Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e09d1a92 by Salvatore Bonaccorso at 2026-07-21T09:48:34+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,37 +3,37 @@ CVE-2026-8082 (The bpost-shipping-platform WordPress plugin 
before 3.2.3 does no
 CVE-2026-6952 (A post-authentication command injection vulnerability in the 
"LogServe ...)
        NOT-FOR-US: Zyxel
 CVE-2026-64651 (The `@ai-sdk/harness-opencode` tool connects HarnessAgent to 
OpenCode  ...)
-       TODO: check
+       NOT-FOR-US: ai-sdk/harness-opencode
 CVE-2026-64650 (The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter 
backed by  ...)
-       TODO: check
+       NOT-FOR-US: ai-sdk/harness-opencode
 CVE-2026-64626 (AVideo versions from commit 0dbadbca through latest master 
contain a s ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-64625 (AVideo before 29.0 contains an incomplete fix for 
CVE-2026-45578 where ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-64624 (FreeRDP before 3.28.0 treats lines beginning with forward 
slash in RDP ...)
        TODO: check
 CVE-2026-64619 (FileCodeBox before 2.4 contains a rate-limit bypass 
vulnerability in t ...)
-       TODO: check
+       NOT-FOR-US: FileCodeBox
 CVE-2026-63771 (Adminer before 5.4.3 contains a cookie injection vulnerability 
that al ...)
        TODO: check
 CVE-2026-63770 (Glance through 0.8.5 contains an IP address spoofing 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Glance (not same as src:glance)
 CVE-2026-63769 (Huginn through 2022.08.18 contains a server-side request 
forgery vulne ...)
-       TODO: check
+       NOT-FOR-US: Huginn
 CVE-2026-63768 (cal.diy through 6.2.0 contains an open redirect vulnerability 
in the c ...)
-       TODO: check
+       NOT-FOR-US: cal.diy
 CVE-2026-63767 (ktransformers through 0.6.3, fixed in commit def0f93, contains 
an unau ...)
-       TODO: check
+       NOT-FOR-US: ktransformers
 CVE-2026-63766 (GPT-SoVITS through 20250606v2pro contains an OS command 
injection vuln ...)
-       TODO: check
+       NOT-FOR-US: GPT-SoVITS
 CVE-2026-63731 (HyperDX before 2.31.0 contains a server-side request forgery 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: HyperDX
 CVE-2026-63730 (HyperDX before 2.31.0 contains a server-side request forgery 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: HyperDX
 CVE-2026-63729 (The SyncTeX parser (synctex_parser.c) shipped with TeX Live 
and embedd ...)
        TODO: check
 CVE-2026-63728 (Gitleaks prior to 8.30.1 contains a template injection 
vulnerability t ...)
-       TODO: check
+       NOT-FOR-US: Gitleaks
 CVE-2026-62414 (The Joomla extension Page Builder CK does not properly apply 
access co ...)
        NOT-FOR-US: Joomla
 CVE-2026-61901 (The Joomla extension Hikashop is vulnerable to an open 
redirect.)
@@ -45,65 +45,65 @@ CVE-2026-61425 (The Joomla extension Gridbox is vulnerable 
an authenticated bypa
 CVE-2026-61424 (The Joomla extension DJ-Classifieds is vulnerable to an 
unauthenticate ...)
        NOT-FOR-US: Joomla
 CVE-2026-59776 (Missing Cryptographic Step (CWE-325) vulnerability exists in 
certain F ...)
-       TODO: check
+       NOT-FOR-US: FeliCa IC chips issues
 CVE-2026-57852 (Grav CMS scheduler-webhook plugin contains an authentication 
bypass vu ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-57495 (AgenticMail gives AI agents real email addresses and phone 
numbers. In ...)
-       TODO: check
+       NOT-FOR-US: AgenticMail
 CVE-2026-57494 (AgenticMail gives AI agents real email addresses and phone 
numbers. In ...)
-       TODO: check
+       NOT-FOR-US: AgenticMail
 CVE-2026-55833 (Netty is a network application framework for development of 
protocol s ...)
        TODO: check
 CVE-2026-55831 (Netty is a network application framework for development of 
protocol s ...)
        TODO: check
 CVE-2026-55550 (NextCRM is open-source customer relationship management (CRM) 
software ...)
-       TODO: check
+       NOT-FOR-US: NextCRM
 CVE-2026-55544 (NextCRM is open-source customer relationship management (CRM) 
software ...)
-       TODO: check
+       NOT-FOR-US: NextCRM
 CVE-2026-55219 (Paymenter is a free and open-source webshop solution for 
management of ...)
-       TODO: check
+       NOT-FOR-US: Paymenter
 CVE-2026-53596 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
-       TODO: check
+       NOT-FOR-US: FreeScout
 CVE-2026-53595 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
-       TODO: check
+       NOT-FOR-US: FreeScout
 CVE-2026-53594 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
-       TODO: check
+       NOT-FOR-US: FreeScout
 CVE-2026-53593 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
-       TODO: check
+       NOT-FOR-US: FreeScout
 CVE-2026-53592 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
-       TODO: check
+       NOT-FOR-US: FreeScout
 CVE-2026-53591 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
-       TODO: check
+       NOT-FOR-US: FreeScout
 CVE-2026-52656 (An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and 
before  ...)
-       TODO: check
+       NOT-FOR-US: SJCAM
 CVE-2026-51385 (An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through 
v0.4.29 al ...)
-       TODO: check
+       NOT-FOR-US: safishamsi Open-Source GRAPHIFY
 CVE-2026-51031 (FlareSolverr before version 3.4.7 contains a server-side 
request forge ...)
-       TODO: check
+       NOT-FOR-US: FlareSolverr
 CVE-2026-51025 (Cross Site Scripting vulnerability in fuint Member Marketing 
System <= ...)
-       TODO: check
+       NOT-FOR-US: fuint Member Marketing System
 CVE-2026-47255 (AgenticMail gives AI agents real email addresses and phone 
numbers. @a ...)
-       TODO: check
+       NOT-FOR-US: AgenticMail
 CVE-2026-47198 (Paymenter is a free and open-source webshop solution for 
management of ...)
-       TODO: check
+       NOT-FOR-US: Paymenter
 CVE-2026-47144 (Shamefile is a linter for undocumented linter warnings. Prior 
to versi ...)
-       TODO: check
+       NOT-FOR-US: Shamefile
 CVE-2026-47134 (ClearanceKit intercepts file-system access events on macOS and 
enforce ...)
-       TODO: check
+       NOT-FOR-US: ClearanceKit
 CVE-2026-47133 (ClearanceKit intercepts file-system access events on macOS and 
enforce ...)
-       TODO: check
+       NOT-FOR-US: ClearanceKit
 CVE-2026-47130 (NextCRM is open-source customer relationship management (CRM) 
software ...)
-       TODO: check
+       NOT-FOR-US: NextCRM
 CVE-2026-47129 (NextCRM is open-source customer relationship management (CRM) 
software ...)
        NOT-FOR-US: Next.js
 CVE-2026-47128 (nono is software that allows users to run AI agents in a 
zero-latency  ...)
-       TODO: check
+       NOT-FOR-US: nono
 CVE-2026-44585 (Paymenter is a free and open-source webshop solution for 
management of ...)
-       TODO: check
+       NOT-FOR-US: Paymenter
 CVE-2026-44584 (Paymenter is a free and open-source webshop solution for 
management of ...)
-       TODO: check
+       NOT-FOR-US: Paymenter
 CVE-2026-44583 (Paymenter is a free and open-source webshop solution for 
management of ...)
-       TODO: check
+       NOT-FOR-US: Paymenter
 CVE-2026-44510 (Rsync is a file-copying tool that uses a delta-transfer 
algorithm to s ...)
        TODO: check
 CVE-2026-44509 (Rsync is a file-copying tool that uses a delta-transfer 
algorithm to s ...)
@@ -115,9 +115,9 @@ CVE-2026-44507 (Rsync is a file-copying tool that uses a 
delta-transfer algorith
 CVE-2026-3182 (Zohocorp ManageEngine Endpoint Central versions 
before11.4.2528.34 are ...)
        NOT-FOR-US: Zoho
 CVE-2026-16337 (Improper authorization in the ToolGroupResource and RoleAjax 
REST/DWR  ...)
-       TODO: check
+       NOT-FOR-US: dotCMS
 CVE-2026-16336 (A vulnerability was found in trinodb trino 481. Affected is an 
unknown ...)
-       TODO: check
+       NOT-FOR-US: trinodb
 CVE-2026-16334 (A vulnerability was identified in itsourcecode Hospital 
Management Sys ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-16332 (A vulnerability was detected in D-Link DNS-320 1.0.2. This 
impacts an  ...)
@@ -131,11 +131,11 @@ CVE-2026-16329 (A vulnerability was identified in D-Link 
DNS-320 1.0.2. Impacted
 CVE-2026-16327 (A vulnerability was determined in D-Link DNS-320 1.0.2. This 
issue aff ...)
        NOT-FOR-US: D-Link
 CVE-2026-16324 (A vulnerability was identified in Metasoft 
\u7f8e\u7279\u8f6f\u4ef6 Me ...)
-       TODO: check
+       NOT-FOR-US: Metasoft
 CVE-2026-16266 (Versions of the package mongo-object before 3.0.3 are 
vulnerable to Pr ...)
-       TODO: check
+       NOT-FOR-US: mongo-object
 CVE-2026-15927 (A flaw was found in Red Hat Quay's repository-level mirror 
configurati ...)
-       TODO: check
+       NOT-FOR-US: Quay
 CVE-2026-15812 (A vulnerability was found in the internal Access Control List 
(ACL) su ...)
        TODO: check
 CVE-2026-15811 (A vulnerability was found in kronosnet's (version <=1.34) 
cryptographi ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e09d1a920136432efe9200cbfc4f7ebfa4c05b96

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e09d1a920136432efe9200cbfc4f7ebfa4c05b96
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to