[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 27 08:41:39 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b36d6ba1 by security tracker role at 2026-08-27T07:14:36+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7,33 +7,33 @@ CVE-2026-81485 (A security vulnerability has been detected in danielpopamd linke
CVE-2026-81421 (A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp ...)
TODO: check
CVE-2026-81203 (A vulnerability has been found in SourceCodester Simple Online Food Or ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-81202 (A flaw has been found in itsourcecode Payroll System 1.0. The impacted ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-80183 (In OpenStack Keystone before 29.0.3, any authenticated user holding ro ...)
TODO: check
CVE-2026-79939 (Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an U ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79938 (Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an I ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-79921 (amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a comprom ...)
TODO: check
CVE-2026-78333 (The 12 Step Meeting List WordPress plugin before 3.19.17 does not sani ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78139 (The Notifima WordPress plugin before 3.1.4 does not verify that the c ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78138 (The Finale Lite WordPress plugin before 2.21.0 does not perform a cap ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78137 (The StoreGrowth WordPress plugin before 2.1.2 does not validate a bro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78125 (The LearnPress WordPress plugin before 4.0.3 does not perform any aut ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77991 (Joomla Extension - joomlaeventmanager.net - Privileged remote code exe ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-77990 (Joomla Extension - joomlaeventmanager.net - Attendee lists readable by ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-77989 (Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-77652 (A heap-based buffer overflow vulnerability exists in the Dia diagram e ...)
TODO: check
CVE-2026-77611 (SeaweedFS is a distributed storage system for files and blobs. In vers ...)
@@ -51,17 +51,17 @@ CVE-2026-77317 (SeaweedFS is a distributed storage system for files and blobs. I
CVE-2026-77298 (SeaweedFS is a distributed storage system for files and blobs. In vers ...)
TODO: check
CVE-2026-77035 (Joomla Extension - joomlaeventmanager.net - Cross-user event and venue ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-77034 (Joomla Extension - joomlaeventmanager.net - Unauthenticated article ov ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-77018 (The Workeera WordPress plugin before 1.0.6 does not restrict which pr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77017 (The Workeera WordPress plugin before 1.0.6 does not restrict which pr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77016 (The Workeera WordPress plugin before 1.0.6 does not restrict which va ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76549 (The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75601 (Static Web Server (SWS) is a production-ready web server suitable for ...)
TODO: check
CVE-2026-75415 (AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommo ...)
@@ -99,25 +99,25 @@ CVE-2026-75328 (In DocSys-master V2.02.85, the downloadDocEx interface in src/co
CVE-2026-75327 (In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/ ...)
TODO: check
CVE-2026-74774 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Imprope ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-74771 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authori ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-74770 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Imprope ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-71172 (Dell Cloud Disaster Recovery, versions20.2 and prior,containa Server-S ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-71054 (Vulnerability in Oracle Java SE (component: 2D). Supported versions t ...)
TODO: check
CVE-2026-69129 (KubePi is a Kubernetes multi-cluster management panel. In versions up ...)
TODO: check
CVE-2026-68863 (Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-ba ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-68861 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Imprope ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-68000 (The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerab ...)
TODO: check
CVE-2026-67275 (Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-66003 (Frappe is a full-stack web application framework written in Python and ...)
TODO: check
CVE-2026-65956 (KubePi is a Kubernetes multi-cluster management panel. In versions up ...)
@@ -149,19 +149,19 @@ CVE-2026-61617 (Wings is the server control plane for the Pterodactyl game-serve
CVE-2026-60004 (Gitea before 1.27.1 allows remote code execution via the diffpatch API ...)
TODO: check
CVE-2026-59278 (JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59275 (A single hostile AMQP message can terminate the entire consumer JVM (S ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59274 (The UnZipTransformer does not limit decompressed entry size or entry c ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59271 (When the RabbitMQ management aliveness check fails, the configured adm ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59270 (Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) ...)
TODO: check
CVE-2026-58070 (A vulnerability that records guest OS processing credentials in cleart ...)
TODO: check
CVE-2026-56547 (The Apple profile generated for the Apple built-in Mail, Calendar and ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-55228 (Weblate is a web-based continuous localization platform used to manage ...)
TODO: check
CVE-2026-55227 (Weblate is a web-based localization tool. In versions prior to 2026.7, ...)
@@ -175,9 +175,9 @@ CVE-2026-52473 (An issue in Wgcloud 3.6.4 allows a remote attacker to escalate p
CVE-2026-52103 (A zero-click remote code execution (RCE) vulnerability in the /Termina ...)
TODO: check
CVE-2026-49809 (Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-47894 (Spring Cloud Config Server native environment repository allows exposu ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47893 (A Spring WebFlux application that supports WebSocket connections may e ...)
TODO: check
CVE-2026-47892 (A WebFlux application using functional endpoints and deployed with Dis ...)
@@ -203,9 +203,9 @@ CVE-2026-47883 (UrlHandlerFilter can be vulnerable to an open redirect when conf
CVE-2026-47881 (Spring Batch's FlatFileItemReader supports files where a single logica ...)
TODO: check
CVE-2026-47880 (A producer who can publish to a JMS destination consumed by any Spring ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47879 (Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary S ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47878 (DefaultExecutionContextSerializer, used by default in Spring Batch's J ...)
TODO: check
CVE-2026-47877 (Spring Security Authorization Server's default consent page renders us ...)
@@ -213,39 +213,39 @@ CVE-2026-47877 (Spring Security Authorization Server's default consent page rend
CVE-2026-47875 (Applications that deserialize execution contexts with Jackson2Executio ...)
TODO: check
CVE-2026-47874 (The vulnerability occurs when a client sends HTTP/1.1 pipelined reques ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47864 (SerializingHttpMessageConverter deserializes the body of incoming HTTP ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47863 (In Reactor Core, applications that use the Flux.bufferTimeout operator ...)
TODO: check
CVE-2026-47862 (An attacker who can set the file_name header on a message reaching a Z ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47861 (An unauthenticated remote attacker who can send a single UDP packet to ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47860 (An attacker who can publish to a queue consumed by an application that ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47859 (RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP i ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47857 (In Reactor Core, applications that use the Flux.windowTimeout operator ...)
TODO: check
CVE-2026-47856 (Spring Integration's JSON to object conversion uses the json__TypeId__ ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47852 (A local attacker on a multi-user host can pre-create the deterministic ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47851 (Analyzing a PDF with a deeply nested or cyclic table of contents can c ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47850 (Spring Data REST does not preserve the persisted version (@Version) pr ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47849 (Spring Data REST does not guard identifier (@Id) and version (@Version ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47848 (In specific scenarios involving WebSocket handshake redirects to a dif ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47845 (In specific scenarios, Reactor Netty HTTP Server may incorrectly evalu ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47844 (In specific scenarios, the Reactor Netty HTTP Server may leak exceptio ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47843 (In specific scenarios involving multiple clients with different DNS re ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47842 (Applications using AesBytesEncryptor with the two-argument constructor ...)
TODO: check
CVE-2026-47834 (Spring Data JPA's Sort validation can be bypassed when parameters cont ...)
@@ -277,23 +277,23 @@ CVE-2026-26446 (Stomper 5e2741e is vulnerable to Denial of Service. When a broke
CVE-2026-26445 (stomper 5e2741e is vulnerable to Denial of Service. A malicious client ...)
TODO: check
CVE-2026-21810 (HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external r ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-21809 (HCL BigFix Quantum Risk Analyzer has a certain validation process that ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-21808 (HCL BigFix Quantum Risk Analyzer generates highly detailed logging inf ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-21807 (HCL BigFix Quantum Risk Analyzer binary lacks several critical, indust ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-19715 (The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19454 (The JetBackup WordPress plugin before 3.1.23.5 does not perform its m ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19398 (\u201cunsupported-when-assigned.\u201d An out-of-bounds write in the S ...)
- TODO: check
+ NOT-FOR-US: ASUS
CVE-2026-19225 (The Defender Security WordPress plugin before 6.2.0 does not restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19223 (The Smush WordPress plugin before 4.3.2 does not restrict a network-w ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18823
REJECTED
CVE-2026-16895 (A logic vulnerability (fail-open condition) has been identified within ...)
@@ -301,19 +301,19 @@ CVE-2026-16895 (A logic vulnerability (fail-open condition) has been identified
CVE-2026-16809 (LimeSurvey Community Edition 7.0.5 contains a stored cross-site script ...)
TODO: check
CVE-2026-16569 (The Mobile App for WooCommerce: ShopApper Mobile App Builder Service f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16568 (The Mobile App for WooCommerce: ShopApper Mobile App Builder Service f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16567 (The Document Embedder WordPress plugin before 2.3.1 does not check a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15973 (LimeSurvey Community Edition 7.0.5 contains a stored cross-site script ...)
TODO: check
CVE-2026-13416 (The CMP WordPress plugin before 4.1.18 does not sanitise and escape a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13415 (The CMP WordPress plugin before 4.1.18 does not enforce an option-nam ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13414 (The CMP WordPress plugin before 4.1.18 does not perform authorization ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-70340 (A Broken Access Control vulnerability exists in ThingsBoard Profession ...)
TODO: check
CVE-2025-70293 (An issue was discovered in Denx U-Boot before 2026.04. An integer over ...)
@@ -321,7 +321,7 @@ CVE-2025-70293 (An issue was discovered in Denx U-Boot before 2026.04. An intege
CVE-2025-70290 (An issue was discovered in Denx U-Boot before 2026.04. An integer over ...)
TODO: check
CVE-2025-62341 (HCL Connections is vulnerable to server-side request forgery (SSRF) wh ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-61480 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Boar ...)
TODO: check
CVE-2025-61479 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Boar ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b36d6ba1c2de3ca4284f301641dd6478cc4c0f3b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b36d6ba1c2de3ca4284f301641dd6478cc4c0f3b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/5e1dd827/attachment.htm>
More information about the debian-security-tracker-commits
mailing list