[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 29 08:12:45 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ab96fef0 by security tracker role at 2026-07-29T07:12:38+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,203 @@
+CVE-2026-6881 (A SQL Injection in the Giving Reports functionality in Ellucian Advanc ...)
+ TODO: check
+CVE-2026-66064 (goshs is a feature-rich single-binary file server for red teamers and ...)
+ TODO: check
+CVE-2026-66063 (goshs is a feature-rich single-binary file server for red teamers and ...)
+ TODO: check
+CVE-2026-64863 (goshs is a feature-rich single-binary file server for red teamers and ...)
+ TODO: check
+CVE-2026-63242 (A business logic vulnerability in Koollab LMS allowed an authenticated ...)
+ TODO: check
+CVE-2026-63241 (An insecure direct object reference vulnerability in Koollab LMS allow ...)
+ TODO: check
+CVE-2026-63240 (An information disclosure vulnerability in Koollab LMS allowed an auth ...)
+ TODO: check
+CVE-2026-63239 (A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed ...)
+ TODO: check
+CVE-2026-63238 (An authentication bypass vulnerability in Koollab LMS allowed an unaut ...)
+ TODO: check
+CVE-2026-63237 (A TOTP two-factor authentication bypass vulnerability in Koollab LMS a ...)
+ TODO: check
+CVE-2026-63236 (An improper access control vulnerability in Koollab LMS allowed an una ...)
+ TODO: check
+CVE-2026-63235 (An improper access control vulnerability in Koollab LMS allowed an una ...)
+ TODO: check
+CVE-2026-63234 (A SQL injection and unsafe deserialisation vulnerability in Koollab LM ...)
+ TODO: check
+CVE-2026-63233 (A SQL injection and unsafe deserialisation vulnerability in Koollab LM ...)
+ TODO: check
+CVE-2026-63232 (A SQL injection and unsafe deserialisation vulnerability in Koollab LM ...)
+ TODO: check
+CVE-2026-63231 (A post-authentication SQL injection vulnerability in Koollab LMS allow ...)
+ TODO: check
+CVE-2026-63230 (A pre-authentication error-based SQL injection vulnerability in Koolla ...)
+ TODO: check
+CVE-2026-63229 (A pre-authentication blind SQL injection vulnerability in Koollab LMS ...)
+ TODO: check
+CVE-2026-63228 (An unrestricted image upload vulnerability in Koollab LMS allowed an a ...)
+ TODO: check
+CVE-2026-63227 (An unrestricted SCORM file upload vulnerability in Koollab LMS allowed ...)
+ TODO: check
+CVE-2026-62325 (goshs is a feature-rich single-binary file server for red teamers and ...)
+ TODO: check
+CVE-2026-5626 (The Survey Form Block plugin for WordPress is vulnerable to unauthoriz ...)
+ TODO: check
+CVE-2026-59943 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
+ TODO: check
+CVE-2026-59942 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior ar ...)
+ TODO: check
+CVE-2026-59941 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior ac ...)
+ TODO: check
+CVE-2026-59921 (Netty is an asynchronous, event-driven network application framework. ...)
+ TODO: check
+CVE-2026-57511 (SuperPlane before 0.30.0 contains an SMTP header injection vulnerabili ...)
+ TODO: check
+CVE-2026-57510 (SuperPlane before 0.27.0 contains a broken object-level authorization ...)
+ TODO: check
+CVE-2026-56822 (Netty is an asynchronous, event-driven network application framework. ...)
+ TODO: check
+CVE-2026-56821 (Netty is an asynchronous, event-driven network application framework. ...)
+ TODO: check
+CVE-2026-56722 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
+ TODO: check
+CVE-2026-55555 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior ar ...)
+ TODO: check
+CVE-2026-55554 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
+ TODO: check
+CVE-2026-55415 (datamodel-code-generator generates Pydantic v2 models, dataclasses, Ty ...)
+ TODO: check
+CVE-2026-55403 (datamodel-code-generator generates Python data models from schema defi ...)
+ TODO: check
+CVE-2026-55391 (datamodel-code-generator generates Pydantic v2 models, dataclasses, Ty ...)
+ TODO: check
+CVE-2026-55390 (datamodel-code-generator generates Python data models from schema defi ...)
+ TODO: check
+CVE-2026-55389 (datamodel-code-generator generates Pydantic v2 models, dataclasses, Ty ...)
+ TODO: check
+CVE-2026-54719 (goshs is a feature-rich single-binary file server for red teamers and ...)
+ TODO: check
+CVE-2026-54691 (datamodel-code-generator generates Python data models from schema defi ...)
+ TODO: check
+CVE-2026-54690 (datamodel-code-generator generates Pydantic v2 models, dataclasses, Ty ...)
+ TODO: check
+CVE-2026-54659 (Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, P ...)
+ TODO: check
+CVE-2026-54658 (Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0. ...)
+ TODO: check
+CVE-2026-54656 (datamodel-code-generator generates Pydantic v2 models, dataclasses, Ty ...)
+ TODO: check
+CVE-2026-54655 (datamodel-code-generator generates Python data models from schema defi ...)
+ TODO: check
+CVE-2026-54654 (datamodel-code-generator generates Python data models from schema defi ...)
+ TODO: check
+CVE-2026-54653 (datamodel-code-generator generates Pydantic v2 models, dataclasses, Ty ...)
+ TODO: check
+CVE-2026-54650 (openhole exposes localhost to the internet in one command. In 0.1.1 an ...)
+ TODO: check
+CVE-2026-54638 (gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, pr ...)
+ TODO: check
+CVE-2026-54621 (datamodel-code-generator generates Python data models from schema defi ...)
+ TODO: check
+CVE-2026-49447 (Cosmos provides users the ability self-host a home server by acting as ...)
+ TODO: check
+CVE-2026-48060 (Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. ...)
+ TODO: check
+CVE-2026-47219 (find-my-way is a framework-independent HTTP router that internally use ...)
+ TODO: check
+CVE-2026-3158 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through ...)
+ TODO: check
+CVE-2026-3157 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through ...)
+ TODO: check
+CVE-2026-1918 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through ...)
+ TODO: check
+CVE-2026-18072 (The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vi ...)
+ TODO: check
+CVE-2026-17166 (The Event Booking Manager for WooCommerce \u2013 Sell Tickets, Event R ...)
+ TODO: check
+CVE-2026-17162 (The WowStore \u2013 Store Builder & Product Blocks for WooCommerce plu ...)
+ TODO: check
+CVE-2026-17161 (The WowStore \u2013 Store Builder & Product Blocks for WooCommerce plu ...)
+ TODO: check
+CVE-2026-16581 (In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclus ...)
+ TODO: check
+CVE-2026-16347 (MikroTik RouterOS contains a weakness in its API authentication handli ...)
+ TODO: check
+CVE-2026-16192 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
+ TODO: check
+CVE-2026-16184 (IBM WebSphere Application Server 9.0, and 8.5 could allow a remote att ...)
+ TODO: check
+CVE-2026-16107 (IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not validat ...)
+ TODO: check
+CVE-2026-15735 (The Contact Form to Any API plugin for WordPress is vulnerable to Stor ...)
+ TODO: check
+CVE-2026-15344 (The WP Photo Album Plus plugin for WordPress is vulnerable to generic ...)
+ TODO: check
+CVE-2026-15328 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+ TODO: check
+CVE-2026-15325 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+ TODO: check
+CVE-2026-15280 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 N ...)
+ TODO: check
+CVE-2026-15064 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+ TODO: check
+CVE-2026-15057 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i ...)
+ TODO: check
+CVE-2026-14996 (IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerabili ...)
+ TODO: check
+CVE-2026-14981 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+ TODO: check
+CVE-2026-14976 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
+ TODO: check
+CVE-2026-14974 (IBM WebSphere Application Server 8.5, and 9.0 traditional could allow ...)
+ TODO: check
+CVE-2026-14973 (IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can ...)
+ TODO: check
+CVE-2026-14959 (IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authen ...)
+ TODO: check
+CVE-2026-14958 (IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authen ...)
+ TODO: check
+CVE-2026-14893 (IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 I ...)
+ TODO: check
+CVE-2026-14528 (IBM WebSphere Application Server 9.0, and 8.5 traditional could allow ...)
+ TODO: check
+CVE-2026-14515 (IBM WebSphere Application Server 8.5, and 9.0 traditional could allow ...)
+ TODO: check
+CVE-2026-14512 (IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerabl ...)
+ TODO: check
+CVE-2026-14446 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken ...)
+ TODO: check
+CVE-2026-14300 (The miniOrange Social Login and Register (Discord, Google, Twitter, Li ...)
+ TODO: check
+CVE-2026-14234 (The WOLF WordPress plugin before 1.1.0 does not perform a nonce or ca ...)
+ TODO: check
+CVE-2026-14224 (The Easy Appointments WordPress plugin through 3.12.26 does not verify ...)
+ TODO: check
+CVE-2026-13692 (The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not ve ...)
+ TODO: check
+CVE-2026-13690 (The UsersWP WordPress plugin before 1.2.67 does not validate the sele ...)
+ TODO: check
+CVE-2026-13605 (The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribu ...)
+ TODO: check
+CVE-2026-13463 (IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain se ...)
+ TODO: check
+CVE-2026-13442 (IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse a ...)
+ TODO: check
+CVE-2026-13423 (The Streamit WordPress theme through 4.5.0 does not perform any author ...)
+ TODO: check
+CVE-2026-12939 (The Newsletters Lite plugin for WordPress is vulnerable to Stored Cros ...)
+ TODO: check
+CVE-2026-12938 (The Newsletters Lite plugin for WordPress is vulnerable to Stored Cros ...)
+ TODO: check
+CVE-2026-12476 (The Easy Digital Downloads plugin for WordPress is vulnerable to Arbit ...)
+ TODO: check
+CVE-2026-12144 (The Wholesale for WooCommerce plugin for WordPress is vulnerable to Pr ...)
+ TODO: check
+CVE-2026-11974 (The wp-media-folder-addon WordPress plugin through 4.1.6 does not vali ...)
+ TODO: check
+CVE-2026-11391 (Tanium addressed a SQL injection vulnerability in Patch.)
+ TODO: check
+CVE-2026-11351 (The ShinyStat Analytics WordPress plugin before 1.0.17 does not perfor ...)
+ TODO: check
CVE-2026-XXXX [relay: use-after-free and double free when a remote relay sends an event with an array as body]
- weechat 4.9.5-1 (bug #1142894)
NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-hx59-4hq9-6vmw
@@ -81871,6 +82071,7 @@ CVE-2026-27315 (Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allo
CVE-2026-27314 (Privilege escalationin Apache Cassandra 5.0 on an mTLS environment usi ...)
- cassandra <itp> (bug #585905)
CVE-2026-24660 (A heap-based buffer overflow vulnerability exists in the x3f_load_huff ...)
+ {DLA-4704-1}
- libraw 0.22.1-1 (bug #1133845)
[trixie] - libraw <no-dsa> (Minor issue)
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2359
@@ -81913,6 +82114,7 @@ CVE-2026-22679 (Weaver (Fanwei) E-cology 10.0 versions prior to20260312 contain
CVE-2026-22666 (Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated rem ...)
- dolibarr <removed>
CVE-2026-21413 (A heap-based buffer overflow vulnerability exists in the lossless_jpeg ...)
+ {DLA-4704-1}
- libraw 0.22.1-1 (bug #1133845)
[trixie] - libraw <no-dsa> (Minor issue)
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2331
@@ -81928,12 +82130,14 @@ CVE-2026-20911 (A heap-based buffer overflow vulnerability exists in the HuffTab
NOTE: https://github.com/LibRaw/LibRaw/commit/5357bb5fc67ac616838fb84de67260d45987489b (0.22.1)
NOTE: Introduced by: https://github.com/LibRaw/LibRaw/commit/12b0e5d60c57bb795382fda8494fc45f683550b8 (0.22.0)
CVE-2026-20889 (A heap-based buffer overflow vulnerability exists in the x3f_thumb_loa ...)
+ {DLA-4704-1}
- libraw 0.22.1-1 (bug #1133845)
[trixie] - libraw <no-dsa> (Minor issue)
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2358
NOTE: https://github.com/LibRaw/LibRaw/commit/657b68d20456eaeb9639976f328827195ff41383
NOTE: https://github.com/LibRaw/LibRaw/commit/b9809e410d07ca7bf408e6d036615fb34f8c47cc (0.22.1)
CVE-2026-20884 (An integer overflow vulnerability exists in the deflate_dng_load_raw f ...)
+ {DLA-4704-1}
- libraw 0.22.1-1 (bug #1133845)
[trixie] - libraw <no-dsa> (Minor issue)
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2364
@@ -83956,6 +84160,7 @@ CVE-2026-5346 (A vulnerability was determined in huimeicloud hm_editor up to 2.2
CVE-2026-5344 (A security vulnerability has been detected in Textpattern up to 4.9.1. ...)
- textpattern <removed>
CVE-2026-5342 (A flaw has been found in LibRaw up to 0.22.0. This affects the functio ...)
+ {DLA-4704-1}
- libraw 0.22.1-1 (bug #1132655)
[trixie] - libraw <no-dsa> (Minor issue)
NOTE: https://github.com/LibRaw/LibRaw/issues/795
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab96fef0dc317333a253379c339ba6a339d235fd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ab96fef0dc317333a253379c339ba6a339d235fd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/b5eb3bc2/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list