Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f9175441 by Salvatore Bonaccorso at 2026-08-14T21:32:54+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,13 +5,13 @@ CVE-2026-73849 (Emlog is an open source website building 
system. In 2.6.26 and e
 CVE-2026-73847 (Emlog is an open source website building system. In 2.6.26 and 
earlier ...)
        NOT-FOR-US: Emlog
 CVE-2026-73846 (CKAN MCP Server is a tool for querying CKAN open data portals. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: CKAN MCP Server
 CVE-2026-73845 (CKAN MCP Server is a tool for querying CKAN open data portals. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: CKAN MCP Server
 CVE-2026-73844 (CKAN MCP Server is a tool for querying CKAN open data portals. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: CKAN MCP Server
 CVE-2026-73673 (Netis NC63 router firmware V3.0.0.3327 contains an 
unauthenticated fir ...)
-       TODO: check
+       NOT-FOR-US: Netis NC63 router
 CVE-2026-73633 (Uncontrolled resource consumption vulnerability in the JSON 
plugin of  ...)
        TODO: check
 CVE-2026-73630 (SiYuan before v3.7.4 contains an information disclosure 
vulnerability  ...)
@@ -27,47 +27,47 @@ CVE-2026-73048 (SiYuan versions before v3.7.4 contain an 
information disclosure
 CVE-2026-72970 (Heap-based buffer overflow in Microsoft Edge (Chromium-based) 
allows a ...)
        NOT-FOR-US: Microsoft
 CVE-2026-72859 (Budibase versions 3.39.4 before 3.40.0 contain an 
authorization regres ...)
-       TODO: check
+       NOT-FOR-US: Budibase
 CVE-2026-72838 (FileBrowser versions before 2.63.19 fail to enforce the 
declared Uploa ...)
-       TODO: check
+       NOT-FOR-US: FileBrowser
 CVE-2026-72837 (File Browser versions before 2.63.20 fail to honor the 
createUserDir i ...)
-       TODO: check
+       NOT-FOR-US: FileBrowser
 CVE-2026-72836 (FileBrowser before 2.63.19 does not account for 
case-insensitive files ...)
-       TODO: check
+       NOT-FOR-US: FileBrowser
 CVE-2026-72835 (filebrowser versions before v2.63.21 fail to canonicalize 
paths before ...)
-       TODO: check
+       NOT-FOR-US: FileBrowser
 CVE-2026-72834 (filebrowser before 2.63.19 contains a permission bypass in the 
/api/re ...)
-       TODO: check
+       NOT-FOR-US: FileBrowser
 CVE-2026-72833 (The Grav API plugin (getgrav/grav-plugin-api) versions >= 
1.0.6 and <= ...)
-       TODO: check
+       NOT-FOR-US: Grav API plugin
 CVE-2026-72832 (Grav versions from 1.5.2 through 2.0.12 contain a stored 
cross-site sc ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-72831 (The Flex Objects plugin (through 1.4.6, tested with Grav 
2.0.11) conta ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72830 (Grav API plugin versions before 1.0.13 fail to enforce API key 
scope c ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72829 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 
contains a ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72828 (Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails 
to enfor ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72827 (Grav CMS before 2.0.13 contains a server-side template 
injection vulne ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-72826 (The getgrav/grav-plugin-api plugin before 1.0.13 fails to 
validate tha ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72825 (The getgrav/grav-plugin-api plugin before 1.0.13 contains an 
API-key s ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72824 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 
contains a ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72823 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 
contains a ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72822 (The getgrav/grav-plugin-api Composer package before 1.0.13 
(affected < ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72821 (Grav Form plugin versions before 9.1.15 contain a stored 
cross-site sc ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72820 (Grav versions before 2.0.13 fail to properly validate backup 
profile r ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-72819 (Grav CMS before 2.0.13 contains a remote code execution 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-72817 (go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing 
vulnera ...)
        TODO: check
 CVE-2026-72816 (go-chi/chi through 5.2.1 contains an IP spoofing vulnerability 
in the  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9175441e4a666012f02af511a536c27e863350f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9175441e4a666012f02af511a536c27e863350f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to