Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
896ec9de by security tracker role at 2026-09-11T07:13:41+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,15 +1,15 @@
 CVE-2026-9768
        REJECTED
 CVE-2026-9667 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to 
server- ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-9327 (IBM WebSphere Application Server 9.0, and 8.5 could allow an 
authentic ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-9225 (IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an 
authenti ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-9176 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to 
a secur ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-8778 (The MIPL Grouped Checkout Fields for WooCommerce \u2013 
Customize & Or ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-89169 (live-boot ff8867c allows attackers to bypass the 
dm-verity-enforce-roo ...)
        TODO: check
 CVE-2026-89162 (In PCRE2 before 10.48, pcre2_serialize_encode might disclose 
two bytes ...)
@@ -47,113 +47,113 @@ CVE-2026-88062 (OmniRoute is an open-source AI gateway 
providing a single endpoi
 CVE-2026-88061 (career-ops is an open-source AI-assisted job search and 
application ma ...)
        TODO: check
 CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is 
vulnerable ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-87908 (multiparty is a Node.js library for parsing 
multipart/form-data reques ...)
        TODO: check
 CVE-2026-86815 (The BackWPup  WordPress plugin before 5.7.5 does not properly 
restrict ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86812 (The WPCafe  WordPress plugin before 3.0.18 does not correctly 
restrict ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86782 (The Visualizer  WordPress plugin before 4.0.6 does not 
properly author ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86781 (The SSL Zen \u2014 SSL Certificate Installer & HTTPS Redirects 
WordPre ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86780 (The Featured Image with URL WordPress plugin before 1.0.6 does 
not san ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86779 (The Visualizer  WordPress plugin before 4.0.6 does not 
properly author ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86093 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could 
allow a ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-86087 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could 
allow a ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-85678 (The AI Builder  WordPress plugin before 2.7.8 does not 
sanitise custom ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85677 (The Gutenverse News  WordPress plugin before 3.3.3 does not 
restrict t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85025 (IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an 
unauthen ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-84960 (The WP-Members Membership Plugin plugin for WordPress is 
vulnerable to ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84941 (An information disclosure vulnerability in the SAML Single 
Sign-On (SS ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-84889 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-84432 (Concrete CMS 9 through  9.5.2 did not validate an anti-CSRF 
token in t ...)
        TODO: check
 CVE-2026-83546 (The CoolClock WordPress plugin before 4.3.8 does not properly 
escape a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-83545 (The CoolClock WordPress plugin before 4.3.8 does not properly 
escape a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82305 (The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 
does not  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82107 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-82100 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-82099 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-82098 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-82097 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-82095 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-82092 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81941 (IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated 
non-admi ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81940 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81906 (Concrete CMS OAuth callback login path prior to version 9.5.3 
did not  ...)
        TODO: check
 CVE-2026-81905 (Concrete CMS below 9.5.3 stores user validation hashes for 
multiple pu ...)
        TODO: check
 CVE-2026-81825 (The Simple Ajax Chat \u2013 Add a Fast, Secure Chat Box plugin 
for Wor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81754 (The Vigilant \u2013 100% Free Security Suite: Firewall, 2FA, 
Login, He ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81554 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81551 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81550 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81540 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81268 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81265 (IBM Langflow OSS 1.0.0 through 1.11.5.)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81213 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81211 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81210 (IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three 
caller- ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81207 (IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any 
authenticated t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81204 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-80436 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-80434 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-80424 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-80380 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote attac ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-80378 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a 
remote authe ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-7438 (The Bold Timeline Lite plugin for WordPress is vulnerable to 
Stored Cr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-79742 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-79725 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-79724 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-79723 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-79592 (An out-of-bounds read vulnerability exists in the 
xls_dumpSummary() fu ...)
        TODO: check
 CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists 
in the  ...)
@@ -161,37 +161,37 @@ CVE-2026-79591 (A heap-buffer-overflow and use-after-free 
vulnerability exists i
 CVE-2026-79590 (A NULL pointer dereference vulnerability exists in the Prism 
parser co ...)
        TODO: check
 CVE-2026-78575 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-78573 (IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a 
remote  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-78571 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-78569 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow an 
authenticated att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-78172 (The Themify \u2013 WooCommerce Product Filter plugin for 
WordPress is  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77807 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and 
Marketing Auto ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77150 (The Unlimited Elements For Elementor plugin for WordPress is 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76653 (A missing authentication vulnerability in the VPN 
configuration manage ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-76652 (An authenticated directory traversal vulnerability in file 
upload func ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-76059 (IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could 
submit cus ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-75940 (A vulnerability was reported in Lenovo Health Android 
Application, dis ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-75777 (IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow 
a local  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-75624 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-74925 (The MultiVendorX  WordPress plugin before 5.0.16 does not 
restrict who ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-73785 (A potential security vulnerability in HPE IceWall Federation 
Agent and ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-73784 (A potential security vulnerability in HPE IceWall products 
could be ex ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-71647 (An issue in EGO-Planner-v2 All versions up to commit 
5c99a95880401e259 ...)
        TODO: check
 CVE-2026-71645 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested 
affected  ...)
@@ -203,7 +203,7 @@ CVE-2026-71642 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All 
versions up to commi
 CVE-2026-71640 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to 
commit 5c99 ...)
        TODO: check
 CVE-2026-63427 (An authentication bypass vulnerability was discovered in 
Lenovo Softwa ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-57844
        REJECTED
 CVE-2026-54054 (Transmute is a free, open-source, self-hosted file conversion 
and comp ...)
@@ -235,67 +235,67 @@ CVE-2026-45752 (Suricata is a network Intrusion Detection 
System, Intrusion Prev
 CVE-2026-45751 (Suricata is a network Intrusion Detection System, Intrusion 
Prevention ...)
        TODO: check
 CVE-2026-3096 (The product's web portals allow external links to be opened in 
a new b ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2026-36392 (FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site 
Scriptin ...)
        TODO: check
 CVE-2026-2310 (IBM webMethods Integration Server 11.1 IBM webMethods 
Integration is v ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19991 (The UsersWP plugin for WordPress is vulnerable to Arbitrary 
File Delet ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19985 (The Relevanssi \u2013 A Better Search plugin for WordPress is 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19646 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, 
ART 9.0, ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19596 (An XML External Entity (XXE) vulnerability exists in the XML 
collector ...)
        TODO: check
 CVE-2026-19136 (A potential command injection vulnerability was reported in 
the Tianxi ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-18994 (A potential improper authorization vulnerability was reported 
in the L ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-18964 (The Floating Chat Widget: Contact Chat Icons, Telegram Chat, 
Line Mess ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18579 (The WP Photo Album Plus plugin for WordPress is vulnerable to 
Stored C ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18562 (The HUSKY \u2013 Products Filter Professional for WooCommerce 
plugin f ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18561 (The Unlimited Elements For Elementor plugin for WordPress is 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18121 (Concrete CMS 9.5.2 and below is vulnerable to an authorization 
bypass  ...)
        TODO: check
 CVE-2026-17176 (An OS command injection vulnerability in the TDDP module of 
Deco BE110 ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-16174 (Netskope was notified about a potential gap in Netskope 
Endpoint DLP ( ...)
-       TODO: check
+       NOT-FOR-US: Netskope
 CVE-2026-16172 (Netskope was notified of an out-of-bounds heap read affecting 
the Endp ...)
-       TODO: check
+       NOT-FOR-US: Netskope
 CVE-2026-15462 (The Sticky Chat Widget plugin for WordPress is vulnerable to 
SQL Injec ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14566 (The advanced-customized-prompts WordPress plugin through 1.0.1 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14565 (The advanced-customized-prompts WordPress plugin through 1.0.1 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14563 (The advanced-customized-prompts WordPress plugin through 1.0.1 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14562 (The teddy-bear-customize-addon WordPress plugin through 1.0.5 
does not ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14560 (The teddy-bear-customize-addon WordPress plugin through 1.0.5 
does not ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14559 (The teddy-bear-customize-addon WordPress plugin through 1.0.5 
does not ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13326 (An out-of-bounds read in Qt NFC's language code length parsing 
allows  ...)
        TODO: check
 CVE-2026-12215 (The OTP Login & Register Woocommerce plugin for WordPress is 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11813 (A potential improper permissions vulnerability was reported in 
the Len ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-11496 (The Woo PDF Invoice Builder plugin (also distributed as "PDF 
Builder f ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11446 (The Booktics \u2013 Booking Calendar for Appointments and 
Service Busi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-57231 (Path Traversal in avatar attachments in Docmost v0.21.0 allows 
an unau ...)
        TODO: check
 CVE-2025-15695 (The Translate WordPress with GTranslate WordPress plugin 
before 3.0.10 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-88914 (A flaw was found in GStreamer's gst-plugins-good isomp4 
plugin. When p ...)
        - gst-plugins-good1.0 1.28.7-1
        NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0079.html



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/896ec9deb30bb1f0bfbd8c6b450a87fe7e79ccb7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/896ec9deb30bb1f0bfbd8c6b450a87fe7e79ccb7
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to