Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4e1009d5 by security tracker role at 2026-07-21T07:13:28+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-8082 (The bpost-shipping-platform WordPress plugin before 3.2.3 does 
not pro ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6952 (A post-authentication command injection vulnerability in the 
"LogServe ...)
-       TODO: check
+       NOT-FOR-US: Zyxel
 CVE-2026-64651 (The `@ai-sdk/harness-opencode` tool connects HarnessAgent to 
OpenCode  ...)
        TODO: check
 CVE-2026-64650 (The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter 
backed by  ...)
@@ -35,15 +35,15 @@ CVE-2026-63729 (The SyncTeX parser (synctex_parser.c) 
shipped with TeX Live and
 CVE-2026-63728 (Gitleaks prior to 8.30.1 contains a template injection 
vulnerability t ...)
        TODO: check
 CVE-2026-62414 (The Joomla extension Page Builder CK does not properly apply 
access co ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-61901 (The Joomla extension Hikashop is vulnerable to an open 
redirect.)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-61900 (The Joomla extension JDownloads is vulnerable to an 
unauthenticated fi ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-61425 (The Joomla extension Gridbox is vulnerable an authenticated 
bypass, po ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-61424 (The Joomla extension DJ-Classifieds is vulnerable to an 
unauthenticate ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-59776 (Missing Cryptographic Step (CWE-325) vulnerability exists in 
certain F ...)
        TODO: check
 CVE-2026-57852 (Grav CMS scheduler-webhook plugin contains an authentication 
bypass vu ...)
@@ -95,7 +95,7 @@ CVE-2026-47133 (ClearanceKit intercepts file-system access 
events on macOS and e
 CVE-2026-47130 (NextCRM is open-source customer relationship management (CRM) 
software ...)
        TODO: check
 CVE-2026-47129 (NextCRM is open-source customer relationship management (CRM) 
software ...)
-       TODO: check
+       NOT-FOR-US: Next.js
 CVE-2026-47128 (nono is software that allows users to run AI agents in a 
zero-latency  ...)
        TODO: check
 CVE-2026-44585 (Paymenter is a free and open-source webshop solution for 
management of ...)
@@ -113,23 +113,23 @@ CVE-2026-44508 (Rsync is a file-copying tool that uses a 
delta-transfer algorith
 CVE-2026-44507 (Rsync is a file-copying tool that uses a delta-transfer 
algorithm to s ...)
        TODO: check
 CVE-2026-3182 (Zohocorp ManageEngine Endpoint Central versions 
before11.4.2528.34 are ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-16337 (Improper authorization in the ToolGroupResource and RoleAjax 
REST/DWR  ...)
        TODO: check
 CVE-2026-16336 (A vulnerability was found in trinodb trino 481. Affected is an 
unknown ...)
        TODO: check
 CVE-2026-16334 (A vulnerability was identified in itsourcecode Hospital 
Management Sys ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-16332 (A vulnerability was detected in D-Link DNS-320 1.0.2. This 
impacts an  ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-16331 (A security vulnerability has been detected in D-Link DNS-320 
1.0.2. Th ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-16330 (A weakness has been identified in D-Link DNS-320 1.0.2. The 
impacted e ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-16329 (A vulnerability was identified in D-Link DNS-320 1.0.2. 
Impacted is an ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-16327 (A vulnerability was determined in D-Link DNS-320 1.0.2. This 
issue aff ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-16324 (A vulnerability was identified in Metasoft 
\u7f8e\u7279\u8f6f\u4ef6 Me ...)
        TODO: check
 CVE-2026-16266 (Versions of the package mongo-object before 3.0.3 are 
vulnerable to Pr ...)
@@ -143,45 +143,45 @@ CVE-2026-15811 (A vulnerability was found in kronosnet's 
(version <=1.34) crypto
 CVE-2026-15788 (BuildKit's cache mount source= selector on Windows Container 
on Window ...)
        TODO: check
 CVE-2026-15782 (The WPForms \u2013 AI Form Builder for WordPress \u2013 
Contact Forms, ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15156 (The Essential Addons for Elementor \u2013 Popular Elementor 
Templates  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14185 (The WPBot  WordPress plugin before 8.2.0 does not perform a 
capability ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14184 (The Academy LMS WordPress plugin before 3.8.1 does not verify 
ownershi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14183 (The Classified Listing  WordPress plugin before 5.3.9 does not 
verify  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13694 (The Bit Form  WordPress plugin before 3.1.0 does not properly 
validate ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13693 (The Bit Form  WordPress plugin before 3.1.0 does not restrict 
a form f ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13439 (The Easy Form Builder by WhiteStudio plugin for WordPress is 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13381 (VSee Clinic 7.1.26 and API1.3.0contain an Insecure Direct 
Object Refer ...)
        TODO: check
 CVE-2026-13380 (VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext 
SFTP cr ...)
        TODO: check
 CVE-2026-12900 (The Spectra Gutenberg Blocks \u2013 Website Builder for the 
Block Edit ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11767 (The Free  Builder for Elementor  WordPress plugin before 1.6.7 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-51316 (The Tenda TX9 V22.03.02.20 firmware has a denial of service 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2024-51315 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2024-51314 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2024-51313 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2024-51312 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2024-51311 (The Tenda TX9 V22.03.02.05 firmware has a stack overflow 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2023-37508 (HCL DevOps Plan is potentially susceptible to Cross-Site 
Scripting (XS ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2023-37507 (HCL DevOps Plan is susceptible to an information disclosure 
that can a ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-58624 (Improper input validation in sshd-git in Apache MINA SSHD. 
Apache MINA ...)
        - mina2 <unfixed>
        - mina <removed>



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e1009d5dc7ec1ec0a0fc67524710e96c57fa0df

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e1009d5dc7ec1ec0a0fc67524710e96c57fa0df
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to