Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
de70dfa7 by Salvatore Bonaccorso at 2026-09-03T11:32:27+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2115,13 +2115,13 @@ CVE-2026-75460 (XueZhiSi Open Source Exam System <=
3.9.0 has a privilege escala
CVE-2026-75458 (The teacher-end interface POST /api/teacher/user/delete/{id}
in XueZhi ...)
NOT-FOR-US: XueZhiSi Open Source Exam System
CVE-2026-74837 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: ash-project
CVE-2026-71415 (Kirby is an open-source content management system. From 5.0.0
until 5. ...)
NOT-FOR-US: Kirby CMS
CVE-2026-67395 (A path traversal vulnerability exists in Sage Employee Self
Service\u2 ...)
- TODO: check
+ NOT-FOR-US: Sage Employee Self Service
CVE-2026-67394 (A critical local privilege escalation via OS command injection
vulnera ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote
authenti ...)
NOT-FOR-US: cPanel
CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the
separation of pr ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de70dfa7c7ef259a6c31ac60b8d6a977cdefe676
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de70dfa7c7ef259a6c31ac60b8d6a977cdefe676
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits