[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Feb 2 08:13:20 GMT 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
92b774ba by security tracker role at 2026-02-02T08:13:13+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,57 @@
+CVE-2026-25253 (OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayU ...)
+ TODO: check
+CVE-2026-25202 (The database account and password are hardcoded, allowing login with t ...)
+ TODO: check
+CVE-2026-25201 (An unauthenticated user can upload arbitrary files to execute remote c ...)
+ TODO: check
+CVE-2026-25200 (A vulnerability in MagicInfo9 Server allows authorized users to upload ...)
+ TODO: check
+CVE-2026-24788 (RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command inj ...)
+ TODO: check
+CVE-2026-22888 (Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0 ...)
+ TODO: check
+CVE-2026-22881 (Cross-site scripting vulnerability exists in Message function of Cyboz ...)
+ TODO: check
+CVE-2026-20711 (Cross-site scripting vulnerability exists in E-mail function of Cybozu ...)
+ TODO: check
+CVE-2026-1746 (A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability ...)
+ TODO: check
+CVE-2026-1745 (A vulnerability was determined in SourceCodester Medical Certificate G ...)
+ TODO: check
+CVE-2026-1744 (A vulnerability was found in D-Link DSL-6641K N8.TR069.20131126. Affec ...)
+ TODO: check
+CVE-2026-1743 (A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini ...)
+ TODO: check
+CVE-2026-1742 (A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected ...)
+ TODO: check
+CVE-2026-1741 (A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected ...)
+ TODO: check
+CVE-2026-1740 (A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts t ...)
+ TODO: check
+CVE-2026-1739 (A vulnerability has been found in Free5GC pcf up to 1.4.1. This affect ...)
+ TODO: check
+CVE-2026-1738 (A flaw has been found in Open5GS up to 2.7.6. The impacted element is ...)
+ TODO: check
+CVE-2026-1737 (A vulnerability was detected in Open5GS up to 2.7.6. The affected elem ...)
+ TODO: check
+CVE-2026-1736 (A security vulnerability has been detected in Open5GS up to 2.7.6. Imp ...)
+ TODO: check
+CVE-2026-1735 (A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. ...)
+ TODO: check
+CVE-2026-1734 (A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. T ...)
+ TODO: check
+CVE-2026-1733 (A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This a ...)
+ TODO: check
+CVE-2026-1518 (A flaw was found in Keycloak\u2019s CIBA feature where insufficient va ...)
+ TODO: check
+CVE-2026-0658 (The Five Star Restaurant Reservations WordPress plugin before 2.7.9 d ...)
+ TODO: check
+CVE-2025-15396 (The Library Viewer WordPress plugin before 3.2.0 does not sanitise and ...)
+ TODO: check
+CVE-2025-15030 (The User Profile Builder WordPress plugin before 3.15.2 does not have ...)
+ TODO: check
+CVE-2025-13348 (An improper access control vulnerability exists in ASUS Secure Delete ...)
+ TODO: check
CVE-2023-54343 (QWE DL 2.0.1 mobile web application contains a persistent input valida ...)
NOT-FOR-US: QWE DL
CVE-2022-50952 (Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cro ...)
@@ -26,7 +80,8 @@ CVE-2021-47918 (Simple CMS 2.1 contains a remote SQL injection vulnerability tha
NOT-FOR-US: Simple CMS
CVE-2021-47917 (Simple CMS 2.1 contains a persistent cross-site scripting vulnerabilit ...)
NOT-FOR-US: Simple CMS
-CVE-2021-47916 (Simple CMS 2.1 contains a remote SQL injection vulnerability that allo ...)
+CVE-2021-47916
+ REJECTED
NOT-FOR-US: Simple CMS
CVE-2021-47915 (PHP Melody version 3.0 contains a remote SQL injection vulnerability i ...)
NOT-FOR-US: PHP Melody
@@ -874,9 +929,9 @@ CVE-2025-15344 (Tanium addressed a SQL injection vulnerability in Asset.)
NOT-FOR-US: Tanium
CVE-2025-14975 (The Custom Login Page Customizer WordPress plugin before 2.5.4 does no ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-1531
+CVE-2026-1531 (A flaw was found in foreman_kubevirt. When configuring the connection ...)
NOT-FOR-US: foreman-kubevirt
-CVE-2026-1530
+CVE-2026-1530 (A flaw was found in fog-kubevirt. This vulnerability allows a remote a ...)
NOT-FOR-US: fog-kubevirt
CVE-2026-24775 (OpenProject is an open-source, web-based project management software. ...)
NOT-FOR-US: OpenProject
@@ -1332,7 +1387,7 @@ CVE-2026-XXXX [RUSTSEC-2025-0143]
[bookworm] - rust-capnp <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0143.html
NOTE: https://github.com/capnproto/capnproto-rust/issues/605
-CVE-2025-13881
+CVE-2025-13881 (A flaw was found in Keycloak Admin API. This vulnerability allows an a ...)
- keycloak <itp> (bug #1088287)
CVE-2026-24875 (Integer Overflow or Wraparound vulnerability in yoyofr modizer.This is ...)
NOT-FOR-US: yoyofr modizer
@@ -10392,9 +10447,11 @@ CVE-2025-15449 (A vulnerability was determined in cld378632668 JavaMall up to 99
NOT-FOR-US: JavaMall
CVE-2025-15448 (A vulnerability was found in cld378632668 JavaMall up to 994f1e2b01937 ...)
NOT-FOR-US: JavaMall
-CVE-2025-15447 (A vulnerability has been found in Seeyon Zhiyuan OA Web Application Sy ...)
+CVE-2025-15447
+ REJECTED
NOT-FOR-US: OA Web Application System
-CVE-2025-15446 (A flaw has been found in Seeyon Zhiyuan OA Web Application System up t ...)
+CVE-2025-15446
+ REJECTED
NOT-FOR-US: OA Web Application System
CVE-2025-15238 (QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a ...)
NOT-FOR-US: QOCA aim AI Medical Cloud Platform
@@ -11876,7 +11933,8 @@ CVE-2025-15429 (A security vulnerability has been detected in UTT \u8fdb\u53d6 5
NOT-FOR-US: UTT
CVE-2025-15428 (A weakness has been identified in UTT \u8fdb\u53d6 512W 1.7.7-171114. ...)
NOT-FOR-US: UTT
-CVE-2025-15427 (A security flaw has been discovered in Seeyon Zhiyuan OA Web Applicati ...)
+CVE-2025-15427
+ REJECTED
NOT-FOR-US: Seeyon Zhiyuan OA Web Application System
CVE-2025-15426 (A vulnerability was identified in jackying H-ui.admin up to 3.1. This ...)
NOT-FOR-US: jackying H-ui.admin
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/92b774baed086af2ab59f5a68601553715d597af
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/92b774baed086af2ab59f5a68601553715d597af
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260202/b1336a9b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list