Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9392760b by Salvatore Bonaccorso at 2026-08-18T07:00:34+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -257,17 +257,17 @@ CVE-2026-50775 (A blind SSRF attack in DataHub v.1.5.0.1
allows a remote attacke
CVE-2026-50774 (An issue in GAPTEQ Designer v.3.5 allows a remote attacker to
escalate ...)
NOT-FOR-US: GAPTEQ Designer
CVE-2026-50773 (An issue in CGM Germany - CompuGroup Medical CGM ISIS MED
2510.1.0.20 ...)
- TODO: check
+ NOT-FOR-US: CGM Germany - CompuGroup Medical CGM ISIS MED
CVE-2026-50772 (An issue in Squirro Cognitive Search < 3.14.2 allows a remote
attacker ...)
- TODO: check
+ NOT-FOR-US: Squirro Cognitive Search
CVE-2026-50771 (Cross Site Scripting vulnerability in Squirro Cognitive Search
< 3.14. ...)
- TODO: check
+ NOT-FOR-US: Squirro Cognitive Search
CVE-2026-50770 (An issue in Squirro Cognitive Search before v.3.14.2 allows a
remote a ...)
- TODO: check
+ NOT-FOR-US: Squirro Cognitive Search
CVE-2026-50769 (The CRM+ application before and including version 2025.6 from
Brainfor ...)
- TODO: check
+ NOT-FOR-US: Brainformatik
CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH
ImageMaster ...)
- TODO: check
+ NOT-FOR-US: T-Systems International GmbH ImageMaster
CVE-2026-49308 (Permission control vulnerability in the clipboard
module.Impact: Succe ...)
NOT-FOR-US: Huawei
CVE-2026-49307 (Permission control vulnerability in the multi-mode input
module.Impact ...)
@@ -285,17 +285,17 @@ CVE-2026-49302 (Permission control vulnerability in the
notification service mod
CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact:
Success ...)
NOT-FOR-US: Huawei
CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to
version 0.19. ...)
- TODO: check
+ NOT-FOR-US: Kolibri
CVE-2026-46345 (compliance-trestle is a tooling platform for managing
compliance as co ...)
- TODO: check
+ NOT-FOR-US: compliance-trestle
CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint
Privilege ...)
NOT-FOR-US: BeyondTrust
CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode
component of ...)
NOT-FOR-US: BeyondTrust
CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based
Cross-Site Scri ...)
- TODO: check
+ NOT-FOR-US: OutSystems Service Center
CVE-2026-33437 (Stirling-PDF is a locally hosted web application that
facilitates vari ...)
- TODO: check
+ NOT-FOR-US: Stirling-PDF
CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital
Management Syste ...)
NOT-FOR-US: itsourcecode System
CVE-2026-19999 (A security vulnerability has been detected in Open Asset
Import Librar ...)
@@ -309,9 +309,9 @@ CVE-2026-18674 (On a Kong Mesh global control plane,
resources received over the
CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially
vulnerabl ...)
NOT-FOR-US: HP
CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software
Technologies ...)
- TODO: check
+ NOT-FOR-US: Dolusoft Software Technologies Sonlogger
CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software
Technologies ...)
- TODO: check
+ NOT-FOR-US: Fortilogger
CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <=
5.12.5 and ...)
NOT-FOR-US: Progress Software
CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and
below versi ...)
@@ -319,7 +319,7 @@ CVE-2026-16138 (In Progress ShareFile Storage Zones
Controller v5.12.5 and below
CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and
below, a pa ...)
NOT-FOR-US: Progress Software
CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The
Mattermost G ...)
- TODO: check
+ NOT-FOR-US: Mattermost Plugins
CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6,
10.11.x <= 10. ...)
- mattermost-server <itp> (bug #823556)
CVE-2026-16047 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21,
11.8.x <= 1 ...)
@@ -333,7 +333,7 @@ CVE-2026-16044 (Mattermost versions 11.7.x <= 11.7.6,
10.11.x <= 10.11.21 fail t
CVE-2026-15754 (Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The
access cont ...)
- mattermost-server <itp> (bug #823556)
CVE-2026-15218 (A flaw was found in the maas-api and maas-controller
ServiceAccounts w ...)
- TODO: check
+ NOT-FOR-US: maas-api and maas-controller ServiceAccounts within Red Hat
OpenShift AI
CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim
Software ...)
TODO: check
CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows
Input D ...)
@@ -465,7 +465,7 @@ CVE-2026-19956 (A vulnerability has been found in
gomarble-ai facebook-ads-mcp-s
CVE-2026-19955 (A vulnerability was detected in TrailDB 0.6. Impacted is the
function ...)
NOT-FOR-US: TrailDB
CVE-2026-15623 (A SQL Injection vulnerability in a legacy dashboard widget API
in Goog ...)
- TODO: check
+ NOT-FOR-US: Google Cloud Google SecOps (Chronicle SOAR)
CVE-2026-14832 (The ShopSmart Loyalty for WooCommerce WordPress plugin through
1.0.0 d ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13700 (The WooMS WordPress plugin through 9.14 does not validate a
user-suppl ...)
@@ -8107,7 +8107,7 @@ CVE-2026-18244 (GitLab has remediated an issue in GitLab
EE affecting all versio
CVE-2026-18235 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
NOT-FOR-US: IBM
CVE-2026-18171 (Docker Sandboxes (sbx) applies the read-only intent of a
runtime host ...)
- TODO: check
+ NOT-FOR-US: Docker Sandboxes
CVE-2026-18144 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
NOT-FOR-US: IBM
CVE-2026-18106 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote
authenticated attack ...)
@@ -8611,7 +8611,7 @@ CVE-2026-15039 (The giftware WordPress plugin before
4.2.10 does not validate th
CVE-2026-14925 (The Import WP WordPress plugin before 2.14.23 does not
perform any au ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14863 (FileRun up to and including version 2026.2.0 contains an OS
command in ...)
- TODO: check
+ NOT-FOR-US: FileRun
CVE-2026-14859 (The WP Crowdfunding WordPress plugin before 2.2.1 does not
check the c ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14858 (The WP Crowdfunding WordPress plugin before 2.2.1 does not
verify orde ...)
@@ -10979,7 +10979,7 @@ CVE-2026-19517 (Improper Validation of Specified
Quantity in Input and Allocatio
NOTE: https://github.com/Samsung/rlottie/pull/596
NOTE: Fixed by:
https://github.com/Samsung/rlottie/commit/2cab35db755b0e39df40b679969495e90d39c578
CVE-2026-19516 (A caller-supplied X-Grafana-URL request header controls the
destinatio ...)
- TODO: check
+ NOT-FOR-US: mcp-grafana
CVE-2026-19425 (Travel Agency Management System developed by Win Men
Intermational has ...)
NOT-FOR-US: Win Men Intermational
CVE-2026-19424 (Chiline Cloud developed by Inventec Appliances has a Insecure
Direct O ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9392760b8a5755986ac91c962b55de387d4766b9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9392760b8a5755986ac91c962b55de387d4766b9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits