[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 18 08:12:46 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
10fa55d6 by security tracker role at 2026-09-18T07:12:38+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,423 @@
+CVE-2026-93485 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-93468 (The OAKlouds developed by HGiga has an Arbitrary File Read vulnerabili ...)
+ TODO: check
+CVE-2026-93467 (The OAKlouds developed by HGiga has a Insecure Deserialization vulnera ...)
+ TODO: check
+CVE-2026-93456 (django-page-cms through 2.0.13 exempts five admin mutation views from ...)
+ TODO: check
+CVE-2026-93455 (django-page-cms through 2.0.13 fails to properly validate page permiss ...)
+ TODO: check
+CVE-2026-93454 (Aureus ERP through 1.6.0 stores the Payment Term note field unsanitize ...)
+ TODO: check
+CVE-2026-93453 (SOGo before 5.12.11 constructs password-reset links using the client-s ...)
+ TODO: check
+CVE-2026-93452 (snappy-java through 1.1.10.8 contains a buffer overflow vulnerability ...)
+ TODO: check
+CVE-2026-93451 (snappy-java through 1.1.10.8 contains a buffer overflow vulnerability ...)
+ TODO: check
+CVE-2026-93450 (go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vuln ...)
+ TODO: check
+CVE-2026-93436 (vLLM through 0.29.0 fails to properly clean up decode-side metadata fo ...)
+ TODO: check
+CVE-2026-93435 (redis-parser through 3.0.0 contains a denial of service vulnerability ...)
+ TODO: check
+CVE-2026-93426 (SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied tel ...)
+ TODO: check
+CVE-2026-93395 (A missing lower-bound validation in the bson_new_from_buffer() functio ...)
+ TODO: check
+CVE-2026-93394 (A flaw in libmongoc's SCRAM authentication implementation caused the c ...)
+ TODO: check
+CVE-2026-93393 (A heap-based buffer overflow exists in the TLS transport layer of the ...)
+ TODO: check
+CVE-2026-93387 (Improper state validation in Skia in Google Chrome prior to 153.0.8010 ...)
+ TODO: check
+CVE-2026-93386 (UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0 ...)
+ TODO: check
+CVE-2026-93385 (Information leak in Paint in Google Chrome prior to 153.0.8010.52 allo ...)
+ TODO: check
+CVE-2026-93384 (Server-side request forgery in Omnibox in Google Chrome on on Android ...)
+ TODO: check
+CVE-2026-93383 (Information leak in Permissions in Google Chrome prior to 153.0.8010.5 ...)
+ TODO: check
+CVE-2026-93382 (Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allow ...)
+ TODO: check
+CVE-2026-93381 (Buffer overflow in PDFium in Google Chrome on on Windows prior to 153. ...)
+ TODO: check
+CVE-2026-93380 (Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 a ...)
+ TODO: check
+CVE-2026-93379 (Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 ...)
+ TODO: check
+CVE-2026-93378 (Missing authorization in Storage in Google Chrome prior to 153.0.8010. ...)
+ TODO: check
+CVE-2026-93377 (Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a ...)
+ TODO: check
+CVE-2026-93376 (Out of bounds read in DataTransfer in Google Chrome prior to 153.0.801 ...)
+ TODO: check
+CVE-2026-93375 (Incorrect reference resolution in Tracing in Google Chrome on on Windo ...)
+ TODO: check
+CVE-2026-93374 (Use after free in Dawn in Google Chrome on on Android prior to 153.0.8 ...)
+ TODO: check
+CVE-2026-93373 (Use after free in Extensions in Google Chrome prior to 153.0.8010.52 a ...)
+ TODO: check
+CVE-2026-93372 (Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0 ...)
+ TODO: check
+CVE-2026-93371 (A security vulnerability has been detected in marcopiovanello yt-dlp-w ...)
+ TODO: check
+CVE-2026-93331 (A vulnerability was identified in GPAC 26.08-DEV. This vulnerability a ...)
+ TODO: check
+CVE-2026-93314 (A vulnerability was determined in Freedesktop Poppler 26.07.0. This af ...)
+ TODO: check
+CVE-2026-93313 (A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted ...)
+ TODO: check
+CVE-2026-93312 (A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the ...)
+ TODO: check
+CVE-2026-93311 (A vulnerability was detected in Freedesktop Poppler 26.07.0. This issu ...)
+ TODO: check
+CVE-2026-93310 (A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This af ...)
+ TODO: check
+CVE-2026-93309 (A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affecte ...)
+ TODO: check
+CVE-2026-93308 (A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by ...)
+ TODO: check
+CVE-2026-93307 (A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affecte ...)
+ TODO: check
+CVE-2026-92991 (The Biggop Library is vulnerable to Cross-Site Scripting via the \u201 ...)
+ TODO: check
+CVE-2026-92757 (Applications built on MongoDB Entity Framework Core Provider which pla ...)
+ TODO: check
+CVE-2026-92714 (The Download Manager plugin for WordPress is vulnerable to Insecure Di ...)
+ TODO: check
+CVE-2026-92619 (The Booking Calendar plugin for WordPress is vulnerable to Privilege E ...)
+ TODO: check
+CVE-2026-92561 (The Booking Calendar plugin for WordPress is vulnerable to Reflected C ...)
+ TODO: check
+CVE-2026-91707 (The The Divi theme for WordPress is vulnerable to arbitrary shortcode ...)
+ TODO: check
+CVE-2026-90984 (The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 do ...)
+ TODO: check
+CVE-2026-90978 (The Filter Gallery WordPress plugin before 1.1.5 does not verify the n ...)
+ TODO: check
+CVE-2026-90977 (The Clean Login WordPress plugin before 1.19 does not verify its regis ...)
+ TODO: check
+CVE-2026-90976 (The Clean Login WordPress plugin before 1.19 does not check whether us ...)
+ TODO: check
+CVE-2026-89413 (The Filter Gallery plugin for WordPress is vulnerable to authorization ...)
+ TODO: check
+CVE-2026-89330 (The EmbedPress \u2013 PDF Embedder, 3D PDF FlipBook, Google Reviews, Y ...)
+ TODO: check
+CVE-2026-89278 (The GPTranslate \u2013 Multilingual AI Translation Agent for WordPress ...)
+ TODO: check
+CVE-2026-89138 (The Filter Gallery plugin for WordPress is vulnerable to authorization ...)
+ TODO: check
+CVE-2026-89008 (The Bookit \u2014 Booking & Appointment Calendar WordPress plugin befo ...)
+ TODO: check
+CVE-2026-89007 (The Bookit \u2014 Booking & Appointment Calendar WordPress plugin befo ...)
+ TODO: check
+CVE-2026-88994 (The All Bootstrap Blocks WordPress plugin through 1.3.31 does not vali ...)
+ TODO: check
+CVE-2026-88993 (The All Bootstrap Blocks WordPress plugin through 1.3.31 does not prop ...)
+ TODO: check
+CVE-2026-88844 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
+ TODO: check
+CVE-2026-88825 (The iGMS Direct Booking WordPress plugin before 2.0 does not authorise ...)
+ TODO: check
+CVE-2026-88798 (The Really Simple Security WordPress plugin before 9.8.3 does not val ...)
+ TODO: check
+CVE-2026-87966 (The Easy Appointments WordPress plugin before 4.0.2.2 does not perform ...)
+ TODO: check
+CVE-2026-87965 (The Easy Appointments WordPress plugin before 4.0.2.2 does not use an ...)
+ TODO: check
+CVE-2026-87886 (Local privilege escalation due to insecure file permissions. The follo ...)
+ TODO: check
+CVE-2026-87775 (The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not s ...)
+ TODO: check
+CVE-2026-87774 (The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not s ...)
+ TODO: check
+CVE-2026-87771 (The Product Question and Answer WordPress plugin through 1.1.0 does no ...)
+ TODO: check
+CVE-2026-87770 (The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 doe ...)
+ TODO: check
+CVE-2026-87767 (The wp shortcut link and advertisement baner WordPress plugin through ...)
+ TODO: check
+CVE-2026-87701 (Improper neutralization of special elements in output used by a downst ...)
+ TODO: check
+CVE-2026-86800 (The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly ...)
+ TODO: check
+CVE-2026-86796 (The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify th ...)
+ TODO: check
+CVE-2026-86688 (Session Fixation vulnerability in team-alembic ash_authentication allo ...)
+ TODO: check
+CVE-2026-86049 (Jupyter Server is the backend for Jupyter web applications. Prior to v ...)
+ TODO: check
+CVE-2026-85917 (Server-side request forgery (ssrf) in Azure AI Foundry allows an unaut ...)
+ TODO: check
+CVE-2026-85889 (Missing authentication for critical function in Azure AI Foundry allow ...)
+ TODO: check
+CVE-2026-85887 (Incorrect permission assignment for critical resource in M365 Copilot ...)
+ TODO: check
+CVE-2026-85885 (Improper neutralization of special elements used in a command ('comman ...)
+ TODO: check
+CVE-2026-85878 (Improper authorization in Azure Database for PostgreSQL allows an auth ...)
+ TODO: check
+CVE-2026-85350 (The UpsellWP WordPress plugin before 2.2.10 does not check that produ ...)
+ TODO: check
+CVE-2026-85127 (The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8. ...)
+ TODO: check
+CVE-2026-85123 (The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 do ...)
+ TODO: check
+CVE-2026-85122 (The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 do ...)
+ TODO: check
+CVE-2026-85009 (The RestroPress WordPress plugin through 3.4.6 does not verify owners ...)
+ TODO: check
+CVE-2026-84909 (The Custom Twitter Feeds \u2013 A Tweets Widget or X Feed Widget plugi ...)
+ TODO: check
+CVE-2026-84904 (The King Addons for Elementor WordPress plugin before 51.1.81 does no ...)
+ TODO: check
+CVE-2026-84903 (The King Addons for Elementor WordPress plugin before 51.1.81 does no ...)
+ TODO: check
+CVE-2026-84902 (The King Addons for Elementor WordPress plugin before 51.1.81 does no ...)
+ TODO: check
+CVE-2026-84738 (The AF Companion WordPress plugin before 2.2.0 does not validate the ...)
+ TODO: check
+CVE-2026-83946 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-83944 (Improper access control in Azure Logic Apps allows an unauthorized att ...)
+ TODO: check
+CVE-2026-82985 (The Photos app's filter-based "smart albums" build their file listing ...)
+ TODO: check
+CVE-2026-82982 (The Approval app's approve/reject endpoint is meant to require the fil ...)
+ TODO: check
+CVE-2026-82980 (Any authenticated user can lock or unlock files they do not own by tar ...)
+ TODO: check
+CVE-2026-81810 (The All-in-One WP Migration and Backup WordPress plugin before 7.111 d ...)
+ TODO: check
+CVE-2026-81340 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
+ TODO: check
+CVE-2026-79954 (NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerabilit ...)
+ TODO: check
+CVE-2026-79713 (The Breeze Cache WordPress plugin before 2.5.15 does not include a set ...)
+ TODO: check
+CVE-2026-78668
+ REJECTED
+CVE-2026-78501 (Improper neutralization of special elements used in a command ('comman ...)
+ TODO: check
+CVE-2026-77903 (Authentication bypass by spoofing in Microsoft Dataverse allows an una ...)
+ TODO: check
+CVE-2026-77615 (Paella Player is a set of libraries to create a multi stream video pla ...)
+ TODO: check
+CVE-2026-77281 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
+ TODO: check
+CVE-2026-77170 (The Deck config API allows authenticated users to set board-scoped con ...)
+ TODO: check
+CVE-2026-77169 (A vulnerability in the team folders (formerly group folders) app when ...)
+ TODO: check
+CVE-2026-77164 (Circles' remote-instance signature verification fetches the attacker-s ...)
+ TODO: check
+CVE-2026-76949 (Authentication Bypass by Spoofing vulnerability in team-alembic ash_au ...)
+ TODO: check
+CVE-2026-76154 (A stored cross-site scripting vulnerability in the Geomap panel's MapL ...)
+ TODO: check
+CVE-2026-75017 (The Magazine Blocks \u2013 Blog Designer, Magazine & Newspaper Website ...)
+ TODO: check
+CVE-2026-75016 (The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross ...)
+ TODO: check
+CVE-2026-70200 (Improper limitation of a pathname to a restricted directory ('path tra ...)
+ TODO: check
+CVE-2026-70009 (Improper limitation of a pathname to a restricted directory ('path tra ...)
+ TODO: check
+CVE-2026-69865 (Authorization bypass through user-controlled key in Microsoft Containe ...)
+ TODO: check
+CVE-2026-69843 (Authentication bypass by spoofing in Microsoft Fabric allows an unauth ...)
+ TODO: check
+CVE-2026-69399 (Azure Arc Elevation of Privilege Vulnerability)
+ TODO: check
+CVE-2026-68791 (Incorrect authorization in Azure Machine Learning allows an unauthoriz ...)
+ TODO: check
+CVE-2026-68537 (`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server th ...)
+ TODO: check
+CVE-2026-68523 (`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server th ...)
+ TODO: check
+CVE-2026-68493 (After guessing a 62^15 complex unique identifier, a malicious logged i ...)
+ TODO: check
+CVE-2026-67071 (HCL DevOps Deploy / HCL Launch is susceptible to an information disclo ...)
+ TODO: check
+CVE-2026-65323
+ REJECTED
+CVE-2026-62874 (Insufficient verification of data authenticity in Azure Billing allows ...)
+ TODO: check
+CVE-2026-57847
+ REJECTED
+CVE-2026-57846
+ REJECTED
+CVE-2026-55946 (Improper neutralization of special elements used in a command ('comman ...)
+ TODO: check
+CVE-2026-54918 (NetBox Device Type Library is a collection of community-sourced device ...)
+ TODO: check
+CVE-2026-54916 (NetBox Device Type Library is a collection of community-sourced device ...)
+ TODO: check
+CVE-2026-54907 (Caddy Proxy Manager is a web interface for managing Caddy Server rever ...)
+ TODO: check
+CVE-2026-54767 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, we ...)
+ TODO: check
+CVE-2026-54752 (NetBox Device Type Library is a collection of community-sourced device ...)
+ TODO: check
+CVE-2026-54734 (Prebid Server Java is the Java version of Prebid Server. Prior to 3.43 ...)
+ TODO: check
+CVE-2026-54716 (Valhalla is an open source routing engine and accompanying libraries f ...)
+ TODO: check
+CVE-2026-54692 (SAIL is a cross-platform library for loading and saving images with su ...)
+ TODO: check
+CVE-2026-54671 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, We ...)
+ TODO: check
+CVE-2026-54670 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, th ...)
+ TODO: check
+CVE-2026-54648 (CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR t ...)
+ TODO: check
+CVE-2026-54647 (CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sour ...)
+ TODO: check
+CVE-2026-54646 (CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sour ...)
+ TODO: check
+CVE-2026-54645 (CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sour ...)
+ TODO: check
+CVE-2026-54644 (CubeCart is an ecommerce software solution. Prior to 6.7.5, the _error ...)
+ TODO: check
+CVE-2026-54643 (CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete ...)
+ TODO: check
+CVE-2026-54642 (CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_ ...)
+ TODO: check
+CVE-2026-54634 (Hamlib is a ham radio control library for radios, rotators, and amplif ...)
+ TODO: check
+CVE-2026-54633 (PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1 ...)
+ TODO: check
+CVE-2026-54627 (SAIL is a cross-platform library for loading and saving images with su ...)
+ TODO: check
+CVE-2026-54626 (SAIL is a cross-platform library for loading and saving images with su ...)
+ TODO: check
+CVE-2026-54618 (Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Pr ...)
+ TODO: check
+CVE-2026-54613 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
+ TODO: check
+CVE-2026-54612 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
+ TODO: check
+CVE-2026-54608 (MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier ...)
+ TODO: check
+CVE-2026-54597 (ITFlow provides an IT documentation, ticketing and accounting system f ...)
+ TODO: check
+CVE-2026-54596 (ITFlow provides an IT documentation, ticketing and accounting system f ...)
+ TODO: check
+CVE-2026-54594 (OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June ...)
+ TODO: check
+CVE-2026-54565 (rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. ...)
+ TODO: check
+CVE-2026-54521 (FairEmail is a fully featured, open source, privacy-friendly email app ...)
+ TODO: check
+CVE-2026-54520 (AI Agent Automation is a modular AI agent workflow automation platform ...)
+ TODO: check
+CVE-2026-54519 (AI Agent Automation is a modular AI agent workflow automation platform ...)
+ TODO: check
+CVE-2026-54510 (Speakr is a personal, self-hosted web application designed for transcr ...)
+ TODO: check
+CVE-2026-54507 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
+ TODO: check
+CVE-2026-54506 (Vvveb is a powerful and easy to use CMS with page builder to build web ...)
+ TODO: check
+CVE-2026-54501 (Browsertrix is a high-fidelity, browser-based crawling service for web ...)
+ TODO: check
+CVE-2026-54495 (The OpenFeature Operator allows users to expose feature flags to appli ...)
+ TODO: check
+CVE-2026-54460 (OpenReception's appointment booking software provides an end-to-end en ...)
+ TODO: check
+CVE-2026-54355 (MapServer is a system for developing web-based GIS applications. From ...)
+ TODO: check
+CVE-2026-54354 (MapServer is a system for developing web-based GIS applications. Prior ...)
+ TODO: check
+CVE-2026-54343 (Frappe Learning Management System (LMS) is a learning system that help ...)
+ TODO: check
+CVE-2026-54339 (Glean is a self-hosted RSS reader and personal knowledge management to ...)
+ TODO: check
+CVE-2026-54237 (Wavelog is web-based amateur radio logging software. From 1.8 until 2. ...)
+ TODO: check
+CVE-2026-53557 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
+ TODO: check
+CVE-2026-53556 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
+ TODO: check
+CVE-2026-53555 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
+ TODO: check
+CVE-2026-53554 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
+ TODO: check
+CVE-2026-53534 (JabRef is a desktop application for managing BibTeX and BibLaTeX libra ...)
+ TODO: check
+CVE-2026-52483 (The ping diagnostics and other similar functions of the MitraStar GPT- ...)
+ TODO: check
+CVE-2026-50291 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
+ TODO: check
+CVE-2026-50285 (Pomerium is an identity and context-aware access proxy. Prior to 0.32. ...)
+ TODO: check
+CVE-2026-50277 (dd-trace-cpp is the Datadog distributed tracing library for C++. Prior ...)
+ TODO: check
+CVE-2026-50275 (The Datadog PHP Tracer provides application performance monitoring and ...)
+ TODO: check
+CVE-2026-50158 (yutu is an AI-powered toolkit for managing and growing YouTube channel ...)
+ TODO: check
+CVE-2026-50125 (MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, ...)
+ TODO: check
+CVE-2026-50022 (Metacat is data repository software that helps researchers preserve, s ...)
+ TODO: check
+CVE-2026-49137
+ REJECTED
+CVE-2026-45726 (Omni manages Kubernetes on bare metal, virtual machines, or in a cloud ...)
+ TODO: check
+CVE-2026-45723 (Omni manages Kubernetes on bare metal, virtual machines, or in a cloud ...)
+ TODO: check
+CVE-2026-45720 (Omni manages Kubernetes on bare metal, virtual machines, or in a cloud ...)
+ TODO: check
+CVE-2026-45143 (Chamilo LMS is an open-source learning management system. From 2.0.0 t ...)
+ TODO: check
+CVE-2026-45140 (Chamilo LMS is an open-source learning management system. Prior to 2.0 ...)
+ TODO: check
+CVE-2026-2585 (The Brizy \u2013 Page Builder plugin for WordPress is vulnerable to St ...)
+ TODO: check
+CVE-2026-18912 (ManageEngine DataSecurity Plus versions before 6310 are vulnerable to ...)
+ TODO: check
+CVE-2026-18911 (ManageEngine DataSecurity Plus versions before 6310 are vulnerable to ...)
+ TODO: check
+CVE-2026-18441 (The Appointment Booking Plugin \u2013 LatePoint | Calendar & Schedulin ...)
+ TODO: check
+CVE-2026-18317 (The Foxtool All-in-One: Contact chat button, Custom login, Media optim ...)
+ TODO: check
+CVE-2026-17576 (The InfiniteWP Client plugin for WordPress is vulnerable to SQL Inject ...)
+ TODO: check
+CVE-2026-17086 (The ShortPixel Image Optimizer \u2013 Optimize Images, Convert WebP & ...)
+ TODO: check
+CVE-2026-16750 (The Motors \u2013 Car Dealership & Classified Listings Plugin plugin f ...)
+ TODO: check
+CVE-2026-16582 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin ...)
+ TODO: check
+CVE-2026-15815 (Grafana OSS and Grafana Enterprise did not safely resolve symbolic lin ...)
+ TODO: check
+CVE-2026-15650 (The RT Mega Menu \u2013 Mega Menu Builder for Elementor & Gutenberg pl ...)
+ TODO: check
+CVE-2026-14855 (The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Si ...)
+ TODO: check
+CVE-2026-14311 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin ...)
+ TODO: check
+CVE-2026-12106 (The Auto Upload Images plugin for WordPress is vulnerable to Limited S ...)
+ TODO: check
+CVE-2026-11432
+ REJECTED
+CVE-2026-11314
+ REJECTED
+CVE-2026-10594
+ REJECTED
+CVE-2025-62167
+ REJECTED
+CVE-2025-55787 (In MailData Email Archiving System v4.2 and earlier, a SQL injection v ...)
+ TODO: check
+CVE-2024-38639 (An improper authentication vulnerability has been reported to affect p ...)
+ TODO: check
+CVE-2024-27123 (A cross-site scripting (XSS) vulnerability has been reported to affect ...)
+ TODO: check
CVE-2026-XXXX [OSSA-2026-039]
- octavia 18.0.0-4 (bug #1148175)
NOTE: https://bugs.launchpad.net/octavia/+bug/2162101
@@ -6656,91 +7076,133 @@ CVE-2026-82374
- znc 1.10.3-1
NOTE: https://wiki.znc.in/ChangeLog/1.10.3
CVE-2026-91726 (Out of bounds read in WebGL in Google Chrome on on Android prior to 15 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91721 (Use after free in Internals in Google Chrome prior to 153.0.8010.47 al ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91749 (Use after free in Workers in Google Chrome prior to 153.0.8010.47 allo ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91724 (Use after free in Input in Google Chrome prior to 153.0.8010.47 allowe ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91728 (Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91734 (Incorrect authorization in Core in Google Chrome on on Windows prior t ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91727 (Incorrect reference resolution in Extensions in Google Chrome on on Ma ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91743 (Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91744 (Race condition in PlatformIntegration in Google Chrome on on Mac prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91712 (Race condition in Extensions in Google Chrome on on Mac prior to 153.0 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91748 (Race condition in Extensions in Google Chrome on on Mac prior to 153.0 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91720 (Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.4 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91731 (Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91747 (Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
- libskia <unfixed>
CVE-2026-91733 (Improper state validation in Skia in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
- libskia <unfixed>
CVE-2026-91741 (Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91709 (Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.4 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91717 (Missing authorization in Android in Google Chrome on on Android prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91735 (Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91708 (Race condition in Network in Google Chrome prior to 153.0.8010.47 allo ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91736 (Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91740 (Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
- libskia <unfixed>
CVE-2026-91710 (Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91718 (Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91716 (Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91746 (Integer overflow in Compositing in Google Chrome prior to 153.0.8010.4 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91729 (Use after free in DigitalCredentials in Google Chrome prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91737 (Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91711 (Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91715 (Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.4 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91745 (Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91723 (Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91732 (Missing authorization in AppManifest in Google Chrome prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91742 (Confused deputy in PriceTracking in Google Chrome on on iOS prior to 1 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91714 (Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.4 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91725 (Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91739 (Missing authorization in Transactions Platform in Google Chrome prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91713 (Missing authorization in Browser in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91738 (Improper input validation in ANGLE in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91730 (Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91722 (Use after free in Input in Google Chrome prior to 153.0.8010.47 allowe ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-91719 (Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-92180 (pdfforge PDF Architect activation-service Update Service Uncontrolled ...)
NOT-FOR-US: pdfforge PDF Architect
@@ -9623,7 +10085,7 @@ CVE-2026-75131
- network-manager-l2tp 1.52.6-1
NOTE: https://github.com/nm-l2tp/NetworkManager-l2tp/security/advisories/GHSA-v2wj-xr2m-xc4j
NOTE: Fixed by: https://github.com/nm-l2tp/NetworkManager-l2tp/commit/64879ce0ad866f7c9a45babe4d95731a916ea00f (1.52.6, 1.20.26)
-CVE-2026-93337
+CVE-2026-93337 (NetworkManager-l2tp contains an improper input validation vulnerabilit ...)
{DSA-6498-1}
- network-manager-l2tp 1.52.6-1
NOTE: https://github.com/nm-l2tp/NetworkManager-l2tp/security/advisories/GHSA-rp84-8h2r-5xc3
@@ -14205,464 +14667,694 @@ CVE-2026-87724 (Tor before 0.4.9.12 interprets the CC_RESPONSE extension even wh
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41345
NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
CVE-2026-87658 (Information leak in Extensions in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87657 (Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87656 (Improper state validation in Safebrowsing in Google Chrome prior to 15 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87655 (Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allo ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87654 (Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87653 (UI misrepresentation in FullScreen in Google Chrome on on Windows prio ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87652 (Incorrect authorization in PushAPI in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87651 (Incorrect authorization in Paint in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87650 (Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 al ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87649 (UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87648 (Use after free in ANGLE in Google Chrome on on Windows prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87647 (Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87646 (Use after free in Web Authentication in Google Chrome prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87645 (Improper state validation in Safebrowsing in Google Chrome prior to 15 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87644 (Incorrect authorization in Views in Google Chrome on on Windows prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87643 (Integer overflow in GPU in Google Chrome on on Android prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87642 (Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.3 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87641 (Race condition in Browser in Google Chrome prior to 153.0.8010.36 allo ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87640 (Out of bounds read in WebView in Google Chrome on on Android prior to ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87639 (Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87638 (Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87637 (Use after free in Extensions in Google Chrome on on Mac prior to 153.0 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87636 (Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87635 (UI misrepresentation in Payments in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87634 (Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87633 (Use after free in Views in Google Chrome prior to 153.0.8010.36 allowe ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87632 (Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87631 (Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87630 (Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87629 (Incorrect authorization in Sources in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87628 (Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87627 (Interpretation conflict in Safebrowsing in Google Chrome on on Mac pri ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87626 (Incorrect authorization in DeviceBoundSessionCredentials in Google Chr ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87625 (Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87624 (UI misrepresentation in Passwords in Google Chrome on on Android prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87623 (Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87622 (Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87621 (Out of bounds write in ANGLE in Google Chrome on on Windows prior to 1 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87620 (Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87619 (Observable discrepancy in Prefetch in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87618 (Incorrect reference resolution in Storage in Google Chrome on on Windo ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87617 (Use after free in DevTools in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87616 (Improper initialization in Views in Google Chrome on on Windows prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87615 (Race condition in Payments in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87614 (Incorrect authorization in ServiceWorker in Google Chrome prior to 153 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87613 (Incorrect reference resolution in Extensions in Google Chrome prior to ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87612 (Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87611 (Missing authorization in FileSystem in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87610 (Incorrect authorization in Omnibox in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87609 (Use after free in Sharing in Google Chrome on on iOS prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87608 (Improper certificate validation in FedCM in Google Chrome prior to 153 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87607 (Use after free in Device in Google Chrome on on Mac prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87606 (Missing authorization in SiteIsolation in Google Chrome prior to 153.0 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87605 (Missing authorization in Contacts in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87604 (Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 al ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87603 (Missing authorization in FileSystem in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87602 (Out of bounds read in ANGLE in Google Chrome on on Windows prior to 15 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87601 (Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87600 (Improper input validation in Safebrowsing in Google Chrome on on Andro ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87599 (Improper input validation in Interstitials in Google Chrome prior to 1 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87598 (Incorrect authorization in ServiceWorker in Google Chrome prior to 153 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87597 (UI misrepresentation in CustomTabs in Google Chrome on on Android prio ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87596 (Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 al ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87595 (Server-side request forgery in Mobile in Google Chrome prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87594 (Incorrect authorization in DataTransfer in Google Chrome prior to 153. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87593 (Information leak in Editing in Google Chrome prior to 153.0.8010.36 al ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87592 (Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87591 (Incorrect authorization in Extensions in Google Chrome prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87590 (Improper input validation in Passwords in Google Chrome prior to 153.0 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87589 (Incorrect authorization in SiteIsolation in Google Chrome prior to 153 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87588 (Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87587 (Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87586 (Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 al ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87585 (Double free in PDFium in Google Chrome on on Windows prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87584 (Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87583 (UI misrepresentation in Passwords in Google Chrome on on Android prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87582 (Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.3 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87581 (Use after free in Payments in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87580 (Incorrect authorization in WebAppInstalls in Google Chrome prior to 15 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87579 (Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allo ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87578 (Use after free in Receiver in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87577 (Incorrect authorization in Isolated in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87576 (Uninitialized resource in GPU in Google Chrome on on Android prior to ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87575 (Incorrect authorization in Loader in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87574 (Information leak in ServiceWorker in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87573 (Improper input validation in Network in Google Chrome prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87572 (Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87571 (Improper certificate validation in Loader in Google Chrome prior to 15 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87570 (Incorrect authorization in SiteIsolation in Google Chrome prior to 153 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87569 (Missing authorization in Views in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87568 (Improper input validation in Chromium in Google Chrome prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87567 (UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87566 (Observable discrepancy in Layout in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87565 (Information leak in Passwords in Google Chrome on on Android prior to ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87564 (Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87563 (Origin validation error in Paint in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87562 (Incorrect reference resolution in Accessibility in Google Chrome on on ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87561 (Incorrect authorization in Web Authentication in Google Chrome prior t ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87560 (Missing authorization in Browser in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87559 (UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87558 (Use after free in Payments in Google Chrome on on Mac prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87557 (Missing authorization in LocalNetworkAccess in Google Chrome prior to ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87556 (Missing authorization in Browser in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87555 (Uninitialized resource in GPU in Google Chrome on on Android prior to ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87554 (Race condition in Chromoting in Google Chrome on on Windows prior to 1 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87553 (Improper input validation in SiteIsolation in Google Chrome prior to 1 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87552 (Missing authorization in TrustedWebActivities in Google Chrome on on A ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87551 (Improper certificate validation in CORS in Google Chrome prior to 153. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87550 (Improper encoding or escaping of output in CSS in Google Chrome prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87549 (Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.3 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87548 (Improper state validation in Installer in Google Chrome prior to 153.0 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87547 (Incorrect reference resolution in FileSystem in Google Chrome prior to ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87546 (Incorrect type conversion or cast in Safebrowsing in Google Chrome on ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87545 (Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87544 (Incorrect authorization in Extensions in Google Chrome prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87543 (Missing authorization in Core in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87542 (Use after free in Input in Google Chrome prior to 153.0.8010.36 allowe ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87541 (Information leak in Navigation in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87540 (Incorrect authorization in Isolated in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87539 (Observable discrepancy in Network in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87538 (Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87537 (Missing authorization in Extensions in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87536 (Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87535 (Information loss or omission in Safebrowsing in Google Chrome on on Ma ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87534 (Missing authorization in WebView in Google Chrome on on Android prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87533 (Use after free in DevTools in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87532 (Improper state validation in Safebrowsing in Google Chrome prior to 15 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87531 (Information leak in CORS in Google Chrome prior to 153.0.8010.36 allow ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87530 (Uncontrolled search path element in CredentialProvider in Google Chrom ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87529 (Numeric truncation error in Media in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87528 (Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87527 (Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allow ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87526 (Use after free in Passwords in Google Chrome prior to 153.0.8010.36 al ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87525 (Out of bounds read in Chromoting in Google Chrome on on Windows prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87524 (Use after free in Core in Google Chrome on on Windows prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87523 (Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87522 (Missing authorization in WebView in Google Chrome on on Android prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87521 (Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87520 (Use after free in Dawn in Google Chrome on on Android prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87519 (Incorrect authorization in Safebrowsing in Google Chrome prior to 153. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87518 (Observable discrepancy in Safebrowsing in Google Chrome on on iOS prio ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87517 (Race condition in Mobile in Google Chrome on on iOS prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87516 (Observable discrepancy in Navigation in Google Chrome prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87515 (Incorrect authorization in FileAPI in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87514 (Use after free in Views in Google Chrome prior to 153.0.8010.36 allowe ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87513 (Missing authorization in ControlledFrame in Google Chrome prior to 153 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87512 (Use after free in ANGLE in Google Chrome on on Windows prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87511 (Missing authorization in DevTools in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87510 (Improper input validation in FileAPI in Google Chrome prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87509 (Incorrect authorization in Updater in Google Chrome on on Windows prio ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87508 (Incorrect authorization in Loader in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87507 (UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87506 (Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87505 (Incorrect authorization in FileSystem in Google Chrome prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87504 (Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87503 (Inappropriate implementation in Downloads in Google Chrome on on Andro ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87502 (Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87501 (UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87500 (Improper validation of array index in ANGLE in Google Chrome prior to ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87499 (Incorrect authorization in Network in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87498 (Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87497 (Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87496 (UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.3 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87495 (Information leak in Scroll in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87494 (Use after free in Browser in Google Chrome on on Windows prior to 153. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87493 (Missing authorization in FileSystem in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87492 (Incorrect authorization in DevTools in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87491 (Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allo ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87490 (Information leak in Transactions Platform in Google Chrome prior to 15 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87489 (Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowe ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87488 (Use after free in WebGL in Google Chrome on on Android prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87487 (Missing authorization in FileSystem in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87486 (Clickjacking in TrustedWebActivities in Google Chrome on on Android pr ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87485 (Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.3 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87484 (UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87483 (Incorrect authorization in Browser in Google Chrome on on Android prio ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87482 (Cleartext transmission of sensitive data in HttpsUpgrades in Google Ch ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87481 (Incorrect authorization in WebView in Google Chrome on on Android prio ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87480 (Use after free in Printing in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87479 (Insufficient policy enforcement in Extensions in Google Chrome prior t ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87478 (Observable discrepancy in Autofill in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87477 (Information leak in Core in Google Chrome prior to 153.0.8010.36 allow ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87476 (Incorrect authorization in Loader in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87475 (Missing authorization in Omnibox in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87474 (Use after free in Payments in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87473 (Incorrect authorization in FileHandling in Google Chrome prior to 153. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87472 (Improper input validation in FedCM in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87471 (Incorrect authorization in ServiceWorker in Google Chrome prior to 153 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87470 (Improper quantity validation in Tint in Google Chrome on on Mac prior ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87469 (Improper input validation in Extensions in Google Chrome prior to 153. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87468 (Incorrect authorization in Isolated in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87467 (Race condition in Updater in Google Chrome on on Windows prior to 153. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87466 (Incorrect authorization in Workers in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87465 (Incorrect authorization in Downloads in Google Chrome prior to 153.0.8 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87464 (Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowe ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87463 (Incorrect authorization in Certificate in Google Chrome on on Android ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87462 (UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87461 (Information leak in Core in Google Chrome prior to 153.0.8010.36 allow ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87460 (Use after free in Platform in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87459 (Observable discrepancy in Select in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87458 (UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87457 (Race condition in Updater in Google Chrome on on Windows prior to 153. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87456 (Uninitialized resource in Media in Google Chrome prior to 153.0.8010.3 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87455 (Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87454 (Information leak in Enterprise in Google Chrome on on Windows prior to ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87453 (Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87452 (Incorrect authorization in GPU in Google Chrome on on Mac prior to 153 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87451 (Information leak in Downloads in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87450 (Incorrect authorization in Permissions in Google Chrome prior to 153.0 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87449 (Cross-site request forgery in DeviceBoundSessionCredentials in Google ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87448 (Use after free in DevTools in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87447 (Incorrect authorization in Network in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87446 (Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87445 (UI misrepresentation in Session in Google Chrome prior to 153.0.8010.3 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87444 (Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 al ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87443 (Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87442 (Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 a ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87441 (Missing authorization in Downloads in Google Chrome prior to 153.0.801 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87440 (Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 al ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87439 (Information leak in ServiceWorker in Google Chrome prior to 153.0.8010 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87438 (Out of bounds write in WebGL in Google Chrome on on Android prior to 1 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87437 (Information leak in Frames in Google Chrome prior to 153.0.8010.36 all ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87436 (Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87435 (Information leak in ControlledFrame in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87434 (Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87433 (Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allo ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87432 (Incorrect authorization in Navigation in Google Chrome prior to 153.0. ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87431 (Missing authorization in Extensions in Google Chrome prior to 153.0.80 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87430 (Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allo ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87429 (Missing authorization in ServiceWorker in Google Chrome prior to 153.0 ...)
+ {DSA-6506-1}
- chromium 153.0.8010.47-1
CVE-2026-87088 (Tanium addressed an unauthorized code execution vulnerability in Enfor ...)
NOT-FOR-US: Tanium
@@ -17620,7 +18312,7 @@ CVE-2026-67648 (Use of uninitialized resource in SQL Server allows an authorized
NOT-FOR-US: Microsoft
CVE-2026-67645 (Out-of-bounds read in SQL Server allows an authorized attacker to disc ...)
NOT-FOR-US: Microsoft
-CVE-2026-67643 (Heap-based buffer overflow in SQL Server allows an authorized attacker ...)
+CVE-2026-67643 (Heap-based buffer overflow in SQL Server allows an unauthorized attack ...)
NOT-FOR-US: Microsoft
CVE-2026-67642 (Heap-based buffer overflow in SQL Server allows an authorized attacker ...)
NOT-FOR-US: Microsoft
@@ -17630,11 +18322,11 @@ CVE-2026-67639 (Heap-based buffer overflow in SQL Server allows an authorized at
NOT-FOR-US: Microsoft
CVE-2026-67638 (Heap-based buffer overflow in SQL Server allows an authorized attacker ...)
NOT-FOR-US: Microsoft
-CVE-2026-67636 (Out-of-bounds read in SQL Server allows an authorized attacker to exec ...)
+CVE-2026-67636 (Out-of-bounds read in SQL Server allows an unauthorized attacker to ex ...)
NOT-FOR-US: Microsoft
CVE-2026-67633 (Out-of-bounds read in SQL Server allows an authorized attacker to deny ...)
NOT-FOR-US: Microsoft
-CVE-2026-67631 (Heap-based buffer overflow in SQL Server allows an authorized attacker ...)
+CVE-2026-67631 (Heap-based buffer overflow in SQL Server allows an unauthorized attack ...)
NOT-FOR-US: Microsoft
CVE-2026-67630 (Out-of-bounds read in SQL Server allows an authorized attacker to disc ...)
NOT-FOR-US: Microsoft
@@ -17664,7 +18356,7 @@ CVE-2026-67380 (Heap-based buffer overflow in SQL Server allows an authorized at
NOT-FOR-US: Microsoft
CVE-2026-67379 (Stack-based buffer overflow in SQL Server allows an authorized attacke ...)
NOT-FOR-US: Microsoft
-CVE-2026-67378 (Untrusted pointer dereference in SQL Server allows an authorized attac ...)
+CVE-2026-67378 (Untrusted pointer dereference in SQL Server allows an unauthorized att ...)
NOT-FOR-US: Microsoft
CVE-2026-67376 (Integer overflow or wraparound in SQL Server allows an unauthorized at ...)
NOT-FOR-US: Microsoft
@@ -37292,7 +37984,7 @@ CVE-2020-37267 (Renovate versions >=19.180.0 and <23.25.1, when used with Azure
NOT-FOR-US: Renovate
CVE-2019-25766 (Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository ...)
NOT-FOR-US: Renovate
-CVE-2026-73639
+CVE-2026-73639 (Imager::File::PNG versions from 1.003 before 1.004 for Perl write past ...)
- libimager-perl 1.035+dfsg-1
[trixie] - libimager-perl <no-dsa> (Minor issue)
[bookworm] - libimager-perl <postponed> (Minor issue)
@@ -37300,7 +37992,7 @@ CVE-2026-73639
NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-jhx5-34j8-9g88
NOTE: https://github.com/tonycoz/imager/pull/567
NOTE: Fixed by: https://github.com/tonycoz/imager/commit/d973bd7e8843f084e8071caa24b89545c88b1e4b (v1.035)
-CVE-2026-73638
+CVE-2026-73638 (Imager versions from 0.45_02 before 1.035 for Perl read outside the EX ...)
- libimager-perl 1.035+dfsg-1 (bug #1144226)
[trixie] - libimager-perl <no-dsa> (Minor issue)
[bookworm] - libimager-perl <postponed> (Minor issue)
@@ -78279,7 +78971,7 @@ CVE-2026-60065 (When NGINX Plus is configured to use the Message Queuing Telemet
CVE-2026-60062 (The NGINX Agent config_dirsdirective allows a low-privileged attacker ...)
NOT-FOR-US: F5
CVE-2026-60005 (NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...)
- {DSA-6496-1}
+ {DSA-6496-1 DLA-4784-1}
- nginx 1.30.1-7
NOTE: https://my.f5.com/manage/s/article/K000162100
CVE-2026-59955 (Apollo is a reliable configuration management system suitable for micr ...)
@@ -78354,7 +79046,7 @@ CVE-2026-56699
CVE-2026-56687 (Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Fe ...)
NOT-FOR-US: Dell / EMC
CVE-2026-56434 (NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...)
- {DSA-6496-1}
+ {DSA-6496-1 DLA-4784-1}
- nginx 1.30.1-7
NOTE: https://my.f5.com/manage/s/article/K000162098
CVE-2026-56400 (open-webui before 0.3.14 contains a cross-origin resource sharing misc ...)
@@ -78461,7 +79153,7 @@ CVE-2026-44986 (Penpot is an open-source design tool for design and code collabo
CVE-2026-43637 (Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability ...)
NOT-FOR-US: Cornac
CVE-2026-42533 (A vulnerability exists in NGINX Plus and NGINX Open Source when a mapd ...)
- {DSA-6496-1}
+ {DSA-6496-1 DLA-4784-1}
- nginx 1.30.4-3
NOTE: https://my.f5.com/manage/s/article/K000162097
CVE-2026-41580 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
@@ -98051,7 +98743,7 @@ CVE-2026-12771 (A vulnerability was identified in BerriAI litellm up to 1.82.2.
NOT-FOR-US: LiteLLM
CVE-2026-12770 (A vulnerability was determined in BerriAI litellm up to 1.63.1. The im ...)
NOT-FOR-US: LiteLLM
-CVE-2026-54604
+CVE-2026-54604 (OpenSlide is a C library for reading whole slide image files. Prior to ...)
[experimental] - openslide 4.0.1+dfsg-1~0exp2
- openslide 4.0.1+dfsg-1 (bug #1146705)
[trixie] - openslide <ignored> (Minor issue; only an exploitable issue with behaviour change of libtiff in 4.7.1)
@@ -106945,7 +107637,7 @@ CVE-2026-47895 (In strongSwan before 6.0.7, identity parsing/cloning is mishandl
{DSA-6330-1}
- strongswan 6.0.7-1
NOTE: https://www.strongswan.org/blog/2026/06/08/strongswan-vulnerability-(cve-2026-47895).html
-CVE-2026-48977
+CVE-2026-48977 (OpenSlide is a C library for reading whole slide image files. From 3.4 ...)
- openslide 3.4.1+dfsg-9 (bug #1140003)
[trixie] - openslide 3.4.1+dfsg-7+deb13u1
[bookworm] - openslide 3.4.1+dfsg-6+deb12u1
@@ -626796,8 +627488,8 @@ CVE-2021-3032 (An information exposure through log file vulnerability exists in
NOT-FOR-US: Palo Alto Networks PAN-OS
CVE-2021-3031 (Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, P ...)
NOT-FOR-US: Palo Alto Networks
-CVE-2021-3030
- RESERVED
+CVE-2021-3030 (Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scri ...)
+ TODO: check
CVE-2021-23234
RESERVED
CVE-2021-23135 (Exposure of System Data to an Unauthorized Control Sphere vulnerabilit ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/10fa55d6966a65dda65ff947021a8b742b2a6cea
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/10fa55d6966a65dda65ff947021a8b742b2a6cea
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/fee3d10b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list