Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6003d1b0 by security tracker role at 2026-08-26T07:14:11+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9805 (SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS 
command 0x32 ...)
-       TODO: check
+       NOT-FOR-US: Insyde
 CVE-2026-9252
        REJECTED
 CVE-2026-9250
@@ -47,15 +47,15 @@ CVE-2026-80104 (DB-GPT builds the destination path for an 
uploaded skill from th
 CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When 
processing a spe ...)
        TODO: check
 CVE-2026-79912 (A vulnerability was detected in TOTOLINK N600R 
4.3.0cu.7647_B20210106. ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-79911 (A security vulnerability has been detected in TOTOLINK N600R 
4.3.0cu.7 ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-79845 (A vulnerability was identified in code-projects Simple 
Inventory Syste ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-79804 (A vulnerability was found in SililaWijesinghe Food Ordering 
System up  ...)
        TODO: check
 CVE-2026-79793 (A vulnerability has been found in code-projects Online 
Shopping System ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-79792 (A flaw has been found in zackees transcribe-anything up to 
4.1.0. Affe ...)
        TODO: check
 CVE-2026-79654 (A flaw was found in Katello where the Content View History API 
does no ...)
@@ -719,23 +719,23 @@ CVE-2026-78655 (Punk::Plugin::TOTP versions before 0.05 
for Perl allow the secon
 CVE-2026-78619 (Punk::Plugin::TOTP versions before 0.05 for Perl accept 
another accoun ...)
        TODO: check
 CVE-2026-78146 (The Simple Newsletter Plugin  WordPress plugin before 4.3.3 
does not v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77790 (The RegistrationMagic  WordPress plugin before 6.0.9.4 does 
not saniti ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77789 (The Stripe Payment Forms by WP Full Pay  WordPress plugin 
before 8.5.1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77758 (The Stripe Payment Forms by WP Full Pay  WordPress plugin 
before 8.5.1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77757 (The Directorist: AI-Powered Business Directory, Listings & 
Classified  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77754 (The Kirki  WordPress plugin before 6.0.14 does not perform a 
capabilit ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77695 (The Return Refund and Exchange For WooCommerce WordPress 
plugin before ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77694 (The Eventin  WordPress plugin before 4.1.19 does not properly 
restrict ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77693 (The Order Tip for WooCommerce WordPress plugin before 1.6.0 
does not c ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77680 (An algorithmic complexity flaw exists in libsoup's HTTP Range 
header p ...)
        TODO: check
 CVE-2026-77585 (The Okta Privileged Access client does not reject a leading 
hyphen in  ...)
@@ -747,23 +747,23 @@ CVE-2026-76149 (CorvusSKK contains an integer overflow 
vulnerability, which may
 CVE-2026-76148 (CorvusSKK contains a code injection vulnerability, which may 
lead to a ...)
        TODO: check
 CVE-2026-75798 (The AI Engine  WordPress plugin before 3.7.2 does not perform 
an autho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75797 (The AI Engine  WordPress plugin before 3.7.2 does not confine 
a caller ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75465 (The /api.php/user/get_list endpoint in Maccms v10 
v2026.1000.4055 is v ...)
        TODO: check
 CVE-2026-75421 (aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in 
the IOFil ...)
        TODO: check
 CVE-2026-74932 (The WP Fastest Cache WordPress plugin before 1.5.1 does not 
validate t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-74930 (The Project Manager  WordPress plugin before 4.0.7 does not 
check that ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-74929 (The Project Manager  WordPress plugin before 4.0.7 does not 
restrict s ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-74928 (The Project Manager  WordPress plugin before 4.0.7 does not 
have any a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-74851 (The Pods  WordPress plugin before 3.3.9.1 does not correctly 
compare a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-73335 (Android application "Myna Point" is vulnerable to Improper 
Authorizati ...)
        TODO: check
 CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat 
meant t ...)
@@ -787,9 +787,9 @@ CVE-2026-68513 (OpenEXR is the reference implementation and 
specification for th
 CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by 
securit ...)
        TODO: check
 CVE-2026-66153 (The NEService auto-upgrade process insecurely handles 
temporary files  ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the 
SonicWall NetE ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the 
[N] flag ...)
        TODO: check
 CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in 
Apache Tomcat ...)
@@ -797,21 +797,21 @@ CVE-2026-65905 (Authentication Bypass by Capture-replay 
vulnerability in Apache
 CVE-2026-65637 (Improper Input Validation vulnerability in Apache Tomcat due 
to incomp ...)
        TODO: check
 CVE-2026-65367 (A null pointer dereference was addressed with improved input 
validatio ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition 
vulnerability in Apa ...)
        TODO: check
 CVE-2026-65182 (Improper Access Control, Incorrect Authorization vulnerability 
in Apac ...)
        TODO: check
 CVE-2026-65105 (NVIDIA NemoClaw for Linux contains a vulnerability in its 
inference se ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65099 (NVIDIA NemoClaw for Linux contains a vulnerability in its 
command-line ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65098 (NVIDIA NemoClaw for Linux contains a vulnerability in its 
remote-acces ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65097 (NVIDIA NemoClaw for Linux contains a vulnerability in its 
installation ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65096 (NVIDIA NemoClaw for Linux contains a vulnerability in the 
Telegram bri ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65093 (NVIDIA OpenShell for Linux contains a vulnerability where an 
attacker  ...)
        TODO: check
 CVE-2026-65092 (NVIDIA OpenShell Sandbox for Linux contains a vulnerability 
where an a ...)
@@ -819,27 +819,27 @@ CVE-2026-65092 (NVIDIA OpenShell Sandbox for Linux 
contains a vulnerability wher
 CVE-2026-65091 (NVIDIA OpenShell for all platforms contains a vulnerability 
where a ma ...)
        TODO: check
 CVE-2026-65090 (NVIDIA NemoClaw for Linux contains a vulnerability in its NIM 
manageme ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65089 (NVIDIA NemoClaw for Linux contains a vulnerability in its 
status and l ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65088 (NVIDIA NemoClaw contains a vulnerability where an attacker 
could cause ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65087 (NVIDIA NemoClaw contains a vulnerability where an attacker 
could cause ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65086 (NVIDIA OpenShell for Linux contains a vulnerability in its 
sandbox exe ...)
        TODO: check
 CVE-2026-65085 (NVIDIA OpenShell for Linux contains a vulnerability in its 
inference p ...)
        TODO: check
 CVE-2026-65084 (NVIDIA NemoClaw for Linux contains a vulnerability in its 
deployment p ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65083 (NVIDIA OpenShell for Linux contains a vulnerability in its 
sandbox pro ...)
        TODO: check
 CVE-2026-65082 (NVIDIA NemoClaw for Linux contains a vulnerability in its 
migration co ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-65081 (NVIDIA NemoClaw for Linux contains a vulnerability in its 
installation ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-64705 (A buffer overflow was addressed with improved bounds checking. 
This is ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-63404 (Faktory is a language-agnostic background job server. In 
versions prio ...)
        TODO: check
 CVE-2026-63403 (Faktory is a language-agnostic background job server. In 
versions prio ...)
@@ -853,7 +853,7 @@ CVE-2026-62861 (TypeBot is a chatbot builder tool. Prior to 
3.18.0, any authenti
 CVE-2026-59981 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
        TODO: check
 CVE-2026-58108 (The personal access token removal query selects 
fromPersonalAccessToke ...)
-       TODO: check
+       NOT-FOR-US: Ericsson
 CVE-2026-58097 (mp_SetEnddisc() copied a user-supplied PSN endpoint value 
without leng ...)
        TODO: check
 CVE-2026-58096 (LcpDecodeConfig() did not validate the length of received 
endpoint dis ...)
@@ -877,7 +877,7 @@ CVE-2026-57171 (Compliance-trestle (Trestle) is a Python 
SDK and command-line to
 CVE-2026-57170 (Compliance-trestle (Trestle) is a Python SDK and command-line 
tool for ...)
        TODO: check
 CVE-2026-55805 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-55588 (ORAS (OCI Registry As Storage) is a CLI and library for 
managing artif ...)
        TODO: check
 CVE-2026-54757 (Compliance-trestle (Trestle) is a Python SDK and command-line 
tool for ...)
@@ -901,13 +901,13 @@ CVE-2026-45018 (Chainlit is a Python framework for 
building production-ready con
 CVE-2026-44476 (Doorkeeper is an OAuth 2 provider for Ruby on Rails. In 
version 1.9.0, ...)
        TODO: check
 CVE-2026-43670 (A Content Security Policy bypass was addressed with improved 
enforceme ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-43657 (A permissions issue was addressed with additional 
restrictions. This i ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-41707 (Authentication Bypass by Capture-replay vulnerability in 
Spring Spring ...)
        TODO: check
 CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & 
Ecosystem ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version 
source snapsh ...)
        TODO: check
 CVE-2026-38474 (GazellePW (GazellePosterWall) commit 
86c4bedf727691b5a97af42a4864869d1 ...)
@@ -933,55 +933,55 @@ CVE-2026-32637 (Velero is an open source tool for backing 
up, restoring, and mig
 CVE-2026-29988 (A cleartext transmission of sensitive information 
vulnerability in the ...)
        TODO: check
 CVE-2026-19760 (The WP Fastest Cache \u2013 WordPress Cache Plugin plugin for 
WordPres ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19718 (The BlogVault Backup & Staging WordPress plugin before 6.65, 
MalCare W ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19632 (The TranslatePress \u2013 Translate Multilingual sites with AI 
Transla ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19226 (The Royal Addons for Elementor  WordPress plugin before 
1.7.1066 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19220 (The Forminator Forms  WordPress plugin before 1.57.1 does not 
verify t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19094 (The Tutor LMS  WordPress plugin before 4.0.6 does not validate 
values  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18985 (Incorrect Authorization vulnerability in Drupal Edit in-place 
field al ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-18431 (The Avada theme for WordPress is vulnerable to Arbitrary File 
Write in ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18331 (The Formidable Forms \u2013 WordPress Form Builder for Contact 
Forms,  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18261 (Vulnerability in Drupal Powerful Surveys. This issue affects 
Powerful  ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-18260 (Vulnerability in Drupal Disable Login Page. This issue affects 
Disable ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-18259 (Observable Timing Discrepancy vulnerability in Drupal Token 
Content Ac ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-16986 (The Booking Package WordPress plugin before 1.7.25 does not 
validate t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16984 (The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, 
Cookie P ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16646 (Vulnerability in Drupal PanKM. This issue affects PanKM 
versions: *.*.)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-16645 (Missing Authorization vulnerability in Drupal PhotoSwipe - 
Responsive  ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-16644 (Incorrect Authorization vulnerability in Drupal Webform REST 
allows Fo ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-16643 (Vulnerability in Drupal Lunr exposed filters. This issue 
affects Lunr  ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-16642 (Vulnerability in Drupal Email Login OTP. This issue affects 
Email Logi ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-16641 (Vulnerability in Drupal Commerce Elavon. This issue affects 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-16640 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-16639 (Authentication Bypass Using an Alternate Path or Channel 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-16638 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-15917 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-15916 (Missing Authorization vulnerability in Drupal Drupal core 
allows Force ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-15366 (A control logic defect in a specific built-in webpage of Kids 
Mode all ...)
        TODO: check
 CVE-2026-15365 (A pop-up logic flaw in a certain feature of Kids Mode allows 
users to  ...)
@@ -989,19 +989,19 @@ CVE-2026-15365 (A pop-up logic flaw in a certain feature 
of Kids Mode allows use
 CVE-2026-15203 (Improper access control in debug and engineering interfaces in 
Danfoss ...)
        TODO: check
 CVE-2026-15088 (Vulnerability in Drupal Development Environment. This issue 
affects De ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-14550 (The WPCafe  WordPress plugin before 3.0.18 does not perform an 
authori ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14216 (The Booking for Appointments and Events Calendar  WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14212 (The Booking for Appointments and Events Calendar  WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13406 (The Royal Addons for Elementor  WordPress plugin before 
1.7.1066 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13404 (The Royal Addons for Elementor  WordPress plugin before 
1.7.1066 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13172 (The Eventin  WordPress plugin before 4.1.22 does not restrict 
access t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-80184 (In OpenStack Keystone before 29.0.3, tokens obtained via 
delegated aut ...)
        - keystone <unfixed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/25/9



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6003d1b0af0b5e03b8b0f301beab0cb1b1ca3baf

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6003d1b0af0b5e03b8b0f301beab0cb1b1ca3baf
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to