[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 2 08:13:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d85f714e by security tracker role at 2026-09-02T07:13:20+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,18 +1,472 @@
+CVE-2026-9055 (The Booking for Appointments and Events Calendar \u2013 Amelia (Premiu ...)
+	TODO: check
+CVE-2026-84715 (FeatherPanel versions before 1.3.7.10 fail to validate permissions in  ...)
+	TODO: check
+CVE-2026-84702 (facefusion through 3.6.1 fails to normalize job identifiers in get_job ...)
+	TODO: check
+CVE-2026-84701 (NocoBase fails to sanitize rich text field values in the read renderer ...)
+	TODO: check
+CVE-2026-84700 (PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server ...)
+	TODO: check
+CVE-2026-84699 (Team Password Manager before 14.184.308 fails to enforce authenticatio ...)
+	TODO: check
+CVE-2026-84698 (PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_ ...)
+	TODO: check
+CVE-2026-84697 (Mailpit's IsInternalIP deny list function fails to block the Azure Wir ...)
+	TODO: check
+CVE-2026-84696 (Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose ...)
+	TODO: check
+CVE-2026-84695 (BookStack before 26.05.4 contains a stored cross-site scripting vulner ...)
+	TODO: check
+CVE-2026-84694 (Coolify before 4.2.0 fails to properly escape environment variable key ...)
+	TODO: check
+CVE-2026-84642 (The values of the mail.allowed_attachment_hostnames advanced config se ...)
+	TODO: check
+CVE-2026-84641 (A malicious IMAP server can trigger use-after-free and heap-memory dis ...)
+	TODO: check
+CVE-2026-84640 (A maliciously constructed mail header could lead to a one byte read pa ...)
+	TODO: check
+CVE-2026-84639 (Triggering an error condition in certain MIME bodies would cause unini ...)
+	TODO: check
+CVE-2026-84637 (Malicious calendar invitations could use file URI attachments to launc ...)
+	TODO: check
+CVE-2026-84485 (APITable through 1.13.0-beta.1 exposes the internal organization loadO ...)
+	TODO: check
+CVE-2026-84484 (ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerabil ...)
+	TODO: check
+CVE-2026-84483 (WWBN AVideo through commit 9c39d8c8 contains an incomplete authenticat ...)
+	TODO: check
+CVE-2026-84482 (WWBN AVideo through commit 9c39d8c8 contains a cross-site request forg ...)
+	TODO: check
+CVE-2026-84481 (WWBN AVideo through 30.0 contains an information disclosure vulnerabil ...)
+	TODO: check
+CVE-2026-84480 (WWBN AVideo fails to validate password recovery token expiration in us ...)
+	TODO: check
+CVE-2026-84479 (WWBN AVideo (current e01e41ecc and earlier) makes three login-time sec ...)
+	TODO: check
+CVE-2026-84478 (WWBN AVideo contains a path traversal vulnerability in the API get_api ...)
+	TODO: check
+CVE-2026-84477 (AVideo Live_schedule::setTitle() and setDescription() store POST input ...)
+	TODO: check
+CVE-2026-84476 (WWBN AVideo fails to validate trusted proxies before accepting X-Real- ...)
+	TODO: check
+CVE-2026-84442 (A vulnerability was identified in MapQuest Get Directions App 10.16.1  ...)
+	TODO: check
+CVE-2026-84441 (A security vulnerability has been detected in Piwigo up to 16.3.0. Aff ...)
+	TODO: check
+CVE-2026-84438 (A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affec ...)
+	TODO: check
+CVE-2026-84437 (A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted el ...)
+	TODO: check
+CVE-2026-84431 (A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Andr ...)
+	TODO: check
+CVE-2026-84430 (A security vulnerability has been detected in gouguoa up to 5.10.0/6.0 ...)
+	TODO: check
+CVE-2026-84427 (A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affec ...)
+	TODO: check
+CVE-2026-84425 (A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impac ...)
+	TODO: check
+CVE-2026-84423 (A vulnerability has been found in Casdoor up to 4.0.0. This affects an ...)
+	TODO: check
+CVE-2026-84375 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15. ...)
+	TODO: check
+CVE-2026-84374 (Laravel Excel provides supercharged Excel exports and imports in Larav ...)
+	TODO: check
+CVE-2026-84372 (Predis is a flexible and feature-complete Redis and Valkey client for  ...)
+	TODO: check
+CVE-2026-84371 (ApostropheCMS is an open-source Node.js content management system, and ...)
+	TODO: check
+CVE-2026-84370 (SVGO, short for SVG Optimizer, is a Node.js library and command-line a ...)
+	TODO: check
+CVE-2026-84369 (SVGO, short for SVG Optimizer, is a Node.js library and command-line a ...)
+	TODO: check
+CVE-2026-84368 (joi is a schema description language and data validator for JavaScript ...)
+	TODO: check
+CVE-2026-84367 (joi is a schema description language and data validator for JavaScript ...)
+	TODO: check
+CVE-2026-84366 (Scrapy is a high-level web crawling and scraping framework for Python. ...)
+	TODO: check
+CVE-2026-84365 (Hono is a Web application framework that provides support for any Java ...)
+	TODO: check
+CVE-2026-84364 (Hono is a Web application framework that provides support for any Java ...)
+	TODO: check
+CVE-2026-84363 (Hono is a Web application framework that provides support for any Java ...)
+	TODO: check
+CVE-2026-84361 (Composer is a dependency Manager for the PHP language. From 1.0 until  ...)
+	TODO: check
+CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
+	TODO: check
+CVE-2026-84308 (phpseclib is a PHP secure communications library. Prior to 3.0.57 and  ...)
+	TODO: check
+CVE-2026-84307 (Filament is a collection of full-stack components for accelerated Lara ...)
+	TODO: check
+CVE-2026-84306 (Filament is a collection of full-stack components for accelerated Lara ...)
+	TODO: check
+CVE-2026-84289 (A vulnerability was found in NousResearch hermes-agent up to 0.18.2. T ...)
+	TODO: check
+CVE-2026-84288 (A vulnerability has been found in NousResearch hermes-agent up to 0.18 ...)
+	TODO: check
+CVE-2026-84287 (A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by ...)
+	TODO: check
+CVE-2026-84208 (AVideo through version 29.0 contains an unauthenticated SQL injection  ...)
+	TODO: check
+CVE-2026-83549 (Post-authentication Improper Neutralization of Special Elements used i ...)
+	TODO: check
+CVE-2026-83548 (A Pre-authentication SSRF vulnerability exists in the SMA1000 Applianc ...)
+	TODO: check
+CVE-2026-82968 (A flaw was found in the first-broker-login flow of the Keycloak identi ...)
+	TODO: check
+CVE-2026-82883 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+	TODO: check
+CVE-2026-82183 (The OAuth Single Sign On  WordPress plugin before 7.0.1 does not verif ...)
+	TODO: check
+CVE-2026-82182 (The WPvivid \u2014 Backup, Migration & Staging WordPress plugin before ...)
+	TODO: check
+CVE-2026-81846 (An authorization bypass in the runZero Platform MCP service has been r ...)
+	TODO: check
+CVE-2026-81807 (The Simple Ajax Chat  WordPress plugin before 20260827 does not escape ...)
+	TODO: check
+CVE-2026-81737 (The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or ...)
+	TODO: check
+CVE-2026-81583 (The  My Login WordPress plugin before 7.2.0 does not enforce the netwo ...)
+	TODO: check
+CVE-2026-81432 (The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does n ...)
+	TODO: check
+CVE-2026-81428 (The WC Vendors  WordPress plugin before 2.7.2.1 does not verify owners ...)
+	TODO: check
+CVE-2026-81427 (The WC Vendors  WordPress plugin before 2.7.2.1 does not verify that t ...)
+	TODO: check
+CVE-2026-81426 (The WC Vendors  WordPress plugin before 2.7.2.1 does not have CSRF pro ...)
+	TODO: check
+CVE-2026-81199 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
+	TODO: check
+CVE-2026-81198 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
+	TODO: check
+CVE-2026-81197 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
+	TODO: check
+CVE-2026-81196 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
+	TODO: check
+CVE-2026-81195 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
+	TODO: check
+CVE-2026-81194 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
+	TODO: check
+CVE-2026-80467 (The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 d ...)
+	TODO: check
+CVE-2026-79621 (The CatalogX  WordPress plugin before 6.1.3 does not sanitise or escap ...)
+	TODO: check
+CVE-2026-78657 (The SigmaForms Pro \u2013 AI Generated Forms plugin for WordPress is v ...)
+	TODO: check
+CVE-2026-78608 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
+	TODO: check
+CVE-2026-78607 (Missing Authorization (CWE-862) in the Elasticsearch custom inference  ...)
+	TODO: check
+CVE-2026-78606 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized d ...)
+	TODO: check
+CVE-2026-78605 (Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling' ...)
+	TODO: check
+CVE-2026-78603 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
+	TODO: check
+CVE-2026-78597 (Missing Authorization (CWE-862) in the Kibana Entity Store feature can ...)
+	TODO: check
+CVE-2026-78592 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
+	TODO: check
+CVE-2026-78151 (The FormLayer WordPress plugin before 1.0.9 does not perform any autho ...)
+	TODO: check
+CVE-2026-77792 (The RegistrationMagic  WordPress plugin before 6.0.9.9 does not escape ...)
+	TODO: check
+CVE-2026-77788 (The Rank Math SEO  WordPress plugin before 1.0.277 does not verify tha ...)
+	TODO: check
+CVE-2026-77787 (The Rank Math SEO  WordPress plugin before 1.0.277 does not perform a  ...)
+	TODO: check
+CVE-2026-77785 (The Rank Math SEO  WordPress plugin before 1.0.277 does not verify tha ...)
+	TODO: check
+CVE-2026-77784 (The Rank Math SEO  WordPress plugin before 1.0.277 does not verify tha ...)
+	TODO: check
+CVE-2026-77783 (The Rank Math SEO  WordPress plugin before 1.0.277 does not verify tha ...)
+	TODO: check
+CVE-2026-77782 (The Rank Math SEO  WordPress plugin before 1.0.277.1 does not check wh ...)
+	TODO: check
+CVE-2026-77764 (The GamiPress  WordPress plugin before 7.9.9.6 does not properly restr ...)
+	TODO: check
+CVE-2026-77223
+	REJECTED
+CVE-2026-77222
+	REJECTED
+CVE-2026-77221
+	REJECTED
+CVE-2026-76851 (A Server-Side Request Forgery (SSRF) vulnerability was identified in G ...)
+	TODO: check
+CVE-2026-76658 (A vulnerability has been identified in the SSH daemon of HPE Networkin ...)
+	TODO: check
+CVE-2026-76657 (Vulnerabilities have been identified in the API of HPE Networking Fabr ...)
+	TODO: check
+CVE-2026-75604 (Next.js is a React framework for building full-stack web applications. ...)
+	TODO: check
+CVE-2026-74927 (The MultiVendorX  WordPress plugin before 5.0.15 does not have proper  ...)
+	TODO: check
+CVE-2026-73783 (Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Suc ...)
+	TODO: check
+CVE-2026-73782 (A format string vulnerability exists in the command line interface of  ...)
+	TODO: check
+CVE-2026-73781 (A vulnerability in the web-based management interface of AOS-CX could  ...)
+	TODO: check
+CVE-2026-73780 (A vulnerability in the web-based management interface of AOS-CX switch ...)
+	TODO: check
+CVE-2026-73779 (Vulnerabilities have been identified in the operating system of AOS-CX ...)
+	TODO: check
+CVE-2026-73778 (A vulnerability exists in the Credential Manager component that may al ...)
+	TODO: check
+CVE-2026-73777 (Vulnerabilities have been identified in the API endpoint of AOS-CX swi ...)
+	TODO: check
+CVE-2026-73776 (A signature verification bypass vulnerability exists in the command li ...)
+	TODO: check
+CVE-2026-73775 (Vulnerabilities in the API endpoint of AOS-CX could allow a remote att ...)
+	TODO: check
+CVE-2026-73774 (A buffer overflow vulnerability exists in the underlying operating sys ...)
+	TODO: check
+CVE-2026-73773 (An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ...)
+	TODO: check
+CVE-2026-73772 (Buffer overflow vulnerabilities exist in an underlying service of AOS- ...)
+	TODO: check
+CVE-2026-73771 (An authentication vulnerability exists in the AOS-CX management interf ...)
+	TODO: check
+CVE-2026-73770 (An authenticated arbitrary file write vulnerability exists in AOS-CX.  ...)
+	TODO: check
+CVE-2026-73768 (A vulnerability exists in the command line interface of AOS-CX that ma ...)
+	TODO: check
+CVE-2026-73767 (Authenticated command injection vulnerabilities exist in the command l ...)
+	TODO: check
+CVE-2026-73766 (Command injection vulnerabilities in the API endpoint of AOS-CX could  ...)
+	TODO: check
+CVE-2026-73765 (Authenticated path traversal vulnerabilities exist in API endpoints of ...)
+	TODO: check
+CVE-2026-73764 (Vulnerabilities have been identified in the operating system of AOS-CX ...)
+	TODO: check
+CVE-2026-73763 (A vulnerability exists in a management component that could allow an u ...)
+	TODO: check
+CVE-2026-73762 (A vulnerability has been identified in the API endpoint of AOS-CX that ...)
+	TODO: check
+CVE-2026-73761 (An out-of-bounds read vulnerability exists in the underlying operating ...)
+	TODO: check
+CVE-2026-73760 (An authenticated Path Traversal vulnerability exists in AOS-CX. Succes ...)
+	TODO: check
+CVE-2026-73759 (Vulnerabilities in AOS-CX could allow an unauthenticated remote malici ...)
+	TODO: check
+CVE-2026-73758 (A privilege escalation vulnerability exists in the API endpoint of AOS ...)
+	TODO: check
+CVE-2026-73757 (A vulnerability in the web-based management interface of AOS-CX could  ...)
+	TODO: check
+CVE-2026-73756 (A vulnerability in an API endpoint of AOS-CX could allow a remote unau ...)
+	TODO: check
+CVE-2026-73755 (A privilege escalation vulnerability exists in the API endpoint of AOS ...)
+	TODO: check
+CVE-2026-73754 (Denial-of-service vulnerabilities exist in the command line interface  ...)
+	TODO: check
+CVE-2026-73753 (Exploitation through affected command-line operations could allow an a ...)
+	TODO: check
+CVE-2026-73752 (An unauthenticated arbitrary file write vulnerability exists in an API ...)
+	TODO: check
+CVE-2026-73751 (An authenticated user with low-privileged access could submit crafted  ...)
+	TODO: check
+CVE-2026-73750 (Vulnerabilities exist in the authentication module that may improperly ...)
+	TODO: check
+CVE-2026-73749 (Multiple vulnerabilities exist in a daemon of AOS-CX that may allow fo ...)
+	TODO: check
+CVE-2026-73748 (A vulnerability in the affected interface of HPE Networking Fabric Com ...)
+	TODO: check
+CVE-2026-73747 (A local privilege-escalation vulnerability has been discovered in HPE  ...)
+	TODO: check
+CVE-2026-73746 (A denial-of-service vulnerability exists in the API of HPE Networking  ...)
+	TODO: check
+CVE-2026-73745 (A vulnerability in the API endpoint of HPE Networking Fabric Composer  ...)
+	TODO: check
+CVE-2026-73744 (A denial-of-service vulnerability exists in the web-based management i ...)
+	TODO: check
+CVE-2026-73743 (A vulnerability in the web-based management interface of HPE Networkin ...)
+	TODO: check
+CVE-2026-73742 (A vulnerability in an API endpoint of HPE Networking Fabric Composer c ...)
+	TODO: check
+CVE-2026-73741 (A vulnerability in the API of HPE Networking Fabric Composer could all ...)
+	TODO: check
+CVE-2026-73740 (A local privilege escalation vulnerability in HPE Networking Fabric Co ...)
+	TODO: check
+CVE-2026-73739 (A vulnerability exists in the API of HPE Networking Fabric Composer th ...)
+	TODO: check
+CVE-2026-73738 (A vulnerability in the underlying operating system of HPE Networking F ...)
+	TODO: check
+CVE-2026-73737 (An unauthenticated path traversal vulnerability exists in the API endp ...)
+	TODO: check
+CVE-2026-73736 (A vulnerability in the web-based management interface of HPE Networkin ...)
+	TODO: check
+CVE-2026-73735 (Vulnerabilities in the API of HPE Networking Fabric Composer could all ...)
+	TODO: check
+CVE-2026-73734 (A vulnerability in the web-based management interface of HPE Networkin ...)
+	TODO: check
+CVE-2026-73733 (Authentication bypasses in the API of HPE Networking Fabric Composer c ...)
+	TODO: check
+CVE-2026-73732 (A vulnerability in the underlying operating system of HPE Networking F ...)
+	TODO: check
+CVE-2026-73731 (A vulnerability in the web-based management interface of HPE Networkin ...)
+	TODO: check
+CVE-2026-73730 (A privilege escalation vulnerability exists in the API of HPE Networki ...)
+	TODO: check
+CVE-2026-73729 (A vulnerability in the underlying operating system of HPE Networking F ...)
+	TODO: check
+CVE-2026-73728 (Denial-of-service vulnerabilities exist in the API of HPE Networking F ...)
+	TODO: check
+CVE-2026-73727 (Vulnerabilities in the API of HPE Networking Fabric Composer could all ...)
+	TODO: check
+CVE-2026-73726 (A vulnerability has been identified in the underlying operating system ...)
+	TODO: check
+CVE-2026-73725 (A local privilege-escalation vulnerability has been discovered in HPE  ...)
+	TODO: check
+CVE-2026-73724 (Privilege escalation vulnerabilities exist in the API of HPE Networkin ...)
+	TODO: check
+CVE-2026-73723 (A privilege escalation vulnerability exists in the web-based managemen ...)
+	TODO: check
+CVE-2026-73722 (Command injection vulnerabilities in the web-based management interfac ...)
+	TODO: check
+CVE-2026-73721 (Vulnerabilities in the API of HPE Networking Fabric Composer could all ...)
+	TODO: check
+CVE-2026-73720 (Insecure file operations in the API of HPE Networking Fabric Composer  ...)
+	TODO: check
+CVE-2026-73719 (An arbitrary file write vulnerability exists in the API of HPE Network ...)
+	TODO: check
+CVE-2026-73718 (A vulnerability in the web-based management interface of HPE Networkin ...)
+	TODO: check
+CVE-2026-73717 (A command injection vulnerability exists in the web-based management i ...)
+	TODO: check
+CVE-2026-73716 (A remote code execution vulnerability exists in the underlying operati ...)
+	TODO: check
+CVE-2026-73715 (A vulnerability in the API of HPE Networking Fabric Composer could all ...)
+	TODO: check
+CVE-2026-73714 (A sensitive information disclosure vulnerability exists in the API of  ...)
+	TODO: check
+CVE-2026-73713 (Local privilege-escalation vulnerabilities have been discovered in HPE ...)
+	TODO: check
+CVE-2026-73712 (A vulnerability in the API of HPE Networking Fabric Composer could all ...)
+	TODO: check
+CVE-2026-73711 (A privilege escalation vulnerability exists in the API endpoint of HPE ...)
+	TODO: check
+CVE-2026-73710 (Vulnerabilities in an API endpoint of HPE Networking Fabric Composer c ...)
+	TODO: check
+CVE-2026-73709 (A vulnerability in the underlying operating system of HPE Networking F ...)
+	TODO: check
+CVE-2026-73708 (A business logic vulnerability exists in the API of HPE Networking Fab ...)
+	TODO: check
+CVE-2026-73707 (Privilege escalation vulnerabilities exist in the API of HPE Networkin ...)
+	TODO: check
+CVE-2026-73706 (A vulnerability in the API of HPE Networking Fabric Composer could all ...)
+	TODO: check
+CVE-2026-73705 (An arbitrary file write vulnerability in the API of HPE Networking Fab ...)
+	TODO: check
+CVE-2026-73704 (A command sanitization bypass exists in the API of HPE Networking Fabr ...)
+	TODO: check
+CVE-2026-73703 (A vulnerability in the web-based management interface of HPE Networkin ...)
+	TODO: check
+CVE-2026-73702 (A privilege escalation vulnerability exists in the API of HPE Networki ...)
+	TODO: check
+CVE-2026-73701 (An unauthenticated remote code execution vulnerability exists in the u ...)
+	TODO: check
+CVE-2026-73700 (A vulnerability in the web-based management interface of HPE Networkin ...)
+	TODO: check
+CVE-2026-73524 (Cypht before 2.12.2 contains a cross-site scripting vulnerability in t ...)
+	TODO: check
+CVE-2026-72682 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
+	TODO: check
+CVE-2026-72654 (Execution with Unnecessary Privileges (CWE-250) in the Kibana machine  ...)
+	TODO: check
+CVE-2026-72652 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
+	TODO: check
+CVE-2026-72649 (Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machi ...)
+	TODO: check
+CVE-2026-72644 (Uncaught Exception (CWE-248) in Kibana can lead to a denial of service ...)
+	TODO: check
+CVE-2026-72641 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized m ...)
+	TODO: check
+CVE-2026-72633 (Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead  ...)
+	TODO: check
+CVE-2026-72628 (Improper Handling of Highly Compressed Data (CWE-409) in Kibana can le ...)
+	TODO: check
+CVE-2026-71981 (Cypht before 2.12.2 contains a PHP object injection vulnerability that ...)
+	TODO: check
+CVE-2026-63435 (Mail is an internet library for Ruby designed to handle email generati ...)
+	TODO: check
+CVE-2026-63138 (Improper Neutralization of Special Elements in Data Query Logic (CWE-9 ...)
+	TODO: check
+CVE-2026-63137 (Incorrect Authorization (CWE-863) in Kibana can lead to privilege esca ...)
+	TODO: check
+CVE-2026-56143 (Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...)
+	TODO: check
+CVE-2026-45221 (Konga before 2.1.0 contains a privilege escalation vulnerability that  ...)
+	TODO: check
+CVE-2026-3851 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
+	TODO: check
+CVE-2026-3850 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
+	TODO: check
+CVE-2026-33465 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
+	TODO: check
+CVE-2026-19766 (An authentication bypass vulnerability exists in the underlying operat ...)
+	TODO: check
+CVE-2026-19754 (Baserow 2.3.3 contains a SQL injection vulnerability in the index() fo ...)
+	TODO: check
+CVE-2026-19723 (The Social Media Share Buttons & Social Sharing Icons WordPress plugin ...)
+	TODO: check
+CVE-2026-19719 (The Social Media Share Buttons & Social Sharing Icons WordPress plugin ...)
+	TODO: check
+CVE-2026-19704 (The Comments  WordPress plugin before 7.6.66 does not validate a value ...)
+	TODO: check
+CVE-2026-19453 (The JetBackup  WordPress plugin before 3.1.23.5 does not verify the ro ...)
+	TODO: check
+CVE-2026-19251 (The Ultimate Member  WordPress plugin before 2.13.0 does not check whe ...)
+	TODO: check
+CVE-2026-19118 (A time-of-check time-of-use race condition vulnerability was identifie ...)
+	TODO: check
+CVE-2026-19116 (The User Frontend  WordPress plugin before 4.3.11 does not prevent use ...)
+	TODO: check
+CVE-2026-18730 (A server-side request forgery (SSRF) vulnerability was identified in G ...)
+	TODO: check
+CVE-2026-16983 (The Gutentor  WordPress plugin before 4.0.6 does not apply the correct ...)
+	TODO: check
+CVE-2026-16966 (The Solace Extra WordPress plugin before 1.7.0 does not perform any au ...)
+	TODO: check
+CVE-2026-15232 (The MotoPress Appointment Booking WordPress plugin before 2.4.8 does n ...)
+	TODO: check
+CVE-2026-14982 (The WP File Download plugin for WordPress is vulnerable to arbitrary f ...)
+	TODO: check
+CVE-2026-14357 (The DevKit Pro plugin for WordPress is vulnerable to Missing Authoriza ...)
+	TODO: check
+CVE-2026-14215 (The Booking for Appointments and Events Calendar  WordPress plugin bef ...)
+	TODO: check
+CVE-2026-12865 (The Photo Gallery by 10Web  WordPress plugin before 1.8.44 does not es ...)
+	TODO: check
+CVE-2026-12526 (The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 d ...)
+	TODO: check
+CVE-2025-46418 (Westermo WeOS 5.x starting from 5.24 allows OS command injection via a ...)
+	TODO: check
+CVE-2025-15664 (The Ultimate Before After Image Slider & Gallery  WordPress plugin bef ...)
+	TODO: check
+CVE-2025-15663 (The Ultimate Before After Image Slider & Gallery  WordPress plugin bef ...)
+	TODO: check
+CVE-2024-35585 (Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP ad ...)
+	TODO: check
+CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentic ...)
+	TODO: check
 CVE-2026-13608
 	- curl 8.22.0~rc2-1
 	NOTE: https://curl.se/docs/CVE-2026-13608.html
 	NOTE: Introduced with: https://github.com/curl/curl/eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 (curl-7_82_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519 (rc-8_22_0-1)
-CVE-2026-84470
+CVE-2026-84470 (A flaw was found in Ansible Automation Platform's automation-controlle ...)
 	NOT-FOR-US: automation-controller/AWX
-CVE-2026-84373
+CVE-2026-84373 (Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 ...)
 	NOT-FOR-US: Vitest
-CVE-2026-84311
+CVE-2026-84311 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
 	- pypdf <unfixed>
 	- pypdf2 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527050
 	TODO: check upstream references
-CVE-2026-84310
+CVE-2026-84310 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
 	- pypdf <unfixed>
 	- pypdf2 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527049
@@ -61,59 +515,59 @@ CVE-2026-73553
 CVE-2026-16658
 	- ansible <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506209
-CVE-2026-84353
+CVE-2026-84353 (Use after free in Shared Tab Groups in Google Chrome on on Android pri ...)
 	- chromium <unfixed>
-CVE-2026-84352
+CVE-2026-84352 (Use after free in WebGL in Google Chrome on on Android prior to 152.0. ...)
 	- chromium <unfixed>
-CVE-2026-84354
+CVE-2026-84354 (Incorrect authorization in FileSystem in Google Chrome prior to 152.0. ...)
 	- chromium <unfixed>
-CVE-2026-84359
+CVE-2026-84359 (Information leak in Skia in Google Chrome prior to 152.0.7977.75 allow ...)
 	- chromium <unfixed>
-CVE-2026-84357
+CVE-2026-84357 (Improper input validation in Omnibox in Google Chrome prior to 152.0.7 ...)
 	- chromium <unfixed>
-CVE-2026-84324
+CVE-2026-84324 (Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowe ...)
 	- chromium <unfixed>
-CVE-2026-84349
+CVE-2026-84349 (Use after free in Browser in Google Chrome prior to 152.0.7977.75 allo ...)
 	- chromium <unfixed>
-CVE-2026-84326
+CVE-2026-84326 (Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 a ...)
 	- chromium <unfixed>
-CVE-2026-84333
+CVE-2026-84333 (Use after free in Dawn in Google Chrome on on Android prior to 152.0.7 ...)
 	- chromium <unfixed>
-CVE-2026-84351
+CVE-2026-84351 (Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7 ...)
 	- chromium <unfixed>
-CVE-2026-84325
+CVE-2026-84325 (Improper input validation in DataTransfer in Google Chrome prior to 15 ...)
 	- chromium <unfixed>
-CVE-2026-84328
+CVE-2026-84328 (Missing authorization in FileSystem in Google Chrome prior to 152.0.79 ...)
 	- chromium <unfixed>
-CVE-2026-84347
+CVE-2026-84347 (Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allow ...)
 	- chromium <unfixed>
-CVE-2026-84323
+CVE-2026-84323 (Missing authorization in FileSystem in Google Chrome prior to 152.0.79 ...)
 	- chromium <unfixed>
-CVE-2026-84355
+CVE-2026-84355 (Incorrect authorization in Navigation in Google Chrome prior to 152.0. ...)
 	- chromium <unfixed>
-CVE-2026-84358
+CVE-2026-84358 (Improper privilege management in Downloads in Google Chrome prior to 1 ...)
 	- chromium <unfixed>
-CVE-2026-84332
+CVE-2026-84332 (Incorrect authorization in SiteSettings in Google Chrome prior to 152. ...)
 	- chromium <unfixed>
-CVE-2026-84330
+CVE-2026-84330 (UI misrepresentation in FullScreen in Google Chrome on on Android prio ...)
 	- chromium <unfixed>
-CVE-2026-84334
+CVE-2026-84334 (Incorrect authorization in Chromoting in Google Chrome on on Windows p ...)
 	- chromium <unfixed>
-CVE-2026-84348
+CVE-2026-84348 (Information leak in MediaCapture in Google Chrome prior to 152.0.7977. ...)
 	- chromium <unfixed>
-CVE-2026-84335
+CVE-2026-84335 (Incorrect authorization in TabStrip in Google Chrome prior to 152.0.79 ...)
 	- chromium <unfixed>
-CVE-2026-84327
+CVE-2026-84327 (Incorrect authorization in Autofill in Google Chrome on on Android pri ...)
 	- chromium <unfixed>
-CVE-2026-84329
+CVE-2026-84329 (Confused deputy in CredentialProvider in Google Chrome on on Windows p ...)
 	- chromium <unfixed>
-CVE-2026-84356
+CVE-2026-84356 (UI misrepresentation in FullScreen in Google Chrome prior to 152.0.797 ...)
 	- chromium <unfixed>
-CVE-2026-84350
+CVE-2026-84350 (Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 all ...)
 	- chromium <unfixed>
-CVE-2026-84331
+CVE-2026-84331 (Incorrect authorization in Actor in Google Chrome prior to 152.0.7977. ...)
 	- chromium <unfixed>
-CVE-2026-81928
+CVE-2026-81928 (Net::DNS versions before 1.57 for Perl allow memory exhaustion via unb ...)
 	- libnet-dns-perl 1.57-1
 	NOTE: https://rt.cpan.org/Ticket/Display.html?id=181125
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43194862/
@@ -643,20 +1097,20 @@ CVE-2024-10085 (CWE-770: Allocation of Resources Without Limits or Throttlingvul
 	NOT-FOR-US: Schneider Electric
 CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites ...)
 	TODO: check
-CVE-2026-84145 (Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firef ...)
+CVE-2026-84145 (Internally found bugs present in Thunderbird 154, Thunderbird ESR 153. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84145
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84145
-CVE-2026-84144 (Internally found bugs present in Firefox 154 and Firefox ESR 153.1. So ...)
+CVE-2026-84144 (Internally found bugs present in Thunderbird 154 and Thunderbird ESR 1 ...)
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84144
-CVE-2026-84143 (Internally found bugs present in Firefox 154, Firefox ESR 153.1 and Fi ...)
+CVE-2026-84143 (Internally found bugs present in Thunderbird 154, Thunderbird ESR 153. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84143
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84143
-CVE-2026-84142 (Internally found bugs present in Firefox 154. Some of these bugs showe ...)
+CVE-2026-84142 (Internally found bugs present in Thunderbird 154. Some of these bugs s ...)
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84142
 CVE-2026-84141 (Integer overflow in the Graphics: ImageLib component. This vulnerabili ...)
@@ -2185,9 +2639,9 @@ CVE-2026-77704 (The Booking for Appointments and Events Calendar  WordPress plug
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77586 (In MongoDB Connector for BI, MongoDB object names such as collection,  ...)
 	NOT-FOR-US: MongoDB BI Connector
-CVE-2026-77218 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticat ...)
+CVE-2026-77218 (PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenti ...)
 	NOT-FOR-US: PLANET
-CVE-2026-77217 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticat ...)
+CVE-2026-77217 (PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenti ...)
 	NOT-FOR-US: PLANET
 CVE-2026-77184 (In MongoDB Connector for BI, the description text of a collection's JS ...)
 	NOT-FOR-US: MongoDB BI Connector
@@ -2227,17 +2681,17 @@ CVE-2026-76546 (The User Profile Builder  WordPress plugin before 4.0.1 does not
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75486 (Synk Sweater Comb before 3.8.8 contains a command injection vulnerabil ...)
 	NOT-FOR-US: Synk Sweater Comb
-CVE-2026-75126 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple au ...)
+CVE-2026-75126 (PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains multiple ...)
 	NOT-FOR-US: PLANET
-CVE-2026-75125 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
+CVE-2026-75125 (PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authe ...)
 	NOT-FOR-US: PLANET
-CVE-2026-75124 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authe ...)
+CVE-2026-75124 (PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains a pre-au ...)
 	NOT-FOR-US: PLANET
-CVE-2026-75123 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
+CVE-2026-75123 (PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authe ...)
 	NOT-FOR-US: PLANET
-CVE-2026-75122 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
+CVE-2026-75122 (PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authe ...)
 	NOT-FOR-US: PLANET
-CVE-2026-75121 (PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenti ...)
+CVE-2026-75121 (PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authe ...)
 	NOT-FOR-US: PLANET
 CVE-2026-75118 (A pre-authentication stack-based buffer overflow vulnerability exists  ...)
 	NOT-FOR-US: TPLink
@@ -4779,6 +5233,7 @@ CVE-2026-81203 (A vulnerability has been found in SourceCodester Simple Online F
 CVE-2026-81202 (A flaw has been found in itsourcecode Payroll System 1.0. The impacted ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-80183 (In OpenStack Keystone before 29.0.3, any authenticated user holding ro ...)
+	{DSA-6480-1}
 	- keystone 2:29.0.2-2 (bug #1145816)
 	NOTE: https://launchpad.net/bugs/2154645
 CVE-2026-79939 (Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an U ...)
@@ -7330,10 +7785,12 @@ CVE-2026-13404 (The Royal Addons for Elementor  WordPress plugin before 1.7.1066
 CVE-2026-13172 (The Eventin  WordPress plugin before 4.1.22 does not restrict access t ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-80184 (In OpenStack Keystone before 29.0.3, tokens obtained via delegated aut ...)
+	{DSA-6480-1}
 	- keystone 2:29.0.2-1 (bug #1145669)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/25/9
 	NOTE: https://bugs.launchpad.net/keystone/+bug/2158538
 CVE-2026-80182 (In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access ...)
+	{DSA-6480-1}
 	- keystone 2:29.0.2-1 (bug #1145669)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/25/9
 	NOTE: https://bugs.launchpad.net/keystone/+bug/2153453
@@ -7936,15 +8393,20 @@ CVE-2026-12878 (In affected versions of the Codefresh platform an authenticated
 	NOT-FOR-US: Octopus Deploy
 CVE-2026-12600 (Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) d ...)
 	NOT-FOR-US: Poppler fork by Innodata Labs
-CVE-2025-71407 (Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability  ...)
+CVE-2025-71407
+	REJECTED
 	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
-CVE-2025-71406 (Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior  ...)
+CVE-2025-71406
+	REJECTED
 	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxslt)
-CVE-2025-71346 (Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (befor ...)
+CVE-2025-71346
+	REJECTED
 	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
-CVE-2024-58378 (Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the ...)
+CVE-2024-58378
+	REJECTED
 	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
-CVE-2024-58377 (Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affect ...)
+CVE-2024-58377
+	REJECTED
 	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
 CVE-2023-54354 (Nokogiri before 1.14.3 (CRuby implementation only, when using the pack ...)
 	- ruby-nokogiri <not-affected> (Debian uses the system copy of libxml)
@@ -15549,7 +16011,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet len
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517490
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
 	NOTE: Followup: https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
-CVE-2026-74990 (Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.1 ...)
+CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
 	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
@@ -15557,13 +16019,13 @@ CVE-2026-74990 (Internally found bugs present in Firefox ESR 115.38, Firefox ESR
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74990
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74990
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74990
-CVE-2026-74989 (Internally found bugs present in Firefox 153. Some of these bugs showe ...)
+CVE-2026-74989 (Internally found bugs present in Thunderbird 153. Some of these bugs s ...)
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74989
-CVE-2026-74988 (Internally found bugs present in Firefox ESR 153.0 and Firefox 153. So ...)
+CVE-2026-74988 (Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird ...)
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
-CVE-2026-74987 (Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 ...)
+CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
 	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
@@ -15762,7 +16224,7 @@ CVE-2026-74951 (Clickjacking issue in Firefox for Android. This vulnerability wa
 CVE-2026-74950 (Privilege escalation in the Downloads API component. This vulnerabilit ...)
 	- firefox 154.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
-CVE-2026-74949 (Use-after-free in the Graphics: Canvas2D component. This vulnerability ...)
+CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canvas2D c ...)
 	{DSA-6461-1 DSA-6451-1 DLA-4754-1 DLA-4750-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
@@ -41422,7 +41884,7 @@ CVE-2026-16566
 	[bullseye] - ansible <not-affected> (Vulnerable code not present)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506113
 	TODO: check upstream report and status on fix
-CVE-2026-14957
+CVE-2026-14957 (In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_Extra ...)
 	- libreswan 5.2-2.5 (bug #1143067)
 	[trixie] - libreswan <no-dsa> (Minor issue; can be fixed via point release)
 	[bullseye] - libreswan <end-of-life> (EOL in bullseye LTS)
@@ -71788,7 +72250,7 @@ CVE-2026-53927 (NocoDB is software for building databases as spreadsheets. Prior
 	NOT-FOR-US: NocoDB
 CVE-2026-53926 (NocoDB is software for building databases as spreadsheets. Prior to 20 ...)
 	NOT-FOR-US: NocoDB
-CVE-2026-53622 (Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, th ...)
+CVE-2026-53622 (Traefik is an HTTP reverse proxy and load balancer. Versions prior to  ...)
 	- traefik <itp> (bug #983289)
 CVE-2026-50193 (jackson-databind contains the general-purpose data-binding functionali ...)
 	- jackson-databind 2.14.0-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d85f714e014c3a7e89238fd70b91fc6619590cd8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d85f714e014c3a7e89238fd70b91fc6619590cd8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/9c5afec8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list