Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
27064b5a by Salvatore Bonaccorso at 2026-07-30T22:25:23+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,73 +1,73 @@
CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere
Applic ...)
NOT-FOR-US: IBM
CVE-2026-7849 (Due to improper neutralization of special elements, an
unauthenticated ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-6540 (Calico's Application Layer Policy (disabled by default), which
enforce ...)
- TODO: check
+ NOT-FOR-US: Calico
CVE-2026-67596 (CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains
a weak e ...)
- TODO: check
+ NOT-FOR-US: CSL 1010 M2M 3G WiFi Module firmware
CVE-2026-67351 (Serendipity before 2.6.1 contains an authentication context
confusion ...)
TODO: check
CVE-2026-67349 (OpenCost before 1.121.0 fails to authenticate the GET
/helmValues endp ...)
- TODO: check
+ NOT-FOR-US: OpenCost
CVE-2026-67348 (Julep contains an insecure direct object reference
vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: Julep
CVE-2026-67347 (Vendure through 3.7.1, fixed in commit f67ef5f, contains a
cross-chann ...)
- TODO: check
+ NOT-FOR-US: Vendure
CVE-2026-67346 (Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a
server-side ...)
- TODO: check
+ NOT-FOR-US: Swarms
CVE-2026-67345 (MaxKey through 4.1.12, fixed in commit ddbb72f, contains an
insufficie ...)
- TODO: check
+ NOT-FOR-US: Dromara MaxKey
CVE-2026-66416 (Leantime 3.6.2 contains a cross-site request forgery
vulnerability tha ...)
- TODO: check
+ NOT-FOR-US: Leantime
CVE-2026-66415 (Leantime 3.6.2 contains a server-side request forgery and
local file i ...)
- TODO: check
+ NOT-FOR-US: Leantime
CVE-2026-66414 (Leantime 3.6.2 contains an open redirect vulnerability in the
Login co ...)
- TODO: check
+ NOT-FOR-US: Leantime
CVE-2026-65635 (Improper Isolation or Compartmentalization vulnerability in
malach-it ...)
- TODO: check
+ NOT-FOR-US: malach-it boruta (Elixir.Boruta.Openid module)
CVE-2026-64870 (MaxKB is an open-source AI assistant for enterprise. In
versions 2.0.0 ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-62663 (Banks generates meaningful LLM prompts using a simple template
languag ...)
- TODO: check
+ NOT-FOR-US: Banks
CVE-2026-61536 (Banks generates meaningful LLM prompts using a simple template
languag ...)
- TODO: check
+ NOT-FOR-US: Banks
CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site
Request Fo ...)
NOT-FOR-US: WordPress plugin
CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr
Information ...)
- TODO: check
+ NOT-FOR-US: E-Commerce Pack
CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for
asyncio an ...)
TODO: check
CVE-2026-59310 (VMware vCenter contains a directory traversal vulnerability in
the Sys ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability
in the ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-57862 (Kanboard 1.2.52 and prior contains a server-side request
forgery vulne ...)
TODO: check
CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: e107
CVE-2026-56428 (The SSH service on BSH ELP (Electronic Platform) modules
contains a pl ...)
NOT-FOR-US: Bosch
CVE-2026-54885 (Server-Side Request Forgery vulnerability in malach-it Boruta
allows a ...)
- TODO: check
+ NOT-FOR-US: malach-it Boruta
CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of
utilities and ...)
- TODO: check
+ NOT-FOR-US: DSSRF
CVE-2026-54522 (MessagePack for Ruby is an implementation of the MessagePack
binary se ...)
TODO: check
CVE-2026-54368 (CentreStack before 17.4 contains a SQL injection vulnerability
in Glad ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54367 (CentreStack before 17.2 contains an authentication bypass
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54366 (CentreStack before 17.4 contains an XML external entity (XXE)
injectio ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54365 (CentreStack before 17.3 contains an unauthenticated
deserialization vu ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54364 (CentreStack before 17.4 contains a session variable injection
vulnerab ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54363 (CentreStack before 17.5 contains a hardcoded cryptographic key
vulnera ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-53431 (Authentication Bypass by Capture-replay vulnerability in
malach-it Bor ...)
- TODO: check
+ NOT-FOR-US: malach-it Boruta
CVE-2026-51295 (SQLite 3.41 is vulnerable to use after free in the
jsonExtractFunc fun ...)
TODO: check
CVE-2026-51294 (SQLite 3.41 is vulnerable to use after free in the
jsonArrayLengthFunc ...)
@@ -81,61 +81,61 @@ CVE-2026-51291 (sqlite 3.41 is vulnerable to use after free
in the json.c jsonCa
CVE-2026-51290 (SQLite 3.41 has a use-after-free vulnerability in the shared
cache loc ...)
TODO: check
CVE-2026-51272 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer
overflow vul ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-4978 (Improper neutralization of special elements used in an SQL
command ('S ...)
- TODO: check
+ NOT-FOR-US: Traffic Analysis System
CVE-2026-48910 (A carefully crafted editing request could trigger an XSS
vulnerability ...)
TODO: check
CVE-2026-48499 (Activepieces is an open source AI workflow automation
platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-47876 (VMware ESX contains an out-of-bounds write vulnerability in
the VMXNET ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-44108 (Due to a flaw in the execution order of scripts during
shutdown, the f ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44107 (A reboot of the charging controller can be triggered via
Modbus TCP wi ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44106 (A privilege escalation vulnerability in the init-script for
user-appli ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44105 (The credentials for the local user "user-app" may be exposed
in log fi ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44104 (The firmware update process for the basemodule of the charging
control ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44103 (An unauthenticated remote attacker can inject malicious
firmware into ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44102 (An unauthenticated remote attacker can trigger a firmware
update downl ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44101 (Due to missing authentication the CHARX OCPP Agent service
allows an u ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44100 (The CHARX JupiCore service allows an unauthenticated remote
attacker t ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44099 (A privilege escalation vulnerability in the system
configuration allow ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44098 (This vulnerability allows an unauthenticated remote attacker
with cont ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44097 (A low-privileged remote attacker with "operator" access can
upload arb ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44096 (A privilege escalation vulnerability in udhcpc allows a local
user "ch ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44095 (A privilege escalation vulnerability in a script used for
network conf ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44094 (An unauthenticated remote attacker can enforce the system to
fall back ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44093 (A local privilege escalation vulnerability in the init-script
for user ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44092 (An unauthenticated remote attacker can inject malicious input
into the ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44091 (An unauthenticated remote attacker can post a malicious ID to
the MQTT ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44090 (Due to missing authentication, an unauthenticated remote
attacker may ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-41709 (VMware ESX contains an insufficient logging vulnerability.A
malicious ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-41703 (VMware ESX,Workstation, and Fusioncontain an out-of-bounds
read vulner ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-41187 (Calico's apiserver wraps tier-scoped resources so that every
operation ...)
- TODO: check
+ NOT-FOR-US: Calico
CVE-2026-41186 (When Calico's shared debug server is enabled (disabled by
default), th ...)
- TODO: check
+ NOT-FOR-US: Calico
CVE-2026-28814 (Arbitrary Wiki Markup rendering due to lack of authentication
in Apach ...)
TODO: check
CVE-2026-28813 (Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking,
which l ...)
@@ -153,21 +153,21 @@ CVE-2026-22621 (Improper input validation in one of the
session management inter
CVE-2026-22620 (Improper input validation in the authentication component
ofEaton's Tr ...)
NOT-FOR-US: Eaton
CVE-2026-18382 (A flaw was found in koku-metrics-operator. The operator's
CostManageme ...)
- TODO: check
+ NOT-FOR-US: koku-metrics-operator
CVE-2026-18381 (A flaw was found in the koku-metrics-operator for Red Hat
OpenShift. T ...)
- TODO: check
+ NOT-FOR-US: koku-metrics-operator
CVE-2026-18378 (A flaw was found in koku-metrics-operator. The operator's
CostManageme ...)
- TODO: check
+ NOT-FOR-US: koku-metrics-operator
CVE-2026-18369 (A flaw was found in Dogtag PKI's ACME responder where the
HTTP-01 chal ...)
TODO: check
CVE-2026-18363 (A logic vulnerability in the password reset token validation
routine i ...)
- TODO: check
+ NOT-FOR-US: osTicket
CVE-2026-18362 (The IRIS web application in version 2.4.26 and possibly others
does no ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-18361 (The IRIS web application in version 2.4.26 and possibly others
is vuln ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-18360 (The IRIS web application in version 2.4.26 and possibly others
is vuln ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-18353 (PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and
checks ...)
NOT-FOR-US: Eclipse
CVE-2026-18245 (Improper control of code generation in Amazon
@aws-amplify/codegen-ui- ...)
@@ -175,29 +175,29 @@ CVE-2026-18245 (Improper control of code generation in
Amazon @aws-amplify/codeg
CVE-2026-18140 (Uncontrolled recursion in the unknown-key skip path of the
aws-smithy- ...)
NOT-FOR-US: Amazon
CVE-2026-16971 (The IRIS web application in version 2.4.26 and possibly others
does no ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-16970 (The IRIS web application in version 2.4.26 and possibly others
contain ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-16969 (The IRIS web application in version 2.4.26 and possibly others
is vuln ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-16308 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and
3.33.1 ...)
NOT-FOR-US: IBM
CVE-2026-15978 (SGLang contains a model weight exfiltration vulnerability when
no API ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15977 (SGLang contains a credential leakage vulnerability in the
/server_info ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15976 (SGLang contains a RCE vulnerability when attempting to load
model weig ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15974 (SGLang contains an SSRF and local file read in the multimodal
generati ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15971 (SGLang contains an RCE vulnerability when the optional dumper
subsyste ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15969 (SGLang contains an unauthenticated RCE in
/load_lora_adapter_from_tens ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15658 (A vulnerability in the foreUP customer REST API allows any
authenticat ...)
- TODO: check
+ NOT-FOR-US: foreUP customer REST API
CVE-2026-15657 (A vulnerability in the foreUP customer REST API allows any
authenticat ...)
- TODO: check
+ NOT-FOR-US: foreUP customer REST API
CVE-2026-15435 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and
12.0.1.0 thr ...)
NOT-FOR-US: IBM
CVE-2026-15397 (The Subscriptions for WooCommerce plugin for WordPress is
vulnerable t ...)
@@ -231,7 +231,7 @@ CVE-2026-12940 (IBM Langflow OSS 1.0.0 through 1.10.1 are
vulnerable to unauthen
CVE-2026-12733 (IBM DataPower Gateway could allow a remote attacker to cause a
denial ...)
NOT-FOR-US: IBM
CVE-2026-12722 (Missing authentication for critical function vulnerability in
FTC Soft ...)
- TODO: check
+ NOT-FOR-US: FTC E-Commerce Management Panel
CVE-2026-12118 (IBM webMethods Integration (on prem) 10.15, 10.11 could allow
an unaut ...)
NOT-FOR-US: IBM
CVE-2026-11980 (IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow
arbitrary code e ...)
@@ -1731,7 +1731,7 @@ CVE-2026-13306 (Autel MaxiCharger AC Elite Home USB
Authentication Bypass Vulner
CVE-2026-13305 (Autel MaxiCharger AC Elite Home Software Update Improper
Verification ...)
NOT-FOR-US: Autel
CVE-2026-13268 (G DATA Total Security Backup Service Link Following Local
Privilege Es ...)
- TODO: check
+ NOT-FOR-US: G DATA
CVE-2026-13178 (The Eventin WordPress plugin before 4.1.16 does not properly
authoriz ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13145 (The WP Travel WordPress plugin before 11.8.1 does not verify
that the ...)
@@ -1747,7 +1747,7 @@ CVE-2026-12500 (The WP Travel Engine WordPress plugin
before 6.8.2 does not per
CVE-2026-12436 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-12357 (Heimdall Data Database Proxy generateFileContent CRLF
Injection Remote ...)
- TODO: check
+ NOT-FOR-US: Heimdall
CVE-2026-11881 (The Fluent Forms WordPress plugin before 6.2.6 does not
sanitise and ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11870 (The WP Ghost (Hide My WP Ghost) WordPress plugin before
7.0.05 does n ...)
@@ -1757,15 +1757,15 @@ CVE-2026-11867 (The Frontend Admin by DynamiApps
WordPress plugin before 3.29.7
CVE-2026-11782 (The Points and Rewards for WooCommerce WordPress plugin before
2.10.1 ...)
NOT-FOR-US: WordPress plugin
CVE-2025-69949 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL
Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-69945 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL
Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-69944 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL
Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-69943 (kishan0725 Hospital Management System 4.0 is vulnerale to SQL
Injectio ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-69942 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL
Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-67408 (Sourcecodester CASAP Automated Enrollment System 1.0 is
vulnerable to ...)
NOT-FOR-US: SourceCodester
CVE-2025-67407 (Sourcecodester CASAP Automated Enrollment System 1.0 is
vulnerable to ...)
@@ -1779,7 +1779,7 @@ CVE-2025-67404 (Sourcecodester CASAP Automated Enrollment
System 1.0 is vulnerab
CVE-2025-67403 (Sourcecodester CASAP Automated Enrollment System 1.0 is
vulnerable to ...)
NOT-FOR-US: SourceCodester
CVE-2025-65340 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL
Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-65337 (Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross
Site Scri ...)
NOT-FOR-US: SourceCodester
CVE-2025-14562 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27064b5af6cdc145a7598c9611edd89f2e02828c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27064b5af6cdc145a7598c9611edd89f2e02828c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits