Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a430a260 by Salvatore Bonaccorso at 2026-07-20T09:44:32+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -6,11 +6,11 @@ CVE-2026-6656 (Crypt::Password versions through 0.28 for Perl
are susceptible to
- libcrypt-password-perl <unfixed>
NOTE: https://rt.cpan.org/Ticket/Display.html?id=180162
CVE-2026-45138 (CI4MS is a CodeIgniter 4-based content management system
skeleton. Pri ...)
- TODO: check
+ NOT-FOR-US: CI4MS
CVE-2026-44359 (Meshtastic is an open source mesh networking solution. Prior
to versio ...)
- TODO: check
+ NOT-FOR-US: Meshtastic
CVE-2026-42566 (Meshtastic is an open source mesh networking solution. Prior
to versio ...)
- TODO: check
+ NOT-FOR-US: Meshtastic
CVE-2026-16235 (Crypt::Password versions through 0.28 for Perl generate
insecure rando ...)
- libcrypt-password-perl <unfixed>
CVE-2026-13432 (The ThumbPress WordPress plugin before 6.2.2 does not perform
a capab ...)
@@ -3147,7 +3147,7 @@ CVE-2026-15343 (A path traversal vulnerability was
identified in GitHub Enterpri
CVE-2026-15007 (A denial of service vulnerability was identified in GitHub
Enterprise ...)
NOT-FOR-US: Github Enterprise Server
CVE-2026-14871 (osTicket versions v1.18.3 and v1.17.7 contain a Broken Object
Level Au ...)
- TODO: check
+ NOT-FOR-US: osTicket
CVE-2026-13410 (Dancer::Plugin::Auth::Google versions through 0.07 for Perl
have TLS v ...)
NOT-FOR-US: Dancer::Plugin::Auth::Google Perl module
CVE-2026-13082 (GD::SecurityImage versions through 1.75 for Perl use rand to
generate ...)
@@ -3677,15 +3677,15 @@ CVE-2026-15610 (The WPBot \u2013 AI ChatBot for Live
Support, Lead Generation, A
CVE-2026-15457 (The Kirki \u2013 Freeform Page Builder, Website Builder &
Customizer p ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15449 (A time-of-check to time-of-use (TOCTOU) flaw in the illumos
data-link ...)
- TODO: check
+ NOT-FOR-US: Illumos
CVE-2026-15422 (The illumos SCTP inbound path performs association lookup for
INIT ACK ...)
- TODO: check
+ NOT-FOR-US: Illumos
CVE-2026-15407 (The Themify Builder plugin for WordPress is vulnerable to
authorizatio ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15395 (The Kali Forms \u2014 Contact Form & Drag-and-Drop Builder
plugin for ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15352 (A vulnerability exists in the Health & Safety (HS) application
of NASA ...)
- TODO: check
+ NOT-FOR-US: NASA Health & Safety (HS) application
CVE-2026-15350 (The The Cache Purger plugin for WordPress is vulnerable to
authorizati ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15349 (The ERP: Complete HR, Accounting & CRM Suite Built for
WooCommerce plu ...)
@@ -3717,7 +3717,7 @@ CVE-2026-15005 (The Loco Translate plugin for WordPress
is vulnerable to Cross-S
CVE-2026-14956 (The Bricksforge plugin for WordPress is vulnerable to
Privilege Escala ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14890 (SGLang uses an expert-parallel backup subsystem that exposes a
ZeroMQ ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-14782 (The Booking for Appointments and Events Calendar \u2013 Amelia
plugin ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14503 (The pCloud WP Backup plugin for WordPress is vulnerable to
Sensitive I ...)
@@ -3725,7 +3725,7 @@ CVE-2026-14503 (The pCloud WP Backup plugin for WordPress
is vulnerable to Sensi
CVE-2026-14371 (The Lenovo XClarity Integrator for Windows Admin Center plugin
version ...)
NOT-FOR-US: Lenovo
CVE-2026-14254 (A race condition in the account lockout mechanism
inDelphixContinousDa ...)
- TODO: check
+ NOT-FOR-US: Delphix
CVE-2026-14253
REJECTED
CVE-2026-13767 (The Quiz Master Next plugin for WordPress is vulnerable to SQL
Injecti ...)
@@ -4517,9 +4517,9 @@ CVE-2026-15746 (Strands Agents is an open-source Python
SDK for building and run
CVE-2026-15583 (A confused-deputy flaw in Grafana MCP Server allows an
unauthenticated ...)
NOT-FOR-US: Grafana MCP Server
CVE-2026-14961 (Pegatron `Tdelo64.sys` exposes a privileged device interface,
`\\.\Tde ...)
- TODO: check
+ NOT-FOR-US: Pegatron
CVE-2026-14960 (Pegatron `Tdelo64.sys` improperly exposes privileged hardware
access f ...)
- TODO: check
+ NOT-FOR-US: Pegatron
CVE-2026-14251 (A flaw was found in the OpenShift GitOps operator. The
ClusterRole rec ...)
NOT-FOR-US: Argo CD
CVE-2026-12997 (The Gravity Forms plugin for WordPress is vulnerable to
Directory Trav ...)
@@ -6444,9 +6444,9 @@ CVE-2026-15389 (A vulnerability relating to insufficient
access control has been
CVE-2026-15305 (Users were able to upload files with arbitrary MIME types to
forms usi ...)
NOT-FOR-US: TYPO3 (core or extensions)
CVE-2026-15265 (A path traversal vulnerability in Tenable Agent 11.2.0 and
11.1.3 and ...)
- TODO: check
+ NOT-FOR-US: Tenable Agent
CVE-2026-15183 (Multiple input validation vulnerabilities in the Snowflake
Spark Conne ...)
- TODO: check
+ NOT-FOR-US: Snowflake Spark Connector
CVE-2026-15076 (In versions up to and including 4.5.29 (4.x branch) and 5.1.4
(5.x bra ...)
NOT-FOR-US: Eclipse
CVE-2026-15075 (In Eclipse Vert.x versions up to and including 4.5.29 (4.x
branch) and ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a430a260264b388ea81b5125aa930842b0b4618f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a430a260264b388ea81b5125aa930842b0b4618f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits