Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
fa22ab95 by security tracker role at 2026-08-27T19:14:31+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -153,19 +153,19 @@ CVE-2026-81335 (Baserow dispatches an Application Builder
data source without ac
CVE-2026-81334 (darknet subscripts its layer array with an index taken from a
configur ...)
TODO: check
CVE-2026-81279 (Subscriber Broken Access Control in Push Notification for Post
and Bud ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81277 (Contributor SQL Injection in Suggestion Engine for WooCommerce
<= 2.0. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81276 (Unauthenticated Broken Access Control in Kali Forms <= 2.4.23
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81274 (Subscriber Broken Access Control in Ditty <= 3.1.67 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81273 (Unauthenticated Cross Site Request Forgery (CSRF) in
FluentBooking Pro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81272 (Editor Broken Access Control in FluentPlayer Pro <= 1.3.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81271 (Unauthenticated Cross Site Request Forgery (CSRF) in
GeoDirectory <= 2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81102 (The Dash MCP server bound its listener to the loopback address
but nev ...)
TODO: check
CVE-2026-81101 (The configure command accepted any endpoint URL and stored it
beside t ...)
@@ -191,7 +191,7 @@ CVE-2026-81092 (mcp-go accepted requests on its HTTP
transports without checking
CVE-2026-81091 (The proxy middleware in mcp-use's inspector forwards requests
to a des ...)
TODO: check
CVE-2026-80433 (Subscriber Sensitive Data Exposure in SureFeedback Client Site
<= 1.2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-80213 (An issue was discovered in the resolv gem before 0.7.2 for
Ruby. Resol ...)
TODO: check
CVE-2026-80212 (An issue was discovered in the resolv gem before 0.7.2 for
Ruby. Resol ...)
@@ -207,7 +207,7 @@ CVE-2026-80208 (APITable through 1.13.0-beta.1 annotates
both getUserHistories a
CVE-2026-80207 (APITable through 1.13.0-beta.1 annotates the create handler of
Interna ...)
TODO: check
CVE-2026-79988 (The Twig sandbox mechanism in Craft CMS is configured to allow
dangero ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-79720 (Reflected XSS in Netron versions <=9.1.2 on desktop
application throug ...)
TODO: check
CVE-2026-79719 (Reflected XSS in Netron versions <=9.1.2 on desktop
application throug ...)
@@ -217,37 +217,37 @@ CVE-2026-79718 (Reflected XSS in Netron versions <=9.1.2
on desktop application
CVE-2026-79653 (In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0,
20.1.0, if t ...)
TODO: check
CVE-2026-78293 (Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB
<= 3.0.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78292 (Unauthenticated PHP Object Injection in Hash Form <= 1.4.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78289 (Unauthenticated Cross Site Scripting (XSS) in CozyStay <=
1.10.0 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78288 (Unauthenticated SQL Injection in Beautiful Taxonomy Filters <=
2.4.6 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78286 (Unauthenticated PHP Object Injection in Geo Controller <=
8.9.8 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78285 (Subscriber SQL Injection in Like Button Rating <= 2.6.61
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78283 (Unauthenticated Cross Site Scripting (XSS) in Music Player for
WooComm ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78281 (Unauthenticated Cross Site Scripting (XSS) in CP Media Player
<= 1.3.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78276 (Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78275 (Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78274 (Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78273 (Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <=
2.0.11 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78271 (Editor Privilege Escalation in FluentCRM Pro <= 3.1.12
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78261 (Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic
IDX plu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78260 (Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78257 (Contributor PHP Object Injection in Booking and Rental Manager
<= 2.7. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote
attacker can tr ...)
TODO: check
CVE-2026-75871 (GitLab has remediated a vulnerability in the GitLab AI Gateway
compone ...)
@@ -259,11 +259,11 @@ CVE-2026-75357 (An issue in Bilibili Desktop v.1.17.9
allows a remote attacker t
CVE-2026-75159 (An unauthenticated client that can reach a MongoDB Connector
for BI de ...)
TODO: check
CVE-2026-75020 (Improper Neutralization of Special Elements used in an LDAP
Query ('LD ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-75005 (Inefficient Algorithmic Complexity vulnerability in Apache
APISIX. A ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-74848 (Inconsistent Interpretation of HTTP Requests ('HTTP
Request/Response S ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-74233 (Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2,
WE826-WD, ...)
TODO: check
CVE-2026-74232 (Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2
firmware 19.110 ...)
@@ -273,9 +273,9 @@ CVE-2026-71402 (An out-of-bounds read was found in the
DHCPv4 packet capture cod
CVE-2026-71401 (An integer underflow was found in the DHCPv4 packet capture
code of wi ...)
TODO: check
CVE-2026-66155 (A vulnerability has been identified in Element maps-ng V47
(All versio ...)
- TODO: check
+ NOT-FOR-US: Siemens
CVE-2026-64896 (Debug and Test Interface With Improper Access Control
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Johnson Controls
CVE-2026-5738 (Improper neutralization of input during web page generation
('cross-si ...)
TODO: check
CVE-2026-5680 (A flaw was found in Undertow. A remote attacker could exploit
this vul ...)
@@ -289,7 +289,7 @@ CVE-2026-59354 (In versions of Spring Security's OAuth2
Authorization Server mod
CVE-2026-59280 (Applications using Spring Framework's FreeMarker integration
may be vu ...)
TODO: check
CVE-2026-59272 (Any application shipping logs to RabbitMQ over TLS via the
Log4j2 appe ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-57499 (Liman is open source server management software. Prior to
2.2.2 - 1103 ...)
TODO: check
CVE-2026-56652 (Dool in versions up to 1.3.8 is vulnerable to a CSV injection
vulnerab ...)
@@ -299,15 +299,15 @@ CVE-2026-56651 (Dool in versions up to 1.3.8 is
vulnerable tosymlink following w
CVE-2026-40526 (Volmarg Personal Management System contains a path traversal
vulnerabi ...)
TODO: check
CVE-2026-34674 (Substance3D - Sampler versions 5.1.3 and earlier are affected
by a Hea ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-32566 (Unauthenticated Privilege Escalation in ACPT (Pro) - Custom
Post Types ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32564 (Subscriber SQL Injection in ACPT (Pro) - Custom Post Types
Plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32550 (Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32479 (Unauthenticated SQL Injection in Visitor Traffic Real Time
Statistics ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-30073 (An issue in the NssaiAvailabilitySubscriptionCreate component
of free5 ...)
TODO: check
CVE-2026-30072 (A NULL pointer dereference in the CDR processing path of
free5gc v4.0. ...)
@@ -349,7 +349,7 @@ CVE-2026-30046 (A reachable assertion vulnerability in the
NUDM-UECM interface o
CVE-2026-30045 (An integer overflow in the /nnrf-disc/v1/nf-instances
component of ope ...)
TODO: check
CVE-2026-27330 (Unauthenticated Broken Access Control in Mobile App for
WooCommerce <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-26899 (An issue was discovered in luci-app-https-dns-proxy on OpenWrt
PR #15 ...)
TODO: check
CVE-2026-26897 (An issue in EcoOnline EHS (com.airsweb.v10) application for
Android, v ...)
@@ -371,15 +371,15 @@ CVE-2026-19854 (When the ClickHouse plugin uses Native
protocol (the default) wi
CVE-2026-17562 (Authorization bypass through User-Controlled key vulnerability
in Summ ...)
TODO: check
CVE-2026-16279 (An Improper Authorization vulnerability affecting 3DPassport
in 3DSwym ...)
- TODO: check
+ NOT-FOR-US: Dassault Systemes
CVE-2026-11754 (Observable discrepancy vulnerability in Seres Software syWEB
allows Ac ...)
TODO: check
CVE-2026-11747 (Improper neutralization of input during web page generation
('cross-si ...)
TODO: check
CVE-2025-62343 (HCL IntelliOps Event Management (IEM) is affected by an Admin
Session ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-62342 (HCL IntelliOps Event Management (IEM) is affected by a Session
Deletio ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2023-49720
REJECTED
CVE-2023-49605
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fa22ab95ca61e3973db2e2f5f0a3ecd2a9a3e98f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fa22ab95ca61e3973db2e2f5f0a3ecd2a9a3e98f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits