[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Sep 14 08:14:00 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
852078fa by security tracker role at 2026-09-14T07:13:53+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,9 +3,9 @@ CVE-2026-90691 (A security vulnerability has been detected in 0x4m4 HexStrike AI
CVE-2026-90690 (A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff57 ...)
TODO: check
CVE-2026-90689 (A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_8 ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-90688 (A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-90687 (A vulnerability was determined in GPAC up to f1219cde. This vulnerabil ...)
TODO: check
CVE-2026-90686 (A vulnerability was found in GPAC up to f1219cde. This affects the fun ...)
@@ -21,7 +21,7 @@ CVE-2026-90682 (A security vulnerability has been detected in Matthias-Wandel jh
CVE-2026-90681 (A weakness has been identified in Matthias-Wandel jhead up to 3.3. Thi ...)
TODO: check
CVE-2026-90680 (A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_201812 ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-90623 (A weakness has been identified in andreashappe cochise up to 0.4.1. Af ...)
TODO: check
CVE-2026-90622 (A security flaw has been discovered in GNU libredwg 0.13.4. This impac ...)
@@ -37,7 +37,7 @@ CVE-2026-90618 (A flaw has been found in GH05TCREW PentestAgent up to cf882dabea
CVE-2026-90617 (A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabe ...)
TODO: check
CVE-2026-90615 (A security vulnerability has been detected in SourceCodester Class and ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-90614 (A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected ...)
TODO: check
CVE-2026-90613 (A security flaw has been discovered in GPAC up to f1219cde. Affected b ...)
@@ -51,15 +51,15 @@ CVE-2026-90610 (A vulnerability was found in GPAC up to f1219cde. This affects t
CVE-2026-90609 (A vulnerability has been found in GPAC up to f1219cde. The impacted el ...)
TODO: check
CVE-2026-90608 (A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affec ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90607 (A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Im ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90606 (A security vulnerability has been detected in Totolink A3002MU Hh-B202 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90605 (A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90604 (A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-90603 (A vulnerability was identified in Anil-matcha Open-Generative-AI up to ...)
TODO: check
CVE-2026-90602 (A vulnerability was determined in Anil-matcha Open-Generative-AI up to ...)
@@ -67,13 +67,13 @@ CVE-2026-90602 (A vulnerability was determined in Anil-matcha Open-Generative-AI
CVE-2026-90601 (A vulnerability was found in getzep graphiti up to 0.30.2. Affected is ...)
TODO: check
CVE-2026-90600 (A vulnerability has been found in itsourcecode Sales and Inventory Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-90599 (A flaw has been found in Rizwan17 inventory-management-system up to 5e ...)
TODO: check
CVE-2026-90598 (A vulnerability was detected in jaygajera17 E-commerce-project-springB ...)
TODO: check
CVE-2026-90597 (A security vulnerability has been detected in itsourcecode Sales and I ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-90596 (A weakness has been identified in embedded-graphics up to 0.8.2 on 32- ...)
TODO: check
CVE-2026-90595 (A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1 ...)
@@ -91,33 +91,33 @@ CVE-2026-90582 (A vulnerability was identified in evanchiu serverless-todo 1.0.3
CVE-2026-90581 (A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This ...)
TODO: check
CVE-2026-90580 (A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulne ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-89050 (The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88853 (Joomla Extension - regularlabs.com - Privileged stored XSS via event h ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-88852 (Joomla Extension - regularlabs.com - Privileged stored XSS via url opt ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-88802 (The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88793 (The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85196 (Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywher ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85195 (Joomla Extension - regularlabs.com - Privileged stored XSS via link op ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85192 (Joomla Extension - regularlabs.com - Authenticated, privileged remote ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85191 (Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-al ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85190 (Joomla Extension - regularlabs.com - Privileged stored XSS via class o ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85189 (Joomla Extension - regularlabs.com - Privileged stored XSS via executa ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85188 (Joomla Extension - regularlabs.com - Database data disclosure in Advan ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85129 (The Hoo Companion WordPress plugin 1.0.2 does not have any authorisati ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85125 (The Android application "YAMAP -Social Trekking GPS App" contains an i ...)
TODO: check
CVE-2026-82796 (SolarView Compact contains a cross-site scripting vulnerability in Ima ...)
@@ -191,9 +191,9 @@ CVE-2026-82763 (Cross-site scripting vulnerability exists in Contec FX5000 serie
CVE-2026-82762 (Improper neutralization of special elements used in an OS command ('OS ...)
TODO: check
CVE-2026-81648 (The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74933 (The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have au ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-68955 (The installer for Rakuten Kobo Desktop Application (Windows version) i ...)
TODO: check
CVE-2026-52297 (FFmpeg before 9.0 has an out-of-bounds read because there is insuffici ...)
@@ -259,11 +259,11 @@ CVE-2026-23787 (An issue was discovered in DPU in Samsung Mobile Processor Exyno
CVE-2026-23786 (An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280 ...)
TODO: check
CVE-2026-16726 (Buffer overflow vulnerabilityin Panasonic IndustryUSB Driver for MINAS ...)
- TODO: check
+ NOT-FOR-US: Panasonic
CVE-2026-15892 (The mcumgr SMP settings-management group handlers settings_mgmt_read() ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-15891 (The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/ ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-70820 (Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach ...)
TODO: check
CVE-2025-68624 (N-able Mail Assure through April 2026 contains a design-level authoriz ...)
@@ -295,7 +295,7 @@ CVE-2023-45858 (A directory traversal was identified in Paessler PRTG before 23.
CVE-2023-45023 (The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access ...)
TODO: check
CVE-2023-40772 (A directory Traversal vulnerability in DataEase before 1.18.10 allows ...)
- TODO: check
+ NOT-FOR-US: DataEase
CVE-2023-37366 (An issue was discovered in Samsung Exynos Mobile Processor, Automotive ...)
TODO: check
CVE-2023-32803 (The ca-certificates package before ca-certificates-2021.2.50-72 for Am ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/852078faae660b2db7938b2ff9b495bcc86d3386
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/852078faae660b2db7938b2ff9b495bcc86d3386
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/717052ca/attachment.htm>
More information about the debian-security-tracker-commits
mailing list