Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
cb3f2e5f by Salvatore Bonaccorso at 2026-08-01T10:03:23+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,67 +3,67 @@ CVE-2026-9044 (An OS command injection vulnerability exists
in the VPN module of
CVE-2026-7623 (The SureForms \u2013 Contact Form, Payment Form & Other Custom
Form Bu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-68771 (ComfyUI v0.23.0 contains an unsafe deserialization
vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: ComfyUI
CVE-2026-68770 (sentence-transformers contains a security control bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: sentence-transformers
CVE-2026-65981 (Coturn is a free open source implementation of TURN and STUN
Server. P ...)
TODO: check
CVE-2026-65841 (Jodit Editor is a WYSIWYG editor with a built-in file browser
& image ...)
- TODO: check
+ NOT-FOR-US: Jodit Editor
CVE-2026-62999 (Copier is a library and CLI app for rendering project
templates. From ...)
- TODO: check
+ NOT-FOR-US: Copier library and CLI app
CVE-2026-62959 (Coturn is a free open source implementation of TURN and STUN
Server. F ...)
TODO: check
CVE-2026-62324 (Jodit Editor is a WYSIWYG editor with a built-in file browser
& image ...)
- TODO: check
+ NOT-FOR-US: Jodit Editor
CVE-2026-55825 (Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6,
an auth ...)
- TODO: check
+ NOT-FOR-US: Contao CMS
CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3,
XORMappedAdd ...)
TODO: check
CVE-2026-54787 (sigstore-go is a Go library for Sigstore signing and
verification. Pri ...)
TODO: check
CVE-2026-54785 (gemini-bridge is a lightweight MCP server bridging AI agents
to Google ...)
- TODO: check
+ NOT-FOR-US: gemini-bridge
CVE-2026-54768 (WPGraphQL provides a GraphQL API for WordPress sites. From
2.0.0 until ...)
- TODO: check
+ NOT-FOR-US: WPGraphQL
CVE-2026-53599 (REDAXO is a PHP-based content management system. From 5.18.2
until 5.2 ...)
- TODO: check
+ NOT-FOR-US: REDAXO CMS
CVE-2026-53573 (GeoNetwork is a catalog application to manage spatially
referenced res ...)
- TODO: check
+ NOT-FOR-US: GeoNetwork
CVE-2026-53551 (free5GC is an open-source implementation of the 5G core
network. Prior ...)
- TODO: check
+ NOT-FOR-US: free5GC
CVE-2026-53510 (Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2,
Savon::Model .al ...)
- TODO: check
+ NOT-FOR-US: Savon Ruby SOAP client
CVE-2026-52371 (A Server-Side Request Forgery (SSRF) in the
xxl-job-admin/jobinfo/trig ...)
- TODO: check
+ NOT-FOR-US: xxl-job
CVE-2026-52232 (A reflected cross-site scripting (XSS) vulnerability in the
/logo.asp ...)
- TODO: check
+ NOT-FOR-US: FS Inc S3150-8T2F Switch 2.2.0D
CVE-2026-52134 (An issue in the parseGoosePayload() function
(/goose/goose_receiver.c) ...)
- TODO: check
+ NOT-FOR-US: MZ Automation libiec61850
CVE-2026-51953 (An issue in FeehiCMS v.2.1.1 allows an attacker to escalate
privileges ...)
- TODO: check
+ NOT-FOR-US: FeehiCMS
CVE-2026-51785 (An issue in Hugo Leisink Hiawatha v.12.1 and before allows a
remote at ...)
- TODO: check
+ NOT-FOR-US: Hugo Leisink Hiawatha
CVE-2026-50986 (PrestaShop module, totadministrativemandate <1.8.1 is
vulnerable to Cr ...)
- TODO: check
+ NOT-FOR-US: PrestaShop module
CVE-2026-45377 (Decidim is a participatory democracy framework. Prior to
0.30.9, from ...)
- TODO: check
+ NOT-FOR-US: Decidim
CVE-2026-45376 (Decidim is a participatory democracy framework. Prior to
0.30.9, from ...)
- TODO: check
+ NOT-FOR-US: Decidim
CVE-2026-45330 (Decidim is a participatory democracy framework. Prior to
0.30.9, from ...)
- TODO: check
+ NOT-FOR-US: Decidim
CVE-2026-45086 (Decidim is a participatory democracy framework. From 0.31.1
before 0.3 ...)
- TODO: check
+ NOT-FOR-US: Decidim
CVE-2026-3141 (The FormGent plugin for WordPress is vulnerable to unauthorized
arbitr ...)
NOT-FOR-US: WordPress plugin
CVE-2026-38713 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23,
WR1300 ...)
- TODO: check
+ NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
CVE-2026-38711 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23,
WR1300 ...)
- TODO: check
+ NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
CVE-2026-38710 (TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a
command ...)
- TODO: check
+ NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
CVE-2026-38708 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23,
WR1300 ...)
- TODO: check
+ NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
CVE-2026-34641 (Premiere Pro is affected by an out-of-bounds write
vulnerability that ...)
NOT-FOR-US: Adobe
CVE-2026-18394 (Incorrect authorization in the http_request tool in Strands
Agents Too ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb3f2e5f110d2795abc5be97a544ef82aa489e3c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb3f2e5f110d2795abc5be97a544ef82aa489e3c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits