Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
1e5f7536 by security tracker role at 2026-07-22T19:14:22+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -13,33 +13,33 @@ CVE-2026-65601 (Traefik versions 3.7.0 through 3.7.6
contain a namespace confusi
CVE-2026-65600 (Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >=
v3.7.0 <= v ...)
TODO: check
CVE-2026-65599 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a
credential ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65598 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race
conditi ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65597 (n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1
contains a D ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65596 (n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the
"Allowed ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65595 (n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes
to JWTs ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65594 (n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from
2.27.0, when ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65593 (n8n versions before 1.123.64 contain a server-side request
forgery vul ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65592 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM
cross-si ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65591 (n8n contains a sanitizer bypass vulnerability in the legacy
expression ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65590 (n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce
shell sand ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65589 (n8n versions before 1.123.64 fail to properly mask custom HTTP
header ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65016 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a
privilege e ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65015 (n8n versions before 2.30.1 contain a privilege escalation
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65014 (n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch)
registers t ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65013 (Onlook through 0.2.32, fixed in commit 423e2e9, contains a
broken obje ...)
TODO: check
CVE-2026-65012 (InvokeAI before 6.13.7 contains an unauthenticated directory
enumerati ...)
@@ -61,39 +61,39 @@ CVE-2026-64830 (FFmpeg versions 2.1 through 8.1.2 contains
a heap buffer overflo
CVE-2026-64828 (Froiden TableTrack through 1.3.10 contains a stored cross-site
scripti ...)
TODO: check
CVE-2026-63264 (The Joomla extension JoomShopping is vulnerable to an
reflected XSS vu ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-63048 (The Joomla extension Page Builder CK is vulnerable to an
authenticated ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-63047 (The Joomla extension Events Booking prior version 5.0-5.8.1
did not pr ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-62145 (A vulnerability in Check Point Gaia Portal allows an
authenticated att ...)
TODO: check
CVE-2026-62144 (An authentication bypass vulnerability in Check Point Security
Managem ...)
TODO: check
CVE-2026-61392 (There is a information disclosure vulnerability in some
Hikvision came ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-61391 (There is a stack-based buffer overflow vulnerability in some
Hikvision ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-61390 (There is a heap buffer overflow vulnerability in some
Hikvision camera ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-57600 (Insufficient validation of input parameters in the firmware of
some Hi ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-57599 (There is a privilege escalation vulnerability in some
Hikvision camera ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-53910 (diff3tool from GNU diffutilsis vulnerable to a heap\u2011based
buffer ...)
TODO: check
CVE-2026-4773 (Improper validation of specified type of input vulnerability in
Magars ...)
TODO: check
CVE-2026-49499 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0,
contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-46738 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0,
contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-46737 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0,
contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-45820 (fflate through 0.8.2 is vulnerable to denial of service via an
infinit ...)
TODO: check
CVE-2026-44276 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0,
contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-44192 (A flaw was found in the Ansible Lightspeed Model Context
Protocol (MCP ...)
TODO: check
CVE-2026-44191 (A flaw was found in the Visual Studio Code Ansible Lightspeed
extensio ...)
@@ -105,17 +105,17 @@ CVE-2026-44189 (A flaw was found in the Visual Studio
Code Ansible Lightspeed ex
CVE-2026-44187 (A flaw was found in the Ansible Lightspeed extension for
Visual Studio ...)
TODO: check
CVE-2026-40714 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0,
contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-40712 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0,
contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-3482 (IBM Sterling B2B Integrator and IBM Sterling File
Gateway6.2.0.0 throu ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-2406 (Authorization bypass through User-Controlled key vulnerability
in Univ ...)
TODO: check
CVE-2026-2395 (Improper neutralization of special elements used in an SQL
command ('S ...)
TODO: check
CVE-2026-22049 (ONTAP versions 9.16.1 and higher with WebAuthn multi-factor
authentica ...)
- TODO: check
+ NOT-FOR-US: NetApp
CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId
creation, allo ...)
TODO: check
CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth
authori ...)
@@ -141,39 +141,39 @@ CVE-2026-16232 (An authentication bypass vulnerability in
the Check Point SmartC
CVE-2026-16157 (Duplicati v2.3.0.1 backup software gives Authenticated Users
MODIFY pe ...)
TODO: check
CVE-2026-15787 (The Ultimate Addons for Elementor plugin for WordPress is
vulnerable t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14985 (The Analog Way Picturall Quad Compact Mark II version 3.5.8,
contains ...)
TODO: check
CVE-2026-14932 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
the obso ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-14865 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
the inte ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-14551 (The servereye client (also known as sensorhub, technically
ClientAgent ...)
TODO: check
CVE-2026-13192 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
insuffic ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13190 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
a deseri ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13189 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
insuffic ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13188 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
DialogHa ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13187 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
DialogHa ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13186 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
a path t ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13185 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
applicat ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13184 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
when Tel ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13183 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
RadAsync ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13182 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
RadAsync ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13181 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708,
forged u ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2025-13146 (The The Contact Form 7 \u2013 Dynamic Text Extension plugin
for WordPr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-64600 [xfs: resample the data fork mapping after cycling ILOCK]
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e5f753688e115792087e41e198646cf2b21b4f7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e5f753688e115792087e41e198646cf2b21b4f7
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits