Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ccc60041 by security tracker role at 2026-08-19T19:14:25+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,591 @@
+CVE-2026-76614 (OpenEMR before 8.3.0 contains a path traversal vulnerability 
in the ED ...)
+       TODO: check
+CVE-2026-76245 (stigmem (pip package stigmem-node) version 0.9.0a1 contains a 
timestam ...)
+       TODO: check
+CVE-2026-76244 (stigmem-node contains an insecure default configuration 
vulnerability  ...)
+       TODO: check
+CVE-2026-76243 (stigmem versions before 0.9.0a2 allow unauthenticated access 
when auth ...)
+       TODO: check
+CVE-2026-76242 (stigmem-node 0.9.0a1 accepts federation peer key material 
during peer  ...)
+       TODO: check
+CVE-2026-76241 (stigmem-node 0.9.0a1 allows plugin signature enforcement to be 
disable ...)
+       TODO: check
+CVE-2026-76240 (stigmem-node 0.9.0a1 interpolates Postgres backend schema 
identifiers  ...)
+       TODO: check
+CVE-2026-76239 (Stigmem before 0.9.0a11 fails to validate the delivery_address 
paramet ...)
+       TODO: check
+CVE-2026-76238 (stigmem versions before 0.9.0a12 contain a broken object level 
authori ...)
+       TODO: check
+CVE-2026-76237 (stigmem-node before 0.9.0a12 contains a broken object level 
authorizat ...)
+       TODO: check
+CVE-2026-76236 (stigmem-node before 0.9.0a12 contains a cross-tenant broken 
object lev ...)
+       TODO: check
+CVE-2026-76235 (A memory leak flaw was found in cockpit-ws. The login page 
handler lea ...)
+       TODO: check
+CVE-2026-76234 (libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq 
before  ...)
+       TODO: check
+CVE-2026-76233 (Renovate versions from 39.53.0 before 40.33.0 contain a 
command inject ...)
+       TODO: check
+CVE-2026-76232 (Renovate versions from 31.51.0 before 40.33.0 contain a 
command inject ...)
+       TODO: check
+CVE-2026-76231 (Renovate versions from 32.135.0 before 40.33.0 contain a 
command injec ...)
+       TODO: check
+CVE-2026-76230 (Renovate versions from 35.63.0 before 40.33.0 contain a 
command inject ...)
+       TODO: check
+CVE-2026-76229 (Renovate versions from 39.218.0 before 40.33.0 contain an 
arbitrary co ...)
+       TODO: check
+CVE-2026-76228 (Renovate versions >=32.124.0 and before 42.68.5 (and Mend 
renovate-ce/ ...)
+       TODO: check
+CVE-2026-76227 (Renovate versions from 42.68.1 before 42.96.3 (and from 
42.68.1 before ...)
+       TODO: check
+CVE-2026-76226 (Renovate versions from 43.65.0 before 43.102.11 contain a 
remote code  ...)
+       TODO: check
+CVE-2026-76225 (ArcadeDB before 26.8.1 contains a server-side request forgery 
vulnerab ...)
+       TODO: check
+CVE-2026-76224 (ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) 
contains ...)
+       TODO: check
+CVE-2026-76223 (ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to 
enforce th ...)
+       TODO: check
+CVE-2026-76222 (GitPython before 3.1.58 fails to validate submodule names from 
.gitmod ...)
+       TODO: check
+CVE-2026-76221 (GitPython before 3.1.58 contains a config-name injection 
vulnerability ...)
+       TODO: check
+CVE-2026-76220 (GitPython before 3.1.58 contains a command execution 
vulnerability in  ...)
+       TODO: check
+CVE-2026-76219 (GitPython versions before 3.1.58 contain an arbitrary file 
overwrite v ...)
+       TODO: check
+CVE-2026-76218 (GitPython before 3.1.58 contains a remote code execution 
vulnerability ...)
+       TODO: check
+CVE-2026-76217 (GitPython versions before 3.1.58 fail to validate options 
passed to gi ...)
+       TODO: check
+CVE-2026-76216 (Vikunja through 2.4.0 contains a principal-type confusion 
vulnerabilit ...)
+       TODO: check
+CVE-2026-76215 (phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility 
checks befo ...)
+       TODO: check
+CVE-2026-76214 (phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to 
persist th ...)
+       TODO: check
+CVE-2026-76213 (phpMyFAQ before 4.1.7 contains a brute-force vulnerability in 
the two- ...)
+       TODO: check
+CVE-2026-76212 (phpMyFAQ before 4.1.7, when configured to use PostgreSQL via 
the nativ ...)
+       TODO: check
+CVE-2026-76211 (phpMyFAQ before 4.1.7 fails to properly enforce 
CONFIGURATION_EDIT per ...)
+       TODO: check
+CVE-2026-76210 (phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ 
answers ...)
+       TODO: check
+CVE-2026-76209 (phpMyFAQ versions before v4.1.6 fail to validate the 
security.enableRe ...)
+       TODO: check
+CVE-2026-76208 (phpMyFAQ versions 3.1.0 through 4.1.6 contain an 
authentication bypass ...)
+       TODO: check
+CVE-2026-76207 (phpMyFAQ before 4.1.7 contains a two-factor authentication 
bypass vuln ...)
+       TODO: check
+CVE-2026-76206 (phpMyFAQ versions before 4.1.7 fail to validate active status 
in the P ...)
+       TODO: check
+CVE-2026-76205 (phpMyFAQ before 4.1.7 contains a SQL injection vulnerability 
in the gl ...)
+       TODO: check
+CVE-2026-76203 (Incorrect Behavior Order: Validate Before Canonicalize in the 
report t ...)
+       TODO: check
+CVE-2026-76166 (A flaw was found in mod_cluster's AdvertiseListenerImpl 
(org.jboss.mod ...)
+       TODO: check
+CVE-2026-76164 (AIL Framework contains a server-side request forgery (SSRF) 
vulnerabil ...)
+       TODO: check
+CVE-2026-75956 (Joomla Extension - cmsjunkie.com - DOS vector in pagination 
parameter  ...)
+       TODO: check
+CVE-2026-75955 (Joomla Extension - cmsjunkie.com - Reflected XSS / XML 
injection in J- ...)
+       TODO: check
+CVE-2026-75954 (Joomla Extension - cmsjunkie.com -  SQL injection in trips 
search in J ...)
+       TODO: check
+CVE-2026-75953 (Joomla Extension - cmsjunkie.com -  Open mail relay in 
J-BusinessDirec ...)
+       TODO: check
+CVE-2026-75952 (Joomla Extension - cmsjunkie.com -  Cross-site request forgery 
in J-Bu ...)
+       TODO: check
+CVE-2026-75951 (Joomla Extension - cmsjunkie.com - Insecure Direct Object 
Reference (m ...)
+       TODO: check
+CVE-2026-75950 (Joomla Extension - cmsjunkie.com - Unauthenticated listing 
ownership t ...)
+       TODO: check
+CVE-2026-75949 (Joomla Extension - cmsjunkie.com -  Arbitrary file upload / 
deletion ( ...)
+       TODO: check
+CVE-2026-75920 (phpMyFAQ before v4.1.6 writes content backup ZIP archives to 
the web-a ...)
+       TODO: check
+CVE-2026-75919 (phpMyFAQ before 4.1.7 contains an authentication bypass 
vulnerability  ...)
+       TODO: check
+CVE-2026-75918 (phpMyFAQ before 4.1.7 stores password reset tokens in a 
publicly acces ...)
+       TODO: check
+CVE-2026-75917 (SiYuan before v3.7.4 contains a cross-site scripting 
vulnerability in  ...)
+       TODO: check
+CVE-2026-75916 (SiYuan through 3.7.3 contains a cross-site scripting 
vulnerability in  ...)
+       TODO: check
+CVE-2026-75619 (Tapo C100/C101 V5 contains a heap-based buffer overflow 
vulnerability  ...)
+       TODO: check
+CVE-2026-75618 (Tapo C100/C101 V5 contains a null pointer dereference 
vulnerability in ...)
+       TODO: check
+CVE-2026-75583 (keeper.sh's calendar module version prior to 2.18.14 contains 
a server ...)
+       TODO: check
+CVE-2026-75149 (marimo before 0.23.15 contains a code injection vulnerability 
in the n ...)
+       TODO: check
+CVE-2026-75148 (cgltf through 1.15 contains an integer overflow vulnerability 
in the n ...)
+       TODO: check
+CVE-2026-75147 (FFmpeg before commit 983dae9 contains an out-of-bounds read in 
the AV1 ...)
+       TODO: check
+CVE-2026-75146 (FFmpeg before commit 65b0dab contains an out-of-bounds read in 
the DAS ...)
+       TODO: check
+CVE-2026-75145 (FFmpeg before commit b4c199c contains an incorrect integer 
narrowing c ...)
+       TODO: check
+CVE-2026-75144 (FFmpeg before commit 1cdeb3c contains a heap buffer overflow 
vulnerabi ...)
+       TODO: check
+CVE-2026-75143 (FFmpeg before commit 1c10bcc contains a heap buffer overflow 
in the RI ...)
+       TODO: check
+CVE-2026-75142 (FFmpeg before commit 9d786e4 contains a stack buffer overflow 
in the M ...)
+       TODO: check
+CVE-2026-75141 (FFmpeg before commit acf5d7c contains a heap buffer overflow 
in the hv ...)
+       TODO: check
+CVE-2026-75114 (Joomla Extension - yootheme.com - Open redirect in 
CommentController:: ...)
+       TODO: check
+CVE-2026-74804 (Joomla Extension - yootheme.com - Unauthenticated SQL 
injection in Ite ...)
+       TODO: check
+CVE-2026-74803 (Joomla Extension - yootheme.com - Unauthenticated arbitrary 
file uploa ...)
+       TODO: check
+CVE-2026-73829 (Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive 
mpp allow ...)
+       TODO: check
+CVE-2026-73541 (Allocation of Resources Without Limits or Throttling in 
ZenHive mpp al ...)
+       TODO: check
+CVE-2026-73394 (Unauthenticated Broken Access Control in Stitch Express <= 
1.9.0 versi ...)
+       TODO: check
+CVE-2026-73391 (Unauthenticated SQL Injection in Total Donations <= 2.0.5 
versions.)
+       TODO: check
+CVE-2026-73390 (Unauthenticated Privilege Escalation in Total Donations <= 
2.0.5 versi ...)
+       TODO: check
+CVE-2026-73389 (Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 
version ...)
+       TODO: check
+CVE-2026-73388 (Unauthenticated SQL Injection in Nikstore Core <= 1.5 
versions.)
+       TODO: check
+CVE-2026-73387 (Unauthenticated Local File Inclusion in Resido <= 1.5 
versions.)
+       TODO: check
+CVE-2026-73386 (Unauthenticated Sensitive Data Exposure in Track Geolocation 
Of Users  ...)
+       TODO: check
+CVE-2026-73385 (Unauthenticated Broken Access Control in Outranking Plugin 
Options <=  ...)
+       TODO: check
+CVE-2026-73384 (Unauthenticated Sensitive Data Exposure in Pay with Contact 
Form 7 <=  ...)
+       TODO: check
+CVE-2026-73364 (Customer PHP Object Injection in Flexible Subscriptions <= 
1.8.1 versi ...)
+       TODO: check
+CVE-2026-73363 (Unauthenticated Broken Access Control in Taxi Booking Manager 
for WooC ...)
+       TODO: check
+CVE-2026-73354 (Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real 
Estate I ...)
+       TODO: check
+CVE-2026-73347 (Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 
versions.)
+       TODO: check
+CVE-2026-73185 (Unauthenticated SQL Injection in NGG Smart Image Search < 
4.0.0 versio ...)
+       TODO: check
+CVE-2026-73184 (Unauthenticated Cross Site Scripting (XSS) in Global Gallery 
<= 11.1.2 ...)
+       TODO: check
+CVE-2026-73183 (Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 
versions.)
+       TODO: check
+CVE-2026-73182 (Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 
versions.)
+       TODO: check
+CVE-2026-73136 (Authentication Bypass by Capture-replay in ZenHive mpp allows 
an unaut ...)
+       TODO: check
+CVE-2026-72717 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-72716 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-72530 (A remote unauthorized attacker with network access via port 
4307/TCP t ...)
+       TODO: check
+CVE-2026-72529 (A remote unauthorized attacker with network access via port 
4307/TCP t ...)
+       TODO: check
+CVE-2026-71961 (Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS 
command  ...)
+       TODO: check
+CVE-2026-71960 (Cudy WR3000 2.0 running firmware before 2.5.24 contains a 
hard-coded J ...)
+       TODO: check
+CVE-2026-71871 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-71869 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-71868 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-71867 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-71866 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-71865 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-71864 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-71694 (An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile 
RTL benchm ...)
+       TODO: check
+CVE-2026-71470 (A flaw was found in the search-v2-operator. This vulnerability 
allows  ...)
+       TODO: check
+CVE-2026-71176 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
+       TODO: check
+CVE-2026-70496 (A flaw was found in search-v2-operator. The operator's 
ClusterRole has ...)
+       TODO: check
+CVE-2026-70424 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
+       TODO: check
+CVE-2026-70423 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
+       TODO: check
+CVE-2026-70422 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
+       TODO: check
+CVE-2026-70421 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
+       TODO: check
+CVE-2026-69159 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
+       TODO: check
+CVE-2026-67581 (Authentication Bypass by Capture-replay in ZenHive mpp allows 
an unaut ...)
+       TODO: check
+CVE-2026-67364 (Joomla Extension - balbooa.com - Pre-auth PHP Code Injection 
in Balboo ...)
+       TODO: check
+CVE-2026-67363 (Joomla Extension - balbooa.com - Pre-auth Payment Amount 
Tampering in  ...)
+       TODO: check
+CVE-2026-67268 (Dell Command Update (DCU), versions prior to 5.7.1, contain an 
Imprope ...)
+       TODO: check
+CVE-2026-67267 (Dell Command Update (DCU), versions prior to 5.7.1, contain an 
Exposur ...)
+       TODO: check
+CVE-2026-67266 (Dell Command Update (DCU), versions prior to 5.7.1, contain an 
Incorre ...)
+       TODO: check
+CVE-2026-66794 (A flaw was found in the `cluster-proxy-addon` component of 
Multicluste ...)
+       TODO: check
+CVE-2026-66668 (Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 
versions.)
+       TODO: check
+CVE-2026-66613 (Unauthenticated Remote Code Execution (RCE) in JetEngine <= 
3.8.14 ver ...)
+       TODO: check
+CVE-2026-66596 (Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 
9.3.3 vers ...)
+       TODO: check
+CVE-2026-65612 (nnn does not sanitize the filename variable. An attacker can 
place a f ...)
+       TODO: check
+CVE-2026-65611 (nnn does not sanitize the path variable. An attacker can 
createa direc ...)
+       TODO: check
+CVE-2026-65610 (nnn stores homelen variable as uchar_t, which can only 
represent value ...)
+       TODO: check
+CVE-2026-65609 (nnn is vulnerable to Out-of-Bound write vulnerability.Due to 
lack of v ...)
+       TODO: check
+CVE-2026-64852 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
+       TODO: check
+CVE-2026-64851 (Grav Shortcode Core Plugin allows for the development 
shortcode plugin ...)
+       TODO: check
+CVE-2026-64850 (Grav is a file-based Web platform. Prior to 2.0.7, Grav 
Blueprint::dyn ...)
+       TODO: check
+CVE-2026-63652 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
+       TODO: check
+CVE-2026-63633 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
+       TODO: check
+CVE-2026-63408 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
+       TODO: check
+CVE-2026-63407 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
+       TODO: check
+CVE-2026-63117 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
+       TODO: check
+CVE-2026-62682 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-62681 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-62680 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
+       TODO: check
+CVE-2026-62673 (Grav is a file-based Web platform. Prior to 2.0.4, the Grav 
.htaccess  ...)
+       TODO: check
+CVE-2026-62672 (Grav is a file-based Web platform. Prior to 2.0.4, Grav 
allowlists the ...)
+       TODO: check
+CVE-2026-62671 (Grav Login Plugin adds login, basic ACL, and session wide 
messages to  ...)
+       TODO: check
+CVE-2026-62670 (Grav Flex Objects Plugin allows you to build custom 
collections of obj ...)
+       TODO: check
+CVE-2026-62669 (Grav Login Plugin adds login, basic ACL, and session wide 
messages to  ...)
+       TODO: check
+CVE-2026-62668 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
+       TODO: check
+CVE-2026-62667 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
+       TODO: check
+CVE-2026-62666 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
+       TODO: check
+CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery 
<= 30.0. ...)
+       TODO: check
+CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav 
Twig conte ...)
+       TODO: check
+CVE-2026-61807 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.2, a s ...)
+       TODO: check
+CVE-2026-61690 (Grav is a file-based Web platform. Prior to 2.0.1, Grav 
ZipArchiver::e ...)
+       TODO: check
+CVE-2026-61607 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
+       TODO: check
+CVE-2026-61518 (ISPConfig contains an authenticated SQL injection 
vulnerability in the ...)
+       TODO: check
+CVE-2026-58565 (Dell Command Update (DCU), versions prior to 5.7.1, contain a 
Missing  ...)
+       TODO: check
+CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an 
Incorre ...)
+       TODO: check
+CVE-2026-58562 (Dell Command Update (DCU), versions prior to 5.7.1, contain a 
Missing  ...)
+       TODO: check
+CVE-2026-58088 (The ELF core dump code counted the number of dumpable VM map 
entries,  ...)
+       TODO: check
+CVE-2026-58087 (The GETALL and SETALL commands in semctl(2) recorded the 
number of sem ...)
+       TODO: check
+CVE-2026-58086 (As an inadvertent side effect of an unrelated code change, 
PRIV_KTRACE ...)
+       TODO: check
+CVE-2026-58085 (After dispatching a decrypt operation to OCF and receiving the 
result, ...)
+       TODO: check
+CVE-2026-58084 (To retrieve the previous timer value, the kernel calls 
realtimer_getti ...)
+       TODO: check
+CVE-2026-58083 (While the kernel was copying knotes during fork, a knote with 
a timer- ...)
+       TODO: check
+CVE-2026-58082 (The ISO-2022 encoding module used a stack buffer sized to 
MB_LEN_MAX ( ...)
+       TODO: check
+CVE-2026-58081 (Several encoding modules, including HZ, UTF-7, VIQR, and ZW, 
did not p ...)
+       TODO: check
+CVE-2026-56797 (Dell Command Update (DCU), versions prior to 5.7.1, a 
Time-of-check Ti ...)
+       TODO: check
+CVE-2026-56796 (Dell Command Update (DCU), versions prior to 5.7.1, contain an 
Imprope ...)
+       TODO: check
+CVE-2026-56088 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
+       TODO: check
+CVE-2026-55703 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.3, any ...)
+       TODO: check
+CVE-2026-55694 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.3, a r ...)
+       TODO: check
+CVE-2026-55643 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.3, a c ...)
+       TODO: check
+CVE-2026-55519 (Snipe-IT is an IT asset/license management system. Prior to 
8.4.1, an  ...)
+       TODO: check
+CVE-2026-55483 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.0, an  ...)
+       TODO: check
+CVE-2026-55482 (Snipe-IT is an IT asset/license management system. Prior to 
8.4.1, a n ...)
+       TODO: check
+CVE-2026-54796 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
+       TODO: check
+CVE-2026-54795 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
+       TODO: check
+CVE-2026-54794 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
a Server ...)
+       TODO: check
+CVE-2026-54793 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains 
an Impro ...)
+       TODO: check
+CVE-2026-53654 (Grav is a file-based Web platform. Prior to 3.8.5, the Login 
plugin tw ...)
+       TODO: check
+CVE-2026-53477 (Dell Command Update (DCU), versions prior to 5.7.1, contain a 
Time-of- ...)
+       TODO: check
+CVE-2026-53452 (Ground Station is a browser-based suite for satellite 
tracking, SDR re ...)
+       TODO: check
+CVE-2026-53451 (Ground Station is a browser-based suite for satellite 
tracking, SDR re ...)
+       TODO: check
+CVE-2026-52889 (Formie is a Craft CMS plugin for creating forms. Prior to 
3.1.27, Form ...)
+       TODO: check
+CVE-2026-52834 (jxl-oxide is a pure Rust implementation of a JPEG XL decoder. 
Prior to ...)
+       TODO: check
+CVE-2026-52792 (Algernon is a small self-contained pure-Go web server. Prior 
to 1.17.9 ...)
+       TODO: check
+CVE-2026-51367 (An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a 
remote  ...)
+       TODO: check
+CVE-2026-51366 (SQL Injection vulnerability in Bottinelli Informatica Vedo 
Suite v.1.2 ...)
+       TODO: check
+CVE-2026-50720 (The Ingenic T31 SoC boot ROM flash-boot verification path 
compares onl ...)
+       TODO: check
+CVE-2026-50719 (The Ingenic T41, and probably also T32, T40, and A1 SoC boot 
ROMs pars ...)
+       TODO: check
+CVE-2026-50550 (Snipe-IT is an IT asset/license management system. Prior to 
8.5.0, a u ...)
+       TODO: check
+CVE-2026-50173 (Flow-Like is a platform for building end-to-end use cases. 
Prior to ve ...)
+       TODO: check
+CVE-2026-49976 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.1, a u ...)
+       TODO: check
+CVE-2026-49870 (Snipe-IT is an IT asset/license management system. Prior to 
8.6.1, POS ...)
+       TODO: check
+CVE-2026-49817 (Dell Command Update (DCU), versions prior to 5.7.1, contain a 
Deserial ...)
+       TODO: check
+CVE-2026-49816 (Dell Command Update (DCU), versions prior to 5.7.1, contain a 
Deserial ...)
+       TODO: check
+CVE-2026-49441 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-49425 (The compat32 kevent() handler translates a 64-bit kevent 
struct into a ...)
+       TODO: check
+CVE-2026-49424 (The Linux waitid() implementation translates a FreeBSD 
siginfo_t struc ...)
+       TODO: check
+CVE-2026-49392 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-49289 (The SimpleSAMLphp SAML2 library is a PHP library for SAML2 
related fun ...)
+       TODO: check
+CVE-2026-49283 (The SimpleSAMLphp SAML2 library is a PHP library for SAML2 
related fun ...)
+       TODO: check
+CVE-2026-49255 (electerm is an open-sourced 
terminal/ssh/sftp/telnet/serialport/RDP/VN ...)
+       TODO: check
+CVE-2026-49253 (electerm is an open-sourced 
terminal/ssh/sftp/telnet/serialport/RDP/VN ...)
+       TODO: check
+CVE-2026-48162 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-48024 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-46343 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-45798 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-45742 (Gotenberg is a Docker-powered stateless API for PDF files. 
From 8.10.0 ...)
+       TODO: check
+CVE-2026-45741 (Gotenberg is a Docker-powered stateless API for PDF files. In 
8.32.0 a ...)
+       TODO: check
+CVE-2026-45274 (MyBooks is anebook management web server also known as 
Talebook. In 3. ...)
+       TODO: check
+CVE-2026-45273 (MyBooks is an ebook management web server also known as 
Talebook. In 3 ...)
+       TODO: check
+CVE-2026-45272 (MyBooks is an enhanced and easy-to-use personal ebook 
management web s ...)
+       TODO: check
+CVE-2026-44901 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-44829 (Gotenberg is a Docker-powered stateless API for PDF files. In 
8.32.0 a ...)
+       TODO: check
+CVE-2026-44256 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-44255 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-44254 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-44253 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-44252 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-41424 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
+       TODO: check
+CVE-2026-40509 (OpenEMR before 8.3.0 contains a cross-site request forgery 
vulnerabili ...)
+       TODO: check
+CVE-2026-40508 (OpenEMR before 8.3.0 contains a stored cross-site scripting 
vulnerabil ...)
+       TODO: check
+CVE-2026-40507 (OpenEMR before 8.3.0 contains a reflected cross-site scripting 
vulnera ...)
+       TODO: check
+CVE-2026-32802 (Dell PowerPath, version 7.2 through to 8.0 SP1, contains an 
Improper P ...)
+       TODO: check
+CVE-2026-32552 (Subscriber SQL Injection in YITH WooCommerce Membership 
Premium <= 2.3 ...)
+       TODO: check
+CVE-2026-32475 (Unrestricted Upload of File with Dangerous Type vulnerability 
in Eleme ...)
+       TODO: check
+CVE-2026-23501 (Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, 
contains an Imp ...)
+       TODO: check
+CVE-2026-20359 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
+       TODO: check
+CVE-2026-20358 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
+       TODO: check
+CVE-2026-20357 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
+       TODO: check
+CVE-2026-20327 (A vulnerability in the web-based management interface of Cisco 
Unified ...)
+       TODO: check
+CVE-2026-20320 (A vulnerability in the Open Client Interface (OCI) XML Parser 
of Cisco ...)
+       TODO: check
+CVE-2026-20319 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
+       TODO: check
+CVE-2026-20318 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
+       TODO: check
+CVE-2026-20317 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
+       TODO: check
+CVE-2026-20315 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
+       TODO: check
+CVE-2026-20314 (A vulnerability in Cisco Packaged Contact Center Enterprise 
(Packaged  ...)
+       TODO: check
+CVE-2026-20302 (A vulnerability in the USB driver of Cisco RoomOS could allow 
an unaut ...)
+       TODO: check
+CVE-2026-20232 (A vulnerability in the web-based management interface of Cisco 
Industr ...)
+       TODO: check
+CVE-2026-20231 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
+       TODO: check
+CVE-2026-20177 (A vulnerability in the handling of management plane packets by 
Cisco I ...)
+       TODO: check
+CVE-2026-20030 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
+       TODO: check
+CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote 
attacker to ...)
+       TODO: check
+CVE-2026-19672 (The tarfile module's tar and data  extraction filters created 
director ...)
+       TODO: check
+CVE-2026-19653 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-19490 (Vulnerability in NetScaler ADC and NetScaler Gateway.  This 
issue affe ...)
+       TODO: check
+CVE-2026-19489 (Vulnerability in NetScaler ADC and NetScaler Gateway.  This 
issue affe ...)
+       TODO: check
+CVE-2026-19321 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, 
and FW1 ...)
+       TODO: check
+CVE-2026-19234 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, 
and FW1 ...)
+       TODO: check
+CVE-2026-19198 (Akaunting 3.1.21 contains an authenticated improper 
authorization vuln ...)
+       TODO: check
+CVE-2026-18874 (A flaw was found in volsync-addon-controller. This 
vulnerability allow ...)
+       TODO: check
+CVE-2026-18848 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, FW1 ...)
+       TODO: check
+CVE-2026-18756 (HumHub Community Edition 1.18.4 contains a reflected 
cross-site script ...)
+       TODO: check
+CVE-2026-18681 (IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, 
FW1060.00  ...)
+       TODO: check
+CVE-2026-18526 (HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a 
stored Cross- ...)
+       TODO: check
+CVE-2026-18430 (HumHub 1.18.4 contains a stored cross-site scripting 
vulnerability in  ...)
+       TODO: check
+CVE-2026-18372 (CSS injection vulnerability in M-Files Web before 26.8.16330.2 
allows  ...)
+       TODO: check
+CVE-2026-18371 (HTML injection vulnerability in M-Files Web before 
26.8.16330.2 allows ...)
+       TODO: check
+CVE-2026-18315 (The TrueBooker \u2013 Appointment Booking and Scheduler System 
plugin  ...)
+       TODO: check
+CVE-2026-17494 (IBM Power Systems Firmware FW1120.00, and FW1110.00 through 
FW1110.30  ...)
+       TODO: check
+CVE-2026-17429 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, FW1 ...)
+       TODO: check
+CVE-2026-17183 (An authenticated user with permission to create or edit alert 
rules ca ...)
+       TODO: check
+CVE-2026-17100 (Power Systems FirmwareFW1120.00, FW1110.00 through FW1110.30, 
FW1060.0 ...)
+       TODO: check
+CVE-2026-17093 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, FW1 ...)
+       TODO: check
+CVE-2026-16938 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, FW1 ...)
+       TODO: check
+CVE-2026-16930 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, and ...)
+       TODO: check
+CVE-2026-16835 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, FW1 ...)
+       TODO: check
+CVE-2026-16832 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, FW1 ...)
+       TODO: check
+CVE-2026-16828 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, FW1 ...)
+       TODO: check
+CVE-2026-16819 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16818 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16817 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16816 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote aut ...)
+       TODO: check
+CVE-2026-16814 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16706 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16703 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
+       TODO: check
+CVE-2026-16690 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16687 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, FW1 ...)
+       TODO: check
+CVE-2026-16686 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16656 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
+       TODO: check
+CVE-2026-16440 (In Eclipse OpenJ9 versions up to 0.60, a crafted .class file 
with deep ...)
+       TODO: check
+CVE-2026-16019 (Improper neutralization of special elements used in an SQL 
command ('S ...)
+       TODO: check
+CVE-2026-15961 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, 
and FW1 ...)
+       TODO: check
+CVE-2026-15078 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow 
a remote ...)
+       TODO: check
+CVE-2026-15068 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow 
a remote ...)
+       TODO: check
+CVE-2026-15065 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow 
a remote ...)
+       TODO: check
+CVE-2026-15061 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis 
registration  ...)
+       TODO: check
+CVE-2026-14970 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server 
process is cr ...)
+       TODO: check
+CVE-2025-14603 (The application component processes user-supplied parameters 
insecurel ...)
+       TODO: check
+CVE-2025-14600 (An insecure deserialization vulnerability in vsDesk allows a 
remote at ...)
+       TODO: check
+CVE-2024-58376 (Renovate versions 37.158.0 before 37.199.0 contain a command 
injection ...)
+       TODO: check
+CVE-2024-13942 (Secure BootROM of RK3588s SoC is vulnerable to a time-of-check 
to time ...)
+       TODO: check
+CVE-2020-37267 (Renovate versions >=19.180.0 and <23.25.1, when used with 
Azure DevOps ...)
+       TODO: check
+CVE-2019-25766 (Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary 
repository  ...)
+       TODO: check
 CVE-2026-73639
        - libimager-perl 1.035+dfsg-1
        [trixie] - libimager-perl <no-dsa> (Minor issue)
@@ -12,12 +600,12 @@ CVE-2026-XXXX [GHSA-xrfq-jhgh-wqch: Authentication bypass 
in the web interface]
        - sabnzbdplus <unfixed> (bug #1144839)
        NOTE: 
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch
        NOTE: Fixed by: 
https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5
 (5.1.1)
-CVE-2026-72889
+CVE-2026-72889 (Net::OAuth versions before 0.33 for Perl allow the sender to 
choose th ...)
        - libnet-oauth-perl 0.33-1 (bug #1144854)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42818761/
        NOTE: 
https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-c8rm-g5cm-4pf5
        NOTE: Fixed by: 
https://github.com/vurtdev/Net-OAuth/commit/c467adf45c8d77ac4b92ad78b3eebf949252ba7f
-CVE-2026-75589
+CVE-2026-75589 (Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, 
HMAC-SHA256  ...)
        - libnet-oauth-perl 0.33-1 (bug #1144855)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42818763/
        NOTE: 
https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-g8xr-69p3-gw56
@@ -2148,7 +2736,7 @@ CVE-2025-11729 (The PPWP: Password Protect Pages, Posts & 
Full or Partial Conten
        NOT-FOR-US: WordPress plugin
 CVE-2026-15571 (A flaw was found in the legacy client-initiated 
account-linking endpoi ...)
        - keycloak <itp> (bug #1088287)
-CVE-2026-75900
+CVE-2026-75900 (An out-of-bounds read vulnerability was found in swtpm's 
SWTPM_NVRAM_C ...)
        - swtpm <unfixed> (bug #1144810)
        NOTE: https://github.com/stefanberger/swtpm/pull/1155
        NOTE: Fixed by: 
https://github.com/stefanberger/swtpm/commit/dc5f5ee3d8261a4d9814ad5da69164a118822401
 (master)
@@ -2355,6 +2943,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient 
validation of packet len
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517490
        TODO: check, Red Hat bugzilla entry (only source) contains no 
information
 CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, 
Thunderbird E ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2368,6 +2957,7 @@ CVE-2026-74988 (Internally found bugs present in 
Thunderbird ESR 153.0 and Thund
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
 CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, 
Thunderbird E ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2384,6 +2974,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine 
component. This vulnerab
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
 CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This 
vulnerab ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2409,6 +3000,7 @@ CVE-2026-74977 (Integer overflow in the Graphics 
component. This vulnerability w
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
 CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. 
This vulne ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2419,6 +3011,7 @@ CVE-2026-74975 (Spoofing issue in the Downloads component 
in Firefox for Android
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
 CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. 
This vu ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2426,6 +3019,7 @@ CVE-2026-74974 (Same-origin policy bypass in the 
Graphics: ImageLib component. T
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
 CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This 
vulnera ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2433,6 +3027,7 @@ CVE-2026-74973 (Race condition, use-after-free in the 
Graphics component. This v
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
 CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions 
component. This  ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2440,6 +3035,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push 
Subscriptions component.
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
 CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling 
componen ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2450,6 +3046,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
 CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This 
vulnerabi ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2460,6 +3057,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics: 
WebRender component. This
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
 CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback 
component. This ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2470,6 +3068,7 @@ CVE-2026-74966 (Information disclosure in the Form 
Autofill component. This vuln
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
 CVE-2026-74965 (Privilege escalation in the Shell Integration component. This 
vulnerab ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2477,6 +3076,7 @@ CVE-2026-74965 (Privilege escalation in the Shell 
Integration component. This vu
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
 CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability 
was fix ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2484,6 +3084,7 @@ CVE-2026-74964 (Integer overflow in the Graphics 
component. This vulnerability w
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
 CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies 
component. This v ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2491,6 +3092,7 @@ CVE-2026-74963 (Same-origin policy bypass in the 
Networking: Cookies component.
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
 CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. 
This vulner ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2501,6 +3103,7 @@ CVE-2026-74961 (Side-channel in the Web Audio component. 
This vulnerability was
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
 CVE-2026-74960 (Site isolation issue in the WebExtensions component. This 
vulnerabilit ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2508,6 +3111,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions 
component. This vulner
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
 CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This 
vulnerabil ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2518,6 +3122,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
 CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This 
vulnerability w ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2534,6 +3139,7 @@ CVE-2026-74954 (Information disclosure due to 
side-channel in the Storage: Cache
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
 CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. 
This vulner ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2550,6 +3156,7 @@ CVE-2026-74950 (Privilege escalation in the Downloads API 
component. This vulner
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
 CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: 
Canvas2D c ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2557,6 +3164,7 @@ CVE-2026-74949 (Privilege escalation due to 
use-after-free in the Graphics: Canv
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
 CVE-2026-74948 (Information disclosure in the Graphics component. This 
vulnerability w ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2567,6 +3175,7 @@ CVE-2026-74947 (Privilege escalation due to invalid 
pointer in the Graphics comp
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
 CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2574,6 +3183,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect 
boundary conditions in the
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
 CVE-2026-74945 (Information disclosure in the Graphics: Text component. This 
vulnerabi ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2581,6 +3191,7 @@ CVE-2026-74945 (Information disclosure in the Graphics: 
Text component. This vul
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
 CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This 
vulnerability w ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2588,6 +3199,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML 
component. This vulnerabi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
 CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This 
vulnerability ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2595,6 +3207,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib 
component. This vulnera
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
 CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. 
This vul ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2602,6 +3215,7 @@ CVE-2026-74942 (Privilege escalation in the Remote 
Settings Client component. Th
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
 CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. 
This vuln ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2609,6 +3223,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics: 
CanvasWebGL component. Thi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
 CVE-2026-74940 (Use-after-free in the Graphics: Text component. This 
vulnerability was ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2616,6 +3231,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text 
component. This vulnerabili
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
 CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This 
vulnerabil ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2629,6 +3245,7 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
 CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This 
vulnerab ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2636,6 +3253,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript: 
WebAssembly component. This vu
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
 CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This 
vulnerabil ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -2643,6 +3261,7 @@ CVE-2026-74935 (Privilege escalation in the DOM: 
Networking component. This vuln
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
 CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. 
This vuln ...)
+       {DSA-6451-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird <unfixed>
@@ -5002,7 +5621,8 @@ CVE-2026-74240 (A flaw was found in Red Hat Quay's JWT 
(JSON Web Token) validati
        NOT-FOR-US: Red Hat Quay
 CVE-2026-73683 (Laravel Socialite's Facebook provider contains an 
authentication bypas ...)
        NOT-FOR-US: Laravel Socialite's Facebook provider
-CVE-2026-73682 (Semaphore versions prior to 2.18.20 contain an OS command 
injection (a ...)
+CVE-2026-73682
+       REJECTED
        NOT-FOR-US: Semaphore UI
 CVE-2026-73680 (Cockpit CMS 2.14.0 and prior contains a command injection 
vulnerabilit ...)
        NOT-FOR-US: Cockpit CMS
@@ -27864,7 +28484,7 @@ CVE-2026-48702 (Rekor is a software supply chain 
transparency log. Starting in v
        NOTE: Fixed by: 
https://github.com/sigstore/rekor/commit/759b98e2a7c39ea9779b6a51299c5f0f987f8802
 (v1.5.2)
 CVE-2026-50540 (Kata Containers is an open source project focusing on a 
standard imple ...)
        NOT-FOR-US: Kata Containers
-CVE-2026-50149
+CVE-2026-50149 (Contour is a Kubernetes ingress controller using Envoy proxy. 
In versi ...)
        NOT-FOR-US: Contour
 CVE-2026-47701
        NOT-FOR-US: OpenTelemetry Operator
@@ -43568,7 +44188,7 @@ CVE-2026-60090 (PraisonAI before 4.6.78 fails to 
validate the caller-controlled
        NOT-FOR-US: PraisonAI
 CVE-2026-60088 (PraisonAI before 4.6.78 fails to validate file path references 
in cust ...)
        NOT-FOR-US: PraisonAI
-CVE-2026-57828 (Joomla Extension - phoca.cz - Authenticated file upload in 
RSFiles com ...)
+CVE-2026-57828 (Joomla Extension - phoca.cz - Authenticated file upload in 
Phoca Downl ...)
        NOT-FOR-US: Joomla
 CVE-2026-57827 (Joomla Extension - rsjoomla.com - Unauthenticated file upload 
in RSFil ...)
        NOT-FOR-US: Joomla
@@ -46665,32 +47285,32 @@ CVE-2026-55827 (FreeRDP is a free implementation of 
the Remote Desktop Protocol.
        [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c495-h83v-3prp
-CVE-2026-55564
+CVE-2026-55564 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
        - freerdp3 3.27.0+dfsg-1
        [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6xmj-pr98-cx4c
-CVE-2026-55648
+CVE-2026-55648 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
        - freerdp3 3.27.0+dfsg-1
        [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5c5v-f78v-h2f6
-CVE-2026-55194
+CVE-2026-55194 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
        - freerdp3 3.27.0+dfsg-1
        [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9gxm-3mf5-f5cx
-CVE-2026-55193
+CVE-2026-55193 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
        - freerdp3 3.27.0+dfsg-1
        [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7rp4-66mc-j9vx
-CVE-2026-55192
+CVE-2026-55192 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
        - freerdp3 3.27.0+dfsg-1
        [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mmf-qh4f-frm6
-CVE-2026-55191
+CVE-2026-55191 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
        - freerdp3 3.27.0+dfsg-1
        [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
@@ -73953,7 +74573,7 @@ CVE-2026-8594 (Text::LineFold versions through 2019.001 
for Perl duplicate the o
        [bullseye] - libunicode-linebreak-perl <postponed> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/40542383/
        NOTE: Patch: 
https://security.metacpan.org/patches/U/Unicode-LineBreak/2019.001/CVE-2026-8594-r1.patch
-CVE-2026-48711
+CVE-2026-48711 (SSHFS is a network filesystem client for connecting to SSH 
servers. Fr ...)
        - sshfs-fuse 3.7.3-1.2 (bug #1138293)
        [trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
        [bookworm] - sshfs-fuse 3.7.3-1.2~deb12u1
@@ -73962,7 +74582,7 @@ CVE-2026-48711
        NOTE: 
https://github.com/libfuse/sshfs/security/advisories/GHSA-mm85-q63v-4476
        NOTE: https://github.com/libfuse/sshfs/pull/362
        NOTE: Fixed by: 
https://github.com/libfuse/sshfs/commit/6678accb85ea4aec15dae9961b92af8d12501a66
 (sshfs-3.7.6)
-CVE-2026-47187
+CVE-2026-47187 (SSHFS is a network filesystem client for connecting to SSH 
servers. Pr ...)
        - sshfs-fuse 3.7.3-1.2 (bug #1138293)
        [trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
        [bookworm] - sshfs-fuse 3.7.3-1.2~deb12u1
@@ -84640,7 +85260,7 @@ CVE-2026-8587 (Use after free in Extensions in Google 
Chrome on Mac prior to 148
        {DSA-6273-1}
        - chromium 148.0.7778.167-1
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-43961
+CVE-2026-43961 (A flaw was found in Vim's netrw plugin. A crafted filename 
containing  ...)
        - vim 2:9.2.0524-1 (bug #1136828)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/14/7
        NOTE: https://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3
@@ -138691,7 +139311,7 @@ CVE-2020-37118 (P5 FNIP-8x16A FNIP-4xSH 1.0.20 
contains a cross-site request for
        NOT-FOR-US: P5
 CVE-2020-37117 (jizhiCMS 1.6.7 contains a file download vulnerability in the 
admin plu ...)
        NOT-FOR-US: jizhiCMS
-CVE-2026-21727 (--- title: Cross-Tenant Legacy Correlation Disclosure and 
Deletion dra ...)
+CVE-2026-21727 (A cross-tenant isolation vulnerability was found in 
Grafana\u2019s Cor ...)
        - grafana <removed>
 CVE-2026-25585 (iccDEV provides a set of libraries and tools that allow for 
the intera ...)
        NOT-FOR-US: iccDEV
@@ -579373,7 +579993,7 @@ CVE-2021-26889 (Windows Update Stack Elevation of 
Privilege Vulnerability)
        NOT-FOR-US: Microsoft
 CVE-2021-26888
        RESERVED
-CVE-2021-26887 (<p>An elevation of privilege vulnerability exists in Microsoft 
Windows ...)
+CVE-2021-26887 (An elevation of privilege vulnerability exists in Microsoft 
Windows wh ...)
        NOT-FOR-US: Microsoft
 CVE-2021-26886 (User Profile Service Denial of Service Vulnerability)
        NOT-FOR-US: Microsoft
@@ -579387,7 +580007,7 @@ CVE-2021-26882 (Remote Access API Elevation of 
Privilege Vulnerability)
        NOT-FOR-US: Microsoft
 CVE-2021-26881 (Microsoft Windows Media Foundation Remote Code Execution 
Vulnerability)
        NOT-FOR-US: Microsoft
-CVE-2021-26880 (Storage Spaces Controller Elevation of Privilege Vulnerability)
+CVE-2021-26880 (Windows Storage Spaces Controller Elevation of Privilege 
Vulnerability)
        NOT-FOR-US: Microsoft
 CVE-2021-26879 (Windows Network Address Translation (NAT) Denial of Service 
Vulnerabil ...)
        NOT-FOR-US: Microsoft



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ccc60041fdc5e152420ec0f74e6c37a8dd694107

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ccc60041fdc5e152420ec0f74e6c37a8dd694107
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to