Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8ee77df6 by Salvatore Bonaccorso at 2026-09-05T11:58:15+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -403,15 +403,15 @@ CVE-2026-82911 (Cross-Site Request Forgery (CSRF) in the
OrderConfirmController
CVE-2026-82846 (The Masteriyo LMS WordPress plugin before 3.4.0 does not
sanitise and ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82729 (Inefficient Algorithmic Complexity vulnerability in
elixir-mint mint a ...)
- TODO: check
+ NOT-FOR-US: elixir-mint Mint
CVE-2026-82728 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: elixir-mint Mint
CVE-2026-82712 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are
vulnerab ...)
- TODO: check
+ NOT-FOR-US: Tycon Systems TPDIN-Monitor-WEB3
CVE-2026-82684 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are
vulnerab ...)
- TODO: check
+ NOT-FOR-US: Tycon Systems TPDIN-Monitor-WEB3
CVE-2026-82538 (ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL
injection v ...)
- TODO: check
+ NOT-FOR-US: ILIAS
CVE-2026-82304 (The Music Store WordPress plugin before 1.4.5 does not
sanitise and e ...)
NOT-FOR-US: WordPress plugin
CVE-2026-81939 (A Zip Slip vulnerability in the SonicWall Network Security
Manager (NS ...)
@@ -433,49 +433,49 @@ CVE-2026-81404 (The IPGP Visitors Origin WordPress plugin
before 1.6 does not sa
CVE-2026-81348 (The My Private Site WordPress plugin before 4.2.3 does not
apply its ...)
NOT-FOR-US: WordPress plugin
CVE-2026-81302 (PALLET CONTROL products contain an incorrect default
permission vulner ...)
- TODO: check
+ NOT-FOR-US: PALLET CONTROL products
CVE-2026-80190 (Apache Allura: stored XSS via SVN code repositories. Git
repositories ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-80119 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
- TODO: check
+ NOT-FOR-US: PassMark PerformanceTest
CVE-2026-80118 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
- TODO: check
+ NOT-FOR-US: PassMark PerformanceTest
CVE-2026-80117 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
- TODO: check
+ NOT-FOR-US: PassMark PerformanceTest
CVE-2026-80116 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
- TODO: check
+ NOT-FOR-US: PassMark PerformanceTest
CVE-2026-80115 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
- TODO: check
+ NOT-FOR-US: PassMark PerformanceTest
CVE-2026-80114 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
- TODO: check
+ NOT-FOR-US: PassMark PerformanceTest
CVE-2026-80113 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
- TODO: check
+ NOT-FOR-US: PassMark PerformanceTest
CVE-2026-80112 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest
before 11. ...)
- TODO: check
+ NOT-FOR-US: PassMark PerformanceTest
CVE-2026-79707 (A Path Traversal vulnerability in the builder endpoint in
Google Cloud ...)
- TODO: check
+ NOT-FOR-US: adk-python
CVE-2026-79426 (An arbitrary file deletion vulnerability in the
/adminapi/file/video_d ...)
- TODO: check
+ NOT-FOR-US: CRMEB
CVE-2026-79423 (An authenticated remote code execution (RCE) vulnerability in
the admi ...)
- TODO: check
+ NOT-FOR-US: seacms
CVE-2026-79419 (A reflected cross-site scripting (XSS) vulnerability exists in
EMX Tec ...)
- TODO: check
+ NOT-FOR-US: EMX Tecnologia Gestao X Business Suite
CVE-2026-79418 (EMX Tecnologia Gestao X version <= 8.4 contains a Stored
Cross-Site Sc ...)
- TODO: check
+ NOT-FOR-US: EMX Tecnologia Gestao X
CVE-2026-79391 (No authentication exists in the MQTT service of Trueview
6.0.23.4. The ...)
- TODO: check
+ NOT-FOR-US: Trueview
CVE-2026-79390 (Trueview TI8161 6.0.23.4 is vulnerable to information
disclosure due t ...)
- TODO: check
+ NOT-FOR-US: Trueview
CVE-2026-79389 (Trueview T18161 S 6.0.23.4 contains an improper verification
in MQTT c ...)
- TODO: check
+ NOT-FOR-US: Trueview
CVE-2026-78970 (JeecgBoot 3.9.2 and earlier contains an authorization bypass
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: JeecgBoot
CVE-2026-78849 (Cross Site Scripting vulnerability in Netgate pfSense Plus
software ve ...)
- TODO: check
+ NOT-FOR-US: Netgate pfSense Plus
CVE-2026-78839 (An arbitrary file upload vulnerability in AppNitro MachForm
v30 allows ...)
- TODO: check
+ NOT-FOR-US: AppNitro MachForm
CVE-2026-78745 (An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350
Hi3751V352E_DMO allow ...)
- TODO: check
+ NOT-FOR-US: HiDPT/ Weyon HiDPTAndroid
CVE-2026-78658 (IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3
through 7 ...)
NOT-FOR-US: IBM
CVE-2026-78543 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
@@ -493,7 +493,7 @@ CVE-2026-78150 (The Smart Post WordPress plugin before
4.0.8 does not check the
CVE-2026-78149 (The Smart Post WordPress plugin before 4.0.8 does not check
whether a ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77847 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are
vulnerab ...)
- TODO: check
+ NOT-FOR-US: Tycon Systems TPDIN-Monitor-WEB3
CVE-2026-77830 (The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin
for WordP ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77826 (The RegistrationMagic WordPress plugin before 6.0.9.9 does
not verify ...)
@@ -501,9 +501,9 @@ CVE-2026-77826 (The RegistrationMagic WordPress plugin
before 6.0.9.9 does not
CVE-2026-77822 (IBM ContextForge MCP Gateway could allow a remote
authenticated attack ...)
NOT-FOR-US: IBM
CVE-2026-77818 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Yordam Information Technology Consulting, Training and
Electronic Systems
CVE-2026-77393 (In Ignition 8.1.53 and earlier, the Gateway "Create Project
Role(s)" s ...)
- TODO: check
+ NOT-FOR-US: Ignition
CVE-2026-77263 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie
Consent + m ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77233 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie
Consent + m ...)
@@ -511,77 +511,77 @@ CVE-2026-77233 (The iubenda | All-in-one Compliance for
GDPR / CCPA Cookie Conse
CVE-2026-76925 (A flaw was found in Flatpak. A Time-of-check to time-of-use
(TOCTOU) r ...)
TODO: check
CVE-2026-76169 (fastify versions >= 4.0.0 and before 5.12.2 can route a
malformed URL ...)
- TODO: check
+ NOT-FOR-US: fastify
CVE-2026-75925 (Improper neutralization of CRLF sequences in IXON VPN Client
before ve ...)
- TODO: check
+ NOT-FOR-US: IXON VPN Client
CVE-2026-75439 (An issue in Free5GC v.4.2.2 allows a remote attacker to cause
a denial ...)
NOT-FOR-US: Free5GC
CVE-2026-75438 (Buffer Overflow vulnerability in Open5GS v2.7.7 allows a
remote attack ...)
TODO: check
CVE-2026-75431 (PowerJob Server version 5.1.2 (and likely earlier) uses a
predictable ...)
- TODO: check
+ NOT-FOR-US: PowerJob Server
CVE-2026-75430 (PowerJob Worker version 5.1.2 (and likely earlier versions)
exposes th ...)
- TODO: check
+ NOT-FOR-US: PowerJob
CVE-2026-75429 (PowerJob versions 4.x through 5.1.2 contain an unauthenticated
remote ...)
- TODO: check
+ NOT-FOR-US: PowerJob
CVE-2026-75171 (An issue in HubCore v.14.1.1 allows a remote attacker to
escalate priv ...)
- TODO: check
+ NOT-FOR-US: HubCore
CVE-2026-75170 (Cross-site scripting (XSS) vulnerability in the
/loginController/doLog ...)
- TODO: check
+ NOT-FOR-US: HubCore
CVE-2026-75169 (An arbitrary file upload vulnerability in
/cgi-bin/ugwupload.cgi of MB ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-75168 (An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in
MBS-Solu ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-75167 (A broken access control vulnerability in the ugw-usr-edit
method of /c ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-75166 (Insecure Permission vulnerability in MBS-Solutions X-Serie
Gateway fir ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-75165 (An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie
Gateway firmw ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-75164 (An arbitrary file read vulnerability in
/cgi-bin/ugwdownload.cgi of MB ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-75163 (An information disclosure vulnerability in the ugw-deviceinfo
method o ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-75162 (An information disclosure vulnerability in the
opcua-configuration met ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-75161 (An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in
MBS-Solut ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-75160 (An issue in X-Serie Gateway Firmware V6_00_05 allows a remote
attacker ...)
- TODO: check
+ NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
CVE-2026-74237 (GFI Exinda AI and ClearView before 7.6.5 contains an argument
injectio ...)
- TODO: check
+ NOT-FOR-US: GFI Exinda AI and ClearView
CVE-2026-74236 (GFI Exinda AI and ClearView before 7.6.5 contains a path
traversal vul ...)
- TODO: check
+ NOT-FOR-US: GFI Exinda AI and ClearView
CVE-2026-74235 (GFI Exinda AI and ClearView before 7.6.5 contains a path
traversal vul ...)
- TODO: check
+ NOT-FOR-US: GFI Exinda AI and ClearView
CVE-2026-73848 (Emlog is an open source website building system. In versions
2.6.29 an ...)
NOT-FOR-US: Emlog
CVE-2026-71626 (An issue in Invoice Ninja v5.13.24 allows a remote attacker to
obtain ...)
- TODO: check
+ NOT-FOR-US: Invoice Ninja
CVE-2026-71625 (An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote
attacker to e ...)
- TODO: check
+ NOT-FOR-US: slimkit plus ThinkSNS+
CVE-2026-71624 (An issue in esoTalk v.1.0.0g4 allows a remote attacker to
execute arbi ...)
- TODO: check
+ NOT-FOR-US: esoTalk
CVE-2026-71622 (SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1
allows a r ...)
- TODO: check
+ NOT-FOR-US: Zhao-github APiAdmin
CVE-2026-71620 (File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1
allows a rem ...)
- TODO: check
+ NOT-FOR-US: Zhao-github APiAdmin
CVE-2026-6958 (Acunetix 25.11.251107123 for Windows contains a local privilege
escala ...)
- TODO: check
+ NOT-FOR-US: Acunetix
CVE-2026-6217 (Use of a One-Way hash without a salt vulnerability in Pik
Online Softw ...)
- TODO: check
+ NOT-FOR-US: Pik Online Portal
CVE-2026-63464 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh VPN. ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-61699 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh VPN. ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-61688 (SolidInvoice is an open-source invoicing platform. Prior to
version 3. ...)
- TODO: check
+ NOT-FOR-US: SolidInvoice
CVE-2026-61686 (SolidInvoice is an open-source invoicing platform. Prior to
version 3. ...)
- TODO: check
+ NOT-FOR-US: SolidInvoice
CVE-2026-61614 (SolidInvoice is an open-source invoicing platform. Prior to
version 3. ...)
- TODO: check
+ NOT-FOR-US: SolidInvoice
CVE-2026-61608 (SolidInvoice is an open-source invoicing platform. Prior to
version 3. ...)
- TODO: check
+ NOT-FOR-US: SolidInvoice
CVE-2026-5522 (IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains
hard-code ...)
NOT-FOR-US: IBM
CVE-2026-57777 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
@@ -603,17 +603,17 @@ CVE-2026-57160 (PJSIP is a free and open source
multimedia communication library
CVE-2026-57159 (PJSIP is a free and open source multimedia communication
library writt ...)
TODO: check
CVE-2026-55513 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh VPN. ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-55512 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh VPN. ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-53932 (laravel-backup-restore restores database backups made with
spatie/lara ...)
- TODO: check
+ NOT-FOR-US: laravel-backup-restore
CVE-2026-53769 (Avo is a framework to create admin panels for Ruby on Rails
apps. From ...)
- TODO: check
+ NOT-FOR-US: Avo
CVE-2026-53761 (Frappe CRM is an open-source customer relationship management
tool. Pr ...)
- TODO: check
+ NOT-FOR-US: Frappe CRM
CVE-2026-53760 (Admidio is an open-source user management solution. In
versions 5.0.11 ...)
- TODO: check
+ NOT-FOR-US: Admidio
CVE-2026-53758 (Emlog is an open source website building system. In versions
2.6.29 an ...)
NOT-FOR-US: Emlog
CVE-2026-53757 (Emlog is an open source website building system. In versions
2.6.29 an ...)
@@ -621,41 +621,41 @@ CVE-2026-53757 (Emlog is an open source website building
system. In versions 2.6
CVE-2026-53756 (Emlog is an open source website building system. Prior to
version 2.6. ...)
NOT-FOR-US: Emlog
CVE-2026-53604 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh VPN. ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-53603 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh VPN. ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-53602 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh VPN. ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-52777 (YesWiki is a wiki system written in PHP. Prior to version
4.6.6, there ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52775 (YesWiki is a wiki system written in PHP. Prior to version
4.6.6, YesWi ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52774 (YesWiki is a wiki system written in PHP. Prior to version
4.6.6, YesWi ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52773 (YesWiki is a wiki system written in PHP. From version 4.1.0 to
before ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52772 (YesWiki is a wiki system written in PHP. Prior to version
4.6.6, Bazar ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52771 (YesWiki is a wiki system written in PHP. From version 4.2.0 to
before ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52770 (YesWiki is a wiki system written in PHP. Prior to version
4.6.6, YesWi ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52769 (YesWiki is a wiki system written in PHP. From version 4.6.2 to
before ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52767 (YesWiki is a wiki system written in PHP. From version 4.6.2 to
before ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52766 (YesWiki is a wiki system written in PHP. Prior to version
4.6.6, the { ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52763 (YesWiki is a wiki system written in PHP. Prior to version
4.6.6, the r ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52762 (YesWiki is a wiki system written in PHP. Prior to version
4.6.6, YesWi ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-52691 (** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of
Special Ele ...)
TODO: check
CVE-2026-50894 (easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of
File with D ...)
- TODO: check
+ NOT-FOR-US: easyadmin
CVE-2026-50553 (Note Mark is an open-source note-taking application. Prior to
version ...)
- TODO: check
+ NOT-FOR-US: Note Mark
CVE-2026-4644 (A Missing Authorization vulnerability in HTTP Connector in
Google Clou ...)
TODO: check
CVE-2026-4361 (The Divi theme for WordPress is vulnerable to Server-Side
Request Forg ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ee77df6b9a7ce0fbfdcc89e1e32174ff575781c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ee77df6b9a7ce0fbfdcc89e1e32174ff575781c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits