Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6ebaf074 by Moritz Muehlenhoff at 2026-08-16T23:06:46+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -105,19 +105,19 @@ CVE-2026-2283 (The User Login History plugin for 
WordPress is vulnerable to SQL
 CVE-2026-19934 (A vulnerability has been found in itsourcecode Hospital 
Management Sys ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-19933 (A weakness has been identified in DefaultFuction 
Customer-Relationship ...)
-       TODO: check
+       NOT-FOR-US: Customer-Relationship-Management-In-C-Project
 CVE-2026-19932 (A security flaw has been discovered in DefaultFuction 
Notice-System-Ma ...)
-       TODO: check
+       NOT-FOR-US: Notice-System-Managent
 CVE-2026-19930 (A security flaw has been discovered in Dolibarr up to 23.0.3. 
Affected ...)
        NOT-FOR-US: Dolibarr
 CVE-2026-19929 (A vulnerability was identified in OpenBoxes up to 0.9.6. This 
impacts  ...)
-       TODO: check
+       NOT-FOR-US: OpenBoxes
 CVE-2026-19928 (A vulnerability was determined in OpenBoxes up to 0.9.7. This 
affects  ...)
-       TODO: check
+       NOT-FOR-US: OpenBoxes
 CVE-2026-19927 (A vulnerability was found in OpenBoxes up to 0.9.7. The 
impacted eleme ...)
-       TODO: check
+       NOT-FOR-US: OpenBoxes
 CVE-2026-19926 (A vulnerability has been found in Evergreen up to 
3.14.11/3.15.11/3.16 ...)
-       TODO: check
+       NOT-FOR-US: Evergreen
 CVE-2026-19925 (A vulnerability was detected in SourceCodester Stock 
Management System ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-19924 (A security vulnerability has been detected in Tenda AC10 
16.03.10.09_m ...)
@@ -133,7 +133,7 @@ CVE-2026-19920 (A vulnerability was determined in 
code-projects Online Shopping
 CVE-2026-19919 (A vulnerability was found in code-projects Online Shopping 
System 1.0. ...)
        NOT-FOR-US: code-projects
 CVE-2026-19918 (A vulnerability has been found in SpaceX Starlink Router Gen 3 
2025.11 ...)
-       TODO: check
+       NOT-FOR-US: SpaceX
 CVE-2026-19917 (A flaw has been found in code-projects Online Food Order 
System 1.0. T ...)
        NOT-FOR-US: code-projects
 CVE-2026-19916 (A vulnerability was detected in code-projects Online Food 
Order System ...)
@@ -287,17 +287,17 @@ CVE-2026-19891 (A vulnerability was determined in 
TRENDnet TEW-WLC100 2.05b02. T
 CVE-2026-19598 (The Pods \u2013 Custom Content Types and Fields plugin for 
WordPress i ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-19474 (@fastify/multipart is a multipart form-data parser for 
Fastify. In ver ...)
-       TODO: check
+       NOT-FOR-US: @fastify/multipart
 CVE-2026-18855 (The Link Library plugin for WordPress is vulnerable to 
arbitrary file  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-18549 (@fastify/multipart is a multipart form-data parser for 
Fastify. In ver ...)
-       TODO: check
+       NOT-FOR-US: @fastify/multipart
 CVE-2026-18500 (@fastify/jwt is a JSON Web Token plugin for Fastify. In 
versions befor ...)
-       TODO: check
+       NOT-FOR-US: @fastify/jwt
 CVE-2026-18438 (The Templately \u2013 Elementor & Gutenberg Template Library: 
6500+ Fr ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-18165 (@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In 
versions from 7 ...)
-       TODO: check
+       NOT-FOR-US: @fastify/oauth2
 CVE-2026-16142 (The TrueBooker plugin for WordPress is vulnerable to Account 
Takeover  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15142 (The Real Estate Manager Pro plugin for WordPress is vulnerable 
to Priv ...)
@@ -989,7 +989,7 @@ CVE-2026-16094 (The Invisible Anti-Spam & CAPTCHA \u2014 
reCAPTCHA Alternative f
 CVE-2026-16080 (The Image Uploader for Welcart plugin for WordPress is 
vulnerable to g ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-16007 (AppFlowy's qcuiknote feature is affected by a SQL injection 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: AppFlowy
 CVE-2026-15993 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop 
Contact For ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15965 (The MaxUpload \u2013 Big File Uploads \u2013 Increase Maximum 
File Upl ...)
@@ -5022,7 +5022,7 @@ CVE-2026-46439 (compliance-trestle is a tooling platform 
for managing compliance
 CVE-2026-46380 (compliance-trestle is a tooling platform for managing 
compliance as co ...)
        NOT-FOR-US: compliance-trestle
 CVE-2026-1621 (Authentication bypass by primary weakness vulnerability in 
Universal S ...)
-       TODO: check
+       NOT-FOR-US: E-Municipality
 CVE-2026-19884 (In Eclipse Theia versions up to and including 1.69.0, opening 
a folder ...)
        NOT-FOR-US: Eclipse
 CVE-2026-19880 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic on 
Java (l ...)
@@ -5111,17 +5111,17 @@ CVE-2026-19628 (A command injection vulnerability 
exists in Tenable Security Cen
 CVE-2026-19626 (A remote code execution vulnerability exists in Tenable 
Security Cente ...)
        NOT-FOR-US: Tenable
 CVE-2026-19188 (A critical OS command injection vulnerability has been 
identified in t ...)
-       TODO: check
+       NOT-FOR-US: Haiwell
 CVE-2026-18403 (LimeSurvey Community Edition 7.0.5 contains an authenticated 
SQL injec ...)
-       TODO: check
+       - limesurvey <itp> (bug #472802)
 CVE-2026-16772 (In Akaunting versions <= 3.1.21, low\u2011privileged 
authenticated use ...)
-       TODO: check
+       NOT-FOR-US: Akaunting
 CVE-2026-13198 (Nozomi Networks Labs identified a CWE-362: Concurrent 
Execution using  ...)
-       TODO: check
+       NOT-FOR-US: KUNBUS
 CVE-2026-13197 (Nozomi Networks Labs identified a CWE-362: Concurrent 
Execution using  ...)
-       TODO: check
+       NOT-FOR-US: KUNBUS
 CVE-2026-13196 (Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: KUNBUS
 CVE-2026-13002 (A flow has been identified into dnssec.c library, causing an 
infinite  ...)
        TODO: check
 CVE-2026-12366 (Zephyr's dynamic kernel-object disposal path unref_check() in 
kernel/u ...)
@@ -5133,7 +5133,7 @@ CVE-2026-12364 (The user-space system-call verifier 
z_vrfy_z_log_msg_static_crea
 CVE-2026-12363 (The LoRaWAN Fragmented Data Block Transport service 
(subsys/lorawan/se ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-7639 (The vulnerability, if exploited, could allow an authenticated 
miscrean ...)
-       TODO: check
+       NOT-FOR-US: AVEVA
 CVE-2025-71405 (chi versions before v5.2.2 contain an open redirect 
vulnerability in t ...)
        TODO: check
 CVE-2023-7347
@@ -5472,7 +5472,7 @@ CVE-2026-19297 (IBM Langflow OSS 1.0.0 through 1.9.6 
could allow a remote attack
 CVE-2026-18846 (IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow 
from im ...)
        NOT-FOR-US: IBM
 CVE-2026-18741 (Worksuite SaaS versions prior to 6.0.14 contains a stored 
cross-site s ...)
-       TODO: check
+       NOT-FOR-US: Froiden Worksuite SaaS
 CVE-2026-18715 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
        NOT-FOR-US: IBM
 CVE-2026-18671 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated 
attacker to  ...)
@@ -5488,7 +5488,7 @@ CVE-2026-18249 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow 
a remote authenticated
 CVE-2026-18193 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
bypass s ...)
        NOT-FOR-US: IBM
 CVE-2026-18164 (An undocumented hard-coded credential, shared by all device 
units, is  ...)
-       TODO: check
+       NOT-FOR-US: Flow Neuroscience FL-100
 CVE-2026-18109 (The W3 Total Cache plugin for WordPress is vulnerable to 
Stored Cross- ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-18101 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
gain elev ...)
@@ -5896,7 +5896,7 @@ CVE-2026-73564 (frp is a fast reverse proxy. From 0.53.0 
until 0.70.1, frp's opt
 CVE-2026-73563 (Backstage is an open framework for building developer portals. 
Prior t ...)
        NOT-FOR-US: Backstage
 CVE-2026-73562 (Mongoose is a MongoDB object modeling tool designed to work in 
an asyn ...)
-       TODO: check
+       NOT-FOR-US: Mongoose object modeling tool (different from src:mongoose)
 CVE-2026-73561 (Hub is a Node.js WebSocket server and client with added 
features. Prio ...)
        NOT-FOR-US: Hub Node.js WebSocket server and client
 CVE-2026-73559 (vLLM is an inference and serving engine for large language 
models. Fro ...)
@@ -6354,7 +6354,7 @@ CVE-2026-19734 (Missing Authorization and Authorization 
Bypass Through User-Cont
 CVE-2026-19730 (The 'podman quadlet install --replace' command opens the 
existing dest ...)
        TODO: check
 CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management 
component  ...)
-       TODO: check
+       NOT-FOR-US: Pentestify
 CVE-2026-19710 (A vulnerability was found in SourceCodester Simple Student 
Information ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-19696 (Ixia IxVeriWave and Vector Informatik BLF file parser crashes 
in 4.6.0 ...)
@@ -6369,9 +6369,9 @@ CVE-2026-19487 (Perl versions from 5.9.4 before 5.41.9 
produce incorrect regular
        NOTE: https://github.com/Perl/perl5/issues/22892
        NOTE: Fixed by: 
https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb 
(v5.41.9)
 CVE-2026-19484 (@fastify/busboy is a multipart form-data parser. In versions 
3.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: @fastify/busboy
 CVE-2026-19481 (@fastify/busboy is a multipart form-data parser. In versions 
1.0.0 thr ...)
-       TODO: check
+       NOT-FOR-US: @fastify/busboy
 CVE-2026-19293 (SMP security request (from peripheral)does not include the 
maximum enc ...)
        NOT-FOR-US: Silicon Labs
 CVE-2026-19292 (Re-pairing with a legitimate device can use a lower security 
level tha ...)
@@ -6391,9 +6391,9 @@ CVE-2026-17220 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow 
a remote attacker to ca
 CVE-2026-17197 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
bypass s ...)
        NOT-FOR-US: IBM
 CVE-2026-16459 (Padding oracle attack vulnerability in Oberon microsystem 
AG\u2019s Ob ...)
-       TODO: check
+       NOT-FOR-US: Oberon PSA Crypto
 CVE-2026-16458 (Padding oracle attack vulnerability in Oberon microsystem 
AG\u2019s oc ...)
-       TODO: check
+       NOT-FOR-US: Oberon PSA Crypto
 CVE-2026-16455 (In Teltonika Networks RUTOS devices running versions 7.07.1 
through 7. ...)
        NOT-FOR-US: Teltonika Networks
 CVE-2026-16101 (Spoofing an already bonded device can force either RS9116W or 
SiWx917  ...)
@@ -6407,7 +6407,7 @@ CVE-2026-14456 (Issue summary: When an OpenSSL QUIC 
server (Listener SSL object)
 CVE-2026-14332 (The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress 
plugin befor ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14298 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x 
<= 11.7 ...)
-       TODO: check
+       - mattermost-server <itp> (bug #823556)
 CVE-2026-14256 (ELAN reported a potential out-of-bounds write vulnerability in 
the ELA ...)
        NOT-FOR-US: Lenovo
 CVE-2026-12908
@@ -6431,9 +6431,9 @@ CVE-2025-62314 (HCL AION is affected by a vulnerability 
where certain endpoints
 CVE-2025-52640 (HCL AION is affected by a vulnerability where the shared 
storage used  ...)
        NOT-FOR-US: HCL
 CVE-2024-58374 (Hongjing e-HR contains an unauthenticated SQL injection 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Hongjing e-HR
 CVE-2019-25765 (ASP-CMS contains a SQL injection vulnerability in the 
commentList.asp  ...)
-       TODO: check
+       NOT-FOR-US: ASP-CMS
 CVE-2022-4993 (HTML::FormHandler versions through 0.40068 for Perl allow 
attacker sel ...)
        - libhtml-formhandler-perl 0.40068-3
        [trixie] - libhtml-formhandler-perl <no-dsa> (Minor issue; will be 
fixed via point release)
@@ -6944,9 +6944,9 @@ CVE-2026-46382 (The Meeting Room Booking System (MRBS) is 
a PHP-based applicatio
 CVE-2026-3835 (The Prevent Direct Access \u2013 Protect WordPress Files plugin 
for Wo ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-19657 (ScadaLTS 2.7.8.1reflects user-supplied input into an HTML 
response wit ...)
-       TODO: check
+       NOT-FOR-US: ScadaLTS
 CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks 
authorization  ...)
-       TODO: check
+       NOT-FOR-US: ScadaLTS
 CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due 
to a flaw ...)
        TODO: check
 CVE-2026-19643 (An out-of-bounds read issue in the Base64 decoder in Amazon 
aws-sdk-cp ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6ebaf0742f368e19d186477c689f6ea49a73ae03

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6ebaf0742f368e19d186477c689f6ea49a73ae03
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to