Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
81f25ecc by Salvatore Bonaccorso at 2026-07-20T21:54:55+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -92,15 +92,15 @@ CVE-2026-63734 (SurrealDB versions before 3.2.0 contain a
denial of service vuln
CVE-2026-63733 (SurrealDB versions before 3.2.0 contain a permissions bypass
vulnerabi ...)
NOT-FOR-US: SurrealDB
CVE-2026-63429 (HeyForm is an open-source form builder. Prior to version
3.0.0-rc.9, ` ...)
- TODO: check
+ NOT-FOR-US: HeyForm
CVE-2026-63428 (HeyForm is an open-source form builder. Prior to version
3.0.0-rc.9, ` ...)
- TODO: check
+ NOT-FOR-US: HeyForm
CVE-2026-63108 (Roo Code through 3.54.0 contains a command injection
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Roo Code
CVE-2026-63107 (LimeSurvey through 6.17.10 and 7.0.4 contains a server-side
request fo ...)
TODO: check
CVE-2026-63102 (rConfig Core before 8.2.8 contains a privilege escalation
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: rConfig
CVE-2026-63071 (Improper Isolation or Compartmentalization vulnerability in
Apache Syn ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-62418 (Low-privileged authenticated Server-Side Request Forgery
(SSRF) vulne ...)
@@ -126,83 +126,83 @@ CVE-2026-60027 (The Joomla extension Quix Page Builder
Pro is vulnerable to a un
CVE-2026-60026 (The Joomla extension Quix Page Builder Pro is vulnerable to an
authent ...)
NOT-FOR-US: Joomla
CVE-2026-59238 (Stored Cross-site Scripting (CWE-79) in the client-side report
renderi ...)
- TODO: check
+ NOT-FOR-US: maalfer Pentestify
CVE-2026-58484 (Network-AI is a TypeScript/Node.js multi-agent orchestrator.
Prior to ...)
- TODO: check
+ NOT-FOR-US: Network-AI
CVE-2026-58482 (Network-AI, a TypeScript/Node.js multi-agent orchestrator, has
a shipp ...)
- TODO: check
+ NOT-FOR-US: Network-AI
CVE-2026-58481 (Network-AI is a TypeScript/Node.js multi-agent orchestrator.
Prior to ...)
- TODO: check
+ NOT-FOR-US: Network-AI
CVE-2026-58414 (Network-AI is a TypeScript/Node.js multi-agent orchestrator.
Prior to ...)
- TODO: check
+ NOT-FOR-US: Network-AI
CVE-2026-58413 (Network-AI is a TypeScript/Node.js multi-agent orchestrator.
Prior to ...)
- TODO: check
+ NOT-FOR-US: Network-AI
CVE-2026-57311 (Windu CMS does not validate types of uploaded files. An
authenticated ...)
- TODO: check
+ NOT-FOR-US: Windu CMS
CVE-2026-57310 (Windu CMS uses hashing algorithm based on MD5 and SHA1 with
static sal ...)
- TODO: check
+ NOT-FOR-US: Windu CMS
CVE-2026-57309 (A Blind SQL injection vulnerability has been identified in
Windu CMS. ...)
- TODO: check
+ NOT-FOR-US: Windu CMS
CVE-2026-57308 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-54910 (FileBrowser Quantum is a free, self-hosted, web-based file
manager. Pr ...)
- TODO: check
+ NOT-FOR-US: FileBrowser Quantum
CVE-2026-54685 (FileBrowser Quantum is a free, self-hosted, web-based file
manager. Pr ...)
- TODO: check
+ NOT-FOR-US: FileBrowser Quantum
CVE-2026-54051 (Network-AI is a TypeScript/Node.js multi-agent orchestrator.
Prior to ...)
- TODO: check
+ NOT-FOR-US: Network-AI
CVE-2026-53421 (Improper Isolation or Compartmentalization vulnerability in
Apache Syn ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-53405 (Improper Isolation or Compartmentalization vulnerability in
Apache Syn ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-52349 (Directory Traversal vulnerability in Menyoo 2.0 Versions
before commit ...)
- TODO: check
+ NOT-FOR-US: Menyoo
CVE-2026-51386
REJECTED
CVE-2026-51027 (An issue in FileThingie v.2.5.7 allows a remote attacker to
obtain sen ...)
- TODO: check
+ NOT-FOR-US: FileThingie
CVE-2026-51026 (Directory Traversal vulnerability in FileThingie v.2.5.7
allows a remo ...)
- TODO: check
+ NOT-FOR-US: FileThingie
CVE-2026-50743 (A CSRF vulnerability exists in the `zone-include.php` script
in Revive ...)
- TODO: check
+ NOT-FOR-US: Revive Adserver
CVE-2026-48824 (Mailpit is an email testing tool and API for developers. Prior
to vers ...)
- TODO: check
+ NOT-FOR-US: Mailpit
CVE-2026-48812 (FreeScout is a free help desk and shared inbox built with
PHP's Larave ...)
- TODO: check
+ NOT-FOR-US: FreeScout
CVE-2026-48389 (DNG SDK versions 1.7.1 2536 and earlier are affected by a
Stack-based ...)
NOT-FOR-US: Adobe
CVE-2026-47276 (In nanomq versions 0.24.11 and earlier, a NULL pointer
dereference in ...)
- TODO: check
+ NOT-FOR-US: NanoMQ
CVE-2026-47275 (In nanomq versions 0.24.11 and earlier, a NULL pointer
dereference in ...)
- TODO: check
+ NOT-FOR-US: NanoMQ
CVE-2026-46715 (Flask-Security-Too allows users to add security features to
their Flas ...)
- TODO: check
+ NOT-FOR-US: Flask-Security-Too
CVE-2026-46701 (Network-AI is a TypeScript/Node.js multi-agent orchestrator.
Prior to ...)
- TODO: check
+ NOT-FOR-US: Network-AI
CVE-2026-46671 (Rust OneNote File Parser is a parser for Microsoft OneNote
files imple ...)
TODO: check
CVE-2026-46555 (WhatsApp MCP Server is a Model Context Protocol (MCP) server
for Whats ...)
- TODO: check
+ NOT-FOR-US: WhatsApp MCP Server
CVE-2026-46516 (Frogman provides headless FreePBX control. Prior to version
1.6.6, Fro ...)
- TODO: check
+ NOT-FOR-US: Frogman
CVE-2026-46428 (lettre is a a mailer library for Rust. Starting in version
0.10.1 and ...)
- TODO: check
+ NOT-FOR-US: Rust create lettre
CVE-2026-46415 (The Caddy Defender plugin is a middleware for Caddy that
allows users ...)
- TODO: check
+ NOT-FOR-US: Caddy Defender plugin
CVE-2026-46412 (@beproduct/nestjs-auth is a NestJS authentication module for
BeProduct ...)
- TODO: check
+ NOT-FOR-US: beproduct/nestjs-auth
CVE-2026-46410 (FileBrowser Quantum is a free, self-hosted, web-based file
manager. Ve ...)
- TODO: check
+ NOT-FOR-US: FileBrowser Quantum
CVE-2026-45797 (HeyForm is an open-source form builder. Prior to version
3.0.0-rc.7, t ...)
- TODO: check
+ NOT-FOR-US: HeyForm
CVE-2026-45713 (Mailpit is an email testing tool and API for developers. Prior
to vers ...)
- TODO: check
+ NOT-FOR-US: Mailpit
CVE-2026-45712 (Mailpit is an email testing tool and API for developers. Prior
to vers ...)
- TODO: check
+ NOT-FOR-US: Mailpit
CVE-2026-45711 (Mailpit is an email testing tool and API for developers. Prior
to vers ...)
- TODO: check
+ NOT-FOR-US: Mailpit
CVE-2026-45709 (Mailpit is an email testing tool and API for developers. The
fix for G ...)
- TODO: check
+ NOT-FOR-US: Mailpit
CVE-2026-45295 (FreeScout is a free help desk and shared inbox built with
PHP's Larave ...)
TODO: check
CVE-2026-45270 (CI4MS is a CodeIgniter 4-based content management system
skeleton. Pri ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81f25eccc156cd46c2bf2d40aceef203f7a89590
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81f25eccc156cd46c2bf2d40aceef203f7a89590
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits