Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9decb637 by security tracker role at 2026-08-04T07:13:11+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-8508 (An improper authentication vulnerability in the 
"social_login.cgi" CGI ...)
-       TODO: check
+       NOT-FOR-US: Zyxel
 CVE-2026-6837 (A post-authentication command injection vulnerability in the 
"export-c ...)
-       TODO: check
+       NOT-FOR-US: Zyxel
 CVE-2026-69249 (python-cryptography is a package designed to expose 
cryptographic prim ...)
        TODO: check
 CVE-2026-69248 (cryptography is a package designed to expose cryptographic 
primitives  ...)
@@ -25,11 +25,11 @@ CVE-2026-69192 (ip-address is a library for parsing and 
manipulating IPv4 and IP
 CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication 
for ever ...)
        TODO: check
 CVE-2026-68981 (Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP 
requests fo ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-68980 (Apache NiFi 2.0.0 through 2.10.0 support creating, reading, 
and deleti ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context 
update R ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() 
function  ...)
        TODO: check
 CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows 
attackers  ...)
@@ -59,41 +59,41 @@ CVE-2026-67616 (Camaleon CMS through 2.9.2, fixed in commit 
88ab703, contains a
 CVE-2026-67599 (ClearOS 7.9 contains an OS command injection vulnerability in 
the Log  ...)
        TODO: check
 CVE-2026-67598 (Emlog Pro through 2.6.23 contains a disabled TLS certificate 
validatio ...)
-       TODO: check
+       NOT-FOR-US: Emlog
 CVE-2026-66326 (Missing authorization in Microsoft Edge (Chromium-based) 
allows an una ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66325 (Server-side request forgery (ssrf) in Microsoft Edge 
(Chromium-based)  ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66322 (Origin validation error in Microsoft Edge (Chromium-based) 
allows an u ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66321 (Access of resource using incompatible type ('type confusion') 
in Micro ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66318 (Origin validation error in Microsoft Edge (Chromium-based) 
allows an u ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66317 (Origin validation error in Microsoft Edge (Chromium-based) 
allows an u ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66316 (Origin validation error in Microsoft Edge (Chromium-based) 
allows an u ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66315 (Use after free in Microsoft Edge (Chromium-based) allows an 
unauthoriz ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66314 (Time-of-check time-of-use (toctou) race condition in Microsoft 
Edge (C ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66313 (Origin validation error in Microsoft Edge (Chromium-based) 
allows an u ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66312 (Buffer over-read in Microsoft Edge (Chromium-based) allows an 
authoriz ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66311 (Missing authorization in Microsoft Edge (Chromium-based) 
allows an una ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66310 (External control of file name or path in Microsoft Edge for 
Android al ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66296 (Improper Neutralization of Input During Web Page Generation 
(XSS) vuln ...)
        TODO: check
 CVE-2026-66065 (Ouroboros is a local-first runtime for AI coding agents that 
records t ...)
        TODO: check
 CVE-2026-65804 (Improper control of generation of code ('code injection') in 
Microsoft ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-65802 (External control of file name or path in Microsoft Edge for 
Android al ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-64565 (In the Linux kernel, the following vulnerability has been 
resolved:  I ...)
        TODO: check
 CVE-2026-64564 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
@@ -105,9 +105,9 @@ CVE-2026-64562 (In the Linux kernel, the following 
vulnerability has been resolv
 CVE-2026-64561 (In the Linux kernel, the following vulnerability has been 
resolved:  K ...)
        TODO: check
 CVE-2026-62870 (Use after free in Microsoft Office Excel allows an 
unauthorized attack ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-62354 (Authorization handling for Parameter Context validation 
requests in Ap ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-58139 (The DuckDB AWS extension for DuckDB contains a security policy 
bypass  ...)
        TODO: check
 CVE-2026-56845 (An unauthenticated path traversal (LFI) vulnerability exists 
under /cu ...)
@@ -115,7 +115,7 @@ CVE-2026-56845 (An unauthenticated path traversal (LFI) 
vulnerability exists und
 CVE-2026-52521 (A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows 
authenticated  ...)
        TODO: check
 CVE-2026-52520 (Emlog CMS <= 2.6.14 contains a stored cross-site scripting 
(XSS) vulne ...)
-       TODO: check
+       NOT-FOR-US: Emlog
 CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md 
plugin  ...)
        TODO: check
 CVE-2026-51775 (SQL injection vulnerability in Fastadmin v.1.6.1.20250430 
allows an at ...)
@@ -127,19 +127,19 @@ CVE-2026-49132 (OPNsense before 26.1.9 contains a stored 
cross-site scripting vu
 CVE-2026-49131 (OPNsense before 26.1.9 contains a stored cross-site scripting 
vulnerab ...)
        TODO: check
 CVE-2026-48399 (Adobe Campaign Classic (ACC) is affected by a Violation of 
Secure Desi ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48333 (Adobe Campaign Classic (ACC) is affected by an Incorrect 
Authorization ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48331 (Adobe Campaign Classic (ACC) is affected by a Server-Side 
Request Forg ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48330 (Adobe Campaign Classic (ACC) is affected by an Improper 
Neutralization ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48326 (Adobe Campaign Classic (ACC) is affected by an Improper 
Neutralization ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48323 (Adobe Campaign Classic (ACC) is affected by an Improper 
Neutralization ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48317 (Adobe Campaign Classic (ACC) is affected by an Improper 
Neutralization ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-48115 (Misskey is an open source, federated social media platform. 
All Misske ...)
        TODO: check
 CVE-2026-48113 (Chisel is a TCP/UDP tunnel, transported over HTTP and secured 
via SSH. ...)
@@ -173,7 +173,7 @@ CVE-2026-18737 (Shlink contains a blind SQL injection 
vulnerability that allows
 CVE-2026-18736 (Shlink contains a server-side request forgery vulnerability 
that allow ...)
        TODO: check
 CVE-2026-18733 (A prompt injection vulnerability in the shell tool in Amazon 
Strands A ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18723 (A vulnerability was determined in diaowen DWSurvey up to 
6.14.0. The a ...)
        TODO: check
 CVE-2026-18722 (A vulnerability was found in diaowen DWSurvey up to 6.14.0. 
Impacted i ...)
@@ -195,9 +195,9 @@ CVE-2026-18682 (A security flaw has been discovered in 
OpenAkita up to 1.27.12.
 CVE-2026-18667 (A vulnerability in Tenable Sensor Proxy allows a remote 
attacker to ex ...)
        TODO: check
 CVE-2026-18655 (Improper restriction of intended endpoints in the RabbitMQ 
broker conn ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18654 (Key exchange without entity authentication in the EMR SSH 
helper comma ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18648 (A vulnerability was detected in Blix Email Blue Mail Calendar 
App 2.2. ...)
        TODO: check
 CVE-2026-18647 (A security vulnerability has been detected in jina-ai reader 
up to 157 ...)
@@ -221,61 +221,61 @@ CVE-2026-17614 (A path traversal flaw was found in 
WildFly's domain mode   imple
 CVE-2026-16881 (A code injection vulnerability exists in the LINE Android app 
prior to ...)
        TODO: check
 CVE-2026-16623 (The Create Block  WordPress plugin before 2.10.0 does not 
correctly es ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16618 (The Improve SEO WordPress plugin through 2.0.11 does not 
properly vali ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16548 (The Chat Widget: Floating Customer Support Button for 30+ 
Channels, Su ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16547 (The REST API Log WordPress plugin before 1.7.1 does not bind 
the token ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16546 (The Wired Impact Volunteer Management WordPress plugin before 
2.8.2 do ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16536 (The Simple Google Calendar Outlook Events Widget WordPress 
plugin befo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16296 (The Clearfy Cache  WordPress plugin before 2.4.3 does not 
validate the ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16295 (The Clearfy Cache  WordPress plugin before 2.4.3 does not 
perform a ca ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16293 (The PowerPress Podcasting plugin by Blubrry WordPress plugin 
before 11 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16070 (The Brizy  WordPress plugin before 2.8.19 does not properly 
verify aut ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16069 (The Brizy  WordPress plugin before 2.8.19 does not sanitize or 
escape  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16068 (The Brizy  WordPress plugin before 2.8.19 does not properly 
restrict w ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16056 (The Contest Gallery  WordPress plugin before 30.0.7 does not 
perform a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16035 (The miniOrange 2FA  WordPress plugin before 6.2.7 does not 
restrict wh ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15958 (The Easy Integration for Dropbox  WordPress plugin before 
2.2.0 does n ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15233 (The Nested Pages WordPress plugin before 3.2.15 does not 
properly esca ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14939 (The Visualizer  WordPress plugin before 4.0.6 does not 
restrict a user ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14872 (The Database for Contact Form 7, WPforms, Elementor forms 
WordPress pl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14848 (The Paid Membership Subscriptions  WordPress plugin before 
3.0.8 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14824 (The Quiz and Survey Master (QSM)  WordPress plugin before 
11.2.2 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14818 (A path traversal vulnerability in the CLI command used to 
execute conf ...)
-       TODO: check
+       NOT-FOR-US: Zyxel
 CVE-2026-14816 (The GDPR Framework By Data443 WordPress plugin before 2.4.0 
does not p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12698 (The wpForo Forum WordPress plugin before 3.1.3 does not 
restrict which ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11836 (Insufficient verification of data authenticity in Caliptra 
Core ROM an ...)
        TODO: check
 CVE-2026-11835 (Time-of-check time-of-use (TOCTOU) vulnerability combined with 
missing ...)
        TODO: check
 CVE-2026-11366 (The MonsterInsights  WordPress plugin before 11.1.0 does not 
correctly ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-10849 (The hawkBit device management client in subsys/mgmt/hawkbit 
accumulate ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10526 (The EmbedPress  WordPress plugin before 4.6.1 does not 
validate user-s ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-8794 (PaperCut NG/MF contains an observable timing discrepancy in its 
authen ...)
        NOT-FOR-US: PaperCut
 CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive 
authentication att ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9decb6370a5985fbb1c76039e0449d199bf07203

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9decb6370a5985fbb1c76039e0449d199bf07203
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to