Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
74903349 by Salvatore Bonaccorso at 2026-07-26T21:09:27+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2098,9 +2098,9 @@ CVE-2026-12688 (The ProfileGrid WordPress plugin before
5.9.9.7 does not verify
CVE-2026-12497 (The Paid Membership Plugin, Ecommerce, User Registration Form,
Login F ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12353 (An unauthenticated attacker could trigger an Out of Memory
condition t ...)
- TODO: check
+ NOT-FOR-US: Red Hat Certificate System
CVE-2026-11922 (A vulnerability in zenml-io/zenml versions 0.57.0 through
0.94.2 allow ...)
- TODO: check
+ NOT-FOR-US: zenml
CVE-2026-11354 (The Participants Database plugin for WordPress is vulnerable
to Sensit ...)
NOT-FOR-US: WordPress plugin
CVE-2026-10697 (Improper Authentication vulnerability in Progress MOVEit
Transfer. Th ...)
@@ -6243,7 +6243,7 @@ CVE-2026-12547 (SoupAuthManager caches proxy
authentication credentials without
- libsoup2.4 <removed>
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506
CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET
/api/v1/stack-deployment/st ...)
- TODO: check
+ NOT-FOR-US: zenml
CVE-2025-68640 (The Apple Find My backend service through 2025-12-17 allows an
attacke ...)
TODO: check
CVE-2025-66390 (In Microsoft Azure API Management through 2025-10-17, when
self-servic ...)
@@ -7247,7 +7247,7 @@ CVE-2026-13724 (Client-Side Enforcement of Server-Side
Security vulnerability in
CVE-2026-12701 (A path traversal vulnerability was found in pulpcore. The
relative_pat ...)
NOT-FOR-US: pulpcore
CVE-2026-12341 (This vulnerability impacts all versions of IdentityIQ and
allows an un ...)
- TODO: check
+ NOT-FOR-US: SailPoint Technologies
CVE-2026-12080 (A flaw was found in the QEMU Guest Agent (qga). A local
unprivileged u ...)
TODO: check
CVE-2026-64207 (In the Linux kernel, the following vulnerability has been
resolved: n ...)
@@ -7443,7 +7443,7 @@ CVE-2026-16151 (A vulnerability has been found in CartoDB
carto-api-client 0.5.2
CVE-2026-16150 (A vulnerability was found in RobinHerbots Inputmask up to
5.0.9. Affec ...)
NOT-FOR-US: RobinHerbots Inputmask
CVE-2026-12228 (A stored cross-site scripting (XSS) vulnerability exists in
the `POST ...)
- TODO: check
+ NOT-FOR-US: parisneo/lollms
CVE-2026-10130 (QueryWeaver contains an authentication bypass vulnerability
that allow ...)
TODO: check
CVE-2026-64186 (In the Linux kernel, the following vulnerability has been
resolved: i ...)
@@ -10497,7 +10497,7 @@ CVE-2026-12692 (Unverified password change
vulnerability in Vimesoft Inc. Enterp
CVE-2026-12691 (Missing authentication for critical function vulnerability in
Vimesoft ...)
NOT-FOR-US: Enterprise Video Platform
CVE-2026-11763 (Authorization bypass through User-Controlled key vulnerability
in Gis ...)
- TODO: check
+ NOT-FOR-US: GisLab Laboratory Management System:
CVE-2025-60357 (AhnLab EPP Management v1.0.14.32-6249 was discovered to
contain a NoSQ ...)
TODO: check
CVE-2025-59866 (The HCL DFMPro, DFXAnalytics and DFXServer installers are
affected by ...)
@@ -11090,13 +11090,13 @@ CVE-2026-12393 (The WPS Bookings for WooCommerce
WordPress plugin before 3.11.7
CVE-2026-12391 (An insecure symlink following vulnerability exists in
Canonical ubuntu ...)
NOT-FOR-US: Canonical
CVE-2026-12379 (An Open Redirect vulnerability (CWE-601) exists in the
OAuth/OIDC auth ...)
- TODO: check
+ NOT-FOR-US: QT Axivion
CVE-2026-11966 (The User Registration & Membership WordPress plugin before
5.2.3 does ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11961 (The User Registration & Membership WordPress plugin before
5.2.3 does ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11889 (SALTO ProAccess Space software using the tenancy feature /
logical pa ...)
- TODO: check
+ NOT-FOR-US: SALTO ProAccess Space software
CVE-2026-11740
REJECTED
CVE-2026-11575 (The PhonePe Payment Solutions WordPress plugin before 3.1.0
does not p ...)
@@ -13897,7 +13897,7 @@ CVE-2026-12478 (The fix for CVE-2026-0716 (commit
6ff7ef0, libsoup 3.6.6) placed
CVE-2026-12281 (The Shibboleth WordPress plugin before 2.5.4 does not fail
closed when ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11944 (openSIS Classic 9.3 contains an authenticated path traversal
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: OpenSIS
CVE-2026-11917 (A path traversal security issue exists within Rockwell
AutomationThinM ...)
NOT-FOR-US: Rockwell Automation
CVE-2026-11851 (Improper Neutralization of Special Elements used in an SQL
Command ("S ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7490334986462582ce192b49f8108ee6e6ebf8d7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7490334986462582ce192b49f8108ee6e6ebf8d7
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits