Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
cb1c9666 by Salvatore Bonaccorso at 2026-09-06T14:24:02+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -200,7 +200,7 @@ CVE-2026-0799 (In BPF instructions that load/store a value
from/to a scratch mem
CVE-2025-9049 (The Nokri \u2013 Job Board WordPress Theme theme for WordPress
is vuln ...)
NOT-FOR-US: WordPress plugin
CVE-2025-15647 (CDT before 1.4.5 contains an out-of-bounds read vulnerability
in the o ...)
- TODO: check
+ NOT-FOR-US: CDT
CVE-2025-15614 (ugrep before 7.6.0 contains a heap buffer over-read
vulnerability in t ...)
- ugrep 7.6.0+dfsg-1
NOTE: https://github.com/Genivia/ugrep/issues/511
@@ -899,15 +899,15 @@ CVE-2026-4644 (A Missing Authorization vulnerability in
HTTP Connector in Google
CVE-2026-4361 (The Divi theme for WordPress is vulnerable to Server-Side
Request Forg ...)
NOT-FOR-US: WordPress plugin
CVE-2026-44402 (Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated
remote co ...)
- TODO: check
+ NOT-FOR-US: Voltronic Power SNMP Web Pro
CVE-2026-3853 (The Divi theme for WordPress is vulnerable to DOM-Based Stored
Cross-S ...)
NOT-FOR-US: WordPress plugin
CVE-2026-38961 (Cross-Site Scripting (XSS) vulnerability in the RSS Widget of
Netgate ...)
- TODO: check
+ NOT-FOR-US: Netgate pfSense Plus
CVE-2026-32480 (Missing Authorization vulnerability in WC Lovers WCFM
Membership allow ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-31020 (In DocsGPT 0.15.0 and below, the application provides a custom
prompt ...)
- TODO: check
+ NOT-FOR-US: DocsGPT
CVE-2026-27432 (Authorization Bypass Through User-Controlled Key vulnerability
in sc I ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-27347 (Missing Authorization vulnerability in Crocoblock JetPopup
allows Expl ...)
@@ -923,7 +923,7 @@ CVE-2026-19858 (The JetFormBuilder \u2014 Dynamic Blocks
Form Builder WordPress
CVE-2026-19769 (The Ninja Forms \u2013 The Contact Form Builder That Grows
With You pl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19727 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Library Information and Document Automation Program
CVE-2026-19649 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and
12.0.1.0 thr ...)
NOT-FOR-US: IBM
CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An
authenticated user ...)
@@ -1074,7 +1074,7 @@ CVE-2026-14975 (The WP File Download plugin for WordPress
is vulnerable to Direc
CVE-2026-14470 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow an
authenticated att ...)
NOT-FOR-US: IBM
CVE-2026-14466 (It\u2019s possible to run a stored XSS in Stormshield\u2019s
web admin ...)
- TODO: check
+ NOT-FOR-US: Stormshield
CVE-2026-14350 (IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001
could a ...)
NOT-FOR-US: IBM
CVE-2026-13447 (The Mstore Api plugin for WordPress is vulnerable to
Authentication By ...)
@@ -1086,7 +1086,7 @@ CVE-2026-13148 (Missing release of memory after effective
lifetime vulnerability
CVE-2026-12483 (The LearnDash LMS plugin for WordPress is vulnerable to
Unrestricted F ...)
NOT-FOR-US: WordPress plugin
CVE-2025-67066 (SQL Injection vulnerability in oasys sysoa version 1.0 allows
a remote ...)
- TODO: check
+ NOT-FOR-US: oasys sysoa
CVE-2025-15694 (The Joli Table Of Contents WordPress plugin before 2.8.1 does
not sani ...)
NOT-FOR-US: WordPress plugin
CVE-2025-15693 (The JCH Optimize WordPress plugin before 5.0.1 does not
properly restr ...)
@@ -502131,11 +502131,11 @@ CVE-2022-35501 (Stored Cross-site Scripting (XSS)
exists in the Amasty Blog Pro
CVE-2022-35500 (Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS)
via lea ...)
NOT-FOR-US: Amasty Blog
CVE-2022-35499 (In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint
is vulne ...)
- TODO: check
+ NOT-FOR-US: Trimble TM4WEB
CVE-2022-35498
RESERVED
CVE-2022-35497 (In Trimble TM4WEB 21.4.0.4 due to security misconfiguration
with sessi ...)
- TODO: check
+ NOT-FOR-US: Trimble TM4WEB
CVE-2022-35496
RESERVED
CVE-2022-35495
@@ -527222,7 +527222,7 @@ CVE-2022-26963
CVE-2022-26962
RESERVED
CVE-2022-26961 (Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS
under NP_ ...)
- TODO: check
+ NOT-FOR-US: Italtel NetMatch-S
CVE-2022-26960 (connector.minimal.php in std42 elFinder through 2.1.60 is
affected by ...)
NOT-FOR-US: std42 elFinder
CVE-2022-26959 (There are two full (read/write) Blind/Time-based SQL injection
vulnera ...)
@@ -549277,9 +549277,9 @@ CVE-2021-44322
CVE-2021-44321 (Mini-Inventory-and-Sales-Management-System is affected by
Cross Site R ...)
NOT-FOR-US: Mini-Inventory-and-Sales-Management-System
CVE-2021-44320 (Parrot AR.Drone version 1 and 2 does not employ a suitable
mechanism t ...)
- TODO: check
+ NOT-FOR-US: Parrot AR.Drone
CVE-2021-44319 (Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of
Service. ...)
- TODO: check
+ NOT-FOR-US: Parrot AR.Drone
CVE-2021-44318
RESERVED
CVE-2021-44317 (In Bus Pass Management System v1.0, parameters 'pagedes' and
`About Us ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb1c96665fd4cdd6749ad4f8b5887b6340bcc08e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb1c96665fd4cdd6749ad4f8b5887b6340bcc08e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits