[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 31 08:12:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fcb7a928 by security tracker role at 2026-07-31T07:12:28+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,269 @@
+CVE-2026-8155 (The BuddyPress WordPress plugin before 14.5.0 does not properly enforc ...)
+	TODO: check
+CVE-2026-6890
+	REJECTED
+CVE-2026-6889
+	REJECTED
+CVE-2026-68563 (A flaw was found in ansible-collection-redhat-leapp. When a remediatio ...)
+	TODO: check
+CVE-2026-68562 (A flaw was found in ansible-collection-redhat-leapp. An attacker with  ...)
+	TODO: check
+CVE-2026-68503 (LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operati ...)
+	TODO: check
+CVE-2026-68502 (LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operati ...)
+	TODO: check
+CVE-2026-68501 (Sylius Mollie Plugin provides Mollie payment integration for Sylius ap ...)
+	TODO: check
+CVE-2026-68500 (Sylius Mollie Plugin provides Mollie payment integration for Sylius ap ...)
+	TODO: check
+CVE-2026-68499 (re2 provides Node.js bindings for Google's RE2 regular expression engi ...)
+	TODO: check
+CVE-2026-67594 (Spikster through commit e1cdf8c contains a missing authentication vuln ...)
+	TODO: check
+CVE-2026-67550 (re2 provides Node.js bindings for Google's RE2 regular expression engi ...)
+	TODO: check
+CVE-2026-67530 (WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earli ...)
+	TODO: check
+CVE-2026-67529 (OpenProject is open-source, web-based project management software. Pri ...)
+	TODO: check
+CVE-2026-67528 (OpenProject is open-source, web-based project management software. Pri ...)
+	TODO: check
+CVE-2026-67527 (OpenProject is open-source, web-based project management software. Pri ...)
+	TODO: check
+CVE-2026-67208 (Juggle through 1.6.0 contains a remote code execution vulnerability th ...)
+	TODO: check
+CVE-2026-67207 (Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerabilit ...)
+	TODO: check
+CVE-2026-67206 (Wolf CMS through 0.8.3.1 contains a remote code execution vulnerabilit ...)
+	TODO: check
+CVE-2026-66803 (Improper access control in Azure Cosmos DB allows an unauthorized atta ...)
+	TODO: check
+CVE-2026-66756 (Improper Protection of Alternate Path vulnerability in Apache Tika.  T ...)
+	TODO: check
+CVE-2026-66755 (Relative Path Traversal in the ISA-Tab parser in Apache Software Found ...)
+	TODO: check
+CVE-2026-66720 (The GOOSE subscriber component improperly validates the UTC timestamp  ...)
+	TODO: check
+CVE-2026-66421 (OpenClaw Dashboard contains a stored cross-site scripting vulnerabilit ...)
+	TODO: check
+CVE-2026-66420 (MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protectio ...)
+	TODO: check
+CVE-2026-66418 (OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulne ...)
+	TODO: check
+CVE-2026-66369 (The GOOSE parser contains an off-by-one boundary-handling flaw that ca ...)
+	TODO: check
+CVE-2026-66364 (The GOOSE payload parser contains a boundary handling flaw that can be ...)
+	TODO: check
+CVE-2026-66360 (The ISO Presentation layer contains a flaw in the handling of specific ...)
+	TODO: check
+CVE-2026-66349 (The MMS server connection handler contains a flaw in its processing of ...)
+	TODO: check
+CVE-2026-65835 (Capsule is a multi-tenancy and policy-based framework for Kubernetes.  ...)
+	TODO: check
+CVE-2026-65834 (Capsule is a multi-tenancy and policy-based framework for Kubernetes.  ...)
+	TODO: check
+CVE-2026-65423 (An integer overflow in the UA_Variant arrayDimensions product  computa ...)
+	TODO: check
+CVE-2026-65421 (The MMS BER decoder contains a flaw in decoding fixed-width BER fields ...)
+	TODO: check
+CVE-2026-64816 (RapidRAW before 1.6.0 does not validate the lutPath field in preset fi ...)
+	TODO: check
+CVE-2026-63559 (An integer overflow in the UA_Variant arrayDimensions product  computa ...)
+	TODO: check
+CVE-2026-63550 (The MMS BER decoder contains a boundary-handling flaw in the processin ...)
+	TODO: check
+CVE-2026-63362 (An unsigned integer underflow in the PubSub signature verification pat ...)
+	TODO: check
+CVE-2026-63223 (CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_ ...)
+	TODO: check
+CVE-2026-63222 (CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling ...)
+	TODO: check
+CVE-2026-63221 (CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7. ...)
+	TODO: check
+CVE-2026-63220 (CodeIgniter is a PHP full-stack web framework. In versions prior to 4. ...)
+	TODO: check
+CVE-2026-63035 (A heap use-after-free vulnerability in the TransferSubscriptions servi ...)
+	TODO: check
+CVE-2026-63033 (A crafted IEC 60870-5-104 I-frame with a declared object count exceedi ...)
+	TODO: check
+CVE-2026-62845 (Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26 ...)
+	TODO: check
+CVE-2026-62323 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
+	TODO: check
+CVE-2026-62246 (Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26 ...)
+	TODO: check
+CVE-2026-61893 (A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an   ...)
+	TODO: check
+CVE-2026-61526 (AdonisJS HTTP Server is a package for handling HTTP requests in the Ad ...)
+	TODO: check
+CVE-2026-5846 (The affectedWatchfire Controller Softwarecontains self-signed hard-cod ...)
+	TODO: check
+CVE-2026-56758 (The ACSE layer contains a flaw in the processing of AARQ PDUs during M ...)
+	TODO: check
+CVE-2026-56673 (ComfyUI is a modular diffusion model GUI, API, and backend with a grap ...)
+	TODO: check
+CVE-2026-56672 (ComfyUI is a node-based diffusion model GUI, API, and backend. Prior t ...)
+	TODO: check
+CVE-2026-56671 (ComfyUI is a modular diffusion model GUI, api and backend with a graph ...)
+	TODO: check
+CVE-2026-56670 (ComfyUI is a modular diffusion model GUI, api and backend with a graph ...)
+	TODO: check
+CVE-2026-55777 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
+	TODO: check
+CVE-2026-55768 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
+	TODO: check
+CVE-2026-55502 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
+	TODO: check
+CVE-2026-55499 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
+	TODO: check
+CVE-2026-55497 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
+	TODO: check
+CVE-2026-55496 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
+	TODO: check
+CVE-2026-55495 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
+	TODO: check
+CVE-2026-54715 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
+	TODO: check
+CVE-2026-52539 (Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When t ...)
+	TODO: check
+CVE-2026-43833 (Full details and mitigation steps are currently restricted and will be ...)
+	TODO: check
+CVE-2026-43832 (Full details and mitigation steps are currently restricted and will be ...)
+	TODO: check
+CVE-2026-43831 (Full details and mitigation steps are currently restricted and will be ...)
+	TODO: check
+CVE-2026-43830 (Full details and mitigation steps are currently restricted and will be ...)
+	TODO: check
+CVE-2026-43829 (Full details and mitigation steps are currently restricted and will be ...)
+	TODO: check
+CVE-2026-38709 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300  ...)
+	TODO: check
+CVE-2026-35847 (An issue in dnsmgr v.2.15 and before allows a local attacker to execut ...)
+	TODO: check
+CVE-2026-18452 (DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Cre ...)
+	TODO: check
+CVE-2026-18157 (A flaw was found in yggdrasil-worker-package-manager. A local attacker ...)
+	TODO: check
+CVE-2026-18064 (An incomplete fix for CVE-2026-15352 in the NASA core Flight System  ( ...)
+	TODO: check
+CVE-2026-16236 (The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitra ...)
+	TODO: check
+CVE-2026-15381 (The WP Go Maps  WordPress plugin before 10.1.04 does not properly sani ...)
+	TODO: check
+CVE-2026-15258 (The Product Feed Manager For WooCommerce  WordPress plugin before 7.6. ...)
+	TODO: check
+CVE-2026-15209 (The JS Help Desk  WordPress plugin before 3.1.5 does not verify that t ...)
+	TODO: check
+CVE-2026-15048 (The Geeky Bot  WordPress plugin before 1.2.8 does not perform an autho ...)
+	TODO: check
+CVE-2026-14931 (The JS Help Desk  WordPress plugin before 3.1.4 grants a support-agent ...)
+	TODO: check
+CVE-2026-14930 (The JS Help Desk  WordPress plugin before 3.1.4 does not perform any a ...)
+	TODO: check
+CVE-2026-14929 (The JS Help Desk  WordPress plugin before 3.1.4 does not verify owners ...)
+	TODO: check
+CVE-2026-14928 (The JS Help Desk  WordPress plugin before 3.1.4 does not perform autho ...)
+	TODO: check
+CVE-2026-14927 (The FluentCart A New Era of eCommerce  WordPress plugin before 1.5.3 d ...)
+	TODO: check
+CVE-2026-14922 (WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in al ...)
+	TODO: check
+CVE-2026-14921 (The Ultimate Addons for WPBakery Page Builder WordPress plugin before  ...)
+	TODO: check
+CVE-2026-14919 (The ShopMonitor.io  WordPress plugin before 1.2.0 does not properly re ...)
+	TODO: check
+CVE-2026-14862 (The Support Genix  WordPress plugin before 1.4.48 does not properly au ...)
+	TODO: check
+CVE-2026-14849 (The Paid Membership Subscriptions  WordPress plugin before 3.0.7 does  ...)
+	TODO: check
+CVE-2026-14847 (The Paid Membership Subscriptions  WordPress plugin before 3.0.7 does  ...)
+	TODO: check
+CVE-2026-14845 (The NewStatPress WordPress plugin before 1.4.5 does not sanitise and e ...)
+	TODO: check
+CVE-2026-14843 (The Events Made Easy WordPress plugin before 3.1.4 does not verify tha ...)
+	TODO: check
+CVE-2026-14834 (The Mailgun for WordPress plugin before 2.2.1 does not perform any cap ...)
+	TODO: check
+CVE-2026-14833 (The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sa ...)
+	TODO: check
+CVE-2026-14830 (The FlxWoo WordPress plugin before 3.1.1 does not verify with the paym ...)
+	TODO: check
+CVE-2026-14554 (The Check & Log Email  WordPress plugin before 2.0.15 does not properl ...)
+	TODO: check
+CVE-2026-14541 (An authentication bypass and audience confusion vulnerability exists i ...)
+	TODO: check
+CVE-2026-14540 (A Server-Side Request Forgery (SSRF) vulnerability exists in the gener ...)
+	TODO: check
+CVE-2026-14539 (An allocation of resources without limits vulnerability in the HTTP ha ...)
+	TODO: check
+CVE-2026-14538 (An improper authorization and security-boundary bypass vulnerability i ...)
+	TODO: check
+CVE-2026-14537 (Incorrect Authorization in the direct HTTP API tool invocation endpoin ...)
+	TODO: check
+CVE-2026-14483 (The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress ...)
+	TODO: check
+CVE-2026-14333 (The Demi  WordPress plugin before 0.0.7 stores its full-site backup ar ...)
+	TODO: check
+CVE-2026-14319 (The GiveWP  WordPress plugin before 4.16.3 does not properly restrict  ...)
+	TODO: check
+CVE-2026-14317 (The GiveWP  WordPress plugin before 4.16.3 does not restrict the set o ...)
+	TODO: check
+CVE-2026-13609 (The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decode ...)
+	TODO: check
+CVE-2026-13393 (The ElementsKit Elementor Addons  WordPress plugin before 3.10.01 does ...)
+	TODO: check
+CVE-2026-13392 (The ElementsKit Elementor Addons  WordPress plugin before 3.10.01 does ...)
+	TODO: check
+CVE-2026-12946 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to ...)
+	TODO: check
+CVE-2026-12721 (The Kirki  WordPress plugin before 6.0.13 does not properly sanitise a ...)
+	TODO: check
+CVE-2026-12720 (The Kirki  WordPress plugin before 6.0.13 does not restrict which clas ...)
+	TODO: check
+CVE-2026-12697 (The wpForo Forum WordPress plugin before 3.1.2 does not verify that an ...)
+	TODO: check
+CVE-2026-12695 (The miniOrange 2FA  WordPress plugin before 6.2.6 does not validate th ...)
+	TODO: check
+CVE-2026-12562 (The RCU II+ and Multiload II+ are vulnerable to an unauthenticated  se ...)
+	TODO: check
+CVE-2026-12376 (The Academy LMS WordPress plugin through 3.8.2 does not restrict acces ...)
+	TODO: check
+CVE-2026-12251 (The Ultimate Member  WordPress plugin before 2.12.1 does not filter ad ...)
+	TODO: check
+CVE-2026-11536 (IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote  ...)
+	TODO: check
+CVE-2026-10569 (IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7 ...)
+	TODO: check
+CVE-2026-10031 (SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that  ...)
+	TODO: check
+CVE-2025-69947 (SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injec ...)
+	TODO: check
+CVE-2025-69941 (SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injec ...)
+	TODO: check
+CVE-2025-69938 (CodeAstro Membership Management System 1.0 is vulnerable to SQL Inject ...)
+	TODO: check
+CVE-2025-69937 (CodeAstro Membership Management System 1.0 is vulnerable to SQL Inject ...)
+	TODO: check
+CVE-2025-69936 (CodeAstro Membership Management System 1.0 is vulnerable to SQL Inject ...)
+	TODO: check
+CVE-2025-69935 (CodeAstro Membership Management System 1.0 is vulnerale to SQL Injecti ...)
+	TODO: check
+CVE-2025-69934 (CodeAstro Membership Management System 1.0 is vulnerable to SQL Inject ...)
+	TODO: check
+CVE-2025-69933 (CodeAstro Membership Management System 1.0 is vulnerable to SQL Inject ...)
+	TODO: check
+CVE-2025-69931 (CodeAstro Membership Management System 1.0 is vulnerable to SQL Inject ...)
+	TODO: check
+CVE-2025-69930 (CodeAstro Membership Management System 1.0 is vulnerable to SQL Inject ...)
+	TODO: check
+CVE-2025-65342 (code-projects Blood System 1.0 is vulnerable to Cross Site Scripting ( ...)
+	TODO: check
+CVE-2025-65341 (Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) ...)
+	TODO: check
+CVE-2025-65336 (Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable t ...)
+	TODO: check
+CVE-2025-51684 (CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). ...)
+	TODO: check
 CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
 	NOT-FOR-US: IBM
 CVE-2026-7849 (Due to improper neutralization of special elements, an unauthenticated ...)
@@ -358,7 +624,7 @@ CVE-2022-4994 (In the Linux kernel, the following vulnerability has been resolve
 CVE-2026-58044
 	- nodejs <unfixed>
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http-parser-header-truncation-can-enable-request-smuggling-cve-2026-58044---low
-CVE-2026-58039
+CVE-2026-58039 (A flaw in Node.js Permission Model enforcement allows process.report w ...)
 	- nodejs <unfixed>
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-allows-process-reports-to-write-outside-the-allowlist-cve-2026-58039---low
 CVE-2026-58045
@@ -39269,7 +39535,7 @@ CVE-2025-56814 (A code injection vulnerability in the wxExecute() function of Op
 CVE-2025-10262 (Nokia SR Linux is vulnerable to local privilege escalation vulnerabili ...)
 	NOT-FOR-US: Nokia
 CVE-2026-56968 (GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsas ...)
-	{DSA-6348-1}
+	{DSA-6348-1 DLA-4707-1}
 	- gsasl 2.2.4-1
 	NOTE: https://lists.gnu.org/archive/html/help-gsasl/2026-06/msg00000.html
 CVE-2026-53704 (A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-u ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcb7a92893c4ce702cde900f7c935363c974e8ac

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcb7a92893c4ce702cde900f7c935363c974e8ac
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/63666229/attachment.htm>


More information about the debian-security-tracker-commits mailing list