[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 20:15:33 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
71458c7d by security tracker role at 2026-08-14T19:15:26+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-73850 (Emlog is an open source website building system. In 2.6.20 and earlier ...)
-	TODO: check
+	NOT-FOR-US: Emlog
 CVE-2026-73849 (Emlog is an open source website building system. In 2.6.26 and earlier ...)
-	TODO: check
+	NOT-FOR-US: Emlog
 CVE-2026-73847 (Emlog is an open source website building system. In 2.6.26 and earlier ...)
-	TODO: check
+	NOT-FOR-US: Emlog
 CVE-2026-73846 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
 	TODO: check
 CVE-2026-73845 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
@@ -15,17 +15,17 @@ CVE-2026-73673 (Netis NC63 router firmware V3.0.0.3327 contains an unauthenticat
 CVE-2026-73633 (Uncontrolled resource consumption vulnerability in the JSON plugin of  ...)
 	TODO: check
 CVE-2026-73630 (SiYuan before v3.7.4 contains an information disclosure vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-73107
 	REJECTED
 CVE-2026-73051 (actix-http versions before 3.12.1 contain an HTTP request smuggling vu ...)
 	TODO: check
 CVE-2026-73049 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-73048 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72970 (Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows a ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-72859 (Budibase versions 3.39.4 before 3.40.0 contain an authorization regres ...)
 	TODO: check
 CVE-2026-72838 (FileBrowser versions before 2.63.19 fail to enforce the declared Uploa ...)
@@ -79,25 +79,25 @@ CVE-2026-72814 (The actix-files crate (actix_files) before version 0.6.10 contai
 CVE-2026-72813 (actix-files before 0.6.10 contains a denial of service vulnerability t ...)
 	TODO: check
 CVE-2026-72812 (SiYuan versions before v3.7.4 contain a missing authorization vulnerab ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72811 (SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72810 (SiYuan versions before v3.7.4 contain a publish-boundary bypass vulner ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-69101 (Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vu ...)
 	TODO: check
 CVE-2026-66272 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-66271 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-66270 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-63702 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-63701 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-63700 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-63361 (LimeSurvey Community Edition 7.0.5 contains an authenticated reflected ...)
 	TODO: check
 CVE-2026-57472 (Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pat ...)
@@ -131,7 +131,7 @@ CVE-2026-46380 (compliance-trestle is a tooling platform for managing compliance
 CVE-2026-1621 (Authentication bypass by primary weakness vulnerability in Universal S ...)
 	TODO: check
 CVE-2026-19884 (In Eclipse Theia versions up to and including 1.69.0, opening a folder ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-19880 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (l ...)
 	TODO: check
 CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP response ...)
@@ -141,17 +141,17 @@ CVE-2026-19871 (Use of Hard-coded Credentials in the human resources component i
 CVE-2026-19870 (Authorization Bypass Through User-Controlled Key in the payroll module ...)
 	TODO: check
 CVE-2026-19847 (A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-19846 (A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-19845 (A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-19844 (A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Th ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-19841 (A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an u ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-19839 (A vulnerability was detected in SourceCodester Simple Doctors Appointm ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19838 (A security vulnerability has been detected in Webkul Bagisto up to 2.4 ...)
 	TODO: check
 CVE-2026-19837 (A weakness has been identified in Webkul Bagisto up to 2.4.4. This aff ...)
@@ -163,7 +163,7 @@ CVE-2026-19835 (A vulnerability was identified in Webkul Bagisto up to 2.4.4. Af
 CVE-2026-19834 (A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected ...)
 	TODO: check
 CVE-2026-19830 (A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1 ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-19829 (A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4 ...)
 	TODO: check
 CVE-2026-19828 (A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-2026 ...)
@@ -173,49 +173,49 @@ CVE-2026-19827 (A flaw has been found in alldatacenter alldata up to 0.6.8. This
 CVE-2026-19826 (A vulnerability was detected in alldatacenter alldata up to 0.6.8. Thi ...)
 	TODO: check
 CVE-2026-19825 (A security vulnerability has been detected in SourceCodester Simple Cl ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19824 (A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_ ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19823 (A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_ ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19822 (A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_ ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19821 (A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. T ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-19815 (A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affect ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-19814 (A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-19813 (A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-19812 (A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-19794 (The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19768 (Improper control of generation of code ('Code Injection') in the setti ...)
-	TODO: check
+	NOT-FOR-US: Devolutions
 CVE-2026-19682 (A command injection vulnerability exists in Security Center where a re ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19681 (An authenticated command injection vulnerability exists in Security Ce ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19680 (A SQL injection vulnerability exists in Security Center that could all ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19679 (An input validation vulnerability exists in Security Center's file upl ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19639 (An improper access control vulnerability exists where an authenticated ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19636 (An issue was identified in which CSRF tokens were generated using a pr ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19635 (A local privilege escalation vulnerability exists in Security Center.  ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19631 (A SQL injection vulnerability exists in Security Center that could all ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19629 (A privilege escalation vulnerability exists in Tenable Security Center ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19628 (A command injection vulnerability exists in Tenable Security Center. A ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19626 (A remote code execution vulnerability exists in Tenable Security Cente ...)
-	TODO: check
+	NOT-FOR-US: Tenable
 CVE-2026-19188 (A critical OS command injection vulnerability has been identified in t ...)
 	TODO: check
 CVE-2026-18403 (LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injec ...)
@@ -231,13 +231,13 @@ CVE-2026-13196 (Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write v
 CVE-2026-13002 (A flow has been identified into dnssec.c library, causing an infinite  ...)
 	TODO: check
 CVE-2026-12366 (Zephyr's dynamic kernel-object disposal path unref_check() in kernel/u ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12365 (A use-after-free exists in the Zephyr second-generation work queue (ke ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12364 (The user-space system-call verifier z_vrfy_z_log_msg_static_create() i ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12363 (The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/se ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-7639 (The vulnerability, if exploited, could allow an authenticated miscrean ...)
 	TODO: check
 CVE-2025-71405 (chi versions before v5.2.2 contain an open redirect vulnerability in t ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71458c7d1dfed87ccccb6976e4c559203541f354

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71458c7d1dfed87ccccb6976e4c559203541f354
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/0fb2c4e3/attachment.htm>


More information about the debian-security-tracker-commits mailing list