Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
bdc6d046 by security tracker role at 2026-08-26T19:13:42+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,453 @@
+CVE-2026-9668 (With legitimate user credentials in hand, attackers can 
construct mali ...)
+       TODO: check
+CVE-2026-81036 (Stalwart Mail Server does not compare an OAuth redirect target 
against ...)
+       TODO: check
+CVE-2026-81035 (Midday allows any member of a team to delete it. The delete 
procedure  ...)
+       TODO: check
+CVE-2026-81034 (Netmaker disables certificate verification on the connection 
to the co ...)
+       TODO: check
+CVE-2026-81033 (Automatisch reveals whether an address is registered through 
the respo ...)
+       TODO: check
+CVE-2026-81032 (NebulaGraph exposes its runtime configuration over an 
unauthenticated  ...)
+       TODO: check
+CVE-2026-81031 (IDURAR ERP CRM changes the password of whichever account a 
request nam ...)
+       TODO: check
+CVE-2026-81030 (Mage AI does not confine the paths accepted by its 
browser-items API t ...)
+       TODO: check
+CVE-2026-81029 (OpenMetadata accepts a caller-supplied post-authentication 
redirect ta ...)
+       TODO: check
+CVE-2026-81028 (ZLMediaKit confines the downloadFile API to a configured set 
of root d ...)
+       TODO: check
+CVE-2026-81027 (one-api gates one of its two channel-pinning paths and not the 
other.  ...)
+       TODO: check
+CVE-2026-80589 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
+       TODO: check
+CVE-2026-80588 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
+       TODO: check
+CVE-2026-80587 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
+       TODO: check
+CVE-2026-80586 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
+       TODO: check
+CVE-2026-80585 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
+       TODO: check
+CVE-2026-80584 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80583 (In the Linux kernel, the following vulnerability has been 
resolved:  A ...)
+       TODO: check
+CVE-2026-80582 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-80581 (In the Linux kernel, the following vulnerability has been 
resolved:  A ...)
+       TODO: check
+CVE-2026-80580 (In the Linux kernel, the following vulnerability has been 
resolved:  f ...)
+       TODO: check
+CVE-2026-80579 (In the Linux kernel, the following vulnerability has been 
resolved:  f ...)
+       TODO: check
+CVE-2026-80578 (In the Linux kernel, the following vulnerability has been 
resolved:  f ...)
+       TODO: check
+CVE-2026-80577 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-80576 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-80575 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80574 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80573 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80572 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80571 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
+       TODO: check
+CVE-2026-80570 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80569 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80568 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80567 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80566 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80565 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
+       TODO: check
+CVE-2026-80564 (In the Linux kernel, the following vulnerability has been 
resolved:  g ...)
+       TODO: check
+CVE-2026-80563 (In the Linux kernel, the following vulnerability has been 
resolved:  g ...)
+       TODO: check
+CVE-2026-80562 (In the Linux kernel, the following vulnerability has been 
resolved:  g ...)
+       TODO: check
+CVE-2026-80561 (In the Linux kernel, the following vulnerability has been 
resolved:  l ...)
+       TODO: check
+CVE-2026-80560 (In the Linux kernel, the following vulnerability has been 
resolved:  o ...)
+       TODO: check
+CVE-2026-80559 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-80558 (In the Linux kernel, the following vulnerability has been 
resolved:  l ...)
+       TODO: check
+CVE-2026-80557 (In the Linux kernel, the following vulnerability has been 
resolved:  l ...)
+       TODO: check
+CVE-2026-80556 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
+       TODO: check
+CVE-2026-80555 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80554 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80553 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80552 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80551 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80550 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80549 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80548 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80547 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80546 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80545 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80544 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80543 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-80542 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-80541 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-80540 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-80539 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-80538 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80537 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80536 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80535 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80534 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80533 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80532 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80531 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80530 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80529 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-80528 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
+       TODO: check
+CVE-2026-80527 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
+       TODO: check
+CVE-2026-80526 (In the Linux kernel, the following vulnerability has been 
resolved:  A ...)
+       TODO: check
+CVE-2026-80525 (In the Linux kernel, the following vulnerability has been 
resolved:  A ...)
+       TODO: check
+CVE-2026-80524 (In the Linux kernel, the following vulnerability has been 
resolved:  o ...)
+       TODO: check
+CVE-2026-80523 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
+       TODO: check
+CVE-2026-80522 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
+       TODO: check
+CVE-2026-80521 (In the Linux kernel, the following vulnerability has been 
resolved:  a ...)
+       TODO: check
+CVE-2026-80520 (In the Linux kernel, the following vulnerability has been 
resolved:  o ...)
+       TODO: check
+CVE-2026-80519 (In the Linux kernel, the following vulnerability has been 
resolved:  o ...)
+       TODO: check
+CVE-2026-80428 (ILIAS deserialises stored session data for an unauthenticated 
caller.  ...)
+       TODO: check
+CVE-2026-80427 (bestzip builds the argument list for the system zip utility 
without se ...)
+       TODO: check
+CVE-2026-80426 (FiftyOne renders a dataset field's description as markup. The 
sidebar  ...)
+       TODO: check
+CVE-2026-80350 (OneUptime's webhook target check rejects private and loopback 
addresse ...)
+       TODO: check
+CVE-2026-80349 (TarsWeb decides whether a request comes from a trusted local 
caller us ...)
+       TODO: check
+CVE-2026-80348 (TarsWeb enforces its per-application roles by calling 
AuthService from ...)
+       TODO: check
+CVE-2026-80347 (mcp-fetch checks a fetch target against its SSRF guard without 
removin ...)
+       TODO: check
+CVE-2026-80346 (StarRocks performs no privilege check when a legacy 
synchronous materi ...)
+       TODO: check
+CVE-2026-80237 (EFence developed by Thinking Software Technology has an 
Arbitrary File ...)
+       TODO: check
+CVE-2026-80236 (Efence developed by Thinking Software Technology has a SQL 
Injection v ...)
+       TODO: check
+CVE-2026-80235 (EFence developed by Thinking Software Technology has an 
Arbitrary File ...)
+       TODO: check
+CVE-2026-80234 (CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a 
Missing A ...)
+       TODO: check
+CVE-2026-80233 (CAYIN CMS-WS, CMS-SE, and SMP series products developed by 
CAYIN Techn ...)
+       TODO: check
+CVE-2026-80206 (NLTK before 3.10.3 contains a regular expression denial of 
service (Re ...)
+       TODO: check
+CVE-2026-80205 (NLTK versions before 3.10.0 contain a regular expression 
denial of ser ...)
+       TODO: check
+CVE-2026-80204 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 
does not a ...)
+       TODO: check
+CVE-2026-80203 (The getgrav/grav-plugin-api plugin before 1.0.18 does not 
enforce API- ...)
+       TODO: check
+CVE-2026-80153
+       REJECTED
+CVE-2026-7487 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-79940 (Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G 
versions pr ...)
+       TODO: check
+CVE-2026-79902 (A flaw was found in the Seattle FilmWorks plugin in GIMP. When 
process ...)
+       TODO: check
+CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a 
capabili ...)
+       TODO: check
+CVE-2026-78237 (Insufficient input validation in ABR allows a low-privileged 
user to i ...)
+       TODO: check
+CVE-2026-78236 (An insecure PIN derivation mechanism in ABR allows a 
low-privileged us ...)
+       TODO: check
+CVE-2026-77801 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia 
diagram  ...)
+       TODO: check
+CVE-2026-77557 (A malicious actor with access to the network could exploit an 
Improper ...)
+       TODO: check
+CVE-2026-77554 (A malicious actor with access to the network could exploit an 
Improper ...)
+       TODO: check
+CVE-2026-77553 (A malicious actor with access to the network and low 
privileges could  ...)
+       TODO: check
+CVE-2026-77552 (A malicious actor with access to the network could exploit an 
Improper ...)
+       TODO: check
+CVE-2026-77551 (A malicious actor with access to the network and under certain 
conditi ...)
+       TODO: check
+CVE-2026-77550 (A malicious actor with access to the network could exploit an 
Improper ...)
+       TODO: check
+CVE-2026-77549 (A malicious actor with access to the network and under certain 
conditi ...)
+       TODO: check
+CVE-2026-77548 (A malicious actor with access to the network and low 
privileges could  ...)
+       TODO: check
+CVE-2026-77547 (A malicious actor with access to the network and low 
privileges could  ...)
+       TODO: check
+CVE-2026-77546 (A malicious actor with access to the network and low 
privileges could  ...)
+       TODO: check
+CVE-2026-77545 (A malicious actor with access to the network, low privileges 
and under ...)
+       TODO: check
+CVE-2026-77543 (A malicious actor with access to the network and low 
privileges could  ...)
+       TODO: check
+CVE-2026-77542 (A malicious actor with access to the network and high 
privileges could ...)
+       TODO: check
+CVE-2026-77541 (A malicious actor with access to the network and high 
privileges could ...)
+       TODO: check
+CVE-2026-77540 (A malicious actor with access to the network and high 
privileges could ...)
+       TODO: check
+CVE-2026-77539 (A malicious actor with access to the network and high 
privileges could ...)
+       TODO: check
+CVE-2026-77538 (A malicious actor with access to the network could exploit an 
Improper ...)
+       TODO: check
+CVE-2026-77537 (A malicious actor with access to the network could exploit an 
Improper ...)
+       TODO: check
+CVE-2026-77536 (A malicious actor with access to the network and low 
privileges could  ...)
+       TODO: check
+CVE-2026-77535 (A malicious actor with access to the network and high 
privileges could ...)
+       TODO: check
+CVE-2026-77534 (A malicious actor with access to the network and low 
privileges could  ...)
+       TODO: check
+CVE-2026-77533 (A malicious actor with access to the network and low 
privileges could  ...)
+       TODO: check
+CVE-2026-77532 (A malicious actor with access to an adjacent network could 
exploit a B ...)
+       TODO: check
+CVE-2026-76784 (Multiple TP-Link Kasa smart home devices contain insufficient 
cryptogr ...)
+       TODO: check
+CVE-2026-75977 (The Mang Board WP plugin for WordPress is vulnerable to 
Missing Author ...)
+       TODO: check
+CVE-2026-75960 (Rently Smart Home versions 20.1.0 and prior are vulnerable to 
an Insuf ...)
+       TODO: check
+CVE-2026-75896 (Use of Hard-coded Credentials vulnerability in T\xdcB\u0130TAK 
B\u0130 ...)
+       TODO: check
+CVE-2026-75466 (libjpeg-turbo 3.2.0 contains an integer division-by-zero 
vulnerability ...)
+       TODO: check
+CVE-2026-75325 (DWSurvey v6.14.0 is is vulnerable to authentication bypass via 
the '/a ...)
+       TODO: check
+CVE-2026-75062 (Improper Neutralization of Directives in Dynamically Evaluated 
Code (' ...)
+       TODO: check
+CVE-2026-74754 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-74753 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
+       TODO: check
+CVE-2026-74752 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-74751 (In the Linux kernel, the following vulnerability has been 
resolved:  r ...)
+       TODO: check
+CVE-2026-74750 (In the Linux kernel, the following vulnerability has been 
resolved:  o ...)
+       TODO: check
+CVE-2026-74749 (In the Linux kernel, the following vulnerability has been 
resolved:  r ...)
+       TODO: check
+CVE-2026-74748 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-74747 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
+       TODO: check
+CVE-2026-74746 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-74745 (In the Linux kernel, the following vulnerability has been 
resolved:  e ...)
+       TODO: check
+CVE-2026-74744 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
+       TODO: check
+CVE-2026-74743 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
+       TODO: check
+CVE-2026-74742 (In the Linux kernel, the following vulnerability has been 
resolved:  v ...)
+       TODO: check
+CVE-2026-74741 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-74740 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-74739 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-74738 (In the Linux kernel, the following vulnerability has been 
resolved:  r ...)
+       TODO: check
+CVE-2026-74737 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-74736 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-74735 (In the Linux kernel, the following vulnerability has been 
resolved:  l ...)
+       TODO: check
+CVE-2026-74734 (In the Linux kernel, the following vulnerability has been 
resolved:  f ...)
+       TODO: check
+CVE-2026-73108 (RustDesk versions before 1.4.7 contain an uncontrolled 
speculative mem ...)
+       TODO: check
+CVE-2026-73102 (RustDesk versions 1.3.9 through 1.4.9 contain a path traversal 
vulnera ...)
+       TODO: check
+CVE-2026-71171 (Dell Cloud Disaster Recovery, versions20.2 and prior,containan 
Imprope ...)
+       TODO: check
+CVE-2026-70419 (Dell Cloud Disaster Recovery, versions 20.2 and 
prior,containan Improp ...)
+       TODO: check
+CVE-2026-6178 (The Betheme theme for WordPress is vulnerable to Stored 
Cross-Site Scr ...)
+       TODO: check
+CVE-2026-63179 (Winter CMS is a content management system built on the Laravel 
PHP fra ...)
+       TODO: check
+CVE-2026-63041 (Reliance on Untrusted Inputs in a Security Decision 
vulnerability in A ...)
+       TODO: check
+CVE-2026-5092 (The Greenshift \u2013 animation and page builder blocks plugin 
for Wor ...)
+       TODO: check
+CVE-2026-59683 (The OpenRGB network protocol allows to write attacker 
controlled strin ...)
+       TODO: check
+CVE-2026-59682 (Arbitrary file overwrite via SAVE_PROFILE message in 
OpenRGB.This issu ...)
+       TODO: check
+CVE-2026-58474 (whichllm before 0.5.16 contains a code injection vulnerability 
in the  ...)
+       TODO: check
+CVE-2026-54614 (DebugKit provides a debugging toolbar for CakePHP 
applications. Prior  ...)
+       TODO: check
+CVE-2026-54606 (SunEditor is a lightweight and powerful WYSIWYG editor in 
vanilla Java ...)
+       TODO: check
+CVE-2026-54569 (SENAITE.CORE is the core framework for the SENAITE laboratory 
informat ...)
+       TODO: check
+CVE-2026-54556 (Http4s is a Scala interface for HTTP services. Prior to 
0.23.35 and 1. ...)
+       TODO: check
+CVE-2026-54553 (Starlette-Admin is a fast, beautiful and extensible 
administrative int ...)
+       TODO: check
+CVE-2026-54550 (IzPack is a widely used tool for packaging applications on the 
Java pl ...)
+       TODO: check
+CVE-2026-54523 (Kyverno is a policy engine designed for cloud native platform 
engineer ...)
+       TODO: check
+CVE-2026-54511 (LogTape is an unobtrusive logging library. Prior to 1.3.11, 
2.0.14, an ...)
+       TODO: check
+CVE-2026-54256 (Winter CMS is a content management system built on the Laravel 
PHP fra ...)
+       TODO: check
+CVE-2026-51106 (An issue in TokTok qTox v1.18.4 allows a local attacker to 
cause a den ...)
+       TODO: check
+CVE-2026-48786 (Fleet is an open-source device management platform built on 
osquery. I ...)
+       TODO: check
+CVE-2026-48549 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 
contains a CSR ...)
+       TODO: check
+CVE-2026-48548 (Nagios Core before 4.5.12 contains a cross-site request 
forgery vulner ...)
+       TODO: check
+CVE-2026-47841 (An application using Spring Security's WebAuthn support may be 
vulnera ...)
+       TODO: check
+CVE-2026-47837 (Missing Authentication for Critical Function vulnerability in 
Spring S ...)
+       TODO: check
+CVE-2026-47836 (The base directory (spring.cloud.config.server.svn.basedir) 
used by th ...)
+       TODO: check
+CVE-2026-41262 (Fleet is an open-source device management platform built on 
osquery. I ...)
+       TODO: check
+CVE-2026-3235 (The WP Data Access plugin for WordPress is vulnerable to 
Insecure Dire ...)
+       TODO: check
+CVE-2026-3035 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-36851 (Path traversal vulnerability in UnPoller 2.33.0 password field 
allows  ...)
+       TODO: check
+CVE-2026-35445 (Winter CMS is a content management system built on the Laravel 
PHP fra ...)
+       TODO: check
+CVE-2026-32639 (Winter CMS is a content management system built on the Laravel 
PHP fra ...)
+       TODO: check
+CVE-2026-32593 (Winter CMS is a content management system built on the Laravel 
PHP fra ...)
+       TODO: check
+CVE-2026-32258 (Winter is a free, open-source content management system (CMS) 
based on ...)
+       TODO: check
+CVE-2026-32257 (Winter is a free, open-source content management system (CMS) 
based on ...)
+       TODO: check
+CVE-2026-2388 (The Reviews and Rating \u2013 Google Reviews plugin for 
WordPress is v ...)
+       TODO: check
+CVE-2026-19538 (The BLOCKED access control list items that are evaluated to 
deny acces ...)
+       TODO: check
+CVE-2026-19485 (A Predictable Resource Name vulnerability in BigQuery Import 
Staging i ...)
+       TODO: check
+CVE-2026-19401 (Any remote client can crash a (debugging/non-release build 
type) NSD s ...)
+       TODO: check
+CVE-2026-19271 (Improper Neutralization of Special Elements used in an LDAP 
Query ('LD ...)
+       TODO: check
+CVE-2026-19197 (A user with organization administrator permissions can delete 
dashboar ...)
+       TODO: check
+CVE-2026-19042 (A command injection vulnerability in TeamViewer Full Client 
and Host f ...)
+       TODO: check
+CVE-2026-18916 (Any remote client can crash a NSD serve child, by throttling 
the TCP r ...)
+       TODO: check
+CVE-2026-18884 (The WooCommerce Lottery plugin for WordPress is vulnerable to 
Time-Bas ...)
+       TODO: check
+CVE-2026-18794 (The OpenRGB network protocol allows attackers to cause memory 
exhausti ...)
+       TODO: check
+CVE-2026-18664 (When ranges are used for access control (i.e. of the form 
1.2.3.4-1.2. ...)
+       TODO: check
+CVE-2026-18252 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-18080 (The ERP: Complete HR, Accounting & CRM Suite Built for 
WooCommerce plu ...)
+       TODO: check
+CVE-2026-16444 (Improper neutralization of path traversal sequences in 
TeamViewer Desk ...)
+       TODO: check
+CVE-2026-15990 (The Formidable Charts plugin for WordPress is vulnerable to 
Directory  ...)
+       TODO: check
+CVE-2026-15985 (The Classified Listing - Mobile Number Verification plugin for 
WordPre ...)
+       TODO: check
+CVE-2026-15387 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2026-13481 (The IEEE 1588 PTP management-message parser in 
subsys/net/lib/ptp/tlv. ...)
+       TODO: check
+CVE-2026-13480 (The LoRaWAN TS004 Fragmented Data Block Transport handler 
frag_transpo ...)
+       TODO: check
+CVE-2026-13479 (The LoRaWAN application-layer clock-synchronization service 
parses dow ...)
+       TODO: check
+CVE-2026-12717 (An Improper Input Validation vulnerability in CData JDBC 
driver integr ...)
+       TODO: check
+CVE-2026-12587 (The vulnerability allows the unauthorised generation of 
physical acces ...)
+       TODO: check
+CVE-2025-61165 (An arbitrary file upload vulnerability in the 
/v1/my_drive/batch_uploa ...)
+       TODO: check
+CVE-2025-61164 (Cohere North AI v1.1.5 was discovered to contain an 
information leak v ...)
+       TODO: check
+CVE-2025-61163 (Cohere North AI v1.1.5 was discovered to contain excessively 
permissiv ...)
+       TODO: check
+CVE-2025-61162 (Incorrect access control in Cohere North AI v1.1.5 allows 
attackers to ...)
+       TODO: check
+CVE-2025-56798 (Cross-Site Request Forgery (CSRF) vulnerability in Lime 
Technology, In ...)
+       TODO: check
+CVE-2025-29419 (CTFd v3.7.6 was discovered to be vulnerable to a 
man-in-the-middle att ...)
+       TODO: check
+CVE-2025-10903 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
+       TODO: check
+CVE-2023-42179 (Bird Home Automation GmbH D1101V-F 000140 is vulnerable to 
Incorrect A ...)
+       TODO: check
 CVE-2026-XXXX [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal 
during setup]
        - bubblewrap 0.12.0-1 (bug #1145655)
        NOTE: 
https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx
@@ -39,11 +489,11 @@ CVE-2026-80191 (GROWI applies its page-viewer permission 
check to attachment req
        NOT-FOR-US: GROWI
 CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how 
much da ...)
        NOT-FOR-US: LeafWiki
-CVE-2026-80186 [Stack Overflow in name2utf8 causes DoS and potential code 
execution]
+CVE-2026-80186 (A stack-based buffer overflow vulnerability exists in BlueZ, 
the Linux ...)
        - bluez <unfixed>
        NOTE: 
https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2
-CVE-2026-80185 [unprivileged-local and adjacent-LE-peer leads to arbitrary 
code execution as root]
+CVE-2026-80185 (BlueZ sdp-xml.c type confusion via 
RegisterProfile(ServiceRecord) can  ...)
        - bluez <unfixed>
        NOTE: 
https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
@@ -1595,7 +2045,8 @@ CVE-2026-78563 (The NotificationX Pro plugin for 
WordPress is vulnerable to Stor
        NOT-FOR-US: WordPress plugin
 CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local 
File Incl ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-78468 (The FluentCRM Pro \u2013 Email Newsletter, Automation, Email 
Marketing ...)
+CVE-2026-78468
+       REJECTED
        NOT-FOR-US: WordPress plugin
 CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the 
python_ ...)
        NOT-FOR-US: Amazon
@@ -2187,9 +2638,11 @@ CVE-2026-78477 (The Jawn theme for WordPress is 
vulnerable to Privilege Escalati
        NOT-FOR-US: WordPress plugin
 CVE-2026-78470 (The WP Project Manager Pro plugin for WordPress is vulnerable 
to SQL I ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-78467 (The Fluent Support Pro plugin for WordPress is vulnerable to 
unauthori ...)
+CVE-2026-78467
+       REJECTED
        NOT-FOR-US: WordPress plugin
-CVE-2026-78466 (The Fluent Boards Pro plugin for WordPress is vulnerable to 
Insecure D ...)
+CVE-2026-78466
+       REJECTED
        NOT-FOR-US: WordPress plugin
 CVE-2026-78435 (A vulnerability has been found in Faveo Helpdesk up to 2.0.3. 
Affected ...)
        NOT-FOR-US: Faveo Helpdesk
@@ -9332,7 +9785,7 @@ CVE-2026-70906 (Vulnerability in Oracle Java SE 
(component: 2D).  Supported vers
        - openjdk-8 <not-affected> (Vulnerable code not present)
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-61308 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6460-1 DSA-6457-1}
+       {DSA-6460-1 DSA-6457-1 DLA-4757-1 DLA-4756-1}
        - openjdk-26 26.0.2.1+1-1
        - openjdk-25 25.0.4.1+1-1
        - openjdk-21 21.0.12.1+1-1
@@ -9341,7 +9794,7 @@ CVE-2026-61308 (Vulnerability in the Oracle Java SE, 
Oracle GraalVM for JDK, Ora
        - openjdk-8 8u504-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-70907 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6460-1 DSA-6457-1}
+       {DSA-6460-1 DSA-6457-1 DLA-4757-1 DLA-4756-1}
        - openjdk-26 26.0.2.1+1-1
        - openjdk-25 25.0.4.1+1-1
        - openjdk-21 21.0.12.1+1-1
@@ -9350,7 +9803,7 @@ CVE-2026-70907 (Vulnerability in the Oracle Java SE, 
Oracle GraalVM for JDK, Ora
        - openjdk-8 8u504-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-60589 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6460-1 DSA-6457-1}
+       {DSA-6460-1 DSA-6457-1 DLA-4757-1 DLA-4756-1}
        - openjdk-26 26.0.2.1+1-1
        - openjdk-25 25.0.4.1+1-1
        - openjdk-21 21.0.12.1+1-1
@@ -10646,7 +11099,8 @@ CVE-2026-75013 (A vulnerability was detected in 
TOTOLINK EX1200L 9.3.5u.6146_B20
        NOT-FOR-US: TOTOLINK
 CVE-2026-75012 (A security vulnerability has been detected in TOTOLINK EX1200L 
9.3.5u. ...)
        NOT-FOR-US: TOTOLINK
-CVE-2026-74234 (Legora before 2026-08-14 contains a cross-site scripting 
vulnerability ...)
+CVE-2026-74234
+       REJECTED
        NOT-FOR-US: Legora
 CVE-2026-73560 (vLLM is an inference and serving engine for large language 
models. Pri ...)
        - vllm <itp> (bug #1095237)
@@ -19572,7 +20026,7 @@ CVE-2026-63134 (Malcolm is a network traffic analysis 
tool suite. Prior to versi
        NOT-FOR-US: Malcolm
 CVE-2026-63133 (Malcolm is a network traffic analysis tool suite. Prior to 
version 26. ...)
        NOT-FOR-US: Malcolm
-CVE-2026-5917 (libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 
SSH bac ...)
+CVE-2026-5917 (libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with 
the li ...)
        {DSA-6453-1}
        - libgit2 1.9.7+ds-1 (bug #1144465)
        NOTE: Fixed by: 
https://github.com/libgit2/libgit2/commit/b2105b8e60798cb28086d4c648b1cb4854eadccb
 (v1.9.7)
@@ -63659,7 +64113,7 @@ CVE-2026-53131 (In the Linux kernel, the following 
vulnerability has been resolv
        - linux 7.0.13-1
        [trixie] - linux 6.12.94-1
        NOTE: 
https://git.kernel.org/linus/62443dc21114c0bbc476fa62973db89743f2f137 (7.1-rc1)
-CVE-2026-54548
+CVE-2026-54548 (kas is a setup tool for bitbake based projects. Prior to 5.4, 
internal ...)
        - kas 5.4-1
        [trixie] - kas <no-dsa> (Minor issue)
        [bookworm] - kas <postponed> (Minor issue)
@@ -107288,6 +107742,7 @@ CVE-2026-6862 (A flaw was found in libefiboot, a 
component of efivar. The device
        [bullseye] - efivar <postponed> (Minor issue; can be fixed in next 
update)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2459982
 CVE-2026-6861 (A flaw was found in GNU Emacs. This vulnerability, a memory 
corruption ...)
+       {DSA-6468-1}
        - emacs 1:30.2+1-3 (bug #1134692)
        [bookworm] - emacs <no-dsa> (Minor issue)
        [bullseye] - emacs <postponed> (Minor issue; can be fixed in next 
update)
@@ -172020,7 +172475,7 @@ CVE-2025-13642 (The Paid Membership Plugin, 
Ecommerce, User Registration Form, L
        NOT-FOR-US: WordPress plugin
 CVE-2025-12946 (A vulnerability in the speedtest feature of affected NETGEAR 
Nighthawk ...)
        NOT-FOR-US: Netgear
-CVE-2025-12945 (A vulnerability in NETGEAR Nighthawk R7000P routers lets an 
authentica ...)
+CVE-2025-12945 (An improper input validationvulnerability in the NETGEAR 
Nighthawk R70 ...)
        NOT-FOR-US: Netgear
 CVE-2025-12941 (Denial of Service Vulnerability in 
NETGEARC6220andC6230(DOCSIS\xae 3.0 ...)
        NOT-FOR-US: Netgear
@@ -247798,7 +248253,7 @@ CVE-2020-36845 (The KnowBe4 Security Awareness 
Training application before 2020-
        NOT-FOR-US: KnowBe4 Security Awareness Training application
 CVE-2020-36844 (The KnowBe4 Security Awareness Training application before 
2020-01-10  ...)
        NOT-FOR-US: KnowBe4 Security Awareness Training application
-CVE-2025-43955 (TwsCachedXPathAPI in Convertigo through 8.3.4 does not 
restrict the us ...)
+CVE-2025-43955 (TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not 
restric ...)
        NOT-FOR-US: Convertigo
 CVE-2025-43954 (QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS 
via header ...)
        NOT-FOR-US: QMarkdown (aka quasar-ui-qmarkdown)
@@ -643710,16 +644165,16 @@ CVE-2020-15880
 CVE-2020-15879 (Bitwarden Server 1.35.1 allows SSRF because it does not 
consider certa ...)
        NOT-FOR-US: Bitwarden Server
        NOTE: bitwarden client is ITP'ed as #956836
-CVE-2020-15878
-       RESERVED
+CVE-2020-15878 (An issue was discovered in LibreNMS 1.65. A remote 
authenticated attac ...)
+       TODO: check
 CVE-2020-15877 (An issue was discovered in LibreNMS before 1.65.1. It has 
insufficient ...)
        NOT-FOR-US: LibreNMS
-CVE-2020-15876
-       RESERVED
+CVE-2020-15876 (An issue was discovered in LibreNMS 1.65. A remote 
authenticated attac ...)
+       TODO: check
 CVE-2020-15875
        RESERVED
-CVE-2020-15874
-       RESERVED
+CVE-2020-15874 (An issue was discovered in LibreNMS 1.65. A remote 
authenticated attac ...)
+       TODO: check
 CVE-2020-15873 (In LibreNMS before 1.65.1, an authenticated attacker can 
achieve SQL I ...)
        NOT-FOR-US: LibreNMS
 CVE-2020-15872



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdc6d046d0c85f143712c219d432a22c86ec6690

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdc6d046d0c85f143712c219d432a22c86ec6690
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to