Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
50b5eb43 by Salvatore Bonaccorso at 2026-07-20T08:01:29+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18,69 +18,69 @@ CVE-2026-16227 (A security vulnerability has been detected 
in SourceCodester Cla
 CVE-2026-16226 (A weakness has been identified in SourceCodester Pizzafy 
Ecommerce Sys ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-16225 (A security flaw has been discovered in davenardella snap7 up 
to 1.4.3. ...)
-       TODO: check
+       NOT-FOR-US: davenardella snap7
 CVE-2026-16224 (A vulnerability was identified in jxxghp MoviePilot up to 
2.13.5. The  ...)
-       TODO: check
+       NOT-FOR-US: jxxghp MoviePilot
 CVE-2026-16223 (A vulnerability was determined in 1Panel-dev CordysCRM up to 
1.4.1. Im ...)
-       TODO: check
+       NOT-FOR-US: 1Panel-dev CordysCRM
 CVE-2026-16222 (A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. 
This is ...)
-       TODO: check
+       NOT-FOR-US: 1Panel-dev CordysCRM
 CVE-2026-16221 (Impact: fast-uri versions from 2.3.1 through 4.1.0 (including 
the 3.x  ...)
        TODO: check
 CVE-2026-16220 (A vulnerability has been found in code-projects Online 
Examination Sys ...)
        NOT-FOR-US: code-projects
 CVE-2026-16219 (A flaw has been found in Croogo CMS up to 4.0.7. This affects 
the func ...)
-       TODO: check
+       NOT-FOR-US: Croogo CMS
 CVE-2026-16218 (A vulnerability was detected in hunvreus devpush up to 0.4.6. 
Affected ...)
-       TODO: check
+       NOT-FOR-US: hunvreus devpush
 CVE-2026-16217 (A security vulnerability has been detected in guohongze 
adminset up to ...)
-       TODO: check
+       NOT-FOR-US: guohongze adminset
 CVE-2026-16216 (A weakness has been identified in geex-arts django-jet up to 
1.0.8. Af ...)
-       TODO: check
+       NOT-FOR-US: geex-arts django-jet
 CVE-2026-16215 (A security flaw has been discovered in geex-arts django-jet up 
to 1.0. ...)
-       TODO: check
+       NOT-FOR-US: geex-arts django-jet
 CVE-2026-16214 (A vulnerability was identified in geex-arts django-jet up to 
1.0.8. Th ...)
-       TODO: check
+       NOT-FOR-US: geex-arts django-jet
 CVE-2026-16213 (A security flaw has been discovered in Fantomas42 
django-blog-zinnia u ...)
-       TODO: check
+       NOT-FOR-US: Fantomas42 django-blog-zinnia
 CVE-2026-16212 (A vulnerability was identified in awesto django-shop up to 
1.2.4. Affe ...)
-       TODO: check
+       NOT-FOR-US: awesto django-shop
 CVE-2026-16211 (A vulnerability was determined in allegro up to 
bcf65b994ef29fb3fc2e10 ...)
-       TODO: check
+       NOT-FOR-US: allegro
 CVE-2026-16210 (A vulnerability was found in newpanjing simpleui 2026.01.13. 
This affe ...)
-       TODO: check
+       NOT-FOR-US: newpanjing simpleui
 CVE-2026-16209 (A vulnerability has been found in Gerapy up to 0.9.13. The 
impacted el ...)
-       TODO: check
+       NOT-FOR-US: Gerapy
 CVE-2026-16208 (A flaw has been found in django-tastypie up to 0.15.1. The 
affected el ...)
-       TODO: check
+       NOT-FOR-US: django-tastypie
 CVE-2026-16207 (A vulnerability was detected in django-tastypie up to 0.15.1. 
Impacted ...)
-       TODO: check
+       NOT-FOR-US: django-tastypie
 CVE-2026-16206 (A security vulnerability has been detected in django-oauth 
django-oaut ...)
-       TODO: check
+       NOT-FOR-US: django-oauth django-oauth-toolkit
 CVE-2026-16205 (A weakness has been identified in Pluck CMS up to 4.7.21. This 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: Pluck CMS
 CVE-2026-16204 (A security flaw has been discovered in zevorn rt-claw up to 
0.2.0. Thi ...)
-       TODO: check
+       NOT-FOR-US: zevorn rt-claw
 CVE-2026-16203 (A vulnerability was identified in SourceCodester Class and 
Exam Timeta ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-16202 (A vulnerability was determined in SourceCodester Class and 
Exam Timeta ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-16201 (A vulnerability was found in zevorn rt-claw up to 0.2.0. 
Affected is t ...)
-       TODO: check
+       NOT-FOR-US: zevorn rt-claw
 CVE-2026-16200 (A vulnerability has been found in zevorn rt-claw up to 0.2.0. 
This imp ...)
-       TODO: check
+       NOT-FOR-US: zevorn rt-claw
 CVE-2026-16199 (A flaw has been found in nextlevelbuilder GoClaw up to 
3.13.3-beta.3.  ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-16198 (A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. 
The impac ...)
-       TODO: check
+       NOT-FOR-US: Sipeed PicoClaw
 CVE-2026-16197 (A security vulnerability has been detected in Sipeed PicoClaw 
up to 0. ...)
-       TODO: check
+       NOT-FOR-US: Sipeed PicoClaw
 CVE-2026-16196 (A weakness has been identified in Sipeed PicoClaw up to 0.2.9. 
Impacte ...)
-       TODO: check
+       NOT-FOR-US: Sipeed PicoClaw
 CVE-2026-16195 (A security flaw has been discovered in Sipeed PicoClaw up to 
0.2.9. Th ...)
-       TODO: check
+       NOT-FOR-US: Sipeed PicoClaw
 CVE-2026-16194 (A vulnerability was determined in zhayujie CowAgent up to 
2.1.1. This  ...)
-       TODO: check
+       NOT-FOR-US: zhayujie CowAgent
 CVE-2026-16156 (A security flaw has been discovered in SourceCodester Class 
and Exam T ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-16155 (A vulnerability was identified in SourceCodester Class and 
Exam Timeta ...)
@@ -90,9 +90,9 @@ CVE-2026-16154 (A vulnerability was determined in 
SourceCodester Class and Exam
 CVE-2026-16152 (A vulnerability was found in SourceCodester Class and Exam 
Timetabling ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-16151 (A vulnerability has been found in CartoDB carto-api-client 
0.5.29. Thi ...)
-       TODO: check
+       NOT-FOR-US: CartoDB carto-api-client
 CVE-2026-16150 (A vulnerability was found in RobinHerbots Inputmask up to 
5.0.9. Affec ...)
-       TODO: check
+       NOT-FOR-US: RobinHerbots Inputmask
 CVE-2026-12228 (A stored cross-site scripting (XSS) vulnerability exists in 
the `POST  ...)
        TODO: check
 CVE-2026-10130 (QueryWeaver contains an authentication bypass vulnerability 
that allow ...)
@@ -2811,17 +2811,17 @@ CVE-2026-44739 (Pimcore is an Open Source Data & 
Experience Management Platform.
 CVE-2026-43636
        REJECTED
 CVE-2026-42168 (django-pyas2 through 1.2.3 is vulnerable to OS command 
injection via t ...)
-       TODO: check
+       NOT-FOR-US: django-pyas2
 CVE-2026-36669 (An unauthenticated arbitrary file upload vulnerability in 
ck_upload_ha ...)
        NOT-FOR-US: Feng Office
 CVE-2026-16118 (A flaw was found in xdgmime. A heap-based buffer overflow can 
be trigg ...)
        TODO: check
 CVE-2026-16076 (A vulnerability has been found in AstrBotDevs AstrBot up to 
4.25.5. Th ...)
-       TODO: check
+       NOT-FOR-US: AstrBotDevs AstrBot
 CVE-2026-16075 (A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. 
This vulner ...)
-       TODO: check
+       NOT-FOR-US: AstrBotDevs AstrBot
 CVE-2026-16074 (A vulnerability was detected in AstrBotDevs AstrBot up to 
4.25.2. This ...)
-       TODO: check
+       NOT-FOR-US: AstrBotDevs AstrBot
 CVE-2026-15995 (IBM Cognos Analytics 12.1.3 GA Version with build number 
through 12.1. ...)
        NOT-FOR-US: IBM
 CVE-2026-15415 (AWS HealthOmics is a HIPAA-eligible service that fully manages 
the com ...)
@@ -3027,7 +3027,7 @@ CVE-2026-44722 (pyzipper is a replacement for Python's 
zipfile that can read and
        NOTE: 
https://github.com/danifus/pyzipper/security/advisories/GHSA-crqm-m339-7m2p
        NOTE: Fixed by; 
https://github.com/danifus/pyzipper/commit/93ce88e7dfd1635443197dab3fb8d477cff579ae
 (v0.4.0)
 CVE-2026-22104 (Improper access control in Hashtopolis server web-interface 
chunk acti ...)
-       TODO: check
+       NOT-FOR-US: Hashtopolis server
 CVE-2026-21764 (HCL DevOps Loop is affected by insufficient input validation 
that allo ...)
        NOT-FOR-US: HCL
 CVE-2026-21762 (HCL DevOps Loop is affected by missing HTTP security headers. 
Missing  ...)
@@ -3049,23 +3049,23 @@ CVE-2026-16093 (Keycloak provides a mechanism called 
Client Policies to enforce
 CVE-2026-16089 (A flaw was found in the keycloak-services component of Red Hat 
Build o ...)
        TODO: check
 CVE-2026-16073 (A security vulnerability has been detected in AstrBotDevs 
AstrBot up t ...)
-       TODO: check
+       NOT-FOR-US: AstrBotDevs AstrBot
 CVE-2026-16072 (A flaw was found in the organization management component of 
Keycloak. ...)
        TODO: check
 CVE-2026-16017 (A security flaw has been discovered in mosaxiv clawlet up to 
0.2.10. I ...)
-       TODO: check
+       NOT-FOR-US: mosaxiv clawlet
 CVE-2026-16016 (A vulnerability was identified in poco-ai poco-claw up to 
0.5.4. This  ...)
-       TODO: check
+       NOT-FOR-US: poco-ai poco-claw
 CVE-2026-16015 (A vulnerability was determined in poco-ai poco-claw up to 
0.5.4. This  ...)
-       TODO: check
+       NOT-FOR-US: poco-ai poco-claw
 CVE-2026-16014 (A vulnerability was found in code-projects Hospital Bed 
Management Sys ...)
        NOT-FOR-US: code-projects
 CVE-2026-16013 (A vulnerability has been found in liftoff-sr CIPster up to 
632336d414e ...)
-       TODO: check
+       NOT-FOR-US: liftoff-sr CIPster
 CVE-2026-16009 (A vulnerability was detected in itsourcecode Hospital 
Management Syste ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-16008 (A security vulnerability has been detected in sagold 
json-schema-libra ...)
-       TODO: check
+       NOT-FOR-US: sagold json-schema-library
 CVE-2026-15943 (A flaw was found in the Keycloak keycloak-services component, 
which ha ...)
        TODO: check
 CVE-2026-15783 (A missing authorization vulnerability was identified in GitHub 
Enterpr ...)
@@ -3525,11 +3525,11 @@ CVE-2026-44433 (Quicly is an IETF QUIC protocol 
implementation intended primaril
 CVE-2026-44251 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
        NOT-FOR-US: Wazuh
 CVE-2026-44182 (Jupyter Enterprise Gateway launches remote Jupyter Notebook 
kernels ac ...)
-       TODO: check
+       NOT-FOR-US: Jupyter Enterprise Gateway
 CVE-2026-44181 (Jupyter Enterprise Gateway launches remote Jupyter Notebook 
kernels ac ...)
-       TODO: check
+       NOT-FOR-US: Jupyter Enterprise Gateway
 CVE-2026-44180 (Jupyter Enterprise Gateway launches remote Jupyter Notebook 
kernels ac ...)
-       TODO: check
+       NOT-FOR-US: Jupyter Enterprise Gateway
 CVE-2026-44177 (Kirby is an open-source content management system. In versions 
5.3.0 a ...)
        NOT-FOR-US: Kirby CMS
 CVE-2026-44176 (Kirby is an open-source content management system. Versions 
prior to 4 ...)
@@ -3937,25 +3937,25 @@ CVE-2026-33444 (CVE-2026-33444 is a memory management 
vulnerability in Secure Ac
 CVE-2026-33443 (CVE-2026-33443 is a memory management error in Secure Access 
servers p ...)
        NOT-FOR-US: Absolute Software
 CVE-2026-30623 (LiteLLM 1.18.10 contains a remote code execution vulnerability 
in its  ...)
-       TODO: check
+       NOT-FOR-US: LiteLLM
 CVE-2026-30618 (xszyou Fay 4.3.1 contains a remote code execution 
vulnerability in its ...)
-       TODO: check
+       NOT-FOR-US: xszyou Fay
 CVE-2026-26719 (Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 
allows a r ...)
-       TODO: check
+       NOT-FOR-US: xxl-job-admin
 CVE-2026-26718 (A Cross-Site Request Forgery (CSRF) vulnerability exists in 
the xxl-jo ...)
-       TODO: check
+       NOT-FOR-US: xxl-job-admin
 CVE-2026-26032 (The PackagerResolver of Apache Ivy is able to download online 
artifact ...)
        TODO: check
 CVE-2026-21729 (Loki queries with large limits can cause large memory 
allocations whic ...)
-       TODO: check
+       NOT-FOR-US: Grafana Loki
 CVE-2026-15925 (Improper TLS hostname verification in Snowflake Connector for 
Python v ...)
-       TODO: check
+       NOT-FOR-US: Snowflake Connector for Python
 CVE-2026-15921 (Node Version Manager (nvm) is a POSIX-compliant shell function 
for man ...)
        TODO: check
 CVE-2026-15909 (A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up 
to ddfe1 ...)
-       TODO: check
+       NOT-FOR-US: RafyMrX TOKO-ONLINE-ROTI
 CVE-2026-15907 (A flaw has been found in H3C SecPath F1000-C8300 up to 
20260522. This  ...)
-       TODO: check
+       NOT-FOR-US: H3C
 CVE-2026-15895 (OS command injection in the npm package loading component in 
AWS jsii- ...)
        NOT-FOR-US: Amazon
 CVE-2026-15652 (The Easy Accordion \u2013 AI-Powered FAQ & Accordion Blocks, 
Product F ...)
@@ -4426,21 +4426,21 @@ CVE-2026-20153 (As part of Cisco's ongoing commitment 
to proactive security and
 CVE-2026-20150 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        NOT-FOR-US: Cisco
 CVE-2026-20146 (A vulnerability in Cisco Identity Services Engine (ISE) and 
Cisco ISE  ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-1563 (Pega Platform versions 8.1.0 through 25.1.2 are affected by an 
Reflect ...)
-       TODO: check
+       NOT-FOR-US: Pega Platform
 CVE-2026-1562 (Pega Platform versions 8.1.0 through 25.1.2 are affected by an 
Stored  ...)
-       TODO: check
+       NOT-FOR-US: Pega Platform
 CVE-2026-15809 (A flaw was found in CRI-O. The fix for a previous 
vulnerability (CVE-2 ...)
        TODO: check
 CVE-2026-15804 (The HCM developed by MetaGuru has a SQL Injection 
vulnerability. Authe ...)
-       TODO: check
+       NOT-FOR-US: MetaGuru
 CVE-2026-15779 (A flaw was found in samba's pam_winbind. When mkhomedir is 
enabled, pa ...)
        TODO: check
 CVE-2026-15746 (Strands Agents is an open-source Python SDK for building and 
running A ...)
        NOT-FOR-US: Amazon
 CVE-2026-15583 (A confused-deputy flaw in Grafana MCP Server allows an 
unauthenticated ...)
-       TODO: check
+       NOT-FOR-US: Grafana MCP Server
 CVE-2026-14961 (Pegatron `Tdelo64.sys` exposes a privileged device interface, 
`\\.\Tde ...)
        TODO: check
 CVE-2026-14960 (Pegatron `Tdelo64.sys` improperly exposes privileged hardware 
access f ...)
@@ -6183,7 +6183,7 @@ CVE-2026-40400 (Relative path traversal in Windows 
PowerShell allows an authoriz
 CVE-2026-40378 (Memory allocation with excessive size value in Windows Local 
Security  ...)
        NOT-FOR-US: Microsoft
 CVE-2026-3014 (Milestone has released a new version of XProtect\xae (and 
several cumu ...)
-       TODO: check
+       NOT-FOR-US: Milestone XProtect
 CVE-2026-38450 (An issue in Aetopia Digital Asset Management DAM v.1.0.0 
allows a remo ...)
        NOT-FOR-US: Aetopia Digital Asset Management DAM
 CVE-2026-36214 (osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 
1.18.3  ...)
@@ -6289,19 +6289,19 @@ CVE-2026-15764 (Use after free in Ozone in Google 
Chrome on Linux prior to 150.0
 CVE-2026-15757 (A security flaw was discovered in the NETGEAR DGND3700v1 that 
could al ...)
        NOT-FOR-US: Netgear
 CVE-2026-15753 (A vulnerability was determined in zhinianboke 
xianyu-auto-reply on Ser ...)
-       TODO: check
+       NOT-FOR-US: zhinianboke xianyu-auto-reply
 CVE-2026-15752 (A vulnerability was found in zhinianboke xianyu-auto-reply up 
to dcb44 ...)
-       TODO: check
+       NOT-FOR-US: zhinianboke xianyu-auto-reply
 CVE-2026-15751 (A security vulnerability has been detected in mastergo-design 
mastergo ...)
-       TODO: check
+       NOT-FOR-US: mastergo-design mastergo-magic-mcp
 CVE-2026-15750 (A weakness has been identified in mastergo-design 
mastergo-magic-mcp u ...)
-       TODO: check
+       NOT-FOR-US: mastergo-design mastergo-magic-mcp
 CVE-2026-15749 (A security flaw has been discovered in mastergo-design 
mastergo-magic- ...)
-       TODO: check
+       NOT-FOR-US: mastergo-design mastergo-magic-mcp
 CVE-2026-15738 (Incorrect behavior order in the Gateway API listener-rule 
generation i ...)
        NOT-FOR-US: Amazon
 CVE-2026-15736 (Snowflake SQLAlchemy versions prior to 1.11.0 contain several 
security ...)
-       TODO: check
+       NOT-FOR-US: Snowflake SQLAlchemy
 CVE-2026-15720 (InOpen5GS through version 2.7.7 a pre-authenticationheap 
out-of-bounds ...)
        TODO: check
 CVE-2026-15715 (A vulnerability was identified in SourceCodester Class and 
Exam Timeta ...)
@@ -6319,17 +6319,17 @@ CVE-2026-15709 (A flaw was found in libsoup's WebSocket 
implementation when usin
 CVE-2026-15703 (A vulnerability was detected in SourceCodester Simple and Nice 
Shoppin ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-15702 (A security vulnerability has been detected in tamagui up to 
2.3.0. Thi ...)
-       TODO: check
+       NOT-FOR-US: tamagui
 CVE-2026-15701 (A weakness has been identified in Totolink NR1800X 
9.1.0u.6279_B202109 ...)
        NOT-FOR-US: TOTOLINK
 CVE-2026-15700 (A security flaw has been discovered in DedeCMS 5.7.118. 
Affected by th ...)
        NOT-FOR-US: DedeCMS
 CVE-2026-15699 (A vulnerability was identified in spencermountain compromise 
up to 14. ...)
-       TODO: check
+       NOT-FOR-US: spencermountain compromise
 CVE-2026-15698 (A vulnerability was determined in kofrasa mingo up to 7.2.1. 
This impa ...)
-       TODO: check
+       NOT-FOR-US: kofrasa mingo
 CVE-2026-15697 (A vulnerability was found in svgdotjs svg.js up to 3.2.5. This 
affects ...)
-       TODO: check
+       NOT-FOR-US: svgdotjs svg.js
 CVE-2026-15696 (A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. 
The impa ...)
        NOT-FOR-US: Tenda
 CVE-2026-15695 (A flaw has been found in Tenda BE12 Pro 16.03.66.23. The 
affected elem ...)
@@ -12415,7 +12415,7 @@ CVE-2026-56841 (A malicious actor with access to the 
network and low privileges
 CVE-2026-56037 (Deserialization of Untrusted Data vulnerability in Themify 
Themify Pop ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-56004 (A shellcode injection in the mercurial handler of the obs 
tar_scm sour ...)
-       TODO: check
+       NOT-FOR-US: obs-service-tar_scm
 CVE-2026-55952 (The Erlang/OTP ssl application does not validate that the PSK 
identity ...)
        - erlang 1:29.0.3+dfsg-1 (bug #1141414)
        NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55952



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50b5eb4360851ac5455ff3c76a36133bb1023f23

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50b5eb4360851ac5455ff3c76a36133bb1023f23
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to