[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 20:15:33 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
71458c7d by security tracker role at 2026-08-14T19:15:26+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-73850 (Emlog is an open source website building system. In 2.6.20 and earlier ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-73849 (Emlog is an open source website building system. In 2.6.26 and earlier ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-73847 (Emlog is an open source website building system. In 2.6.26 and earlier ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-73846 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
TODO: check
CVE-2026-73845 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
@@ -15,17 +15,17 @@ CVE-2026-73673 (Netis NC63 router firmware V3.0.0.3327 contains an unauthenticat
CVE-2026-73633 (Uncontrolled resource consumption vulnerability in the JSON plugin of ...)
TODO: check
CVE-2026-73630 (SiYuan before v3.7.4 contains an information disclosure vulnerability ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73107
REJECTED
CVE-2026-73051 (actix-http versions before 3.12.1 contain an HTTP request smuggling vu ...)
TODO: check
CVE-2026-73049 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73048 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72970 (Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows a ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-72859 (Budibase versions 3.39.4 before 3.40.0 contain an authorization regres ...)
TODO: check
CVE-2026-72838 (FileBrowser versions before 2.63.19 fail to enforce the declared Uploa ...)
@@ -79,25 +79,25 @@ CVE-2026-72814 (The actix-files crate (actix_files) before version 0.6.10 contai
CVE-2026-72813 (actix-files before 0.6.10 contains a denial of service vulnerability t ...)
TODO: check
CVE-2026-72812 (SiYuan versions before v3.7.4 contain a missing authorization vulnerab ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72811 (SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72810 (SiYuan versions before v3.7.4 contain a publish-boundary bypass vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-69101 (Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vu ...)
TODO: check
CVE-2026-66272 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-66271 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-66270 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-63702 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-63701 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-63700 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-63361 (LimeSurvey Community Edition 7.0.5 contains an authenticated reflected ...)
TODO: check
CVE-2026-57472 (Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pat ...)
@@ -131,7 +131,7 @@ CVE-2026-46380 (compliance-trestle is a tooling platform for managing compliance
CVE-2026-1621 (Authentication bypass by primary weakness vulnerability in Universal S ...)
TODO: check
CVE-2026-19884 (In Eclipse Theia versions up to and including 1.69.0, opening a folder ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-19880 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (l ...)
TODO: check
CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP response ...)
@@ -141,17 +141,17 @@ CVE-2026-19871 (Use of Hard-coded Credentials in the human resources component i
CVE-2026-19870 (Authorization Bypass Through User-Controlled Key in the payroll module ...)
TODO: check
CVE-2026-19847 (A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-19846 (A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-19845 (A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-19844 (A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Th ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-19841 (A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an u ...)
- TODO: check
+ NOT-FOR-US: TRENDnet
CVE-2026-19839 (A vulnerability was detected in SourceCodester Simple Doctors Appointm ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-19838 (A security vulnerability has been detected in Webkul Bagisto up to 2.4 ...)
TODO: check
CVE-2026-19837 (A weakness has been identified in Webkul Bagisto up to 2.4.4. This aff ...)
@@ -163,7 +163,7 @@ CVE-2026-19835 (A vulnerability was identified in Webkul Bagisto up to 2.4.4. Af
CVE-2026-19834 (A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected ...)
TODO: check
CVE-2026-19830 (A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1 ...)
- TODO: check
+ NOT-FOR-US: TRENDnet
CVE-2026-19829 (A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4 ...)
TODO: check
CVE-2026-19828 (A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-2026 ...)
@@ -173,49 +173,49 @@ CVE-2026-19827 (A flaw has been found in alldatacenter alldata up to 0.6.8. This
CVE-2026-19826 (A vulnerability was detected in alldatacenter alldata up to 0.6.8. Thi ...)
TODO: check
CVE-2026-19825 (A security vulnerability has been detected in SourceCodester Simple Cl ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-19824 (A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_ ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-19823 (A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_ ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-19822 (A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_ ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-19821 (A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. T ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-19815 (A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affect ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-19814 (A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-19813 (A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-19812 (A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-19794 (The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19768 (Improper control of generation of code ('Code Injection') in the setti ...)
- TODO: check
+ NOT-FOR-US: Devolutions
CVE-2026-19682 (A command injection vulnerability exists in Security Center where a re ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19681 (An authenticated command injection vulnerability exists in Security Ce ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19680 (A SQL injection vulnerability exists in Security Center that could all ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19679 (An input validation vulnerability exists in Security Center's file upl ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19639 (An improper access control vulnerability exists where an authenticated ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19636 (An issue was identified in which CSRF tokens were generated using a pr ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19635 (A local privilege escalation vulnerability exists in Security Center. ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19631 (A SQL injection vulnerability exists in Security Center that could all ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19629 (A privilege escalation vulnerability exists in Tenable Security Center ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19628 (A command injection vulnerability exists in Tenable Security Center. A ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19626 (A remote code execution vulnerability exists in Tenable Security Cente ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-19188 (A critical OS command injection vulnerability has been identified in t ...)
TODO: check
CVE-2026-18403 (LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injec ...)
@@ -231,13 +231,13 @@ CVE-2026-13196 (Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write v
CVE-2026-13002 (A flow has been identified into dnssec.c library, causing an infinite ...)
TODO: check
CVE-2026-12366 (Zephyr's dynamic kernel-object disposal path unref_check() in kernel/u ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12365 (A use-after-free exists in the Zephyr second-generation work queue (ke ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12364 (The user-space system-call verifier z_vrfy_z_log_msg_static_create() i ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12363 (The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/se ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-7639 (The vulnerability, if exploited, could allow an authenticated miscrean ...)
TODO: check
CVE-2025-71405 (chi versions before v5.2.2 contain an open redirect vulnerability in t ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71458c7d1dfed87ccccb6976e4c559203541f354
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71458c7d1dfed87ccccb6976e4c559203541f354
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/0fb2c4e3/attachment.htm>
More information about the debian-security-tracker-commits
mailing list