[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Mar 11 08:13:59 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
08f945ea by security tracker role at 2026-03-11T08:13:50+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-3911 (A flaw was found in Keycloak. An authenticated user with the view-user ...)
 	TODO: check
 CVE-2026-3903 (The Modular DS: Monitor, update, and backup multiple websites plugin f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-3884 (Versions of the package spin.js before 3.0.0 are vulnerable to Cross-s ...)
 	TODO: check
 CVE-2026-3826 (IFTOP developed by WellChoose has a Local File Inclusion vulnerability ...)
@@ -11,11 +11,11 @@ CVE-2026-3825 (IFTOP developed by WellChoose has a Reflected Cross-site Scriptin
 CVE-2026-3824 (IFTOP developed by WellChoose has an Open redirect vulnerability, allo ...)
 	TODO: check
 CVE-2026-3534 (The Astra theme for WordPress is vulnerable to Stored Cross-Site Scrip ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-3453 (The ProfilePress plugin for WordPress is vulnerable to Insecure Direct ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-3222 (The WP Maps plugin for WordPress is vulnerable to time-based blind SQL ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-31844 (An authenticated SQL Injection vulnerability (CWE-89) exists in the Ko ...)
 	TODO: check
 CVE-2026-31838 (Istio is an open platform to connect, manage, and secure microservices ...)
@@ -23,11 +23,11 @@ CVE-2026-31838 (Istio is an open platform to connect, manage, and secure microse
 CVE-2026-31837 (Istio is an open platform to connect, manage, and secure microservices ...)
 	TODO: check
 CVE-2026-31834 (Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A  ...)
-	TODO: check
+	NOT-FOR-US: Umbraco CMS
 CVE-2026-31833 (Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An ...)
-	TODO: check
+	NOT-FOR-US: Umbraco CMS
 CVE-2026-31832 (Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A  ...)
-	TODO: check
+	NOT-FOR-US: Umbraco CMS
 CVE-2026-31830 (sigstore-ruby is a pure Ruby implementation of the sigstore verify com ...)
 	TODO: check
 CVE-2026-31829 (Flowise is a drag & drop user interface to build a customized large la ...)
@@ -97,25 +97,25 @@ CVE-2026-30946 (Parse Server is an open source backend that can be deployed to a
 CVE-2026-30837 (Elysia is a Typescript framework for request validation, type inferenc ...)
 	TODO: check
 CVE-2026-2918 (The Happy Addons for Elementor plugin for WordPress is vulnerable to I ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2917 (The Happy Addons for Elementor plugin for WordPress is vulnerable to I ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2707 (The weForms plugin for WordPress is vulnerable to Stored Cross-Site Sc ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2631 (The Datalogics Ecommerce Delivery  WordPress plugin before 2.6.60 expo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2626 (The divi-booster WordPress plugin before 5.0.2 does not have authoriza ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2569 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed, PDF vie ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2466 (The DukaPress WordPress plugin through 3.2.4 does not sanitise and esc ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2413 (The Ally \u2013 Web Accessibility & Usability plugin for WordPress is  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2358 (The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2324 (The LatePoint \u2013 Calendar Booking Plugin for Appointments and Even ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-29793 (Feathersjs is a framework for creating web APIs and real-time applicat ...)
 	TODO: check
 CVE-2026-29792 (Feathersjs is a framework for creating web APIs and real-time applicat ...)
@@ -129,209 +129,209 @@ CVE-2026-28806 (Improper Authorization vulnerability in nerves-hub nerves_hub_we
 CVE-2026-27842 (Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which ...)
 	TODO: check
 CVE-2026-27278 (Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and e ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27272 (Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-o ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27271 (Illustrator versions 29.8.4, 30.1 and earlier are affected by a Heap-b ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27270 (Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-o ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27268 (Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-o ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27267 (Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack- ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27266 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27265 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27264 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27263 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27262 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27261 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27260 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27259 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27257 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27256 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27255 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27254 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27253 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27252 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27251 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27250 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27249 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27248 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27247 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27244 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27242 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27241 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27240 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27239 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27237 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27236 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27235 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27234 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27233 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27232 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27231 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27230 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27229 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27228 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27226 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27225 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27224 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27223 (Adobe Experience Manager versions 6.5.23 and earlier are affected by a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27221 (Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and e ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-27220 (Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and e ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-24448 (Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L ...)
 	TODO: check
 CVE-2026-23817 (A vulnerability in the web-based management interface of AOS-CX Switch ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-23816 (A vulnerability in the command line interface of AOS-CX Switches could ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-23815 (A vulnerability in a custom binary used in AOS-CX Switches' CLI could  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-23814 (A vulnerability in the command parameters of a certain AOS-CX CLI comm ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-23813 (A vulnerability has been identified in the web-based management interf ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-21362 (Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-o ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21361 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21360 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21359 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21333 (Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untru ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21311 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21310 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21309 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21297 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21296 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21295 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21294 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21293 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21292 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21291 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21290 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21289 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21286 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21285 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21284 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-21282 (Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2 ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-20892 (Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, whic ...)
 	TODO: check
 CVE-2026-1867 (The Guest posting / Frontend Posting / Front Editor  WordPress plugin  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-1781 (The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-1753 (The Gutena Forms  WordPress plugin before 1.6.1 does not validate opti ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-1708 (The Appointment Booking Calendar \u2014 Simply Schedule Appointments B ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-0124 (There is a possible out of bounds write due to a missing bounds check. ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0123 (In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a po ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0122 (In multiple places, there is a possible out of bounds write due to mem ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0121 (In VPU, there is a possible use-after-free read due to a race conditio ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0120 (In modem, there is a possible out of bounds write due to an incorrect  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0119 (In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible o ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0118 (In oobconfig, there is a possible bypass of carrier restrictions due t ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0117 (In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0116 (In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible ou ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0115 (In Trusted Execution Environment, there is a possible key leak due to  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0114 (In Modem, there is a possible out of bounds write due to an incorrect  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0113 (In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of b ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0112 (In vpu_open_inst of vpu_ioctl.c, there is a possible use after free du ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0111 (In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of b ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0110 (In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP du ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0109 (In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Ser ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0108 (The register protection of the PowerVR GPU is incorrectly configured.  ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2026-0107 (In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible esc ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2025-70802 (Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contai ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2025-70798 (Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2025-70244 (Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the we ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2025-70242 (Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the we ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2025-66413 (Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is  ...)
 	TODO: check
 CVE-2025-36920 (In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible o ...)
-	TODO: check
+	NOT-FOR-US: Google devices
 CVE-2025-22850 (Time-of-check time-of-use race condition in the UEFI PdaSmm module for ...)
 	TODO: check
 CVE-2025-22444 (Exposure of resource to wrong sphere in the UEFI PdaSmm module for som ...)
@@ -353,19 +353,19 @@ CVE-2025-20027 (Improper input validation in the UEFI WheaERST module for some I
 CVE-2025-20005 (Improper buffer restrictions in some UEFI firmware for some Intel(R) r ...)
 	TODO: check
 CVE-2025-13219 (IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive informati ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-13213 (IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP head ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-13067 (The Royal Addons for Elementor plugin for WordPress is vulnerable to a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-12473 (The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-14026 (A command injection vulnerability has been reported to affect several  ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2024-14025 (An SQL injection vulnerability has been reported to affect Video Stati ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2024-14024 (An improper certificate validation vulnerability has been reported to  ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2026-3805
 	- curl <unfixed>
 	[trixie] - curl <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/08f945ea48155a0c839c8d0c3bd203c24b8e07c0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/08f945ea48155a0c839c8d0c3bd203c24b8e07c0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260311/d2739404/attachment.htm>


More information about the debian-security-tracker-commits mailing list