[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 1 20:13:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b0e38878 by security tracker role at 2026-09-01T19:13:00+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,104 +1,530 @@
-CVE-2026-84145
+CVE-2026-9637 (A denial-of-service security issue exists in the affected Logix platfo ...)
+	TODO: check
+CVE-2026-9634 (A security issue exists within the Redundancy Module Configuration Too ...)
+	TODO: check
+CVE-2026-9633 (A security issue exists within the Redundancy Module Configuration Too ...)
+	TODO: check
+CVE-2026-9625 (A denial-of-service security issue exists within RSLinx\xae Classic. A ...)
+	TODO: check
+CVE-2026-9624 (A denial-of-service security issue exists within RSLinx\xae Classic. A ...)
+	TODO: check
+CVE-2026-9622 (A denial-of-service security issue exists within RSLinx\xae Classic. A ...)
+	TODO: check
+CVE-2026-9621 (A denial-of-service security issue exists within RSLinx\xae Classic. T ...)
+	TODO: check
+CVE-2026-8712 (Wyoming before 1.10.2 contains a server-side request forgery vulnerabi ...)
+	TODO: check
+CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
+	TODO: check
+CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)
+	TODO: check
+CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ...)
+	TODO: check
+CVE-2026-84270 (A flaw was found in the MTP backend in gvfs. When reading a file from  ...)
+	TODO: check
+CVE-2026-84269 (A flaw was found in the AFP backend in gvfs. When mounting a share, a  ...)
+	TODO: check
+CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a share an ...)
+	TODO: check
+CVE-2026-84267 (A flaw was found in the SFTP backend in gvfs. When mounting a share, a ...)
+	TODO: check
+CVE-2026-84235 (A denial-of-service security issue exists in the affected product. The ...)
+	TODO: check
+CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a specially cra ...)
+	TODO: check
+CVE-2026-84232 (A flaw was found in pulpcore's content serving application. Files uplo ...)
+	TODO: check
+CVE-2026-84218 (A flaw was found in Jolokia's JSR-160 proxy functionality where insuff ...)
+	TODO: check
+CVE-2026-84207 (Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send ...)
+	TODO: check
+CVE-2026-84206 (Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the ass ...)
+	TODO: check
+CVE-2026-84205 (GROWI contains an access control vulnerability in the GET /_api/v3/rev ...)
+	TODO: check
+CVE-2026-84204 (GROWI contains an access control vulnerability in the GET /_api/v3/att ...)
+	TODO: check
+CVE-2026-84203 (Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens whe ...)
+	TODO: check
+CVE-2026-84202 (ModelScope uses PyYAML's unsafe yaml.Loader to parse model configurati ...)
+	TODO: check
+CVE-2026-84201 (appium-mcp-server through 0.1.61 fails to validate or normalize file p ...)
+	TODO: check
+CVE-2026-84200 (Kyverno versions v1.9.0 through v1.12.7 contain a policy exception han ...)
+	TODO: check
+CVE-2026-84199 (Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vu ...)
+	TODO: check
+CVE-2026-84196 (Kyverno before 1.18.0 contains a server-side request forgery vulnerabi ...)
+	TODO: check
+CVE-2026-84195 (Kyverno before 1.16.4 automatically attaches the admission controller' ...)
+	TODO: check
+CVE-2026-84194 (LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an ...)
+	TODO: check
+CVE-2026-84193 (LibreNMS through 26.2.0 contains a stored cross-site scripting vulnera ...)
+	TODO: check
+CVE-2026-84192 (LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerab ...)
+	TODO: check
+CVE-2026-84191 (LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabil ...)
+	TODO: check
+CVE-2026-84190 (LibreNMS versions before 26.5.0 contain a remote code execution vulner ...)
+	TODO: check
+CVE-2026-84189 (LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author,  ...)
+	TODO: check
+CVE-2026-84188 (LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vuln ...)
+	TODO: check
+CVE-2026-84187 (AVideo contains a missing authentication vulnerability in plugin/Live/ ...)
+	TODO: check
+CVE-2026-84165 (A vulnerability relating to incorrect access control in OpenNebula by  ...)
+	TODO: check
+CVE-2026-84153 (A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. T ...)
+	TODO: check
+CVE-2026-84149 (This vulnerability exists in the ERP system due to exposure of reposit ...)
+	TODO: check
+CVE-2026-84148 (This vulnerability exists in the ERP system due to improper authentica ...)
+	TODO: check
+CVE-2026-84147 (This vulnerability exists in the ERP system due to improper authentica ...)
+	TODO: check
+CVE-2026-84115 (A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected ...)
+	TODO: check
+CVE-2026-84114 (A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacte ...)
+	TODO: check
+CVE-2026-84111 (A flaw has been found in Chanjet CRM up to 20260707. This issue affect ...)
+	TODO: check
+CVE-2026-84110 (A vulnerability was detected in Releasit Releasit COD Form & Upsells v ...)
+	TODO: check
+CVE-2026-84109 (A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. A ...)
+	TODO: check
+CVE-2026-84061 (A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3. ...)
+	TODO: check
+CVE-2026-84059 (A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. T ...)
+	TODO: check
+CVE-2026-83619 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83618 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83617 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83616 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83615 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83614 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83613 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83612 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83611 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83610 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83609 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83608 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83607 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83606 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83605 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
+	TODO: check
+CVE-2026-83595 (AVideo contains a cross-site request forgery vulnerability in plugin/A ...)
+	TODO: check
+CVE-2026-83557 (DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator appli ...)
+	TODO: check
+CVE-2026-83551 (Cleartext storage of sensitive information in the @step and @remote de ...)
+	TODO: check
+CVE-2026-82927 (Untrusted pointer dereference vulnerability in Samsung Open Source mTo ...)
+	TODO: check
+CVE-2026-82926 (NULL pointer dereference vulnerability in Samsung Open Source mTower a ...)
+	TODO: check
+CVE-2026-80047 (A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and < ...)
+	TODO: check
+CVE-2026-7877 (The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stor ...)
+	TODO: check
+CVE-2026-79687 (Dell PowerStore SDNAS contains a Missing Authentication for Critical F ...)
+	TODO: check
+CVE-2026-79686 (Dell PowerStore contains a Protection Mechanism Failure vulnerability. ...)
+	TODO: check
+CVE-2026-79685 (Dell PowerStore contains an Argument Injection vulnerability. An authe ...)
+	TODO: check
+CVE-2026-79684 (Dell PowerStore contains a Protection Mechanism Failure vulnerability. ...)
+	TODO: check
+CVE-2026-79683 (Dell PowerStore contains a Protection Mechanism Failure vulnerability. ...)
+	TODO: check
+CVE-2026-79682 (Dell PowerStore contains a Command Injection vulnerability. An authent ...)
+	TODO: check
+CVE-2026-78363 (The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcod ...)
+	TODO: check
+CVE-2026-78012 (An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow  ...)
+	TODO: check
+CVE-2026-77194 (The Simple Membership plugin for WordPress is vulnerable to Authentica ...)
+	TODO: check
+CVE-2026-76111 (Dell PowerStore contains an Incorrect Authorization vulnerability. An  ...)
+	TODO: check
+CVE-2026-75538 (An attacker that connects to an open Erlang TCP port that uses the ine ...)
+	TODO: check
+CVE-2026-74994 (The mod_auth module in OTP's inets httpd server, when configured with  ...)
+	TODO: check
+CVE-2026-74916 (The WP Fastest Cache WordPress plugin before 1.5.1 does not include a  ...)
+	TODO: check
+CVE-2026-74835 (The inets application HTTP server httpd fails to enforce a configured  ...)
+	TODO: check
+CVE-2026-73812 (httpd function check_header/3 rejects duplicate Content-Length (per CV ...)
+	TODO: check
+CVE-2026-73276 (Gracefulness code ignored cases that should be rejected, resulting in  ...)
+	TODO: check
+CVE-2026-73270 (Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inet ...)
+	TODO: check
+CVE-2026-71562 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
+	TODO: check
+CVE-2026-71380 (Missing Release of Resource after Effective Lifetime vulnerability in  ...)
+	TODO: check
+CVE-2026-70409 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
+	TODO: check
+CVE-2026-70405 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
+	TODO: check
+CVE-2026-70399 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
+	TODO: check
+CVE-2026-69664 (Missing Release of Resource after Effective Lifetime vulnerability in  ...)
+	TODO: check
+CVE-2026-66835 (Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remo ...)
+	TODO: check
+CVE-2026-66357 (httpd has never implemented obs-fold (RFC 2616 \xa72.2 / RFC 7230 \xa7 ...)
+	TODO: check
+CVE-2026-61779 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61778 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61777 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61776 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61775 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61774 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61773 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61772 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61771 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61770 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61769 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61768 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61767 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61766 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61765 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61764 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61763 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61762 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61761 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61760 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61759 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61758 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61757 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61756 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61755 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61754 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61753 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61752 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61751 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-61750 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)
+	TODO: check
+CVE-2026-5480
+	REJECTED
+CVE-2026-59696 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
+	TODO: check
+CVE-2026-59681 (A OS command injection vulnerability in yast2-auth-client allows an at ...)
+	TODO: check
+CVE-2026-59680 (An OS command injection vulnerability was found in yast2-users. When d ...)
+	TODO: check
+CVE-2026-58575 (Dell PowerStore contains an Authentication Bypass by Spoofing vulnerab ...)
+	TODO: check
+CVE-2026-58572 (Dell PowerStore contains a Code Injection vulnerability. An authentica ...)
+	TODO: check
+CVE-2026-58571 (Dell PowerStore contains an OS Command Injection vulnerability. An aut ...)
+	TODO: check
+CVE-2026-58569 (Dell PowerStore contains an Inclusion of Functionality from Untrusted  ...)
+	TODO: check
+CVE-2026-58567 (Dell PowerStore contains an OS Command Injection vulnerability. An aut ...)
+	TODO: check
+CVE-2026-58566 (Dell PowerStore, an Incorrect Authorization vulnerability. A low privi ...)
+	TODO: check
+CVE-2026-55951 (The Erlang/OTP httpc HTTP client does not enforce a limit on the total ...)
+	TODO: check
+CVE-2026-53682 (An unauthenticated client can query the Security Domain hosts inventor ...)
+	TODO: check
+CVE-2026-52295 (Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an atta ...)
+	TODO: check
+CVE-2026-52132 (llama.cpp through commit 97f06e9, when started with the --reranking fl ...)
+	TODO: check
+CVE-2026-52131 (llama.cpp b5693 and before has a Reachable Assertion via the gguf_read ...)
+	TODO: check
+CVE-2026-52130 (llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in  ...)
+	TODO: check
+CVE-2026-52111 (An issue in fast-note-sync-service <=2.13.7 allows a remote attacker t ...)
+	TODO: check
+CVE-2026-52023 (An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...)
+	TODO: check
+CVE-2026-52022 (An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...)
+	TODO: check
+CVE-2026-51974 (An eval() injection vulnerability in the get_list function in modules/ ...)
+	TODO: check
+CVE-2026-51956 (A Broken Object Level Authorization vulnerability exists in Grashjs At ...)
+	TODO: check
+CVE-2026-51934 (Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co ...)
+	TODO: check
+CVE-2026-51788 (An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause ...)
+	TODO: check
+CVE-2026-51770 (Incorrect access control in the sendToMasterQosConfig function of TOTO ...)
+	TODO: check
+CVE-2026-51769 (Incorrect access control in the remoteCloudUpdateCheck function of TOT ...)
+	TODO: check
+CVE-2026-51768 (Incorrect access control in the setElinkQosConfig function of TOTOLINK ...)
+	TODO: check
+CVE-2026-51767 (Incorrect access control in the recvClearPairCfg function of TOTOLINK  ...)
+	TODO: check
+CVE-2026-51766 (Incorrect access control in the setDevReboot function of TOTOLINK T6 4 ...)
+	TODO: check
+CVE-2026-51765 (Incorrect access control in the recvIndirectMeshInfo function of TOTOL ...)
+	TODO: check
+CVE-2026-51764 (Incorrect access control in the recvSlaveCloudCheckStatus function of  ...)
+	TODO: check
+CVE-2026-51763 (Incorrect access control in the freeStaClient function of TOTOLINK T6  ...)
+	TODO: check
+CVE-2026-51762 (Incorrect access control in the meshInfoKick function of TOTOLINK T6 4 ...)
+	TODO: check
+CVE-2026-51761 (Incorrect access control in the updateLanIp function of TOTOLINK T6 4. ...)
+	TODO: check
+CVE-2026-51760 (Incorrect access control in the informSyncUpgfw function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51757 (Incorrect access control in the meshSlaveUpdate function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51756 (Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51754 (Incorrect access control in the updateSlaveIpList function of TOTOLINK ...)
+	TODO: check
+CVE-2026-51752 (Incorrect access control in the staticInfoSend function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51751 (Incorrect access control in the delSlaveDevice function of TOTOLINK T6 ...)
+	TODO: check
+CVE-2026-51750 (Incorrect access control in the updatePriChannel function of TOTOLINK  ...)
+	TODO: check
+CVE-2026-51748 (Incorrect access control in the sendStaticInfoToMaster function of TOT ...)
+	TODO: check
+CVE-2026-51747 (Incorrect access control in the keepAlive function of TOTOLINK T6 4.1. ...)
+	TODO: check
+CVE-2026-51745 (Incorrect access control in the updatePriStaList function of TOTOLINK  ...)
+	TODO: check
+CVE-2026-51744 (Incorrect access control in the recv_mesh_info_sync function of TOTOLI ...)
+	TODO: check
+CVE-2026-51743 (Incorrect access control in the guest_wifi_sync function of TOTOLINK T ...)
+	TODO: check
+CVE-2026-51742 (Incorrect access control in the discoverWan function of TOTOLINK T6 4. ...)
+	TODO: check
+CVE-2026-51741 (Incorrect access control in the clearDiagnosisLog function of TOTOLINK ...)
+	TODO: check
+CVE-2026-4813 (A vulnerability in the Lutece Core XSL export management module up to  ...)
+	TODO: check
+CVE-2026-49329 (A flaw was found in openshift/oauth-server. The OAuth login and error  ...)
+	TODO: check
+CVE-2026-25706 (Improper neutralization of special elements used in an OS command in y ...)
+	TODO: check
+CVE-2026-19914 (The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cr ...)
+	TODO: check
+CVE-2026-19593 (OpenAI Codex Desktop for Windows and macOS automatically inspected Git ...)
+	TODO: check
+CVE-2026-19592 (OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for W ...)
+	TODO: check
+CVE-2026-19591 (OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for W ...)
+	TODO: check
+CVE-2026-19590 (OpenAI Codex Desktop for Windows and macOS could execute attacker-cont ...)
+	TODO: check
+CVE-2026-19513 (The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File ...)
+	TODO: check
+CVE-2026-19472 (A denial-of-service security issue exists within ArmorStart\xae LT. Th ...)
+	TODO: check
+CVE-2026-19471 (Multiple stored cross-site scripting security issues exist within Armo ...)
+	TODO: check
+CVE-2026-18931 (Use of Hard-coded Credentials vulnerability in TMT Machine Industry an ...)
+	TODO: check
+CVE-2026-18808 (Improper Control of Generation of Code ('Code Injection') vulnerabilit ...)
+	TODO: check
+CVE-2026-18780 (Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industr ...)
+	TODO: check
+CVE-2026-18771 (Missing authentication for critical function vulnerability in TMT Mach ...)
+	TODO: check
+CVE-2026-18765 (Improper neutralization of special elements used in an SQL command ('S ...)
+	TODO: check
+CVE-2026-18630 (Improper neutralization of special elements used in an SQL command ('S ...)
+	TODO: check
+CVE-2026-18550 (The Nokri - Job Board WordPress Theme for WordPress is vulnerable to P ...)
+	TODO: check
+CVE-2026-18210 (Improper neutralization of special elements used in an SQL command ('S ...)
+	TODO: check
+CVE-2026-16788 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
+	TODO: check
+CVE-2026-16786 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
+	TODO: check
+CVE-2026-16675 (A privilege escalation security issue exists within FactoryTalk\xae Ac ...)
+	TODO: check
+CVE-2026-15101 (The WPBakery Page Builder plugin for WordPress is vulnerable to Stored ...)
+	TODO: check
+CVE-2026-13611 (The KiviCare WordPress plugin before 4.5.5 does not perform authorizat ...)
+	TODO: check
+CVE-2026-13348 (CWE-307: Improper Restriction of Excessive Authentication Attempts vul ...)
+	TODO: check
+CVE-2026-13337 (CWE-564: SQL Injection: Hibernate vulnerability exists that could allo ...)
+	TODO: check
+CVE-2026-13336 (CWE-78: Improper Neutralization of Special Elements used in an OS Comm ...)
+	TODO: check
+CVE-2026-12663 (A security issue exists within ControlFLASH\u2122, where the installer ...)
+	TODO: check
+CVE-2026-12661 (A denial-of-service security issue exists within FactoryTalk\xae Histo ...)
+	TODO: check
+CVE-2026-11873 (An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/res ...)
+	TODO: check
+CVE-2026-10420 (Untrusted pointer dereference vulnerability in Samsung Open Source mTo ...)
+	TODO: check
+CVE-2026-10195 (The FS-Poster plugin for WordPress is vulnerable to Remote Code Execut ...)
+	TODO: check
+CVE-2025-15613 (Kyverno before v1.13.4 is vulnerable to server-side request forgery (S ...)
+	TODO: check
+CVE-2025-12768 (A security issue exists within FactoryTalk\xae Historian Machine Editi ...)
+	TODO: check
+CVE-2024-7953 (A vulnerability exists in the affected products that allows a threat a ...)
+	TODO: check
+CVE-2024-7952 (A data exposure vulnerability exists in the affected product. There ar ...)
+	TODO: check
+CVE-2024-14047 (A local vulnerability in the Winlogbeat Windows installer caused runti ...)
+	TODO: check
+CVE-2024-10085 (CWE-770: Allocation of Resources Without Limits or Throttlingvulnerabi ...)
+	TODO: check
+CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites ...)
+	TODO: check
+CVE-2026-84145 (Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firef ...)
 	- firefox <unfixed>
 	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84145
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84145
-CVE-2026-84144
+CVE-2026-84144 (Internally found bugs present in Firefox 154 and Firefox ESR 153.1. So ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84144
-CVE-2026-84143
+CVE-2026-84143 (Internally found bugs present in Firefox 154, Firefox ESR 153.1 and Fi ...)
 	- firefox <unfixed>
 	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84143
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84143
-CVE-2026-84142
+CVE-2026-84142 (Internally found bugs present in Firefox 154. Some of these bugs showe ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84142
-CVE-2026-84141
+CVE-2026-84141 (Integer overflow in the Graphics: ImageLib component. This vulnerabili ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84141
-CVE-2026-84140
+CVE-2026-84140 (Site isolation issue in the DOM: Navigation component. This vulnerabil ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84140
-CVE-2026-84139
+CVE-2026-84139 (Clickjacking issue in the DOM: Events component. This vulnerability wa ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84139
-CVE-2026-84138
+CVE-2026-84138 (Denial-of-service in the PDF Viewer component. This vulnerability was  ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84138
-CVE-2026-84137
+CVE-2026-84137 (Spoofing issue in the DOM: Core & HTML component. This vulnerability w ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84137
-CVE-2026-84136
+CVE-2026-84136 (Other issue in the DOM: Navigation component. This vulnerability was f ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84136
-CVE-2026-84135
+CVE-2026-84135 (Other issue in Firefox Focus for Android. This vulnerability was fixed ...)
 	- firefox <not-affected> (Only affects Firefox on Android)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84135
-CVE-2026-84134
+CVE-2026-84134 (Other issue in the Profile Backup component. This vulnerability was fi ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84134
-CVE-2026-84133
+CVE-2026-84133 (Site isolation issue in the DOM: Push Subscriptions component. This vu ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84133
-CVE-2026-84132
+CVE-2026-84132 (Information disclosure in the Networking: HTTP component. This vulnera ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84132
-CVE-2026-84131
+CVE-2026-84131 (Privilege escalation due to invalid pointer in the Graphics component. ...)
 	- firefox <unfixed>
 	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84131
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84131
-CVE-2026-84130
+CVE-2026-84130 (Information disclosure in the Graphics: WebGPU component. This vulnera ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84130
-CVE-2026-84129
+CVE-2026-84129 (Site isolation issue in the DOM: Navigation component. This vulnerabil ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84129
-CVE-2026-84128
+CVE-2026-84128 (Privilege escalation in the WebDriver BiDi component. This vulnerabili ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84128
-CVE-2026-84127
+CVE-2026-84127 (Information disclosure in the WebExtensions component in Firefox for A ...)
 	- firefox <not-affected> (Only affects Firefox on Android)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84127
-CVE-2026-84126
+CVE-2026-84126 (Incorrect boundary conditions in the Layout: Grid component. This vuln ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84126
-CVE-2026-84125
+CVE-2026-84125 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84125
-CVE-2026-84124
+CVE-2026-84124 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
 	- firefox <unfixed>
 	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84124
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84124
-CVE-2026-84123
+CVE-2026-84123 (Privilege escalation due to use-after-free in the Graphics: WebGPU com ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84123
-CVE-2026-84122
+CVE-2026-84122 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
 	- firefox <unfixed>
 	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84122
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84122
-CVE-2026-84121
+CVE-2026-84121 (Sandbox escape due to use-after-free in the DOM: Security component. T ...)
 	- firefox <unfixed>
 	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84121
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84121
-CVE-2026-84120
+CVE-2026-84120 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
 	- firefox <unfixed>
 	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84120
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84120
-CVE-2026-84119
+CVE-2026-84119 (Sandbox escape due to use-after-free in the DOM: Navigation component. ...)
 	- firefox <unfixed>
 	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84119
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84119
-CVE-2026-84118
+CVE-2026-84118 (Use-after-free in the JavaScript: GC component. This vulnerability was ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84118
-CVE-2026-84117
+CVE-2026-84117 (Privilege escalation in Firefox for Android. This vulnerability was fi ...)
 	- firefox <not-affected> (Only affects Firefox on Android)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84117
 CVE-2026-83772 (A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satell ...)
@@ -6842,19 +7268,26 @@ CVE-2026-78684 (vLLM before 0.27.0 fails to properly classify DeepStream as a GP
 	- vllm <itp> (bug #1095237)
 CVE-2026-78581 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
 	- kibana <itp> (bug #700337)
-CVE-2026-78576 (The Readabler plugin for WordPress is vulnerable to SQL Injection in a ...)
+CVE-2026-78576
+	REJECTED
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78572 (The Kalles Addons plugin for WordPress is vulnerable to PHP Object Inj ...)
+CVE-2026-78572
+	REJECTED
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78570 (The Total Donations plugin for WordPress is vulnerable to Privilege Es ...)
+CVE-2026-78570
+	REJECTED
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78568 (The Total Donations plugin for WordPress is vulnerable to SQL Injectio ...)
+CVE-2026-78568
+	REJECTED
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78566 (The Shuffle theme for WordPress is vulnerable to Local File Inclusion  ...)
+CVE-2026-78566
+	REJECTED
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78563 (The NotificationX Pro plugin for WordPress is vulnerable to Stored Cro ...)
+CVE-2026-78563
+	REJECTED
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local File Incl ...)
+CVE-2026-78562
+	REJECTED
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78468
 	REJECTED
@@ -7449,7 +7882,8 @@ CVE-2026-78551 (RansomLook contains multiple weaknesses in its authentication en
 	NOT-FOR-US: RansomLook
 CVE-2026-78478 (The Mane theme for WordPress is vulnerable to Local File Inclusion in  ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-78477 (The Jawn theme for WordPress is vulnerable to Privilege Escalation in  ...)
+CVE-2026-78477
+	REJECTED
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78470 (The WP Project Manager Pro plugin for WordPress is vulnerable to SQL I ...)
 	NOT-FOR-US: WordPress plugin
@@ -15811,7 +16245,7 @@ CVE-2026-28567 (Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28192 (Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor  ...)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-28191 (Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.)
+CVE-2026-28191 (Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allo ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24301 (Improper neutralization of special elements used in a command ('comman ...)
 	NOT-FOR-US: Microsoft
@@ -52238,26 +52672,32 @@ CVE-2026-49998 (Centrifugo is an open-source scalable real-time messaging server
 CVE-2026-47751 (Claude Code Action is a general-purpose GitHub action that runs Claude ...)
 	NOT-FOR-US: Claude
 CVE-2026-47089 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. L ...)
+	{DLA-4766-1}
 	- cyrus-imapd 3.12.3-1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47088 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
+	{DLA-4766-1}
 	- cyrus-imapd 3.12.3-1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47087 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. U ...)
+	{DLA-4766-1}
 	- cyrus-imapd 3.12.3-1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47086 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. G ...)
+	{DLA-4766-1}
 	- cyrus-imapd 3.12.3-1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47085 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. U ...)
+	{DLA-4766-1}
 	- cyrus-imapd 3.12.3-1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47084 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
+	{DLA-4766-1}
 	- cyrus-imapd 3.12.3-1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
@@ -52266,10 +52706,12 @@ CVE-2026-47083 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47082 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
+	{DLA-4766-1}
 	- cyrus-imapd 3.12.3-1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
 CVE-2026-47081 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
+	{DLA-4766-1}
 	- cyrus-imapd 3.12.3-1
 	[trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
 	NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
@@ -128835,7 +129277,7 @@ CVE-2026-24372 (Authentication Bypass by Spoofing vulnerability in WP Swings Sub
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24370 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-24369 (Missing Authorization vulnerability in Theme-one The Grid the-grid all ...)
+CVE-2026-24369 (Missing Authorization vulnerability in ThemeOne The Grid allows Exploi ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24364 (Missing Authorization vulnerability in weDevs WP User Frontend wp-user ...)
 	NOT-FOR-US: WordPress plugin or theme
@@ -156743,7 +157185,7 @@ CVE-2026-24374 (Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Reg
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24371 (Missing Authorization vulnerability in bookingalgorithms BA Book Every ...)
 	NOT-FOR-US: WordPress plugin or theme
-CVE-2026-24368 (Missing Authorization vulnerability in Theme-one The Grid the-grid all ...)
+CVE-2026-24368 (Missing Authorization vulnerability in ThemeOne The Grid allows Exploi ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24367 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	NOT-FOR-US: WordPress plugin or theme



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0e3887827512e62dfacc543052ede268e782b31

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0e3887827512e62dfacc543052ede268e782b31
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/991e0fb1/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list