Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
852078fa by security tracker role at 2026-09-14T07:13:53+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,9 +3,9 @@ CVE-2026-90691 (A security vulnerability has been detected in
0x4m4 HexStrike AI
CVE-2026-90690 (A weakness has been identified in 0x4m4 HexStrike AI up to
d689933ff57 ...)
TODO: check
CVE-2026-90689 (A security flaw has been discovered in Tenda W20E
15.11.0.61068_1546_8 ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-90688 (A vulnerability was identified in Tenda W20E
15.11.0.61068_1546_841_CN ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-90687 (A vulnerability was determined in GPAC up to f1219cde. This
vulnerabil ...)
TODO: check
CVE-2026-90686 (A vulnerability was found in GPAC up to f1219cde. This affects
the fun ...)
@@ -21,7 +21,7 @@ CVE-2026-90682 (A security vulnerability has been detected in
Matthias-Wandel jh
CVE-2026-90681 (A weakness has been identified in Matthias-Wandel jhead up to
3.3. Thi ...)
TODO: check
CVE-2026-90680 (A security flaw has been discovered in D-Link DIR-823G
1.0.2B05_201812 ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-90623 (A weakness has been identified in andreashappe cochise up to
0.4.1. Af ...)
TODO: check
CVE-2026-90622 (A security flaw has been discovered in GNU libredwg 0.13.4.
This impac ...)
@@ -37,7 +37,7 @@ CVE-2026-90618 (A flaw has been found in GH05TCREW
PentestAgent up to cf882dabea
CVE-2026-90617 (A vulnerability was detected in GH05TCREW PentestAgent up to
cf882dabe ...)
TODO: check
CVE-2026-90615 (A security vulnerability has been detected in SourceCodester
Class and ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-90614 (A weakness has been identified in FedML-AI FedML up to 0.9.6.
Affected ...)
TODO: check
CVE-2026-90613 (A security flaw has been discovered in GPAC up to f1219cde.
Affected b ...)
@@ -51,15 +51,15 @@ CVE-2026-90610 (A vulnerability was found in GPAC up to
f1219cde. This affects t
CVE-2026-90609 (A vulnerability has been found in GPAC up to f1219cde. The
impacted el ...)
TODO: check
CVE-2026-90608 (A flaw has been found in Totolink A3002MU Hh-B20211125.1046.
The affec ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90607 (A vulnerability was detected in Totolink A3002MU
Hh-B20211125.1046. Im ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90606 (A security vulnerability has been detected in Totolink A3002MU
Hh-B202 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90605 (A weakness has been identified in Totolink A3002MU
Hh-B20211125.1046. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90604 (A security flaw has been discovered in Totolink A3002MU
Hh-B20211125.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90603 (A vulnerability was identified in Anil-matcha
Open-Generative-AI up to ...)
TODO: check
CVE-2026-90602 (A vulnerability was determined in Anil-matcha
Open-Generative-AI up to ...)
@@ -67,13 +67,13 @@ CVE-2026-90602 (A vulnerability was determined in
Anil-matcha Open-Generative-AI
CVE-2026-90601 (A vulnerability was found in getzep graphiti up to 0.30.2.
Affected is ...)
TODO: check
CVE-2026-90600 (A vulnerability has been found in itsourcecode Sales and
Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-90599 (A flaw has been found in Rizwan17 inventory-management-system
up to 5e ...)
TODO: check
CVE-2026-90598 (A vulnerability was detected in jaygajera17
E-commerce-project-springB ...)
TODO: check
CVE-2026-90597 (A security vulnerability has been detected in itsourcecode
Sales and I ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-90596 (A weakness has been identified in embedded-graphics up to
0.8.2 on 32- ...)
TODO: check
CVE-2026-90595 (A security flaw has been discovered in wxiaoqi
Spring-Cloud-Platform 1 ...)
@@ -91,33 +91,33 @@ CVE-2026-90582 (A vulnerability was identified in evanchiu
serverless-todo 1.0.3
CVE-2026-90581 (A vulnerability was determined in cym1102 nginxWebUI up to
4.4.2. This ...)
TODO: check
CVE-2026-90580 (A vulnerability was found in FlowiseAI Flowise up to 3.0.2.
This vulne ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-89050 (The Quads Ads Manager for Google AdSense WordPress plugin
before 3.0.5 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88853 (Joomla Extension - regularlabs.com - Privileged stored XSS via
event h ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-88852 (Joomla Extension - regularlabs.com - Privileged stored XSS via
url opt ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-88802 (The MDJM Event Management WordPress plugin before 1.7.8.5 and
the Mobi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88793 (The YouTube Embed WordPress plugin from 10.0 to 10.3 does not
perform ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85196 (Joomla Extension - regularlabs.com - Reflected XSS in Articles
Anywher ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85195 (Joomla Extension - regularlabs.com - Privileged stored XSS via
link op ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85192 (Joomla Extension - regularlabs.com - Authenticated, privileged
remote ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85191 (Joomla Extension - regularlabs.com - Privileged stored XSS via
rtla-al ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85190 (Joomla Extension - regularlabs.com - Privileged stored XSS via
class o ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85189 (Joomla Extension - regularlabs.com - Privileged stored XSS via
executa ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85188 (Joomla Extension - regularlabs.com - Database data disclosure
in Advan ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85129 (The Hoo Companion WordPress plugin 1.0.2 does not have any
authorisati ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85125 (The Android application "YAMAP -Social Trekking GPS App"
contains an i ...)
TODO: check
CVE-2026-82796 (SolarView Compact contains a cross-site scripting
vulnerability in Ima ...)
@@ -191,9 +191,9 @@ CVE-2026-82763 (Cross-site scripting vulnerability exists
in Contec FX5000 serie
CVE-2026-82762 (Improper neutralization of special elements used in an OS
command ('OS ...)
TODO: check
CVE-2026-81648 (The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2
does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74933 (The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not
have au ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-68955 (The installer for Rakuten Kobo Desktop Application (Windows
version) i ...)
TODO: check
CVE-2026-52297 (FFmpeg before 9.0 has an out-of-bounds read because there is
insuffici ...)
@@ -259,11 +259,11 @@ CVE-2026-23787 (An issue was discovered in DPU in Samsung
Mobile Processor Exyno
CVE-2026-23786 (An issue was discovered in DPU in Samsung Mobile Processor
Exynos 1280 ...)
TODO: check
CVE-2026-16726 (Buffer overflow vulnerabilityin Panasonic IndustryUSB Driver
for MINAS ...)
- TODO: check
+ NOT-FOR-US: Panasonic
CVE-2026-15892 (The mcumgr SMP settings-management group handlers
settings_mgmt_read() ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-15891 (The MQTT-SN client keepalive handler process_ping() in
subsys/net/lib/ ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-70820 (Zettlab D6 Ultra before 1.7.0 allows absolute path traversal
to reach ...)
TODO: check
CVE-2025-68624 (N-able Mail Assure through April 2026 contains a design-level
authoriz ...)
@@ -295,7 +295,7 @@ CVE-2023-45858 (A directory traversal was identified in
Paessler PRTG before 23.
CVE-2023-45023 (The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect
Access ...)
TODO: check
CVE-2023-40772 (A directory Traversal vulnerability in DataEase before 1.18.10
allows ...)
- TODO: check
+ NOT-FOR-US: DataEase
CVE-2023-37366 (An issue was discovered in Samsung Exynos Mobile Processor,
Automotive ...)
TODO: check
CVE-2023-32803 (The ca-certificates package before
ca-certificates-2021.2.50-72 for Am ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/852078faae660b2db7938b2ff9b495bcc86d3386
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/852078faae660b2db7938b2ff9b495bcc86d3386
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits