Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8ee77df6 by Salvatore Bonaccorso at 2026-09-05T11:58:15+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -403,15 +403,15 @@ CVE-2026-82911 (Cross-Site Request Forgery (CSRF) in the 
OrderConfirmController
 CVE-2026-82846 (The Masteriyo LMS  WordPress plugin before 3.4.0 does not 
sanitise and ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-82729 (Inefficient Algorithmic Complexity vulnerability in 
elixir-mint mint a ...)
-       TODO: check
+       NOT-FOR-US: elixir-mint Mint
 CVE-2026-82728 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: elixir-mint Mint
 CVE-2026-82712 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Tycon Systems TPDIN-Monitor-WEB3
 CVE-2026-82684 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Tycon Systems TPDIN-Monitor-WEB3
 CVE-2026-82538 (ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL 
injection v ...)
-       TODO: check
+       NOT-FOR-US: ILIAS
 CVE-2026-82304 (The Music Store  WordPress plugin before 1.4.5 does not 
sanitise and e ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-81939 (A Zip Slip vulnerability in the SonicWall Network Security 
Manager (NS ...)
@@ -433,49 +433,49 @@ CVE-2026-81404 (The IPGP Visitors Origin WordPress plugin 
before 1.6 does not sa
 CVE-2026-81348 (The My Private Site  WordPress plugin before 4.2.3 does not 
apply its  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-81302 (PALLET CONTROL products contain an incorrect default 
permission vulner ...)
-       TODO: check
+       NOT-FOR-US: PALLET CONTROL products
 CVE-2026-80190 (Apache Allura: stored XSS via SVN code repositories. Git 
repositories  ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-80119 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
-       TODO: check
+       NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80118 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
-       TODO: check
+       NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80117 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
-       TODO: check
+       NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80116 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
-       TODO: check
+       NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80115 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
-       TODO: check
+       NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80114 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
-       TODO: check
+       NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80113 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
-       TODO: check
+       NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80112 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
-       TODO: check
+       NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-79707 (A Path Traversal vulnerability in the builder endpoint in 
Google Cloud ...)
-       TODO: check
+       NOT-FOR-US: adk-python
 CVE-2026-79426 (An arbitrary file deletion vulnerability in the 
/adminapi/file/video_d ...)
-       TODO: check
+       NOT-FOR-US: CRMEB
 CVE-2026-79423 (An authenticated remote code execution (RCE) vulnerability in 
the admi ...)
-       TODO: check
+       NOT-FOR-US: seacms
 CVE-2026-79419 (A reflected cross-site scripting (XSS) vulnerability exists in 
EMX Tec ...)
-       TODO: check
+       NOT-FOR-US: EMX Tecnologia Gestao X Business Suite
 CVE-2026-79418 (EMX Tecnologia Gestao X version <= 8.4 contains a Stored 
Cross-Site Sc ...)
-       TODO: check
+       NOT-FOR-US: EMX Tecnologia Gestao X
 CVE-2026-79391 (No authentication exists in the MQTT service of Trueview 
6.0.23.4. The ...)
-       TODO: check
+       NOT-FOR-US: Trueview
 CVE-2026-79390 (Trueview TI8161 6.0.23.4 is vulnerable to information 
disclosure due t ...)
-       TODO: check
+       NOT-FOR-US: Trueview
 CVE-2026-79389 (Trueview T18161 S 6.0.23.4 contains an improper verification 
in MQTT c ...)
-       TODO: check
+       NOT-FOR-US: Trueview
 CVE-2026-78970 (JeecgBoot 3.9.2 and earlier contains an authorization bypass 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: JeecgBoot
 CVE-2026-78849 (Cross Site Scripting vulnerability in Netgate pfSense Plus 
software ve ...)
-       TODO: check
+       NOT-FOR-US: Netgate pfSense Plus
 CVE-2026-78839 (An arbitrary file upload vulnerability in AppNitro MachForm 
v30 allows ...)
-       TODO: check
+       NOT-FOR-US: AppNitro MachForm
 CVE-2026-78745 (An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 
Hi3751V352E_DMO allow ...)
-       TODO: check
+       NOT-FOR-US: HiDPT/ Weyon HiDPTAndroid
 CVE-2026-78658 (IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 
through 7 ...)
        NOT-FOR-US: IBM
 CVE-2026-78543 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
@@ -493,7 +493,7 @@ CVE-2026-78150 (The Smart Post  WordPress plugin before 
4.0.8 does not check the
 CVE-2026-78149 (The Smart Post  WordPress plugin before 4.0.8 does not check 
whether a ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-77847 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Tycon Systems TPDIN-Monitor-WEB3
 CVE-2026-77830 (The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin 
for WordP ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-77826 (The RegistrationMagic  WordPress plugin before 6.0.9.9 does 
not verify ...)
@@ -501,9 +501,9 @@ CVE-2026-77826 (The RegistrationMagic  WordPress plugin 
before 6.0.9.9 does not
 CVE-2026-77822 (IBM ContextForge MCP Gateway could allow a remote 
authenticated attack ...)
        NOT-FOR-US: IBM
 CVE-2026-77818 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Yordam Information Technology Consulting, Training and 
Electronic Systems
 CVE-2026-77393 (In Ignition 8.1.53 and earlier, the Gateway "Create Project 
Role(s)" s ...)
-       TODO: check
+       NOT-FOR-US: Ignition
 CVE-2026-77263 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie 
Consent + m ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-77233 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie 
Consent + m ...)
@@ -511,77 +511,77 @@ CVE-2026-77233 (The iubenda | All-in-one Compliance for 
GDPR / CCPA Cookie Conse
 CVE-2026-76925 (A flaw was found in Flatpak. A Time-of-check to time-of-use 
(TOCTOU) r ...)
        TODO: check
 CVE-2026-76169 (fastify versions >= 4.0.0 and before 5.12.2 can route a 
malformed URL  ...)
-       TODO: check
+       NOT-FOR-US: fastify
 CVE-2026-75925 (Improper neutralization of CRLF sequences in IXON VPN Client 
before ve ...)
-       TODO: check
+       NOT-FOR-US: IXON VPN Client
 CVE-2026-75439 (An issue in Free5GC v.4.2.2 allows a remote attacker to cause 
a denial ...)
        NOT-FOR-US: Free5GC
 CVE-2026-75438 (Buffer Overflow vulnerability in Open5GS v2.7.7 allows a 
remote attack ...)
        TODO: check
 CVE-2026-75431 (PowerJob Server version 5.1.2 (and likely earlier) uses a 
predictable  ...)
-       TODO: check
+       NOT-FOR-US: PowerJob Server
 CVE-2026-75430 (PowerJob Worker version 5.1.2 (and likely earlier versions) 
exposes th ...)
-       TODO: check
+       NOT-FOR-US: PowerJob
 CVE-2026-75429 (PowerJob versions 4.x through 5.1.2 contain an unauthenticated 
remote  ...)
-       TODO: check
+       NOT-FOR-US: PowerJob
 CVE-2026-75171 (An issue in HubCore v.14.1.1 allows a remote attacker to 
escalate priv ...)
-       TODO: check
+       NOT-FOR-US: HubCore
 CVE-2026-75170 (Cross-site scripting (XSS) vulnerability in the 
/loginController/doLog ...)
-       TODO: check
+       NOT-FOR-US: HubCore
 CVE-2026-75169 (An arbitrary file upload vulnerability in 
/cgi-bin/ugwupload.cgi of MB ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75168 (An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in 
MBS-Solu ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75167 (A broken access control vulnerability in the ugw-usr-edit 
method of /c ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75166 (Insecure Permission vulnerability in MBS-Solutions X-Serie 
Gateway fir ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75165 (An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie 
Gateway firmw ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75164 (An arbitrary file read vulnerability in 
/cgi-bin/ugwdownload.cgi of MB ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75163 (An information disclosure vulnerability in the ugw-deviceinfo 
method o ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75162 (An information disclosure vulnerability in the 
opcua-configuration met ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75161 (An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in 
MBS-Solut ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75160 (An issue in X-Serie Gateway Firmware V6_00_05 allows a remote 
attacker ...)
-       TODO: check
+       NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-74237 (GFI Exinda AI and ClearView before 7.6.5 contains an argument 
injectio ...)
-       TODO: check
+       NOT-FOR-US: GFI Exinda AI and ClearView
 CVE-2026-74236 (GFI Exinda AI and ClearView before 7.6.5 contains a path 
traversal vul ...)
-       TODO: check
+       NOT-FOR-US: GFI Exinda AI and ClearView
 CVE-2026-74235 (GFI Exinda AI and ClearView before 7.6.5 contains a path 
traversal vul ...)
-       TODO: check
+       NOT-FOR-US: GFI Exinda AI and ClearView
 CVE-2026-73848 (Emlog is an open source website building system. In versions 
2.6.29 an ...)
        NOT-FOR-US: Emlog
 CVE-2026-71626 (An issue in Invoice Ninja v5.13.24 allows a remote attacker to 
obtain  ...)
-       TODO: check
+       NOT-FOR-US: Invoice Ninja
 CVE-2026-71625 (An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote 
attacker to e ...)
-       TODO: check
+       NOT-FOR-US: slimkit plus ThinkSNS+
 CVE-2026-71624 (An issue in esoTalk v.1.0.0g4 allows a remote attacker to 
execute arbi ...)
-       TODO: check
+       NOT-FOR-US: esoTalk
 CVE-2026-71622 (SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 
allows a r ...)
-       TODO: check
+       NOT-FOR-US: Zhao-github APiAdmin
 CVE-2026-71620 (File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 
allows a rem ...)
-       TODO: check
+       NOT-FOR-US: Zhao-github APiAdmin
 CVE-2026-6958 (Acunetix 25.11.251107123 for Windows contains a local privilege 
escala ...)
-       TODO: check
+       NOT-FOR-US: Acunetix
 CVE-2026-6217 (Use of a One-Way hash without a salt vulnerability in Pik 
Online Softw ...)
-       TODO: check
+       NOT-FOR-US: Pik Online Portal
 CVE-2026-63464 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh VPN.  ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-61699 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh VPN.  ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-61688 (SolidInvoice is an open-source invoicing platform. Prior to 
version 3. ...)
-       TODO: check
+       NOT-FOR-US: SolidInvoice
 CVE-2026-61686 (SolidInvoice is an open-source invoicing platform. Prior to 
version 3. ...)
-       TODO: check
+       NOT-FOR-US: SolidInvoice
 CVE-2026-61614 (SolidInvoice is an open-source invoicing platform. Prior to 
version 3. ...)
-       TODO: check
+       NOT-FOR-US: SolidInvoice
 CVE-2026-61608 (SolidInvoice is an open-source invoicing platform. Prior to 
version 3. ...)
-       TODO: check
+       NOT-FOR-US: SolidInvoice
 CVE-2026-5522 (IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains 
hard-code ...)
        NOT-FOR-US: IBM
 CVE-2026-57777 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
@@ -603,17 +603,17 @@ CVE-2026-57160 (PJSIP is a free and open source 
multimedia communication library
 CVE-2026-57159 (PJSIP is a free and open source multimedia communication 
library writt ...)
        TODO: check
 CVE-2026-55513 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh VPN.  ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-55512 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh VPN.  ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-53932 (laravel-backup-restore restores database backups made with 
spatie/lara ...)
-       TODO: check
+       NOT-FOR-US: laravel-backup-restore
 CVE-2026-53769 (Avo is a framework to create admin panels for Ruby on Rails 
apps. From ...)
-       TODO: check
+       NOT-FOR-US: Avo
 CVE-2026-53761 (Frappe CRM is an open-source customer relationship management 
tool. Pr ...)
-       TODO: check
+       NOT-FOR-US: Frappe CRM
 CVE-2026-53760 (Admidio is an open-source user management solution. In 
versions 5.0.11 ...)
-       TODO: check
+       NOT-FOR-US: Admidio
 CVE-2026-53758 (Emlog is an open source website building system. In versions 
2.6.29 an ...)
        NOT-FOR-US: Emlog
 CVE-2026-53757 (Emlog is an open source website building system. In versions 
2.6.29 an ...)
@@ -621,41 +621,41 @@ CVE-2026-53757 (Emlog is an open source website building 
system. In versions 2.6
 CVE-2026-53756 (Emlog is an open source website building system. Prior to 
version 2.6. ...)
        NOT-FOR-US: Emlog
 CVE-2026-53604 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh VPN.  ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-53603 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh VPN.  ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-53602 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh VPN.  ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-52777 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.6, there ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52775 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.6, YesWi ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52774 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.6, YesWi ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52773 (YesWiki is a wiki system written in PHP. From version 4.1.0 to 
before  ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52772 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.6, Bazar ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52771 (YesWiki is a wiki system written in PHP. From version 4.2.0 to 
before  ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52770 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.6, YesWi ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52769 (YesWiki is a wiki system written in PHP. From version 4.6.2 to 
before  ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52767 (YesWiki is a wiki system written in PHP. From version 4.6.2 to 
before  ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52766 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.6, the { ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52763 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.6, the r ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52762 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.6, YesWi ...)
-       TODO: check
+       NOT-FOR-US: YesWiki
 CVE-2026-52691 (** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of 
Special Ele ...)
        TODO: check
 CVE-2026-50894 (easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of 
File with D ...)
-       TODO: check
+       NOT-FOR-US: easyadmin
 CVE-2026-50553 (Note Mark is an open-source note-taking application. Prior to 
version  ...)
-       TODO: check
+       NOT-FOR-US: Note Mark
 CVE-2026-4644 (A Missing Authorization vulnerability in HTTP Connector in 
Google Clou ...)
        TODO: check
 CVE-2026-4361 (The Divi theme for WordPress is vulnerable to Server-Side 
Request Forg ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ee77df6b9a7ce0fbfdcc89e1e32174ff575781c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ee77df6b9a7ce0fbfdcc89e1e32174ff575781c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to