Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2b171171 by Salvatore Bonaccorso at 2026-09-04T14:41:27+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -228,17 +228,17 @@ CVE-2026-79631 (The WPFunnels WordPress plugin before
3.13.0 does not restrict
CVE-2026-79630 (The WPFunnels WordPress plugin before 3.13.0 does not verify
that the ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77465 (toml-node is a TOML parser for Node.js and the browser. Prior
to 4.2.0 ...)
- TODO: check
+ NOT-FOR-US: toml-node
CVE-2026-75754 (Missing Authentication for Critical Function, Server-Side
Request Forg ...)
NOT-FOR-US: ASUS
CVE-2026-74853 (The Pods WordPress plugin before 3.3.9.2 does not restrict
which func ...)
NOT-FOR-US: WordPress plugin
CVE-2026-71429 (stream-json is a micro-library of stream components for
processing JSO ...)
- TODO: check
+ NOT-FOR-US: stream-json
CVE-2026-71216 (PagerDuty alarm hook transmits the integration routing key
over cleart ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-70403 (XING CPTrans-ME-X contains a Use of Hard-coded Password
(CWE-259). Any ...)
- TODO: check
+ NOT-FOR-US: XING CPTrans-ME-X
CVE-2026-70352 (Missing authentication for critical function in Azure AI
Language allo ...)
NOT-FOR-US: Microsoft
CVE-2026-70178 (Missing authorization in Microsoft Fabric allows an authorized
attacke ...)
@@ -246,15 +246,15 @@ CVE-2026-70178 (Missing authorization in Microsoft Fabric
allows an authorized a
CVE-2026-69857 (Authorization bypass through user-controlled key in Azure
Cosmos DB al ...)
NOT-FOR-US: Microsoft
CVE-2026-69657 (XING CPTrans-ME-X contains a Use of Default Password
(CWE-1393). Anyon ...)
- TODO: check
+ NOT-FOR-US: XING CPTrans-ME-X
CVE-2026-67402 (An insecure Apache configuration in ConfigServer Security &
Firewall m ...)
- TODO: check
+ NOT-FOR-US: ConfigServer Security & Firewall
CVE-2026-67398 (Missing authorization vulnerability has been discovered in
2Checkout p ...)
- TODO: check
+ NOT-FOR-US: WHMCS
CVE-2026-67397 (Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80
through 18.0 ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-66840 (XING CPTrans-ME-X contains an Exposure of Sensitive System
Information ...)
- TODO: check
+ NOT-FOR-US: XING CPTrans-ME-X
CVE-2026-65818 (Server-side request forgery (ssrf) in Power Automate allows an
authori ...)
NOT-FOR-US: Microsoft
CVE-2026-64200 (There is an out-of-bounds read vulnerability in DASYLab due to
imprope ...)
@@ -703,11 +703,11 @@ CVE-2026-82299 (Incorrect Authorization (CWE-863) in
Kibana can lead to informat
CVE-2026-82298 (Incorrect Authorization (CWE-863) in Kibana can lead to denial
of serv ...)
- kibana <itp> (bug #700337)
CVE-2026-82180 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the
MQTT API is ...)
- TODO: check
+ NOT-FOR-US: Eclipse Arrowhead
CVE-2026-82024 (LearnPress WordPress Plugin before 4.4.6 contains a stored
cross-site ...)
- TODO: check
+ NOT-FOR-US: WordPress Plugin
CVE-2026-82023 (LearnPress WordPress Plugin before 4.4.6 contains a broken
object-leve ...)
- TODO: check
+ NOT-FOR-US: WordPress Plugin
CVE-2026-81776 (Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <=
3.8.8 v ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81773 (Unauthenticated Cross Site Scripting (XSS) in Ninja Forms
File Upload ...)
@@ -723,13 +723,13 @@ CVE-2026-81282 (Subscriber Cross Site Scripting (XSS) in
Product Variations Swat
CVE-2026-81281 (Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4
versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-80515 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the
management-autho ...)
- TODO: check
+ NOT-FOR-US: Eclipse Arrowhead
CVE-2026-80465 (A vulnerability has been identified in Mendix SAML (Mendix 10
compatib ...)
NOT-FOR-US: Siemens
CVE-2026-80254 (Authorization bypass through user-controlled key issue exists
in Shize ...)
- TODO: check
+ NOT-FOR-US: ShizenBox2 (edge-app)
CVE-2026-80253 (An improper physical access control issue exists in ShizenBox2
(dev-co ...)
- TODO: check
+ NOT-FOR-US: ShizenBox2
CVE-2026-79679 (Use of Weak Credentials vulnerability in B&R Industrial
Automation Gmb ...)
NOT-FOR-US: ABB group
CVE-2026-78596 (Missing Authorization in Kibana Leading to Unauthorized
Modification o ...)
@@ -765,23 +765,23 @@ CVE-2026-76175 (SQL injection vulnerability in the
del_check parameter of the /o
CVE-2026-76174 (Unrestricted file upload vulnerability in the CSV file upload
function ...)
TODO: check
CVE-2026-75602 (OpenList a file list program that supports multiple storage.
Prior to ...)
- TODO: check
+ NOT-FOR-US: OpenList
CVE-2026-75137 (UpSignOn for Windows before 7.19.0 contains a sensitive data
exposure ...)
- TODO: check
+ NOT-FOR-US: UpSignOn
CVE-2026-75136 (UpSignOn for Windows before 7.19.0 contains an insecure
credential sto ...)
- TODO: check
+ NOT-FOR-US: UpSignOn
CVE-2026-75135 (UpSignOn for Windows before 7.19.0 contains a sensitive data
exposure ...)
- TODO: check
+ NOT-FOR-US: UpSignOn
CVE-2026-75134 (SEOWriting plugin for WordPress through 1.12.5 contains a
stored cross ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75036 (A security vulnerability was discovered in Fleet's Helm
template prepr ...)
- TODO: check
+ NOT-FOR-US: Rancher Fleet
CVE-2026-75035 (A flaw was found in Rancher Manager. When a non-administrative
caller ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-75034 (A flaw was found in Rancher Manager. The SAML assertion replay
protect ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-75033 (A flaw was found in Rancher Manager. Project Secrets were
propagated i ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-74769 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below,
contain a ...)
NOT-FOR-US: Dell / EMC
CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below,
contain a ...)
@@ -789,11 +789,11 @@ CVE-2026-74768 (Dell PowerProtect Data Manager, versions
20.2.0.0 and below, con
CVE-2026-73600 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below,
contain a ...)
NOT-FOR-US: Dell / EMC
CVE-2026-71963 (Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0,
contains ...)
- TODO: check
+ NOT-FOR-US: Hermes Agent
CVE-2026-71404 (A flaw was found in Rancher Manager. The GlobalRole controller
derived ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-71403 (A flaw was found in Rancher Manager. The /v3/users update path
did not ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-71224 (A stack overflow vulnerability was found in gfs2-utils. The
metadata w ...)
- gfs2-utils <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511397
@@ -3643,7 +3643,7 @@ CVE-2026-71257 (Apache Wicket enforces the upload limits
configured on a form or
CVE-2026-70449 (Improper validation of resource URL attributes in Apache
Wicket allows ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2
contains ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-63083
REJECTED
CVE-2026-5956 (Improper neutralization of special elements used in an SQL
command ('S ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b171171ddda81673ab3aefd94ed1c99f715b649
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b171171ddda81673ab3aefd94ed1c99f715b649
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits