Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
88d407cb by security tracker role at 2026-08-12T07:14:28+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -61,9 +61,9 @@ CVE-2026-71290 (Improper TLS hostname verification
vulnerability in Apache HttpC
CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of
Red Hat Ad ...)
TODO: check
CVE-2026-70339 (Access of resource using incompatible type ('type confusion')
in Micro ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-6484 (In an UEFI, Lack of verified boot to certain FV may cause
arbitrary co ...)
- TODO: check
+ NOT-FOR-US: Insyde
CVE-2026-68067 (The login endpoint on the Mira cloud API accepts any
format-valid stri ...)
TODO: check
CVE-2026-67568 (The distributed Mira Android APK v4.5.15.4 allows an attacker
read/wri ...)
@@ -77,23 +77,23 @@ CVE-2026-66875 (In the Mira hormone monitor device firmware
v1.7.1.47 build 0107
CVE-2026-66832 (When the Mira Android app opens in-app WebView content (e.g.,
shop red ...)
TODO: check
CVE-2026-66659 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66340 (The Mira cloud authentication endpoints do not enforce
per-account rat ...)
TODO: check
CVE-2026-66154 (An insufficient certificate validation in a privileged
communication w ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66150 (Improper Control of Generation of Code ('Code Injection')
Vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66149 (Improper Control of Generation of Code ('Code Injection')
Vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66148 (An authenticated command injection vulnerability was
identified in GMS ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66147 (An unauthenticated command injection vulnerability was
identified in t ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66146 (Multiple Cross-Site Scripting (XSS) vulnerabilities were
identified in ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66145 (An unauthenticated remote code execution vulnerability was
identified ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write
from any ...)
TODO: check
CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS
terminates ...)
@@ -141,105 +141,105 @@ CVE-2026-19579 (Snipe-IT before 8.6.0 contains an
authorization bypass (insecure
CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command
is gated ...)
TODO: check
CVE-2026-19217 (The Royal Addons for Elementor WordPress plugin before
1.7.1065 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19091 (The GeoDirectory \u2013 WP Business Directory Plugin and
Classified Li ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19073 (The Order Sync with Zendesk for WooCommerce WordPress plugin
before 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19052 (The ProSolution WP Client WordPress plugin before 2.0.9 does
not perfo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19050 (The ProSolution WP Client WordPress plugin before 2.0.9 does
not valid ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18962 (The WP Photo Album Plus WordPress plugin before 9.2.09.002
does not ch ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18961 (The Social Login, Passkeys, Magic Link & Email OTP \u2013
Passwordless ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18943 (The WPC Admin Columns WordPress plugin before 2.3.4 does not
have auth ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts
several undi ...)
TODO: check
CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly
restrict ac ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18710 (A MongoDB driver component could write sensitive configuration
informa ...)
TODO: check
CVE-2026-18634 (An insecure handling of serialized objects vulnerability was
found in ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-18474 (The WP Directory Kit WordPress plugin before 1.5.6 does not
sanitise a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18391 (The WooCommerce Subscriptions WordPress plugin before 9.1.0
does not v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18366 (The Events Manager WordPress plugin before 7.4.1 does not
properly sc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18230 (The WP Directory Kit WordPress plugin before 1.5.6 does not
sanitise a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18057 (The Events Manager WordPress plugin before 7.4.1 does not
sanitise an ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18049 (The WP Photo Album Plus WordPress plugin before 9.2.07.002
does not pe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18048 (The WP Photo Album Plus WordPress plugin before 9.2.07.002
does not va ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18046 (The Cookie Consent WordPress plugin before 0.0.10 does not
correctly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18035 (The User Access Manager WordPress plugin before 2.3.15 does
not apply ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17013 (The WP Photo Album Plus WordPress plugin before 9.2.07.002
does not sa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16977 (The Form Maker by 10Web WordPress plugin before 1.15.45 does
not prop ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16737 (The WP Travel Engine WordPress plugin before 6.8.5 does not
perform a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16538 (The Wallet for WooCommerce WordPress plugin before 1.6.10 does
not ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16294 (The PowerPress Podcasting plugin by Blubrry WordPress plugin
before 11 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16253 (The Total Upkeep WordPress plugin before 1.17.3 does not
adequately p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16230 (The Formidable Digital Signatures plugin for WordPress is
vulnerable t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16066 (The Welcart e-Commerce WordPress plugin before 2.11.34 does
not saniti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16051 (The wpmudev-updates WordPress plugin before 5.0.1 does not
verify the ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15606 (The Frontend Admin by DynamiApps plugin for WordPress is
vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15388 (The Cookie Consent WordPress plugin before 0.0.10 does not
correctly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15249 (The Patterns Kit WordPress plugin through 1.0.3 does not
escape a link ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15039 (The giftware WordPress plugin before 4.2.10 does not validate
the type ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14925 (The Import WP WordPress plugin before 2.14.23 does not
perform any au ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14863 (FileRun up to and including version 2026.2.0 contains an OS
command in ...)
TODO: check
CVE-2026-14859 (The WP Crowdfunding WordPress plugin before 2.2.1 does not
check the c ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14858 (The WP Crowdfunding WordPress plugin before 2.2.1 does not
verify orde ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14857 (The WP Crowdfunding WordPress plugin before 2.2.1 does not
verify owne ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13613 (The KiviCare WordPress plugin before 4.5.2 does not properly
sanitise ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13612 (The KiviCare WordPress plugin before 4.5.2 does not verify
that the r ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13457 (The InstaWP Connect \u2013 1-click WP Staging & Migration
plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13177 (The Eventin WordPress plugin before 4.1.20 does not properly
restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13171 (The Eventin WordPress plugin before 4.1.20 does not perform
an author ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13168 (The Eventin WordPress plugin before 4.1.20 does not properly
restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12976 (The LearnPress WordPress plugin before 4.4.4 does not verify
that a u ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12235 (The Linkable Loadable Extensions (llext) subsystem mis-handles
PLT/REL ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12234 (The userspace syscall verifiers z_vrfy_zsock_sendmsg() and
z_vrfy_zsoc ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12233 (The PSA Protected Storage credential backend
(subsys/net/lib/tls_crede ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12232 (The Intel ALH digital-audio-interface driver function
dai_alh_get_prop ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-15687 (A security flaw has been discovered in Open5GS up to 2.7.6.
Impacted i ...)
TODO: check
CVE-2025-15686 (A vulnerability has been found in Open5GS up to 2.7.6.
Affected by thi ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d407cba39e71fd571f2810cfbef51cf6a74022
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d407cba39e71fd571f2810cfbef51cf6a74022
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits