Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b9b6a010 by security tracker role at 2026-08-19T19:15:18+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
CVE-2026-76614 (OpenEMR before 8.3.0 contains a path traversal vulnerability
in the ED ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-76245 (stigmem (pip package stigmem-node) version 0.9.0a1 contains a
timestam ...)
TODO: check
CVE-2026-76244 (stigmem-node contains an insecure default configuration
vulnerability ...)
@@ -89,21 +89,21 @@ CVE-2026-76166 (A flaw was found in mod_cluster's
AdvertiseListenerImpl (org.jbo
CVE-2026-76164 (AIL Framework contains a server-side request forgery (SSRF)
vulnerabil ...)
TODO: check
CVE-2026-75956 (Joomla Extension - cmsjunkie.com - DOS vector in pagination
parameter ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75955 (Joomla Extension - cmsjunkie.com - Reflected XSS / XML
injection in J- ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75954 (Joomla Extension - cmsjunkie.com - SQL injection in trips
search in J ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75953 (Joomla Extension - cmsjunkie.com - Open mail relay in
J-BusinessDirec ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75952 (Joomla Extension - cmsjunkie.com - Cross-site request forgery
in J-Bu ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75951 (Joomla Extension - cmsjunkie.com - Insecure Direct Object
Reference (m ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75950 (Joomla Extension - cmsjunkie.com - Unauthenticated listing
ownership t ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75949 (Joomla Extension - cmsjunkie.com - Arbitrary file upload /
deletion ( ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75920 (phpMyFAQ before v4.1.6 writes content backup ZIP archives to
the web-a ...)
TODO: check
CVE-2026-75919 (phpMyFAQ before 4.1.7 contains an authentication bypass
vulnerability ...)
@@ -111,13 +111,13 @@ CVE-2026-75919 (phpMyFAQ before 4.1.7 contains an
authentication bypass vulnerab
CVE-2026-75918 (phpMyFAQ before 4.1.7 stores password reset tokens in a
publicly acces ...)
TODO: check
CVE-2026-75917 (SiYuan before v3.7.4 contains a cross-site scripting
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-75916 (SiYuan through 3.7.3 contains a cross-site scripting
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-75619 (Tapo C100/C101 V5 contains a heap-based buffer overflow
vulnerability ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-75618 (Tapo C100/C101 V5 contains a null pointer dereference
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-75583 (keeper.sh's calendar module version prior to 2.18.14 contains
a server ...)
TODO: check
CVE-2026-75149 (marimo before 0.23.15 contains a code injection vulnerability
in the n ...)
@@ -139,49 +139,49 @@ CVE-2026-75142 (FFmpeg before commit 9d786e4 contains a
stack buffer overflow in
CVE-2026-75141 (FFmpeg before commit acf5d7c contains a heap buffer overflow
in the hv ...)
TODO: check
CVE-2026-75114 (Joomla Extension - yootheme.com - Open redirect in
CommentController:: ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-74804 (Joomla Extension - yootheme.com - Unauthenticated SQL
injection in Ite ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-74803 (Joomla Extension - yootheme.com - Unauthenticated arbitrary
file uploa ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73829 (Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive
mpp allow ...)
TODO: check
CVE-2026-73541 (Allocation of Resources Without Limits or Throttling in
ZenHive mpp al ...)
TODO: check
CVE-2026-73394 (Unauthenticated Broken Access Control in Stitch Express <=
1.9.0 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73391 (Unauthenticated SQL Injection in Total Donations <= 2.0.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73390 (Unauthenticated Privilege Escalation in Total Donations <=
2.0.5 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73389 (Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73388 (Unauthenticated SQL Injection in Nikstore Core <= 1.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73387 (Unauthenticated Local File Inclusion in Resido <= 1.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73386 (Unauthenticated Sensitive Data Exposure in Track Geolocation
Of Users ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73385 (Unauthenticated Broken Access Control in Outranking Plugin
Options <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73384 (Unauthenticated Sensitive Data Exposure in Pay with Contact
Form 7 <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73364 (Customer PHP Object Injection in Flexible Subscriptions <=
1.8.1 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73363 (Unauthenticated Broken Access Control in Taxi Booking Manager
for WooC ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73354 (Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real
Estate I ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73347 (Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73185 (Unauthenticated SQL Injection in NGG Smart Image Search <
4.0.0 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73184 (Unauthenticated Cross Site Scripting (XSS) in Global Gallery
<= 11.1.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73183 (Unauthenticated SQL Injection in Maps Marker Pro <= 4.32
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73182 (Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73136 (Authentication Bypass by Capture-replay in ZenHive mpp allows
an unaut ...)
TODO: check
CVE-2026-72717 (Orval generates type-safe JavaScript clients in TypeScript
from OpenAP ...)
@@ -215,39 +215,39 @@ CVE-2026-71694 (An issue in Berkeley Out-of-Order Machine
(BOOM) / BoomTile RTL
CVE-2026-71470 (A flaw was found in the search-v2-operator. This vulnerability
allows ...)
TODO: check
CVE-2026-71176 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-70496 (A flaw was found in search-v2-operator. The operator's
ClusterRole has ...)
TODO: check
CVE-2026-70424 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-70423 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-70422 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-70421 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-69159 (FreeRDP is a free implementation of the Remote Desktop
Protocol. Prior ...)
TODO: check
CVE-2026-67581 (Authentication Bypass by Capture-replay in ZenHive mpp allows
an unaut ...)
TODO: check
CVE-2026-67364 (Joomla Extension - balbooa.com - Pre-auth PHP Code Injection
in Balboo ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-67363 (Joomla Extension - balbooa.com - Pre-auth Payment Amount
Tampering in ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-67268 (Dell Command Update (DCU), versions prior to 5.7.1, contain an
Imprope ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-67267 (Dell Command Update (DCU), versions prior to 5.7.1, contain an
Exposur ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-67266 (Dell Command Update (DCU), versions prior to 5.7.1, contain an
Incorre ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-66794 (A flaw was found in the `cluster-proxy-addon` component of
Multicluste ...)
TODO: check
CVE-2026-66668 (Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66613 (Unauthenticated Remote Code Execution (RCE) in JetEngine <=
3.8.14 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66596 (Unauthenticated Cross Site Scripting (XSS) in Newsletter <=
9.3.3 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65612 (nnn does not sanitize the filename variable. An attacker can
place a f ...)
TODO: check
CVE-2026-65611 (nnn does not sanitize the path variable. An attacker can
createa direc ...)
@@ -295,7 +295,7 @@ CVE-2026-62667 (Grav API Plugin is a RESTful API for Grav
CMS that provides full
CVE-2026-62666 (Grav API Plugin is a RESTful API for Grav CMS that provides
full headl ...)
TODO: check
CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery
<= 30.0. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav
Twig conte ...)
TODO: check
CVE-2026-61807 (Snipe-IT is an IT asset/license management system. Prior to
8.6.2, a s ...)
@@ -307,11 +307,11 @@ CVE-2026-61607 (Grav API Plugin is a RESTful API for Grav
CMS that provides full
CVE-2026-61518 (ISPConfig contains an authenticated SQL injection
vulnerability in the ...)
TODO: check
CVE-2026-58565 (Dell Command Update (DCU), versions prior to 5.7.1, contain a
Missing ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an
Incorre ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-58562 (Dell Command Update (DCU), versions prior to 5.7.1, contain a
Missing ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-58088 (The ELF core dump code counted the number of dumpable VM map
entries, ...)
TODO: check
CVE-2026-58087 (The GETALL and SETALL commands in semctl(2) recorded the
number of sem ...)
@@ -329,11 +329,11 @@ CVE-2026-58082 (The ISO-2022 encoding module used a stack
buffer sized to MB_LEN
CVE-2026-58081 (Several encoding modules, including HZ, UTF-7, VIQR, and ZW,
did not p ...)
TODO: check
CVE-2026-56797 (Dell Command Update (DCU), versions prior to 5.7.1, a
Time-of-check Ti ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56796 (Dell Command Update (DCU), versions prior to 5.7.1, contain an
Imprope ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56088 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-55703 (Snipe-IT is an IT asset/license management system. Prior to
8.6.3, any ...)
TODO: check
CVE-2026-55694 (Snipe-IT is an IT asset/license management system. Prior to
8.6.3, a r ...)
@@ -347,23 +347,23 @@ CVE-2026-55483 (Snipe-IT is an IT asset/license
management system. Prior to 8.6.
CVE-2026-55482 (Snipe-IT is an IT asset/license management system. Prior to
8.4.1, a n ...)
TODO: check
CVE-2026-54796 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-54795 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-54794 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
a Server ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-54793 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains
an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-53654 (Grav is a file-based Web platform. Prior to 3.8.5, the Login
plugin tw ...)
TODO: check
CVE-2026-53477 (Dell Command Update (DCU), versions prior to 5.7.1, contain a
Time-of- ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-53452 (Ground Station is a browser-based suite for satellite
tracking, SDR re ...)
TODO: check
CVE-2026-53451 (Ground Station is a browser-based suite for satellite
tracking, SDR re ...)
TODO: check
CVE-2026-52889 (Formie is a Craft CMS plugin for creating forms. Prior to
3.1.27, Form ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-52834 (jxl-oxide is a pure Rust implementation of a JPEG XL decoder.
Prior to ...)
TODO: check
CVE-2026-52792 (Algernon is a small self-contained pure-Go web server. Prior
to 1.17.9 ...)
@@ -385,9 +385,9 @@ CVE-2026-49976 (Snipe-IT is an IT asset/license management
system. Prior to 8.6.
CVE-2026-49870 (Snipe-IT is an IT asset/license management system. Prior to
8.6.1, POS ...)
TODO: check
CVE-2026-49817 (Dell Command Update (DCU), versions prior to 5.7.1, contain a
Deserial ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-49816 (Dell Command Update (DCU), versions prior to 5.7.1, contain a
Deserial ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-49441 (Wazuh is a free and open source platform used for threat
prevention, d ...)
TODO: check
CVE-2026-49425 (The compat32 kevent() handler translates a 64-bit kevent
struct into a ...)
@@ -439,19 +439,19 @@ CVE-2026-44252 (Wazuh is a free and open source platform
used for threat prevent
CVE-2026-41424 (Wazuh is a free and open source platform used for threat
prevention, d ...)
TODO: check
CVE-2026-40509 (OpenEMR before 8.3.0 contains a cross-site request forgery
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-40508 (OpenEMR before 8.3.0 contains a stored cross-site scripting
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-40507 (OpenEMR before 8.3.0 contains a reflected cross-site scripting
vulnera ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-32802 (Dell PowerPath, version 7.2 through to 8.0 SP1, contains an
Improper P ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-32552 (Subscriber SQL Injection in YITH WooCommerce Membership
Premium <= 2.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32475 (Unrestricted Upload of File with Dangerous Type vulnerability
in Eleme ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-23501 (Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1,
contains an Imp ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-20359 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
TODO: check
CVE-2026-20358 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
@@ -461,7 +461,7 @@ CVE-2026-20357 (As part of Cisco's ongoing commitment to
proactive security and
CVE-2026-20327 (A vulnerability in the web-based management interface of Cisco
Unified ...)
TODO: check
CVE-2026-20320 (A vulnerability in the Open Client Interface (OCI) XML Parser
of Cisco ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20319 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
TODO: check
CVE-2026-20318 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
@@ -473,7 +473,7 @@ CVE-2026-20315 (As part of Cisco's ongoing commitment to
proactive security and
CVE-2026-20314 (A vulnerability in Cisco Packaged Contact Center Enterprise
(Packaged ...)
TODO: check
CVE-2026-20302 (A vulnerability in the USB driver of Cisco RoomOS could allow
an unaut ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20232 (A vulnerability in the web-based management interface of Cisco
Industr ...)
TODO: check
CVE-2026-20231 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
@@ -483,97 +483,97 @@ CVE-2026-20177 (A vulnerability in the handling of
management plane packets by C
CVE-2026-20030 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
TODO: check
CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19672 (The tarfile module's tar and data extraction filters created
director ...)
TODO: check
CVE-2026-19653 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19490 (Vulnerability in NetScaler ADC and NetScaler Gateway. This
issue affe ...)
- TODO: check
+ NOT-FOR-US: NetScaler
CVE-2026-19489 (Vulnerability in NetScaler ADC and NetScaler Gateway. This
issue affe ...)
- TODO: check
+ NOT-FOR-US: NetScaler
CVE-2026-19321 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30,
and FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19234 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30,
and FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19198 (Akaunting 3.1.21 contains an authenticated improper
authorization vuln ...)
TODO: check
CVE-2026-18874 (A flaw was found in volsync-addon-controller. This
vulnerability allow ...)
TODO: check
CVE-2026-18848 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18756 (HumHub Community Edition 1.18.4 contains a reflected
cross-site script ...)
TODO: check
CVE-2026-18681 (IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30,
FW1060.00 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18526 (HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a
stored Cross- ...)
TODO: check
CVE-2026-18430 (HumHub 1.18.4 contains a stored cross-site scripting
vulnerability in ...)
TODO: check
CVE-2026-18372 (CSS injection vulnerability in M-Files Web before 26.8.16330.2
allows ...)
- TODO: check
+ NOT-FOR-US: M-Files
CVE-2026-18371 (HTML injection vulnerability in M-Files Web before
26.8.16330.2 allows ...)
- TODO: check
+ NOT-FOR-US: M-Files
CVE-2026-18315 (The TrueBooker \u2013 Appointment Booking and Scheduler System
plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17494 (IBM Power Systems Firmware FW1120.00, and FW1110.00 through
FW1110.30 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17429 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17183 (An authenticated user with permission to create or edit alert
rules ca ...)
TODO: check
CVE-2026-17100 (Power Systems FirmwareFW1120.00, FW1110.00 through FW1110.30,
FW1060.0 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17093 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16938 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16930 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, and ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16835 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16832 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16828 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16819 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16818 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16817 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16816 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote aut ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16814 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16706 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16703 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16690 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16687 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16686 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16656 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16440 (In Eclipse OpenJ9 versions up to 0.60, a crafted .class file
with deep ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-16019 (Improper neutralization of special elements used in an SQL
command ('S ...)
TODO: check
CVE-2026-15961 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30,
and FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15078 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow
a remote ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15068 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow
a remote ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15065 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow
a remote ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15061 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis
registration ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14970 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server
process is cr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-14603 (The application component processes user-supplied parameters
insecurel ...)
TODO: check
CVE-2025-14600 (An insecure deserialization vulnerability in vsDesk allows a
remote at ...)
@@ -1899,15 +1899,15 @@ CVE-2026-62608 (Vulnerability in the Oracle Reports
Developer product of Oracle
CVE-2026-62607 (Vulnerability in the Oracle Customer Care product of Oracle
E-Business ...)
TODO: check
CVE-2026-62606 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62605 (Vulnerability in the Oracle Partner Management product of
Oracle E-Bus ...)
TODO: check
CVE-2026-62604 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62603 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62602 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62601 (Vulnerability in the Oracle Sales product of Oracle E-Business
Suite ( ...)
TODO: check
CVE-2026-62600 (Vulnerability in the Oracle Sales product of Oracle E-Business
Suite ( ...)
@@ -1915,7 +1915,7 @@ CVE-2026-62600 (Vulnerability in the Oracle Sales product
of Oracle E-Business S
CVE-2026-62599 (Vulnerability in the Oracle Trading Community product of
Oracle E-Busi ...)
TODO: check
CVE-2026-62598 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62596 (Vulnerability in the Siebel CRM Integration product of Oracle
Siebel C ...)
NOT-FOR-US: Oracle
CVE-2026-62595 (Vulnerability in the Siebel CRM Integration product of Oracle
Siebel C ...)
@@ -1945,15 +1945,15 @@ CVE-2026-62584 (Vulnerability in the Oracle Hyperion
Infrastructure Technology p
CVE-2026-62583 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-62582 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62581 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-62580 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62579 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-62578 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62577 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-62576 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
@@ -1965,7 +1965,7 @@ CVE-2026-62573 (Vulnerability in the Oracle Hyperion
Infrastructure Technology p
CVE-2026-62572 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-62571 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62570 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-62569 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
@@ -2011,13 +2011,13 @@ CVE-2026-62536 (Vulnerability in the Oracle Hyperion
Infrastructure Technology p
CVE-2026-62535 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-62533 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62532 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62531 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-62529 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62526 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-62523 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
@@ -2065,11 +2065,11 @@ CVE-2026-62463 (Vulnerability in the Oracle Hyperion
Infrastructure Technology p
CVE-2026-62462 (Vulnerability in the Oracle Work in Process product of Oracle
E-Busine ...)
TODO: check
CVE-2026-62461 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62460 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62459 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62458 (Vulnerability in the Oracle Work in Process product of Oracle
E-Busine ...)
TODO: check
CVE-2026-62457 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
@@ -2087,17 +2087,17 @@ CVE-2026-62449 (Vulnerability in the Oracle Work in
Process product of Oracle E-
CVE-2026-62448 (Vulnerability in the Oracle Email Center product of Oracle
E-Business ...)
TODO: check
CVE-2026-62446 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62442 (Vulnerability in the Siebel CRM Cloud Applications product of
Oracle S ...)
NOT-FOR-US: Oracle
CVE-2026-62441 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62377 (libheif is a HEIF and AVIF file format decoder and encoder. In
1.23.0 ...)
TODO: check
CVE-2026-62291 (libheif is a HEIF and AVIF file format decoder and encoder. In
1.23.0 ...)
TODO: check
CVE-2026-61342 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61341 (Vulnerability in the Siebel CRM Cloud Applications product of
Oracle S ...)
NOT-FOR-US: Oracle
CVE-2026-61340 (Vulnerability in the Oracle MES for Process Manufacturing
product of O ...)
@@ -2121,7 +2121,7 @@ CVE-2026-61318 (Vulnerability in the Siebel CRM Cloud
Applications product of Or
CVE-2026-61317 (Vulnerability in the Siebel CRM Cloud Applications product of
Oracle S ...)
NOT-FOR-US: Oracle
CVE-2026-61313 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61307 (Vulnerability in the PeopleSoft Enterprise CC Common
Application Objec ...)
NOT-FOR-US: Oracle
CVE-2026-61306 (Vulnerability in the Oracle Complex Maintenance, Repair and
Overhaul p ...)
@@ -2139,7 +2139,7 @@ CVE-2026-61296 (Vulnerability in the Oracle Enterprise
Asset Management product
CVE-2026-61295 (Vulnerability in the Oracle WebCenter Content product of
Oracle Fusion ...)
NOT-FOR-US: Oracle
CVE-2026-61293 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61291 (Vulnerability in the Oracle WebCenter Content product of
Oracle Fusion ...)
NOT-FOR-US: Oracle
CVE-2026-61290 (Vulnerability in the Oracle WebCenter Content product of
Oracle Fusion ...)
@@ -2151,9 +2151,9 @@ CVE-2026-61286 (Vulnerability in the Oracle Enterprise
Manager Base Platform pro
CVE-2026-61284 (Vulnerability in the Oracle Enterprise Manager Base Platform
product o ...)
NOT-FOR-US: Oracle
CVE-2026-61281 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61276 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61273 (Vulnerability in the JD Edwards EnterpriseOne Tools product of
Oracle ...)
NOT-FOR-US: Oracle
CVE-2026-61272 (Vulnerability in the JD Edwards EnterpriseOne Tools product of
Oracle ...)
@@ -2165,7 +2165,7 @@ CVE-2026-61268 (Vulnerability in the JD Edwards
EnterpriseOne Tools product of O
CVE-2026-61265 (Vulnerability in the JD Edwards EnterpriseOne Orchestrator
product of ...)
TODO: check
CVE-2026-61259 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61258 (Vulnerability in the Oracle Internet Directory product of
Oracle Fusio ...)
TODO: check
CVE-2026-61248 (Vulnerability in the Oracle Internet Directory product of
Oracle Fusio ...)
@@ -2195,7 +2195,7 @@ CVE-2026-61212 (Vulnerability in the Oracle WebCenter
Portal product of Oracle F
CVE-2026-61208 (Vulnerability in the Oracle WebCenter Portal product of Oracle
Fusion ...)
NOT-FOR-US: Oracle
CVE-2026-61206 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61199 (Vulnerability in the Oracle WebCenter Portal product of Oracle
Fusion ...)
NOT-FOR-US: Oracle
CVE-2026-61198 (Vulnerability in the Oracle Learning Management product of
Oracle E-Bu ...)
@@ -2355,7 +2355,7 @@ CVE-2026-60861 (Vulnerability in the Service Delivery
Platform product of Oracle
CVE-2026-60860 (Vulnerability in the Service Delivery Platform product of
Oracle Fusio ...)
TODO: check
CVE-2026-60858 (Vulnerability in the Oracle Hyperion Calculation Manager
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60856 (Vulnerability in the PeopleSoft Enterprise PeopleTools product
of Orac ...)
NOT-FOR-US: Oracle
CVE-2026-60853 (Vulnerability in the Helidon product of Oracle Fusion
Middleware (comp ...)
@@ -2391,9 +2391,9 @@ CVE-2026-60792 (Vulnerability in the Siebel CRM
Deployment product of Oracle Sie
CVE-2026-60791 (Vulnerability in the Siebel CRM Deployment product of Oracle
Siebel CR ...)
NOT-FOR-US: Oracle
CVE-2026-60782 (Vulnerability in the Oracle Payments product of Oracle
E-Business Suit ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60781 (Vulnerability in the Oracle Payments product of Oracle
E-Business Suit ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60779 (Vulnerability in the Siebel Apps - Marketing product of Oracle
Siebel ...)
NOT-FOR-US: Oracle
CVE-2026-60769 (Vulnerability in the Oracle General Ledger product of Oracle
E-Busines ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9b6a01092e48df586658a3d02d2833b477e682f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9b6a01092e48df586658a3d02d2833b477e682f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits