Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f5224ac5 by security tracker role at 2026-07-20T19:14:37+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -19,67 +19,67 @@ CVE-2026-64194 (Net::DNS versions through 1.55 for Perl
allow Denial of Service
CVE-2026-64193 (Net::DNS versions through 1.55 for Perl allow remote execution
injecti ...)
TODO: check
CVE-2026-63763 (SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a
confused dep ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63762 (SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a
denial o ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63761 (SurrealDB before 3.1.0 silently substitutes the ES384
algorithm when a ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63760 (SurrealDB before 3.1.0 fails to enforce the configured
recursion depth ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63759 (SurrealDB before 3.1.0 fails to enforce recursion depth limits
in the ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63758 (SurrealDB versions before 3.1.0 contain an authorization
bypass vulner ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63757 (SurrealDB versions before 3.1.0 contain a session hijacking
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63756 (SurrealDB versions before 3.1.0 contain a
time-of-check/time-of-use ra ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63755 (SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses
in SELECT ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63754 (SurrealDB versions before 3.1.0 contain a denial of service
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63753 (SurrealDB before 3.1.0 fails to refresh authentication state
in LIVE S ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63752 (SurrealDB before 3.1.0 contains an authorization bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63751 (SurrealDB versions before 3.1.0 contain a field-level
permission bypas ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63750 (SurrealDB versions before 3.1.0 fail to apply the
SURREAL_WEBSOCKET_MA ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63749 (SurrealDB versions before 3.1.0 contain an authentication
bypass vulne ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63748 (SurrealDB versions before 3.1.0 contain an information
disclosure vuln ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63747 (SurrealDB versions before 3.1.0 contain a denial of service
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63746 (SurrealDB versions before 3.1.0 fail to enforce table SELECT
permissio ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63745 (SurrealDB versions before 3.1.0 contain an authorization
bypass vulner ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63744 (SurrealDB before 3.1.5 contains a server-side request forgery
vulnerab ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63743 (SurrealDB before 3.1.0 contains a capability bypass
vulnerability in H ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63742 (SurrealDB versions before 3.1.0 contain a field-level SELECT
permissio ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63741 (SurrealDB versions before 3.1.0 fail to validate DEFINE
NAMESPACE or D ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63740 (SurrealDB versions before 3.1.4 fail to properly enforce
SELECT permis ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63739 (SurrealDB before 3.1.5 contains an arbitrary file read
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63738 (SurrealDB versions 3.1.0 before 3.1.5 fail to enforce
field-level SELE ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63737 (SurrealDB versions before 3.1.5 contain a denial of service
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63736 (SurrealDB before 3.2.0 contains a server-side request forgery
vulnerab ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63735 (SurrealDB versions before 3.2.0 fail to validate namespace and
databas ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63734 (SurrealDB versions before 3.2.0 contain a denial of service
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63733 (SurrealDB versions before 3.2.0 contain a permissions bypass
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: SurrealDB
CVE-2026-63429 (HeyForm is an open-source form builder. Prior to version
3.0.0-rc.9, ` ...)
TODO: check
CVE-2026-63428 (HeyForm is an open-source form builder. Prior to version
3.0.0-rc.9, ` ...)
@@ -91,29 +91,29 @@ CVE-2026-63107 (LimeSurvey through 6.17.10 and 7.0.4
contains a server-side requ
CVE-2026-63102 (rConfig Core before 8.2.8 contains a privilege escalation
vulnerabilit ...)
TODO: check
CVE-2026-63071 (Improper Isolation or Compartmentalization vulnerability in
Apache Syn ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-62418 (Low-privileged authenticated Server-Side Request Forgery
(SSRF) vulne ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-62183 (Improper Privilege Management vulnerability in Apache Syncope.
When: ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-60034 (The Joomla extension JMedia is vulnerable to a stored XSS
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-60033 (The Joomla extension JMedia is vulnerable to an SSRF
vulnerability. Re ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-60032 (The Joomla extension JMedia is vulnerable to an authenticated
arbitrar ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-60031 (The Joomla extension Quix Page Builder Pro is vulnerable to an
informa ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-60030 (The Joomla extension Quix Page Builder Pro is vulnerable to an
imprope ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-60029 (The Joomla extension Quix Page Builder Pro is vulnerable to an
authent ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-60028 (The Joomla extension Quix Page Builder Pro is vulnerable to an
authent ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-60027 (The Joomla extension Quix Page Builder Pro is vulnerable to a
unauthen ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-60026 (The Joomla extension Quix Page Builder Pro is vulnerable to an
authent ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-59238 (Stored Cross-site Scripting (CWE-79) in the client-side report
renderi ...)
TODO: check
CVE-2026-58484 (Network-AI is a TypeScript/Node.js multi-agent orchestrator.
Prior to ...)
@@ -133,7 +133,7 @@ CVE-2026-57310 (Windu CMS uses hashing algorithm based on
MD5 and SHA1 with stat
CVE-2026-57309 (A Blind SQL injection vulnerability has been identified in
Windu CMS. ...)
TODO: check
CVE-2026-57308 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-54910 (FileBrowser Quantum is a free, self-hosted, web-based file
manager. Pr ...)
TODO: check
CVE-2026-54685 (FileBrowser Quantum is a free, self-hosted, web-based file
manager. Pr ...)
@@ -141,9 +141,9 @@ CVE-2026-54685 (FileBrowser Quantum is a free, self-hosted,
web-based file manag
CVE-2026-54051 (Network-AI is a TypeScript/Node.js multi-agent orchestrator.
Prior to ...)
TODO: check
CVE-2026-53421 (Improper Isolation or Compartmentalization vulnerability in
Apache Syn ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-53405 (Improper Isolation or Compartmentalization vulnerability in
Apache Syn ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-52349 (Directory Traversal vulnerability in Menyoo 2.0 Versions
before commit ...)
TODO: check
CVE-2026-51386
@@ -159,7 +159,7 @@ CVE-2026-48824 (Mailpit is an email testing tool and API
for developers. Prior t
CVE-2026-48812 (FreeScout is a free help desk and shared inbox built with
PHP's Larave ...)
TODO: check
CVE-2026-48389 (DNG SDK versions 1.7.1 2536 and earlier are affected by a
Stack-based ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-47276 (In nanomq versions 0.24.11 and earlier, a NULL pointer
dereference in ...)
TODO: check
CVE-2026-47275 (In nanomq versions 0.24.11 and earlier, a NULL pointer
dereference in ...)
@@ -207,7 +207,7 @@ CVE-2026-40187 (In egroupware version 26.0 and earlier, an
authenticated adminis
CVE-2026-39879 (Due to a missing sanitization call in
[`afsql_dd_run_query`](https://g ...)
TODO: check
CVE-2026-39878 (Chamilo LMS versions 1.11.38 and earlier contain a stored
cross-site s ...)
- TODO: check
+ NOT-FOR-US: Chamilo LMS
CVE-2026-39385 (Frappe LMS is an open source learning management system. In
version 2. ...)
TODO: check
CVE-2026-35591 (libvips is a fast image processing library with low memory
needs. The ...)
@@ -245,7 +245,7 @@ CVE-2026-32807 (dataCycle is a data management system for
centrally storing, man
CVE-2026-32806 (dataCycle is a data management system for centrally storing,
managing, ...)
TODO: check
CVE-2026-2445 (The affected product accepts user-supplied input within a URL
paramete ...)
- TODO: check
+ NOT-FOR-US: WSO2
CVE-2026-28220 (Wazuh is a free and open source platform used for threat
prevention, d ...)
TODO: check
CVE-2026-27823 (A vulnerability has been identified in EGroupware that may
lead to Rem ...)
@@ -259,7 +259,7 @@ CVE-2026-26197 (HDF5 is a high-performance library and a
file format specificati
CVE-2026-25039 (Parsec is a cloud-based application for simple and
cryptographically s ...)
TODO: check
CVE-2026-21824 (HCL Commerce contains an privilege escalation vulnerability
that could ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-16312
REJECTED
CVE-2026-16277 (A stack-based buffer overflow was found in rpcbind's rpcinfo
utility. ...)
@@ -269,13 +269,13 @@ CVE-2026-16254 (A flaw was found in claircore's apk
package scanner. Malformed p
CVE-2026-16252 (A security flaw has been discovered in Beijing Shenzhou Shihan
Technol ...)
TODO: check
CVE-2026-16248 (A vulnerability was found in Tenda AC10
16.03.10.09_multi_TDE01. This ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-16247 (In _connect.BRAIN versions prior to 5.06, the application
LogPathConfi ...)
- TODO: check
+ NOT-FOR-US: Bizerba
CVE-2026-16246 (In BRAIN2 versions prior to 3.09, the application
LogPathConfig.exe is ...)
- TODO: check
+ NOT-FOR-US: Bizerba
CVE-2026-16244 (A security vulnerability has been detected in itsourcecode
Hospital Ma ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-16242 (A flaw was found in the Konnectivity proxy-server
configuration for ho ...)
TODO: check
CVE-2026-15813 (A vulnerability was found in the network packet
de-fragmentation engin ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f5224ac5a59252d4a5e7b4d77b0b1be5713590e0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f5224ac5a59252d4a5e7b4d77b0b1be5713590e0
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits