Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2b171171 by Salvatore Bonaccorso at 2026-09-04T14:41:27+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -228,17 +228,17 @@ CVE-2026-79631 (The WPFunnels  WordPress plugin before 
3.13.0 does not restrict
 CVE-2026-79630 (The WPFunnels  WordPress plugin before 3.13.0 does not verify 
that the ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-77465 (toml-node is a TOML parser for Node.js and the browser. Prior 
to 4.2.0 ...)
-       TODO: check
+       NOT-FOR-US: toml-node
 CVE-2026-75754 (Missing Authentication for Critical Function, Server-Side 
Request Forg ...)
        NOT-FOR-US: ASUS
 CVE-2026-74853 (The Pods  WordPress plugin before 3.3.9.2 does not restrict 
which func ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-71429 (stream-json is a micro-library of stream components for 
processing JSO ...)
-       TODO: check
+       NOT-FOR-US: stream-json
 CVE-2026-71216 (PagerDuty alarm hook transmits the integration routing key 
over cleart ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-70403 (XING CPTrans-ME-X contains a Use of Hard-coded Password 
(CWE-259). Any ...)
-       TODO: check
+       NOT-FOR-US: XING CPTrans-ME-X
 CVE-2026-70352 (Missing authentication for critical function in Azure AI 
Language allo ...)
        NOT-FOR-US: Microsoft
 CVE-2026-70178 (Missing authorization in Microsoft Fabric allows an authorized 
attacke ...)
@@ -246,15 +246,15 @@ CVE-2026-70178 (Missing authorization in Microsoft Fabric 
allows an authorized a
 CVE-2026-69857 (Authorization bypass through user-controlled key in Azure 
Cosmos DB al ...)
        NOT-FOR-US: Microsoft
 CVE-2026-69657 (XING CPTrans-ME-X contains a Use of Default Password 
(CWE-1393). Anyon ...)
-       TODO: check
+       NOT-FOR-US: XING CPTrans-ME-X
 CVE-2026-67402 (An insecure Apache configuration in ConfigServer Security & 
Firewall m ...)
-       TODO: check
+       NOT-FOR-US: ConfigServer Security & Firewall
 CVE-2026-67398 (Missing authorization vulnerability has been discovered in 
2Checkout p ...)
-       TODO: check
+       NOT-FOR-US: WHMCS
 CVE-2026-67397 (Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 
through 18.0 ...)
-       TODO: check
+       NOT-FOR-US: Plesk
 CVE-2026-66840 (XING CPTrans-ME-X contains an Exposure of Sensitive System 
Information ...)
-       TODO: check
+       NOT-FOR-US: XING CPTrans-ME-X
 CVE-2026-65818 (Server-side request forgery (ssrf) in Power Automate allows an 
authori ...)
        NOT-FOR-US: Microsoft
 CVE-2026-64200 (There is an out-of-bounds read vulnerability in DASYLab due to 
imprope ...)
@@ -703,11 +703,11 @@ CVE-2026-82299 (Incorrect Authorization (CWE-863) in 
Kibana can lead to informat
 CVE-2026-82298 (Incorrect Authorization (CWE-863) in Kibana can lead to denial 
of serv ...)
        - kibana <itp> (bug #700337)
 CVE-2026-82180 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the 
MQTT API is ...)
-       TODO: check
+       NOT-FOR-US: Eclipse Arrowhead
 CVE-2026-82024 (LearnPress WordPress Plugin before 4.4.6 contains a stored 
cross-site  ...)
-       TODO: check
+       NOT-FOR-US: WordPress Plugin
 CVE-2026-82023 (LearnPress WordPress Plugin before 4.4.6 contains a broken 
object-leve ...)
-       TODO: check
+       NOT-FOR-US: WordPress Plugin
 CVE-2026-81776 (Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 
3.8.8 v ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81773 (Unauthenticated Cross Site Scripting (XSS) in  Ninja Forms 
File Upload ...)
@@ -723,13 +723,13 @@ CVE-2026-81282 (Subscriber Cross Site Scripting (XSS) in 
Product Variations Swat
 CVE-2026-81281 (Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 
versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-80515 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the 
management-autho ...)
-       TODO: check
+       NOT-FOR-US: Eclipse Arrowhead
 CVE-2026-80465 (A vulnerability has been identified in Mendix SAML (Mendix 10 
compatib ...)
        NOT-FOR-US: Siemens
 CVE-2026-80254 (Authorization bypass through user-controlled key issue exists 
in Shize ...)
-       TODO: check
+       NOT-FOR-US: ShizenBox2 (edge-app)
 CVE-2026-80253 (An improper physical access control issue exists in ShizenBox2 
(dev-co ...)
-       TODO: check
+       NOT-FOR-US: ShizenBox2
 CVE-2026-79679 (Use of Weak Credentials vulnerability in B&R Industrial 
Automation Gmb ...)
        NOT-FOR-US: ABB group
 CVE-2026-78596 (Missing Authorization in Kibana Leading to Unauthorized 
Modification o ...)
@@ -765,23 +765,23 @@ CVE-2026-76175 (SQL injection vulnerability in the 
del_check parameter of the /o
 CVE-2026-76174 (Unrestricted file upload vulnerability in the CSV file upload 
function ...)
        TODO: check
 CVE-2026-75602 (OpenList a file list program that supports multiple storage. 
Prior to  ...)
-       TODO: check
+       NOT-FOR-US: OpenList
 CVE-2026-75137 (UpSignOn for Windows before 7.19.0 contains a sensitive data 
exposure  ...)
-       TODO: check
+       NOT-FOR-US: UpSignOn
 CVE-2026-75136 (UpSignOn for Windows before 7.19.0 contains an insecure 
credential sto ...)
-       TODO: check
+       NOT-FOR-US: UpSignOn
 CVE-2026-75135 (UpSignOn for Windows before 7.19.0 contains a sensitive data 
exposure  ...)
-       TODO: check
+       NOT-FOR-US: UpSignOn
 CVE-2026-75134 (SEOWriting plugin for WordPress through 1.12.5 contains a 
stored cross ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75036 (A security vulnerability was discovered in Fleet's Helm 
template prepr ...)
-       TODO: check
+       NOT-FOR-US: Rancher Fleet
 CVE-2026-75035 (A flaw was found in Rancher Manager. When a non-administrative 
caller  ...)
-       TODO: check
+       NOT-FOR-US: Rancher
 CVE-2026-75034 (A flaw was found in Rancher Manager. The SAML assertion replay 
protect ...)
-       TODO: check
+       NOT-FOR-US: Rancher
 CVE-2026-75033 (A flaw was found in Rancher Manager. Project Secrets were 
propagated i ...)
-       TODO: check
+       NOT-FOR-US: Rancher
 CVE-2026-74769 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, 
contain a ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, 
contain a ...)
@@ -789,11 +789,11 @@ CVE-2026-74768 (Dell PowerProtect Data Manager, versions 
20.2.0.0 and below, con
 CVE-2026-73600 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, 
contain a ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-71963 (Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, 
contains  ...)
-       TODO: check
+       NOT-FOR-US: Hermes Agent
 CVE-2026-71404 (A flaw was found in Rancher Manager. The GlobalRole controller 
derived ...)
-       TODO: check
+       NOT-FOR-US: Rancher
 CVE-2026-71403 (A flaw was found in Rancher Manager. The /v3/users update path 
did not ...)
-       TODO: check
+       NOT-FOR-US: Rancher
 CVE-2026-71224 (A stack overflow vulnerability was found in gfs2-utils. The 
metadata w ...)
        - gfs2-utils <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511397
@@ -3643,7 +3643,7 @@ CVE-2026-71257 (Apache Wicket enforces the upload limits 
configured on a form or
 CVE-2026-70449 (Improper validation of resource URL attributes in Apache 
Wicket allows ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 
contains  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-63083
        REJECTED
 CVE-2026-5956 (Improper neutralization of special elements used in an SQL 
command ('S ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b171171ddda81673ab3aefd94ed1c99f715b649

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b171171ddda81673ab3aefd94ed1c99f715b649
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to