[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 5 08:13:33 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
208a2809 by security tracker role at 2026-09-05T07:13:27+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,15 +1,15 @@
CVE-2026-9317 (Nango before 0.71.6 contains a missing authentication vulnerability in ...)
TODO: check
CVE-2026-9186 (IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-9138 (IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenti ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-8625 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed, PDF vie ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8623 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed, PDF vie ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8447 (IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-86145 (PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write becaus ...)
TODO: check
CVE-2026-86144 (In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXInclu ...)
@@ -43,11 +43,11 @@ CVE-2026-86091 (ntopng before 6.7.260717 fails to check user privileges in the p
CVE-2026-86090 (ntopng before 6.7.260717 fails to perform authorization checks in the ...)
TODO: check
CVE-2026-85787 (An incomplete list of disallowed inputs in the SQL validation componen ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85786 (Improper handling of highly compressed data in Amazon ion-java before ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85781 (Unverified ownership of a storage access point in the volume deletion ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85769 (A flaw was found in libtpms, a library that provides software TPM 2.0 ...)
TODO: check
CVE-2026-85730 (smol-toml is a small, fast, and correct TOML parser and serializer. Pr ...)
@@ -129,9 +129,9 @@ CVE-2026-85661 (excel-mcp-server 0.1.8 fails to enforce path confinement in stdi
CVE-2026-85660 (cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability ...)
TODO: check
CVE-2026-85656 (An OS command injection issue in the log4j-cve-2021-44228-hotpatch pac ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85654 (Improper neutralization of special elements used in a template engine ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85651 (Trigger.dev versions before 4.5.2 fail to validate environment members ...)
TODO: check
CVE-2026-85650 (Trigger.dev before 4.5.2 contains a server-side request forgery vulner ...)
@@ -139,7 +139,7 @@ CVE-2026-85650 (Trigger.dev before 4.5.2 contains a server-side request forgery
CVE-2026-85649 ((Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fa ...)
TODO: check
CVE-2026-85643 (A flaw has been found in code-projects Online Shopping System 1.0. Imp ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-85639 (A security vulnerability has been detected in jofpin trape 2.0. This v ...)
TODO: check
CVE-2026-85638 (A weakness has been identified in jofpin trape 2.0. This affects an un ...)
@@ -231,21 +231,21 @@ CVE-2026-85587 (phpMyFAQ before 4.1.8 enforces incorrect permission checks on ad
CVE-2026-85586 (phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store ...)
TODO: check
CVE-2026-85585 (SiYuan before v3.8.2 contains an unbounded resource consumption vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85584 (SiYuan versions before v3.8.2 contain a denial of service vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85583 (SiYuan versions before v3.8.2 contain a path traversal vulnerability i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85582 (SiYuan versions before v3.8.2 contain an unbounded session creation vu ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85581 (SiYuan before v3.8.2 contains a denial of service vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85580 (SiYuan versions before v3.8.2 contain a path guard bypass vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85579 (SiYuan is affected by an information disclosure vulnerability (confirm ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85578 (SiYuan through 3.8.1 contains an authorization bypass vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85577 (AVideo through commit c91b5975d contains a reflected cross-site script ...)
TODO: check
CVE-2026-85547 (A cross-site request forgery (CSRF) vulnerability exists in MISP due t ...)
@@ -269,19 +269,19 @@ CVE-2026-85525 (Improper OCSP response validation in the Snowflake Python, Go, J
CVE-2026-85522 (A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Af ...)
TODO: check
CVE-2026-85517 (A flaw has been found in code-projects Vehicle Management System 1.0. ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-85516 (A vulnerability was detected in code-projects Vehicle Management Syste ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-85514 (A security vulnerability has been detected in StackStorm st2 up to 3.9 ...)
TODO: check
CVE-2026-85513 (A weakness has been identified in StackStorm st2 up to 3.9.0. This iss ...)
TODO: check
CVE-2026-85512 (A security flaw has been discovered in SourceCodester Class and Exam T ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-85311 (Missing Authorization vulnerability in Kings Plugins MarketKing allows ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85229 (** UNSUPPORTED WHEN ASSIGNED **Improper neutralization of input during ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ...)
TODO: check
CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to r ...)
@@ -299,35 +299,35 @@ CVE-2026-84961 (undici's BalancedPool constructor passes its entire options obje
CVE-2026-84947 (undici's dump interceptor reads and discards a response body up to a c ...)
TODO: check
CVE-2026-84937 (The Video Player for YouTube WordPress plugin before 2.1.0 does not p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84936 (The EmbedPress WordPress plugin before 4.6.4 does not have proper aut ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84935 (The HT Menu WordPress plugin before 1.2.7 does not perform any capabi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84934 (The JCH Optimize WordPress plugin before 6.0.1 does not perform a capa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84933 (undici's cache interceptor does not handle the Set-Cookie response hea ...)
TODO: check
CVE-2026-84931 (The Joli Table Of Contents WordPress plugin before 3.0.3 does not sani ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84930 (The CatFolders Document Gallery & PDF Library WordPress plugin before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84927 (The EmbedPress WordPress plugin before 4.6.4 does not perform a suffi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84926 (The EmbedPress WordPress plugin before 4.6.4 does not correctly restr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84901 (The Eventin WordPress plugin before 4.1.22 does not properly check au ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84899 (The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84898 (The Eventin WordPress plugin before 4.1.21 does not properly validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84896 (The King Addons for Elementor WordPress plugin before 51.1.77 does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84890 (undici's decompress interceptor decompresses response bodies according ...)
TODO: check
CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not restrict ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84504 (fastify versions before 5.12.2 treat the object resolved by a successf ...)
TODO: check
CVE-2026-84469 (fastify versions before 5.12.2 decide whether to compile a request sch ...)
@@ -335,33 +335,33 @@ CVE-2026-84469 (fastify versions before 5.12.2 decide whether to compile a reque
CVE-2026-84428 (fastify versions before 5.12.2 implement the case-insensitive nature o ...)
TODO: check
CVE-2026-84225 (The Kirki WordPress plugin before 6.3.0 does not check that a user is ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84221 (The Kirki WordPress plugin before 6.3.0 does not escape a user-suppli ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84045 (The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84044 (The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 d ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84043 (The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84022 (The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84021 (The Bold Page Builder WordPress plugin before 5.9.8 does not properly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83628 (The Theme My Login plugin for WordPress is vulnerable to Missing Autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83627 (The Hummingbird \u2013 Speed Optimization, Caching, Minify, Compress & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83544 (The Greenshift WordPress plugin before 13.2.0 does not properly escap ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83543 (The Greenshift WordPress plugin before 13.2.0 does not validate a use ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82923 (The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82911 (Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET ...)
TODO: check
CVE-2026-82846 (The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82729 (Inefficient Algorithmic Complexity vulnerability in elixir-mint mint a ...)
TODO: check
CVE-2026-82728 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
@@ -373,29 +373,29 @@ CVE-2026-82684 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vu
CVE-2026-82538 (ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection v ...)
TODO: check
CVE-2026-82304 (The Music Store WordPress plugin before 1.4.5 does not sanitise and e ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81939 (A Zip Slip vulnerability in the SonicWall Network Security Manager (NS ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-81859 (CP4BA - IBM Enterprise Records could allow a local attacker to obtain ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81832 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81666 (An integer overflow was found in Corosync's handling of membership com ...)
TODO: check
CVE-2026-81665 (A heap-based buffer overflow was found in Corosync's Totem Process Gro ...)
TODO: check
CVE-2026-81424 (The Accept Stripe Payments WordPress plugin before 2.1.4 does not veri ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81423 (The Accept Stripe Payments WordPress plugin before 2.1.4 does not vali ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81404 (The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81348 (The My Private Site WordPress plugin before 4.2.3 does not apply its ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81302 (PALLET CONTROL products contain an incorrect default permission vulner ...)
TODO: check
CVE-2026-80190 (Apache Allura: stored XSS via SVN code repositories. Git repositories ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-80119 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
TODO: check
CVE-2026-80118 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
@@ -437,37 +437,37 @@ CVE-2026-78839 (An arbitrary file upload vulnerability in AppNitro MachForm v30
CVE-2026-78745 (An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allow ...)
TODO: check
CVE-2026-78658 (IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7 ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-78543 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-78438 (The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross- ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78362 (The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not corr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78328 (A missing authorization vulnerability in the SonicWall Network Securit ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-78327 (An Improper Neutralization of Special Elements used in an OS Command ( ...)
- TODO: check
+ NOT-FOR-US: SonicWall
CVE-2026-78150 (The Smart Post WordPress plugin before 4.0.8 does not check the type, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78149 (The Smart Post WordPress plugin before 4.0.8 does not check whether a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77847 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerab ...)
TODO: check
CVE-2026-77830 (The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordP ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77826 (The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77822 (IBM ContextForge MCP Gateway could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-77818 (Improper neutralization of input during web page generation ('cross-si ...)
TODO: check
CVE-2026-77393 (In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" s ...)
TODO: check
CVE-2026-77263 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + m ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77233 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + m ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76925 (A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) r ...)
TODO: check
CVE-2026-76169 (fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL ...)
@@ -475,7 +475,7 @@ CVE-2026-76169 (fastify versions >= 4.0.0 and before 5.12.2 can route a malforme
CVE-2026-75925 (Improper neutralization of CRLF sequences in IXON VPN Client before ve ...)
TODO: check
CVE-2026-75439 (An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial ...)
- TODO: check
+ NOT-FOR-US: Free5GC
CVE-2026-75438 (Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attack ...)
TODO: check
CVE-2026-75431 (PowerJob Server version 5.1.2 (and likely earlier) uses a predictable ...)
@@ -515,7 +515,7 @@ CVE-2026-74236 (GFI Exinda AI and ClearView before 7.6.5 contains a path travers
CVE-2026-74235 (GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vul ...)
TODO: check
CVE-2026-73848 (Emlog is an open source website building system. In versions 2.6.29 an ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-71626 (An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain ...)
TODO: check
CVE-2026-71625 (An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to e ...)
@@ -543,9 +543,9 @@ CVE-2026-61614 (SolidInvoice is an open-source invoicing platform. Prior to vers
CVE-2026-61608 (SolidInvoice is an open-source invoicing platform. Prior to version 3. ...)
TODO: check
CVE-2026-5522 (IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-code ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-57777 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57166 (PJSIP is a free and open source multimedia communication library writt ...)
TODO: check
CVE-2026-57165 (PJSIP is a free and open source multimedia communication library writt ...)
@@ -575,11 +575,11 @@ CVE-2026-53761 (Frappe CRM is an open-source customer relationship management to
CVE-2026-53760 (Admidio is an open-source user management solution. In versions 5.0.11 ...)
TODO: check
CVE-2026-53758 (Emlog is an open source website building system. In versions 2.6.29 an ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-53757 (Emlog is an open source website building system. In versions 2.6.29 an ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-53756 (Emlog is an open source website building system. Prior to version 2.6. ...)
- TODO: check
+ NOT-FOR-US: Emlog
CVE-2026-53604 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. ...)
TODO: check
CVE-2026-53603 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. ...)
@@ -619,61 +619,61 @@ CVE-2026-50553 (Note Mark is an open-source note-taking application. Prior to ve
CVE-2026-4644 (A Missing Authorization vulnerability in HTTP Connector in Google Clou ...)
TODO: check
CVE-2026-4361 (The Divi theme for WordPress is vulnerable to Server-Side Request Forg ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-44402 (Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote co ...)
TODO: check
CVE-2026-3853 (The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-38961 (Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate ...)
TODO: check
CVE-2026-32480 (Missing Authorization vulnerability in WC Lovers WCFM Membership allow ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-31020 (In DocsGPT 0.15.0 and below, the application provides a custom prompt ...)
TODO: check
CVE-2026-27432 (Authorization Bypass Through User-Controlled Key vulnerability in sc I ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27347 (Missing Authorization vulnerability in Crocoblock JetPopup allows Expl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27086 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-19887 (The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Objec ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19861 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder WordPress plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19858 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder WordPress plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19769 (The Ninja Forms \u2013 The Contact Form Builder That Grows With You pl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19727 (Improper neutralization of input during web page generation ('cross-si ...)
TODO: check
CVE-2026-19649 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19534 (undici's WebSocket client crashes the whole Node.js process during the ...)
TODO: check
CVE-2026-19306 (IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19305 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19304 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19303 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19302 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19301 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19300 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19299 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19298 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19283 (IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 I ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19274 (IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 I ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-19205 (Observable response discrepancy vulnerability in GastroMenum GastroMen ...)
TODO: check
CVE-2026-19081 (Missing Authorization vulnerability in Gastromenum Gastromenum Ticket ...)
@@ -689,129 +689,129 @@ CVE-2026-19043 (Missing Authorization vulnerability in Menulux Software Inc. Men
CVE-2026-18957 (Improper neutralization of input during web page generation ('cross-si ...)
TODO: check
CVE-2026-18905 (IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MC ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18887 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18858 (IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtai ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18843 (The Beaver Builder Plugin (Starter Version) plugin for WordPress is vu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18745
REJECTED
CVE-2026-18658 (IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18567 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18540 (undici's retry interceptor can append the body of a ranged retry respo ...)
TODO: check
CVE-2026-18489 (IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18486 (IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18406 (The SureForms \u2013 Contact Form Builder, AI Forms, Payment Form, Sur ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18404 (The Social Chat \u2013 Click To Chat App Button plugin for WordPress i ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18341 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18221 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain una ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18198 (Improper neutralization of special elements used in an SQL command ('S ...)
TODO: check
CVE-2026-18175 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipula ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18149 (undici's retry handler can leave an already-exposed response body pend ...)
TODO: check
CVE-2026-18078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18076 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18073 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17631 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17627 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17622 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticat ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17621 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17499 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17483 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attac ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17470 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17469 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacke ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17444 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17443 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17442 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17440 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17274 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17273 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17270 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a d ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17259 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17255 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17207 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17057 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16941 (IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16892 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16826 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16693 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16689 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16660 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker t ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16649 (The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16180 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-15984 (The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15937 (Improper certificate validation in Checkmk <2.5.0p10 allows a relay an ...)
TODO: check
CVE-2026-15247 (The Search Atlas SEO WordPress plugin before 2.6.24 does not perform ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14975 (The WP File Download plugin for WordPress is vulnerable to Directory T ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14470 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-14466 (It\u2019s possible to run a stored XSS in Stormshield\u2019s web admin ...)
TODO: check
CVE-2026-14350 (IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13447 (The Mstore Api plugin for WordPress is vulnerable to Authentication By ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13297 (IBM Verify Identity Access Advanced Access Control may be vulnerable t ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-13148 (Missing release of memory after effective lifetime vulnerability in So ...)
- TODO: check
+ NOT-FOR-US: Softing
CVE-2026-12483 (The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted F ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-67066 (SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote ...)
TODO: check
CVE-2025-15694 (The Joli Table Of Contents WordPress plugin before 2.8.1 does not sani ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-15693 (The JCH Optimize WordPress plugin before 5.0.1 does not properly restr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-14945 (The Events Manager - Calendar, Bookings, Tickets, and more! plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82309 (Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbo ...)
NOT-FOR-US: Robots::Validate Perl module
CVE-2026-80911 (In the Linux kernel, the following vulnerability has been resolved: A ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/208a280977dd46352d779df6b0c25da3b6dc2f4b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/208a280977dd46352d779df6b0c25da3b6dc2f4b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/e38ee06a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list