Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d3e2c22f by security tracker role at 2026-08-10T07:13:01+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,146 @@
-CVE-2026-12372
+CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant 
infinite ...)
+       TODO: check
+CVE-2026-19389 (Multiple integer overflow and underflow vulnerabilities were 
found in  ...)
+       TODO: check
+CVE-2026-19387 (A heap out-of-bounds write vulnerability was found in the 
GStreamer gs ...)
+       TODO: check
+CVE-2026-19384 (A weakness has been identified in SourceCodester Simple 
Doctors Appoin ...)
+       TODO: check
+CVE-2026-19383 (A security vulnerability has been detected in 
saithink/saigroup SaiAdm ...)
+       TODO: check
+CVE-2026-19382 (A weakness has been identified in Almico Speedfan 4.52. This 
affects t ...)
+       TODO: check
+CVE-2026-19381 (A security flaw has been discovered in Kingston FURY CTRL RGB 
Control  ...)
+       TODO: check
+CVE-2026-19380 (A vulnerability was identified in Mullvad wireguard.sys 
0.10.1. The af ...)
+       TODO: check
+CVE-2026-19379 (A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. 
Impacted ...)
+       TODO: check
+CVE-2026-19378 (A vulnerability was found in code-projects Task Management 
System 1.0. ...)
+       TODO: check
+CVE-2026-19376 (A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. 
This vuln ...)
+       TODO: check
+CVE-2026-19375 (A vulnerability was detected in dmitriiweb article-scraper-mcp 
1.0.0.  ...)
+       TODO: check
+CVE-2026-19374 (A security vulnerability has been detected in adafap api-mcp 
up to 92b ...)
+       TODO: check
+CVE-2026-19373 (A weakness has been identified in PhialsBasement 
KoboldCPP-MCP-Server  ...)
+       TODO: check
+CVE-2026-19372 (A security flaw has been discovered in Handwriting-OCR 
handwriting-ocr ...)
+       TODO: check
+CVE-2026-19371 (A vulnerability was identified in Nikolaibibo 
claude-comfyui-mcp 1.0.0 ...)
+       TODO: check
+CVE-2026-19370 (A vulnerability was determined in bartekke8it56w2 new-mcp 
0.1.0. This  ...)
+       TODO: check
+CVE-2026-19369 (A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. 
This aff ...)
+       TODO: check
+CVE-2026-19368 (A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. 
Affected by t ...)
+       TODO: check
+CVE-2026-19367 (A vulnerability has been found in NocteDefensor LudusMCP 
1.0.24. Affec ...)
+       TODO: check
+CVE-2026-19089 (The Product Input Fields for WooCommerce WordPress plugin 
before 2.0.2 ...)
+       TODO: check
+CVE-2026-19077 (The Duplicate Post WordPress plugin before 1.5.5 does not 
perform per- ...)
+       TODO: check
+CVE-2026-19075 (All-in-One Video Gallery registers a public, unauthenticated 
file-down ...)
+       TODO: check
+CVE-2026-19074 (The Advanced Classifieds & Directory Pro Advanced Classifieds 
& Direct ...)
+       TODO: check
+CVE-2026-19053 (The ProSolution WP Client WordPress plugin before 2.0.6 does 
not sanit ...)
+       TODO: check
+CVE-2026-19049 (The ProSolution WP Client WordPress plugin before 2.0.9 does 
not sanit ...)
+       TODO: check
+CVE-2026-18960 (The Block User Account WordPress plugin before 2.0.1 does not 
enforce  ...)
+       TODO: check
+CVE-2026-18946 (The Contact Form to Any API WordPress plugin before 3.0.7 does 
not use ...)
+       TODO: check
+CVE-2026-18934 (The RSS Aggregator by Feedzy  WordPress plugin before 5.2.6 
does not v ...)
+       TODO: check
+CVE-2026-18786 (The CheckView  WordPress plugin before 2.3.2 does not restrict 
its RES ...)
+       TODO: check
+CVE-2026-18666 (The Library Management System WordPress plugin before 3.6.7 
does not s ...)
+       TODO: check
+CVE-2026-18470 (The Login & Register Forms  WordPress plugin before 4.0.2 does 
not ver ...)
+       TODO: check
+CVE-2026-18469 (The Login & Register Forms  WordPress plugin before 4.0.2 does 
not enf ...)
+       TODO: check
+CVE-2026-18468 (The Login & Register Forms  WordPress plugin before 4.0.2 does 
not bin ...)
+       TODO: check
+CVE-2026-18200 (The FoodBoxBooker WordPress plugin before 1.0.8 does not 
verify that t ...)
+       TODO: check
+CVE-2026-18030 (The BricksForge WordPress plugin before 3.1.8.8 does not 
verify the id ...)
+       TODO: check
+CVE-2026-17542 (The File Manager WordPress plugin before 6.9.1 does not 
perform any ca ...)
+       TODO: check
+CVE-2026-17541 (The File Manager WordPress plugin before 6.9.1 does not have 
authorisa ...)
+       TODO: check
+CVE-2026-17540 (The File Manager WordPress plugin before 6.9.1 does not 
properly autho ...)
+       TODO: check
+CVE-2026-17519
+       REJECTED
+CVE-2026-17023 (The Salon Booking System  WordPress plugin through 10.30.33 
does not p ...)
+       TODO: check
+CVE-2026-17022 (The Salon Booking System  WordPress plugin through 10.30.33 
does not p ...)
+       TODO: check
+CVE-2026-17021 (The Salon Booking System  WordPress plugin through 10.30.33 
does not p ...)
+       TODO: check
+CVE-2026-17020 (The Salon Booking System  WordPress plugin through 10.30.33 
does not v ...)
+       TODO: check
+CVE-2026-17019 (The JetEngine WordPress plugin before 3.8.13.1 does not 
sanitise uploa ...)
+       TODO: check
+CVE-2026-17018 (The CubeWP Framework WordPress plugin through 1.1.30 does not 
perform  ...)
+       TODO: check
+CVE-2026-17016 (The Accept PayPal & Stripe with Subscriptions for WooCommerce 
WordPres ...)
+       TODO: check
+CVE-2026-17012 (The Accept PayPal & Stripe with Subscriptions for WooCommerce 
WordPres ...)
+       TODO: check
+CVE-2026-17010 (The Saitama Addon Pack WordPress plugin through 1.0.8 does not 
sanitis ...)
+       TODO: check
+CVE-2026-16985 (The Squeeze  WordPress plugin before 1.7.12 does not validate 
the file ...)
+       TODO: check
+CVE-2026-16949 (The Term Pages WordPress plugin before 2.0.0 does not properly 
sanitis ...)
+       TODO: check
+CVE-2026-16299 (The Single Sign On For TNG WordPress plugin before 2.2.0 does 
not prop ...)
+       TODO: check
+CVE-2026-16298 (The FoodBoxBooker WordPress plugin before 1.0.7 does not 
properly vali ...)
+       TODO: check
+CVE-2026-16257 (The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not 
properl ...)
+       TODO: check
+CVE-2026-15238 (The MotoPress Hotel Booking WordPress plugin before 6.2.3 does 
not ver ...)
+       TODO: check
+CVE-2026-15237 (The MotoPress Hotel Booking WordPress plugin before 6.2.3 does 
not per ...)
+       TODO: check
+CVE-2026-15229 (The Pinpoint Booking System  WordPress plugin through 
2.9.9.6.9 does n ...)
+       TODO: check
+CVE-2026-15047 (The s2Member  WordPress plugin before 260805 does not escape 
several s ...)
+       TODO: check
+CVE-2026-14941 (The Customer Reviews for WooCommerce WordPress plugin before 
5.116.0 d ...)
+       TODO: check
+CVE-2026-14860 (The Podcast Player  WordPress plugin before 8.3.1 does not 
validate th ...)
+       TODO: check
+CVE-2026-14293 (The Autopay WordPress plugin before 5.0.1 does not perform any 
capabil ...)
+       TODO: check
+CVE-2026-14238 (The vitepos WordPress plugin before 3.6.0 does not sanitize or 
paramet ...)
+       TODO: check
+CVE-2026-14237 (The vitepos WordPress plugin before 3.6.0, Vitepos  WordPress 
plugin b ...)
+       TODO: check
+CVE-2026-14211 (The Booking for Appointments and Events Calendar  WordPress 
plugin bef ...)
+       TODO: check
+CVE-2026-14206 (The HT Contact Form  WordPress plugin before 2.9.3 does not 
perform an ...)
+       TODO: check
+CVE-2026-13701 (The Advanced Excerpt WordPress plugin before 4.5 does not 
sanitise and ...)
+       TODO: check
+CVE-2026-13600 (The AutoNetTV Relay WordPress plugin before 3.0.14 does not 
perform an ...)
+       TODO: check
+CVE-2026-13170 (The Eventin  WordPress plugin before 4.1.20 does not properly 
validate ...)
+       TODO: check
+CVE-2026-13133 (A vulnerability has been identified in LineInst.exe (LINE for 
Windows) ...)
+       TODO: check
+CVE-2026-12971 (The LearnPress  WordPress plugin before 4.4.4 does not 
validate a user ...)
+       TODO: check
+CVE-2026-12570 (A vulnerability in keras-team/keras versions <= 3.15.0 allows 
for a de ...)
+       TODO: check
+CVE-2026-12372 (A Server-Side Request Forgery (SSRF) vulnerability exists in 
nltk/nltk ...)
        - nltk <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513003
 CVE-2026-70395 (Improper Neutralization of Special Elements in Data Query 
Logic vulner ...)
@@ -49631,66 +49773,82 @@ CVE-2026-45447 (Issue summary: A specially crafted 
PKCS#7 or S/MIME signed messa
        NOTE: Fixed by: 
https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54
 (openssl-3.0.21)
        NOTE: Fixed by: 
https://github.com/openssl/openssl/commit/18de9aba8294b5fb0915866cf3a1bb45f9599b8d
 (openssl-3.0.21)
 CVE-2026-62434 (A guest started with Populated on Demand enabled (PoD) can 
attempt to  ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-507.html
 CVE-2026-62433 (Parts of the DM_OP handling code assumes the caller has 
provided the r ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-506.html
 CVE-2026-62432 (The EVTCHNOP_expand_array hypercall checks for whether FIFO 
event chan ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-505.html
 CVE-2026-62431 (The logic to handle periodic Viridian STIMERs performs a 
division with ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-504.html
 CVE-2026-62430 (Accesses to the CMOS memory contents are done using an 
indirect IO por ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-503.html
 CVE-2026-62429 (Accessing the vNUMA configuration data of a guest is still 
possible wh ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-502.html
 CVE-2026-62435 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-501.html
 CVE-2026-62436 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-501.html
 CVE-2026-62428 (When grant-copy operations are processed, the respective grant 
may or  ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-500.html
 CVE-2026-62426 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-499.html
 CVE-2026-62427 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-499.html
 CVE-2026-42494 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-497.html
 CVE-2026-42495 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-497.html
 CVE-2026-62423 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-497.html
 CVE-2026-62424 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-497.html
 CVE-2026-62425 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-497.html
@@ -49698,15 +49856,17 @@ CVE-2026-42492 (Xenstore, to have an up-to-date 
picture of the entire system, wa
        - xen <not-affected> (Vulnerable code introduced later)
        NOTE: https://xenbits.xen.org/xsa/advisory-496.html
 CVE-2026-42493 (Addressing certain issues, in particular related to operations 
which m ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-495.html
 CVE-2026-42488 (Some shadow paging errors paths will switch the page-tables 
without up ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-494.html
 CVE-2025-10263 (Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, 
Neoverse V1 ...)
-       {DLA-4671-1 DLA-4665-1 DLA-4664-1}
+       {DSA-6424-1 DLA-4671-1 DLA-4665-1 DLA-4664-1}
        - linux 7.0.13-1
        [trixie] - linux 6.12.94-1
        - xen 4.20.3+127-gc42374a105-1
@@ -49714,14 +49874,17 @@ CVE-2025-10263 (Arm C1-Ultra, C1-Premium, Neoverse V3 
& V3AE, Neoverse V2, Neove
        NOTE: https://xenbits.xen.org/xsa/advisory-493.html
        NOTE: Mitigations in src:linux: 
https://lore.kernel.org/all/[email protected]/
 CVE-2026-42490 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-492.html
 CVE-2026-42489 ([This CNA information record relates to multiple CVEs; the 
text explai ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-492.html
 CVE-2026-42487 (HVM guest I/O port accesses are subject to either emulation or 
at leas ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (out of LTS support)
        NOTE: https://xenbits.xen.org/xsa/advisory-491.html
@@ -69397,6 +69560,7 @@ CVE-2025-12659 (Siemens Simcenter Femapcontains a 
memory corruption vulnerabilit
 CVE-2024-54017 (A vulnerability has been identified in SIPROTEC 5 6MD84 
(CP300) (All v ...)
        NOT-FOR-US: Siemens
 CVE-2025-54518 (Improper isolation of shared resources within the CPU 
operation cache  ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bullseye] - xen <end-of-life> (EOLed in Bullseye)
        NOTE: https://xenbits.xen.org/xsa/advisory-490.html
@@ -79354,11 +79518,13 @@ CVE-2026-6691 (The MongoDB C Driver's Cyrus SASL 
integration performs unsafe str
        NOTE: 
https://github.com/mongodb/mongo-c-driver/commit/b4984965877d559862e225beba09cb4e9d4a56a6
 (2.2.0)
        NOTE: 
https://github.com/mongodb/mongo-c-driver/commit/d9c26f49e75d3de746a690db9c81ff5b4f6e21b0
 (2.2.0)
 CVE-2026-23556 (When oxenstored is tearing a domain down, the node data is 
cleaned up  ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bookworm] - xen <no-dsa> (Minor issue)
        [bullseye] - xen <end-of-life> (EOLed in Bullseye)
        NOTE: https://xenbits.xen.org/xsa/advisory-483.html
 CVE-2026-23557 (Any guest can cause xenstored to crash by issuing a 
XS_RESET_WATCHES c ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1 (unimportant)
        NOTE: https://xenbits.xen.org/xsa/advisory-484.html
        NOTE: Debian uses the ocaml-based xenstored
@@ -79367,6 +79533,7 @@ CVE-2026-31786 (In the Linux kernel, the following 
vulnerability has been resolv
        - linux 7.0.3-1
        NOTE: https://xenbits.xen.org/xsa/advisory-485.html
 CVE-2026-23558 (The adjustments made for XSA-379 as well as those subsequently 
becomin ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bookworm] - xen <no-dsa> (Minor issue)
        [bullseye] - xen <end-of-life> (EOLed in Bullseye)
@@ -85072,6 +85239,7 @@ CVE-2026-1838 (The Hostel plugin for WordPress is 
vulnerable to Reflected Cross-
 CVE-2026-1559 (The Youzify plugin for WordPress is vulnerable to Stored 
Cross-Site Sc ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-54505 (A transient execution vulnerability within AMD CPUs may allow 
a local  ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bookworm] - xen <no-dsa> (Minor issue)
        [bullseye] - xen <end-of-life> (not supported under bullseye)
@@ -199411,12 +199579,14 @@ CVE-2025-23970 (Incorrect Privilege Assignment 
vulnerability in aonetheme Servic
 CVE-2024-9453 (A vulnerability was found in Red Hat OpenShift Jenkins. The 
bearer tok ...)
        NOT-FOR-US: Red Hat OpenShift Jenkins
 CVE-2026-23555 (Any guest issuing a Xenstore command accessing a node using 
the (illeg ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1 (unimportant)
        [bookworm] - xen <not-affected> (Vulnerable code not present)
        [bullseye] - xen <end-of-life> (EOLed in Bullseye)
        NOTE: https://xenbits.xen.org/xsa/advisory-481.html
        NOTE: Debian uses the ocaml-based xenstored
 CVE-2026-23554 (The Intel EPT paging code uses an optimization to defer 
flushing of an ...)
+       {DSA-6424-1}
        - xen 4.20.3+127-gc42374a105-1
        [bookworm] - xen <no-dsa> (Minor issue)
        [bullseye] - xen <not-affected> (Vulnerable code not present)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d3e2c22fac3194326808e08a658fc6f1feabf5ec

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d3e2c22fac3194326808e08a658fc6f1feabf5ec
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to