Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8a332f87 by security tracker role at 2026-09-12T19:14:28+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -49,11 +49,11 @@ CVE-2026-90537 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf33
CVE-2026-90536 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 fa ...)
TODO: check
CVE-2026-90535 (Flowise versions before 3.1.4 contain an unauthenticated
denial of ser ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-90534 (Flowise is a low-code platform for building LLM applications.
In versi ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-90533 (Flowise before 3.1.4 contains a broken access control
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-90474 (MCPHub before 1.0.32 contains an authentication bypass
vulnerability i ...)
TODO: check
CVE-2026-90473 (msgpack-java through 0.9.12 contains an integer overflow
vulnerability ...)
@@ -61,29 +61,29 @@ CVE-2026-90473 (msgpack-java through 0.9.12 contains an
integer overflow vulnera
CVE-2026-90472 (msgpack-java through 0.9.12 contains a stack overflow
vulnerability in ...)
TODO: check
CVE-2026-89172 (Improper protection of physical side channels vulnerability in
Microch ...)
- TODO: check
+ NOT-FOR-US: Microchip
CVE-2026-85200 (The GEO my WP plugin for WordPress is vulnerable to Local File
Inclusi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85198 (The MPG \u2013 Multiple Page Generator, Bulk Landing Pages &
Programma ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78175 (The Tutor LMS \u2013 eLearning and online course solution
plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78159 (The The Events Calendar plugin for WordPress is vulnerable to
Remote C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78006 (The The Events Calendar plugin for WordPress is vulnerable to
Remote C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77161 (The Smart Marketing SMS and Newsletters Forms plugin for
WordPress is ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17585 (The Royal Addons for Elementor \u2013 Addons and Templates Kit
for Ele ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16482 (The rtMedia for WordPress, BuddyPress and bbPress plugin for
WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15451 (The MemberPress Corporate Accounts plugin for WordPress is
vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11355 (The DT LMS \u2013 elearning, WordPress LMS plugin for
WordPress is vul ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-10148 (The Booking for Appointments and Events Calendar plugin for
WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90467 (aiosmtplib before 5.1.3 fails to properly validate email
addresses sup ...)
- aiosmtplib <unfixed> (bug #1147474)
NOTE: Fixed by:
https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2
(v5.1.3)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a332f87e94782f1b0074c328a37899a46ce3e7d
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a332f87e94782f1b0074c328a37899a46ce3e7d
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits