Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
81f25ecc by Salvatore Bonaccorso at 2026-07-20T21:54:55+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -92,15 +92,15 @@ CVE-2026-63734 (SurrealDB versions before 3.2.0 contain a 
denial of service vuln
 CVE-2026-63733 (SurrealDB versions before 3.2.0 contain a permissions bypass 
vulnerabi ...)
        NOT-FOR-US: SurrealDB
 CVE-2026-63429 (HeyForm is an open-source form builder. Prior to version 
3.0.0-rc.9, ` ...)
-       TODO: check
+       NOT-FOR-US: HeyForm
 CVE-2026-63428 (HeyForm is an open-source form builder. Prior to version 
3.0.0-rc.9, ` ...)
-       TODO: check
+       NOT-FOR-US: HeyForm
 CVE-2026-63108 (Roo Code through 3.54.0 contains a command injection 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Roo Code
 CVE-2026-63107 (LimeSurvey through 6.17.10 and 7.0.4 contains a server-side 
request fo ...)
        TODO: check
 CVE-2026-63102 (rConfig Core before 8.2.8 contains a privilege escalation 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: rConfig
 CVE-2026-63071 (Improper Isolation or Compartmentalization vulnerability in 
Apache Syn ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-62418 (Low-privileged authenticated Server-Side Request Forgery 
(SSRF)  vulne ...)
@@ -126,83 +126,83 @@ CVE-2026-60027 (The Joomla extension Quix Page Builder 
Pro is vulnerable to a un
 CVE-2026-60026 (The Joomla extension Quix Page Builder Pro is vulnerable to an 
authent ...)
        NOT-FOR-US: Joomla
 CVE-2026-59238 (Stored Cross-site Scripting (CWE-79) in the client-side report 
renderi ...)
-       TODO: check
+       NOT-FOR-US: maalfer Pentestify
 CVE-2026-58484 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
-       TODO: check
+       NOT-FOR-US: Network-AI
 CVE-2026-58482 (Network-AI, a TypeScript/Node.js multi-agent orchestrator, has 
a shipp ...)
-       TODO: check
+       NOT-FOR-US: Network-AI
 CVE-2026-58481 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
-       TODO: check
+       NOT-FOR-US: Network-AI
 CVE-2026-58414 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
-       TODO: check
+       NOT-FOR-US: Network-AI
 CVE-2026-58413 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
-       TODO: check
+       NOT-FOR-US: Network-AI
 CVE-2026-57311 (Windu CMS does not validate types of uploaded files. An 
authenticated  ...)
-       TODO: check
+       NOT-FOR-US: Windu CMS
 CVE-2026-57310 (Windu CMS uses hashing algorithm based on MD5 and SHA1 with 
static sal ...)
-       TODO: check
+       NOT-FOR-US: Windu CMS
 CVE-2026-57309 (A Blind SQL injection vulnerability has been identified in 
Windu CMS.  ...)
-       TODO: check
+       NOT-FOR-US: Windu CMS
 CVE-2026-57308 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-54910 (FileBrowser Quantum is a free, self-hosted, web-based file 
manager. Pr ...)
-       TODO: check
+       NOT-FOR-US: FileBrowser Quantum
 CVE-2026-54685 (FileBrowser Quantum is a free, self-hosted, web-based file 
manager. Pr ...)
-       TODO: check
+       NOT-FOR-US: FileBrowser Quantum
 CVE-2026-54051 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
-       TODO: check
+       NOT-FOR-US: Network-AI
 CVE-2026-53421 (Improper Isolation or Compartmentalization vulnerability in 
Apache Syn ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-53405 (Improper Isolation or Compartmentalization vulnerability in 
Apache Syn ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-52349 (Directory Traversal vulnerability in Menyoo 2.0 Versions 
before commit ...)
-       TODO: check
+       NOT-FOR-US: Menyoo
 CVE-2026-51386
        REJECTED
 CVE-2026-51027 (An issue in FileThingie v.2.5.7 allows a remote attacker to 
obtain sen ...)
-       TODO: check
+       NOT-FOR-US: FileThingie
 CVE-2026-51026 (Directory Traversal vulnerability in FileThingie v.2.5.7 
allows a remo ...)
-       TODO: check
+       NOT-FOR-US: FileThingie
 CVE-2026-50743 (A CSRF vulnerability exists in the `zone-include.php` script 
in Revive ...)
-       TODO: check
+       NOT-FOR-US: Revive Adserver
 CVE-2026-48824 (Mailpit is an email testing tool and API for developers. Prior 
to vers ...)
-       TODO: check
+       NOT-FOR-US: Mailpit
 CVE-2026-48812 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
-       TODO: check
+       NOT-FOR-US: FreeScout
 CVE-2026-48389 (DNG SDK versions 1.7.1 2536 and earlier are affected by a 
Stack-based  ...)
        NOT-FOR-US: Adobe
 CVE-2026-47276 (In nanomq versions 0.24.11 and earlier, a NULL pointer 
dereference in  ...)
-       TODO: check
+       NOT-FOR-US: NanoMQ
 CVE-2026-47275 (In nanomq versions 0.24.11 and earlier, a NULL pointer 
dereference in  ...)
-       TODO: check
+       NOT-FOR-US: NanoMQ
 CVE-2026-46715 (Flask-Security-Too allows users to add security features to 
their Flas ...)
-       TODO: check
+       NOT-FOR-US: Flask-Security-Too
 CVE-2026-46701 (Network-AI is a TypeScript/Node.js multi-agent orchestrator. 
Prior to  ...)
-       TODO: check
+       NOT-FOR-US: Network-AI
 CVE-2026-46671 (Rust OneNote File Parser is a parser for Microsoft OneNote 
files imple ...)
        TODO: check
 CVE-2026-46555 (WhatsApp MCP Server is a Model Context Protocol (MCP) server 
for Whats ...)
-       TODO: check
+       NOT-FOR-US: WhatsApp MCP Server
 CVE-2026-46516 (Frogman provides headless FreePBX control. Prior to version 
1.6.6, Fro ...)
-       TODO: check
+       NOT-FOR-US: Frogman
 CVE-2026-46428 (lettre is a a mailer library for Rust. Starting in version 
0.10.1 and  ...)
-       TODO: check
+       NOT-FOR-US: Rust create lettre
 CVE-2026-46415 (The Caddy Defender plugin is a middleware for Caddy that 
allows users  ...)
-       TODO: check
+       NOT-FOR-US: Caddy Defender plugin
 CVE-2026-46412 (@beproduct/nestjs-auth is a NestJS authentication module for 
BeProduct ...)
-       TODO: check
+       NOT-FOR-US: beproduct/nestjs-auth
 CVE-2026-46410 (FileBrowser Quantum is a free, self-hosted, web-based file 
manager. Ve ...)
-       TODO: check
+       NOT-FOR-US: FileBrowser Quantum
 CVE-2026-45797 (HeyForm is an open-source form builder. Prior to version 
3.0.0-rc.7, t ...)
-       TODO: check
+       NOT-FOR-US: HeyForm
 CVE-2026-45713 (Mailpit is an email testing tool and API for developers. Prior 
to vers ...)
-       TODO: check
+       NOT-FOR-US: Mailpit
 CVE-2026-45712 (Mailpit is an email testing tool and API for developers. Prior 
to vers ...)
-       TODO: check
+       NOT-FOR-US: Mailpit
 CVE-2026-45711 (Mailpit is an email testing tool and API for developers. Prior 
to vers ...)
-       TODO: check
+       NOT-FOR-US: Mailpit
 CVE-2026-45709 (Mailpit is an email testing tool and API for developers. The 
fix for G ...)
-       TODO: check
+       NOT-FOR-US: Mailpit
 CVE-2026-45295 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
        TODO: check
 CVE-2026-45270 (CI4MS is a CodeIgniter 4-based content management system 
skeleton. Pri ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81f25eccc156cd46c2bf2d40aceef203f7a89590

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81f25eccc156cd46c2bf2d40aceef203f7a89590
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to