Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2a484189 by Moritz Muehlenhoff at 2026-08-12T08:30:48+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,5 @@
+CVE-2026-19496
+ NOT-FOR-US: Red Hat sources-api-go
CVE-2026-73283
- openssh <unfixed>
NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
@@ -2294,11 +2296,11 @@ CVE-2026-14549 (The Ray Enterprise Translation
WordPress plugin through 1.7.3 do
CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3
does not ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows
any pod wi ...)
- TODO: check
+ NOT-FOR-US: Red Hat OpenShift AI
CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS
Gateway. Imp ...)
NOT-FOR-US: Red Hat OpenShift AI
CVE-2026-13716 (Path traversal in server import and admin file upload in
Crafty Contro ...)
- TODO: check
+ NOT-FOR-US: Crafty Controller
CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler
usbd_cdc_ncm ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12051 (The USB DFU class implementation in Zephyr's new
(experimental) device ...)
@@ -2380,7 +2382,7 @@ CVE-2026-72863 (Dokploy is a free, self-hostable Platform
as a Service (PaaS). P
CVE-2026-72862 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
NOT-FOR-US: Dokploy
CVE-2026-72761 (The webhook URL validator in
`website/notifications/webhooks.py` uses ...)
- TODO: check
+ NOT-FOR-US: vulnerability-lookup
CVE-2026-72760 (Affected versions of MISP cti-transmute disclose users' email
addresse ...)
NOT-FOR-US: MISP
CVE-2026-72759 (In affected versions of MISP cti-transmute, the
conversion-history det ...)
@@ -2608,9 +2610,9 @@ CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger-
provided by Nishishi Factory
CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or
convert op ...)
TODO: check
CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL
injection ...)
- TODO: check
+ NOT-FOR-US: ReadyEcommerceCrafty Controller
CVE-2026-63105 (ReadyEcommerce before 4.5.2 contains a stored cross-site
scripting (XS ...)
- TODO: check
+ NOT-FOR-US: ReadyEcommerceCrafty Controller
CVE-2026-59233 (Missing Authorization in the permission management component
in Roskus ...)
TODO: check
CVE-2026-59112 (Improper verification of cryptographic signature and Improper
Check fo ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a4841893fffb9d862e41119f463a17ba1d4ce38
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a4841893fffb9d862e41119f463a17ba1d4ce38
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits