Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8bd1d123 by Salvatore Bonaccorso at 2026-07-27T09:44:42+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin 
before 5.7.3 ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Leantime
 CVE-2026-17501 (A flaw has been found in ggml-org llama.cpp e15efe0. This 
vulnerabilit ...)
        TODO: check
 CVE-2026-17500 (A vulnerability was detected in ggml-org llama.cpp 
d006858/e15efe0. Th ...)
@@ -110,15 +110,15 @@ CVE-2026-57989 (Origin validation error in Microsoft Edge 
(Chromium-based) allow
 CVE-2026-57978 (Origin validation error in Microsoft Edge (Chromium-based) 
allows an u ...)
        NOT-FOR-US: Microsoft
 CVE-2026-17497 (NoteGen before 0.32.0 grants the Tauri shell plugin 
shell:allow-execut ...)
-       TODO: check
+       NOT-FOR-US: NoteGen
 CVE-2026-17496 (NoteGen before 0.32.0 renders AI chat responses with 
markdown-it confi ...)
-       TODO: check
+       NOT-FOR-US: NoteGen
 CVE-2026-17459 (A vulnerability was determined in perwendel spark up to 2.9.4. 
This vu ...)
-       TODO: check
+       NOT-FOR-US: perwendel spark
 CVE-2026-17458 (A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. 
This aff ...)
-       TODO: check
+       NOT-FOR-US: mf-yang openclaw-cn
 CVE-2026-17457 (A vulnerability has been found in mf-yang openclaw-cn up to 
0.2.1. Aff ...)
-       TODO: check
+       NOT-FOR-US: mf-yang openclaw-cn
 CVE-2026-63319
        - qemu 1:11.0.3+ds-1
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3995
@@ -2071,7 +2071,7 @@ CVE-2026-12502 (Improper Privilege Management (CWE-269)in 
`/usr/bin/ltsudo` in L
 CVE-2026-12496 (Stored Cross-Site Scripting (CWE-79)in the OPC XML-DA server 
statistic ...)
        NOT-FOR-US: Loytec
 CVE-2026-10610 (Local privilege escalationpotentially allowed an attacker to 
execute a ...)
-       TODO: check
+       NOT-FOR-US: ESET
 CVE-2026-10033 (The EventON Action User plugin for WordPress is vulnerable to 
authoriz ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-16634 (TOML::XS versions before 0.06 for Perl bundle an unsupported 
and vulne ...)
@@ -7649,7 +7649,7 @@ CVE-2026-16150 (A vulnerability was found in RobinHerbots 
Inputmask up to 5.0.9.
 CVE-2026-12228 (A stored cross-site scripting (XSS) vulnerability exists in 
the `POST  ...)
        NOT-FOR-US: parisneo/lollms
 CVE-2026-10130 (QueryWeaver contains an authentication bypass vulnerability 
that allow ...)
-       TODO: check
+       NOT-FOR-US: FalkorDB QueryWeaver
 CVE-2026-64186 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
        - linux 7.0.12-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
@@ -11354,7 +11354,7 @@ CVE-2026-11740
 CVE-2026-11575 (The PhonePe Payment Solutions WordPress plugin before 3.1.0 
does not p ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11386 (An input validation and injection vulnerability exists in 
Canonical ub ...)
-       TODO: check
+       NOT-FOR-US: Canonical ubuntu-pro-client
 CVE-2026-11324 (The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay 
gateway plug ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-10590 (A potential missing authentication vulnerability could allow a 
local p ...)
@@ -15674,7 +15674,7 @@ CVE-2026-11591 (The Widgets for Google Reviews plugin 
for WordPress is vulnerabl
 CVE-2026-11426 (The UnderConstructionPage PRO plugin for WordPress is 
vulnerable to Ar ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11321 (The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) 
concatenates ...)
-       TODO: check
+       NOT-FOR-US: DataInjection plugin for GLPI
 CVE-2026-10865 (The Cost Calculator Builder plugin for WordPress is vulnerable 
to Sens ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-10770 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bd1d1234ca2b29bad2581f550e0e431e9d55aff

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bd1d1234ca2b29bad2581f550e0e431e9d55aff
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to