[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 22 20:15:03 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2c6fefa8 by security tracker role at 2026-09-22T19:14:52+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,51 +1,669 @@
-CVE-2026-95831
+CVE-2026-9231 (The WP Travel Engine \u2013 Tour Booking Plugin \u2013 Tour Operator S ...)
+ TODO: check
+CVE-2026-9004 (The WP-CRM System \u2013 Manage Clients and Projects plugin for WordPr ...)
+ TODO: check
+CVE-2026-95862 (A malicious actor with access to the network could exploit an Out-of-b ...)
+ TODO: check
+CVE-2026-95861 (A malicious actor with access to the network could exploit an Uncontro ...)
+ TODO: check
+CVE-2026-95806 (MISP ships with PHP's phar stream wrapper registered in both its web e ...)
+ TODO: check
+CVE-2026-95805 (A typo in the MISP ACLComponent access control configuration caused th ...)
+ TODO: check
+CVE-2026-95754 (In MISP's UsersController login() method, the pre-authentication datab ...)
+ TODO: check
+CVE-2026-95703 (In MISP, the OrganisationsController::__uploadLogo method processed a ...)
+ TODO: check
+CVE-2026-95701 (In MISP, the __statisticsOrgs method in UsersController.php used the o ...)
+ TODO: check
+CVE-2026-95698 (The findOrgImage method in MISP's OrgImgHelper constructs a filesystem ...)
+ TODO: check
+CVE-2026-95697 (MISP contains an authorization flaw in the Organisation model's captur ...)
+ TODO: check
+CVE-2026-95693 (In MISP, the EventReport::uploadPicture method in processed a caller-s ...)
+ TODO: check
+CVE-2026-95685 (MISP contains an access control flaw in the EventReports functionality ...)
+ TODO: check
+CVE-2026-95683 (In MISP, the Overmind event view enriches an event with its most recen ...)
+ TODO: check
+CVE-2026-95682 (MISP contains a stored cross-site scripting (XSS) vulnerability in the ...)
+ TODO: check
+CVE-2026-95679 (MISP's RequestHandlerComponent automatically decodes XML request bodie ...)
+ TODO: check
+CVE-2026-95675 (D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthen ...)
+ TODO: check
+CVE-2026-95674 (In MISP, the queryEnrichment method in EventsController.php accepted a ...)
+ TODO: check
+CVE-2026-95671 (In MISP, the CollectionsController add() method enforced the sharing-g ...)
+ TODO: check
+CVE-2026-95667 (The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, an ...)
+ TODO: check
+CVE-2026-95666 (Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7 ...)
+ TODO: check
+CVE-2026-95665 (MISP contains a reflected cross-site scripting (XSS) vulnerability in ...)
+ TODO: check
+CVE-2026-95661 (MISP contains a reflected cross-site scripting (XSS) vulnerability in ...)
+ TODO: check
+CVE-2026-95660 (A security flaw has been discovered in Moonshot AI Kimi Code up to 0.3 ...)
+ TODO: check
+CVE-2026-95659 (MISP contains a reflected cross-site scripting (XSS) vulnerability in ...)
+ TODO: check
+CVE-2026-95658 (MISP's WorkflowsController exposed the moduleStatelessExecution action ...)
+ TODO: check
+CVE-2026-95657 (A vulnerability was determined in dgtlmoon Changedetection.io up to 0. ...)
+ TODO: check
+CVE-2026-95656 (A vulnerability was found in dgtlmoon changedetection.io up to 50389b0 ...)
+ TODO: check
+CVE-2026-95655 (Aureus ERP before 1.5.0 fails to scope message lookups to the current ...)
+ TODO: check
+CVE-2026-95654 (Databasement before 1.7.14 validates invitation tokens only when the a ...)
+ TODO: check
+CVE-2026-95653 (Concrete CMS Community Store before 2.7.8 derives digital product down ...)
+ TODO: check
+CVE-2026-95624 (The Tauri updater plugin's 'check' IPC command accepts an allowDowngra ...)
+ TODO: check
+CVE-2026-95623 (The Tauri HTTP plugin validates requested URLs against the application ...)
+ TODO: check
+CVE-2026-95619 (A flaw was found in libstdc++. An integer overflow can occur when proc ...)
+ TODO: check
+CVE-2026-95511
+ REJECTED
+CVE-2026-95508 (A heap-based buffer overflow was found in the DHCPv6 and TFTP response ...)
+ TODO: check
+CVE-2026-95503 (A flaw was found in the Kerberos federation provider of Keycloak, an o ...)
+ TODO: check
+CVE-2026-95501 (A vulnerability was found in mtrano APENCMS up to 6546096d354153309693 ...)
+ TODO: check
+CVE-2026-95500 (A vulnerability has been found in JosephChuks php-file-manager-with-co ...)
+ TODO: check
+CVE-2026-95499 (A flaw has been found in JosephChuks php-file-manager-with-code-editor ...)
+ TODO: check
+CVE-2026-95396 (A vulnerability was identified in sfturing hosp_order up to 627f426331 ...)
+ TODO: check
+CVE-2026-95273 (A vulnerability was determined in dgtlmoon changedetection.io up to 0. ...)
+ TODO: check
+CVE-2026-95272 (A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. ...)
+ TODO: check
+CVE-2026-95271 (A vulnerability has been found in dgtlmoon changedetection.io up to 0. ...)
+ TODO: check
+CVE-2026-95270 (A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The ...)
+ TODO: check
+CVE-2026-94570 (SGLang contains a DoS vulnerability caused by missing input validation ...)
+ TODO: check
+CVE-2026-94462 (Spree is an open source e-commerce solution built with Ruby on Rails. ...)
+ TODO: check
+CVE-2026-94456 (Postiz generates security-sensitive credentials using `Math.random()` ...)
+ TODO: check
+CVE-2026-94455 (An HTTP endpoint intended for provisioning enterprise and reseller org ...)
+ TODO: check
+CVE-2026-94384 (Missing authorization in Amazon amazon-connect-salesforce-lambda befor ...)
+ TODO: check
+CVE-2026-94127 (When a BIG-IP APM access policy and an OAuth profile is configured on ...)
+ TODO: check
+CVE-2026-94117 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
+ TODO: check
+CVE-2026-93952 (VeloCloud Orchestrator (VCO) on-prem has a security issue where this i ...)
+ TODO: check
+CVE-2026-93928 (Authentication Bypass Using an Alternate Path or Channel vulnerability ...)
+ TODO: check
+CVE-2026-93836 (The WPC Product Bundles for WooCommerce plugin for WordPress is vulner ...)
+ TODO: check
+CVE-2026-93778 (The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored ...)
+ TODO: check
+CVE-2026-93616 (A directory traversal and file upload vulnerability allows an unauthen ...)
+ TODO: check
+CVE-2026-93556 (The \u2018/password/guardarClau/recover\u2019 endpoint accepts the \u2 ...)
+ TODO: check
+CVE-2026-93345 (MikroTik RouterOS before 7.25beta4 contains an improper input validati ...)
+ TODO: check
+CVE-2026-93344 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
+ TODO: check
+CVE-2026-93343 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
+ TODO: check
+CVE-2026-93342 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
+ TODO: check
+CVE-2026-93341 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
+ TODO: check
+CVE-2026-93088 (SGLang's multimodal generation runtime is vulnerable to unauthenticate ...)
+ TODO: check
+CVE-2026-92969 (The HUSKY \u2013 Products Filter for WooCommerce Professional plugin f ...)
+ TODO: check
+CVE-2026-92882 (Insufficiently protected credentials in the host and folder configurat ...)
+ TODO: check
+CVE-2026-92706 (Dark Reader is an accessibility browser extension that makes web pages ...)
+ TODO: check
+CVE-2026-92235 (The The WP Ultimate Review plugin for WordPress is vulnerable to arbit ...)
+ TODO: check
+CVE-2026-91130 (Home Assistant is open source home automation software focused on loca ...)
+ TODO: check
+CVE-2026-91129 (Home Assistant is open source home automation software focused on loca ...)
+ TODO: check
+CVE-2026-91092 (The wpForo Forum plugin for WordPress is vulnerable to authorization b ...)
+ TODO: check
+CVE-2026-90990 (Improper neutralization of newlines in filter values in the monitoring ...)
+ TODO: check
+CVE-2026-90882 (The open-vsx.org deployment returned Access-Control-Allow-Origin refle ...)
+ TODO: check
+CVE-2026-90462 (A flaw was found in SSSD. When configured with the LDAP access provide ...)
+ TODO: check
+CVE-2026-8849 (Use After Free vulnerability in RTI Connext Professional (Security Plu ...)
+ TODO: check
+CVE-2026-89422 (Key Exchange without Entity Authentication vulnerability in Erlang/OTP ...)
+ TODO: check
+CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
+ TODO: check
+CVE-2026-89407 (NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-valid ...)
+ TODO: check
+CVE-2026-89277 (CAI Content Credentials is affected by an Integer Overflow or Wraparou ...)
+ TODO: check
+CVE-2026-89276 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
+ TODO: check
+CVE-2026-89275 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
+ TODO: check
+CVE-2026-88415 (MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting ...)
+ TODO: check
+CVE-2026-88414 (MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the ...)
+ TODO: check
+CVE-2026-88010 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
+ TODO: check
+CVE-2026-87902 (An unauthenticated attacker can make `get_page_template()` page-templa ...)
+ TODO: check
+CVE-2026-87119 (Authentication Bypass by Capture-replay in ZenHive mpp allows an attac ...)
+ TODO: check
+CVE-2026-86698 (Insufficient Session Expiration vulnerability in OAuth token issuance ...)
+ TODO: check
+CVE-2026-86062 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
+ TODO: check
+CVE-2026-86059 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
+ TODO: check
+CVE-2026-86056 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
+ TODO: check
+CVE-2026-86054 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
+ TODO: check
+CVE-2026-85995 (Notepad++ is a free and open-source source code editor. From 8.9.7 unt ...)
+ TODO: check
+CVE-2026-85740 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
+ TODO: check
+CVE-2026-85734 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
+ TODO: check
+CVE-2026-85725 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
+ TODO: check
+CVE-2026-85709 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
+ TODO: check
+CVE-2026-85288 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
+ TODO: check
+CVE-2026-85279 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
+ TODO: check
+CVE-2026-85055 (Twenty is an open-source CRM (customer relationship management) platfo ...)
+ TODO: check
+CVE-2026-84412 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
+ TODO: check
+CVE-2026-84396 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
+ TODO: check
+CVE-2026-84395 (Premiere Pro [NEEDS REVIEW: environment mismatch \u2014 product 'Premi ...)
+ TODO: check
+CVE-2026-84388 (A improper restriction of rendered ui layers or frames vulnerability i ...)
+ TODO: check
+CVE-2026-84301 (FastGPT is an open-source LLM platform for building AI applications on ...)
+ TODO: check
+CVE-2026-83964 (Adobe Connect is affected by an Improper Certificate Validation vulner ...)
+ TODO: check
+CVE-2026-83963 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
+ TODO: check
+CVE-2026-83962 (Substance3D - Modeler is affected by a Stack-based Buffer Overflow vul ...)
+ TODO: check
+CVE-2026-83803 (Sentry is an error tracking and performance monitoring tool. From 23.1 ...)
+ TODO: check
+CVE-2026-83660 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
+ TODO: check
+CVE-2026-83603 (Netdata is an open source observability tool. Prior to 2.10.4, the set ...)
+ TODO: check
+CVE-2026-83602 (Netdata is an open source observability tool. From 2.0.0 until 2.11.0, ...)
+ TODO: check
+CVE-2026-83601 (Netdata is an open source observability tool. Prior to 2.10.4, an auth ...)
+ TODO: check
+CVE-2026-83600 (Netdata is an open source observability tool. Prior to 2.10.4, an auth ...)
+ TODO: check
+CVE-2026-83599 (Netdata is an open source observability tool. Prior to 2.11.0, Netdata ...)
+ TODO: check
+CVE-2026-83598 (Netdata is an open source observability tool. From rom 2.0.0 until 2.1 ...)
+ TODO: check
+CVE-2026-83597 (Netdata is an open source observability tool. From version 2.0.0 until ...)
+ TODO: check
+CVE-2026-82443 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
+ TODO: check
+CVE-2026-82013 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
+ TODO: check
+CVE-2026-82011 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
+ TODO: check
+CVE-2026-82010 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
+ TODO: check
+CVE-2026-82009 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
+ TODO: check
+CVE-2026-82008 (Adobe Campaign Classic (ACC) is affected by an Improper Input Validati ...)
+ TODO: check
+CVE-2026-82003 (Adobe Campaign Classic (ACC) is affected by an Improper Input Validati ...)
+ TODO: check
+CVE-2026-82000 (Adobe Experience Manager Forms JEE is affected by a Server-Side Reques ...)
+ TODO: check
+CVE-2026-81999 (Adobe Experience Manager Forms JEE is affected by a Server-Side Reques ...)
+ TODO: check
+CVE-2026-81998 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
+ TODO: check
+CVE-2026-81995 (Adobe Experience Manager Forms JEE is affected by an Improper Input Va ...)
+ TODO: check
+CVE-2026-81886 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
+ TODO: check
+CVE-2026-81885 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
+ TODO: check
+CVE-2026-81884 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
+ TODO: check
+CVE-2026-81883 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
+ TODO: check
+CVE-2026-81882 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
+ TODO: check
+CVE-2026-81881 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
+ TODO: check
+CVE-2026-81880 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
+ TODO: check
+CVE-2026-81879 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
+ TODO: check
+CVE-2026-81878 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
+ TODO: check
+CVE-2026-80156 (Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80155 (Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80154 (All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, ...)
+ TODO: check
+CVE-2026-80152 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80151 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80150 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80149 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80148 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80147 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80146 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80145 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80144 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-80143 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
+ TODO: check
+CVE-2026-7866 (Stack-based Buffer Overflow vulnerability in RTI Connext Professional ...)
+ TODO: check
+CVE-2026-7622 (The ThumbPress plugin for WordPress is vulnerable to unauthorized acce ...)
+ TODO: check
+CVE-2026-79913 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
+ TODO: check
+CVE-2026-79906 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
+ TODO: check
+CVE-2026-79315 (A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. T ...)
+ TODO: check
+CVE-2026-79314 (A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. ...)
+ TODO: check
+CVE-2026-79313 (webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. Th ...)
+ TODO: check
+CVE-2026-79312 (webpy web.py 0.76 is vulnerable to Session Fixation. The component Ses ...)
+ TODO: check
+CVE-2026-79311 (webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via rend ...)
+ TODO: check
+CVE-2026-77637 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
+ TODO: check
+CVE-2026-77633 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
+ TODO: check
+CVE-2026-77621 (Vector is a high-performance observability data pipeline. From 0.10.0 ...)
+ TODO: check
+CVE-2026-77620 (Vector is a high-performance observability data pipeline. From 0.15.0 ...)
+ TODO: check
+CVE-2026-77619 (Vector is a high-performance observability data pipeline. From 0.15.0 ...)
+ TODO: check
+CVE-2026-77605 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
+ TODO: check
+CVE-2026-77558 (A malicious actor with access to the network could exploit an Out-of-b ...)
+ TODO: check
+CVE-2026-77556 (A malicious actor with access to the network could exploit an Out-of-b ...)
+ TODO: check
+CVE-2026-77555 (A malicious actor with access to the network could exploit an Out-of-b ...)
+ TODO: check
+CVE-2026-77544 (A malicious actor with access to the network could exploit an Out-of-b ...)
+ TODO: check
+CVE-2026-77399 (icalendar is an RFC 5545 compatible parser and generator of iCalendar ...)
+ TODO: check
+CVE-2026-77274 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77272 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77271 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77270 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77269 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77268 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77267 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77266 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77265 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77262 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77261 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77260 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77259 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77258 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77257 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77256 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77255 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77254 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77253 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77252 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77251 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77250 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77249 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77248 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77247 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77246 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77244 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77243 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-77242 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
+ TODO: check
+CVE-2026-76819
+ REJECTED
+CVE-2026-76805 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
+ TODO: check
+CVE-2026-76804 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
+ TODO: check
+CVE-2026-76803 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
+ TODO: check
+CVE-2026-76802 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
+ TODO: check
+CVE-2026-76194 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
+ TODO: check
+CVE-2026-76192 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
+ TODO: check
+CVE-2026-75791 (Zohocorp ManageEngine ADSelfService Plus versions before build 7001 ar ...)
+ TODO: check
+CVE-2026-75745 (Adobe Experience Manager Forms JEE is affected by an Incorrect Authori ...)
+ TODO: check
+CVE-2026-75744 (Adobe Experience Manager Forms JEE is affected by a stored Cross-Site ...)
+ TODO: check
+CVE-2026-75743 (Adobe Experience Manager Forms JEE is affected by a Cross-Site Request ...)
+ TODO: check
+CVE-2026-75728 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
+ TODO: check
+CVE-2026-75723 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
+ TODO: check
+CVE-2026-75721 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
+ TODO: check
+CVE-2026-75703 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
+ TODO: check
+CVE-2026-75699 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
+ TODO: check
+CVE-2026-75698 (Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vu ...)
+ TODO: check
+CVE-2026-75697 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
+ TODO: check
+CVE-2026-75689 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
+ TODO: check
+CVE-2026-75686 (Adobe Connect is affected by an Improper Input Validation vulnerabilit ...)
+ TODO: check
+CVE-2026-75684 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
+ TODO: check
+CVE-2026-75682 (Adobe Connect is affected by an Improper Neutralization of Special Ele ...)
+ TODO: check
+CVE-2026-75676 (Bridge is affected by a Stack-based Buffer Overflow vulnerability that ...)
+ TODO: check
+CVE-2026-75665 (Bridge is affected by a Heap-based Buffer Overflow vulnerability that ...)
+ TODO: check
+CVE-2026-75663 (Bridge is affected by an out-of-bounds write vulnerability that could ...)
+ TODO: check
+CVE-2026-75658 (Bridge is affected by an out-of-bounds write vulnerability that could ...)
+ TODO: check
+CVE-2026-75656 (Bridge is affected by an out-of-bounds read vulnerability that could l ...)
+ TODO: check
+CVE-2026-75655 (Bridge is affected by an Uncontrolled Recursion vulnerability that cou ...)
+ TODO: check
+CVE-2026-75649 (Bridge is affected by a Heap-based Buffer Overflow vulnerability that ...)
+ TODO: check
+CVE-2026-75638 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
+ TODO: check
+CVE-2026-75634 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
+ TODO: check
+CVE-2026-75633 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
+ TODO: check
+CVE-2026-75632 (CAI Content Credentials is affected by an Uncontrolled Resource Consum ...)
+ TODO: check
+CVE-2026-75608 (Frigate is an open source network video recorder. Prior to 0.18.0, the ...)
+ TODO: check
+CVE-2026-75607 (Frigate is an open source network video recorder. Prior to 0.17.2, the ...)
+ TODO: check
+CVE-2026-75517 (Novu provides an API for sending notifications through multiple channe ...)
+ TODO: check
+CVE-2026-75511 (Novu provides an API for sending notifications through multiple channe ...)
+ TODO: check
+CVE-2026-75510 (Novu provides an API for sending notifications through multiple channe ...)
+ TODO: check
+CVE-2026-74849 (Zohocorp ManageEngine ADSelfService Plus versions before build 7001 ar ...)
+ TODO: check
+CVE-2026-73369 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
+ TODO: check
+CVE-2026-70410 (Use of Externally-Controlled Input to Select Classes or Code ('Unsafe ...)
+ TODO: check
+CVE-2026-6922 (The WP Table Builder \u2013 Drag & Drop Table Builder plugin for WordP ...)
+ TODO: check
+CVE-2026-68956 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
+ TODO: check
+CVE-2026-65634 (Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENT ...)
+ TODO: check
+CVE-2026-65179 (NVIDIA NeMo contains a vulnerability in the TabularTokenizer class whe ...)
+ TODO: check
+CVE-2026-65178 (NVIDIA NeMo contains a vulnerability in its dataset-loading workflow w ...)
+ TODO: check
+CVE-2026-65130 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65129 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65128 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65127 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65126 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65125 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65124 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65121 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65118 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65117 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65115 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65114 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65113 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65112 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
+ TODO: check
+CVE-2026-65111 (NVIDIA NeMo Speech for all platforms contains a vulnerability where ma ...)
+ TODO: check
+CVE-2026-63386 (js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does n ...)
+ TODO: check
+CVE-2026-63279 (LibreOffice can import PICT images, which may be embedded in documents ...)
+ TODO: check
+CVE-2026-63278 (URLs could be constructed which expanded environment variable or INI f ...)
+ TODO: check
+CVE-2026-63276 (LibreOffice converts CFF fonts to Type 1 when it subsets a font, which ...)
+ TODO: check
+CVE-2026-63275 (LibreOffice can read CFF fonts, which may be embedded in documents. A ...)
+ TODO: check
+CVE-2026-63274 (LibreOffice Draw can import PDF documents. A heap buffer overflow exis ...)
+ TODO: check
+CVE-2026-63273 (LibreOffice Draw can import PDF documents. A heap buffer overflow exis ...)
+ TODO: check
+CVE-2026-63272 (LibreOffice can import WMF graphics, which may be embedded in document ...)
+ TODO: check
+CVE-2026-57149 (plone.app.portlets.portlets provides a Plone-specific user interface f ...)
+ TODO: check
+CVE-2026-56682 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
+ TODO: check
+CVE-2026-56681 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
+ TODO: check
+CVE-2026-4123 (The RW Elephant Rental Inventory plugin for WordPress is vulnerable to ...)
+ TODO: check
+CVE-2026-48361 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
+ TODO: check
+CVE-2026-43643 (Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an a ...)
+ TODO: check
+CVE-2026-43642 (Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PH ...)
+ TODO: check
+CVE-2026-43641 (Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an O ...)
+ TODO: check
+CVE-2026-37604 (pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves ...)
+ TODO: check
+CVE-2026-37603 (Improper Restriction of Excessive Authentication Attempts in the admin ...)
+ TODO: check
+CVE-2026-34689 (Adobe Connect is affected by an Improper Limitation of a Pathname to a ...)
+ TODO: check
+CVE-2026-25265 (Privilege escalation due to weak configuration while temporary file ha ...)
+ TODO: check
+CVE-2026-25264 (Privilege escalation due to weak configuration during package extracti ...)
+ TODO: check
+CVE-2026-25262 (Memory corruption while processing a crafted ELF file in the Primary B ...)
+ TODO: check
+CVE-2026-25255 (Exposed dangerous function lead to privilege escalation via gRPC serve ...)
+ TODO: check
+CVE-2026-25254 (Improper authorization leads to Remote Code Execution via SocketIO int ...)
+ TODO: check
+CVE-2026-24267 (NVIDIA NeMo Speech for all platforms contains a vulnerability in the s ...)
+ TODO: check
+CVE-2026-24239 (NVIDIA NeMo Speech for all platforms contains a vulnerability where ma ...)
+ TODO: check
+CVE-2026-1645 (The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scr ...)
+ TODO: check
+CVE-2026-19915 (A potential security vulnerability has been identified in the HP Suppo ...)
+ TODO: check
+CVE-2026-19480 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
+ TODO: check
+CVE-2026-18626 (Out-of-bounds Read vulnerability in RTI Connext Professional (Core Lib ...)
+ TODO: check
+CVE-2026-18462 (Integer Overflow or Wraparound, Improper Access Control vulnerability ...)
+ TODO: check
+CVE-2026-18461 (Use of Externally-Controlled Format String vulnerability in RTI Connex ...)
+ TODO: check
+CVE-2026-18460 (Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Pro ...)
+ TODO: check
+CVE-2026-18459 (Incorrect Calculation vulnerability in RTI Connext Professional (Core ...)
+ TODO: check
+CVE-2026-18458 (Out-of-bounds Read, Function Call With Incorrect Number of Arguments, ...)
+ TODO: check
+CVE-2026-18457 (Heap-based Buffer Overflow vulnerability in RTI Connext Professional ( ...)
+ TODO: check
+CVE-2026-18439 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
+ TODO: check
+CVE-2026-18345 (The WP User Manager plugin for WordPress is vulnerable to unauthorized ...)
+ TODO: check
+CVE-2026-16778 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
+ TODO: check
+CVE-2026-15095 (The Product Feed Manager for WooCommerce \u2013 CTX Feed \u2013 Suppor ...)
+ TODO: check
+CVE-2026-13087 (A heap out-of-bounds write vulnerability was found in the Linux kernel ...)
+ TODO: check
+CVE-2026-12995 (The Custom Field Template plugin for WordPress is vulnerable to Insecu ...)
+ TODO: check
+CVE-2026-12718 (Improper neutralization of special elements used in an SQL command ('S ...)
+ TODO: check
+CVE-2026-11389 (Out-of-bounds Read, Function Call With Incorrect Number of Arguments, ...)
+ TODO: check
+CVE-2026-11388 (Double Free vulnerability in RTI Connext Professional (Core Libraries) ...)
+ TODO: check
+CVE-2025-1281 (The BM Content Builder plugin for WordPress is vulnerable to arbitrary ...)
+ TODO: check
+CVE-2025-1280 (The BM Content Builder plugin for WordPress is vulnerable to Directory ...)
+ TODO: check
+CVE-2025-14487 (The Handily plugin for WordPress is vulnerable to unauthorized payment ...)
+ TODO: check
+CVE-2025-14486 (The PixelPlay plugin for WordPress is vulnerable to unauthorized API k ...)
+ TODO: check
+CVE-2025-14484 (The Image Buzz plugin for WordPress is vulnerable to unauthorized API ...)
+ TODO: check
+CVE-2026-95831 (Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contai ...)
NOT-FOR-US: Crypt::SelfCertificate Perl module
-CVE-2026-95818
+CVE-2026-95818 (A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU ...)
- glibc <unfixed> (bug #1148728)
NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0023
NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=ed0c137b97eb940b4b64981e84ed806d3276edd9
-CVE-2026-86805
+CVE-2026-86805 (A time-of-check to time-of-use (TOCTOU) race condition in the dynamic ...)
- glibc <unfixed> (bug #1148727)
NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0022
NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=ed0c137b97eb940b4b64981e84ed806d3276edd9
-CVE-2026-87082
+CVE-2026-87082 (Net::IDN::Punycode versions before 2.590 for Perl hang, crash or retur ...)
- libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753021/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/0918fb4a951ed5f4494c4cf202419c2842507ea4 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/59dc7f2c605a897bcbfe0ac5eb2b8dbe6792348d (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/accb6df57ad107ec0c4bfb27b21551eed97c700e (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/572af0183b3a6294e22c6b509268da09697cf77d (v2.590-TRIAL)
-CVE-2026-87081
+CVE-2026-87081 (Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion vi ...)
- libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753018/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/5ac3315131264670efcd3a29857b651506dfee8e (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/ea34f812d7dc67f3b211f4d92e74c6a7e24d764a (v2.590-TRIAL)
-CVE-2026-87080
+CVE-2026-87080 (Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncat ...)
- libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753025/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/48436c7ad2c4d4c6398110e11133754fc476a783 (v2.590-TRIAL)
-CVE-2026-87079
+CVE-2026-87079 (Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion ...)
- libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753023/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/00d723423b66810af26b88c552bedc61975b3078 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/447c6b38ef5d4570329fa4f78690f4e14e09ba0c (v2.590-TRIAL)
-CVE-2026-87078
+CVE-2026-87078 (Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the ...)
- libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753020/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/92572f726e48af5559de4cc8a831463b79dfb217 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/edad63e0eeeeb18d93bc6dfe4d9dcdff9c244e1b (v2.590-TRIAL)
-CVE-2026-74766
+CVE-2026-74766 (Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a h ...)
- libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753027/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/259e74c5739175b063c5393a4ce4a0705678ba61 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/2fbc71e4d8517ab65c5d5d35fda086371b735a3f (v2.590-TRIAL)
-CVE-2026-74765
+CVE-2026-74765 (Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-boun ...)
- libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753029/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/27a91ccdb6c9b41f75ba198f5ae154d14e225de2 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/81c7f99fe7430bdc5116081508dffdb56f376861 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/89d5aa8d3504c5e96061ab76d1541a89c16157cf (v2.590-TRIAL)
-CVE-2016-15059
+CVE-2016-15059 (Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer ...)
- libnet-idn-encode-perl 2.303-1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753031/
NOTE: https://rt.cpan.org/Ticket/Display.html?id=118924
@@ -585,7 +1203,7 @@ CVE-2026-94449 (A flaw was found in the SmallRye Fault Tolerance library, which
NOT-FOR-US: Quarkus
CVE-2026-94368 (A flaw was found in the signature verification logic of noobaa-core, t ...)
NOT-FOR-US: noobaa
-CVE-2026-94640
+CVE-2026-94640 (A flaw was found in rpcbind. This vulnerability allows a remote, unaut ...)
- rpcbind <unfixed> (bug #1148730)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462960
CVE-2026-15801 (A vulnerability was found in CRI-O related to the container checkpoint ...)
@@ -2003,7 +2621,7 @@ CVE-2026-63406 (AnyCable is a realtime server for reliable two-way communication
NOT-FOR-US: AnyCable
CVE-2026-63405 (AnyCable is a realtime server for reliable two-way communication that ...)
NOT-FOR-US: AnyCable
-CVE-2026-63374
+CVE-2026-63374 (AnyIO is a high level asynchronous concurrency and networking framewor ...)
- python-anyio <unfixed> (bug #1148561)
NOTE: https://github.com/agronholm/anyio/security/advisories/GHSA-82r6-8w77-94w6
NOTE: https://github.com/agronholm/anyio/pull/1208
@@ -2767,7 +3385,7 @@ CVE-2024-38639 (An improper authentication vulnerability has been reported to af
NOT-FOR-US: QNAP
CVE-2024-27123 (A cross-site scripting (XSS) vulnerability has been reported to affect ...)
NOT-FOR-US: QNAP
-CVE-2026-94572 [OSSA-2026-039]
+CVE-2026-94572 (In OpenStack Octavia before 18.0.1, the Amphora provider driver did no ...)
- octavia 18.0.0-4 (bug #1148175)
[trixie] - octavia <no-dsa> (Minor issue)
[bookworm] - octavia <postponed> (Minor issue)
@@ -2776,7 +3394,7 @@ CVE-2026-94572 [OSSA-2026-039]
NOTE: https://bugs.launchpad.net/octavia/+bug/2162103
NOTE: https://security.openstack.org/ossa/OSSA-2026-039.html
NOTE: https://opendev.org/openstack/octavia/commit/cad62902e4984a46ad80cbfa943e90006d8d599d
-CVE-2026-94571 [OSSA-2026-039]
+CVE-2026-94571 (In OpenStack Octavia before 18.0.1, the Amphora provider driver did no ...)
- octavia 18.0.0-4 (bug #1148175)
[trixie] - octavia <no-dsa> (Minor issue)
[bookworm] - octavia <postponed> (Minor issue)
@@ -21573,7 +22191,7 @@ CVE-2026-86484 (In JetBrains YouTrack before 2026.2.18634 angularJS template inj
NOT-FOR-US: JetBrains
CVE-2026-86483 (In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom fiel ...)
NOT-FOR-US: JetBrains
-CVE-2026-86482 (In JetBrains YouTrack before 2026.2.18634 unchecked group membership c ...)
+CVE-2026-86482 (In JetBrains YouTrack before 2026.2.18634, insufficient validation of ...)
NOT-FOR-US: JetBrains
CVE-2026-86481 (In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed dis ...)
NOT-FOR-US: JetBrains
@@ -55547,6 +56165,7 @@ CVE-2026-XXXX [GHSA-9rww-v4mm-x4jg]
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-9rww-v4mm-x4jg
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/e6fa2f9b416ec382644694c8737dc8fbe7f07b89 (1.18.1)
CVE-2026-92162 [GHSA-v2gw-v9h5-9q4x]
+ {DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-v2gw-v9h5-9q4x
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/19456b916842b079af833a86b9ab89c5db154b92 (1.18.1)
@@ -60304,7 +60923,7 @@ CVE-2026-66662 (Unauthenticated Privilege Escalation in Frontend Admin by Dynami
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66470 (Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3. ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-66457 (Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 ...)
+CVE-2026-66457 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66452 (Unauthenticated Broken Access Control in Legal Text Connector of the I ...)
NOT-FOR-US: WordPress plugin or theme
@@ -103101,7 +103720,7 @@ CVE-2026-30799 (Missing Authentication for Critical Function vulnerability in RT
NOT-FOR-US: RTI Connext
CVE-2026-2675 (Missing Authentication for Critical Function vulnerability in RTI Conn ...)
NOT-FOR-US: RTI Connext
-CVE-2026-2674 (Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerab ...)
+CVE-2026-2674 (Out-of-bounds Write vulnerability in RTI Connext Professional (Queuein ...)
NOT-FOR-US: RTI Connext
CVE-2026-2467 (Heap-based Buffer Overflow vulnerability in RTI Connext Professional ( ...)
NOT-FOR-US: RTI Connext
@@ -132055,7 +132674,8 @@ CVE-2026-8069 (PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privil
NOT-FOR-US: PredatorSense
CVE-2026-8034 (A server-side request forgery (SSRF) vulnerability was identified in t ...)
NOT-FOR-US: Github Enterprise Server
-CVE-2026-7891 (A vulnerability has been identified in Mendix Runtime (All versions). ...)
+CVE-2026-7891
+ REJECTED
NOT-FOR-US: VerySecureApp
CVE-2026-7541 (A denial of service vulnerability was identified in GitHub Enterprise ...)
NOT-FOR-US: Github Enterprise Server
@@ -264866,7 +265486,7 @@ CVE-2025-5141 (A binary in the BoKS Server Agent component of Fortra's Core Priv
NOT-FOR-US: BoKS
CVE-2025-4879 (Local Privilege escalation allows a low-privileged user to gain SYSTEM ...)
NOT-FOR-US: Citrix
-CVE-2025-4754 (Insufficient Session Expiration vulnerability in ash-project ash_authe ...)
+CVE-2025-4754 (Insufficient Session Expiration vulnerability in team-alembic ash_auth ...)
NOT-FOR-US: ash-project ash_authentication_phoenix
CVE-2025-7493 (A privilege escalation flaw from host to domain administrator was foun ...)
- freeipa <unfixed> (unimportant)
@@ -443209,9 +443829,9 @@ CVE-2023-4556 (A vulnerability was found in SourceCodester Online Graduate Trace
NOT-FOR-US: SourceCodester Online Graduate Tracer System
CVE-2023-4555 (A vulnerability has been found in SourceCodester Inventory Management ...)
NOT-FOR-US: SourceCodester Inventory Management System
-CVE-2023-4548 (A vulnerability classified as critical has been found in SPA-Cart eCom ...)
+CVE-2023-4548 (A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The ...)
NOT-FOR-US: SPA-Cart eCommerce CMS
-CVE-2023-4547 (A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. It has be ...)
+CVE-2023-4547 (A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected ...)
NOT-FOR-US: SPA-Cart eCommerce CMS
CVE-2023-4546 (A vulnerability was found in Byzoro Smart S85F Management Platform up ...)
NOT-FOR-US: Beijing Baichuo Smart S85F Management Plattform
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c6fefa8fb614a440484653fc244aa400b11d4ad
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c6fefa8fb614a440484653fc244aa400b11d4ad
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/e177eec7/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list