[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 4 08:13:18 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9decb637 by security tracker role at 2026-08-04T07:13:11+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-8508 (An improper authentication vulnerability in the "social_login.cgi" CGI ...)
- TODO: check
+ NOT-FOR-US: Zyxel
CVE-2026-6837 (A post-authentication command injection vulnerability in the "export-c ...)
- TODO: check
+ NOT-FOR-US: Zyxel
CVE-2026-69249 (python-cryptography is a package designed to expose cryptographic prim ...)
TODO: check
CVE-2026-69248 (cryptography is a package designed to expose cryptographic primitives ...)
@@ -25,11 +25,11 @@ CVE-2026-69192 (ip-address is a library for parsing and manipulating IPv4 and IP
CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication for ever ...)
TODO: check
CVE-2026-68981 (Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests fo ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-68980 (Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleti ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update R ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function ...)
TODO: check
CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers ...)
@@ -59,41 +59,41 @@ CVE-2026-67616 (Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a
CVE-2026-67599 (ClearOS 7.9 contains an OS command injection vulnerability in the Log ...)
TODO: check
CVE-2026-67598 (Emlog Pro through 2.6.23 contains a disabled TLS certificate validatio ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-66326 (Missing authorization in Microsoft Edge (Chromium-based) allows an una ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66325 (Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66322 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66321 (Access of resource using incompatible type ('type confusion') in Micro ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66318 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66317 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66316 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66315 (Use after free in Microsoft Edge (Chromium-based) allows an unauthoriz ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66314 (Time-of-check time-of-use (toctou) race condition in Microsoft Edge (C ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66313 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66312 (Buffer over-read in Microsoft Edge (Chromium-based) allows an authoriz ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66311 (Missing authorization in Microsoft Edge (Chromium-based) allows an una ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66310 (External control of file name or path in Microsoft Edge for Android al ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-66296 (Improper Neutralization of Input During Web Page Generation (XSS) vuln ...)
TODO: check
CVE-2026-66065 (Ouroboros is a local-first runtime for AI coding agents that records t ...)
TODO: check
CVE-2026-65804 (Improper control of generation of code ('code injection') in Microsoft ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-65802 (External control of file name or path in Microsoft Edge for Android al ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-64565 (In the Linux kernel, the following vulnerability has been resolved: I ...)
TODO: check
CVE-2026-64564 (In the Linux kernel, the following vulnerability has been resolved: s ...)
@@ -105,9 +105,9 @@ CVE-2026-64562 (In the Linux kernel, the following vulnerability has been resolv
CVE-2026-64561 (In the Linux kernel, the following vulnerability has been resolved: K ...)
TODO: check
CVE-2026-62870 (Use after free in Microsoft Office Excel allows an unauthorized attack ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-62354 (Authorization handling for Parameter Context validation requests in Ap ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-58139 (The DuckDB AWS extension for DuckDB contains a security policy bypass ...)
TODO: check
CVE-2026-56845 (An unauthenticated path traversal (LFI) vulnerability exists under /cu ...)
@@ -115,7 +115,7 @@ CVE-2026-56845 (An unauthenticated path traversal (LFI) vulnerability exists und
CVE-2026-52521 (A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated ...)
TODO: check
CVE-2026-52520 (Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulne ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md plugin ...)
TODO: check
CVE-2026-51775 (SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an at ...)
@@ -127,19 +127,19 @@ CVE-2026-49132 (OPNsense before 26.1.9 contains a stored cross-site scripting vu
CVE-2026-49131 (OPNsense before 26.1.9 contains a stored cross-site scripting vulnerab ...)
TODO: check
CVE-2026-48399 (Adobe Campaign Classic (ACC) is affected by a Violation of Secure Desi ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48333 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48331 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48330 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48326 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48323 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48317 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-48115 (Misskey is an open source, federated social media platform. All Misske ...)
TODO: check
CVE-2026-48113 (Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. ...)
@@ -173,7 +173,7 @@ CVE-2026-18737 (Shlink contains a blind SQL injection vulnerability that allows
CVE-2026-18736 (Shlink contains a server-side request forgery vulnerability that allow ...)
TODO: check
CVE-2026-18733 (A prompt injection vulnerability in the shell tool in Amazon Strands A ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18723 (A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The a ...)
TODO: check
CVE-2026-18722 (A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted i ...)
@@ -195,9 +195,9 @@ CVE-2026-18682 (A security flaw has been discovered in OpenAkita up to 1.27.12.
CVE-2026-18667 (A vulnerability in Tenable Sensor Proxy allows a remote attacker to ex ...)
TODO: check
CVE-2026-18655 (Improper restriction of intended endpoints in the RabbitMQ broker conn ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18654 (Key exchange without entity authentication in the EMR SSH helper comma ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18648 (A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2. ...)
TODO: check
CVE-2026-18647 (A security vulnerability has been detected in jina-ai reader up to 157 ...)
@@ -221,61 +221,61 @@ CVE-2026-17614 (A path traversal flaw was found in WildFly's domain mode imple
CVE-2026-16881 (A code injection vulnerability exists in the LINE Android app prior to ...)
TODO: check
CVE-2026-16623 (The Create Block WordPress plugin before 2.10.0 does not correctly es ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16618 (The Improve SEO WordPress plugin through 2.0.11 does not properly vali ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16548 (The Chat Widget: Floating Customer Support Button for 30+ Channels, Su ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16547 (The REST API Log WordPress plugin before 1.7.1 does not bind the token ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16546 (The Wired Impact Volunteer Management WordPress plugin before 2.8.2 do ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16536 (The Simple Google Calendar Outlook Events Widget WordPress plugin befo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16296 (The Clearfy Cache WordPress plugin before 2.4.3 does not validate the ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16295 (The Clearfy Cache WordPress plugin before 2.4.3 does not perform a ca ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16293 (The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16070 (The Brizy WordPress plugin before 2.8.19 does not properly verify aut ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16069 (The Brizy WordPress plugin before 2.8.19 does not sanitize or escape ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16068 (The Brizy WordPress plugin before 2.8.19 does not properly restrict w ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16056 (The Contest Gallery WordPress plugin before 30.0.7 does not perform a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16035 (The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict wh ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15958 (The Easy Integration for Dropbox WordPress plugin before 2.2.0 does n ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15233 (The Nested Pages WordPress plugin before 3.2.15 does not properly esca ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14939 (The Visualizer WordPress plugin before 4.0.6 does not restrict a user ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14872 (The Database for Contact Form 7, WPforms, Elementor forms WordPress pl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14848 (The Paid Membership Subscriptions WordPress plugin before 3.0.8 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14824 (The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14818 (A path traversal vulnerability in the CLI command used to execute conf ...)
- TODO: check
+ NOT-FOR-US: Zyxel
CVE-2026-14816 (The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12698 (The wpForo Forum WordPress plugin before 3.1.3 does not restrict which ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11836 (Insufficient verification of data authenticity in Caliptra Core ROM an ...)
TODO: check
CVE-2026-11835 (Time-of-check time-of-use (TOCTOU) vulnerability combined with missing ...)
TODO: check
CVE-2026-11366 (The MonsterInsights WordPress plugin before 11.1.0 does not correctly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-10849 (The hawkBit device management client in subsys/mgmt/hawkbit accumulate ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-10526 (The EmbedPress WordPress plugin before 4.6.1 does not validate user-s ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8794 (PaperCut NG/MF contains an observable timing discrepancy in its authen ...)
NOT-FOR-US: PaperCut
CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive authentication att ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9decb6370a5985fbb1c76039e0449d199bf07203
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9decb6370a5985fbb1c76039e0449d199bf07203
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/4de59418/attachment.htm>
More information about the debian-security-tracker-commits
mailing list