[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 22 08:14:08 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d427db2c by security tracker role at 2026-09-22T07:13:59+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,43 +1,551 @@
-CVE-2026-80110
+CVE-2026-94627 (vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV ...)
+ TODO: check
+CVE-2026-94626 (vLLM through 0.29.0 fails to validate the tp_size parameter in kv_tran ...)
+ TODO: check
+CVE-2026-94625 (vLLM through 0.29.0 contains a resource exhaustion vulnerability in Mo ...)
+ TODO: check
+CVE-2026-94624 (vLLM through 0.29.0 contains a denial of service vulnerability in P2P ...)
+ TODO: check
+CVE-2026-94623 (vLLM through 0.29.0 contains a denial of service vulnerability in the ...)
+ TODO: check
+CVE-2026-94622 (vLLM versions through 0.29.0 contain a denial of service vulnerability ...)
+ TODO: check
+CVE-2026-94588 (In Proxmox pmg-api, an argument injection vulnerability exists in the ...)
+ TODO: check
+CVE-2026-94572 (In OpenStack Octavia before 18.0.1, the Amphora provider driver did no ...)
+ TODO: check
+CVE-2026-94571 (In OpenStack Octavia before 18.0.1, the Amphora provider driver did no ...)
+ TODO: check
+CVE-2026-94540 (DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerabil ...)
+ TODO: check
+CVE-2026-94536 (lamp-cloud through 5.10.0 fails to validate the employeeId parameter i ...)
+ TODO: check
+CVE-2026-94535 (lamp-cloud through 5.10.0 contains an authorization bypass vulnerabili ...)
+ TODO: check
+CVE-2026-94534 (lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyo ...)
+ TODO: check
+CVE-2026-94533 (lamp-cloud through 5.10.0 contains an authorization bypass vulnerabili ...)
+ TODO: check
+CVE-2026-94532 (lamp-cloud through 5.10.0 contains an authorization bypass vulnerabili ...)
+ TODO: check
+CVE-2026-94504 (Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and rend ...)
+ TODO: check
+CVE-2026-94501 (jshERP through 3.6 contains an authorization bypass vulnerability in t ...)
+ TODO: check
+CVE-2026-94497 (jshERP through 3.6 fails to validate object ownership in by-id info, u ...)
+ TODO: check
+CVE-2026-94496 (jshERP through 3.6 fails to validate caller permissions in role manage ...)
+ TODO: check
+CVE-2026-94495 (jshERP through 3.6 fails to properly validate user privileges in Syste ...)
+ TODO: check
+CVE-2026-94494 (jshERP through 3.6 contains a tenant isolation bypass vulnerability th ...)
+ TODO: check
+CVE-2026-94493 (A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. ...)
+ TODO: check
+CVE-2026-94492 (A security vulnerability has been detected in Yonyou U8cloud 5.x. This ...)
+ TODO: check
+CVE-2026-94491 (A weakness has been identified in Yonyou KSOA 9.0. This affects an unk ...)
+ TODO: check
+CVE-2026-94490 (A security flaw has been discovered in OctoPrint 1.0.0. Affected by th ...)
+ TODO: check
+CVE-2026-94489 (A vulnerability was identified in OctoPrint 1.0.0. Affected by this vu ...)
+ TODO: check
+CVE-2026-94488 (Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The fi ...)
+ TODO: check
+CVE-2026-94426 (A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The imp ...)
+ TODO: check
+CVE-2026-94425 (A vulnerability was found in Moore Threads MTT S80 Driver Package 340. ...)
+ TODO: check
+CVE-2026-94424 (A vulnerability has been found in Moore Threads MTT S80 Driver Package ...)
+ TODO: check
+CVE-2026-94414 (jshERP through 3.6 is missing an authorization check on the POST /user ...)
+ TODO: check
+CVE-2026-94413 (jshERP through 3.6 fails to redact password hashes in the /user/info e ...)
+ TODO: check
+CVE-2026-94412 (jshERP through 3.6 contains an authorization bypass vulnerability in t ...)
+ TODO: check
+CVE-2026-94411 (jshERP 3.6 contains a privilege escalation vulnerability in the update ...)
+ TODO: check
+CVE-2026-94404 (MISP has a security issue that could let an attacker change threat-int ...)
+ TODO: check
+CVE-2026-94403 (A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This i ...)
+ TODO: check
+CVE-2026-94401 (MISP has a file-handling vulnerability that could let certain authenti ...)
+ TODO: check
+CVE-2026-94394 (When a regular user adds a reference between objects or attributes, MI ...)
+ TODO: check
+CVE-2026-94393 (When a user creates or edits a report inside an event, MISP can identi ...)
+ TODO: check
+CVE-2026-94387 (Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnera ...)
+ TODO: check
+CVE-2026-94383 (The MISP blocklist workflow module accepted a user-supplied blocklist ...)
+ TODO: check
+CVE-2026-94382 (Beszel before 0.19.0 contains an insecure direct object reference vuln ...)
+ TODO: check
+CVE-2026-94381 (MISP has a security issue that can let a user gain more access than th ...)
+ TODO: check
+CVE-2026-94379 (The login() function in MISP's UsersController.php contained insuffici ...)
+ TODO: check
+CVE-2026-94374 (MISP contains an insecure direct object reference vulnerability in the ...)
+ TODO: check
+CVE-2026-94373 (MISP contains a DOM-based cross-site scripting (XSS) vulnerability in ...)
+ TODO: check
+CVE-2026-94372 (MISP contains a stored cross-site scripting (XSS) vulnerability in the ...)
+ TODO: check
+CVE-2026-94277 (MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxy ...)
+ TODO: check
+CVE-2026-94216 (A vulnerability was determined in ST Engineering iDirect Evolution and ...)
+ TODO: check
+CVE-2026-94214 (A vulnerability was found in ST Engineering iDirect Evolution and Velo ...)
+ TODO: check
+CVE-2026-94211 (A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected ...)
+ TODO: check
+CVE-2026-94210 (A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this ...)
+ TODO: check
+CVE-2026-94152 (A security vulnerability has been detected in Omega Solution FBP Fulfi ...)
+ TODO: check
+CVE-2026-94151 (A weakness has been identified in Omega Solution HRM OS up to 20260717 ...)
+ TODO: check
+CVE-2026-94150 (A security flaw has been discovered in Omega Solution HRM OS up to 202 ...)
+ TODO: check
+CVE-2026-94149 (A vulnerability was identified in Omega Solution HRM OS up to 20260717 ...)
+ TODO: check
+CVE-2026-94148 (A vulnerability was determined in ScadaBR up to 1.1. Impacted is the f ...)
+ TODO: check
+CVE-2026-93884
+ REJECTED
+CVE-2026-93655 (The Booking Calendar plugin for WordPress is vulnerable to Reflected C ...)
+ TODO: check
+CVE-2026-93340 (Gladys Assistant before 5.1.0 contains a password reset link poisoning ...)
+ TODO: check
+CVE-2026-93339 (Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a ...)
+ TODO: check
+CVE-2026-92612 (In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exp ...)
+ TODO: check
+CVE-2026-92438 (The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form ...)
+ TODO: check
+CVE-2026-92400 (The Payment Gateway for PayPal on WooCommerce WordPress plugin before ...)
+ TODO: check
+CVE-2026-91921 (Cross-Site Scripting (XSS) vulnerability due to inadequate input sanit ...)
+ TODO: check
+CVE-2026-91867 (When Neethi fetches a remote policy reference, it only limits the time ...)
+ TODO: check
+CVE-2026-91866 (A specially crafted pair of WS-Policy documents can force Neethi's pol ...)
+ TODO: check
+CVE-2026-91865 (A small WS-Policy document using repeated policy references can force ...)
+ TODO: check
+CVE-2026-91864 (A specially crafted WS-Policy document can pack unlimited content insi ...)
+ TODO: check
+CVE-2026-91863 (A specially crafted WS-Policy document with deeply nested policy eleme ...)
+ TODO: check
+CVE-2026-91827 (The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitte ...)
+ TODO: check
+CVE-2026-91167 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
+ TODO: check
+CVE-2026-91166 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
+ TODO: check
+CVE-2026-91165 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
+ TODO: check
+CVE-2026-91164 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
+ TODO: check
+CVE-2026-89412 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
+ TODO: check
+CVE-2026-89139 (Temporal Server compiles a Worker Controller Instance module into its ...)
+ TODO: check
+CVE-2026-88978 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
+ TODO: check
+CVE-2026-88807 (A heap overflow in libXrender before 0.9.13 inRenderQueryPictFormats c ...)
+ TODO: check
+CVE-2026-88806 (A malicious X server could exploit a buffer overflow in libX11 before ...)
+ TODO: check
+CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not sanitise and e ...)
+ TODO: check
+CVE-2026-88756 (Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQ ...)
+ TODO: check
+CVE-2026-88746 (idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/mak ...)
+ TODO: check
+CVE-2026-88745 (EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers t ...)
+ TODO: check
+CVE-2026-88738 (Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upl ...)
+ TODO: check
+CVE-2026-88467 (CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verif ...)
+ TODO: check
+CVE-2026-88412 (An integer overflow in the _BulkInsert_ReadProperty component (/bulk_i ...)
+ TODO: check
+CVE-2026-88411 (Improper error handling in the GRAPH.EFFECT component (/effects/effect ...)
+ TODO: check
+CVE-2026-88410 (The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not reg ...)
+ TODO: check
+CVE-2026-88409 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
+ TODO: check
+CVE-2026-88408 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
+ TODO: check
+CVE-2026-88407 (An out-of-bounds read in the node_token_count/relation_token_count com ...)
+ TODO: check
+CVE-2026-88406 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
+ TODO: check
+CVE-2026-88405 (A remote code execution (RCE) vulnerability in the RemoteRegisterFunct ...)
+ TODO: check
+CVE-2026-88404 (A remote code execution (RCE) vulnerability in the UniscriptExecutionS ...)
+ TODO: check
+CVE-2026-88403 (A Server-Side Request Forgery (SSRF) in the serverRequest function of ...)
+ TODO: check
+CVE-2026-88402 (A SQL injection vulnerability in the checkSQL function of nocobase v2. ...)
+ TODO: check
+CVE-2026-87858 (Temporal Server decided whether a Workflow completion callback was int ...)
+ TODO: check
+CVE-2026-86802 (The To Do List Member WordPress plugin through 1.6 does not have autho ...)
+ TODO: check
+CVE-2026-86473 (Apache Airflow: the Core API logout endpoint revokes only a session to ...)
+ TODO: check
+CVE-2026-85751 (Mailu is a mail server distributed as a set of Docker images. From Mai ...)
+ TODO: check
+CVE-2026-85653 (The Contextual Related Posts plugin for WordPress is vulnerable to Sto ...)
+ TODO: check
+CVE-2026-85220 (A vulnerability in the Thinkst Canary honeypot Redis service allows an ...)
+ TODO: check
+CVE-2026-85219 (Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 ...)
+ TODO: check
+CVE-2026-85113 (The GiveWP WordPress plugin before 4.16.9 does not remove shortcode de ...)
+ TODO: check
+CVE-2026-85010 (The RestroPress WordPress plugin before 3.4.6 does not validate a clie ...)
+ TODO: check
+CVE-2026-84990 (ntopng is a web-based network traffic monitoring application. Prior to ...)
+ TODO: check
+CVE-2026-84298 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
+ TODO: check
+CVE-2026-84285 (An OS Command Injection vulnerability affecting Tuleap Enterprise Edit ...)
+ TODO: check
+CVE-2026-83621 (ntopng is a web-based network traffic monitoring application. Prior to ...)
+ TODO: check
+CVE-2026-82412 (ntopng is a web-based network traffic monitoring application. Prior to ...)
+ TODO: check
+CVE-2026-82355 (When a request to the Airflow core API carries both a session cookie a ...)
+ TODO: check
+CVE-2026-82165 (Dell Command | Integration Suite for System Center, versions prior to ...)
+ TODO: check
+CVE-2026-82163 (Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contai ...)
+ TODO: check
+CVE-2026-81469 (Dell Inventory Collector Client, versions prior to 15.0.0, contain an ...)
+ TODO: check
+CVE-2026-79920 (Ajenti is a Linux & BSD modular server admin panel. Prior to version 2 ...)
+ TODO: check
+CVE-2026-79919 (MaxKB is an open-source AI assistant for enterprise. Prior to version ...)
+ TODO: check
+CVE-2026-79918 (MaxKB is an open-source AI assistant for enterprise. Prior to version ...)
+ TODO: check
+CVE-2026-79917 (MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through ...)
+ TODO: check
+CVE-2026-79916 (MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-l ...)
+ TODO: check
+CVE-2026-79320 (Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vu ...)
+ TODO: check
+CVE-2026-79319 (Stencil core 4.43.5 is vulnerable to Incorrect Access Control.)
+ TODO: check
+CVE-2026-79318 (web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) ...)
+ TODO: check
+CVE-2026-79317 (A session invalidation flaw exists in x-ui 0.3.2. The full user object ...)
+ TODO: check
+CVE-2026-79316 (An improper access control vulnerability exists in x-ui 0.3.2. Any aut ...)
+ TODO: check
+CVE-2026-79079 (An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execu ...)
+ TODO: check
+CVE-2026-78847 (An issue in gray-matter All versions (verified on 4.0.3) allows the Ja ...)
+ TODO: check
+CVE-2026-78806 (An issue in Matter Standard Specification-Implementation gap v1.5.1 Ma ...)
+ TODO: check
+CVE-2026-77582 (Tinyauth is an authentication and authorization server. Prior to 5.1.0 ...)
+ TODO: check
+CVE-2026-77561 (Tinyauth is an authentication and authorization server. Prior to 5.1.0 ...)
+ TODO: check
+CVE-2026-77560 (Tinyauth is an authentication and authorization server. Prior to 5.1.2 ...)
+ TODO: check
+CVE-2026-77525 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
+ TODO: check
+CVE-2026-77523 (MaxKB is an open-source AI assistant for enterprise. In version 2.10.3 ...)
+ TODO: check
+CVE-2026-77522 (MaxKB is an open-source AI assistant for enterprise. In version 2.10.3 ...)
+ TODO: check
+CVE-2026-77521 (MaxKB is an open-source AI assistant for enterprise. Prior to version ...)
+ TODO: check
+CVE-2026-77520 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
+ TODO: check
+CVE-2026-77519 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
+ TODO: check
+CVE-2026-77518 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
+ TODO: check
+CVE-2026-77517 (MaxKB is an open-source AI assistant for enterprise. From version 2.0. ...)
+ TODO: check
+CVE-2026-77516 (MaxKB is an open-source AI assistant for enterprise. From version 2.0. ...)
+ TODO: check
+CVE-2026-77166 (The emoji field in the page emoji update endpoint does not properly va ...)
+ TODO: check
+CVE-2026-77165 (File owners were unable to unlock TYPE_TOKEN locks placed by other use ...)
+ TODO: check
+CVE-2026-77021 (Improper handling of highly compressed data (data amplification) in Ch ...)
+ TODO: check
+CVE-2026-76974 (SAP Fiori Launchpad does not sufficiently validate certain user-contro ...)
+ TODO: check
+CVE-2026-76898 (draw.io is a configurable diagramming and whiteboarding application. P ...)
+ TODO: check
+CVE-2026-75158 (Apache Airflow's `/assets/events` API returned asset events for every ...)
+ TODO: check
+CVE-2026-71543 (OpenBao is an open source identity-based secrets management system. Pr ...)
+ TODO: check
+CVE-2026-69190 (Graylog is a free and open log management platform. From 6.3.0 until 6 ...)
+ TODO: check
+CVE-2026-68919 (GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD do ...)
+ TODO: check
+CVE-2026-67827 (Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9 ...)
+ TODO: check
+CVE-2026-66280
+ REJECTED
+CVE-2026-65980 (Chartbrew is an open-source web application that can connect directly ...)
+ TODO: check
+CVE-2026-65654 (github.com/temporalio/ringpop-go enforces configured LabelOptions limi ...)
+ TODO: check
+CVE-2026-65653 (github.com/temporalio/tchannel-go did not reject TChannel call fragmen ...)
+ TODO: check
+CVE-2026-65652 (github.com/temporalio/tchannel-go did not validate the one-byte checks ...)
+ TODO: check
+CVE-2026-65651 (temporalio/sqlparser accepts SQL containing deeply nested unary expres ...)
+ TODO: check
+CVE-2026-63416 (draw.io is a configurable diagramming and whiteboarding application. P ...)
+ TODO: check
+CVE-2026-63373 (draw.io is a configurable diagramming and whiteboarding application. P ...)
+ TODO: check
+CVE-2026-63342 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
+ TODO: check
+CVE-2026-63334 (draw.io is a configurable diagramming and whiteboarding application. P ...)
+ TODO: check
+CVE-2026-63330 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
+ TODO: check
+CVE-2026-63329 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
+ TODO: check
+CVE-2026-63116 (deepstream is a server that allows clients and backend services to syn ...)
+ TODO: check
+CVE-2026-62987 (Fabio is an HTTP(S) and TCP router for deploying applications managed ...)
+ TODO: check
+CVE-2026-62866 (Dasel is a command-line tool and library for querying, modifying, and ...)
+ TODO: check
+CVE-2026-62371 (KubeEdge is an open source system for extending native containerized a ...)
+ TODO: check
+CVE-2026-62370 (KubeEdge is an open source system for extending native containerized a ...)
+ TODO: check
+CVE-2026-62369 (KubeEdge is an open source system for extending native containerized a ...)
+ TODO: check
+CVE-2026-62247 (Supabase Realtime provides Broadcast, Presence, and Postgres Changes v ...)
+ TODO: check
+CVE-2026-62182 (KubeEdge is an open source system for extending native containerized a ...)
+ TODO: check
+CVE-2026-61852 (Chartbrew is an open-source web application that can connect directly ...)
+ TODO: check
+CVE-2026-61851 (Chartbrew is an open-source web application that can connect directly ...)
+ TODO: check
+CVE-2026-61749 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
+ TODO: check
+CVE-2026-61748 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
+ TODO: check
+CVE-2026-61747 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
+ TODO: check
+CVE-2026-61746 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
+ TODO: check
+CVE-2026-61745 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
+ TODO: check
+CVE-2026-61744 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
+ TODO: check
+CVE-2026-61743 (Chartbrew is an open-source web application that can connect directly ...)
+ TODO: check
+CVE-2026-61687 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
+ TODO: check
+CVE-2026-61681 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
+ TODO: check
+CVE-2026-61674 (Fluent Bit is a fast and lightweight logs, metrics, and traces process ...)
+ TODO: check
+CVE-2026-61652 (Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to ...)
+ TODO: check
+CVE-2026-61647 (NotebookLM MCP is an MCP server and HTTP service for interacting with ...)
+ TODO: check
+CVE-2026-61630 (nginx ignition is a user interface for the nginx web server. In versio ...)
+ TODO: check
+CVE-2026-61629 (nginx ignition is a user interface for the nginx web server. In versio ...)
+ TODO: check
+CVE-2026-61628 (nginx ignition is a user interface for the nginx web server. Prior to ...)
+ TODO: check
+CVE-2026-61612 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
+ TODO: check
+CVE-2026-61541 (Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to ...)
+ TODO: check
+CVE-2026-59830 (Discourse is an open-source discussion platform. Prior to 2026.7.0, th ...)
+ TODO: check
+CVE-2026-59816 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-59815 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-59814 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-59168 (Dasel is a command-line tool and library for querying, modifying, and ...)
+ TODO: check
+CVE-2026-58504 (draw.io is a configurable diagramming and whiteboarding application. P ...)
+ TODO: check
+CVE-2026-58491 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
+ TODO: check
+CVE-2026-58272 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
+ TODO: check
+CVE-2026-58271 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
+ TODO: check
+CVE-2026-58270 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
+ TODO: check
+CVE-2026-58269 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
+ TODO: check
+CVE-2026-55897 (luci-app-advanced-reboot is a LuCI (web interface) application for Ope ...)
+ TODO: check
+CVE-2026-55870 (GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return ...)
+ TODO: check
+CVE-2026-55625 (GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the int ...)
+ TODO: check
+CVE-2026-55567 (BleachBit cleans files to free disk space and to maintain privacy. Pri ...)
+ TODO: check
+CVE-2026-55563 (Feast is the open source feature store for AI and machine learning. Pr ...)
+ TODO: check
+CVE-2026-55473 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
+ TODO: check
+CVE-2026-55210 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-55179 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-55159 (luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-block ...)
+ TODO: check
+CVE-2026-55105 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-55074 (Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin ...)
+ TODO: check
+CVE-2026-55071 (MCP-for-Stata is a MCP server for integrating Stata into agent loops w ...)
+ TODO: check
+CVE-2026-55060 (GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go ...)
+ TODO: check
+CVE-2026-54915 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
+ TODO: check
+CVE-2026-54584 (mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPD ...)
+ TODO: check
+CVE-2026-53940 (Conda is a system-level binary package and environment manager that ru ...)
+ TODO: check
+CVE-2026-52835 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
+ TODO: check
+CVE-2026-52743 (GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoC ...)
+ TODO: check
+CVE-2026-52742 (GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy ...)
+ TODO: check
+CVE-2026-52741 (GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD ca ...)
+ TODO: check
+CVE-2026-52740 (GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get ...)
+ TODO: check
+CVE-2026-49995 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
+ TODO: check
+CVE-2026-49811 (Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an In ...)
+ TODO: check
+CVE-2026-49810 (Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 cont ...)
+ TODO: check
+CVE-2026-49453 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-49450 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-49449 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-48976 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
+ TODO: check
+CVE-2026-48975 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
+ TODO: check
+CVE-2026-48974 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
+ TODO: check
+CVE-2026-48826 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
+ TODO: check
+CVE-2026-46650 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-46649 (Joplin is an open source note-taking and to-do application that organi ...)
+ TODO: check
+CVE-2026-45381 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
+ TODO: check
+CVE-2026-36472 (CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper ...)
+ TODO: check
+CVE-2026-36471 (Deserialization of Untrusted Data of the __post_data parameter in cn_p ...)
+ TODO: check
+CVE-2026-36470 (CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index. ...)
+ TODO: check
+CVE-2026-36469 (CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) i ...)
+ TODO: check
+CVE-2026-36468 (Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows rem ...)
+ TODO: check
+CVE-2026-36467 (Unrestricted Upload of File with Dangerous Type in core/modules/media. ...)
+ TODO: check
+CVE-2026-19658 (The Give Tributes plugin for WordPress is vulnerable to PHP Object Inj ...)
+ TODO: check
+CVE-2026-17054 (The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parse ...)
+ TODO: check
+CVE-2026-17052 (The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read ...)
+ TODO: check
+CVE-2026-17051 (The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm ...)
+ TODO: check
+CVE-2026-17050 (The experimental USB host stack allocates a per-device configuration-d ...)
+ TODO: check
+CVE-2026-16652 (Temporal Server did not bound the work performed while searching for a ...)
+ TODO: check
+CVE-2026-16651 (temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNex ...)
+ TODO: check
+CVE-2026-15890 (The default AEAD nonce provider for the PSA Internal Trusted Storage t ...)
+ TODO: check
+CVE-2026-13355 (The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escal ...)
+ TODO: check
+CVE-2026-12470 (The CMP \u2013 Coming Soon & Maintenance Plugin by NiteoThemes plugin ...)
+ TODO: check
+CVE-2025-71421 (UVdesk core-framework before 1.1.7 contains an improper privilege mana ...)
+ TODO: check
+CVE-2025-71420 (UVdesk core-framework before 1.1.7 contains an authorization bypass vu ...)
+ TODO: check
+CVE-2025-71419 (UVdesk core-framework before 1.1.7 contains a stored cross-site script ...)
+ TODO: check
+CVE-2025-12999 (UrlUtil.getBaseUrl builds the absolute URLs in a response \u2014 downl ...)
+ TODO: check
+CVE-2026-80110 (A flaw was found in pki-core. The v2 REST ACL filter selects a tie-bre ...)
- dogtag-pki <removed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523749
-CVE-2026-92574
+CVE-2026-92574 (A vulnerability in CRI-O checkpoint restore allows a user who can crea ...)
- cri-o <itp> (bug #979702)
-CVE-2026-75939
+CVE-2026-75939 (A flaw was found in openshift/oc-mirror. The tool incorrectly verifies ...)
NOT-FOR-US: openshift/oc-mirror
-CVE-2026-93433
+CVE-2026-93433 (A flaw was found in libstoragemgmt. An attacker with control over a lo ...)
NOT-FOR-US: libstoragemgmt
-CVE-2026-94184
+CVE-2026-94184 (A stack-based buffer overflow flaw was found in fetchmail when built w ...)
- fetchmail <unfixed>
NOTE: https://www.fetchmail.info/fetchmail-SA-2026-01.txt
NOTE: Fixed by: https://gitlab.com/fetchmail/fetchmail/-/commit/cb5be5c38471eec19e519ace0bc569176317ea92 (6.6.7.rc1)
-CVE-2026-94449
+CVE-2026-94449 (A flaw was found in the SmallRye Fault Tolerance library, which is use ...)
NOT-FOR-US: Quarkus
-CVE-2026-94368
+CVE-2026-94368 (A flaw was found in the signature verification logic of noobaa-core, t ...)
NOT-FOR-US: noobaa
CVE-2026-94640
- rpcbind <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462960
-CVE-2026-15801
+CVE-2026-15801 (A vulnerability was found in CRI-O related to the container checkpoint ...)
- cri-o <itp> (bug #979702)
-CVE-2026-93712
+CVE-2026-93712 (Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from out ...)
- libdancer2-perl <unfixed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742973/
NOTE: https://github.com/PerlDancer/Dancer2/security/advisories/GHSA-6xw8-v24c-m783
NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/2446a09ffb83fef71cc75c327bd6e4b1f007b885 (v2.2.0)
-CVE-2026-93711
+CVE-2026-93711 (Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from res ...)
- libdancer2-perl <unfixed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742971/
NOTE: https://github.com/PerlDancer/Dancer2/issues/1822
NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/ff89ac12af7b8899812a79e9924dfea7a5d9833b (v2.2.0)
-CVE-2026-93710
+CVE-2026-93710 (Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route tha ...)
- libdancer2-perl <unfixed>
[trixie] - libdancer2-perl <not-affected> (Vulnerable code introduced later in 2.0.0)
[bookworm] - libdancer2-perl <not-affected> (Vulnerable code introduced later in 2.0.0)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742969/
NOTE: https://github.com/PerlDancer/Dancer2/security/advisories/GHSA-v527-r4px-7vx7
NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/8fd31a32798f9aa25e4fccbd6c7cb9dd3a0c1029 (v2.2.0)
-CVE-2026-93709
+CVE-2026-93709 (Dancer2 versions before 2.2.0 for Perl serve a layout as a page when a ...)
- libdancer2-perl <unfixed> (unimportant)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742968/
NOTE: https://github.com/PerlDancer/Dancer2/issues/1823
@@ -59,7 +567,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0293]
[trixie] - rust-ringbuf <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0293.html
NOTE: https://github.com/agerasev/ringbuf/pull/60
-CVE-2026-93012
+CVE-2026-93012 (Email::Sender::Transport::Sendmail versions before 2.602 for Perl allo ...)
- libemail-sender-perl <not-affected> (Only affects Email::Sender on Windows)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43733017/
NOTE: Fixed by: https://github.com/rjbs/Email-Sender/commit/9a587bc9ff4edae13239190c2651da2c76b1e72c (2.602)
@@ -152,7 +660,7 @@ CVE-2026-90839
REJECTED
CVE-2026-82187 (The Web to Print Online Designer WordPress plugin before 2.15.0 does n ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-92382 [usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write]
+CVE-2026-92382 (An out-of-bounds write flaw was found in usbredir. Starting an isochro ...)
- usbredir <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2535972
TODO: check details once Red Hat opens up bugzilla entry
@@ -1154,7 +1662,7 @@ CVE-2026-92745 (A flaw was found in cockpit-machines. This vulnerability allows
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2476266
CVE-2026-92702 (Cocos AI is a confidential computing system for running AI workloads i ...)
NOT-FOR-US: Cocos AI
-CVE-2026-92701 (trusted execution environments. In versions up to and including 0.8.2, ...)
+CVE-2026-92701 (Cocos AI is a confidential computing system for running AI workloads i ...)
NOT-FOR-US: Cocos AI
CVE-2026-92622 (The Strong Testimonials plugin for WordPress is vulnerable to Stored C ...)
NOT-FOR-US: WordPress plugin
@@ -1313,7 +1821,8 @@ CVE-2026-77607 (Semantic MediaWiki is a free, open-source extension to MediaWiki
NOT-FOR-US: Semantic MediaWiki MediaWiki extension
CVE-2026-77606 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
NOT-FOR-US: Semantic MediaWiki MediaWiki extension
-CVE-2026-77568 (Mojolicious is a real-time web framework for Perl. Prior to 9.48, the ...)
+CVE-2026-77568
+ REJECTED
TODO: check, duplicate of CVE-2026-15747, CNAs contacted to resolve issue
CVE-2026-77396 (PJSIP is a free and open source multimedia communication library writt ...)
- pjproject <removed>
@@ -1362,7 +1871,8 @@ CVE-2026-71537 (Paymenter is a free and open-source webshop solution for managem
NOT-FOR-US: Paymenter
CVE-2026-6205 (An external control of file name or path vulnerability in Upload API i ...)
NOT-FOR-US: Synology
-CVE-2026-68914 (Mojolicious is a real-time web framework for Perl. Prior to 9.47, the ...)
+CVE-2026-68914
+ REJECTED
TODO: check, duplicate of CVE-2026-14803, CNAs contacted to resolve issue
CVE-2026-67549 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
- openimageio <not-affected> (Vulnerable code introduced later)
@@ -15659,7 +16169,7 @@ CVE-2026-81800 (Unauthenticated SQL Injection in Verified Reviews (Avis V\xe9rif
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81799 (Unauthenticated Broken Access Control in Return Refund and Exchange Fo ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-81796 (Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.)
+CVE-2026-81796 (Authentication Bypass Using an Alternate Path or Channel vulnerability ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81795 (Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter R ...)
NOT-FOR-US: WordPress plugin or theme
@@ -18574,7 +19084,8 @@ CVE-2026-81352 (Heap-based buffer overflow in Microsoft Windows Codecs Library a
NOT-FOR-US: Microsoft
CVE-2026-81349 (Improper neutralization of special elements used in an os command ('os ...)
NOT-FOR-US: Microsoft
-CVE-2026-80219 (A flaw was found in hawtio-operator. When deploying Hawtio in cluster ...)
+CVE-2026-80219
+ REJECTED
NOT-FOR-US: hawtio-operator
CVE-2026-80097 (Improper authentication in Microsoft Authenticator allows an unauthori ...)
NOT-FOR-US: Microsoft
@@ -18710,7 +19221,7 @@ CVE-2026-78512 (Numeric truncation error in Microsoft Office Word allows an unau
NOT-FOR-US: Microsoft
CVE-2026-78511 (Heap-based buffer overflow in Microsoft Office Word allows an unauthor ...)
NOT-FOR-US: Microsoft
-CVE-2026-78510 (Heap-based buffer overflow in Microsoft Office Word allows an unauthor ...)
+CVE-2026-78510 (Heap-based buffer overflow in Microsoft Office allows an unauthorized ...)
NOT-FOR-US: Microsoft
CVE-2026-78509 (Heap-based buffer overflow in Microsoft Office Outlook allows an unaut ...)
NOT-FOR-US: Microsoft
@@ -25978,31 +26489,31 @@ CVE-2026-19625 (When a Quarkus application has multiple endpoints secured by ind
NOT-FOR-US: Quarkus OIDC
CVE-2026-19651 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 thro ...)
NOT-FOR-US: Quarkus
-CVE-2026-48521
+CVE-2026-48521 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-50572
+CVE-2026-50572 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73511
+CVE-2026-73511 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73512
+CVE-2026-73512 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73513
+CVE-2026-73513 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73546
+CVE-2026-73546 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73547
+CVE-2026-73547 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73548
+CVE-2026-73548 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73549
+CVE-2026-73549 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73550
+CVE-2026-73550 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73551
+CVE-2026-73551 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73552
+CVE-2026-73552 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
-CVE-2026-73553
+CVE-2026-73553 (Envoy is an open source edge and service proxy designed for cloud-nati ...)
- envoyproxy <itp> (bug #987544)
CVE-2026-16658
- ansible <unfixed> (bug #1146701)
@@ -35792,7 +36303,7 @@ CVE-2026-34491 (Improper neutralization of input during web page generation ('cr
NOT-FOR-US: Johnson Controls
CVE-2026-32558 (Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Prog ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-32551 (Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.)
+CVE-2026-32551 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-32478 (Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.)
NOT-FOR-US: WordPress plugin or theme
@@ -71547,7 +72058,7 @@ CVE-2026-65494 (Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65493 (Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-65492 (Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versi ...)
+CVE-2026-65492 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65491 (Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.)
NOT-FOR-US: WordPress plugin or theme
@@ -112837,7 +113348,7 @@ CVE-2026-47325 (ProjectsAndPrograms school-management-systemuses predictable cre
NOT-FOR-US: ProjectsAndPrograms school-management-system
CVE-2026-47324 (ProjectsAndPrograms school-management-system is vulnerable to Stored C ...)
NOT-FOR-US: ProjectsAndPrograms school-management-system
-CVE-2026-47321
+CVE-2026-47321 (The CompressionFilter class uses ZLib to deflate and inflate data sent ...)
- mina2 2.2.9-1 (bug #1139162)
[trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <no-dsa> (Minor issue)
@@ -112846,7 +113357,7 @@ CVE-2026-47321
[bookworm] - mina <no-dsa> (Minor issue)
[bullseye] - mina <postponed> (Minor issue)
NOTE: https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj
-CVE-2026-94301
+CVE-2026-94301 (The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridde ...)
NOTE: CVE exists because fix for CVE-2026-47065 was only applied to 2.2.x branch
NOTE: while intended to be applied as well to 2.0.x and 2.1.x branches.
NOTE: https://lists.apache.org/thread/rzos6zds5x7obl8trkvznt1djw4f996p
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d427db2c602ee7a36fd9e6de1776036c7c84db40
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d427db2c602ee7a36fd9e6de1776036c7c84db40
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/9d7975c9/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list