[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 23 08:13:45 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ed93165f by security tracker role at 2026-09-23T07:13:38+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,379 @@
+CVE-2026-96273 (Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB. ...)
+ TODO: check
+CVE-2026-96272 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnera ...)
+ TODO: check
+CVE-2026-96271 (Photoview through 2.4.0 contains an authorization bypass vulnerability ...)
+ TODO: check
+CVE-2026-96269 (GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon openi ...)
+ TODO: check
+CVE-2026-96260 (Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7 ...)
+ TODO: check
+CVE-2026-96259 (Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7 ...)
+ TODO: check
+CVE-2026-96258 (A vulnerability has been found in onSite internet GmbH Auktion NG Aukt ...)
+ TODO: check
+CVE-2026-96257 (A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected ...)
+ TODO: check
+CVE-2026-95958 (A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Imp ...)
+ TODO: check
+CVE-2026-95957 (A vulnerability was found in SourceCodester Smart Attendance System wi ...)
+ TODO: check
+CVE-2026-95930 (A security vulnerability has been detected in iFlytek astron-agent up ...)
+ TODO: check
+CVE-2026-95929 (A weakness has been identified in iFlytek astron-agent up to 1.0.7. Af ...)
+ TODO: check
+CVE-2026-95928 (A security flaw has been discovered in recommenders-team recommenders ...)
+ TODO: check
+CVE-2026-95927 (A vulnerability was identified in SourceCodester Online Reviewer Manag ...)
+ TODO: check
+CVE-2026-95926 (A vulnerability was determined in SourceCodester Online Reviewer Manag ...)
+ TODO: check
+CVE-2026-95925 (A vulnerability was found in SourceCodester Online Reviewer Management ...)
+ TODO: check
+CVE-2026-95924 (A vulnerability has been found in SourceCodester Online Reviewer Manag ...)
+ TODO: check
+CVE-2026-95897 (A security vulnerability has been detected in Dask up to 2026.8.0. Thi ...)
+ TODO: check
+CVE-2026-95868 (A weakness has been identified in AdithyaYelloju Restaurant-Management ...)
+ TODO: check
+CVE-2026-95833 (A weakness has been identified in itsourcecode Leave Management System ...)
+ TODO: check
+CVE-2026-95830 (A security flaw has been discovered in theRealSain Pixtream up to 866a ...)
+ TODO: check
+CVE-2026-95829 (A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. ...)
+ TODO: check
+CVE-2026-95828 (A vulnerability was determined in Mstfakts College-Management-System. ...)
+ TODO: check
+CVE-2026-95820 (A vulnerability was found in anirbandutta9 College-Notes-Gallery up to ...)
+ TODO: check
+CVE-2026-95819 (A vulnerability has been found in anirbandutta9 College-Notes-Gallery ...)
+ TODO: check
+CVE-2026-95815 (OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs inclu ...)
+ TODO: check
+CVE-2026-95814 (Vaultwarden through 1.37.3 omits organization membership status valida ...)
+ TODO: check
+CVE-2026-95813 (e621ng versions before 26.09.16 pass untrusted request parameters dire ...)
+ TODO: check
+CVE-2026-95812 (ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site script ...)
+ TODO: check
+CVE-2026-94574 (A local cross-user code execution vulnerability exists in GNU wget (Wi ...)
+ TODO: check
+CVE-2026-94450 (Improper validation of the Destination Connection ID length in s2n-qui ...)
+ TODO: check
+CVE-2026-94367 (OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains ...)
+ TODO: check
+CVE-2026-93528 (The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 do ...)
+ TODO: check
+CVE-2026-93511 (The Premium Packages WordPress plugin before 7.2.1 does not verify Pa ...)
+ TODO: check
+CVE-2026-93510 (The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 ...)
+ TODO: check
+CVE-2026-93508 (The WC Fields Factory WordPress plugin before 4.1.11 does not properly ...)
+ TODO: check
+CVE-2026-93507 (The WC Fields Factory WordPress plugin before 4.1.11 does not properly ...)
+ TODO: check
+CVE-2026-92930 (OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an a ...)
+ TODO: check
+CVE-2026-92929 (OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an ...)
+ TODO: check
+CVE-2026-92928 (OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains ...)
+ TODO: check
+CVE-2026-91777 (Forward-reference completion for @JsonIdentityInfo object IDs in Faste ...)
+ TODO: check
+CVE-2026-91776 (TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind ...)
+ TODO: check
+CVE-2026-91077 (The Event Booking Manager for WooCommerce WordPress plugin before 5.7 ...)
+ TODO: check
+CVE-2026-91073 (The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise a ...)
+ TODO: check
+CVE-2026-91025 (The Booking Manager WordPress plugin before 2.1.21 does not verify th ...)
+ TODO: check
+CVE-2026-91024 (The Booking Manager WordPress plugin before 2.1.21 does not sanitize ...)
+ TODO: check
+CVE-2026-91018 (lwIP (Lightweight IP)has a double free vulnerability, which could cras ...)
+ TODO: check
+CVE-2026-90985 (The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 do ...)
+ TODO: check
+CVE-2026-90951 (The Paid Membership Subscriptions WordPress plugin before 3.1.0 does ...)
+ TODO: check
+CVE-2026-89425 (UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-cor ...)
+ TODO: check
+CVE-2026-89331 (The FluentBoards WordPress plugin before 2.1.0 does not properly rest ...)
+ TODO: check
+CVE-2026-89282 (The Apache Lounge Windows distribution of Apache HTTP Server build con ...)
+ TODO: check
+CVE-2026-89281 (The Apache Lounge Windows distribution of Apache HTTP Server build con ...)
+ TODO: check
+CVE-2026-89019
+ REJECTED
+CVE-2026-88997 (The JSM Show Post Metadata WordPress plugin before 4.9.1 does not prop ...)
+ TODO: check
+CVE-2026-88929 (The Product Badge, Label, Countdown Timer for WooCommerce WordPress p ...)
+ TODO: check
+CVE-2026-88624 (Missing path validation in the Worktree.remove component of openCode v ...)
+ TODO: check
+CVE-2026-88419 (An unrestricted upload of files with a dangerous type in the thumbnail ...)
+ TODO: check
+CVE-2026-88418 (CMSimple 5.24 ships with CSRF protection disabled by default, which tu ...)
+ TODO: check
+CVE-2026-88416 (MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the cust ...)
+ TODO: check
+CVE-2026-88350 (An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_ ...)
+ TODO: check
+CVE-2026-88345 (An out-of-bounds read vulnerability exists in the schema lexer of flat ...)
+ TODO: check
+CVE-2026-88344 (An out-of-bounds read vulnerability exists in the schema lexer of flat ...)
+ TODO: check
+CVE-2026-88341 (A reachable assertion vulnerability exists in YARA 4.5.8 when loading ...)
+ TODO: check
+CVE-2026-88340 (An invalid pointer release vulnerability exists in YARA 4.5.8 during d ...)
+ TODO: check
+CVE-2026-88339 (A NULL pointer dereference vulnerability exists in the gf_sg_vrml_fiel ...)
+ TODO: check
+CVE-2026-88020 (Autonomy Logic OpenPLC 3is susceptible to an improper neutralization o ...)
+ TODO: check
+CVE-2026-87981 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not per ...)
+ TODO: check
+CVE-2026-87979 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
+ TODO: check
+CVE-2026-87121 (lwIPTCP/IP Stack MQTTis vulnerable to an out-of-bounds write, which ma ...)
+ TODO: check
+CVE-2026-87074 (The Forminator Forms WordPress plugin before 1.57.2.1 does not bind i ...)
+ TODO: check
+CVE-2026-87069 (The Forminator Forms WordPress plugin before 1.57.2.1 does not perfor ...)
+ TODO: check
+CVE-2026-86842 (The Real3D Flipbook WordPress plugin before 5.4 does not perform capa ...)
+ TODO: check
+CVE-2026-86785 (The Social Commerce for WooCommerce WordPress plugin through 2.5.4 doe ...)
+ TODO: check
+CVE-2026-86783 (The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does no ...)
+ TODO: check
+CVE-2026-86608 (The WP Recipe Maker WordPress plugin before 10.8.2 does not have any a ...)
+ TODO: check
+CVE-2026-86603 (The WP Recipe Maker WordPress plugin before 10.8.2 does not have any a ...)
+ TODO: check
+CVE-2026-86602 (The WP Recipe Maker WordPress plugin before 10.8.2 does not perform an ...)
+ TODO: check
+CVE-2026-85006 (The HappyAddons for Elementor WordPress plugin before 3.50.0 does not ...)
+ TODO: check
+CVE-2026-84743 (The Events Calendar WordPress plugin before 6.17.5 does not perform a ...)
+ TODO: check
+CVE-2026-84742 (The Events Calendar WordPress plugin before 6.17.5 does not check the ...)
+ TODO: check
+CVE-2026-84741 (The Events Calendar WordPress plugin before 6.17.5 does not check the ...)
+ TODO: check
+CVE-2026-84168 (The Easy Hide Login WordPress plugin before 1.7 does not fully enforce ...)
+ TODO: check
+CVE-2026-84150 (The Directorist: AI-Powered Business Directory, Listings & Classified ...)
+ TODO: check
+CVE-2026-84098 (The Directorist: AI-Powered Business Directory, Listings & Classified ...)
+ TODO: check
+CVE-2026-84046 (The Directorist: AI-Powered Business Directory, Listings & Classified ...)
+ TODO: check
+CVE-2026-84027 (The Directorist: AI-Powered Business Directory, Listings & Classified ...)
+ TODO: check
+CVE-2026-84026 (The Directorist: AI-Powered Business Directory, Listings & Classified ...)
+ TODO: check
+CVE-2026-83805 (Nautobot is a Network Source of Truth and Network Automation Platform. ...)
+ TODO: check
+CVE-2026-83801 (Nautobot is a Network Source of Truth and Network Automation Platform. ...)
+ TODO: check
+CVE-2026-83555 (The Email Subscribers & Newsletters WordPress plugin before 5.9.35 do ...)
+ TODO: check
+CVE-2026-82843 (The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6 ...)
+ TODO: check
+CVE-2026-82331 (Improper link resolution before file access ('link following') vulnera ...)
+ TODO: check
+CVE-2026-81339 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
+ TODO: check
+CVE-2026-81338 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
+ TODO: check
+CVE-2026-80342 (The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0 ...)
+ TODO: check
+CVE-2026-79767 (Gardener implements the automated management and operation of Kubernet ...)
+ TODO: check
+CVE-2026-77987 (A server-side request forgery (SSRF) vulnerability was identified in t ...)
+ TODO: check
+CVE-2026-77912 (A stored cross-site scripting (XSS) vulnerability was identified in Gi ...)
+ TODO: check
+CVE-2026-77766 (The Directorist: AI-Powered Business Directory, Listings & Classified ...)
+ TODO: check
+CVE-2026-77765 (The Better Payment WordPress plugin before 2.3.4 does not validate th ...)
+ TODO: check
+CVE-2026-77426 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
+ TODO: check
+CVE-2026-77425 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
+ TODO: check
+CVE-2026-77322 (SIPGO is a library for writing SIP services in the GO language. Prior ...)
+ TODO: check
+CVE-2026-76910 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
+ TODO: check
+CVE-2026-76909 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
+ TODO: check
+CVE-2026-76717 (A vulnerability exists in the Analytics and Location Engine (ALE) API ...)
+ TODO: check
+CVE-2026-76716 (Multiple vulnerabilities exist in the Analytics and Location Engine (A ...)
+ TODO: check
+CVE-2026-76715 (A vulnerability in an administrative component of Analytics and Locati ...)
+ TODO: check
+CVE-2026-76714 (Vulnerabilities in the Analytics and Location Engine web interface all ...)
+ TODO: check
+CVE-2026-76713 (A vulnerability exists in the maintenance restore functionality of Ana ...)
+ TODO: check
+CVE-2026-76712 (A vulnerability exists in the Analytics and Location Engine (ALE) that ...)
+ TODO: check
+CVE-2026-76711 (A vulnerability exists in an Analytics and Location Engine (ALE) compo ...)
+ TODO: check
+CVE-2026-76710 (A vulnerability exists in the Analytics and Location Engine (ALE) mana ...)
+ TODO: check
+CVE-2026-76709 (A vulnerability exists in the internal administrative component of Ana ...)
+ TODO: check
+CVE-2026-76708 (A vulnerability exists in the Analytics and Location Engine (ALE) wher ...)
+ TODO: check
+CVE-2026-75799 (The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate th ...)
+ TODO: check
+CVE-2026-75432 (An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitiv ...)
+ TODO: check
+CVE-2026-75101 (An authorization bypass vulnerability was identified in GitHub Enterpr ...)
+ TODO: check
+CVE-2026-6831 (The Advanced Contact form 7 DB plugin for WordPress is vulnerable to m ...)
+ TODO: check
+CVE-2026-67615 (openEQUELLA before 2026.1.0 contains an authenticated remote code exec ...)
+ TODO: check
+CVE-2026-65829 (MPXJ is an open source library to read and write project plans from a ...)
+ TODO: check
+CVE-2026-63628 (mppx is a TypeScript interface for machine payments protocol. Prior to ...)
+ TODO: check
+CVE-2026-63627 (mppx is a TypeScript interface for machine payments protocol. Prior to ...)
+ TODO: check
+CVE-2026-63104 (Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vu ...)
+ TODO: check
+CVE-2026-62985 (request-filtering-agent is an http(s).Agent implementation that blocks ...)
+ TODO: check
+CVE-2026-62364 (wlc is a Weblate command-line client using Weblate's REST API. Prior t ...)
+ TODO: check
+CVE-2026-61685 (ReactPress is a publishing system for React developers. Prior to versi ...)
+ TODO: check
+CVE-2026-61570 (MPXJ is an open source library to read and write project plans from a ...)
+ TODO: check
+CVE-2026-5924 (The Getwid \u2013 Gutenberg Blocks plugin for WordPress is vulnerable ...)
+ TODO: check
+CVE-2026-59991 (psd-tools is a Python package for working with Adobe Photoshop PSD fil ...)
+ TODO: check
+CVE-2026-58268 (SIPGO is a library for writing SIP services in the GO language. Prior ...)
+ TODO: check
+CVE-2026-57576 (plone.app.dexterity is a content-type system for the Plone content man ...)
+ TODO: check
+CVE-2026-47116 (LTSecurity LTK3500SF contains a hard-coded credentials vulnerability w ...)
+ TODO: check
+CVE-2026-28325 (SolarWinds Observability Self-Hosted was found to be affected by an un ...)
+ TODO: check
+CVE-2026-28324 (SolarWinds Observability Self-Hosted was found to be affected by an un ...)
+ TODO: check
+CVE-2026-19438 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
+ TODO: check
+CVE-2026-19202 (A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-pyth ...)
+ TODO: check
+CVE-2026-18365 (The zportals WordPress plugin before 6.4.2 does not perform any capabi ...)
+ TODO: check
+CVE-2026-18364 (The zportals WordPress plugin before 6.4.2 does not perform any capabi ...)
+ TODO: check
+CVE-2026-18176 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18173 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18172 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18170 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18169 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18163 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18162 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18161 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18156 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18154 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18153 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18152 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18137 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18134 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18133 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18132 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18131 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18124 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18123 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18114 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18095 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18074 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18066 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17647 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17646 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17645 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17644 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17643 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17637 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17636 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17635 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17620 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 t ...)
+ TODO: check
+CVE-2026-17618 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-17472 (IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated att ...)
+ TODO: check
+CVE-2026-17465 (IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated att ...)
+ TODO: check
+CVE-2026-17102 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-16672 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-16469 (IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a r ...)
+ TODO: check
+CVE-2026-16468 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-16426 (IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request f ...)
+ TODO: check
+CVE-2026-16346 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-16264 (The Newsletters WordPress plugin before 4.18.1 does not perform an own ...)
+ TODO: check
+CVE-2026-15915 (IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain ...)
+ TODO: check
+CVE-2026-14321 (The divi-dash WordPress plugin before 1.0.7 does not validate the sour ...)
+ TODO: check
+CVE-2025-36084 (IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographi ...)
+ TODO: check
+CVE-2025-15696 (The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or ...)
+ TODO: check
+CVE-2025-12767 (IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause ...)
+ TODO: check
+CVE-2022-4997 (The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does ...)
+ TODO: check
CVE-2026-95350
- chromium <unfixed>
CVE-2026-95357
@@ -318,7 +694,7 @@ CVE-2026-94455 (An HTTP endpoint intended for provisioning enterprise and resell
NOT-FOR-US: Postiz App
CVE-2026-94384 (Missing authorization in Amazon amazon-connect-salesforce-lambda befor ...)
NOT-FOR-US: Amazon
-CVE-2026-94127 (When a BIG-IP APM access policy and an OAuth profile is configured on ...)
+CVE-2026-94127 (When a BIG-IP APM access policy and an OAuth profile are configured on ...)
NOT-FOR-US: F5
CVE-2026-94117 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: WordPress plugin or theme
@@ -434,7 +810,7 @@ CVE-2026-84412 (Adobe Campaign Classic (ACC) is affected by an Improper Control
NOT-FOR-US: Adobe
CVE-2026-84396 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
NOT-FOR-US: Adobe
-CVE-2026-84395 (Premiere Pro [NEEDS REVIEW: environment mismatch \u2014 product 'Premi ...)
+CVE-2026-84395 (Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulne ...)
NOT-FOR-US: Adobe
CVE-2026-84388 (A improper restriction of rendered ui layers or frames vulnerability i ...)
NOT-FOR-US: Fortinet
@@ -1596,7 +1972,7 @@ CVE-2026-94112 (mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP pas
NOT-FOR-US: ezBookkeeping
CVE-2026-94111 (Tencent BrowserSkill through 0.3.0 contains an authentication bypass v ...)
NOT-FOR-US: Tencent
-CVE-2026-94109 (openEQUELLA versions before 2026.1.0 contain a remote code execution v ...)
+CVE-2026-94109 (openEQUELLA before 2026.1.0 contains an authenticated stored server-si ...)
NOT-FOR-US: openEQUELLA
CVE-2026-94108 (getID3 through 1.9.26 contains an XML external entity injection vulner ...)
- php-getid3 <unfixed> (unimportant)
@@ -56377,6 +56753,7 @@ CVE-2026-XXXX [GHSA-qrwq-7qwx-q9rp]
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/076f77a4775490b2aef43f4e01eeee9aa965bd21 (branch flatpak-1.16.x)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/769ad563bae82b948496a7edffa5eb3f71d0cc72 (branch flatpak-1.16.x)
CVE-2026-96275 [GHSA-fqx6-vh4p-42cg]
+ {DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/c42326c74d63e550d874312be0c7a800cf5fc39f (1.18.1)
@@ -56392,6 +56769,7 @@ CVE-2026-96275 [GHSA-fqx6-vh4p-42cg]
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/3d43a0f5fa602cc3edc557d8ab835030140792b1 (branch flatpak-1.16.x)
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
CVE-2026-96276 [GHSA-8qxj-x646-phcm]
+ {DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/c42326c74d63e550d874312be0c7a800cf5fc39f (1.18.1)
@@ -56421,6 +56799,7 @@ CVE-2026-92162 [GHSA-v2gw-v9h5-9q4x]
NOTE: Additional tests: https://github.com/flatpak/flatpak/commit/e52c97fc2f307f695f5db16d8a5ba44b23d1d894 (branch flatpak-1.16.x)
NOTE: Test workaround for old meson: https://github.com/flatpak/flatpak/pull/6768
CVE-2026-96280 [GHSA-jr92-2v97-wgvc]
+ {DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/892d261255449d0cd5d97f6a8f2a731e566ff913 (1.18.1)
@@ -56442,6 +56821,7 @@ CVE-2026-XXXX [GHSA-99wv-m8rp-g58x]
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/3d43a0f5fa602cc3edc557d8ab835030140792b1 (branch flatpak-1.16.x)
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
CVE-2026-96282 [GHSA-w69g-9x8j-7p8f]
+ {DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-w69g-9x8j-7p8f
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/6ec728c15b4eff47b7d69a2cc22e4aef52011585 (1.18.1)
@@ -56451,6 +56831,7 @@ CVE-2026-96282 [GHSA-w69g-9x8j-7p8f]
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/3d43a0f5fa602cc3edc557d8ab835030140792b1 (branch flatpak-1.16.x)
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
CVE-2026-96281 [GHSA-q4gr-vc25-57m5]
+ {DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/d5939b0f1751df7dede31a1ee7fb5b8dfe49fd79 (1.18.1)
@@ -125068,12 +125449,12 @@ CVE-2026-4883 (The Piotnet Forms plugin for WordPress is vulnerable to arbitrary
CVE-2026-4630 (A flaw was found in Keycloak. An authenticated client could exploit an ...)
- keycloak <itp> (bug #1088287)
CVE-2026-47784 (In memcached before 1.6.42, password data for SASL password database a ...)
- {DLA-4601-1}
+ {DLA-4791-1 DLA-4601-1}
- memcached 1.6.42-1 (bug #1137214)
[trixie] - memcached <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed (1.6.42)
CVE-2026-47783 (In memcached before 1.6.42, username data for SASL password database a ...)
- {DLA-4601-1}
+ {DLA-4791-1 DLA-4601-1}
- memcached 1.6.42-1 (bug #1137214)
[trixie] - memcached <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed (1.6.42)
@@ -151251,9 +151632,11 @@ CVE-2026-39860 (Nix is a package manager for Linux and other Unix systems. A bug
NOTE: CVE exists for guix because the fix for CVE-2024-27297 introduces the issue.
TODO: check, potentially affecting guix if same issue in backporting fix for CVE-2024-2729
CVE-2026-96284 [GHSA-2fxp-43j9-pwvc: Arbitrary read-access to files readable by _flatpak user]
+ {DSA-6223-1 DSA-6207-1}
- flatpak 1.16.4-1 (bug #1132946)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-2fxp-43j9-pwvc
CVE-2026-96283 [GHSA-89xm-3m96-w3jg: cross-user CancelPull orphans another user's ongoing pull]
+ {DSA-6223-1}
- flatpak 1.16.4-1 (bug #1132945)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-89xm-3m96-w3jg
CVE-2026-34079 (Flatpak is a Linux application sandboxing and distribution framework. ...)
@@ -182562,7 +182945,7 @@ CVE-2025-63624 (SQL Injection vulnerability in Shandong Kede Electronics Co., Lt
NOT-FOR-US: Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform
CVE-2025-63372 (Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Direc ...)
NOT-FOR-US: Articentgroup Zip Rar Extractor Tool
-CVE-2025-62673 (Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 ( ...)
+CVE-2025-62673 (Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 ...)
NOT-FOR-US: TP-Link
CVE-2025-62501 (SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 ...)
NOT-FOR-US: TP-Link
@@ -433595,11 +433978,13 @@ CVE-2023-5443 (Improper Protection for Outbound Error Messages and Alert Signals
CVE-2023-4967 (Denial of Service in NetScaler ADC and NetScaler Gateway when configur ...)
NOT-FOR-US: Citrix
CVE-2023-46853 (In Memcached before 1.6.22, an off-by-one error exists when processing ...)
+ {DLA-4791-1}
- memcached 1.6.22-1
[bullseye] - memcached <no-dsa> (Minor issue)
[buster] - memcached <not-affected> (The vulnerable code was introduced later)
NOTE: https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa (1.6.22)
CVE-2023-46852 (In Memcached before 1.6.22, a buffer overflow exists when processing m ...)
+ {DLA-4791-1}
- memcached 1.6.22-1
[bullseye] - memcached <no-dsa> (Minor issue)
[buster] - memcached <not-affected> (The vulnerable code was introduced later)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ed93165f45909729d17016529d5a08f4c2dd75a5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ed93165f45909729d17016529d5a08f4c2dd75a5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/7739e403/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list