[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 23 20:13:55 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
60a0fffa by security tracker role at 2026-07-23T19:13:49+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,603 @@
+CVE-2026-9729 (The Webpushr Push Notifications plugin for WordPress is vulnerable to ...)
+ TODO: check
+CVE-2026-9713 (The Lumise Product Designer for WooCommerce plugin for WordPress is vu ...)
+ TODO: check
+CVE-2026-9635 (The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to ...)
+ TODO: check
+CVE-2026-8287 (Allocation of resources without limits or throttling vulnerability in ...)
+ TODO: check
+CVE-2026-6516 (Zohocorp ManageEngine ADAudit Plus versionsbefore 8606 are affected by ...)
+ TODO: check
+CVE-2026-65920 (Diffusers through 0.39.0, fixed in commit cee298c, contains a path tra ...)
+ TODO: check
+CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary file read ...)
+ TODO: check
+CVE-2026-65918 (PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains ...)
+ TODO: check
+CVE-2026-65917 (CyberPanel through 1.9.1, fixed in commit b198460, contains an insecur ...)
+ TODO: check
+CVE-2026-65916 (CyberPanel through 1.9.1, fixed in commit b198460, contains a missing ...)
+ TODO: check
+CVE-2026-65914 (DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sani ...)
+ TODO: check
+CVE-2026-65913 (DOMPurify before 3.3.2 contains a prototype pollution vulnerability in ...)
+ TODO: check
+CVE-2026-65912 (DOMPurify before 3.3.2 contains a URI validation bypass vulnerability ...)
+ TODO: check
+CVE-2026-65911 (In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR ...)
+ TODO: check
+CVE-2026-65908 (In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution ...)
+ TODO: check
+CVE-2026-65907 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git ...)
+ TODO: check
+CVE-2026-65906 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 \u0441ode execution v ...)
+ TODO: check
+CVE-2026-65904 (DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_P ...)
+ TODO: check
+CVE-2026-65903 (DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function ...)
+ TODO: check
+CVE-2026-65902 (DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct refe ...)
+ TODO: check
+CVE-2026-65901 (DOMPurify through 3.4.6 contains a cross-site scripting vulnerability ...)
+ TODO: check
+CVE-2026-65900 (DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE ...)
+ TODO: check
+CVE-2026-65899 (DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types ...)
+ TODO: check
+CVE-2026-65898 (DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when ...)
+ TODO: check
+CVE-2026-65897 (Grav API Plugin versions before 1.0.10 fail to validate the groups fie ...)
+ TODO: check
+CVE-2026-65896 (Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0. ...)
+ TODO: check
+CVE-2026-65895 (Grav API Plugin versions before 1.0.10 fail to restrict write access t ...)
+ TODO: check
+CVE-2026-65763 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Map ...)
+ TODO: check
+CVE-2026-65762 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Gue ...)
+ TODO: check
+CVE-2026-65761 (Joomla Extension - joomshaper.com - Unauthenticated SQL injection in E ...)
+ TODO: check
+CVE-2026-65760 (Joomla Extension - joomshaper.com - cross-customer order and personal ...)
+ TODO: check
+CVE-2026-65759 (Joomla Extension - joomshaper.com - unauthenticated payment/order forg ...)
+ TODO: check
+CVE-2026-65758 (Joomla Extension - tassos.gr - Sensitive data exposure in Convert Form ...)
+ TODO: check
+CVE-2026-65757 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
+ TODO: check
+CVE-2026-65756 (Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts ...)
+ TODO: check
+CVE-2026-65755 (Joomla Extension - regularlabs.com - Date-sensitive query-cache leakag ...)
+ TODO: check
+CVE-2026-65754 (Joomla Extension - regularlabs.com - Insecure path handling in ReRepla ...)
+ TODO: check
+CVE-2026-65713 (Joomla Extension - regularlabs.com - Insecure path handling in Modals ...)
+ TODO: check
+CVE-2026-65712 (Joomla Extension - regularlabs.com - Insecure path handling in CDN for ...)
+ TODO: check
+CVE-2026-65702 (Vanna through 2.0.2 contains a path traversal vulnerability in the Fil ...)
+ TODO: check
+CVE-2026-65701 (SoftVC VITS Singing Voice Conversion through commit 730930d contains a ...)
+ TODO: check
+CVE-2026-65700 (h2oGPT through 0.2.1 contains a path traversal vulnerability in the Op ...)
+ TODO: check
+CVE-2026-65699 (AgentGPT through 1.0.0 contains an authorization bypass through user-c ...)
+ TODO: check
+CVE-2026-65698 (Void through 1.3.4 contains a path traversal vulnerability in the AI a ...)
+ TODO: check
+CVE-2026-65697 (Fathom Lite through 1.3.1 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-65696 (Overseerr through 1.35.0 contains an authorization bypass through user ...)
+ TODO: check
+CVE-2026-65695 (Office-Word-MCP-Server through 1.1.11 contains a path traversal vulner ...)
+ TODO: check
+CVE-2026-65690 (Bold Reports Standalone Report Designer before 14.1.12 contains a miss ...)
+ TODO: check
+CVE-2026-65689 (Bold Reports Standalone Report Designer before 14.1.12 contains a miss ...)
+ TODO: check
+CVE-2026-65688 (Bold Reports Standalone Report Designer before 14.1.12 contains a miss ...)
+ TODO: check
+CVE-2026-65687 (Bold Reports Standalone Report Designer before 14.1.12 contains a miss ...)
+ TODO: check
+CVE-2026-65608 (Grav versions >= 1.7.0 and before 2.0.9 contain a remote code executio ...)
+ TODO: check
+CVE-2026-65607 (SiYuan before v3.7.2 contains a path traversal vulnerability in the /e ...)
+ TODO: check
+CVE-2026-65606 (SiYuan before v3.7.2 contains a cross-site scripting vulnerability in ...)
+ TODO: check
+CVE-2026-65605 (SiYuan before v3.7.2 contains a stored cross-site scripting vulnerabil ...)
+ TODO: check
+CVE-2026-65550 (Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.)
+ TODO: check
+CVE-2026-65540 (Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 wit ...)
+ TODO: check
+CVE-2026-65539 (Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitema ...)
+ TODO: check
+CVE-2026-65538 (Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.)
+ TODO: check
+CVE-2026-65537 (Subscriber Broken Access Control in Cyr to Lat reloaded \u2013 transli ...)
+ TODO: check
+CVE-2026-65536 (Unauthenticated Cross Site Request Forgery (CSRF) in \u0627\u0641\u063 ...)
+ TODO: check
+CVE-2026-65535 (Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 vers ...)
+ TODO: check
+CVE-2026-65534 (Author Cross Site Scripting (XSS) in Custom links in Elementor Image C ...)
+ TODO: check
+CVE-2026-65533 (Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 vers ...)
+ TODO: check
+CVE-2026-65532 (Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 version ...)
+ TODO: check
+CVE-2026-65531 (Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.)
+ TODO: check
+CVE-2026-65530 (Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.)
+ TODO: check
+CVE-2026-65529 (Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.)
+ TODO: check
+CVE-2026-65528 (Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versi ...)
+ TODO: check
+CVE-2026-65527 (Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2 ...)
+ TODO: check
+CVE-2026-65526 (Contributor SQL Injection in Visualizer <= 4.0.6 versions.)
+ TODO: check
+CVE-2026-65525 (Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versi ...)
+ TODO: check
+CVE-2026-65524 (Contributor Broken Access Control in Avada Custom Branding <= 1.2 vers ...)
+ TODO: check
+CVE-2026-65522 (Contributor Cross Site Scripting (XSS) in Manual - Documentation, Know ...)
+ TODO: check
+CVE-2026-65521 (Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 ve ...)
+ TODO: check
+CVE-2026-65519 (Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 version ...)
+ TODO: check
+CVE-2026-65518 (Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal ...)
+ TODO: check
+CVE-2026-65516 (Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimat ...)
+ TODO: check
+CVE-2026-65514 (Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= ...)
+ TODO: check
+CVE-2026-65512 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log < ...)
+ TODO: check
+CVE-2026-65511 (Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, ...)
+ TODO: check
+CVE-2026-65510 (Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoic ...)
+ TODO: check
+CVE-2026-65506 (Unauthenticated Broken Access Control in MP3 Audio Player for Music, R ...)
+ TODO: check
+CVE-2026-65505 (Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elemento ...)
+ TODO: check
+CVE-2026-65503 (Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor ...)
+ TODO: check
+CVE-2026-65501 (Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic ...)
+ TODO: check
+CVE-2026-65500 (Unauthenticated Broken Access Control in Manual - Documentation, Knowl ...)
+ TODO: check
+CVE-2026-65499 (Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= ...)
+ TODO: check
+CVE-2026-65498 (Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions ...)
+ TODO: check
+CVE-2026-65497 (Administrator PHP Object Injection in Complianz <= 7.5.0 versions.)
+ TODO: check
+CVE-2026-65496 (Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versio ...)
+ TODO: check
+CVE-2026-65495 (Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.)
+ TODO: check
+CVE-2026-65494 (Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.)
+ TODO: check
+CVE-2026-65493 (Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.)
+ TODO: check
+CVE-2026-65492 (Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versi ...)
+ TODO: check
+CVE-2026-65491 (Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.)
+ TODO: check
+CVE-2026-65490 (Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5. ...)
+ TODO: check
+CVE-2026-65489 (Unauthenticated Broken Access Control in LA-Studio Element Kit for Ele ...)
+ TODO: check
+CVE-2026-65488 (Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element ...)
+ TODO: check
+CVE-2026-65487 (Unauthenticated Broken Access Control in Photography <= 7.7.6 versions ...)
+ TODO: check
+CVE-2026-65486 (Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.)
+ TODO: check
+CVE-2026-65485 (Unauthenticated Broken Access Control in Content Control <= 2.6.5 vers ...)
+ TODO: check
+CVE-2026-65484 (Contributor Broken Access Control in Style Kits <= 2.6.5 versions.)
+ TODO: check
+CVE-2026-65483 (Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 ...)
+ TODO: check
+CVE-2026-65482 (Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for El ...)
+ TODO: check
+CVE-2026-65481 (Contributor Local File Inclusion in Vino <= 1.9 versions.)
+ TODO: check
+CVE-2026-65480 (Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.)
+ TODO: check
+CVE-2026-65479 (Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.)
+ TODO: check
+CVE-2026-65478 (Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.)
+ TODO: check
+CVE-2026-65477 (Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.)
+ TODO: check
+CVE-2026-65476 (Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.)
+ TODO: check
+CVE-2026-65475 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+ TODO: check
+CVE-2026-65474 (Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 vers ...)
+ TODO: check
+CVE-2026-65473 (Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolk ...)
+ TODO: check
+CVE-2026-65472 (Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= ...)
+ TODO: check
+CVE-2026-65471 (Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.1 ...)
+ TODO: check
+CVE-2026-65470 (Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 vers ...)
+ TODO: check
+CVE-2026-65469 (Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 vers ...)
+ TODO: check
+CVE-2026-65468 (Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.)
+ TODO: check
+CVE-2026-65467 (Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 ...)
+ TODO: check
+CVE-2026-65466 (Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 ...)
+ TODO: check
+CVE-2026-65465 (Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= ...)
+ TODO: check
+CVE-2026-65464 (Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 ...)
+ TODO: check
+CVE-2026-65463 (Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS ...)
+ TODO: check
+CVE-2026-65462 (Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.)
+ TODO: check
+CVE-2026-65461 (Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1 ...)
+ TODO: check
+CVE-2026-65460 (Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway ...)
+ TODO: check
+CVE-2026-65458 (Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.)
+ TODO: check
+CVE-2026-65457 (Subscriber Broken Access Control in \u042eKassa \u0434\u043b\u044f Woo ...)
+ TODO: check
+CVE-2026-65456 (Contributor Insecure Direct Object References (IDOR) in Product Slider ...)
+ TODO: check
+CVE-2026-65455 (Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.)
+ TODO: check
+CVE-2026-65454 (Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions ...)
+ TODO: check
+CVE-2026-65453 (Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.)
+ TODO: check
+CVE-2026-65452 (Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.)
+ TODO: check
+CVE-2026-65451 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
+ TODO: check
+CVE-2026-65450 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
+ TODO: check
+CVE-2026-65449 (Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.)
+ TODO: check
+CVE-2026-65431 (Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo ...)
+ TODO: check
+CVE-2026-65430 (Joomla Extension - regularlabs.com - MaxMind Credential leakage in Geo ...)
+ TODO: check
+CVE-2026-65010 (Datasets through 5.00, fixed in commit ad2d853, contains a symlink-fol ...)
+ TODO: check
+CVE-2026-64876 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
+ TODO: check
+CVE-2026-64875 (Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoI ...)
+ TODO: check
+CVE-2026-64874 (Joomla Extension - regularlabs.com - CDN Credential leakage Cache Clea ...)
+ TODO: check
+CVE-2026-64873 (Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extensi ...)
+ TODO: check
+CVE-2026-64872 (Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner P ...)
+ TODO: check
+CVE-2026-64871 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
+ TODO: check
+CVE-2026-64815 (In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was ...)
+ TODO: check
+CVE-2026-64814 (In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was ...)
+ TODO: check
+CVE-2026-64813 (In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modific ...)
+ TODO: check
+CVE-2026-64812 (In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection ...)
+ TODO: check
+CVE-2026-64811 (In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was ...)
+ TODO: check
+CVE-2026-64810 (In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible i ...)
+ TODO: check
+CVE-2026-64809 (In JetBrains PhpStorm before 2026.2 arbitrary code execution was possi ...)
+ TODO: check
+CVE-2026-64808 (In JetBrains PhpStorm before 2026.2 arbitrary code execution was possi ...)
+ TODO: check
+CVE-2026-64807 (In JetBrains WebStorm before 2026.2 arbitrary code execution was possi ...)
+ TODO: check
+CVE-2026-64806 (In JetBrains WebStorm before 2026.2 arbitrary code execution was possi ...)
+ TODO: check
+CVE-2026-64805 (In JetBrains WebStorm before 2026.2 arbitrary code execution was possi ...)
+ TODO: check
+CVE-2026-64804 (In JetBrains WebStorm before 2026.2 arbitrary code execution was possi ...)
+ TODO: check
+CVE-2026-64803 (In JetBrains GoLand before 2026.2 arbitrary code execution was possibl ...)
+ TODO: check
+CVE-2026-64802 (In JetBrains GoLand before 2026.2 arbitrary code execution was possibl ...)
+ TODO: check
+CVE-2026-64800 (In JetBrains GoLand before 2026.2 sensitive configuration values writt ...)
+ TODO: check
+CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF via remote image downloads i ...)
+ TODO: check
+CVE-2026-64611 (A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ...)
+ TODO: check
+CVE-2026-63765 (Chatwoot before 4.16.0 contains an authentication bypass vulnerability ...)
+ TODO: check
+CVE-2026-61981 (Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Direc ...)
+ TODO: check
+CVE-2026-61973 (Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.)
+ TODO: check
+CVE-2026-61972 (Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versi ...)
+ TODO: check
+CVE-2026-61954 (Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.)
+ TODO: check
+CVE-2026-61951 (Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.)
+ TODO: check
+CVE-2026-61950 (Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.)
+ TODO: check
+CVE-2026-61949 (Unauthenticated SQL Injection in Bookly <= 27.7 versions.)
+ TODO: check
+CVE-2026-61948 (Unauthenticated SQL Injection in WPDM \u2013 Premium Packages <= 6.2.0 ...)
+ TODO: check
+CVE-2026-61947 (Unauthenticated Cross Site Scripting (XSS) in Form Vibes \u2013 Databa ...)
+ TODO: check
+CVE-2026-61946 (Unauthenticated Insecure Direct Object References (IDOR) in Easy Appoi ...)
+ TODO: check
+CVE-2026-61945 (Exposure of Sensitive System Information to an Unauthorized Control Sp ...)
+ TODO: check
+CVE-2026-61944 (Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.)
+ TODO: check
+CVE-2026-61943 (Unauthenticated Broken Access Control in WPDM \u2013 Premium Packages ...)
+ TODO: check
+CVE-2026-59678 (An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt ...)
+ TODO: check
+CVE-2026-59677 (A Missing Authorization vulnerability in selinux policycoreutils seuns ...)
+ TODO: check
+CVE-2026-59555 (Unauthenticated Arbitrary File Deletion in Participants Database <= 2. ...)
+ TODO: check
+CVE-2026-59554 (Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.)
+ TODO: check
+CVE-2026-59547 (Unauthenticated Broken Access Control in Payment Gateway for PayPal on ...)
+ TODO: check
+CVE-2026-59545 (Unauthenticated Broken Authentication in miniOrange Discord Integratio ...)
+ TODO: check
+CVE-2026-59544 (Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3. ...)
+ TODO: check
+CVE-2026-59543 (Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 ver ...)
+ TODO: check
+CVE-2026-59542 (Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.)
+ TODO: check
+CVE-2026-59541 (Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.)
+ TODO: check
+CVE-2026-59540 (Unauthenticated Privilege Escalation in SMS Alert Order Notifications ...)
+ TODO: check
+CVE-2026-59526 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
+ TODO: check
+CVE-2026-59525 (Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 vers ...)
+ TODO: check
+CVE-2026-59524 (Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6 ...)
+ TODO: check
+CVE-2026-59522 (Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.)
+ TODO: check
+CVE-2026-59517 (Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0 ...)
+ TODO: check
+CVE-2026-59514 (Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.)
+ TODO: check
+CVE-2026-59513 (Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 vers ...)
+ TODO: check
+CVE-2026-59512 (Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooC ...)
+ TODO: check
+CVE-2026-57809 (Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 ve ...)
+ TODO: check
+CVE-2026-57808 (Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.)
+ TODO: check
+CVE-2026-57785 (Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1. ...)
+ TODO: check
+CVE-2026-57784 (Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File ...)
+ TODO: check
+CVE-2026-57769 (Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7 ...)
+ TODO: check
+CVE-2026-57767 (Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10 ...)
+ TODO: check
+CVE-2026-57735 (Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 vers ...)
+ TODO: check
+CVE-2026-57717 (Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.)
+ TODO: check
+CVE-2026-57716 (Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2 ...)
+ TODO: check
+CVE-2026-57704 (Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 ...)
+ TODO: check
+CVE-2026-57703 (Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 ve ...)
+ TODO: check
+CVE-2026-57701 (Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro ...)
+ TODO: check
+CVE-2026-57699 (Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions ...)
+ TODO: check
+CVE-2026-57696 (Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versio ...)
+ TODO: check
+CVE-2026-57626 (Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cro ...)
+ TODO: check
+CVE-2026-57428 (Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 ...)
+ TODO: check
+CVE-2026-57427 (Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPFor ...)
+ TODO: check
+CVE-2026-57425 (Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2. ...)
+ TODO: check
+CVE-2026-57397 (Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versio ...)
+ TODO: check
+CVE-2026-57384 (Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 v ...)
+ TODO: check
+CVE-2026-57374 (Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builde ...)
+ TODO: check
+CVE-2026-57373 (Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO < ...)
+ TODO: check
+CVE-2026-57370 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Tim ...)
+ TODO: check
+CVE-2026-57367 (Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versi ...)
+ TODO: check
+CVE-2026-52684 (If the auth responds very slowly and the records expire in between, th ...)
+ TODO: check
+CVE-2026-48539 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-48538 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-48537 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-48536 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-48535 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-48534 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-48533
+ REJECTED
+CVE-2026-48532 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-48531 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-48530 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
+ TODO: check
+CVE-2026-47769 (APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generate ...)
+ TODO: check
+CVE-2026-47755 (ITFlow provides an IT documentation, ticketing and accounting system f ...)
+ TODO: check
+CVE-2026-47752 (Tugtainer is a self-hosted app for automating updates of Docker contai ...)
+ TODO: check
+CVE-2026-47743 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three re ...)
+ TODO: check
+CVE-2026-47668 (DbGate is cross-platform database manager. In versions 7.1.8 and prior ...)
+ TODO: check
+CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection mechanism in its ...)
+ TODO: check
+CVE-2026-44210 (Kata Containers is an open source project focusing on a standard imple ...)
+ TODO: check
+CVE-2026-43823 (When initializing an RSA public key from DER or PEM bytes throws an er ...)
+ TODO: check
+CVE-2026-43820 (NIOSSLCertificate._subjectAlternativeNames provides access to the raw ...)
+ TODO: check
+CVE-2026-27423 (Subscriber Broken Access Control in Participants Database <= 2.7.8.4 v ...)
+ TODO: check
+CVE-2026-27422 (Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.)
+ TODO: check
+CVE-2026-27418 (Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81. ...)
+ TODO: check
+CVE-2026-27403 (Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versio ...)
+ TODO: check
+CVE-2026-27399 (Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions ...)
+ TODO: check
+CVE-2026-27392 (Contributor Broken Access Control in uListing <= 2.2.0 versions.)
+ TODO: check
+CVE-2026-27391 (Subscriber Broken Access Control in uListing <= 2.2.0 versions.)
+ TODO: check
+CVE-2026-27377 (Booking Agent Broken Access Control in QuickCal - Appointment Booking ...)
+ TODO: check
+CVE-2026-27372 (Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice < ...)
+ TODO: check
+CVE-2026-27355 (Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.)
+ TODO: check
+CVE-2026-27064 (Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.)
+ TODO: check
+CVE-2026-25466 (Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 version ...)
+ TODO: check
+CVE-2026-25427 (Subscriber Broken Access Control in eRoom <= 1.7.1 versions.)
+ TODO: check
+CVE-2026-25424 (Contributor Broken Access Control in Mediavine Control Panel <= 2.10.1 ...)
+ TODO: check
+CVE-2026-25405 (Contributor SQL Injection in eRoom <= 1.7.1 versions.)
+ TODO: check
+CVE-2026-24639 (Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 vers ...)
+ TODO: check
+CVE-2026-24628 (Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic ...)
+ TODO: check
+CVE-2026-24552 (Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.)
+ TODO: check
+CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility ...)
+ TODO: check
+CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO f ...)
+ TODO: check
+CVE-2026-16756 (Missing connection and header-read timeouts and the absence of a concu ...)
+ TODO: check
+CVE-2026-16745 (A flaw was found in odh-dashboard, the web console component of Red Ha ...)
+ TODO: check
+CVE-2026-16735 (A security vulnerability has been detected in release-it conventional- ...)
+ TODO: check
+CVE-2026-16733 (A weakness has been identified in bahmutov find-cypress-specs up to 1. ...)
+ TODO: check
+CVE-2026-16723 (A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 ...)
+ TODO: check
+CVE-2026-16584 (Improper handling of an initialization failure in AWS API MCP Server f ...)
+ TODO: check
+CVE-2026-16287 (Improper neutralization of special elements used in an OS command ('OS ...)
+ TODO: check
+CVE-2026-16078 (The WCPOS \u2013 Point of Sale (POS) plugin for WooCommerce plugin for ...)
+ TODO: check
+CVE-2026-15906 (The Premium Packages \u2013 Sell Digital Products Securely plugin for ...)
+ TODO: check
+CVE-2026-15827 (The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized ...)
+ TODO: check
+CVE-2026-15794 (The Grid/List View for WooCommerce plugin for WordPress is vulnerable ...)
+ TODO: check
+CVE-2026-15786 (The WP Encryption \u2013 One Click Free SSL Certificate & SSL / HTTPS ...)
+ TODO: check
+CVE-2026-15761 (The Tickera \u2013 Sell Tickets & Manage Events plugin for WordPress i ...)
+ TODO: check
+CVE-2026-15687 (A security issue was discovered in the Kubernetes Java client library ...)
+ TODO: check
+CVE-2026-15647 (The Brands for WooCommerce plugin for WordPress is vulnerable to Store ...)
+ TODO: check
+CVE-2026-15646 (The Brands for WooCommerce plugin for WordPress is vulnerable to Store ...)
+ TODO: check
+CVE-2026-15617 (Logto performs principal lookup without normalizing email and identifi ...)
+ TODO: check
+CVE-2026-15616 (Logto does not enforce locally configured MFA during SSO authenticatio ...)
+ TODO: check
+CVE-2026-15615 (Logto omits validation of the SAML <Conditions> element, enabling atta ...)
+ TODO: check
+CVE-2026-15614 (Logto silently fails to delete IdP-initiated SAML sessions, enabling s ...)
+ TODO: check
+CVE-2026-15612 (Logto bypasses OIDC nonce validation when the nonce claim is absent fr ...)
+ TODO: check
+CVE-2026-15611 (Logto allows unverified email-based SSO account linking, enabling an a ...)
+ TODO: check
+CVE-2026-15448 (The Tickera \u2013 Sell Tickets & Manage Events plugin for WordPress i ...)
+ TODO: check
+CVE-2026-15404 (The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Sc ...)
+ TODO: check
+CVE-2026-15394 (The Header Footer Script Adder \u2013 Insert Code in Header, Body & Fo ...)
+ TODO: check
+CVE-2026-15348 (The Premium Packages \u2013 Sell Digital Products Securely plugin for ...)
+ TODO: check
+CVE-2026-15037 (Improper output neutralization (XML injection) in QDom comment, CDATA, ...)
+ TODO: check
+CVE-2026-15017 (The MDJM Event Management plugin for WordPress is vulnerable to Privil ...)
+ TODO: check
+CVE-2026-15015 (The MountDev AI MCP Connector for WordPress plugin for WordPress is vu ...)
+ TODO: check
+CVE-2026-15011 (The Customer Support Ticket System & Helpdesk plugin for WordPress is ...)
+ TODO: check
+CVE-2026-14481 (The Equalize Digital Accessibility Checker \u2013 WCAG, ADA, EAA and S ...)
+ TODO: check
+CVE-2026-14282 (The GoDAM \u2013 Organize WordPress Media Library & File Manager with ...)
+ TODO: check
+CVE-2026-14257 (brace-expansion through 5.0.7 is vulnerable to denial of service via m ...)
+ TODO: check
+CVE-2026-13119 (The Registrations For The Events Calendar plugin for WordPress is vuln ...)
+ TODO: check
+CVE-2026-13009 (The AI Copilot \u2013 Content Generator plugin for WordPress is vulner ...)
+ TODO: check
+CVE-2026-12421 (The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Sc ...)
+ TODO: check
+CVE-2026-11804 (Improper handling of insufficient permissions or privileges vulnerabil ...)
+ TODO: check
+CVE-2025-68081 (Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 version ...)
+ TODO: check
+CVE-2024-58330 (A missing authentication check in Bosch IP cameras of families CPP13 a ...)
+ TODO: check
+CVE-2024-58023 (Information disclosure in Bosch Configuration Manager in Version 7.72. ...)
+ TODO: check
CVE-2026-9737 (During query planning when reading the sort pattern in raw BSONObj for ...)
- mongodb <removed>
NOTE: https://jira.mongodb.org/browse/SERVER-128341
@@ -17,33 +617,33 @@ CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message handlin
TODO: check upstream status
CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation vulnerab ...)
NOT-FOR-US: Question2Answer
-CVE-2026-64798 (Persistent URL login keys were also generated using a non-cryptographi ...)
+CVE-2026-64798 (Joomla Extension - regularlabs.com - Insecure login URL keys in IP log ...)
NOT-FOR-US: Joomla
-CVE-2026-64797 (IP Login trusted forwarded client-IP headers without requiring a confi ...)
+CVE-2026-64797 (Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP l ...)
NOT-FOR-US: Joomla
-CVE-2026-64796 (Free did not require both the article creator and last modifier to be ...)
+CVE-2026-64796 (Joomla Extension - regularlabs.com - various code injection vectors in ...)
NOT-FOR-US: Joomla
-CVE-2026-64795 (Tag-provided custom HTML, module content/title overrides and decoded m ...)
+CVE-2026-64795 (Joomla Extension - regularlabs.com - XSS vectors in tag-provided input ...)
NOT-FOR-US: Joomla
-CVE-2026-64794 (User tags, filters and conditions allowed access to insufficiently res ...)
+CVE-2026-64794 (Joomla Extension - regularlabs.com - restricted user-data exposure in ...)
NOT-FOR-US: Joomla
-CVE-2026-64793 (Content tags could use ignore flags or property overrides to render re ...)
+CVE-2026-64793 (Joomla Extension - regularlabs.com - Content access and publication by ...)
NOT-FOR-US: Joomla
-CVE-2026-64792 (Smart Search indexing could render generated content using the indexin ...)
+CVE-2026-64792 (Joomla Extension - regularlabs.com - disclosure of restricted content ...)
NOT-FOR-US: Joomla
-CVE-2026-64791 (Administrator routes and install/update/uninstall processing did not c ...)
+CVE-2026-64791 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
NOT-FOR-US: Joomla
-CVE-2026-63685 (Administrator routes and replacement requests did not consistently req ...)
+CVE-2026-63685 (Joomla Extension - regularlabs.com - Authorization bypass in DB Replac ...)
NOT-FOR-US: Joomla
-CVE-2026-63684 (Administrator actions, editor popups and import/export requests lacked ...)
+CVE-2026-63684 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
NOT-FOR-US: Joomla
-CVE-2026-63683 (IP and GeoIP conditions trusted spoofable forwarded headers, allowing ...)
+CVE-2026-63683 (Joomla Extension - regularlabs.com - Client IP spoofing vulnerability ...)
NOT-FOR-US: Joomla
-CVE-2026-63281 (Stored condition values could also execute HTML/JavaScript in administ ...)
+CVE-2026-63281 (Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs ...)
NOT-FOR-US: Joomla
-CVE-2026-63280 (Conditions administration did not consistently enforce tokens and comp ...)
+CVE-2026-63280 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
NOT-FOR-US: Joomla
-CVE-2026-63265 (Privileged Regular Labs AJAX endpoints did not consistently require va ...)
+CVE-2026-63265 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
NOT-FOR-US: Joomla
CVE-2026-63226 (Printers and Multifunction Printers (MFPs) provided by Ricoh Company, ...)
NOT-FOR-US: Ricoh
@@ -251,11 +851,11 @@ CVE-2026-64830 (FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflo
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951
CVE-2026-64828 (Froiden TableTrack through 1.3.10 contains a stored cross-site scripti ...)
NOT-FOR-US: Froiden TableTrack
-CVE-2026-63264 (The Joomla extension JoomShopping is vulnerable to an reflected XSS vu ...)
+CVE-2026-63264 (Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < ...)
NOT-FOR-US: Joomla
-CVE-2026-63048 (The Joomla extension Page Builder CK is vulnerable to an authenticated ...)
+CVE-2026-63048 (Joomla Extension - joomlack.fr - Improper access control in Page Build ...)
NOT-FOR-US: Joomla
-CVE-2026-63047 (The Joomla extension Events Booking prior version 5.0-5.8.1 did not pr ...)
+CVE-2026-63047 (Joomla Extension - joomdonation.com - Invoice data exfiltration via in ...)
NOT-FOR-US: Joomla
CVE-2026-62145 (A vulnerability in Check Point Gaia Portal allows an authenticated att ...)
NOT-FOR-US: Check Point Gaia Portal
@@ -322,7 +922,8 @@ CVE-2026-16606 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Soft
CVE-2026-16560 (A heap-buffer-overflow flaw was found in Directory Server (389-ds-base ...)
- 389-ds-base <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506102
-CVE-2026-16552 (A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d con ...)
+CVE-2026-16552
+ REJECTED
- systemd <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506073
CVE-2026-16551 (Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB modu ...)
@@ -485,13 +1086,13 @@ CVE-2026-13321 (The BIND resolver accepts validly-signed NSEC records where the
{DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-13321
-CVE-2026-52688
+CVE-2026-52688 (RRSIGs with too few labels can lead to bypass of DNSSEC wildcard valid ...)
{DSA-6397-1}
- pdns-recursor 5.4.4-1
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
[bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
NOTE: https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-10.html
-CVE-2026-52686
+CVE-2026-52686 (The issue is a DNSSEC validation bypass where wildcard expansion proof ...)
{DSA-6397-1}
- pdns-recursor 5.4.4-1
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
@@ -575,7 +1176,7 @@ CVE-2026-64614 (Data::Deque::Shared versions before 0.06 for Perl create a world
NOT-FOR-US: Data::Deque::Shared Perl module
CVE-2026-64613 (Data::Buffer::Shared versions before 0.05 for Perl create a world-read ...)
NOT-FOR-US: Data::Buffer::Shared Perl module
-CVE-2026-63764 (lmdeploy's OpenAI-compatible API server contains a server-side request ...)
+CVE-2026-63764 (LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-si ...)
NOT-FOR-US: lmdeploy
CVE-2026-63358 (FileGator accepts arbitrary Unix permission values via the '/chmoditem ...)
NOT-FOR-US: FileGator
@@ -3194,7 +3795,7 @@ CVE-2026-63454 (An authenticated path traversal vulnerability exists in AOS-CX.
NOT-FOR-US: HPE
CVE-2026-63453 (Buffer overflow vulnerabilities exist in the command line interface of ...)
NOT-FOR-US: HPE
-CVE-2026-62415 (The Joomla extension Membership Pro prior version 4.6.2 did by default ...)
+CVE-2026-62415 (Joomla Extension - joomdonation.com - Insecure default configuration M ...)
NOT-FOR-US: Joomla
CVE-2026-60080 (Use After Free vulnerability in the Rust deserialization logic of Apac ...)
NOT-FOR-US: Apache software not packaged in Debian
@@ -3423,19 +4024,19 @@ CVE-2026-16361 (Memory safety bugs present in Thunderbird ESR 140.12. Some of th
{DSA-6394-1 DLA-4695-1}
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
-CVE-2026-16360 (Memory safety bugs present in Thunderbird ESR 140.12 and Thunderbird 1 ...)
+CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 a ...)
{DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
-CVE-2026-16412 (Memory safety bugs present in Thunderbird ESR 140.12 and Thunderbird 1 ...)
+CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some ...)
{DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
-CVE-2026-16411 (Memory safety bugs present in Thunderbird 152. Some of these bugs show ...)
+CVE-2026-16411 (Memory safety bugs present in Firefox 152. Some of these bugs showed e ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16411
CVE-2026-16410 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
@@ -3816,15 +4417,15 @@ CVE-2026-63729 (The SyncTeX parser (synctex_parser.c) shipped with TeX Live and
NOTE: https://fatihhcelik.github.io/posts/evince-synctex-heap-use-after-free/
CVE-2026-63728 (Gitleaks prior to 8.30.1 contains a template injection vulnerability t ...)
NOT-FOR-US: Gitleaks
-CVE-2026-62414 (The Joomla extension Page Builder CK does not properly apply access co ...)
+CVE-2026-62414 (Joomla Extension - joomlack.fr - Improper access control in Page Build ...)
NOT-FOR-US: Joomla
-CVE-2026-61901 (The Joomla extension Hikashop is vulnerable to an open redirect.)
+CVE-2026-61901 (Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - ...)
NOT-FOR-US: Joomla
-CVE-2026-61900 (The Joomla extension JDownloads is vulnerable to an unauthenticated fi ...)
+CVE-2026-61900 (Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file ...)
NOT-FOR-US: Joomla
-CVE-2026-61425 (The Joomla extension Gridbox is vulnerable an authenticated bypass, po ...)
+CVE-2026-61425 (Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1. ...)
NOT-FOR-US: Joomla
-CVE-2026-61424 (The Joomla extension DJ-Classifieds is vulnerable to an unauthenticate ...)
+CVE-2026-61424 (Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file ...)
NOT-FOR-US: Joomla
CVE-2026-59776 (Missing Cryptographic Step (CWE-325) vulnerability exists in certain F ...)
NOT-FOR-US: FeliCa IC chips issues
@@ -4112,23 +4713,23 @@ CVE-2026-62418 (Low-privileged authenticated Server-Side Request Forgery (SSRF)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-62183 (Improper Privilege Management vulnerability in Apache Syncope. When: ...)
NOT-FOR-US: Apache software not packaged in Debian
-CVE-2026-60034 (The Joomla extension JMedia is vulnerable to a stored XSS vulnerabilit ...)
+CVE-2026-60034 (Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia ...)
NOT-FOR-US: Joomla
-CVE-2026-60033 (The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Re ...)
+CVE-2026-60033 (Joomla Extension - themexpert.com - SSRF via remote download in JMedia ...)
NOT-FOR-US: Joomla
-CVE-2026-60032 (The Joomla extension JMedia is vulnerable to an authenticated arbitrar ...)
+CVE-2026-60032 (Joomla Extension - themexpert.com - Authenticated arbitrary file uploa ...)
NOT-FOR-US: Joomla
-CVE-2026-60031 (The Joomla extension Quix Page Builder Pro is vulnerable to an informa ...)
+CVE-2026-60031 (Joomla Extension - themexpert.com - Information disclosure in Quix Pag ...)
NOT-FOR-US: Joomla
-CVE-2026-60030 (The Joomla extension Quix Page Builder Pro is vulnerable to an imprope ...)
+CVE-2026-60030 (Joomla Extension - themexpert.com - Broken Access Control for media ma ...)
NOT-FOR-US: Joomla
-CVE-2026-60029 (The Joomla extension Quix Page Builder Pro is vulnerable to an authent ...)
+CVE-2026-60029 (Joomla Extension - themexpert.com - Authenticated stored XSS in Quix P ...)
NOT-FOR-US: Joomla
-CVE-2026-60028 (The Joomla extension Quix Page Builder Pro is vulnerable to an authent ...)
+CVE-2026-60028 (Joomla Extension - themexpert.com - Authenticated stored XSS in Quix P ...)
NOT-FOR-US: Joomla
-CVE-2026-60027 (The Joomla extension Quix Page Builder Pro is vulnerable to a unauthen ...)
+CVE-2026-60027 (Joomla Extension - themexpert.com - Unauthenticated path traversal / f ...)
NOT-FOR-US: Joomla
-CVE-2026-60026 (The Joomla extension Quix Page Builder Pro is vulnerable to an authent ...)
+CVE-2026-60026 (Joomla Extension - themexpert.com - Authenticated PHP code execution i ...)
NOT-FOR-US: Joomla
CVE-2026-59238 (Stored Cross-site Scripting (CWE-79) in the client-side report renderi ...)
NOT-FOR-US: maalfer Pentestify
@@ -7394,9 +7995,9 @@ CVE-2026-63093 (Cursor for Windows version 3.2.16 contains a binary planting vul
NOT-FOR-US: Cursor
CVE-2026-62764 (Improper Handling of Insufficient Privileges vulnerability in Apache A ...)
NOT-FOR-US: Apache software not packaged in Debian
-CVE-2026-60025 (The Joomla extension Events Booking prior version 5.8.0 had an fronten ...)
+CVE-2026-60025 (Joomla Extension - joomdonation.com - User enumeration in Events Booki ...)
NOT-FOR-US: Joomla
-CVE-2026-60024 (The Joomla extension Events Booking prior version 5.8.0 did by default ...)
+CVE-2026-60024 (Joomla Extension - joomdonation.com - Insecure default configuration E ...)
NOT-FOR-US: Joomla
CVE-2026-59695 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
NOT-FOR-US: ZenHive mpp
@@ -7406,9 +8007,9 @@ CVE-2026-59252 (Improper Validation of Specified Quantity in Input in ZenHive mp
NOT-FOR-US: ZenHive mpp
CVE-2026-58195 (Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, a ...)
NOT-FOR-US: Agentic-Flow
-CVE-2026-58149 (The Joomla extension Events Booking is vulnerable to an unauthenticate ...)
+CVE-2026-58149 (Joomla Extension - joomdonation.com - User enumeration in Events Booki ...)
NOT-FOR-US: Joomla
-CVE-2026-58148 (The Joomla extension ChronoForms is vulnerable to an unauthenticated s ...)
+CVE-2026-58148 (Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extens ...)
NOT-FOR-US: Joomla
CVE-2026-57860 (ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automati ...)
NOT-FOR-US: ForgeCode
@@ -7824,7 +8425,7 @@ CVE-2026-58598 (Concurrent execution using shared resource with improper synchro
NOT-FOR-US: Microsoft
CVE-2026-58317 (Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in ...)
NOT-FOR-US: Tera Term
-CVE-2026-58078 (The Joomla extension Quix Page Builder Pro is vulnerable to an unauthe ...)
+CVE-2026-58078 (Joomla Extension - themexpert.com - Unauthenticated SQL injection in Q ...)
NOT-FOR-US: Joomla
CVE-2026-57896 (An out-of-bounds read vulnerability in the Productivity Suite allows a ...)
NOT-FOR-US: Productivity Suite
@@ -8568,6 +9169,7 @@ CVE-2026-62164
CVE-2026-61873 (Grav before 9.1.8 contains an arbitrary file write vulnerability in th ...)
NOT-FOR-US: Grav CMS
CVE-2026-61872 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h5r4-w88w-7ccr
@@ -8583,12 +9185,14 @@ CVE-2026-61871 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/e4b68bfb6a9541a9c3a4af81a21bf0c253661083 (6.9.13-51)
NOTE: Introduced by: https://github.com/ImageMagick/ImageMagick6/commit/24397534f7c5694840bd6b70bf2d16efe7382b5c (6.9.13-11)
CVE-2026-61869 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r628-69v2-2f9c
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/b2dc602e175ee07b0794f3e31f1a29ae6b7267d1 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ca6c9da425880fde937da41d59666dedf5e719e1 (6.9.13-51)
CVE-2026-61868 (ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memo ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h7f2-f9cc-h2gv
@@ -8603,12 +9207,14 @@ CVE-2026-61867 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/f34065ecd9512df16cb10083c8b4b46b5cd09b30 (7.1.2-26)
NOTE: Introduced by https://github.com/ImageMagick/ImageMagick/commit/14c08dcd1910ecd8360f51d13885b2c9c39b655d (7.0.1-0)
CVE-2026-61866 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/0bb3578ee087f3c4f14bbf1d8883ae456fc99092 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/353e2604d1983b6d8ec4c04f4f38bbd4668ba0e1 (6.9.13-51)
CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x
@@ -8616,6 +9222,7 @@ CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862, CVE-2026-61864, CVE-2026-61863
CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in co ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq
@@ -8623,6 +9230,7 @@ CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862, CVE-2026-61861, CVE-2026-61865
CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memo ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9
@@ -8630,6 +9238,7 @@ CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862, CVE-2026-61864, CVE-2026-61865
CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disc ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx
@@ -8637,12 +9246,14 @@ CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an informatio
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
NOTE: For imagemagick 6 patch include fix for CVE-2026-61863, CVE-2026-61864
CVE-2026-61860 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vu ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/3fc646a498eecda9163164046189f90dc677ae64 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/eed471c1286aa27c076348b453b35a2e962967bc (6.9.13-51)
CVE-2026-61859 (ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a p ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398
@@ -8681,6 +9292,7 @@ CVE-2026-61606
CVE-2026-61605
REJECTED
CVE-2026-61464 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr
@@ -8780,15 +9392,15 @@ CVE-2026-58550 (Out-of-bounds read vulnerability in the image codec module. Impa
NOT-FOR-US: Huawei
CVE-2026-58549 (Out-of-bounds read vulnerability in the image codec module. Impact: Su ...)
NOT-FOR-US: Huawei
-CVE-2026-58077 (The Joomla extension 4Analytics is vulnerable to an unauthenticated st ...)
+CVE-2026-58077 (Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analyti ...)
NOT-FOR-US: Joomla
CVE-2026-57996 (phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in ...)
NOT-FOR-US: phpMyFAQ
-CVE-2026-57833 (The Joomla extension 4Analytics is vulnerable to an unauthenticated st ...)
+CVE-2026-57833 (Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analyti ...)
NOT-FOR-US: Joomla
-CVE-2026-57832 (The Joomla extension EDocman is vulnerable to an unauthenticated SQL i ...)
+CVE-2026-57832 (Joomla Extension - joomdonation.com - Unauthenticated blind SQL inject ...)
NOT-FOR-US: Joomla
-CVE-2026-57831 (The Joomla extension DP Calendar is vulnerable to an unauthenticated S ...)
+CVE-2026-57831 (Joomla Extension - digital-peak.com - Unauthenticated blind SQL inject ...)
NOT-FOR-US: Joomla
CVE-2026-57821 (A SQL Injection vulnerability exists in Apache Fineract's Office Searc ...)
NOT-FOR-US: Apache software not packaged in Debian
@@ -11364,9 +11976,9 @@ CVE-2026-58228 (Cross-site scripting vulnerability in phoenixframework phoenix_l
NOT-FOR-US: phoenixframework phoenix_live_view
CVE-2026-58065 (The Apache Airflow Git provider runs its git-over-SSH operations with ...)
NOT-FOR-US: Apache Airflow Git provider
-CVE-2026-57830 (The Joomla extension Helix Ultimate is vulnerable to an unauthenticate ...)
+CVE-2026-57830 (Joomla Extension - joomshaper.com - Unauthenticated arbitrary file del ...)
NOT-FOR-US: Joomla
-CVE-2026-57829 (The Joomla extension Helix Ultimate is vulnerable to an unauthenticate ...)
+CVE-2026-57829 (Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Heli ...)
NOT-FOR-US: Joomla
CVE-2026-57816 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
@@ -11972,6 +12584,7 @@ CVE-2026-15471 (A vulnerability was found in Eleveo Call Recording Software 9.7.
CVE-2026-15470 (A vulnerability has been found in Eleveo Call Recording Software 9.7.0 ...)
NOT-FOR-US: Eleveo Call Recording Software
CVE-2026-61870 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability in th ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m596-67p7-69wh
@@ -11987,18 +12600,21 @@ CVE-2026-61861 (ImageMagick before 7.1.2-26 contains a use-after-free vulnerabil
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/0091f38a106601893c77c2d298708048cd2930f5 (6.9.13-51)
NOTE: Introduced by https://github.com/ImageMagick/ImageMagick6/commit/1d597191bd1f45d05ff041c89b7e3f8759e9eaf5 (6.9.12-24)
CVE-2026-61858 (ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/19c11cb0aefbd627c95c4c08c44722e660025aa1 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/5fbcfe76fd8be554e30ec1d8723c00ae8b68f470 (6.9.13-51)
CVE-2026-61857 (ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerabili ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh5g-q395-cx4j
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/150c9852402ac1aa1f223e5bf5109e3a2022ebbc (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/e1d94d92d985f8c0bb648ddbcd70ba3362a84674 (6.9.13-51)
CVE-2026-61465 (ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the a ...)
+ {DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvhp-75f6-9jqh
@@ -12028,9 +12644,9 @@ CVE-2026-60090 (PraisonAI before 4.6.78 fails to validate the caller-controlled
NOT-FOR-US: PraisonAI
CVE-2026-60088 (PraisonAI before 4.6.78 fails to validate file path references in cust ...)
NOT-FOR-US: PraisonAI
-CVE-2026-57828 (The Joomla extension Phoca Downloads is vulnerable to an authenticated ...)
+CVE-2026-57828 (Joomla Extension - phoca.cz - Authenticated file upload in RSFiles com ...)
NOT-FOR-US: Joomla
-CVE-2026-57827 (The Joomla extension RSFiles is vulnerable to an unauthenticated arbit ...)
+CVE-2026-57827 (Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFil ...)
NOT-FOR-US: Joomla
CVE-2026-56763 (Hono before 4.12.7 allows __proto__ key in parseBody with dot option e ...)
NOT-FOR-US: Hono
@@ -13284,9 +13900,9 @@ CVE-2026-56459 (HCL DevOps Deploy / HCL Launch is susceptible to sensitive infor
NOT-FOR-US: HCL
CVE-2026-56458 (HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which coul ...)
NOT-FOR-US: HCL
-CVE-2026-56292 (A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was ...)
+CVE-2026-56292 (Joomla Extension - acymailing.com - SQL Injection in AcyMailing extens ...)
NOT-FOR-US: Joomla
-CVE-2026-56291 (The Joomla extension Balbooa Forms is vulnerable to an unauthenticated ...)
+CVE-2026-56291 (Joomla Extension - balbooa.com - Unauthenticated file upload in Balboo ...)
NOT-FOR-US: Joomla
CVE-2026-56289 (GNU patch is vulnerable to a denial of service (DoS) due to improper v ...)
- patch <unfixed> (unimportant)
@@ -20659,6 +21275,7 @@ CVE-2026-51218 (A heap buffer overflow in the TS7Worker::PerformFunctionWrite()
CVE-2026-43746 (A use-after-free issue was addressed with improved memory management. ...)
NOT-FOR-US: Apple
CVE-2026-43745 (An out-of-bounds write issue was addressed with improved input validat ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20670,6 +21287,7 @@ CVE-2026-43745 (An out-of-bounds write issue was addressed with improved input v
CVE-2026-43743 (A race condition was addressed with improved state handling. This issu ...)
NOT-FOR-US: Apple
CVE-2026-43742 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20679,6 +21297,7 @@ CVE-2026-43742 (A use-after-free issue was addressed with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43740 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20690,6 +21309,7 @@ CVE-2026-43740 (The issue was addressed with improved memory handling. This issu
CVE-2026-43735 (The issue was addressed with improved checks. This issue is fixed in S ...)
NOT-FOR-US: Apple
CVE-2026-43734 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20699,6 +21319,7 @@ CVE-2026-43734 (A use-after-free issue was addressed with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43732 (A path handling issue was addressed with improved validation. This iss ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20708,6 +21329,7 @@ CVE-2026-43732 (A path handling issue was addressed with improved validation. Th
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43731 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20717,6 +21339,7 @@ CVE-2026-43731 (A use-after-free issue was addressed with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43727 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20726,6 +21349,7 @@ CVE-2026-43727 (A use-after-free issue was addressed with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43726 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20735,6 +21359,7 @@ CVE-2026-43726 (A use-after-free issue was addressed with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43725 (The issue was addressed with improved input validation. This issue is ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20748,6 +21373,7 @@ CVE-2026-43724 (The issue was addressed with improved input sanitization. This i
CVE-2026-43722 (The issue was addressed with improved input sanitization. This issue i ...)
NOT-FOR-US: Apple
CVE-2026-43721 (This issue was addressed through improved state management. This issue ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20757,6 +21383,7 @@ CVE-2026-43721 (This issue was addressed through improved state management. This
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43720 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20770,6 +21397,7 @@ CVE-2026-43718 (A stack overflow was addressed with improved input validation. T
CVE-2026-43717 (A use-after-free issue was addressed with improved memory management. ...)
NOT-FOR-US: Apple
CVE-2026-43716 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20779,6 +21407,7 @@ CVE-2026-43716 (The issue was addressed with improved memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43715 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20788,6 +21417,7 @@ CVE-2026-43715 (A use-after-free issue was addressed with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43713 (A permissions issue was addressed with additional restrictions. This i ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20797,6 +21427,7 @@ CVE-2026-43713 (A permissions issue was addressed with additional restrictions.
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0004.html
CVE-2026-43712 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20810,6 +21441,7 @@ CVE-2026-43709 (A use-after-free issue was addressed with improved memory manage
CVE-2026-43708 (The issue was addressed with improved input validation. This issue is ...)
NOT-FOR-US: Apple
CVE-2026-43707 (A memory corruption issue was addressed with improved memory handling. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20821,6 +21453,7 @@ CVE-2026-43707 (A memory corruption issue was addressed with improved memory han
CVE-2026-43706 (A double free issue was addressed with improved memory management. Thi ...)
NOT-FOR-US: Apple
CVE-2026-43705 (A type confusion issue was addressed with improved checks. This issue ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20834,6 +21467,7 @@ CVE-2026-43704 (A use-after-free issue was addressed with improved memory manage
CVE-2026-43703 (The issue was addressed with improved memory handling. This issue is f ...)
NOT-FOR-US: Apple
CVE-2026-43701 (The issue was addressed with improved checks. This issue is fixed in S ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20845,6 +21479,7 @@ CVE-2026-43701 (The issue was addressed with improved checks. This issue is fixe
CVE-2026-43700 (A cross-origin issue was addressed with improved tracking of security ...)
NOT-FOR-US: Apple
CVE-2026-43699 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20854,6 +21489,7 @@ CVE-2026-43699 (A use-after-free issue was addressed with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0002.html
CVE-2026-43676 (An out-of-bounds access issue was addressed with improved bounds check ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20863,6 +21499,7 @@ CVE-2026-43676 (An out-of-bounds access issue was addressed with improved bounds
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0002.html
CVE-2026-43663 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -20874,6 +21511,7 @@ CVE-2026-43663 (The issue was addressed with improved memory handling. This issu
CVE-2026-41896 (Coolify is an open-source and self-hostable tool for managing servers, ...)
NOT-FOR-US: Coolify
CVE-2026-39872 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.5-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -21115,7 +21753,7 @@ CVE-2026-56780 (Modoboa before 2.9.0 contains an insecure direct object referenc
NOT-FOR-US: Modoboa
CVE-2026-56457 (HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensit ...)
NOT-FOR-US: HCL
-CVE-2026-56290 (The Joomla extension Page Builder CK is vulnerable to an unauthenticat ...)
+CVE-2026-56290 (Joomla Extension - joomlack.fr - Unauthenticated file upload in Page B ...)
NOT-FOR-US: Joomla
CVE-2026-56285 (Nitter's /video media proxy endpoint fails to validate target URLs aga ...)
NOT-FOR-US: Nitter
@@ -48098,7 +48736,7 @@ CVE-2026-9274 (This vulnerability exists in CP Plus Wi-Fi Camera due to improper
NOT-FOR-US: CP Plus Wi-Fi Camera
CVE-2026-9078 (Firefox for iOS displayed specially crafted right-to-left (RTL) and in ...)
NOT-FOR-US: Firefox for iOS
-CVE-2026-9058 (Szafir SDK returns a success status code from the cryptographic digita ...)
+CVE-2026-9058 (For untrusted certificates that contain the "Authority Information Acc ...)
NOT-FOR-US: Szafir SDK
CVE-2026-7766 (Kenik Camera management Panel is vulnerable to Path Traversal vulnerab ...)
NOT-FOR-US: Kenik Camera management Panel
@@ -55162,6 +55800,7 @@ CVE-2026-43666 (An out-of-bounds write issue was addressed with improved bounds
CVE-2026-43661 (A buffer overflow issue was addressed with improved memory handling. T ...)
NOT-FOR-US: Apple
CVE-2026-43660 (A validation issue was addressed with improved logic. This issue is fi ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55173,6 +55812,7 @@ CVE-2026-43660 (A validation issue was addressed with improved logic. This issue
CVE-2026-43659 (A race condition was addressed with additional validation. This issue ...)
NOT-FOR-US: Apple
CVE-2026-43658 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55342,6 +55982,7 @@ CVE-2026-28961 (This issue was addressed with improved checks. This issue is fix
CVE-2026-28959 (A buffer overflow was addressed with improved bounds checking. This is ...)
NOT-FOR-US: Apple
CVE-2026-28958 (This issue was addressed with improved data protection. This issue is ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55355,6 +55996,7 @@ CVE-2026-28957 (An issue with app access to camera metadata was addressed with i
CVE-2026-28956 (A memory corruption issue was addressed with improved input validation ...)
NOT-FOR-US: Apple
CVE-2026-28955 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55366,6 +56008,7 @@ CVE-2026-28955 (The issue was addressed with improved memory handling. This issu
CVE-2026-28954 (A file quarantine bypass was addressed with additional checks. This is ...)
NOT-FOR-US: Apple
CVE-2026-28953 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55379,6 +56022,7 @@ CVE-2026-28952 (An integer overflow was addressed with improved input validation
CVE-2026-28951 (An authorization issue was addressed with improved state management. T ...)
NOT-FOR-US: Apple
CVE-2026-28947 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55388,6 +56032,7 @@ CVE-2026-28947 (A use-after-free issue was addressed with improved memory manage
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28946 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55401,6 +56046,7 @@ CVE-2026-28944 (The issue was addressed with improved memory handling. This issu
CVE-2026-28943 (A logging issue was addressed with improved data redaction. This issue ...)
NOT-FOR-US: Apple
CVE-2026-28942 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55446,6 +56092,7 @@ CVE-2026-28910 (This issue was addressed with improved permissions checking. Thi
CVE-2026-28908 (A denial of service issue was addressed by removing the vulnerable cod ...)
NOT-FOR-US: Apple
CVE-2026-28907 (The issue was addressed with improved input validation. This issue is ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55457,6 +56104,7 @@ CVE-2026-28907 (The issue was addressed with improved input validation. This iss
CVE-2026-28906 (This issue was addressed through improved state management. This issue ...)
NOT-FOR-US: Apple
CVE-2026-28905 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55466,6 +56114,7 @@ CVE-2026-28905 (The issue was addressed with improved memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28904 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55475,6 +56124,7 @@ CVE-2026-28904 (The issue was addressed with improved memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28903 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55484,6 +56134,7 @@ CVE-2026-28903 (The issue was addressed with improved memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28902 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55493,6 +56144,7 @@ CVE-2026-28902 (The issue was addressed with improved memory handling. This issu
[bullseye] - wpewebkit <end-of-life> (see #1035997)
NOTE: https://webkitgtk.org/security/WSA-2026-0003.html
CVE-2026-28901 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55504,6 +56156,7 @@ CVE-2026-28901 (The issue was addressed with improved memory handling. This issu
CVE-2026-28897 (A buffer overflow was addressed with improved input validation. This i ...)
NOT-FOR-US: Apple
CVE-2026-28883 (A use-after-free issue was addressed with improved memory management. ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -55521,6 +56174,7 @@ CVE-2026-28860 (The issue was addressed with improved input validation. This iss
CVE-2026-28848 (A buffer overflow was addressed with improved bounds checking. This is ...)
NOT-FOR-US: Apple
CVE-2026-28847 (The issue was addressed with improved memory handling. This issue is f ...)
+ {DSA-6398-1}
- webkit2gtk 2.52.4-1
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -310383,7 +311037,7 @@ CVE-2024-4765 (Web application manifests were stored by using an insecure MD5 ha
- firefox <not-affected> (Android-specific)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-21/#CVE-2024-4765
CVE-2024-4367 (A type check was missing when handling fonts in PDF.js, which would al ...)
- {DSA-5742-1 DSA-5693-1 DSA-5691-1 DLA-3817-1 DLA-3815-1}
+ {DSA-6398-1 DSA-5742-1 DSA-5693-1 DSA-5691-1 DLA-3817-1 DLA-3815-1}
- firefox 126.0-1
- firefox-esr 115.11.0esr-1
- thunderbird 1:115.11.0-1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60a0fffaa57d1ebdce1d6a002f0b0a48d4a33f5a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60a0fffaa57d1ebdce1d6a002f0b0a48d4a33f5a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/e2755d80/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list