Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
edcd239a by security tracker role at 2026-08-20T19:15:12+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9033 (An unauthenticated attacker with network access to the captive 
portal  ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-8717
        REJECTED
 CVE-2026-7485 (Incorrect authorization in frozen BI aggregations in Checkmk 
<2.5.0p2, ...)
@@ -11,39 +11,39 @@ CVE-2026-77148 (A vulnerability was found in Comfast 
CF-N1-S 2.6.0.1. This impac
 CVE-2026-77118 (A heap out-of-bounds write exists in the Photo CD (PCD) 
decoder of Gra ...)
        TODO: check
 CVE-2026-77085 (n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF 
protection ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77084 (n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains 
a code e ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77083 (n8n is a workflow automation platform. In versions prior to 
1.123.69,  ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77082 (n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 
2.34.1 conta ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77081 (n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 
contain  ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77080 (n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 
2.34.1 conta ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77079 (n8n before 2.34.1 and 2.33.4 contains an authorization bypass 
in the c ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77077 (n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a 
JavaScript  ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77076 (n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an 
informatio ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77075 (n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 
2.34.1 conta ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77074 (n8n versions before 1.123.69 contain a server-side request 
forgery vul ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77073 (n8n versions before 2.34.1 contain a credential validation 
bypass in t ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77072 (n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored 
cross-site s ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77071 (n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST 
filter in ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77070 (n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL 
injection vul ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77069 (n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF 
protection by ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77068 (n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote 
code execu ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-77067 (The setWebhookResolver in 
packages/api/src/resolvers/webhooks/index.ts ...)
        TODO: check
 CVE-2026-77066 (The scanFeedsResolver in 
packages/api/src/resolvers/subscriptions/inde ...)
@@ -51,37 +51,37 @@ CVE-2026-77066 (The scanFeedsResolver in 
packages/api/src/resolvers/subscription
 CVE-2026-77036 (A vulnerability was found in elunez eladmin up to 2.7. The 
impacted el ...)
        TODO: check
 CVE-2026-77031 (A vulnerability has been found in Tenda CH22 1.0.0.1. The 
affected ele ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-77026 (Joomla Extension - tassos.gr - Client-controlled validation 
bypass in  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77025 (A weakness has been identified in itsourcecode Hospital 
Management Sys ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-77022 (A security flaw has been discovered in Comfast CF-N1-S 
2.6.0.1. Affect ...)
        TODO: check
 CVE-2026-77020 (A vulnerability was identified in CodeAstro Apartment Visitor 
Manageme ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2026-77019 (A vulnerability was determined in CodeAstro Apartment Visitor 
Manageme ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2026-77014 (A flaw was found in libsoup's SoupServer HTTP Range header 
processing. ...)
        TODO: check
 CVE-2026-77004 (A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts 
the fun ...)
        TODO: check
 CVE-2026-76999 (A vulnerability was detected in SourceCodester CET Automated 
Grading S ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-76998 (A security vulnerability has been detected in SourceCodester 
Simple On ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-76997 (A weakness has been identified in SourceCodester Simple Online 
Food Or ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-76996 (A security flaw has been discovered in SourceCodester Simple 
Online Fo ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-76995 (A vulnerability was identified in SourceCodester Simple Online 
Food Or ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-76993 (A vulnerability was determined in GreyDGL PentestGPT up to 
1.0.0. This ...)
        TODO: check
 CVE-2026-76991 (A vulnerability was found in itsourcecode Hospital Management 
System 1 ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-76990 (A vulnerability has been found in code-projects Simple 
Inventory Syste ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-76989 (A security vulnerability has been detected in liftoff-sr 
CIPster 18025 ...)
        TODO: check
 CVE-2026-76988 (A weakness has been identified in liftoff-sr CIPster 
1802525be27d33e19 ...)
@@ -95,21 +95,21 @@ CVE-2026-76641 (Expat through 2.8.3 contains an 
out-of-bounds read vulnerability
 CVE-2026-76635 (baserCMS before 5.3.0 contains a SQL injection vulnerability 
in BcData ...)
        TODO: check
 CVE-2026-76634 (WeGIA before 3.9.2 contains an insecure direct object 
reference vulner ...)
-       TODO: check
+       NOT-FOR-US: WeGIA
 CVE-2026-76633 (WeGIA before 3.9.2 contains an authorization bypass 
vulnerability in t ...)
-       TODO: check
+       NOT-FOR-US: WeGIA
 CVE-2026-76632
        REJECTED
 CVE-2026-76610 (Joomla Extension - yootheme.com - Unauthenticated tag 
modifications in ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-76569 (Joomla Extension - phoca.cz - Reflected XSS via the search GET 
paramet ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-76565 (Joomla Extension - phoca.cz - Reflected XSS via price_from & 
price_to  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-76564 (Joomla Extension - phoca.cz -  Stored XSS via User-Agent 
header in Adm ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-75948 (Joomla Extension - icagenda.com -  Authenticated Stored XSS in 
iCagend ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-75526 (django CMS is an easy-to-use and developer-friendly enterprise 
content ...)
        TODO: check
 CVE-2026-75514 (BunkerWeb is an open-source, next-generation Web Application 
Firewall. ...)
@@ -117,31 +117,31 @@ CVE-2026-75514 (BunkerWeb is an open-source, 
next-generation Web Application Fir
 CVE-2026-75140 (jsoup through 1.23.2, fixed in commit 862ba2f, contains an 
uncontrolle ...)
        TODO: check
 CVE-2026-74021 (Unauthenticated Broken Access Control in Chaplin <= 2.6.8 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74020 (Unauthenticated Broken Access Control in Koji <= 2.2.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74019 (Unauthenticated Broken Access Control in EPROLO Dropshipping 
<= 2.4.2  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74018 (Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74016 (Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74014 (Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74013 (Subscriber SQL Injection in eShipper Commerce <= 2.16.13 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74011 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74001 (Unauthenticated Broken Authentication in User Registration & 
Membershi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73998 (Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73993 (Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73992 (Subscriber Remote Code Execution (RCE) in Query Wrangler <= 
1.5.57 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73402 (Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 
6.3.2 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73259 (Mongoose is an embedded web server and network library. Prior 
to 7.22, ...)
        TODO: check
 CVE-2026-73258 (Mongoose is an embedded web server and network library. Prior 
to 7.22, ...)
@@ -189,9 +189,9 @@ CVE-2026-6260
 CVE-2026-69183 (Monkeytype is a minimalistic and customizable typing test. In 
26.26.0  ...)
        TODO: check
 CVE-2026-68566 (Unauthenticated SQL Injection in BookingPress Appointment 
Booking Pro  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-68564 (Unauthenticated Cross Site Scripting (XSS) in NotificationX 
Pro <= 3.1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66788 (A flaw was found in Lighthouse. A remote attacker, by 
compromising a s ...)
        TODO: check
 CVE-2026-66787 (A flaw was found in the lighthouse component of Red Hat 
Advanced Clust ...)
@@ -199,65 +199,65 @@ CVE-2026-66787 (A flaw was found in the lighthouse 
component of Red Hat Advanced
 CVE-2026-66785 (A flaw was found in Submariner. This vulnerability allows a 
malicious  ...)
        TODO: check
 CVE-2026-66682 (Unauthenticated Privilege Escalation in Abandoned Cart Pro for 
WooComm ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66680 (Unauthenticated SQL Injection in Locatoraid Store Locator <= 
3.9.72 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66677 (Subscriber Broken Authentication in Leyka <= 3.32.3 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66673 (Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66672 (Unauthenticated PHP Object Injection in Flatastic <= 2.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66649 (Unauthenticated SQL Injection in Directory Pro <= 2.5.8 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66647 (Subscriber Broken Access Control in Homlisti <= 3.1.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66616 (Unauthenticated Cross Site Scripting (XSS) in Form Maker by 
10Web <= 1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66615 (Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast 
Publishe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66614 (Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by 
Squirrly S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66612 (Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66611 (Unauthenticated Cross Site Scripting (XSS) in Paymob for 
WooCommerce < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66609 (Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66607 (Unauthenticated Cross Site Scripting (XSS) in Advance Product 
Search < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66606 (Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 
1.2.0 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66605 (Unauthenticated Cross Site Scripting (XSS) in Swatchly \u2013 
WooComme ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66604 (Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 
2.8.173  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66601 (Subscriber Cross Site Scripting (XSS) in Media LIbrary 
Assistant <= 3. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66600 (Author Arbitrary File Upload in Media LIbrary Assistant <= 
3.39 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66598 (Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium 
<= 5.6.0 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66597 (Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 
6.5.1.4  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66595 (Unauthenticated Broken Access Control in WP Data Access <= 
5.5.80 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66594 (Subscriber SQL Injection in WordPress Persistent Login <= 
3.1.0 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66593 (Unauthenticated SQL Injection in Security & Malware scan by 
CleanTalk  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66592 (Unauthenticated SQL Injection in rtMedia for WordPress, 
BuddyPress and ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66590 (Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66586 (Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66583 (Unauthenticated PHP Object Injection in Forminator <= 1.57.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66582 (Unauthenticated Cross Site Scripting (XSS) in TranslatePress 
<= 3.3.2  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66581 (Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 
3.8.14.1 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66002 (Frappe is a full-stack web application framework. Prior to 
15.115.0 an ...)
        TODO: check
 CVE-2026-66001 (Frappe is a full-stack web application framework. Prior to 
15.114.0 an ...)
@@ -293,7 +293,7 @@ CVE-2026-64960 (ATutor Gameme module allows users to upload 
files of any type an
 CVE-2026-64846 (Nix is a package manager for Linux and other Unix systems. 
Prior to 2. ...)
        TODO: check
 CVE-2026-64777 (A malicious builder peer may be able to request an in-context 
file by  ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-63654 (Frappe is a full-stack web application framework. In version 
16.31.0 a ...)
        TODO: check
 CVE-2026-63495 (Libevent is an event notification library. From 
2.2.0-alpha-dev until  ...)
@@ -397,25 +397,25 @@ CVE-2026-46533
 CVE-2026-44725 (EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, 
and con ...)
        TODO: check
 CVE-2026-43678 (An unauthenticated remote peer can crash any 
NIOWebSocket-based server ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-40345 (deepmerge-ts is a typescript library providing functionality 
to deep m ...)
        TODO: check
 CVE-2026-2334 (An issue was discovered in vsDesk v14.0101. An authenticated 
attacker  ...)
        TODO: check
 CVE-2026-28164 (Cross-Site Request Forgery (CSRF) vulnerability in HashThemes 
Easy Ele ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28163 (Missing Authorization vulnerability in myCred New User Approve 
allows  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28150 (Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-21784 (HCL IntelliOps Event Management (IEM) is affected by missing 
or insecu ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-19683 (A vulnerability exists in the Dynamic DNS (DDNS) functionality 
of TP-L ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-19611 (A flaw was found in WildFly Elytron. Password hashing and 
verification ...)
        TODO: check
 CVE-2026-19586 (A pre-authentication OS command injection vulnerability has 
been ident ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-18917 (A flaw was found in libvirt. An unprivileged local user could 
exploit  ...)
        TODO: check
 CVE-2026-18482 (Neo.mjs contains a command injection vulnerability within the 
FileSyst ...)
@@ -509,21 +509,21 @@ CVE-2026-18263 (Parallels RAS Client RDP Backend Service 
Exposed Dangerous Funct
 CVE-2026-18262 (Parallels RAS Client RDP Backend Service Exposed Dangerous 
Function Lo ...)
        TODO: check
 CVE-2026-16932 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16928 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16927 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16926 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16925 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16924 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16923 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16922 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-15743 (Catalyst::Plugin::Static::Simple versions through 0.38 for 
Perl mark r ...)
        TODO: check
 CVE-2026-15706 (Missing authentication for critical function vulnerability in 
Baylan M ...)
@@ -555,21 +555,21 @@ CVE-2026-13097 (A privilege escalation flaw was found in 
FreeIPA. The uniqueness
 CVE-2026-11861 (A flaw was found in FreeIPA. When a trust relationship is 
configured b ...)
        TODO: check
 CVE-2025-62307 (HCL IntelliOps Event Management (IEM) is affected by 
insufficient logg ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-62306 (HCL IntelliOps Event Management (IEM) is affected by 
information omiss ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-62300 (HCL IntelliOps Event Management (IEM) is affected by a race 
condition. ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-62299 (HCL IntelliOps Event Management (IEM) is affected by a least 
privilege ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-53999 (Unauthenticated Broken Access Control in Altair <= 5.2.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2025-15689 (Unauthenticated Privilege Escalation in Capella <= 2.5.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2025-15688 (Unauthenticated SQL Injection in Capella <= 2.5.5 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2025-15637 (Unauthenticated Local File Inclusion in Shuffle <= 1.8 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2025-14601 (An OS command injection vulnerability in vsDesk allows an 
authenticate ...)
        TODO: check
 CVE-2026-XXXX [OSSN-0103]



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/edcd239a3b5ac290dca5ce308ab8b303f2ea4992

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/edcd239a3b5ac290dca5ce308ab8b303f2ea4992
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to