[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 19 20:15:24 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b9b6a010 by security tracker role at 2026-08-19T19:15:18+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
CVE-2026-76614 (OpenEMR before 8.3.0 contains a path traversal vulnerability in the ED ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-76245 (stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestam ...)
TODO: check
CVE-2026-76244 (stigmem-node contains an insecure default configuration vulnerability ...)
@@ -89,21 +89,21 @@ CVE-2026-76166 (A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jbo
CVE-2026-76164 (AIL Framework contains a server-side request forgery (SSRF) vulnerabil ...)
TODO: check
CVE-2026-75956 (Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75955 (Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J- ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75954 (Joomla Extension - cmsjunkie.com - SQL injection in trips search in J ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75953 (Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirec ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75952 (Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-Bu ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75951 (Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (m ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75950 (Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership t ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75949 (Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion ( ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-75920 (phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-a ...)
TODO: check
CVE-2026-75919 (phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability ...)
@@ -111,13 +111,13 @@ CVE-2026-75919 (phpMyFAQ before 4.1.7 contains an authentication bypass vulnerab
CVE-2026-75918 (phpMyFAQ before 4.1.7 stores password reset tokens in a publicly acces ...)
TODO: check
CVE-2026-75917 (SiYuan before v3.7.4 contains a cross-site scripting vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-75916 (SiYuan through 3.7.3 contains a cross-site scripting vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-75619 (Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-75618 (Tapo C100/C101 V5 contains a null pointer dereference vulnerability in ...)
- TODO: check
+ NOT-FOR-US: TPLink
CVE-2026-75583 (keeper.sh's calendar module version prior to 2.18.14 contains a server ...)
TODO: check
CVE-2026-75149 (marimo before 0.23.15 contains a code injection vulnerability in the n ...)
@@ -139,49 +139,49 @@ CVE-2026-75142 (FFmpeg before commit 9d786e4 contains a stack buffer overflow in
CVE-2026-75141 (FFmpeg before commit acf5d7c contains a heap buffer overflow in the hv ...)
TODO: check
CVE-2026-75114 (Joomla Extension - yootheme.com - Open redirect in CommentController:: ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-74804 (Joomla Extension - yootheme.com - Unauthenticated SQL injection in Ite ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-74803 (Joomla Extension - yootheme.com - Unauthenticated arbitrary file uploa ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73829 (Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allow ...)
TODO: check
CVE-2026-73541 (Allocation of Resources Without Limits or Throttling in ZenHive mpp al ...)
TODO: check
CVE-2026-73394 (Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73391 (Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73390 (Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73389 (Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73388 (Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73387 (Unauthenticated Local File Inclusion in Resido <= 1.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73386 (Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73385 (Unauthenticated Broken Access Control in Outranking Plugin Options <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73384 (Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73364 (Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73363 (Unauthenticated Broken Access Control in Taxi Booking Manager for WooC ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73354 (Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate I ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73347 (Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73185 (Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73184 (Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73183 (Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73182 (Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73136 (Authentication Bypass by Capture-replay in ZenHive mpp allows an unaut ...)
TODO: check
CVE-2026-72717 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
@@ -215,39 +215,39 @@ CVE-2026-71694 (An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL
CVE-2026-71470 (A flaw was found in the search-v2-operator. This vulnerability allows ...)
TODO: check
CVE-2026-71176 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-70496 (A flaw was found in search-v2-operator. The operator's ClusterRole has ...)
TODO: check
CVE-2026-70424 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-70423 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-70422 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-70421 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-69159 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
TODO: check
CVE-2026-67581 (Authentication Bypass by Capture-replay in ZenHive mpp allows an unaut ...)
TODO: check
CVE-2026-67364 (Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balboo ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-67363 (Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-67268 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Imprope ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-67267 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposur ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-67266 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorre ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-66794 (A flaw was found in the `cluster-proxy-addon` component of Multicluste ...)
TODO: check
CVE-2026-66668 (Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66613 (Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66596 (Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65612 (nnn does not sanitize the filename variable. An attacker can place a f ...)
TODO: check
CVE-2026-65611 (nnn does not sanitize the path variable. An attacker can createa direc ...)
@@ -295,7 +295,7 @@ CVE-2026-62667 (Grav API Plugin is a RESTful API for Grav CMS that provides full
CVE-2026-62666 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
TODO: check
CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig conte ...)
TODO: check
CVE-2026-61807 (Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a s ...)
@@ -307,11 +307,11 @@ CVE-2026-61607 (Grav API Plugin is a RESTful API for Grav CMS that provides full
CVE-2026-61518 (ISPConfig contains an authenticated SQL injection vulnerability in the ...)
TODO: check
CVE-2026-58565 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-58564 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorre ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-58562 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-58088 (The ELF core dump code counted the number of dumpable VM map entries, ...)
TODO: check
CVE-2026-58087 (The GETALL and SETALL commands in semctl(2) recorded the number of sem ...)
@@ -329,11 +329,11 @@ CVE-2026-58082 (The ISO-2022 encoding module used a stack buffer sized to MB_LEN
CVE-2026-58081 (Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not p ...)
TODO: check
CVE-2026-56797 (Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Ti ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56796 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Imprope ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56088 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-55703 (Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any ...)
TODO: check
CVE-2026-55694 (Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a r ...)
@@ -347,23 +347,23 @@ CVE-2026-55483 (Snipe-IT is an IT asset/license management system. Prior to 8.6.
CVE-2026-55482 (Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a n ...)
TODO: check
CVE-2026-54796 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-54795 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-54794 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-54793 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-53654 (Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin tw ...)
TODO: check
CVE-2026-53477 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of- ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-53452 (Ground Station is a browser-based suite for satellite tracking, SDR re ...)
TODO: check
CVE-2026-53451 (Ground Station is a browser-based suite for satellite tracking, SDR re ...)
TODO: check
CVE-2026-52889 (Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Form ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-52834 (jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to ...)
TODO: check
CVE-2026-52792 (Algernon is a small self-contained pure-Go web server. Prior to 1.17.9 ...)
@@ -385,9 +385,9 @@ CVE-2026-49976 (Snipe-IT is an IT asset/license management system. Prior to 8.6.
CVE-2026-49870 (Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POS ...)
TODO: check
CVE-2026-49817 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserial ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-49816 (Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserial ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-49441 (Wazuh is a free and open source platform used for threat prevention, d ...)
TODO: check
CVE-2026-49425 (The compat32 kevent() handler translates a 64-bit kevent struct into a ...)
@@ -439,19 +439,19 @@ CVE-2026-44252 (Wazuh is a free and open source platform used for threat prevent
CVE-2026-41424 (Wazuh is a free and open source platform used for threat prevention, d ...)
TODO: check
CVE-2026-40509 (OpenEMR before 8.3.0 contains a cross-site request forgery vulnerabili ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-40508 (OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerabil ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-40507 (OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnera ...)
- TODO: check
+ NOT-FOR-US: OpenEMR
CVE-2026-32802 (Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper P ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-32552 (Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-32475 (Unrestricted Upload of File with Dangerous Type vulnerability in Eleme ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-23501 (Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Imp ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-20359 (As part of Cisco's ongoing commitment to proactive security and produc ...)
TODO: check
CVE-2026-20358 (As part of Cisco's ongoing commitment to proactive security and produc ...)
@@ -461,7 +461,7 @@ CVE-2026-20357 (As part of Cisco's ongoing commitment to proactive security and
CVE-2026-20327 (A vulnerability in the web-based management interface of Cisco Unified ...)
TODO: check
CVE-2026-20320 (A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20319 (As part of Cisco's ongoing commitment to proactive security and produc ...)
TODO: check
CVE-2026-20318 (As part of Cisco's ongoing commitment to proactive security and produc ...)
@@ -473,7 +473,7 @@ CVE-2026-20315 (As part of Cisco's ongoing commitment to proactive security and
CVE-2026-20314 (A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged ...)
TODO: check
CVE-2026-20302 (A vulnerability in the USB driver of Cisco RoomOS could allow an unaut ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20232 (A vulnerability in the web-based management interface of Cisco Industr ...)
TODO: check
CVE-2026-20231 (As part of Cisco's ongoing commitment to proactive security and produc ...)
@@ -483,97 +483,97 @@ CVE-2026-20177 (A vulnerability in the handling of management plane packets by C
CVE-2026-20030 (As part of Cisco's ongoing commitment to proactive security and produc ...)
TODO: check
CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19672 (The tarfile module's tar and data extraction filters created director ...)
TODO: check
CVE-2026-19653 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19490 (Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affe ...)
- TODO: check
+ NOT-FOR-US: NetScaler
CVE-2026-19489 (Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affe ...)
- TODO: check
+ NOT-FOR-US: NetScaler
CVE-2026-19321 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19234 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19198 (Akaunting 3.1.21 contains an authenticated improper authorization vuln ...)
TODO: check
CVE-2026-18874 (A flaw was found in volsync-addon-controller. This vulnerability allow ...)
TODO: check
CVE-2026-18848 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18756 (HumHub Community Edition 1.18.4 contains a reflected cross-site script ...)
TODO: check
CVE-2026-18681 (IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18526 (HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross- ...)
TODO: check
CVE-2026-18430 (HumHub 1.18.4 contains a stored cross-site scripting vulnerability in ...)
TODO: check
CVE-2026-18372 (CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows ...)
- TODO: check
+ NOT-FOR-US: M-Files
CVE-2026-18371 (HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows ...)
- TODO: check
+ NOT-FOR-US: M-Files
CVE-2026-18315 (The TrueBooker \u2013 Appointment Booking and Scheduler System plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17494 (IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17429 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17183 (An authenticated user with permission to create or edit alert rules ca ...)
TODO: check
CVE-2026-17100 (Power Systems FirmwareFW1120.00, FW1110.00 through FW1110.30, FW1060.0 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17093 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16938 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16930 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16835 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16832 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16828 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16819 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16818 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16817 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16816 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16814 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16706 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16703 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16690 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16687 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16686 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16656 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16440 (In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deep ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-16019 (Improper neutralization of special elements used in an SQL command ('S ...)
TODO: check
CVE-2026-15961 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15078 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15068 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15065 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15061 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14970 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is cr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-14603 (The application component processes user-supplied parameters insecurel ...)
TODO: check
CVE-2025-14600 (An insecure deserialization vulnerability in vsDesk allows a remote at ...)
@@ -1899,15 +1899,15 @@ CVE-2026-62608 (Vulnerability in the Oracle Reports Developer product of Oracle
CVE-2026-62607 (Vulnerability in the Oracle Customer Care product of Oracle E-Business ...)
TODO: check
CVE-2026-62606 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62605 (Vulnerability in the Oracle Partner Management product of Oracle E-Bus ...)
TODO: check
CVE-2026-62604 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62603 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62602 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62601 (Vulnerability in the Oracle Sales product of Oracle E-Business Suite ( ...)
TODO: check
CVE-2026-62600 (Vulnerability in the Oracle Sales product of Oracle E-Business Suite ( ...)
@@ -1915,7 +1915,7 @@ CVE-2026-62600 (Vulnerability in the Oracle Sales product of Oracle E-Business S
CVE-2026-62599 (Vulnerability in the Oracle Trading Community product of Oracle E-Busi ...)
TODO: check
CVE-2026-62598 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62596 (Vulnerability in the Siebel CRM Integration product of Oracle Siebel C ...)
NOT-FOR-US: Oracle
CVE-2026-62595 (Vulnerability in the Siebel CRM Integration product of Oracle Siebel C ...)
@@ -1945,15 +1945,15 @@ CVE-2026-62584 (Vulnerability in the Oracle Hyperion Infrastructure Technology p
CVE-2026-62583 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
NOT-FOR-US: Oracle
CVE-2026-62582 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62581 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
NOT-FOR-US: Oracle
CVE-2026-62580 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62579 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
NOT-FOR-US: Oracle
CVE-2026-62578 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62577 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
NOT-FOR-US: Oracle
CVE-2026-62576 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
@@ -1965,7 +1965,7 @@ CVE-2026-62573 (Vulnerability in the Oracle Hyperion Infrastructure Technology p
CVE-2026-62572 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
NOT-FOR-US: Oracle
CVE-2026-62571 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62570 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
NOT-FOR-US: Oracle
CVE-2026-62569 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
@@ -2011,13 +2011,13 @@ CVE-2026-62536 (Vulnerability in the Oracle Hyperion Infrastructure Technology p
CVE-2026-62535 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
NOT-FOR-US: Oracle
CVE-2026-62533 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62532 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62531 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
NOT-FOR-US: Oracle
CVE-2026-62529 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62526 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
NOT-FOR-US: Oracle
CVE-2026-62523 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
@@ -2065,11 +2065,11 @@ CVE-2026-62463 (Vulnerability in the Oracle Hyperion Infrastructure Technology p
CVE-2026-62462 (Vulnerability in the Oracle Work in Process product of Oracle E-Busine ...)
TODO: check
CVE-2026-62461 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62460 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62459 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62458 (Vulnerability in the Oracle Work in Process product of Oracle E-Busine ...)
TODO: check
CVE-2026-62457 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
@@ -2087,17 +2087,17 @@ CVE-2026-62449 (Vulnerability in the Oracle Work in Process product of Oracle E-
CVE-2026-62448 (Vulnerability in the Oracle Email Center product of Oracle E-Business ...)
TODO: check
CVE-2026-62446 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62442 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
NOT-FOR-US: Oracle
CVE-2026-62441 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-62377 (libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 ...)
TODO: check
CVE-2026-62291 (libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 ...)
TODO: check
CVE-2026-61342 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61341 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
NOT-FOR-US: Oracle
CVE-2026-61340 (Vulnerability in the Oracle MES for Process Manufacturing product of O ...)
@@ -2121,7 +2121,7 @@ CVE-2026-61318 (Vulnerability in the Siebel CRM Cloud Applications product of Or
CVE-2026-61317 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
NOT-FOR-US: Oracle
CVE-2026-61313 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61307 (Vulnerability in the PeopleSoft Enterprise CC Common Application Objec ...)
NOT-FOR-US: Oracle
CVE-2026-61306 (Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul p ...)
@@ -2139,7 +2139,7 @@ CVE-2026-61296 (Vulnerability in the Oracle Enterprise Asset Management product
CVE-2026-61295 (Vulnerability in the Oracle WebCenter Content product of Oracle Fusion ...)
NOT-FOR-US: Oracle
CVE-2026-61293 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61291 (Vulnerability in the Oracle WebCenter Content product of Oracle Fusion ...)
NOT-FOR-US: Oracle
CVE-2026-61290 (Vulnerability in the Oracle WebCenter Content product of Oracle Fusion ...)
@@ -2151,9 +2151,9 @@ CVE-2026-61286 (Vulnerability in the Oracle Enterprise Manager Base Platform pro
CVE-2026-61284 (Vulnerability in the Oracle Enterprise Manager Base Platform product o ...)
NOT-FOR-US: Oracle
CVE-2026-61281 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61276 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61273 (Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle ...)
NOT-FOR-US: Oracle
CVE-2026-61272 (Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle ...)
@@ -2165,7 +2165,7 @@ CVE-2026-61268 (Vulnerability in the JD Edwards EnterpriseOne Tools product of O
CVE-2026-61265 (Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of ...)
TODO: check
CVE-2026-61259 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61258 (Vulnerability in the Oracle Internet Directory product of Oracle Fusio ...)
TODO: check
CVE-2026-61248 (Vulnerability in the Oracle Internet Directory product of Oracle Fusio ...)
@@ -2195,7 +2195,7 @@ CVE-2026-61212 (Vulnerability in the Oracle WebCenter Portal product of Oracle F
CVE-2026-61208 (Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion ...)
NOT-FOR-US: Oracle
CVE-2026-61206 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61199 (Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion ...)
NOT-FOR-US: Oracle
CVE-2026-61198 (Vulnerability in the Oracle Learning Management product of Oracle E-Bu ...)
@@ -2355,7 +2355,7 @@ CVE-2026-60861 (Vulnerability in the Service Delivery Platform product of Oracle
CVE-2026-60860 (Vulnerability in the Service Delivery Platform product of Oracle Fusio ...)
TODO: check
CVE-2026-60858 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60856 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
NOT-FOR-US: Oracle
CVE-2026-60853 (Vulnerability in the Helidon product of Oracle Fusion Middleware (comp ...)
@@ -2391,9 +2391,9 @@ CVE-2026-60792 (Vulnerability in the Siebel CRM Deployment product of Oracle Sie
CVE-2026-60791 (Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CR ...)
NOT-FOR-US: Oracle
CVE-2026-60782 (Vulnerability in the Oracle Payments product of Oracle E-Business Suit ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60781 (Vulnerability in the Oracle Payments product of Oracle E-Business Suit ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60779 (Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel ...)
NOT-FOR-US: Oracle
CVE-2026-60769 (Vulnerability in the Oracle General Ledger product of Oracle E-Busines ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9b6a01092e48df586658a3d02d2833b477e682f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9b6a01092e48df586658a3d02d2833b477e682f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/937c7bc5/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list