Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9decb637 by security tracker role at 2026-08-04T07:13:11+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-8508 (An improper authentication vulnerability in the
"social_login.cgi" CGI ...)
- TODO: check
+ NOT-FOR-US: Zyxel
CVE-2026-6837 (A post-authentication command injection vulnerability in the
"export-c ...)
- TODO: check
+ NOT-FOR-US: Zyxel
CVE-2026-69249 (python-cryptography is a package designed to expose
cryptographic prim ...)
TODO: check
CVE-2026-69248 (cryptography is a package designed to expose cryptographic
primitives ...)
@@ -25,11 +25,11 @@ CVE-2026-69192 (ip-address is a library for parsing and
manipulating IPv4 and IP
CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication
for ever ...)
TODO: check
CVE-2026-68981 (Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP
requests fo ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-68980 (Apache NiFi 2.0.0 through 2.10.0 support creating, reading,
and deleti ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context
update R ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr()
function ...)
TODO: check
CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows
attackers ...)
@@ -59,41 +59,41 @@ CVE-2026-67616 (Camaleon CMS through 2.9.2, fixed in commit
88ab703, contains a
CVE-2026-67599 (ClearOS 7.9 contains an OS command injection vulnerability in
the Log ...)
TODO: check
CVE-2026-67598 (Emlog Pro through 2.6.23 contains a disabled TLS certificate
validatio ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-66326 (Missing authorization in Microsoft Edge (Chromium-based)
allows an una ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66325 (Server-side request forgery (ssrf) in Microsoft Edge
(Chromium-based) ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66322 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66321 (Access of resource using incompatible type ('type confusion')
in Micro ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66318 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66317 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66316 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66315 (Use after free in Microsoft Edge (Chromium-based) allows an
unauthoriz ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66314 (Time-of-check time-of-use (toctou) race condition in Microsoft
Edge (C ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66313 (Origin validation error in Microsoft Edge (Chromium-based)
allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66312 (Buffer over-read in Microsoft Edge (Chromium-based) allows an
authoriz ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66311 (Missing authorization in Microsoft Edge (Chromium-based)
allows an una ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66310 (External control of file name or path in Microsoft Edge for
Android al ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66296 (Improper Neutralization of Input During Web Page Generation
(XSS) vuln ...)
TODO: check
CVE-2026-66065 (Ouroboros is a local-first runtime for AI coding agents that
records t ...)
TODO: check
CVE-2026-65804 (Improper control of generation of code ('code injection') in
Microsoft ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-65802 (External control of file name or path in Microsoft Edge for
Android al ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-64565 (In the Linux kernel, the following vulnerability has been
resolved: I ...)
TODO: check
CVE-2026-64564 (In the Linux kernel, the following vulnerability has been
resolved: s ...)
@@ -105,9 +105,9 @@ CVE-2026-64562 (In the Linux kernel, the following
vulnerability has been resolv
CVE-2026-64561 (In the Linux kernel, the following vulnerability has been
resolved: K ...)
TODO: check
CVE-2026-62870 (Use after free in Microsoft Office Excel allows an
unauthorized attack ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-62354 (Authorization handling for Parameter Context validation
requests in Ap ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-58139 (The DuckDB AWS extension for DuckDB contains a security policy
bypass ...)
TODO: check
CVE-2026-56845 (An unauthenticated path traversal (LFI) vulnerability exists
under /cu ...)
@@ -115,7 +115,7 @@ CVE-2026-56845 (An unauthenticated path traversal (LFI)
vulnerability exists und
CVE-2026-52521 (A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows
authenticated ...)
TODO: check
CVE-2026-52520 (Emlog CMS <= 2.6.14 contains a stored cross-site scripting
(XSS) vulne ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md
plugin ...)
TODO: check
CVE-2026-51775 (SQL injection vulnerability in Fastadmin v.1.6.1.20250430
allows an at ...)
@@ -127,19 +127,19 @@ CVE-2026-49132 (OPNsense before 26.1.9 contains a stored
cross-site scripting vu
CVE-2026-49131 (OPNsense before 26.1.9 contains a stored cross-site scripting
vulnerab ...)
TODO: check
CVE-2026-48399 (Adobe Campaign Classic (ACC) is affected by a Violation of
Secure Desi ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48333 (Adobe Campaign Classic (ACC) is affected by an Incorrect
Authorization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48331 (Adobe Campaign Classic (ACC) is affected by a Server-Side
Request Forg ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48330 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48326 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48323 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48317 (Adobe Campaign Classic (ACC) is affected by an Improper
Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48115 (Misskey is an open source, federated social media platform.
All Misske ...)
TODO: check
CVE-2026-48113 (Chisel is a TCP/UDP tunnel, transported over HTTP and secured
via SSH. ...)
@@ -173,7 +173,7 @@ CVE-2026-18737 (Shlink contains a blind SQL injection
vulnerability that allows
CVE-2026-18736 (Shlink contains a server-side request forgery vulnerability
that allow ...)
TODO: check
CVE-2026-18733 (A prompt injection vulnerability in the shell tool in Amazon
Strands A ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18723 (A vulnerability was determined in diaowen DWSurvey up to
6.14.0. The a ...)
TODO: check
CVE-2026-18722 (A vulnerability was found in diaowen DWSurvey up to 6.14.0.
Impacted i ...)
@@ -195,9 +195,9 @@ CVE-2026-18682 (A security flaw has been discovered in
OpenAkita up to 1.27.12.
CVE-2026-18667 (A vulnerability in Tenable Sensor Proxy allows a remote
attacker to ex ...)
TODO: check
CVE-2026-18655 (Improper restriction of intended endpoints in the RabbitMQ
broker conn ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18654 (Key exchange without entity authentication in the EMR SSH
helper comma ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18648 (A vulnerability was detected in Blix Email Blue Mail Calendar
App 2.2. ...)
TODO: check
CVE-2026-18647 (A security vulnerability has been detected in jina-ai reader
up to 157 ...)
@@ -221,61 +221,61 @@ CVE-2026-17614 (A path traversal flaw was found in
WildFly's domain mode imple
CVE-2026-16881 (A code injection vulnerability exists in the LINE Android app
prior to ...)
TODO: check
CVE-2026-16623 (The Create Block WordPress plugin before 2.10.0 does not
correctly es ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16618 (The Improve SEO WordPress plugin through 2.0.11 does not
properly vali ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16548 (The Chat Widget: Floating Customer Support Button for 30+
Channels, Su ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16547 (The REST API Log WordPress plugin before 1.7.1 does not bind
the token ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16546 (The Wired Impact Volunteer Management WordPress plugin before
2.8.2 do ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16536 (The Simple Google Calendar Outlook Events Widget WordPress
plugin befo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16296 (The Clearfy Cache WordPress plugin before 2.4.3 does not
validate the ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16295 (The Clearfy Cache WordPress plugin before 2.4.3 does not
perform a ca ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16293 (The PowerPress Podcasting plugin by Blubrry WordPress plugin
before 11 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16070 (The Brizy WordPress plugin before 2.8.19 does not properly
verify aut ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16069 (The Brizy WordPress plugin before 2.8.19 does not sanitize or
escape ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16068 (The Brizy WordPress plugin before 2.8.19 does not properly
restrict w ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16056 (The Contest Gallery WordPress plugin before 30.0.7 does not
perform a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16035 (The miniOrange 2FA WordPress plugin before 6.2.7 does not
restrict wh ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15958 (The Easy Integration for Dropbox WordPress plugin before
2.2.0 does n ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15233 (The Nested Pages WordPress plugin before 3.2.15 does not
properly esca ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14939 (The Visualizer WordPress plugin before 4.0.6 does not
restrict a user ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14872 (The Database for Contact Form 7, WPforms, Elementor forms
WordPress pl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14848 (The Paid Membership Subscriptions WordPress plugin before
3.0.8 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14824 (The Quiz and Survey Master (QSM) WordPress plugin before
11.2.2 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14818 (A path traversal vulnerability in the CLI command used to
execute conf ...)
- TODO: check
+ NOT-FOR-US: Zyxel
CVE-2026-14816 (The GDPR Framework By Data443 WordPress plugin before 2.4.0
does not p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12698 (The wpForo Forum WordPress plugin before 3.1.3 does not
restrict which ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11836 (Insufficient verification of data authenticity in Caliptra
Core ROM an ...)
TODO: check
CVE-2026-11835 (Time-of-check time-of-use (TOCTOU) vulnerability combined with
missing ...)
TODO: check
CVE-2026-11366 (The MonsterInsights WordPress plugin before 11.1.0 does not
correctly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-10849 (The hawkBit device management client in subsys/mgmt/hawkbit
accumulate ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-10526 (The EmbedPress WordPress plugin before 4.6.1 does not
validate user-s ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8794 (PaperCut NG/MF contains an observable timing discrepancy in its
authen ...)
NOT-FOR-US: PaperCut
CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive
authentication att ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9decb6370a5985fbb1c76039e0449d199bf07203
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9decb6370a5985fbb1c76039e0449d199bf07203
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits