Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
86ba8288 by security tracker role at 2026-08-11T07:14:29+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III,
GPUTweakII, AI Su ...)
- TODO: check
+ NOT-FOR-US: ASUS
CVE-2026-8718 (tls_opt_dtls_peer_connection_id_value_get() in
subsys/net/lib/sockets/ ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-8158 (The Signed Video Framework contained a buffer overflow issue
which co ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-73035 (npm-check-updates through 23.0.2, fixed in commit b554b84,
contains a ...)
TODO: check
CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3
contains a path ...)
@@ -83,11 +83,11 @@ CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c,
contains an authentic
CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an
authenticated r ...)
TODO: check
CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use
(TOCTOU) ra ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost
inflight migra ...)
TODO: check
CVE-2026-6181 (The Device Configuration Framework is vulnerable to an
authentication ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection
vulnera ...)
TODO: check
CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown
rendering an ...)
@@ -97,85 +97,85 @@ CVE-2026-69114 (Spacebar Server before commit 8d126f4
contains a cross-channel m
CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path
traversal vulne ...)
TODO: check
CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP
NetWeaver App ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66778 (SAP Approuter does not sufficiently sanitize certain request
headers b ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66777 (SAP Approuter does not sufficiently validate certain incoming
requests ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66776 (SAP Approuter does not consistently enforce integrity
verification on ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66775 (SAP Approuter does not enforce cross-site request forgery
protection o ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66774 (SAP Approuter does not consistently handle certain error
conditions. A ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66773 (A malicious or compromised OData service could disclose
sensitive auth ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66772 (SAP BusinessObjects Business Intelligence Platform (Admin
Tools) does ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66771 (SAPUI5 allows a key user with content adaptation privileges to
inject ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66770 (Due to an SQL Injection vulnerability in SAP Social
intelligence, an a ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66764 (Reprocess Bank Statement Items in SAP S/4HANA does not perform
the nec ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66763 (SAP BusinessObjects Business Intelligence Platform stores
certain sens ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66761 (SAP Approuter does not enforce sufficient flow control in
certain func ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66760 (SAP Approuter does not correctly validate client certificates
in certa ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a
process ...)
TODO: check
CVE-2026-5304 (An ACAP configuration file lacks input validation, which could
potenti ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-5303 (The ACAP framework contains a Time-of-Check to Time-of-Use
(TOCTOU) ra ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-58248 (SAP BusinessObjects Business Intelligence Platform (Web
Intelligence) ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58247 (SAP ABAP Platform allows an unauthenticated user to send a
specially c ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58245 (SAP Advanced Planning and Optimization (Model Mix Planning)
contains a ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58244 (SAP Manufacturing Integration and Intelligence (MII) does not
perform ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58243 (SAP ABAP Development Tools does not perform necessary
authorization ch ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58241 (SAP NetWeaver and ABAP Platform (Change and Transport System -
Custome ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58239 (SAP Approuter does not sufficiently validate tenant context in
inbound ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58238 (SAP Approuter does not sufficiently handle certain requests
under spec ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58237 (WebSocket of SAP Approuter does not perform sufficient
authorization c ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58236 (SAP NetWeaver Application Server ABAP and ABAP Platform allow
an attac ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58235 (SAP NetWeaver Application Server Java (Adobe Document Service)
uses ou ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58230 (SAP Approuter does not sufficiently validate certain token
content und ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-4757 (A VAPIX API parameter had improper input validation which could
allow ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-48161 (react18-use is a React 19 use hook shim. Between 2026-05-19
01:07:01 a ...)
TODO: check
CVE-2026-48160 (react-tracked provides state usage tracking with Proxies.
Between 2026 ...)
TODO: check
CVE-2026-44765 (Due to a Missing Authorization Check vulnerability in SAP
Manufacturin ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44764 (Due to a Missing Authorization Check vulnerability in SAP
Manufacturin ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44763 (SAP Manufacturing Integration and Intelligence allows a
privileged att ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44762 (SAP Data Services Management Console allows an overly
permissive Conte ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44758 (SAP Manufacturing Integration and Intelligence (MII) allows an
attacke ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44401 (Typemill CMS version 2.x contains a persistent cross-site
scripting vu ...)
TODO: check
CVE-2026-40130 (SAP SAPSPrint Service has memory corruption vulnerabilities in
the han ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-34265 (SAP NetWeaver Application Server ABAP allows an
unauthenticated attack ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-24330 (A flaw was found in wildfly-core. A remote attacker,
authenticated as ...)
TODO: check
CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated
as an ad ...)
@@ -225,21 +225,21 @@ CVE-2026-18608 (A flaw was found in the Data Science
Pipelines Operator (DSPO).
CVE-2026-18348 (Missing authorization check in the upload_azure, upload_sftp,
and uplo ...)
TODO: check
CVE-2026-16974 (The Kirki \u2013 Freeform Page Builder, Website Builder &
Customizer p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16456 (A flaw was found in the `odh-model-controller`. An
authenticated user ...)
TODO: check
CVE-2026-16053 (Zohocorp ManageEngineM365 Manager Plus and M365 Security Plus
versions ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-15581 (A flaw was found in the TrustyAI Service (TAS) deployment.
This vulner ...)
TODO: check
CVE-2026-15467 (A flaw was found in the trustyai-service-operator's LMEvalJob
controll ...)
TODO: check
CVE-2026-14886 (Vault Enterprise's identity entity batch-delete endpoint is
vulnerable ...)
- TODO: check
+ NOT-FOR-US: Hashicorp products not packaged in Debian
CVE-2026-14549 (The Ray Enterprise Translation WordPress plugin through 1.7.3
does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3
does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows
any pod wi ...)
TODO: check
CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS
Gateway. Imp ...)
@@ -247,35 +247,35 @@ CVE-2026-13717 (A flaw was found in the Red Hat OpenShift
AI (RHOAI) MaaS Gatewa
CVE-2026-13716 (Path traversal in server import and admin file upload in
Crafty Contro ...)
TODO: check
CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler
usbd_cdc_ncm ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12051 (The USB DFU class implementation in Zephyr's new
(experimental) device ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11985 (On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU)
forces ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11894 (The Realtek BEE Bluetooth HCI driver's send callback,
bt_hci_bee_send( ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11893 (The Bluetooth HCI driver for Bouffalo Lab on-chip BLE
controllers (BL6 ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11812 (The UpdateHub management subsystem
(subsys/mgmt/updatehub/updatehub.c) ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11811 (The UpdateHub over-the-air update client's start_coap_client()
in subs ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11810 (The UpdateHub firmware-update agent's probe handler
(z_impl_updatehub_ ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11809 (The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c
contains ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-32736 (Cross-Site Request Forgery weaknesses in the Administrative
Console of ...)
- TODO: check
+ NOT-FOR-US: Ping Identity Corporation
CVE-2025-30241 (Certain web interface components in affected TP-Link Aginet
devices do ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-30240 (The affected TP-Link Aginet devices do not properly validate
symbolic ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-30239 (In affected TP-Link Aginet devices, use of hardcoded
cryptographic key ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-30238 (In affected TP-Link Aginet devices, insufficient authorization
validat ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-30237 (The affected TP-Link Aginet devicescontain a flaw in the web
managemen ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-15683 (TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple
unauthenticated denial ...)
TODO: check
CVE-2025-15682 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated
resource exh ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86ba8288e309bbba1885e4a8bb2347732f4809c2
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86ba8288e309bbba1885e4a8bb2347732f4809c2
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits