[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 29 08:15:57 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d834f424 by security tracker role at 2026-08-29T07:13:00+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,473 @@
+CVE-2026-82343 (A flaw was found in the file-psd plugin in GIMP. When processing a spe ...)
+ TODO: check
+CVE-2026-82333 (multer is a middleware for handling multipart/form-data in Node.js. A ...)
+ TODO: check
+CVE-2026-82329 (JFrog Artifactory contains an authentication weakness that, under defa ...)
+ TODO: check
+CVE-2026-82306 (StarRocks through 4.0.13 contains an information disclosure vulnerabil ...)
+ TODO: check
+CVE-2026-82291 (HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS r ...)
+ TODO: check
+CVE-2026-82290 (Chainlit through 2.12.0 fails to validate ownership of feedback record ...)
+ TODO: check
+CVE-2026-82289 (Gitingest through 0.3.1 fails to properly validate hostnames in _valid ...)
+ TODO: check
+CVE-2026-82288 (Stable Diffusion WebUI through 1.10.1 contains a credential disclosure ...)
+ TODO: check
+CVE-2026-82287 (Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability tha ...)
+ TODO: check
+CVE-2026-82286 (gpt-crawler through 1.5.1 fails to validate the outputFileName paramet ...)
+ TODO: check
+CVE-2026-82285 (bisheng through 2.6.0-fix2 contains a server-side request forgery vuln ...)
+ TODO: check
+CVE-2026-82284 (Quivr versions through 0.0.322 fail to validate chat ownership in the ...)
+ TODO: check
+CVE-2026-82283 (VoltAgent through 2.1.20 fails to validate conversation ownership in m ...)
+ TODO: check
+CVE-2026-82282 (Atlantis through 0.47.1 fails to authenticate the /github-app/setup en ...)
+ TODO: check
+CVE-2026-82281 (Kotaemon through 0.12.0 fails to properly validate conversation owners ...)
+ TODO: check
+CVE-2026-82280 (Quivr through 0.0.322 fails to validate ownership in prompt endpoints, ...)
+ TODO: check
+CVE-2026-82279 (HyperDX through 1.10.1 fails to enforce role-based access controls in ...)
+ TODO: check
+CVE-2026-82278 (BISHENG before 2.6.0 contains a remote code execution vulnerability in ...)
+ TODO: check
+CVE-2026-82277 (Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exp ...)
+ TODO: check
+CVE-2026-82276 (StarRocks through 4.0.13 contains an authentication bypass vulnerabili ...)
+ TODO: check
+CVE-2026-82275 (Qwen-Agent through 0.0.34 contains a path traversal vulnerability in t ...)
+ TODO: check
+CVE-2026-82274 (Twenty through 2.35.0 contains an open redirect vulnerability in the O ...)
+ TODO: check
+CVE-2026-82273 (Mastra through 1.63.0 contains an authentication bypass vulnerability ...)
+ TODO: check
+CVE-2026-82272 (Immich through 3.1.0 fails to properly enforce locked asset visibility ...)
+ TODO: check
+CVE-2026-82271 (R2R through 3.6.5 fails to properly validate user ownership in convers ...)
+ TODO: check
+CVE-2026-82270 (Portkey AI Gateway through 1.15.2 contains a server-side request forge ...)
+ TODO: check
+CVE-2026-82269 (Gophish through 0.12.1 fails to enforce account lockout and password c ...)
+ TODO: check
+CVE-2026-82268 (Qwen-Agent through 0.0.34 contains a server-side request forgery vulne ...)
+ TODO: check
+CVE-2026-82267 (Komodo through 2.3.2 discloses internal resource identifiers and write ...)
+ TODO: check
+CVE-2026-82266 (Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin ...)
+ TODO: check
+CVE-2026-82265 (Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tra ...)
+ TODO: check
+CVE-2026-82264 (Duplicacy through 3.2.5 contains a path traversal vulnerability in the ...)
+ TODO: check
+CVE-2026-82263 (Logto through 1.42.0 contains a server-side request forgery vulnerabil ...)
+ TODO: check
+CVE-2026-82262 (Logto through 1.42.0 contains a server-side request forgery vulnerabil ...)
+ TODO: check
+CVE-2026-82021 (Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerabil ...)
+ TODO: check
+CVE-2026-82020 (Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restrict ...)
+ TODO: check
+CVE-2026-82018 (IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 c ...)
+ TODO: check
+CVE-2026-82017 (IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boo ...)
+ TODO: check
+CVE-2026-81849 (Improper limitation of a pathname to a restricted directory in the aws ...)
+ TODO: check
+CVE-2026-81533 (An application using the MongoDB BI Connector ODBC Driver may encounte ...)
+ TODO: check
+CVE-2026-81532 (A user able to submit SQL through an application using the MongoDB Con ...)
+ TODO: check
+CVE-2026-81520 (A network-reachable client that has not yet authenticated can hold a M ...)
+ TODO: check
+CVE-2026-81518 (When mongosqld is configured with a client certificate authority file, ...)
+ TODO: check
+CVE-2026-81517 (An unauthenticated party able to reach the port of a MongoDB Connector ...)
+ TODO: check
+CVE-2026-81490 (A database user able to create a view in a namespace that MongoDB Conn ...)
+ TODO: check
+CVE-2026-81346 (The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does ...)
+ TODO: check
+CVE-2026-81342 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 d ...)
+ TODO: check
+CVE-2026-81200 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 d ...)
+ TODO: check
+CVE-2026-81026 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 d ...)
+ TODO: check
+CVE-2026-80725 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ TODO: check
+CVE-2026-80488 (The WP Ultimate CSV Importer WordPress plugin before 9.0 does not pro ...)
+ TODO: check
+CVE-2026-80311 (The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 ...)
+ TODO: check
+CVE-2026-77939 (Flextype CMS through v1.0.0-dev contains an expression language inject ...)
+ TODO: check
+CVE-2026-77786 (The Rank Math SEO WordPress plugin before 1.0.277 does not check that ...)
+ TODO: check
+CVE-2026-77704 (The Booking for Appointments and Events Calendar WordPress plugin bef ...)
+ TODO: check
+CVE-2026-77586 (In MongoDB Connector for BI, MongoDB object names such as collection, ...)
+ TODO: check
+CVE-2026-77218 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticat ...)
+ TODO: check
+CVE-2026-77217 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticat ...)
+ TODO: check
+CVE-2026-77184 (In MongoDB Connector for BI, the description text of a collection's JS ...)
+ TODO: check
+CVE-2026-77078 (multer is a middleware for handling multipart/form-data in Node.js. A ...)
+ TODO: check
+CVE-2026-77063 (multer is a middleware for handling multipart/form-data in Node.js. Wh ...)
+ TODO: check
+CVE-2026-77037 (multer is a middleware for handling multipart/form-data in Node.js. In ...)
+ TODO: check
+CVE-2026-77012 (The \u7231\u91c7\u96c6\u6570\u636e\u91c7\u96c6\u548c\u53d1\u5e03\u63d2 ...)
+ TODO: check
+CVE-2026-77010 (The HEL Online Classroom: AI-powered Online Classrooms WordPress plugi ...)
+ TODO: check
+CVE-2026-77008 (The HEL Online Classroom: AI-powered Online Classrooms WordPress plugi ...)
+ TODO: check
+CVE-2026-77007 (The HEL Online Classroom: AI-powered Online Classrooms WordPress plugi ...)
+ TODO: check
+CVE-2026-76798 (The MongoSQL Transition Readiness Tool writes query text and user name ...)
+ TODO: check
+CVE-2026-76797 (The MongoSQL Transition Readiness Tool writes database and collection ...)
+ TODO: check
+CVE-2026-76794 (MongoSQL Transition Readiness Tool does not sufficiently encode databa ...)
+ TODO: check
+CVE-2026-76651 (A buffer overflow vulnerability exists in the embedded HTTP servicein ...)
+ TODO: check
+CVE-2026-76650 (A NULL pointer dereference vulnerability exists inTL-WR841N v14inthe U ...)
+ TODO: check
+CVE-2026-76649 (A NULL pointer dereference vulnerability exists in TL-WR841N v14 in th ...)
+ TODO: check
+CVE-2026-76586 (The Appointment Booking Calendar Plugin and Scheduling Plugin WordPre ...)
+ TODO: check
+CVE-2026-76548 (The User Profile Builder WordPress plugin before 4.0.1 does not prope ...)
+ TODO: check
+CVE-2026-76547 (The User Profile Builder WordPress plugin before 4.0.1 does not valid ...)
+ TODO: check
+CVE-2026-76546 (The User Profile Builder WordPress plugin before 4.0.1 does not escap ...)
+ TODO: check
+CVE-2026-75486 (Synk Sweater Comb before 3.8.8 contains a command injection vulnerabil ...)
+ TODO: check
+CVE-2026-75126 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple au ...)
+ TODO: check
+CVE-2026-75125 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
+ TODO: check
+CVE-2026-75124 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authe ...)
+ TODO: check
+CVE-2026-75123 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
+ TODO: check
+CVE-2026-75122 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
+ TODO: check
+CVE-2026-75121 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
+ TODO: check
+CVE-2026-75118 (A pre-authentication stack-based buffer overflow vulnerability exists ...)
+ TODO: check
+CVE-2026-72984 (Access of resource using incompatible type ('type confusion') in Micro ...)
+ TODO: check
+CVE-2026-70331 (Improper neutralization of input used for llm prompting in Microsoft E ...)
+ TODO: check
+CVE-2026-70309 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
+ TODO: check
+CVE-2026-66324 (External control of file name or path in Microsoft Edge (Chromium-base ...)
+ TODO: check
+CVE-2026-66323 (Improper neutralization of parameter/argument delimiters in Microsoft ...)
+ TODO: check
+CVE-2026-62904 (Incorrect authorization in Microsoft Edge (Chromium-based) allows an u ...)
+ TODO: check
+CVE-2026-58616 (Concurrent execution using shared resource with improper synchronizati ...)
+ TODO: check
+CVE-2026-56100 (SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalatio ...)
+ TODO: check
+CVE-2026-55891 (PrivateBin is an online pastebin where the server has zero knowledge o ...)
+ TODO: check
+CVE-2026-55867 (Graylog is a free and open log management platform. From 6.2.0 until 6 ...)
+ TODO: check
+CVE-2026-55860 (MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client imp ...)
+ TODO: check
+CVE-2026-55859 (MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client imp ...)
+ TODO: check
+CVE-2026-55858 (MariaDB Connector/J is used to connect applications developed in Java ...)
+ TODO: check
+CVE-2026-55857 (MariaDB Connector/J is used to connect applications developed in Java ...)
+ TODO: check
+CVE-2026-55856 (MariaDB Connector/J is used to connect applications developed in Java ...)
+ TODO: check
+CVE-2026-55855 (MariaDB Connector/Node.js is used to connect applications developed on ...)
+ TODO: check
+CVE-2026-55854 (MariaDB Connector/Node.js is used to connect applications developed on ...)
+ TODO: check
+CVE-2026-55848 (mapfish-print is a component of MapFish for printing templated cartogr ...)
+ TODO: check
+CVE-2026-55841 (Graylog is a free and open log management platform. Prior to Graylog S ...)
+ TODO: check
+CVE-2026-55834 (Pocket ID is an OIDC provider that allows users to authenticate with t ...)
+ TODO: check
+CVE-2026-55785 (free5GC is an open-source implementation of the 5G core network. Prior ...)
+ TODO: check
+CVE-2026-55784 (free5GC is an open-source implementation of the 5G core network. In ve ...)
+ TODO: check
+CVE-2026-55779 (Silverstripe Versioned provides versioning for Silverstripe models. Pr ...)
+ TODO: check
+CVE-2026-55764 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-55763 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-55696 (PrivateBin is an online pastebin where the server has zero knowledge o ...)
+ TODO: check
+CVE-2026-55678 (Arc is an open, SQL-native time-series database for telemetry. From 26 ...)
+ TODO: check
+CVE-2026-55673 (PowSyBl (Power System Blocks) is a framework to build power system ori ...)
+ TODO: check
+CVE-2026-55634 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
+ TODO: check
+CVE-2026-55584 (phpSysInfo is a customizable PHP script that displays system informati ...)
+ TODO: check
+CVE-2026-55569 (aqua is a declarative command-line version manager written in Go. Prio ...)
+ TODO: check
+CVE-2026-55566 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
+ TODO: check
+CVE-2026-55565 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
+ TODO: check
+CVE-2026-55559 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
+ TODO: check
+CVE-2026-55552 (Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFi ...)
+ TODO: check
+CVE-2026-55549 (Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects a ...)
+ TODO: check
+CVE-2026-55547 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
+ TODO: check
+CVE-2026-55545 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
+ TODO: check
+CVE-2026-55521 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
+ TODO: check
+CVE-2026-55511 (Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamc ...)
+ TODO: check
+CVE-2026-55509 (WsgiDAV is a generic and extendable WebDAV server based on WSGI. Prior ...)
+ TODO: check
+CVE-2026-55485 (Piccolo Admin is an admin interface and content management system for ...)
+ TODO: check
+CVE-2026-55484 (ALOS HTTP is a Linux-first Go web framework and application server bui ...)
+ TODO: check
+CVE-2026-55425 (Graylog is a free and open log management platform. From 7.1.0 until 7 ...)
+ TODO: check
+CVE-2026-55378 (JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 ...)
+ TODO: check
+CVE-2026-55248 (plone.app.portlets provides portlets and a Plone-specific user interfa ...)
+ TODO: check
+CVE-2026-55247 (plone.app.event provides the event content type for Plone. Prior to ve ...)
+ TODO: check
+CVE-2026-55245 (Bifrost is an enterprise AI gateway for routing requests to model prov ...)
+ TODO: check
+CVE-2026-55220 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
+ TODO: check
+CVE-2026-55215 (MariaDB Connector/Node.js is used to connect applications developed on ...)
+ TODO: check
+CVE-2026-55108 (KubeVela is an open source application delivery platform. Prior to 1.9 ...)
+ TODO: check
+CVE-2026-55068 (free5GC is an open-source implementation of the 5G core network. In 4. ...)
+ TODO: check
+CVE-2026-55067 (Vikunja is an open-source self-hosted task management platform. Prior ...)
+ TODO: check
+CVE-2026-55066 (Vikunja is an open-source self-hosted task management platform. Prior ...)
+ TODO: check
+CVE-2026-55065 (Vikunja is an open-source self-hosted task management platform. From 0 ...)
+ TODO: check
+CVE-2026-55064 (Vikunja is an open-source self-hosted task management platform. From 2 ...)
+ TODO: check
+CVE-2026-54788 (dd-trace-rs provides Datadog application performance monitoring for Ru ...)
+ TODO: check
+CVE-2026-54766 (Vikunja is an open-source self-hosted task management platform. From 0 ...)
+ TODO: check
+CVE-2026-54755 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-54754 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-54746 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
+ TODO: check
+CVE-2026-54745 (Kubeflow Pipelines enables users to build and deploy portable, scalabl ...)
+ TODO: check
+CVE-2026-51665 (Incorrect access control in the getTracerouteCfg function of TOTOLINK ...)
+ TODO: check
+CVE-2026-51664 (Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51663 (Incorrect access control in the getWiFiApcliScan function of TOTOLINK ...)
+ TODO: check
+CVE-2026-51662 (Incorrect access control in the getCloudSrvCheckStatus function of TOT ...)
+ TODO: check
+CVE-2026-51661 (Incorrect access control in the getPortForwardRules function of TOTOLI ...)
+ TODO: check
+CVE-2026-51660 (Incorrect access control in the getIpPortFilterRules function of TOTOL ...)
+ TODO: check
+CVE-2026-51659 (Incorrect access control in the getUrlFilterRules function of TOTOLINK ...)
+ TODO: check
+CVE-2026-51658 (Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1. ...)
+ TODO: check
+CVE-2026-51657 (Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51656 (Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51655 (Incorrect access control in the getMacFilterRules function of TOTOLINK ...)
+ TODO: check
+CVE-2026-51654 (Incorrect access control in the getScheduleCfg function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51653 (Incorrect access control in the getStorageCfg function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51652 (Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51651 (Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51650 (Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51649 (Incorrect access control in the getDiagnosisCfg function of TOTOLINK T ...)
+ TODO: check
+CVE-2026-51648 (Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51647 (Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51646 (Incorrect access control in the getParentalRules function of TOTOLINK ...)
+ TODO: check
+CVE-2026-51645 (Incorrect access control in the getPasswordCfg function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51644 (Incorrect access control in the getCrpcConfig function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51643 (Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1. ...)
+ TODO: check
+CVE-2026-51642 (Incorrect access control in the getMeshRoutingTable function of TOTOLI ...)
+ TODO: check
+CVE-2026-51641 (Incorrect access control in the getWiFiMeshConfig function of TOTOLINK ...)
+ TODO: check
+CVE-2026-51640 (Incorrect access control in the getMeshNeighborTable function of TOTOL ...)
+ TODO: check
+CVE-2026-51639 (Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T ...)
+ TODO: check
+CVE-2026-51638 (Incorrect access control in the getWiFiGuestCfg function of TOTOLINK T ...)
+ TODO: check
+CVE-2026-51637 (Incorrect access control in the getMeshPortalTable function of TOTOLIN ...)
+ TODO: check
+CVE-2026-51636 (Incorrect access control in the getWiFiAclRules function of TOTOLINK T ...)
+ TODO: check
+CVE-2026-51635 (Incorrect access control in the getWiFiScheduleCfg function of TOTOLIN ...)
+ TODO: check
+CVE-2026-51634 (Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T ...)
+ TODO: check
+CVE-2026-51633 (Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLI ...)
+ TODO: check
+CVE-2026-51632 (Incorrect access control in the getWiFiAdvancedCfg function of TOTOLIN ...)
+ TODO: check
+CVE-2026-51631 (Incorrect access control in the getStaticDhcpRules function of TOTOLIN ...)
+ TODO: check
+CVE-2026-51630 (Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51629 (Incorrect access control in the getStaticDhcpRules function of TOTOLIN ...)
+ TODO: check
+CVE-2026-51628 (Incorrect access control in the getGenerateWiFiWpsPin function of TOTO ...)
+ TODO: check
+CVE-2026-51627 (Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51626 (Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51625 (Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51624 (Incorrect access control in the getStationMacByIp function of TOTOLINK ...)
+ TODO: check
+CVE-2026-51623 (Incorrect access control in the getDdnsStatus function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51622 (Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1. ...)
+ TODO: check
+CVE-2026-51621 (Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1 ...)
+ TODO: check
+CVE-2026-51620 (Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51619 (Incorrect access control in the getOnlineClient function of TOTOLINK T ...)
+ TODO: check
+CVE-2026-51618 (Incorrect access control in the getWizardCfg function of TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51617 (Incorrect access control in the getSysStatusCfg function of TOTOLINK T ...)
+ TODO: check
+CVE-2026-51616 (Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4. ...)
+ TODO: check
+CVE-2026-51615 (Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1. ...)
+ TODO: check
+CVE-2026-51614 (Incorrect access control in the getAccessDeviceCfg function of TOTOLIN ...)
+ TODO: check
+CVE-2026-51613 (Incorrect access control in the getDeviceInfo function of TOTOLINK T6 ...)
+ TODO: check
+CVE-2026-51611 (Incorrect access control in the startSlaveReboot function of TOTOLINK ...)
+ TODO: check
+CVE-2026-51610 (Incorrect access control in the RebootSystem function of TOTOLINK T6 4 ...)
+ TODO: check
+CVE-2026-51376 (An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause ...)
+ TODO: check
+CVE-2026-50980 (Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management ...)
+ TODO: check
+CVE-2026-41012 (Traffic interception vulnerability in BOSH Director vCenter CPI allows ...)
+ TODO: check
+CVE-2026-3686 (IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vuln ...)
+ TODO: check
+CVE-2026-3627 (IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remo ...)
+ TODO: check
+CVE-2026-39071 (WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cr ...)
+ TODO: check
+CVE-2026-39070 (WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross ...)
+ TODO: check
+CVE-2026-22056 (StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher i ...)
+ TODO: check
+CVE-2026-19430 (The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does ...)
+ TODO: check
+CVE-2026-19295 (IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker ...)
+ TODO: check
+CVE-2026-19294 (IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticat ...)
+ TODO: check
+CVE-2026-19286 (IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to ...)
+ TODO: check
+CVE-2026-18904 (IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to ...)
+ TODO: check
+CVE-2026-18899 (IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to ...)
+ TODO: check
+CVE-2026-18891 (IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to ...)
+ TODO: check
+CVE-2026-18729 (IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticat ...)
+ TODO: check
+CVE-2026-18545 (IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side req ...)
+ TODO: check
+CVE-2026-18527 (IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime ...)
+ TODO: check
+CVE-2026-18234 (The MStore API WordPress plugin before 4.21.1 does not verify that th ...)
+ TODO: check
+CVE-2026-18233 (The MStore API WordPress plugin before 4.21.1 does not verify that th ...)
+ TODO: check
+CVE-2026-17522 (The Newsletters WordPress plugin before 4.17 does not perform any nonc ...)
+ TODO: check
+CVE-2026-17520 (The Newsletters WordPress plugin before 4.17 does not generate its API ...)
+ TODO: check
+CVE-2026-17203 (IBM Administration Runtime Expert for i 1R1M0 could allow a remote aut ...)
+ TODO: check
+CVE-2026-16947 (The Total processing card payments for WooCommerce WordPress plugin th ...)
+ TODO: check
+CVE-2026-16821 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
+ TODO: check
+CVE-2026-16600 (The SmartAIPress WordPress plugin through 1.2.0 does not perform a cap ...)
+ TODO: check
+CVE-2026-16259 (The Uix UserCenter WordPress plugin through 1.0.3 does not verify that ...)
+ TODO: check
+CVE-2026-16061 (The Rest Routes WordPress plugin through 5.5.5 does not sanitize and ...)
+ TODO: check
+CVE-2026-13735 (Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypt ...)
+ TODO: check
+CVE-2026-13734 (Zephyr's WireGuard VPN data-plane receive handler wg_process_data_mess ...)
+ TODO: check
+CVE-2026-10522 (The MemberHero WordPress plugin through 6.9 does not restrict which a ...)
+ TODO: check
+CVE-2025-64649 (IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perfo ...)
+ TODO: check
+CVE-2025-36290 (IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not vali ...)
+ TODO: check
+CVE-2025-36271 (IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker t ...)
+ TODO: check
CVE-2026-59944
- composer 2.10.3-1
[trixie] - composer <no-dsa> (Minor issue)
@@ -14696,7 +15166,7 @@ CVE-2026-66801
NOT-FOR-US: Red Hat cluster-backup-operator
CVE-2026-66800 (Server-side request forgery (ssrf) in Azure Data Factory allows an una ...)
NOT-FOR-US: Red Hat cluster-backup-operator
-CVE-2026-66798
+CVE-2026-66798 (Use after free in Microsoft Edge (Chromium-based) allows an unauthoriz ...)
NOT-FOR-US: Red Hat cluster-backup-operator
CVE-2026-66797 (Improper access control in CloudStack's annotation functionality allow ...)
NOT-FOR-US: Red Hat cluster-backup-operator
@@ -57408,21 +57878,21 @@ CVE-2026-42505 (Handshakes which used Encrypted Client Hello could be de-anonymi
NOTE: Fixed by: https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0 (go1.26.5)
NOTE: Fixed by: https://github.com/golang/go/commit/fc9f821bb660c1dcb9e57868b62f62bf3afb5842 (go1.25.12)
CVE-2026-41252 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-w5vg-6qmv-j63j
NOTE: https://github.com/neutrinolabs/xrdp/commit/a64b788f24d8f5c133b75cee2f920b1258e3fb09 (v0.10.6.1-rc.1)
NOTE: https://github.com/neutrinolabs/xrdp/commit/b07b78f170732480c5ecab010d2105ac74e8c0bd (v0.10.6.1-rc.1)
CVE-2026-41521 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-v8w6-pf78-9458
NOTE: https://github.com/neutrinolabs/xrdp/commit/1179d6b737b59024e70a0b223652656947a3047c (v0.10.6.1-rc.1)
NOTE: https://github.com/neutrinolabs/xrdp/commit/c610765475361e30f498f69674f25b650266ab77 (v0.10.6.1-rc.1)
CVE-2026-44178 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-hh7r-2rmq-q4g4
@@ -57437,19 +57907,19 @@ CVE-2026-42218 (xrdp is an open source RDP server. Versions 0.10.6 and prior con
NOTE: Fixed by: https://github.com/neutrinolabs/xrdp/commit/13bbb975d49c7e2e328322c3ea052c9d01d53092 (v0.10.6.1-rc.1)
NOTE: Regression fix: https://github.com/neutrinolabs/xrdp/commit/36bce27b5ea50878038a4b66a6dcf11afd5128d9 (v0.10.6.1-rc.1)
CVE-2026-44978 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9cg5-f7m7-ppvj
NOTE: https://github.com/neutrinolabs/xrdp/commit/d308e77c3d115b6528e6cf9df0861838f31606ab (v0.10.6.1-rc.1)
CVE-2026-54538 (xrdp is an open source RDP server. In versions 0.10.6 and prior, a n i ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9j3q-9mvw-qv7j
NOTE: https://github.com/neutrinolabs/xrdp/commit/9a610fc2f297613790bc91086b183ca81d06e6f5 (v0.10.6.1-rc.1)
CVE-2026-55238 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-mg8j-x9rw-9xv3
@@ -57463,13 +57933,13 @@ CVE-2026-55626 (xrdp is an open source RDP server. In versions 0.10.6 and prior,
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-m3xx-cpc4-982r
NOTE: https://github.com/neutrinolabs/xrdp/commit/517b8a180d8cbad1b7950ff4f6b31491318f5bb5 (v0.10.6.1-rc.1)
CVE-2026-55639 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-6g36-mxcf-r3gc
NOTE: https://github.com/neutrinolabs/xrdp/commit/5d72302e1b777ae879f202678f5c1fd4c9b15fbf (v0.10.6.1-rc.1)
CVE-2026-55645 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3m4m-h22g-c7xx
@@ -65592,7 +66062,7 @@ CVE-2026-77506 (Znuny before LTS 6.5.22 allows AgentTicketEmailResend template X
[trixie] - znuny <no-dsa> (Non-free not supported)
[bookworm] - znuny <no-dsa> (Non-free not supported)
NOTE: https://www.znuny.org/en/advisories/zsa-2026-12
-CVE-2026-55520
+CVE-2026-55520 (Protego is a pure-Python robots.txt parser with support for modern con ...)
- python-protego 0.6.2+dfsg-1
[trixie] - python-protego <no-dsa> (Minor issue)
[bookworm] - python-protego <postponed> (Minor issue)
@@ -113686,14 +114156,14 @@ CVE-2026-35402 (mcp-neo4j-cypher is an MCP server for executing Cypher queries a
CVE-2026-35061 (Anviz CX7 Firmwareis vulnerable to the most recently captured test pho ...)
NOT-FOR-US: Anviz
CVE-2026-33689 (xrdp is an open source RDP server. Versions through 0.10.5 have an out ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-92mr-6wpp-27jj
NOTE: https://github.com/neutrinolabs/xrdp/commit/d1323f9bb0caebdb9ca46627579954c25599ed25 (v0.10.6)
CVE-2026-33569 (AnvizCX2 Lite and CX7 administrative sessions occur over HTTP, enablin ...)
NOT-FOR-US: Anviz
CVE-2026-33516 (xrdp is an open source RDP server. Versions through 0.10.5 contain an ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-rvh9-9wm3-28c7
NOTE: https://github.com/neutrinolabs/xrdp/commit/d2a8802c3124c103cd0c40aba661602420d01a73 (v0.10.6)
@@ -113713,24 +114183,24 @@ CVE-2026-32650 (Anviz CrossChex Standardis vulnerable when an attacker manipulat
CVE-2026-32648 (AnvizCX2 Lite and CX7are vulnerable to unauthenticated access that dis ...)
NOT-FOR-US: Anviz
CVE-2026-32624 (xrdp is an open source RDP server. Versions through 0.10.5 contain a h ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-7q2g-6fjr-h6pp
NOTE: https://github.com/neutrinolabs/xrdp/commit/4594d4ed9198f5fa6c1f2eb03fac96110a4e0ebb (v0.10.6)
CVE-2026-32623 (xrdp is an open source RDP server. Versions through 0.10.5 contain a h ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-phw3-qp59-x2v4
NOTE: https://github.com/neutrinolabs/xrdp/commit/b6b610f5f7bba56fcd355bb2131adffd2ba19e5a (v0.10.6)
CVE-2026-32324 (Anviz CX7 Firmwareis vulnerable because the application embeds reusabl ...)
NOT-FOR-US: Anviz
CVE-2026-32107 (xrdp is an open source RDP server. In versions through 0.10.5, the ses ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-p5m6-7m43-pjv9
NOTE: https://github.com/neutrinolabs/xrdp/commit/68b5ae9e2e3b3e040fe2174aa5fc652f0c5c67d1 (v0.10.6)
CVE-2026-32105 (xrdp is an open source RDP server. In versions through 0.10.5, xrdp do ...)
- {DSA-6469-1}
+ {DSA-6469-1 DLA-4759-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-j2jm-c596-c5q3
NOTE: https://github.com/neutrinolabs/xrdp/commit/391aaf92f9f944a612b8187552c9a49dcf3a60a5 (v0.10.6)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d834f42451d1900c13ecd4cb816bf7a02584145a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d834f42451d1900c13ecd4cb816bf7a02584145a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260829/0d061ad1/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list