Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6b4376bc by security tracker role at 2026-07-28T19:15:08+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5,17 +5,17 @@ CVE-2026-8167 (Improper neutralization of input during web
page generation ('cro
CVE-2026-8164 (Uncontrolled Search Path Element vulnerability in ArkSigner
Software a ...)
TODO: check
CVE-2026-8058 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through
FW1060. ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-7868 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through
FW1060. ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-7775 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0
through 6 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-7769 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0
through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-7521 (Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x
<= 11.6 ...)
TODO: check
CVE-2026-7362 (IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and
6.2.2.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-7187 (Missing authentication for critical function vulnerability in
Universa ...)
TODO: check
CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()`
exhibit `O ...)
@@ -71,11 +71,11 @@ CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502)
in the Tribes-based
CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache
Tomcat's Web ...)
TODO: check
CVE-2026-65882 (Joomla Extension - joomdle.com - Reflected XSS vulnerability
in Joomdl ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65881 (Joomla Extension - joomdle.com - Insecure default
configuration allows ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65880 (Joomla Extension - balbooa.com - Unauthenticated remote code
execution ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65624 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
TODO: check
CVE-2026-63727 (Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0
contain an ...)
@@ -87,7 +87,7 @@ CVE-2026-63302 (Quick.CMS is vulnerable to Local File
Inclusion (LFI) in the adm
CVE-2026-63301 (In Quick.CMS, the administrative user interface restricts
deletion of ...)
TODO: check
CVE-2026-62828 (Improper input validation in Microsoft Edge for Android allows
an unau ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-61609 (Pterodactyl is a free, open-source game server management
panel. From ...)
TODO: check
CVE-2026-61487 (Improper Authorization vulnerability in Apache ActiveMQ
Broker, Apache ...)
@@ -95,7 +95,7 @@ CVE-2026-61487 (Improper Authorization vulnerability in
Apache ActiveMQ Broker,
CVE-2026-61376 (ELECOM wireless LAN routers and access points devices contain
an OS Co ...)
TODO: check
CVE-2026-5114 (The SpeedyCache plugin for WordPress is vulnerable to Arbitrary
File R ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-59933 (PhpSpreadsheet is a pure PHP library for reading and writing
spreadshe ...)
TODO: check
CVE-2026-59932 (PhpSpreadsheet is a pure PHP library for reading and writing
spreadshe ...)
@@ -109,7 +109,7 @@ CVE-2026-59764 (ELECOM wireless LAN routers and access
points devices contain an
CVE-2026-59248 (Allocation of resources without limits vulnerability in
ninenines cowl ...)
TODO: check
CVE-2026-58246 (SAP NetWeaver Application Server for ABAP and ABAP Platform
writes sen ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-55977 (Successful exploitation of this vulnerability could allow an
attacker ...)
TODO: check
CVE-2026-54635 (pytonapi is a Python SDK for TONAPI that provides REST API,
streaming, ...)
@@ -173,9 +173,9 @@ CVE-2026-50736 (The pglogical queue mechanism, used to
convey out-of-band comman
CVE-2026-50735 (pglogical's apply worker does not sufficiently validate the
length of ...)
TODO: check
CVE-2026-4932 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and
FW1060.00 thro ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-4912 (The Media Cleaner: Clean your WordPress! plugin for WordPress
is vulne ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-4648 (Use of an insecure cryptographic algorithm in the cashless
payment sys ...)
TODO: check
CVE-2026-49332 (A flaw was found in openshift/oauth-proxy. The proxy sets
authenticate ...)
@@ -183,25 +183,25 @@ CVE-2026-49332 (A flaw was found in
openshift/oauth-proxy. The proxy sets authen
CVE-2026-49258 (Nebula Mesh is a self-hosted control plane for the Slack
Nebula mesh V ...)
TODO: check
CVE-2026-48396 (Bridge is affected by an Incorrect Authorization vulnerability
that co ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48395 (Bridge is affected by an Untrusted Search Path vulnerability
that coul ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48394 (Bridge is affected by an out-of-bounds write vulnerability
that could ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48393 (Bridge is affected by an out-of-bounds write vulnerability
that could ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48392 (Bridge is affected by an out-of-bounds write vulnerability
that could ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48391 (Bridge is affected by an Untrusted Search Path vulnerability
that coul ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48390 (Bridge is affected by an Incorrect Authorization vulnerability
that co ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48388 (Adobe Photoshop Installer was affected by an Uncontrolled
Search Path ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48374 (Bridge is affected by an Improper Limitation of a Pathname to
a Restri ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48372 (Format Plugins is affected by a Heap-based Buffer Overflow
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48058 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh virtu ...)
TODO: check
CVE-2026-48025 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh virtu ...)
@@ -225,27 +225,27 @@ CVE-2026-43910 (Appium Java Client is the Java language
binding for writing Appi
CVE-2026-41874 (Quick.Cart stores hard-coded, plaintext admin credentials in a
configu ...)
TODO: check
CVE-2026-21047 (Out-of-bounds write in ImsService prior to SMR Jul-2026
Release 1 allo ...)
- TODO: check
+ NOT-FOR-US: Samsung Mobile
CVE-2026-18107 (A flaw was found in CRIU's handling of restartable sequences
(rseq) du ...)
TODO: check
CVE-2026-18085 (An Improper Input Validation in the BlackBerry
UEMManagementConsoleofB ...)
- TODO: check
+ NOT-FOR-US: Blackberry
CVE-2026-18084 (Improper Neutralization of Input During Web Page Generation
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Blackberry
CVE-2026-18047 (A flaw was found in Dogtag PKI's ACME responder where the
web.xml secu ...)
TODO: check
CVE-2026-18038 (A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2.
Affecte ...)
TODO: check
CVE-2026-18029 (Our payment integration with GiroCheckout did not properly
validate p ...)
- TODO: check
+ NOT-FOR-US: rami.io products
CVE-2026-18028 (The "quick setup" view presented to users after they first
create an ...)
- TODO: check
+ NOT-FOR-US: rami.io products
CVE-2026-17072 (A flaw was found in GStreamer's gst-plugins-good. A heap-based
out-of- ...)
TODO: check
CVE-2026-16774 (The Chatbot plugin for WordPress is vulnerable to Missing
Authorizatio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16773 (The WPBot \u2013 AI ChatBot for Live Support, Lead Generation,
AI Serv ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16771 (In firmware versions 2.7.7 and earlier, the Arris
BGW210\u2011700 gate ...)
TODO: check
CVE-2026-16498 (The terraform-mcp-server before version 1.1.0 is vulnerable to
a cross ...)
@@ -257,39 +257,39 @@ CVE-2026-16462 (In PROCON-WEB SCADA the endpoint
'GetGridData' is not properly s
CVE-2026-16313 (A flaw was found in sg3_utils. The sg_inq command, when
invoked with t ...)
TODO: check
CVE-2026-15992 (The WP Password Policy plugin for WordPress is vulnerable to
Privilege ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15730 (The GamiPress \u2013 Gamification plugin to reward points,
achievement ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15673 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order
Notifications & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15671 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order
Notifications & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15670 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order
Notifications & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15444 (The Tutor LMS \u2013 eLearning and online course solution
plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15411 (The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO,
Upsells, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15393 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE
with 60 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15304 (The Plugin Organizer plugin for WordPress is vulnerable to SQL
Injecti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15267 (The Taskbuilder \u2013 Project Management & Task Management
Tool With ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15025 (The Uncanny Automator \u2013 Easy Automation, Integration,
Webhooks & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15016 (The Paid Memberships Pro \u2013 Content Restriction, User
Registration ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15014 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order
Notifications & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14869 (The terraform-mcp-server before version 1.1.0 is vulnerable to
a serve ...)
TODO: check
CVE-2026-14785 (The Web Directory Free plugin for WordPress is vulnerable to
generic S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14516 (The Online Scheduling and Appointment Booking System \u2013
Bookly plu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14328 (The Eazy Plugin Manager \u2013 Powerful Plugin Management
Solution for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14171 (An unauthenticated remote attacker can abuse the improper
validation o ...)
TODO: check
CVE-2026-14170
@@ -301,23 +301,23 @@ CVE-2026-14168 (A low privileged remote attacker can gain
administrator privileg
CVE-2026-14167 (A low privileged remote attacker can perform privileged
configuration ...)
TODO: check
CVE-2026-13440 (The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO,
Upsells, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13161 (The TrueBooker \u2013 Appointment Booking and Scheduler System
plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13110 (The Storegrowth Sales Booster plugin for WordPress is
vulnerable to Mi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12800 (The Premium Packages \u2013 Sell Digital Products Securely
plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12741 (The WP Fast Total Search \u2013 The Power of Indexed Search
plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11841 (An attacker may perform unauthenticated read and write
operations on s ...)
- TODO: check
+ NOT-FOR-US: SICK AG
CVE-2026-11756 (A Deserialization of Untrusted Data vulnerability affecting
Station La ...)
- TODO: check
+ NOT-FOR-US: Dassault Systemes
CVE-2026-11598 (The Shortcodify plugin for WordPress is vulnerable to Stored
Cross-Sit ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-10207 (The PickPlugins Question Answer plugin for WordPress is
vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-14041 (In Bouncy Castle for Java from 1.73 to before 1.78, three
ML-KEM (CRYS ...)
TODO: check
CVE-2026-59986
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b4376bc4e499ad3e3119f532c1d7bcd2c528e82
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b4376bc4e499ad3e3119f532c1d7bcd2c528e82
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits