Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
27064b5a by Salvatore Bonaccorso at 2026-07-30T22:25:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,73 +1,73 @@
 CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere 
Applic ...)
        NOT-FOR-US: IBM
 CVE-2026-7849 (Due to improper neutralization of special elements, an 
unauthenticated ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-6540 (Calico's Application Layer Policy (disabled by default), which 
enforce ...)
-       TODO: check
+       NOT-FOR-US: Calico
 CVE-2026-67596 (CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains 
a weak e ...)
-       TODO: check
+       NOT-FOR-US: CSL 1010 M2M 3G WiFi Module firmware
 CVE-2026-67351 (Serendipity before 2.6.1 contains an authentication context 
confusion  ...)
        TODO: check
 CVE-2026-67349 (OpenCost before 1.121.0 fails to authenticate the GET 
/helmValues endp ...)
-       TODO: check
+       NOT-FOR-US: OpenCost
 CVE-2026-67348 (Julep contains an insecure direct object reference 
vulnerability in th ...)
-       TODO: check
+       NOT-FOR-US: Julep
 CVE-2026-67347 (Vendure through 3.7.1, fixed in commit f67ef5f, contains a 
cross-chann ...)
-       TODO: check
+       NOT-FOR-US: Vendure
 CVE-2026-67346 (Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a 
server-side  ...)
-       TODO: check
+       NOT-FOR-US: Swarms
 CVE-2026-67345 (MaxKey through 4.1.12, fixed in commit ddbb72f, contains an 
insufficie ...)
-       TODO: check
+       NOT-FOR-US: Dromara MaxKey
 CVE-2026-66416 (Leantime 3.6.2 contains a cross-site request forgery 
vulnerability tha ...)
-       TODO: check
+       NOT-FOR-US: Leantime
 CVE-2026-66415 (Leantime 3.6.2 contains a server-side request forgery and 
local file i ...)
-       TODO: check
+       NOT-FOR-US: Leantime
 CVE-2026-66414 (Leantime 3.6.2 contains an open redirect vulnerability in the 
Login co ...)
-       TODO: check
+       NOT-FOR-US: Leantime
 CVE-2026-65635 (Improper Isolation or Compartmentalization vulnerability in 
malach-it  ...)
-       TODO: check
+       NOT-FOR-US: malach-it boruta (Elixir.Boruta.Openid module)
 CVE-2026-64870 (MaxKB is an open-source AI assistant for enterprise. In 
versions 2.0.0 ...)
-       TODO: check
+       NOT-FOR-US: MaxKB
 CVE-2026-62663 (Banks generates meaningful LLM prompts using a simple template 
languag ...)
-       TODO: check
+       NOT-FOR-US: Banks
 CVE-2026-61536 (Banks generates meaningful LLM prompts using a simple template 
languag ...)
-       TODO: check
+       NOT-FOR-US: Banks
 CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site 
Request Fo ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr 
Information  ...)
-       TODO: check
+       NOT-FOR-US: E-Commerce Pack
 CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for 
asyncio an ...)
        TODO: check
 CVE-2026-59310 (VMware vCenter contains a directory traversal vulnerability in 
the Sys ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability 
in the  ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-57862 (Kanboard 1.2.52 and prior contains a server-side request 
forgery vulne ...)
        TODO: check
 CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: e107
 CVE-2026-56428 (The SSH service on BSH ELP (Electronic Platform) modules 
contains a pl ...)
        NOT-FOR-US: Bosch
 CVE-2026-54885 (Server-Side Request Forgery vulnerability in malach-it Boruta 
allows a ...)
-       TODO: check
+       NOT-FOR-US: malach-it Boruta
 CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of 
utilities and ...)
-       TODO: check
+       NOT-FOR-US: DSSRF
 CVE-2026-54522 (MessagePack for Ruby is an implementation of the MessagePack 
binary se ...)
        TODO: check
 CVE-2026-54368 (CentreStack before 17.4 contains a SQL injection vulnerability 
in Glad ...)
-       TODO: check
+       NOT-FOR-US: CentreStack
 CVE-2026-54367 (CentreStack before 17.2 contains an authentication bypass 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: CentreStack
 CVE-2026-54366 (CentreStack before 17.4 contains an XML external entity (XXE) 
injectio ...)
-       TODO: check
+       NOT-FOR-US: CentreStack
 CVE-2026-54365 (CentreStack before 17.3 contains an unauthenticated 
deserialization vu ...)
-       TODO: check
+       NOT-FOR-US: CentreStack
 CVE-2026-54364 (CentreStack before 17.4 contains a session variable injection 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: CentreStack
 CVE-2026-54363 (CentreStack before 17.5 contains a hardcoded cryptographic key 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: CentreStack
 CVE-2026-53431 (Authentication Bypass by Capture-replay vulnerability in 
malach-it Bor ...)
-       TODO: check
+       NOT-FOR-US: malach-it Boruta
 CVE-2026-51295 (SQLite 3.41 is vulnerable to use after free in the 
jsonExtractFunc fun ...)
        TODO: check
 CVE-2026-51294 (SQLite 3.41 is vulnerable to use after free in the 
jsonArrayLengthFunc ...)
@@ -81,61 +81,61 @@ CVE-2026-51291 (sqlite 3.41 is vulnerable to use after free 
in the json.c jsonCa
 CVE-2026-51290 (SQLite 3.41 has a use-after-free vulnerability in the shared 
cache loc ...)
        TODO: check
 CVE-2026-51272 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer 
overflow vul ...)
-       TODO: check
+       NOT-FOR-US: schreibfaul1 ESP32-audioI2S
 CVE-2026-4978 (Improper neutralization of special elements used in an SQL 
command ('S ...)
-       TODO: check
+       NOT-FOR-US: Traffic Analysis System
 CVE-2026-48910 (A carefully crafted editing request could trigger an XSS 
vulnerability ...)
        TODO: check
 CVE-2026-48499 (Activepieces is an open source AI workflow automation 
platform. Prior  ...)
-       TODO: check
+       NOT-FOR-US: Activepieces
 CVE-2026-47876 (VMware ESX contains an out-of-bounds write vulnerability in 
the VMXNET ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-44108 (Due to a flaw in the execution order of scripts during 
shutdown, the f ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44107 (A reboot of the charging controller can be triggered via 
Modbus TCP wi ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44106 (A privilege escalation vulnerability in the init-script for 
user-appli ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44105 (The credentials for the local user "user-app" may be exposed 
in log fi ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44104 (The firmware update process for the basemodule of the charging 
control ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44103 (An unauthenticated remote attacker can inject malicious 
firmware into  ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44102 (An unauthenticated remote attacker can trigger a firmware 
update downl ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44101 (Due to missing authentication the CHARX OCPP Agent service 
allows an u ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44100 (The CHARX JupiCore service allows an unauthenticated remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44099 (A privilege escalation vulnerability in the system 
configuration allow ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44098 (This vulnerability allows an unauthenticated remote attacker 
with cont ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44097 (A low-privileged remote attacker with "operator" access can 
upload arb ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44096 (A privilege escalation vulnerability in udhcpc allows a local 
user "ch ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44095 (A privilege escalation vulnerability in a script used for 
network conf ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44094 (An unauthenticated remote attacker can enforce the system to 
fall back ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44093 (A local privilege escalation vulnerability in the init-script 
for user ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44092 (An unauthenticated remote attacker can inject malicious input 
into the ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44091 (An unauthenticated remote attacker can post a malicious ID to 
the MQTT ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-44090 (Due to missing authentication, an unauthenticated remote 
attacker may  ...)
-       TODO: check
+       NOT-FOR-US: Phoenix Contact
 CVE-2026-41709 (VMware ESX contains an insufficient logging vulnerability.A 
malicious  ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-41703 (VMware ESX,Workstation, and Fusioncontain an out-of-bounds 
read vulner ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-41187 (Calico's apiserver wraps tier-scoped resources so that every 
operation ...)
-       TODO: check
+       NOT-FOR-US: Calico
 CVE-2026-41186 (When Calico's shared debug server is enabled (disabled by 
default), th ...)
-       TODO: check
+       NOT-FOR-US: Calico
 CVE-2026-28814 (Arbitrary Wiki Markup rendering due to lack of authentication 
in Apach ...)
        TODO: check
 CVE-2026-28813 (Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, 
which l ...)
@@ -153,21 +153,21 @@ CVE-2026-22621 (Improper input validation in one of the 
session management inter
 CVE-2026-22620 (Improper input validation in the authentication component 
ofEaton's Tr ...)
        NOT-FOR-US: Eaton
 CVE-2026-18382 (A flaw was found in koku-metrics-operator. The operator's 
CostManageme ...)
-       TODO: check
+       NOT-FOR-US: koku-metrics-operator
 CVE-2026-18381 (A flaw was found in the koku-metrics-operator for Red Hat 
OpenShift. T ...)
-       TODO: check
+       NOT-FOR-US: koku-metrics-operator
 CVE-2026-18378 (A flaw was found in koku-metrics-operator. The operator's 
CostManageme ...)
-       TODO: check
+       NOT-FOR-US: koku-metrics-operator
 CVE-2026-18369 (A flaw was found in Dogtag PKI's ACME responder where the 
HTTP-01 chal ...)
        TODO: check
 CVE-2026-18363 (A logic vulnerability in the password reset token validation 
routine i ...)
-       TODO: check
+       NOT-FOR-US: osTicket
 CVE-2026-18362 (The IRIS web application in version 2.4.26 and possibly others 
does no ...)
-       TODO: check
+       NOT-FOR-US: IRIS web application
 CVE-2026-18361 (The IRIS web application in version 2.4.26 and possibly others 
is vuln ...)
-       TODO: check
+       NOT-FOR-US: IRIS web application
 CVE-2026-18360 (The IRIS web application in version 2.4.26 and possibly others 
is vuln ...)
-       TODO: check
+       NOT-FOR-US: IRIS web application
 CVE-2026-18353 (PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and 
checks  ...)
        NOT-FOR-US: Eclipse
 CVE-2026-18245 (Improper control of code generation in Amazon 
@aws-amplify/codegen-ui- ...)
@@ -175,29 +175,29 @@ CVE-2026-18245 (Improper control of code generation in 
Amazon @aws-amplify/codeg
 CVE-2026-18140 (Uncontrolled recursion in the unknown-key skip path of the 
aws-smithy- ...)
        NOT-FOR-US: Amazon
 CVE-2026-16971 (The IRIS web application in version 2.4.26 and possibly others 
does no ...)
-       TODO: check
+       NOT-FOR-US: IRIS web application
 CVE-2026-16970 (The IRIS web application in version 2.4.26 and possibly others 
contain ...)
-       TODO: check
+       NOT-FOR-US: IRIS web application
 CVE-2026-16969 (The IRIS web application in version 2.4.26 and possibly others 
is vuln ...)
-       TODO: check
+       NOT-FOR-US: IRIS web application
 CVE-2026-16308 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 
3.33.1  ...)
        NOT-FOR-US: IBM
 CVE-2026-15978 (SGLang contains a model weight exfiltration vulnerability when 
no API  ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-15977 (SGLang contains a credential leakage vulnerability in the 
/server_info ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-15976 (SGLang contains a RCE vulnerability when attempting to load 
model weig ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-15974 (SGLang contains an SSRF and local file read in the multimodal 
generati ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-15971 (SGLang contains an RCE vulnerability when the optional dumper 
subsyste ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-15969 (SGLang contains an unauthenticated RCE in 
/load_lora_adapter_from_tens ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-15658 (A vulnerability in the foreUP customer REST API allows any 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: foreUP customer REST API
 CVE-2026-15657 (A vulnerability in the foreUP customer REST API allows any 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: foreUP customer REST API
 CVE-2026-15435 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 
12.0.1.0 thr ...)
        NOT-FOR-US: IBM
 CVE-2026-15397 (The Subscriptions for WooCommerce plugin for WordPress is 
vulnerable t ...)
@@ -231,7 +231,7 @@ CVE-2026-12940 (IBM Langflow OSS 1.0.0 through 1.10.1 are 
vulnerable to unauthen
 CVE-2026-12733 (IBM DataPower Gateway could allow a remote attacker to cause a 
denial  ...)
        NOT-FOR-US: IBM
 CVE-2026-12722 (Missing authentication for critical function vulnerability in 
FTC Soft ...)
-       TODO: check
+       NOT-FOR-US: FTC E-Commerce Management Panel
 CVE-2026-12118 (IBM webMethods Integration (on prem) 10.15, 10.11 could allow 
an unaut ...)
        NOT-FOR-US: IBM
 CVE-2026-11980 (IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow 
arbitrary code e ...)
@@ -1731,7 +1731,7 @@ CVE-2026-13306 (Autel MaxiCharger AC Elite Home USB 
Authentication Bypass Vulner
 CVE-2026-13305 (Autel MaxiCharger AC Elite Home Software Update Improper 
Verification  ...)
        NOT-FOR-US: Autel
 CVE-2026-13268 (G DATA Total Security Backup Service Link Following Local 
Privilege Es ...)
-       TODO: check
+       NOT-FOR-US: G DATA
 CVE-2026-13178 (The Eventin  WordPress plugin before 4.1.16 does not properly 
authoriz ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13145 (The WP Travel  WordPress plugin before 11.8.1 does not verify 
that the ...)
@@ -1747,7 +1747,7 @@ CVE-2026-12500 (The WP Travel Engine  WordPress plugin 
before 6.8.2 does not per
 CVE-2026-12436 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-12357 (Heimdall Data Database Proxy generateFileContent CRLF 
Injection Remote ...)
-       TODO: check
+       NOT-FOR-US: Heimdall
 CVE-2026-11881 (The Fluent Forms  WordPress plugin before 6.2.6 does not 
sanitise and  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11870 (The WP Ghost (Hide My WP Ghost)  WordPress plugin before 
7.0.05 does n ...)
@@ -1757,15 +1757,15 @@ CVE-2026-11867 (The Frontend Admin by DynamiApps 
WordPress plugin before 3.29.7
 CVE-2026-11782 (The Points and Rewards for WooCommerce WordPress plugin before 
2.10.1  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-69949 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL 
Injecti ...)
-       TODO: check
+       NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-69945 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL 
Injecti ...)
-       TODO: check
+       NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-69944 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL 
Injecti ...)
-       TODO: check
+       NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-69943 (kishan0725 Hospital Management System 4.0 is vulnerale to SQL 
Injectio ...)
-       TODO: check
+       NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-69942 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL 
Injecti ...)
-       TODO: check
+       NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-67408 (Sourcecodester CASAP Automated Enrollment System 1.0 is 
vulnerable to  ...)
        NOT-FOR-US: SourceCodester
 CVE-2025-67407 (Sourcecodester CASAP Automated Enrollment System 1.0 is 
vulnerable to  ...)
@@ -1779,7 +1779,7 @@ CVE-2025-67404 (Sourcecodester CASAP Automated Enrollment 
System 1.0 is vulnerab
 CVE-2025-67403 (Sourcecodester CASAP Automated Enrollment System 1.0 is 
vulnerable to  ...)
        NOT-FOR-US: SourceCodester
 CVE-2025-65340 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL 
Injecti ...)
-       TODO: check
+       NOT-FOR-US: kishan0725 Hospital Management System
 CVE-2025-65337 (Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross 
Site Scri ...)
        NOT-FOR-US: SourceCodester
 CVE-2025-14562 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27064b5af6cdc145a7598c9611edd89f2e02828c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27064b5af6cdc145a7598c9611edd89f2e02828c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to