Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
896ec9de by security tracker role at 2026-09-11T07:13:41+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,15 +1,15 @@
CVE-2026-9768
REJECTED
CVE-2026-9667 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to
server- ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-9327 (IBM WebSphere Application Server 9.0, and 8.5 could allow an
authentic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-9225 (IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an
authenti ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-9176 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to
a secur ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-8778 (The MIPL Grouped Checkout Fields for WooCommerce \u2013
Customize & Or ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89169 (live-boot ff8867c allows attackers to bypass the
dm-verity-enforce-roo ...)
TODO: check
CVE-2026-89162 (In PCRE2 before 10.48, pcre2_serialize_encode might disclose
two bytes ...)
@@ -47,113 +47,113 @@ CVE-2026-88062 (OmniRoute is an open-source AI gateway
providing a single endpoi
CVE-2026-88061 (career-ops is an open-source AI-assisted job search and
application ma ...)
TODO: check
CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is
vulnerable ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-87908 (multiparty is a Node.js library for parsing
multipart/form-data reques ...)
TODO: check
CVE-2026-86815 (The BackWPup WordPress plugin before 5.7.5 does not properly
restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86812 (The WPCafe WordPress plugin before 3.0.18 does not correctly
restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86782 (The Visualizer WordPress plugin before 4.0.6 does not
properly author ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86781 (The SSL Zen \u2014 SSL Certificate Installer & HTTPS Redirects
WordPre ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86780 (The Featured Image with URL WordPress plugin before 1.0.6 does
not san ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86779 (The Visualizer WordPress plugin before 4.0.6 does not
properly author ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86093 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could
allow a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-86087 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could
allow a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-85678 (The AI Builder WordPress plugin before 2.7.8 does not
sanitise custom ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85677 (The Gutenverse News WordPress plugin before 3.3.3 does not
restrict t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85025 (IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an
unauthen ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84960 (The WP-Members Membership Plugin plugin for WordPress is
vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84941 (An information disclosure vulnerability in the SAML Single
Sign-On (SS ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-84889 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84432 (Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF
token in t ...)
TODO: check
CVE-2026-83546 (The CoolClock WordPress plugin before 4.3.8 does not properly
escape a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83545 (The CoolClock WordPress plugin before 4.3.8 does not properly
escape a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82305 (The YITH WooCommerce Wishlist WordPress plugin before 4.18.1
does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82107 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82100 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82099 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82098 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82097 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82095 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82092 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81941 (IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated
non-admi ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81940 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81906 (Concrete CMS OAuth callback login path prior to version 9.5.3
did not ...)
TODO: check
CVE-2026-81905 (Concrete CMS below 9.5.3 stores user validation hashes for
multiple pu ...)
TODO: check
CVE-2026-81825 (The Simple Ajax Chat \u2013 Add a Fast, Secure Chat Box plugin
for Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81754 (The Vigilant \u2013 100% Free Security Suite: Firewall, 2FA,
Login, He ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81554 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81551 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81550 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81540 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81268 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81265 (IBM Langflow OSS 1.0.0 through 1.11.5.)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81213 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81211 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81210 (IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three
caller- ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81207 (IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any
authenticated t ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81204 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-80436 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-80434 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-80424 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-80380 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote attac ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-80378 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-7438 (The Bold Timeline Lite plugin for WordPress is vulnerable to
Stored Cr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-79742 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-79725 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-79724 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-79723 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-79592 (An out-of-bounds read vulnerability exists in the
xls_dumpSummary() fu ...)
TODO: check
CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists
in the ...)
@@ -161,37 +161,37 @@ CVE-2026-79591 (A heap-buffer-overflow and use-after-free
vulnerability exists i
CVE-2026-79590 (A NULL pointer dereference vulnerability exists in the Prism
parser co ...)
TODO: check
CVE-2026-78575 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-78573 (IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a
remote ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-78571 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-78569 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow an
authenticated att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-78172 (The Themify \u2013 WooCommerce Product Filter plugin for
WordPress is ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77807 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and
Marketing Auto ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77150 (The Unlimited Elements For Elementor plugin for WordPress is
vulnerabl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76653 (A missing authentication vulnerability in the VPN
configuration manage ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-76652 (An authenticated directory traversal vulnerability in file
upload func ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-76059 (IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could
submit cus ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-75940 (A vulnerability was reported in Lenovo Health Android
Application, dis ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-75777 (IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow
a local ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-75624 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-74925 (The MultiVendorX WordPress plugin before 5.0.16 does not
restrict who ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-73785 (A potential security vulnerability in HPE IceWall Federation
Agent and ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-73784 (A potential security vulnerability in HPE IceWall products
could be ex ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-71647 (An issue in EGO-Planner-v2 All versions up to commit
5c99a95880401e259 ...)
TODO: check
CVE-2026-71645 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested
affected ...)
@@ -203,7 +203,7 @@ CVE-2026-71642 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All
versions up to commi
CVE-2026-71640 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to
commit 5c99 ...)
TODO: check
CVE-2026-63427 (An authentication bypass vulnerability was discovered in
Lenovo Softwa ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-57844
REJECTED
CVE-2026-54054 (Transmute is a free, open-source, self-hosted file conversion
and comp ...)
@@ -235,67 +235,67 @@ CVE-2026-45752 (Suricata is a network Intrusion Detection
System, Intrusion Prev
CVE-2026-45751 (Suricata is a network Intrusion Detection System, Intrusion
Prevention ...)
TODO: check
CVE-2026-3096 (The product's web portals allow external links to be opened in
a new b ...)
- TODO: check
+ NOT-FOR-US: WSO2
CVE-2026-36392 (FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site
Scriptin ...)
TODO: check
CVE-2026-2310 (IBM webMethods Integration Server 11.1 IBM webMethods
Integration is v ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19991 (The UsersWP plugin for WordPress is vulnerable to Arbitrary
File Delet ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19985 (The Relevanssi \u2013 A Better Search plugin for WordPress is
vulnerab ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19646 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2,
ART 9.0, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19596 (An XML External Entity (XXE) vulnerability exists in the XML
collector ...)
TODO: check
CVE-2026-19136 (A potential command injection vulnerability was reported in
the Tianxi ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-18994 (A potential improper authorization vulnerability was reported
in the L ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-18964 (The Floating Chat Widget: Contact Chat Icons, Telegram Chat,
Line Mess ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18579 (The WP Photo Album Plus plugin for WordPress is vulnerable to
Stored C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18562 (The HUSKY \u2013 Products Filter Professional for WooCommerce
plugin f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18561 (The Unlimited Elements For Elementor plugin for WordPress is
vulnerabl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18121 (Concrete CMS 9.5.2 and below is vulnerable to an authorization
bypass ...)
TODO: check
CVE-2026-17176 (An OS command injection vulnerability in the TDDP module of
Deco BE110 ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-16174 (Netskope was notified about a potential gap in Netskope
Endpoint DLP ( ...)
- TODO: check
+ NOT-FOR-US: Netskope
CVE-2026-16172 (Netskope was notified of an out-of-bounds heap read affecting
the Endp ...)
- TODO: check
+ NOT-FOR-US: Netskope
CVE-2026-15462 (The Sticky Chat Widget plugin for WordPress is vulnerable to
SQL Injec ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14566 (The advanced-customized-prompts WordPress plugin through 1.0.1
does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14565 (The advanced-customized-prompts WordPress plugin through 1.0.1
does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14563 (The advanced-customized-prompts WordPress plugin through 1.0.1
does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14562 (The teddy-bear-customize-addon WordPress plugin through 1.0.5
does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14560 (The teddy-bear-customize-addon WordPress plugin through 1.0.5
does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14559 (The teddy-bear-customize-addon WordPress plugin through 1.0.5
does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13326 (An out-of-bounds read in Qt NFC's language code length parsing
allows ...)
TODO: check
CVE-2026-12215 (The OTP Login & Register Woocommerce plugin for WordPress is
vulnerabl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11813 (A potential improper permissions vulnerability was reported in
the Len ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-11496 (The Woo PDF Invoice Builder plugin (also distributed as "PDF
Builder f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11446 (The Booktics \u2013 Booking Calendar for Appointments and
Service Busi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-57231 (Path Traversal in avatar attachments in Docmost v0.21.0 allows
an unau ...)
TODO: check
CVE-2025-15695 (The Translate WordPress with GTranslate WordPress plugin
before 3.0.10 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88914 (A flaw was found in GStreamer's gst-plugins-good isomp4
plugin. When p ...)
- gst-plugins-good1.0 1.28.7-1
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0079.html
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/896ec9deb30bb1f0bfbd8c6b450a87fe7e79ccb7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/896ec9deb30bb1f0bfbd8c6b450a87fe7e79ccb7
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits