Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
951b3f16 by security tracker role at 2026-09-07T19:13:45+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-8279 (The Masteriyo LMS plugin for WordPress is vulnerable to
unauthorized d ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86506 (In JetBrains GoLand before 2026.2.2.1 missing authentication
on the Go ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86505 (In JetBrains IntelliJ IDEA before 2026.2.2 missing
project-trust check ...)
TODO: check
CVE-2026-86504 (In JetBrains IntelliJ IDEA before 2026.2.2 missing
project-trust confi ...)
@@ -13,51 +13,51 @@ CVE-2026-86502 (In JetBrains IntelliJ IDEA before 2026.2.2
missing TLS and authe
CVE-2026-86501 (In JetBrains IntelliJ IDEA before 2026.2.2 terminal command
input coul ...)
TODO: check
CVE-2026-86500 (In JetBrains YouTrack before 2026.1.14047 a missing escalation
check l ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86499 (In JetBrains YouTrack before 2026.1.14047 predefined search
fields lea ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86498 (In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT
requests ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86497 (In JetBrains YouTrack before 2026.2.18769 changing a mailbox
host with ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86496 (In JetBrains YouTrack before 2026.2.18769 missing access
control on He ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86495 (In JetBrains YouTrack before 2026.2.18687 missing permission
checks al ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86494 (In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard
allowed ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86493 (In JetBrains YouTrack before 2026.2.18634 improper permission
checks a ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86492 (In JetBrains YouTrack before 2026.2.18634 a shared token cache
allowed ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86491 (In JetBrains YouTrack before 2026.2.18634 stored XSS was
possible via ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86490 (In JetBrains YouTrack before 2026.2.18634 improper permission
checks a ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86489 (In JetBrains YouTrack before 2026.2.18634 an IDOR in the user
profile ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86488 (In JetBrains YouTrack before 2026.2.18634 iDOR via the
watchRules and ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86487 (In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket
message ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86486 (In JetBrains YouTrack before 2026.2.18634 the generic VCS
webhook hand ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86485 (In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP
headers ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86484 (In JetBrains YouTrack before 2026.2.18634 angularJS template
injection ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86483 (In JetBrains YouTrack before 2026.2.18634 stored XSS via a
custom fiel ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86482 (In JetBrains YouTrack before 2026.2.18634 unchecked group
membership c ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86481 (In JetBrains YouTrack before 2026.2.18634 signed URL reuse
allowed dis ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86480 (In JetBrains Hub before 2026.2.52442 an unauthenticated
attacker could ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86479 (In JetBrains YouTrack before 2026.2.18788, 2026.1.14055,
2025.3.1612 ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86478 (In JetBrains YouTrack before 2025.3.161254, 2026.1.14042
improper aut ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-86469 (A flaw was found in GLib2. When g_file_replace() is used with
G_FILE_C ...)
TODO: check
CVE-2026-86452 (Affected versions of MISP permit unauthenticated or weakly
constrained ...)
@@ -129,9 +129,9 @@ CVE-2026-86318 (A flaw has been found in java-json-tools
json-patch up to 1.13.
CVE-2026-86317 (A vulnerability was detected in ggml-org llama.cpp up to
0.4.0. This i ...)
TODO: check
CVE-2026-86310 (A vulnerability has been found in itsourcecode Sales and
Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-86309 (A flaw has been found in itsourcecode Sales and Inventory
System 1.0. ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-86308 (A vulnerability was detected in light0011 cms
c774dce31c6df0055568a8d5 ...)
TODO: check
CVE-2026-86307 (A security vulnerability has been detected in light0011 cms
c774dce31c ...)
@@ -143,31 +143,31 @@ CVE-2026-86305 (A security flaw has been discovered in
light0011 cms c774dce31c6
CVE-2026-86303 (A vulnerability was determined in 92181 markdown up to
058cab0cb7fb245 ...)
TODO: check
CVE-2026-86302 (A vulnerability was found in code-projects Hospital
Information System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-86301 (A vulnerability has been found in code-projects Hospital
Information S ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-86300 (A flaw has been found in Tenda AC9 15.03.05.14. This impacts
the funct ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-86299 (A vulnerability was detected in Linksys RE7000 2.0.15. This
affects th ...)
- TODO: check
+ NOT-FOR-US: Linksys
CVE-2026-86298 (A security flaw has been discovered in SourceCodester Class
and Exam T ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-86297 (A vulnerability was identified in D-Link DIR-605 B1v202WWB03.
This iss ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-86296 (A vulnerability was determined in D-Link DIR-822A A_101. This
vulnerab ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-86295 (A vulnerability was found in D-Link DIR-895L A1_102b07. This
affects t ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-86294 (A vulnerability has been found in SourceCodester Simple
Traffic Offens ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-86293 (A flaw has been found in SourceCodester Simple Traffic Offense
System ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-86292 (A vulnerability was detected in SourceCodester Simple Traffic
Offense ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-86291 (A security vulnerability has been detected in itsourcecode
Sales and I ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-86290 (A weakness has been identified in SourceCodester Online Voting
System ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-86289 (A vulnerability was found in Ollama up to 0.31.1. This issue
affects t ...)
TODO: check
CVE-2026-86288 (A vulnerability has been found in ModelCloud GPTQModel up to
7.2.0. Th ...)
@@ -181,11 +181,11 @@ CVE-2026-86284 (A security vulnerability has been
detected in jaychouchannel Tou
CVE-2026-86282 (A weakness has been identified in jaychouchannel
Tourism-Management-Sy ...)
TODO: check
CVE-2026-86281 (A security flaw has been discovered in SourceCodester
Syllabus-Aligned ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-86280 (A vulnerability was identified in SourceCodester
Syllabus-Aligned Lear ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-85640 (Zohocorp ManageEngine Endpoint Central versions below
11.5.2600.15 are ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-85201 (In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent
does not li ...)
TODO: check
CVE-2026-84186 (Vulnerability involving incorrect access control in the
Tools::getRemo ...)
@@ -197,103 +197,103 @@ CVE-2026-82325 (A use-after-free vulnerability in the
OpenVPN ovpn-dco-win drive
CVE-2026-81830 (The Windows interactive service in OpenVPN 2.4.0 through
2.6.22 allows ...)
TODO: check
CVE-2026-80238 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80178 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80176 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80170 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80167 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80166 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80164 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80135 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80134 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80133 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80132 (ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 Ap ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80131 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80130 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80129 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80128 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80127 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80126 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80125 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80058 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80057 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80056 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-80054 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-7861 (Deserialization of untrusted data vulnerability in Next4Biz
Informatio ...)
TODO: check
CVE-2026-79975 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79943 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79734 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79691 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79678 (A flaw was found in FreeIPA's idp-add command, where
insufficiently va ...)
TODO: check
CVE-2026-79645 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79644 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79643 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79642 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79639 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-78488 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-78487 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-78480 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-78325 (Cross-site scripting in the Evernote and Google Keep note
importers in ...)
TODO: check
CVE-2026-77699 (ZohocorpManageEngine Endpoint Central versions below
11.5.2605.01 are ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-77698 (Zohocorp ManageEngine Endpoint Central versions before
11.5.2605.01 ar ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-77697 (Zohocorp ManageEngine Endpoint Central versions below
11.4.2540.23 are ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-76578 (A flaw was found in FreeIPA. The self-managed OTP token ACI
does not r ...)
TODO: check
CVE-2026-76560 (A flaw was found in 389 Directory Server. The SELFDN ACI
bind-rule eva ...)
TODO: check
CVE-2026-6431 (The User Profile Builder \u2013 Beautiful User Registration
Forms, Use ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-6377 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
TODO: check
CVE-2026-6223 (Improper restriction of excessive authentication attempts
vulnerabilit ...)
TODO: check
CVE-2026-61410 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-61409 (Dell Secure Connect Gateway (SCG) 5.0 Application, versions
prior to 5 ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-4945 (The Otter Blocks \u2013 Gutenberg Blocks, Page Builder for
Gutenberg E ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-2390 (The Powerkit plugin for WordPress is vulnerable to Stored
Cross-Site S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19843 (A flaw was found in 389-ds-base. The Cockpit 389 Console's
LDAP editor ...)
TODO: check
CVE-2026-19204 (A client may send a WebSocket frame with an unknown opcode and
a very ...)
@@ -309,21 +309,21 @@ CVE-2026-18355 (A heap buffer overflow flaw was found in
the SASL I/O layer of 3
CVE-2026-16028 (Protocol::HTTP2 versions before 1.14 for Perl allow memory
exhaustion ...)
TODO: check
CVE-2026-14444 (The WP Fusion (Pro) plugin for WordPress is vulnerable to
Privilege Es ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14297 (A buffer overflow in the Bluetooth Continuous Glucose
Monitoring ...)
TODO: check
CVE-2026-14296 (When using the Direct XIP update strategy, the main
application image ...)
TODO: check
CVE-2026-12853 (The Flamingo plugin for WordPress is vulnerable to
authorization bypas ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12757 (The The Email Subscribers & Newsletters \u2013 Email
Marketing, Post N ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-52657 (HCL MyXalytics was affected by Potential DOS Vulnerability. It
allows ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-52652 (HCL MyXalytics was affected by Content Spoofing Vulnerability.
It may ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-52651 (HCL MyXalytics was affected by Improper Input validation
Vulnerability ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2022-51018 (PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not
limit book ...)
TODO: check
CVE-2022-51017 (PocketMine-MP versions before 3.26.5 and 4.0.5 fail to
validate the le ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/951b3f166772dfdf176b1ea51260b21d9612d563
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/951b3f166772dfdf176b1ea51260b21d9612d563
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits