Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
1f43d44e by Salvatore Bonaccorso at 2026-08-04T21:33:11+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,25 +9,25 @@ CVE-2026-70471 (Flowise is a drag-and-drop user interface for
building customize
CVE-2026-70470 (Flowise is a drag & drop user interface to build a customized
large la ...)
NOT-FOR-US: Flowise
CVE-2026-70373 (Koha's reports/issues_stats.pl (the circulation statistics
report) bui ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70372 (Koha's reports/bor_issues_top.pl builds dynamic SQL in sub
calculate b ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70371 (Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub
calculate ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70370 (Koha's reports/catalogue_stats.pl builds dynamic SQL in sub
calculate ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70369 (Koha's reports/acquisitions_stats.pl builds its per-cell
statistics qu ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70368 (A stack-based out-of-bounds read vulnerability exists in the
"s_vlog" ...)
TODO: check
CVE-2026-70367 (A Server-Side Request Forgery (SSRF) bypass vulnerability
exists in \u ...)
TODO: check
CVE-2026-69704 (Atals-Livre contains a SQL injection vulnerability that allows
attacke ...)
- TODO: check
+ NOT-FOR-US: Atals-Livre
CVE-2026-69703 (Atlas-Livre contains an improper access control vulnerability
in the a ...)
- TODO: check
+ NOT-FOR-US: Atals-Livre
CVE-2026-69702 (SnailJob 1.7.0 contains a denial of service vulnerability in
the FuryU ...)
- TODO: check
+ NOT-FOR-US: SnailJob
CVE-2026-69264 (Prior to 3.1.3, Flowise CSVAgent interpolates an
attacker-controlled s ...)
NOT-FOR-US: Flowise
CVE-2026-69263 (Flowise is a drag & drop user interface to build a customized
large la ...)
@@ -55,43 +55,43 @@ CVE-2026-69251 (Flowise is a drag & drop user interface to
build a customized la
CVE-2026-69250 (Flowise is a drag & drop user interface to build a customized
large la ...)
NOT-FOR-US: Flowise
CVE-2026-69110 (OpenCode Studio before 2.4.4 contains a missing authentication
vulnera ...)
- TODO: check
+ NOT-FOR-US: OpenCode Studio
CVE-2026-69100 (LAMP Rapid Development Platform through 5.6.2, fixed in commit
84b0c27 ...)
- TODO: check
+ NOT-FOR-US: LAMP Rapid Development Platform
CVE-2026-69098 (kotaemon through 0.12.0 contains an insecure deserialization
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: kotaemon
CVE-2026-68743 (A flaw was found in SSSD. The extract_authtok_v1() function in
the PAM ...)
TODO: check
CVE-2026-68494 (The fix released in jackson-core 2.18.6 and 2.21.1 for
CVE-2026-18401 ...)
TODO: check
CVE-2026-67618 (marimo before 0.23.15 contains a configuration injection
vulnerability ...)
- TODO: check
+ NOT-FOR-US: marimo
CVE-2026-67243 (freo2 provided by refirio contains an unrestricted upload of
file with ...)
- TODO: check
+ NOT-FOR-US: freo2
CVE-2026-67200 (Perspective 5.0.0 contains a path traversal vulnerability that
allows ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-67199 (Perspective 5.0.0 contains a denial of service vulnerability
that allo ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-67198 (Perspective 5.0.0 contains a denial-of-service vulnerability
in the Vi ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-67196 (Perspective 5.0.0 contains a cross-site scripting
vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-67195 (Perspective 5.0.0 contains a remote code execution
vulnerability that ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-66884 (Cross-Site Request Forgery vulnerability in Erlang Ecosystem
Foundatio ...)
TODO: check
CVE-2026-66883 (Improper Handling of Case Sensitivity vulnerability in Erlang
Ecosyste ...)
TODO: check
CVE-2026-66300 (SNOMED International Snowstorm contains a reflected XSS
vulnerability ...)
- TODO: check
+ NOT-FOR-US: SNOMED International Snowstorm
CVE-2026-64634 (A vulnerability allowing local privilege escalation to the
Reporter se ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-64633 (A vulnerability allowing remote unauthenticated code execution
on the ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-64631 (A vulnerability allowing a low-privileged user to inject SQL
and extra ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-64630 (A vulnerability allowing a low-privileged user to retrieve
report data ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-63456 (Multiple vulnerabilities in the REST API interface of HPE
Networking S ...)
NOT-FOR-US: HPE
CVE-2026-63455 (Multiple vulnerabilities in the REST API interface of HPE
Networking S ...)
@@ -103,9 +103,9 @@ CVE-2026-63248 (In Eclipse Milo versions 0.6.0 through
1.1.4, OPC UA server diag
CVE-2026-62927 (In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service
dispatc ...)
TODO: check
CVE-2026-61515 (Puwell IP Camera firmware versions 2.x through 4.x contains an
unauthe ...)
- TODO: check
+ NOT-FOR-US: Puwell IP Camera firmware
CVE-2026-61514 (Puwell IP Camera firmware versions 2.x through 4.x contains an
authent ...)
- TODO: check
+ NOT-FOR-US: Puwell IP Camera firmware
CVE-2026-61387 (In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item
quota acc ...)
TODO: check
CVE-2026-60007 (In Eclipse Milo versions 0.6.0 through 1.1.4, username-token
processin ...)
@@ -113,21 +113,21 @@ CVE-2026-60007 (In Eclipse Milo versions 0.6.0 through
1.1.4, username-token pro
CVE-2026-58080 (In Eclipse Milo versions 1.0.0 through 1.1.4,
`OpcUaServerConfig.copy( ...)
TODO: check
CVE-2026-58075 (A vulnerability allowing an unauthenticated attacker to read
arbitrary ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58074 (A vulnerability allowing a high-privileged user to execute
arbitrary c ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58073 (A vulnerability in Veeam Service Provider Console allowing an
unauthen ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58072 (A vulnerability in Veeam Service Provider Console allowing
arbitrary f ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58071 (A vulnerability in Veeam Service Provider Console allowing an
unauthen ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58067 (A vulnerability in Veeam Service Provider Console allowing an
unauthen ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-49435 (Keysight IxChariot Endpoint and associated products contain a
stack-ba ...)
- TODO: check
+ NOT-FOR-US: Keysight
CVE-2026-48121 (@langchain/langgraph-checkpoint-mongodb provides a
LangGraph.js Checkp ...)
- TODO: check
+ NOT-FOR-US: langchain/langgraph-checkpoint-mongodb
CVE-2026-47781 (PDM is a Python package and dependency manager. In versions up
to and ...)
TODO: check
CVE-2026-47764 (pdm is a Python package and dependency manager supporting the
latest P ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f43d44e5906d79f219d35217120c0fe7be7553e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f43d44e5906d79f219d35217120c0fe7be7553e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits