Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a7e0cecc by Salvatore Bonaccorso at 2026-07-19T08:36:50+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -20,109 +20,109 @@ CVE-2026-47866 (VMware Avi Load Balancer contains an 
authorization bypass vulner
 CVE-2026-47865 (VMware Avi Load Balancer contains an authentication bypass 
vulnerabili ...)
        NOT-FOR-US: VMware
 CVE-2026-16158 (Impact: @fastify/reply-from versions from 8.3.1 up to but not 
includin ...)
-       TODO: check
+       NOT-FOR-US: fastify/reply-from
 CVE-2026-16133 (A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. 
Affected by thi ...)
-       TODO: check
+       NOT-FOR-US: LiuMengxuan04 MiniCode
 CVE-2026-16131 (A weakness has been identified in itsourcecode Hospital 
Management Sys ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-16130 (A vulnerability was identified in nearai ironclaw up to 
0.29.1. The af ...)
-       TODO: check
+       NOT-FOR-US: ironclaw
 CVE-2026-16129 (A vulnerability has been found in princezuda SafestClaw up to 
4.2.4. T ...)
-       TODO: check
+       NOT-FOR-US: princezuda SafestClaw
 CVE-2026-16128 (A security flaw has been discovered in zevorn rt-claw up to 
0.2.0. Thi ...)
-       TODO: check
+       NOT-FOR-US: zevorn rt-claw
 CVE-2026-16127 (A vulnerability was identified in zevorn rt-claw up to 0.2.0. 
This aff ...)
-       TODO: check
+       NOT-FOR-US: zevorn rt-claw
 CVE-2026-16126 (A vulnerability was determined in zevorn rt-claw up to 0.2.0. 
The impa ...)
-       TODO: check
+       NOT-FOR-US: zevorn rt-claw
 CVE-2026-16125 (A vulnerability was found in zevorn rt-claw up to 0.2.0. The 
affected  ...)
-       TODO: check
+       NOT-FOR-US: zevorn rt-claw
 CVE-2026-16124 (A security vulnerability has been detected in nextlevelbuilder 
GoClaw  ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-16123 (A weakness has been identified in nextlevelbuilder GoClaw up 
to 3.13.2 ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-16122 (A security flaw has been discovered in nextlevelbuilder GoClaw 
up to 3 ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-16121 (A vulnerability was identified in nextlevelbuilder GoClaw up 
to 3.13.2 ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-16120 (A vulnerability was determined in nextlevelbuilder GoClaw up 
to 3.13.3 ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-16119 (A vulnerability was found in nextlevelbuilder GoClaw up to 
3.13.2. Thi ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-16117 (Impact: @fastify/http-proxy versions up to and including 
11.5.0 fail t ...)
-       TODO: check
+       NOT-FOR-US: fastify/http-proxy
 CVE-2026-16097 (A vulnerability was found in Shibby Tomato 1.28. This 
vulnerability af ...)
-       TODO: check
+       NOT-FOR-US: Shibby Tomato
 CVE-2026-16096 (A vulnerability has been found in Shibby Tomato 1.28 RT-N5x 
MIPSR2 Bui ...)
-       TODO: check
+       NOT-FOR-US: Shibby Tomato
 CVE-2026-16095 (A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 
Build 124. A ...)
-       TODO: check
+       NOT-FOR-US: Shibby Tomato
 CVE-2026-16088 (A vulnerability was detected in halo-dev halo up to 2.24.2. 
Affected b ...)
-       TODO: check
+       NOT-FOR-US: halo-dev halo
 CVE-2026-16085 (A security vulnerability has been detected in Sipeed PicoClaw 
up to 0. ...)
-       TODO: check
+       NOT-FOR-US: Sipeed PicoClaw
 CVE-2026-16084 (A weakness has been identified in Sipeed PicoClaw up to 0.2.9. 
This im ...)
-       TODO: check
+       NOT-FOR-US: Sipeed PicoClaw
 CVE-2026-16083 (A security flaw has been discovered in Sipeed PicoClaw up to 
0.2.9. Th ...)
-       TODO: check
+       NOT-FOR-US: Sipeed PicoClaw
 CVE-2026-16082 (A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. 
The imp ...)
-       TODO: check
+       NOT-FOR-US: Sipeed PicoClaw
 CVE-2026-16081 (A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. 
The aff ...)
-       TODO: check
+       NOT-FOR-US: Sipeed PicoClaw
 CVE-2026-16077 (A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. 
Impacte ...)
-       TODO: check
+       NOT-FOR-US: AstrBot
 CVE-2026-15631 (Impact: @fastify/http-proxy versions from 9.4.0 up to and 
including 11 ...)
-       TODO: check
+       NOT-FOR-US: fastify/http-proxy
 CVE-2026-11826 (OpenPLC_v3 contains a heap-based buffer overflow in the 
getData() func ...)
-       TODO: check
+       NOT-FOR-US: OpenPLC
 CVE-2025-71398 (SurrealDB before 2.2.2 fails to validate HTTP redirects in 
http functi ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2025-71397 (SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 
2.2.2 all ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2025-71396 (SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 
2.2.2 doe ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2025-71395 (SurrealDB versions before 2.2.2 contain a memory exhaustion 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2025-71394 (SurrealDB versions before 2.2.2 contain a local file read 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2025-71393 (SurrealDB before 2.2.2 with scripting enabled fails to 
properly enforc ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2025-71392 (SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 
2.2.2 fai ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2025-71391 (SurrealDB versions before 2.2.2 contain an uncaught exception 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2025-71390 (SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 
and earlie ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58370 (SurrealDB versions before 1.1.0 fail to enforce recursion 
depth limits ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58369 (SurrealDB versions before 1.1.1 fail to properly validate 
invocation o ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58368 (SurrealDB versions before 1.1.0 fail to properly parse the ID, 
DB, and ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58367 (SurrealDB versions before 2.0.4 fail to properly enforce field 
permiss ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58366 (SurrealDB before 1.1.1 contains a format string vulnerability 
in the r ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58365 (SurrealDB versions before 1.2.0 contain an uncaught exception 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58364 (SurrealDB versions before 1.2.1 contain an uncaught exception 
handling ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58363 (SurrealDB before 1.5.4 fails to properly validate 
authentication when  ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58362 (SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) 
accepts an ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58361 (SurrealDB versions before 2.0.4 contain an uncaught exception 
handling ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58359 (SurrealDB versions before 2.1.0 contain a denial of service 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58358 (SurrealDB versions before 2.1.0 contain a denial of service 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58357 (SurrealDB versions before 2.1.0 contain an uncaught exception 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2024-58356 (SurrealDB before 2.1.4 silently fails to overwrite table 
definitions w ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2023-54366 (SurrealDB before 1.0.1 sets default table permissions to FULL 
instead  ...)
-       TODO: check
+       NOT-FOR-US: SurrealDB
 CVE-2026-9734 (The W3SC Elementor to Zoho CRM plugin for WordPress is 
vulnerable to C ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-8861 (IBM Security Verify could allow a remote attacker to obtain 
sensitive  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a7e0cecc76f8e476615bd77426f674e773a3c3c3

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a7e0cecc76f8e476615bd77426f674e773a3c3c3
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to