Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
29a025a1 by security tracker role at 2026-08-18T19:13:58+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -17,7 +17,7 @@ CVE-2026-75904 (libmodplug through 0.8.9.1 contains an
out-of-bounds read in pat
CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery
vulnerabi ...)
TODO: check
CVE-2026-75897 (Improper input validation in the capabilities route handler in
OpenSea ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-75890
REJECTED
CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This
vulnerabi ...)
@@ -85,11 +85,11 @@ CVE-2026-75828 (Grav before 2.0.15 contains a stored
cross-site scripting vulner
CVE-2026-75827 (Grav before 2.0.15 contains an arbitrary file write
vulnerability in t ...)
TODO: check
CVE-2026-75784 (A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01.
Affecte ...)
- TODO: check
+ NOT-FOR-US: TRENDnet
CVE-2026-75783 (A security vulnerability has been detected in TRENDnet
TEW-WLC100P 12. ...)
- TODO: check
+ NOT-FOR-US: TRENDnet
CVE-2026-75778 (A vulnerability was identified in code-projects Task
Management System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-75774 (A vulnerability was determined in karakeep-app karakeep up to
0.32.0. ...)
TODO: check
CVE-2026-75773 (A vulnerability was found in karakeep-app karakeep up to
0.32.0. The a ...)
@@ -227,15 +227,15 @@ CVE-2026-74908 (Grav plugin-api before 1.0.15 contains a
script injection vulner
CVE-2026-74907 (Grav before 2.0.15 contains a path traversal vulnerability in
the stat ...)
TODO: check
CVE-2026-74906 (SiYuan before v3.7.4 contains an incorrect authorization
vulnerability ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74905 (SiYuan before v3.7.4 contains a server-side request forgery
(SSRF) vul ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74904 (SiYuan before v3.7.4 is missing authorization checks in 17
block metad ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74903 (SiYuan before v3.7.4 contains an insufficient access control
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74902 (SiYuan before v3.7.4 contains a cross-site scripting
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74046 (Wazuh 4.4.0 before 4.14.7 contains a denial of service
vulnerability i ...)
TODO: check
CVE-2026-74044 (Wazuh 4.0.0 before 4.14.6 contains a path traversal
vulnerability that ...)
@@ -245,29 +245,29 @@ CVE-2026-74039 (Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2
contain a denial of se
CVE-2026-74038 (Wazuh 4.0.0 before 4.14.6 contains a path traversal
vulnerability that ...)
TODO: check
CVE-2026-74015 (Unauthenticated SQL Injection in Readabler < 2.0.18 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74012 (Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74009 (Unauthenticated Insecure Direct Object References (IDOR) in
Razorpay f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74008 (Unauthenticated Sensitive Data Exposure in Shortcodes and
extra featur ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74007 (Unauthenticated Sensitive Data Exposure in 3D FlipBook \u2013
PDF Flip ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74006 (Contributor Broken Access Control in WP Table Builder <= 2.2.0
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74004 (Subscriber Broken Access Control in Gravity Booster –
Styles &am ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74003 (Contributor Broken Access Control in RomethemeForm For
Elementor <= 1. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73997 (Unauthenticated Denial of Service Attack in Starter Templates
by Kaden ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73996 (Unauthenticated Arbitrary File Upload in Masteriyo - LMS <=
2.3.2 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73995 (Subscriber Broken Authentication in User Registration <= 5.2.6
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73994 (Unauthenticated Broken Access Control in Charitable <=
1.8.11.3 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73834 (A flaw was found in the must-gather component of Red Hat
Advanced Clus ...)
TODO: check
CVE-2026-73692
@@ -277,105 +277,105 @@ CVE-2026-73502 (kin-openapi is a Go project for
handling OpenAPI files. From 0.2
CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for
everyday w ...)
TODO: check
CVE-2026-73404 (Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73400 (Unauthenticated Local File Inclusion in Restaurant Menu by
MotoPress < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73399 (Unauthenticated Broken Authentication in Flutterwave
WooCommerce <= 3. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73398 (Unauthenticated Broken Authentication in Piraeus Bank
WooCommerce Paym ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73397 (Unauthenticated Deserialization of untrusted data in Youzify
<= 1.3.7 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73396 (Subscriber Broken Authentication in MWB HubSpot for
WooCommerce <= 1.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73395 (Unauthenticated Insecure Direct Object References (IDOR) in
Booking ca ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73393 (Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <=
10.46 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73392 (Unauthenticated SQL Injection in Super Store Finder <= 7.8
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73383 (Shop manager Arbitrary File Download in CTX Feed <= 6.6.47
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73382 (Unauthenticated Cross Site Scripting (XSS) in Site Reviews <=
8.2.0 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73381 (Unauthenticated Broken Authentication in Popup by Supsystic <=
1.13.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73380 (Unauthenticated PHP Object Injection in Popup by Supsystic <=
1.13.0 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73379 (Unauthenticated Bypass Vulnerability in Contact Form by
Supsystic < 1. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73378 (Unauthenticated Cross Site Scripting (XSS) in Contact Form by
Supsysti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73377 (Unauthenticated Broken Access Control in Ultimate Maps by
Supsystic < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73376 (Unauthenticated PHP Object Injection in Ultimate Maps by
Supsystic < 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73375 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by
Supsyst ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73373 (Joomla! Core - [20260810] - Unrestricted uploads of SHTML
files in Joo ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73372 (Joomla! Core - [20260809] - Improper ACL checks when injection
schema. ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73371 (Joomla! Core - [20260808] - Improper ACL checks for batch copy
actions ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73367 (Unauthenticated Remote File Inclusion in Easy Google Maps <
1.14.2 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73366 (Unauthenticated PHP Object Injection in Easy Google Maps <=
1.13.0 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73365 (Unauthenticated SQL Injection in JetAppointment <= 2.5.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73362 (Unauthenticated Cross Site Scripting (XSS) in URL Shortify <=
2.5.0 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73361 (Unauthenticated Cross Site Scripting (XSS) in Recipe Card
Blocks for G ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73360 (Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <=
3.5.8 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73359 (Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for
GDPR, CC ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73358 (Unauthenticated Cross Site Scripting (XSS) in Affiliates
Manager <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73356 (Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73355 (Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73352 (Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73351 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social
Login a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73350 (Unauthenticated Broken Authentication in SupportCandy <= 3.5.1
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73348 (Unauthenticated Broken Access Control in GiveWP < 4.16.6
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73345 (Customer SQL Injection in License Manager for WooCommerce <=
3.0.18 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73343 (Unauthenticated Remote Code Execution (RCE) in WP Compress <
7.20.01 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73342 (Unauthenticated Cross Site Scripting (XSS) in WP Multilang <=
2.4.31 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73341 (Unauthenticated PHP Object Injection in RegistrationMagic <=
6.0.9.7 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73339 (Unauthenticated SQL Injection in Modern Events Calendar <
7.35.0 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73338 (Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73337 (Joomla! Core - [20260807] - MFA Authentication Bypass in
Joomla 4.0.0- ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73336 (Joomla! Core - [20260806] - XSS through schema.org outputs in
Joomla 5 ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73190 (Unauthenticated Cross Site Scripting (XSS) in WPDM \u2013
Premium Pack ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73189 (Subscriber Insecure Direct Object References (IDOR) in WP
Crowdfunding ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73187 (Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73181 (Unauthenticated Arbitrary File Download in Extra Product
Options & Add ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73073 (Vim is an open source, command line text editor. Prior to
9.2.0845, St ...)
TODO: check
CVE-2026-72532 (Joomla! Core - [20260806] - Improper ACL checks for category
webservic ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-72531 (Joomla! Core - [20260804] - Improper ACL checks for custom
fields webs ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-71880 (Interpretation of untrusted input in template engine in GBIF
Integrate ...)
TODO: check
CVE-2026-71879 (Missing authentication in initial setup functionality left
exposed unt ...)
@@ -383,15 +383,15 @@ CVE-2026-71879 (Missing authentication in initial setup
functionality left expos
CVE-2026-71878 (Missing authentication in initial setup functionality left
exposed aft ...)
TODO: check
CVE-2026-71574 (Joomla! Core - [20260803] - Inconsistent ACL checks for
mutating webse ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-71573 (Joomla! Core - [20260802] - Improper CORS origin validation in
Joomla ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-71572 (Joomla! Core - [20260801] - Response header injection in
download view ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-71551 (Super Productivity is an advanced todo list app with
integrated timebo ...)
TODO: check
CVE-2026-71539 (n8n is an open source workflow automation platform. Prior to
1.123.64, ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-71477 (mise manages dev tools like node, python, cmake, and
terraform. Prior ...)
TODO: check
CVE-2026-71365 (A server-side request forgery (SSRF) vulnerability was found
in AWX's ...)
@@ -401,7 +401,7 @@ CVE-2026-70667 (Lemur manages TLS certificate creation.
Prior to 1.9.3, _validat
CVE-2026-70657 (Copyparty is a portable file server. Prior to 1.20.17,
copyparty volum ...)
TODO: check
CVE-2026-70415 (Dell PowerStore SDNAS contains a Buffer Copy without Checking
Size of ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based
application ...)
TODO: check
CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based
application ...)
@@ -421,11 +421,11 @@ CVE-2026-68923 (MobSF is a mobile application security
testing tool used. Prior
CVE-2026-68922 (MobSF is a mobile application security testing tool used.
Prior to 4.5 ...)
TODO: check
CVE-2026-68568 (Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-68567 (Unauthenticated Cross Site Scripting (XSS) in Convert Pro <=
1.0.1 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-68565 (Contributor Cross Site Scripting (XSS) in GeoDirectory <=
2.8.172 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-67921 (Cross-Site Request Forgery (CSRF) vulnerability exists in Halo
CMS ver ...)
TODO: check
CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote attacker to execute
arbitrary ...)
@@ -433,9 +433,9 @@ CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote
attacker to execute arbi
CVE-2026-67846 (Berkeley Out-of-Order Machine (BOOM) commit
5223e44cfeb26f41380057a2eb ...)
TODO: check
CVE-2026-67271 (Dell PowerStore SDNAS, contains an Out-of-bounds Write
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-67262 (Dell PowerStore contains a Missing Authorization
vulnerability. An att ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-66793 (A flaw was found in the governance-policy-addon-controller
component o ...)
TODO: check
CVE-2026-66783 (A flaw was found in the `submariner-operator` component of Red
Hat Adv ...)
@@ -447,47 +447,47 @@ CVE-2026-66781 (A flaw was found in the Submariner
operator. The Submariner Cust
CVE-2026-66780 (A flaw was found in the submariner-operator component. The
`submariner ...)
TODO: check
CVE-2026-66679 (Unauthenticated Broken Access Control in Appointment Hour
Booking <= 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66667 (Unauthenticated Cross Site Scripting (XSS) in Templately <=
3.7.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66651 (Unauthenticated Broken Access Control in MultiVendorX <=
5.0.14 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66646 (Contributor Cross Site Scripting (XSS) in WP Tab Widget <=
1.2.11 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66645 (Contributor Cross Site Scripting (XSS) in Table Of Contents
Block <= 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66644 (Contributor Cross Site Scripting (XSS) in Typing Effect <=
1.3.7 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66643 (Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <=
1.55 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66641 (Contributor Cross Site Scripting (XSS) in Video Conferencing
with Zoom ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66640 (Contributor Cross Site Scripting (XSS) in Login With Ajax <=
4.5.1 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66639 (Contributor Cross Site Scripting (XSS) in WPZOOM Forms \u2013
Contact ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66638 (Contributor Cross Site Scripting (XSS) in Frontend Admin by
DynamiApps ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66637 (Contributor Cross Site Scripting (XSS) in Featured Video Plus
<= 2.3.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66636 (Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66635 (Unauthenticated Cross Site Request Forgery (CSRF) in Slider by
10Web < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66634 (Subscriber Insecure Direct Object References (IDOR) in Modal
Survey <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66633 (Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro
Add On ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66629 (Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66627 (Contributor Arbitrary File Upload in GP Premium <= 2.5.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66622 (Unauthenticated SQL Injection in Depicter Slider <= 4.8.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate
Dashboard <= 3. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability
caused ...)
TODO: check
CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling
of MySQL ...)
@@ -523,7 +523,7 @@ CVE-2026-61634 (The RabbitMQ Java client library allows
Java and JVM-based appli
CVE-2026-61574 (authentik is an open-source identity provider. Prior to
2026.2.6 and 2 ...)
TODO: check
CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain
an Expose ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in
Kriptok Cr ...)
TODO: check
CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to
1.11.1, JN ...)
@@ -617,113 +617,113 @@ CVE-2026-48744 (Saleor is an e-commerce platform. From
3.14.67 until 3.21.67, 3.
CVE-2026-48508 (Lemur manages TLS certificate creation. Prior to 1.9.1,
StrictRolePerm ...)
TODO: check
CVE-2026-47630 (NVIDIA Triton Inference Server for Linux contains a
vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47629 (NVIDIA Triton Inference Server for Linux contains a
vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47628 (NVIDIA Triton Inference Server for Linux contains a
vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47627 (NVIDIA Triton Inference Server for Linux contains a
vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47606 (NVIDIA Triton Inference Server for Linux contains a
vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47245 (MyBB is free and open source forum software. Prior to 1.8.40,
the User ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-46482 (### Impact The registration component does not validate the
text-based ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45734 (MyBB is free and open source forum software. Prior to 1.8.40,
the buil ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45733 (Trilium Notes is a cross-platform, hierarchical note taking
applicatio ...)
TODO: check
CVE-2026-45532 (DataEase is an open source data visualization and analysis
tool. Versi ...)
- TODO: check
+ NOT-FOR-US: DataEase
CVE-2026-45129 (MyBB is free and open source forum software. Prior to 1.8.40,
the Admi ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45128 (MyBB is free and open source forum software. Prior to 1.8.40,
the ACP ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45127 (MyBB is free and open source forum software. Prior to 1.8.40,
the ACP ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45126 (MyBB is free and open source forum software. Prior to 1.8.40,
the Admi ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45125 (MyBB is free and open source forum software. Prior to 1.8.40,
the Emai ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45124 (MyBB is free and open source forum software. Prior to 1.8.40,
the Mod ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45123 (MyBB is free and open source forum software. Prior to 1.8.40,
the remo ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45122 (MyBB is free and open source forum software. Prior to 1.8.40,
the cale ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45121 (MyBB is free and open source forum software. Prior to 1.8.40,
the cale ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45120 (MyBB is free and open source forum software. Prior to 1.8.40,
the cale ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45119 (MyBB is free and open source forum software. Prior to 1.8.40,
the Admi ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45118 (MyBB is free and open source forum software. Prior to 1.8.40,
the Cont ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45117 (MyBB is free and open source forum software. From 1.8.13 until
1.8.40, ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45116 (MyBB is free and open source forum software. Prior to 1.8.40,
the user ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45115 (MyBB is free and open source forum software. Prior to 1.8.40,
the Budd ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-44472 (Saleor is an e-commerce platform. From 2.10.0rc1 until
3.21.67, 3.22.6 ...)
TODO: check
CVE-2026-43971 (Improper Encoding or Escaping of Output vulnerability in
ninenines cow ...)
TODO: check
CVE-2026-34884 (SSRF via set_skywalking_url Tool and GraphQL expression
injection vuln ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-32657 (Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0,
Dell UCC ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-32553 (Unauthenticated Server Side Request Forgery (SSRF) in OttoKit
<= 1.1.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32549 (Unauthenticated Broken Access Control in ThumbPress < 6.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32547 (Unauthenticated Cross Site Scripting (XSS) in BP Better
Messages <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32481 (Unauthenticated Broken Authentication in Ezoic <= 2.22.11
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32474 (Contributor Arbitrary File Upload in Templatiq <= 0.2.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32473 (Unauthenticated Server Side Request Forgery (SSRF) in PDF
Smart Viewer ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32472 (Unauthenticated Broken Access Control in Online Contact Widget
<= 1.3. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32470 (Unauthenticated PHP Object Injection in FundEngine <= 1.7.9
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32468 (Unauthenticated Sensitive Data Exposure in Duitku Payment
Gateway <= 2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32467 (Subscriber Server Side Request Forgery (SSRF) in [Aotuman]
Grab WeChat ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32466 (Subscriber SQL Injection in Gravity Forms Bookings premium <=
2.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32465 (Customer PHP Object Injection in Essential Real Estate <=
5.3.3 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32464 (Unauthenticated Local File Inclusion in Theme Test Drive <=
2.9.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32463 (Contributor Arbitrary File Upload in Sync Post With Other Site
<= 1.9. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32444 (Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32333 (Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <=
5.4.7 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-30250 (Cross-site scripting vulnerability in the user documentation
field in ...)
TODO: check
CVE-2026-28571 (Unauthenticated Broken Access Control in FormyChat <= 2.15.7
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28570 (Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28569 (Unauthenticated Cross Site Scripting (XSS) in SSL Zen <=
4.7.43 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28568 (Unauthenticated Cross Site Scripting (XSS) in Quill Forms <=
5.7.1 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28567 (Unauthenticated Broken Access Control in WP Sort Order <=
1.3.5 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28192 (Unauthenticated Arbitrary File Upload in Piotnet Addons For
Elementor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28191 (Subscriber Privilege Escalation in The Grid <= 2.7.9.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24301 (Improper neutralization of special elements used in a command
('comman ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-24185 (NVIDIA NVOS for network switches contains a vulnerability in
the secur ...)
TODO: check
CVE-2026-24184 (NVIDIA Cumulus Linux contains a vulnerability in the Link
Layer Discov ...)
@@ -765,7 +765,7 @@ CVE-2026-18963 (A flaw was found in the reset-credentials
flow of the keycloak-s
CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of
protection a ...)
TODO: check
CVE-2026-18751 (External control of file name or path vulnerability in Citrix
WorkSpac ...)
- TODO: check
+ NOT-FOR-US: Citrix
CVE-2026-18534 (ArcSearch for iOS versions prior to 1.48.0 could keep the
address bar ...)
TODO: check
CVE-2026-18392
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29a025a1789d61171a7c19af1e6d09ace8d79307
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29a025a1789d61171a7c19af1e6d09ace8d79307
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits