Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e41f5938 by security tracker role at 2026-08-08T07:13:50+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,8 +1,170 @@
+CVE-2026-9031 (An input validation vulnerability exists in the HTTP-WRITEOEM 
handler  ...)
+       TODO: check
+CVE-2026-9030 (A denial-of-service vulnerability exists in httpd service on 
Archer A6 ...)
+       TODO: check
+CVE-2026-8798 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, 
the nati ...)
+       TODO: check
+CVE-2026-71381 (Adobe Genuine Software Integrity Service was affected by an 
Incorrect  ...)
+       TODO: check
+CVE-2026-70624
+       REJECTED
+CVE-2026-70623
+       REJECTED
+CVE-2026-69207 (Hono is a Web application framework that provides support for 
any Java ...)
+       TODO: check
+CVE-2026-66151 (SonicWall Global VPN Client version 4.10.8.1108 and earlier is 
vulnera ...)
+       TODO: check
+CVE-2026-66061 (Home Assistant is open source home automation software focused 
on loca ...)
+       TODO: check
+CVE-2026-66060 (Home Assistant is open source home automation software focused 
on loca ...)
+       TODO: check
+CVE-2026-65819 (gopacket provides packet processing capabilities for Go. 
Through versi ...)
+       TODO: check
+CVE-2026-64676 (Kata Containers is an open source implementation of 
lightweight Virtua ...)
+       TODO: check
+CVE-2026-62296 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
+       TODO: check
+CVE-2026-62295 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
+       TODO: check
+CVE-2026-62293 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
+       TODO: check
+CVE-2026-61808 (LightRAG provides simple and fast retrieval-augmented 
generation. Thro ...)
+       TODO: check
+CVE-2026-59717 (Home Assistant is open source home automation software focused 
on loca ...)
+       TODO: check
+CVE-2026-58262 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
+       TODO: check
+CVE-2026-54338 (JupyterHub is software that allows users to create a 
multi-user server ...)
+       TODO: check
+CVE-2026-52880 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
+       TODO: check
+CVE-2026-52879 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
+       TODO: check
+CVE-2026-52878 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
+       TODO: check
+CVE-2026-49343 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
+       TODO: check
+CVE-2026-48170 (`scim-patch`, a library to perform SCIM patch, prior to 
version 0.9.1  ...)
+       TODO: check
+CVE-2026-48169 (PraisonAI is a multi-agent teams system. Versions prior to 
0.1.4 of th ...)
+       TODO: check
+CVE-2026-48122 (Ruby LSP is an implementation of the language server protocol 
for Ruby ...)
+       TODO: check
+CVE-2026-48120 (Kakoune is a code editor. Prior to version 2026.05.21, the 
bundled, en ...)
+       TODO: check
+CVE-2026-48047 (XWiki Platform WebJars API is a package for XWiki, a generic 
wiki plat ...)
+       TODO: check
+CVE-2026-48039 (Meta Ads MCP is a Model Context Protocol (MCP) server that 
lets AI ass ...)
+       TODO: check
+CVE-2026-48026 (lakeFS is an open-source tool that transforms object storage 
into a Gi ...)
+       TODO: check
+CVE-2026-48007 (Element Call is a native Matrix video conferencing 
application. Versio ...)
+       TODO: check
+CVE-2026-47664 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
+       TODO: check
+CVE-2026-47663 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
+       TODO: check
+CVE-2026-47662 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
+       TODO: check
+CVE-2026-47661 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
+       TODO: check
+CVE-2026-47660 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
+       TODO: check
+CVE-2026-47659 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
+       TODO: check
+CVE-2026-47249 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
+       TODO: check
+CVE-2026-47127 (Ghostfolio is an open source wealth management software. Prior 
to vers ...)
+       TODO: check
+CVE-2026-46409 (OpenYak is a local-first agent runtime for reliable tool-using 
models, ...)
+       TODO: check
+CVE-2026-46405 (OpenBao is an open source identity-based secrets management 
system. Pr ...)
+       TODO: check
+CVE-2026-46358 (OpenBao is an open source identity-based secrets management 
system. Pr ...)
+       TODO: check
+CVE-2026-45808 (OpenBao is an open source identity-based secrets management 
system. Pr ...)
+       TODO: check
+CVE-2026-19263 (A vulnerability was found in INQUIRELAB mcp-bridge-api up to 
b30a82aa1 ...)
+       TODO: check
+CVE-2026-19259 (A vulnerability has been found in MZ Automation libiec61850 up 
to 1.6. ...)
+       TODO: check
+CVE-2026-19246 (A vulnerability has been found in HKUDS nanobot up to 0.2.1. 
This affe ...)
+       TODO: check
+CVE-2026-19245 (A flaw has been found in HKUDS nanobot up to 0.2.1. The 
impacted eleme ...)
+       TODO: check
+CVE-2026-19244 (A vulnerability was detected in HKUDS nanobot up to 0.2.1. The 
affecte ...)
+       TODO: check
+CVE-2026-19243 (A security vulnerability has been detected in HKUDS nanobot up 
to 0.2. ...)
+       TODO: check
+CVE-2026-19113 (Consul Community Edition and Consul Enterprise 1.3.0 through 
2.0.2 are ...)
+       TODO: check
+CVE-2026-19017 (Consul Community Edition and Consul Enterprise 1.18.21 through 
2.0.2 a ...)
+       TODO: check
+CVE-2026-19016 (Consul Community Edition and Consul Enterprise 1.19.1 through 
2.0.2 di ...)
+       TODO: check
+CVE-2026-19015 (Consul Community Edition and Consul Enterprise 1.2.0 through 
2.0.2 are ...)
+       TODO: check
+CVE-2026-19014 (Consul Community Edition and Consul Enterprise 1.17.0 through 
2.0.2 ar ...)
+       TODO: check
+CVE-2026-19012 (Consul Community Edition and Consul Enterprise 1.18.0 through 
2.0.2 ar ...)
+       TODO: check
+CVE-2026-18988 (The Easy Accordion plugin for WordPress is vulnerable to 
Stored Cross- ...)
+       TODO: check
+CVE-2026-16955 (The AI Engine  WordPress plugin before 3.6.6 does not confine 
a caller ...)
+       TODO: check
+CVE-2026-16953 (The AI Engine  WordPress plugin before 3.6.4 does not verify 
ownership ...)
+       TODO: check
+CVE-2026-16948 (The Solace Extra WordPress plugin before 1.6.1 does not 
perform capabi ...)
+       TODO: check
+CVE-2026-16608 (The Download Monitor WordPress plugin before 5.2.6 does not 
perform au ...)
+       TODO: check
+CVE-2026-16595 (The WP Directory Kit WordPress plugin before 1.5.5 does not 
perform au ...)
+       TODO: check
+CVE-2026-16594 (The WP Directory Kit WordPress plugin before 1.5.5 does not 
perform au ...)
+       TODO: check
+CVE-2026-16590 (The WP Directory Kit WordPress plugin before 1.5.5 does not 
perform au ...)
+       TODO: check
+CVE-2026-16589 (The WP Directory Kit WordPress plugin before 1.5.5 does not 
sanitize a ...)
+       TODO: check
+CVE-2026-16578 (The Admin Safety Guard \u2014 Login Security, Limit Logins, 
2FA & Brut ...)
+       TODO: check
+CVE-2026-16574 (The Dokan: AI Powered WooCommerce Multivendor Marketplace 
Solution  Wo ...)
+       TODO: check
+CVE-2026-16562 (The WP Statistics  WordPress plugin before 14.16.10 does not 
perform a ...)
+       TODO: check
+CVE-2026-16559 (The YMC Filter WordPress plugin before 3.12.9 does not 
sanitize SVG fi ...)
+       TODO: check
+CVE-2026-16558 (The YMC Filter WordPress plugin before 3.12.8 does not 
sanitize and es ...)
+       TODO: check
+CVE-2026-16535 (The Link Library WordPress plugin before 7.9.4 does not 
sanitise and e ...)
+       TODO: check
+CVE-2026-16282 (The Appointment Hour Booking  WordPress plugin before 1.5.88 
does not  ...)
+       TODO: check
+CVE-2026-16269 (The Newsletters WordPress plugin before 4.16 does not strictly 
compare ...)
+       TODO: check
+CVE-2026-16267 (The Newsletters WordPress plugin before 4.16 does not restrict 
the cla ...)
+       TODO: check
+CVE-2026-15972 (Consul Community Edition and Consul Enterprise 1.13.0 through 
2.0.2 ar ...)
+       TODO: check
+CVE-2026-15970 (Consul Community Edition and Consul Enterprise 1.20.1 through 
2.0.2 ar ...)
+       TODO: check
+CVE-2026-14526 (The AI Copilot \u2013 Content Generator plugin for WordPress 
is vulner ...)
+       TODO: check
+CVE-2026-13505 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 
(1.0.X  ...)
+       TODO: check
+CVE-2026-11743 (The SF32LB MPI QSPI NOR flash driver 
(drivers/flash/flash_sf32lb_mpi_q ...)
+       TODO: check
+CVE-2026-11742 (The kernel queue helper z_queue_node_peek() in kernel/queue.c 
derefere ...)
+       TODO: check
+CVE-2026-11425 (Domoticz versions prior to 2026.3 contains a stored cross-site 
scripti ...)
+       TODO: check
+CVE-2025-4438
+       REJECTED
 CVE-2026-66808
        NOT-FOR-US: hypershift-addon-operator
 CVE-2026-9169 (DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 
1.0.80.49 on ...)
        NOT-FOR-US: LUCID Vision Labs Arena SDK
-CVE-2026-71870
+CVE-2026-71870 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.15 ...)
        - pypdf <unfixed>
        - pypdf2 <removed>
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3f-mc75-235c
@@ -141,17 +303,17 @@ CVE-2026-48094 (The ShareOpenly WordPress plugin prior to 
version 1.2.1 contains
        NOT-FOR-US: WordPress plugin
 CVE-2026-48093 (The Code Embed WordPress plugin prior to version 2.6.1 is 
vulnerable t ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-47364 (On every successful login, the Datadog Android application 
calls Fireb ...)
+CVE-2026-47364 (In versions of the Datadog Android application prior to 
v545-5.9.2, th ...)
        NOT-FOR-US: Datadog Android application
-CVE-2026-47363 (The launcher activity AppActivity in the Datadog Android 
application i ...)
+CVE-2026-47363 (In versions of the Datadog Android application prior to 
v541-5.9.2, th ...)
        NOT-FOR-US: Datadog Android application
-CVE-2026-47362 (The Datadog Android application stores operationally sensitive 
content ...)
+CVE-2026-47362 (In versions of the Datadog Android application prior to 
v554-5.9.4, tw ...)
        NOT-FOR-US: Datadog Android application
-CVE-2026-47361 (BubbleChatActivity in the Datadog Android application is 
declared andr ...)
+CVE-2026-47361 (In versions of the Datadog Android application prior to 
v541-5.9.2, Bu ...)
        NOT-FOR-US: Datadog Android application
-CVE-2026-44965 (Six Android App Widget configuration activities in the Datadog 
Android ...)
+CVE-2026-44965 (In versions of the Datadog Android application prior to 
v545-5.9.2, si ...)
        NOT-FOR-US: Datadog Android application
-CVE-2026-44964 (The OnCallNotificationActivity in the Datadog Android 
application is d ...)
+CVE-2026-44964 (In versions of the Datadog Android application prior to 
v545-5.9.2, On ...)
        NOT-FOR-US: Datadog Android application
 CVE-2026-37171 (A lack of tenant separation in SuperTokens Inc. SuperTokens 
Core v6.0. ...)
        NOT-FOR-US: SuperTokens
@@ -9594,7 +9756,7 @@ CVE-2026-48702
        - rekor 1.5.2-1
        NOTE: https://github.com/sigstore/rekor/pull/2831
        NOTE: Fixed by: 
https://github.com/sigstore/rekor/commit/759b98e2a7c39ea9779b6a51299c5f0f987f8802
 (v1.5.2)
-CVE-2026-50540
+CVE-2026-50540 (Kata Containers is an open source project focusing on a 
standard imple ...)
        NOT-FOR-US: Kata Containers
 CVE-2026-50149
        NOT-FOR-US: Contour
@@ -62903,7 +63065,7 @@ CVE-2026-43495 (In the Linux kernel, the following 
vulnerability has been resolv
        [trixie] - linux 6.12.88-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/0e7c074cfcd9bd93765505f9eb8b42f03ed2a744 (7.1-rc3)
-CVE-2026-47243
+CVE-2026-47243 (Kata Containers is an open source project focusing on a 
standard imple ...)
        NOT-FOR-US: Kata Containers
 CVE-2026-45250 (The setcred(2) system call is only available to privileged 
users.  How ...)
        NOT-FOR-US: FreeBSD
@@ -148101,7 +148263,7 @@ CVE-2020-36877 (ReQuest Serious Play F3 Media Server 
7.0.3 contains an unauthent
        NOT-FOR-US: ReQuest Serious Play F3 Media Server
 CVE-2020-36876 (ReQuest Serious Play F3 Media Server versions 7.0.3.4968 
(Pro), 7.0.2. ...)
        NOT-FOR-US: ReQuest Serious Play F3 Media Server
-CVE-2025-6946 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
+CVE-2025-6946 (A stored cross-site scripting (XSS) vulnerability exists in the 
manage ...)
        NOT-FOR-US: WatchGuard
 CVE-2025-66576 (Remote Keyboard Desktop 1.0.1 enables remote attackers to 
execute syst ...)
        NOT-FOR-US: Remote Keyboard Desktop
@@ -175245,7 +175407,7 @@ CVE-2025-9808 (The The Events Calendar plugin for 
WordPress is vulnerable to Inf
        NOT-FOR-US: WordPress plugin
 CVE-2025-6999 (An HTTP Request Smuggling [CWE-444] vulnerability in the 
Authenticatio ...)
        NOT-FOR-US: WatchGuard
-CVE-2025-6947 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
+CVE-2025-6947 (A stored cross-site scripting (XSS) vulnerability exists in the 
manage ...)
        NOT-FOR-US: WatchGuard
 CVE-2025-5518 (Authorization Bypass Through User-Controlled Key vulnerability 
with us ...)
        NOT-FOR-US: ArgusTech BILGER
@@ -212858,7 +213020,7 @@ CVE-2025-4811 (A vulnerability was found in CodeAstro 
Pharmacy Management System
        NOT-FOR-US: CodeAstro
 CVE-2025-4810 (A vulnerability was found in Tenda AC7 15.03.06.44. It has been 
declar ...)
        NOT-FOR-US: Tenda
-CVE-2025-4805 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
+CVE-2025-4805 (A stored cross-site scripting (XSS) vulnerability exists in the 
manage ...)
        NOT-FOR-US: WatchGuard
 CVE-2025-4804 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
        NOT-FOR-US: WatchGuard
@@ -245680,9 +245842,9 @@ CVE-2025-22702 (Missing Authorization vulnerability 
in ThemeGoods Photography ph
        NOT-FOR-US: WordPress plugin
 CVE-2025-22698 (Missing Authorization vulnerability in Ability, Inc 
Accessibility Suit ...)
        NOT-FOR-US: WordPress plugin
-CVE-2025-1239 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
+CVE-2025-1239 (A stored cross-site scripting (XSS) vulnerability exists in the 
manage ...)
        NOT-FOR-US: WatchGuard Fireware OS
-CVE-2025-1071 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
+CVE-2025-1071 (A stored cross-site scripting (XSS) vulnerability exists in the 
manage ...)
        NOT-FOR-US: WatchGuard Fireware OS
 CVE-2025-0867 (The standard user uses the run as function to start the MEAC 
applicati ...)
        NOT-FOR-US: SICK
@@ -245690,7 +245852,7 @@ CVE-2025-0821 (Bit Assist plugin for WordPress is 
vulnerable to time-based SQL I
        NOT-FOR-US: WordPress plugin
 CVE-2025-0503 (Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs 
from the d ...)
        - mattermost-server <itp> (bug #823556)
-CVE-2025-0178 (Improper Input Validation vulnerability in WatchGuard Fireware 
OS allo ...)
+CVE-2025-0178 (An Improper Input Validation vulnerability in WatchGuard 
Fireware OS a ...)
        NOT-FOR-US: WatchGuard Fireware OS
 CVE-2024-8893 (Use of Hard-coded Credentials vulnerability in GoodWe 
Technologies Co. ...)
        NOT-FOR-US: GoodWe Technologies
@@ -287184,7 +287346,7 @@ CVE-2024-6594 (Improper Handling of Exceptional 
Conditions vulnerability in the
        NOT-FOR-US: WatchGuard Single Sign-On Client on Windows
 CVE-2024-6593 (Incorrect Authorization vulnerability in WatchGuard 
Authentication Gat ...)
        NOT-FOR-US: WatchGuard
-CVE-2024-6592 (Incorrect Authorization vulnerability in the protocol 
communication be ...)
+CVE-2024-6592 (An incorrect authorization vulnerability in the protocol 
communication ...)
        NOT-FOR-US: WatchGuard
 CVE-2024-6512 (Authorization bypass in thePAM access request approval 
mechanism in De ...)
        NOT-FOR-US: Devolutions Server



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e41f593860c1eb78e5a2eee1c04a174a50a2b947

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e41f593860c1eb78e5a2eee1c04a174a50a2b947
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to