[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 24 08:13:03 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
032290e3 by security tracker role at 2026-07-24T07:12:54+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,8 +1,184 @@
+CVE-2026-6924 (A bug in the entropy initialization for SiWx917 causes the DRBG to use ...)
+	TODO: check
+CVE-2026-6454 (The Firelight Lightbox plugin for WordPress is vulnerable to Stored DO ...)
+	TODO: check
+CVE-2026-66141 (Exim before 4.99.5 allows .forward privilege escalation because force_ ...)
+	TODO: check
+CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files outside  ...)
+	TODO: check
+CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXT ...)
+	TODO: check
+CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, aproject-scoped user  ...)
+	TODO: check
+CVE-2026-65706 (FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulne ...)
+	TODO: check
+CVE-2026-65705 (FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulne ...)
+	TODO: check
+CVE-2026-65704 (FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability tha ...)
+	TODO: check
+CVE-2026-65703 (FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulne ...)
+	TODO: check
+CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path traversal vulnerability  ...)
+	TODO: check
+CVE-2026-65604 (Skipper contains an incomplete fix for CVE-2026-50197 in which oversiz ...)
+	TODO: check
+CVE-2026-64785 (SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that  ...)
+	TODO: check
+CVE-2026-63732 (9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities:  ...)
+	TODO: check
+CVE-2026-63359 (The Appriss Insights (Equifax) Victim Information Notification Exchang ...)
+	TODO: check
+CVE-2026-63313 (9Router before 0.4.72 contains a server-side request forgery (SSRF) vu ...)
+	TODO: check
+CVE-2026-62825 (Improper authentication in Azure Key Vault allows an unauthorized atta ...)
+	TODO: check
+CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains a code  ...)
+	TODO: check
+CVE-2026-58275 (Missing authorization in Azure DNS allows an unauthorized attacker to  ...)
+	TODO: check
+CVE-2026-56191 (Improper authentication in Microsoft Exchange Online allows an unautho ...)
+	TODO: check
+CVE-2026-56167 (Server-side request forgery (ssrf) in Azure AI Search allows an author ...)
+	TODO: check
+CVE-2026-56165 (Heap-based buffer overflow in Microsoft Account allows an unauthorized ...)
+	TODO: check
+CVE-2026-56160 (Improper authorization in Azure Red Hat OpenShift (ARO) allows an auth ...)
+	TODO: check
+CVE-2026-54120 (Improper input validation in Microsoft Surface allows an authorized at ...)
+	TODO: check
+CVE-2026-52439 (An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute  ...)
+	TODO: check
+CVE-2026-50517 (Deserialization of untrusted data in M365 Copilot allows an authorized ...)
+	TODO: check
+CVE-2026-50103 (A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser,  ...)
+	TODO: check
+CVE-2026-50044 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encr ...)
+	TODO: check
+CVE-2026-50039 (The affected product is vulnerable to a stack-based buffer overflow, w ...)
+	TODO: check
+CVE-2026-50032 (A NULL pointer dereference in the MMS Write Named Variable List handle ...)
+	TODO: check
+CVE-2026-49159 (Exposure of sensitive information to an unauthorized actor in Microsof ...)
+	TODO: check
+CVE-2026-49035 (The affected product is vulnerable to a heap-based buffer overflow via ...)
+	TODO: check
+CVE-2026-48013 (Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1 ...)
+	TODO: check
+CVE-2026-48012 (Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10 ...)
+	TODO: check
+CVE-2026-47724 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
+	TODO: check
+CVE-2026-47723 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
+	TODO: check
+CVE-2026-47722 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
+	TODO: check
+CVE-2026-47670 (DbGate is cross-platform database manager. Versions 7.1.8 and prior ar ...)
+	TODO: check
+CVE-2026-47669 (DbGate is cross-platform database manager. In versions 7.1.8 and prior ...)
+	TODO: check
+CVE-2026-44955 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sen ...)
+	TODO: check
+CVE-2026-42933 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended prox ...)
+	TODO: check
+CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storag ...)
+	TODO: check
+CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability ...)
+	TODO: check
+CVE-2026-38764 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
+	TODO: check
+CVE-2026-35425 (Improper access control in Azure API Management (APIM) allows an autho ...)
+	TODO: check
+CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows ...)
+	TODO: check
+CVE-2026-28698 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sen ...)
+	TODO: check
+CVE-2026-25800 (Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC ...)
+	TODO: check
+CVE-2026-21655 (Deserialization of untrusted data vulnerability in Johnson Control vic ...)
+	TODO: check
+CVE-2026-21653 (Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor ap ...)
+	TODO: check
+CVE-2026-16870 (Multiple security vulnerabilities in Snowflake libsnowflakeclient vers ...)
+	TODO: check
+CVE-2026-16807 (Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 ...)
+	TODO: check
+CVE-2026-16806 (Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allo ...)
+	TODO: check
+CVE-2026-16805 (Use after free in Blink in Google Chrome prior to 150.0.7871.186 allow ...)
+	TODO: check
+CVE-2026-16804 (Use after free in Input in Google Chrome prior to 150.0.7871.186 allow ...)
+	TODO: check
+CVE-2026-16796 (Improper neutralization of argument delimiters in the install_packages ...)
+	TODO: check
+CVE-2026-16767 (A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affe ...)
+	TODO: check
+CVE-2026-16765 (A vulnerability was determined in CodeAstro Online Classroom 1.0. Affe ...)
+	TODO: check
+CVE-2026-16764 (A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue  ...)
+	TODO: check
+CVE-2026-16763 (A vulnerability was identified in localstack serverless-localstack up  ...)
+	TODO: check
+CVE-2026-16002 (The affected product is vulnerable to an Out-of-bounds read, which may ...)
+	TODO: check
+CVE-2026-15981 (The SAML Single Sign On \u2013 SSO Login plugin for WordPress is vulne ...)
+	TODO: check
+CVE-2026-15968 (Improper neutralization of input during web page generation ('cross-si ...)
+	TODO: check
+CVE-2026-15967 (Insufficient session expiration vulnerability in Progress MOVEit Trans ...)
+	TODO: check
+CVE-2026-15966 (Permissive cross-domain security policy with untrusted domains vulnera ...)
+	TODO: check
+CVE-2026-15630 (A non-global organization admin in one tenant can bypass tenant bounda ...)
+	TODO: check
+CVE-2026-15420 (The Nexter Blocks \u2013 Gutenberg Blocks, Page Builder & AI Website B ...)
+	TODO: check
+CVE-2026-15212 (The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Re ...)
+	TODO: check
+CVE-2026-15100 (The Post Grid Gutenberg Blocks \u2013 PostX plugin for WordPress is vu ...)
+	TODO: check
+CVE-2026-14603 (The WowOptin: Next-Gen Popup Maker  WordPress plugin before 1.4.38 doe ...)
+	TODO: check
+CVE-2026-14172 (Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered ex ...)
+	TODO: check
+CVE-2026-13464 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
+	TODO: check
+CVE-2026-12981 (The CAFEHAUS API WordPress plugin through 1.0.0 does not have any auth ...)
+	TODO: check
+CVE-2026-12877 (The Project Management, Bug and Issue Tracking Plugin  WordPress plugi ...)
+	TODO: check
+CVE-2026-12736 (The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalati ...)
+	TODO: check
+CVE-2026-12690 (The ProfileGrid  WordPress plugin before 5.9.9.7 does not perform a ca ...)
+	TODO: check
+CVE-2026-12689 (The ProfileGrid  WordPress plugin before 5.9.9.7 does not perform any  ...)
+	TODO: check
+CVE-2026-12688 (The ProfileGrid  WordPress plugin before 5.9.9.7 does not verify PayPa ...)
+	TODO: check
+CVE-2026-12497 (The Paid Membership Plugin, Ecommerce, User Registration Form, Login F ...)
+	TODO: check
+CVE-2026-12353 (An unauthenticated attacker could trigger an Out of Memory condition t ...)
+	TODO: check
+CVE-2026-11922 (A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allow ...)
+	TODO: check
+CVE-2026-11354 (The Participants Database plugin for WordPress is vulnerable to Sensit ...)
+	TODO: check
+CVE-2026-10697 (Improper Authentication vulnerability in Progress MOVEit Transfer.  Th ...)
+	TODO: check
+CVE-2025-9205 (The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scr ...)
+	TODO: check
+CVE-2025-71389 (Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated ...)
+	TODO: check
+CVE-2024-58355 (Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cros ...)
+	TODO: check
+CVE-2024-58354 (cal.com (calcom repository, later renamed cal.diy) is affected by a re ...)
+	TODO: check
+CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerabl ...)
+	TODO: check
 CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
 	- knot-resolver 6.4.1-1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
 	NOTE: https://lists.nic.cz/hyperkitty/list/knot-resolver-announce@lists.nic.cz/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
-CVE-2026-54422
+CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious bootc cont ...)
 	- ironic-python-agent <unfixed>
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
@@ -558,7 +734,7 @@ CVE-2026-27422 (Unauthenticated Broken Access Control in YT Player <= 2.0.9 vers
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27418 (Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81. ...)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-27403 (Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versio ...)
+CVE-2026-27403 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27399 (Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions ...)
 	NOT-FOR-US: WordPress plugin or theme
@@ -7771,6 +7947,7 @@ CVE-2026-63030 (WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected
 	NOTE: https://github.com/WordPress/wordpress-develop/commit/6f2074dda61864a03f334d70414d1690ce7e5c79 (6.9.5)
 	NOTE: The error handling in the problematic function is different in 6.8 and below.
 CVE-2026-60137 (WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0 ...)
+	{DSA-6399-1}
 	- wordpress 7.0.2+dfsg1-1 (bug #1142510)
 	[bookworm] - wordpress <not-affected> (Vulnerable is_array-gated author__not_in handling introduced in 6.8; shipped version applies absint unconditionally)
 	[bullseye] - wordpress <not-affected> (Vulnerable is_array-gated author__not_in handling introduced in 6.8; shipped version applies absint unconditionally)
@@ -23351,7 +23528,7 @@ CVE-2026-8720 (wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message w
 	[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
 	[bullseye] - wolfssl <postponed> (Minor issue)
 	NOTE: https://github.com/wolfSSL/wolfssl/pull/10447 (v5.9.2-stable)
-CVE-2026-8661 (Server-Side Cross-Site Scripting and Server-Side Request Forgery vulne ...)
+CVE-2026-8661 (Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 In ...)
 	NOT-FOR-US: Rapid7
 CVE-2026-8380 (The Frontend File Manager Plugin WordPress plugin through 23.6 does no ...)
 	NOT-FOR-US: WordPress plugin
@@ -33599,14 +33776,14 @@ CVE-2017-20240 (Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable t
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40929601/
 	NOTE: Fixed by: https://github.com/arodland/Crypt-PBKDF2/commit/ac5aac7c8c0e411165a6665a9c1f449b745f2629 (0.261630)
 CVE-2026-50012 (Squid is a caching proxy for the Web. Prior to 7.6, due to an improper ...)
-	{DSA-6360-1}
+	{DSA-6360-1 DLA-4697-1}
 	- squid 7.6-1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/06/12/1
 	NOTE: Fixed by: https://github.com/squid-cache/squid/commit/19fcfe922717c8b255270c032dcde4071c003bcd (SQUID_7_6)
 	NOTE: Follow-up: https://github.com/squid-cache/squid/commit/c9c9a06be6fb21f400014dcb0ec7e6d573167a5d (SQUID_7_6)
 	NOTE: https://github.com/squid-cache/squid/security/advisories/GHSA-5vmx-9x64-9284
 CVE-2026-47729 (Squid is a caching proxy for the Web. Prior to 7.6, due to an improper ...)
-	{DSA-6360-1}
+	{DSA-6360-1 DLA-4697-1}
 	- squid 7.6-1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/06/12/1
 	NOTE: https://blog.calif.io/p/squidbleed-cve-2026-47729
@@ -35988,7 +36165,7 @@ CVE-2025-55657 (A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs functi
 CVE-2025-55651 (A NULL pointer dereference in the gf_isom_get_user_data_count function ...)
 	- gpac <removed>
 	[bullseye] - gpac <end-of-life> (EOL in bullseye LTS)
-CVE-2025-54509 (Improper access control for register interface in the input-output mem ...)
+CVE-2025-54509 (Improper access control for register interface in the Input-Output Mem ...)
 	NOT-FOR-US: AMD
 CVE-2025-52293 (A segmentation violaton in the gf_hevc_read_sps_bs_internal function ( ...)
 	- gpac <removed>
@@ -84519,7 +84696,7 @@ CVE-2026-3608 (Sending a maliciously crafted message to the kea-ctrl-agent, kea-
 	[trixie] - isc-kea 2.6.3-1+deb13u1
 	NOTE: https://kb.isc.org/docs/cve-2026-3608
 CVE-2026-33515 (Squid is a caching proxy for the Web. Prior to version 7.5, due to imp ...)
-	{DSA-6360-1}
+	{DSA-6360-1 DLA-4697-1}
 	- squid 7.5-1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/4
 	NOTE: Fxied by: https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165 (SQUID_7_5)
@@ -84531,7 +84708,7 @@ CVE-2026-32748 (Squid is a caching proxy for the Web. Prior to version 7.5, due
 	NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/3
 	NOTE: Fixed by: https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b (SQUID_7_5)
 CVE-2026-33526 (Squid is a caching proxy for the Web. Prior to version 7.5, due to hea ...)
-	{DSA-6360-1}
+	{DSA-6360-1 DLA-4697-1}
 	- squid 7.5-1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/2
 	NOTE: Fixed by: https://github.com/squid-cache/squid/commit/8a7d42f9d44befb8fcbbb619505587c8de6a1e91 (SQUID_7_5)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/032290e3941895795a6b5531276b3f45bac32de7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/032290e3941895795a6b5531276b3f45bac32de7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/460e8a12/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list