Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f8d2266e by security tracker role at 2026-08-06T07:12:31+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,241 @@
+CVE-2026-71321 (Nuxt is an open-source web development framework for Vue.js.
From 3.1. ...)
+ TODO: check
+CVE-2026-71320 (Nuxt is an open-source web development framework for Vue.js.
From 3.4. ...)
+ TODO: check
+CVE-2026-71319 (Nuxt is an open-source web development framework for Vue.js.
Prior to ...)
+ TODO: check
+CVE-2026-71318 (Nuxt is an open-source web development framework for Vue.js.
From 3.1. ...)
+ TODO: check
+CVE-2026-71316 (Nuxt is an open-source web development framework for Vue.js.
From 4.4. ...)
+ TODO: check
+CVE-2026-71315 (Nuxt is an open-source web development framework for Vue.js.
From 3.21 ...)
+ TODO: check
+CVE-2026-71314 (Nuxt is an open-source web development framework for Vue.js.
From 3.1. ...)
+ TODO: check
+CVE-2026-71313 (rclone is a command-line program to sync files and directories
to and ...)
+ TODO: check
+CVE-2026-71312 (rclone is a command-line program to sync files and directories
to and ...)
+ TODO: check
+CVE-2026-71311 (rclone is a command-line program to sync files and directories
to and ...)
+ TODO: check
+CVE-2026-71310 (rclone is a command-line program to sync files and directories
to and ...)
+ TODO: check
+CVE-2026-71309 (rclone is a command-line program to sync files and directories
to and ...)
+ TODO: check
+CVE-2026-70618 (Spacebar Server before commit 51da17c contains a missing
authorization ...)
+ TODO: check
+CVE-2026-70617 (Spacebar Server before commit dcfd910 contains a missing
authorization ...)
+ TODO: check
+CVE-2026-70616 (boringproxy through 0.10.0 contains a resource exhaustion
vulnerabilit ...)
+ TODO: check
+CVE-2026-70615 (boringproxy through 0.10.0 contains a newline injection
vulnerability ...)
+ TODO: check
+CVE-2026-69111 (Milvus through 2.6.22 and 3.0.0 contains an unauthenticated
denial of ...)
+ TODO: check
+CVE-2026-68746 (Not Failing Securely ('Failing Open') vulnerability in
livebook-dev li ...)
+ TODO: check
+CVE-2026-67873 (A heap-based buffer overflow exists in lib60870-C 2.4.0 in the
server- ...)
+ TODO: check
+CVE-2026-67872 (An issue in Systerel S2OPC 1.7.3 allows a remote attacker to
cause a d ...)
+ TODO: check
+CVE-2026-67871 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a
remote ...)
+ TODO: check
+CVE-2026-67870 (In open62541 v1.5.5, the server-side AddReferences
implementation cont ...)
+ TODO: check
+CVE-2026-67869 (Buffer Overflow vulnerability in open62541 v1.5.5 allows a
remote atta ...)
+ TODO: check
+CVE-2026-67867 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a
remote ...)
+ TODO: check
+CVE-2026-67866 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a
remote ...)
+ TODO: check
+CVE-2026-67865 (S2OPC 1.7.3 contains an out-of-bounds read in
RepublishResponse handli ...)
+ TODO: check
+CVE-2026-67864 (An issue in open62541 v.1.5.5 and before allows a remote
attacker to c ...)
+ TODO: check
+CVE-2026-67863 (In open62541 1.5.5, a server-side use-after-free exists in the
local M ...)
+ TODO: check
+CVE-2026-67531 (FrontMCP is a TypeScript-first framework for the Model Context
Protoco ...)
+ TODO: check
+CVE-2026-66885 (Cross-Site Request Forgery (CSRF) vulnerability in
livebook-dev livebo ...)
+ TODO: check
+CVE-2026-66881 (Relative Path Traversal vulnerability in livebook-dev livebook
allows ...)
+ TODO: check
+CVE-2026-66298 (Origin Validation Error vulnerability in livebook-dev livebook
allows ...)
+ TODO: check
+CVE-2026-66297 (Improper Neutralization of Special Elements used in an OS
Command (OS ...)
+ TODO: check
+CVE-2026-55524 (PraisonAI is a multi-agent teams system. In versions prior to
1.6.58, ...)
+ TODO: check
+CVE-2026-55523 (PraisonAI is a multi-agent teams system. In versions 1.5.128
through 1 ...)
+ TODO: check
+CVE-2026-55522 (PraisonAI is a multi-agent teams system. In versions 3.9.26
through 4. ...)
+ TODO: check
+CVE-2026-52466 (Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable
to toIno ...)
+ TODO: check
+CVE-2026-34966 (Gitea prior to 1.27.0 contains a server-side request forgery
vulnerabi ...)
+ TODO: check
+CVE-2026-21766 (The default login portlet in HCL Digital Experience and
Digital Experi ...)
+ TODO: check
+CVE-2026-19028 (H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through
2.3.0 comput ...)
+ TODO: check
+CVE-2026-19027 (The H5Z__nbit_decompress_one_byte,
H5Z__nbit_decompress_one_nooptype, ...)
+ TODO: check
+CVE-2026-19026 (H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0
dereferences cd_va ...)
+ TODO: check
+CVE-2026-19025 (H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does
not valid ...)
+ TODO: check
+CVE-2026-19024 (NULL pointer dereference in H5Pget_fill_value in HDF5 before
2.1.1 all ...)
+ TODO: check
+CVE-2026-19023 (Untrusted pointer dereference in the render_bin_output
function in the ...)
+ TODO: check
+CVE-2026-19007 (A vulnerability was determined in mf-yang openclaw-cn up to
0.2.1. Thi ...)
+ TODO: check
+CVE-2026-19006 (A vulnerability was found in mf-yang openclaw-cn 2026.2.5.
This affect ...)
+ TODO: check
+CVE-2026-19005 (A vulnerability was detected in nanocoai NanoClaw up to
2.0.64. Affect ...)
+ TODO: check
+CVE-2026-19000 (A vulnerability was identified in JeecgBoot up to 3.9.2. The
affected ...)
+ TODO: check
+CVE-2026-18998 (A vulnerability was determined in cosmicstack-labs
mercury-agent up to ...)
+ TODO: check
+CVE-2026-18997 (A vulnerability was found in cosmicstack-labs mercury-agent up
to 1.1. ...)
+ TODO: check
+CVE-2026-18996 (A vulnerability has been found in cosmicstack-labs
mercury-agent up to ...)
+ TODO: check
+CVE-2026-18995 (A flaw has been found in netease-youdao LobsterAI 2026.6.10.
This affe ...)
+ TODO: check
+CVE-2026-18993 (A vulnerability was detected in NousResearch hermes-agent up
to 0.16.0 ...)
+ TODO: check
+CVE-2026-18992 (A vulnerability was detected in zhayujie CowAgent up to 2.1.1.
This vu ...)
+ TODO: check
+CVE-2026-18991 (A security vulnerability has been detected in nanocoai
NanoClaw up to ...)
+ TODO: check
+CVE-2026-18990 (A vulnerability was detected in letta-ai LettaBot 0.2.0.
Impacted is a ...)
+ TODO: check
+CVE-2026-18980 (A vulnerability was identified in nearai ironclaw up to
0.29.1. Affect ...)
+ TODO: check
+CVE-2026-18976 (A vulnerability was determined in NousResearch hermes-agent up
to 0.16 ...)
+ TODO: check
+CVE-2026-18974 (A vulnerability was found in heshengtao super-agent-party up
to 0.4.1. ...)
+ TODO: check
+CVE-2026-18973 (A vulnerability has been found in heshengtao super-agent-party
up to 0 ...)
+ TODO: check
+CVE-2026-18970 (A flaw has been found in Rongzhitong Visual Integrated Command
and Dis ...)
+ TODO: check
+CVE-2026-18969 (A vulnerability was detected in Rongzhitong Visual Integrated
Command ...)
+ TODO: check
+CVE-2026-18968 (A security vulnerability has been detected in ttttonyhe OBlog
up to 3c ...)
+ TODO: check
+CVE-2026-18967 (A flaw was found in the SAML broker component of Keycloak, an
identity ...)
+ TODO: check
+CVE-2026-18959 (A flaw has been found in yushine InnoShop up to 0.8.2.
Affected by thi ...)
+ TODO: check
+CVE-2026-18958 (A vulnerability was detected in imranrisal-dev
Student-Management-Syst ...)
+ TODO: check
+CVE-2026-18954 (Incorrect authorization in the aggregation pipeline tool in
Amazon AWS ...)
+ TODO: check
+CVE-2026-18953 (Improper limitation of a pathname to a restricted directory in
the get ...)
+ TODO: check
+CVE-2026-18909 (A stack-based buffer overflow vulnerability exists in ELAN
Microelectr ...)
+ TODO: check
+CVE-2026-18839 (An integer underflow was found in the popt library when
formatting hel ...)
+ TODO: check
+CVE-2026-18510 (The TranslatePress \u2013 Translate Multilingual sites with AI
Transla ...)
+ TODO: check
+CVE-2026-18411 (The KARR Security System and SWDS dealer-installed automotive
anti-the ...)
+ TODO: check
+CVE-2026-18400 (The Slider, Gallery, and Carousel by MetaSlider \u2013 Image
Slider, V ...)
+ TODO: check
+CVE-2026-18395 (The Child Pages Card WordPress plugin before 1.09 does not
sanitise an ...)
+ TODO: check
+CVE-2026-18325 (The Forminator Forms \u2013 Contact Form, Payment Form &
Custom Form B ...)
+ TODO: check
+CVE-2026-18050 (The Events Manager WordPress plugin before 7.4 does not
perform any a ...)
+ TODO: check
+CVE-2026-17583 (The affected Thermo Fisher Applied Biosystems Genetic
Analyzers arevu ...)
+ TODO: check
+CVE-2026-17556 (A path traversal vulnerability was identified in GitHub
Enterprise Ser ...)
+ TODO: check
+CVE-2026-16954 (The AI Engine WordPress plugin before 3.6.4 does not redact
secret co ...)
+ TODO: check
+CVE-2026-16734 (The Stripe Payment Forms by WP Full Pay WordPress plugin
before 8.5.2 ...)
+ TODO: check
+CVE-2026-16636 (The FluentSMTP \u2013 WP SMTP Plugin with Amazon SES,
SendGrid, MailGu ...)
+ TODO: check
+CVE-2026-16537 (The Slick Slider WordPress plugin before 0.5.3 does not
sanitize and e ...)
+ TODO: check
+CVE-2026-16290 (The ProfileGrid WordPress plugin before 6.0.0.0 does not
perform auth ...)
+ TODO: check
+CVE-2026-16268 (The Newsletters WordPress plugin before 4.16 does not
authenticate or ...)
+ TODO: check
+CVE-2026-16065 (The Welcart e-Commerce WordPress plugin before 2.11.32 does
not proper ...)
+ TODO: check
+CVE-2026-16054 (The Drag and Drop Multiple File Upload for WooCommerce
WordPress plugi ...)
+ TODO: check
+CVE-2026-15996 (A denial of service vulnerability was identified in GitHub
Enterprise ...)
+ TODO: check
+CVE-2026-15991 (The File Manager plugin for WordPress is vulnerable to
arbitrary file ...)
+ TODO: check
+CVE-2026-15459 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to
Authentic ...)
+ TODO: check
+CVE-2026-14829 (The Checkimate \u2014 WooCommerce Checkout, Abandoned Cart
Recovery & ...)
+ TODO: check
+CVE-2026-14547 (The Estatik Real Estate Plugin WordPress plugin before 4.3.3
does not ...)
+ TODO: check
+CVE-2026-14314 (The PeproDev WooCommerce Receipt Uploader WordPress plugin
through 2.8 ...)
+ TODO: check
+CVE-2026-14313 (PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce
Receipt Up ...)
+ TODO: check
+CVE-2026-14240 (The tourmaster WordPress plugin before 5.4.9 writes its
order/booking ...)
+ TODO: check
+CVE-2026-14204 (The Google Authenticator WordPress plugin before 0.56 does not
verify ...)
+ TODO: check
+CVE-2026-13703 (The SEO Redirection Plugin WordPress plugin before 9.19 does
not perf ...)
+ TODO: check
+CVE-2026-13154 (The Gutenberg Essential Blocks WordPress plugin before 6.4.0
does not ...)
+ TODO: check
+CVE-2026-13153 (The Gutenberg Essential Blocks WordPress plugin before 6.4.0
does not ...)
+ TODO: check
+CVE-2026-12713 (The WPCargo Track & Trace WordPress plugin before 8.0.4 does
not prope ...)
+ TODO: check
+CVE-2026-11588 (The EONSR AEO Agent WordPress plugin through 3.7.9 does not
perform an ...)
+ TODO: check
+CVE-2025-63823 (My Safetipin Android Application 5.2.1 contains Hardcoded
credentials ...)
+ TODO: check
+CVE-2025-63822 (SirenGPS Android Application 2.19.44 is vulnerable to
Incorrect Access ...)
+ TODO: check
+CVE-2025-15678 (The Nexter Blocks WordPress plugin before 5.0.2 does not
sanitize upl ...)
+ TODO: check
+CVE-2023-54389
+ REJECTED
+CVE-2023-54388
+ REJECTED
+CVE-2023-54387
+ REJECTED
+CVE-2023-54386
+ REJECTED
+CVE-2023-54385
+ REJECTED
+CVE-2023-54384
+ REJECTED
+CVE-2023-54383
+ REJECTED
+CVE-2023-54382
+ REJECTED
+CVE-2023-54381
+ REJECTED
+CVE-2023-54380
+ REJECTED
+CVE-2023-54379
+ REJECTED
+CVE-2023-54378
+ REJECTED
+CVE-2023-54377
+ REJECTED
+CVE-2023-54376
+ REJECTED
+CVE-2023-54375
+ REJECTED
CVE-2026-9205 (IBM Langflow OSS contains a weak cryptographic key derivation
vulnerab ...)
NOT-FOR-US: IBM
CVE-2026-9203 (A server-side request forgery vulnerability in Progress
MarkLogic Serv ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8d2266e836d80de49eb3a574249301444f96064
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8d2266e836d80de49eb3a574249301444f96064
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits