Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5f93d258 by security tracker role at 2026-08-18T07:12:52+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,293 @@
+CVE-2026-9859 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 
11.8.x <= 1 ...)
+       TODO: check
+CVE-2026-9816 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 
11.8.x <= 1 ...)
+       TODO: check
+CVE-2026-9693 (Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 
Mattermost f ...)
+       TODO: check
+CVE-2026-75587 (Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact 
the pre-a ...)
+       TODO: check
+CVE-2026-75531 (Pandora contains a stored cross-site scripting (XSS) 
vulnerability in  ...)
+       TODO: check
+CVE-2026-75529 (Pandora is affected by a stored cross-site scripting 
vulnerability in  ...)
+       TODO: check
+CVE-2026-75483 (powerlevel10k fails to neutralize control characters in the 
package.js ...)
+       TODO: check
+CVE-2026-75482 (SWE-agent's trajectory inspector (sweagent inspector), 
confirmed in v1 ...)
+       TODO: check
+CVE-2026-75481 (SkyPilot fails to validate that authenticated users are 
entitled to gr ...)
+       TODO: check
+CVE-2026-75480 (OpenViking debug vector scroll and count endpoints apply only 
account- ...)
+       TODO: check
+CVE-2026-75479 (JimuReport contains an authentication bypass vulnerability in 
the repo ...)
+       TODO: check
+CVE-2026-75151 (A vulnerability has been found in SourceCodester Onlne 
Examination & L ...)
+       TODO: check
+CVE-2026-75111 (Evidently UI fails to properly validate the filename parameter 
in the  ...)
+       TODO: check
+CVE-2026-75110 (MemOS is a memory operating system for LLMs and AI agents. In 
deployme ...)
+       TODO: check
+CVE-2026-75109 (Determined fails to authorize requests on the generic task 
kill, pause ...)
+       TODO: check
+CVE-2026-75108 (Next Terminal fails to enforce per-asset authorization checks 
on the p ...)
+       TODO: check
+CVE-2026-75106 (OpnForm derives editable-submission secrets from sequential 
row identi ...)
+       TODO: check
+CVE-2026-75105 (phpIPAM through 1.8.1 fails to verify that a requested IP 
address belo ...)
+       TODO: check
+CVE-2026-75104 (Hugging Face Transformers fails to validate shard filenames in 
checkpo ...)
+       TODO: check
+CVE-2026-75103 (Crawlab fails to verify user ownership or administrative role 
on the p ...)
+       TODO: check
+CVE-2026-75094 (A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts 
the fun ...)
+       TODO: check
+CVE-2026-75093 (A security vulnerability has been detected in sonos tract up 
to 0.23.4 ...)
+       TODO: check
+CVE-2026-75091 (The Quill Forms | Conversational Multi Step Forms, Surveys & 
quizzes p ...)
+       TODO: check
+CVE-2026-75090 (A vulnerability was detected in EricLBuehler Mistral.rs up to 
0.8.22.  ...)
+       TODO: check
+CVE-2026-75089 (A weakness has been identified in PHPGurukul Complaint 
Management Syst ...)
+       TODO: check
+CVE-2026-75088 (A vulnerability was determined in itsourcecode Hospital 
Management Sys ...)
+       TODO: check
+CVE-2026-75087 (A vulnerability was found in itsourcecode Hospital Management 
System 1 ...)
+       TODO: check
+CVE-2026-75086 (A vulnerability has been found in itsourcecode Hospital 
Management Sys ...)
+       TODO: check
+CVE-2026-75082 (A flaw has been found in Webkul Bagisto up to 2.4.4. The 
affected elem ...)
+       TODO: check
+CVE-2026-75081 (A vulnerability was detected in Webkul Bagisto up to 2.4.4. 
Impacted i ...)
+       TODO: check
+CVE-2026-75080 (A security vulnerability has been detected in SourceCodester 
Class and ...)
+       TODO: check
+CVE-2026-75079 (A weakness has been identified in SourceCodester Class and 
Exam Timeta ...)
+       TODO: check
+CVE-2026-75078 (A security flaw has been discovered in SourceCodester Class 
and Exam T ...)
+       TODO: check
+CVE-2026-75077 (A vulnerability was identified in SourceCodester Class and 
Exam Timeta ...)
+       TODO: check
+CVE-2026-75014 (A flaw has been found in SourceCodester Pet Grooming 
Management Softwa ...)
+       TODO: check
+CVE-2026-75013 (A vulnerability was detected in TOTOLINK EX1200L 
9.3.5u.6146_B20201023 ...)
+       TODO: check
+CVE-2026-75012 (A security vulnerability has been detected in TOTOLINK EX1200L 
9.3.5u. ...)
+       TODO: check
+CVE-2026-74234 (Legora before 2026-08-14 contains a cross-site scripting 
vulnerability ...)
+       TODO: check
+CVE-2026-73560 (vLLM is an inference and serving engine for large language 
models. Pri ...)
+       TODO: check
+CVE-2026-73410 (Budibase is an open-source low-code platform. Prior to 3.40.0, 
package ...)
+       TODO: check
+CVE-2026-71858 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.7 ...)
+       TODO: check
+CVE-2026-71553 (ApostropheCMS is an open-source Node.js content management 
system. In  ...)
+       TODO: check
+CVE-2026-71518 (Typemill before 2.26.0 contains an authorization bypass 
vulnerability  ...)
+       TODO: check
+CVE-2026-71486 (vLLM is an inference and serving engine for large language 
models. Pri ...)
+       TODO: check
+CVE-2026-71472 (A flaw was found in acm-search-v2-rhel9. This vulnerability 
allows an  ...)
+       TODO: check
+CVE-2026-71424 (Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, 
and 4.0.0 ...)
+       TODO: check
+CVE-2026-70495 (A flaw was found in search-v2-operator. This component's 
`search-servi ...)
+       TODO: check
+CVE-2026-69148 (MLflow is an open source AI engineering platform for agents, 
large lan ...)
+       TODO: check
+CVE-2026-69146 (MLflow is an open source AI engineering platform for agents, 
large lan ...)
+       TODO: check
+CVE-2026-68765 (hashcat master branch builds after v7.1.2 contain a heap 
buffer overfl ...)
+       TODO: check
+CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote 
attacker to ...)
+       TODO: check
+CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 
allows a remo ...)
+       TODO: check
+CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) 
allows an ...)
+       TODO: check
+CVE-2026-67966 (Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows 
unauthentic ...)
+       TODO: check
+CVE-2026-67965 (An issue in Tneda W20E v.16.01.0.6(2782) allows a remote 
attacker to e ...)
+       TODO: check
+CVE-2026-67961 (An issue in O2OA v.10.0.2 allows a local attacker to execute 
arbitrary ...)
+       TODO: check
+CVE-2026-67960 (An issue in PbootCMS v.3.2.15 allows an attacker to execute 
arbitrary  ...)
+       TODO: check
+CVE-2026-67926 (An issue in JeecgBoot v.3.9.2 allows a remote attacker to 
execute arbi ...)
+       TODO: check
+CVE-2026-67925 (Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows 
a remot ...)
+       TODO: check
+CVE-2026-67919 (An issue in Halo 2.25.4 allows a remote attacker to execute 
arbitrary  ...)
+       TODO: check
+CVE-2026-67918 (Directory Traversal vulnerability in hermes-studio v.0.6.26 
allows a r ...)
+       TODO: check
+CVE-2026-67917 (zuraCast versions up to and including 0.23.7 contain a SQL 
injection v ...)
+       TODO: check
+CVE-2026-67868 (A heap-based out-of-bounds write vulnerability exists in S2OPC 
1.7.3 i ...)
+       TODO: check
+CVE-2026-67854 (SQL Injection vulnerability in Qcms v.6.0.6 allows a remote 
attacker t ...)
+       TODO: check
+CVE-2026-67678 (File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 
allows a ...)
+       TODO: check
+CVE-2026-66795 (A flaw was found in the managedcluster-import-controller. The 
Certific ...)
+       TODO: check
+CVE-2026-65976 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 
until contin ...)
+       TODO: check
+CVE-2026-65974 (ERPNext is a free and open source Enterprise Resource Planning 
tool. P ...)
+       TODO: check
+CVE-2026-65832 (Deskflow is a keyboard and mouse sharing app. Prior to 
continuous buil ...)
+       TODO: check
+CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning 
tool. P ...)
+       TODO: check
+CVE-2026-65640 (WordPress is vulnerable to a remote code execution 
vulnerability via m ...)
+       TODO: check
+CVE-2026-65351 (This issue was addressed through improved state management. 
This issue ...)
+       TODO: check
+CVE-2026-65349 (An out-of-bounds read was addressed with improved input 
validation. Th ...)
+       TODO: check
+CVE-2026-65347 (The issue was addressed with improved checks. This issue is 
fixed in i ...)
+       TODO: check
+CVE-2026-65346 (An integer overflow was addressed with improved input 
validation. This ...)
+       TODO: check
+CVE-2026-65343 (A use after free issue was addressed with improved memory 
management.  ...)
+       TODO: check
+CVE-2026-65341 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       TODO: check
+CVE-2026-65340 (This issue was addressed through improved state management. 
This issue ...)
+       TODO: check
+CVE-2026-65339 (A logic issue was addressed with improved checks. This issue 
is fixed  ...)
+       TODO: check
+CVE-2026-65338 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       TODO: check
+CVE-2026-65337 (This issue was addressed through improved state management. 
This issue ...)
+       TODO: check
+CVE-2026-65336 (This issue was addressed through improved state management. 
This issue ...)
+       TODO: check
+CVE-2026-65335 (This issue was addressed through improved state management. 
This issue ...)
+       TODO: check
+CVE-2026-65334 (A memory corruption issue was addressed with improved state 
management ...)
+       TODO: check
+CVE-2026-65333 (This issue was addressed through improved state management. 
This issue ...)
+       TODO: check
+CVE-2026-65332 (This issue was addressed through improved state management. 
This issue ...)
+       TODO: check
+CVE-2026-65331 (This issue was addressed through improved state management. 
This issue ...)
+       TODO: check
+CVE-2026-65330 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       TODO: check
+CVE-2026-65329 (An authentication issue was addressed with improved state 
management.  ...)
+       TODO: check
+CVE-2026-64849 (MLflow is an open source AI engineering platform for agents, 
large lan ...)
+       TODO: check
+CVE-2026-64788 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       TODO: check
+CVE-2026-64787 (A use-after-free issue was addressed with improved memory 
management.  ...)
+       TODO: check
+CVE-2026-64784 (An out-of-bounds access issue was addressed with improved 
bounds check ...)
+       TODO: check
+CVE-2026-64782 (A memory corruption vulnerability was addressed with improved 
locking. ...)
+       TODO: check
+CVE-2026-64781 (The issue was addressed with improved input validation. This 
issue is  ...)
+       TODO: check
+CVE-2026-64780 (The issue was addressed with improved checks. This issue is 
fixed in i ...)
+       TODO: check
+CVE-2026-64779 (A memory corruption vulnerability was addressed with improved 
locking. ...)
+       TODO: check
+CVE-2026-64778 (The issue was addressed with improved checks. This issue is 
fixed in i ...)
+       TODO: check
+CVE-2026-64760 (An information leakage was addressed with additional 
validation. This  ...)
+       TODO: check
+CVE-2026-64715 (A use-after-free issue was addressed with improved memory 
management.  ...)
+       TODO: check
+CVE-2026-64657 (Budibase is an open-source low-code platform. Prior to 
3.39.19, the Po ...)
+       TODO: check
+CVE-2026-63670 (ApostropheCMS is an open-source Node.js content management 
system. Pri ...)
+       TODO: check
+CVE-2026-63669 (ApostropheCMS is an open-source Node.js content management 
system. Pri ...)
+       TODO: check
+CVE-2026-63667 (ApostropheCMS is an open-source Node.js content management 
system. Pri ...)
+       TODO: check
+CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 
until contin ...)
+       TODO: check
+CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx 
Enterprise Ed ...)
+       TODO: check
+CVE-2026-57485 (Stirling-PDF is a locally hosted web application that 
facilitates vari ...)
+       TODO: check
+CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.7 ...)
+       TODO: check
+CVE-2026-56677 (9Router is an AI router & token saver. In 0.5.4 and earlier, 
the POST  ...)
+       TODO: check
+CVE-2026-54758 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.7 ...)
+       TODO: check
+CVE-2026-54385
+       REJECTED
+CVE-2026-54356 (Budibase is an open-source low-code platform. Prior to 3.41.3, 
POST /a ...)
+       TODO: check
+CVE-2026-54336 (JumpServer is an open source bastion host and an operation and 
mainten ...)
+       TODO: check
+CVE-2026-52886 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.7 ...)
+       TODO: check
+CVE-2026-51977 (An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security 
Camera Ve ...)
+       TODO: check
+CVE-2026-47698 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, 
lib/bri ...)
+       TODO: check
+CVE-2026-47686 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, 
handleE ...)
+       TODO: check
+CVE-2026-47683 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, 
the buf ...)
+       TODO: check
+CVE-2026-45791 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-45790 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
+       TODO: check
+CVE-2026-44846 (JumpServer is an open source bastion host and an operation and 
mainten ...)
+       TODO: check
+CVE-2026-44845 (JumpServer is an open source bastion host and an operation and 
mainten ...)
+       TODO: check
+CVE-2026-43795 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       TODO: check
+CVE-2026-43794 (A memory corruption issue was addressed with improved memory 
handling. ...)
+       TODO: check
+CVE-2026-43667 (A reachable assertion was addressed with improved input 
validation. Th ...)
+       TODO: check
+CVE-2026-42164 (Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text 
block/sect ...)
+       TODO: check
+CVE-2026-42163 (Mahara before 25.04.5 and 26.04.0 is vulnerable to 
unauthorized access ...)
+       TODO: check
+CVE-2026-42162 (Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts 
being acc ...)
+       TODO: check
+CVE-2026-40506 (OpenEMR before 8.2.0 contains a path traversal vulnerability 
in the st ...)
+       TODO: check
+CVE-2026-39255 (Buffer Overflow vulnerability in SteelSeries GG (macOS) 
v.107.0.0 allo ...)
+       TODO: check
+CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS) 
v.107.0.0 allo ...)
+       TODO: check
+CVE-2026-38165 (A Server-Side Template Injection (SSTI) vulnerability in the 
Velocity  ...)
+       TODO: check
+CVE-2026-35219 (Budibase is an open-source low-code platform. Prior to 3.41.3, 
automat ...)
+       TODO: check
+CVE-2026-34789 (FreeCAD is a free and open-source multiplatform 3D parametric 
modeler. ...)
+       TODO: check
+CVE-2026-34399 (FreeCAD is a free and open-source multiplatform 3D parametric 
modeler. ...)
+       TODO: check
+CVE-2026-34398 (FreeCAD is a free and open-source multiplatform 3D parametric 
modeler. ...)
+       TODO: check
+CVE-2026-28984 (The issue was addressed with improved memory handling. This 
issue is f ...)
+       TODO: check
+CVE-2026-19650 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-19589 (Packer up to 1.15.4 is vulnerable to an issue in the 
third-party plugi ...)
+       TODO: check
+CVE-2026-19478 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-15748 (The Forminator Forms plugin for WordPress is vulnerable to 
Arbitrary F ...)
+       TODO: check
+CVE-2026-15371 (Velociraptor's web GUI allows specifying a custom type for 
columns in  ...)
+       TODO: check
+CVE-2026-11817 (This vulnerability only affects Grafana stacks configured with 
multipl ...)
+       TODO: check
+CVE-2026-11801 (The WPAdverts \u2013 Classifieds Plugin plugin for WordPress 
is vulner ...)
+       TODO: check
+CVE-2026-10080 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 
11.8.x <= 1 ...)
+       TODO: check
 CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy() 
in dri ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was 
possible via u ...)
@@ -13329,6 +13619,7 @@ CVE-2026-XXXX [Neutron sub-resource APIs do not verify 
parent ownership]
        NOTE: https://review.opendev.org/c/openstack/neutron/+/989624/
        NOTE: https://review.opendev.org/c/openstack/neutron/+/991586
 CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant 
infinite ...)
+       {DSA-6446-1}
        - expat 2.8.3-1 (bug #1144064)
        NOTE: https://github.com/libexpat/libexpat/pull/1296
        NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
@@ -42233,6 +42524,7 @@ CVE-2026-53730 (DataEase is an open source data 
visualization and analysis tool.
 CVE-2026-53729 (DataEase is an open source data visualization and analysis 
tool. Prior ...)
        NOT-FOR-US: DataEase
 CVE-2026-53511 (calibre is an e-book manager. Prior to 9.10.0, a malicious 
EPUB, OPF,  ...)
+       {DLA-4744-1}
        - calibre 9.10.0+ds+~0.10.6-1
        [trixie] - calibre <no-dsa> (Minor issue)
        [bullseye] - calibre <not-affected> (Vulnerable code introduced later)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f93d25814ebdffbfbe93eddbf7ce78c2beb2f7b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f93d25814ebdffbfbe93eddbf7ce78c2beb2f7b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to