Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e8cc8a89 by Salvatore Bonaccorso at 2026-07-31T10:25:08+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -103,35 +103,35 @@ CVE-2026-61893 (A crafted IEC 60870-5-104 I-frame with 
TypeID 104 (C_TS_NA_1) an
 CVE-2026-61526 (AdonisJS HTTP Server is a package for handling HTTP requests 
in the Ad ...)
        NOT-FOR-US: AdonisJS HTTP Server
 CVE-2026-5846 (The affectedWatchfire Controller Softwarecontains self-signed 
hard-cod ...)
-       TODO: check
+       NOT-FOR-US: Watchfire
 CVE-2026-56758 (The ACSE layer contains a flaw in the processing of AARQ PDUs 
during M ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-56673 (ComfyUI is a modular diffusion model GUI, API, and backend 
with a grap ...)
-       TODO: check
+       NOT-FOR-US: ComfyUI
 CVE-2026-56672 (ComfyUI is a node-based diffusion model GUI, API, and backend. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: ComfyUI
 CVE-2026-56671 (ComfyUI is a modular diffusion model GUI, api and backend with 
a graph ...)
-       TODO: check
+       NOT-FOR-US: ComfyUI
 CVE-2026-56670 (ComfyUI is a modular diffusion model GUI, api and backend with 
a graph ...)
-       TODO: check
+       NOT-FOR-US: ComfyUI
 CVE-2026-55777 (GoAccess is a real-time web log analyzer and interactive 
viewer that r ...)
        TODO: check
 CVE-2026-55768 (GoAccess is a real-time web log analyzer and interactive 
viewer that r ...)
        TODO: check
 CVE-2026-55502 (Cloudreve is a self-hosted file management and sharing system. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: Cloudreve
 CVE-2026-55499 (Cloudreve is a self-hosted file management and sharing system. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: Cloudreve
 CVE-2026-55497 (Cloudreve is a self-hosted file management and sharing system. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: Cloudreve
 CVE-2026-55496 (Cloudreve is a self-hosted file management and sharing system. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: Cloudreve
 CVE-2026-55495 (Cloudreve is a self-hosted file management and sharing system. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: Cloudreve
 CVE-2026-54715 (GoAccess is a real-time web log analyzer and interactive 
viewer that r ...)
        TODO: check
 CVE-2026-52539 (Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing 
secret. When t ...)
-       TODO: check
+       NOT-FOR-US: Outstatic CMS
 CVE-2026-43833 (Full details and mitigation steps are currently restricted and 
will be ...)
        TODO: check
 CVE-2026-43832 (Full details and mitigation steps are currently restricted and 
will be ...)
@@ -143,15 +143,15 @@ CVE-2026-43830 (Full details and mitigation steps are 
currently restricted and w
 CVE-2026-43829 (Full details and mitigation steps are currently restricted and 
will be ...)
        TODO: check
 CVE-2026-38709 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, 
WR1300  ...)
-       TODO: check
+       NOT-FOR-US: Cudy
 CVE-2026-35847 (An issue in dnsmgr v.2.15 and before allows a local attacker 
to execut ...)
-       TODO: check
+       NOT-FOR-US: dnsmgr
 CVE-2026-18452 (DMS+ (Non-Mobile) developed by Rich Source has a Use of 
Hard-coded Cre ...)
-       TODO: check
+       NOT-FOR-US: Rich Source
 CVE-2026-18157 (A flaw was found in yggdrasil-worker-package-manager. A local 
attacker ...)
-       TODO: check
+       NOT-FOR-US: yggdrasil-worker-package-manager
 CVE-2026-18064 (An incomplete fix for CVE-2026-15352 in the NASA core Flight 
System  ( ...)
-       TODO: check
+       NOT-FOR-US: NASA HS
 CVE-2026-16236 (The Realtyna Organic IDX plugin for WordPress is vulnerable to 
Arbitra ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15381 (The WP Go Maps  WordPress plugin before 10.1.04 does not 
properly sani ...)
@@ -197,15 +197,15 @@ CVE-2026-14830 (The FlxWoo WordPress plugin before 3.1.1 
does not verify with th
 CVE-2026-14554 (The Check & Log Email  WordPress plugin before 2.0.15 does not 
properl ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14541 (An authentication bypass and audience confusion vulnerability 
exists i ...)
-       TODO: check
+       NOT-FOR-US: Google mcp-toolbox
 CVE-2026-14540 (A Server-Side Request Forgery (SSRF) vulnerability exists in 
the gener ...)
-       TODO: check
+       NOT-FOR-US: Google mcp-toolbox
 CVE-2026-14539 (An allocation of resources without limits vulnerability in the 
HTTP ha ...)
-       TODO: check
+       NOT-FOR-US: Google mcp-toolbox
 CVE-2026-14538 (An improper authorization and security-boundary bypass 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Google mcp-toolbox
 CVE-2026-14537 (Incorrect Authorization in the direct HTTP API tool invocation 
endpoin ...)
-       TODO: check
+       NOT-FOR-US: Google mcp-toolbox
 CVE-2026-14483 (The Realtyna Organic IDX plugin + WPL Real Estate plugin for 
WordPress ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14333 (The Demi  WordPress plugin before 0.0.7 stores its full-site 
backup ar ...)
@@ -231,7 +231,7 @@ CVE-2026-12697 (The wpForo Forum WordPress plugin before 
3.1.2 does not verify t
 CVE-2026-12695 (The miniOrange 2FA  WordPress plugin before 6.2.6 does not 
validate th ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12562 (The RCU II+ and Multiload II+ are vulnerable to an 
unauthenticated  se ...)
-       TODO: check
+       NOT-FOR-US: RCU II+ and Multiload II+
 CVE-2026-12376 (The Academy LMS WordPress plugin through 3.8.2 does not 
restrict acces ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12251 (The Ultimate Member  WordPress plugin before 2.12.1 does not 
filter ad ...)
@@ -265,11 +265,11 @@ CVE-2025-69930 (CodeAstro Membership Management System 
1.0 is vulnerable to SQL
 CVE-2025-65342 (code-projects Blood System 1.0 is vulnerable to Cross Site 
Scripting ( ...)
        NOT-FOR-US: code-projects
 CVE-2025-65341 (Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site 
Scripting (XSS) ...)
-       TODO: check
+       NOT-FOR-US: Ecommerce Fruits Bazar
 CVE-2025-65336 (Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is 
vulnerable t ...)
-       TODO: check
+       NOT-FOR-US: Ecommerce-project-with-php-and-mysqli-Fruits-Bazar
 CVE-2025-51684 (CleverTap Web SDK v1.15.1 is vulnerable to Cross Site 
Scripting (XSS). ...)
-       TODO: check
+       NOT-FOR-US: CleverTap Web SDK
 CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere 
Applic ...)
        NOT-FOR-US: IBM
 CVE-2026-7849 (Due to improper neutralization of special elements, an 
unauthenticated ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8cc8a89f63130c193ab68e927dd7e866f327d65

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8cc8a89f63130c193ab68e927dd7e866f327d65
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to