Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
74903349 by Salvatore Bonaccorso at 2026-07-26T21:09:27+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2098,9 +2098,9 @@ CVE-2026-12688 (The ProfileGrid  WordPress plugin before 
5.9.9.7 does not verify
 CVE-2026-12497 (The Paid Membership Plugin, Ecommerce, User Registration Form, 
Login F ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12353 (An unauthenticated attacker could trigger an Out of Memory 
condition t ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Certificate System
 CVE-2026-11922 (A vulnerability in zenml-io/zenml versions 0.57.0 through 
0.94.2 allow ...)
-       TODO: check
+       NOT-FOR-US: zenml
 CVE-2026-11354 (The Participants Database plugin for WordPress is vulnerable 
to Sensit ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-10697 (Improper Authentication vulnerability in Progress MOVEit 
Transfer.  Th ...)
@@ -6243,7 +6243,7 @@ CVE-2026-12547 (SoupAuthManager caches proxy 
authentication credentials without
        - libsoup2.4 <removed>
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506
 CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET 
/api/v1/stack-deployment/st ...)
-       TODO: check
+       NOT-FOR-US: zenml
 CVE-2025-68640 (The Apple Find My backend service through 2025-12-17 allows an 
attacke ...)
        TODO: check
 CVE-2025-66390 (In Microsoft Azure API Management through 2025-10-17, when 
self-servic ...)
@@ -7247,7 +7247,7 @@ CVE-2026-13724 (Client-Side Enforcement of Server-Side 
Security vulnerability in
 CVE-2026-12701 (A path traversal vulnerability was found in pulpcore. The 
relative_pat ...)
        NOT-FOR-US: pulpcore
 CVE-2026-12341 (This vulnerability impacts all versions of IdentityIQ and 
allows an un ...)
-       TODO: check
+       NOT-FOR-US: SailPoint Technologies
 CVE-2026-12080 (A flaw was found in the QEMU Guest Agent (qga). A local 
unprivileged u ...)
        TODO: check
 CVE-2026-64207 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
@@ -7443,7 +7443,7 @@ CVE-2026-16151 (A vulnerability has been found in CartoDB 
carto-api-client 0.5.2
 CVE-2026-16150 (A vulnerability was found in RobinHerbots Inputmask up to 
5.0.9. Affec ...)
        NOT-FOR-US: RobinHerbots Inputmask
 CVE-2026-12228 (A stored cross-site scripting (XSS) vulnerability exists in 
the `POST  ...)
-       TODO: check
+       NOT-FOR-US: parisneo/lollms
 CVE-2026-10130 (QueryWeaver contains an authentication bypass vulnerability 
that allow ...)
        TODO: check
 CVE-2026-64186 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
@@ -10497,7 +10497,7 @@ CVE-2026-12692 (Unverified password change 
vulnerability in Vimesoft Inc. Enterp
 CVE-2026-12691 (Missing authentication for critical function vulnerability in 
Vimesoft ...)
        NOT-FOR-US: Enterprise Video Platform
 CVE-2026-11763 (Authorization bypass through User-Controlled key vulnerability 
in Gis  ...)
-       TODO: check
+       NOT-FOR-US: GisLab Laboratory Management System:
 CVE-2025-60357 (AhnLab EPP Management v1.0.14.32-6249 was discovered to 
contain a NoSQ ...)
        TODO: check
 CVE-2025-59866 (The HCL DFMPro, DFXAnalytics and DFXServer installers are 
affected by  ...)
@@ -11090,13 +11090,13 @@ CVE-2026-12393 (The WPS Bookings for WooCommerce 
WordPress plugin before 3.11.7
 CVE-2026-12391 (An insecure symlink following vulnerability exists in 
Canonical ubuntu ...)
        NOT-FOR-US: Canonical
 CVE-2026-12379 (An Open Redirect vulnerability (CWE-601) exists in the 
OAuth/OIDC auth ...)
-       TODO: check
+       NOT-FOR-US: QT Axivion
 CVE-2026-11966 (The User Registration & Membership  WordPress plugin before 
5.2.3 does ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11961 (The User Registration & Membership  WordPress plugin before 
5.2.3 does ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11889 (SALTO ProAccess Space software using the tenancy feature / 
logical  pa ...)
-       TODO: check
+       NOT-FOR-US: SALTO ProAccess Space software
 CVE-2026-11740
        REJECTED
 CVE-2026-11575 (The PhonePe Payment Solutions WordPress plugin before 3.1.0 
does not p ...)
@@ -13897,7 +13897,7 @@ CVE-2026-12478 (The fix for CVE-2026-0716 (commit 
6ff7ef0, libsoup 3.6.6) placed
 CVE-2026-12281 (The Shibboleth WordPress plugin before 2.5.4 does not fail 
closed when ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11944 (openSIS Classic 9.3 contains an authenticated path traversal 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: OpenSIS
 CVE-2026-11917 (A path traversal security issue exists within Rockwell 
AutomationThinM ...)
        NOT-FOR-US: Rockwell Automation
 CVE-2026-11851 (Improper Neutralization of Special Elements used in an SQL 
Command ("S ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7490334986462582ce192b49f8108ee6e6ebf8d7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7490334986462582ce192b49f8108ee6e6ebf8d7
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to