Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d918ae95 by security tracker role at 2026-07-21T07:12:37+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,16 +1,200 @@
-CVE-2026-58624
+CVE-2026-8082 (The bpost-shipping-platform WordPress plugin before 3.2.3 does 
not pro ...)
+       TODO: check
+CVE-2026-6952 (A post-authentication command injection vulnerability in the 
"LogServe ...)
+       TODO: check
+CVE-2026-64651 (The `@ai-sdk/harness-opencode` tool connects HarnessAgent to 
OpenCode  ...)
+       TODO: check
+CVE-2026-64650 (The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter 
backed by  ...)
+       TODO: check
+CVE-2026-64626 (AVideo versions from commit 0dbadbca through latest master 
contain a s ...)
+       TODO: check
+CVE-2026-64625 (AVideo before 29.0 contains an incomplete fix for 
CVE-2026-45578 where ...)
+       TODO: check
+CVE-2026-64624 (FreeRDP before 3.28.0 treats lines beginning with forward 
slash in RDP ...)
+       TODO: check
+CVE-2026-64619 (FileCodeBox before 2.4 contains a rate-limit bypass 
vulnerability in t ...)
+       TODO: check
+CVE-2026-63771 (Adminer before 5.4.3 contains a cookie injection vulnerability 
that al ...)
+       TODO: check
+CVE-2026-63770 (Glance through 0.8.5 contains an IP address spoofing 
vulnerability in  ...)
+       TODO: check
+CVE-2026-63769 (Huginn through 2022.08.18 contains a server-side request 
forgery vulne ...)
+       TODO: check
+CVE-2026-63768 (cal.diy through 6.2.0 contains an open redirect vulnerability 
in the c ...)
+       TODO: check
+CVE-2026-63767 (ktransformers through 0.6.3, fixed in commit def0f93, contains 
an unau ...)
+       TODO: check
+CVE-2026-63766 (GPT-SoVITS through 20250606v2pro contains an OS command 
injection vuln ...)
+       TODO: check
+CVE-2026-63731 (HyperDX before 2.31.0 contains a server-side request forgery 
vulnerabi ...)
+       TODO: check
+CVE-2026-63730 (HyperDX before 2.31.0 contains a server-side request forgery 
vulnerabi ...)
+       TODO: check
+CVE-2026-63729 (The SyncTeX parser (synctex_parser.c) shipped with TeX Live 
and embedd ...)
+       TODO: check
+CVE-2026-63728 (Gitleaks prior to 8.30.1 contains a template injection 
vulnerability t ...)
+       TODO: check
+CVE-2026-62414 (The Joomla extension Page Builder CK does not properly apply 
access co ...)
+       TODO: check
+CVE-2026-61901 (The Joomla extension Hikashop is vulnerable to an open 
redirect.)
+       TODO: check
+CVE-2026-61900 (The Joomla extension JDownloads is vulnerable to an 
unauthenticated fi ...)
+       TODO: check
+CVE-2026-61425 (The Joomla extension Gridbox is vulnerable an authenticated 
bypass, po ...)
+       TODO: check
+CVE-2026-61424 (The Joomla extension DJ-Classifieds is vulnerable to an 
unauthenticate ...)
+       TODO: check
+CVE-2026-59776 (Missing Cryptographic Step (CWE-325) vulnerability exists in 
certain F ...)
+       TODO: check
+CVE-2026-57852 (Grav CMS scheduler-webhook plugin contains an authentication 
bypass vu ...)
+       TODO: check
+CVE-2026-57495 (AgenticMail gives AI agents real email addresses and phone 
numbers. In ...)
+       TODO: check
+CVE-2026-57494 (AgenticMail gives AI agents real email addresses and phone 
numbers. In ...)
+       TODO: check
+CVE-2026-55833 (Netty is a network application framework for development of 
protocol s ...)
+       TODO: check
+CVE-2026-55831 (Netty is a network application framework for development of 
protocol s ...)
+       TODO: check
+CVE-2026-55550 (NextCRM is open-source customer relationship management (CRM) 
software ...)
+       TODO: check
+CVE-2026-55544 (NextCRM is open-source customer relationship management (CRM) 
software ...)
+       TODO: check
+CVE-2026-55219 (Paymenter is a free and open-source webshop solution for 
management of ...)
+       TODO: check
+CVE-2026-53596 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
+       TODO: check
+CVE-2026-53595 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
+       TODO: check
+CVE-2026-53594 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
+       TODO: check
+CVE-2026-53593 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
+       TODO: check
+CVE-2026-53592 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
+       TODO: check
+CVE-2026-53591 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
+       TODO: check
+CVE-2026-52656 (An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and 
before  ...)
+       TODO: check
+CVE-2026-51385 (An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through 
v0.4.29 al ...)
+       TODO: check
+CVE-2026-51031 (FlareSolverr before version 3.4.7 contains a server-side 
request forge ...)
+       TODO: check
+CVE-2026-51025 (Cross Site Scripting vulnerability in fuint Member Marketing 
System <= ...)
+       TODO: check
+CVE-2026-47255 (AgenticMail gives AI agents real email addresses and phone 
numbers. @a ...)
+       TODO: check
+CVE-2026-47198 (Paymenter is a free and open-source webshop solution for 
management of ...)
+       TODO: check
+CVE-2026-47144 (Shamefile is a linter for undocumented linter warnings. Prior 
to versi ...)
+       TODO: check
+CVE-2026-47134 (ClearanceKit intercepts file-system access events on macOS and 
enforce ...)
+       TODO: check
+CVE-2026-47133 (ClearanceKit intercepts file-system access events on macOS and 
enforce ...)
+       TODO: check
+CVE-2026-47130 (NextCRM is open-source customer relationship management (CRM) 
software ...)
+       TODO: check
+CVE-2026-47129 (NextCRM is open-source customer relationship management (CRM) 
software ...)
+       TODO: check
+CVE-2026-47128 (nono is software that allows users to run AI agents in a 
zero-latency  ...)
+       TODO: check
+CVE-2026-44585 (Paymenter is a free and open-source webshop solution for 
management of ...)
+       TODO: check
+CVE-2026-44584 (Paymenter is a free and open-source webshop solution for 
management of ...)
+       TODO: check
+CVE-2026-44583 (Paymenter is a free and open-source webshop solution for 
management of ...)
+       TODO: check
+CVE-2026-44510 (Rsync is a file-copying tool that uses a delta-transfer 
algorithm to s ...)
+       TODO: check
+CVE-2026-44509 (Rsync is a file-copying tool that uses a delta-transfer 
algorithm to s ...)
+       TODO: check
+CVE-2026-44508 (Rsync is a file-copying tool that uses a delta-transfer 
algorithm to s ...)
+       TODO: check
+CVE-2026-44507 (Rsync is a file-copying tool that uses a delta-transfer 
algorithm to s ...)
+       TODO: check
+CVE-2026-3182 (Zohocorp ManageEngine Endpoint Central versions 
before11.4.2528.34 are ...)
+       TODO: check
+CVE-2026-16337 (Improper authorization in the ToolGroupResource and RoleAjax 
REST/DWR  ...)
+       TODO: check
+CVE-2026-16336 (A vulnerability was found in trinodb trino 481. Affected is an 
unknown ...)
+       TODO: check
+CVE-2026-16334 (A vulnerability was identified in itsourcecode Hospital 
Management Sys ...)
+       TODO: check
+CVE-2026-16332 (A vulnerability was detected in D-Link DNS-320 1.0.2. This 
impacts an  ...)
+       TODO: check
+CVE-2026-16331 (A security vulnerability has been detected in D-Link DNS-320 
1.0.2. Th ...)
+       TODO: check
+CVE-2026-16330 (A weakness has been identified in D-Link DNS-320 1.0.2. The 
impacted e ...)
+       TODO: check
+CVE-2026-16329 (A vulnerability was identified in D-Link DNS-320 1.0.2. 
Impacted is an ...)
+       TODO: check
+CVE-2026-16327 (A vulnerability was determined in D-Link DNS-320 1.0.2. This 
issue aff ...)
+       TODO: check
+CVE-2026-16324 (A vulnerability was identified in Metasoft 
\u7f8e\u7279\u8f6f\u4ef6 Me ...)
+       TODO: check
+CVE-2026-16266 (Versions of the package mongo-object before 3.0.3 are 
vulnerable to Pr ...)
+       TODO: check
+CVE-2026-15927 (A flaw was found in Red Hat Quay's repository-level mirror 
configurati ...)
+       TODO: check
+CVE-2026-15812 (A vulnerability was found in the internal Access Control List 
(ACL) su ...)
+       TODO: check
+CVE-2026-15811 (A vulnerability was found in kronosnet's (version <=1.34) 
cryptographi ...)
+       TODO: check
+CVE-2026-15788 (BuildKit's cache mount source= selector on Windows Container 
on Window ...)
+       TODO: check
+CVE-2026-15782 (The WPForms \u2013 AI Form Builder for WordPress \u2013 
Contact Forms, ...)
+       TODO: check
+CVE-2026-15156 (The Essential Addons for Elementor \u2013 Popular Elementor 
Templates  ...)
+       TODO: check
+CVE-2026-14185 (The WPBot  WordPress plugin before 8.2.0 does not perform a 
capability ...)
+       TODO: check
+CVE-2026-14184 (The Academy LMS WordPress plugin before 3.8.1 does not verify 
ownershi ...)
+       TODO: check
+CVE-2026-14183 (The Classified Listing  WordPress plugin before 5.3.9 does not 
verify  ...)
+       TODO: check
+CVE-2026-13694 (The Bit Form  WordPress plugin before 3.1.0 does not properly 
validate ...)
+       TODO: check
+CVE-2026-13693 (The Bit Form  WordPress plugin before 3.1.0 does not restrict 
a form f ...)
+       TODO: check
+CVE-2026-13439 (The Easy Form Builder by WhiteStudio plugin for WordPress is 
vulnerabl ...)
+       TODO: check
+CVE-2026-13381 (VSee Clinic 7.1.26 and API1.3.0contain an Insecure Direct 
Object Refer ...)
+       TODO: check
+CVE-2026-13380 (VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext 
SFTP cr ...)
+       TODO: check
+CVE-2026-12900 (The Spectra Gutenberg Blocks \u2013 Website Builder for the 
Block Edit ...)
+       TODO: check
+CVE-2026-11767 (The Free  Builder for Elementor  WordPress plugin before 1.6.7 
does no ...)
+       TODO: check
+CVE-2024-51316 (The Tenda TX9 V22.03.02.20 firmware has a denial of service 
vulnerabil ...)
+       TODO: check
+CVE-2024-51315 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow 
vulnerability ...)
+       TODO: check
+CVE-2024-51314 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow 
vulnerability ...)
+       TODO: check
+CVE-2024-51313 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow 
vulnerability ...)
+       TODO: check
+CVE-2024-51312 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow 
vulnerability ...)
+       TODO: check
+CVE-2024-51311 (The Tenda TX9 V22.03.02.05 firmware has a stack overflow 
vulnerability ...)
+       TODO: check
+CVE-2023-37508 (HCL DevOps Plan is potentially susceptible to Cross-Site 
Scripting (XS ...)
+       TODO: check
+CVE-2023-37507 (HCL DevOps Plan is susceptible to an information disclosure 
that can a ...)
+       TODO: check
+CVE-2026-58624 (Improper input validation in sshd-git in Apache MINA SSHD. 
Apache MINA ...)
        - mina2 <unfixed>
        - mina <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/18
-CVE-2026-56624
+CVE-2026-56624 (Improper certificate validation in Apache MINA SSHD 
(server-side).Apac ...)
        - mina2 <unfixed>
        - mina <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/17
-CVE-2026-56623
+CVE-2026-56623 (Path traversal on Windows in Apache MINA SSHD component 
sshd-git.Apach ...)
        - mina2 <not-affected> (Only affects MINA SSHD on Windows)
        - mina <not-affected> (Only affects MINA SSHD on Windows)
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/16
-CVE-2026-56452
+CVE-2026-56452 (Path traversal in the sshd-scp component of Apache MINA 
SSHD.Apache MI ...)
        - mina2 <unfixed>
        - mina <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/15
@@ -3617,25 +3801,25 @@ CVE-2026-14266
        NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only an empty 
source package
        NOTE: depending on 7zip. Mark this version as fixed version.
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-444/
-CVE-2026-15899
+CVE-2026-15899 (Use after free in CameraCapture in Google Chrome on Mac prior 
to 150.0 ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-15900
+CVE-2026-15900 (Use after free in GPU in Google Chrome on Android prior to 
150.0.7871. ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-15901
+CVE-2026-15901 (Use after free in Network in Google Chrome prior to 
150.0.7871.128 all ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-15902
+CVE-2026-15902 (Use after free in Cast in Google Chrome prior to 
150.0.7871.128 allowe ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-15903
+CVE-2026-15903 (Out of bounds read and write in V8 in Google Chrome prior to 
150.0.787 ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-15904
+CVE-2026-15904 (Use after free in Ozone in Google Chrome on Linux prior to 
150.0.7871. ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-15905
+CVE-2026-15905 (Use after free in Aura in Google Chrome prior to 
150.0.7871.128 allowe ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-59173 (Uncontrolled Resource Consumption vulnerability in Apache 
Traffic Serv ...)
@@ -45859,13 +46043,13 @@ CVE-2026-41073 (RT is an open source, 
enterprise-grade issue and ticket tracking
        - request-tracker4 <removed>
        NOTE: https://github.com/bestpractical/rt/releases/tag/rt-5.0.10
        NOTE: Fixed by: 
https://github.com/bestpractical/rt/commit/dce7ff6799d930d09c10a50539325f1290440d4b
 (rt-5.0.10)
-CVE-2026-44229
+CVE-2026-44229 (RT is an open source, enterprise-grade issue and ticket 
tracking syste ...)
        {DSA-6327-1 DSA-6324-1}
        - request-tracker5 5.0.10+dfsg-1
        - request-tracker4 <removed>
        NOTE: https://github.com/bestpractical/rt/releases/tag/rt-5.0.10
        NOTE: Fixed by: 
https://github.com/bestpractical/rt/commit/ecdb229b38206888401655974d0aec153640eb59
 (rt-5.0.10)
-CVE-2026-44230
+CVE-2026-44230 (RT is an open source, enterprise-grade issue and ticket 
tracking syste ...)
        - request-tracker5 5.0.10+dfsg-1
        [trixie] - request-tracker5 5.0.7+dfsg-4+deb13u3
        [bookworm] - request-tracker5 <not-affected> (Vulnerable code 
introduced later)
@@ -45894,7 +46078,7 @@ CVE-2026-41075 (RT is an open source, enterprise-grade 
issue and ticket tracking
        - request-tracker4 <removed>
        NOTE: https://github.com/bestpractical/rt/releases/tag/rt-5.0.10
        NOTE: Fixed by: 
https://github.com/bestpractical/rt/commit/9ed06dadc29a75e17b25017f929edeff62d224bc
 (rt-5.0.10)
-CVE-2026-44231
+CVE-2026-44231 (RT is an open source, enterprise-grade issue and ticket 
tracking syste ...)
        {DSA-6327-1 DSA-6324-1}
        - request-tracker5 5.0.10+dfsg-1
        - request-tracker4 <removed>
@@ -53800,7 +53984,7 @@ CVE-2026-7263 (In PHP versions 8.4.* before 8.4.21 and 
8.5.* before 8.5.6, DOMNo
        - php7.4 <not-affected> (Only affects 8.4 and later)
        NOTE: 
https://github.com/php/php-src/security/advisories/GHSA-4jhr-8w89-j733
        NOTE: 
https://github.com/php/php-src/commit/d43c523c48960e9ca0bf9c747e9bad8e5121edff
-CVE-2026-8149 (A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS on 
Linux, X ...)
+CVE-2026-8149 (A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS 
bcprov-lts8 ...)
        NOT-FOR-US: FIPS provider for Bouncycastle, not part of the Debian 
package for Bouncycastle
 CVE-2026-8148 (NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a 
local atta ...)
        NOT-FOR-US: NAVER MYBOX Explorer for Windows
@@ -76469,6 +76653,7 @@ CVE-2026-5292 (Out of bounds read in WebCodecs in 
Google Chrome prior to 146.0.7
        - chromium 146.0.7680.177-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-34743 (XZ Utils provide a general-purpose data-compression library 
plus comma ...)
+       {DLA-4690-1}
        - xz-utils 5.8.3-1 (bug #1132497)
        [trixie] - xz-utils 5.8.1-1+deb13u1
        [bookworm] - xz-utils 5.4.1-1+deb12u1
@@ -172191,6 +172376,7 @@ CVE-2023-32251 (A vulnerability has been identified 
in the Linux kernel's ksmbd
        NOTE: 
https://git.kernel.org/linus/b096d97f47326b1e2dbdef1c91fab69ffda54d17 (6.4-rc1)
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-699/
 CVE-2025-53399 (In Sipwise rtpengine before 13.4.1.1, an origin-validation 
error in th ...)
+       {DLA-4691-1}
        - rtpengine 12.5.1.35-1 (bug #1110316)
        NOTE: https://www.openwall.com/lists/oss-security/2025/07/31/1
        NOTE: 
https://github.com/EnableSecurity/advisories/tree/master/ES2025-01-rtpengine-improper-behavior-bleed-inject



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d918ae95d4f14171710a893bf000e2a4b86a48e4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d918ae95d4f14171710a893bf000e2a4b86a48e4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to