Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
208a2809 by security tracker role at 2026-09-05T07:13:27+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,15 +1,15 @@
CVE-2026-9317 (Nango before 0.71.6 contains a missing authentication
vulnerability in ...)
TODO: check
CVE-2026-9186 (IBM Langflow OSS 1.0.0 through 1.11.2 allows remote
authenticated atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-9138 (IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an
authenti ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-8625 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed,
PDF vie ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8623 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed,
PDF vie ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8447 (IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored
cross-site ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-86145 (PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds
write becaus ...)
TODO: check
CVE-2026-86144 (In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and
xmlXInclu ...)
@@ -43,11 +43,11 @@ CVE-2026-86091 (ntopng before 6.7.260717 fails to check
user privileges in the p
CVE-2026-86090 (ntopng before 6.7.260717 fails to perform authorization checks
in the ...)
TODO: check
CVE-2026-85787 (An incomplete list of disallowed inputs in the SQL validation
componen ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85786 (Improper handling of highly compressed data in Amazon ion-java
before ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85781 (Unverified ownership of a storage access point in the volume
deletion ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85769 (A flaw was found in libtpms, a library that provides software
TPM 2.0 ...)
TODO: check
CVE-2026-85730 (smol-toml is a small, fast, and correct TOML parser and
serializer. Pr ...)
@@ -129,9 +129,9 @@ CVE-2026-85661 (excel-mcp-server 0.1.8 fails to enforce
path confinement in stdi
CVE-2026-85660 (cli-mcp-server 0.2.5 contains a command allowlist bypass
vulnerability ...)
TODO: check
CVE-2026-85656 (An OS command injection issue in the
log4j-cve-2021-44228-hotpatch pac ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85654 (Improper neutralization of special elements used in a template
engine ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85651 (Trigger.dev versions before 4.5.2 fail to validate environment
members ...)
TODO: check
CVE-2026-85650 (Trigger.dev before 4.5.2 contains a server-side request
forgery vulner ...)
@@ -139,7 +139,7 @@ CVE-2026-85650 (Trigger.dev before 4.5.2 contains a
server-side request forgery
CVE-2026-85649 ((Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier
contains a fa ...)
TODO: check
CVE-2026-85643 (A flaw has been found in code-projects Online Shopping System
1.0. Imp ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-85639 (A security vulnerability has been detected in jofpin trape
2.0. This v ...)
TODO: check
CVE-2026-85638 (A weakness has been identified in jofpin trape 2.0. This
affects an un ...)
@@ -231,21 +231,21 @@ CVE-2026-85587 (phpMyFAQ before 4.1.8 enforces incorrect
permission checks on ad
CVE-2026-85586 (phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when
the store ...)
TODO: check
CVE-2026-85585 (SiYuan before v3.8.2 contains an unbounded resource
consumption vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85584 (SiYuan versions before v3.8.2 contain a denial of service
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85583 (SiYuan versions before v3.8.2 contain a path traversal
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85582 (SiYuan versions before v3.8.2 contain an unbounded session
creation vu ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85581 (SiYuan before v3.8.2 contains a denial of service
vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85580 (SiYuan versions before v3.8.2 contain a path guard bypass
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85579 (SiYuan is affected by an information disclosure vulnerability
(confirm ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85578 (SiYuan through 3.8.1 contains an authorization bypass
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85577 (AVideo through commit c91b5975d contains a reflected
cross-site script ...)
TODO: check
CVE-2026-85547 (A cross-site request forgery (CSRF) vulnerability exists in
MISP due t ...)
@@ -269,19 +269,19 @@ CVE-2026-85525 (Improper OCSP response validation in the
Snowflake Python, Go, J
CVE-2026-85522 (A vulnerability was detected in valkey-io valkey up to
9.5.4/9.1.0. Af ...)
TODO: check
CVE-2026-85517 (A flaw has been found in code-projects Vehicle Management
System 1.0. ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-85516 (A vulnerability was detected in code-projects Vehicle
Management Syste ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-85514 (A security vulnerability has been detected in StackStorm st2
up to 3.9 ...)
TODO: check
CVE-2026-85513 (A weakness has been identified in StackStorm st2 up to 3.9.0.
This iss ...)
TODO: check
CVE-2026-85512 (A security flaw has been discovered in SourceCodester Class
and Exam T ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-85311 (Missing Authorization vulnerability in Kings Plugins
MarketKing allows ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85229 (** UNSUPPORTED WHEN ASSIGNED **Improper neutralization of
input during ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a
Man-in-the ...)
TODO: check
CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide
whether to r ...)
@@ -299,35 +299,35 @@ CVE-2026-84961 (undici's BalancedPool constructor passes
its entire options obje
CVE-2026-84947 (undici's dump interceptor reads and discards a response body
up to a c ...)
TODO: check
CVE-2026-84937 (The Video Player for YouTube WordPress plugin before 2.1.0
does not p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84936 (The EmbedPress WordPress plugin before 4.6.4 does not have
proper aut ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84935 (The HT Menu WordPress plugin before 1.2.7 does not perform
any capabi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84934 (The JCH Optimize WordPress plugin before 6.0.1 does not
perform a capa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84933 (undici's cache interceptor does not handle the Set-Cookie
response hea ...)
TODO: check
CVE-2026-84931 (The Joli Table Of Contents WordPress plugin before 3.0.3 does
not sani ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84930 (The CatFolders Document Gallery & PDF Library WordPress plugin
before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84927 (The EmbedPress WordPress plugin before 4.6.4 does not perform
a suffi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84926 (The EmbedPress WordPress plugin before 4.6.4 does not
correctly restr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84901 (The Eventin WordPress plugin before 4.1.22 does not properly
check au ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84899 (The VikWidgetsLoader WordPress plugin before 1.12.0 does not
sanitise ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84898 (The Eventin WordPress plugin before 4.1.21 does not properly
validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84896 (The King Addons for Elementor WordPress plugin before 51.1.77
does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84890 (undici's decompress interceptor decompresses response bodies
according ...)
TODO: check
CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not
restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84504 (fastify versions before 5.12.2 treat the object resolved by a
successf ...)
TODO: check
CVE-2026-84469 (fastify versions before 5.12.2 decide whether to compile a
request sch ...)
@@ -335,33 +335,33 @@ CVE-2026-84469 (fastify versions before 5.12.2 decide
whether to compile a reque
CVE-2026-84428 (fastify versions before 5.12.2 implement the case-insensitive
nature o ...)
TODO: check
CVE-2026-84225 (The Kirki WordPress plugin before 6.3.0 does not check that a
user is ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84221 (The Kirki WordPress plugin before 6.3.0 does not escape a
user-suppli ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84045 (The E-cab Taxi Booking Manager for Woocommerce WordPress
plugin before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84044 (The Restaurant Menu and Food Ordering WordPress plugin before
2.4.12 d ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84043 (The ePayco Payment Gateway for WooCommerce WordPress plugin
before 8.4 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84022 (The Bold Page Builder WordPress plugin before 5.9.8 does not
sanitise ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84021 (The Bold Page Builder WordPress plugin before 5.9.8 does not
properly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83628 (The Theme My Login plugin for WordPress is vulnerable to
Missing Autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83627 (The Hummingbird \u2013 Speed Optimization, Caching, Minify,
Compress & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83544 (The Greenshift WordPress plugin before 13.2.0 does not
properly escap ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83543 (The Greenshift WordPress plugin before 13.2.0 does not
validate a use ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82923 (The AI Website Builder WordPress plugin (GitHub build) 1.0.0
does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82911 (Cross-Site Request Forgery (CSRF) in the
OrderConfirmController at GET ...)
TODO: check
CVE-2026-82846 (The Masteriyo LMS WordPress plugin before 3.4.0 does not
sanitise and ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82729 (Inefficient Algorithmic Complexity vulnerability in
elixir-mint mint a ...)
TODO: check
CVE-2026-82728 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
@@ -373,29 +373,29 @@ CVE-2026-82684 (Tycon Systems TPDIN-Monitor-WEB3 versions
2.2.9 and prior are vu
CVE-2026-82538 (ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL
injection v ...)
TODO: check
CVE-2026-82304 (The Music Store WordPress plugin before 1.4.5 does not
sanitise and e ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81939 (A Zip Slip vulnerability in the SonicWall Network Security
Manager (NS ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-81859 (CP4BA - IBM Enterprise Records could allow a local attacker to
obtain ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81832 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81666 (An integer overflow was found in Corosync's handling of
membership com ...)
TODO: check
CVE-2026-81665 (A heap-based buffer overflow was found in Corosync's Totem
Process Gro ...)
TODO: check
CVE-2026-81424 (The Accept Stripe Payments WordPress plugin before 2.1.4 does
not veri ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81423 (The Accept Stripe Payments WordPress plugin before 2.1.4 does
not vali ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81404 (The IPGP Visitors Origin WordPress plugin before 1.6 does not
sanitise ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81348 (The My Private Site WordPress plugin before 4.2.3 does not
apply its ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81302 (PALLET CONTROL products contain an incorrect default
permission vulner ...)
TODO: check
CVE-2026-80190 (Apache Allura: stored XSS via SVN code repositories. Git
repositories ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-80119 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
TODO: check
CVE-2026-80118 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
@@ -437,37 +437,37 @@ CVE-2026-78839 (An arbitrary file upload vulnerability in
AppNitro MachForm v30
CVE-2026-78745 (An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350
Hi3751V352E_DMO allow ...)
TODO: check
CVE-2026-78658 (IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3
through 7 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-78543 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-78438 (The W3 Total Cache plugin for WordPress is vulnerable to
Stored Cross- ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78362 (The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does
not corr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78328 (A missing authorization vulnerability in the SonicWall Network
Securit ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-78327 (An Improper Neutralization of Special Elements used in an OS
Command ( ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-78150 (The Smart Post WordPress plugin before 4.0.8 does not check
the type, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78149 (The Smart Post WordPress plugin before 4.0.8 does not check
whether a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77847 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are
vulnerab ...)
TODO: check
CVE-2026-77830 (The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin
for WordP ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77826 (The RegistrationMagic WordPress plugin before 6.0.9.9 does
not verify ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77822 (IBM ContextForge MCP Gateway could allow a remote
authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-77818 (Improper neutralization of input during web page generation
('cross-si ...)
TODO: check
CVE-2026-77393 (In Ignition 8.1.53 and earlier, the Gateway "Create Project
Role(s)" s ...)
TODO: check
CVE-2026-77263 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie
Consent + m ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77233 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie
Consent + m ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76925 (A flaw was found in Flatpak. A Time-of-check to time-of-use
(TOCTOU) r ...)
TODO: check
CVE-2026-76169 (fastify versions >= 4.0.0 and before 5.12.2 can route a
malformed URL ...)
@@ -475,7 +475,7 @@ CVE-2026-76169 (fastify versions >= 4.0.0 and before 5.12.2
can route a malforme
CVE-2026-75925 (Improper neutralization of CRLF sequences in IXON VPN Client
before ve ...)
TODO: check
CVE-2026-75439 (An issue in Free5GC v.4.2.2 allows a remote attacker to cause
a denial ...)
- TODO: check
+ NOT-FOR-US: Free5GC
CVE-2026-75438 (Buffer Overflow vulnerability in Open5GS v2.7.7 allows a
remote attack ...)
TODO: check
CVE-2026-75431 (PowerJob Server version 5.1.2 (and likely earlier) uses a
predictable ...)
@@ -515,7 +515,7 @@ CVE-2026-74236 (GFI Exinda AI and ClearView before 7.6.5
contains a path travers
CVE-2026-74235 (GFI Exinda AI and ClearView before 7.6.5 contains a path
traversal vul ...)
TODO: check
CVE-2026-73848 (Emlog is an open source website building system. In versions
2.6.29 an ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-71626 (An issue in Invoice Ninja v5.13.24 allows a remote attacker to
obtain ...)
TODO: check
CVE-2026-71625 (An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote
attacker to e ...)
@@ -543,9 +543,9 @@ CVE-2026-61614 (SolidInvoice is an open-source invoicing
platform. Prior to vers
CVE-2026-61608 (SolidInvoice is an open-source invoicing platform. Prior to
version 3. ...)
TODO: check
CVE-2026-5522 (IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains
hard-code ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-57777 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57166 (PJSIP is a free and open source multimedia communication
library writt ...)
TODO: check
CVE-2026-57165 (PJSIP is a free and open source multimedia communication
library writt ...)
@@ -575,11 +575,11 @@ CVE-2026-53761 (Frappe CRM is an open-source customer
relationship management to
CVE-2026-53760 (Admidio is an open-source user management solution. In
versions 5.0.11 ...)
TODO: check
CVE-2026-53758 (Emlog is an open source website building system. In versions
2.6.29 an ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-53757 (Emlog is an open source website building system. In versions
2.6.29 an ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-53756 (Emlog is an open source website building system. Prior to
version 2.6. ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-53604 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh VPN. ...)
TODO: check
CVE-2026-53603 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh VPN. ...)
@@ -619,61 +619,61 @@ CVE-2026-50553 (Note Mark is an open-source note-taking
application. Prior to ve
CVE-2026-4644 (A Missing Authorization vulnerability in HTTP Connector in
Google Clou ...)
TODO: check
CVE-2026-4361 (The Divi theme for WordPress is vulnerable to Server-Side
Request Forg ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-44402 (Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated
remote co ...)
TODO: check
CVE-2026-3853 (The Divi theme for WordPress is vulnerable to DOM-Based Stored
Cross-S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-38961 (Cross-Site Scripting (XSS) vulnerability in the RSS Widget of
Netgate ...)
TODO: check
CVE-2026-32480 (Missing Authorization vulnerability in WC Lovers WCFM
Membership allow ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-31020 (In DocsGPT 0.15.0 and below, the application provides a custom
prompt ...)
TODO: check
CVE-2026-27432 (Authorization Bypass Through User-Controlled Key vulnerability
in sc I ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27347 (Missing Authorization vulnerability in Crocoblock JetPopup
allows Expl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27086 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-19887 (The Welcart e-Commerce plugin for WordPress is vulnerable to
PHP Objec ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19861 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder
WordPress plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19858 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder
WordPress plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19769 (The Ninja Forms \u2013 The Contact Form Builder That Grows
With You pl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19727 (Improper neutralization of input during web page generation
('cross-si ...)
TODO: check
CVE-2026-19649 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An
authenticated user ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19534 (undici's WebSocket client crashes the whole Node.js process
during the ...)
TODO: check
CVE-2026-19306 (IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated
attacker ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19305 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19304 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19303 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19302 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19301 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19300 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19299 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19298 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19283 (IBM Observability with Instana (Agent) Build 1.0.303 through
1.0.323 I ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19274 (IBM Observability with Instana (Agent) Build 1.0.303 through
1.0.323 I ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19205 (Observable response discrepancy vulnerability in GastroMenum
GastroMen ...)
TODO: check
CVE-2026-19081 (Missing Authorization vulnerability in Gastromenum Gastromenum
Ticket ...)
@@ -689,129 +689,129 @@ CVE-2026-19043 (Missing Authorization vulnerability in
Menulux Software Inc. Men
CVE-2026-18957 (Improper neutralization of input during web page generation
('cross-si ...)
TODO: check
CVE-2026-18905 (IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <=
v1.0.6 MC ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18887 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18858 (IBM i 7.6, and 7.5 could allow a local authenticated attacker
to obtai ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18843 (The Beaver Builder Plugin (Starter Version) plugin for
WordPress is vu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18745
REJECTED
CVE-2026-18658 (IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0,
8.11.0.1, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18567 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18540 (undici's retry interceptor can append the body of a ranged
retry respo ...)
TODO: check
CVE-2026-18489 (IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP
Context ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18486 (IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could
allow a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18406 (The SureForms \u2013 Contact Form Builder, AI Forms, Payment
Form, Sur ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18404 (The Social Chat \u2013 Click To Chat App Button plugin for
WordPress i ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18341 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18221 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
gain una ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18198 (Improper neutralization of special elements used in an SQL
command ('S ...)
TODO: check
CVE-2026-18175 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
manipula ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18149 (undici's retry handler can leave an already-exposed response
body pend ...)
TODO: check
CVE-2026-18078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18076 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18073 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated
attacke ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17631 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17627 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17622 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote
authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17621 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17499 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to
execute a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17483 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a
local attac ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17470 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17469 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated
attacke ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17444 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17443 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17442 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17440 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17274 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17273 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17270 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to
cause a d ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17259 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17255 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17207 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17057 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16941 (IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated
attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16892 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16826 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to
execute a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16693 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16689 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16660 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote
attacker t ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16649 (The Gravity Forms plugin for WordPress is vulnerable to Stored
Cross-S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16180 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15984 (The QuickCal plugin for WordPress is vulnerable to Stored
Cross-Site S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15937 (Improper certificate validation in Checkmk <2.5.0p10 allows a
relay an ...)
TODO: check
CVE-2026-15247 (The Search Atlas SEO WordPress plugin before 2.6.24 does not
perform ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14975 (The WP File Download plugin for WordPress is vulnerable to
Directory T ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14470 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow an
authenticated att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14466 (It\u2019s possible to run a stored XSS in Stormshield\u2019s
web admin ...)
TODO: check
CVE-2026-14350 (IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001
could a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13447 (The Mstore Api plugin for WordPress is vulnerable to
Authentication By ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13297 (IBM Verify Identity Access Advanced Access Control may be
vulnerable t ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13148 (Missing release of memory after effective lifetime
vulnerability in So ...)
- TODO: check
+ NOT-FOR-US: Softing
CVE-2026-12483 (The LearnDash LMS plugin for WordPress is vulnerable to
Unrestricted F ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-67066 (SQL Injection vulnerability in oasys sysoa version 1.0 allows
a remote ...)
TODO: check
CVE-2025-15694 (The Joli Table Of Contents WordPress plugin before 2.8.1 does
not sani ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-15693 (The JCH Optimize WordPress plugin before 5.0.1 does not
properly restr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-14945 (The Events Manager - Calendar, Bookings, Tickets, and more!
plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82309 (Robots::Validate versions from 0.3.2 before 0.3.11 for Perl
allow unbo ...)
NOT-FOR-US: Robots::Validate Perl module
CVE-2026-80911 (In the Linux kernel, the following vulnerability has been
resolved: A ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/208a280977dd46352d779df6b0c25da3b6dc2f4b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/208a280977dd46352d779df6b0c25da3b6dc2f4b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits