Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
852078fa by security tracker role at 2026-09-14T07:13:53+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,9 +3,9 @@ CVE-2026-90691 (A security vulnerability has been detected in 
0x4m4 HexStrike AI
 CVE-2026-90690 (A weakness has been identified in 0x4m4 HexStrike AI up to 
d689933ff57 ...)
        TODO: check
 CVE-2026-90689 (A security flaw has been discovered in Tenda W20E 
15.11.0.61068_1546_8 ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-90688 (A vulnerability was identified in Tenda W20E 
15.11.0.61068_1546_841_CN ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-90687 (A vulnerability was determined in GPAC up to f1219cde. This 
vulnerabil ...)
        TODO: check
 CVE-2026-90686 (A vulnerability was found in GPAC up to f1219cde. This affects 
the fun ...)
@@ -21,7 +21,7 @@ CVE-2026-90682 (A security vulnerability has been detected in 
Matthias-Wandel jh
 CVE-2026-90681 (A weakness has been identified in Matthias-Wandel jhead up to 
3.3. Thi ...)
        TODO: check
 CVE-2026-90680 (A security flaw has been discovered in D-Link DIR-823G 
1.0.2B05_201812 ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-90623 (A weakness has been identified in andreashappe cochise up to 
0.4.1. Af ...)
        TODO: check
 CVE-2026-90622 (A security flaw has been discovered in GNU libredwg 0.13.4. 
This impac ...)
@@ -37,7 +37,7 @@ CVE-2026-90618 (A flaw has been found in GH05TCREW 
PentestAgent up to cf882dabea
 CVE-2026-90617 (A vulnerability was detected in GH05TCREW PentestAgent up to 
cf882dabe ...)
        TODO: check
 CVE-2026-90615 (A security vulnerability has been detected in SourceCodester 
Class and ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-90614 (A weakness has been identified in FedML-AI FedML up to 0.9.6. 
Affected ...)
        TODO: check
 CVE-2026-90613 (A security flaw has been discovered in GPAC up to f1219cde. 
Affected b ...)
@@ -51,15 +51,15 @@ CVE-2026-90610 (A vulnerability was found in GPAC up to 
f1219cde. This affects t
 CVE-2026-90609 (A vulnerability has been found in GPAC up to f1219cde. The 
impacted el ...)
        TODO: check
 CVE-2026-90608 (A flaw has been found in Totolink A3002MU Hh-B20211125.1046. 
The affec ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-90607 (A vulnerability was detected in Totolink A3002MU 
Hh-B20211125.1046. Im ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-90606 (A security vulnerability has been detected in Totolink A3002MU 
Hh-B202 ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-90605 (A weakness has been identified in Totolink A3002MU 
Hh-B20211125.1046.  ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-90604 (A security flaw has been discovered in Totolink A3002MU 
Hh-B20211125.1 ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-90603 (A vulnerability was identified in Anil-matcha 
Open-Generative-AI up to ...)
        TODO: check
 CVE-2026-90602 (A vulnerability was determined in Anil-matcha 
Open-Generative-AI up to ...)
@@ -67,13 +67,13 @@ CVE-2026-90602 (A vulnerability was determined in 
Anil-matcha Open-Generative-AI
 CVE-2026-90601 (A vulnerability was found in getzep graphiti up to 0.30.2. 
Affected is ...)
        TODO: check
 CVE-2026-90600 (A vulnerability has been found in itsourcecode Sales and 
Inventory Sys ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-90599 (A flaw has been found in Rizwan17 inventory-management-system 
up to 5e ...)
        TODO: check
 CVE-2026-90598 (A vulnerability was detected in jaygajera17 
E-commerce-project-springB ...)
        TODO: check
 CVE-2026-90597 (A security vulnerability has been detected in itsourcecode 
Sales and I ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-90596 (A weakness has been identified in embedded-graphics up to 
0.8.2 on 32- ...)
        TODO: check
 CVE-2026-90595 (A security flaw has been discovered in wxiaoqi 
Spring-Cloud-Platform 1 ...)
@@ -91,33 +91,33 @@ CVE-2026-90582 (A vulnerability was identified in evanchiu 
serverless-todo 1.0.3
 CVE-2026-90581 (A vulnerability was determined in cym1102 nginxWebUI up to 
4.4.2. This ...)
        TODO: check
 CVE-2026-90580 (A vulnerability was found in FlowiseAI Flowise up to 3.0.2. 
This vulne ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-89050 (The Quads Ads Manager for Google AdSense WordPress plugin 
before 3.0.5 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-88853 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
event h ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-88852 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
url opt ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-88802 (The MDJM Event Management WordPress plugin before 1.7.8.5 and 
the Mobi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-88793 (The YouTube Embed WordPress plugin from 10.0 to 10.3 does not 
perform  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85196 (Joomla Extension - regularlabs.com - Reflected XSS in Articles 
Anywher ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-85195 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
link op ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-85192 (Joomla Extension - regularlabs.com - Authenticated, privileged 
remote  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-85191 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
rtla-al ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-85190 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
class o ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-85189 (Joomla Extension - regularlabs.com - Privileged stored XSS via 
executa ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-85188 (Joomla Extension - regularlabs.com - Database data disclosure 
in Advan ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-85129 (The Hoo Companion WordPress plugin 1.0.2 does not have any 
authorisati ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85125 (The Android application "YAMAP -Social Trekking GPS App" 
contains an i ...)
        TODO: check
 CVE-2026-82796 (SolarView Compact contains a cross-site scripting 
vulnerability in Ima ...)
@@ -191,9 +191,9 @@ CVE-2026-82763 (Cross-site scripting vulnerability exists 
in Contec FX5000 serie
 CVE-2026-82762 (Improper neutralization of special elements used in an OS 
command ('OS ...)
        TODO: check
 CVE-2026-81648 (The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-74933 (The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not 
have au ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-68955 (The installer for Rakuten Kobo Desktop Application (Windows 
version) i ...)
        TODO: check
 CVE-2026-52297 (FFmpeg before 9.0 has an out-of-bounds read because there is 
insuffici ...)
@@ -259,11 +259,11 @@ CVE-2026-23787 (An issue was discovered in DPU in Samsung 
Mobile Processor Exyno
 CVE-2026-23786 (An issue was discovered in DPU in Samsung Mobile Processor 
Exynos 1280 ...)
        TODO: check
 CVE-2026-16726 (Buffer overflow vulnerabilityin Panasonic IndustryUSB Driver 
for MINAS ...)
-       TODO: check
+       NOT-FOR-US: Panasonic
 CVE-2026-15892 (The mcumgr SMP settings-management group handlers 
settings_mgmt_read() ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-15891 (The MQTT-SN client keepalive handler process_ping() in 
subsys/net/lib/ ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-70820 (Zettlab D6 Ultra before 1.7.0 allows absolute path traversal 
to reach  ...)
        TODO: check
 CVE-2025-68624 (N-able Mail Assure through April 2026 contains a design-level 
authoriz ...)
@@ -295,7 +295,7 @@ CVE-2023-45858 (A directory traversal was identified in 
Paessler PRTG before 23.
 CVE-2023-45023 (The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect 
Access  ...)
        TODO: check
 CVE-2023-40772 (A directory Traversal vulnerability in DataEase before 1.18.10 
allows  ...)
-       TODO: check
+       NOT-FOR-US: DataEase
 CVE-2023-37366 (An issue was discovered in Samsung Exynos Mobile Processor, 
Automotive ...)
        TODO: check
 CVE-2023-32803 (The ca-certificates package before 
ca-certificates-2021.2.50-72 for Am ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/852078faae660b2db7938b2ff9b495bcc86d3386

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/852078faae660b2db7938b2ff9b495bcc86d3386
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to