Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4095cd62 by security tracker role at 2026-07-24T07:13:49+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-6924 (A bug in the entropy initialization for SiWx917 causes the DRBG 
to use ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-6454 (The Firelight Lightbox plugin for WordPress is vulnerable to 
Stored DO ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-66141 (Exim before 4.99.5 allows .forward privilege escalation 
because force_ ...)
        TODO: check
 CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files 
outside  ...)
@@ -23,7 +23,7 @@ CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path 
traversal vulnerab
 CVE-2026-65604 (Skipper contains an incomplete fix for CVE-2026-50197 in which 
oversiz ...)
        TODO: check
 CVE-2026-64785 (SwiftNIO HTTP/2 was missing validation on inbound HEADERS 
frames that  ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-63732 (9router 0.4.59 (fixed in 0.4.60) contains a chain of 
vulnerabilities:  ...)
        TODO: check
 CVE-2026-63359 (The Appriss Insights (Equifax) Victim Information Notification 
Exchang ...)
@@ -31,25 +31,25 @@ CVE-2026-63359 (The Appriss Insights (Equifax) Victim 
Information Notification E
 CVE-2026-63313 (9Router before 0.4.72 contains a server-side request forgery 
(SSRF) vu ...)
        TODO: check
 CVE-2026-62825 (Improper authentication in Azure Key Vault allows an 
unauthorized atta ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains 
a code  ...)
        TODO: check
 CVE-2026-58275 (Missing authorization in Azure DNS allows an unauthorized 
attacker to  ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-56191 (Improper authentication in Microsoft Exchange Online allows an 
unautho ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-56167 (Server-side request forgery (ssrf) in Azure AI Search allows 
an author ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-56165 (Heap-based buffer overflow in Microsoft Account allows an 
unauthorized ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-56160 (Improper authorization in Azure Red Hat OpenShift (ARO) allows 
an auth ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-54120 (Improper input validation in Microsoft Surface allows an 
authorized at ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-52439 (An issue in xiandafu beetl 3.20.2 allows a remote attacker to 
execute  ...)
        TODO: check
 CVE-2026-50517 (Deserialization of untrusted data in M365 Copilot allows an 
authorized ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-50103 (A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared 
parser,  ...)
        TODO: check
 CVE-2026-50044 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
inadequate encr ...)
@@ -59,7 +59,7 @@ CVE-2026-50039 (The affected product is vulnerable to a 
stack-based buffer overf
 CVE-2026-50032 (A NULL pointer dereference in the MMS Write Named Variable 
List handle ...)
        TODO: check
 CVE-2026-49159 (Exposure of sensitive information to an unauthorized actor in 
Microsof ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-49035 (The affected product is vulnerable to a heap-based buffer 
overflow via ...)
        TODO: check
 CVE-2026-48013 (Shopware is an open commerce platform. Prior to 6.6.10.18 and 
6.7.10.1 ...)
@@ -87,17 +87,17 @@ CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 
3.5.4 contains a vulnera
 CVE-2026-38764 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
        TODO: check
 CVE-2026-35425 (Improper access control in Azure API Management (APIM) allows 
an autho ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on 
Windows allows ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-28698 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
exposure of sen ...)
        TODO: check
 CVE-2026-25800 (Quinn is a pure-Rust, async-compatible implementation of the 
IETF QUIC ...)
        TODO: check
 CVE-2026-21655 (Deserialization of untrusted data vulnerability in Johnson 
Control vic ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-21653 (Victor SSRF vulnerability in Johnson Controls CCure 9000 and 
victor ap ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-16870 (Multiple security vulnerabilities in Snowflake 
libsnowflakeclient vers ...)
        TODO: check
 CVE-2026-16807 (Out of bounds write in Codecs in Google Chrome prior to 
150.0.7871.186 ...)
@@ -109,7 +109,7 @@ CVE-2026-16805 (Use after free in Blink in Google Chrome 
prior to 150.0.7871.186
 CVE-2026-16804 (Use after free in Input in Google Chrome prior to 
150.0.7871.186 allow ...)
        TODO: check
 CVE-2026-16796 (Improper neutralization of argument delimiters in the 
install_packages ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-16767 (A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. 
This affe ...)
        TODO: check
 CVE-2026-16765 (A vulnerability was determined in CodeAstro Online Classroom 
1.0. Affe ...)
@@ -121,53 +121,53 @@ CVE-2026-16763 (A vulnerability was identified in 
localstack serverless-localsta
 CVE-2026-16002 (The affected product is vulnerable to an Out-of-bounds read, 
which may ...)
        TODO: check
 CVE-2026-15981 (The SAML Single Sign On \u2013 SSO Login plugin for WordPress 
is vulne ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15968 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-15967 (Insufficient session expiration vulnerability in Progress 
MOVEit Trans ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-15966 (Permissive cross-domain security policy with untrusted domains 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-15630 (A non-global organization admin in one tenant can bypass 
tenant bounda ...)
        TODO: check
 CVE-2026-15420 (The Nexter Blocks \u2013 Gutenberg Blocks, Page Builder & AI 
Website B ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15212 (The WPO365 | Login plugin for WordPress is vulnerable to 
Cross-Site Re ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15100 (The Post Grid Gutenberg Blocks \u2013 PostX plugin for 
WordPress is vu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14603 (The WowOptin: Next-Gen Popup Maker  WordPress plugin before 
1.4.38 doe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14172 (Rapid7 InsightVM, Nexpose, and the Insight Agent execute 
discovered ex ...)
        TODO: check
 CVE-2026-13464 (The Kirki \u2013 Freeform Page Builder, Website Builder & 
Customizer p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12981 (The CAFEHAUS API WordPress plugin through 1.0.0 does not have 
any auth ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12877 (The Project Management, Bug and Issue Tracking Plugin  
WordPress plugi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12736 (The Wpify Woo plugin for WordPress is vulnerable to Privilege 
Escalati ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12690 (The ProfileGrid  WordPress plugin before 5.9.9.7 does not 
perform a ca ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12689 (The ProfileGrid  WordPress plugin before 5.9.9.7 does not 
perform any  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12688 (The ProfileGrid  WordPress plugin before 5.9.9.7 does not 
verify PayPa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12497 (The Paid Membership Plugin, Ecommerce, User Registration Form, 
Login F ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12353 (An unauthenticated attacker could trigger an Out of Memory 
condition t ...)
        TODO: check
 CVE-2026-11922 (A vulnerability in zenml-io/zenml versions 0.57.0 through 
0.94.2 allow ...)
        TODO: check
 CVE-2026-11354 (The Participants Database plugin for WordPress is vulnerable 
to Sensit ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-10697 (Improper Authentication vulnerability in Progress MOVEit 
Transfer.  Th ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2025-9205 (The MapSVG plugin for WordPress is vulnerable to Stored 
Cross-Site Scr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-71389 (Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to 
unauthenticated ...)
-       TODO: check
+       NOT-FOR-US: Next.js
 CVE-2024-58355 (Cal.com (calcom/cal.diy) versions through 4.7.15 contain a 
stored cros ...)
        TODO: check
 CVE-2024-58354 (cal.com (calcom repository, later renamed cal.diy) is affected 
by a re ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4095cd62f1f05008f7ae78aa18eda46bdda0cfee

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4095cd62f1f05008f7ae78aa18eda46bdda0cfee
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to