Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6003d1b0 by security tracker role at 2026-08-26T07:14:11+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
CVE-2026-9805 (SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS
command 0x32 ...)
- TODO: check
+ NOT-FOR-US: Insyde
CVE-2026-9252
REJECTED
CVE-2026-9250
@@ -47,15 +47,15 @@ CVE-2026-80104 (DB-GPT builds the destination path for an
uploaded skill from th
CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When
processing a spe ...)
TODO: check
CVE-2026-79912 (A vulnerability was detected in TOTOLINK N600R
4.3.0cu.7647_B20210106. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-79911 (A security vulnerability has been detected in TOTOLINK N600R
4.3.0cu.7 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-79845 (A vulnerability was identified in code-projects Simple
Inventory Syste ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-79804 (A vulnerability was found in SililaWijesinghe Food Ordering
System up ...)
TODO: check
CVE-2026-79793 (A vulnerability has been found in code-projects Online
Shopping System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-79792 (A flaw has been found in zackees transcribe-anything up to
4.1.0. Affe ...)
TODO: check
CVE-2026-79654 (A flaw was found in Katello where the Content View History API
does no ...)
@@ -719,23 +719,23 @@ CVE-2026-78655 (Punk::Plugin::TOTP versions before 0.05
for Perl allow the secon
CVE-2026-78619 (Punk::Plugin::TOTP versions before 0.05 for Perl accept
another accoun ...)
TODO: check
CVE-2026-78146 (The Simple Newsletter Plugin WordPress plugin before 4.3.3
does not v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77790 (The RegistrationMagic WordPress plugin before 6.0.9.4 does
not saniti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77789 (The Stripe Payment Forms by WP Full Pay WordPress plugin
before 8.5.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77758 (The Stripe Payment Forms by WP Full Pay WordPress plugin
before 8.5.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77757 (The Directorist: AI-Powered Business Directory, Listings &
Classified ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77754 (The Kirki WordPress plugin before 6.0.14 does not perform a
capabilit ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77695 (The Return Refund and Exchange For WooCommerce WordPress
plugin before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77694 (The Eventin WordPress plugin before 4.1.19 does not properly
restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77693 (The Order Tip for WooCommerce WordPress plugin before 1.6.0
does not c ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77680 (An algorithmic complexity flaw exists in libsoup's HTTP Range
header p ...)
TODO: check
CVE-2026-77585 (The Okta Privileged Access client does not reject a leading
hyphen in ...)
@@ -747,23 +747,23 @@ CVE-2026-76149 (CorvusSKK contains an integer overflow
vulnerability, which may
CVE-2026-76148 (CorvusSKK contains a code injection vulnerability, which may
lead to a ...)
TODO: check
CVE-2026-75798 (The AI Engine WordPress plugin before 3.7.2 does not perform
an autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75797 (The AI Engine WordPress plugin before 3.7.2 does not confine
a caller ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75465 (The /api.php/user/get_list endpoint in Maccms v10
v2026.1000.4055 is v ...)
TODO: check
CVE-2026-75421 (aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in
the IOFil ...)
TODO: check
CVE-2026-74932 (The WP Fastest Cache WordPress plugin before 1.5.1 does not
validate t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74930 (The Project Manager WordPress plugin before 4.0.7 does not
check that ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74929 (The Project Manager WordPress plugin before 4.0.7 does not
restrict s ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74928 (The Project Manager WordPress plugin before 4.0.7 does not
have any a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74851 (The Pods WordPress plugin before 3.3.9.1 does not correctly
compare a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-73335 (Android application "Myna Point" is vulnerable to Improper
Authorizati ...)
TODO: check
CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat
meant t ...)
@@ -787,9 +787,9 @@ CVE-2026-68513 (OpenEXR is the reference implementation and
specification for th
CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by
securit ...)
TODO: check
CVE-2026-66153 (The NEService auto-upgrade process insecurely handles
temporary files ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the
SonicWall NetE ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the
[N] flag ...)
TODO: check
CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in
Apache Tomcat ...)
@@ -797,21 +797,21 @@ CVE-2026-65905 (Authentication Bypass by Capture-replay
vulnerability in Apache
CVE-2026-65637 (Improper Input Validation vulnerability in Apache Tomcat due
to incomp ...)
TODO: check
CVE-2026-65367 (A null pointer dereference was addressed with improved input
validatio ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition
vulnerability in Apa ...)
TODO: check
CVE-2026-65182 (Improper Access Control, Incorrect Authorization vulnerability
in Apac ...)
TODO: check
CVE-2026-65105 (NVIDIA NemoClaw for Linux contains a vulnerability in its
inference se ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65099 (NVIDIA NemoClaw for Linux contains a vulnerability in its
command-line ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65098 (NVIDIA NemoClaw for Linux contains a vulnerability in its
remote-acces ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65097 (NVIDIA NemoClaw for Linux contains a vulnerability in its
installation ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65096 (NVIDIA NemoClaw for Linux contains a vulnerability in the
Telegram bri ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65093 (NVIDIA OpenShell for Linux contains a vulnerability where an
attacker ...)
TODO: check
CVE-2026-65092 (NVIDIA OpenShell Sandbox for Linux contains a vulnerability
where an a ...)
@@ -819,27 +819,27 @@ CVE-2026-65092 (NVIDIA OpenShell Sandbox for Linux
contains a vulnerability wher
CVE-2026-65091 (NVIDIA OpenShell for all platforms contains a vulnerability
where a ma ...)
TODO: check
CVE-2026-65090 (NVIDIA NemoClaw for Linux contains a vulnerability in its NIM
manageme ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65089 (NVIDIA NemoClaw for Linux contains a vulnerability in its
status and l ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65088 (NVIDIA NemoClaw contains a vulnerability where an attacker
could cause ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65087 (NVIDIA NemoClaw contains a vulnerability where an attacker
could cause ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65086 (NVIDIA OpenShell for Linux contains a vulnerability in its
sandbox exe ...)
TODO: check
CVE-2026-65085 (NVIDIA OpenShell for Linux contains a vulnerability in its
inference p ...)
TODO: check
CVE-2026-65084 (NVIDIA NemoClaw for Linux contains a vulnerability in its
deployment p ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65083 (NVIDIA OpenShell for Linux contains a vulnerability in its
sandbox pro ...)
TODO: check
CVE-2026-65082 (NVIDIA NemoClaw for Linux contains a vulnerability in its
migration co ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65081 (NVIDIA NemoClaw for Linux contains a vulnerability in its
installation ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-64705 (A buffer overflow was addressed with improved bounds checking.
This is ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-63404 (Faktory is a language-agnostic background job server. In
versions prio ...)
TODO: check
CVE-2026-63403 (Faktory is a language-agnostic background job server. In
versions prio ...)
@@ -853,7 +853,7 @@ CVE-2026-62861 (TypeBot is a chatbot builder tool. Prior to
3.18.0, any authenti
CVE-2026-59981 (OpenEXR is the reference implementation and specification for
the EXR ...)
TODO: check
CVE-2026-58108 (The personal access token removal query selects
fromPersonalAccessToke ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2026-58097 (mp_SetEnddisc() copied a user-supplied PSN endpoint value
without leng ...)
TODO: check
CVE-2026-58096 (LcpDecodeConfig() did not validate the length of received
endpoint dis ...)
@@ -877,7 +877,7 @@ CVE-2026-57171 (Compliance-trestle (Trestle) is a Python
SDK and command-line to
CVE-2026-57170 (Compliance-trestle (Trestle) is a Python SDK and command-line
tool for ...)
TODO: check
CVE-2026-55805 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-55588 (ORAS (OCI Registry As Storage) is a CLI and library for
managing artif ...)
TODO: check
CVE-2026-54757 (Compliance-trestle (Trestle) is a Python SDK and command-line
tool for ...)
@@ -901,13 +901,13 @@ CVE-2026-45018 (Chainlit is a Python framework for
building production-ready con
CVE-2026-44476 (Doorkeeper is an OAuth 2 provider for Ruby on Rails. In
version 1.9.0, ...)
TODO: check
CVE-2026-43670 (A Content Security Policy bypass was addressed with improved
enforceme ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-43657 (A permissions issue was addressed with additional
restrictions. This i ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-41707 (Authentication Bypass by Capture-replay vulnerability in
Spring Spring ...)
TODO: check
CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons &
Ecosystem ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version
source snapsh ...)
TODO: check
CVE-2026-38474 (GazellePW (GazellePosterWall) commit
86c4bedf727691b5a97af42a4864869d1 ...)
@@ -933,55 +933,55 @@ CVE-2026-32637 (Velero is an open source tool for backing
up, restoring, and mig
CVE-2026-29988 (A cleartext transmission of sensitive information
vulnerability in the ...)
TODO: check
CVE-2026-19760 (The WP Fastest Cache \u2013 WordPress Cache Plugin plugin for
WordPres ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19718 (The BlogVault Backup & Staging WordPress plugin before 6.65,
MalCare W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19632 (The TranslatePress \u2013 Translate Multilingual sites with AI
Transla ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19226 (The Royal Addons for Elementor WordPress plugin before
1.7.1066 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19220 (The Forminator Forms WordPress plugin before 1.57.1 does not
verify t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19094 (The Tutor LMS WordPress plugin before 4.0.6 does not validate
values ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18985 (Incorrect Authorization vulnerability in Drupal Edit in-place
field al ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-18431 (The Avada theme for WordPress is vulnerable to Arbitrary File
Write in ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18331 (The Formidable Forms \u2013 WordPress Form Builder for Contact
Forms, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18261 (Vulnerability in Drupal Powerful Surveys. This issue affects
Powerful ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-18260 (Vulnerability in Drupal Disable Login Page. This issue affects
Disable ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-18259 (Observable Timing Discrepancy vulnerability in Drupal Token
Content Ac ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16986 (The Booking Package WordPress plugin before 1.7.25 does not
validate t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16984 (The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA,
Cookie P ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16646 (Vulnerability in Drupal PanKM. This issue affects PanKM
versions: *.*.)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16645 (Missing Authorization vulnerability in Drupal PhotoSwipe -
Responsive ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16644 (Incorrect Authorization vulnerability in Drupal Webform REST
allows Fo ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16643 (Vulnerability in Drupal Lunr exposed filters. This issue
affects Lunr ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16642 (Vulnerability in Drupal Email Login OTP. This issue affects
Email Logi ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16641 (Vulnerability in Drupal Commerce Elavon. This issue affects
Commerce E ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16640 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16639 (Authentication Bypass Using an Alternate Path or Channel
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16638 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-15917 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-15916 (Missing Authorization vulnerability in Drupal Drupal core
allows Force ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-15366 (A control logic defect in a specific built-in webpage of Kids
Mode all ...)
TODO: check
CVE-2026-15365 (A pop-up logic flaw in a certain feature of Kids Mode allows
users to ...)
@@ -989,19 +989,19 @@ CVE-2026-15365 (A pop-up logic flaw in a certain feature
of Kids Mode allows use
CVE-2026-15203 (Improper access control in debug and engineering interfaces in
Danfoss ...)
TODO: check
CVE-2026-15088 (Vulnerability in Drupal Development Environment. This issue
affects De ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-14550 (The WPCafe WordPress plugin before 3.0.18 does not perform an
authori ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14216 (The Booking for Appointments and Events Calendar WordPress
plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14212 (The Booking for Appointments and Events Calendar WordPress
plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13406 (The Royal Addons for Elementor WordPress plugin before
1.7.1066 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13404 (The Royal Addons for Elementor WordPress plugin before
1.7.1066 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13172 (The Eventin WordPress plugin before 4.1.22 does not restrict
access t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-80184 (In OpenStack Keystone before 29.0.3, tokens obtained via
delegated aut ...)
- keystone <unfixed>
NOTE: https://www.openwall.com/lists/oss-security/2026/08/25/9
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6003d1b0af0b5e03b8b0f301beab0cb1b1ca3baf
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6003d1b0af0b5e03b8b0f301beab0cb1b1ca3baf
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits