[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 31 08:14:57 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4e9a26a5 by security tracker role at 2026-08-31T07:14:50+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -21,17 +21,17 @@ CVE-2026-82656 (Admidio before 5.0.12 fails to sanitize album names in the photo
CVE-2026-82655 (Admidio before 5.0.12 contains a blind SQL injection vulnerability in ...)
TODO: check
CVE-2026-82654 (SiYuan before v3.8.1 fails to properly escape block name, alias, and m ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82653 (SiYuan before v3.8.1 contains a stored cross-site scripting vulnerabil ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82652 (SiYuan before v3.8.1 fails to filter invisible-tier content from SQL e ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82651 (SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (intr ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82650 (SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulne ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82649 (SiYuan Windows installer before version 3.8.1 (affected versions >= 2. ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82648 (WWBN AVideo contains a server-side request forgery filter bypass vulne ...)
TODO: check
CVE-2026-82647 (WWBN AVideo contains a cross-site request forgery vulnerability in sen ...)
@@ -63,17 +63,17 @@ CVE-2026-82635 (Pake before 3.13.1 joins the JavaScript-supplied filename for th
CVE-2026-82634 (Frappe Framework development builds contain an authorization flaw in t ...)
TODO: check
CVE-2026-82633 (Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object auth ...)
- TODO: check
+ NOT-FOR-US: Dolibarr
CVE-2026-82628 (A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulne ...)
TODO: check
CVE-2026-82625 (A vulnerability has been found in code-projects Simple Inventory Syste ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-82624 (A flaw has been found in code-projects Simple Inventory System 1.0. Af ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-82623 (A vulnerability was detected in open62541 up to 1.5.5. Affected by thi ...)
TODO: check
CVE-2026-82622 (A security vulnerability has been detected in code-projects Employee L ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-82621 (A weakness has been identified in Soarkey StudentManagement and \u5b66 ...)
TODO: check
CVE-2026-82620 (A security flaw has been discovered in Soarkey StudentManagement and \ ...)
@@ -83,21 +83,21 @@ CVE-2026-82619 (A vulnerability was identified in Systerel S2OPC up to 1.7.3. Th
CVE-2026-82618 (A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affe ...)
TODO: check
CVE-2026-82616 (A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. I ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-82615 (A vulnerability has been found in itsourcecode Online Medicine Deliver ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82614 (A flaw has been found in itsourcecode Online Medicine Delivery System ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82613 (A vulnerability was detected in itsourcecode Online Medicine Delivery ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82612 (A security vulnerability has been detected in itsourcecode Online Medi ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82611 (A weakness has been identified in itsourcecode Online Medicine Deliver ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82610 (A security flaw has been discovered in itsourcecode Online Medicine De ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82609 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82608 (A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This aff ...)
TODO: check
CVE-2026-82607 (A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3 ...)
@@ -119,17 +119,17 @@ CVE-2026-82599 (A vulnerability was identified in SeaCMS up to 13.6. Affected by
CVE-2026-82598 (A vulnerability was determined in SeaCMS up to 13.6. Affected is the f ...)
TODO: check
CVE-2026-82597 (A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B202307 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-82596 (A vulnerability was determined in LatencyUtils up to 2.0.3. Affected b ...)
TODO: check
CVE-2026-82595 (A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this v ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82594 (A vulnerability has been found in LogNet grpc-spring-boot-starter up t ...)
TODO: check
CVE-2026-82593 (A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the funct ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82592 (A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects th ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-82591 (A security vulnerability has been detected in Open Asset Import Librar ...)
TODO: check
CVE-2026-82590 (A weakness has been identified in Open5GS up to 2.7.7. The affected el ...)
@@ -149,9 +149,9 @@ CVE-2026-82564 (Authorization Bypass Through User-Controlled Key vulnerability i
CVE-2026-82556 (A vulnerability was found in Forgejo up to 15.0.4. This issue affects ...)
TODO: check
CVE-2026-82555 (A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B2022050 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-82554 (A flaw has been found in SourceCodester Queue Management System 1.0. T ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-82553 (A vulnerability was detected in sambitraj Student Management System up ...)
TODO: check
CVE-2026-82552 (A security vulnerability has been detected in Linux Foundation Magma 1 ...)
@@ -167,19 +167,19 @@ CVE-2026-82548 (A vulnerability was determined in Linux Foundation Magma 1.9.0.
CVE-2026-82547 (A vulnerability was found in Linux Foundation Magma 1.9.0. The affecte ...)
TODO: check
CVE-2026-82545 (A vulnerability has been found in itsourcecode Sales and Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82544 (A flaw has been found in wger-project wger up to 2.6.0-alpha2. This is ...)
TODO: check
CVE-2026-82543 (A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vul ...)
TODO: check
CVE-2026-82542 (A weakness has been identified in Tenda HG10 300001138. Affected by th ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-82541 (A security flaw has been discovered in itsourcecode Sales and Inventor ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82540 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82539 (A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-82488 (A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vuln ...)
TODO: check
CVE-2026-82487 (A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affe ...)
@@ -187,9 +187,9 @@ CVE-2026-82487 (A vulnerability was determined in Beetel 450TC3 01.00.00_01. Thi
CVE-2026-82486 (A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this ...)
TODO: check
CVE-2026-82485 (A vulnerability has been found in itsourcecode Sales and Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82484 (A flaw has been found in itsourcecode Sales and Inventory System 1.0. ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-82483 (A vulnerability was detected in coppermine-gallery Coppermine Photo Ga ...)
TODO: check
CVE-2026-82367 (Exposure of Data Element to Wrong Session vulnerability in ash-project ...)
@@ -235,7 +235,7 @@ CVE-2026-77850 (Stored Cross-site Scripting vulnerability in ash-project ash_adm
CVE-2026-77454 (Incorrect Authorization vulnerability in ash-project ash_sql allows a ...)
TODO: check
CVE-2026-77013 (The \u7231\u91c7\u96c6\u6570\u636e\u91c7\u96c6\u548c\u53d1\u5e03\u63d2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75760 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
TODO: check
CVE-2026-75757 (Reliance on Cookies without Validation and Integrity Checking vulnerab ...)
@@ -255,7 +255,7 @@ CVE-2026-64840
CVE-2026-64839
REJECTED
CVE-2026-58574 (Dell PowerStore contains a Missing Authentication for Critical Functio ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-56718 (AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a pa ...)
TODO: check
CVE-2026-56716
@@ -267,11 +267,11 @@ CVE-2026-56713
CVE-2026-53620 (GROWI contains a vulnerability with an authorization bypass through us ...)
TODO: check
CVE-2026-40465 (NSP is vulnerable to an open redirect due to insufficient server-side ...)
- TODO: check
+ NOT-FOR-US: Nokia
CVE-2026-40464 (NSP is vulnerable to a stored XSS due to insufficient validation or en ...)
- TODO: check
+ NOT-FOR-US: Nokia
CVE-2026-40463 (WaveSuite is affected by an insufficient role-based access control vul ...)
- TODO: check
+ NOT-FOR-US: Nokia
CVE-2026-18054
- qemu 1:11.1.0+ds-1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/1f24066fc88d33455ee54a20f29994d9e69997ba (v11.1.0-rc3)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e9a26a5d05bd0f36f7485b9cc065182864d6611
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e9a26a5d05bd0f36f7485b9cc065182864d6611
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/83dd83c3/attachment.htm>
More information about the debian-security-tracker-commits
mailing list