Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ce7104ed by Salvatore Bonaccorso at 2026-08-06T22:29:43+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -217,7 +217,7 @@ CVE-2026-5391 (The LatePoint plugin for WordPress is
vulnerable to Stored Cross-
CVE-2026-5158 (The Post Grid Gutenberg Blocks for News, Magazines, Blog
Websites \u20 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-5134 (Improper neutralization of special elements used in an SQL
command ('S ...)
- TODO: check
+ NOT-FOR-US: Loca Software Informatics Technology Ltd. Co. CMS
CVE-2026-57819 (Apache CXF allows to set a limit on the number of form
parameters in a ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-57818 (A race condition in JCacheCodeDataProvider allows an attacker
to redee ...)
@@ -293,47 +293,47 @@ CVE-2026-25403 (Unauthenticated Broken Access Control in
Ultimate Store Kit Elem
CVE-2026-1728 (Tokens issued to a low-privileged user are not sufficiently
restricted ...)
NOT-FOR-US: WSO2
CVE-2026-19047 (A vulnerability was detected in NocteDefensor LudusMCP up to
1.0.24. T ...)
- TODO: check
+ NOT-FOR-US: NocteDefensor LudusMCP
CVE-2026-19046 (A security vulnerability has been detected in NocteDefensor
LudusMCP u ...)
- TODO: check
+ NOT-FOR-US: NocteDefensor LudusMCP
CVE-2026-19045 (A weakness has been identified in NocteDefensor LudusMCP up to
1.0.24. ...)
- TODO: check
+ NOT-FOR-US: NocteDefensor LudusMCP
CVE-2026-19044 (A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected
by this ...)
- TODO: check
+ NOT-FOR-US: LeeSinLiang godot-mcp
CVE-2026-19041 (A vulnerability has been found in MissionSquad mcp-api up to
1.11.8. T ...)
- TODO: check
+ NOT-FOR-US: MissionSquad mcp-api
CVE-2026-19040 (A flaw has been found in MissionSquad mcp-api up to 1.11.9.
The affect ...)
- TODO: check
+ NOT-FOR-US: MissionSquad mcp-api
CVE-2026-19039 (A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server
up to 8 ...)
- TODO: check
+ NOT-FOR-US: Kino-Kafkaesque ssh-mcp-server
CVE-2026-19038 (A security vulnerability has been detected in
MonomythDevelopment la-f ...)
- TODO: check
+ NOT-FOR-US: MonomythDevelopmentla-forge-mcp
CVE-2026-19037 (A weakness has been identified in WonderTrader up to 0.9.9.
This vulne ...)
- TODO: check
+ NOT-FOR-US: WonderTrader
CVE-2026-19036 (A security flaw has been discovered in Shibby Tomato
1.28.0000. This a ...)
- TODO: check
+ NOT-FOR-US: Shibby Tomato
CVE-2026-19035 (A vulnerability was identified in Shibby Tomato 1.28.0000.
Affected by ...)
- TODO: check
+ NOT-FOR-US: Shibby Tomato
CVE-2026-19034 (A vulnerability was determined in Shibby Tomato 1.28.0000.
Affected by ...)
- TODO: check
+ NOT-FOR-US: Shibby Tomato
CVE-2026-19022 (A vulnerability was determined in OpenHands up to 0.62.0. The
affected ...)
- TODO: check
+ NOT-FOR-US: OpenHands
CVE-2026-19021 (A security vulnerability has been detected in SourceCodester
Computer ...)
NOT-FOR-US: SourceCodester
CVE-2026-19020 (A weakness has been identified in itsourcecode Hospital
Management Sys ...)
NOT-FOR-US: itsourcecode System
CVE-2026-19019 (A security flaw has been discovered in poco-ai poco-agent up
to 0.5.4. ...)
- TODO: check
+ NOT-FOR-US: poco-ai poco-agent
CVE-2026-19011 (A vulnerability was detected in TinyAGI 0.0.20. The affected
element i ...)
- TODO: check
+ NOT-FOR-US: TinyAGI
CVE-2026-19010 (A security vulnerability has been detected in TinyAGI 0.0.20.
Impacted ...)
- TODO: check
+ NOT-FOR-US: TinyAGI
CVE-2026-19009 (A weakness has been identified in TinyAGI 0.0.20. This issue
affects t ...)
- TODO: check
+ NOT-FOR-US: TinyAGI
CVE-2026-19008 (A vulnerability was identified in mf-yang openclaw-cn up to
0.2.1. Thi ...)
- TODO: check
+ NOT-FOR-US: mf-yang openclaw-cn
CVE-2026-18915 (Invocation of process using visible sensitive information
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: eta-otp-lock
CVE-2026-18649 (A flaw was found in the GStreamer gst-plugins-good package.
The rtph26 ...)
TODO: check
CVE-2026-18597 (The PDF creation feature of Foxit PDF Services API supports
referencin ...)
@@ -341,25 +341,25 @@ CVE-2026-18597 (The PDF creation feature of Foxit PDF
Services API supports refe
CVE-2026-18501 (The UsersWP \u2013 Front-end login form, User Registration,
User Profi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18427 (@fastify/static before version 10.1.3 contains an incomplete
fix for a ...)
- TODO: check
+ NOT-FOR-US: fastify/static
CVE-2026-18359 (Server-side request forgery in the METS and IIIF import URI
handling i ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-18277 (Missing authorization in the OcrModelRight create and delete
views in ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-18276 (Missing authorization in the websocket consumer in Scripta
eScriptoriu ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-18275 (Authorization bypass in the process and annotation taxonomy
serializer ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-18258 (Authorization bypass in the Line, LineTranscription,
VirtualCollection ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-16731 (OMICRON StationScout before version 3.05 contains a
cryptographic timi ...)
- TODO: check
+ NOT-FOR-US: OMICRON
CVE-2026-16316 (OMICRON StationGuard 4.00 contains an improper input
validation vulner ...)
- TODO: check
+ NOT-FOR-US: OMICRON
CVE-2026-16315 (OMICRON StationGuard before version 4.10 contains a
cryptographic timi ...)
- TODO: check
+ NOT-FOR-US: OMICRON
CVE-2026-15599 (Unverified ownership vulnerability in T\xdcB\u0130TAK
B\u0130LGEM Soft ...)
- TODO: check
+ NOT-FOR-US: pardus-domain-joiner
CVE-2026-15246 (The RealHomes Memberships WordPress plugin before 3.1.0 does
not verif ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12605 (In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF
in Downl ...)
@@ -719,7 +719,7 @@ CVE-2026-18325 (The Forminator Forms \u2013 Contact Form,
Payment Form & Custom
CVE-2026-18050 (The Events Manager WordPress plugin before 7.4 does not
perform any a ...)
NOT-FOR-US: WordPress plugin
CVE-2026-17583 (The affected Thermo Fisher Applied Biosystems Genetic
Analyzers arevu ...)
- TODO: check
+ NOT-FOR-US: Thermo Fisher
CVE-2026-17556 (A path traversal vulnerability was identified in GitHub
Enterprise Ser ...)
NOT-FOR-US: Github Enterprise Server
CVE-2026-16954 (The AI Engine WordPress plugin before 3.6.4 does not redact
secret co ...)
@@ -767,9 +767,9 @@ CVE-2026-12713 (The WPCargo Track & Trace WordPress plugin
before 8.0.4 does not
CVE-2026-11588 (The EONSR AEO Agent WordPress plugin through 3.7.9 does not
perform an ...)
NOT-FOR-US: WordPress plugin
CVE-2025-63823 (My Safetipin Android Application 5.2.1 contains Hardcoded
credentials ...)
- TODO: check
+ NOT-FOR-US: My Safetipin Android Application
CVE-2025-63822 (SirenGPS Android Application 2.19.44 is vulnerable to
Incorrect Access ...)
- TODO: check
+ NOT-FOR-US: SirenGPS Android Application
CVE-2025-15678 (The Nexter Blocks WordPress plugin before 5.0.2 does not
sanitize upl ...)
NOT-FOR-US: WordPress plugin
CVE-2023-54389
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ce7104edf21ef862abaf3fd04044f6b474e9e1e1
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ce7104edf21ef862abaf3fd04044f6b474e9e1e1
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits