[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 08:13:37 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3ea7f2a5 by security tracker role at 2026-09-04T07:13:30+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
 CVE-2026-9745 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9744 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validat ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9736 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an u ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9036 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validat ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-8862 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-85509 (FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_ ...)
 	TODO: check
 CVE-2026-85508 (ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow i ...)
@@ -99,19 +99,19 @@ CVE-2026-85406 (A vulnerability has been found in Eleveo Quality Management 9.7.
 CVE-2026-85405 (A flaw has been found in Eleveo Call Recording Software 9.7.0. This af ...)
 	TODO: check
 CVE-2026-85403 (A flaw has been found in code-projects Doctor Appointment System 1.0.  ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-85402 (A vulnerability was detected in code-projects Doctor Appointment Syste ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-85401 (A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. ...)
-	TODO: check
+	NOT-FOR-US: Dolibarr
 CVE-2026-85399 (A security flaw has been discovered in code-projects Hospital Informat ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-85398 (A vulnerability was identified in code-projects Hospital Information S ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-85397 (A vulnerability was determined in code-projects Hospital Information S ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-85383 (A flaw has been found in itsourcecode Sales and Inventory System 1.0.  ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-85382 (A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5 ...)
 	TODO: check
 CVE-2026-85381 (A security vulnerability has been detected in light0011 cms c774dce31c ...)
@@ -125,17 +125,17 @@ CVE-2026-85378 (A vulnerability was identified in light0011 cms c774dce31c6df005
 CVE-2026-85241 (A weakness has been identified in SpecterOps BloodHound up to 9.5.1. T ...)
 	TODO: check
 CVE-2026-85225 (A vulnerability was identified in code-projects Doctor Appointment Sys ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-85224 (A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01.  ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-85223 (A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-85222 (A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-85208 (A security flaw has been discovered in itsourcecode Online Medicine De ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-85207 (A vulnerability was identified in itsourcecode Online Medicine Deliver ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-85149 (SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded ...)
 	TODO: check
 CVE-2026-85148 (SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded ...)
@@ -181,11 +181,11 @@ CVE-2026-85042 (Use after free in DevTools in Google Chrome prior to 152.0.7977.
 CVE-2026-84185 (A flaw was found in the jwcrypto library, which is used for implementi ...)
 	TODO: check
 CVE-2026-84146 (The Xpro Addons \u2014 140+ Widgets for Elementor WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84066 (The Directorist: AI-Powered Business Directory, Listings & Classified  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-83711 (Authorization bypass through user-controlled key in Microsoft Azure Ac ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-82527 (R2R through 3.6.6 contains a SQL injection vulnerability that allows u ...)
 	TODO: check
 CVE-2026-82521 (parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files usi ...)
@@ -193,47 +193,47 @@ CVE-2026-82521 (parsedmarc 9.0.6 before 11.0.1 writes forensic report sample fil
 CVE-2026-82520 (parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a si ...)
 	TODO: check
 CVE-2026-82194 (The WPvivid \u2014 Backup, Migration & Staging WordPress plugin before ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82193 (The WPvivid \u2014 Backup, Migration & Staging WordPress plugin before ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82186 (The WPLP Cookie Consent  WordPress plugin before 4.4.2 does not proper ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81347 (The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81270 (Apache Allura: exposure of non-public information via search.    This  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-80438 (The Ninja Forms  WordPress plugin before 3.15.2 does not restrict its  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-80181 (Apache Allura'swebhooksare vulnerable to Server-Side Request Forgery ( ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-80180 (Stored XSS via markdown HTML processingin Apache Allura.    This issue ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-80098 (Improper verification of cryptographic signature in Copilot Studio all ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-79632 (The WPFunnels  WordPress plugin before 3.13.0 does not perform any aut ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-79631 (The WPFunnels  WordPress plugin before 3.13.0 does not restrict access ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-79630 (The WPFunnels  WordPress plugin before 3.13.0 does not verify that the ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77465 (toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0 ...)
 	TODO: check
 CVE-2026-75754 (Missing Authentication for Critical Function, Server-Side Request Forg ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-74853 (The Pods  WordPress plugin before 3.3.9.2 does not restrict which func ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-71429 (stream-json is a micro-library of stream components for processing JSO ...)
 	TODO: check
 CVE-2026-71216 (PagerDuty alarm hook transmits the integration routing key over cleart ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-70403 (XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Any ...)
 	TODO: check
 CVE-2026-70352 (Missing authentication for critical function in Azure AI Language allo ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-70178 (Missing authorization in Microsoft Fabric allows an authorized attacke ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69857 (Authorization bypass through user-controlled key in Azure Cosmos DB al ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69657 (XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyon ...)
 	TODO: check
 CVE-2026-67402 (An insecure Apache configuration in ConfigServer Security & Firewall m ...)
@@ -245,55 +245,55 @@ CVE-2026-67397 (Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 throug
 CVE-2026-66840 (XING CPTrans-ME-X contains an Exposure of Sensitive System Information ...)
 	TODO: check
 CVE-2026-65818 (Server-side request forgery (ssrf) in Power Automate allows an authori ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-64200 (There is an out-of-bounds read vulnerability in DASYLab due to imprope ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-64199 (There is an out-of-bounds read vulnerability in DASYLab due to imprope ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-64198 (There is an out-of-bounds read vulnerability in DASYLab due to imprope ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-64197 (There is an out-of-bounds write vulnerability in DASYLabdue to imprope ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-64196 (There is an out-of-bounds write vulnerability in DASYLabdue to imprope ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-64195 (There is an out-of-bounds write vulnerability in DASYLab due to lack o ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-63376 (toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2 ...)
 	TODO: check
 CVE-2026-62928 (XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthent ...)
 	TODO: check
 CVE-2026-62916 (Authentication bypass using an alternate path or channel in Microsoft  ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-62906 (Improper neutralization of special elements in data query logic in Mic ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-53728 (Medplum is a developer platform that enables development of healthcare ...)
 	TODO: check
 CVE-2026-49509 (Out-of-bounds read vulnerability in Samsung Opensource Escargot allows ...)
 	TODO: check
 CVE-2026-45200 (Software installed and run as a non-privileged user may conduct improp ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-45197 (Kernel software installed and running inside a Guest VM may post impro ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-44506 (Medplum is a developer platform that enables development of healthcare ...)
 	TODO: check
 CVE-2026-19795 (IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cau ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19224 (The Hummingbird Performance  WordPress plugin before 3.21.2 does not r ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18330 (A hard-coded cryptographic key vulnerability exists in theweb module o ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-18167 (A stack-based buffer overflow vulnerability exists in the EasyMesh mod ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-17517 (The Content Views  WordPress plugin before 4.5.1.2 does not check whet ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16281 (The Classified Listing  WordPress plugin before 6.1.1 does not verify  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15354 (The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Esc ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11613 (The Divi Ajax Filter plugin for WordPress is vulnerable to Local File  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-15691 (The WPFunnels  WordPress plugin before 3.13.0 does not check whether u ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-XXXX [RUSTSEC-2026-0269]
 	- rust-wasmtime <unfixed>
 	NOTE: https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-vqjp-4c8c-hfgg



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ea7f2a5629f8cf08e05b9e28e66df398bd0b735

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ea7f2a5629f8cf08e05b9e28e66df398bd0b735
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/b44f7066/attachment.htm>


More information about the debian-security-tracker-commits mailing list