Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c65d14b1 by Salvatore Bonaccorso at 2026-08-21T06:34:56+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -95,7 +95,7 @@ CVE-2026-76988 (A weakness has been identified in liftoff-sr
CIPster 1802525be27
CVE-2026-76987 (A security flaw has been discovered in liftoff-sr CIPster
1802525be27d ...)
NOT-FOR-US: liftoff-sr CIPster
CVE-2026-76833 (@cgauge/yaml npm package contains an arbitrary code execution
vulnerab ...)
- TODO: check
+ NOT-FOR-US: gauge/yaml Node.js module
CVE-2026-76641 (Expat through 2.8.3 contains an out-of-bounds read
vulnerability that ...)
- expat <not-affected> (Vulnerable code not present)
NOTE: https://github.com/libexpat/libexpat/pull/1331
@@ -212,7 +212,7 @@ CVE-2026-72844 (The Lean 4 kernel does not verify that the
structure named in a
CVE-2026-71492 (Banks generates meaningful LLM prompts using a simple template
languag ...)
NOT-FOR-US: Banks
CVE-2026-71428 (The unstructured library provides open-source components for
ingesting ...)
- TODO: check
+ NOT-FOR-US: unstructured
CVE-2026-70383 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
TODO: check
CVE-2026-6822
@@ -226,11 +226,11 @@ CVE-2026-68566 (Unauthenticated SQL Injection in
BookingPress Appointment Bookin
CVE-2026-68564 (Unauthenticated Cross Site Scripting (XSS) in NotificationX
Pro <= 3.1 ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66788 (A flaw was found in Lighthouse. A remote attacker, by
compromising a s ...)
- TODO: check
+ NOT-FOR-US: Lighthouse (component of Red Hat Advanced Cluster
Management for Kubernetes)
CVE-2026-66787 (A flaw was found in the lighthouse component of Red Hat
Advanced Clust ...)
- TODO: check
+ NOT-FOR-US: Lighthouse (component of Red Hat Advanced Cluster
Management for Kubernetes)
CVE-2026-66785 (A flaw was found in Submariner. This vulnerability allows a
malicious ...)
- TODO: check
+ NOT-FOR-US: Submariner
CVE-2026-66682 (Unauthenticated Privilege Escalation in Abandoned Cart Pro for
WooComm ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66680 (Unauthenticated SQL Injection in Locatoraid Store Locator <=
3.9.72 ve ...)
@@ -292,43 +292,43 @@ CVE-2026-66582 (Unauthenticated Cross Site Scripting
(XSS) in TranslatePress <=
CVE-2026-66581 (Unauthenticated Cross Site Scripting (XSS) in JetEngine <=
3.8.14.1 ve ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66002 (Frappe is a full-stack web application framework. Prior to
15.115.0 an ...)
- TODO: check
+ NOT-FOR-US: Frappe
CVE-2026-66001 (Frappe is a full-stack web application framework. Prior to
15.114.0 an ...)
- TODO: check
+ NOT-FOR-US: Frappe
CVE-2026-65842 (Plate is a rich-text editor with AI and shadcn/ui. Prior to
53.3.2, @p ...)
- TODO: check
+ NOT-FOR-US: Plate
CVE-2026-64972 (ATutor is vulnerable to Reflected XSS via popup parameter in
preview.p ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64971 (ATutor is vulnerable to Reflected XSS in restore
functionality. An att ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64970 (ATutor is vulnerable to Stored Cross Site Scripting in
registration fu ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64969 (ATutor is vulnerable to InsecureDirect Object Reference (IDOR)
attack ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64968 (ATutor is vulnerable toServer-Side request forgery in import
functiona ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64967 (A path traversal vulnerability in ATutor's error log viewer
allows an ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64966 (ATutor is vulnerable to a Path Traversal vulnerability in ZIP
extracti ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64965 (ATutor is vulnerable to Missing Authorization Check on Test
and Questi ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64964 (ATutor generates predictable email confirmation tokens due to
the use ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64963 (A path traversal vulnerability in ATutor allows an
authenticated user ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64962 (ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in
profile u ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64961 (ATutor is vulnerable to authentication bypass .Although a
token valida ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64960 (ATutor Gameme module allows users to upload files of any type
and exte ...)
- TODO: check
+ NOT-FOR-US: ATutor
CVE-2026-64846 (Nix is a package manager for Linux and other Unix systems.
Prior to 2. ...)
TODO: check
CVE-2026-64777 (A malicious builder peer may be able to request an in-context
file by ...)
NOT-FOR-US: Apple
CVE-2026-63654 (Frappe is a full-stack web application framework. In version
16.31.0 a ...)
- TODO: check
+ NOT-FOR-US: Frappe
CVE-2026-63495 (Libevent is an event notification library. From
2.2.0-alpha-dev until ...)
TODO: check
CVE-2026-63490 (Handlebars.java provides logic-less and semantic Mustache
templates wi ...)
@@ -372,7 +372,7 @@ CVE-2026-63016 (Uncontrolled Resource Consumption
vulnerability in Apache InLong
CVE-2026-63015 (Uncontrolled Resource Consumption vulnerability in Apache
InLong.Non-t ...)
TODO: check
CVE-2026-63003 (django CMS is an easy-to-use and developer-friendly enterprise
content ...)
- TODO: check
+ NOT-FOR-US: Django CMS
CVE-2026-62315 (Frappe is a full-stack web application framework. In version
16.31.0 a ...)
TODO: check
CVE-2026-61704 (Link Preview JS extracts web links information. Prior to
4.0.4, the re ...)
@@ -1071,15 +1071,15 @@ CVE-2026-68553 (Coturn is a free open source
implementation of TURN and STUN Ser
CVE-2026-68552 (Coturn is a free open source implementation of TURN and STUN
Server. P ...)
TODO: check
CVE-2026-67189 (pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain
a store ...)
- TODO: check
+ NOT-FOR-US: pfSense Plus
CVE-2026-63722 (ICEcoder 8.1 contains an unauthenticated remote code execution
vulnera ...)
- TODO: check
+ NOT-FOR-US: ICEcoder
CVE-2026-63188 (Logto is the modern, open-source auth infrastructure for SaaS
and AI a ...)
- TODO: check
+ NOT-FOR-US: Logto
CVE-2026-63187 (Logto is the modern, open-source auth infrastructure for SaaS
and AI a ...)
- TODO: check
+ NOT-FOR-US: Logto
CVE-2026-63123 (Tina is a headless content management system. Prior to 2.5.2,
the Tina ...)
- TODO: check
+ NOT-FOR-US: Tina CMS
CVE-2026-62727 (Concurrent execution using shared resource with improper
synchronizati ...)
NOT-FOR-US: Microsoft
CVE-2026-62317 (Logto is the modern, open-source auth infrastructure for SaaS
and AI a ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c65d14b16cd5e174e5357a59198c50d49eba18b9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c65d14b16cd5e174e5357a59198c50d49eba18b9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits