Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
502211c7 by Moritz Muehlenhoff at 2026-08-11T23:47:23+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -244,51 +244,51 @@ CVE-2026-72694 (A flaw was found in MRTG. When the MRTG 
daemon is started as a r
 CVE-2026-72693 (`openvt -u` is intended to identify the owner of the current 
VT and th ...)
        TODO: check
 CVE-2026-72610 (A stored SQL injection vulnerability in Koha through 24.11.17, 
25.05.1 ...)
-       TODO: check
+       - koha <itp> (bug #702134)
 CVE-2026-72609 (An SQL injection vulnerability in Koha through 24.11.17, 
25.05.12, 25. ...)
-       TODO: check
+       - koha <itp> (bug #702134)
 CVE-2026-72608 (A stored SQL injection vulnerability in Koha through 24.11.17, 
25.05.1 ...)
-       TODO: check
+       - koha <itp> (bug #702134)
 CVE-2026-72607 (A stored SQL injection vulnerability in Koha through 24.11.17, 
25.05.1 ...)
-       TODO: check
+       - koha <itp> (bug #702134)
 CVE-2026-72606 (A server-side request forgery vulnerability in Pinry through 
2.1.13 al ...)
        TODO: check
 CVE-2026-72605 (A missing authentication vulnerability in Swing Music 3.0.0 
allows una ...)
        TODO: check
 CVE-2026-72604 (A path traversal vulnerability in Intelliants Subrion CMS 
through 4.2. ...)
-       TODO: check
+       NOT-FOR-US: Subrion CMS
 CVE-2026-72603 (An OS command injection vulnerability in wg-easy 15.3.0 allows 
users w ...)
        TODO: check
 CVE-2026-72602 (A path traversal vulnerability in AsyncFuncAI deepwiki-open 
through co ...)
-       TODO: check
+       NOT-FOR-US: AsyncFuncAI deepwiki-open
 CVE-2026-72601 (A broken access control vulnerability in CSZ CMS 1.3.2 allows 
unauthen ...)
-       TODO: check
+       NOT-FOR-US: CSZ CMS
 CVE-2026-72600 (A broken access control vulnerability in Idurar IDURAR ERP CRM 
4.1.0 a ...)
-       TODO: check
+       NOT-FOR-US: Idurar IDURAR ERP CRM
 CVE-2026-72599 (An SQL injection vulnerability in e107 2.4.0 allows 
unauthenticated re ...)
-       TODO: check
+       NOT-FOR-US: e107
 CVE-2026-72598 (A server-side request forgery vulnerability in Apioo Fusio 
8.8.3 allow ...)
-       TODO: check
+       NOT-FOR-US: Apioo Fusio
 CVE-2026-72597 (A server-side request forgery vulnerability in Friendica 
through the 2 ...)
-       TODO: check
+       NOT-FOR-US: Friendica
 CVE-2026-72596 (A broken access control vulnerability in Ghost Foundation 
Ghost 5.x al ...)
-       TODO: check
+       - ghost <itp> (bug #892150)
 CVE-2026-72595 (A broken access control vulnerability in BadChoice Handesk as 
of 2026- ...)
-       TODO: check
+       NOT-FOR-US: BadChoice Handesk
 CVE-2026-72563 (A broken access control vulnerability in BadChoice Handesk as 
of 2026- ...)
-       TODO: check
+       NOT-FOR-US: BadChoice Handesk
 CVE-2026-72562 (An SQL injection vulnerability in Pimcore 
admin-ui-classic-bundle thro ...)
-       TODO: check
+       NOT-FOR-US: Pimcore admin-ui-classic-bundle
 CVE-2026-72561 (A broken access control vulnerability in Peppermint Lab 
Peppermint thr ...)
        TODO: check
 CVE-2026-72560 (A server-side request forgery vulnerability in HumanSignal 
Label Studi ...)
        TODO: check
 CVE-2026-72559 (A stored cross-site scripting vulnerability in HortusFox 5.9 
allows au ...)
-       TODO: check
+       NOT-FOR-US: HortusFox
 CVE-2026-72558 (An SQL injection vulnerability in CiviCRM through 6.18.alpha1 
allows a ...)
        TODO: check
 CVE-2026-72557 (An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 
allows  ...)
-       TODO: check
+       NOT-FOR-US: Cockpit CMS
 CVE-2026-72556 (A remote code execution vulnerability in ZoneMinder 1.39.17 
allows any ...)
        TODO: check
 CVE-2026-72555 (A broken access control vulnerability in Peppermint Lab 
Peppermint thr ...)
@@ -296,47 +296,47 @@ CVE-2026-72555 (A broken access control vulnerability in 
Peppermint Lab Peppermi
 CVE-2026-72554 (A broken access control vulnerability in Ladybird Web Solution 
Faveo H ...)
        TODO: check
 CVE-2026-72553 (A stored cross-site scripting vulnerability in ElkArte Forum 
2.0 Beta  ...)
-       TODO: check
+       NOT-FOR-US: ElkArte Forum
 CVE-2026-72552 (A server-side request forgery vulnerability in Dub as of 
2026-07-10 al ...)
        TODO: check
 CVE-2026-72551 (A remote code execution vulnerability in Apioo Fusio 8.8.3 
allows auth ...)
        TODO: check
 CVE-2026-72550 (An SQL injection vulnerability in Friendica through the 
2026.08-dev br ...)
-       TODO: check
+       NOT-FOR-US: Friendica
 CVE-2026-72549 (An information disclosure vulnerability in OpenSignLabs 
OpenSign throu ...)
-       TODO: check
+       NOT-FOR-US: OpenSignLabs OpenSign
 CVE-2026-72548 (An information disclosure vulnerability in OpenSignLabs 
OpenSign throu ...)
-       TODO: check
+       NOT-FOR-US: OpenSignLabs OpenSign
 CVE-2026-72547 (An insecure direct object reference vulnerability in Attendize 
through ...)
        TODO: check
 CVE-2026-72546 (An insecure direct object reference vulnerability in Attendize 
through ...)
        TODO: check
 CVE-2026-72545 (An insecure direct object reference vulnerability in 
OpenSignLabs Open ...)
-       TODO: check
+       NOT-FOR-US: OpenSignLabs OpenSign
 CVE-2026-72544 (An integrity verification vulnerability in OpenSignLabs 
OpenSign throu ...)
-       TODO: check
+       NOT-FOR-US: OpenSignLabs OpenSign
 CVE-2026-72543 (An insecure direct object reference vulnerability in 
OpenSignLabs Open ...)
-       TODO: check
+       NOT-FOR-US: OpenSignLabs OpenSign
 CVE-2026-72542 (A missing authorization vulnerability in Windmill Labs 
Windmill throug ...)
-       TODO: check
+       NOT-FOR-US: Windmill
 CVE-2026-72541 (A missing authorization vulnerability in Windmill Labs 
Windmill throug ...)
-       TODO: check
+       NOT-FOR-US: Windmill
 CVE-2026-72540 (An insecure direct object reference vulnerability in 
PhotoPrism throug ...)
-       TODO: check
+       NOT-FOR-US: PhotoPrism
 CVE-2026-72539 (An information disclosure vulnerability in Windmill Labs 
Windmill thro ...)
-       TODO: check
+       NOT-FOR-US: Windmill
 CVE-2026-72538 (An argument injection vulnerability in PrefectHQ Prefect 
through 3.8.2 ...)
        TODO: check
 CVE-2026-72537 (A privilege escalation vulnerability in Authentik Security 
authentik t ...)
-       TODO: check
+       NOT-FOR-US: authentik
 CVE-2026-72536 (A missing authentication vulnerability in Chaskiq through 
commit 46dfd ...)
        TODO: check
 CVE-2026-72535 (A missing authentication vulnerability in Chaskiq through 
commit 46dfd ...)
        TODO: check
 CVE-2026-72534 (A privilege escalation vulnerability in Authentik Security 
authentik t ...)
-       TODO: check
+       NOT-FOR-US: authentik
 CVE-2026-72533 (An authentication bypass vulnerability in Portainer CE through 
2.44.0  ...)
-       TODO: check
+       NOT-FOR-US: Portainer
 CVE-2026-71398 (Adobe Campaign Classic (ACC) is affected by an Incorrect 
Authorization ...)
        NOT-FOR-US: Adobe
 CVE-2026-71390 (CAI Content Credentials is affected by an Improper Input 
Validation vu ...)
@@ -1172,9 +1172,9 @@ CVE-2026-57105 (Improper neutralization of input during 
web page generation ('cr
 CVE-2026-57104 (Improper neutralization of input during web page generation 
('cross-si ...)
        NOT-FOR-US: Microsoft
 CVE-2026-56721 (CamaleonCMS version 2.9.2 and earlier contains a privilege 
escalation  ...)
-       TODO: check
+       NOT-FOR-US: CamaleonCMS
 CVE-2026-56720 (CamaleonCMS version 2.9.2 and earlier contains a missing 
authorization ...)
-       TODO: check
+       NOT-FOR-US: CamaleonCMS
 CVE-2026-56179 (Origin validation error in Windows Network Address Translation 
(NAT) a ...)
        NOT-FOR-US: Microsoft
 CVE-2026-56174 (Untrusted search path in Windows Narrator Braille allows an 
authorized ...)
@@ -1230,17 +1230,17 @@ CVE-2026-48802 (python-engineio is a Python 
implementation of the Engine.IO real
 CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the 
open-source datab ...)
        TODO: check
 CVE-2026-48771 (ishankportfolio is a portfolio website. Prior to version 
1.0.1, contac ...)
-       TODO: check
+       NOT-FOR-US: ishankportfolio
 CVE-2026-48767 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 
allow a lo ...)
-       TODO: check
+       NOT-FOR-US: TypeBot
 CVE-2026-48766 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 
allow a lo ...)
-       TODO: check
+       NOT-FOR-US: TypeBot
 CVE-2026-48495 (TypeBot is a chatbot builder tool. Prior to version 3.17.0, 
the Google ...)
-       TODO: check
+       NOT-FOR-US: TypeBot
 CVE-2026-48494 (TypeBot is a chatbot builder tool. In version 3.16.1, an 
authenticated ...)
-       TODO: check
+       NOT-FOR-US: TypeBot
 CVE-2026-48483 (TypeBot is a chatbot builder tool. Prior to version 3.17.0, 
Typebot's  ...)
-       TODO: check
+       NOT-FOR-US: TypeBot
 CVE-2026-48447 (Lightroom Classic is affected by an Incorrect Authorization 
vulnerabil ...)
        NOT-FOR-US: Adobe
 CVE-2026-48446 (CAI Content Credentials is affected by an Improper Limitation 
of a Pat ...)
@@ -1322,17 +1322,17 @@ CVE-2026-47940 (Lightroom Classic is affected by an 
Integer Overflow or Wraparou
 CVE-2026-47922 (CAI Content Credentials is affected by a Server-Side Request 
Forgery ( ...)
        NOT-FOR-US: Adobe
 CVE-2026-47705 (TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV 
injection  ...)
-       TODO: check
+       NOT-FOR-US: TypeBot
 CVE-2026-47704 (TypeBot is a chatbot builder tool. Prior to version 3.17.0, an 
authent ...)
-       TODO: check
+       NOT-FOR-US: TypeBot
 CVE-2026-47702 (TypeBot is a chatbot builder tool. In version 3.16.1, API 
tokens (bear ...)
-       TODO: check
+       NOT-FOR-US: TypeBot
 CVE-2026-47299 (Improper neutralization of special elements used in a command 
('comman ...)
        NOT-FOR-US: Microsoft
 CVE-2026-47285 (Improper neutralization of special elements used in a command 
('comman ...)
        NOT-FOR-US: Microsoft
 CVE-2026-46670 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.4,  an u ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-43606 (Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA 
secp256 ...)
        TODO: check
 CVE-2026-42976 (Missing authentication for critical function in Windows RPC 
API allows ...)
@@ -1496,63 +1496,63 @@ CVE-2026-18972 (An authenticated attacker can spoof 
another GUI user's identity
 CVE-2026-18860 (Velociraptor allows multi-tenant deployments named "Orgs".  By 
default ...)
        TODO: check
 CVE-2026-18712 (An issue in MongoDB Server's Queryable Encryption maintenance 
operatio ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18711 (An issue in MongoDB Server's query execution engine could 
allow an aut ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18709 (An issue in MongoDB Server could allow an authenticated user 
with dire ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18708 (An issue in MongoDB Server's JavaScript scripting engine could 
allow a ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18707 (An issue in MongoDB Server could allow an authenticated user, 
includin ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18706 (An issue in MongoDB Server's $graphLookup aggregation stage 
could allo ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18705 (An issue in MongoDB Server's Atlas Vector Search feature could 
allow a ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18704 (An issue in MongoDB Server's aggregation framework could allow 
an auth ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18703 (An issue in MongoDB Server could allow a party with a valid 
client cer ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18702 (An issue in MongoDB Server could allow an authenticated user 
with limi ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18701 (An issue in MongoDB Server's query subsystem could allow an 
authentica ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18700 (An issue in MongoDB Server's geospatial validation could allow 
an auth ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18699 (An issue in MongoDB Server's query planner could allow an 
authenticate ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18698 (An issue in MongoDB Server could allow an authenticated user 
with a li ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18697 (An issue in MongoDB Server's aggregation framework could allow 
an unau ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18696 (An issue in MongoDB Server's applyOps command could allow an 
authentic ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18695 (An issue in MongoDB Server's handling of certain query 
predicates agai ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18694 (An issue in MongoDB Server's geospatial query processing could 
allow a ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18693 (An issue in MongoDB Server's handling of timeseries 
collections could  ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18692 (An issue in MongoDB Server's handling of timeseries bucket 
lifecycle c ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18691 (An issue in MongoDB Server's intra-cluster connection setup 
could allo ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18690 (An issue in MongoDB Server could allow an authenticated user 
with a li ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18688 (An issue in MongoDB Server's aggregation framework could allow 
an auth ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18687 (MongoDB Server's handling of a Queryable Encryption 
maintenance operat ...)
-       TODO: check
+       - mongodb <removed>
 CVE-2026-18640 (The NewNotebook API does not sufficiently sanitize its 
parameters allo ...)
        TODO: check
 CVE-2026-18639 (When Velociraptor is configured to use an OIDC IdP for 
authentication, ...)
-       TODO: check
+       NOT-FOR-US: Velociraptor
 CVE-2026-18638 (Any authenticated Velociraptor user \u2014 including one 
holding only  ...)
-       TODO: check
+       NOT-FOR-US: Velociraptor
 CVE-2026-18636 (The Velociraptor gRPC API has a VFSGetBuffer endpoint which 
allows rea ...)
-       TODO: check
+       NOT-FOR-US: Velociraptor
 CVE-2026-18635 (Velociraptor's VQL has a query() plugin which allows running a 
VQL que ...)
-       TODO: check
+       NOT-FOR-US: Velociraptor
 CVE-2026-18247 (A Cross Site Scripting (XSS) vulnerability in the Web Portals 
of AtHoc ...)
        NOT-FOR-US: Blackberry
 CVE-2026-18129 (Cleartext transmission of sensitive information in the Core of 
Ivanti  ...)
@@ -1562,7 +1562,7 @@ CVE-2026-18127 (External control of a filename in the 
Core of Ivanti Endpoint Ma
 CVE-2026-18125 (An out-of-boundsread intheAgent ofIvanti Endpoint 
Managerbeforeversion ...)
        NOT-FOR-US: Ivanti
 CVE-2026-17535 (Velociraptor's NTFS parsing library mishandles several out of 
bound an ...)
-       TODO: check
+       NOT-FOR-US: Velociraptor
 CVE-2026-17061 (A Deserialization of Untrusted Data vulnerability affecting 
SIMULIA Ex ...)
        NOT-FOR-US: Dassault Systemes
 CVE-2026-15567 (A flaw was found in Wildfly. A remote unauthenticated attacker 
can tri ...)
@@ -1652,7 +1652,7 @@ CVE-2023-54368
 CVE-2023-54367
        REJECTED
 CVE-2022-50997 (Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Weaver E-cology
 CVE-2022-50974
        REJECTED
 CVE-2021-47995
@@ -1690,7 +1690,7 @@ CVE-2020-37258
 CVE-2020-37257
        REJECTED
 CVE-2016-20097 (Weaver (Fanwei) E-cology 8.0 contains a SQL injection 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: Weaver E-cology
 CVE-2026-20707 (Hardware logic contains race conditions for some 3rd Gen 
Intel(R) Xeon ...)
        - intel-microcode <unfixed> (bug #1144158)
        [trixie] - intel-microcode <postponed> (As usual fixed top-down, expose 
first in unstable, then likely point release)
@@ -1915,9 +1915,9 @@ CVE-2026-72873 (Dokploy is a free, self-hostable Platform 
as a Service (PaaS). P
 CVE-2026-72743 (SQLBot through 1.10.0, fixed in commit c3f40a5, contains a 
stored cros ...)
        NOT-FOR-US: SQLBot
 CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an 
authenticated c ...)
-       TODO: check
+       NOT-FOR-US: CyberPanel
 CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an 
authenticated r ...)
-       TODO: check
+       NOT-FOR-US: CyberPanel
 CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use 
(TOCTOU) ra ...)
        NOT-FOR-US: Axis Communication
 CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost 
inflight migra ...)
@@ -1927,7 +1927,7 @@ CVE-2026-6181 (The Device Configuration Framework is 
vulnerable to an authentica
 CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection 
vulnera ...)
        TODO: check
 CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown 
rendering an ...)
-       TODO: check
+       NOT-FOR-US: FlyEnv
 CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel 
message ...)
        TODO: check
 CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path 
traversal vulne ...)
@@ -2113,17 +2113,17 @@ CVE-2025-30238 (In affected TP-Link Aginet devices, 
insufficient authorization v
 CVE-2025-30237 (The affected TP-Link Aginet devicescontain a flaw in the web 
managemen ...)
        NOT-FOR-US: TPLink
 CVE-2025-15683 (TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple 
unauthenticated denial ...)
-       TODO: check
+       NOT-FOR-US: TBEA TLogger
 CVE-2025-15682 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated 
resource exh ...)
-       TODO: check
+       NOT-FOR-US: TBEA TLogger
 CVE-2025-15681 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication 
bypass in its ...)
-       TODO: check
+       NOT-FOR-US: TBEA TLogger
 CVE-2025-15680 (TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the 
device's ...)
-       TODO: check
+       NOT-FOR-US: TBEA TLogger
 CVE-2025-13294 (An unauthenticated SQL injection vulnerability exists in the 
web serve ...)
-       TODO: check
+       NOT-FOR-US: TBEA TLogger
 CVE-2025-13293 (A hard-coded or default root account credential in TBEA 
TLogger V2.1.0 ...)
-       TODO: check
+       NOT-FOR-US: TBEA TLogger
 CVE-2026-19349
        - lemonldap-ng 2.23.3+ds-1
        NOTE: 
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8c6015d6f0b4f1aa78bd54e159a74cd151e8e00d
 (v2.23.3)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/502211c70a775711b44ab9c85efd1de658f940ec

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/502211c70a775711b44ab9c85efd1de658f940ec
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to