Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6b4376bc by security tracker role at 2026-07-28T19:15:08+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,17 +5,17 @@ CVE-2026-8167 (Improper neutralization of input during web 
page generation ('cro
 CVE-2026-8164 (Uncontrolled Search Path Element vulnerability in ArkSigner 
Software a ...)
        TODO: check
 CVE-2026-8058 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through 
FW1060. ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7868 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through 
FW1060. ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7775 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 
through 6 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7769 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 
through ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7521 (Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x 
<= 11.6 ...)
        TODO: check
 CVE-2026-7362 (IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 
6.2.2.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7187 (Missing authentication for critical function vulnerability in 
Universa ...)
        TODO: check
 CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` 
exhibit `O ...)
@@ -71,11 +71,11 @@ CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) 
in the Tribes-based
 CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache 
Tomcat's Web ...)
        TODO: check
 CVE-2026-65882 (Joomla Extension - joomdle.com - Reflected XSS vulnerability 
in Joomdl ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65881 (Joomla Extension - joomdle.com - Insecure default 
configuration allows ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65880 (Joomla Extension - balbooa.com - Unauthenticated remote code 
execution ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65624 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
        TODO: check
 CVE-2026-63727 (Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 
contain an ...)
@@ -87,7 +87,7 @@ CVE-2026-63302 (Quick.CMS is vulnerable to Local File 
Inclusion (LFI) in the adm
 CVE-2026-63301 (In Quick.CMS, the administrative user interface restricts 
deletion of  ...)
        TODO: check
 CVE-2026-62828 (Improper input validation in Microsoft Edge for Android allows 
an unau ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-61609 (Pterodactyl is a free, open-source game server management 
panel. From  ...)
        TODO: check
 CVE-2026-61487 (Improper Authorization vulnerability in Apache ActiveMQ 
Broker, Apache ...)
@@ -95,7 +95,7 @@ CVE-2026-61487 (Improper Authorization vulnerability in 
Apache ActiveMQ Broker,
 CVE-2026-61376 (ELECOM wireless LAN routers and access points devices contain 
an OS Co ...)
        TODO: check
 CVE-2026-5114 (The SpeedyCache plugin for WordPress is vulnerable to Arbitrary 
File R ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-59933 (PhpSpreadsheet is a pure PHP library for reading and writing 
spreadshe ...)
        TODO: check
 CVE-2026-59932 (PhpSpreadsheet is a pure PHP library for reading and writing 
spreadshe ...)
@@ -109,7 +109,7 @@ CVE-2026-59764 (ELECOM wireless LAN routers and access 
points devices contain an
 CVE-2026-59248 (Allocation of resources without limits vulnerability in 
ninenines cowl ...)
        TODO: check
 CVE-2026-58246 (SAP NetWeaver Application Server for ABAP and ABAP Platform 
writes sen ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-55977 (Successful exploitation of this vulnerability could allow an 
attacker  ...)
        TODO: check
 CVE-2026-54635 (pytonapi is a Python SDK for TONAPI that provides REST API, 
streaming, ...)
@@ -173,9 +173,9 @@ CVE-2026-50736 (The pglogical queue mechanism, used to 
convey out-of-band comman
 CVE-2026-50735 (pglogical's apply worker does not sufficiently validate the 
length of  ...)
        TODO: check
 CVE-2026-4932 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and 
FW1060.00 thro ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-4912 (The Media Cleaner: Clean your WordPress! plugin for WordPress 
is vulne ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-4648 (Use of an insecure cryptographic algorithm in the cashless 
payment sys ...)
        TODO: check
 CVE-2026-49332 (A flaw was found in openshift/oauth-proxy. The proxy sets 
authenticate ...)
@@ -183,25 +183,25 @@ CVE-2026-49332 (A flaw was found in 
openshift/oauth-proxy. The proxy sets authen
 CVE-2026-49258 (Nebula Mesh is a self-hosted control plane for the Slack 
Nebula mesh V ...)
        TODO: check
 CVE-2026-48396 (Bridge is affected by an Incorrect Authorization vulnerability 
that co ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48395 (Bridge is affected by an Untrusted Search Path vulnerability 
that coul ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48394 (Bridge is affected by an out-of-bounds write vulnerability 
that could  ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48393 (Bridge is affected by an out-of-bounds write vulnerability 
that could  ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48392 (Bridge is affected by an out-of-bounds write vulnerability 
that could  ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48391 (Bridge is affected by an Untrusted Search Path vulnerability 
that coul ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48390 (Bridge is affected by an Incorrect Authorization vulnerability 
that co ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48388 (Adobe Photoshop Installer was affected by an Uncontrolled 
Search Path  ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48374 (Bridge is affected by an Improper Limitation of a Pathname to 
a Restri ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48372 (Format Plugins is affected by a Heap-based Buffer Overflow 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48058 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh virtu ...)
        TODO: check
 CVE-2026-48025 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh virtu ...)
@@ -225,27 +225,27 @@ CVE-2026-43910 (Appium Java Client is the Java language 
binding for writing Appi
 CVE-2026-41874 (Quick.Cart stores hard-coded, plaintext admin credentials in a 
configu ...)
        TODO: check
 CVE-2026-21047 (Out-of-bounds write in ImsService prior to SMR Jul-2026 
Release 1 allo ...)
-       TODO: check
+       NOT-FOR-US: Samsung Mobile
 CVE-2026-18107 (A flaw was found in CRIU's handling of restartable sequences 
(rseq) du ...)
        TODO: check
 CVE-2026-18085 (An Improper Input Validation in the BlackBerry 
UEMManagementConsoleofB ...)
-       TODO: check
+       NOT-FOR-US: Blackberry
 CVE-2026-18084 (Improper Neutralization of Input During Web Page Generation 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: Blackberry
 CVE-2026-18047 (A flaw was found in Dogtag PKI's ACME responder where the 
web.xml secu ...)
        TODO: check
 CVE-2026-18038 (A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. 
Affecte ...)
        TODO: check
 CVE-2026-18029 (Our payment integration with GiroCheckout did not properly 
validate  p ...)
-       TODO: check
+       NOT-FOR-US: rami.io products
 CVE-2026-18028 (The "quick setup" view presented to users after they first 
create an   ...)
-       TODO: check
+       NOT-FOR-US: rami.io products
 CVE-2026-17072 (A flaw was found in GStreamer's gst-plugins-good. A heap-based 
out-of- ...)
        TODO: check
 CVE-2026-16774 (The Chatbot plugin for WordPress is vulnerable to Missing 
Authorizatio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16773 (The WPBot \u2013 AI ChatBot for Live Support, Lead Generation, 
AI Serv ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16771 (In firmware versions 2.7.7 and earlier, the Arris 
BGW210\u2011700 gate ...)
        TODO: check
 CVE-2026-16498 (The terraform-mcp-server before version 1.1.0 is vulnerable to 
a cross ...)
@@ -257,39 +257,39 @@ CVE-2026-16462 (In PROCON-WEB SCADA the endpoint 
'GetGridData' is not properly s
 CVE-2026-16313 (A flaw was found in sg3_utils. The sg_inq command, when 
invoked with t ...)
        TODO: check
 CVE-2026-15992 (The WP Password Policy plugin for WordPress is vulnerable to 
Privilege ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15730 (The GamiPress \u2013 Gamification plugin to reward points, 
achievement ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15673 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order 
Notifications &  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15671 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order 
Notifications &  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15670 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order 
Notifications &  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15444 (The Tutor LMS \u2013 eLearning and online course solution 
plugin for W ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15411 (The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, 
Upsells,  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15393 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE 
with 60 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15304 (The Plugin Organizer plugin for WordPress is vulnerable to SQL 
Injecti ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15267 (The Taskbuilder \u2013 Project Management & Task Management 
Tool With  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15025 (The Uncanny Automator \u2013 Easy Automation, Integration, 
Webhooks &  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15016 (The Paid Memberships Pro \u2013 Content Restriction, User 
Registration ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15014 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order 
Notifications &  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14869 (The terraform-mcp-server before version 1.1.0 is vulnerable to 
a serve ...)
        TODO: check
 CVE-2026-14785 (The Web Directory Free plugin for WordPress is vulnerable to 
generic S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14516 (The Online Scheduling and Appointment Booking System \u2013 
Bookly plu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14328 (The Eazy Plugin Manager \u2013 Powerful Plugin Management 
Solution for ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14171 (An unauthenticated remote attacker can abuse the improper 
validation o ...)
        TODO: check
 CVE-2026-14170
@@ -301,23 +301,23 @@ CVE-2026-14168 (A low privileged remote attacker can gain 
administrator privileg
 CVE-2026-14167 (A low privileged remote attacker can perform privileged 
configuration  ...)
        TODO: check
 CVE-2026-13440 (The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, 
Upsells,  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13161 (The TrueBooker \u2013 Appointment Booking and Scheduler System 
plugin  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13110 (The Storegrowth Sales Booster plugin for WordPress is 
vulnerable to Mi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12800 (The Premium Packages \u2013 Sell Digital Products Securely 
plugin for  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12741 (The WP Fast Total Search \u2013 The Power of Indexed Search 
plugin for ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11841 (An attacker may perform unauthenticated read and write 
operations on s ...)
-       TODO: check
+       NOT-FOR-US: SICK AG
 CVE-2026-11756 (A Deserialization of Untrusted Data vulnerability affecting 
Station La ...)
-       TODO: check
+       NOT-FOR-US: Dassault Systemes
 CVE-2026-11598 (The Shortcodify plugin for WordPress is vulnerable to Stored 
Cross-Sit ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-10207 (The PickPlugins Question Answer plugin for WordPress is 
vulnerable to  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-14041 (In Bouncy Castle for Java from 1.73 to before 1.78, three 
ML-KEM (CRYS ...)
        TODO: check
 CVE-2026-59986



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b4376bc4e499ad3e3119f532c1d7bcd2c528e82

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b4376bc4e499ad3e3119f532c1d7bcd2c528e82
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to