[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Sep 6 08:13:13 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
62872576 by security tracker role at 2026-09-06T07:13:06+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,79 @@
+CVE-2026-86218 (N-central is vulnerable to a pre-auth remote code execution This issue ...)
+ TODO: check
+CVE-2026-86207 (An authentication bypass in N-central < 2026.3 HF 3 leads to authentic ...)
+ TODO: check
+CVE-2026-86206 (A vulnerability in the N-central internal API access control filter al ...)
+ TODO: check
+CVE-2026-86171 (A security vulnerability has been detected in DefaultFuction CRM 1.0.0 ...)
+ TODO: check
+CVE-2026-86170 (A weakness has been identified in DefaultFuction CRM 1.0.0. The impact ...)
+ TODO: check
+CVE-2026-86168 (A security flaw has been discovered in code-projects Content Managemen ...)
+ TODO: check
+CVE-2026-86167 (A vulnerability was identified in Tenda HG10 300001138. Impacted is th ...)
+ TODO: check
+CVE-2026-86166 (A vulnerability was determined in Tenda HG10 300001138. This issue aff ...)
+ TODO: check
+CVE-2026-86165 (A vulnerability was found in Tenda HG10 300001138. This vulnerability ...)
+ TODO: check
+CVE-2026-86164 (A security flaw has been discovered in itsourcecode Sales and Inventor ...)
+ TODO: check
+CVE-2026-86163 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
+ TODO: check
+CVE-2026-86162 (A vulnerability was determined in SourceCodester Online Voting System ...)
+ TODO: check
+CVE-2026-86161 (A vulnerability was found in SourceCodester Online Voting System 1.0. ...)
+ TODO: check
+CVE-2026-86160 (A vulnerability has been found in SourceCodester Online Voting System ...)
+ TODO: check
+CVE-2026-86159 (A flaw has been found in SourceCodester Online Voting System 1.0. Impa ...)
+ TODO: check
+CVE-2026-86153 (A vulnerability has been found in Tenda CP3 27.5.57.101. This affects ...)
+ TODO: check
+CVE-2026-86152 (A flaw has been found in Tenda CP3 27.5.57.101. The impacted element i ...)
+ TODO: check
+CVE-2026-86151 (A vulnerability was detected in Tenda CP3 27.5.57.101. The affected el ...)
+ TODO: check
+CVE-2026-86150 (A security vulnerability has been detected in Tenda CP3 27.5.57.101. I ...)
+ TODO: check
+CVE-2026-86149 (A weakness has been identified in Tenda CP3 27.5.57.101. This issue af ...)
+ TODO: check
+CVE-2026-86148 (A security flaw has been discovered in Tenda CP3 27.5.57.101. This vul ...)
+ TODO: check
+CVE-2026-86060 (RouterOS contains an argument-handling flaw in the SSH login path invo ...)
+ TODO: check
+CVE-2026-85038 (The B2BKing \u2014 Ultimate WooCommerce B2B and Wholesale Plugin \u201 ...)
+ TODO: check
+CVE-2026-84219 (The Kirki WordPress plugin before 6.3.0 does not hold back every spel ...)
+ TODO: check
+CVE-2026-84028 (The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise ...)
+ TODO: check
+CVE-2026-76161
+ REJECTED
+CVE-2026-76160
+ REJECTED
+CVE-2026-75816 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
+ TODO: check
+CVE-2026-75793 (The SureCart WordPress plugin before 4.7.0 does not consult the site' ...)
+ TODO: check
+CVE-2026-67281 (RouterOS WebFig contains an unauthenticated file-read vulnerability in ...)
+ TODO: check
+CVE-2026-67279 (RouterOS SSH enters the connection protocol after a client-requested r ...)
+ TODO: check
+CVE-2026-67278 (MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during ...)
+ TODO: check
+CVE-2026-67277 (RouterOS accepts a "related" btest connection before the corresponding ...)
+ TODO: check
+CVE-2026-67276 (RouterOS does not compare the complete RSA public key when matching an ...)
+ TODO: check
+CVE-2026-18480 (The SureCart WordPress plugin before 4.6.3 does not ensure that the a ...)
+ TODO: check
+CVE-2026-18056 (The HivePress Authentication plugin for WordPress is vulnerable to Aut ...)
+ TODO: check
+CVE-2026-16310 (The MemberDash plugin for WordPress is vulnerable to Insecure Direct O ...)
+ TODO: check
+CVE-2026-13159 (The Real Estate Papi WordPress theme through 1.0.5 does not perform ca ...)
+ TODO: check
CVE-2026-85498 [Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]
- policykit-1 <unfixed>
[trixie] - policykit-1 <not-affected> (Fix for CVE-2026-4897 not applied)
@@ -1826,29 +1902,41 @@ CVE-2026-85062 (Colord is a tiny yet powerful tool for high-performance color ma
CVE-2026-85061 (MapLibre GL JS is an interactive vector tile map library for web brows ...)
NOT-FOR-US: MapLibre GL JS
CVE-2026-85053 (Improper resource exposure in CacheStorage in Google Chrome prior to 1 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85052 (Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85051 (Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85050 (Out of bounds write in WebGL in Google Chrome on on Android prior to 1 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85049 (Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
- libskia 146.20260602~git.3476902+dfsg-4
CVE-2026-85048 (Use after free in Compositing in Google Chrome prior to 152.0.7977.82 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85047 (Improper input validation in Transactions Platform in Google Chrome on ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85046 (Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85045 (Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85044 (Use of released resource in Mobile in Google Chrome on on Android prio ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85043 (Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85042 (Use after free in DevTools in Google Chrome prior to 152.0.7977.82 all ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-84185 (A flaw was found in the jwcrypto library, which is used for implementi ...)
- python-jwcrypto <unfixed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62872576d2a907e9e4205c785edcbf79cbfbdefb
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62872576d2a907e9e4205c785edcbf79cbfbdefb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/a7c52da1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list