Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ea649b8a by security tracker role at 2026-07-29T07:13:29+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -41,7 +41,7 @@ CVE-2026-63227 (An unrestricted SCORM file upload
vulnerability in Koollab LMS a
CVE-2026-62325 (goshs is a feature-rich single-binary file server for red
teamers and ...)
TODO: check
CVE-2026-5626 (The Survey Form Block plugin for WordPress is vulnerable to
unauthoriz ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-59943 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15
and prior ...)
TODO: check
CVE-2026-59942 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and
prior ar ...)
@@ -105,99 +105,99 @@ CVE-2026-48060 (Litestar is an Asynchronous Server
Gateway Interface (ASGI) fram
CVE-2026-47219 (find-my-way is a framework-independent HTTP router that
internally use ...)
TODO: check
CVE-2026-3158 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0
through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-3157 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0
through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-1918 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0
through ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18072 (The Advanced Responsive Video Embedder for Rumble, Odysee,
YouTube, Vi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17166 (The Event Booking Manager for WooCommerce \u2013 Sell Tickets,
Event R ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17162 (The WowStore \u2013 Store Builder & Product Blocks for
WooCommerce plu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17161 (The WowStore \u2013 Store Builder & Product Blocks for
WooCommerce plu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16581 (In igloohome Smart Lock Mobile App versions 3.2.3 and prior,
an Inclus ...)
TODO: check
CVE-2026-16347 (MikroTik RouterOS contains a weakness in its API
authentication handli ...)
- TODO: check
+ NOT-FOR-US: MikroTik
CVE-2026-16192 (IBM WebSphere Application Server - Liberty 17.0.0.3 through
26.0.0.8 i ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16184 (IBM WebSphere Application Server 9.0, and 8.5 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16107 (IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not
validat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15735 (The Contact Form to Any API plugin for WordPress is vulnerable
to Stor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15344 (The WP Photo Album Plus plugin for WordPress is vulnerable to
generic ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15328 (IBM WebSphere Application Server 9.0, and 8.5 and IBM
WebSphere Applic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15325 (IBM WebSphere Application Server 9.0, and 8.5 and IBM
WebSphere Applic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15280 (IBM WebSphere Application Server - Liberty 17.0.0.3 through
26.0.0.8 N ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15064 (IBM WebSphere Application Server 9.0, and 8.5 and IBM
WebSphere Applic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15057 (IBM WebSphere Application Server - Liberty 17.0.0.3 through
26.0.0.7 i ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14996 (IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14981 (IBM WebSphere Application Server 9.0, and 8.5 and IBM
WebSphere Applic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14976 (IBM WebSphere Application Server - Liberty 17.0.0.3 through
26.0.0.8 i ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14974 (IBM WebSphere Application Server 8.5, and 9.0 traditional
could allow ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14973 (IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for
desktop can ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14959 (IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a
remote authen ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14958 (IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a
remote authen ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14893 (IBM Observability with Instana (Agent) Build 1.0.303 through
1.0.320 I ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14528 (IBM WebSphere Application Server 9.0, and 8.5 traditional
could allow ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14515 (IBM WebSphere Application Server 8.5, and 9.0 traditional
could allow ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14512 (IBM WebSphere Application Server 9.0, and 8.5 traditional is
vulnerabl ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14446 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to
broken ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14300 (The miniOrange Social Login and Register (Discord, Google,
Twitter, Li ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14234 (The WOLF WordPress plugin before 1.1.0 does not perform a
nonce or ca ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14224 (The Easy Appointments WordPress plugin through 3.12.26 does
not verify ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13692 (The PayU CommercePro Plugin WordPress plugin through 3.8.9
does not ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13690 (The UsersWP WordPress plugin before 1.2.67 does not validate
the sele ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13605 (The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title
attribu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13463 (IBM Cloud Pak System 2.3.5.0 could allow a local attacker to
obtain se ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13442 (IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to
reuse a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13423 (The Streamit WordPress theme through 4.5.0 does not perform
any author ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12939 (The Newsletters Lite plugin for WordPress is vulnerable to
Stored Cros ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12938 (The Newsletters Lite plugin for WordPress is vulnerable to
Stored Cros ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12476 (The Easy Digital Downloads plugin for WordPress is vulnerable
to Arbit ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12144 (The Wholesale for WooCommerce plugin for WordPress is
vulnerable to Pr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11974 (The wp-media-folder-addon WordPress plugin through 4.1.6 does
not vali ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11391 (Tanium addressed a SQL injection vulnerability in Patch.)
- TODO: check
+ NOT-FOR-US: Tanium
CVE-2026-11351 (The ShinyStat Analytics WordPress plugin before 1.0.17 does
not perfor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-XXXX [relay: use-after-free and double free when a remote relay sends
an event with an array as body]
- weechat 4.9.5-1 (bug #1142894)
NOTE:
https://github.com/weechat/weechat/security/advisories/GHSA-hx59-4hq9-6vmw
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea649b8a6c2338d6c9824610f81948bb2503fd7b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea649b8a6c2338d6c9824610f81948bb2503fd7b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits