[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 18 20:15:04 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4b132d10 by security tracker role at 2026-09-18T19:14:57+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -91,7 +91,7 @@ CVE-2026-93593 (ArcadeDB before 26.9.1 fails to enforce security-group types ACL
CVE-2026-93592 (vLLM versions before 0.28.0 fail to validate the lower bound of token ...)
TODO: check
CVE-2026-93591 (SiYuan versions before 3.8.3 contain an SQL injection vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-93590 (ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in ...)
TODO: check
CVE-2026-93589 (ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero ...)
@@ -177,11 +177,11 @@ CVE-2026-92702 (Cocos AI is a confidential computing system for running AI workl
CVE-2026-92701 (trusted execution environments. In versions up to and including 0.8.2, ...)
TODO: check
CVE-2026-92622 (The Strong Testimonials plugin for WordPress is vulnerable to Stored C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92554 (The ShopLentor \u2013 All-in-One WooCommerce Growth & Store Enhancemen ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92249 (The Qi Addons For Elementor plugin for WordPress is vulnerable to Refl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91149 (A flaw was found in Cockpit. An unauthenticated remote attacker can ex ...)
TODO: check
CVE-2026-91147 (A flaw was found in `cockpit-ws`. This vulnerability allows a remote, ...)
@@ -191,9 +191,9 @@ CVE-2026-91142 (A flaw was found in Cockpit. An integer overflow vulnerability i
CVE-2026-91127 (File Viewer is a browser-native viewer for Office, PDF, CAD, archive, ...)
TODO: check
CVE-2026-90981 (The Newsletter \u2013 Send awesome emails from WordPress plugin for Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90884 (The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89059 (A flaw was found in RESTEasy's IIOImageProvider, which decodes attacke ...)
TODO: check
CVE-2026-89058 (A flaw was found in RESTEasy's CorsFilter, which, when configured to a ...)
@@ -205,15 +205,15 @@ CVE-2026-88622 (NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injec
CVE-2026-88259 (CareCam CM2507 IP cameras do not require authentication for access to ...)
TODO: check
CVE-2026-87915 (The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers w ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86689 (Bransys ELDis shipped with hardcoded MQTT credentials, which will gran ...)
TODO: check
CVE-2026-86520 (Bransys ELDis shipped with hardcoded MQTT credentials, which will gran ...)
TODO: check
CVE-2026-85705 (The Location Manager plugin for WordPress is vulnerable to generic SQL ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85652 (The Photo Gallery by 10Web \u2013 Mobile-Friendly Image Gallery plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85511 (A flaw was found in EAP's Elytron. An EAP application whose security d ...)
TODO: check
CVE-2026-85497 (CareCam CM2507 IP cameras store the device's root-account password usi ...)
@@ -221,7 +221,7 @@ CVE-2026-85497 (CareCam CM2507 IP cameras store the device's root-account passwo
CVE-2026-85478 (A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 ex ...)
TODO: check
CVE-2026-85410 (The Master Addons for Elementor \u2013 Elementor Addons, Widgets, Mega ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85058 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffic ...)
TODO: check
CVE-2026-84992 (md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeS ...)
@@ -245,7 +245,7 @@ CVE-2026-84398 (CM2507 IP cameras accept an empty password for a privileged acco
CVE-2026-84384 (libheif is a HEIF and AVIF file format decoder and encoder. From 1.19. ...)
TODO: check
CVE-2026-83561 (The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81946 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
TODO: check
CVE-2026-81945 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
@@ -315,7 +315,7 @@ CVE-2026-77240 (WACRM is a self-hostable CRM template for WhatsApp. In version 0
CVE-2026-77239 (WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 a ...)
TODO: check
CVE-2026-75961 (The NEX-Forms \u2013 Ultimate Forms Plugin for WordPress plugin for Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75894 (In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found i ...)
TODO: check
CVE-2026-75893 (In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow iss ...)
@@ -333,19 +333,19 @@ CVE-2026-73863 (NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side
CVE-2026-71537 (Paymenter is a free and open-source webshop solution for management of ...)
TODO: check
CVE-2026-6205 (An external control of file name or path vulnerability in Upload API i ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-68914 (Mojolicious is a real-time web framework for Perl. Prior to 9.47, the ...)
TODO: check
CVE-2026-67549 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
TODO: check
CVE-2026-67103 (HCL BigFix Service Management is affected by Cross-Site Scripting (XSS ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-67102 (HCL BigFix Service Management is affected by a high-severity Broken Ac ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-67101 (HCL BigFix Service Management is affected by a Server-Side Request For ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-67100 (HCL BigFix Service Management is affected by SQL Injection flaw and a ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-65970 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
TODO: check
CVE-2026-65969 (OpenImageIO is a toolset for reading, writing, and manipulating image ...)
@@ -407,41 +407,41 @@ CVE-2026-59156 (OpenImageIO is a toolset for reading, writing, and manipulating
CVE-2026-58197 (ToolHive is a utility designed to simplify the deployment and manageme ...)
TODO: check
CVE-2026-56597 (HCL BigFix Service Management is affected by a Sensitive Information L ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56595 (HCL BigFix Service Management is affected by a CORS Misconfiguration v ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56592 (HCL BigFix Service Management is affected by an Improper Authenticatio ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-56590 (HCL BigFix Service Management is affected by an Unrestricted File Uplo ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-54148 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to ...)
TODO: check
CVE-2026-54147 (http4k is a functional toolkit for Kotlin HTTP applications. Prior to ...)
TODO: check
CVE-2026-4036 (An improper neutralization of special elements used in an SQL command ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-44639 (NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property ...)
TODO: check
CVE-2026-40539 (An improper certificate validation vulnerability in Email API in Synol ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40538 (An improper restriction of excessive authentication attempts vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40537 (A server-side request forgery (SSRF) vulnerability in PersonMail API i ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40536 (An improper limitation of a pathname to a restricted directory ('path ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40535 (An improper limitation of a pathname to a restricted directory ('path ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40534 (An improper neutralization of input during web page generation ('cross ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40533 (An exposure of sensitive information through data queries vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40532 (A direct request ('forced browsing') vulnerability in Wallpaper Path i ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40531 (An integer overflow or wraparound vulnerability in File Operation in S ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40530 (An improper neutralization of CRLF sequences ('CRLF injection') vulner ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-33625 (LMDeploy is a toolkit for compressing, deploying, and serving large la ...)
TODO: check
CVE-2026-32641 (Parseable is a log analytics platform built for high-volume data inges ...)
@@ -453,141 +453,141 @@ CVE-2026-28198 (An authenticated, low-privileged user with access to the NetBack
CVE-2026-28197 (An authenticated, low-privileged user with access to the NetBackup Fle ...)
TODO: check
CVE-2026-25684 (A file type attribution issue in Zscaler Internet Access File Type Con ...)
- TODO: check
+ NOT-FOR-US: Zscaler
CVE-2026-21848 (HCL BigFix Service Management is affected by a Security Misconfigurati ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-21822 (HCLSoftware AppScan 360\xb0 was affected by a Path Traversal vulnerabi ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-21806 (HCL BigFix Service Management is affected by an Administrative Session ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-1037 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-1031 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-1030 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-1029 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-1025 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-18442 (The WCFM Marketplace \u2013 Multivendor Marketplace for WooCommerce pl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18405 (The Jeg Kit for Elementor \u2013 Powerful Addons for Elementor, Widget ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17607 (The WP Inventory Manager plugin for WordPress is vulnerable to SQL Inj ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17586 (The VK All in One Expansion Unit plugin for WordPress is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16777 (The Store Exporter \u2013 Export WooCommerce Products, Orders, Subscri ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16515 (net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-16514 (gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c wa ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-16512 (gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced t ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-15797 (The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers w ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15579 (An out-of-bounds write vulnerability exists in some of the Ethernet sw ...)
- TODO: check
+ NOT-FOR-US: Moxa
CVE-2026-15275 (The WP Multi Store Locator Pro plugin for WordPress is vulnerable to g ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15004 (The FileBird \u2013 WordPress Media Library Folders & File Manager plu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14472 (The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14323 (The Printcart Web to Print Product Designer for WooCommerce plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13684 (An improper encoding or escaping of output vulnerability in SCGI in Sy ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-13683 (An improper neutralization of special elements used in an SQL command ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-13673 (An incorrect permission assignment for critical resource vulnerability ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-13666 (An improper neutralization of CRLF sequences ('CRLF Injection') vulner ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-13639 (An insufficient entropy vulnerability in login logic in Synology DiskS ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-13635 (An improper encoding or escaping of output vulnerability in Auth API i ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-13623 (An improper neutralization of input during web page generation ('Cross ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-13471 (The LatePoint \u2013 Calendar Booking Plugin for Appointments and Even ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12954 (The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary Us ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12739 (The WP Easy Pay \u2013 Payment and Donation form Builder for Square pl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12384 (Authorization bypass through User-Controlled key vulnerability in TECH ...)
TODO: check
CVE-2026-11757 (Improper neutralization of input during web page generation ('cross-si ...)
TODO: check
CVE-2026-11538 (IBM WebSphere Application Server 9.0 and 8.5 is affected by a log inje ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11537 (IBM WebSphere Application Server 9.0, and 8.5 could allow a remote att ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11381 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11378 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11375 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10858 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authentic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10853 (IBM MQ could allow an authenticated attacker with cluster access to ca ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10841 (IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10832 (A flaw was found in the DERDecoder class within wildfly-elytron-asn1. ...)
TODO: check
CVE-2026-10751 (IBM MQ Java and JMS client libraries could allow an authenticated atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10747 (IBM MQ Appliance could allow a remote attacker to cause a denial of se ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10744 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authentic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10575 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10030 (IBM MQ Console allows authenticated non-administrative users to create ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-10027 (IBM MQ could allow a remote attacker to cause a denial of service or e ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-66455 (LMDeploy is a toolkit for compressing, deploying, and serving large la ...)
TODO: check
CVE-2025-61682 (Semantic MediaWiki is a free, open-source extension to MediaWiki that ...)
TODO: check
CVE-2025-53837 (XWiki Rendering is a generic rendering system that converts textual in ...)
- TODO: check
+ NOT-FOR-US: XWiki
CVE-2025-36421 (IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-36178 (IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-36147 (IBM Financial Transaction Manager for SWIFT Services for Multiplatform ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-36076 (IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12. ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-36045 (IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user t ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-33147 (IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12. ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-33141 (IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an aut ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-1350 (IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-15399 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-14754 (IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to exec ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-14753 (IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-13882 (IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 thr ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-13533 (The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Sto ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-56344 (IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12. ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2023-5778 (Improper handling of length parameter inconsistency vulnerability in A ...)
- TODO: check
+ NOT-FOR-US: ABB group
CVE-2023-54399 (Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the ...)
TODO: check
CVE-2021-48008 (Chanjet CRM contains an unauthenticated SQL injection vulnerability th ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b132d10942f415280b556765575edf4ac3ad071
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b132d10942f415280b556765575edf4ac3ad071
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/07b119db/attachment.htm>
More information about the debian-security-tracker-commits
mailing list