[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 11 08:14:36 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
86ba8288 by security tracker role at 2026-08-11T07:14:29+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Su ...)
- TODO: check
+ NOT-FOR-US: ASUS
CVE-2026-8718 (tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/ ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-8158 (The Signed Video Framework contained a buffer overflow issue which co ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-73035 (npm-check-updates through 23.0.2, fixed in commit b554b84, contains a ...)
TODO: check
CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3 contains a path ...)
@@ -83,11 +83,11 @@ CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authentic
CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated r ...)
TODO: check
CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) ra ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost inflight migra ...)
TODO: check
CVE-2026-6181 (The Device Configuration Framework is vulnerable to an authentication ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection vulnera ...)
TODO: check
CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering an ...)
@@ -97,85 +97,85 @@ CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel m
CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path traversal vulne ...)
TODO: check
CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver App ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66778 (SAP Approuter does not sufficiently sanitize certain request headers b ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66777 (SAP Approuter does not sufficiently validate certain incoming requests ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66776 (SAP Approuter does not consistently enforce integrity verification on ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66775 (SAP Approuter does not enforce cross-site request forgery protection o ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66774 (SAP Approuter does not consistently handle certain error conditions. A ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66773 (A malicious or compromised OData service could disclose sensitive auth ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66772 (SAP BusinessObjects Business Intelligence Platform (Admin Tools) does ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66771 (SAPUI5 allows a key user with content adaptation privileges to inject ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66770 (Due to an SQL Injection vulnerability in SAP Social intelligence, an a ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66764 (Reprocess Bank Statement Items in SAP S/4HANA does not perform the nec ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66763 (SAP BusinessObjects Business Intelligence Platform stores certain sens ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66761 (SAP Approuter does not enforce sufficient flow control in certain func ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-66760 (SAP Approuter does not correctly validate client certificates in certa ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a process ...)
TODO: check
CVE-2026-5304 (An ACAP configuration file lacks input validation, which could potenti ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-5303 (The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) ra ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-58248 (SAP BusinessObjects Business Intelligence Platform (Web Intelligence) ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58247 (SAP ABAP Platform allows an unauthenticated user to send a specially c ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58245 (SAP Advanced Planning and Optimization (Model Mix Planning) contains a ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58244 (SAP Manufacturing Integration and Intelligence (MII) does not perform ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58243 (SAP ABAP Development Tools does not perform necessary authorization ch ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58241 (SAP NetWeaver and ABAP Platform (Change and Transport System - Custome ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58239 (SAP Approuter does not sufficiently validate tenant context in inbound ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58238 (SAP Approuter does not sufficiently handle certain requests under spec ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58237 (WebSocket of SAP Approuter does not perform sufficient authorization c ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58236 (SAP NetWeaver Application Server ABAP and ABAP Platform allow an attac ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58235 (SAP NetWeaver Application Server Java (Adobe Document Service) uses ou ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-58230 (SAP Approuter does not sufficiently validate certain token content und ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-4757 (A VAPIX API parameter had improper input validation which could allow ...)
- TODO: check
+ NOT-FOR-US: Axis Communication
CVE-2026-48161 (react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 a ...)
TODO: check
CVE-2026-48160 (react-tracked provides state usage tracking with Proxies. Between 2026 ...)
TODO: check
CVE-2026-44765 (Due to a Missing Authorization Check vulnerability in SAP Manufacturin ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44764 (Due to a Missing Authorization Check vulnerability in SAP Manufacturin ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44763 (SAP Manufacturing Integration and Intelligence allows a privileged att ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44762 (SAP Data Services Management Console allows an overly permissive Conte ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44758 (SAP Manufacturing Integration and Intelligence (MII) allows an attacke ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-44401 (Typemill CMS version 2.x contains a persistent cross-site scripting vu ...)
TODO: check
CVE-2026-40130 (SAP SAPSPrint Service has memory corruption vulnerabilities in the han ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-34265 (SAP NetWeaver Application Server ABAP allows an unauthenticated attack ...)
- TODO: check
+ NOT-FOR-US: SAP
CVE-2026-24330 (A flaw was found in wildfly-core. A remote attacker, authenticated as ...)
TODO: check
CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated as an ad ...)
@@ -225,21 +225,21 @@ CVE-2026-18608 (A flaw was found in the Data Science Pipelines Operator (DSPO).
CVE-2026-18348 (Missing authorization check in the upload_azure, upload_sftp, and uplo ...)
TODO: check
CVE-2026-16974 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16456 (A flaw was found in the `odh-model-controller`. An authenticated user ...)
TODO: check
CVE-2026-16053 (Zohocorp ManageEngineM365 Manager Plus and M365 Security Plus versions ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-15581 (A flaw was found in the TrustyAI Service (TAS) deployment. This vulner ...)
TODO: check
CVE-2026-15467 (A flaw was found in the trustyai-service-operator's LMEvalJob controll ...)
TODO: check
CVE-2026-14886 (Vault Enterprise's identity entity batch-delete endpoint is vulnerable ...)
- TODO: check
+ NOT-FOR-US: Hashicorp products not packaged in Debian
CVE-2026-14549 (The Ray Enterprise Translation WordPress plugin through 1.7.3 does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3 does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows any pod wi ...)
TODO: check
CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Imp ...)
@@ -247,35 +247,35 @@ CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gatewa
CVE-2026-13716 (Path traversal in server import and admin file upload in Crafty Contro ...)
TODO: check
CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12051 (The USB DFU class implementation in Zephyr's new (experimental) device ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11985 (On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11894 (The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send( ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11893 (The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL6 ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11812 (The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11811 (The UpdateHub over-the-air update client's start_coap_client() in subs ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11810 (The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_ ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11809 (The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-32736 (Cross-Site Request Forgery weaknesses in the Administrative Console of ...)
- TODO: check
+ NOT-FOR-US: Ping Identity Corporation
CVE-2025-30241 (Certain web interface components in affected TP-Link Aginet devices do ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-30240 (The affected TP-Link Aginet devices do not properly validate symbolic ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-30239 (In affected TP-Link Aginet devices, use of hardcoded cryptographic key ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-30238 (In affected TP-Link Aginet devices, insufficient authorization validat ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-30237 (The affected TP-Link Aginet devicescontain a flaw in the web managemen ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2025-15683 (TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial ...)
TODO: check
CVE-2025-15682 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exh ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86ba8288e309bbba1885e4a8bb2347732f4809c2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86ba8288e309bbba1885e4a8bb2347732f4809c2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/ed5c7d6b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list