Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8960a777 by security tracker role at 2026-08-21T19:14:50+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -41,7 +41,7 @@ CVE-2026-77751 (A path traversal vulnerability existed in the
handling of MISP o
CVE-2026-77710 (A vulnerability in misp-stix could allow a crafted STIX
document to in ...)
TODO: check
CVE-2026-77686 (A weakness has been identified in Dolibarr up to 23.0.4. This
affects ...)
- TODO: check
+ NOT-FOR-US: Dolibarr
CVE-2026-77683 (A security flaw has been discovered in Comfast CF-N1-S
2.6.0.1. Affect ...)
TODO: check
CVE-2026-77681 (A vulnerability was identified in CodeAstro Online Job Portal
1.0. Aff ...)
@@ -59,19 +59,19 @@ CVE-2026-77645 (A critical remote code execution (RCE)
vulnerability has been re
CVE-2026-77644 (A critical bypass access control vulnerability has been
reported in PT ...)
TODO: check
CVE-2026-77392 (A weakness has been identified in SourceCodester Dynamic Input
Field G ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-77391 (A security flaw has been discovered in SourceCodester Dynamic
Input Fi ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-77264 (The Automation Web Platform \u2013 Notifications and OTP for
WooCommer ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77237 (Missing queue-set type validation in xQueueAddToSet() in the
FreeRTOS- ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-77236 (Missing minimum size validation in secure context allocation
in FreeRT ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-77235 (Missing privilege verification in the secure context cleanup
handler i ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-77234 (Improper input validation in FreeRTOS-Kernel before 11.3.1
might allow ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-77151 (A security flaw has been discovered in lin-snow Ech0 up to
5.4.1. Affe ...)
TODO: check
CVE-2026-77113 (Path traversal in apport-unpack in Canonical Apport
before2.36.0,2.34. ...)
@@ -79,17 +79,17 @@ CVE-2026-77113 (Path traversal in apport-unpack in
Canonical Apport before2.36.0
CVE-2026-77087 (Paperclip before 0.3.1 in default local_trusted mode fails to
validate ...)
TODO: check
CVE-2026-77086 (SiYuan before v3.7.4 fails to validate the packageName
parameter in Ba ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-77029 (Joomla Extension - yootheme.com - Missing CSRF tokens on
front-end sta ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-77028 (Joomla Extension - yootheme.com - Reflected XSS and open
redirect via ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-76613 (Joomla Extension - yootheme.com - Authenticated, privileged
SQL inject ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-76612 (Joomla Extension - yootheme.com - Unauthenticated stored XSS
via user- ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-76611 (Joomla Extension - yootheme.com - Unauthenticated arbitrary
directory ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-76158 (External Control of File Name or Path in the upload API
endpoint of Da ...)
TODO: check
CVE-2026-76157 (Missing authentication for a critical function in the upload
API endpo ...)
@@ -117,7 +117,7 @@ CVE-2026-76018 (Privilege elevation in Import in Google
Chrome prior to 151.0.79
CVE-2026-76017 (Use after free in Chromoting in Google Chrome prior to
151.0.7922.173 ...)
TODO: check
CVE-2026-75946 (A potential security vulnerability has been identified in the
OMEN Gam ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-75933 (Jet Admin allows an authenticated attacker to inject
JavaScript via th ...)
TODO: check
CVE-2026-75932 (Jet Admin allows an attacker to create a malicious app and
connect it ...)
@@ -125,15 +125,15 @@ CVE-2026-75932 (Jet Admin allows an attacker to create a
malicious app and conne
CVE-2026-75928 (The Brushfire platform's video content streaming application
(https:// ...)
TODO: check
CVE-2026-75910 (Incorrect privilege assignment in the ClickHouse connector
deployment ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-75796 (The AI Engine WordPress plugin before 3.6.1 does not verify
that the ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75501 (A vulnerability in the Calix EXOS firmware for the GS7 XGS
(GS5239XG) ...)
TODO: check
CVE-2026-75484 (Improper Neutralization of CRLF Sequences ('CRLF Injection')
vulnerabi ...)
TODO: check
CVE-2026-75115 (Joomla Extension - yootheme.com - Authenticated, privileged
arbitrary ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-74866 (@fastify/busboy is a multipart form-data parser for Node.js.
Its multi ...)
TODO: check
CVE-2026-74836 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
@@ -179,29 +179,29 @@ CVE-2026-70652 (libvips is a fast image processing
library with low memory needs
CVE-2026-70651 (libvips is a fast image processing library with low memory
needs. Prio ...)
TODO: check
CVE-2026-70105 (Improper input validation in Microsoft Office Word allows an
unauthori ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69855 (Server-side request forgery (ssrf) in Microsoft Copilot in
Azure allow ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69851 (Server-side request forgery (ssrf) in Azure Active Directory
allows an ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69836 (Deserialization of untrusted data in Microsoft Entra ID allows
an unau ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69701
REJECTED
CVE-2026-69558 (Authorization bypass through user-controlled key in Microsoft
Partner ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69555 (Incorrect authorization in Azure Arc allows an unauthorized
attacker t ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69543 (Server-side request forgery (ssrf) in Azure Virtual Machines
allows an ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69519 (Observable response discrepancy in Azure Stack HCI allows an
unauthori ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69502 (Server-side request forgery (ssrf) in Azure SQL Database
allows an una ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69419 (Integer overflow or wraparound in Azure Data Manager for
Energy allows ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69400 (Improper limitation of a pathname to a restricted directory
('path tra ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69242 (libvips is a fast image processing library with low memory
needs. Prio ...)
TODO: check
CVE-2026-69099
@@ -209,11 +209,11 @@ CVE-2026-69099
CVE-2026-68921 (DiceBear is an avatar library for designers and developers.
Prior to 9 ...)
TODO: check
CVE-2026-68789 (Improper neutralization of special elements used in an sql
command ('s ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-68782 (Improper neutralization of special elements used in an sql
command ('s ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-68745 (Certificate validation failures in SAML authentication in
Apache Cloud ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-67567 (A flaw was found in the multicloud-operators-subscription
component. T ...)
TODO: check
CVE-2026-67448 (Mailpit is an email testing tool and API for developers. From
1.29.0 u ...)
@@ -225,43 +225,43 @@ CVE-2026-67446 (Mailpit is an email testing tool and API
for developers. Prior t
CVE-2026-67445 (Mailpit is an email testing tool and API for developers. Prior
to 1.30 ...)
TODO: check
CVE-2026-66722 (Improper authorization for CRUD operations on Project Roles
and Projec ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66721 (Missing authorization issue for domain admins in CloudStack's
host tag ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66309 (Improper access control in Azure SQL Database allows an
authorized att ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-65816 (Use of incorrectly-resolved name or reference in Azure Arc
allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-65801 (Server-side request forgery (ssrf) in Microsoft Exchange
Online allows ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-65770 (Improper neutralization of argument delimiters in a command
('argument ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-65645 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3,
8.4.6. 8.3. ...)
TODO: check
CVE-2026-65644 (Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3,
8.4.6, 8.3. ...)
TODO: check
CVE-2026-65613 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-64773 (An attacker that can reach a container's published TCP port
may be abl ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-63726
REJECTED
CVE-2026-63723
REJECTED
CVE-2026-63509 (Relative path traversal in Microsoft Fabric allows an
authorized attac ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-63466 (Unleash is an open-source feature management platform. Prior
to 8.0.3, ...)
TODO: check
CVE-2026-63462 (Unleash is an open-source feature management platform. Prior
to 7.5.2, ...)
TODO: check
CVE-2026-63046 (Improper Neutralization of Argument Delimiters in a Command
('Argument ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-63004 (Unleash is an open-source feature management platform. Prior
to 7.5.2, ...)
TODO: check
CVE-2026-62945 (TREK is a collaborative travel planner. Prior to 3.1.3, TREK
file uplo ...)
TODO: check
CVE-2026-62834 (Improper verification of cryptographic signature in Azure Data
Factory ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-62677 (Omnigent is an open-source AI agent framework and meta-harness
for orc ...)
TODO: check
CVE-2026-62676 (Omnigent is an open-source AI agent framework and meta-harness
for orc ...)
@@ -271,39 +271,39 @@ CVE-2026-62675 (Omnigent is an open-source AI agent
framework and meta-harness f
CVE-2026-62674 (Omnigent is an open-source AI agent framework and meta-harness
for orc ...)
TODO: check
CVE-2026-62440 (Improper Access Control vulnerability in Apache CloudStack's
Kubernete ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-61422 (Authenticated pre-validation SSRF vulnerability in Apache
CloudStack's ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-61400 (Improper Neutralization of Special Elements used in a Command
('Comman ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-61399 (Improper Encoding or Escaping of Output vulnerability in
Apache CloudS ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-61398 (Improper Encoding or Escaping of Output vulnerability in
Apache CloudS ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-61397 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-59799 (Improper Privilege Management vulnerability in Apache
CloudStack's Two ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-59780 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-59657 (Cleartext Storage of Sensitive Information vulnerability in
Apache Clo ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-59655 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-59654 (Missing Release of Resource after Effective Lifetime
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-59323 (An application using Micrometer Tracing with W3C baggage
propagation i ...)
TODO: check
CVE-2026-59318 (In Spring AI's tool calling support, the per-request tool list
is adve ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59308 (In Spring AI's Semantic Cache support, the context hash used
to isolat ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59296 (Using untrusted, non-normalized input as-is for metrics data
(such as ...)
TODO: check
CVE-2026-59279 (The MCP Streamable HTTP server transport (WebFlux and WebMvc
variants) ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59085 (Server-Side Request Forgery (SSRF) vulnerability in Apache
CloudStack' ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-57835
REJECTED
CVE-2026-56875
@@ -325,9 +325,9 @@ CVE-2026-55489 (BigBlueButton is an open-source virtual
classroom. Prior to 3.0.
CVE-2026-55241 (Checkmate is an open-source, self-hosted tool designed to
track and mo ...)
TODO: check
CVE-2026-55015 (Uncontrolled search path element in Windows Remote Help allows
an auth ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-55013 (Uncontrolled search path element in Windows Remote Help
Defense allows ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-54789 (mod_auth_openidc is an OpenID Certified authentication and
authorizati ...)
TODO: check
CVE-2026-54682 (DiscordChatExporter saves Discord chat logs to a file. Prior
to 2.47.2 ...)
@@ -361,11 +361,11 @@ CVE-2026-52021 (An issue in code100xDevs 100xdevs CMS
v.1.0 (2026-04-30) allows
CVE-2026-50278 (iccDEV provides a set of libraries and tools for working with
ICC colo ...)
TODO: check
CVE-2026-50222 (Missing Authorization, Exposure of Sensitive Information to an
Unautho ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-50192 (Kerberos Agent is an open source video (surveillance)
management agent ...)
TODO: check
CVE-2026-50112 (SSRF via Metalink Mirror URL Resolution: An authenticated
tenant can ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-49436 (LinkAce is a self-hosted archive to collect website links.
Prior to ve ...)
TODO: check
CVE-2026-49245 (SFTPGo is an open source, event-driven file transfer solution.
From 2. ...)
@@ -381,7 +381,7 @@ CVE-2026-48590 (XML Injection vulnerability in joshnuss
xml_builder (XmlBuilder
CVE-2026-47827 (Command Injection in BOSH CLI tool on windows in Cloud Foundry
allows ...)
TODO: check
CVE-2026-47359 (Improper Neutralization of Special Elements used in an OS
Command ('OS ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-47080 (XML Injection vulnerability in joshnuss xml_builder
(XmlBuilder module ...)
TODO: check
CVE-2026-47079 (Inappropriate Encoding for Output Context vulnerability in
joshnuss xm ...)
@@ -391,15 +391,15 @@ CVE-2026-46682 (BigBlueButton is an open-source virtual
classroom. Prior to 3.0.
CVE-2026-46355 (BigBlueButton is an open-source virtual classroom. Prior to
3.0.23, Bi ...)
TODO: check
CVE-2026-45202 (Software installed and run as a non-privileged user may
conduct GPU sy ...)
- TODO: check
+ NOT-FOR-US: Imagination Technologies
CVE-2026-45201 (Software installed and run as a non-privileged user may
conduct improp ...)
- TODO: check
+ NOT-FOR-US: Imagination Technologies
CVE-2026-45199 (Kernel software installed and running inside a Guest VM may
post impro ...)
- TODO: check
+ NOT-FOR-US: Imagination Technologies
CVE-2026-43798 (A single crafted SSH message gives an unauthenticated network
attacker ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-43679 (This issue was addressed with improved permissions checking.
This issu ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-41451 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0
contain a ...)
TODO: check
CVE-2026-41450 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0
contain a ...)
@@ -411,183 +411,183 @@ CVE-2026-39909 (llama.cpp before b8585 contains a
use-after-free vulnerability i
CVE-2026-35163 (OctoPrint provides a web interface for controlling consumer 3D
printer ...)
TODO: check
CVE-2026-27875 (Cleartext Storage of Sensitive Information in Memory
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Johnson Controls
CVE-2026-22681 (OpenViking before 0.3.4contains a server-side request forgery
vulnerab ...)
TODO: check
CVE-2026-20679 (The issue was addressed with improved checks. This issue is
fixed in m ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-19848 (The ProfilePress WordPress plugin before 4.17.1 does not strip
shortco ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19783 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19755 (NoSleep 1.5.1 exposes a privileged XPC Mach service and
accepts raw di ...)
TODO: check
CVE-2026-19449 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a
vulnerability in c ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19448 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory
corruptio ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19446 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote
unauthen ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19442 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer
validation ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19441 (Missing authentication for critical function vulnerability in
IKAS Tec ...)
TODO: check
CVE-2026-19437 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19435 (The Duplicate Post WordPress plugin before 1.5.6 does not
check the us ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19085 (The Duplicate Post WordPress plugin before 1.5.6 does not
check that a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18842 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18840 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18835 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote aut ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18832 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18828 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18824 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote aut ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18822 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18781 (The Drag and Drop Multiple File Upload for Contact Form 7
WordPress pl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18716 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote aut ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18670 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18420 (Improper input validation in the Time Series Visual Builder
(TSVB) plu ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18409 (The WPForms Pro plugin for WordPress is vulnerable to Stored
Cross-Sit ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18356 (The Limit Login Attempts Reloaded WordPress plugin before
3.3.5 does n ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17559 (The Passster WordPress plugin before 4.3.9 does not correctly
match it ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17436 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17425 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17424 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17423 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17422 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17252 (A stack-based out-of-bounds write vulnerability exists in the
login re ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-17251 (A NULL pointer dereference vulnerability exists in the HTTP
request pa ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-17250 (A stack-based buffer overflow vulnerability exists in the
firmware upd ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-17195 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17171 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17170 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17168 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote aut ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17165 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17163 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17160 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17159 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17157 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17152 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17145 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17142 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17141 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17138 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17136 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17124 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17122 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17121 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17120 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17118 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17060 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17040 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17024 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17009 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17007 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17006 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17003 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17000 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16997 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16996 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16991 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16989 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16980 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16973 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16972 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16964 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16962 (The Tamara Checkout WordPress plugin through 1.9.9.20 does not
verify ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16959 (The Media Library Assistant WordPress plugin before 3.40 does
not vali ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16958 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16952 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16951 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local auth ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16946 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16945 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16944 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16943 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16937 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16936 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16935 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16934 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16650 (The Charitable WordPress plugin before 1.8.12 does not verify
the auth ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16577 (The Dokan: AI Powered WooCommerce Multivendor Marketplace
Solution Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16576 (The Dokan: AI Powered WooCommerce Multivendor Marketplace
Solution Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16575 (The Dokan: AI Powered WooCommerce Multivendor Marketplace
Solution Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16520 (Improper input validation and Exposure of sensitive
information throug ...)
TODO: check
CVE-2026-16323 (Execution after redirect (EAR) vulnerability in FuyaWeb
Internet and I ...)
@@ -597,19 +597,19 @@ CVE-2026-15580 (vault token disclosure via unvalidated
postMessage vulnerability
CVE-2026-15576 (Improper authentication in the agent receiver of Checkmk
<2.5.0p10 all ...)
TODO: check
CVE-2026-15150 (The myCred WordPress plugin before 3.2.5 does not verify that
the rece ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15046 (The LitExtension WordPress plugin through 1.2.5 does not
verify a nonc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14601 (The Link Whisper Free WordPress plugin before 0.9.7 does not
properly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14325 (The Drag and Drop Multiple File Upload for Contact Form 7
WordPress pl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14208 (Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL
files in ...)
TODO: check
CVE-2026-13736 (The NewPath WildApricotPress Add-on WordPress plugin through
1.0.0 do ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13176 (The Eventin WordPress plugin before 4.1.21 does not validate a
user-su ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11938
REJECTED
CVE-2026-11902
@@ -625,7 +625,7 @@ CVE-2025-3127
CVE-2025-2795
REJECTED
CVE-2025-15671 (The Welcart e-Commerce WordPress plugin before 2.12.1 does not
regener ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2023-7344
REJECTED
CVE-2023-7336
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8960a777bf80c9b86daacd71728f5bcc59cf47c8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8960a777bf80c9b86daacd71728f5bcc59cf47c8
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits