Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3e2f532f by security tracker role at 2026-08-05T19:14:53+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,73 +1,73 @@
 CVE-2026-9205 (IBM Langflow OSS contains a weak cryptographic key derivation 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-9203 (A server-side request forgery vulnerability in Progress 
MarkLogic Serv ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-9201 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow an 
authenticated att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-9196 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow an 
authenticated att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-9195 (A cross-site scripting vulnerability in the Query Console of 
Progress  ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-9193 (An improper privilege management vulnerability in the Hadoop 
integrati ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-9192 (An authentication bypass vulnerability in the ODBC App Server 
of Progr ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-9190 (An HTTP request smuggling vulnerability in the HTTP App Server 
of Prog ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-9130 (IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization 
bypass  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-9081 (IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 
contai ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-9077 (IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote 
authentic ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-8709 (An improper privilege management vulnerability in the REST API 
documen ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-8478 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-8470 (IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 
1.0.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-8446 (IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication 
bypass ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-8400 (IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere 
Applic ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-8183 (IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 
1.0.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-8182 (IBM Langflow OSS 1.0.0 through 1.10.3 installations allow 
anyone on th ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-8029 (The ZTE Smart Life app contains an SQL injection vulnerability 
that al ...)
-       TODO: check
+       NOT-FOR-US: ZTE
 CVE-2026-7869 (IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path 
Traversal  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7726 (The Layouts for WPBakery plugin for WordPress is vulnerable to 
unautho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7693 (The Backup Migration plugin for WordPress is vulnerable to OS 
Command  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7658 (IBM Langflow OSS 1.0.0 through 1.10.3 does not properly 
validate the u ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7657 (IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow 
server-side ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7646 (IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read 
arbitrary f ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7557 (An improper verification of cryptographic signature 
vulnerability in t ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-7529 (The wiseCampaign \u2013 WooCommerce Conversions Made Easy 
plugin for W ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7520 (The MailChimp Forms by MailMunch plugin for WordPress is 
vulnerable to ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7456 (The Udimi Tools plugin for WordPress is vulnerable to 
unauthorized mod ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7444 (The Search Analytics for WP plugin for WordPress is vulnerable 
to Cros ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7441 (The Simple Yearly Archive plugin for WordPress is vulnerable to 
Stored ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7329 (An improper privilege management vulnerability in the SQL, 
SPARQL, and ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-7327 (An improper privilege management vulnerability in the REST API 
documen ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-7326 (A cross-site request forgery vulnerability in the Admin UI of 
Progress ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-7105 (The Xpro Addons plugin for WordPress is vulnerable to 
unauthorized cre ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-71294 (Cotonti CMS's Comments plugin deserializes user-supplied data 
without  ...)
        TODO: check
 CVE-2026-71293 (Statamic CMS's user-augmentation resolver, 
AugmentedUser::get() in src ...)
@@ -203,7 +203,7 @@ CVE-2026-71213 (Typemill's login endpoint (POST /tm/login, 
ControllerWebAuth::lo
 CVE-2026-71212 (xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp 
command-line in ...)
        TODO: check
 CVE-2026-71211 (MLflow's AI Gateway accepts an auth_config.api_base value when 
creatin ...)
-       TODO: check
+       NOT-FOR-US: mlflow
 CVE-2026-71210 (Mealie's AsyncSafeTransport SSRF guard 
(mealie/pkgs/safehttp/transport ...)
        TODO: check
 CVE-2026-71209 (audiobookshelf's authentication-exemption check 
(server/routers/Auth.j ...)
@@ -259,51 +259,51 @@ CVE-2026-70596 (Ghost is a Node.js content management 
system. From 4.9.0 until 6
 CVE-2026-70595 (Ghost is a Node.js content management system. From 6.26.0 
until 6.54.1 ...)
        TODO: check
 CVE-2026-70448 (Jenkins Ivy Report Plugin 1.2 and earlier does not configure 
its XML p ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70447 (Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 
and ear ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70446 (Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 
and earlie ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70445 (Missing permission checks in Jenkins Sauce OnDemand Plugin 
2.2.0 and e ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70444 (A missing permission check in Jenkins Violation Comments to 
GitLab Plu ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70443 (Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier 
does not ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70442 (Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and 
earlier ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70441 (Jenkins Summary Display Plugin 1.15 and earlier does not 
escape the jo ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70440 (Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and 
earlier ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70439 (Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not 
perform  ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70438 (A missing permission check in Jenkins Parameterized Remote 
Trigger Plu ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70437 (Jenkins Webhook Secret Credentials Provider Plugin 
16.v0cfa_f0215cf5 a ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70436 (Jenkins External Workspace Manager Plugin 1.4.1 and earlier 
does not p ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70435 (A missing permission check in Jenkins SCM-Manager Plugin 
1.11.1 and ea ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70434 (A cross-site request forgery (CSRF) vulnerability in Jenkins 
SCM-Manag ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70433 (Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 
and earl ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70432 (A cross-site request forgery (CSRF) vulnerability in Jenkins 
Multijob  ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70431 (Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier 
provides Groov ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70430 (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not 
restrict t ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70429 (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles 
case-insens ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70428 (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly 
identifi ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70427 (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not 
safely han ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70426 (In Remoting 3384.v60d89463d9e0 and earlier, except 
3355.3357.v931d3c99 ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70378 (imagecli's `carve <ratio>` pipeline operation (Carve::apply() 
in src/i ...)
        TODO: check
 CVE-2026-70377 (imagecli's `scale <ratio>` pipeline operation (Scale::apply() 
in src/i ...)
@@ -311,25 +311,25 @@ CVE-2026-70377 (imagecli's `scale <ratio>` pipeline 
operation (Scale::apply() in
 CVE-2026-70376 (Pluck CMS's admin panel relies solely on a Referer-header 
comparison ( ...)
        TODO: check
 CVE-2026-6972 (The SKT Skill Bar plugin for WordPress is vulnerable to Stored 
Cross-S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6639 (The AI Chatbot & Workflow Automation by AIWU plugin for 
WordPress is v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6627 (The WPFormify \u2013 Stripe Payments with Form and Checkout 
plugin for ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6147 (The LightSync Pro plugin for WordPress is vulnerable to 
arbitrary file ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6079 (The Material Dashboard plugin for WordPress is vulnerable to 
unauthori ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6020 (The ShopLentor plugin for WordPress is vulnerable to arbitrary 
functio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-67623 (Mistral Vibe before 2.23.3 contains a remote code execution 
vulnerabil ...)
        TODO: check
 CVE-2026-66747 (Zbtlink router firmware ships an embedded remote-control 
implant, ENDL ...)
        TODO: check
 CVE-2026-63457 (A potential denial of service vulnerability exists in HPE 
Integrated L ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-61891 (In Eclipse Theia versions up to and including 1.73.1, the 
`@theia/file ...)
-       TODO: check
+       NOT-FOR-US: Eclipse
 CVE-2026-61486 (** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow 
vulnerabil ...)
        TODO: check
 CVE-2026-61485 (** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with 
Excessive Size  ...)
@@ -339,25 +339,25 @@ CVE-2026-61484 (** UNSUPPORTED WHEN ASSIGNED ** 
Deserialization of Untrusted Dat
 CVE-2026-61483 (** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion 
vulnerability i ...)
        TODO: check
 CVE-2026-60053 (Insufficient Session Expiration vulnerability in Apache 
Answer.  This  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-60023 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-60009 (In Eclipse Theia versions up to and including 1.73.1, the 
`@theia/file ...)
-       TODO: check
+       NOT-FOR-US: Eclipse
 CVE-2026-5651 (The Askeet plugin for WordPress is vulnerable to SQL Injection 
via the ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-5581 (The Multi Uploader for Gravity Forms plugin for WordPress is 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-5116 (The Contact Form 7 \u2013 Dynamic Text Extension plugin for 
WordPress  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-5108 (The Super Progressive Web Apps plugin for WordPress is 
vulnerable to S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-59675 (When API audit logging is enabled, the middleware reads the 
entire HTT ...)
        TODO: check
 CVE-2026-55998 (The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the 
cluster ...)
        TODO: check
 CVE-2026-55997 (Rancher issues long-lived registration tokens to authenticate 
nodes an ...)
-       TODO: check
+       NOT-FOR-US: SUSE
 CVE-2026-55996 (A denial-of-service vulnerability was identified in multiple 
TLS liste ...)
        TODO: check
 CVE-2026-55747 (The pocketflow-coding-agent cookbook example in 
The-Pocket/PocketFlow  ...)
@@ -371,17 +371,17 @@ CVE-2026-54416 (Pluck CMS through 4.7.21 restricts 
dangerous file uploads in its
 CVE-2026-53992 (ProjectSend r2029 contains a reflected cross-site scripting 
vulnerabil ...)
        TODO: check
 CVE-2026-50749 (Improper Authorization vulnerability in Apache Answer.  This 
issue aff ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-4431 (The Easy Post Submission plugin for WordPress is vulnerable to 
unautho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-49331 (A flaw was found in openshift/oauth-proxy. On paths configured 
to bypa ...)
        TODO: check
 CVE-2026-48912 (Improper Input Validation vulnerability in Apache Answer.  
This issue  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48911 (Insufficient Verification of Data Authenticity vulnerability 
in Apache ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48834 (Improper Handling of Length Parameter Inconsistency 
vulnerability in A ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48168 (PraisonAI is a multi-agent teams system. In versions prior to 
4.6.40,  ...)
        TODO: check
 CVE-2026-46581 (In Eclipse Mojarra versions 2.3 and following, URL handing in 
`Default ...)
@@ -401,11 +401,11 @@ CVE-2026-20313 (As part of Cisco's ongoing commitment to 
proactive security and
 CVE-2026-20312 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20311 (A vulnerability in the web-based management interface of Cisco 
IOS XE  ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20310 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20308 (A vulnerability in the web-based management interface of Cisco 
IOS XE  ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20304 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20303 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
@@ -413,33 +413,33 @@ CVE-2026-20303 (As part of Cisco's ongoing commitment to 
proactive security and
 CVE-2026-20301 (A vulnerability in the Extensible Messaging Client Protocol 
(XMCP), al ...)
        TODO: check
 CVE-2026-20294 (A vulnerability in the web-based management interface of Cisco 
Catalys ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20289 (A vulnerability in the logging subsystem of Cisco RoomOS could 
allow a ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20288 (A vulnerability in the web-based management interface of Cisco 
IMC cou ...)
        TODO: check
 CVE-2026-20273 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20272 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20271 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20270 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20269 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20268 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20267 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20263 (A vulnerability in the Blocks Extensible Exchange Protocol 
(BEEP) feat ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20200 (A vulnerability in the web-based management interface of Cisco 
IMC cou ...)
        TODO: check
 CVE-2026-20198 (A vulnerability in the web-based management interface of Cisco 
Integra ...)
        TODO: check
 CVE-2026-20124 (A vulnerability in the Simple Network Management Protocol 
(SNMP) subsy ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20028 (A vulnerability in the network driver of Cisco Terminal 
Service (TS) A ...)
        TODO: check
 CVE-2026-18933 (The wp-downloadmanager WordPress plugin, in version 1.68.11 
(also affe ...)
@@ -447,37 +447,37 @@ CVE-2026-18933 (The wp-downloadmanager WordPress plugin, 
in version 1.68.11 (als
 CVE-2026-18927 (A vulnerability was determined in imranrisal-dev 
Student-Management-Sy ...)
        TODO: check
 CVE-2026-18881 (The TableOn \u2013 WordPress Posts Table Filterable plugin for 
WordPre ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18531 (IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a 
remote at ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18485 (There is a local privilege escalation vulnerability recently 
discovere ...)
-       TODO: check
+       NOT-FOR-US: National Instruments
 CVE-2026-17633 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17632 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17630 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17626 (IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an 
authenti ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17625 (IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 
1.0.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17624 (IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 
1.0.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17623 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17617 (IBM Application Gateway Operator 22.2 through 26.06 is 
vulnerable to S ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17613 (Penpot\u2019s ::import-binfile RPC command lacks authorization 
on the  ...)
        TODO: check
 CVE-2026-17578 (Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do 
not enfor ...)
        TODO: check
 CVE-2026-17532 (The Seraphinite Accelerator plugin for WordPress is vulnerable 
to Refl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17506 (The Independent Analytics plugin for WordPress is vulnerable 
to Stored ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17505 (The Translate Multilingual sites \u2013 TranslatePress plugin 
for Word ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16443 (A flaw was found in the SAML metadata import functionality of 
the keyc ...)
        TODO: check
 CVE-2026-16442 (A flaw was found in the SAML broker component of Keycloak, 
which is us ...)
@@ -491,9 +491,9 @@ CVE-2026-16071 (A flaw was found in the LDAP storage 
provider of Keycloak, which
 CVE-2026-16022 (@oblique/cli 15.4.0 contains an OS command injection 
vulnerability in  ...)
        TODO: check
 CVE-2026-15979 (The Content Egg \u2013 Affiliate Product Importer & Price 
Comparison p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15656 (IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set 
the secure ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-15587 (Improper Privilege Management in Google SecOps (Chronicle 
SOAR) versio ...)
        TODO: check
 CVE-2026-15573 (A flaw was found in Keycloak's Authorization Services. The 
component r ...)
@@ -501,51 +501,51 @@ CVE-2026-15573 (A flaw was found in Keycloak's 
Authorization Services. The compo
 CVE-2026-15572 (A flaw was found in Keycloak's Dynamic Client Registration 
(DCR) secur ...)
        TODO: check
 CVE-2026-15452 (The Smash Balloon Social Photo Feed \u2013 Easy Social Feeds 
Plugin pl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15281 (The User Access Manager plugin for WordPress is vulnerable to 
Second-O ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14587 (Neo4j's Bolt modern handshake decoder treats an overlong 
capability bi ...)
        TODO: check
 CVE-2026-14574 (In Eclipse Theia versions 0.7.0 and up until including 1.73.1, 
the `Pr ...)
-       TODO: check
+       NOT-FOR-US: Eclipse
 CVE-2026-14304 (In Eclipse Accessibility Tools Framework (ACTF) versions up to 
1.6.0 ( ...)
        TODO: check
 CVE-2026-13477 (IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 
15 Inte ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12762 (IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, 
and 26.0 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12730 (IBM Business Automation Workflow containers and traditional 
26.0.0, 25 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12609 (In Eclipse Theia versions 1.66.0 and up until including 
1.73.1, the `@ ...)
-       TODO: check
+       NOT-FOR-US: Eclipse
 CVE-2026-12410 (Link following vulnerability in the Uninstaller component in 
CCleaner  ...)
        TODO: check
 CVE-2026-12000 (The Page and Post Restriction plugin for WordPress is 
vulnerable to Se ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11977 (The WP Post Author \u2013 Author Box, Multiple Authors, Guest 
Authors  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11969 (The WP TripAdvisor Review Slider plugin for WordPress is 
vulnerable to ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11920 (The JoomSport \u2013 for Sports: Team & League, Football, 
Hockey & mor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11454 (The Groundhogg \u2014 CRM, Newsletters, and Marketing 
Automation plugi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-10716 (Directus contains an authenticated SQL injection vulnerability 
in the  ...)
-       TODO: check
+       NOT-FOR-US: Directus
 CVE-2026-10547 (IBM Langflow OSS 1.0.0 through 1.10.3 does not properly 
validate owner ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-10128 (IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated 
users can e ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-10090 (A flaw was found in the Application Subscription controller 
(multiclus ...)
        TODO: check
 CVE-2026-10059 (A flaw was found in the Multicluster Engine for Kubernetes 
ClusterCura ...)
        TODO: check
 CVE-2026-10025 (IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 
15 Inte ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-0931 (Denial-of-service vulnerability in M-Files Server versions 
before26.5. ...)
-       TODO: check
+       NOT-FOR-US: M-Files
 CVE-2026-0516 (A improper neutralization of HTTP Headers for Scripting Syntax 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2025-70962 (Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect 
Access Contro ...)
        TODO: check
 CVE-2026-54876 (Issue summary: A malicious TLS server can cause a memory leak 
in a TLS ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e2f532fe33f56322fc70edba9ef8cc5ec7884ed

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e2f532fe33f56322fc70edba9ef8cc5ec7884ed
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to