Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
eb41839e by Salvatore Bonaccorso at 2026-09-12T11:10:53+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -127,7 +127,7 @@ CVE-2026-80494 (The Yogeta WP Cloud WordPress plugin
through 1.0 does not valida
CVE-2026-80491 (The SAMO Forms WordPress plugin through 1.0.0 does not
properly saniti ...)
NOT-FOR-US: WordPress plugin
CVE-2026-79035 (A reflected cross-site scripting (XSS) vulnerability in the
p.rfihub.c ...)
- TODO: check
+ NOT-FOR-US: p.rfihub.com component of Zeta Marketing Platform (ZMP)
CVE-2026-78547 (Out-of-bounds write vulnerability in Citrix Citrix Workspace
app for W ...)
NOT-FOR-US: Citrix
CVE-2026-78546 (Out-of-bounds read vulnerability in Citirx Workspace app for
Windows. ...)
@@ -157,51 +157,51 @@ CVE-2026-68526 (Concrete CMS before 9.5.3 did not
validate an anti-CSRF token in
CVE-2026-54258 (ZoneMinder is a free, open source closed-circuit television
software a ...)
TODO: check
CVE-2026-54248 (Doco-CD is a GitOps continuous delivery tool that
automatically deploy ...)
- TODO: check
+ NOT-FOR-US: Doco-CD
CVE-2026-54174 (melange allows users to build apk packages using declarative
pipelines ...)
- TODO: check
+ NOT-FOR-US: Melange
CVE-2026-54166 (Shelf is a platform for tracking physical assets. Prior to
version 1.2 ...)
- TODO: check
+ NOT-FOR-US: Shelf
CVE-2026-54165 (Dobase is an open-source, self-hosted workspace with
installable tools ...)
- TODO: check
+ NOT-FOR-US: Dobase
CVE-2026-54135 (AirSane is a SANE frontend, and a scanner server that supports
Apple's ...)
TODO: check
CVE-2026-53952 (GetSimple CMS is a content management system (CMS), and
GetSimple CMS ...)
- TODO: check
+ NOT-FOR-US: GetSimple CMS
CVE-2026-52630 (SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before
allows a ...)
- TODO: check
+ NOT-FOR-US: Woltlab WCF
CVE-2026-50025 (Mousehole is a background service to update a seedbox IP for
MAM and w ...)
- TODO: check
+ NOT-FOR-US: Mousehole
CVE-2026-50018 (Hoverfly is an open source API simulation tool. Prior to
version 1.12. ...)
- TODO: check
+ NOT-FOR-US: Hoverfly
CVE-2026-50013 (Hoverfly is an open source API simulation tool. Prior to
version 1.12. ...)
- TODO: check
+ NOT-FOR-US: Hoverfly
CVE-2026-49992 (Kimai is an open-source time tracking application. Versions
prior to 2 ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-49865 (Kimai is an open-source time tracking application. Versions
prior to 2 ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-49846 (libks provides foundational support for signalwire C products.
Prior t ...)
- TODO: check
+ NOT-FOR-US: libks
CVE-2026-49464 (NL Portal Backend Libraries provide backend components for
Dutch gover ...)
- TODO: check
+ NOT-FOR-US: NL Portal Backend Libraries
CVE-2026-49463 (NL Portal Backend Libraries provide backend components for
Dutch gover ...)
- TODO: check
+ NOT-FOR-US: NL Portal Backend Libraries
CVE-2026-49462 (NL Portal Backend Libraries provide backend components for
Dutch gover ...)
- TODO: check
+ NOT-FOR-US: NL Portal Backend Libraries
CVE-2026-49439 (OpenRemote is an open-source internet-of-things platform.
Prior to ver ...)
- TODO: check
+ NOT-FOR-US: OpenRemote
CVE-2026-48496 (OpenTelemetry eBPF Profiler is a production-scale agent for
profiling ...)
- TODO: check
+ NOT-FOR-US: OpenTelemetry eBPF Profiler
CVE-2026-48490 (ArduinoCore-avr contains the source code and configuration
files of th ...)
- TODO: check
+ NOT-FOR-US: ArduinoCore-avr
CVE-2026-47773 (ArduinoBLE enables Bluetooth Low Energy connectivity on
certain Arduin ...)
- TODO: check
+ NOT-FOR-US: ArduinoBLE
CVE-2026-45057 (matrix-sdk-ui provides GUI-centric utilities on top of
matrix-rust-sdk ...)
- TODO: check
+ NOT-FOR-US: matrix-sdk-ui
CVE-2026-45056 (matrix-sdk-crypto is a no-network-IO implementation of a state
machine ...)
- TODO: check
+ NOT-FOR-US: matrix-sdk-crypto Rust crate
CVE-2026-44715 (OpenMRS is an open source electronic medical record system
platform. P ...)
- TODO: check
+ NOT-FOR-US: OpenMRS
CVE-2026-89673 (In the Linux kernel, the following vulnerability has been
resolved: n ...)
- linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/
@@ -1960,7 +1960,7 @@ CVE-2026-80462 (A vulnerability in the Chef Automate API
gateway and identity va
CVE-2026-7863 (Improper neutralization of special elements used in an OS
command ('OS ...)
NOT-FOR-US: Pardus Software
CVE-2026-7298 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: IdeaSoft Software Industry and Trade Inc. Smart E-Commerce
CVE-2026-79396 (Use of hardcoded default credentials in Xiongmai IP Camera
XM530 firmw ...)
NOT-FOR-US: Xiongmai IP Camera XM530 firmware
CVE-2026-79395 (An improper authentication vulnerability in the WS-Security
(wsse:User ...)
@@ -1995,13 +1995,13 @@ CVE-2026-72708 (SPIP before 4.4.18 contains an
unauthenticated blind SQL injecti
NOTE: https://blog.lexfo.fr/casse-spip-sqli-to-rce.html
NOTE:
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html
CVE-2026-71646 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested
affected ...)
- TODO: check
+ NOT-FOR-US: Robotics-STAR-Lab
CVE-2026-71644 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested
affected ...)
- TODO: check
+ NOT-FOR-US: Robotics-STAR-Lab
CVE-2026-71641 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to
commit 5c99 ...)
- TODO: check
+ NOT-FOR-US: ZJU-FAST-Lab EGO-Planner-v2
CVE-2026-71416 (Headroom compresses data before the data reaches a large
language mode ...)
- TODO: check
+ NOT-FOR-US: Headroom
CVE-2026-70341 (Use after free in Microsoft Edge (Chromium-based) allows an
authorized ...)
NOT-FOR-US: Microsoft
CVE-2026-6642 (The Media Library Assistant plugin for WordPress is vulnerable
to Stor ...)
@@ -2061,25 +2061,25 @@ CVE-2026-62089 (Missing Authorization vulnerability in
Pixar Labs Master Addons
CVE-2026-62088 (Insertion of Sensitive Information Into Sent Data
vulnerability in 10u ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-57843 (NetBSD contains an information disclosure vulnerability in
mm_open() w ...)
- TODO: check
+ NOT-FOR-US: NetBSD
CVE-2026-57842 (NetBSD contains a use-after-free and double-free vulnerability
in msg_ ...)
- TODO: check
+ NOT-FOR-US: NetBSD
CVE-2026-54072 (Authorizer is an open-source, self-hostable authentication and
authori ...)
- TODO: check
+ NOT-FOR-US: Authorizer
CVE-2026-54047 (Laci Synchroni is a decentralized mod and appearance sync
server and p ...)
- TODO: check
+ NOT-FOR-US: Laci Synchroni
CVE-2026-47839 (A vulnerability allows users authenticating through a
federated OIDC p ...)
- TODO: check
+ NOT-FOR-US: Cloud Foundry Foundation UAA
CVE-2026-3869 (CWE-303 : Incorrect Implementation of Authentication Algorithm
vulnera ...)
NOT-FOR-US: Schneider Electric
CVE-2026-38058 (The endpoint on the iDirect iQ200 VSAT terminal returns the
complete d ...)
- TODO: check
+ NOT-FOR-US: iDirect
CVE-2026-38056 (A local privilege escalation vulnerability exists in the
iDirect iQ200 ...)
- TODO: check
+ NOT-FOR-US: iDirect
CVE-2026-27378 (Unauthenticated Broken Access Control in Deposits and Partial
Payments ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-19486 (A Server-Side Request Forgery (SSRF) vulnerability in Google
Cloud Gem ...)
- TODO: check
+ NOT-FOR-US: Google Cloud Gemini Enterprise Agent Platform App Builder
CVE-2026-18495 (A flaw was found in libtiff. A heap-buffer overflow
vulnerability exis ...)
TODO: check
CVE-2026-18122 (Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint
exposes res ...)
@@ -2093,11 +2093,11 @@ CVE-2026-15710 (An information leakage vulnerability
exists in the Endpoint DLP
CVE-2026-15439 (The GamiPress plugin for WordPress is vulnerable to
authenticated (Sub ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11765 (Improper neutralization of argument delimiters in a command
('argument ...)
- TODO: check
+ NOT-FOR-US: TUBITAK BILGEM Software Technologies Research Institute
Pardus Pen
CVE-2025-69904 (Linkstack v4.8.4 and earlier is vulnerable to Path Traversal,
which al ...)
- TODO: check
+ NOT-FOR-US: Linkstack
CVE-2025-15679 (Under certain circumstances such as reset to factory default
operation ...)
- TODO: check
+ NOT-FOR-US: BullSequana
CVE-2024-12145 (The BuddyPress plugin for WordPress is vulnerable to Insecure
Direct O ...)
NOT-FOR-US: WordPress plugin
CVE-2026-9768
@@ -2341,7 +2341,7 @@ CVE-2026-19985 (The Relevanssi \u2013 A Better Search
plugin for WordPress is vu
CVE-2026-19646 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2,
ART 9.0, ...)
NOT-FOR-US: IBM
CVE-2026-19596 (An XML External Entity (XXE) vulnerability exists in the XML
collector ...)
- TODO: check
+ NOT-FOR-US: OpenNMS
CVE-2026-19136 (A potential command injection vulnerability was reported in
the Tianxi ...)
NOT-FOR-US: Lenovo
CVE-2026-18994 (A potential improper authorization vulnerability was reported
in the L ...)
@@ -2387,7 +2387,7 @@ CVE-2026-11496 (The Woo PDF Invoice Builder plugin (also
distributed as "PDF Bui
CVE-2026-11446 (The Booktics \u2013 Booking Calendar for Appointments and
Service Busi ...)
NOT-FOR-US: WordPress plugin
CVE-2025-57231 (Path Traversal in avatar attachments in Docmost v0.21.0 allows
an unau ...)
- TODO: check
+ NOT-FOR-US: Docmost
CVE-2025-15695 (The Translate WordPress with GTranslate WordPress plugin
before 3.0.10 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88914 (A flaw was found in GStreamer's gst-plugins-good isomp4
plugin. When p ...)
@@ -2878,7 +2878,7 @@ CVE-2026-80352 (Improper Control of Generation of Code
('Code Injection') vulner
CVE-2026-80351 (Improper neutralization of directives in dynamically evaluated
code (' ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-7188 (Improper neutralization of special elements used in an SQL
command ('S ...)
- TODO: check
+ NOT-FOR-US: Armiya Information Technologies Access Control System
CVE-2026-79987 (A remote, authenticated, non-admin Craft CMS Control Panel
user with o ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-78536 (Unauthenticated Broken Access Control in Robokassa payment
gateway for ...)
@@ -2908,13 +2908,13 @@ CVE-2026-73694 (FileRun before 2026.3.0 contains an OS
command injection vulnera
CVE-2026-73693 (FileRun before 2026.3.0 contains an OS command injection
vulnerability ...)
NOT-FOR-US: FileRun
CVE-2026-6285 (Weak Password Recovery Mechanism for Forgotten Password
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
CVE-2026-68527 (Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an
authori ...)
NOT-FOR-US: Concrete CMS
CVE-2026-68488 (A Time-of-check Time-of-use (TOCTOU) race condition leading to
insecur ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-68487 (Path traversal in Plesk's Backup Manager causes arbitrary file
write a ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-68006 (An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker
to exec ...)
TODO: check
CVE-2026-66674 (Unauthenticated Bypass Vulnerability in Simple Cloudflare
Turnstile <= ...)
@@ -2922,21 +2922,21 @@ CVE-2026-66674 (Unauthenticated Bypass Vulnerability in
Simple Cloudflare Turnst
CVE-2026-66632 (Unauthenticated Content Injection in Simple Cloudflare
Turnstile <= 1. ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65639 (OS command injection in the advanced-rule parser of
ConfigServer Secur ...)
- TODO: check
+ NOT-FOR-US: Cpanel ConfigServer Security & Firewall
CVE-2026-65638 (Improper escaping of a request URL in ConfigServer Security &
Firewal ...)
- TODO: check
+ NOT-FOR-US: Cpanel ConfigServer Security & Firewall
CVE-2026-64838 (ICEcoder versions through 8.1 fail to properly validate the
oldFileNam ...)
- TODO: check
+ NOT-FOR-US: ICEcoder
CVE-2026-64837 (ICEcoder through 8.1 passes an unescaped filesystem path into
a shell ...)
- TODO: check
+ NOT-FOR-US: ICEcoder
CVE-2026-64836 (ICEcoder versions through 8.1 contain a path traversal
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: ICEcoder
CVE-2026-5399 (The Redux Framework plugin for WordPress is vulnerable to
Stored Cross ...)
NOT-FOR-US: WordPress plugin
CVE-2026-52098 (An issue in Flowise 3.1.2 allows a remote attacker to execute
arbitrar ...)
NOT-FOR-US: Flowise
CVE-2026-52097 (An issue in AppFlowy 0.11.8 allows a remote attacker to
execute arbitr ...)
- TODO: check
+ NOT-FOR-US: AppFlowy
CVE-2026-4130 (There is a storage of sensitive information in cleartext
vulnerability ...)
NOT-FOR-US: National Instruments
CVE-2026-4129 (There is an improper access control vulnerability in NI
SystemLink tha ...)
@@ -2952,9 +2952,9 @@ CVE-2026-42805 (A stack-based buffer overflow
vulnerability exists in the Bosch
CVE-2026-42804 (A stack-based buffer overflow vulnerability exists in the
Bosch Sensor ...)
NOT-FOR-US: Bosch
CVE-2026-38626 (Garlic-Hub v1.0.1 is vulnerable to SQL Injection in
src/Modules/Items/ ...)
- TODO: check
+ NOT-FOR-US: Garlic-Hub
CVE-2026-17038 (DrEryk Gabinet before 11.5.0uses hard-coded API credentials in
its tic ...)
- TODO: check
+ NOT-FOR-US: DrEryk Gabinet
CVE-2026-15889 (The Aruba HiSpeed Cache plugin for WordPress is vulnerable to
Stored C ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15461 (The Sierra Wireless HL78xx modem GNSS driver
(drivers/modem/hl78xx/, l ...)
@@ -2966,11 +2966,11 @@ CVE-2026-15418 (In the silabser.sys driver for CP210x
devices v11.5.0 and earlie
CVE-2026-15417 (In the silabser.sys Windows 8 driver for CP210x devices, a
local unpri ...)
NOT-FOR-US: Silicon Labs
CVE-2026-13745 (A vulnerability in the Gemini CLI and associated GitHub Action
allowed ...)
- TODO: check
+ NOT-FOR-US: Gemini CLI
CVE-2026-12683 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
CVE-2026-12682 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
CVE-2026-88069 (Pandora contains a path traversal vulnerability in its archive
extract ...)
NOT-FOR-US: Pandora
CVE-2026-88002 (Open WebUI is an extensible, feature-rich, and user-friendly
self-host ...)
@@ -3097,7 +3097,7 @@ CVE-2026-71805 (An arbitrary file upload and path
traversal vulnerability exists
CVE-2026-71803 (money-pos 1.0 contains a stored Cross-Site Scripting (XSS)
vulnerabili ...)
NOT-FOR-US: money-pos
CVE-2026-71802 (A stored Cross-Site Scripting (XSS) vulnerability exists in
the announ ...)
- TODO: check
+ NOT-FOR-US: REBUILD
CVE-2026-71801 (An issue was discovered in s-pms SPMS-Server through v1.0. The
applica ...)
NOT-FOR-US: s-pms SPMS-Server
CVE-2026-71616 (An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3
allows an at ...)
@@ -536233,7 +536233,7 @@ CVE-2022-26964 (Weak password derivation for export
in Devolutions Remote Deskto
CVE-2022-26963
RESERVED
CVE-2022-26962 (Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under
NP_BCCAS- ...)
- TODO: check
+ NOT-FOR-US: Italtel
CVE-2022-26961 (Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS
under NP_ ...)
NOT-FOR-US: Italtel NetMatch-S
CVE-2022-26960 (connector.minimal.php in std42 elFinder through 2.1.60 is
affected by ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb41839e5534d47abf5972836084e125d93b505f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb41839e5534d47abf5972836084e125d93b505f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits