[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 22 20:14:29 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1e5f7536 by security tracker role at 2026-07-22T19:14:22+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -13,33 +13,33 @@ CVE-2026-65601 (Traefik versions 3.7.0 through 3.7.6 contain a namespace confusi
CVE-2026-65600 (Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v ...)
TODO: check
CVE-2026-65599 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65598 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race conditi ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65597 (n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a D ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65596 (n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65595 (n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65594 (n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65593 (n8n versions before 1.123.64 contain a server-side request forgery vul ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65592 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-si ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65591 (n8n contains a sanitizer bypass vulnerability in the legacy expression ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65590 (n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sand ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65589 (n8n versions before 1.123.64 fail to properly mask custom HTTP header ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65016 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege e ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65015 (n8n versions before 2.30.1 contain a privilege escalation vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65014 (n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers t ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-65013 (Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken obje ...)
TODO: check
CVE-2026-65012 (InvokeAI before 6.13.7 contains an unauthenticated directory enumerati ...)
@@ -61,39 +61,39 @@ CVE-2026-64830 (FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflo
CVE-2026-64828 (Froiden TableTrack through 1.3.10 contains a stored cross-site scripti ...)
TODO: check
CVE-2026-63264 (The Joomla extension JoomShopping is vulnerable to an reflected XSS vu ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-63048 (The Joomla extension Page Builder CK is vulnerable to an authenticated ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-63047 (The Joomla extension Events Booking prior version 5.0-5.8.1 did not pr ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-62145 (A vulnerability in Check Point Gaia Portal allows an authenticated att ...)
TODO: check
CVE-2026-62144 (An authentication bypass vulnerability in Check Point Security Managem ...)
TODO: check
CVE-2026-61392 (There is a information disclosure vulnerability in some Hikvision came ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-61391 (There is a stack-based buffer overflow vulnerability in some Hikvision ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-61390 (There is a heap buffer overflow vulnerability in some Hikvision camera ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-57600 (Insufficient validation of input parameters in the firmware of some Hi ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-57599 (There is a privilege escalation vulnerability in some Hikvision camera ...)
- TODO: check
+ NOT-FOR-US: Hikvision
CVE-2026-53910 (diff3tool from GNU diffutilsis vulnerable to a heap\u2011based buffer ...)
TODO: check
CVE-2026-4773 (Improper validation of specified type of input vulnerability in Magars ...)
TODO: check
CVE-2026-49499 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-46738 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-46737 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-45820 (fflate through 0.8.2 is vulnerable to denial of service via an infinit ...)
TODO: check
CVE-2026-44276 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-44192 (A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP ...)
TODO: check
CVE-2026-44191 (A flaw was found in the Visual Studio Code Ansible Lightspeed extensio ...)
@@ -105,17 +105,17 @@ CVE-2026-44189 (A flaw was found in the Visual Studio Code Ansible Lightspeed ex
CVE-2026-44187 (A flaw was found in the Ansible Lightspeed extension for Visual Studio ...)
TODO: check
CVE-2026-40714 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-40712 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-3482 (IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 throu ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-2406 (Authorization bypass through User-Controlled key vulnerability in Univ ...)
TODO: check
CVE-2026-2395 (Improper neutralization of special elements used in an SQL command ('S ...)
TODO: check
CVE-2026-22049 (ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentica ...)
- TODO: check
+ NOT-FOR-US: NetApp
CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId creation, allo ...)
TODO: check
CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth authori ...)
@@ -141,39 +141,39 @@ CVE-2026-16232 (An authentication bypass vulnerability in the Check Point SmartC
CVE-2026-16157 (Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY pe ...)
TODO: check
CVE-2026-15787 (The Ultimate Addons for Elementor plugin for WordPress is vulnerable t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14985 (The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains ...)
TODO: check
CVE-2026-14932 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, the obso ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-14865 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, the inte ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-14551 (The servereye client (also known as sensorhub, technically ClientAgent ...)
TODO: check
CVE-2026-13192 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, insuffic ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13190 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, a deseri ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13189 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, insuffic ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13188 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, DialogHa ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13187 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, DialogHa ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13186 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, a path t ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13185 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, applicat ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13184 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, when Tel ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13183 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, RadAsync ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13182 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, RadAsync ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-13181 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, forged u ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2025-13146 (The The Contact Form 7 \u2013 Dynamic Text Extension plugin for WordPr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-64600 [xfs: resample the data fork mapping after cycling ILOCK]
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e5f753688e115792087e41e198646cf2b21b4f7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e5f753688e115792087e41e198646cf2b21b4f7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/4c65b83a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list