[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jul 27 20:19:59 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d165318a by security tracker role at 2026-07-27T19:19:53+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11,31 +11,31 @@ CVE-2026-66730 (facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulner
CVE-2026-66729 (facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerabili ...)
TODO: check
CVE-2026-66477 (Unauthenticated Broken Access Control in Gillion <= 4.13 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66476 (Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66475 (Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66474 (Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers an ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66448 (Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66445 (Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66442 (Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66438 (Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66437 (Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66434 (Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66433 (Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66428 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66427 (Administrator SQL Injection in WP Google Review Slider <= 18.4 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66399 (phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in ...)
TODO: check
CVE-2026-66398 (phpMyFAQ before v4.1.6 contains a remote code execution vulnerability ...)
@@ -49,9 +49,9 @@ CVE-2026-66395 (SiYuan desktop before v3.7.2 contains a reflected cross-site scr
CVE-2026-66394 (SiYuan before v3.7.3 contains stored and reflected cross-site scriptin ...)
TODO: check
CVE-2026-66391 (Use of Insufficiently Random Values, Protection Mechanism Failure vuln ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66390 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66053 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
TODO: check
CVE-2026-66050 (NitroShare Desktop through 0.3.4 contains a path traversal vulnerabili ...)
@@ -69,121 +69,121 @@ CVE-2026-65894 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to imp
CVE-2026-65893 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecu ...)
TODO: check
CVE-2026-65879 (Joomla Extension - joomshaper.com - Unauthenticated mail relay via a h ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65878 (Joomla Extension - joomshaper.com - Authenticated arbitrary file delet ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65877 (Joomla Extension - joomshaper.com - Authenticated SQL injection in SP ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65876 (Joomla Extension - joomshaper.com - Unauthenticated SQL injection in ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65766 (Joomla Extension - joomshaper.com - Unauthenticated SQL injection in ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65765 (Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Co ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65764 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Com ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65568 (Contributor Broken Access Control in Visual Composer Website Builder < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65567 (Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65564 (Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65563 (Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65562 (Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65561 (Contributor Cross Site Scripting (XSS) in WordPress Social Login and R ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65558 (Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65557 (Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for Woo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65436 (Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65435 (Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65434 (Subscriber Sensitive Data Exposure in \u042eKassa \u0434\u043b\u044f W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65433 (Subscriber Broken Access Control in RT Mega Menu \u2013 Mega Menu Buil ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-64647 (Next.js is a React framework for building full-stack web applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64646 (Next.js is a React framework for building full-stack web applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64645 (Next.js is a React framework for building full-stack web applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64644 (Next.js is a React framework for building full-stack web applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64643 (Next.js is a React framework for building full-stack web applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64642 (Next.js is a React framework for building full-stack web applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-64641 (Next.js is a React framework for building full-stack web applications. ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-63077 (In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remot ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-61511 (vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval inj ...)
- TODO: check
+ NOT-FOR-US: vBulletin
CVE-2026-59690 (A Missing Authorization vulnerability in Progress Software LoadMaster, ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59689 (An Incorrect Authorization vulnerability in Progress Software LoadMast ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59688 (An OS Command Injection vulnerability in Progress Software LoadMaster, ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59687 (An OS Command Injection vulnerability in Progress Software LoadMaster, ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59686 (An OS Command Injection vulnerability in Progress Software LoadMaster, ...)
- TODO: check
+ NOT-FOR-US: Progress Software
CVE-2026-59560 (Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59559 (Subscriber Cross Site Scripting (XSS) in RT Mega Menu \u2013 Mega Menu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59558 (Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59557 (Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59556 (Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Dis ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59553 (Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59552 (Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59551 (Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59550 (Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59549 (Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59548 (Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hote ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59546 (Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59539 (Subscriber Insecure Direct Object References (IDOR) in Paid Member Sub ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59538 (Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59537 (Administrator SQL Injection in Sender \u2013 Newsletter, SMS and Email ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59536 (Unauthenticated Broken Access Control in CoCart \u2013 Headless ecomme ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59535 (Unauthenticated Broken Access Control in Thrive Product Manager <= 10. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59534 (Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59533 (Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59532 (Unauthenticated Other Vulnerability Type in Booking and Rental Manager ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59531 (Unauthenticated Unknown in Falcon \u2013 WordPress Optimizations & Twe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59530 (Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59529 (Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59528 (Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Ra ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59527 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP public_key certif ...)
TODO: check
CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver ...)
@@ -203,9 +203,9 @@ CVE-2026-57917 (proCertum SmartSignparses external XML entities from arbitrary c
CVE-2026-57916 (proCertum SmartSign opens Certificate Practice Statement (CPS) URI wit ...)
TODO: check
CVE-2026-56538 (An endpoint in HCL Connections is vulnerable to information disclosure ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56537 (HCL Connections is vulnerable to information disclosure which could al ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-55971 (Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings ...)
TODO: check
CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings. This is ...)
@@ -273,11 +273,11 @@ CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erl
CVE-2026-41608 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
TODO: check
CVE-2026-40000 (The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity wit ...)
- TODO: check
+ NOT-FOR-US: ZTE
CVE-2026-24252 (NVIDIA NeMo for Linux contains a vulnerability where an attacker may c ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-17612 (Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to a ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability. Processing a c ...)
TODO: check
CVE-2026-17573 (A double free vulnerability was discovered in the HDF5 library. Proces ...)
@@ -285,11 +285,11 @@ CVE-2026-17573 (A double free vulnerability was discovered in the HDF5 library.
CVE-2026-17572 (Heap-based buffer overflow in the SOHM list-index deserialization code ...)
TODO: check
CVE-2026-17570 (Improper access control in the PAM password history endpoints in Devol ...)
- TODO: check
+ NOT-FOR-US: Devolutions
CVE-2026-17569 (Improper access control in the NetBox synchronizer in Devolutions Serv ...)
- TODO: check
+ NOT-FOR-US: Devolutions
CVE-2026-17568 (Improper access control in the role membership management endpoint in ...)
- TODO: check
+ NOT-FOR-US: Devolutions
CVE-2026-17552 (Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an a ...)
TODO: check
CVE-2026-17534 (Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL S ...)
@@ -311,11 +311,11 @@ CVE-2026-17513 (A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affe
CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This ...)
TODO: check
CVE-2026-17192 (A VCO feature does not sufficiently validate caller-supplied input, al ...)
- TODO: check
+ NOT-FOR-US: Arista Networks
CVE-2026-17191 (An input validation vulnerability exists in an API component of the or ...)
- TODO: check
+ NOT-FOR-US: Arista Networks
CVE-2026-16812 (VeloCloud Orchestrator (VCO) on-prem has a security issue where this i ...)
- TODO: check
+ NOT-FOR-US: Arista Networks
CVE-2026-16554 (cJSON library is vulnerable to an integer overflow in the print_string ...)
TODO: check
CVE-2026-16481 (A Server-Side Request Forgery (SSRF) and credential exfiltration vulne ...)
@@ -341,21 +341,21 @@ CVE-2026-12383 (A flaw was found in the Event-Driven Ansible (EDA) server. The E
CVE-2026-10819 (Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 1 ...)
TODO: check
CVE-2026-10683 (In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-10682 (The userspace verifier z_vrfy_log_filter_set() for the log_filter_set ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-10600 (Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6 ...)
TODO: check
CVE-2025-59181 (Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-59180 (Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-59178 (Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-59177 (Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-59172 (Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter of the /c ...)
TODO: check
CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
@@ -53021,9 +53021,9 @@ CVE-2026-9157 (Improper input validation, Unrestricted upload of file with dange
CVE-2026-9089 (The ConnectWise Automate\u2122 Agent does not fully verify the authent ...)
NOT-FOR-US: ConnectWise
CVE-2026-5434 (Honeywell Control Network Module (CNM)contains insertion of sensitive ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2026-5433 (Honeywell Control Network Module (CNM)contains command injection vulne ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2026-5118 (The Divi Form Builder plugin for WordPress is vulnerable to privilege ...)
NOT-FOR-US: WordPress plugin
CVE-2026-4858 (Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d165318a4a3af49c97eaf53e73eac3530efe250f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d165318a4a3af49c97eaf53e73eac3530efe250f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/523abd81/attachment.htm>
More information about the debian-security-tracker-commits
mailing list