[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Oct 9 21:13:48 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d4dc0dfd by security tracker role at 2025-10-09T20:13:41+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,17 +1,17 @@
 CVE-2025-9371 (The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-62228 (Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via m ...)
 	TODO: check
 CVE-2025-61577 (D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overfl ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2025-61532 (Cross Site Scripting vulnerability in SVX Portal v.2.7A to execute arb ...)
 	TODO: check
 CVE-2025-60316 (SourceCodester Pet Grooming Management Software 1.0 is vulnerable to S ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-60304 (code-projects Simple Scheduling System 1.0 is vulnerable to Cross Site ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2025-60302 (code-projects Client Details System 1.0 is vulnerable to Cross Site Sc ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2025-60267 (In xckk v9.6, there is a SQL injection vulnerability in which the cond ...)
 	TODO: check
 CVE-2025-60266 (In xckk v9.6, there is a SQL injection vulnerability in which the orde ...)
@@ -19,79 +19,79 @@ CVE-2025-60266 (In xckk v9.6, there is a SQL injection vulnerability in which th
 CVE-2025-60265 (In xckk v9.6, there is a SQL injection vulnerability in which the orde ...)
 	TODO: check
 CVE-2025-60010 (A password aging vulnerability in the RADIUS client of Juniper Network ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-60009 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-60006 (Multiple instances of an Improper Neutralization of Special Elements u ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-60004 (An Improper Check for Unusual or Exceptional Conditions vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-60002 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-60001 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-60000 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59999 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59998 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59997 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59996 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59995 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59994 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59993 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59992 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59991 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59990 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59989 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59988 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59987 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59986 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59985 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59984 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59983 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59982 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59981 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59980 (An Authentication Bypass by Primary Weakness  in the FTP server of Jun ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59978 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59976 (An arbitrary file download vulnerability in the web interface of Junip ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59975 (An Uncontrolled Resource Consumption vulnerability in the HTTP daemon  ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59974 (An Improper Neutralization of Input During Web Page Generation ('Cross ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59968 (A Missing Authorization vulnerability in the Juniper Networks Junos Sp ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59967 (A NULL Pointer Dereference vulnerability in the PFE management daemon  ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59964 (A Use of Uninitialized Resource vulnerability in the Packet Forwarding ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59962 (An Access of Uninitialized Pointer vulnerability in the routing protoc ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59958 (An Improper Check for Unusual or Exceptional Conditions vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59957 (An Origin Validation Error vulnerability in an insufficient protected  ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-59146 (New API is a large language mode (LLM) gateway and artificial intellig ...)
 	TODO: check
 CVE-2025-56683 (A cross-site scripting (XSS) vulnerability in the component /app/marke ...)
@@ -101,47 +101,47 @@ CVE-2025-56426 (An issue WebKul Bagisto v.2.3.6 allows a remote attacker to exec
 CVE-2025-55200 (BigBlueButton is an open-source virtual classroom. In versions prior t ...)
 	TODO: check
 CVE-2025-52961 (An Uncontrolled Resource Consumption vulnerability in the Connectivity ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-52960 (A Buffer Copy without Checking Size of Input vulnerability in the   Se ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-4615 (An improper input neutralization vulnerability in the management web i ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2025-4614 (An information disclosure vulnerability in Palo Alto Networks PAN-OS\x ...)
-	TODO: check
+	NOT-FOR-US: Palo Alto Networks
 CVE-2025-45095 (Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions  ...)
 	TODO: check
 CVE-2025-39664 (Insufficient escaping in the report scheduler within Checkmk <2.4.0p13 ...)
 	TODO: check
 CVE-2025-36225 (IBM Aspera 5.0.0 through 5.0.13.1   could disclose sensitive user info ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36171 (IBM Aspera Faspex 5.0.0 through 5.0.13.1could allow a privileged user  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-32919 (Use of an insecure temporary directory in the Windows License plugin f ...)
 	TODO: check
 CVE-2025-32916 (Potential use of sensitive information in GET requests in Checkmk GmbH ...)
 	TODO: check
 CVE-2025-11573 (An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 ma ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2025-11561 (A flaw was found in the integration of Active Directory and the System ...)
 	TODO: check
 CVE-2025-11554 (A security vulnerability has been detected in Portabilis i-Educar up t ...)
-	TODO: check
+	NOT-FOR-US: Portabilis
 CVE-2025-11553 (A weakness has been identified in code-projects Courier Management Sys ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2025-11552 (A vulnerability was identified in code-projects Online Complaint Site  ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2025-11551 (A vulnerability was determined in code-projects Student Result Manager ...)
 	TODO: check
 CVE-2025-11550 (A vulnerability was found in Tenda W12 3.0.0.6(3948). The impacted ele ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2025-11549 (A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affecte ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2025-11371 (In the default installation and configuration of Gladinet CentreStack  ...)
 	TODO: check
 CVE-2025-11198 (A Missing Authentication for Critical Function vulnerability in Junipe ...)
-	TODO: check
+	NOT-FOR-US: Juniper
 CVE-2025-10862 (The Popup builder with Gamification, Multi-Step Popups, Page-Level Tar ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-10284 (BBOT's unarchive module could be abused by supplying malicious archive ...)
 	TODO: check
 CVE-2025-10283 (BBOT's gitdumper module could be abused to execute commands through a  ...)
@@ -151,13 +151,13 @@ CVE-2025-10282 (BBOT's gitlab module could be abused to disclose a GitLab API ke
 CVE-2025-10281 (BBOT's git_clone module could be abused to disclose a GitHub API key t ...)
 	TODO: check
 CVE-2025-10249 (The Slider Revolution plugin for WordPress is vulnerable to unauthoriz ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-10240 (A vulnerability exists in the Progress Flowmon web application prior t ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2025-10239 (In Flowmon versions prior to 12.5.5, a vulnerability has been identifi ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2023-37401 (IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy fi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2017-20203 (NetSarang Xmanager Enterprise 5.0 Build 1232,Xmanager 5.0 Build 1045,X ...)
 	TODO: check
 CVE-2025-39963 (In the Linux kernel, the following vulnerability has been resolved:  i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4dc0dfd4f9c61efe3cc200eb07080a0722777c2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4dc0dfd4f9c61efe3cc200eb07080a0722777c2
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251009/9244350a/attachment.htm>


More information about the debian-security-tracker-commits mailing list