel, the following vulnerability has been resolved:  l ...)
+	TODO: check
+CVE-2026-80560 (In the Linux kernel, the following vulnerability has been resolved:  o ...)
+	TODO: check
+CVE-2026-80559 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	TODO: check
+CVE-2026-80558 (In the Linux kernel, the following vulnerability has been resolved:  l ...)
+	TODO: check
+CVE-2026-80557 (In the Linux kernel, the following vulnerability has been resolved:  l ...)
+	TODO: check
+CVE-2026-80556 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
+	TODO: check
+CVE-2026-80555 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80554 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80553 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80552 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80551 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80550 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80549 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80548 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80547 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80546 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80545 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80544 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80543 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-80542 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
+	TODO: check
+CVE-2026-80541 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
+	TODO: check
+CVE-2026-80540 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
+	TODO: check
+CVE-2026-80539 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
+	TODO: check
+CVE-2026-80538 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80537 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80536 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80535 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80534 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80533 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80532 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80531 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80530 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80529 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	TODO: check
+CVE-2026-80528 (In the Linux kernel, the following vulnerability has been resolved:  c ...)
+	TODO: check
+CVE-2026-80527 (In the Linux kernel, the following vulnerability has been resolved:  c ...)
+	TODO: check
+CVE-2026-80526 (In the Linux kernel, the following vulnerability has been resolved:  A ...)
+	TODO: check
+CVE-2026-80525 (In the Linux kernel, the following vulnerability has been resolved:  A ...)
+	TODO: check
+CVE-2026-80524 (In the Linux kernel, the following vulnerability has been resolved:  o ...)
+	TODO: check
+CVE-2026-80523 (In the Linux kernel, the following vulnerability has been resolved:  c ...)
+	TODO: check
+CVE-2026-80522 (In the Linux kernel, the following vulnerability has been resolved:  c ...)
+	TODO: check
+CVE-2026-80521 (In the Linux kernel, the following vulnerability has been resolved:  a ...)
+	TODO: check
+CVE-2026-80520 (In the Linux kernel, the following vulnerability has been resolved:  o ...)
+	TODO: check
+CVE-2026-80519 (In the Linux kernel, the following vulnerability has been resolved:  o ...)
+	TODO: check
+CVE-2026-80428 (ILIAS deserialises stored session data for an unauthenticated caller.  ...)
+	TODO: check
+CVE-2026-80427 (bestzip builds the argument list for the system zip utility without se ...)
+	TODO: check
+CVE-2026-80426 (FiftyOne renders a dataset field's description as markup. The sidebar  ...)
+	TODO: check
+CVE-2026-80350 (OneUptime's webhook target check rejects private and loopback addresse ...)
+	TODO: check
+CVE-2026-80349 (TarsWeb decides whether a request comes from a trusted local caller us ...)
+	TODO: check
+CVE-2026-80348 (TarsWeb enforces its per-application roles by calling AuthService from ...)
+	TODO: check
+CVE-2026-80347 (mcp-fetch checks a fetch target against its SSRF guard without removin ...)
+	TODO: check
+CVE-2026-80346 (StarRocks performs no privilege check when a legacy synchronous materi ...)
+	TODO: check
+CVE-2026-80237 (EFence developed by Thinking Software Technology has an Arbitrary File ...)
+	TODO: check
+CVE-2026-80236 (Efence developed by Thinking Software Technology has a SQL Injection v ...)
+	TODO: check
+CVE-2026-80235 (EFence developed by Thinking Software Technology has an Arbitrary File ...)
+	TODO: check
+CVE-2026-80234 (CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing A ...)
+	TODO: check
+CVE-2026-80233 (CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Techn ...)
+	TODO: check
+CVE-2026-80206 (NLTK before 3.10.3 contains a regular expression denial of service (Re ...)
+	TODO: check
+CVE-2026-80205 (NLTK versions before 3.10.0 contain a regular expression denial of ser ...)
+	TODO: check
+CVE-2026-80204 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not a ...)
+	TODO: check
+CVE-2026-80203 (The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API- ...)
+	TODO: check
+CVE-2026-80153
+	REJECTED
+CVE-2026-7487 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2026-79940 (Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions pr ...)
+	TODO: check
+CVE-2026-79902 (A flaw was found in the Seattle FilmWorks plugin in GIMP. When process ...)
+	TODO: check
+CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a capabili ...)
+	TODO: check
+CVE-2026-78237 (Insufficient input validation in ABR allows a low-privileged user to i ...)
+	TODO: check
+CVE-2026-78236 (An insecure PIN derivation mechanism in ABR allows a low-privileged us ...)
+	TODO: check
+CVE-2026-77801 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
+	TODO: check
+CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia diagram  ...)
+	TODO: check
+CVE-2026-77557 (A malicious actor with access to the network could exploit an Improper ...)
+	TODO: check
+CVE-2026-77554 (A malicious actor with access to the network could exploit an Improper ...)
+	TODO: check
+CVE-2026-77553 (A malicious actor with access to the network and low privileges could  ...)
+	TODO: check
+CVE-2026-77552 (A malicious actor with access to the network could exploit an Improper ...)
+	TODO: check
+CVE-2026-77551 (A malicious actor with access to the network and under certain conditi ...)
+	TODO: check
+CVE-2026-77550 (A malicious actor with access to the network could exploit an Improper ...)
+	TODO: check
+CVE-2026-77549 (A malicious actor with access to the network and under certain conditi ...)
+	TODO: check
+CVE-2026-77548 (A malicious actor with access to the network and low privileges could  ...)
+	TODO: check
+CVE-2026-77547 (A malicious actor with access to the network and low privileges could  ...)
+	TODO: check
+CVE-2026-77546 (A malicious actor with access to the network and low privileges could  ...)
+	TODO: check
+CVE-2026-77545 (A malicious actor with access to the network, low privileges and under ...)
+	TODO: check
+CVE-2026-77543 (A malicious actor with access to the network and low privileges could  ...)
+	TODO: check
+CVE-2026-77542 (A malicious actor with access to the network and high privileges could ...)
+	TODO: check
+CVE-2026-77541 (A malicious actor with access to the network and high privileges could ...)
+	TODO: check
+CVE-2026-77540 (A malicious actor with access to the network and high privileges could ...)
+	TODO: check
+CVE-2026-77539 (A malicious actor with access to the network and high privileges could ...)
+	TODO: check
+CVE-2026-77538 (A malicious actor with access to the network could exploit an Improper ...)
+	TODO: check
+CVE-2026-77537 (A malicious actor with access to the network could exploit an Improper ...)
+	TODO: check
+CVE-2026-77536 (A malicious actor with access to the network and low privileges could  ...)
+	TODO: check
+CVE-2026-77535 (A malicious actor with access to the network and high privileges could ...)
+	TODO: check
+CVE-2026-77534 (A malicious actor with access to the network and low privileges could  ...)
+	TODO: check
+CVE-2026-77533 (A malicious actor with access to the network and low privileges could  ...)
+	TODO: check
+CVE-2026-77532 (A malicious actor with access to an adjacent network could exploit a B ...)
+	TODO: check
+CVE-2026-76784 (Multiple TP-Link Kasa smart home devices contain insufficient cryptogr ...)
+	TODO: check
+CVE-2026-75977 (The Mang Board WP plugin for WordPress is vulnerable to Missing Author ...)
+	TODO: check
+CVE-2026-75960 (Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insuf ...)
+	TODO: check
+CVE-2026-75896 (Use of Hard-coded Credentials vulnerability in T\xdcB\u0130TAK B\u0130 ...)
+	TODO: check
+CVE-2026-75466 (libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability ...)
+	TODO: check
+CVE-2026-75325 (DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/a ...)
+	TODO: check
+CVE-2026-75062 (Improper Neutralization of Directives in Dynamically Evaluated Code (' ...)
+	TODO: check
+CVE-2026-74754 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-74753 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
+	TODO: check
+CVE-2026-74752 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	TODO: check
+CVE-2026-74751 (In the Linux kernel, the following vulnerability has been resolved:  r ...)
+	TODO: check
+CVE-2026-74750 (In the Linux kernel, the following vulnerability has been resolved:  o ...)
+	TODO: check
+CVE-2026-74749 (In the Linux kernel, the following vulnerability has been resolved:  r ...)
+	TODO: check
+CVE-2026-74748 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
+	TODO: check
+CVE-2026-74747 (In the Linux kernel, the following vulnerability has been resolved:  i ...)
+	TODO: check
+CVE-2026-74746 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
+	TODO: check
+CVE-2026-74745 (In the Linux kernel, the following vulnerability has been resolved:  e ...)
+	TODO: check
+CVE-2026-74744 (In the Linux kernel, the following vulnerability has been resolved:  i ...)
+	TODO: check
+CVE-2026-74743 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
+	TODO: check
+CVE-2026-74742 (In the Linux kernel, the following vulnerability has been resolved:  v ...)
+	TODO: check
+CVE-2026-74741 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
+	TODO: check
+CVE-2026-74740 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
+	TODO: check
+CVE-2026-74739 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
+	TODO: check
+CVE-2026-74738 (In the Linux kernel, the following vulnerability has been resolved:  r ...)
+	TODO: check
+CVE-2026-74737 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
+	TODO: check
+CVE-2026-74736 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
+	TODO: check
+CVE-2026-74735 (In the Linux kernel, the following vulnerability has been resolved:  l ...)
+	TODO: check
+CVE-2026-74734 (In the Linux kernel, the following vulnerability has been resolved:  f ...)
+	TODO: check
+CVE-2026-73108 (RustDesk versions before 1.4.7 contain an uncontrolled speculative mem ...)
+	TODO: check
+CVE-2026-73102 (RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnera ...)
+	TODO: check
+CVE-2026-71171 (Dell Cloud Disaster Recovery, versions20.2 and prior,containan Imprope ...)
+	TODO: check
+CVE-2026-70419 (Dell Cloud Disaster Recovery, versions 20.2 and prior,containan Improp ...)
+	TODO: check
+CVE-2026-6178 (The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scr ...)
+	TODO: check
+CVE-2026-63179 (Winter CMS is a content management system built on the Laravel PHP fra ...)
+	TODO: check
+CVE-2026-63041 (Reliance on Untrusted Inputs in a Security Decision vulnerability in A ...)
+	TODO: check
+CVE-2026-5092 (The Greenshift \u2013 animation and page builder blocks plugin for Wor ...)
+	TODO: check
+CVE-2026-59683 (The OpenRGB network protocol allows to write attacker controlled strin ...)
+	TODO: check
+CVE-2026-59682 (Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB.This issu ...)
+	TODO: check
+CVE-2026-58474 (whichllm before 0.5.16 contains a code injection vulnerability in the  ...)
+	TODO: check
+CVE-2026-54614 (DebugKit provides a debugging toolbar for CakePHP applications. Prior  ...)
+	TODO: check
+CVE-2026-54606 (SunEditor is a lightweight and powerful WYSIWYG editor in vanilla Java ...)
+	TODO: check
+CVE-2026-54569 (SENAITE.CORE is the core framework for the SENAITE laboratory informat ...)
+	TODO: check
+CVE-2026-54556 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
+	TODO: check
+CVE-2026-54553 (Starlette-Admin is a fast, beautiful and extensible administrative int ...)
+	TODO: check
+CVE-2026-54550 (IzPack is a widely used tool for packaging applications on the Java pl ...)
+	TODO: check
+CVE-2026-54523 (Kyverno is a policy engine designed for cloud native platform engineer ...)
+	TODO: check
+CVE-2026-54511 (LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, an ...)
+	TODO: check
+CVE-2026-54256 (Winter CMS is a content management system built on the Laravel PHP fra ...)
+	TODO: check
+CVE-2026-51106 (An issue in TokTok qTox v1.18.4 allows a local attacker to cause a den ...)
+	TODO: check
+CVE-2026-48786 (Fleet is an open-source device management platform built on osquery. I ...)
+	TODO: check
+CVE-2026-48549 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSR ...)
+	TODO: check
+CVE-2026-48548 (Nagios Core before 4.5.12 contains a cross-site request forgery vulner ...)
+	TODO: check
+CVE-2026-47841 (An application using Spring Security's WebAuthn support may be vulnera ...)
+	TODO: check
+CVE-2026-47837 (Missing Authentication for Critical Function vulnerability in Spring S ...)
+	TODO: check
+CVE-2026-47836 (The base directory (spring.cloud.config.server.svn.basedir) used by th ...)
+	TODO: check
+CVE-2026-41262 (Fleet is an open-source device management platform built on osquery. I ...)
+	TODO: check
+CVE-2026-3235 (The WP Data Access plugin for WordPress is vulnerable to Insecure Dire ...)
+	TODO: check
+CVE-2026-3035 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2026-36851 (Path traversal vulnerability in UnPoller 2.33.0 password field allows  ...)
+	TODO: check
+CVE-2026-35445 (Winter CMS is a content management system built on the Laravel PHP fra ...)
+	TODO: check
+CVE-2026-32639 (Winter CMS is a content management system built on the Laravel PHP fra ...)
+	TODO: check
+CVE-2026-32593 (Winter CMS is a content management system built on the Laravel PHP fra ...)
+	TODO: check
+CVE-2026-32258 (Winter is a free, open-source content management system (CMS) based on ...)
+	TODO: check
+CVE-2026-32257 (Winter is a free, open-source content management system (CMS) based on ...)
+	TODO: check
+CVE-2026-2388 (The Reviews and Rating \u2013 Google Reviews plugin for WordPress is v ...)
+	TODO: check
+CVE-2026-19538 (The BLOCKED access control list items that are evaluated to deny acces ...)
+	TODO: check
+CVE-2026-19485 (A Predictable Resource Name vulnerability in BigQuery Import Staging i ...)
+	TODO: check
+CVE-2026-19401 (Any remote client can crash a (debugging/non-release build type) NSD s ...)
+	TODO: check
+CVE-2026-19271 (Improper Neutralization of Special Elements used in an LDAP Query ('LD ...)
+	TODO: check
+CVE-2026-19197 (A user with organization administrator permissions can delete dashboar ...)
+	TODO: check
+CVE-2026-19042 (A command injection vulnerability in TeamViewer Full Client and Host f ...)
+	TODO: check
+CVE-2026-18916 (Any remote client can crash a NSD serve child, by throttling the TCP r ...)
+	TODO: check
+CVE-2026-18884 (The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Bas ...)
+	TODO: check
+CVE-2026-18794 (The OpenRGB network protocol allows attackers to cause memory exhausti ...)
+	TODO: check
+CVE-2026-18664 (When ranges are used for access control (i.e. of the form 1.2.3.4-1.2. ...)
+	TODO: check
+CVE-2026-18252 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2026-18080 (The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plu ...)
+	TODO: check
+CVE-2026-16444 (Improper neutralization of path traversal sequences in TeamViewer Desk ...)
+	TODO: check
+CVE-2026-15990 (The Formidable Charts plugin for WordPress is vulnerable to Directory  ...)
+	TODO: check
+CVE-2026-15985 (The Classified Listing - Mobile Number Verification plugin for WordPre ...)
+	TODO: check
+CVE-2026-15387 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2026-13481 (The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv. ...)
+	TODO: check
+CVE-2026-13480 (The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transpo ...)
+	TODO: check
+CVE-2026-13479 (The LoRaWAN application-layer clock-synchronization service parses dow ...)
+	TODO: check
+CVE-2026-12717 (An Improper Input Validation vulnerability in CData JDBC driver integr ...)
+	TODO: check
+CVE-2026-12587 (The vulnerability allows the unauthorised generation of physical acces ...)
+	TODO: check
+CVE-2025-61165 (An arbitrary file upload vulnerability in the /v1/my_drive/batch_uploa ...)
+	TODO: check
+CVE-2025-61164 (Cohere North AI v1.1.5 was discovered to contain an information leak v ...)
+	TODO: check
+CVE-2025-61163 (Cohere North AI v1.1.5 was discovered to contain excessively permissiv ...)
+	TODO: check
+CVE-2025-61162 (Incorrect access control in Cohere North AI v1.1.5 allows attackers to ...)
+	TODO: check
+CVE-2025-56798 (Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, In ...)
+	TODO: check
+CVE-2025-29419 (CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle att ...)
+	TODO: check
+CVE-2025-10903 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+	TODO: check
+CVE-2023-42179 (Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect A ...)
+	TODO: check
 CVE-2026-XXXX [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal during setup]
 	- bubblewrap 0.12.0-1 (bug #1145655)
 	NOTE: https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx
@@ -39,11 +489,11 @@ CVE-2026-80191 (GROWI applies its page-viewer permission check to attachment req
 	NOT-FOR-US: GROWI
 CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how much da ...)
 	NOT-FOR-US: LeafWiki
-CVE-2026-80186 [Stack Overflow in name2utf8 causes DoS and potential code execution]
+CVE-2026-80186 (A stack-based buffer overflow vulnerability exists in BlueZ, the Linux ...)
 	- bluez <unfixed>
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2
-CVE-2026-80185 [unprivileged-local and adjacent-LE-peer leads to arbitrary code execution as root]
+CVE-2026-80185 (BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can  ...)
 	- bluez <unfixed>
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
@@ -1595,7 +2045,8 @@ CVE-2026-78563 (The NotificationX Pro plugin for WordPress is vulnerable to Stor
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local File Incl ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78468 (The FluentCRM Pro \u2013 Email Newsletter, Automation, Email Marketing ...)
+CVE-2026-78468
+	REJECTED
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the python_ ...)
 	NOT-FOR-US: Amazon
@@ -2187,9 +2638,11 @@ CVE-2026-78477 (The Jawn theme for WordPress is vulnerable to Privilege Escalati
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78470 (The WP Project Manager Pro plugin for WordPress is vulnerable to SQL I ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78467 (The Fluent Support Pro plugin for WordPress is vulnerable to unauthori ...)
+CVE-2026-78467
+	REJECTED
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78466 (The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure D ...)
+CVE-2026-78466
+	REJECTED
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78435 (A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected ...)
 	NOT-FOR-US: Faveo Helpdesk
@@ -9332,7 +9785,7 @@ CVE-2026-70906 (Vulnerability in Oracle Java SE (component: 2D).  Supported vers
 	- openjdk-8 <not-affected> (Vulnerable code not present)
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-61308 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
-	{DSA-6460-1 DSA-6457-1}
+	{DSA-6460-1 DSA-6457-1 DLA-4757-1 DLA-4756-1}
 	- openjdk-26 26.0.2.1+1-1
 	- openjdk-25 25.0.4.1+1-1
 	- openjdk-21 21.0.12.1+1-1
@@ -9341,7 +9794,7 @@ CVE-2026-61308 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
 	- openjdk-8 8u504-ga-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-70907 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
-	{DSA-6460-1 DSA-6457-1}
+	{DSA-6460-1 DSA-6457-1 DLA-4757-1 DLA-4756-1}
 	- openjdk-26 26.0.2.1+1-1
 	- openjdk-25 25.0.4.1+1-1
 	- openjdk-21 21.0.12.1+1-1
@@ -9350,7 +9803,7 @@ CVE-2026-70907 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
 	- openjdk-8 8u504-ga-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-60589 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
-	{DSA-6460-1 DSA-6457-1}
+	{DSA-6460-1 DSA-6457-1 DLA-4757-1 DLA-4756-1}
 	- openjdk-26 26.0.2.1+1-1
 	- openjdk-25 25.0.4.1+1-1
 	- openjdk-21 21.0.12.1+1-1
@@ -10646,7 +11099,8 @@ CVE-2026-75013 (A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20
 	NOT-FOR-US: TOTOLINK
 CVE-2026-75012 (A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u. ...)
 	NOT-FOR-US: TOTOLINK
-CVE-2026-74234 (Legora before 2026-08-14 contains a cross-site scripting vulnerability ...)
+CVE-2026-74234
+	REJECTED
 	NOT-FOR-US: Legora
 CVE-2026-73560 (vLLM is an inference and serving engine for large language models. Pri ...)
 	- vllm <itp> (bug #1095237)
@@ -19572,7 +20026,7 @@ CVE-2026-63134 (Malcolm is a network traffic analysis tool suite. Prior to versi
 	NOT-FOR-US: Malcolm
 CVE-2026-63133 (Malcolm is a network traffic analysis tool suite. Prior to version 26. ...)
 	NOT-FOR-US: Malcolm
-CVE-2026-5917 (libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH bac ...)
+CVE-2026-5917 (libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the li ...)
 	{DSA-6453-1}
 	- libgit2 1.9.7+ds-1 (bug #1144465)
 	NOTE: Fixed by: https://github.com/libgit2/libgit2/commit/b2105b8e60798cb28086d4c648b1cb4854eadccb (v1.9.7)
@@ -63659,7 +64113,7 @@ CVE-2026-53131 (In the Linux kernel, the following vulnerability has been resolv
 	- linux 7.0.13-1
 	[trixie] - linux 6.12.94-1
 	NOTE: https://git.kernel.org/linus/62443dc21114c0bbc476fa62973db89743f2f137 (7.1-rc1)
-CVE-2026-54548
+CVE-2026-54548 (kas is a setup tool for bitbake based projects. Prior to 5.4, internal ...)
 	- kas 5.4-1
 	[trixie] - kas <no-dsa> (Minor issue)
 	[bookworm] - kas <postponed> (Minor issue)
@@ -107288,6 +107742,7 @@ CVE-2026-6862 (A flaw was found in libefiboot, a component of efivar. The device
 	[bullseye] - efivar <postponed> (Minor issue; can be fixed in next update)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2459982
 CVE-2026-6861 (A flaw was found in GNU Emacs. This vulnerability, a memory corruption ...)
+	{DSA-6468-1}
 	- emacs 1:30.2+1-3 (bug #1134692)
 	[bookworm] - emacs <no-dsa> (Minor issue)
 	[bullseye] - emacs <postponed> (Minor issue; can be fixed in next update)
@@ -172020,7 +172475,7 @@ CVE-2025-13642 (The Paid Membership Plugin, Ecommerce, User Registration Form, L
 	NOT-FOR-US: WordPress plugin
 CVE-2025-12946 (A vulnerability in the speedtest feature of affected NETGEAR Nighthawk ...)
 	NOT-FOR-US: Netgear
-CVE-2025-12945 (A vulnerability in NETGEAR Nighthawk R7000P routers lets an authentica ...)
+CVE-2025-12945 (An improper input validationvulnerability in the NETGEAR Nighthawk R70 ...)
 	NOT-FOR-US: Netgear
 CVE-2025-12941 (Denial of Service Vulnerability in NETGEARC6220andC6230(DOCSIS\xae 3.0 ...)
 	NOT-FOR-US: Netgear
@@ -247798,7 +248253,7 @@ CVE-2020-36845 (The KnowBe4 Security Awareness Training application before 2020-
 	NOT-FOR-US: KnowBe4 Security Awareness Training application
 CVE-2020-36844 (The KnowBe4 Security Awareness Training application before 2020-01-10  ...)
 	NOT-FOR-US: KnowBe4 Security Awareness Training application
-CVE-2025-43955 (TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the us ...)
+CVE-2025-43955 (TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restric ...)
 	NOT-FOR-US: Convertigo
 CVE-2025-43954 (QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via header ...)
 	NOT-FOR-US: QMarkdown (aka quasar-ui-qmarkdown)
@@ -643710,16 +644165,16 @@ CVE-2020-15880
 CVE-2020-15879 (Bitwarden Server 1.35.1 allows SSRF because it does not consider certa ...)
 	NOT-FOR-US: Bitwarden Server
 	NOTE: bitwarden client is ITP'ed as #956836
-CVE-2020-15878
-	RESERVED
+CVE-2020-15878 (An issue was discovered in LibreNMS 1.65. A remote authenticated attac ...)
+	TODO: check
 CVE-2020-15877 (An issue was discovered in LibreNMS before 1.65.1. It has insufficient ...)
 	NOT-FOR-US: LibreNMS
-CVE-2020-15876
-	RESERVED
+CVE-2020-15876 (An issue was discovered in LibreNMS 1.65. A remote authenticated attac ...)
+	TODO: check
 CVE-2020-15875
 	RESERVED
-CVE-2020-15874
-	RESERVED
+CVE-2020-15874 (An issue was discovered in LibreNMS 1.65. A remote authenticated attac ...)
+	TODO: check
 CVE-2020-15873 (In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL I ...)
 	NOT-FOR-US: LibreNMS
 CVE-2020-15872



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdc6d046d0c85f143712c219d432a22c86ec6690

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdc6d046d0c85f143712c219d432a22c86ec6690
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/237e711e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list