[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 18 08:13:58 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1f82ed6d by security tracker role at 2026-08-18T07:13:46+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -21,7 +21,7 @@ CVE-2026-75480 (OpenViking debug vector scroll and count endpoints apply only ac
CVE-2026-75479 (JimuReport contains an authentication bypass vulnerability in the repo ...)
TODO: check
CVE-2026-75151 (A vulnerability has been found in SourceCodester Onlne Examination & L ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-75111 (Evidently UI fails to properly validate the filename parameter in the ...)
TODO: check
CVE-2026-75110 (MemOS is a memory operating system for LLMs and AI agents. In deployme ...)
@@ -43,35 +43,35 @@ CVE-2026-75094 (A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts t
CVE-2026-75093 (A security vulnerability has been detected in sonos tract up to 0.23.4 ...)
TODO: check
CVE-2026-75091 (The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75090 (A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. ...)
TODO: check
CVE-2026-75089 (A weakness has been identified in PHPGurukul Complaint Management Syst ...)
- TODO: check
+ NOT-FOR-US: PHPGurukul
CVE-2026-75088 (A vulnerability was determined in itsourcecode Hospital Management Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-75087 (A vulnerability was found in itsourcecode Hospital Management System 1 ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-75086 (A vulnerability has been found in itsourcecode Hospital Management Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-75082 (A flaw has been found in Webkul Bagisto up to 2.4.4. The affected elem ...)
TODO: check
CVE-2026-75081 (A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted i ...)
TODO: check
CVE-2026-75080 (A security vulnerability has been detected in SourceCodester Class and ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-75079 (A weakness has been identified in SourceCodester Class and Exam Timeta ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-75078 (A security flaw has been discovered in SourceCodester Class and Exam T ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-75077 (A vulnerability was identified in SourceCodester Class and Exam Timeta ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-75014 (A flaw has been found in SourceCodester Pet Grooming Management Softwa ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-75013 (A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-75012 (A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-74234 (Legora before 2026-08-14 contains a cross-site scripting vulnerability ...)
TODO: check
CVE-2026-73560 (vLLM is an inference and serving engine for large language models. Pri ...)
@@ -93,9 +93,9 @@ CVE-2026-71424 (Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and
CVE-2026-70495 (A flaw was found in search-v2-operator. This component's `search-servi ...)
TODO: check
CVE-2026-69148 (MLflow is an open source AI engineering platform for agents, large lan ...)
- TODO: check
+ NOT-FOR-US: mlflow
CVE-2026-69146 (MLflow is an open source AI engineering platform for agents, large lan ...)
- TODO: check
+ NOT-FOR-US: mlflow
CVE-2026-68765 (hashcat master branch builds after v7.1.2 contain a heap buffer overfl ...)
TODO: check
CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to ...)
@@ -103,9 +103,9 @@ CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote attac
CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remo ...)
TODO: check
CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-67966 (Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthentic ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-67965 (An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to e ...)
TODO: check
CVE-2026-67961 (An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary ...)
@@ -141,63 +141,63 @@ CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning t
CVE-2026-65640 (WordPress is vulnerable to a remote code execution vulnerability via m ...)
TODO: check
CVE-2026-65351 (This issue was addressed through improved state management. This issue ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65349 (An out-of-bounds read was addressed with improved input validation. Th ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65347 (The issue was addressed with improved checks. This issue is fixed in i ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65346 (An integer overflow was addressed with improved input validation. This ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65343 (A use after free issue was addressed with improved memory management. ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65341 (The issue was addressed with improved memory handling. This issue is f ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65340 (This issue was addressed through improved state management. This issue ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65339 (A logic issue was addressed with improved checks. This issue is fixed ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65338 (The issue was addressed with improved memory handling. This issue is f ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65337 (This issue was addressed through improved state management. This issue ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65336 (This issue was addressed through improved state management. This issue ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65335 (This issue was addressed through improved state management. This issue ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65334 (A memory corruption issue was addressed with improved state management ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65333 (This issue was addressed through improved state management. This issue ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65332 (This issue was addressed through improved state management. This issue ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65331 (This issue was addressed through improved state management. This issue ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65330 (The issue was addressed with improved memory handling. This issue is f ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65329 (An authentication issue was addressed with improved state management. ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64849 (MLflow is an open source AI engineering platform for agents, large lan ...)
- TODO: check
+ NOT-FOR-US: mlflow
CVE-2026-64788 (The issue was addressed with improved memory handling. This issue is f ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64787 (A use-after-free issue was addressed with improved memory management. ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64784 (An out-of-bounds access issue was addressed with improved bounds check ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64782 (A memory corruption vulnerability was addressed with improved locking. ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64781 (The issue was addressed with improved input validation. This issue is ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64780 (The issue was addressed with improved checks. This issue is fixed in i ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64779 (A memory corruption vulnerability was addressed with improved locking. ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64778 (The issue was addressed with improved checks. This issue is fixed in i ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64760 (An information leakage was addressed with additional validation. This ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64715 (A use-after-free issue was addressed with improved memory management. ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-64657 (Budibase is an open-source low-code platform. Prior to 3.39.19, the Po ...)
TODO: check
CVE-2026-63670 (ApostropheCMS is an open-source Node.js content management system. Pri ...)
@@ -243,11 +243,11 @@ CVE-2026-44846 (JumpServer is an open source bastion host and an operation and m
CVE-2026-44845 (JumpServer is an open source bastion host and an operation and mainten ...)
TODO: check
CVE-2026-43795 (The issue was addressed with improved memory handling. This issue is f ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-43794 (A memory corruption issue was addressed with improved memory handling. ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-43667 (A reachable assertion was addressed with improved input validation. Th ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-42164 (Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/sect ...)
TODO: check
CVE-2026-42163 (Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access ...)
@@ -255,7 +255,7 @@ CVE-2026-42163 (Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized
CVE-2026-42162 (Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being acc ...)
TODO: check
CVE-2026-40506 (OpenEMR before 8.2.0 contains a path traversal vulnerability in the st ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-39255 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ...)
TODO: check
CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ...)
@@ -263,7 +263,7 @@ CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.
CVE-2026-38165 (A Server-Side Template Injection (SSTI) vulnerability in the Velocity ...)
TODO: check
CVE-2026-35219 (Budibase is an open-source low-code platform. Prior to 3.41.3, automat ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-34789 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
TODO: check
CVE-2026-34399 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
@@ -271,21 +271,21 @@ CVE-2026-34399 (FreeCAD is a free and open-source multiplatform 3D parametric mo
CVE-2026-34398 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
TODO: check
CVE-2026-28984 (The issue was addressed with improved memory handling. This issue is f ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-19650 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-19589 (Packer up to 1.15.4 is vulnerable to an issue in the third-party plugi ...)
TODO: check
CVE-2026-19478 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-15748 (The Forminator Forms plugin for WordPress is vulnerable to Arbitrary F ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15371 (Velociraptor's web GUI allows specifying a custom type for columns in ...)
- TODO: check
+ NOT-FOR-US: Rapid7
CVE-2026-11817 (This vulnerability only affects Grafana stacks configured with multipl ...)
TODO: check
CVE-2026-11801 (The WPAdverts \u2013 Classifieds Plugin plugin for WordPress is vulner ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-10080 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
TODO: check
CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy() in dri ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f82ed6dc40dc42b0d27d05bb64a2e634bba2ee7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f82ed6dc40dc42b0d27d05bb64a2e634bba2ee7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/b8134a74/attachment.htm>
More information about the debian-security-tracker-commits
mailing list