Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a430a260 by Salvatore Bonaccorso at 2026-07-20T09:44:32+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6,11 +6,11 @@ CVE-2026-6656 (Crypt::Password versions through 0.28 for Perl 
are susceptible to
        - libcrypt-password-perl <unfixed>
        NOTE: https://rt.cpan.org/Ticket/Display.html?id=180162
 CVE-2026-45138 (CI4MS is a CodeIgniter 4-based content management system 
skeleton. Pri ...)
-       TODO: check
+       NOT-FOR-US: CI4MS
 CVE-2026-44359 (Meshtastic is an open source mesh networking solution. Prior 
to versio ...)
-       TODO: check
+       NOT-FOR-US: Meshtastic
 CVE-2026-42566 (Meshtastic is an open source mesh networking solution. Prior 
to versio ...)
-       TODO: check
+       NOT-FOR-US: Meshtastic
 CVE-2026-16235 (Crypt::Password versions through 0.28 for Perl generate 
insecure rando ...)
        - libcrypt-password-perl <unfixed>
 CVE-2026-13432 (The ThumbPress  WordPress plugin before 6.2.2 does not perform 
a capab ...)
@@ -3147,7 +3147,7 @@ CVE-2026-15343 (A path traversal vulnerability was 
identified in GitHub Enterpri
 CVE-2026-15007 (A denial of service vulnerability was identified in GitHub 
Enterprise  ...)
        NOT-FOR-US: Github Enterprise Server
 CVE-2026-14871 (osTicket versions v1.18.3 and v1.17.7 contain a Broken Object 
Level Au ...)
-       TODO: check
+       NOT-FOR-US: osTicket
 CVE-2026-13410 (Dancer::Plugin::Auth::Google versions through 0.07 for Perl 
have TLS v ...)
        NOT-FOR-US: Dancer::Plugin::Auth::Google Perl module
 CVE-2026-13082 (GD::SecurityImage versions through 1.75 for Perl use rand to 
generate  ...)
@@ -3677,15 +3677,15 @@ CVE-2026-15610 (The WPBot \u2013 AI ChatBot for Live 
Support, Lead Generation, A
 CVE-2026-15457 (The Kirki \u2013 Freeform Page Builder, Website Builder & 
Customizer p ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15449 (A time-of-check to time-of-use (TOCTOU) flaw in the illumos 
data-link  ...)
-       TODO: check
+       NOT-FOR-US: Illumos
 CVE-2026-15422 (The illumos SCTP inbound path performs association lookup for 
INIT ACK ...)
-       TODO: check
+       NOT-FOR-US: Illumos
 CVE-2026-15407 (The Themify Builder plugin for WordPress is vulnerable to 
authorizatio ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15395 (The Kali Forms \u2014 Contact Form & Drag-and-Drop Builder 
plugin for  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15352 (A vulnerability exists in the Health & Safety (HS) application 
of NASA ...)
-       TODO: check
+       NOT-FOR-US: NASA Health & Safety (HS) application
 CVE-2026-15350 (The The Cache Purger plugin for WordPress is vulnerable to 
authorizati ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15349 (The ERP: Complete HR, Accounting & CRM Suite Built for 
WooCommerce plu ...)
@@ -3717,7 +3717,7 @@ CVE-2026-15005 (The Loco Translate plugin for WordPress 
is vulnerable to Cross-S
 CVE-2026-14956 (The Bricksforge plugin for WordPress is vulnerable to 
Privilege Escala ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14890 (SGLang uses an expert-parallel backup subsystem that exposes a 
ZeroMQ  ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-14782 (The Booking for Appointments and Events Calendar \u2013 Amelia 
plugin  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14503 (The pCloud WP Backup plugin for WordPress is vulnerable to 
Sensitive I ...)
@@ -3725,7 +3725,7 @@ CVE-2026-14503 (The pCloud WP Backup plugin for WordPress 
is vulnerable to Sensi
 CVE-2026-14371 (The Lenovo XClarity Integrator for Windows Admin Center plugin 
version ...)
        NOT-FOR-US: Lenovo
 CVE-2026-14254 (A race condition in the account lockout mechanism 
inDelphixContinousDa ...)
-       TODO: check
+       NOT-FOR-US: Delphix
 CVE-2026-14253
        REJECTED
 CVE-2026-13767 (The Quiz Master Next plugin for WordPress is vulnerable to SQL 
Injecti ...)
@@ -4517,9 +4517,9 @@ CVE-2026-15746 (Strands Agents is an open-source Python 
SDK for building and run
 CVE-2026-15583 (A confused-deputy flaw in Grafana MCP Server allows an 
unauthenticated ...)
        NOT-FOR-US: Grafana MCP Server
 CVE-2026-14961 (Pegatron `Tdelo64.sys` exposes a privileged device interface, 
`\\.\Tde ...)
-       TODO: check
+       NOT-FOR-US: Pegatron
 CVE-2026-14960 (Pegatron `Tdelo64.sys` improperly exposes privileged hardware 
access f ...)
-       TODO: check
+       NOT-FOR-US: Pegatron
 CVE-2026-14251 (A flaw was found in the OpenShift GitOps operator. The 
ClusterRole rec ...)
        NOT-FOR-US: Argo CD
 CVE-2026-12997 (The Gravity Forms plugin for WordPress is vulnerable to 
Directory Trav ...)
@@ -6444,9 +6444,9 @@ CVE-2026-15389 (A vulnerability relating to insufficient 
access control has been
 CVE-2026-15305 (Users were able to upload files with arbitrary MIME types to 
forms usi ...)
        NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-15265 (A path traversal vulnerability in Tenable Agent 11.2.0 and 
11.1.3 and  ...)
-       TODO: check
+       NOT-FOR-US: Tenable Agent
 CVE-2026-15183 (Multiple input validation vulnerabilities in the Snowflake 
Spark Conne ...)
-       TODO: check
+       NOT-FOR-US: Snowflake Spark Connector
 CVE-2026-15076 (In versions up to and including 4.5.29 (4.x branch) and 5.1.4 
(5.x bra ...)
        NOT-FOR-US: Eclipse
 CVE-2026-15075 (In Eclipse Vert.x versions up to and including 4.5.29 (4.x 
branch) and ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a430a260264b388ea81b5125aa930842b0b4618f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a430a260264b388ea81b5125aa930842b0b4618f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to