Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
012d052b by security tracker role at 2026-08-03T19:14:38+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -65,11 +65,11 @@ CVE-2026-68585 (SiYuan versions before v3.7.3 contain a
metadata disclosure vuln
CVE-2026-68584 (SiYuan versions before v3.7.3 contain an authentication bypass
vulnera ...)
TODO: check
CVE-2026-67612 (OpenEMR through 8.2.0 contains a stored cross-site scripting
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-67611 (OpenEMR through 8.2.0 contains an authentication bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-67610 (OpenEMR through 8.2.0 contains an improper authentication
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-67609 (Telenia Software TVox 26.5.3 and prior 26.x versions, and
24.9.21 and ...)
TODO: check
CVE-2026-67608 (Telenia Software TVox 26.5.3 and prior 26.x versions, and
24.9.21 and ...)
@@ -91,23 +91,23 @@ CVE-2026-61372 (Improper Limitation of a Pathname to a
Restricted Directory ('Pa
CVE-2026-60011 (Sharp and Toshiba Tec MFPs (multifunction printers) fail to
properly a ...)
TODO: check
CVE-2026-59913 (Dell Display and Peripheral Manager (DDPM Mac), versions prior
to 2.3. ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-59912 (Dell Display and Peripheral Manager (DDPM Mac), versions prior
to 2.3. ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56609 (HCL iControl is affected by Weak SSL/TLS Version Supported
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56608 (HCL iControl is affected by Missing Access Control
vulnerability. The ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-41453 (Krayin CRM before 2.2.4 contains a blind SQL injection
vulnerability i ...)
TODO: check
CVE-2026-41452 (Krayin CRM 2.2.4 contains a missing authentication
vulnerability in th ...)
TODO: check
CVE-2026-40717 (Dell Monitor driver, version 1.0.0.0, contains an Improper
Link Resolu ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-39932 (OpenEMR through 8.2.0 contains a remote code execution
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-39931 (OpenEMR through 8.2.0 contains an authenticated SQL injection
vulnerab ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-38447 (osTicket 1.18.3 generates API keys using a predictable
construction ba ...)
TODO: check
CVE-2026-38446 (A stored cross-site scripting (XSS) vulnerability exists in
osTicket 1 ...)
@@ -119,23 +119,23 @@ CVE-2026-33591 (A vulnerability in Wapt Server before
version 2.6.1.17813 allows
CVE-2026-2346 (Authorization bypass through User-Controlled key vulnerability
in Menu ...)
TODO: check
CVE-2026-28147 (Missing Authorization vulnerability in Unlimited Elements
Unlimited El ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-21555 (In modem, there is a possible improper input validation. This
could le ...)
- TODO: check
+ NOT-FOR-US: Unisoc
CVE-2026-21554 (In modem, there is a possible improper input validation. This
could le ...)
- TODO: check
+ NOT-FOR-US: Unisoc
CVE-2026-21553 (In modem, there is a possible improper input validation. This
could le ...)
- TODO: check
+ NOT-FOR-US: Unisoc
CVE-2026-21552 (In modem, there is a possible improper input validation. This
could le ...)
- TODO: check
+ NOT-FOR-US: Unisoc
CVE-2026-21551 (In modem, there is a possible improper input validation. This
could le ...)
- TODO: check
+ NOT-FOR-US: Unisoc
CVE-2026-21550 (In modem, there is a possible improper input validation. This
could le ...)
- TODO: check
+ NOT-FOR-US: Unisoc
CVE-2026-21549 (In modem, there is a possible improper input validation. This
could le ...)
- TODO: check
+ NOT-FOR-US: Unisoc
CVE-2026-21548 (In nr modem, there is a possible improper input validation.
This could ...)
- TODO: check
+ NOT-FOR-US: Unisoc
CVE-2026-18718 (Ghidra contains an arbitrary code execution vulnerability in
the Swift ...)
TODO: check
CVE-2026-18651 (A flaw was found in 389 Directory Server. During SASL PLAIN
authentica ...)
@@ -155,7 +155,7 @@ CVE-2026-18612 (A flaw has been found in GL-iNet GL-MT3000
up to 4.4.5. This vul
CVE-2026-18610 (A vulnerability was detected in NewType WebEIP up to 3.0. This
affects ...)
TODO: check
CVE-2026-18607 (A security vulnerability has been detected in Wavlink WN572,
WN570H, W ...)
- TODO: check
+ NOT-FOR-US: Wavlink
CVE-2026-18606 (A weakness has been identified in Razer RzUpdateService
1.10.14.0. Aff ...)
TODO: check
CVE-2026-18605 (A security flaw has been discovered in CheckMAL AppCheck Pro
3.1.43.10 ...)
@@ -179,7 +179,7 @@ CVE-2026-18592 (A security flaw has been discovered in
osCommerce 4.14.63493. Af
CVE-2026-18591 (A vulnerability was identified in Meesho Online Shopping App
up to 202 ...)
TODO: check
CVE-2026-18590 (A vulnerability was determined in Wavlink WL-NU516U1
708c073-mt7628. A ...)
- TODO: check
+ NOT-FOR-US: Wavlink
CVE-2026-18574 (An authentication bypass vulnerability in Check Point Security
Managem ...)
TODO: check
CVE-2026-18508 (A flaw was found in GNU tar. When extracting an archive with
the --one ...)
@@ -189,7 +189,7 @@ CVE-2026-18477 (A TOCTOU (Time-of-Check Time-of-Use)
vulnerability in GNU tar's
CVE-2026-18248 (@fastify/aws-lambda version 6.4.0 decorates each Fastify
request with ...)
TODO: check
CVE-2026-18243 (Certain HP DesignJet products may be potentially vulnerable to
cross-s ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-15430 (Improper access control in the IRP_MJ_WRITE command interface
in Wellb ...)
TODO: check
CVE-2026-12259 (In nltk version 3.9.4, the
`nltk.downloader.Downloader._download_packa ...)
@@ -197,19 +197,19 @@ CVE-2026-12259 (In nltk version 3.9.4, the
`nltk.downloader.Downloader._download
CVE-2026-0392 (eParakst\u012bt\u0101js 3.0 for Windows before version 1.10.0
retrieve ...)
TODO: check
CVE-2025-9291 (A certification validation weakness exists in communication
between af ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-15631 (A cryptographic weakness exists in affected Omada devices
where site c ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-15630 (A race condition exists in the cloud-based Omada device
adoption proce ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-15629 (A cryptographic weakness exists in the Omada adoption protocol
where s ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-15628 (Affected Omada devices rely on embedded certificates that are
shared a ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-15627 (A cryptographic weakness exists in the Omada adoption
protocol. The pr ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-15544 (A cryptographic weakness exists in the Omada device adoption
process. ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-18089 (Net::SAML2 versions before 0.86 for Perl allow SAML
authentication byp ...)
NOT-FOR-US: Net-SAML2 Perl module
CVE-2026-18108 (Net::SAML2 versions before 0.86 for Perl allow authentication
bypass b ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/012d052b02a2c9ccc0f963f670bbbb8529f88865
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/012d052b02a2c9ccc0f963f670bbbb8529f88865
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits