Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b36d6ba1 by security tracker role at 2026-08-27T07:14:36+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,33 +7,33 @@ CVE-2026-81485 (A security vulnerability has been detected in 
danielpopamd linke
 CVE-2026-81421 (A security flaw has been discovered in ddfourtwo 
sentry-selfhosted-mcp ...)
        TODO: check
 CVE-2026-81203 (A vulnerability has been found in SourceCodester Simple Online 
Food Or ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-81202 (A flaw has been found in itsourcecode Payroll System 1.0. The 
impacted ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-80183 (In OpenStack Keystone before 29.0.3, any authenticated user 
holding ro ...)
        TODO: check
 CVE-2026-79939 (Dell PowerProtect Cyber Recovery, versions Prior to 20.3, 
contain an U ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79938 (Dell PowerProtect Cyber Recovery, versions prior to 20.3, 
contain an I ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79921 (amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a 
comprom ...)
        TODO: check
 CVE-2026-78333 (The 12 Step Meeting List WordPress plugin before 3.19.17 does 
not sani ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78139 (The Notifima  WordPress plugin before 3.1.4 does not verify 
that the c ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78138 (The Finale Lite  WordPress plugin before 2.21.0 does not 
perform a cap ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78137 (The StoreGrowth  WordPress plugin before 2.1.2 does not 
validate a bro ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78125 (The LearnPress  WordPress plugin before 4.0.3 does not perform 
any aut ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77991 (Joomla Extension - joomlaeventmanager.net - Privileged remote 
code exe ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77990 (Joomla Extension - joomlaeventmanager.net - Attendee lists 
readable by ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77989 (Joomla Extension - joomlaeventmanager.net - Reflected XSS via 
the PDF  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77652 (A heap-based buffer overflow vulnerability exists in the Dia 
diagram e ...)
        TODO: check
 CVE-2026-77611 (SeaweedFS is a distributed storage system for files and blobs. 
In vers ...)
@@ -51,17 +51,17 @@ CVE-2026-77317 (SeaweedFS is a distributed storage system 
for files and blobs. I
 CVE-2026-77298 (SeaweedFS is a distributed storage system for files and blobs. 
In vers ...)
        TODO: check
 CVE-2026-77035 (Joomla Extension - joomlaeventmanager.net - Cross-user event 
and venue ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77034 (Joomla Extension - joomlaeventmanager.net - Unauthenticated 
article ov ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77018 (The Workeera  WordPress plugin before 1.0.6 does not restrict 
which pr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77017 (The Workeera  WordPress plugin before 1.0.6 does not restrict 
which pr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77016 (The Workeera  WordPress plugin before 1.0.6 does not restrict 
which va ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76549 (The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin 
before  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75601 (Static Web Server (SWS) is a production-ready web server 
suitable for  ...)
        TODO: check
 CVE-2026-75415 (AntFlow V2.0.0 is vulnerable to Incorrect Access Control. 
JiMuMDCCommo ...)
@@ -99,25 +99,25 @@ CVE-2026-75328 (In DocSys-master V2.02.85, the 
downloadDocEx interface in src/co
 CVE-2026-75327 (In DocSys-master V2.02.85, the uploadMarkdownPic interface in 
src/com/ ...)
        TODO: check
 CVE-2026-74774 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an 
Imprope ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-74771 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an 
Authori ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-74770 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an 
Imprope ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-71172 (Dell Cloud Disaster Recovery, versions20.2 and prior,containa 
Server-S ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-71054 (Vulnerability in Oracle Java SE (component: 2D).  Supported 
versions t ...)
        TODO: check
 CVE-2026-69129 (KubePi is a Kubernetes multi-cluster management panel. In 
versions up  ...)
        TODO: check
 CVE-2026-68863 (Dell PowerProtect One, versions 20.1.0.0 and below, contain a 
Stack-ba ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-68861 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an 
Imprope ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-68000 (The front-end interface /cms/category/list of MCMS <=6.2.0 is 
vulnerab ...)
        TODO: check
 CVE-2026-67275 (Dell PowerProtect One, versions 20.1.0.0 and below, contain a 
Reliance ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-66003 (Frappe is a full-stack web application framework written in 
Python and ...)
        TODO: check
 CVE-2026-65956 (KubePi is a Kubernetes multi-cluster management panel. In 
versions up  ...)
@@ -149,19 +149,19 @@ CVE-2026-61617 (Wings is the server control plane for the 
Pterodactyl game-serve
 CVE-2026-60004 (Gitea before 1.27.1 allows remote code execution via the 
diffpatch API ...)
        TODO: check
 CVE-2026-59278 (JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include 
java.net in ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59275 (A single hostile AMQP message can terminate the entire 
consumer JVM (S ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59274 (The UnZipTransformer does not limit decompressed entry size or 
entry c ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59271 (When the RabbitMQ management aliveness check fails, the 
configured adm ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59270 (Spring Security's embedded UnboundID LDAP server 
(UnboundIdContainer)  ...)
        TODO: check
 CVE-2026-58070 (A vulnerability that records guest OS processing credentials 
in cleart ...)
        TODO: check
 CVE-2026-56547 (The Apple profile generated for the Apple built-in Mail, 
Calendar and  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-55228 (Weblate is a web-based continuous localization platform used 
to manage ...)
        TODO: check
 CVE-2026-55227 (Weblate is a web-based localization tool. In versions prior to 
2026.7, ...)
@@ -175,9 +175,9 @@ CVE-2026-52473 (An issue in Wgcloud 3.6.4 allows a remote 
attacker to escalate p
 CVE-2026-52103 (A zero-click remote code execution (RCE) vulnerability in the 
/Termina ...)
        TODO: check
 CVE-2026-49809 (Dell PowerProtect Cyber Recovery, versions 20.2 and prior, 
contain an  ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-47894 (Spring Cloud Config Server native environment repository 
allows exposu ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47893 (A Spring WebFlux application that supports WebSocket 
connections may e ...)
        TODO: check
 CVE-2026-47892 (A WebFlux application using functional endpoints and deployed 
with Dis ...)
@@ -203,9 +203,9 @@ CVE-2026-47883 (UrlHandlerFilter can be vulnerable to an 
open redirect when conf
 CVE-2026-47881 (Spring Batch's FlatFileItemReader supports files where a 
single logica ...)
        TODO: check
 CVE-2026-47880 (A producer who can publish to a JMS destination consumed by 
any Spring ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47879 (Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows 
arbitrary S ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47878 (DefaultExecutionContextSerializer, used by default in Spring 
Batch's J ...)
        TODO: check
 CVE-2026-47877 (Spring Security Authorization Server's default consent page 
renders us ...)
@@ -213,39 +213,39 @@ CVE-2026-47877 (Spring Security Authorization Server's 
default consent page rend
 CVE-2026-47875 (Applications that deserialize execution contexts with 
Jackson2Executio ...)
        TODO: check
 CVE-2026-47874 (The vulnerability occurs when a client sends HTTP/1.1 
pipelined reques ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47864 (SerializingHttpMessageConverter deserializes the body of 
incoming HTTP ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47863 (In Reactor Core, applications that use the Flux.bufferTimeout 
operator ...)
        TODO: check
 CVE-2026-47862 (An attacker who can set the file_name header on a message 
reaching a Z ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47861 (An unauthenticated remote attacker who can send a single UDP 
packet to ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47860 (An attacker who can publish to a queue consumed by an 
application that ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47859 (RFC6587SyslogDeserializer, used by the Spring Integration 
syslog TCP i ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47857 (In Reactor Core, applications that use the Flux.windowTimeout 
operator ...)
        TODO: check
 CVE-2026-47856 (Spring Integration's JSON to object conversion uses the 
json__TypeId__ ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47852 (A local attacker on a multi-user host can pre-create the 
deterministic ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47851 (Analyzing a PDF with a deeply nested or cyclic table of 
contents can c ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47850 (Spring Data REST does not preserve the persisted version 
(@Version) pr ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47849 (Spring Data REST does not guard identifier (@Id) and version 
(@Version ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47848 (In specific scenarios involving WebSocket handshake redirects 
to a dif ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47845 (In specific scenarios, Reactor Netty HTTP Server may 
incorrectly evalu ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47844 (In specific scenarios, the Reactor Netty HTTP Server may leak 
exceptio ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47843 (In specific scenarios involving multiple clients with 
different DNS re ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47842 (Applications using AesBytesEncryptor with the two-argument 
constructor ...)
        TODO: check
 CVE-2026-47834 (Spring Data JPA's Sort validation can be bypassed when 
parameters cont ...)
@@ -277,23 +277,23 @@ CVE-2026-26446 (Stomper 5e2741e is vulnerable to Denial 
of Service. When a broke
 CVE-2026-26445 (stomper 5e2741e is vulnerable to Denial of Service. A 
malicious client ...)
        TODO: check
 CVE-2026-21810 (HCL BigFix Quantum Risk Analyzer is affected by a hardcoded 
external r ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-21809 (HCL BigFix Quantum Risk Analyzer has a certain validation 
process that ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-21808 (HCL BigFix Quantum Risk Analyzer generates highly detailed 
logging inf ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-21807 (HCL BigFix Quantum Risk Analyzer binary lacks several 
critical, indust ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-19715 (The WP OAuth Server ( Login with WordPress ) WordPress plugin 
before 6 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19454 (The JetBackup  WordPress plugin before 3.1.23.5 does not 
perform its m ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19398 (\u201cunsupported-when-assigned.\u201d An out-of-bounds write 
in the S ...)
-       TODO: check
+       NOT-FOR-US: ASUS
 CVE-2026-19225 (The Defender Security  WordPress plugin before 6.2.0 does not 
restrict ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19223 (The Smush  WordPress plugin before 4.3.2 does not restrict a 
network-w ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18823
        REJECTED
 CVE-2026-16895 (A logic vulnerability (fail-open condition) has been 
identified within ...)
@@ -301,19 +301,19 @@ CVE-2026-16895 (A logic vulnerability (fail-open 
condition) has been identified
 CVE-2026-16809 (LimeSurvey Community Edition 7.0.5 contains a stored 
cross-site script ...)
        TODO: check
 CVE-2026-16569 (The Mobile App for WooCommerce: ShopApper Mobile App Builder 
Service f ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16568 (The Mobile App for WooCommerce: ShopApper Mobile App Builder 
Service f ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16567 (The Document Embedder  WordPress plugin before 2.3.1 does not 
check a  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15973 (LimeSurvey Community Edition 7.0.5 contains a stored 
cross-site script ...)
        TODO: check
 CVE-2026-13416 (The CMP  WordPress plugin before 4.1.18 does not sanitise and 
escape a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13415 (The CMP  WordPress plugin before 4.1.18 does not enforce an 
option-nam ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13414 (The CMP  WordPress plugin before 4.1.18 does not perform 
authorization ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-70340 (A Broken Access Control vulnerability exists in ThingsBoard 
Profession ...)
        TODO: check
 CVE-2025-70293 (An issue was discovered in Denx U-Boot before 2026.04. An 
integer over ...)
@@ -321,7 +321,7 @@ CVE-2025-70293 (An issue was discovered in Denx U-Boot 
before 2026.04. An intege
 CVE-2025-70290 (An issue was discovered in Denx U-Boot before 2026.04. An 
integer over ...)
        TODO: check
 CVE-2025-62341 (HCL Connections is vulnerable to server-side request forgery 
(SSRF) wh ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-61480 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 
Main Boar ...)
        TODO: check
 CVE-2025-61479 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 
Main Boar ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b36d6ba1c2de3ca4284f301641dd6478cc4c0f3b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b36d6ba1c2de3ca4284f301641dd6478cc4c0f3b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to