Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ac210c50 by security tracker role at 2026-09-17T07:14:29+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-92839 (Canva Desktop before v1.125.0 performed double decoding in the 
deeplin ...)
        TODO: check
 CVE-2026-92838 (A DLL hijacking vulnerability exists in the GeoVisionGV-Remote 
E-Mapde ...)
-       TODO: check
+       NOT-FOR-US: GeoVision
 CVE-2026-92816 (ComfyUI before 0.30.0 fails to sanitize folder_name input in 
dataset s ...)
        TODO: check
 CVE-2026-92815 (changedetection.io through 0.60.6 fails to validate the Goto 
URL actio ...)
@@ -19,7 +19,7 @@ CVE-2026-92810 (PrestaShop blockwishlist through 3.0.2 fails 
to validate wishlis
 CVE-2026-92809 (PrestaShop psgdpr versions through 1.4.3 fail to validate that 
GDPR co ...)
        TODO: check
 CVE-2026-92808 (A server-side request forgery (SSRF) vulnerability exists in 
the Unifi ...)
-       TODO: check
+       NOT-FOR-US: Altium
 CVE-2026-92806 (phpList versions before 3.6.17 fail to validate cross-site 
request for ...)
        TODO: check
 CVE-2026-92805 (UVdesk Community Skeleton through 1.1.8 fails to authenticate 
or valid ...)
@@ -125,21 +125,21 @@ CVE-2026-92596 (Nodemailer before 9.1.0 contains a 
quadratic time complexity vul
 CVE-2026-92595 (Nodemailer (npm package `nodemailer`) versions 9.1.0 and 
earlier do no ...)
        TODO: check
 CVE-2026-92594 (Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly 
authori ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92593 (Craft CMS versions 5.10.0 through 5.10.12 contain an 
incomplete fix fo ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92592 (Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign 
an authe ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92591 (Craft CMS 5.0.0 through 5.10.12 treats a database connection 
failure a ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92590 (Craft CMS versions from 5.7.0 before 5.10.13 contain a stored 
cross-si ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92589 (Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a 
broken a ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92588 (n8n is a workflow automation platform. In n8n versions before 
1.123.76 ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-92587 (n8n is a workflow automation platform. In versions before 
1.123.76, 2. ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-92586 (AVideo through 29.0 (commit 
c3edcc274c389816d434acadac07ee78eaf330c1)  ...)
        TODO: check
 CVE-2026-92585 (AVideo through 29.0 (commit 
c3edcc274c389816d434acadac07ee78eaf330c1)  ...)
@@ -165,7 +165,7 @@ CVE-2026-92576 (HKUDS nanobot before 0.3.0 contains a 
server-side request forger
 CVE-2026-92527 (A vulnerability has been found in chatwoot up to 4.17.1. This 
impacts  ...)
        TODO: check
 CVE-2026-92526 (A flaw has been found in itsourcecode Leave Management System 
1.0. Thi ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-92475 (A weakness has been identified in GPAC 26.08-DEV. This impacts 
the fun ...)
        TODO: check
 CVE-2026-92474 (A security flaw has been discovered in GPAC 26.08-DEV. This 
affects th ...)
@@ -173,93 +173,93 @@ CVE-2026-92474 (A security flaw has been discovered in 
GPAC 26.08-DEV. This affe
 CVE-2026-92473 (A vulnerability was identified in GPAC 26.08-DEV. The impacted 
element ...)
        TODO: check
 CVE-2026-91019 (The Event Booking Manager for WooCommerce  WordPress plugin 
before 5.6 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-91017 (The Robokassa payment gateway for Woocommerce WordPress plugin 
before  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-91016 (The Motors  WordPress plugin before 1.4.121 does not verify 
that a req ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-91015 (The Master Addons for Elementor  WordPress plugin before 3.1.9 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-91014 (The Realtyna Organic IDX plugin + WPL Real Estate WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-91011 (The EWWW Image Optimizer WordPress plugin before 8.7.7 does 
not proper ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-91010 (The Invisible Anti-Spam & CAPTCHA \u2014 reCAPTCHA Alternative 
for All ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-91009 (The Active Woot Products Tables for WooCommerce. 100% FREE 
WordPress p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-91008 (The Event Booking Manager for WooCommerce  WordPress plugin 
before 5.3 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-90982 (@fastify/static is a Fastify plugin that serves static files 
from a co ...)
        TODO: check
 CVE-2026-90923 (The Autopay WordPress plugin before 5.0.1 does not enforce the 
signatu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-90922 (The Paid Membership Subscriptions  WordPress plugin before 
3.0.9 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-89084 (HP has identified potential security vulnerabilities in the HP 
Advance ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-89083 (HP has identified potential security vulnerabilities in the HP 
Advance ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-89082 (HP has identified potential security vulnerabilities in the HP 
Advance ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-89064 (The All-in-One WP Migration and Backup plugin for WordPress is 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-89034 (TCH QRing smart ring model R20_B006 running firmware 
RT09R20_1.00.00_2 ...)
        TODO: check
 CVE-2026-88904 (The PuppyFW WordPress plugin through 0.4.4 does not have 
proper author ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-88795 (The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-88792 (The Dictionary WordPress plugin through 1.0 does not have 
authorisatio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-88592 (kkFileView >= 4.2.0 is vulnerable to Server-Side Request 
Forgery (SSRF ...)
        TODO: check
 CVE-2026-87976 (Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path 
manipula ...)
        TODO: check
 CVE-2026-87963 (The Yo WordPress plugin from 1.1 through 1.3.1 does not 
sanitize or pa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87935 (The Paid Downloads plugin for WordPress is vulnerable to 
Arbitrary Fil ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87836 (The Comments Import & Export WordPress plugin before 2.5.4 
does not re ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87796 (The Multi Uploader for Gravity Forms plugin for WordPress is 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87786 (The Dewa Kirim  WordPress plugin through 1.0.0 does not escape 
deliver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87116 (Tanium addressed a server-side request forgery vulnerability 
in Threat ...)
-       TODO: check
+       NOT-FOR-US: Tanium
 CVE-2026-87113 (Tanium addressed an improper access controls vulnerability in 
Threat R ...)
-       TODO: check
+       NOT-FOR-US: Tanium
 CVE-2026-87105 (Tanium addressed a SQL injection vulnerability in Threat 
Response.)
-       TODO: check
+       NOT-FOR-US: Tanium
 CVE-2026-87076 (Tanium addressed an information disclosure vulnerability in 
Discover.)
-       TODO: check
+       NOT-FOR-US: Tanium
 CVE-2026-87026 (Tanium addressed an improper access controls vulnerability in 
Threat R ...)
-       TODO: check
+       NOT-FOR-US: Tanium
 CVE-2026-87024 (Tanium addressed a SQL injection vulnerability in Asset.)
-       TODO: check
+       NOT-FOR-US: Tanium
 CVE-2026-86865 (Tanium addressed a SQL injection vulnerability in Asset.)
-       TODO: check
+       NOT-FOR-US: Tanium
 CVE-2026-86831 (Improper validation of pod identifier uniqueness in 
aws-network-policy ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-86824 (The Newsletter  WordPress plugin before 9.3.8 does not 
generate its em ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86801 (The To Do List Member WordPress plugin from 1.4 through 1.6 
ships a fi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86788 (The HT Mega Addons for Elementor  WordPress plugin before 
3.2.6 does n ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86710 (The Login with QR WordPress plugin through 1.0.0 does not 
verify that  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86709 (The Pressengine WordPress plugin through 1.0 does not stop its 
login h ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86707 (The Private Feed Key WordPress plugin through 0.1 does not 
verify that ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86446 (The LearnPress  WordPress plugin before 4.4.7 does not 
restrict the co ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86311 (The Photo Gallery by 10Web \u2013 Mobile-Friendly Image 
Gallery plugin ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86089 (Apache NiFi 2.11.0 supports migrating the contents of a 
version-contro ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86071 (Junrar is an open source Java RAR archive library. Prior to 
version 7. ...)
        TODO: check
 CVE-2026-85789
@@ -267,11 +267,11 @@ CVE-2026-85789
 CVE-2026-85469 (A flaw was found in quay-builder-qemu. A remote attacker could 
exploit ...)
        TODO: check
 CVE-2026-85130 (The WPLP Cookie Consent  WordPress plugin before 4.4.4 does 
not escape ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85128 (The Choose User Role at Registration WordPress plugin before 
1.3.3 doe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82561 (Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that 
replace ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-81872 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. 
Prior to v ...)
        TODO: check
 CVE-2026-81871 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. 
Prior to v ...)
@@ -281,7 +281,7 @@ CVE-2026-81870 (OpenTelemetry-Go is the Go implementation 
of OpenTelemetry. From
 CVE-2026-81869 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. 
From versi ...)
        TODO: check
 CVE-2026-81866 (Apache NiFi 2.9.0 through 2.11.0 provide Connector 
configuration updat ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-81546 (The Affinity by Canva application before 3.3.0 (September 2026 
release ...)
        TODO: check
 CVE-2026-76646 (A remote attacker could cause excessive resource consumption 
by supply ...)
@@ -305,7 +305,7 @@ CVE-2026-76444 (A vulnerability in an internal service of 
Cisco ISE and Cisco IS
 CVE-2026-76439 (A vulnerability in the endpoint posture status reporting 
functionality ...)
        TODO: check
 CVE-2026-76438 (A vulnerability in the web-based management interface of Cisco 
BroadWo ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-76434 (A vulnerability in the certificate import functionality of the 
web-bas ...)
        TODO: check
 CVE-2026-76433 (A vulnerability in the client provisioning download feature of 
Cisco I ...)
@@ -321,9 +321,9 @@ CVE-2026-76427 (A vulnerability in the offline profiler 
feed service of Cisco IS
 CVE-2026-76426 (A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC 
could a ...)
        TODO: check
 CVE-2026-76425 (A vulnerability in the APIs of Cisco ISE could allow an 
authenticated, ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-76424 (A vulnerability in the REST API of Cisco ISE could allow an 
authentica ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-76423 (A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC 
could a ...)
        TODO: check
 CVE-2026-76413 (A vulnerability in Cisco Adaptive Security Device Manager 
(ASDM) singl ...)
@@ -331,15 +331,15 @@ CVE-2026-76413 (A vulnerability in Cisco Adaptive 
Security Device Manager (ASDM)
 CVE-2026-76412 (A vulnerability in the remote diagnostics debugger of Cisco 
Secure FMC ...)
        TODO: check
 CVE-2026-76409 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-75513 (Marten is a .NET Transactional Document DB and Event Store on 
PostgreS ...)
        TODO: check
 CVE-2026-73462 (On affected platforms running Arista EOS with IGMP (Internet 
Group Man ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-70469 (Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP 
requests for ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-65388 (A remote attacker who controls a container registry may be 
able to dir ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-64684 (RMCP is an official Rust SDK for the Model Context Protocol. 
Prior to  ...)
        TODO: check
 CVE-2026-63506 (Tina is a headless content management system. Prior to 
@tinacms/auth 1 ...)
@@ -369,45 +369,45 @@ CVE-2026-61589 (djust provides Phoenix LiveView-style 
reactive server-side rende
 CVE-2026-61588 (djust provides Phoenix LiveView-style reactive server-side 
rendering f ...)
        TODO: check
 CVE-2026-50604 (A vulnerability has been identified in the Acer Agent Service 
componen ...)
-       TODO: check
+       NOT-FOR-US: Acer
 CVE-2026-50603 (A vulnerability has been identified in the Acer Agent Service 
componen ...)
-       TODO: check
+       NOT-FOR-US: Acer
 CVE-2026-44940 (The rancher-extension-stackstate extension in SUSE 
Observability expos ...)
        TODO: check
 CVE-2026-25294 (Transient DOS while parsing frame during channel usage.)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-25290 (Memory Corruption when validating large data buffers from 
external sou ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-25284 (Information Disclosure when a pointer is reused after being 
deallocate ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-25283 (Memory Corruption when copying unverified data from an 
external source ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-25282 (Transient DOS when processing unverified data from a 
neighboring syste ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-25281 (Transient DOS when processing large or numerous request 
buffers withou ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-25280 (Memory corruption when processing escape handling flow with 
insufficie ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-25278 (Memory Corruption when processing I2C transfer requests due to 
a race  ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-25275 (Transient DOS when processing authentication frames with 
invalid FILS  ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-25261 (Memory corruption while processing rear sensor IOCTL calls.)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-24081 (Transient DOS when processing a channel map with insufficient 
used cha ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-24075 (Memory Corruption when multiple threads issue concurrent IOCTL 
request ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-24074 (Memory Corruption when processing data with large offset and 
length va ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-24073 (Memory corruption when processing decode statistics due to 
insufficien ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2026-20361 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20360 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20352 (A vulnerability in the RADIUS feature of Cisco Identity 
Services Engin ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20350 (A vulnerability in the web-based management interface of Cisco 
Thousan ...)
        TODO: check
 CVE-2026-20344 (A vulnerability in the web-based management interface of Cisco 
Secure  ...)
@@ -435,35 +435,35 @@ CVE-2026-20330 (As part of Cisco's ongoing commitment to 
proactive security and
 CVE-2026-20329 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20326 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20325 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20324 (A vulnerability in the sftunnel inter-device communication 
protocol of ...)
        TODO: check
 CVE-2026-20323 (A vulnerability in the sftunnel inter-device communication 
protocol of ...)
        TODO: check
 CVE-2026-20322 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20309 (A vulnerability in the web-based management interface of Cisco 
Identit ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20300 (A vulnerability in Cisco ISE could allow an authenticated, 
remote atta ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20295 (A vulnerability in the sftunnel inter-device communication 
protocol of ...)
        TODO: check
 CVE-2026-20290 (A vulnerability in SSL/TLS certificate parsing in the Snort 2 
Detectio ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20287 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20286 (A vulnerability in the web-based management interface of Cisco 
Identif ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20285 (A vulnerability in the web-based management interface of Cisco 
Identit ...)
        TODO: check
 CVE-2026-20284 (A vulnerability in the SXP REST API of Cisco ISE could allow 
an authen ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20283 (A vulnerability in the IPsec Open API endpoint of Cisco ISE 
could allo ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20282 (A vulnerability in Cisco ISE could allow an authenticated, 
remote atta ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20250 (A vulnerability in Datagram TLS (DTLS) message handling of 
Cisco Secur ...)
        TODO: check
 CVE-2026-20249 (A vulnerability in the certification authentication feature of 
Interne ...)
@@ -471,27 +471,27 @@ CVE-2026-20249 (A vulnerability in the certification 
authentication feature of I
 CVE-2026-20248 (A vulnerability in the DNS over TCP implementation of Cisco 
Secure Fir ...)
        TODO: check
 CVE-2026-20247 (A vulnerability in Cisco ISE could allow an unauthenticated, 
remote at ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20242 (A vulnerability in the External Database Access feature of 
Cisco Secur ...)
        TODO: check
 CVE-2026-20237 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20235 (A vulnerability in the API of Cisco Identity Services Engine 
(ISE) cou ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20222 (A vulnerability in the EIGRP implementation in Cisco Secure 
Firewall A ...)
        TODO: check
 CVE-2026-20211 (A vulnerability in Cisco ISE could allow an authenticated, 
remote atta ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20194 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20192 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20176 (A vulnerability in Cisco ISE could allow an authenticated, 
remote atta ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20154 (A vulnerability in the system rate-limiting process for syslog 
message ...)
        TODO: check
 CVE-2026-20135 (A vulnerability in the TLS 1.3 implementation in Cisco Secure 
Firewall ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20130 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20121 (A vulnerability in the access control list (ACL) Object Group 
Search ( ...)
@@ -499,19 +499,19 @@ CVE-2026-20121 (A vulnerability in the access control 
list (ACL) Object Group Se
 CVE-2026-20120 (A vulnerability in the access control list (ACL) Object Group 
Search ( ...)
        TODO: check
 CVE-2026-20072 (A vulnerability in the web-based management interface of Cisco 
ISE cou ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20071 (A vulnerability in the SSID bring-your-own-device (BYOD) 
onboarding wo ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2025-59607 (Memory Corruption when copying large input data exceeds normal 
allocat ...)
-       TODO: check
+       NOT-FOR-US: Qualcomm
 CVE-2025-56566 (MikroTik firmware 7.19.4 stores sensitive authentication 
credentials a ...)
-       TODO: check
+       NOT-FOR-US: MikroTik
 CVE-2025-56565 (DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through 
v4 hardwa ...)
-       TODO: check
+       NOT-FOR-US: TP-Link
 CVE-2025-56563 (A Server-Side Request Forgery vulnerability exists in 
sat_proxy.php in ...)
        TODO: check
 CVE-2025-15697 (The Dictionary WordPress plugin through 1.0 does not escape 
user input ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-62846 [SQUID-2026:9]
        - squid 7.7-1
        TODO: check SQUID-2026:9 information not yet public



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac210c5093820990b00a8185d85e794abb279399

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac210c5093820990b00a8185d85e794abb279399
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to