Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7d0ed139 by security tracker role at 2026-08-15T07:13:36+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-8840 (The Booking calendar, Appointment Booking System plugin for 
WordPress  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-74250 (In OpenStack Ironic before 38.0.1, the autodetect deploy 
interface may ...)
        TODO: check
 CVE-2026-74248 (OpenStack Octavia through 18.0.0 mishandles quality of service 
(QoS) p ...)
@@ -29,23 +29,23 @@ CVE-2026-73679 (ImpressCMS contains an authenticated remote 
code execution vulne
 CVE-2026-73678 (MindsDB Minds Platform version 26.1.0 and earlier contains an 
unauthen ...)
        TODO: check
 CVE-2026-71571 (Joomla Extension - icagenda.com -  Authenticated SQL injection 
via une ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-71570 (Joomla Extension - icagenda.com - ACL bypass allowing 
arbitrary user e ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-69414 (Microsoft is aware of an elevation of privilege in the 
Microsoft Malwa ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-67366 (Joomla Extension - icagenda.com - CSRF on frontend 
registration action ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67365 (Joomla Extension - icagenda.com - Unauthenticated SQL 
injection in iCa ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64887 (Use of hard-coded cryptographic key vulnerability in Johnson 
Controls  ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-63650 (OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote 
authentic ...)
        TODO: check
 CVE-2026-63649 (The Windows interactive service in OpenVPN 2.4.0 through 
2.6.21 and 2. ...)
        TODO: check
 CVE-2026-50523 (Improper neutralization of special elements used in a command 
('comman ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-50029 (js-toml is a TOML parser for JavaScript, Prior to version 
1.1.2, the i ...)
        TODO: check
 CVE-2026-50027 (mcp-memory-service is a semantic memory layer for AI 
applications. Pri ...)
@@ -53,9 +53,9 @@ CVE-2026-50027 (mcp-memory-service is a semantic memory layer 
for AI application
 CVE-2026-39925
        REJECTED
 CVE-2026-34492 (External control of file name or path vulnerability in Johnson 
Control ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-27871 (Cwe-327 Use of a Broken or Risky Cryptographic Algorithm 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-19910 (PAX Technology Q80 Application Installer Signature 
Verification Bypass ...)
        TODO: check
 CVE-2026-19909 (PAX Technology Q80 AIP File Parsing Link Following Remote Code 
Executi ...)
@@ -65,99 +65,99 @@ CVE-2026-19908 (PAX Technology Q80 XCB Daemon Missing 
Authentication Vulnerabili
 CVE-2026-18932
        REJECTED
 CVE-2026-18807 (The ECS  WordPress plugin before 4.3.8 does not have 
capability or own ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18554 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18387 (The Groundhogg \u2014 CRM, Newsletters, and Marketing 
Automation plugi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18216 (The Backup Migration WordPress plugin before 2.1.7 does not 
properly r ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18178 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17227 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17209 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17186 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17184 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17182 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17181 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17179 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17177 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17175 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17173 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17090 (The Beaver Builder Page Builder \u2013 Drag and Drop Website 
Builder p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17081 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17079 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16915 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16905 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16879 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
authentica ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16708 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16611 (The Product Feed PRO for WooCommerce by AdTribes  WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16586 (The Contest Gallery \u2013 Upload & Vote Photos, Media, Sell 
with PayP ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16541 (The Simply Schedule Appointments WordPress plugin before 
1.6.12.17 doe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16146 (The Invisible Anti-Spam & CAPTCHA \u2014 reCAPTCHA Alternative 
for All ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16145 (The Invisible Anti-Spam & CAPTCHA \u2014 reCAPTCHA Alternative 
for All ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16094 (The Invisible Anti-Spam & CAPTCHA \u2014 reCAPTCHA Alternative 
for All ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16080 (The Image Uploader for Welcart plugin for WordPress is 
vulnerable to g ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16007 (AppFlowy's qcuiknote feature is affected by a SQL injection 
vulnerabil ...)
        TODO: check
 CVE-2026-15993 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop 
Contact For ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15965 (The MaxUpload \u2013 Big File Uploads \u2013 Increase Maximum 
File Upl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15948 (The Hydra Booking \u2014 Appointment Scheduling & Booking 
Calendar plu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15826 (The User Profile Builder plugin for WordPress is vulnerable to 
Authent ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15453 (The KiviCare \u2013 Clinic & Patient Management System (EHR) 
plugin fo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15341 (The User Session Synchronizer plugin for WordPress is 
vulnerable to Au ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15312 (The Propovoice: All-in-One Client Management System plugin for 
WordPre ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15303 (The 6Storage Rentals plugin for WordPress is vulnerable to 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15162 (The Object Sync for Salesforce plugin is vulnerable to 
unauthenticated ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15001 (The bLoyal: Loyalty & Promotions by bLoyal plugin for 
WordPress is vul ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14484 (The RapiSafe \u2013 Secure Multi File Upload for Contact Form 
7 plugin ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14433 (The Online Booking & Scheduling Calendar for WordPress by 
vcita plugin ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14279 (The Wholesale Market plugin for WordPress is vulnerable to 
privilege e ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14230 (The ECS  WordPress plugin before 4.3.8 does not perform 
capability or  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14229 (The ECS  WordPress plugin before 4.3.8 does not check the post 
status  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13360 (The Cookie Banner for GDPR / CCPA \u2013 WPLP Cookie Consent 
plugin fo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12128 (The Pinpoint Booking System \u2013 Version 2 plugin for 
WordPress is v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19720
        - inetutils <unfixed>
        [trixie] - inetutils <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d0ed139ee263b79354579dc927863d5a37a0b0e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d0ed139ee263b79354579dc927863d5a37a0b0e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to