Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c37ec2d0 by Salvatore Bonaccorso at 2026-07-19T22:18:24+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-57857 (The Flow Payment plugin for WordPress (flow.cl) version 3.0.8
is vulne ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-57848 (Stoat for Android exports the
chat.stoat.activities.ShareTargetActivit ...)
- TODO: check
+ NOT-FOR-US: Stoat for Android
CVE-2026-53994 (ProFTPD mod_sftp contains a heap-based buffer overflow
reachable by an ...)
TODO: check
CVE-2026-16229 (A flaw has been found in itsourcecode Courier Management
System up to ...)
@@ -2808,7 +2808,7 @@ CVE-2026-43636
CVE-2026-42168 (django-pyas2 through 1.2.3 is vulnerable to OS command
injection via t ...)
TODO: check
CVE-2026-36669 (An unauthenticated arbitrary file upload vulnerability in
ck_upload_ha ...)
- TODO: check
+ NOT-FOR-US: Feng Office
CVE-2026-16118 (A flaw was found in xdgmime. A heap-based buffer overflow can
be trigg ...)
TODO: check
CVE-2026-16076 (A vulnerability has been found in AstrBotDevs AstrBot up to
4.25.5. Th ...)
@@ -3510,15 +3510,15 @@ CVE-2026-44452 (h2o is an HTTP server with support for
HTTP/1.x, HTTP/2 and HTTP
NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-w68q-rqwx-7wvq
NOTE: Fixed by (merge):
https://github.com/h2o/h2o/commit/8dc37cb1e6171f7f772667618ea440696fed82c3
CVE-2026-44436 (Quicly is an IETF QUIC protocol implementation intended
primarily for ...)
- TODO: check
+ NOT-FOR-US: Quicly
CVE-2026-44435 (Quicly is an IETF QUIC protocol implementation intended
primarily for ...)
- TODO: check
+ NOT-FOR-US: Quicly
CVE-2026-44434 (Quicly is an IETF QUIC protocol implementation intended
primarily for ...)
- TODO: check
+ NOT-FOR-US: Quicly
CVE-2026-44433 (Quicly is an IETF QUIC protocol implementation intended
primarily for ...)
- TODO: check
+ NOT-FOR-US: Quicly
CVE-2026-44251 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-44182 (Jupyter Enterprise Gateway launches remote Jupyter Notebook
kernels ac ...)
TODO: check
CVE-2026-44181 (Jupyter Enterprise Gateway launches remote Jupyter Notebook
kernels ac ...)
@@ -3526,31 +3526,31 @@ CVE-2026-44181 (Jupyter Enterprise Gateway launches
remote Jupyter Notebook kern
CVE-2026-44180 (Jupyter Enterprise Gateway launches remote Jupyter Notebook
kernels ac ...)
TODO: check
CVE-2026-44177 (Kirby is an open-source content management system. In versions
5.3.0 a ...)
- TODO: check
+ NOT-FOR-US: Kirby CMS
CVE-2026-44176 (Kirby is an open-source content management system. Versions
prior to 4 ...)
- TODO: check
+ NOT-FOR-US: Kirby CMS
CVE-2026-44175 (Kirby is an open-source content management system. In versions
prior t ...)
- TODO: check
+ NOT-FOR-US: Kirby CMS
CVE-2026-44174 (Kirby is an open-source content management system. Prior to
4.9.1 and ...)
- TODO: check
+ NOT-FOR-US: Kirby CMS
CVE-2026-44023 (Docling Core defines core data types and transformations for
the docum ...)
- TODO: check
+ NOT-FOR-US: Docling Core
CVE-2026-44019 (Docling Core defines core data types and transformations for
the docum ...)
- TODO: check
+ NOT-FOR-US: Docling Core
CVE-2026-43978 (wger is a free, open-source workout and fitness manager. In
versions p ...)
- TODO: check
+ NOT-FOR-US: wger
CVE-2026-43977 (wger is a free, open-source workout and fitness manager. In
versions p ...)
- TODO: check
+ NOT-FOR-US: wger
CVE-2026-41993 (Improper Access Control vulnerability in the Removable Media
Validatio ...)
- TODO: check
+ NOT-FOR-US: TXOne Networks
CVE-2026-40106 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-39359 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-38158 (A SQL injection vulnerability in the
/ureport/datasource/previewData c ...)
- TODO: check
+ NOT-FOR-US: ureport
CVE-2026-36425 (An issue in OPSWAT AppRemover Driver (ardrv.sys)
v2017.10.02.1551 and ...)
- TODO: check
+ NOT-FOR-US: OPSWAT AppRemover Driver
CVE-2026-35149 (HCL DFXServer is affected by an Authentication Bypass
vulnerability vi ...)
NOT-FOR-US: HCL
CVE-2026-35148 (HCL DFXServer is affected by a Missing Access Control
vulnerability. T ...)
@@ -3570,15 +3570,15 @@ CVE-2026-35141 (HCL DFXAnalytics is affected by a Login
Replay Attack vulnerabil
CVE-2026-35140 (HCL DFXAnalytics is affected by a Missing Secure Attribute in
Encrypte ...)
NOT-FOR-US: HCL
CVE-2026-34150 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-33754 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-33731 (WWBN AVideo is an open source video platform. In versions
prior to 29. ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-33692 (WWBN AVideo is an open source video platform. Versions prior
to 29.0 e ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-33434 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-2594 (The Smart Custom Fields plugin for WordPress is vulnerable to
Stored C ...)
NOT-FOR-US: WordPress plugin
CVE-2026-22752 (Authentication bypass by primary weakness vulnerability in
Spring Secu ...)
@@ -3922,9 +3922,9 @@ CVE-2026-38753 (A use-after-free in the awk_sub()
function (editors/awk.c) of Bu
CVE-2026-38752 (A stack overflow in the evaluate() function (editors/awk.c) of
BusyBox ...)
TODO: check
CVE-2026-36590 (An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to
cause a de ...)
- TODO: check
+ NOT-FOR-US: EMQ NanoMQ
CVE-2026-33684 (WWBN AVideo is an open source video platform. Prior to version
29.0, P ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-33445 (CVE-2026-33445 is a memory management vulnerability in Secure
Access s ...)
NOT-FOR-US: Absolute Software
CVE-2026-33444 (CVE-2026-33444 is a memory management vulnerability in Secure
Access s ...)
@@ -4388,20 +4388,20 @@ CVE-2026-45150 (Zen is a firefox-based browser. Prior
to 1.19.13b, Zen Browser d
CVE-2026-44986 (Penpot is an open-source design tool for design and code
collaboration ...)
NOT-FOR-US: Penpot
CVE-2026-43637 (Cornac before 2.6.0 contains a path traversal (Tar Slip)
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Cornac
CVE-2026-42533 (A vulnerability exists in NGINX Plus and NGINX Open Source
when a mapd ...)
- nginx <unfixed>
NOTE: https://my.f5.com/manage/s/article/K000162097
CVE-2026-41580 (Stirling-PDF is a locally hosted web application that
facilitates vari ...)
- TODO: check
+ NOT-FOR-US: Stirling-PDF
CVE-2026-40633 (Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7,
versions 9.11 ...)
NOT-FOR-US: Dell / EMC
CVE-2026-40501 (Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit
1518530, ...)
- TODO: check
+ NOT-FOR-US: Cherry Studio
CVE-2026-35152 (A SQL Injection vulnerability exists in Apache Fineract's
Report Execu ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-33213 (Redash is a package for data visualization and sharing. From
5.0.2 to ...)
- TODO: check
+ NOT-FOR-US: Redash
CVE-2026-20298 (In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8,
and 9.4.13 ...)
NOT-FOR-US: Cisco
CVE-2026-20297 (In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8,
9.4.13, an ...)
@@ -6162,13 +6162,13 @@ CVE-2026-42982 (Improper validation of consistency
within input in Windows Secur
CVE-2026-42975 (Heap-based buffer overflow in Windows Bluetooth Port Driver
allows an ...)
NOT-FOR-US: Microsoft
CVE-2026-42936 (The installer of HYPER SBI 2 insecurely loads Dynamic Link
Libraries. ...)
- TODO: check
+ NOT-FOR-US: HYPER SBI 2
CVE-2026-42900 (Concurrent execution using shared resource with improper
synchronizati ...)
NOT-FOR-US: Microsoft
CVE-2026-42447 (jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is
affected ...)
- TODO: check
+ NOT-FOR-US: jadx
CVE-2026-42049 (jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts
the and ...)
- TODO: check
+ NOT-FOR-US: jadx
CVE-2026-41087 (Exposure of sensitive information to an unauthorized actor in
Windows ...)
NOT-FOR-US: Microsoft
CVE-2026-40422 (Use of uninitialized resource in Windows File Explorer allows
an autho ...)
@@ -6180,11 +6180,11 @@ CVE-2026-40378 (Memory allocation with excessive size
value in Windows Local Sec
CVE-2026-3014 (Milestone has released a new version of XProtect\xae (and
several cumu ...)
TODO: check
CVE-2026-38450 (An issue in Aetopia Digital Asset Management DAM v.1.0.0
allows a remo ...)
- TODO: check
+ NOT-FOR-US: Aetopia Digital Asset Management DAM
CVE-2026-36214 (osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to
1.18.3 ...)
- TODO: check
+ NOT-FOR-US: osTicket
CVE-2026-36035 (Incorrect access control in the /api/License/deactivateOffline
endpoin ...)
- TODO: check
+ NOT-FOR-US: CAXPerts UniversalPlantViewer WebServices Server
CVE-2026-34349 (Exposure of sensitive information to an unauthorized actor in
Windows ...)
NOT-FOR-US: Microsoft
CVE-2026-34348 (Protection mechanism failure in Windows Event Logging Service
allows a ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c37ec2d0f813d1e0e6a2f8a92c6a989f34ad3cce
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c37ec2d0f813d1e0e6a2f8a92c6a989f34ad3cce
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits