Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c07613ad by security tracker role at 2026-08-07T07:14:25+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-8325 (A maliciously crafted PDF file, when parsed through Autodesk 
Revit, ca ...)
-       TODO: check
+       NOT-FOR-US: Autodesk
 CVE-2026-7406 (A maliciously crafted BMP file, when parsed through certain 
Autodesk p ...)
-       TODO: check
+       NOT-FOR-US: Autodesk
 CVE-2026-7405 (A maliciously crafted TIF file, when parsed through certain 
Autodesk p ...)
-       TODO: check
+       NOT-FOR-US: Autodesk
 CVE-2026-71555 (PILOS (Platform for Interactive Live-Online Seminars) is a 
frontend fo ...)
        TODO: check
 CVE-2026-71554 (h2 is a pure-Python implementation of a HTTP/2 protocol stack. 
Version ...)
@@ -57,7 +57,7 @@ CVE-2026-70639 (llama.cpp builds b1886 through b7445 contain 
a null pointer dere
 CVE-2026-70638 (llama.cpp builds b1886 through b7445 contain an integer 
overflow vulne ...)
        TODO: check
 CVE-2026-70636 (Flowise through 3.1.4 contains an authentication bypass 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-70635 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains 
an out-o ...)
        TODO: check
 CVE-2026-70634 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains 
an out-o ...)
@@ -81,7 +81,7 @@ CVE-2026-70558 (Dinky's POST /download/uploadFromRsByLocal 
handler passes the ca
 CVE-2026-70557 (diboot-core's POST /common/load-related-data endpoint resolves 
caller- ...)
        TODO: check
 CVE-2026-70332 (Server-side request forgery (ssrf) in Microsoft Office 
SharePoint allo ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-69125
        REJECTED
 CVE-2026-69124
@@ -103,7 +103,7 @@ CVE-2026-68942
 CVE-2026-68941
        REJECTED
 CVE-2026-68823 (Exposed dangerous method or function in Azure Confidential 
Ledger allo ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-67689 (SQL Injection vulnerability in FineAdmin V1.0 allows a remote 
attacker ...)
        TODO: check
 CVE-2026-67688 (ICS-Park Smart Park Management System v2.0 contains an 
unrestricted fi ...)
@@ -111,19 +111,19 @@ CVE-2026-67688 (ICS-Park Smart Park Management System 
v2.0 contains an unrestric
 CVE-2026-67687 (Insecure Permissions vulnerability in ics-park v.2.0 allows a 
remote a ...)
        TODO: check
 CVE-2026-67622 (Flowise through 3.1.4 contains an insecure direct object 
reference vul ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-67621 (Flowise through 3.1.4 contains a missing authorization 
vulnerability t ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-67434 (PHP_CodeSniffer tokenizes PHP files and detects violations of 
a define ...)
        TODO: check
 CVE-2026-67422 (pymdown-extensions is a collection of extensions for the 
Python Markdo ...)
        TODO: check
 CVE-2026-65668 (Improper access control in Microsoft Purview eDiscovery allows 
an auth ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-65667 (Missing authorization in Microsoft Teams allows an 
unauthorized attack ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-65400 (An authentication issue was addressed with improved state 
management.  ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-64677 (Anki is a program for creating and reviewing flashcards. Prior 
to 25.0 ...)
        TODO: check
 CVE-2026-64665 (Statamic is a Laravel and Git powered content management 
system (CMS). ...)
@@ -147,19 +147,19 @@ CVE-2026-63725 (sysPass's 
FileBackupService::doBackupFiles() in lib/SP/Services/
 CVE-2026-63637 (Dgraph is an open source distributed GraphQL database. Prior 
to 25.3.8 ...)
        TODO: check
 CVE-2026-63508 (Missing authentication for critical function in Microsoft 
Planetary Co ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-62918 (Improper verification of cryptographic signature in Microsoft 
Teams al ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-62896 (Improper authentication in Microsoft Teams allows an 
authorized attack ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-62873 (Improper verification of cryptographic signature in Microsoft 
365 Admi ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-62857 (Fedify is a TypeScript library for building federated server 
apps powe ...)
        TODO: check
 CVE-2026-62836 (Improper restriction of communication channel to intended 
endpoints in ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-62830 (Missing authorization in Azure SRE Agent allows an authorized 
attacker ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-61632 (PyMdown Extensions is a set of extensions for the 
Python-Markdown mark ...)
        TODO: check
 CVE-2026-5857 (Contiki-NG's MQTT client parse_publish_vhdr() in 
os/net/app-layer/mqtt ...)
@@ -169,15 +169,15 @@ CVE-2026-5856 (Contiki-NG's DNS/mDNS resolver skip_name() 
in os/services/resolv/
 CVE-2026-5855 (Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in 
os/services/lwm2m/lw ...)
        TODO: check
 CVE-2026-5336 (The DataPress (Dataverse Integration) WordPress plugin before 
2.91 doe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-59118 (Improper authorization in Microsoft Power Apps allows an 
unauthorized  ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-59115 ('.../...//' in Microsoft Entra Provisioning Service 
(SyncFabric) allow ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-56162 (Improper authentication in Azure SQL Database allows an 
unauthorized a ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-56161 (Improper access control in Azure Logic Apps allows an 
authorized attac ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-54717 (Silverstripe CMS is an open source content management system. 
Prior to ...)
        TODO: check
 CVE-2026-53984 (Ground Station prior to0.6.0 contains an unauthenticated 
database-dest ...)
@@ -185,19 +185,19 @@ CVE-2026-53984 (Ground Station prior to0.6.0 contains an 
unauthenticated databas
 CVE-2026-53983 (Ground Station prior to0.6.0contains an unauthenticated blind 
server-s ...)
        TODO: check
 CVE-2026-50515 (Deserialization of untrusted data in Azure Service Bus allows 
an autho ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-50481 (Modification of assumed-immutable data (maid) in Azure Active 
Director ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-50159 (Mermaid is a JavaScript tool that uses Markdown-inspired text 
to creat ...)
        TODO: check
 CVE-2026-49746 (Software installed and run as a non-privileged user may 
conduct improp ...)
-       TODO: check
+       NOT-FOR-US: Imagination Technologies
 CVE-2026-49391 (Frappe is a full-stack web application framework. Prior to 
16.19.0 and ...)
        TODO: check
 CVE-2026-49163 (Improper limitation of a pathname to a restricted directory 
('path tra ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-49005 (The root password hash of the device can be obtained through 
unencrypt ...)
-       TODO: check
+       NOT-FOR-US: ZTE
 CVE-2026-48088 (OpenReception's appointment booking software provides an 
end-to-end en ...)
        TODO: check
 CVE-2026-48087 (OpenReception's appointment booking software provides an 
end-to-end en ...)
@@ -249,9 +249,9 @@ CVE-2026-45414 (Decidim is a participatory democracy 
framework. Prior to 0.31.5
 CVE-2026-45378 (Decidim is a participatory democracy framework. Prior to 
0.30.9, from  ...)
        TODO: check
 CVE-2026-45204 (Software installed and run as a non-privileged user may 
conduct improp ...)
-       TODO: check
+       NOT-FOR-US: Imagination Technologies
 CVE-2026-45198 (Kernel software from a non-secure operating system on a 
platform with  ...)
-       TODO: check
+       NOT-FOR-US: Imagination Technologies
 CVE-2026-43632 (llama.cpp builds b7492 through the latest b9060 contains a 
use-after-f ...)
        TODO: check
 CVE-2026-43631 (llama.cpp builds b7492 through the latest b9060 contains a 
use-after-f ...)
@@ -267,15 +267,15 @@ CVE-2026-43627 (llama.cpp builds b1283 through b9058 
contain an integer overflow
 CVE-2026-41861 (Path Traversal in BOSH-Ecosystem / BOSH allows an 
IaaS-metadata attack ...)
        TODO: check
 CVE-2026-3418 (The System REST API accepts user-supplied file uploads without 
enforci ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2026-3415 (The XML and schema validation functionalities within the 
SchemaValidat ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2026-33181
        REJECTED
 CVE-2026-1289 (A maliciously crafted PDF file, when parsed through Autodesk 
Revit, ca ...)
-       TODO: check
+       NOT-FOR-US: Autodesk
 CVE-2026-19196 (A vulnerability was found in SourceCodester Photo Share 
Website 1.0. T ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-19195 (A vulnerability has been found in V-Secure Jingyun Antivirus 
2.4.2.39. ...)
        TODO: check
 CVE-2026-19193 (A flaw has been found in Jiangmin Antivirus 21. Impacted is 
the functi ...)
@@ -291,27 +291,27 @@ CVE-2026-19189 (A security flaw has been discovered in 
Power Sofware PowerISO 9.
 CVE-2026-19127 (An issue in the billing and license activation subsystem 
allows remote ...)
        TODO: check
 CVE-2026-19111 (Insecure direct object reference in the mongodb_memory, 
elasticsearch_ ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-19110 (A vulnerability was determined in DataGear up to 5.0.0. The 
impacted e ...)
        TODO: check
 CVE-2026-19108 (A vulnerability was found in MZ Automation libiec61850 up to 
1.6.1. Th ...)
        TODO: check
 CVE-2026-19071 (A flaw has been found in itsourcecode Hospital Management 
System 1.0.  ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-19070 (A vulnerability was detected in itsourcecode Hospital 
Management Syste ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-19069 (A security vulnerability has been detected in itsourcecode 
Hospital Ma ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-19068 (A weakness has been identified in itsourcecode Hospital 
Management Sys ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-19067 (A security flaw has been discovered in itsourcecode Hospital 
Managemen ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-19066 (A vulnerability was identified in SourceCodester Online 
Examination &  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-19065 (A vulnerability was determined in SourceCodester Online 
Examination &  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-19064 (A vulnerability was found in SourceCodester Online Examination 
& Learn ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-19062 (A vulnerability has been found in chiuwingyan house up to 
dea6bcceaebe ...)
        TODO: check
 CVE-2026-19061 (A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. 
Affected ...)
@@ -327,33 +327,33 @@ CVE-2026-19054 (A vulnerability was detected in Lspace-io 
lspace-server up to 79
 CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser 
reads web ad ...)
        TODO: check
 CVE-2026-18367 (A privilege escalation vulnerability allows local users to 
execute arb ...)
-       TODO: check
+       NOT-FOR-US: Sophos
 CVE-2026-17264 (Opening a crafted DICOM file containing malicious 
JPEG-compressed pixe ...)
        TODO: check
 CVE-2026-17032 (Multiple Supsystic Pro plugins were distributed with malicious 
code th ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16620 (The WPC Name Your Price for WooCommerce WordPress plugin 
before 2.2.5  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16619 (The miniOrange 2FA WordPress plugin before 6.2.8 does not 
correctly li ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16265 (The WP Maps  WordPress plugin before 4.9.7 does not perform a 
capabili ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16263 (The WP Maps  WordPress plugin before 4.9.7 does not perform a 
capabili ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16262 (The Estatik Real Estate Plugin WordPress plugin before 4.3.3 
does not  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16258 (The Ajax Search Lite  WordPress plugin before 4.14.5 does not 
prevent  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16067 (The Event Booking Manager for WooCommerce (Pro) WordPress 
plugin befor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16041 (The MStore API  WordPress plugin before 4.21.0 does not 
perform author ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16039 (The MStore API  WordPress plugin before 4.21.0 does not 
restrict its v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16038 (The MStore API  WordPress plugin before 4.21.0 does not verify 
the pay ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16030 (The MStore API  WordPress plugin before 4.21.0 does not 
correctly veri ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15805
        REJECTED
 CVE-2026-15734 (A Server-Side Template Injection (SSTI) vulnerability in 
WGDashboard v ...)
@@ -363,87 +363,87 @@ CVE-2026-15733 (A Remote Code Execution (RCE) 
vulnerability exist in WGDashboard
 CVE-2026-15732 (A Server-Side Request Forgery (SSFR) vulnerability exist in 
WGDashboar ...)
        TODO: check
 CVE-2026-15386 (The Meow Gallery WordPress plugin before 5.5.2 does not escape 
an atta ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15361 (The Content Views  WordPress plugin before 4.5 does not 
perform a capa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15359 (The Templately  WordPress plugin before 3.7.1 does not have an 
authori ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15256 (The Ninja Forms WordPress plugin before 3.14.10 does not 
prevent user- ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15245 (The BNE Testimonials WordPress plugin before 2.0.8.2 does not 
properly ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15215 (The Subscriptions for WooCommerce WordPress plugin before 
2.0.1 does n ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15214 (The Subscriptions for WooCommerce WordPress plugin before 
2.0.1 does n ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15208 (The RegistrationMagic WordPress plugin before 6.0.9.5 does not 
compare ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15152 (The WP Hotel Booking WordPress plugin before 2.3.2 does not 
verify tha ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15149 (The WP Hotel Booking WordPress plugin before 2.3.3 does not 
ensure tha ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15147 (The Five Star Restaurant Reservations WordPress plugin before 
2.7.23 d ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15032 (The Comments  WordPress plugin before 7.6.60 does not properly 
escape  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14943 (The Password Protected \u2014 Lock Entire Site, Pages, Posts, 
Categori ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14936 (The Simple Membership WordPress plugin before 4.7.7 does not 
verify th ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14842 (The Events Made Easy WordPress plugin before 3.1.2 does not 
bind the p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14831 (The Easy Booking WordPress plugin before 3.5.0 does not 
re-enforce a b ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14812 (The Premium SEO WordPress plugin is malicious: it ships an 
unauthentic ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14365 (The TrueBooker \u2013 Appointment Booking and Scheduler System 
plugin  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14364 (The TrueBooker \u2013 Appointment Booking and Scheduler System 
plugin  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14331 (The Subscribe2  WordPress plugin before 10.46 does not 
properly escape ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14306 (The Tutor LMS WordPress plugin before 3.9.14 does not properly 
verify  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14225 (The Easy Appointments WordPress plugin through 3.12.26 does 
not correc ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14205 (The WP Events Manager WordPress plugin before 2.2.5 does not 
validate  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13399 (The Payment Plugins for PayPal WooCommerce WordPress plugin 
before 2.0 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13342 (The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 
does not c ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12901 (The GetPaid WordPress plugin before 2.8.55 does not verify the 
authent ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12801 (The Ultra Addons for Contact Form 7 plugin for WordPress is 
vulnerable ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12584 (The Payment Gateway for Redsys & WooCommerce Lite WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12501 (The WP Travel Engine WordPress plugin before 6.8.2 does not 
verify tha ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12261 (A vulnerability in `nltk.downloader` in nltk/nltk versions <= 
3.9.4 al ...)
        TODO: check
 CVE-2026-11976 (The official MonsterInsights Pro update distribution bucket 
(`monster- ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11907 (The Stream plugin for WordPress is vulnerable to authorization 
bypass  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11803 (A maliciously crafted PDF file, when parsed through Autodesk 
Revit, ca ...)
-       TODO: check
+       NOT-FOR-US: Autodesk
 CVE-2026-11361 (The Formidable Forms WordPress plugin before 6.32.1 does not 
properly  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-10599 (The Integrate PhonePe with WooCommerce WordPress plugin 
through 1.2.1  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-10524 (The CoCart WordPress plugin before 4.9.0 does not validate a 
user-supp ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-6508 (The Swagger UI Try-out console within the API Publisher 
documentation  ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2025-15674 (The Passster WordPress plugin before 4.3.7 does not restrict 
low-privi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-14561 (In multi-tenant deployments, the Publisher REST APIs fail to 
enforce t ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2025-12317 (When internal roles are removed from a user within the WSO2 
product, t ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2024-6541 (The Class Mediator fails to correctly validate or sanitize 
`messageCon ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2024-39024 (In Packetfence 13.2.0, the WebGui interface setting allows 
authenticat ...)
        TODO: check
 CVE-2026-18938



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07613addc3812ecc8eefc270b79455d68bd8b1c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07613addc3812ecc8eefc270b79455d68bd8b1c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to