Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
951b3f16 by security tracker role at 2026-09-07T19:13:45+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-8279 (The Masteriyo LMS plugin for WordPress is vulnerable to 
unauthorized d ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86506 (In JetBrains GoLand before 2026.2.2.1 missing authentication 
on the Go ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86505 (In JetBrains IntelliJ IDEA before 2026.2.2 missing 
project-trust check ...)
        TODO: check
 CVE-2026-86504 (In JetBrains IntelliJ IDEA before 2026.2.2 missing 
project-trust confi ...)
@@ -13,51 +13,51 @@ CVE-2026-86502 (In JetBrains IntelliJ IDEA before 2026.2.2 
missing TLS and authe
 CVE-2026-86501 (In JetBrains IntelliJ IDEA before 2026.2.2 terminal command 
input coul ...)
        TODO: check
 CVE-2026-86500 (In JetBrains YouTrack before 2026.1.14047 a missing escalation 
check l ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86499 (In JetBrains YouTrack before 2026.1.14047 predefined search 
fields lea ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86498 (In JetBrains YouTrack before 2025.3.160480,  2026.1.14047 pUT 
requests ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86497 (In JetBrains YouTrack before 2026.2.18769 changing a mailbox 
host with ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86496 (In JetBrains YouTrack before 2026.2.18769 missing access 
control on He ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86495 (In JetBrains YouTrack before 2026.2.18687 missing permission 
checks al ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86494 (In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard 
allowed ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86493 (In JetBrains YouTrack before 2026.2.18634 improper permission 
checks a ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86492 (In JetBrains YouTrack before 2026.2.18634 a shared token cache 
allowed ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86491 (In JetBrains YouTrack before 2026.2.18634 stored XSS was 
possible via  ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86490 (In JetBrains YouTrack before 2026.2.18634 improper permission 
checks a ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86489 (In JetBrains YouTrack before 2026.2.18634 an IDOR in the user 
profile  ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86488 (In JetBrains YouTrack before 2026.2.18634 iDOR via the 
watchRules and  ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86487 (In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket 
message  ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86486 (In JetBrains YouTrack before 2026.2.18634 the generic VCS 
webhook hand ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86485 (In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP 
headers ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86484 (In JetBrains YouTrack before 2026.2.18634 angularJS template 
injection ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86483 (In JetBrains YouTrack before 2026.2.18634 stored XSS via a 
custom fiel ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86482 (In JetBrains YouTrack before 2026.2.18634 unchecked group 
membership c ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86481 (In JetBrains YouTrack before 2026.2.18634 signed URL reuse 
allowed dis ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86480 (In JetBrains Hub before 2026.2.52442 an unauthenticated 
attacker could ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86479 (In JetBrains YouTrack before 2026.2.18788,  2026.1.14055,  
2025.3.1612 ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86478 (In JetBrains YouTrack before 2025.3.161254,  2026.1.14042 
improper aut ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-86469 (A flaw was found in GLib2. When g_file_replace() is used with 
G_FILE_C ...)
        TODO: check
 CVE-2026-86452 (Affected versions of MISP permit unauthenticated or weakly 
constrained ...)
@@ -129,9 +129,9 @@ CVE-2026-86318 (A flaw has been found in java-json-tools 
json-patch up to 1.13.
 CVE-2026-86317 (A vulnerability was detected in ggml-org llama.cpp up to 
0.4.0. This i ...)
        TODO: check
 CVE-2026-86310 (A vulnerability has been found in itsourcecode Sales and 
Inventory Sys ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-86309 (A flaw has been found in itsourcecode Sales and Inventory 
System 1.0.  ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-86308 (A vulnerability was detected in light0011 cms 
c774dce31c6df0055568a8d5 ...)
        TODO: check
 CVE-2026-86307 (A security vulnerability has been detected in light0011 cms 
c774dce31c ...)
@@ -143,31 +143,31 @@ CVE-2026-86305 (A security flaw has been discovered in 
light0011 cms c774dce31c6
 CVE-2026-86303 (A vulnerability was determined in 92181 markdown up to 
058cab0cb7fb245 ...)
        TODO: check
 CVE-2026-86302 (A vulnerability was found in code-projects Hospital 
Information System ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-86301 (A vulnerability has been found in code-projects Hospital 
Information S ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-86300 (A flaw has been found in Tenda AC9 15.03.05.14. This impacts 
the funct ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-86299 (A vulnerability was detected in Linksys RE7000 2.0.15. This 
affects th ...)
-       TODO: check
+       NOT-FOR-US: Linksys
 CVE-2026-86298 (A security flaw has been discovered in SourceCodester Class 
and Exam T ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-86297 (A vulnerability was identified in D-Link DIR-605 B1v202WWB03. 
This iss ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-86296 (A vulnerability was determined in D-Link DIR-822A A_101. This 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-86295 (A vulnerability was found in D-Link DIR-895L A1_102b07. This 
affects t ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-86294 (A vulnerability has been found in SourceCodester Simple 
Traffic Offens ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-86293 (A flaw has been found in SourceCodester Simple Traffic Offense 
System  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-86292 (A vulnerability was detected in SourceCodester Simple Traffic 
Offense  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-86291 (A security vulnerability has been detected in itsourcecode 
Sales and I ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-86290 (A weakness has been identified in SourceCodester Online Voting 
System  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-86289 (A vulnerability was found in Ollama up to 0.31.1. This issue 
affects t ...)
        TODO: check
 CVE-2026-86288 (A vulnerability has been found in ModelCloud GPTQModel up to 
7.2.0. Th ...)
@@ -181,11 +181,11 @@ CVE-2026-86284 (A security vulnerability has been 
detected in jaychouchannel Tou
 CVE-2026-86282 (A weakness has been identified in jaychouchannel 
Tourism-Management-Sy ...)
        TODO: check
 CVE-2026-86281 (A security flaw has been discovered in SourceCodester 
Syllabus-Aligned ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-86280 (A vulnerability was identified in SourceCodester 
Syllabus-Aligned Lear ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-85640 (Zohocorp ManageEngine Endpoint Central versions below 
11.5.2600.15 are ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-85201 (In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent 
does not li ...)
        TODO: check
 CVE-2026-84186 (Vulnerability involving incorrect access control in the 
Tools::getRemo ...)
@@ -197,103 +197,103 @@ CVE-2026-82325 (A use-after-free vulnerability in the 
OpenVPN ovpn-dco-win drive
 CVE-2026-81830 (The Windows interactive service in OpenVPN 2.4.0 through 
2.6.22 allows ...)
        TODO: check
 CVE-2026-80238 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80178 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80176 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80170 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80167 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80166 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80164 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80135 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80134 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80133 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80132 (ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 Ap ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80131 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80130 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80129 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80128 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80127 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80126 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80125 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80058 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80057 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80056 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-80054 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-7861 (Deserialization of untrusted data vulnerability in Next4Biz 
Informatio ...)
        TODO: check
 CVE-2026-79975 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79943 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79734 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79691 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79678 (A flaw was found in FreeIPA's idp-add command, where 
insufficiently va ...)
        TODO: check
 CVE-2026-79645 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79644 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79643 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79642 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79639 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-78488 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-78487 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-78480 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-78325 (Cross-site scripting in the Evernote and Google Keep note 
importers in ...)
        TODO: check
 CVE-2026-77699 (ZohocorpManageEngine Endpoint Central versions below 
11.5.2605.01 are  ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-77698 (Zohocorp ManageEngine Endpoint Central versions before 
11.5.2605.01 ar ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-77697 (Zohocorp ManageEngine Endpoint Central versions below 
11.4.2540.23 are ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-76578 (A flaw was found in FreeIPA. The self-managed OTP token ACI 
does not r ...)
        TODO: check
 CVE-2026-76560 (A flaw was found in 389 Directory Server. The SELFDN ACI 
bind-rule eva ...)
        TODO: check
 CVE-2026-6431 (The User Profile Builder \u2013 Beautiful User Registration 
Forms, Use ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6377 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
        TODO: check
 CVE-2026-6223 (Improper restriction of excessive authentication attempts 
vulnerabilit ...)
        TODO: check
 CVE-2026-61410 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-61409 (Dell Secure Connect Gateway (SCG) 5.0 Application, versions 
prior to 5 ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-4945 (The Otter Blocks \u2013 Gutenberg Blocks, Page Builder for 
Gutenberg E ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2390 (The Powerkit plugin for WordPress is vulnerable to Stored 
Cross-Site S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19843 (A flaw was found in 389-ds-base. The Cockpit 389 Console's 
LDAP editor ...)
        TODO: check
 CVE-2026-19204 (A client may send a WebSocket frame with an unknown opcode and 
a very  ...)
@@ -309,21 +309,21 @@ CVE-2026-18355 (A heap buffer overflow flaw was found in 
the SASL I/O layer of 3
 CVE-2026-16028 (Protocol::HTTP2 versions before 1.14 for Perl allow memory 
exhaustion  ...)
        TODO: check
 CVE-2026-14444 (The WP Fusion (Pro) plugin for WordPress is vulnerable to 
Privilege Es ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14297 (A buffer overflow in the Bluetooth Continuous Glucose      
Monitoring  ...)
        TODO: check
 CVE-2026-14296 (When using the Direct XIP update strategy, the main 
application image  ...)
        TODO: check
 CVE-2026-12853 (The Flamingo plugin for WordPress is vulnerable to 
authorization bypas ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12757 (The The Email Subscribers & Newsletters \u2013 Email 
Marketing, Post N ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-52657 (HCL MyXalytics was affected by Potential DOS Vulnerability. It 
allows  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-52652 (HCL MyXalytics was affected by Content Spoofing Vulnerability. 
It may  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-52651 (HCL MyXalytics was affected by Improper Input validation 
Vulnerability ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2022-51018 (PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not 
limit book ...)
        TODO: check
 CVE-2022-51017 (PocketMine-MP versions before 3.26.5 and 4.0.5 fail to 
validate the le ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/951b3f166772dfdf176b1ea51260b21d9612d563

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/951b3f166772dfdf176b1ea51260b21d9612d563
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to