Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
62872576 by security tracker role at 2026-09-06T07:13:06+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,79 @@
+CVE-2026-86218 (N-central is vulnerable to a pre-auth remote code execution
This issue ...)
+ TODO: check
+CVE-2026-86207 (An authentication bypass in N-central < 2026.3 HF 3 leads to
authentic ...)
+ TODO: check
+CVE-2026-86206 (A vulnerability in the N-central internal API access control
filter al ...)
+ TODO: check
+CVE-2026-86171 (A security vulnerability has been detected in DefaultFuction
CRM 1.0.0 ...)
+ TODO: check
+CVE-2026-86170 (A weakness has been identified in DefaultFuction CRM 1.0.0.
The impact ...)
+ TODO: check
+CVE-2026-86168 (A security flaw has been discovered in code-projects Content
Managemen ...)
+ TODO: check
+CVE-2026-86167 (A vulnerability was identified in Tenda HG10 300001138.
Impacted is th ...)
+ TODO: check
+CVE-2026-86166 (A vulnerability was determined in Tenda HG10 300001138. This
issue aff ...)
+ TODO: check
+CVE-2026-86165 (A vulnerability was found in Tenda HG10 300001138. This
vulnerability ...)
+ TODO: check
+CVE-2026-86164 (A security flaw has been discovered in itsourcecode Sales and
Inventor ...)
+ TODO: check
+CVE-2026-86163 (A vulnerability was identified in itsourcecode Sales and
Inventory Sys ...)
+ TODO: check
+CVE-2026-86162 (A vulnerability was determined in SourceCodester Online Voting
System ...)
+ TODO: check
+CVE-2026-86161 (A vulnerability was found in SourceCodester Online Voting
System 1.0. ...)
+ TODO: check
+CVE-2026-86160 (A vulnerability has been found in SourceCodester Online Voting
System ...)
+ TODO: check
+CVE-2026-86159 (A flaw has been found in SourceCodester Online Voting System
1.0. Impa ...)
+ TODO: check
+CVE-2026-86153 (A vulnerability has been found in Tenda CP3 27.5.57.101. This
affects ...)
+ TODO: check
+CVE-2026-86152 (A flaw has been found in Tenda CP3 27.5.57.101. The impacted
element i ...)
+ TODO: check
+CVE-2026-86151 (A vulnerability was detected in Tenda CP3 27.5.57.101. The
affected el ...)
+ TODO: check
+CVE-2026-86150 (A security vulnerability has been detected in Tenda CP3
27.5.57.101. I ...)
+ TODO: check
+CVE-2026-86149 (A weakness has been identified in Tenda CP3 27.5.57.101. This
issue af ...)
+ TODO: check
+CVE-2026-86148 (A security flaw has been discovered in Tenda CP3 27.5.57.101.
This vul ...)
+ TODO: check
+CVE-2026-86060 (RouterOS contains an argument-handling flaw in the SSH login
path invo ...)
+ TODO: check
+CVE-2026-85038 (The B2BKing \u2014 Ultimate WooCommerce B2B and Wholesale
Plugin \u201 ...)
+ TODO: check
+CVE-2026-84219 (The Kirki WordPress plugin before 6.3.0 does not hold back
every spel ...)
+ TODO: check
+CVE-2026-84028 (The Bold Page Builder WordPress plugin before 5.9.9 does not
sanitise ...)
+ TODO: check
+CVE-2026-76161
+ REJECTED
+CVE-2026-76160
+ REJECTED
+CVE-2026-75816 (The Frontend Admin by DynamiApps plugin for WordPress is
vulnerable to ...)
+ TODO: check
+CVE-2026-75793 (The SureCart WordPress plugin before 4.7.0 does not consult
the site' ...)
+ TODO: check
+CVE-2026-67281 (RouterOS WebFig contains an unauthenticated file-read
vulnerability in ...)
+ TODO: check
+CVE-2026-67279 (RouterOS SSH enters the connection protocol after a
client-requested r ...)
+ TODO: check
+CVE-2026-67278 (MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures
during ...)
+ TODO: check
+CVE-2026-67277 (RouterOS accepts a "related" btest connection before the
corresponding ...)
+ TODO: check
+CVE-2026-67276 (RouterOS does not compare the complete RSA public key when
matching an ...)
+ TODO: check
+CVE-2026-18480 (The SureCart WordPress plugin before 4.6.3 does not ensure
that the a ...)
+ TODO: check
+CVE-2026-18056 (The HivePress Authentication plugin for WordPress is
vulnerable to Aut ...)
+ TODO: check
+CVE-2026-16310 (The MemberDash plugin for WordPress is vulnerable to Insecure
Direct O ...)
+ TODO: check
+CVE-2026-13159 (The Real Estate Papi WordPress theme through 1.0.5 does not
perform ca ...)
+ TODO: check
CVE-2026-85498 [Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack
buffer underflow]
- policykit-1 <unfixed>
[trixie] - policykit-1 <not-affected> (Fix for CVE-2026-4897 not
applied)
@@ -1826,29 +1902,41 @@ CVE-2026-85062 (Colord is a tiny yet powerful tool for
high-performance color ma
CVE-2026-85061 (MapLibre GL JS is an interactive vector tile map library for
web brows ...)
NOT-FOR-US: MapLibre GL JS
CVE-2026-85053 (Improper resource exposure in CacheStorage in Google Chrome
prior to 1 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85052 (Out of bounds read in CrashReporting in Google Chrome prior to
152.0.7 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85051 (Type confusion in Compositing in Google Chrome prior to
152.0.7977.82 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85050 (Out of bounds write in WebGL in Google Chrome on on Android
prior to 1 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85049 (Use after free in Skia in Google Chrome prior to 152.0.7977.82
allowed ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
- libskia 146.20260602~git.3476902+dfsg-4
CVE-2026-85048 (Use after free in Compositing in Google Chrome prior to
152.0.7977.82 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85047 (Improper input validation in Transactions Platform in Google
Chrome on ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85046 (Type confusion in V8 in Google Chrome prior to 152.0.7977.82
allowed a ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85045 (Race condition in V8 in Google Chrome prior to 152.0.7977.82
allowed a ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85044 (Use of released resource in Mobile in Google Chrome on on
Android prio ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85043 (Incomplete cleanup in Network in Google Chrome prior to
152.0.7977.82 ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-85042 (Use after free in DevTools in Google Chrome prior to
152.0.7977.82 all ...)
+ {DSA-6484-1}
- chromium 152.0.7977.82-1
CVE-2026-84185 (A flaw was found in the jwcrypto library, which is used for
implementi ...)
- python-jwcrypto <unfixed>
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62872576d2a907e9e4205c785edcbf79cbfbdefb
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62872576d2a907e9e4205c785edcbf79cbfbdefb
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits