Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
30ee9421 by security tracker role at 2026-08-31T19:14:55+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,17 +1,17 @@
CVE-2026-83497 (Unrestricted deserialization of untrusted data in the cursor
paginatio ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-83492 (Improper input validation vulnerability in Extend Themes Kubio
AI Webs ...)
TODO: check
CVE-2026-82970 (Unrestricted Upload of File with Dangerous Type vulnerability
in WP Le ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82881 (Aix-DB through 1.2.4 renders markdown with raw HTML enabled
into v-htm ...)
TODO: check
CVE-2026-82880 (YaCy Search Server through 1.941 contains an XML external
entity injec ...)
TODO: check
CVE-2026-82879 (DataEase before 2.10.26 contains multiple access control
defects in th ...)
- TODO: check
+ NOT-FOR-US: DataEase
CVE-2026-82878 (DataEase versions before 2.10.26 omit object-level
authorization check ...)
- TODO: check
+ NOT-FOR-US: DataEase
CVE-2026-82877 (ILIAS versions before 9.22, 10.0 through 10.9, and 11.0
through 11.2 c ...)
TODO: check
CVE-2026-82876 (Phison PS3111-S11 controller firmware verifies RSA signatures
using a ...)
@@ -63,7 +63,7 @@ CVE-2026-82854 (Nodemailer before 8.0.4 is vulnerable to SMTP
command injection
CVE-2026-82853 (Nodemailer versions before 8.0.5 contain an SMTP command
injection vul ...)
TODO: check
CVE-2026-82838 (The default docker image shipped for Venueless did not
properly ensure ...)
- TODO: check
+ NOT-FOR-US: rami.io products
CVE-2026-82823
REJECTED
CVE-2026-82821 (A vulnerability was determined in FLVMeta up to 1.2.2.
Affected by thi ...)
@@ -101,13 +101,13 @@ CVE-2026-82801 (A vulnerability was detected in NASA
earthdata-search 1.0.0. Aff
CVE-2026-82797 (Uncontrolled Recursion vulnerability in Samsung Open Source
rlottie al ...)
TODO: check
CVE-2026-82703 (A security flaw has been discovered in Edimax BR-6214K 1.40.
This vuln ...)
- TODO: check
+ NOT-FOR-US: Edimax
CVE-2026-82702 (A vulnerability was identified in Edimax BR-6214K 1.40. This
affects t ...)
- TODO: check
+ NOT-FOR-US: Edimax
CVE-2026-82701 (A vulnerability was determined in code-projects Online
Shopping System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-82700 (A vulnerability was found in code-projects Online Shopping
System 1.0. ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-82699 (A flaw has been found in sambitraj Student Management System
up to 56b ...)
TODO: check
CVE-2026-82698 (A vulnerability was detected in sambitraj
Student-Management-System up ...)
@@ -115,25 +115,25 @@ CVE-2026-82698 (A vulnerability was detected in sambitraj
Student-Management-Sys
CVE-2026-82697 (A security vulnerability has been detected in sambitraj
Student-Manage ...)
TODO: check
CVE-2026-82696 (A weakness has been identified in itsourcecode Sales and
Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82695 (A security flaw has been discovered in Tenda AC18 15.03.05.19.
Impacte ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-82694 (A vulnerability was identified in Tenda AC1206 15.03.06.23.
This issue ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-82693 (A vulnerability was determined in Tenda AC1206 15.03.06.23.
This vulne ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-82692 (A vulnerability was found in D-Link DNS-340L and DNS-345 up to
2026071 ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82691 (A vulnerability has been found in D-Link DNS-320L, DNS-327L,
DNS-340L ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82690 (A flaw has been found in D-Link DNS-327L and DNS-340L up to
20260717. ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82689 (A vulnerability was detected in D-Link DNS-320L, DNS-327L,
DNS-340L an ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82688 (A security vulnerability has been detected in D-Link DNS-340L
and DNS- ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82680 (A weakness has been identified in D-Link DSM-G600 1.01. This
affects a ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82679 (A security flaw has been discovered in diem-project diem up to
5.1.3. ...)
TODO: check
CVE-2026-82678 (A vulnerability was identified in diem-project diem up to
5.1.3. The a ...)
@@ -171,7 +171,7 @@ CVE-2026-82630 (A vulnerability was identified in PowerJob
up to 5.1.2. Impacted
CVE-2026-82629 (A vulnerability was determined in jeecgboot jeewx-boot up to
641ab52c3 ...)
TODO: check
CVE-2026-82217 (In Eclipse Theia versions 1.73.0 up to but not including
1.75.0, the A ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-81624 (Undertow is a flexible performant web server used in JBoss EAP
and Wil ...)
TODO: check
CVE-2026-79750 (MCPHub is a unified hub for centrally managing and dynamically
orchest ...)
@@ -193,53 +193,53 @@ CVE-2026-79743 (MCPHub is a unified hub for centrally
managing and dynamically o
CVE-2026-78422 (Subject::new_for_owner() in the zbus_polkit crate encodes the
uid entr ...)
TODO: check
CVE-2026-78079 (Joomla Extension - joomshaper.com - Open Redirect via Base64
Return Pa ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78078 (Joomla Extension - joomshaper.com - Privileged File Upload
Bypass via ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78077 (Joomla Extension - joomshaper.com - Stored Cross-Site
Scripting (XSS) ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78076 (Joomla Extension - joomshaper.com - Broken Access Control &
Missing Au ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78075 (Joomla Extension - joomshaper.com - Broken Object-Level
Authorization ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78074 (Joomla Extension - miniorgange.com - Unauthenticated arbitrary
extensi ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-77975 (The affected Ebyte product exports administrative
credentials and ot ...)
TODO: check
CVE-2026-77966 (The affectedEbyte productdoes not provide separation between
limited ...)
TODO: check
CVE-2026-76986 (Improper neutralization of input during web page generation in
Apache ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-76985 (Improper neutralization of input during web page generation in
Apache ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-76984 (Improper neutralization of input during web page generation in
Apache ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-76983 (Improper neutralization of input during web page generation in
Apache ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-76982 (Improper neutralization of input during web page generation in
Apache ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-76763 (A flaw was found in SmallRye GraphQL. The number scalar
coercion for B ...)
TODO: check
CVE-2026-76133 (The affectedEbyte product uses a deprecated hashing
algorithm in an ...)
TODO: check
CVE-2026-75802 (AjaxEditableChoiceLabel in wicket-extensions, when constructed
with a ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-75133 (Keep Backup Daily plugin for WordPress before 2.1.4 contains a
sensiti ...)
TODO: check
CVE-2026-75132 (WAPT Server versions 2.6.1.17834 and earlier contains a SQL
injection ...)
TODO: check
CVE-2026-74010 (Missing Authorization vulnerability in John James Jacoby
bbPress allow ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73819 (The affectedEbyte product's vendor configuration utility
permits acc ...)
TODO: check
CVE-2026-72001 (Pangolin before 1.22.0 contains an authentication bypass
vulnerability ...)
TODO: check
CVE-2026-71378 (ResourceIsolationRequestCycleListener protects a Wicket
application ag ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-71257 (Apache Wicket enforces the upload limits configured on a form
or uploa ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-70449 (Improper validation of resource URL attributes in Apache
Wicket allows ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2
contains ...)
TODO: check
CVE-2026-63083
@@ -259,137 +259,137 @@ CVE-2026-53508 (oasdiff is a command-line and Go
package that compares and detec
CVE-2026-53507 (oasdiff-action is a GitHub Action that detects breaking
changes in Ope ...)
TODO: check
CVE-2026-51730 (Incorrect access control in the delWiFiAclRules function of
TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51729 (Incorrect access control in the delDevice function of TOTOLINK
T6 4.1. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51728 (Incorrect access control in the UploadFirmwareFile function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51727 (Incorrect access control in the SystemSettings function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51726 (Incorrect access control in the delParentalRules function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51725 (Incorrect access control in the NTPSyncWithHost function of
TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51724 (Incorrect access control in the delSmartQosCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51723 (Incorrect access control in the UploadCustomModule function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51722 (Incorrect access control in the setWiFiRepeaterCfg function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51721 (Incorrect access control in the setPairCfg function of
TOTOLINK T6 4.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51720 (Incorrect access control in the delIpPortFilterRules function
of TOTOL ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51719 (Incorrect access control in the delUrlFilterRules function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51718 (Incorrect access control in the delStaticDhcpRules function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51717 (Incorrect access control in the setOpModeCfg function of
TOTOLINK T6 4 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51716 (Incorrect access control in the delPortForwardRules function
of TOTOLI ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51715 (Incorrect access control in the delMacFilterRules function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51714 (Incorrect access control in the setRoamingCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51713 (Incorrect access control in the setManualDialCfg function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51712 (Incorrect access control in the setApWiFiSchCfg function of
TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51711 (Incorrect access control in the setWiFiWpsStart function of
TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51710 (Incorrect access control in the setParentalRules function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51709 (Incorrect access control in the setWiFiBasicCfg function of
TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51708 (Incorrect access control in the setWiFiWpsCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51706 (Incorrect access control in the setSmartQosCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51705 (Incorrect access control in the setWiFiMeshName function of
TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51704 (Incorrect access control in the setWiFiMeshConfig function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51703 (Incorrect access control in the setWiFiScheduleCfg function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51702 (Incorrect access control in the setIpPortFilterRules function
of TOTOL ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51701 (Incorrect access control in the setMacFilterRules function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51700 (Incorrect access control in the setWiFiAdvancedCfg function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51699 (Incorrect access control in the setDmzCfg function of TOTOLINK
T6 4.1. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51698 (Incorrect access control in the setUrlFilterRules function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51697 (Incorrect access control in the setIptvCfg function of
TOTOLINK T6 4.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51696 (Incorrect access control in the setPortForwardRules function
of TOTOLI ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51695 (Incorrect access control in the setDdnsCfg function of
TOTOLINK T6 4.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51694 (Incorrect access control in the setStaticDhcpRules function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51693 (Incorrect access control in the setVpnPassCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51692 (Incorrect access control in the setWiFiGuestCfg function of
TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51691 (Incorrect access control in the setUploadSetting function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51690 (Incorrect access control in the setWanCfg function of TOTOLINK
T6 4.1. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51689 (Incorrect access control in the setUpgradeFW function of
TOTOLINK T6 4 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51688 (Incorrect access control in the setWiFiSignalCfg function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51687 (Incorrect access control in the setWiFiEasyGuestCf function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51686 (Incorrect access control in the setWiFiEasyCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51684 (Incorrect access control in the setStorageCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51683 (Incorrect access control in the setLanCfg function of TOTOLINK
T6 4.1. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51681 (Incorrect access control in the setRemoteCfg function of
TOTOLINK T6 4 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51680 (Incorrect access control in the setLedCfg function of TOTOLINK
T6 4.1. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51679 (Incorrect access control in the setPasswordCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51678 (Incorrect access control in the setSyslogCfg function of
TOTOLINK T6 4 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51677 (Incorrect access control in the setUPnPCfg function of
TOTOLINK T6 4.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51676 (Incorrect access control in the setAccessDeviceCfg function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51675 (Incorrect access control in the setWanIeCfg function of
TOTOLINK T6 4. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51674 (Incorrect access control in the setScheduleCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51673 (Incorrect access control in the setNtpCfg function of TOTOLINK
T6 4.1. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51672 (Incorrect access control in the getRoamingCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51671 (Incorrect access control in the getCloudDownloadStatus
function of TOT ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51670 (Incorrect access control in the getSlaveUpdate function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51669 (Incorrect access control in the getPairCfg function of
TOTOLINK T6 4.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51668 (Incorrect access control in the setLanguageCfg function of
TOTOLINK T6 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51667 (Incorrect access control in the getWiFiIpMacTable function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51666 (Incorrect access control in the setWizardCfg function of
TOTOLINK T6 4 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51153 (Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in
web/hand ...)
TODO: check
CVE-2026-51152 (Server-side request forgery (SSRF) in the /har/test endpoint
in QD 202 ...)
TODO: check
CVE-2026-49003 (Attackers can exploit command injection vulnerabilities to
delete core ...)
- TODO: check
+ NOT-FOR-US: ZTE
CVE-2026-21827 (HCL Connections is vulnerable to an information disclosure
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-19702 (Improper neutralization of special elements used in an OS
command ('OS ...)
TODO: check
CVE-2026-19616 (Missing Authorization vulnerability in TBC Technology Inc.
KitLogistic ...)
@@ -399,13 +399,13 @@ CVE-2026-19410 (An Incorrect Authorization vulnerability
in GitHub Trigger Comme
CVE-2026-17615 (A flaw was found in RESTEasy's SourceProvider. This
vulnerability allo ...)
TODO: check
CVE-2026-14696 (When Ethernet bridging is enabled
(CONFIG_NET_ETHERNET_BRIDGE), eth_br ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-14368 (The LwM2M JSON content formatter's get_string() in
subsys/net/lib/lwm2 ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-14367 (The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out
statica ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-14366 (The Silicon Labs SiWx917 WiFi driver's transmit callback
siwx91x_send( ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12894 (A flaw was found in the Qute template engine, which is used by
Quarkus ...)
TODO: check
CVE-2024-58379 (nodemailer before 6.9.9 contains a regular expression denial
of servic ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30ee9421a770c1c3c944ac3644de2b8f117e0b85
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30ee9421a770c1c3c944ac3644de2b8f117e0b85
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits