Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
50b5eb43 by Salvatore Bonaccorso at 2026-07-20T08:01:29+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18,69 +18,69 @@ CVE-2026-16227 (A security vulnerability has been detected
in SourceCodester Cla
CVE-2026-16226 (A weakness has been identified in SourceCodester Pizzafy
Ecommerce Sys ...)
NOT-FOR-US: SourceCodester
CVE-2026-16225 (A security flaw has been discovered in davenardella snap7 up
to 1.4.3. ...)
- TODO: check
+ NOT-FOR-US: davenardella snap7
CVE-2026-16224 (A vulnerability was identified in jxxghp MoviePilot up to
2.13.5. The ...)
- TODO: check
+ NOT-FOR-US: jxxghp MoviePilot
CVE-2026-16223 (A vulnerability was determined in 1Panel-dev CordysCRM up to
1.4.1. Im ...)
- TODO: check
+ NOT-FOR-US: 1Panel-dev CordysCRM
CVE-2026-16222 (A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1.
This is ...)
- TODO: check
+ NOT-FOR-US: 1Panel-dev CordysCRM
CVE-2026-16221 (Impact: fast-uri versions from 2.3.1 through 4.1.0 (including
the 3.x ...)
TODO: check
CVE-2026-16220 (A vulnerability has been found in code-projects Online
Examination Sys ...)
NOT-FOR-US: code-projects
CVE-2026-16219 (A flaw has been found in Croogo CMS up to 4.0.7. This affects
the func ...)
- TODO: check
+ NOT-FOR-US: Croogo CMS
CVE-2026-16218 (A vulnerability was detected in hunvreus devpush up to 0.4.6.
Affected ...)
- TODO: check
+ NOT-FOR-US: hunvreus devpush
CVE-2026-16217 (A security vulnerability has been detected in guohongze
adminset up to ...)
- TODO: check
+ NOT-FOR-US: guohongze adminset
CVE-2026-16216 (A weakness has been identified in geex-arts django-jet up to
1.0.8. Af ...)
- TODO: check
+ NOT-FOR-US: geex-arts django-jet
CVE-2026-16215 (A security flaw has been discovered in geex-arts django-jet up
to 1.0. ...)
- TODO: check
+ NOT-FOR-US: geex-arts django-jet
CVE-2026-16214 (A vulnerability was identified in geex-arts django-jet up to
1.0.8. Th ...)
- TODO: check
+ NOT-FOR-US: geex-arts django-jet
CVE-2026-16213 (A security flaw has been discovered in Fantomas42
django-blog-zinnia u ...)
- TODO: check
+ NOT-FOR-US: Fantomas42 django-blog-zinnia
CVE-2026-16212 (A vulnerability was identified in awesto django-shop up to
1.2.4. Affe ...)
- TODO: check
+ NOT-FOR-US: awesto django-shop
CVE-2026-16211 (A vulnerability was determined in allegro up to
bcf65b994ef29fb3fc2e10 ...)
- TODO: check
+ NOT-FOR-US: allegro
CVE-2026-16210 (A vulnerability was found in newpanjing simpleui 2026.01.13.
This affe ...)
- TODO: check
+ NOT-FOR-US: newpanjing simpleui
CVE-2026-16209 (A vulnerability has been found in Gerapy up to 0.9.13. The
impacted el ...)
- TODO: check
+ NOT-FOR-US: Gerapy
CVE-2026-16208 (A flaw has been found in django-tastypie up to 0.15.1. The
affected el ...)
- TODO: check
+ NOT-FOR-US: django-tastypie
CVE-2026-16207 (A vulnerability was detected in django-tastypie up to 0.15.1.
Impacted ...)
- TODO: check
+ NOT-FOR-US: django-tastypie
CVE-2026-16206 (A security vulnerability has been detected in django-oauth
django-oaut ...)
- TODO: check
+ NOT-FOR-US: django-oauth django-oauth-toolkit
CVE-2026-16205 (A weakness has been identified in Pluck CMS up to 4.7.21. This
vulnera ...)
- TODO: check
+ NOT-FOR-US: Pluck CMS
CVE-2026-16204 (A security flaw has been discovered in zevorn rt-claw up to
0.2.0. Thi ...)
- TODO: check
+ NOT-FOR-US: zevorn rt-claw
CVE-2026-16203 (A vulnerability was identified in SourceCodester Class and
Exam Timeta ...)
NOT-FOR-US: SourceCodester
CVE-2026-16202 (A vulnerability was determined in SourceCodester Class and
Exam Timeta ...)
NOT-FOR-US: SourceCodester
CVE-2026-16201 (A vulnerability was found in zevorn rt-claw up to 0.2.0.
Affected is t ...)
- TODO: check
+ NOT-FOR-US: zevorn rt-claw
CVE-2026-16200 (A vulnerability has been found in zevorn rt-claw up to 0.2.0.
This imp ...)
- TODO: check
+ NOT-FOR-US: zevorn rt-claw
CVE-2026-16199 (A flaw has been found in nextlevelbuilder GoClaw up to
3.13.3-beta.3. ...)
- TODO: check
+ NOT-FOR-US: nextlevelbuilder GoClaw
CVE-2026-16198 (A vulnerability was detected in Sipeed PicoClaw up to 0.2.9.
The impac ...)
- TODO: check
+ NOT-FOR-US: Sipeed PicoClaw
CVE-2026-16197 (A security vulnerability has been detected in Sipeed PicoClaw
up to 0. ...)
- TODO: check
+ NOT-FOR-US: Sipeed PicoClaw
CVE-2026-16196 (A weakness has been identified in Sipeed PicoClaw up to 0.2.9.
Impacte ...)
- TODO: check
+ NOT-FOR-US: Sipeed PicoClaw
CVE-2026-16195 (A security flaw has been discovered in Sipeed PicoClaw up to
0.2.9. Th ...)
- TODO: check
+ NOT-FOR-US: Sipeed PicoClaw
CVE-2026-16194 (A vulnerability was determined in zhayujie CowAgent up to
2.1.1. This ...)
- TODO: check
+ NOT-FOR-US: zhayujie CowAgent
CVE-2026-16156 (A security flaw has been discovered in SourceCodester Class
and Exam T ...)
NOT-FOR-US: SourceCodester
CVE-2026-16155 (A vulnerability was identified in SourceCodester Class and
Exam Timeta ...)
@@ -90,9 +90,9 @@ CVE-2026-16154 (A vulnerability was determined in
SourceCodester Class and Exam
CVE-2026-16152 (A vulnerability was found in SourceCodester Class and Exam
Timetabling ...)
NOT-FOR-US: SourceCodester
CVE-2026-16151 (A vulnerability has been found in CartoDB carto-api-client
0.5.29. Thi ...)
- TODO: check
+ NOT-FOR-US: CartoDB carto-api-client
CVE-2026-16150 (A vulnerability was found in RobinHerbots Inputmask up to
5.0.9. Affec ...)
- TODO: check
+ NOT-FOR-US: RobinHerbots Inputmask
CVE-2026-12228 (A stored cross-site scripting (XSS) vulnerability exists in
the `POST ...)
TODO: check
CVE-2026-10130 (QueryWeaver contains an authentication bypass vulnerability
that allow ...)
@@ -2811,17 +2811,17 @@ CVE-2026-44739 (Pimcore is an Open Source Data &
Experience Management Platform.
CVE-2026-43636
REJECTED
CVE-2026-42168 (django-pyas2 through 1.2.3 is vulnerable to OS command
injection via t ...)
- TODO: check
+ NOT-FOR-US: django-pyas2
CVE-2026-36669 (An unauthenticated arbitrary file upload vulnerability in
ck_upload_ha ...)
NOT-FOR-US: Feng Office
CVE-2026-16118 (A flaw was found in xdgmime. A heap-based buffer overflow can
be trigg ...)
TODO: check
CVE-2026-16076 (A vulnerability has been found in AstrBotDevs AstrBot up to
4.25.5. Th ...)
- TODO: check
+ NOT-FOR-US: AstrBotDevs AstrBot
CVE-2026-16075 (A flaw has been found in AstrBotDevs AstrBot up to 4.25.5.
This vulner ...)
- TODO: check
+ NOT-FOR-US: AstrBotDevs AstrBot
CVE-2026-16074 (A vulnerability was detected in AstrBotDevs AstrBot up to
4.25.2. This ...)
- TODO: check
+ NOT-FOR-US: AstrBotDevs AstrBot
CVE-2026-15995 (IBM Cognos Analytics 12.1.3 GA Version with build number
through 12.1. ...)
NOT-FOR-US: IBM
CVE-2026-15415 (AWS HealthOmics is a HIPAA-eligible service that fully manages
the com ...)
@@ -3027,7 +3027,7 @@ CVE-2026-44722 (pyzipper is a replacement for Python's
zipfile that can read and
NOTE:
https://github.com/danifus/pyzipper/security/advisories/GHSA-crqm-m339-7m2p
NOTE: Fixed by;
https://github.com/danifus/pyzipper/commit/93ce88e7dfd1635443197dab3fb8d477cff579ae
(v0.4.0)
CVE-2026-22104 (Improper access control in Hashtopolis server web-interface
chunk acti ...)
- TODO: check
+ NOT-FOR-US: Hashtopolis server
CVE-2026-21764 (HCL DevOps Loop is affected by insufficient input validation
that allo ...)
NOT-FOR-US: HCL
CVE-2026-21762 (HCL DevOps Loop is affected by missing HTTP security headers.
Missing ...)
@@ -3049,23 +3049,23 @@ CVE-2026-16093 (Keycloak provides a mechanism called
Client Policies to enforce
CVE-2026-16089 (A flaw was found in the keycloak-services component of Red Hat
Build o ...)
TODO: check
CVE-2026-16073 (A security vulnerability has been detected in AstrBotDevs
AstrBot up t ...)
- TODO: check
+ NOT-FOR-US: AstrBotDevs AstrBot
CVE-2026-16072 (A flaw was found in the organization management component of
Keycloak. ...)
TODO: check
CVE-2026-16017 (A security flaw has been discovered in mosaxiv clawlet up to
0.2.10. I ...)
- TODO: check
+ NOT-FOR-US: mosaxiv clawlet
CVE-2026-16016 (A vulnerability was identified in poco-ai poco-claw up to
0.5.4. This ...)
- TODO: check
+ NOT-FOR-US: poco-ai poco-claw
CVE-2026-16015 (A vulnerability was determined in poco-ai poco-claw up to
0.5.4. This ...)
- TODO: check
+ NOT-FOR-US: poco-ai poco-claw
CVE-2026-16014 (A vulnerability was found in code-projects Hospital Bed
Management Sys ...)
NOT-FOR-US: code-projects
CVE-2026-16013 (A vulnerability has been found in liftoff-sr CIPster up to
632336d414e ...)
- TODO: check
+ NOT-FOR-US: liftoff-sr CIPster
CVE-2026-16009 (A vulnerability was detected in itsourcecode Hospital
Management Syste ...)
NOT-FOR-US: itsourcecode System
CVE-2026-16008 (A security vulnerability has been detected in sagold
json-schema-libra ...)
- TODO: check
+ NOT-FOR-US: sagold json-schema-library
CVE-2026-15943 (A flaw was found in the Keycloak keycloak-services component,
which ha ...)
TODO: check
CVE-2026-15783 (A missing authorization vulnerability was identified in GitHub
Enterpr ...)
@@ -3525,11 +3525,11 @@ CVE-2026-44433 (Quicly is an IETF QUIC protocol
implementation intended primaril
CVE-2026-44251 (Wazuh is a free and open source platform used for threat
prevention, d ...)
NOT-FOR-US: Wazuh
CVE-2026-44182 (Jupyter Enterprise Gateway launches remote Jupyter Notebook
kernels ac ...)
- TODO: check
+ NOT-FOR-US: Jupyter Enterprise Gateway
CVE-2026-44181 (Jupyter Enterprise Gateway launches remote Jupyter Notebook
kernels ac ...)
- TODO: check
+ NOT-FOR-US: Jupyter Enterprise Gateway
CVE-2026-44180 (Jupyter Enterprise Gateway launches remote Jupyter Notebook
kernels ac ...)
- TODO: check
+ NOT-FOR-US: Jupyter Enterprise Gateway
CVE-2026-44177 (Kirby is an open-source content management system. In versions
5.3.0 a ...)
NOT-FOR-US: Kirby CMS
CVE-2026-44176 (Kirby is an open-source content management system. Versions
prior to 4 ...)
@@ -3937,25 +3937,25 @@ CVE-2026-33444 (CVE-2026-33444 is a memory management
vulnerability in Secure Ac
CVE-2026-33443 (CVE-2026-33443 is a memory management error in Secure Access
servers p ...)
NOT-FOR-US: Absolute Software
CVE-2026-30623 (LiteLLM 1.18.10 contains a remote code execution vulnerability
in its ...)
- TODO: check
+ NOT-FOR-US: LiteLLM
CVE-2026-30618 (xszyou Fay 4.3.1 contains a remote code execution
vulnerability in its ...)
- TODO: check
+ NOT-FOR-US: xszyou Fay
CVE-2026-26719 (Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0
allows a r ...)
- TODO: check
+ NOT-FOR-US: xxl-job-admin
CVE-2026-26718 (A Cross-Site Request Forgery (CSRF) vulnerability exists in
the xxl-jo ...)
- TODO: check
+ NOT-FOR-US: xxl-job-admin
CVE-2026-26032 (The PackagerResolver of Apache Ivy is able to download online
artifact ...)
TODO: check
CVE-2026-21729 (Loki queries with large limits can cause large memory
allocations whic ...)
- TODO: check
+ NOT-FOR-US: Grafana Loki
CVE-2026-15925 (Improper TLS hostname verification in Snowflake Connector for
Python v ...)
- TODO: check
+ NOT-FOR-US: Snowflake Connector for Python
CVE-2026-15921 (Node Version Manager (nvm) is a POSIX-compliant shell function
for man ...)
TODO: check
CVE-2026-15909 (A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up
to ddfe1 ...)
- TODO: check
+ NOT-FOR-US: RafyMrX TOKO-ONLINE-ROTI
CVE-2026-15907 (A flaw has been found in H3C SecPath F1000-C8300 up to
20260522. This ...)
- TODO: check
+ NOT-FOR-US: H3C
CVE-2026-15895 (OS command injection in the npm package loading component in
AWS jsii- ...)
NOT-FOR-US: Amazon
CVE-2026-15652 (The Easy Accordion \u2013 AI-Powered FAQ & Accordion Blocks,
Product F ...)
@@ -4426,21 +4426,21 @@ CVE-2026-20153 (As part of Cisco's ongoing commitment
to proactive security and
CVE-2026-20150 (As part of Cisco's ongoing commitment to proactive security
and produc ...)
NOT-FOR-US: Cisco
CVE-2026-20146 (A vulnerability in Cisco Identity Services Engine (ISE) and
Cisco ISE ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-1563 (Pega Platform versions 8.1.0 through 25.1.2 are affected by an
Reflect ...)
- TODO: check
+ NOT-FOR-US: Pega Platform
CVE-2026-1562 (Pega Platform versions 8.1.0 through 25.1.2 are affected by an
Stored ...)
- TODO: check
+ NOT-FOR-US: Pega Platform
CVE-2026-15809 (A flaw was found in CRI-O. The fix for a previous
vulnerability (CVE-2 ...)
TODO: check
CVE-2026-15804 (The HCM developed by MetaGuru has a SQL Injection
vulnerability. Authe ...)
- TODO: check
+ NOT-FOR-US: MetaGuru
CVE-2026-15779 (A flaw was found in samba's pam_winbind. When mkhomedir is
enabled, pa ...)
TODO: check
CVE-2026-15746 (Strands Agents is an open-source Python SDK for building and
running A ...)
NOT-FOR-US: Amazon
CVE-2026-15583 (A confused-deputy flaw in Grafana MCP Server allows an
unauthenticated ...)
- TODO: check
+ NOT-FOR-US: Grafana MCP Server
CVE-2026-14961 (Pegatron `Tdelo64.sys` exposes a privileged device interface,
`\\.\Tde ...)
TODO: check
CVE-2026-14960 (Pegatron `Tdelo64.sys` improperly exposes privileged hardware
access f ...)
@@ -6183,7 +6183,7 @@ CVE-2026-40400 (Relative path traversal in Windows
PowerShell allows an authoriz
CVE-2026-40378 (Memory allocation with excessive size value in Windows Local
Security ...)
NOT-FOR-US: Microsoft
CVE-2026-3014 (Milestone has released a new version of XProtect\xae (and
several cumu ...)
- TODO: check
+ NOT-FOR-US: Milestone XProtect
CVE-2026-38450 (An issue in Aetopia Digital Asset Management DAM v.1.0.0
allows a remo ...)
NOT-FOR-US: Aetopia Digital Asset Management DAM
CVE-2026-36214 (osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to
1.18.3 ...)
@@ -6289,19 +6289,19 @@ CVE-2026-15764 (Use after free in Ozone in Google
Chrome on Linux prior to 150.0
CVE-2026-15757 (A security flaw was discovered in the NETGEAR DGND3700v1 that
could al ...)
NOT-FOR-US: Netgear
CVE-2026-15753 (A vulnerability was determined in zhinianboke
xianyu-auto-reply on Ser ...)
- TODO: check
+ NOT-FOR-US: zhinianboke xianyu-auto-reply
CVE-2026-15752 (A vulnerability was found in zhinianboke xianyu-auto-reply up
to dcb44 ...)
- TODO: check
+ NOT-FOR-US: zhinianboke xianyu-auto-reply
CVE-2026-15751 (A security vulnerability has been detected in mastergo-design
mastergo ...)
- TODO: check
+ NOT-FOR-US: mastergo-design mastergo-magic-mcp
CVE-2026-15750 (A weakness has been identified in mastergo-design
mastergo-magic-mcp u ...)
- TODO: check
+ NOT-FOR-US: mastergo-design mastergo-magic-mcp
CVE-2026-15749 (A security flaw has been discovered in mastergo-design
mastergo-magic- ...)
- TODO: check
+ NOT-FOR-US: mastergo-design mastergo-magic-mcp
CVE-2026-15738 (Incorrect behavior order in the Gateway API listener-rule
generation i ...)
NOT-FOR-US: Amazon
CVE-2026-15736 (Snowflake SQLAlchemy versions prior to 1.11.0 contain several
security ...)
- TODO: check
+ NOT-FOR-US: Snowflake SQLAlchemy
CVE-2026-15720 (InOpen5GS through version 2.7.7 a pre-authenticationheap
out-of-bounds ...)
TODO: check
CVE-2026-15715 (A vulnerability was identified in SourceCodester Class and
Exam Timeta ...)
@@ -6319,17 +6319,17 @@ CVE-2026-15709 (A flaw was found in libsoup's WebSocket
implementation when usin
CVE-2026-15703 (A vulnerability was detected in SourceCodester Simple and Nice
Shoppin ...)
NOT-FOR-US: SourceCodester
CVE-2026-15702 (A security vulnerability has been detected in tamagui up to
2.3.0. Thi ...)
- TODO: check
+ NOT-FOR-US: tamagui
CVE-2026-15701 (A weakness has been identified in Totolink NR1800X
9.1.0u.6279_B202109 ...)
NOT-FOR-US: TOTOLINK
CVE-2026-15700 (A security flaw has been discovered in DedeCMS 5.7.118.
Affected by th ...)
NOT-FOR-US: DedeCMS
CVE-2026-15699 (A vulnerability was identified in spencermountain compromise
up to 14. ...)
- TODO: check
+ NOT-FOR-US: spencermountain compromise
CVE-2026-15698 (A vulnerability was determined in kofrasa mingo up to 7.2.1.
This impa ...)
- TODO: check
+ NOT-FOR-US: kofrasa mingo
CVE-2026-15697 (A vulnerability was found in svgdotjs svg.js up to 3.2.5. This
affects ...)
- TODO: check
+ NOT-FOR-US: svgdotjs svg.js
CVE-2026-15696 (A vulnerability has been found in Tenda BE12 Pro 16.03.66.23.
The impa ...)
NOT-FOR-US: Tenda
CVE-2026-15695 (A flaw has been found in Tenda BE12 Pro 16.03.66.23. The
affected elem ...)
@@ -12415,7 +12415,7 @@ CVE-2026-56841 (A malicious actor with access to the
network and low privileges
CVE-2026-56037 (Deserialization of Untrusted Data vulnerability in Themify
Themify Pop ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-56004 (A shellcode injection in the mercurial handler of the obs
tar_scm sour ...)
- TODO: check
+ NOT-FOR-US: obs-service-tar_scm
CVE-2026-55952 (The Erlang/OTP ssl application does not validate that the PSK
identity ...)
- erlang 1:29.0.3+dfsg-1 (bug #1141414)
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55952
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50b5eb4360851ac5455ff3c76a36133bb1023f23
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50b5eb4360851ac5455ff3c76a36133bb1023f23
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits