[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 21 08:13:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4e1009d5 by security tracker role at 2026-07-21T07:13:28+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-8082 (The bpost-shipping-platform WordPress plugin before 3.2.3 does not pro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-6952 (A post-authentication command injection vulnerability in the "LogServe ...)
- TODO: check
+ NOT-FOR-US: Zyxel
CVE-2026-64651 (The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode ...)
TODO: check
CVE-2026-64650 (The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by ...)
@@ -35,15 +35,15 @@ CVE-2026-63729 (The SyncTeX parser (synctex_parser.c) shipped with TeX Live and
CVE-2026-63728 (Gitleaks prior to 8.30.1 contains a template injection vulnerability t ...)
TODO: check
CVE-2026-62414 (The Joomla extension Page Builder CK does not properly apply access co ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-61901 (The Joomla extension Hikashop is vulnerable to an open redirect.)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-61900 (The Joomla extension JDownloads is vulnerable to an unauthenticated fi ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-61425 (The Joomla extension Gridbox is vulnerable an authenticated bypass, po ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-61424 (The Joomla extension DJ-Classifieds is vulnerable to an unauthenticate ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-59776 (Missing Cryptographic Step (CWE-325) vulnerability exists in certain F ...)
TODO: check
CVE-2026-57852 (Grav CMS scheduler-webhook plugin contains an authentication bypass vu ...)
@@ -95,7 +95,7 @@ CVE-2026-47133 (ClearanceKit intercepts file-system access events on macOS and e
CVE-2026-47130 (NextCRM is open-source customer relationship management (CRM) software ...)
TODO: check
CVE-2026-47129 (NextCRM is open-source customer relationship management (CRM) software ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-47128 (nono is software that allows users to run AI agents in a zero-latency ...)
TODO: check
CVE-2026-44585 (Paymenter is a free and open-source webshop solution for management of ...)
@@ -113,23 +113,23 @@ CVE-2026-44508 (Rsync is a file-copying tool that uses a delta-transfer algorith
CVE-2026-44507 (Rsync is a file-copying tool that uses a delta-transfer algorithm to s ...)
TODO: check
CVE-2026-3182 (Zohocorp ManageEngine Endpoint Central versions before11.4.2528.34 are ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-16337 (Improper authorization in the ToolGroupResource and RoleAjax REST/DWR ...)
TODO: check
CVE-2026-16336 (A vulnerability was found in trinodb trino 481. Affected is an unknown ...)
TODO: check
CVE-2026-16334 (A vulnerability was identified in itsourcecode Hospital Management Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-16332 (A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-16331 (A security vulnerability has been detected in D-Link DNS-320 1.0.2. Th ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-16330 (A weakness has been identified in D-Link DNS-320 1.0.2. The impacted e ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-16329 (A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-16327 (A vulnerability was determined in D-Link DNS-320 1.0.2. This issue aff ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-16324 (A vulnerability was identified in Metasoft \u7f8e\u7279\u8f6f\u4ef6 Me ...)
TODO: check
CVE-2026-16266 (Versions of the package mongo-object before 3.0.3 are vulnerable to Pr ...)
@@ -143,45 +143,45 @@ CVE-2026-15811 (A vulnerability was found in kronosnet's (version <=1.34) crypto
CVE-2026-15788 (BuildKit's cache mount source= selector on Windows Container on Window ...)
TODO: check
CVE-2026-15782 (The WPForms \u2013 AI Form Builder for WordPress \u2013 Contact Forms, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15156 (The Essential Addons for Elementor \u2013 Popular Elementor Templates ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14185 (The WPBot WordPress plugin before 8.2.0 does not perform a capability ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14184 (The Academy LMS WordPress plugin before 3.8.1 does not verify ownershi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14183 (The Classified Listing WordPress plugin before 5.3.9 does not verify ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13694 (The Bit Form WordPress plugin before 3.1.0 does not properly validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13693 (The Bit Form WordPress plugin before 3.1.0 does not restrict a form f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13439 (The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerabl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13381 (VSee Clinic 7.1.26 and API1.3.0contain an Insecure Direct Object Refer ...)
TODO: check
CVE-2026-13380 (VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP cr ...)
TODO: check
CVE-2026-12900 (The Spectra Gutenberg Blocks \u2013 Website Builder for the Block Edit ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11767 (The Free Builder for Elementor WordPress plugin before 1.6.7 does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-51316 (The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2024-51315 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2024-51314 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2024-51313 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2024-51312 (The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2024-51311 (The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2023-37508 (HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XS ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2023-37507 (HCL DevOps Plan is susceptible to an information disclosure that can a ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-58624 (Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA ...)
- mina2 <unfixed>
- mina <removed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e1009d5dc7ec1ec0a0fc67524710e96c57fa0df
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e1009d5dc7ec1ec0a0fc67524710e96c57fa0df
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/3b3809f0/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list