Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
71faffc8 by security tracker role at 2026-08-05T07:13:19+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
CVE-2026-9273 (The Membership Plugin \u2013 Kadence Memberships plugin for
WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8790 (The Football Pool plugin for WordPress is vulnerable to
Reflected Cros ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8761 (The Dokan plugin for WordPress is vulnerable to Privilege
Escalation i ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-7753 (The Cost Calculator Builder plugin for WordPress is vulnerable
to unau ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-71201 (In OpenStack Ironic through 38.0.0, a project reader that
makes a craf ...)
TODO: check
CVE-2026-71192 (In OpenStack Swift through 2.38.0, the S3API middleware does
not sanit ...)
@@ -71,13 +71,13 @@ CVE-2026-70480 (Open WebUI is an extensible, feature-rich,
and user-friendly sel
CVE-2026-70479 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
TODO: check
CVE-2026-70478 (Flowise is a drag & drop user interface to build a customized
large la ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-70477 (Flowise is a drag & drop user interface to build a customized
large la ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-70476 (Flowise is a drag & drop user interface to build a customized
large la ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-70475 (Flowise is a drag & drop user interface to build a customized
large la ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-70375 (HashBrown CMS through 1.4.6 contains an OS Command Injection
vulnerabi ...)
TODO: check
CVE-2026-70374 (HashBrown CMS through 1.4.6 contains an OS Command Injection
vulnerabi ...)
@@ -155,7 +155,7 @@ CVE-2026-66257 (A pre-authentication attacker could
leverage unbounded symbol va
CVE-2026-65986 (CVAT is an open source interactive video and image annotation
tool for ...)
TODO: check
CVE-2026-5062 (The PrettyLinks \u2013 Affiliate Links, Link Branding, Link
Tracking, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-54020 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
TODO: check
CVE-2026-52370 (A reflected cross-site scripting (XSS) vulnerability in the
Forum post ...)
@@ -167,7 +167,7 @@ CVE-2026-51400 (An issue in Vim Project v9.2.0389 and
earlier allows a local att
CVE-2026-51144 (Cross Site Scripting vulnerability in Soliton Systems MailZen
Manageme ...)
TODO: check
CVE-2026-49004 (The built-in PostgreSQL service on the mobile device suffers
from misc ...)
- TODO: check
+ NOT-FOR-US: ZTE
CVE-2026-48154 (GoRest is a Golang starter kit built with the Gin framework
for protot ...)
TODO: check
CVE-2026-47682 (CVAT is an open source interactive video and image annotation
tool for ...)
@@ -189,7 +189,7 @@ CVE-2026-45100 (OpenSIPS is a Session Initiation Protocol
(SIP) server implement
CVE-2026-45084 (OpenSIPS is a Session Initiation Protocol (SIP) server
implementation. ...)
TODO: check
CVE-2026-18907 (Path Traversal in Download File Feature in com.talpa.hibrowser
2.23.1. ...)
- TODO: check
+ NOT-FOR-US: TECNO Mobile
CVE-2026-18903 (A vulnerability was determined in yeqifu warehouse up to
aaf29962ba407 ...)
TODO: check
CVE-2026-18902 (A vulnerability was detected in H3C NX15 V100R017. Affected by
this vu ...)
@@ -207,7 +207,7 @@ CVE-2026-18896 (A vulnerability was determined in
lavkush-maurya Student-Registr
CVE-2026-18895 (A vulnerability was found in UTT HiPER 1250GW up to
3.2.7-210907-18053 ...)
TODO: check
CVE-2026-18859 (A vulnerability was identified in ESAFENET CDG up to 20260615.
Affecte ...)
- TODO: check
+ NOT-FOR-US: ESAFENET
CVE-2026-18856 (A vulnerability was determined in Poesis Rhymix CMS up to
2.1.33. This ...)
TODO: check
CVE-2026-18854 (A vulnerability has been found in Shandong Hoteam PDM Product
Data Man ...)
@@ -235,77 +235,77 @@ CVE-2026-18811 (A vulnerability was detected in H3C NX15
V100R017. The affected
CVE-2026-18810 (A security vulnerability has been detected in H3C NX15
V100R017. Impac ...)
TODO: check
CVE-2026-18657 (An uncontrolled search path element in Kiro CLI before version
2.10.0 ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18656 (An uncontrolled search path element in Kiro IDE before version
1.0.228 ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18322 (The Smart Popup by Supsystic plugin for WordPress is
vulnerable to Pri ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with
network access ...)
TODO: check
CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate
Listings WordPr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16993 (The DHL Shipping Germany for WooCommerce WordPress plugin
before 4.0.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16981 (The DHL Shipping Germany for WooCommerce WordPress plugin
before 4.0.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16968 (The GeoDirectory WordPress plugin before 2.8.168 does not
restrict a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16942 (The WP Custom HTML Page WordPress plugin through 0.6.2 does
not saniti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16940 (The Custom Fields WordPress plugin before 1.5.1 does not
validate a us ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16793 (An improper neutralization of special elements used in an
operating sy ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-16792 (An improper certificate validation vulnerability was reported
in multi ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-16791 (A temporary file creation vulnerability in the Linux version
of Lenovo ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-16746 (The MultiVendorX WordPress plugin before 5.0.11 does not
verify that ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16736 (The User Registration & Membership WordPress plugin before
5.2.6 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16613 (The GDPR Cookie Compliance WordPress plugin before 5.1.0
expires the ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16605 (The MultiVendorX WordPress plugin before 5.0.11 does not
verify that ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16604 (The Passster WordPress plugin before 4.3.6 outputs
password-protected ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16603 (The Passster WordPress plugin before 4.3.6 does not enforce
its categ ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16602 (The Passster WordPress plugin before 4.3.6 does not perform a
post-st ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16583 (The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie
Notice, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16573 (The Bit Form WordPress plugin before 3.2.0 does not sanitize
an uploa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16561 (The Sunshine Photo Cart WordPress plugin before 3.6.12 does
not perfo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16143 (The VikRentItems \u2013 Flexible Rental Management System
plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16055 (The Contest Gallery WordPress plugin before 30.0.7 does not
route its ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16036 (The miniOrange 2FA WordPress plugin before 6.2.7 does not
bind the se ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15941 (The plugin provides an Admin Search page that allows users
with the `e ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15918 (VikAppointments Service Booking Calendar wordpress plugin is
vulnerabl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15372 (The WP 2FA WordPress plugin before 4.1.0 does not validate
the second ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15360 (The Ajax Load More WordPress plugin before 8.0.1 does not
properly sa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15230 (The YayPricing WordPress plugin before 3.5.7 does not perform
capabil ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15210 (The OTP Login With Phone Number, OTP Verification WordPress
plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14553 (The zportals WordPress plugin before 6.3.4 does not properly
validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13227 (An Improper Authorization vulnerability exists in ERPNext
version <v16 ...)
TODO: check
CVE-2026-11421 (The ERP: Complete HR, Accounting & CRM Suite with WooCommerce
CRM Supp ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-15677 (The GeoDirectory WordPress plugin before 2.8.110 does not
sanitise an ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-42170
- gimp 3.2.4-1
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16161
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71faffc886c11e78f18912074dfa19993eeda64d
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71faffc886c11e78f18912074dfa19993eeda64d
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits