Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d4cc664a by Salvatore Bonaccorso at 2026-09-02T22:14:05+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
CVE-2026-8151 (The Simple Membership MailChimp Integration WordPress plugin
before 1. ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84841 (A security flaw has been discovered in tsi-coop tsi-dpdp-cms
up to 0.5 ...)
- TODO: check
+ NOT-FOR-US: tsi-coop tsi-dpdp-cms
CVE-2026-84840 (A vulnerability was identified in tsi-coop tsi-dpdp-cms up to
0.5.0. T ...)
- TODO: check
+ NOT-FOR-US: tsi-coop tsi-dpdp-cms
CVE-2026-84839 (A vulnerability was determined in tsi-coop tsi-dpdp-cms up to
0.5.0. A ...)
- TODO: check
+ NOT-FOR-US: tsi-coop tsi-dpdp-cms
CVE-2026-84838 (A flaw was found in rpmuncompress. This command injection
vulnerabilit ...)
TODO: check
CVE-2026-84837 (A flaw was found in rpm. An attacker can exploit a command
injection v ...)
@@ -13,23 +13,23 @@ CVE-2026-84837 (A flaw was found in rpm. An attacker can
exploit a command injec
CVE-2026-84835 (Missing Authorization vulnerability in DimaFreund Rentsyst
allows Expl ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-84833 (A vulnerability was found in ntegrals openbrowser up to
067fc45d649baa ...)
- TODO: check
+ NOT-FOR-US: ntegrals openbrowser
CVE-2026-84811 (agentverus-scanner fails to analyze compiled Python bytecode
files in ...)
- TODO: check
+ NOT-FOR-US: agentverus-scanner
CVE-2026-84810 (claude-skill-antivirus fails to analyze executable files when
scanning ...)
- TODO: check
+ NOT-FOR-US: claude-skill-antivirus
CVE-2026-84809 (Tencent AI-Infra-Guard's skill-scan component excludes
compiled Python ...)
- TODO: check
+ NOT-FOR-US: Tencent AI-Infra-Guard
CVE-2026-84808 (Kimai versions before 2.65.0 contain an authorization bypass
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84807 (Kimai (kimai/kimai) through 2.65.0 contains a business logic /
imprope ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84806 (Kimai before 2.63.0 contains an improper authorization
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84805 (Kimai versions from 2.61.0 before 2.63.0 fail to disable
admin-only wo ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84804 (Kimai before 2.65.0 fails to properly validate permissions
when removi ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84803 (SiYuan before v3.8.2 contains a stored cross-site scripting
vulnerabil ...)
NOT-FOR-US: SiYuan
CVE-2026-84802 (Craft CMS versions from 5.7.0 before 5.10.12 contain an
information di ...)
@@ -149,9 +149,9 @@ CVE-2026-84379 (HTTPX2 is a next generation HTTP client for
Python. Prior to 2.1
CVE-2026-84378 (HTTPX2 is a next generation HTTP client for Python. From 2.5.0
until 2 ...)
TODO: check
CVE-2026-84377 (LiteLLM is a proxy server (AI Gateway) to call LLM APIs in
OpenAI (or ...)
- TODO: check
+ NOT-FOR-US: LiteLLM
CVE-2026-84376 (Astro is a web framework for content-driven websites. Prior to
7.2.4, ...)
- TODO: check
+ NOT-FOR-US: Astro
CVE-2026-84217 (Missing Authorization vulnerability in Mamunur Rashid
Classified Listi ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-84175 (In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service
fetches W ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4cc664a08fea27aa51977d1b12d5a29d68ae37a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4cc664a08fea27aa51977d1b12d5a29d68ae37a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits