Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8fc4a97f by Salvatore Bonaccorso at 2026-09-05T21:28:13+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,79 +1,79 @@
CVE-2026-86197 (Grav before 2.0.20 contains a cross-site scripting
vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-86196 (Grav API plugin versions before 1.0.20 build password reset
links from ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-86195 (grav-plugin-api versions before 1.0.20 contain a privilege
escalation ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-86194 (Grav Form Plugin before 9.1.22 fails to verify page
authorization when ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-86193 (grav-plugin-api before 1.0.20 fails to validate
group-inherited super ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-86192 (SiYuan versions before v3.8.2 fail to properly filter private
attribut ...)
NOT-FOR-US: SiYuan
CVE-2026-86191 (SiYuan versions before v3.8.2 contain an information
disclosure vulner ...)
NOT-FOR-US: SiYuan
CVE-2026-86190 (WWBN AVideo contains a broken access control vulnerability in
videoVie ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86189 (WWBN AVideo contains a path traversal vulnerability in
notify.ffmpeg.j ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86188 (AVideo with YPTSocket plugin enabled contains a cross-site
scripting v ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86187 (WWBN AVideo generates passwords for external-login accounts
using rand ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86186 (AVideo API fails to enforce rate limits when clients send a
bot User-A ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86185 (Bilibili Desktop through 1.18.0 disables TLS certificate
verification ...)
- TODO: check
+ NOT-FOR-US: Bilibili Desktop
CVE-2026-86184 (Lara Dashboard before 1.3.0 contains an authentication bypass
vulnerab ...)
- TODO: check
+ NOT-FOR-US: Lara Dashboard
CVE-2026-86178 (Pixelfed through 0.12.9 fails to validate follower status in
StoryComp ...)
- TODO: check
+ NOT-FOR-US: Pixelfed
CVE-2026-86177 (Pterodactyl Panel before 1.14.1 fails to validate
action-specific perm ...)
- TODO: check
+ NOT-FOR-US: Pterodactyl Panel
CVE-2026-86176 (NetBox through 4.7.0 fails to properly scope user-private
records in R ...)
TODO: check
CVE-2026-86175 (NetBox through 4.7.0 fails to redact sensitive data source
backend cre ...)
TODO: check
CVE-2026-86174 (Plane through 1.4.2 fails to validate that issues belong to
the deploy ...)
- TODO: check
+ NOT-FOR-US: Plane
CVE-2026-86173 (MindsDB through 26.1.0 contains a server-side request forgery
vulnerab ...)
- TODO: check
+ NOT-FOR-US: MindsDB
CVE-2026-86169 (Axolotl through 0.18.0 contains a remote code execution
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Axolotl
CVE-2026-86124 (AutoAgent contains an unauthenticated remote code execution
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: AutoAgent
CVE-2026-86123 (SQL Chat contains four unauthenticated API endpoints that
accept clien ...)
- TODO: check
+ NOT-FOR-US: SQL Chat
CVE-2026-86122 (Rowboat through 0.9.1 fails to validate custom MCP server and
webhook ...)
- TODO: check
+ NOT-FOR-US: Rowboat
CVE-2026-86121 (Cua computer-server versions before 0.3.42 skip authentication
when th ...)
- TODO: check
+ NOT-FOR-US: Cua computer-server
CVE-2026-86120 (APITable through 1.13.0-beta.1 contains an incorrect
authorization vul ...)
- TODO: check
+ NOT-FOR-US: APITable
CVE-2026-86119 (Webstudio through 0.296.0 contains an unauthenticated
server-side requ ...)
- TODO: check
+ NOT-FOR-US: Webstudio
CVE-2026-86118 (gonic versions before 0.22.0 fail to validate administrator
privileges ...)
- TODO: check
+ NOT-FOR-US: gonic music streaming server
CVE-2026-86117 (Coolify through 4.3.17 contains an authentication bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Coolify
CVE-2026-86116 (Metabase versions before 0.63.1 fail to enforce data analyst
permissio ...)
- TODO: check
+ NOT-FOR-US: Metabase
CVE-2026-86115 (Sim before 0.8.14 classifies tool requests as internal based
on URL pr ...)
- TODO: check
+ NOT-FOR-US: Sim
CVE-2026-86114 (Arcane versions before 2.0.0 fail to properly restrict
template operat ...)
- TODO: check
+ NOT-FOR-US: Arcane
CVE-2026-86113 (BookWyrm through 0.9.1 contains an authorization bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: BookWyrm
CVE-2026-86112 (BookWyrm through 0.9.1 fails to validate user visibility
permissions i ...)
- TODO: check
+ NOT-FOR-US: BookWyrm
CVE-2026-86111 (BookWyrm through 0.9.1 fails to validate user visibility
permissions i ...)
- TODO: check
+ NOT-FOR-US: BookWyrm
CVE-2026-85414 (The Gallery : FooGallery plugin for WordPress is vulnerable to
Stored ...)
NOT-FOR-US: WordPress plugin
CVE-2026-83625 (The Contact Form by Supsystic plugin for WordPress is
vulnerable to St ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82752 (Improper Validation of Specified Quantity in Input
vulnerability in as ...)
- TODO: check
+ NOT-FOR-US: ash-project
CVE-2026-81543 (The Abandoned Cart Pro for WooCommerce plugin for WordPress is
vulnera ...)
NOT-FOR-US: WordPress plugin
CVE-2026-76573 (The Pods \u2013 Custom Content Types and Fields plugin for
WordPress i ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fc4a97f8ec3c5085ef21d900bebfc0b2f97e803
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fc4a97f8ec3c5085ef21d900bebfc0b2f97e803
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits