Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
4e9a26a5 by security tracker role at 2026-08-31T07:14:50+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -21,17 +21,17 @@ CVE-2026-82656 (Admidio before 5.0.12 fails to sanitize
album names in the photo
CVE-2026-82655 (Admidio before 5.0.12 contains a blind SQL injection
vulnerability in ...)
TODO: check
CVE-2026-82654 (SiYuan before v3.8.1 fails to properly escape block name,
alias, and m ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82653 (SiYuan before v3.8.1 contains a stored cross-site scripting
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82652 (SiYuan before v3.8.1 fails to filter invisible-tier content
from SQL e ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82651 (SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath
guard (intr ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82650 (SiYuan 3.8.0 contains a path traversal / sensitive file
exposure vulne ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82649 (SiYuan Windows installer before version 3.8.1 (affected
versions >= 2. ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82648 (WWBN AVideo contains a server-side request forgery filter
bypass vulne ...)
TODO: check
CVE-2026-82647 (WWBN AVideo contains a cross-site request forgery
vulnerability in sen ...)
@@ -63,17 +63,17 @@ CVE-2026-82635 (Pake before 3.13.1 joins the
JavaScript-supplied filename for th
CVE-2026-82634 (Frappe Framework development builds contain an authorization
flaw in t ...)
TODO: check
CVE-2026-82633 (Dolibarr versions 10.0.0 before 24.0.0 fail to perform
per-object auth ...)
- TODO: check
+ NOT-FOR-US: Dolibarr
CVE-2026-82628 (A vulnerability was found in Colorful iGameCenter 2.0.0.81.
This vulne ...)
TODO: check
CVE-2026-82625 (A vulnerability has been found in code-projects Simple
Inventory Syste ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-82624 (A flaw has been found in code-projects Simple Inventory System
1.0. Af ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-82623 (A vulnerability was detected in open62541 up to 1.5.5.
Affected by thi ...)
TODO: check
CVE-2026-82622 (A security vulnerability has been detected in code-projects
Employee L ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-82621 (A weakness has been identified in Soarkey StudentManagement
and \u5b66 ...)
TODO: check
CVE-2026-82620 (A security flaw has been discovered in Soarkey
StudentManagement and \ ...)
@@ -83,21 +83,21 @@ CVE-2026-82619 (A vulnerability was identified in Systerel
S2OPC up to 1.7.3. Th
CVE-2026-82618 (A vulnerability was determined in Systerel S2OPC up to 1.7.3.
The affe ...)
TODO: check
CVE-2026-82616 (A vulnerability was found in TOTOLINK NR1800X
9.1.0u.6681_B20230703. I ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-82615 (A vulnerability has been found in itsourcecode Online Medicine
Deliver ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82614 (A flaw has been found in itsourcecode Online Medicine Delivery
System ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82613 (A vulnerability was detected in itsourcecode Online Medicine
Delivery ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82612 (A security vulnerability has been detected in itsourcecode
Online Medi ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82611 (A weakness has been identified in itsourcecode Online Medicine
Deliver ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82610 (A security flaw has been discovered in itsourcecode Online
Medicine De ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82609 (A vulnerability was identified in itsourcecode Sales and
Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82608 (A vulnerability was determined in Kamailio up to 5.5.0/6.0.7.
This aff ...)
TODO: check
CVE-2026-82607 (A vulnerability was found in Cozmoslabs Profile Builder Plugin
up to 3 ...)
@@ -119,17 +119,17 @@ CVE-2026-82599 (A vulnerability was identified in SeaCMS
up to 13.6. Affected by
CVE-2026-82598 (A vulnerability was determined in SeaCMS up to 13.6. Affected
is the f ...)
TODO: check
CVE-2026-82597 (A vulnerability was identified in TOTOLINK NR1800X
9.1.0u.6681_B202307 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-82596 (A vulnerability was determined in LatencyUtils up to 2.0.3.
Affected b ...)
TODO: check
CVE-2026-82595 (A vulnerability was found in D-Link DIR-825M 1.1.8. Affected
by this v ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82594 (A vulnerability has been found in LogNet
grpc-spring-boot-starter up t ...)
TODO: check
CVE-2026-82593 (A flaw has been found in D-Link DIR-825M 1.1.8. This impacts
the funct ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82592 (A vulnerability was detected in D-Link DIR-825M 1.1.8. This
affects th ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82591 (A security vulnerability has been detected in Open Asset
Import Librar ...)
TODO: check
CVE-2026-82590 (A weakness has been identified in Open5GS up to 2.7.7. The
affected el ...)
@@ -149,9 +149,9 @@ CVE-2026-82564 (Authorization Bypass Through
User-Controlled Key vulnerability i
CVE-2026-82556 (A vulnerability was found in Forgejo up to 15.0.4. This issue
affects ...)
TODO: check
CVE-2026-82555 (A vulnerability has been found in TOTOLINK N600R
4.3.0cu.7866_B2022050 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-82554 (A flaw has been found in SourceCodester Queue Management
System 1.0. T ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-82553 (A vulnerability was detected in sambitraj Student Management
System up ...)
TODO: check
CVE-2026-82552 (A security vulnerability has been detected in Linux Foundation
Magma 1 ...)
@@ -167,19 +167,19 @@ CVE-2026-82548 (A vulnerability was determined in Linux
Foundation Magma 1.9.0.
CVE-2026-82547 (A vulnerability was found in Linux Foundation Magma 1.9.0. The
affecte ...)
TODO: check
CVE-2026-82545 (A vulnerability has been found in itsourcecode Sales and
Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82544 (A flaw has been found in wger-project wger up to 2.6.0-alpha2.
This is ...)
TODO: check
CVE-2026-82543 (A vulnerability was detected in vastsa FileCodeBox up to 2.3.
This vul ...)
TODO: check
CVE-2026-82542 (A weakness has been identified in Tenda HG10 300001138.
Affected by th ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-82541 (A security flaw has been discovered in itsourcecode Sales and
Inventor ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82540 (A vulnerability was identified in itsourcecode Sales and
Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82539 (A vulnerability was determined in TOTOLINK A720R
4.1.5cu.630_B20250509 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-82488 (A vulnerability was identified in Beetel 450TC3 01.00.00_01.
This vuln ...)
TODO: check
CVE-2026-82487 (A vulnerability was determined in Beetel 450TC3 01.00.00_01.
This affe ...)
@@ -187,9 +187,9 @@ CVE-2026-82487 (A vulnerability was determined in Beetel
450TC3 01.00.00_01. Thi
CVE-2026-82486 (A vulnerability was found in SiteServer SSCMS 7.4.0. Affected
by this ...)
TODO: check
CVE-2026-82485 (A vulnerability has been found in itsourcecode Sales and
Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82484 (A flaw has been found in itsourcecode Sales and Inventory
System 1.0. ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82483 (A vulnerability was detected in coppermine-gallery Coppermine
Photo Ga ...)
TODO: check
CVE-2026-82367 (Exposure of Data Element to Wrong Session vulnerability in
ash-project ...)
@@ -235,7 +235,7 @@ CVE-2026-77850 (Stored Cross-site Scripting vulnerability
in ash-project ash_adm
CVE-2026-77454 (Incorrect Authorization vulnerability in ash-project ash_sql
allows a ...)
TODO: check
CVE-2026-77013 (The
\u7231\u91c7\u96c6\u6570\u636e\u91c7\u96c6\u548c\u53d1\u5e03\u63d2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75760 (Generation of Error Message Containing Sensitive Information
vulnerabi ...)
TODO: check
CVE-2026-75757 (Reliance on Cookies without Validation and Integrity Checking
vulnerab ...)
@@ -255,7 +255,7 @@ CVE-2026-64840
CVE-2026-64839
REJECTED
CVE-2026-58574 (Dell PowerStore contains a Missing Authentication for Critical
Functio ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56718 (AJCloud AJY IPC firmware prior to version 01.10715.11.37
contains a pa ...)
TODO: check
CVE-2026-56716
@@ -267,11 +267,11 @@ CVE-2026-56713
CVE-2026-53620 (GROWI contains a vulnerability with an authorization bypass
through us ...)
TODO: check
CVE-2026-40465 (NSP is vulnerable to an open redirect due to insufficient
server-side ...)
- TODO: check
+ NOT-FOR-US: Nokia
CVE-2026-40464 (NSP is vulnerable to a stored XSS due to insufficient
validation or en ...)
- TODO: check
+ NOT-FOR-US: Nokia
CVE-2026-40463 (WaveSuite is affected by an insufficient role-based access
control vul ...)
- TODO: check
+ NOT-FOR-US: Nokia
CVE-2026-18054
- qemu 1:11.1.0+ds-1
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/1f24066fc88d33455ee54a20f29994d9e69997ba
(v11.1.0-rc3)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e9a26a5d05bd0f36f7485b9cc065182864d6611
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e9a26a5d05bd0f36f7485b9cc065182864d6611
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits