Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
81741661 by Salvatore Bonaccorso at 2025-12-22T22:46:04+01:00
Process some new NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -47,31 +47,31 @@ CVE-2025-68326 (In the Linux kernel, the following 
vulnerability has been resolv
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/0e234632e39bd21dd28ffc9ba3ae8eec4deb949c (6.18)
 CVE-2025-67826 (An issue was discovered in K7 Ultimate Security 17.0.2045. A 
Local Pri ...)
-       TODO: check
+       NOT-FOR-US: K7 Ultimate Security
 CVE-2025-67443 (Schlix CMS before v2.2.9-5 is vulnerable to Cross Site 
Scripting (XSS) ...)
-       TODO: check
+       NOT-FOR-US: Schlix CMS
 CVE-2025-67418 (ClipBucket 5.5.2 is affected by an improper access control 
issue where ...)
-       TODO: check
+       NOT-FOR-US: ClipBucket
 CVE-2025-67291 (A stored cross-site scripting (XSS) vulnerability in the Media 
module  ...)
-       TODO: check
+       NOT-FOR-US: Piranha CMS
 CVE-2025-67290 (A stored cross-site scripting (XSS) vulnerability in the Page 
Settings ...)
-       TODO: check
+       NOT-FOR-US: Piranha CMS
 CVE-2025-67289 (An arbitrary file upload vulnerability in the Attachments 
module of Fr ...)
-       TODO: check
+       NOT-FOR-US: Frappe Framework
 CVE-2025-67288 (An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 
allows a ...)
        NOT-FOR-US: Umbraco CMS
 CVE-2025-65837 (PublicCMS V5.202506.b is vulnerable to Cross Site Scripting 
(XSS) in t ...)
-       TODO: check
+       NOT-FOR-US: PublicCMS
 CVE-2025-65790 (A reflected cross-site scripting (XSS) vulnerability exists in 
FuguHub ...)
-       TODO: check
+       NOT-FOR-US: FuguHub
 CVE-2025-65270 (Reflected cross-site scripting (XSS) vulnerability in 
ClinCapture EDC  ...)
-       TODO: check
+       NOT-FOR-US: ClinCapture EDC
 CVE-2025-63664 (Incorrect access control in the 
/api/v1/conversations/*/messages API o ...)
-       TODO: check
+       NOT-FOR-US: GT Edge AI Platform
 CVE-2025-63663 (Incorrect access control in the /api/v1/conversations/*/files 
API of G ...)
-       TODO: check
+       NOT-FOR-US: GT Edge AI Platform
 CVE-2025-63662 (Insecure permissions in the /api/v1/agents API of GT Edge AI 
Platform  ...)
-       TODO: check
+       NOT-FOR-US: GT Edge AI Platform
 CVE-2025-62880 (Cross-Site Request Forgery (CSRF) vulnerability in Kunal Nagar 
Custom  ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2025-62107 (Cross-Site Request Forgery (CSRF) vulnerability in PluginOps 
Feather L ...)
@@ -87,7 +87,7 @@ CVE-2025-61738 (Under certain circumstances, attacker can 
capture the network ke
 CVE-2025-54890 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
        NOT-FOR-US: Centreon
 CVE-2025-26787 (An error in the SignServer container startup logic was found 
in Keyfac ...)
-       TODO: check
+       NOT-FOR-US: Keyfactor SignServer
 CVE-2025-26379 (Use of a weak pseudo-random number generator, which may allow 
an attac ...)
        TODO: check
 CVE-2025-15033 (A vulnerability in WooCommerce 8.1 to 10.4.2 can allow 
logged-in custo ...)
@@ -95,17 +95,17 @@ CVE-2025-15033 (A vulnerability in WooCommerce 8.1 to 
10.4.2 can allow logged-in
 CVE-2025-14273 (Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 
10.12.x <= 10. ...)
        TODO: check
 CVE-2025-14018 (Unquoted Search Path or Element vulnerability in NetBT 
Consulting Serv ...)
-       TODO: check
+       NOT-FOR-US: E-Fatura
 CVE-2025-12514 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
        NOT-FOR-US: Centreon
 CVE-2025-10021 (A Use of Uninitialized Variable vulnerability exists in Open 
DesignAll ...)
-       TODO: check
+       NOT-FOR-US: Open Design
 CVE-2024-35321 (MyNET up to v26.08 was discovered to contain a Reflected 
cross-site sc ...)
-       TODO: check
+       NOT-FOR-US: MyNET
 CVE-2024-25814 (MyNET up to v26.05 was discovered to contain a reflected 
cross-site sc ...)
-       TODO: check
+       NOT-FOR-US: MyNET
 CVE-2024-25812 (MyNET up to v26.05 was discovered to contain a reflected 
cross-site sc ...)
-       TODO: check
+       NOT-FOR-US: MyNET
 CVE-2025-8305 (An authenticated local user can obtain information that allows 
claimin ...)
        NOT-FOR-US: Check Point
 CVE-2025-8304 (An authenticated local user can obtain information that allows 
claimin ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8174166136df196433f637e0286d2e681583172e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8174166136df196433f637e0286d2e681583172e
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to