[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 26 08:14:39 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6003d1b0 by security tracker role at 2026-08-26T07:14:11+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
CVE-2026-9805 (SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32 ...)
- TODO: check
+ NOT-FOR-US: Insyde
CVE-2026-9252
REJECTED
CVE-2026-9250
@@ -47,15 +47,15 @@ CVE-2026-80104 (DB-GPT builds the destination path for an uploaded skill from th
CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When processing a spe ...)
TODO: check
CVE-2026-79912 (A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-79911 (A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-79845 (A vulnerability was identified in code-projects Simple Inventory Syste ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-79804 (A vulnerability was found in SililaWijesinghe Food Ordering System up ...)
TODO: check
CVE-2026-79793 (A vulnerability has been found in code-projects Online Shopping System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-79792 (A flaw has been found in zackees transcribe-anything up to 4.1.0. Affe ...)
TODO: check
CVE-2026-79654 (A flaw was found in Katello where the Content View History API does no ...)
@@ -719,23 +719,23 @@ CVE-2026-78655 (Punk::Plugin::TOTP versions before 0.05 for Perl allow the secon
CVE-2026-78619 (Punk::Plugin::TOTP versions before 0.05 for Perl accept another accoun ...)
TODO: check
CVE-2026-78146 (The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77790 (The RegistrationMagic WordPress plugin before 6.0.9.4 does not saniti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77789 (The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77758 (The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77757 (The Directorist: AI-Powered Business Directory, Listings & Classified ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77754 (The Kirki WordPress plugin before 6.0.14 does not perform a capabilit ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77695 (The Return Refund and Exchange For WooCommerce WordPress plugin before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77694 (The Eventin WordPress plugin before 4.1.19 does not properly restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77693 (The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not c ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77680 (An algorithmic complexity flaw exists in libsoup's HTTP Range header p ...)
TODO: check
CVE-2026-77585 (The Okta Privileged Access client does not reject a leading hyphen in ...)
@@ -747,23 +747,23 @@ CVE-2026-76149 (CorvusSKK contains an integer overflow vulnerability, which may
CVE-2026-76148 (CorvusSKK contains a code injection vulnerability, which may lead to a ...)
TODO: check
CVE-2026-75798 (The AI Engine WordPress plugin before 3.7.2 does not perform an autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75797 (The AI Engine WordPress plugin before 3.7.2 does not confine a caller ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75465 (The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is v ...)
TODO: check
CVE-2026-75421 (aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFil ...)
TODO: check
CVE-2026-74932 (The WP Fastest Cache WordPress plugin before 1.5.1 does not validate t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74930 (The Project Manager WordPress plugin before 4.0.7 does not check that ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74929 (The Project Manager WordPress plugin before 4.0.7 does not restrict s ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74928 (The Project Manager WordPress plugin before 4.0.7 does not have any a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74851 (The Pods WordPress plugin before 3.3.9.1 does not correctly compare a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-73335 (Android application "Myna Point" is vulnerable to Improper Authorizati ...)
TODO: check
CVE-2026-73180 (Insufficient Session Expiration vulnerability in Apache Tomcat meant t ...)
@@ -787,9 +787,9 @@ CVE-2026-68513 (OpenEXR is the reference implementation and specification for th
CVE-2026-66422 (Improper Authorization vulnerability in Apache Tomcat cause by securit ...)
TODO: check
CVE-2026-66153 (The NEService auto-upgrade process insecurely handles temporary files ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-66152 (A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetE ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-65927 (Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag ...)
TODO: check
CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in Apache Tomcat ...)
@@ -797,21 +797,21 @@ CVE-2026-65905 (Authentication Bypass by Capture-replay vulnerability in Apache
CVE-2026-65637 (Improper Input Validation vulnerability in Apache Tomcat due to incomp ...)
TODO: check
CVE-2026-65367 (A null pointer dereference was addressed with improved input validatio ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-65183 (Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ...)
TODO: check
CVE-2026-65182 (Improper Access Control, Incorrect Authorization vulnerability in Apac ...)
TODO: check
CVE-2026-65105 (NVIDIA NemoClaw for Linux contains a vulnerability in its inference se ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65099 (NVIDIA NemoClaw for Linux contains a vulnerability in its command-line ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65098 (NVIDIA NemoClaw for Linux contains a vulnerability in its remote-acces ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65097 (NVIDIA NemoClaw for Linux contains a vulnerability in its installation ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65096 (NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bri ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65093 (NVIDIA OpenShell for Linux contains a vulnerability where an attacker ...)
TODO: check
CVE-2026-65092 (NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an a ...)
@@ -819,27 +819,27 @@ CVE-2026-65092 (NVIDIA OpenShell Sandbox for Linux contains a vulnerability wher
CVE-2026-65091 (NVIDIA OpenShell for all platforms contains a vulnerability where a ma ...)
TODO: check
CVE-2026-65090 (NVIDIA NemoClaw for Linux contains a vulnerability in its NIM manageme ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65089 (NVIDIA NemoClaw for Linux contains a vulnerability in its status and l ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65088 (NVIDIA NemoClaw contains a vulnerability where an attacker could cause ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65087 (NVIDIA NemoClaw contains a vulnerability where an attacker could cause ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65086 (NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exe ...)
TODO: check
CVE-2026-65085 (NVIDIA OpenShell for Linux contains a vulnerability in its inference p ...)
TODO: check
CVE-2026-65084 (NVIDIA NemoClaw for Linux contains a vulnerability in its deployment p ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65083 (NVIDIA OpenShell for Linux contains a vulnerability in its sandbox pro ...)
TODO: check
CVE-2026-65082 (NVIDIA NemoClaw for Linux contains a vulnerability in its migration co ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-65081 (NVIDIA NemoClaw for Linux contains a vulnerability in its installation ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-64705 (A buffer overflow was addressed with improved bounds checking. This is ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-63404 (Faktory is a language-agnostic background job server. In versions prio ...)
TODO: check
CVE-2026-63403 (Faktory is a language-agnostic background job server. In versions prio ...)
@@ -853,7 +853,7 @@ CVE-2026-62861 (TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenti
CVE-2026-59981 (OpenEXR is the reference implementation and specification for the EXR ...)
TODO: check
CVE-2026-58108 (The personal access token removal query selects fromPersonalAccessToke ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2026-58097 (mp_SetEnddisc() copied a user-supplied PSN endpoint value without leng ...)
TODO: check
CVE-2026-58096 (LcpDecodeConfig() did not validate the length of received endpoint dis ...)
@@ -877,7 +877,7 @@ CVE-2026-57171 (Compliance-trestle (Trestle) is a Python SDK and command-line to
CVE-2026-57170 (Compliance-trestle (Trestle) is a Python SDK and command-line tool for ...)
TODO: check
CVE-2026-55805 (Improper Neutralization of Input During Web Page Generation ("Cross-si ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-55588 (ORAS (OCI Registry As Storage) is a CLI and library for managing artif ...)
TODO: check
CVE-2026-54757 (Compliance-trestle (Trestle) is a Python SDK and command-line tool for ...)
@@ -901,13 +901,13 @@ CVE-2026-45018 (Chainlit is a Python framework for building production-ready con
CVE-2026-44476 (Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, ...)
TODO: check
CVE-2026-43670 (A Content Security Policy bypass was addressed with improved enforceme ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-43657 (A permissions issue was addressed with additional restrictions. This i ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-41707 (Authentication Bypass by Capture-replay vulnerability in Spring Spring ...)
TODO: check
CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & Ecosystem ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version source snapsh ...)
TODO: check
CVE-2026-38474 (GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d1 ...)
@@ -933,55 +933,55 @@ CVE-2026-32637 (Velero is an open source tool for backing up, restoring, and mig
CVE-2026-29988 (A cleartext transmission of sensitive information vulnerability in the ...)
TODO: check
CVE-2026-19760 (The WP Fastest Cache \u2013 WordPress Cache Plugin plugin for WordPres ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19718 (The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19632 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19226 (The Royal Addons for Elementor WordPress plugin before 1.7.1066 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19220 (The Forminator Forms WordPress plugin before 1.57.1 does not verify t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19094 (The Tutor LMS WordPress plugin before 4.0.6 does not validate values ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18985 (Incorrect Authorization vulnerability in Drupal Edit in-place field al ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-18431 (The Avada theme for WordPress is vulnerable to Arbitrary File Write in ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18331 (The Formidable Forms \u2013 WordPress Form Builder for Contact Forms, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18261 (Vulnerability in Drupal Powerful Surveys. This issue affects Powerful ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-18260 (Vulnerability in Drupal Disable Login Page. This issue affects Disable ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-18259 (Observable Timing Discrepancy vulnerability in Drupal Token Content Ac ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16986 (The Booking Package WordPress plugin before 1.7.25 does not validate t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16984 (The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie P ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16646 (Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16645 (Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16644 (Incorrect Authorization vulnerability in Drupal Webform REST allows Fo ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16643 (Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16642 (Vulnerability in Drupal Email Login OTP. This issue affects Email Logi ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16641 (Vulnerability in Drupal Commerce Elavon. This issue affects Commerce E ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16640 (Improper Neutralization of Input During Web Page Generation ("Cross-si ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16639 (Authentication Bypass Using an Alternate Path or Channel vulnerability ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-16638 (Improper Neutralization of Input During Web Page Generation ("Cross-si ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-15917 (Improper Neutralization of Input During Web Page Generation ("Cross-si ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-15916 (Missing Authorization vulnerability in Drupal Drupal core allows Force ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-15366 (A control logic defect in a specific built-in webpage of Kids Mode all ...)
TODO: check
CVE-2026-15365 (A pop-up logic flaw in a certain feature of Kids Mode allows users to ...)
@@ -989,19 +989,19 @@ CVE-2026-15365 (A pop-up logic flaw in a certain feature of Kids Mode allows use
CVE-2026-15203 (Improper access control in debug and engineering interfaces in Danfoss ...)
TODO: check
CVE-2026-15088 (Vulnerability in Drupal Development Environment. This issue affects De ...)
- TODO: check
+ NOT-FOR-US: Drupal core and addons
CVE-2026-14550 (The WPCafe WordPress plugin before 3.0.18 does not perform an authori ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14216 (The Booking for Appointments and Events Calendar WordPress plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14212 (The Booking for Appointments and Events Calendar WordPress plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13406 (The Royal Addons for Elementor WordPress plugin before 1.7.1066 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13404 (The Royal Addons for Elementor WordPress plugin before 1.7.1066 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13172 (The Eventin WordPress plugin before 4.1.22 does not restrict access t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-80184 (In OpenStack Keystone before 29.0.3, tokens obtained via delegated aut ...)
- keystone <unfixed>
NOTE: https://www.openwall.com/lists/oss-security/2026/08/25/9
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6003d1b0af0b5e03b8b0f301beab0cb1b1ca3baf
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6003d1b0af0b5e03b8b0f301beab0cb1b1ca3baf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/2f3ad3c6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list