Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
08f945ea by security tracker role at 2026-03-11T08:13:50+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-3911 (A flaw was found in Keycloak. An authenticated user with the 
view-user ...)
        TODO: check
 CVE-2026-3903 (The Modular DS: Monitor, update, and backup multiple websites 
plugin f ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-3884 (Versions of the package spin.js before 3.0.0 are vulnerable to 
Cross-s ...)
        TODO: check
 CVE-2026-3826 (IFTOP developed by WellChoose has a Local File Inclusion 
vulnerability ...)
@@ -11,11 +11,11 @@ CVE-2026-3825 (IFTOP developed by WellChoose has a 
Reflected Cross-site Scriptin
 CVE-2026-3824 (IFTOP developed by WellChoose has an Open redirect 
vulnerability, allo ...)
        TODO: check
 CVE-2026-3534 (The Astra theme for WordPress is vulnerable to Stored 
Cross-Site Scrip ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-3453 (The ProfilePress plugin for WordPress is vulnerable to Insecure 
Direct ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-3222 (The WP Maps plugin for WordPress is vulnerable to time-based 
blind SQL ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-31844 (An authenticated SQL Injection vulnerability (CWE-89) exists 
in the Ko ...)
        TODO: check
 CVE-2026-31838 (Istio is an open platform to connect, manage, and secure 
microservices ...)
@@ -23,11 +23,11 @@ CVE-2026-31838 (Istio is an open platform to connect, 
manage, and secure microse
 CVE-2026-31837 (Istio is an open platform to connect, manage, and secure 
microservices ...)
        TODO: check
 CVE-2026-31834 (Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 
17.2.2, A  ...)
-       TODO: check
+       NOT-FOR-US: Umbraco CMS
 CVE-2026-31833 (Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 
17.2.2, An ...)
-       TODO: check
+       NOT-FOR-US: Umbraco CMS
 CVE-2026-31832 (Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 
17.2.2, A  ...)
-       TODO: check
+       NOT-FOR-US: Umbraco CMS
 CVE-2026-31830 (sigstore-ruby is a pure Ruby implementation of the sigstore 
verify com ...)
        TODO: check
 CVE-2026-31829 (Flowise is a drag & drop user interface to build a customized 
large la ...)
@@ -97,25 +97,25 @@ CVE-2026-30946 (Parse Server is an open source backend that 
can be deployed to a
 CVE-2026-30837 (Elysia is a Typescript framework for request validation, type 
inferenc ...)
        TODO: check
 CVE-2026-2918 (The Happy Addons for Elementor plugin for WordPress is 
vulnerable to I ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2917 (The Happy Addons for Elementor plugin for WordPress is 
vulnerable to I ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2707 (The weForms plugin for WordPress is vulnerable to Stored 
Cross-Site Sc ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2631 (The Datalogics Ecommerce Delivery  WordPress plugin before 
2.6.60 expo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2626 (The divi-booster WordPress plugin before 5.0.2 does not have 
authoriza ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2569 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed, 
PDF vie ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2466 (The DukaPress WordPress plugin through 3.2.4 does not sanitise 
and esc ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2413 (The Ally \u2013 Web Accessibility & Usability plugin for 
WordPress is  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2358 (The WP ULike plugin for WordPress is vulnerable to Stored 
Cross-Site S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2324 (The LatePoint \u2013 Calendar Booking Plugin for Appointments 
and Even ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-29793 (Feathersjs is a framework for creating web APIs and real-time 
applicat ...)
        TODO: check
 CVE-2026-29792 (Feathersjs is a framework for creating web APIs and real-time 
applicat ...)
@@ -129,209 +129,209 @@ CVE-2026-28806 (Improper Authorization vulnerability in 
nerves-hub nerves_hub_we
 CVE-2026-27842 (Authentication bypass issue exists in MR-GM5L-S1 and 
MR-GM5A-L1, which ...)
        TODO: check
 CVE-2026-27278 (Acrobat Reader versions 24.001.30307, 24.001.30308, 
25.001.21265 and e ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27272 (Illustrator versions 29.8.4, 30.1 and earlier are affected by 
an out-o ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27271 (Illustrator versions 29.8.4, 30.1 and earlier are affected by 
a Heap-b ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27270 (Illustrator versions 29.8.4, 30.1 and earlier are affected by 
an Out-o ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27268 (Illustrator versions 29.8.4, 30.1 and earlier are affected by 
an Out-o ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27267 (Illustrator versions 29.8.4, 30.1 and earlier are affected by 
a Stack- ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27266 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27265 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27264 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27263 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27262 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27261 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27260 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27259 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27257 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27256 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27255 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27254 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27253 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27252 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27251 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27250 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27249 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27248 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27247 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27244 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27242 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27241 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27240 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27239 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27237 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27236 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27235 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27234 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27233 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27232 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27231 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27230 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27229 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27228 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27226 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27225 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27224 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27223 (Adobe Experience Manager versions 6.5.23 and earlier are 
affected by a ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27221 (Acrobat Reader versions 24.001.30307, 24.001.30308, 
25.001.21265 and e ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-27220 (Acrobat Reader versions 24.001.30307, 24.001.30308, 
25.001.21265 and e ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-24448 (Use of hard-coded credentials issue exists in MR-GM5L-S1 and 
MR-GM5A-L ...)
        TODO: check
 CVE-2026-23817 (A vulnerability in the web-based management interface of 
AOS-CX Switch ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-23816 (A vulnerability in the command line interface of AOS-CX 
Switches could ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-23815 (A vulnerability in a custom binary used in AOS-CX Switches' 
CLI could  ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-23814 (A vulnerability in the command parameters of a certain AOS-CX 
CLI comm ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-23813 (A vulnerability has been identified in the web-based 
management interf ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-21362 (Illustrator versions 29.8.4, 30.1 and earlier are affected by 
an out-o ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21361 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21360 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21359 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21333 (Illustrator versions 29.8.4, 30.1 and earlier are affected by 
an Untru ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21311 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21310 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21309 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21297 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21296 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21295 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21294 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21293 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21292 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21291 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21290 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21289 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21286 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21285 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21284 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-21282 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 
2.4.6-p13, 2 ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-20892 (Code injection vulnerability exists in MR-GM5L-S1 and 
MR-GM5A-L1, whic ...)
        TODO: check
 CVE-2026-1867 (The Guest posting / Frontend Posting / Front Editor  WordPress 
plugin  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-1781 (The MC4WP: Mailchimp for WordPress plugin for WordPress is 
vulnerable  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-1753 (The Gutena Forms  WordPress plugin before 1.6.1 does not 
validate opti ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-1708 (The Appointment Booking Calendar \u2014 Simply Schedule 
Appointments B ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-0124 (There is a possible out of bounds write due to a missing bounds 
check. ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0123 (In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there 
is a po ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0122 (In multiple places, there is a possible out of bounds write due 
to mem ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0121 (In VPU, there is a possible use-after-free read due to a race 
conditio ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0120 (In modem, there is a possible out of bounds write due to an 
incorrect  ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0119 (In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a 
possible o ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0118 (In oobconfig, there is a possible bypass of carrier 
restrictions due t ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0117 (In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of 
bounds  ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0116 (In __mfc_handle_released_buf of mfc_core_isr.c, there is a 
possible ou ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0115 (In Trusted Execution Environment, there is a possible key leak 
due to  ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0114 (In Modem, there is a possible out of bounds write due to an 
incorrect  ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0113 (In ns_GetUserData of ns_SmscbUtilities.c, there is a possible 
out of b ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0112 (In vpu_open_inst of vpu_ioctl.c, there is a possible use after 
free du ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0111 (In ns_GetUserData of ns_SmscbUtilities.c, there is a possible 
out of b ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0110 (In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible 
EoP du ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0109 (In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial 
of Ser ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0108 (The register protection of the PowerVR GPU is incorrectly 
configured.  ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2026-0107 (In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a 
possible esc ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2025-70802 (Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered 
to contai ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2025-70798 (Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to 
contain a ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2025-70244 (Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 
via the we ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2025-70242 (Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 
via the we ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2025-66413 (Git for Windows is the Windows port of Git. Prior to 
2.53.0(2), it is  ...)
        TODO: check
 CVE-2025-36920 (In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a 
possible o ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2025-22850 (Time-of-check time-of-use race condition in the UEFI PdaSmm 
module for ...)
        TODO: check
 CVE-2025-22444 (Exposure of resource to wrong sphere in the UEFI PdaSmm module 
for som ...)
@@ -353,19 +353,19 @@ CVE-2025-20027 (Improper input validation in the UEFI 
WheaERST module for some I
 CVE-2025-20005 (Improper buffer restrictions in some UEFI firmware for some 
Intel(R) r ...)
        TODO: check
 CVE-2025-13219 (IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive 
informati ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2025-13213 (IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to 
HTTP head ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2025-13067 (The Royal Addons for Elementor plugin for WordPress is 
vulnerable to a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-12473 (The RTMKit plugin for WordPress is vulnerable to Reflected 
Cross-Site  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-14026 (A command injection vulnerability has been reported to affect 
several  ...)
-       TODO: check
+       NOT-FOR-US: QNAP
 CVE-2024-14025 (An SQL injection vulnerability has been reported to affect 
Video Stati ...)
-       TODO: check
+       NOT-FOR-US: QNAP
 CVE-2024-14024 (An improper certificate validation vulnerability has been 
reported to  ...)
-       TODO: check
+       NOT-FOR-US: QNAP
 CVE-2026-3805
        - curl <unfixed>
        [trixie] - curl <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/08f945ea48155a0c839c8d0c3bd203c24b8e07c0

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/08f945ea48155a0c839c8d0c3bd203c24b8e07c0
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to