Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d165318a by security tracker role at 2026-07-27T19:19:53+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11,31 +11,31 @@ CVE-2026-66730 (facil.io 0.6.0 through 0.7.6 contains a
denial-of-service vulner
CVE-2026-66729 (facil.io 0.6.0 through 0.7.6 contains an integer underflow
vulnerabili ...)
TODO: check
CVE-2026-66477 (Unauthenticated Broken Access Control in Gillion <= 4.13
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66476 (Administrator Arbitrary File Deletion in Easy Digital
Downloads <= 3.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66475 (Shop manager Cross Site Scripting (XSS) in Checkout Field
Editor for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66474 (Unauthenticated Cross Site Request Forgery (CSRF) in Insert
Headers an ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66448 (Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks
<= 1.3.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66445 (Contributor Cross Site Scripting (XSS) in Open User Map <=
1.4.46 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66442 (Subscriber Broken Access Control in YayPricing <= 3.5.6
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66438 (Unauthenticated Sensitive Data Exposure in Exclusive Addons
Elementor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66437 (Contributor Server Side Request Forgery (SSRF) in Feedzy <=
5.2.4 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66434 (Contributor Cross Site Scripting (XSS) in Photonic Gallery &
Lightbox ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66433 (Contributor Cross Site Scripting (XSS) in Location Weather <=
3.0.6 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66428 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Google
Review ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66427 (Administrator SQL Injection in WP Google Review Slider <= 18.4
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66399 (phpMyFAQ before 4.1.6 contains a privilege escalation
vulnerability in ...)
TODO: check
CVE-2026-66398 (phpMyFAQ before v4.1.6 contains a remote code execution
vulnerability ...)
@@ -49,9 +49,9 @@ CVE-2026-66395 (SiYuan desktop before v3.7.2 contains a
reflected cross-site scr
CVE-2026-66394 (SiYuan before v3.7.3 contains stored and reflected cross-site
scriptin ...)
TODO: check
CVE-2026-66391 (Use of Insufficiently Random Values, Protection Mechanism
Failure vuln ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66390 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66053 (Improper Validation of Certificate with Host Mismatch
vulnerability in ...)
TODO: check
CVE-2026-66050 (NitroShare Desktop through 0.3.4 contains a path traversal
vulnerabili ...)
@@ -69,121 +69,121 @@ CVE-2026-65894 (This vulnerability exists in CP PLUS
EZ-P21 IP Camera due to imp
CVE-2026-65893 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to
an insecu ...)
TODO: check
CVE-2026-65879 (Joomla Extension - joomshaper.com - Unauthenticated mail relay
via a h ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65878 (Joomla Extension - joomshaper.com - Authenticated arbitrary
file delet ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65877 (Joomla Extension - joomshaper.com - Authenticated SQL
injection in SP ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65876 (Joomla Extension - joomshaper.com - Unauthenticated SQL
injection in ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65766 (Joomla Extension - joomshaper.com - Unauthenticated SQL
injection in ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65765 (Joomla Extension - phoca.cz - Path Traversal vulnerability in
Phoca Co ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65764 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in
Phoca Com ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65568 (Contributor Broken Access Control in Visual Composer Website
Builder < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65567 (Unauthenticated Broken Access Control in Event Tickets <=
5.29.0.1 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65564 (Unauthenticated Sensitive Data Exposure in MapPress Maps for
WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65563 (Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <=
3.0.7 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65562 (Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65561 (Contributor Cross Site Scripting (XSS) in WordPress Social
Login and R ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65558 (Unauthenticated Server Side Request Forgery (SSRF) in
AffiliateX <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65557 (Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite
for Woo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65436 (Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65435 (Unauthenticated Broken Access Control in Thrive Leads Version
<= 10.9. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65434 (Subscriber Sensitive Data Exposure in \u042eKassa
\u0434\u043b\u044f W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65433 (Subscriber Broken Access Control in RT Mega Menu \u2013 Mega
Menu Buil ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-64647 (Next.js is a React framework for building full-stack web
applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64646 (Next.js is a React framework for building full-stack web
applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64645 (Next.js is a React framework for building full-stack web
applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64644 (Next.js is a React framework for building full-stack web
applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64643 (Next.js is a React framework for building full-stack web
applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64642 (Next.js is a React framework for building full-stack web
applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64641 (Next.js is a React framework for building full-stack web
applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-63077 (In JetBrains TeamCity before 2026.1.3, 2025.11.7
unauthenticated remot ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-61511 (vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an
eval inj ...)
- TODO: check
+ NOT-FOR-US: vBulletin
CVE-2026-59690 (A Missing Authorization vulnerability in Progress Software
LoadMaster, ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59689 (An Incorrect Authorization vulnerability in Progress Software
LoadMast ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59688 (An OS Command Injection vulnerability in Progress Software
LoadMaster, ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59687 (An OS Command Injection vulnerability in Progress Software
LoadMaster, ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59686 (An OS Command Injection vulnerability in Progress Software
LoadMaster, ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59560 (Subscriber Broken Access Control in FundEngine <= 1.7.8
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59559 (Subscriber Cross Site Scripting (XSS) in RT Mega Menu \u2013
Mega Menu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59558 (Unauthenticated Cross Site Scripting (XSS) in Booking Calendar
<= 11.4 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59557 (Unauthenticated Broken Access Control in Events Made Easy <=
3.1.3 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59556 (Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing
With Dis ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59553 (Unauthenticated Cross Site Scripting (XSS) in Product Feed
Manager <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59552 (Unauthenticated Server Side Request Forgery (SSRF) in 3D
Flipbook PDF ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59551 (Subscriber SQL Injection in rtMedia for WordPress, BuddyPress
and bbPr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59550 (Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59549 (Unauthenticated SQL Injection in rtMedia for WordPress,
BuddyPress and ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59548 (Unauthenticated Sensitive Data Exposure in Byteflows Travel
& Hote ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59546 (Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59539 (Subscriber Insecure Direct Object References (IDOR) in Paid
Member Sub ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59538 (Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59537 (Administrator SQL Injection in Sender \u2013 Newsletter, SMS
and Email ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59536 (Unauthenticated Broken Access Control in CoCart \u2013
Headless ecomme ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59535 (Unauthenticated Broken Access Control in Thrive Product
Manager <= 10. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59534 (Unauthenticated Broken Access Control in Post My CF7 Form <=
6.2.0 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59533 (Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59532 (Unauthenticated Other Vulnerability Type in Booking and Rental
Manager ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59531 (Unauthenticated Unknown in Falcon \u2013 WordPress
Optimizations & Twe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59530 (Unauthenticated Broken Access Control in Stripe For
WooCommerce <= 4.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59529 (Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59528 (Subscriber Sensitive Data Exposure in ShipTime: Discounted
Shipping Ra ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59527 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP
public_key certif ...)
TODO: check
CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner
C driver ...)
@@ -203,9 +203,9 @@ CVE-2026-57917 (proCertum SmartSignparses external XML
entities from arbitrary c
CVE-2026-57916 (proCertum SmartSign opens Certificate Practice Statement (CPS)
URI wit ...)
TODO: check
CVE-2026-56538 (An endpoint in HCL Connections is vulnerable to information
disclosure ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56537 (HCL Connections is vulnerable to information disclosure which
could al ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-55971 (Heap-based Buffer Overflow vulnerability in Apache Thrift C++
bindings ...)
TODO: check
CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This is ...)
@@ -273,11 +273,11 @@ CVE-2026-42792 (Improper Handling of Exceptional
Conditions vulnerability in Erl
CVE-2026-41608 (Improper Handling of Highly Compressed Data (Data
Amplification) vulne ...)
TODO: check
CVE-2026-40000 (The Activity
zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity wit ...)
- TODO: check
+ NOT-FOR-US: ZTE
CVE-2026-24252 (NVIDIA NeMo for Linux contains a vulnerability where an
attacker may c ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-17612 (Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions
prior to a ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability.
Processing a c ...)
TODO: check
CVE-2026-17573 (A double free vulnerability was discovered in the HDF5
library. Proces ...)
@@ -285,11 +285,11 @@ CVE-2026-17573 (A double free vulnerability was
discovered in the HDF5 library.
CVE-2026-17572 (Heap-based buffer overflow in the SOHM list-index
deserialization code ...)
TODO: check
CVE-2026-17570 (Improper access control in the PAM password history endpoints
in Devol ...)
- TODO: check
+ NOT-FOR-US: Devolutions
CVE-2026-17569 (Improper access control in the NetBox synchronizer in
Devolutions Serv ...)
- TODO: check
+ NOT-FOR-US: Devolutions
CVE-2026-17568 (Improper access control in the role membership management
endpoint in ...)
- TODO: check
+ NOT-FOR-US: Devolutions
CVE-2026-17552 (Plack::App::Prerender versions before 0.3.0 for Perl can proxy
to an a ...)
TODO: check
CVE-2026-17534 (Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements
FetchURL S ...)
@@ -311,11 +311,11 @@ CVE-2026-17513 (A vulnerability was found in ggml-org
whisper.cpp 95ea8f9b. Affe
CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp
1.8.4-58. This ...)
TODO: check
CVE-2026-17192 (A VCO feature does not sufficiently validate caller-supplied
input, al ...)
- TODO: check
+ NOT-FOR-US: Arista Networks
CVE-2026-17191 (An input validation vulnerability exists in an API component
of the or ...)
- TODO: check
+ NOT-FOR-US: Arista Networks
CVE-2026-16812 (VeloCloud Orchestrator (VCO) on-prem has a security issue
where this i ...)
- TODO: check
+ NOT-FOR-US: Arista Networks
CVE-2026-16554 (cJSON library is vulnerable to an integer overflow in the
print_string ...)
TODO: check
CVE-2026-16481 (A Server-Side Request Forgery (SSRF) and credential
exfiltration vulne ...)
@@ -341,21 +341,21 @@ CVE-2026-12383 (A flaw was found in the Event-Driven
Ansible (EDA) server. The E
CVE-2026-10819 (Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20,
11.8.x <= 1 ...)
TODO: check
CVE-2026-10683 (In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c)
operating ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-10682 (The userspace verifier z_vrfy_log_filter_set() for the
log_filter_set ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-10600 (Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x
<= 11.6 ...)
TODO: check
CVE-2025-59181 (Ericsson Packet Core Controller (PCC) versions prior to 1.39
contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-59180 (Ericsson Packet Core Controller (PCC) versions prior to 1.38
contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-59178 (Ericsson Packet Core Controller (PCC) versions prior to 1.39
contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-59177 (Ericsson Packet Core Controller (PCC) versions prior to 1.39
contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-59172 (Ericsson Packet Core Controller (PCC) versions prior to 1.38
contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter
of the /c ...)
TODO: check
CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
@@ -53021,9 +53021,9 @@ CVE-2026-9157 (Improper input validation, Unrestricted
upload of file with dange
CVE-2026-9089 (The ConnectWise Automate\u2122 Agent does not fully verify the
authent ...)
NOT-FOR-US: ConnectWise
CVE-2026-5434 (Honeywell Control Network Module (CNM)contains insertion of
sensitive ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2026-5433 (Honeywell Control Network Module (CNM)contains command
injection vulne ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2026-5118 (The Divi Form Builder plugin for WordPress is vulnerable to
privilege ...)
NOT-FOR-US: WordPress plugin
CVE-2026-4858 (Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x
<= 11.4 ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d165318a4a3af49c97eaf53e73eac3530efe250f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d165318a4a3af49c97eaf53e73eac3530efe250f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits