[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 12 08:14:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
88d407cb by security tracker role at 2026-08-12T07:14:28+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -61,9 +61,9 @@ CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache HttpC
CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of Red Hat Ad ...)
TODO: check
CVE-2026-70339 (Access of resource using incompatible type ('type confusion') in Micro ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-6484 (In an UEFI, Lack of verified boot to certain FV may cause arbitrary co ...)
- TODO: check
+ NOT-FOR-US: Insyde
CVE-2026-68067 (The login endpoint on the Mira cloud API accepts any format-valid stri ...)
TODO: check
CVE-2026-67568 (The distributed Mira Android APK v4.5.15.4 allows an attacker read/wri ...)
@@ -77,23 +77,23 @@ CVE-2026-66875 (In the Mira hormone monitor device firmware v1.7.1.47 build 0107
CVE-2026-66832 (When the Mira Android app opens in-app WebView content (e.g., shop red ...)
TODO: check
CVE-2026-66659 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66340 (The Mira cloud authentication endpoints do not enforce per-account rat ...)
TODO: check
CVE-2026-66154 (An insufficient certificate validation in a privileged communication w ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66150 (Improper Control of Generation of Code ('Code Injection') Vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66149 (Improper Control of Generation of Code ('Code Injection') Vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66148 (An authenticated command injection vulnerability was identified in GMS ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66147 (An unauthenticated command injection vulnerability was identified in t ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66146 (Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66145 (An unauthenticated remote code execution vulnerability was identified ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write from any ...)
TODO: check
CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS terminates ...)
@@ -141,105 +141,105 @@ CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass (insecure
CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command is gated ...)
TODO: check
CVE-2026-19217 (The Royal Addons for Elementor WordPress plugin before 1.7.1065 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19091 (The GeoDirectory \u2013 WP Business Directory Plugin and Classified Li ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19073 (The Order Sync with Zendesk for WooCommerce WordPress plugin before 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19052 (The ProSolution WP Client WordPress plugin before 2.0.9 does not perfo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19050 (The ProSolution WP Client WordPress plugin before 2.0.9 does not valid ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18962 (The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not ch ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18961 (The Social Login, Passkeys, Magic Link & Email OTP \u2013 Passwordless ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18943 (The WPC Admin Columns WordPress plugin before 2.3.4 does not have auth ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts several undi ...)
TODO: check
CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly restrict ac ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18710 (A MongoDB driver component could write sensitive configuration informa ...)
TODO: check
CVE-2026-18634 (An insecure handling of serialized objects vulnerability was found in ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-18474 (The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18391 (The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18366 (The Events Manager WordPress plugin before 7.4.1 does not properly sc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18230 (The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18057 (The Events Manager WordPress plugin before 7.4.1 does not sanitise an ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18049 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not pe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18048 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not va ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18046 (The Cookie Consent WordPress plugin before 0.0.10 does not correctly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18035 (The User Access Manager WordPress plugin before 2.3.15 does not apply ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17013 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16977 (The Form Maker by 10Web WordPress plugin before 1.15.45 does not prop ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16737 (The WP Travel Engine WordPress plugin before 6.8.5 does not perform a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16538 (The Wallet for WooCommerce WordPress plugin before 1.6.10 does not ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16294 (The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16253 (The Total Upkeep WordPress plugin before 1.17.3 does not adequately p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16230 (The Formidable Digital Signatures plugin for WordPress is vulnerable t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16066 (The Welcart e-Commerce WordPress plugin before 2.11.34 does not saniti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16051 (The wpmudev-updates WordPress plugin before 5.0.1 does not verify the ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15606 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15388 (The Cookie Consent WordPress plugin before 0.0.10 does not correctly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15249 (The Patterns Kit WordPress plugin through 1.0.3 does not escape a link ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15039 (The giftware WordPress plugin before 4.2.10 does not validate the type ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14925 (The Import WP WordPress plugin before 2.14.23 does not perform any au ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14863 (FileRun up to and including version 2026.2.0 contains an OS command in ...)
TODO: check
CVE-2026-14859 (The WP Crowdfunding WordPress plugin before 2.2.1 does not check the c ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14858 (The WP Crowdfunding WordPress plugin before 2.2.1 does not verify orde ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14857 (The WP Crowdfunding WordPress plugin before 2.2.1 does not verify owne ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13613 (The KiviCare WordPress plugin before 4.5.2 does not properly sanitise ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13612 (The KiviCare WordPress plugin before 4.5.2 does not verify that the r ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13457 (The InstaWP Connect \u2013 1-click WP Staging & Migration plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13177 (The Eventin WordPress plugin before 4.1.20 does not properly restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13171 (The Eventin WordPress plugin before 4.1.20 does not perform an author ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13168 (The Eventin WordPress plugin before 4.1.20 does not properly restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12976 (The LearnPress WordPress plugin before 4.4.4 does not verify that a u ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12235 (The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/REL ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12234 (The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsoc ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12233 (The PSA Protected Storage credential backend (subsys/net/lib/tls_crede ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12232 (The Intel ALH digital-audio-interface driver function dai_alh_get_prop ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-15687 (A security flaw has been discovered in Open5GS up to 2.7.6. Impacted i ...)
TODO: check
CVE-2025-15686 (A vulnerability has been found in Open5GS up to 2.7.6. Affected by thi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d407cba39e71fd571f2810cfbef51cf6a74022
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d407cba39e71fd571f2810cfbef51cf6a74022
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/c851d7fe/attachment.htm>
More information about the debian-security-tracker-commits
mailing list