Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
cb1c9666 by Salvatore Bonaccorso at 2026-09-06T14:24:02+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -200,7 +200,7 @@ CVE-2026-0799 (In BPF instructions that load/store a value 
from/to a scratch mem
 CVE-2025-9049 (The Nokri \u2013 Job Board WordPress Theme theme for WordPress 
is vuln ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-15647 (CDT before 1.4.5 contains an out-of-bounds read vulnerability 
in the o ...)
-       TODO: check
+       NOT-FOR-US: CDT
 CVE-2025-15614 (ugrep before 7.6.0 contains a heap buffer over-read 
vulnerability in t ...)
        - ugrep 7.6.0+dfsg-1
        NOTE: https://github.com/Genivia/ugrep/issues/511
@@ -899,15 +899,15 @@ CVE-2026-4644 (A Missing Authorization vulnerability in 
HTTP Connector in Google
 CVE-2026-4361 (The Divi theme for WordPress is vulnerable to Server-Side 
Request Forg ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-44402 (Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated 
remote co ...)
-       TODO: check
+       NOT-FOR-US: Voltronic Power SNMP Web Pro
 CVE-2026-3853 (The Divi theme for WordPress is vulnerable to DOM-Based Stored 
Cross-S ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-38961 (Cross-Site Scripting (XSS) vulnerability in the RSS Widget of 
Netgate  ...)
-       TODO: check
+       NOT-FOR-US: Netgate pfSense Plus
 CVE-2026-32480 (Missing Authorization vulnerability in WC Lovers WCFM 
Membership allow ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-31020 (In DocsGPT 0.15.0 and below, the application provides a custom 
prompt  ...)
-       TODO: check
+       NOT-FOR-US: DocsGPT
 CVE-2026-27432 (Authorization Bypass Through User-Controlled Key vulnerability 
in sc I ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27347 (Missing Authorization vulnerability in Crocoblock JetPopup 
allows Expl ...)
@@ -923,7 +923,7 @@ CVE-2026-19858 (The JetFormBuilder \u2014 Dynamic Blocks 
Form Builder WordPress
 CVE-2026-19769 (The Ninja Forms \u2013 The Contact Form Builder That Grows 
With You pl ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-19727 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Library Information and Document Automation Program
 CVE-2026-19649 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
        NOT-FOR-US: IBM
 CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An 
authenticated user  ...)
@@ -1074,7 +1074,7 @@ CVE-2026-14975 (The WP File Download plugin for WordPress 
is vulnerable to Direc
 CVE-2026-14470 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow an 
authenticated att ...)
        NOT-FOR-US: IBM
 CVE-2026-14466 (It\u2019s possible to run a stored XSS in Stormshield\u2019s 
web admin ...)
-       TODO: check
+       NOT-FOR-US: Stormshield
 CVE-2026-14350 (IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 
could a ...)
        NOT-FOR-US: IBM
 CVE-2026-13447 (The Mstore Api plugin for WordPress is vulnerable to 
Authentication By ...)
@@ -1086,7 +1086,7 @@ CVE-2026-13148 (Missing release of memory after effective 
lifetime vulnerability
 CVE-2026-12483 (The LearnDash LMS plugin for WordPress is vulnerable to 
Unrestricted F ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-67066 (SQL Injection vulnerability in oasys sysoa version 1.0 allows 
a remote ...)
-       TODO: check
+       NOT-FOR-US: oasys sysoa
 CVE-2025-15694 (The Joli Table Of Contents WordPress plugin before 2.8.1 does 
not sani ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-15693 (The JCH Optimize WordPress plugin before 5.0.1 does not 
properly restr ...)
@@ -502131,11 +502131,11 @@ CVE-2022-35501 (Stored Cross-site Scripting (XSS) 
exists in the Amasty Blog Pro
 CVE-2022-35500 (Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) 
via lea ...)
        NOT-FOR-US: Amasty Blog
 CVE-2022-35499 (In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint 
is vulne ...)
-       TODO: check
+       NOT-FOR-US: Trimble TM4WEB
 CVE-2022-35498
        RESERVED
 CVE-2022-35497 (In Trimble TM4WEB 21.4.0.4 due to security misconfiguration 
with sessi ...)
-       TODO: check
+       NOT-FOR-US: Trimble TM4WEB
 CVE-2022-35496
        RESERVED
 CVE-2022-35495
@@ -527222,7 +527222,7 @@ CVE-2022-26963
 CVE-2022-26962
        RESERVED
 CVE-2022-26961 (Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS 
under NP_ ...)
-       TODO: check
+       NOT-FOR-US: Italtel NetMatch-S
 CVE-2022-26960 (connector.minimal.php in std42 elFinder through 2.1.60 is 
affected by  ...)
        NOT-FOR-US: std42 elFinder
 CVE-2022-26959 (There are two full (read/write) Blind/Time-based SQL injection 
vulnera ...)
@@ -549277,9 +549277,9 @@ CVE-2021-44322
 CVE-2021-44321 (Mini-Inventory-and-Sales-Management-System is affected by 
Cross Site R ...)
        NOT-FOR-US: Mini-Inventory-and-Sales-Management-System
 CVE-2021-44320 (Parrot AR.Drone version 1 and 2 does not employ a suitable 
mechanism t ...)
-       TODO: check
+       NOT-FOR-US: Parrot AR.Drone
 CVE-2021-44319 (Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of 
Service.  ...)
-       TODO: check
+       NOT-FOR-US: Parrot AR.Drone
 CVE-2021-44318
        RESERVED
 CVE-2021-44317 (In Bus Pass Management System v1.0, parameters 'pagedes' and 
`About Us ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb1c96665fd4cdd6749ad4f8b5887b6340bcc08e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb1c96665fd4cdd6749ad4f8b5887b6340bcc08e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to