[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 21 20:14:33 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
73f53587 by security tracker role at 2026-07-21T19:14:26+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -25,7 +25,7 @@ CVE-2026-65008 (Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vul
CVE-2026-65007 (The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly a ...)
TODO: check
CVE-2026-64877 (An authenticated non-admin user can exploit a SQL injection flaw in th ...)
- TODO: check
+ NOT-FOR-US: Tenable
CVE-2026-64825 (Home Assistant Core before 2026.6.0 contains a path traversal vulnerab ...)
TODO: check
CVE-2026-64824 (Home Assistant Core before 2026.7.0 contains a path traversal vulnerab ...)
@@ -35,21 +35,21 @@ CVE-2026-64823 (Home Assistant Core before 2026.5.4 contains a cross-site script
CVE-2026-64628 (Grav contains a stored cross-site scripting vulnerability in shortcode ...)
TODO: check
CVE-2026-64627 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions befo ...)
- TODO: check
+ NOT-FOR-US: Parse Server
CVE-2026-64609 (Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-ban ...)
TODO: check
CVE-2026-64608 (Heap type confusion and out-of-bounds read/write in the Apache Fory C+ ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-64606 (Deserialization of untrusted data vulnerability that may allow class-r ...)
TODO: check
CVE-2026-63454 (An authenticated path traversal vulnerability exists in AOS-CX. Succes ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-63453 (Buffer overflow vulnerabilities exist in the command line interface of ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-62415 (The Joomla extension Membership Pro prior version 4.6.2 did by default ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-60080 (Use After Free vulnerability in the Rust deserialization logic of Apac ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-59142 (Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bo ...)
TODO: check
CVE-2026-59141 (Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of- ...)
@@ -59,27 +59,27 @@ CVE-2026-59140 (Data::SortedSet::Shared versions before 0.03 for Perl allow an o
CVE-2026-59139 (Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bou ...)
TODO: check
CVE-2026-56587 (HCL IEM was affected with Strict transport security not enforced. It m ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56586 (HCL IEM was affected with X-Content-Type-Options Header Missing. It ma ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56585 (HCL IEM was affected with the Anti Clickjacking XFrame Options Header ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56584 (HCL IEM was affected with the Information disclosure nginx server. It ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56583 (HCL MyCloud was affected with Concurrent Login Vulnerability. It may i ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56582 (HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An atta ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56581 (HCL MyCloud was affected with Cookie Attribute Path Not Set. It may in ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56580 (HCL MyCloud was affected by Using Components with Known Vulnerability ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56579 (HCL MyCloud was affected with License Key Revealed in HTTP Response. I ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56578 (HCL MyCloud was affected by Server Version Disclosure. It may help att ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56577 (HCL MyCloud was affected with Weak Password Policy. It may increase th ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-55084 (DHIS2 is a flexible information system for data capture, management, v ...)
TODO: check
CVE-2026-55082 (DHIS2 is a flexible information system for data capture, management, v ...)
@@ -149,53 +149,53 @@ CVE-2026-46681 (@nevware21/ts-utils is a comprehensive TypeScript/JavaScript uti
CVE-2026-44907 (A denial of service vulnerability could be triggered by sending specia ...)
TODO: check
CVE-2026-44880 (A buffer overflow vulnerability was found in the command line interfac ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-3183 (Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vuln ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-28321 (SolarWinds Serv-U is affected by a broken access control vulnerability ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28317 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28316 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28315 (SolarWinds Serv-U was found to be affected by a stored cross-site scri ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28314 (SolarWinds Serv-U is affected by an insecure direct object reference v ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28313 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28312 (SolarWinds Serv-U is affected by a privilege escalation vulnerability. ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28310 (SolarWinds Serv-U is affected by a privilege escalation vulnerability ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28309 (SolarWinds Serv-U is affected by a broken access control vulnerability ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28308 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28307 (SolarWinds Serv-U is affected by a privilege escalation vulnerability ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28306 (SolarWinds Serv-U is affected by a privilege escalation vulnerability ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28305 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28304 (SolarWinds Serv-U is affected by a remote code execution vulnerability ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-28302 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
- TODO: check
+ NOT-FOR-US: SolarWinds
CVE-2026-24232 (NVIDIA Tranformers4Rec contains a vulnerability where an attacker coul ...)
TODO: check
CVE-2026-21579 (This High severity Information Disclosure vulnerability was introduced ...)
- TODO: check
+ NOT-FOR-US: Atlassian
CVE-2026-21577 (This High severity DoS (Denial of Service) vulnerability was introduce ...)
- TODO: check
+ NOT-FOR-US: Atlassian
CVE-2026-21575 (This High severity RCE (Remote Code Execution) vulnerability was intro ...)
- TODO: check
+ NOT-FOR-US: Atlassian
CVE-2026-1771 (The MapSVG plugin for WordPress is vulnerable to arbitrary file upload ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-1617 (Improper neutralization of special elements used in an SQL command ('S ...)
TODO: check
CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to M ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16493 (A flaw was found in ansible-core. The _extract_collection_from_git() f ...)
TODO: check
CVE-2026-16461 (A stack-based buffer overflow was found in rpcbind's rpcinfo utility. ...)
@@ -209,17 +209,17 @@ CVE-2026-16450 (A vulnerability was identified in zsadmin2025 ZS-Admin up to b52
CVE-2026-16449 (A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536 ...)
TODO: check
CVE-2026-16448 (A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-3 ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-16447 (A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-16445 (A flaw was found in dracut. A remote attacker on the adjacent network ...)
TODO: check
CVE-2026-16441 (In Eclipse OpenJ9 versions up to 0.60, when executing class files wher ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-16439 (In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method a ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-16243 (In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation f ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-15829 (A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulner ...)
TODO: check
CVE-2026-15793 (BuildKit custom frontends or clients using the raw low-level API can s ...)
@@ -231,13 +231,13 @@ CVE-2026-15791 (A crafted message in the BuildKit low-level build API can be use
CVE-2026-15789 (A custom client can produce such an upload request to the BuildKit dae ...)
TODO: check
CVE-2026-15724 (In Progress ShareFile Storage Zones Controller versions prior to 5.12. ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-15432 (When verifying a mac with a ChunkedMacVerification object, Tink compar ...)
TODO: check
CVE-2026-15342 (Plane contains a multi\u2011tenant authorization flaw in its asset\u20 ...)
TODO: check
CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor Templates ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When parsing mult ...)
TODO: check
CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials without scopin ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73f535871486bcdd72ac1dc113a23af2b18b4583
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73f535871486bcdd72ac1dc113a23af2b18b4583
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/17178f62/attachment.htm>
More information about the debian-security-tracker-commits
mailing list