[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 21 08:13:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4e1009d5 by security tracker role at 2026-07-21T07:13:28+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-8082 (The bpost-shipping-platform WordPress plugin before 3.2.3 does not pro ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6952 (A post-authentication command injection vulnerability in the "LogServe ...)
-	TODO: check
+	NOT-FOR-US: Zyxel
 CVE-2026-64651 (The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode  ...)
 	TODO: check
 CVE-2026-64650 (The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by  ...)
@@ -35,15 +35,15 @@ CVE-2026-63729 (The SyncTeX parser (synctex_parser.c) shipped with TeX Live and
 CVE-2026-63728 (Gitleaks prior to 8.30.1 contains a template injection vulnerability t ...)
 	TODO: check
 CVE-2026-62414 (The Joomla extension Page Builder CK does not properly apply access co ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-61901 (The Joomla extension Hikashop is vulnerable to an open redirect.)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-61900 (The Joomla extension JDownloads is vulnerable to an unauthenticated fi ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-61425 (The Joomla extension Gridbox is vulnerable an authenticated bypass, po ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-61424 (The Joomla extension DJ-Classifieds is vulnerable to an unauthenticate ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-59776 (Missing Cryptographic Step (CWE-325) vulnerability exists in certain F ...)
 	TODO: check
 CVE-2026-57852 (Grav CMS scheduler-webhook plugin contains an authentication bypass vu ...)
@@ -95,7 +95,7 @@ CVE-2026-47133 (ClearanceKit intercepts file-system access events on macOS and e
 CVE-2026-47130 (NextCRM is open-source customer relationship management (CRM) software ...)
 	TODO: check
 CVE-2026-47129 (NextCRM is open-source customer relationship management (CRM) software ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-47128 (nono is software that allows users to run AI agents in a zero-latency  ...)
 	TODO: check
 CVE-2026-44585 (Paymenter is a free and open-source webshop solution for management of ...)
@@ -113,23 +113,23 @@ CVE-2026-44508 (Rsync is a file-copying tool that uses a delta-transfer algorith
 CVE-2026-44507 (Rsync is a file-copying tool that uses a delta-transfer algorithm to s ...)
 	TODO: check
 CVE-2026-3182 (Zohocorp ManageEngine Endpoint Central versions before11.4.2528.34 are ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-16337 (Improper authorization in the ToolGroupResource and RoleAjax REST/DWR  ...)
 	TODO: check
 CVE-2026-16336 (A vulnerability was found in trinodb trino 481. Affected is an unknown ...)
 	TODO: check
 CVE-2026-16334 (A vulnerability was identified in itsourcecode Hospital Management Sys ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-16332 (A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an  ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-16331 (A security vulnerability has been detected in D-Link DNS-320 1.0.2. Th ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-16330 (A weakness has been identified in D-Link DNS-320 1.0.2. The impacted e ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-16329 (A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-16327 (A vulnerability was determined in D-Link DNS-320 1.0.2. This issue aff ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-16324 (A vulnerability was identified in Metasoft \u7f8e\u7279\u8f6f\u4ef6 Me ...)
 	TODO: check
 CVE-2026-16266 (Versions of the package mongo-object before 3.0.3 are vulnerable to Pr ...)
@@ -143,45 +143,45 @@ CVE-2026-15811 (A vulnerability was found in kronosnet's (version <=1.34) crypto
 CVE-2026-15788 (BuildKit's cache mount source= selector on Windows Container on Window ...)
 	TODO: check
 CVE-2026-15782 (The WPForms \u2013 AI Form Builder for WordPress \u2013 Contact Forms, ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15156 (The Essential Addons for Elementor \u2013 Popular Elementor Templates  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14185 (The WPBot  WordPress plugin before 8.2.0 does not perform a capability ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14184 (The Academy LMS WordPress plugin before 3.8.1 does not verify ownershi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14183 (The Classified Listing  WordPress plugin before 5.3.9 does not verify  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13694 (The Bit Form  WordPress plugin before 3.1.0 does not properly validate ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13693 (The Bit Form  WordPress plugin before 3.1.0 does not restrict a form f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13439 (The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerabl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13381 (VSee Clinic 7.1.26 and API1.3.0contain an Insecure Direct Object Refer ...)
 	TODO: check
 CVE-2026-13380 (VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP cr ...)
 	TODO: check
 CVE-2026-12900 (The Spectra Gutenberg Blocks \u2013 Website Builder for the Block Edit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11767 (The Free  Builder for Elementor  WordPress plugin before 1.6.7 does no ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-51316 (The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2024-51315 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2024-51314 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2024-51313 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2024-51312 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2024-51311 (The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2023-37508 (HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XS ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2023-37507 (HCL DevOps Plan is susceptible to an information disclosure that can a ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2026-58624 (Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA ...)
 	- mina2 <unfixed>
 	- mina <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e1009d5dc7ec1ec0a0fc67524710e96c57fa0df

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e1009d5dc7ec1ec0a0fc67524710e96c57fa0df
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/3b3809f0/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list