[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 22 20:16:13 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c32abbc9 by security tracker role at 2026-09-22T19:15:51+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
CVE-2026-9231 (The WP Travel Engine \u2013 Tour Booking Plugin \u2013 Tour Operator S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-9004 (The WP-CRM System \u2013 Manage Clients and Projects plugin for WordPr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-95862 (A malicious actor with access to the network could exploit an Out-of-b ...)
- TODO: check
+ NOT-FOR-US: Ubiquity
CVE-2026-95861 (A malicious actor with access to the network could exploit an Uncontro ...)
- TODO: check
+ NOT-FOR-US: Ubiquity
CVE-2026-95806 (MISP ships with PHP's phar stream wrapper registered in both its web e ...)
TODO: check
CVE-2026-95805 (A typo in the MISP ACLComponent access control configuration caused th ...)
@@ -31,7 +31,7 @@ CVE-2026-95682 (MISP contains a stored cross-site scripting (XSS) vulnerability
CVE-2026-95679 (MISP's RequestHandlerComponent automatically decodes XML request bodie ...)
TODO: check
CVE-2026-95675 (D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthen ...)
- TODO: check
+ NOT-FOR-US: D-Link
CVE-2026-95674 (In MISP, the queryEnrichment method in EventsController.php accepted a ...)
TODO: check
CVE-2026-95671 (In MISP, the CollectionsController add() method enforced the sharing-g ...)
@@ -97,25 +97,25 @@ CVE-2026-94456 (Postiz generates security-sensitive credentials using `Math.rand
CVE-2026-94455 (An HTTP endpoint intended for provisioning enterprise and reseller org ...)
TODO: check
CVE-2026-94384 (Missing authorization in Amazon amazon-connect-salesforce-lambda befor ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-94127 (When a BIG-IP APM access policy and an OAuth profile is configured on ...)
- TODO: check
+ NOT-FOR-US: F5
CVE-2026-94117 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-93952 (VeloCloud Orchestrator (VCO) on-prem has a security issue where this i ...)
- TODO: check
+ NOT-FOR-US: Arista Networks
CVE-2026-93928 (Authentication Bypass Using an Alternate Path or Channel vulnerability ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-93836 (The WPC Product Bundles for WooCommerce plugin for WordPress is vulner ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93778 (The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93616 (A directory traversal and file upload vulnerability allows an unauthen ...)
- TODO: check
+ NOT-FOR-US: Check Point
CVE-2026-93556 (The \u2018/password/guardarClau/recover\u2019 endpoint accepts the \u2 ...)
TODO: check
CVE-2026-93345 (MikroTik RouterOS before 7.25beta4 contains an improper input validati ...)
- TODO: check
+ NOT-FOR-US: MikroTik
CVE-2026-93344 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
TODO: check
CVE-2026-93343 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
@@ -127,27 +127,27 @@ CVE-2026-93341 (MarketKing plugin for WordPress before 2.1.72 contains a missing
CVE-2026-93088 (SGLang's multimodal generation runtime is vulnerable to unauthenticate ...)
TODO: check
CVE-2026-92969 (The HUSKY \u2013 Products Filter for WooCommerce Professional plugin f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92882 (Insufficiently protected credentials in the host and folder configurat ...)
- TODO: check
+ NOT-FOR-US: Checkmk
CVE-2026-92706 (Dark Reader is an accessibility browser extension that makes web pages ...)
TODO: check
CVE-2026-92235 (The The WP Ultimate Review plugin for WordPress is vulnerable to arbit ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91130 (Home Assistant is open source home automation software focused on loca ...)
TODO: check
CVE-2026-91129 (Home Assistant is open source home automation software focused on loca ...)
TODO: check
CVE-2026-91092 (The wpForo Forum plugin for WordPress is vulnerable to authorization b ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90990 (Improper neutralization of newlines in filter values in the monitoring ...)
- TODO: check
+ NOT-FOR-US: Checkmk
CVE-2026-90882 (The open-vsx.org deployment returned Access-Control-Allow-Origin refle ...)
TODO: check
CVE-2026-90462 (A flaw was found in SSSD. When configured with the LDAP access provide ...)
TODO: check
CVE-2026-8849 (Use After Free vulnerability in RTI Connext Professional (Security Plu ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-89422 (Key Exchange without Entity Authentication vulnerability in Erlang/OTP ...)
TODO: check
CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
@@ -155,11 +155,11 @@ CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive mp
CVE-2026-89407 (NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-valid ...)
TODO: check
CVE-2026-89277 (CAI Content Credentials is affected by an Integer Overflow or Wraparou ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-89276 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-89275 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-88415 (MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting ...)
TODO: check
CVE-2026-88414 (MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the ...)
@@ -197,25 +197,25 @@ CVE-2026-85279 (Notepad++ is a free and open-source source code editor. Prior to
CVE-2026-85055 (Twenty is an open-source CRM (customer relationship management) platfo ...)
TODO: check
CVE-2026-84412 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-84396 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-84395 (Premiere Pro [NEEDS REVIEW: environment mismatch \u2014 product 'Premi ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-84388 (A improper restriction of rendered ui layers or frames vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Fortinet
CVE-2026-84301 (FastGPT is an open-source LLM platform for building AI applications on ...)
TODO: check
CVE-2026-83964 (Adobe Connect is affected by an Improper Certificate Validation vulner ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-83963 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-83962 (Substance3D - Modeler is affected by a Stack-based Buffer Overflow vul ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-83803 (Sentry is an error tracking and performance monitoring tool. From 23.1 ...)
TODO: check
CVE-2026-83660 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-83603 (Netdata is an open source observability tool. Prior to 2.10.4, the set ...)
TODO: check
CVE-2026-83602 (Netdata is an open source observability tool. From 2.0.0 until 2.11.0, ...)
@@ -231,27 +231,27 @@ CVE-2026-83598 (Netdata is an open source observability tool. From rom 2.0.0 unt
CVE-2026-83597 (Netdata is an open source observability tool. From version 2.0.0 until ...)
TODO: check
CVE-2026-82443 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-82013 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-82011 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-82010 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-82009 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-82008 (Adobe Campaign Classic (ACC) is affected by an Improper Input Validati ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-82003 (Adobe Campaign Classic (ACC) is affected by an Improper Input Validati ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-82000 (Adobe Experience Manager Forms JEE is affected by a Server-Side Reques ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-81999 (Adobe Experience Manager Forms JEE is affected by a Server-Side Reques ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-81998 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-81995 (Adobe Experience Manager Forms JEE is affected by an Improper Input Va ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-81886 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
TODO: check
CVE-2026-81885 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
@@ -297,13 +297,13 @@ CVE-2026-80144 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 befo
CVE-2026-80143 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
TODO: check
CVE-2026-7866 (Stack-based Buffer Overflow vulnerability in RTI Connext Professional ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-7622 (The ThumbPress plugin for WordPress is vulnerable to unauthorized acce ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-79913 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
TODO: check
CVE-2026-79906 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-79315 (A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. T ...)
TODO: check
CVE-2026-79314 (A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. ...)
@@ -327,13 +327,13 @@ CVE-2026-77619 (Vector is a high-performance observability data pipeline. From 0
CVE-2026-77605 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
TODO: check
CVE-2026-77558 (A malicious actor with access to the network could exploit an Out-of-b ...)
- TODO: check
+ NOT-FOR-US: Ubiquity
CVE-2026-77556 (A malicious actor with access to the network could exploit an Out-of-b ...)
- TODO: check
+ NOT-FOR-US: Ubiquity
CVE-2026-77555 (A malicious actor with access to the network could exploit an Out-of-b ...)
- TODO: check
+ NOT-FOR-US: Ubiquity
CVE-2026-77544 (A malicious actor with access to the network could exploit an Out-of-b ...)
- TODO: check
+ NOT-FOR-US: Ubiquity
CVE-2026-77399 (icalendar is an RFC 5545 compatible parser and generator of iCalendar ...)
TODO: check
CVE-2026-77274 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
@@ -405,61 +405,61 @@ CVE-2026-76803 (Nuclei is a vulnerability scanner built on a simple YAML-based D
CVE-2026-76802 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
TODO: check
CVE-2026-76194 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-76192 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75791 (Zohocorp ManageEngine ADSelfService Plus versions before build 7001 ar ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-75745 (Adobe Experience Manager Forms JEE is affected by an Incorrect Authori ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75744 (Adobe Experience Manager Forms JEE is affected by a stored Cross-Site ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75743 (Adobe Experience Manager Forms JEE is affected by a Cross-Site Request ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75728 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75723 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75721 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75703 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75699 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75698 (Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vu ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75697 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75689 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75686 (Adobe Connect is affected by an Improper Input Validation vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75684 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75682 (Adobe Connect is affected by an Improper Neutralization of Special Ele ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75676 (Bridge is affected by a Stack-based Buffer Overflow vulnerability that ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75665 (Bridge is affected by a Heap-based Buffer Overflow vulnerability that ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75663 (Bridge is affected by an out-of-bounds write vulnerability that could ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75658 (Bridge is affected by an out-of-bounds write vulnerability that could ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75656 (Bridge is affected by an out-of-bounds read vulnerability that could l ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75655 (Bridge is affected by an Uncontrolled Recursion vulnerability that cou ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75649 (Bridge is affected by a Heap-based Buffer Overflow vulnerability that ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75638 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75634 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75633 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75632 (CAI Content Credentials is affected by an Uncontrolled Resource Consum ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-75608 (Frigate is an open source network video recorder. Prior to 0.18.0, the ...)
TODO: check
CVE-2026-75607 (Frigate is an open source network video recorder. Prior to 0.17.2, the ...)
@@ -471,13 +471,13 @@ CVE-2026-75511 (Novu provides an API for sending notifications through multiple
CVE-2026-75510 (Novu provides an API for sending notifications through multiple channe ...)
TODO: check
CVE-2026-74849 (Zohocorp ManageEngine ADSelfService Plus versions before build 7001 ar ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-73369 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-70410 (Use of Externally-Controlled Input to Select Classes or Code ('Unsafe ...)
TODO: check
CVE-2026-6922 (The WP Table Builder \u2013 Drag & Drop Table Builder plugin for WordP ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-68956 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
TODO: check
CVE-2026-65634 (Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENT ...)
@@ -535,13 +535,13 @@ CVE-2026-63272 (LibreOffice can import WMF graphics, which may be embedded in do
CVE-2026-57149 (plone.app.portlets.portlets provides a Plone-specific user interface f ...)
TODO: check
CVE-2026-56682 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-56681 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-4123 (The RW Elephant Rental Inventory plugin for WordPress is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-48361 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-43643 (Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an a ...)
TODO: check
CVE-2026-43642 (Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PH ...)
@@ -553,69 +553,69 @@ CVE-2026-37604 (pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 re
CVE-2026-37603 (Improper Restriction of Excessive Authentication Attempts in the admin ...)
TODO: check
CVE-2026-34689 (Adobe Connect is affected by an Improper Limitation of a Pathname to a ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-25265 (Privilege escalation due to weak configuration while temporary file ha ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25264 (Privilege escalation due to weak configuration during package extracti ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25262 (Memory corruption while processing a crafted ELF file in the Primary B ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25255 (Exposed dangerous function lead to privilege escalation via gRPC serve ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-25254 (Improper authorization leads to Remote Code Execution via SocketIO int ...)
- TODO: check
+ NOT-FOR-US: Qualcomm
CVE-2026-24267 (NVIDIA NeMo Speech for all platforms contains a vulnerability in the s ...)
TODO: check
CVE-2026-24239 (NVIDIA NeMo Speech for all platforms contains a vulnerability where ma ...)
TODO: check
CVE-2026-1645 (The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19915 (A potential security vulnerability has been identified in the HP Suppo ...)
TODO: check
CVE-2026-19480 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-18626 (Out-of-bounds Read vulnerability in RTI Connext Professional (Core Lib ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-18462 (Integer Overflow or Wraparound, Improper Access Control vulnerability ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-18461 (Use of Externally-Controlled Format String vulnerability in RTI Connex ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-18460 (Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Pro ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-18459 (Incorrect Calculation vulnerability in RTI Connext Professional (Core ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-18458 (Out-of-bounds Read, Function Call With Incorrect Number of Arguments, ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-18457 (Heap-based Buffer Overflow vulnerability in RTI Connext Professional ( ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-18439 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18345 (The WP User Manager plugin for WordPress is vulnerable to unauthorized ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16778 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15095 (The Product Feed Manager for WooCommerce \u2013 CTX Feed \u2013 Suppor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13087 (A heap out-of-bounds write vulnerability was found in the Linux kernel ...)
TODO: check
CVE-2026-12995 (The Custom Field Template plugin for WordPress is vulnerable to Insecu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12718 (Improper neutralization of special elements used in an SQL command ('S ...)
TODO: check
CVE-2026-11389 (Out-of-bounds Read, Function Call With Incorrect Number of Arguments, ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2026-11388 (Double Free vulnerability in RTI Connext Professional (Core Libraries) ...)
- TODO: check
+ NOT-FOR-US: RTI Connext
CVE-2025-1281 (The BM Content Builder plugin for WordPress is vulnerable to arbitrary ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-1280 (The BM Content Builder plugin for WordPress is vulnerable to Directory ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-14487 (The Handily plugin for WordPress is vulnerable to unauthorized payment ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-14486 (The PixelPlay plugin for WordPress is vulnerable to unauthorized API k ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-14484 (The Image Buzz plugin for WordPress is vulnerable to unauthorized API ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-95831 (Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contai ...)
NOT-FOR-US: Crypt::SelfCertificate Perl module
CVE-2026-95818 (A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c32abbc9e7cfea867d0234fd253f7ced36fc456e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c32abbc9e7cfea867d0234fd253f7ced36fc456e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/d6a98d01/attachment.htm>
More information about the debian-security-tracker-commits
mailing list