Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
40170225 by security tracker role at 2026-07-24T19:13:48+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,290 @@
-CVE-2026-16634
+CVE-2026-9765 (Note: The CVE and blog post don't exist because we determined 
this is  ...)
+       TODO: check
+CVE-2026-8789 (The Easy Appointments plugin for WordPress is vulnerable to 
unauthoriz ...)
+       TODO: check
+CVE-2026-8308 (Improper neutralization of input during web page generation 
('cross-si ...)
+       TODO: check
+CVE-2026-7484 (External control of Assumed-Immutable web parameter 
vulnerability in A ...)
+       TODO: check
+CVE-2026-7483 (Local privilege escalationpotentially allowed an attacker to 
write an  ...)
+       TODO: check
+CVE-2026-7007 (The Zephyr ext2 file system validates the on-disk superblock in 
ext2_v ...)
+       TODO: check
+CVE-2026-66144 (Although remote policy references are not retrieved during 
policy norm ...)
+       TODO: check
+CVE-2026-66143 (It is possible to bypass themaximum number of normalized 
policy altern ...)
+       TODO: check
+CVE-2026-66142 (Apache Neethi is vulnerable to uncontrolled recursion when 
parsing pol ...)
+       TODO: check
+CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit 42e33d8, contains a 
pre-authen ...)
+       TODO: check
+CVE-2026-66034 (libssh2 through 1.11.1, fixed in commit a13bb6c, contains a 
missing bo ...)
+       TODO: check
+CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit a2ed82d, contains a 
pre-authen ...)
+       TODO: check
+CVE-2026-66032 (libssh2 through 1.11.1, fixed in commit 5e47761, contains a 
double-fre ...)
+       TODO: check
+CVE-2026-66027 (Suna before 0.9.102 contains a broken access control 
vulnerability in  ...)
+       TODO: check
+CVE-2026-66010 (DOMPurify before 3.4.12 fails to execute afterSanitizeElements 
hook fo ...)
+       TODO: check
+CVE-2026-66009 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 
8.2.2 befo ...)
+       TODO: check
+CVE-2026-66008 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 
8.2.2 befo ...)
+       TODO: check
+CVE-2026-66007 (Datasets through 5.0.0, fixed in commit f989ef9, contains a 
path trave ...)
+       TODO: check
+CVE-2026-66006 (lakeFS through 1.83.0, fixed in commit 71a45ee, contains an 
authentica ...)
+       TODO: check
+CVE-2026-66005 (Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS 
misconfigu ...)
+       TODO: check
+CVE-2026-66004 (BlenderMCP before commit 30a3308 contains a path traversal 
vulnerabili ...)
+       TODO: check
+CVE-2026-65711 (sysPass through version 3.2.11 contains an OS command 
injection vulner ...)
+       TODO: check
+CVE-2026-65710 (sysPass through version 3.2.11 contains a missing 
authorization vulner ...)
+       TODO: check
+CVE-2026-65709 (sysPass through version 3.2.11 contains a missing object-level 
authori ...)
+       TODO: check
+CVE-2026-65708 (sysPass through version 3.2.11 contains an insecure direct 
object refe ...)
+       TODO: check
+CVE-2026-65707 (Likeshop through 3.0.5 contains an authenticated SQL injection 
vulnera ...)
+       TODO: check
+CVE-2026-65693 (Microweber CMS through 2.0.20 contains a server-side template 
injectio ...)
+       TODO: check
+CVE-2026-65623 (Inefficient Algorithmic Complexity vulnerability in mtrudel 
bandit all ...)
+       TODO: check
+CVE-2026-64255 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
+       TODO: check
+CVE-2026-64254 (In the Linux kernel, the following vulnerability has been 
resolved:  N ...)
+       TODO: check
+CVE-2026-64253 (In the Linux kernel, the following vulnerability has been 
resolved:  k ...)
+       TODO: check
+CVE-2026-64252 (In the Linux kernel, the following vulnerability has been 
resolved:  M ...)
+       TODO: check
+CVE-2026-64251 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
+       TODO: check
+CVE-2026-64250 (In the Linux kernel, the following vulnerability has been 
resolved:  L ...)
+       TODO: check
+CVE-2026-64249 (In the Linux kernel, the following vulnerability has been 
resolved:  f ...)
+       TODO: check
+CVE-2026-64248 (In the Linux kernel, the following vulnerability has been 
resolved:  M ...)
+       TODO: check
+CVE-2026-64247 (In the Linux kernel, the following vulnerability has been 
resolved:  K ...)
+       TODO: check
+CVE-2026-64246 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
+       TODO: check
+CVE-2026-64245 (In the Linux kernel, the following vulnerability has been 
resolved:  f ...)
+       TODO: check
+CVE-2026-64244 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-64243 (In the Linux kernel, the following vulnerability has been 
resolved:  A ...)
+       TODO: check
+CVE-2026-64242 (In the Linux kernel, the following vulnerability has been 
resolved:  u ...)
+       TODO: check
+CVE-2026-64241 (In the Linux kernel, the following vulnerability has been 
resolved:  g ...)
+       TODO: check
+CVE-2026-64240 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
+       TODO: check
+CVE-2026-64239 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
+       TODO: check
+CVE-2026-64238 (In the Linux kernel, the following vulnerability has been 
resolved:  g ...)
+       TODO: check
+CVE-2026-64237 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
+       TODO: check
+CVE-2026-64236 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
+       TODO: check
+CVE-2026-64235 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-64234 (In the Linux kernel, the following vulnerability has been 
resolved:  t ...)
+       TODO: check
+CVE-2026-64233 (In the Linux kernel, the following vulnerability has been 
resolved:  u ...)
+       TODO: check
+CVE-2026-64232 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
+       TODO: check
+CVE-2026-64231 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-64230 (In the Linux kernel, the following vulnerability has been 
resolved:  r ...)
+       TODO: check
+CVE-2026-64229 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
+       TODO: check
+CVE-2026-64228 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-64227 (In the Linux kernel, the following vulnerability has been 
resolved:  A ...)
+       TODO: check
+CVE-2026-64226 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-64225 (In the Linux kernel, the following vulnerability has been 
resolved:  o ...)
+       TODO: check
+CVE-2026-64224 (In the Linux kernel, the following vulnerability has been 
resolved:  o ...)
+       TODO: check
+CVE-2026-64223 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
+       TODO: check
+CVE-2026-64222 (In the Linux kernel, the following vulnerability has been 
resolved:  o ...)
+       TODO: check
+CVE-2026-64221 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-64220 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-64219 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-64218 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
+       TODO: check
+CVE-2026-64217 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-64216 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-64215 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
+       TODO: check
+CVE-2026-64214 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
+       TODO: check
+CVE-2026-64213 (In the Linux kernel, the following vulnerability has been 
resolved:  h ...)
+       TODO: check
+CVE-2026-64212 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
+       TODO: check
+CVE-2026-64211 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
+       TODO: check
+CVE-2026-64210 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
+       TODO: check
+CVE-2026-64209 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
+       TODO: check
+CVE-2026-64208 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
+       TODO: check
+CVE-2026-63317 (Arbitrary Class Instantiation via XML Feature Generator 
Descriptor and ...)
+       TODO: check
+CVE-2026-58630 (Improper access control in Azure App Service allows an 
unauthorized at ...)
+       TODO: check
+CVE-2026-58586 (Image::WebP versions through 0.2 for Perl bundle a vulnerable 
version  ...)
+       TODO: check
+CVE-2026-57106 (Server-side request forgery (ssrf) in Data Quality allows an 
unauthori ...)
+       TODO: check
+CVE-2026-56392 (GNU coreutils unexpand is vulnerable to a heap-based buffer 
overflow d ...)
+       TODO: check
+CVE-2026-56391 (GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds 
read du ...)
+       TODO: check
+CVE-2026-56163 (Missing authentication for critical function in Microsoft 
Azure Kubern ...)
+       TODO: check
+CVE-2026-55732 (Out-of-bounds Read (CWE-125)in BACnet packet parsing 
(`bacdt_datetime_ ...)
+       TODO: check
+CVE-2026-55731 (Unchecked input for loop condition (CWE-606)in the SNMP agent 
in Loyte ...)
+       TODO: check
+CVE-2026-55730 (Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec 
LWEB-802  ...)
+       TODO: check
+CVE-2026-55729 (Exposure of Sensitive Information (CWE-200)in LWEB802 browser 
`localSt ...)
+       TODO: check
+CVE-2026-55728 (Stack-based Buffer Overflow (CWE-121)in `/usr/bin/ltsudo` 
`cmd_ipaddr_ ...)
+       TODO: check
+CVE-2026-54342 (In epa4all, prior to version 2026-05-20, an attacker on the 
network pa ...)
+       TODO: check
+CVE-2026-49745 (Kernel software installed and running inside a Guest VM may 
post impro ...)
+       TODO: check
+CVE-2026-49744 (Kernel software installed and running inside a Guest VM may 
post impro ...)
+       TODO: check
+CVE-2026-49743 (Software installed and run as a non-privileged user may 
conduct improp ...)
+       TODO: check
+CVE-2026-49326 (Missing Authorization vulnerability in Apache HBase thrift and 
rest de ...)
+       TODO: check
+CVE-2026-48037 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
+       TODO: check
+CVE-2026-48036 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
+       TODO: check
+CVE-2026-48035 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
+       TODO: check
+CVE-2026-48034 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
+       TODO: check
+CVE-2026-48033 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
+       TODO: check
+CVE-2026-48032 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
+       TODO: check
+CVE-2026-48021 (In epa4all, prior to version 2026-05-20, an attacker who can 
intercept ...)
+       TODO: check
+CVE-2026-46452 (Improper Input Validation vulnerability in Apache NimBLE in 
Mesh Proxy ...)
+       TODO: check
+CVE-2026-45816 (NULL Pointer Dereference vulnerability in Apache NimBLE inLE 
Long Term ...)
+       TODO: check
+CVE-2026-45815 (Reachable Assertion vulnerability in Apache NimBLE. A 
specially crafte ...)
+       TODO: check
+CVE-2026-45813 (Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) 
vulnerabil ...)
+       TODO: check
+CVE-2026-45812 (Incorrect Calculation of Buffer Size vulnerability in Apache 
NimBLE wh ...)
+       TODO: check
+CVE-2026-45811 (Buffer Copy without Checking Size of Input ('Classic Buffer 
Overflow') ...)
+       TODO: check
+CVE-2026-24727 (An unrestricted upload of file with dangerous type 
vulnerability in th ...)
+       TODO: check
+CVE-2026-17107 (A flaw was found in the cluster-proxy service-proxy component 
used in  ...)
+       TODO: check
+CVE-2026-17059 (A flaw was found in the role-users endpoint of the 
keycloak-services l ...)
+       TODO: check
+CVE-2026-17048 (A flaw was found in the Keycloak Admin REST API, which is used 
to mana ...)
+       TODO: check
+CVE-2026-17039 (A flaw was found in pki-core. The certificate authority (CA) 
renewal r ...)
+       TODO: check
+CVE-2026-16910 (A flaw was found in Red Hat Quay's notification webhook 
feature. The S ...)
+       TODO: check
+CVE-2026-16802 (Cleartext storage of sensitive information in the variables 
feature in ...)
+       TODO: check
+CVE-2026-16801 (Improper control of generation of code ('Code Injection') in 
the varia ...)
+       TODO: check
+CVE-2026-16800 (Improper control of generation of code ('Code Injection') in 
the sched ...)
+       TODO: check
+CVE-2026-16799 (Improper access control in the automation tests and workflows 
features ...)
+       TODO: check
+CVE-2026-16798 (Insertion of sensitive information into sent data in the 
automation jo ...)
+       TODO: check
+CVE-2026-16743 (A flaw was found in accountsservice. The systemd-homed code 
path for S ...)
+       TODO: check
+CVE-2026-16730 (A flaw was found in dbus-broker. When the process 
file-descriptor limi ...)
+       TODO: check
+CVE-2026-16519 (A DLL hijacking vulnerability exists in the GeoVision GV-IP 
Device Uti ...)
+       TODO: check
+CVE-2026-15821 (The SureDash \u2013 Community, Courses & Member Dashboard 
plugin for W ...)
+       TODO: check
+CVE-2026-15810 (A Cross-Site Scripting (XSS) vulnerability in Google Cloud 
Looker vers ...)
+       TODO: check
+CVE-2026-15755 (The Open User Map \u2013 Interactive Leaflet Maps plugin for 
WordPress ...)
+       TODO: check
+CVE-2026-15739 (The Rich Showcase for Google Reviews plugin for WordPress is 
vulnerabl ...)
+       TODO: check
+CVE-2026-15704 (In Eclipse BaSyx Go Components versions up to and including 
1.0.0, ABA ...)
+       TODO: check
+CVE-2026-15665 (The Fluent Support \u2013 Helpdesk & Customer Support Ticket 
System pl ...)
+       TODO: check
+CVE-2026-15663 (The Ninja Forms \u2013 The Contact Form Builder That Grows 
With You pl ...)
+       TODO: check
+CVE-2026-15653 (The Visualizer \u2013 Tables & Charts Manager with Built-in AI 
Generat ...)
+       TODO: check
+CVE-2026-15648 (The Brands for WooCommerce plugin for WordPress is vulnerable 
to Store ...)
+       TODO: check
+CVE-2026-15464 (The WP Hotel Booking plugin for WordPress is vulnerable to 
Stored Cros ...)
+       TODO: check
+CVE-2026-15401 (The VikBooking Hotel Booking Engine & PMS plugin for WordPress 
is vuln ...)
+       TODO: check
+CVE-2026-15346 (The VikBooking Hotel Booking Engine & PMS plugin for WordPress 
is vuln ...)
+       TODO: check
+CVE-2026-15334 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE 
with 60 ...)
+       TODO: check
+CVE-2026-15333 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE 
with 60 ...)
+       TODO: check
+CVE-2026-15243 (Apereo CAS Clientaccepts any CA-trusted certificate for any 
hostname,  ...)
+       TODO: check
+CVE-2026-12702 (In affected versions of Octopus Deploy Insufficient checks on 
the proj ...)
+       TODO: check
+CVE-2026-12654 (The Payment Plugins for Stripe WooCommerce plugin for 
WordPress is vul ...)
+       TODO: check
+CVE-2026-12504 (Improper Authentication (CWE-287)in the PAM configuration in 
Loytec LI ...)
+       TODO: check
+CVE-2026-12503 (Improper Link Resolution (CWE-59)in `/usr/bin/larm_starter` in 
Loytec  ...)
+       TODO: check
+CVE-2026-12502 (Improper Privilege Management (CWE-269)in `/usr/bin/ltsudo` in 
Loytec  ...)
+       TODO: check
+CVE-2026-12496 (Stored Cross-Site Scripting (CWE-79)in the OPC XML-DA server 
statistic ...)
+       TODO: check
+CVE-2026-10610 (Local privilege escalationpotentially allowed an attacker to 
execute a ...)
+       TODO: check
+CVE-2026-10033 (The EventON Action User plugin for WordPress is vulnerable to 
authoriz ...)
+       TODO: check
+CVE-2026-16634 (TOML::XS versions before 0.06 for Perl bundle an unsupported 
and vulne ...)
        NOT-FOR-US: TOML::XS Perl module
 CVE-2026-6924 (A bug in the entropy initialization for SiWx917 causes the DRBG 
to use ...)
        NOT-FOR-US: Silicon Labs
@@ -1032,12 +1318,12 @@ CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 
allows attackers to execut
        TODO: check
 CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to 
execute ...)
        TODO: check
-CVE-2026-66140 [EXIM-Security-2026-06-22.1]
+CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files 
outside  ...)
        - exim4 4.99.4-2
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
        NOTE: 
https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt
        NOTE: Fixed by: 
https://code.exim.org/exim/exim/commit/a2ceac7c7e1183f7e35792480cb4a06a71b915ba 
(exim-4.99.5)
-CVE-2026-66141 [EXIM-Security-2026-06-22.3]
+CVE-2026-66141 (Exim before 4.99.5 allows .forward privilege escalation 
because force_ ...)
        - exim4 4.99.4-2
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
        NOTE: 
https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.3/EXIM-Security-2026-06-22.3.txt
@@ -15256,7 +15542,7 @@ CVE-2026-3688 (The WCFM Membership \u2013 WooCommerce 
Memberships for Multivendo
        NOT-FOR-US: WordPress plugin
 CVE-2026-3144 (IBM API Connect 12.1.0.0 through 12.1.0.3 uses default 
credentials whi ...)
        NOT-FOR-US: IBM
-CVE-2026-29009 (U-Boot through 2026.04-rc3 contains a buffer overflow 
vulnerability in ...)
+CVE-2026-29009 (U-Boot before 2026.07-rc2 contains a buffer overflow 
vulnerability in  ...)
        - u-boot <unfixed> (bug #1142070)
        NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
        NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
@@ -21928,11 +22214,13 @@ CVE-2026-58000 (luci-proto-openvpn through 0.11.1, 
fixed in commit e4ff45e, cont
 CVE-2026-57999 (luci-app-tailscale-community contains a command injection 
vulnerabilit ...)
        NOT-FOR-US: luci-app-tailscale-community
 CVE-2026-57966 (A path traversal vulnerability was found in spice-vdagent. 
This flaw a ...)
+       {DLA-4698-1}
        - spice-vdagent 0.23.0-3 (bug #1141317)
        [trixie] - spice-vdagent <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2493582
        NOTE: 
https://gitlab.freedesktop.org/spice/linux/vd_agent/-/commit/c2eaec460acb555d4c0ceb244a0782b50745b278
 (master)
 CVE-2026-57965 (A flaw was found in spice-vdagent. A malicious or compromised 
SPICE ho ...)
+       {DLA-4698-1}
        - spice-vdagent 0.23.0-3 (bug #1141318)
        [trixie] - spice-vdagent <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2493581
@@ -22430,7 +22718,8 @@ CVE-2026-58055 (nghttp2's nghttpx proxy through 1.69.0 
forwards an HTTP/1.1 Upgr
        [bullseye] - nghttp2 <postponed> (Minor issue)
        NOTE: 
https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc
        NOTE: 
https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e
-CVE-2026-58054 (MyBB 1.8.40 does not restrict which usergroup a limited Admin 
Control  ...)
+CVE-2026-58054
+       REJECTED
        NOT-FOR-US: MyBB
 CVE-2026-58053 (Gitea act_runner with the Docker backend (through act 0.262.0) 
passes  ...)
        - gitea <removed>
@@ -109105,7 +109394,8 @@ CVE-2026-1734 (A security flaw has been discovered in 
Zhong Bang CRMEB up to 5.6
        NOT-FOR-US: Zhong Bang CRMEB
 CVE-2026-1733 (A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. 
This a ...)
        NOT-FOR-US: Zhong Bang CRMEB
-CVE-2026-1518 (A flaw was found in Keycloak\u2019s CIBA feature where 
insufficient va ...)
+CVE-2026-1518
+       REJECTED
        - keycloak <itp> (bug #1088287)
 CVE-2026-0658 (The Five Star Restaurant Reservations  WordPress plugin before 
2.7.9 d ...)
        NOT-FOR-US: WordPress plugin



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/401702251680b791124ef64423101b5eaa0feb48

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/401702251680b791124ef64423101b5eaa0feb48
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to