Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2ba7ccf0 by security tracker role at 2026-07-20T07:13:29+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,51 @@
+CVE-2026-9833 (The Tag Groups is the Advanced Way to Display Your Taxonomy
Terms Word ...)
+ TODO: check
+CVE-2026-8825 (The Elementor Website Builder WordPress plugin before 4.1.4
does not ...)
+ TODO: check
+CVE-2026-6656 (Crypt::Password versions through 0.28 for Perl are susceptible
to timi ...)
+ TODO: check
+CVE-2026-45138 (CI4MS is a CodeIgniter 4-based content management system
skeleton. Pri ...)
+ TODO: check
+CVE-2026-44359 (Meshtastic is an open source mesh networking solution. Prior
to versio ...)
+ TODO: check
+CVE-2026-42566 (Meshtastic is an open source mesh networking solution. Prior
to versio ...)
+ TODO: check
+CVE-2026-16235 (Crypt::Password versions through 0.28 for Perl generate
insecure rando ...)
+ TODO: check
+CVE-2026-13432 (The ThumbPress WordPress plugin before 6.2.2 does not perform
a capab ...)
+ TODO: check
+CVE-2026-13156 (The MailerSend WordPress plugin before 1.0.8 does not perform
a nonce ...)
+ TODO: check
+CVE-2026-13147 (The Kirki WordPress plugin before 6.0.12 does not validate a
user-sup ...)
+ TODO: check
+CVE-2026-13142 (The Social Login, Passkeys, Magic Link & Email OTP WordPress
plugin b ...)
+ TODO: check
+CVE-2026-12973 (The PayPlus Payment Gateway WordPress plugin before 8.2.2 does
not per ...)
+ TODO: check
+CVE-2026-12972 (The PayPlus Payment Gateway WordPress plugin before 8.2.2 does
not per ...)
+ TODO: check
+CVE-2026-12970 (The LearnPress WordPress plugin before 4.4.1 does not escape
a search ...)
+ TODO: check
+CVE-2026-12898 (The All-in-One WP Migration and Backup WordPress plugin before
7.106 d ...)
+ TODO: check
+CVE-2026-12724 (The Kirki WordPress plugin before 6.0.12 does not sanitise or
escape ...)
+ TODO: check
+CVE-2026-12723 (The Kirki WordPress plugin before 6.0.12 does not perform any
authori ...)
+ TODO: check
+CVE-2026-12592 (The SlimStat Analytics WordPress plugin before 5.5.0 does not
escape a ...)
+ TODO: check
+CVE-2026-12484 (A vulnerability in keras-team/keras version 3.15.0 allows
unsafe deser ...)
+ TODO: check
+CVE-2026-11868 (The WP Travel WordPress plugin before 11.7.1 does not perform
capabil ...)
+ TODO: check
+CVE-2026-11349 (The Modern Event Calendar Pro WordPress plugin before 7.34.0,
Modern E ...)
+ TODO: check
+CVE-2026-10755 (The All in One SEO WordPress plugin before 4.9.9 does not
correctly r ...)
+ TODO: check
+CVE-2026-10724 (The Reviews Feed WordPress plugin before 2.6.5 does not
neutralize Wo ...)
+ TODO: check
+CVE-2026-10081 (The Unlimited Elements For Elementor WordPress plugin before
2.0.11 do ...)
+ TODO: check
CVE-2026-57857 (The Flow Payment plugin for WordPress (flow.cl) version 3.0.8
is vulne ...)
NOT-FOR-US: WordPress plugin
CVE-2026-57848 (Stoat for Android exports the
chat.stoat.activities.ShareTargetActivit ...)
@@ -7282,7 +7330,7 @@ CVE-2026-15531 (A vulnerability has been found in
yashbhalgat HashNeRF-pytorch u
NOT-FOR-US: yashbhalgat HashNeRF-pytorch
CVE-2026-15530 (A flaw has been found in WuzhiCMS up to 4.1.0. Affected by
this vulner ...)
NOT-FOR-US: WuzhiCMS
-CVE-2026-15529 (A vulnerability was detected in yzhao062 pyod
3.5.0/3.5.1/3.5.2. Affec ...)
+CVE-2026-15529 (A vulnerability was detected in yzhao062 pyod up to 3.6.1.
Affected is ...)
NOT-FOR-US: yzhao062 pyod
CVE-2026-15528 (A vulnerability was found in lamaalrajih kicad-mcp up to
3.3.1. This i ...)
NOT-FOR-US: lamaalrajih kicad-mcp
@@ -16041,13 +16089,13 @@ CVE-2026-58036 (Exposure of Sensitive Information to
an Unauthorized Actor vulne
NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1306035 (master)
CVE-2026-13766 (DBIx::QuickORM versions before 0.000026 for Perl allow SQL
injection v ...)
NOT-FOR-US: DBIx::QuickORM Perl module
-CVE-2026-57082 (Net::BitTorrent versions through 2.0.1 for Perl generate the
MSE Diffi ...)
+CVE-2026-57082 (Net::BitTorrent versions before 2.1.0 for Perl generate the
MSE Diffie ...)
NOT-FOR-US: Net::BitTorrent Perl module
-CVE-2026-57081 (Net::BitTorrent versions through 2.0.1 for Perl allow remote
memory ex ...)
+CVE-2026-57081 (Net::BitTorrent versions through 2.1.0 for Perl allow remote
memory ex ...)
NOT-FOR-US: Net::BitTorrent Perl module
-CVE-2026-57080 (Net::BitTorrent versions through 2.0.1 for Perl allow remote
memory ex ...)
+CVE-2026-57080 (Net::BitTorrent versions through 2.1.0 for Perl allow remote
memory ex ...)
NOT-FOR-US: Net::BitTorrent Perl module
-CVE-2026-57079 (Net::BitTorrent versions through 2.0.1 for Perl write files
outside th ...)
+CVE-2026-57079 (Net::BitTorrent versions before 2.1.0 for Perl write files
outside the ...)
NOT-FOR-US: Net::BitTorrent Perl module
CVE-2026-57964
- spice-vdagent <not-affected> (MacOS/BSD specific)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ba7ccf01ababe5cdd26f1b84580876722f241b8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ba7ccf01ababe5cdd26f1b84580876722f241b8
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits