[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 24 08:13:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
04693d59 by security tracker role at 2026-09-24T07:13:02+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,876 @@
-CVE-2026-87022
+CVE-2026-97177 (A flaw was found in the user update mechanism of the Keycloak Admin RE ...)
+ TODO: check
+CVE-2026-97176 (A flaw was found in the Level of Authentication enforcement mechanism ...)
+ TODO: check
+CVE-2026-97168
+ REJECTED
+CVE-2026-97155 (Fabasoft Folio Client before 2026, a locally installed component that ...)
+ TODO: check
+CVE-2026-97152 (Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely expl ...)
+ TODO: check
+CVE-2026-97151 (mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype poll ...)
+ TODO: check
+CVE-2026-97149 (In OpenStack Swift before 2.38.2, the tempurl middleware does not reje ...)
+ TODO: check
+CVE-2026-97056 (SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when ...)
+ TODO: check
+CVE-2026-97055 (SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing ...)
+ TODO: check
+CVE-2026-96898 (A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected ...)
+ TODO: check
+CVE-2026-96892 (A flaw has been found in Edimax BR-6428nC 1.16. The impacted element i ...)
+ TODO: check
+CVE-2026-96891 (A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is ...)
+ TODO: check
+CVE-2026-96889 (A flaw was found in librsvg. When processing an SVG document containin ...)
+ TODO: check
+CVE-2026-96884 (A security flaw has been discovered in MantisZip up to 0.4.5. Affected ...)
+ TODO: check
+CVE-2026-96882 (A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0. ...)
+ TODO: check
+CVE-2026-96881 (A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0. ...)
+ TODO: check
+CVE-2026-96880 (A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. ...)
+ TODO: check
+CVE-2026-96872 (Improper handling of insufficient permissions or privileges vulnerabil ...)
+ TODO: check
+CVE-2026-96826 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
+ TODO: check
+CVE-2026-96810 (A vulnerability was identified in huanzi-qch base-admin up to 52816b76 ...)
+ TODO: check
+CVE-2026-96804 (MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW ...)
+ TODO: check
+CVE-2026-96803 (A vulnerability was identified in java110 MicroCommunity up to 2.0. Af ...)
+ TODO: check
+CVE-2026-96777 (A vulnerability was determined in Forma LMS up to 4.1.43. This impacts ...)
+ TODO: check
+CVE-2026-96775 (MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKL ...)
+ TODO: check
+CVE-2026-96774 (A vulnerability was found in SPON Communications IP Network Audio Devi ...)
+ TODO: check
+CVE-2026-96773 (A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. ...)
+ TODO: check
+CVE-2026-96772 (A security flaw has been discovered in Intelliants Subrion CMS up to 4 ...)
+ TODO: check
+CVE-2026-96770 (All published s2s-proxy versions through 0.2.2 are affected. In versio ...)
+ TODO: check
+CVE-2026-96764 (A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3 ...)
+ TODO: check
+CVE-2026-96763 (A security flaw has been discovered in kvcache-ai mooncake up to 0.3.1 ...)
+ TODO: check
+CVE-2026-96762 (A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3 ...)
+ TODO: check
+CVE-2026-96759 (orval before 8.29.0 fails to escape the operationId parameter when emi ...)
+ TODO: check
+CVE-2026-96758 (orval @orval/core before 8.28.0 contains a code injection vulnerabilit ...)
+ TODO: check
+CVE-2026-96757 (orval before 8.29.0 fails to escape OpenAPI media-type keys when emitt ...)
+ TODO: check
+CVE-2026-96756 (orval versions before 8.30.0 contain a code injection vulnerability in ...)
+ TODO: check
+CVE-2026-96755 (orval versions 8.14.0 through 8.28.1 contain a code injection vulnerab ...)
+ TODO: check
+CVE-2026-96754 (orval versions before 8.29.0 contain a code injection vulnerability in ...)
+ TODO: check
+CVE-2026-96751 (A vulnerability has been found in pmTicket Project-Management-Software ...)
+ TODO: check
+CVE-2026-96739 (A flaw has been found in SEMCMS up to 4.2. Affected by this issue is s ...)
+ TODO: check
+CVE-2026-96680 (A vulnerability was detected in ByteDance Coze Scraper Extension up to ...)
+ TODO: check
+CVE-2026-96678 (A security vulnerability has been detected in weiqingwen spring-boot-f ...)
+ TODO: check
+CVE-2026-96676 (A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The im ...)
+ TODO: check
+CVE-2026-96675 (alsa-lib through 1.2.16.1 contains a denial of service vulnerability i ...)
+ TODO: check
+CVE-2026-96674 (alsa-lib through 1.2.16.1 computes combined topology element size usin ...)
+ TODO: check
+CVE-2026-96673 (Photoview through 2.4.0 contains an SQL injection vulnerability in the ...)
+ TODO: check
+CVE-2026-96672 (Frappe ERPNext versions before 16.34.1 fail to validate that Financial ...)
+ TODO: check
+CVE-2026-96656 (Plex Media Server before 1.43.3.10861 allows an admin user to write ar ...)
+ TODO: check
+CVE-2026-96655 (Plex Media Server before 1.43.3.10861 allows an authenticated user to ...)
+ TODO: check
+CVE-2026-96654 (Plex Media Server before 1.43.3.10861 does not correctly neutralize UR ...)
+ TODO: check
+CVE-2026-96652 (Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timelin ...)
+ TODO: check
+CVE-2026-96651 (Plex Media Server before 1.43.3.10861 builds a file path from the url ...)
+ TODO: check
+CVE-2026-96611 (FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. ...)
+ TODO: check
+CVE-2026-96609 (Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of t ...)
+ TODO: check
+CVE-2026-96606 (A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. Thi ...)
+ TODO: check
+CVE-2026-96604 (A vulnerability was identified in SoftNews Media Group DataLife Engine ...)
+ TODO: check
+CVE-2026-96603 (A vulnerability has been found in Abdurrab5 online-makeup-store. Affec ...)
+ TODO: check
+CVE-2026-96602 (A flaw has been found in Abdurrab5 online-makeup-store. This impacts a ...)
+ TODO: check
+CVE-2026-96601 (A vulnerability was detected in Abdurrab5 online-makeup-store. This af ...)
+ TODO: check
+CVE-2026-96600 (Isotope eCommerce through 2.9.10 contains a blind SQL injection vulner ...)
+ TODO: check
+CVE-2026-96599 (Isotope eCommerce through 2.9.10 derives order identifiers from uniqid ...)
+ TODO: check
+CVE-2026-96560 (LightLLM through 1.2.0 contains a remote code execution vulnerability ...)
+ TODO: check
+CVE-2026-96559
+ REJECTED
+CVE-2026-96556 (A flaw has been found in Neethuharii CafeManagement. Affected by this ...)
+ TODO: check
+CVE-2026-96552 (A vulnerability was identified in sfturing hosp_order up to 627f426331 ...)
+ TODO: check
+CVE-2026-96551 (A vulnerability was determined in sfturing hosp_order up to 627f426331 ...)
+ TODO: check
+CVE-2026-96550 (A vulnerability was found in sfturing hosp_order up to 627f426331da808 ...)
+ TODO: check
+CVE-2026-96549 (A vulnerability has been found in sfturing hosp_order up to 627f426331 ...)
+ TODO: check
+CVE-2026-96548 (A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8 ...)
+ TODO: check
+CVE-2026-96546 (A one-byte out-of-bounds heap read flaw was found in GIMP's uncompress ...)
+ TODO: check
+CVE-2026-96545 (An out-of-bounds heap read flaw was found in GIMP's TIM image loader. ...)
+ TODO: check
+CVE-2026-96541 (A denial-of-service flaw was found in gnome-remote-desktop. An unauthe ...)
+ TODO: check
+CVE-2026-96514 (A weakness has been identified in Neethuharii CafeManagement. Impacted ...)
+ TODO: check
+CVE-2026-96513 (A security flaw has been discovered in Neethuharii CafeManagement. Thi ...)
+ TODO: check
+CVE-2026-96512 (A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER ...)
+ TODO: check
+CVE-2026-96456 (The Reachy Mini Bluetooth service asks a connecting device for a PIN b ...)
+ TODO: check
+CVE-2026-96455 (The Reachy Mini daemon exposes an HTTP API for managing the robot. Its ...)
+ TODO: check
+CVE-2026-96454 (Pake turns a website into a desktop application built on Tauri. Every ...)
+ TODO: check
+CVE-2026-96446 (A flaw was found in the Pushed Authorization Request PAR implementatio ...)
+ TODO: check
+CVE-2026-96445 (A flaw was found in the Conditional OTP authenticator of Keycloak, an ...)
+ TODO: check
+CVE-2026-96443 (Insufficient validation of the JDBC driver URL in Apache Doris allows ...)
+ TODO: check
+CVE-2026-96442 (A code execution flaw was found in Emacs, affecting versions prior to ...)
+ TODO: check
+CVE-2026-95848 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a co ...)
+ TODO: check
+CVE-2026-95847 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2Persist ...)
+ TODO: check
+CVE-2026-95846 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffic ...)
+ TODO: check
+CVE-2026-95845 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broke ...)
+ TODO: check
+CVE-2026-95844 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette ...)
+ TODO: check
+CVE-2026-95843 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffic ...)
+ TODO: check
+CVE-2026-95842 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEv ...)
+ TODO: check
+CVE-2026-95676 (A missing/improper authentication vulnerability in the WatchGuard Auth ...)
+ TODO: check
+CVE-2026-95627 (When a Tauri application uses the dialog plugin's file or folder picke ...)
+ TODO: check
+CVE-2026-95626 (Tauri's Content Security Policy hardening, which injects a random nonc ...)
+ TODO: check
+CVE-2026-95625 (The Tauri updater plugin verifies update binaries using minisign signa ...)
+ TODO: check
+CVE-2026-95604 (Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versio ...)
+ TODO: check
+CVE-2026-95603 (Shop manager PHP Object Injection in Reycob Product Import Export <= 2 ...)
+ TODO: check
+CVE-2026-95602 (Authorization Bypass Through User-Controlled Key vulnerability in YITH ...)
+ TODO: check
+CVE-2026-95601 (Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versio ...)
+ TODO: check
+CVE-2026-95600 (Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2 ...)
+ TODO: check
+CVE-2026-95593 (Editor SQL Injection in Ultimeter <= 3.0.8 versions.)
+ TODO: check
+CVE-2026-95592 (Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6. ...)
+ TODO: check
+CVE-2026-95590 (Subscriber SQL Injection in Tainacan <= 1.2.0 versions.)
+ TODO: check
+CVE-2026-95586 (Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact ...)
+ TODO: check
+CVE-2026-95530 (Subscriber Cross Site Scripting (XSS) in PixelYourSite \u2013 Your sma ...)
+ TODO: check
+CVE-2026-95529 (Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form < ...)
+ TODO: check
+CVE-2026-95528 (Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSp ...)
+ TODO: check
+CVE-2026-95527 (Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6. ...)
+ TODO: check
+CVE-2026-95525 (Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versi ...)
+ TODO: check
+CVE-2026-95524 (Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 ver ...)
+ TODO: check
+CVE-2026-95523 (Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions ...)
+ TODO: check
+CVE-2026-95522 (Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions ...)
+ TODO: check
+CVE-2026-95515 (Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 ve ...)
+ TODO: check
+CVE-2026-95514 (Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.)
+ TODO: check
+CVE-2026-95513 (Unauthenticated Broken Access Control in Online Booking & Scheduling C ...)
+ TODO: check
+CVE-2026-94684 (Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 version ...)
+ TODO: check
+CVE-2026-94682 (Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine ...)
+ TODO: check
+CVE-2026-94680 (Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versi ...)
+ TODO: check
+CVE-2026-94679 (Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.)
+ TODO: check
+CVE-2026-94671 (Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versi ...)
+ TODO: check
+CVE-2026-94500 (Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons ...)
+ TODO: check
+CVE-2026-94498 (Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.)
+ TODO: check
+CVE-2026-94487 (Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capa ...)
+ TODO: check
+CVE-2026-94461 (Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.)
+ TODO: check
+CVE-2026-94457 (Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.)
+ TODO: check
+CVE-2026-94391 (Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versi ...)
+ TODO: check
+CVE-2026-94251 (A vulnerability in Apache Sling Security Bundle:ContentDispositionFilt ...)
+ TODO: check
+CVE-2026-94243 (A vulnerability in Apache Sling Security Bundle: the ReferrerFilter ac ...)
+ TODO: check
+CVE-2026-94183 (Arc Search for Android before version 1.12.10 does not display a fulls ...)
+ TODO: check
+CVE-2026-94181 (An address bar spoofing issue in affected versions of Arc could allow ...)
+ TODO: check
+CVE-2026-94179 (Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button ...)
+ TODO: check
+CVE-2026-94176 (Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 v ...)
+ TODO: check
+CVE-2026-94174 (Administrator SQL Injection in Email Log <= 2.63 versions.)
+ TODO: check
+CVE-2026-94168 (Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor ...)
+ TODO: check
+CVE-2026-94124 (Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.)
+ TODO: check
+CVE-2026-94118 (Contributor Cross Site Scripting (XSS) in Premium Blocks \u2013 Gutenb ...)
+ TODO: check
+CVE-2026-94080 (Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions ...)
+ TODO: check
+CVE-2026-94079 (Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 ver ...)
+ TODO: check
+CVE-2026-93774 (Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9 ...)
+ TODO: check
+CVE-2026-93773 (Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.)
+ TODO: check
+CVE-2026-93772 (Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 version ...)
+ TODO: check
+CVE-2026-93769 (HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulne ...)
+ TODO: check
+CVE-2026-93662 (The Events Manager WordPress plugin before 7.4.5 does not force the s ...)
+ TODO: check
+CVE-2026-93661 (The Events Manager WordPress plugin before 7.4.5 does not stop a tick ...)
+ TODO: check
+CVE-2026-93623 (Unauthenticated Insecure Direct Object References (IDOR) in AI Engine ...)
+ TODO: check
+CVE-2026-93622 (Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9 ...)
+ TODO: check
+CVE-2026-93620 (Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8. ...)
+ TODO: check
+CVE-2026-93618 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+ TODO: check
+CVE-2026-93577 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
+ TODO: check
+CVE-2026-93529 (Contributor Broken Access Control in WSP MCP – AI Agents Connect ...)
+ TODO: check
+CVE-2026-93527 (Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 v ...)
+ TODO: check
+CVE-2026-93526 (Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 ...)
+ TODO: check
+CVE-2026-93513 (Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2 ...)
+ TODO: check
+CVE-2026-93421 (Mesop is a Python-based UI framework that allows users to build web ap ...)
+ TODO: check
+CVE-2026-93368 (The Rename wp-login.php to anything you want plugin for WordPress is v ...)
+ TODO: check
+CVE-2026-93352 (Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for C ...)
+ TODO: check
+CVE-2026-93349 (Frictionless through 5.20.0rc1 contains an OS command injection vulner ...)
+ TODO: check
+CVE-2026-92874 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
+ TODO: check
+CVE-2026-92730 (LimeSurvey Community Edition 7.0.14 contains a reflected cross-site sc ...)
+ TODO: check
+CVE-2026-92700 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
+ TODO: check
+CVE-2026-92692 (Sulu is an open-source PHP content management system based on the Symf ...)
+ TODO: check
+CVE-2026-92628 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
+ TODO: check
+CVE-2026-92530 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
+ TODO: check
+CVE-2026-92529 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+ TODO: check
+CVE-2026-92470 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+ TODO: check
+CVE-2026-92419 (WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in ...)
+ TODO: check
+CVE-2026-92378 (A session management vulnerability exists in the Legacy UI Reduced Fun ...)
+ TODO: check
+CVE-2026-92284 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
+ TODO: check
+CVE-2026-92164 (Streamlink is a CLI utility which pipes video streams from various ser ...)
+ TODO: check
+CVE-2026-92001 (Improper restriction of recursive entity references in DTDs ('XML enti ...)
+ TODO: check
+CVE-2026-91999 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-91928 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-91852 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-91818 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
+ TODO: check
+CVE-2026-91817 (A heap-based out-of-bounds read vulnerability exists in Foxit PDF Edit ...)
+ TODO: check
+CVE-2026-91816 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
+ TODO: check
+CVE-2026-91815 (Foxit PDF Editor/Reader does not perform sufficient verification of th ...)
+ TODO: check
+CVE-2026-91814 (A signature validation vulnerability exists in Foxit PDF Editor/Reader ...)
+ TODO: check
+CVE-2026-91813 (A vulnerability in Foxit PDF Editor/Reader\u2019s update mechanism all ...)
+ TODO: check
+CVE-2026-91812 (A vulnerability in Foxit PDF Editor/Reader\u2019s update mechanism all ...)
+ TODO: check
+CVE-2026-91811 (A heap-based out-of-bounds write vulnerability exists in Foxit PDF Edi ...)
+ TODO: check
+CVE-2026-91810 (A heap-based out-of-bounds read vulnerability exists in Foxit PDF Edit ...)
+ TODO: check
+CVE-2026-91809 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
+ TODO: check
+CVE-2026-91808 (A heap-based out-of-bounds read vulnerability exists in Foxit PDF Edit ...)
+ TODO: check
+CVE-2026-91807 (A heap-based out-of-bounds read vulnerability exists in Foxit PDF Edit ...)
+ TODO: check
+CVE-2026-91806 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
+ TODO: check
+CVE-2026-91805 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
+ TODO: check
+CVE-2026-91804 (A heap-based out-of-bounds write vulnerability exists in Foxit PDF Edi ...)
+ TODO: check
+CVE-2026-91803 (A local privilege escalation vulnerability exists in the updater of Fo ...)
+ TODO: check
+CVE-2026-91802 (A heap-based out-of-bounds write vulnerability exists in Foxit PDF Edi ...)
+ TODO: check
+CVE-2026-91801 (A path traversal vulnerability exists in Foxit PDF Editor/Reader's han ...)
+ TODO: check
+CVE-2026-91800 (A local privilege escalation vulnerability exists in the installer of ...)
+ TODO: check
+CVE-2026-91799 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
+ TODO: check
+CVE-2026-91798 (A local privilege escalation vulnerability exists in the update daemon ...)
+ TODO: check
+CVE-2026-91797 (Foxit PDF Editor/Reader failed to validate the directory traversal pat ...)
+ TODO: check
+CVE-2026-91796 (The interface of Foxit PDF Editor/Reader lacks the permission verifica ...)
+ TODO: check
+CVE-2026-91795 (Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate ...)
+ TODO: check
+CVE-2026-91794 (An out-of-bounds write vulnerability exists in the PDF rendering proce ...)
+ TODO: check
+CVE-2026-91793 (When opening a specially crafted PDF, Foxit PDF Editor/Reader executes ...)
+ TODO: check
+CVE-2026-91792 (When processing a specially crafted PDF, Foxit PDF Editor/Reader may p ...)
+ TODO: check
+CVE-2026-91791 (When processing a specially crafted PDF file, Foxit PDF Editor/Reader ...)
+ TODO: check
+CVE-2026-91790 (When rendering the page image, Foxit PDF Editor/Reader fails to perfor ...)
+ TODO: check
+CVE-2026-91789 (Foxit PDF Editor/Reader\u2019s U3D/GIF texture decoding path contained ...)
+ TODO: check
+CVE-2026-91788 (When implementing the JavaScript interface, Foxit PDF Editor/Reader di ...)
+ TODO: check
+CVE-2026-91775 (LimeSurvey fails to safely encode attacker-controlled content from a c ...)
+ TODO: check
+CVE-2026-90950 (The Paid Membership Subscriptions WordPress plugin before 3.1.0 does n ...)
+ TODO: check
+CVE-2026-90905 (Joomla Extension - joomshaper.com - Missing CSRF and Access Control on ...)
+ TODO: check
+CVE-2026-90904 (Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) ...)
+ TODO: check
+CVE-2026-90903 (Joomla Extension - joomshaper.com - Missing CSRF Token Verification ac ...)
+ TODO: check
+CVE-2026-90902 (Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Inje ...)
+ TODO: check
+CVE-2026-90901 (Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Inje ...)
+ TODO: check
+CVE-2026-90900 (Joomla Extension - joomshaper.com - Missing CSRF Token Verification in ...)
+ TODO: check
+CVE-2026-90899 (Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via I ...)
+ TODO: check
+CVE-2026-89078 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
+ TODO: check
+CVE-2026-89005 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not ...)
+ TODO: check
+CVE-2026-89004 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not ...)
+ TODO: check
+CVE-2026-89002 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not ...)
+ TODO: check
+CVE-2026-88974 (WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, ...)
+ TODO: check
+CVE-2026-88847 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
+ TODO: check
+CVE-2026-88846 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
+ TODO: check
+CVE-2026-88845 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
+ TODO: check
+CVE-2026-88843 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
+ TODO: check
+CVE-2026-88840 (BusyBox TLS get_client_hello() reads past the end of the input buffer ...)
+ TODO: check
+CVE-2026-88839 (BusyBox passwd/group tokenize() references a stale endpoint pointer af ...)
+ TODO: check
+CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) password hashes as plaintext durin ...)
+ TODO: check
+CVE-2026-88835 (BusyBox dpkg read_package_field() steps past a NUL terminator on malfo ...)
+ TODO: check
+CVE-2026-88832 (BusyBox romfs volume ID parsing uses unbounded strlen on attacker-cont ...)
+ TODO: check
+CVE-2026-88831 (BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open ...)
+ TODO: check
+CVE-2026-88830 (A unit confusion in BusyBox TLS Montgomery reduction buffer allocation ...)
+ TODO: check
+CVE-2026-87978 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
+ TODO: check
+CVE-2026-87900 (Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier a ...)
+ TODO: check
+CVE-2026-87899 (Execution with unnecessary privileges in cPanel allows remote authenti ...)
+ TODO: check
+CVE-2026-87898 (OS command injection in Plesk allows remote authenticated users to exe ...)
+ TODO: check
+CVE-2026-87848 (The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have a ...)
+ TODO: check
+CVE-2026-87739 (An improper authentication vulnerability in PaperCut MF/NG allows an u ...)
+ TODO: check
+CVE-2026-87071 (The Forminator Forms WordPress plugin before 1.57.2.1 does not restric ...)
+ TODO: check
+CVE-2026-87070 (The Forminator Forms WordPress plugin before 1.57.2.1 does not verify ...)
+ TODO: check
+CVE-2026-86938 (A DLL hijacking vulnerability in the FileMaker Pro installer for Windo ...)
+ TODO: check
+CVE-2026-86934 (An authorization bypass vulnerability in the FileMaker Server Web Publ ...)
+ TODO: check
+CVE-2026-86930 (An out-of-bounds read vulnerability in FileMaker Server for Linux allo ...)
+ TODO: check
+CVE-2026-86926 (A heap buffer overflow vulnerability in the FileMaker Server database ...)
+ TODO: check
+CVE-2026-86867 (Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-u ...)
+ TODO: check
+CVE-2026-86708 (ZohoCorp ManageEngine Applications Manager versions 182200 and below w ...)
+ TODO: check
+CVE-2026-86683 (ZohoCorp ManageEngine Applications Manager versions 182000 and below a ...)
+ TODO: check
+CVE-2026-86681 (ZohoCorp ManageEngine Applications Manager versions 182200 and below w ...)
+ TODO: check
+CVE-2026-86679 (ZohoCorp ManageEngine Applications Manager versions 182000 and below w ...)
+ TODO: check
+CVE-2026-86678 (ZohoCorp ManageEngine Applications Manager versions 182000 and below a ...)
+ TODO: check
+CVE-2026-86677 (ZohoCorp ManageEngine Applications Manager versions 182000 and below a ...)
+ TODO: check
+CVE-2026-86612 (The Ninja Tables WordPress plugin before 5.2.17 does not restrict shor ...)
+ TODO: check
+CVE-2026-86604 (The GTranslate WordPress plugin before 5.0.1 does not remove shortcode ...)
+ TODO: check
+CVE-2026-86601 (The WP Recipe Maker WordPress plugin before 10.8.2 does not remove sho ...)
+ TODO: check
+CVE-2026-86583 (The Import and export users and customers plugin for WordPress is vuln ...)
+ TODO: check
+CVE-2026-86065 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-86064 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-85724 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when patt ...)
+ TODO: check
+CVE-2026-85475 (A flaw was found in the Ansible Automation Platform automation control ...)
+ TODO: check
+CVE-2026-84791 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
+ TODO: check
+CVE-2026-84789 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
+ TODO: check
+CVE-2026-84787 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
+ TODO: check
+CVE-2026-84724 (An argument-injection flaw was found in the Ansible Automation Platfor ...)
+ TODO: check
+CVE-2026-84721 (A server-side request forgery flaw was found in the Ansible Automation ...)
+ TODO: check
+CVE-2026-84720 (A flaw was found in the Ansible Automation Platform automation-control ...)
+ TODO: check
+CVE-2026-84719 (A flaw was found in the Ansible Automation Platform automation-control ...)
+ TODO: check
+CVE-2026-84718 (A flaw was found in the Ansible Automation Platform automation-control ...)
+ TODO: check
+CVE-2026-84717 (A flaw was found in the Ansible Automation Platform automation-control ...)
+ TODO: check
+CVE-2026-84716 (A flaw was found in the automation-controller instance ...)
+ TODO: check
+CVE-2026-84714 (A flaw was found in the automation-controller input-validation ...)
+ TODO: check
+CVE-2026-84713 (A flaw was found in the automation-controller notification ...)
+ TODO: check
+CVE-2026-84712 (A flaw was found in the automation-controller API. The ...)
+ TODO: check
+CVE-2026-84706 (A flaw was found in Ansible Automation Platform's automation-controlle ...)
+ TODO: check
+CVE-2026-84691 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
+ TODO: check
+CVE-2026-84683 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
+ TODO: check
+CVE-2026-84502 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
+ TODO: check
+CVE-2026-84499 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
+ TODO: check
+CVE-2026-84486 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
+ TODO: check
+CVE-2026-84474 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
+ TODO: check
+CVE-2026-84151 (The Post Grid WordPress plugin before 7.9.5 does not limit an expansi ...)
+ TODO: check
+CVE-2026-84091 (The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0. ...)
+ TODO: check
+CVE-2026-82850 (The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict acc ...)
+ TODO: check
+CVE-2026-82849 (The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that ...)
+ TODO: check
+CVE-2026-82409 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-82407 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-82406 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-82405 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
+ TODO: check
+CVE-2026-82370 (Unauthenticated remote command injection in the Brocade SANnav orchest ...)
+ TODO: check
+CVE-2026-82369 (Insufficient input sanitization of shell metacharacters in the Brocade ...)
+ TODO: check
+CVE-2026-82368 (Insecure access controls on internal service ports in Brocade SANnav v ...)
+ TODO: check
+CVE-2026-82356 (Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair af ...)
+ TODO: check
+CVE-2026-82195 (The 10Web Booster WordPress plugin before 2.34.0 does not restrict ac ...)
+ TODO: check
+CVE-2026-82077 (An improper limitation of a pathname to a restricted directory (path t ...)
+ TODO: check
+CVE-2026-81645 (Out-of-bounds read vulnerability in the graphics module.Successful exp ...)
+ TODO: check
+CVE-2026-81537 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-81536 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-81208 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticat ...)
+ TODO: check
+CVE-2026-80513 (The wpForo Forum WordPress plugin before 3.1.6 does not restrict which ...)
+ TODO: check
+CVE-2026-80444 (URL redirection to untrusted site ('open redirect') vulnerability in A ...)
+ TODO: check
+CVE-2026-80425 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-80423 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-80412 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-80379 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
+ TODO: check
+CVE-2026-80338 (The CMB2 WordPress plugin before 2.13.0 does not perform any capabilit ...)
+ TODO: check
+CVE-2026-79616 (Out-of-bounds read while parsing untrusted SVG path strings in Qt Quic ...)
+ TODO: check
+CVE-2026-79310 (webpy web.py 0.76 is vulnerable to server-side template injection (SST ...)
+ TODO: check
+CVE-2026-79306 (CyberPanel v1.9.1 contains a path traversal vulnerability in the compr ...)
+ TODO: check
+CVE-2026-79304 (CyberPanel 1.9.1 contains a path traversal vulnerability in the readFi ...)
+ TODO: check
+CVE-2026-78253 (Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Gr ...)
+ TODO: check
+CVE-2026-77602 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
+ TODO: check
+CVE-2026-77601 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
+ TODO: check
+CVE-2026-77423 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
+ TODO: check
+CVE-2026-77422 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
+ TODO: check
+CVE-2026-77421 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
+ TODO: check
+CVE-2026-77420 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
+ TODO: check
+CVE-2026-77394 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
+ TODO: check
+CVE-2026-77285 (OpenBao is an open source identity-based secrets management system. Pr ...)
+ TODO: check
+CVE-2026-77112 (Server-Side request forgery (SSRF) vulnerability in Global IT Informat ...)
+ TODO: check
+CVE-2026-76980 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
+ TODO: check
+CVE-2026-76979 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
+ TODO: check
+CVE-2026-76978 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
+ TODO: check
+CVE-2026-76648 (CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (I ...)
+ TODO: check
+CVE-2026-76089 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
+ TODO: check
+CVE-2026-76087 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
+ TODO: check
+CVE-2026-76086 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
+ TODO: check
+CVE-2026-75887 (A flaw was found in the OpenShift console. An unauthenticated attacker ...)
+ TODO: check
+CVE-2026-75886 (A flaw was found in openshift/console. An unauthenticated remote attac ...)
+ TODO: check
+CVE-2026-75884 (A flaw was found in AWX. The container group pod_spec_override field u ...)
+ TODO: check
+CVE-2026-75825 (ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the A ...)
+ TODO: check
+CVE-2026-74991 (The WPForms WordPress plugin before 2.0.2 does not verify that a Stri ...)
+ TODO: check
+CVE-2026-73858 (Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-bu ...)
+ TODO: check
+CVE-2026-73591 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
+ TODO: check
+CVE-2026-73589 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
+ TODO: check
+CVE-2026-73588 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
+ TODO: check
+CVE-2026-73587 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
+ TODO: check
+CVE-2026-73586 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
+ TODO: check
+CVE-2026-73192 (An improper neutralization of input during web page generation ('Cross ...)
+ TODO: check
+CVE-2026-71465 (RunAdHocCommand.build_args() appends limit as bare posit ...)
+ TODO: check
+CVE-2026-71464 (LaunchConfigurationBaseSerializer.scm_branch has no vali ...)
+ TODO: check
+CVE-2026-71463 (Notification template Jinja AST whitelist only inspects ...)
+ TODO: check
+CVE-2026-71462 (StringListPathField.to_internal_value() calls os.path.ex ...)
+ TODO: check
+CVE-2026-71461 (HostList.list() catches bare Exception and returns str(e) ...)
+ TODO: check
+CVE-2026-71460 (/api/v2/config/ is protected only by IsAuthenticated. li ...)
+ TODO: check
+CVE-2026-71459 (JobJobEventsChildrenSummary view has no model/parent_model. ...)
+ TODO: check
+CVE-2026-71458 (URLModificationMiddleware resolves named-URL lookups aga ...)
+ TODO: check
+CVE-2026-71178 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
+ TODO: check
+CVE-2026-71177 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
+ TODO: check
+CVE-2026-70125 (Microsoft Outlook Remote Code Execution Vulnerability)
+ TODO: check
+CVE-2026-6935 (IBM Concert 1.0.0 through 3.0.0 invokes operating system commands with ...)
+ TODO: check
+CVE-2026-6928 (IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it ...)
+ TODO: check
+CVE-2026-6925 (IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to trave ...)
+ TODO: check
+CVE-2026-6794 (IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that e ...)
+ TODO: check
+CVE-2026-6730 (IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, ca ...)
+ TODO: check
+CVE-2026-6721 (IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attac ...)
+ TODO: check
+CVE-2026-6718 (IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access contr ...)
+ TODO: check
+CVE-2026-6669 (Missing upper bound on the key derivation iteration count accepted dur ...)
+ TODO: check
+CVE-2026-6668 (Integer overflow in the packet buffer growth logic in PgBouncer throug ...)
+ TODO: check
+CVE-2026-6327 (IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to in ...)
+ TODO: check
+CVE-2026-68492 (An untrusted search path vulnerability in Plesk from 18.0.34 before 18 ...)
+ TODO: check
+CVE-2026-68490 (Incorrect permission assignment allows local users to obtain sensitive ...)
+ TODO: check
+CVE-2026-67405 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-67404 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-67240 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 ...)
+ TODO: check
+CVE-2026-67238 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 ...)
+ TODO: check
+CVE-2026-67235 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, ...)
+ TODO: check
+CVE-2026-67232 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-67231 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-67229 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-67228 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 ...)
+ TODO: check
+CVE-2026-67224 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-67221 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-67220 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-67219 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-67218 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22 ...)
+ TODO: check
+CVE-2026-66080 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11 ...)
+ TODO: check
+CVE-2026-66079 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-66077 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-66076 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-66075 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-66074 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-66072 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-66070 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-66069 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13 ...)
+ TODO: check
+CVE-2026-66068 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
+ TODO: check
+CVE-2026-66067 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 ...)
+ TODO: check
+CVE-2026-63132 (OpenBao is an open source identity-based secrets management system. Pr ...)
+ TODO: check
+CVE-2026-63131 (OpenBao is an open source identity-based secrets management system. Pr ...)
+ TODO: check
+CVE-2026-63002 (REDAXO is a PHP-based content management system. Prior to 5.21.2, reda ...)
+ TODO: check
+CVE-2026-63001 (REDAXO is a PHP-based content management system. Prior to 5.21.2, the ...)
+ TODO: check
+CVE-2026-63000 (REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_ ...)
+ TODO: check
+CVE-2026-62998 (REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_ ...)
+ TODO: check
+CVE-2026-61834 (scim-patch is a library for applying SCIM patch operations. Prior to 0 ...)
+ TODO: check
+CVE-2026-61814 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser ...)
+ TODO: check
+CVE-2026-61695 (Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, an ...)
+ TODO: check
+CVE-2026-61413 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
+ TODO: check
+CVE-2026-5696 (Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability ...)
+ TODO: check
+CVE-2026-5695 (Arbitrary file upload vulnerability due to a lack of proper validation ...)
+ TODO: check
+CVE-2026-59990 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods ...)
+ TODO: check
+CVE-2026-59980 (hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, ...)
+ TODO: check
+CVE-2026-59167 (SunEditor is a lightweight and powerful WYSIWYG editor in vanilla Java ...)
+ TODO: check
+CVE-2026-57854
+ REJECTED
+CVE-2026-57168
+ REJECTED
+CVE-2026-55632 (GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the int ...)
+ TODO: check
+CVE-2026-55610 (InvoiceShelf is an open-source web & mobile app that helps track expen ...)
+ TODO: check
+CVE-2026-55456
+ REJECTED
+CVE-2026-53979
+ REJECTED
+CVE-2026-53978
+ REJECTED
+CVE-2026-53969
+ REJECTED
+CVE-2026-53968
+ REJECTED
+CVE-2026-52744 (GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the int ...)
+ TODO: check
+CVE-2026-50228 (An unauthenticated local attacker can connect to the Electron DevTools ...)
+ TODO: check
+CVE-2026-50227 (An unauthenticated local attacker can connect to the MQTT broker over ...)
+ TODO: check
+CVE-2026-4921 (IBM Guardium Data Protection 12.2 could allow an administrative user t ...)
+ TODO: check
+CVE-2026-42801 (NULL pointer dereference vulnerability in ASR Crane\uff0cFalcon on Lin ...)
+ TODO: check
+CVE-2026-3626 (IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtai ...)
+ TODO: check
+CVE-2026-31377 (An Improper Authentication vulnerability in the Apache Doris Frontend ...)
+ TODO: check
+CVE-2026-19888 (Missing validation of a mandatory attribute in the SCRAM client-final- ...)
+ TODO: check
+CVE-2026-19599 (ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were v ...)
+ TODO: check
+CVE-2026-19267 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
+ TODO: check
+CVE-2026-19179 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-19125 (The EthPress \u2013 Web3 Login plugin for WordPress is vulnerable to A ...)
+ TODO: check
+CVE-2026-19087 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18944
+ REJECTED
+CVE-2026-18875 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
+ TODO: check
+CVE-2026-18872 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
+ TODO: check
+CVE-2026-18505 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
+ TODO: check
+CVE-2026-18490 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
+ TODO: check
+CVE-2026-18467 (The Paytium: Mollie payment forms & donations plugin for WordPress is ...)
+ TODO: check
+CVE-2026-18185 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18184 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18181 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18180 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18179 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-18177 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
+ TODO: check
+CVE-2026-15358 (ZohoCorp ManageEngine OpManager and Network Configuration Manager vers ...)
+ TODO: check
+CVE-2026-15027 (CGServiSign developed by Changing has a OS Command Injection vulnerabi ...)
+ TODO: check
+CVE-2026-14913 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.66 ...)
+ TODO: check
+CVE-2026-14780 (A vulnerability exists in the PaperCut NG/MF platform's device-scripti ...)
+ TODO: check
+CVE-2026-12974 (A Security Policy Bypass vulnerability exists in Forcepoint Security E ...)
+ TODO: check
+CVE-2026-12370 (ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configu ...)
+ TODO: check
+CVE-2026-11744 (An input validation vulnerability exists in the PaperCut Hive embedded ...)
+ TODO: check
+CVE-2025-63564 (SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through ...)
+ TODO: check
+CVE-2026-87022 (Improper handling of length parameter inconsistency vulnerability in A ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -6,7 +878,7 @@ CVE-2026-87022
NOTE: https://github.com/apache/tomcat/commit/4fef25fe2ab7509e697af093280b9daadb515615 (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/567a85515b78d1cd6410a89844b88109fcc2306f (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/959a52a227cc35101b92dae35b722546167594d6 (9.0.122)
-CVE-2026-86350
+CVE-2026-86350 (Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -14,7 +886,7 @@ CVE-2026-86350
NOTE: https://github.com/apache/tomcat/commit/192bc74996e1ad35d79118f750574d366bd43cea (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/259e938d3dedf07f3b24189fd5032adb95b01f2a (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/5adadc4ef413d5050f664d40800bbff74bd5d5ed (9.0.122)
-CVE-2026-86248
+CVE-2026-86248 (CLIENT_CERT authentication does not fail as expected for some scenario ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -22,7 +894,7 @@ CVE-2026-86248
NOTE: https://github.com/apache/tomcat/commit/9aab76056e7470bcc8ca9a20b33b6558b1046da2 (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/e5191b1e3292681097503f093b5432451ff5aa83 (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/fc41d82e0e383e4d6e88ad321d245dafdc17d26d (9.0.122)
-CVE-2026-79677
+CVE-2026-79677 (Missing release of resource after effective lifetime, Comparison using ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -30,7 +902,7 @@ CVE-2026-79677
NOTE: https://github.com/apache/tomcat/commit/7ab11d10de79a7a2226f41c8289871db69c6ca9c (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/bb676e53cd0bdcbecfe9650841e99973a7693f7e (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/c8fa5430233bca5b209c593dd446f88fda9d543e (9.0.122)
-CVE-2026-78437
+CVE-2026-78437 (Incomplete cleanup vulnerability in Apache Tomcat allows a malformed r ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -38,7 +910,7 @@ CVE-2026-78437
NOTE: https://github.com/apache/tomcat/commit/70579060454a203977b5696ece71e7cbd6ee9bde (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/4ac5da0906c500f6042844d7f17e9fb174820758 (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/a28c35055ab11d35929ad564beb1a23a67b39546 (9.0.122)
-CVE-2026-78383
+CVE-2026-78383 (Allocation of resources without limits or throttling vulnerability in ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -46,7 +918,7 @@ CVE-2026-78383
NOTE: https://github.com/apache/tomcat/commit/6dabd4303095785183ede57f6d162c542955a5a8 (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/2ed6d18ebfe4b085ef050dd0a0f4f20aff3bc48d (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/265bdc0a58b1447ff5d8f8b96ea81de58cb74c8c (9.0.122)
-CVE-2026-77791
+CVE-2026-77791 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat durin ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -54,7 +926,7 @@ CVE-2026-77791
NOTE: https://github.com/apache/tomcat/commit/ce291bbc65393e3bfbec2a8d23fcee0106a1ade9 (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/e896f73c868f66dfb2a93565fda4d13cd5909d2d (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/7a5945f1de1d3310214234dfbbd7c569af52d058 (9.0.122)
-CVE-2026-77762
+CVE-2026-77762 (Concurrent Execution using Shared Resource with Improper Synchronizati ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -62,7 +934,7 @@ CVE-2026-77762
NOTE: https://github.com/apache/tomcat/commit/fd309997dfd0d351b26959a8afd7bffec33dd0de (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/77d2d59347891eced52b0cb5a979fc33a8a2620c (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/71f27c2e84810930beda468b5ba732dcd0ef2652 (9.0.122)
-CVE-2026-77756
+CVE-2026-77756 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -70,7 +942,7 @@ CVE-2026-77756
NOTE: https://github.com/apache/tomcat/commit/1ad63de866a6e7007304ebe5165f72e65ece32b6 (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/bf44bee23d97fbb1a64cbbbb213ff2b6506d26c4 (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/e590588ab7649c93d49b0eb7b3152700a977880d (9.0.122)
-CVE-2026-76183
+CVE-2026-76183 (Authentication Bypass by Alternate Name vulnerability in Apache Tomcat ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -78,7 +950,7 @@ CVE-2026-76183
NOTE: https://github.com/apache/tomcat/commit/e182d86b7d4cc19ec4c24c38f37acc004404fe8e (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/5b48790abd13d94c2bd351027a39a671916b5ddf (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/a93a60a33f4cc202542eb6a0b87b7142d7db311c (9.0.122)
-CVE-2026-75973
+CVE-2026-75973 (Improper Authentication vulnerability in Apache Tomcat. When Jakarta A ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -86,7 +958,7 @@ CVE-2026-75973
NOTE: https://github.com/apache/tomcat/commit/2585fc798f24f0b8811fd20ad9b4e8affb6f69a6 (11.0.26)
NOTE: https://github.com/apache/tomcat/commit/f62c65768fdaa300e22e64ffa7b5118dce0571a1 (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/043115414a39127cad015e9d285296e59c18bb41 (9.0.122)
-CVE-2026-73581
+CVE-2026-73581 (Improper Check for Certificate Revocation vulnerability in Apache Tomc ...)
- tomcat11 <unfixed>
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
@@ -126,19 +998,20 @@ CVE-2026-XXXX [GHSA-r6xj-6488-p8mv: NTFS-3G-SA_2026-06-1_05]
[experimental] - ntfs-3g 1:2026.9.18-1
- ntfs-3g <unfixed>
NOTE: https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-r6xj-6488-p8mv
-CVE-2026-86247
+CVE-2026-86247 (Race condition within a thread vulnerability in Apache Tomcat Native a ...)
- tomcat-native 2.0.16-1
NOTE: Fixed by: https://github.com/apache/tomcat-native/commit/fb688de41e837d98e76961e44584b37989e4f7d0 (2.0.16)
NOTE: Fixed by: https://github.com/apache/tomcat-native/commit/3dc73c118d2202c8dfc6053787cc6d61416ddce6 (1.3.9)
-CVE-2026-86246
+CVE-2026-86246 (Initialization of a resource with an insecure default vulnerability in ...)
- tomcat-native 2.0.16-1
NOTE: Fixed by: https://github.com/apache/tomcat-native/commit/f6bb04b28f234a35c21a2997963195ae1d86de69 (2.0.16)
NOTE: Fixed by: https://github.com/apache/tomcat-native/commit/77a87991079211805f41ddb2c51067bb807dcb40 (1.3.9)
-CVE-2026-86243
+CVE-2026-86243 (Buffer over-read vulnerability in Apache Tomcat Native during the TLS ...)
- tomcat-native 2.0.16-1
NOTE: Fixed by: https://github.com/apache/tomcat-native/commit/9a7c804afc05fdc630520eb4012ce1c4ff787862 (2.0.16)
NOTE: Fixed by: https://github.com/apache/tomcat-native/commit/ce019af0db385dfd5bc7c7a759f71602559a0499 (1.3.9)
CVE-2026-94422
+ {DSA-6510-1}
- xdg-dbus-proxy 0.1.9-1 (bug #1148782)
NOTE: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq
CVE-2026-92709
@@ -7349,7 +8222,7 @@ CVE-2026-92770 (Harbor through 2.15.2 fails to properly restrict the q query par
NOT-FOR-US: Harbor
CVE-2026-92765 (ArcherySec through 2.0.6 fails to validate organization ownership in t ...)
NOT-FOR-US: ArcherySec
-CVE-2026-92764 (OpenCVE before 3.1.0 fails to properly scope the organizations API end ...)
+CVE-2026-92764 (OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organi ...)
NOT-FOR-US: OpenCVE
CVE-2026-92763 (Rundeck through 6.2.1 fails to properly authorize the importConfig and ...)
NOT-FOR-US: Rundeck
@@ -11351,9 +12224,11 @@ CVE-2026-89088 [heap buffer overflow in duplicate_legacy_root_dir]
NOTE: https://alioth-lists.debian.net/pipermail/parted-devel/2026-September/006032.html
NOTE: Fixed by: https://gitweb.git.savannah.gnu.org/gitweb/?p=parted.git;a=commit;h=73301c6915781c2eee66d0b1cc9d41a70bf901d6 (v3.7.13)
CVE-2026-82373
+ {DSA-6511-1}
- znc 1.10.3-1
NOTE: https://wiki.znc.in/ChangeLog/1.10.3
CVE-2026-82374
+ {DSA-6511-1}
- znc 1.10.3-1
NOTE: https://wiki.znc.in/ChangeLog/1.10.3
CVE-2026-91726 (Out of bounds read in WebGL in Google Chrome on on Android prior to 15 ...)
@@ -14439,12 +15314,12 @@ CVE-2026-19624 (A flaw was found in NetworkManager-l2tp. The plugin writes attac
- network-manager-l2tp 1.52.6-1
NOTE: https://github.com/nm-l2tp/NetworkManager-l2tp/security/advisories/GHSA-fcq2-qh3w-4xq5
NOTE: Fixed by: https://github.com/nm-l2tp/NetworkManager-l2tp/commit/3704d8c9d5e5f9ed1626a8ce7627a04247cea673 (1.52.6, 1.20.26)
-CVE-2026-75131
+CVE-2026-75131 (NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privil ...)
{DSA-6498-1}
- network-manager-l2tp 1.52.6-1
NOTE: https://github.com/nm-l2tp/NetworkManager-l2tp/security/advisories/GHSA-v2wj-xr2m-xc4j
NOTE: Fixed by: https://github.com/nm-l2tp/NetworkManager-l2tp/commit/64879ce0ad866f7c9a45babe4d95731a916ea00f (1.52.6, 1.20.26)
-CVE-2026-93337 (NetworkManager-l2tp contains an improper input validation vulnerabilit ...)
+CVE-2026-93337 (NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an impro ...)
{DSA-6498-1}
- network-manager-l2tp 1.52.6-1
NOTE: https://github.com/nm-l2tp/NetworkManager-l2tp/security/advisories/GHSA-rp84-8h2r-5xc3
@@ -15245,7 +16120,7 @@ CVE-2026-77689 (The Booking for Appointments and Events Calendar WordPress plug
NOT-FOR-US: WordPress plugin
CVE-2026-77490 (Improper neutralization of input during web page generation ('cross-si ...)
NOT-FOR-US: Microsoft
-CVE-2026-77006 (The WebTotem Backups WordPress plugin through 1.0.1 does not validate ...)
+CVE-2026-77006 (The WebTotem Backups WordPress plugin before 1.1.0 does not validate a ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77005 (The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not va ...)
NOT-FOR-US: WordPress plugin
@@ -18142,7 +19017,7 @@ CVE-2026-15418 (In the silabser.sys driver for CP210x devices v11.5.0 and earlie
NOT-FOR-US: Silicon Labs
CVE-2026-15417 (In the silabser.sys Windows 8 driver for CP210x devices, a local unpri ...)
NOT-FOR-US: Silicon Labs
-CVE-2026-13745 (A vulnerability in the Gemini CLI and associated GitHub Action allowed ...)
+CVE-2026-13745 (A vulnerability in the Gemini CLI prior to version 0.39.1 allows attac ...)
NOT-FOR-US: Gemini CLI
CVE-2026-12683 (Improper neutralization of input during web page generation ('cross-si ...)
NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
@@ -22254,7 +23129,7 @@ CVE-2026-69445 (Improper limitation of a pathname to a restricted directory ('pa
NOT-FOR-US: Microsoft
CVE-2026-69444 (Heap-based buffer overflow in Microsoft Windows Speech allows an autho ...)
NOT-FOR-US: Microsoft
-CVE-2026-69443 (Out-of-bounds read in Windows Device Health Attestation (DHA) allows a ...)
+CVE-2026-69443 (Out-of-bounds read in Microsoft Azure Attestation service and Device H ...)
NOT-FOR-US: Microsoft
CVE-2026-69442 (Heap-based buffer overflow in Microsoft Office allows an unauthorized ...)
NOT-FOR-US: Microsoft
@@ -27222,7 +28097,7 @@ CVE-2026-84837 (A flaw was found in rpm. An attacker can exploit a command injec
[trixie] - rpm <no-dsa> (Minor issue)
[bookworm] - rpm <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478408
-CVE-2026-84835 (Missing Authorization vulnerability in DimaFreund Rentsyst allows Expl ...)
+CVE-2026-84835 (Missing Authorization vulnerability in DimaFreund Rentsyst rentsyst al ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-84833 (A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa ...)
NOT-FOR-US: ntegrals openbrowser
@@ -28726,7 +29601,7 @@ CVE-2026-82927 (Untrusted pointer dereference vulnerability in Samsung Open Sour
NOT-FOR-US: Samsung mTower
CVE-2026-82926 (NULL pointer dereference vulnerability in Samsung Open Source mTower a ...)
NOT-FOR-US: Samsung mTower
-CVE-2026-80047 (A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and < ...)
+CVE-2026-80047 (A vulnerability in Hugging Face Transformers (versions 4.57.0 to 5.16. ...)
NOT-FOR-US: Hugging Face Transformers
CVE-2026-7877 (The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stor ...)
NOT-FOR-US: WordPress plugin
@@ -41802,7 +42677,8 @@ CVE-2026-79992 (A flaw was found in Emacs TRAMP. A local attacker could exploit
- emacs <unfixed> (bug #1145049)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/21/1
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=f3e7104d05bdb8e32ba13bf75604108ad88536dc
-CVE-2026-96269 [arbitrary code execution upon opening file]
+CVE-2026-96269 (GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon openi ...)
+ {DSA-6468-1}
- emacs 1:30.2+1-11
NOTE: https://www.openwall.com/lists/oss-security/2026/08/20/3
NOTE: https://eshelyaron.com/posts/2026-08-06-emacs-arbitrary-code-execution-returns.html
@@ -57262,7 +58138,8 @@ CVE-2026-90616 (In Flatpak before 1.18.1, a malicious sandboxed app can obtain a
NOTE: Additional tests: https://github.com/flatpak/flatpak/commit/f9da73e1e9830e134886be5a50e9de9c382379c4 (branch flatpak-1.16.x)
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/3d43a0f5fa602cc3edc557d8ab835030140792b1 (branch flatpak-1.16.x)
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
-CVE-2026-96808 [GHSA-qrwq-7qwx-q9rp]
+CVE-2026-96808 (In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-sys ...)
+ {DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/a3583bc87d4f86c2794ff879ea56fce95b0b0b5f (1.18.1)
@@ -57273,7 +58150,7 @@ CVE-2026-96808 [GHSA-qrwq-7qwx-q9rp]
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/4d1eb212237069681b1f994e2b5b61e40015050f (branch flatpak-1.16.x)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/076f77a4775490b2aef43f4e01eeee9aa965bd21 (branch flatpak-1.16.x)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/769ad563bae82b948496a7edffa5eb3f71d0cc72 (branch flatpak-1.16.x)
-CVE-2026-96275 [GHSA-fqx6-vh4p-42cg]
+CVE-2026-96275 (A malicious or compromised Flatpak repository can write attacker-contr ...)
{DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg
@@ -57289,7 +58166,7 @@ CVE-2026-96275 [GHSA-fqx6-vh4p-42cg]
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/de3decabfd2bc62a774698342d1a9e8ea98077d7 (branch flatpak-1.16.x)
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/3d43a0f5fa602cc3edc557d8ab835030140792b1 (branch flatpak-1.16.x)
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
-CVE-2026-96276 [GHSA-8qxj-x646-phcm]
+CVE-2026-96276 (If a malicious SDK container declares an extension point with a crafte ...)
{DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm
@@ -57329,7 +58206,8 @@ CVE-2026-96280 [GHSA-jr92-2v97-wgvc]
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/6be548dd3ac780407ff3cc5824eb9d2acb9f406a (branch flatpak-1.16.x)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/592e8c6704d310e3b6418caff52e0cc85271c8e3 (branch flatpak-1.16.x)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/a79764d78b29aa592b612061071b2c361bda4f9e (branch flatpak-1.16.x)
-CVE-2026-96807 [GHSA-99wv-m8rp-g58x]
+CVE-2026-96807 (In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var ...)
+ {DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/e13dfeda330625d2fecc3a54672dfd4dc9c83a5c (1.18.1)
@@ -62248,8 +63126,8 @@ CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack rec
- apr-util 1.6.4-1 (bug #1143837)
NOTE: https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1
NOTE: Fixed by: https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8 (1.6.4-rc1-candidate)
-CVE-2026-28183
- REJECTED
+CVE-2026-28183 (Incorrect Privilege Assignment vulnerability in PublishPress PublishPr ...)
+ TODO: check
CVE-2026-28180 (Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pa ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28179 (Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versio ...)
@@ -69269,19 +70147,19 @@ CVE-2026-15735 (The Contact Form to Any API plugin for WordPress is vulnerable t
NOT-FOR-US: WordPress plugin
CVE-2026-15344 (The WP Photo Album Plus plugin for WordPress is vulnerable to generic ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-15328 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+CVE-2026-15328 (IBM WebSphere Application Server and IBM WebSphere Application Server ...)
NOT-FOR-US: IBM
CVE-2026-15325 (IBM WebSphere Application Server and IBM WebSphere Application Server ...)
NOT-FOR-US: IBM
CVE-2026-15280 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 N ...)
NOT-FOR-US: IBM
-CVE-2026-15064 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+CVE-2026-15064 (IBM WebSphere Application Server and IBM WebSphere Application Server ...)
NOT-FOR-US: IBM
CVE-2026-15057 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i ...)
NOT-FOR-US: IBM
CVE-2026-14996 (IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerabili ...)
NOT-FOR-US: IBM
-CVE-2026-14981 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
+CVE-2026-14981 (IBM WebSphere Application Server and IBM WebSphere Application Server ...)
NOT-FOR-US: IBM
CVE-2026-14976 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
NOT-FOR-US: IBM
@@ -74214,7 +75092,7 @@ CVE-2026-43820 (NIOSSLCertificate._subjectAlternativeNames provides access to th
NOT-FOR-US: Apple
CVE-2026-27423 (Subscriber Broken Access Control in Participants Database <= 2.7.8.4 v ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-27422 (Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.)
+CVE-2026-27422 (Missing Authorization vulnerability in bPlugins YT Player yt-player al ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-27418 (Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81. ...)
NOT-FOR-US: WordPress plugin or theme
@@ -98124,7 +99002,7 @@ CVE-2026-37149 (GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v
NOT-FOR-US: GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN
CVE-2026-2299 (The Mattermost Google Drive plugin before version 1.1.0 fails to valid ...)
NOT-FOR-US: Mattermost plugin
-CVE-2026-22879 (vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow ...)
+CVE-2026-22879 (A heap-based buffer overflow vulnerability exists in the vtkDICOMItem: ...)
- vtk-dicom <unfixed> (bug #1142344)
[trixie] - vtk-dicom <no-dsa> (Minor issue)
[bookworm] - vtk-dicom <postponed> (Minor issue; OOB write reachable only by parsing an attacker-supplied DICOM file, and no upstream fix exists yet, PR #253 unmerged)
@@ -123406,11 +124284,11 @@ CVE-2026-25901 (Lack of output escaping leads to a XSS vector in the multilingua
NOT-FOR-US: Joomla
CVE-2026-25900 (Lack of output escaping leads to a XSS vector in the feed modules.)
NOT-FOR-US: Joomla
-CVE-2026-25713 (MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerabilit ...)
+CVE-2026-25713 (A heap-based buffer overflow vulnerability exists in the ID3v2 parsing ...)
NOT-FOR-US: MediaArea MediaInfoLib
CVE-2026-25112 (A high-severity vulnerability in the deployment of Genetec RabbitMQ th ...)
NOT-FOR-US: Genetec
-CVE-2026-25104 (MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerab ...)
+CVE-2026-25104 (A heap-based buffer overflow vulnerability exists in the LXF parsing f ...)
NOT-FOR-US: MediaArea MediaInfoLib
CVE-2026-24638 (Missing Authorization vulnerability in Webful Creations RepairBuddy al ...)
NOT-FOR-US: WordPress plugin or theme
@@ -124966,7 +125844,7 @@ CVE-2026-34926 (A directory traversal vulnerability in the Apex One (on-premise)
NOT-FOR-US: Trend Micro
CVE-2026-2740 (Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecu ...)
NOT-FOR-US: Zoho
-CVE-2026-28764 (MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow ...)
+CVE-2026-28764 (A heap-based buffer overflow vulnerability exists in the LXF element p ...)
NOT-FOR-US: MediaInfoLib
CVE-2026-27393 (Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Ex ...)
NOT-FOR-US: WordPress plugin or theme
@@ -125645,7 +126523,7 @@ CVE-2026-24425 (Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox
[bullseye] - php-twig <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/twigphp/Twig/security/advisories/GHSA-2q52-x2ff-qgfr
NOTE: https://symfony.com/blog/cve-2026-24425-possible-sandbox-bypass-when-using-a-source-policy
-CVE-2026-22554 (MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vu ...)
+CVE-2026-22554 (A heap-based buffer overflow vulnerability exists in the Channel Split ...)
NOT-FOR-US: MediaInfoLib
CVE-2026-22315 (Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client L ...)
NOT-FOR-US: Meona
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/04693d5947179318b16b16367d93888c9da5a75f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/04693d5947179318b16b16367d93888c9da5a75f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/fc04e970/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list