[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 18 20:14:03 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
29a025a1 by security tracker role at 2026-08-18T19:13:58+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -17,7 +17,7 @@ CVE-2026-75904 (libmodplug through 0.8.9.1 contains an out-of-bounds read in pat
CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery vulnerabi ...)
TODO: check
CVE-2026-75897 (Improper input validation in the capabilities route handler in OpenSea ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-75890
REJECTED
CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This vulnerabi ...)
@@ -85,11 +85,11 @@ CVE-2026-75828 (Grav before 2.0.15 contains a stored cross-site scripting vulner
CVE-2026-75827 (Grav before 2.0.15 contains an arbitrary file write vulnerability in t ...)
TODO: check
CVE-2026-75784 (A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affecte ...)
- TODO: check
+ NOT-FOR-US: TRENDnet
CVE-2026-75783 (A security vulnerability has been detected in TRENDnet TEW-WLC100P 12. ...)
- TODO: check
+ NOT-FOR-US: TRENDnet
CVE-2026-75778 (A vulnerability was identified in code-projects Task Management System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-75774 (A vulnerability was determined in karakeep-app karakeep up to 0.32.0. ...)
TODO: check
CVE-2026-75773 (A vulnerability was found in karakeep-app karakeep up to 0.32.0. The a ...)
@@ -227,15 +227,15 @@ CVE-2026-74908 (Grav plugin-api before 1.0.15 contains a script injection vulner
CVE-2026-74907 (Grav before 2.0.15 contains a path traversal vulnerability in the stat ...)
TODO: check
CVE-2026-74906 (SiYuan before v3.7.4 contains an incorrect authorization vulnerability ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74905 (SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vul ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74904 (SiYuan before v3.7.4 is missing authorization checks in 17 block metad ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74903 (SiYuan before v3.7.4 contains an insufficient access control vulnerabi ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74902 (SiYuan before v3.7.4 contains a cross-site scripting vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-74046 (Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability i ...)
TODO: check
CVE-2026-74044 (Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that ...)
@@ -245,29 +245,29 @@ CVE-2026-74039 (Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of se
CVE-2026-74038 (Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that ...)
TODO: check
CVE-2026-74015 (Unauthenticated SQL Injection in Readabler < 2.0.18 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74012 (Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74009 (Unauthenticated Insecure Direct Object References (IDOR) in Razorpay f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74008 (Unauthenticated Sensitive Data Exposure in Shortcodes and extra featur ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74007 (Unauthenticated Sensitive Data Exposure in 3D FlipBook \u2013 PDF Flip ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74006 (Contributor Broken Access Control in WP Table Builder <= 2.2.0 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74004 (Subscriber Broken Access Control in Gravity Booster – Styles &am ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-74003 (Contributor Broken Access Control in RomethemeForm For Elementor <= 1. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73997 (Unauthenticated Denial of Service Attack in Starter Templates by Kaden ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73996 (Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73995 (Subscriber Broken Authentication in User Registration <= 5.2.6 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73994 (Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73834 (A flaw was found in the must-gather component of Red Hat Advanced Clus ...)
TODO: check
CVE-2026-73692
@@ -277,105 +277,105 @@ CVE-2026-73502 (kin-openapi is a Go project for handling OpenAPI files. From 0.2
CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
TODO: check
CVE-2026-73404 (Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73400 (Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73399 (Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73398 (Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Paym ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73397 (Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73396 (Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73395 (Unauthenticated Insecure Direct Object References (IDOR) in Booking ca ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73393 (Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73392 (Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73383 (Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73382 (Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73381 (Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73380 (Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73379 (Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73378 (Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsysti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73377 (Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73376 (Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73375 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsyst ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73373 (Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joo ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73372 (Joomla! Core - [20260809] - Improper ACL checks when injection schema. ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73371 (Joomla! Core - [20260808] - Improper ACL checks for batch copy actions ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73367 (Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73366 (Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73365 (Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73362 (Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73361 (Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for G ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73360 (Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73359 (Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CC ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73358 (Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73356 (Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73355 (Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73352 (Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73351 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73350 (Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73348 (Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73345 (Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73343 (Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73342 (Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73341 (Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73339 (Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73338 (Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73337 (Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0- ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73336 (Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5 ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73190 (Unauthenticated Cross Site Scripting (XSS) in WPDM \u2013 Premium Pack ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73189 (Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73187 (Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73181 (Unauthenticated Arbitrary File Download in Extra Product Options & Add ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73073 (Vim is an open source, command line text editor. Prior to 9.2.0845, St ...)
TODO: check
CVE-2026-72532 (Joomla! Core - [20260806] - Improper ACL checks for category webservic ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-72531 (Joomla! Core - [20260804] - Improper ACL checks for custom fields webs ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-71880 (Interpretation of untrusted input in template engine in GBIF Integrate ...)
TODO: check
CVE-2026-71879 (Missing authentication in initial setup functionality left exposed unt ...)
@@ -383,15 +383,15 @@ CVE-2026-71879 (Missing authentication in initial setup functionality left expos
CVE-2026-71878 (Missing authentication in initial setup functionality left exposed aft ...)
TODO: check
CVE-2026-71574 (Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webse ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-71573 (Joomla! Core - [20260802] - Improper CORS origin validation in Joomla ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-71572 (Joomla! Core - [20260801] - Response header injection in download view ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-71551 (Super Productivity is an advanced todo list app with integrated timebo ...)
TODO: check
CVE-2026-71539 (n8n is an open source workflow automation platform. Prior to 1.123.64, ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-71477 (mise manages dev tools like node, python, cmake, and terraform. Prior ...)
TODO: check
CVE-2026-71365 (A server-side request forgery (SSRF) vulnerability was found in AWX's ...)
@@ -401,7 +401,7 @@ CVE-2026-70667 (Lemur manages TLS certificate creation. Prior to 1.9.3, _validat
CVE-2026-70657 (Copyparty is a portable file server. Prior to 1.20.17, copyparty volum ...)
TODO: check
CVE-2026-70415 (Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based application ...)
TODO: check
CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based application ...)
@@ -421,11 +421,11 @@ CVE-2026-68923 (MobSF is a mobile application security testing tool used. Prior
CVE-2026-68922 (MobSF is a mobile application security testing tool used. Prior to 4.5 ...)
TODO: check
CVE-2026-68568 (Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-68567 (Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-68565 (Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-67921 (Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS ver ...)
TODO: check
CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary ...)
@@ -433,9 +433,9 @@ CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote attacker to execute arbi
CVE-2026-67846 (Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb ...)
TODO: check
CVE-2026-67271 (Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-67262 (Dell PowerStore contains a Missing Authorization vulnerability. An att ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-66793 (A flaw was found in the governance-policy-addon-controller component o ...)
TODO: check
CVE-2026-66783 (A flaw was found in the `submariner-operator` component of Red Hat Adv ...)
@@ -447,47 +447,47 @@ CVE-2026-66781 (A flaw was found in the Submariner operator. The Submariner Cust
CVE-2026-66780 (A flaw was found in the submariner-operator component. The `submariner ...)
TODO: check
CVE-2026-66679 (Unauthenticated Broken Access Control in Appointment Hour Booking <= 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66667 (Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66651 (Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66646 (Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66645 (Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66644 (Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66643 (Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66641 (Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66640 (Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66639 (Contributor Cross Site Scripting (XSS) in WPZOOM Forms \u2013 Contact ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66638 (Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66637 (Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66636 (Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66635 (Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66634 (Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66633 (Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66629 (Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66627 (Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66622 (Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability caused ...)
TODO: check
CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling of MySQL ...)
@@ -523,7 +523,7 @@ CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based appli
CVE-2026-61574 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
TODO: check
CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Expose ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kriptok Cr ...)
TODO: check
CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
@@ -617,113 +617,113 @@ CVE-2026-48744 (Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.
CVE-2026-48508 (Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePerm ...)
TODO: check
CVE-2026-47630 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47629 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47628 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47627 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47606 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-47245 (MyBB is free and open source forum software. Prior to 1.8.40, the User ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-46482 (### Impact The registration component does not validate the text-based ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45734 (MyBB is free and open source forum software. Prior to 1.8.40, the buil ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45733 (Trilium Notes is a cross-platform, hierarchical note taking applicatio ...)
TODO: check
CVE-2026-45532 (DataEase is an open source data visualization and analysis tool. Versi ...)
- TODO: check
+ NOT-FOR-US: DataEase
CVE-2026-45129 (MyBB is free and open source forum software. Prior to 1.8.40, the Admi ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45128 (MyBB is free and open source forum software. Prior to 1.8.40, the ACP ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45127 (MyBB is free and open source forum software. Prior to 1.8.40, the ACP ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45126 (MyBB is free and open source forum software. Prior to 1.8.40, the Admi ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45125 (MyBB is free and open source forum software. Prior to 1.8.40, the Emai ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45124 (MyBB is free and open source forum software. Prior to 1.8.40, the Mod ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45123 (MyBB is free and open source forum software. Prior to 1.8.40, the remo ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45122 (MyBB is free and open source forum software. Prior to 1.8.40, the cale ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45121 (MyBB is free and open source forum software. Prior to 1.8.40, the cale ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45120 (MyBB is free and open source forum software. Prior to 1.8.40, the cale ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45119 (MyBB is free and open source forum software. Prior to 1.8.40, the Admi ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45118 (MyBB is free and open source forum software. Prior to 1.8.40, the Cont ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45117 (MyBB is free and open source forum software. From 1.8.13 until 1.8.40, ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45116 (MyBB is free and open source forum software. Prior to 1.8.40, the user ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-45115 (MyBB is free and open source forum software. Prior to 1.8.40, the Budd ...)
- TODO: check
+ NOT-FOR-US: MyBB
CVE-2026-44472 (Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.6 ...)
TODO: check
CVE-2026-43971 (Improper Encoding or Escaping of Output vulnerability in ninenines cow ...)
TODO: check
CVE-2026-34884 (SSRF via set_skywalking_url Tool and GraphQL expression injection vuln ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-32657 (Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-32553 (Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32549 (Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32547 (Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32481 (Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32474 (Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32473 (Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32472 (Unauthenticated Broken Access Control in Online Contact Widget <= 1.3. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32470 (Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32468 (Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32467 (Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32466 (Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32465 (Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32464 (Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32463 (Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32444 (Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32333 (Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-30250 (Cross-site scripting vulnerability in the user documentation field in ...)
TODO: check
CVE-2026-28571 (Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28570 (Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28569 (Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28568 (Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28567 (Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28192 (Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28191 (Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24301 (Improper neutralization of special elements used in a command ('comman ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-24185 (NVIDIA NVOS for network switches contains a vulnerability in the secur ...)
TODO: check
CVE-2026-24184 (NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discov ...)
@@ -765,7 +765,7 @@ CVE-2026-18963 (A flaw was found in the reset-credentials flow of the keycloak-s
CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of protection a ...)
TODO: check
CVE-2026-18751 (External control of file name or path vulnerability in Citrix WorkSpac ...)
- TODO: check
+ NOT-FOR-US: Citrix
CVE-2026-18534 (ArcSearch for iOS versions prior to 1.48.0 could keep the address bar ...)
TODO: check
CVE-2026-18392
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29a025a1789d61171a7c19af1e6d09ace8d79307
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29a025a1789d61171a7c19af1e6d09ace8d79307
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/e49fc5fc/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list