Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
07e4aaed by security tracker role at 2026-08-03T19:13:46+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,14 +1,226 @@
-CVE-2026-18089
+CVE-2026-8794 (PaperCut NG/MF contains an observable timing discrepancy in its
authen ...)
+ TODO: check
+CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive
authentication att ...)
+ TODO: check
+CVE-2026-69153 (PostCSS takes a CSS file and provides an API to analyze and
modify its ...)
+ TODO: check
+CVE-2026-69152 (The brace-expansion library generates arbitrary strings
containing a c ...)
+ TODO: check
+CVE-2026-69151 (Angular is a development platform for building mobile and
desktop web ...)
+ TODO: check
+CVE-2026-69149 (Angular is a development platform for building mobile and
desktop web ...)
+ TODO: check
+CVE-2026-69097 (GitPython before 3.1.53 fails to properly escape section names
in git ...)
+ TODO: check
+CVE-2026-69096 (OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12
snapshots co ...)
+ TODO: check
+CVE-2026-69095 (OpenWrt luci-app-bmx7 before commit
5890760a454dad2cb00389dba2cdc5e779 ...)
+ TODO: check
+CVE-2026-69094 (Admidio before 5.0.11 contains an insecure direct object
reference vul ...)
+ TODO: check
+CVE-2026-69093 (Admidio before 5.0.11 does not validate the adm_csrf_token in
modules/ ...)
+ TODO: check
+CVE-2026-69092 (Admidio versions before 5.0.11 contain a reflected cross-site
scriptin ...)
+ TODO: check
+CVE-2026-69091 (Admidio before 5.0.11 contains an authentication bypass
vulnerability ...)
+ TODO: check
+CVE-2026-69090 (Admidio before 5.0.11 fails to validate target organization
membership ...)
+ TODO: check
+CVE-2026-69089 (Grav CMS 2.0.10 contains a path traversal vulnerability in
ImageMedium ...)
+ TODO: check
+CVE-2026-69088 (Grav CMS versions 2.0.7 through 2.0.10 fail to validate
fully-qualifie ...)
+ TODO: check
+CVE-2026-69087 (The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13
contains ...)
+ TODO: check
+CVE-2026-69086 (SiYuan versions before v3.7.3 fail to validate the avID
parameter on a ...)
+ TODO: check
+CVE-2026-69085 (SiYuan before v3.7.3 contains a SQL injection vulnerability in
the /ap ...)
+ TODO: check
+CVE-2026-69084 (SiYuan versions <= v3.7.2 expose the
/api/search/searchEmbedBlock endp ...)
+ TODO: check
+CVE-2026-69083 (SiYuan versions before v3.7.3 contain SQL injection
vulnerabilities in ...)
+ TODO: check
+CVE-2026-69082 (CTI-Transmute contained a cross-site request forgery
vulnerability in ...)
+ TODO: check
+CVE-2026-69079 (CTI-Transmute contains an uncontrolled resource-consumption
vulnerabil ...)
+ TODO: check
+CVE-2026-69078 (CTI-Transmute is affected by a server-side request forgery
vulnerabili ...)
+ TODO: check
+CVE-2026-69075 (FlowIntel is affected by a stored cross-site scripting
vulnerability t ...)
+ TODO: check
+CVE-2026-68945 (Angular is a development platform for building mobile and
desktop web ...)
+ TODO: check
+CVE-2026-68930 (Russh is a Rust SSH client & server library. Prior to 0.62.5,
russh di ...)
+ TODO: check
+CVE-2026-68869
+ REJECTED
+CVE-2026-68742 (A flaw was found in SSSD. The sss_nss_protocol_parse_addr()
function i ...)
+ TODO: check
+CVE-2026-68587 (SiYuan versions before v3.7.3 contain an information
disclosure vulner ...)
+ TODO: check
+CVE-2026-68586 (SiYuan before v3.7.3 fails to apply publish-access filters to
the getB ...)
+ TODO: check
+CVE-2026-68585 (SiYuan versions before v3.7.3 contain a metadata disclosure
vulnerabil ...)
+ TODO: check
+CVE-2026-68584 (SiYuan versions before v3.7.3 contain an authentication bypass
vulnera ...)
+ TODO: check
+CVE-2026-67612 (OpenEMR through 8.2.0 contains a stored cross-site scripting
vulnerabi ...)
+ TODO: check
+CVE-2026-67611 (OpenEMR through 8.2.0 contains an authentication bypass
vulnerability ...)
+ TODO: check
+CVE-2026-67610 (OpenEMR through 8.2.0 contains an improper authentication
vulnerabilit ...)
+ TODO: check
+CVE-2026-67609 (Telenia Software TVox 26.5.3 and prior 26.x versions, and
24.9.21 and ...)
+ TODO: check
+CVE-2026-67608 (Telenia Software TVox 26.5.3 and prior 26.x versions, and
24.9.21 and ...)
+ TODO: check
+CVE-2026-64827 (Telenia Software TVox 26.5.3 and prior 26.x versions, and
24.9.21 and ...)
+ TODO: check
+CVE-2026-63563 (Sharp and Toshiba Tec MFPs (multifunction printers) for a
certain mark ...)
+ TODO: check
+CVE-2026-63545 (Sharp and Toshiba Tec MFPs (multifunction printers) caches
data intern ...)
+ TODO: check
+CVE-2026-62416 (Network Scanner Tool and Network Scanner Tool Lite provided by
Sharp C ...)
+ TODO: check
+CVE-2026-61524 (WebsiteBaker CMS before 2.13.10 contains an unrestricted file
upload v ...)
+ TODO: check
+CVE-2026-61523 (WebsiteBaker CMS before 2.13.10 contains a code injection
vulnerabilit ...)
+ TODO: check
+CVE-2026-61372 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
+ TODO: check
+CVE-2026-60011 (Sharp and Toshiba Tec MFPs (multifunction printers) fail to
properly a ...)
+ TODO: check
+CVE-2026-59913 (Dell Display and Peripheral Manager (DDPM Mac), versions prior
to 2.3. ...)
+ TODO: check
+CVE-2026-59912 (Dell Display and Peripheral Manager (DDPM Mac), versions prior
to 2.3. ...)
+ TODO: check
+CVE-2026-56609 (HCL iControl is affected by Weak SSL/TLS Version Supported
vulnerabili ...)
+ TODO: check
+CVE-2026-56608 (HCL iControl is affected by Missing Access Control
vulnerability. The ...)
+ TODO: check
+CVE-2026-41453 (Krayin CRM before 2.2.4 contains a blind SQL injection
vulnerability i ...)
+ TODO: check
+CVE-2026-41452 (Krayin CRM 2.2.4 contains a missing authentication
vulnerability in th ...)
+ TODO: check
+CVE-2026-40717 (Dell Monitor driver, version 1.0.0.0, contains an Improper
Link Resolu ...)
+ TODO: check
+CVE-2026-39932 (OpenEMR through 8.2.0 contains a remote code execution
vulnerability i ...)
+ TODO: check
+CVE-2026-39931 (OpenEMR through 8.2.0 contains an authenticated SQL injection
vulnerab ...)
+ TODO: check
+CVE-2026-38447 (osTicket 1.18.3 generates API keys using a predictable
construction ba ...)
+ TODO: check
+CVE-2026-38446 (A stored cross-site scripting (XSS) vulnerability exists in
osTicket 1 ...)
+ TODO: check
+CVE-2026-38444 (osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting
(XSS) vi ...)
+ TODO: check
+CVE-2026-33591 (A vulnerability in Wapt Server before version 2.6.1.17813
allows a rem ...)
+ TODO: check
+CVE-2026-2346 (Authorization bypass through User-Controlled key vulnerability
in Menu ...)
+ TODO: check
+CVE-2026-28147 (Missing Authorization vulnerability in Unlimited Elements
Unlimited El ...)
+ TODO: check
+CVE-2026-21555 (In modem, there is a possible improper input validation. This
could le ...)
+ TODO: check
+CVE-2026-21554 (In modem, there is a possible improper input validation. This
could le ...)
+ TODO: check
+CVE-2026-21553 (In modem, there is a possible improper input validation. This
could le ...)
+ TODO: check
+CVE-2026-21552 (In modem, there is a possible improper input validation. This
could le ...)
+ TODO: check
+CVE-2026-21551 (In modem, there is a possible improper input validation. This
could le ...)
+ TODO: check
+CVE-2026-21550 (In modem, there is a possible improper input validation. This
could le ...)
+ TODO: check
+CVE-2026-21549 (In modem, there is a possible improper input validation. This
could le ...)
+ TODO: check
+CVE-2026-21548 (In nr modem, there is a possible improper input validation.
This could ...)
+ TODO: check
+CVE-2026-18718 (Ghidra contains an arbitrary code execution vulnerability in
the Swift ...)
+ TODO: check
+CVE-2026-18651 (A flaw was found in 389 Directory Server. During SASL PLAIN
authentica ...)
+ TODO: check
+CVE-2026-18642 (Deserialization of untrusted data vulnerability in TUBITAK
BILGEM Soft ...)
+ TODO: check
+CVE-2026-18616 (A vulnerability was identified in GL-iNet GL-MT3000 up to
4.4.5. The i ...)
+ TODO: check
+CVE-2026-18615 (A vulnerability was determined in GL-iNet GL-MT3000 up to
4.4.5. The a ...)
+ TODO: check
+CVE-2026-18614 (A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5.
Impacted i ...)
+ TODO: check
+CVE-2026-18613 (A vulnerability has been found in GL-iNet GL-MT3000 up to
4.4.5. This ...)
+ TODO: check
+CVE-2026-18612 (A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This
vulnerabi ...)
+ TODO: check
+CVE-2026-18610 (A vulnerability was detected in NewType WebEIP up to 3.0. This
affects ...)
+ TODO: check
+CVE-2026-18607 (A security vulnerability has been detected in Wavlink WN572,
WN570H, W ...)
+ TODO: check
+CVE-2026-18606 (A weakness has been identified in Razer RzUpdateService
1.10.14.0. Aff ...)
+ TODO: check
+CVE-2026-18605 (A security flaw has been discovered in CheckMAL AppCheck Pro
3.1.43.10 ...)
+ TODO: check
+CVE-2026-18604 (A vulnerability was identified in textPlus Text Message and
Call App u ...)
+ TODO: check
+CVE-2026-18602 (A vulnerability was determined in GL.iNet GL-MT3000 up to
4.4.5. Affec ...)
+ TODO: check
+CVE-2026-18601 (A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5.
This impac ...)
+ TODO: check
+CVE-2026-18600 (A vulnerability has been found in GL.iNet GL-MT3000 up to
4.4.5. This ...)
+ TODO: check
+CVE-2026-18599 (A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The
impacted e ...)
+ TODO: check
+CVE-2026-18598 (A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5.
The aff ...)
+ TODO: check
+CVE-2026-18593 (A weakness has been identified in vxcontrol PentAGI up to
2.1.0. This ...)
+ TODO: check
+CVE-2026-18592 (A security flaw has been discovered in osCommerce 4.14.63493.
Affected ...)
+ TODO: check
+CVE-2026-18591 (A vulnerability was identified in Meesho Online Shopping App
up to 202 ...)
+ TODO: check
+CVE-2026-18590 (A vulnerability was determined in Wavlink WL-NU516U1
708c073-mt7628. A ...)
+ TODO: check
+CVE-2026-18574 (An authentication bypass vulnerability in Check Point Security
Managem ...)
+ TODO: check
+CVE-2026-18508 (A flaw was found in GNU tar. When extracting an archive with
the --one ...)
+ TODO: check
+CVE-2026-18477 (A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU
tar's increm ...)
+ TODO: check
+CVE-2026-18248 (@fastify/aws-lambda version 6.4.0 decorates each Fastify
request with ...)
+ TODO: check
+CVE-2026-18243 (Certain HP DesignJet products may be potentially vulnerable to
cross-s ...)
+ TODO: check
+CVE-2026-15430 (Improper access control in the IRP_MJ_WRITE command interface
in Wellb ...)
+ TODO: check
+CVE-2026-12259 (In nltk version 3.9.4, the
`nltk.downloader.Downloader._download_packa ...)
+ TODO: check
+CVE-2026-0392 (eParakst\u012bt\u0101js 3.0 for Windows before version 1.10.0
retrieve ...)
+ TODO: check
+CVE-2025-9291 (A certification validation weakness exists in communication
between af ...)
+ TODO: check
+CVE-2025-15631 (A cryptographic weakness exists in affected Omada devices
where site c ...)
+ TODO: check
+CVE-2025-15630 (A race condition exists in the cloud-based Omada device
adoption proce ...)
+ TODO: check
+CVE-2025-15629 (A cryptographic weakness exists in the Omada adoption protocol
where s ...)
+ TODO: check
+CVE-2025-15628 (Affected Omada devices rely on embedded certificates that are
shared a ...)
+ TODO: check
+CVE-2025-15627 (A cryptographic weakness exists in the Omada adoption
protocol. The pr ...)
+ TODO: check
+CVE-2025-15544 (A cryptographic weakness exists in the Omada device adoption
process. ...)
+ TODO: check
+CVE-2026-18089 (Net::SAML2 versions before 0.86 for Perl allow SAML
authentication byp ...)
NOT-FOR-US: Net-SAML2 Perl module
-CVE-2026-18108
+CVE-2026-18108 (Net::SAML2 versions before 0.86 for Perl allow authentication
bypass b ...)
NOT-FOR-US: Net-SAML2 Perl module
-CVE-2026-18092
+CVE-2026-18092 (Net::SAML2 versions before 0.86 for Perl allow SAML
authentication byp ...)
NOT-FOR-US: Net-SAML2 Perl module
-CVE-2026-9390
+CVE-2026-9390 (XML::Sig versions before 0.71 for Perl allow XPath injection in
ID loo ...)
NOT-FOR-US: XML-Sig Perl module
-CVE-2026-9487
+CVE-2026-9487 (XML::Sig versions before 0.71 for Perl allow signature wrapping
via du ...)
NOT-FOR-US: XML-Sig Perl module
-CVE-2026-18568
+CVE-2026-18568 (XML::Sig versions from 0.29 before 0.72 for Perl allow
signature verif ...)
NOT-FOR-US: XML-Sig Perl module
CVE-2026-9593 (A vulnerability in the iDTM FDI allows an attacker with
elevated privi ...)
NOT-FOR-US: iDTM FDI
@@ -8373,7 +8585,7 @@ CVE-2026-65528 (Contributor Cross Site Scripting (XSS) in
BSK PDF Manager <= 3.8
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65527 (Contributor Cross Site Scripting (XSS) in LIQUID SPEECH
BALLOON <= 1.2 ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-65526 (Contributor SQL Injection in Visualizer <= 4.0.6 versions.)
+CVE-2026-65526 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65525 (Unauthenticated Broken Access Control in Civi Framework <=
2.2.0 versi ...)
NOT-FOR-US: WordPress plugin or theme
@@ -26423,7 +26635,7 @@ CVE-2026-27404 (Unauthenticated Cross Site Scripting
(XSS) in LMS <= 9.7 version
NOT-FOR-US: WordPress plugin or theme
CVE-2026-27402 (Unauthenticated Cross Site Scripting (XSS) in Kids Life |
Children Sch ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-27060 (Contributor PHP Object Injection in ARMember Premium <= 7.0
versions.)
+CVE-2026-27060 (Deserialization of Untrusted Data vulnerability in Repute
Infosystems ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-14449 (u5CMSthroughv12.8.8 is vulnerable to reflected XSS via the
\u2018thank ...)
NOT-FOR-US: u5CMSthroughv12.8.8
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07e4aaed4037a11f1198577bf9c249dd422b2293
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07e4aaed4037a11f1198577bf9c249dd422b2293
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits