Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
88d407cb by security tracker role at 2026-08-12T07:14:28+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -61,9 +61,9 @@ CVE-2026-71290 (Improper TLS hostname verification 
vulnerability in Apache HttpC
 CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of 
Red Hat Ad ...)
        TODO: check
 CVE-2026-70339 (Access of resource using incompatible type ('type confusion') 
in Micro ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-6484 (In an UEFI, Lack of verified boot to certain FV may cause 
arbitrary co ...)
-       TODO: check
+       NOT-FOR-US: Insyde
 CVE-2026-68067 (The login endpoint on the Mira cloud API accepts any 
format-valid stri ...)
        TODO: check
 CVE-2026-67568 (The distributed Mira Android APK v4.5.15.4 allows an attacker 
read/wri ...)
@@ -77,23 +77,23 @@ CVE-2026-66875 (In the Mira hormone monitor device firmware 
v1.7.1.47 build 0107
 CVE-2026-66832 (When the Mira Android app opens in-app WebView content (e.g., 
shop red ...)
        TODO: check
 CVE-2026-66659 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66340 (The Mira cloud authentication endpoints do not enforce 
per-account rat ...)
        TODO: check
 CVE-2026-66154 (An insufficient certificate validation in a privileged 
communication w ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-66150 (Improper Control of Generation of Code ('Code Injection') 
Vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-66149 (Improper Control of Generation of Code ('Code Injection') 
Vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-66148 (An authenticated command injection vulnerability was 
identified in GMS ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-66147 (An unauthenticated command injection vulnerability was 
identified in t ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-66146 (Multiple Cross-Site Scripting (XSS) vulnerabilities were 
identified in ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-66145 (An unauthenticated remote code execution vulnerability was 
identified  ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write 
from any ...)
        TODO: check
 CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS 
terminates ...)
@@ -141,105 +141,105 @@ CVE-2026-19579 (Snipe-IT before 8.6.0 contains an 
authorization bypass (insecure
 CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command 
is gated  ...)
        TODO: check
 CVE-2026-19217 (The Royal Addons for Elementor  WordPress plugin before 
1.7.1065 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19091 (The GeoDirectory \u2013 WP Business Directory Plugin and 
Classified Li ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19073 (The Order Sync with Zendesk for WooCommerce WordPress plugin 
before 2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19052 (The ProSolution WP Client WordPress plugin before 2.0.9 does 
not perfo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19050 (The ProSolution WP Client WordPress plugin before 2.0.9 does 
not valid ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18962 (The WP Photo Album Plus WordPress plugin before 9.2.09.002 
does not ch ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18961 (The Social Login, Passkeys, Magic Link & Email OTP \u2013 
Passwordless ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18943 (The WPC Admin Columns WordPress plugin before 2.3.4 does not 
have auth ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts 
several undi ...)
        TODO: check
 CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly 
restrict ac ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18710 (A MongoDB driver component could write sensitive configuration 
informa ...)
        TODO: check
 CVE-2026-18634 (An insecure handling of serialized objects vulnerability was 
found in  ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-18474 (The WP Directory Kit WordPress plugin before 1.5.6 does not 
sanitise a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18391 (The WooCommerce Subscriptions WordPress plugin before 9.1.0 
does not v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18366 (The Events Manager  WordPress plugin before 7.4.1 does not 
properly sc ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18230 (The WP Directory Kit WordPress plugin before 1.5.6 does not 
sanitise a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18057 (The Events Manager  WordPress plugin before 7.4.1 does not 
sanitise an ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18049 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 
does not pe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18048 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 
does not va ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18046 (The Cookie Consent  WordPress plugin before 0.0.10 does not 
correctly  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18035 (The User Access Manager WordPress plugin before 2.3.15 does 
not apply  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17013 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 
does not sa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16977 (The Form Maker by 10Web  WordPress plugin before 1.15.45 does 
not prop ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16737 (The WP Travel Engine  WordPress plugin before 6.8.5 does not 
perform a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16538 (The Wallet for WooCommerce WordPress plugin before 1.6.10 does 
not ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16294 (The PowerPress Podcasting plugin by Blubrry WordPress plugin 
before 11 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16253 (The Total Upkeep  WordPress plugin before 1.17.3 does not 
adequately p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16230 (The Formidable Digital Signatures plugin for WordPress is 
vulnerable t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16066 (The Welcart e-Commerce WordPress plugin before 2.11.34 does 
not saniti ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16051 (The wpmudev-updates WordPress plugin before 5.0.1 does not 
verify the  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15606 (The Frontend Admin by DynamiApps plugin for WordPress is 
vulnerable to ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15388 (The Cookie Consent  WordPress plugin before 0.0.10 does not 
correctly  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15249 (The Patterns Kit WordPress plugin through 1.0.3 does not 
escape a link ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15039 (The giftware WordPress plugin before 4.2.10 does not validate 
the type ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14925 (The Import WP  WordPress plugin before 2.14.23 does not 
perform any au ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14863 (FileRun up to and including version 2026.2.0 contains an OS 
command in ...)
        TODO: check
 CVE-2026-14859 (The WP Crowdfunding WordPress plugin before 2.2.1 does not 
check the c ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14858 (The WP Crowdfunding WordPress plugin before 2.2.1 does not 
verify orde ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14857 (The WP Crowdfunding WordPress plugin before 2.2.1 does not 
verify owne ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13613 (The KiviCare  WordPress plugin before 4.5.2 does not properly 
sanitise ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13612 (The KiviCare  WordPress plugin before 4.5.2 does not verify 
that the r ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13457 (The InstaWP Connect \u2013 1-click WP Staging & Migration 
plugin for W ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13177 (The Eventin  WordPress plugin before 4.1.20 does not properly 
restrict ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13171 (The Eventin  WordPress plugin before 4.1.20 does not perform 
an author ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13168 (The Eventin  WordPress plugin before 4.1.20 does not properly 
restrict ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12976 (The LearnPress  WordPress plugin before 4.4.4 does not verify 
that a u ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12235 (The Linkable Loadable Extensions (llext) subsystem mis-handles 
PLT/REL ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12234 (The userspace syscall verifiers z_vrfy_zsock_sendmsg() and 
z_vrfy_zsoc ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12233 (The PSA Protected Storage credential backend 
(subsys/net/lib/tls_crede ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12232 (The Intel ALH digital-audio-interface driver function 
dai_alh_get_prop ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-15687 (A security flaw has been discovered in Open5GS up to 2.7.6. 
Impacted i ...)
        TODO: check
 CVE-2025-15686 (A vulnerability has been found in Open5GS up to 2.7.6. 
Affected by thi ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d407cba39e71fd571f2810cfbef51cf6a74022

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d407cba39e71fd571f2810cfbef51cf6a74022
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to