Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
daeb62a2 by Salvatore Bonaccorso at 2026-07-26T14:57:05+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,13 +3,13 @@ CVE-2026-64530 (In the Linux kernel, the following 
vulnerability has been resolv
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/a8a02897f2b479127db261de05cbf0c28b98d159 (7.2-rc1)
 CVE-2026-63720 (datamodel-code-generator prior to version 0.70.0 contains a 
code injec ...)
-       TODO: check
+       NOT-FOR-US: datamodel-code-generator
 CVE-2026-17434 (A flaw has been found in nanocoai NanoClaw up to 2.0.64. 
Affected is t ...)
-       TODO: check
+       NOT-FOR-US: nanocoai NanoClaw
 CVE-2026-17433 (A vulnerability was detected in nanocoai NanoClaw up to 
2.0.64. This i ...)
-       TODO: check
+       NOT-FOR-US: nanocoai NanoClaw
 CVE-2026-17432 (A vulnerability was detected in NousResearch hermes-agent 
2026.6.5. Af ...)
-       TODO: check
+       NOT-FOR-US: NousResearch hermes-agent
 CVE-2026-15962 (The Fluent Forms Pro Add On Pack plugin for WordPress is 
vulnerable to ...)
        NOT-FOR-US: WordPress plugin
 CVE-2024-14040 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
@@ -22,7 +22,7 @@ CVE-2026-66012 (SiYuan before v3.7.2 contains a missing 
authorization vulnerabil
 CVE-2026-66011 (ImageMagick before 7.1.2-27 contains a memory leak 
vulnerability in th ...)
        TODO: check
 CVE-2026-16766 (Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl 
allow shell ...)
-       TODO: check
+       NOT-FOR-US: Catalyst::View::Wkhtmltopdf Perl module
 CVE-2026-15425 (The Yoast SEO \u2013 Advanced SEO with real-time guidance and 
built-in ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-10818 (The WPForms Pro plugin for WordPress is vulnerable to 
Arbitrary File U ...)
@@ -1383,21 +1383,21 @@ CVE-2026-66036 (FFmpeg through 8.1.2, fixed in commit 
5d7112c, contains a heap o
 CVE-2026-62835 (Improper authorization in Azure Portal allows an unauthorized 
attacker ...)
        NOT-FOR-US: Microsoft
 CVE-2026-61892 (Weintek cMT3092X HMI allows a non-privileged user to modify 
tokens to  ...)
-       TODO: check
+       NOT-FOR-US: Weintek cMT3092X HMI
 CVE-2026-61886 (Weintek cMT3092X HMI stores user account passwords in 
plaintext.)
-       TODO: check
+       NOT-FOR-US: Weintek cMT3092X HMI
 CVE-2026-61884 (The web management interface ofTycon Systems 
TPDIN-Monitor-WEB2  does  ...)
-       TODO: check
+       NOT-FOR-US: Tycon Systems
 CVE-2026-60135 (An attacker can modify data that should be restricted to 
read\u2011onl ...)
-       TODO: check
+       NOT-FOR-US: Weintek
 CVE-2026-60134 (Weintek cMT3092X HMI allows a non-privileged user to modify 
cookies to ...)
-       TODO: check
+       NOT-FOR-US: Weintek
 CVE-2026-57531 (Milkdown before 7.21.3 contains a DOM cross-site scripting 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Milkdown
 CVE-2026-57530 (Milkdown before 7.21.3 contains a stored cross-site scripting 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Milkdown
 CVE-2026-55985 (The web management interface in Tycon Systems 
TPDIN-Monitor-WEB2  stor ...)
-       TODO: check
+       NOT-FOR-US: Tycon Systems
 CVE-2026-16280 (An integer overflow when calculating physical offsets for 
sparse PMRs  ...)
        NOT-FOR-US: Imagination Technologies
 CVE-2026-14955 (The Checkout Field Editor for WooCommerce (Pro) plugin for 
WordPress i ...)
@@ -1869,13 +1869,13 @@ CVE-2026-12702 (In affected versions of Octopus Deploy 
Insufficient checks on th
 CVE-2026-12654 (The Payment Plugins for Stripe WooCommerce plugin for 
WordPress is vul ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12504 (Improper Authentication (CWE-287)in the PAM configuration in 
Loytec LI ...)
-       TODO: check
+       NOT-FOR-US: Loytec
 CVE-2026-12503 (Improper Link Resolution (CWE-59)in `/usr/bin/larm_starter` in 
Loytec  ...)
-       TODO: check
+       NOT-FOR-US: Loytec
 CVE-2026-12502 (Improper Privilege Management (CWE-269)in `/usr/bin/ltsudo` in 
Loytec  ...)
-       TODO: check
+       NOT-FOR-US: Loytec
 CVE-2026-12496 (Stored Cross-Site Scripting (CWE-79)in the OPC XML-DA server 
statistic ...)
-       TODO: check
+       NOT-FOR-US: Loytec
 CVE-2026-10610 (Local privilege escalationpotentially allowed an attacker to 
execute a ...)
        TODO: check
 CVE-2026-10033 (The EventON Action User plugin for WordPress is vulnerable to 
authoriz ...)
@@ -2702,7 +2702,7 @@ CVE-2026-15786 (The WP Encryption \u2013 One Click Free 
SSL Certificate & SSL /
 CVE-2026-15761 (The Tickera \u2013 Sell Tickets & Manage Events plugin for 
WordPress i ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15687 (A security issue was discovered in the Kubernetes Java client 
library  ...)
-       TODO: check
+       NOT-FOR-US: Kubernetes Java client
 CVE-2026-15647 (The Brands for WooCommerce plugin for WordPress is vulnerable 
to Store ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15646 (The Brands for WooCommerce plugin for WordPress is vulnerable 
to Store ...)
@@ -11028,7 +11028,7 @@ CVE-2026-13103 (A potential path traversal 
vulnerability was reported in Lenovo
 CVE-2026-12393 (The WPS Bookings for WooCommerce WordPress plugin before 
3.11.7 does n ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12391 (An insecure symlink following vulnerability exists in 
Canonical ubuntu ...)
-       TODO: check
+       NOT-FOR-US: Canonical
 CVE-2026-12379 (An Open Redirect vulnerability (CWE-601) exists in the 
OAuth/OIDC auth ...)
        TODO: check
 CVE-2026-11966 (The User Registration & Membership  WordPress plugin before 
5.2.3 does ...)
@@ -11843,7 +11843,7 @@ CVE-2026-14251 (A flaw was found in the OpenShift 
GitOps operator. The ClusterRo
 CVE-2026-12997 (The Gravity Forms plugin for WordPress is vulnerable to 
Directory Trav ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12382 (A flaw was found in the AAP Gateway Envoy proxy configuration. 
The non ...)
-       TODO: check
+       NOT-FOR-US: AAP Gateway (Red Hat)
 CVE-2026-10673 (The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver 
(drivers/e ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-32781 (Apollo is a reliable configuration management system suitable 
for micr ...)
@@ -14624,7 +14624,7 @@ CVE-2026-15540 (A vulnerability was detected in 
SourceCodester Online Book Store
 CVE-2026-14934 (A Missing Authorization vulnerability in the repository 
creation funct ...)
        NOT-FOR-US: Google Cloud BigQuery, Dataform and Colab Enterprise
 CVE-2026-14906 (Pages with malicious titles could potentially allow saved PDF 
content  ...)
-       TODO: check
+       NOT-FOR-US: Firefox for iOS
 CVE-2026-14846 (In version 8.2.1 of PrestaShop, there is a vulnerability 
relating to t ...)
        NOT-FOR-US: PrestaShop
 CVE-2026-14453 (This vulnerability is a critical Server-Side Template 
Injection (SSTI) ...)
@@ -16358,7 +16358,7 @@ CVE-2026-13011 (The ERP: Complete HR, Accounting & CRM 
Suite with Recruitment an
 CVE-2026-12879 (An Improper Input Validation vulnerability in BigQuery DAO in 
Google C ...)
        NOT-FOR-US: Google Cloud Apigee
 CVE-2026-12593 (The implementation of an internalandundocumentedDashboardAPI 
endpoint( ...)
-       TODO: check
+       NOT-FOR-US: QT Axivion
 CVE-2026-12590 (Impact: In body-parser versions prior to 1.20.6 (1.x line) and 
2.3.0 ( ...)
        TODO: check
 CVE-2026-12433 (The Hydra Booking \u2013 Appointment Scheduling & Booking 
Calendar plu ...)
@@ -17329,7 +17329,7 @@ CVE-2026-22927 (Omnissa Workspace ONE\xae Tunnel for 
Windows addresses a   Local
 CVE-2026-15067 (Snowflake Terraform Provider versions prior to 2.18.0 contain 
several  ...)
        NOT-FOR-US: Snowflake Terraform Provider
 CVE-2026-15063 (A flaw was found in the gorch service template, which is part 
of the t ...)
-       TODO: check
+       NOT-FOR-US: Red Hat OpenShift AI (RHOAI)
 CVE-2026-15062 (SQL injection vulnerabilities in the Snowflake Snowpark Python 
SDK (sn ...)
        NOT-FOR-US: Snowflake Snowpark Python SDK
 CVE-2026-15053 (Tanium addressed a denial of service vulnerability in Tanium 
Server.)
@@ -17349,7 +17349,7 @@ CVE-2026-15036 (A vulnerability was determined in 
Harness up to 2.28.2. This vul
 CVE-2026-15035 (A vulnerability was found in bentoml OpenLLM 0.6.30. This 
affects the  ...)
        NOT-FOR-US: bentoml OpenLLM
 CVE-2026-15034 (A vulnerability has been found in flask-dashboard 
Flask-MonitoringDash ...)
-       TODO: check
+       NOT-FOR-US: Flask-MonitoringDashboard
 CVE-2026-15033 (A flaw has been found in christopherthielen 
check-peer-dependencies up ...)
        NOT-FOR-US: christopherthielen check-peer-dependencies
 CVE-2026-14967 (BBOT's `github_workflows` module could be induced to write a 
downloade ...)
@@ -98020,7 +98020,7 @@ CVE-2026-26002 (Open OnDemand is an open-source 
high-performance computing porta
 CVE-2026-25750 (Langchain Helm Charts are Helm charts for deploying Langchain 
applicat ...)
        NOT-FOR-US: Langchain Helm Charts
 CVE-2026-25702 (A Improper Access Control vulnerability in the kernel of SUSE 
SUSE Lin ...)
-       TODO: check
+       NOT-FOR-US: SUSE
 CVE-2026-24963 (Incorrect Privilege Assignment vulnerability in ameliabooking 
Amelia a ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24960 (Unrestricted Upload of File with Dangerous Type vulnerability 
in zozot ...)
@@ -100715,7 +100715,7 @@ CVE-2026-25746 (OpenEMR is a free and open source 
electronic health records and
 CVE-2026-25743 (OpenEMR is a free and open source electronic health records 
and medica ...)
        NOT-FOR-US: OpenEMR
 CVE-2026-25701 (An Insecure Temporary File vulnerability in openSUSE 
sdbootutil allows ...)
-       TODO: check
+       NOT-FOR-US: openSUSE sdbootutil package
 CVE-2026-25554 (OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt 
module (pri ...)
        NOT-FOR-US: OpenSIPS
 CVE-2026-25476 (OpenEMR is a free and open source electronic health records 
and medica ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/daeb62a2ca83b78d76aa8059f174df70c230fe64

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/daeb62a2ca83b78d76aa8059f174df70c230fe64
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to