Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
eb41839e by Salvatore Bonaccorso at 2026-09-12T11:10:53+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -127,7 +127,7 @@ CVE-2026-80494 (The Yogeta WP Cloud WordPress plugin 
through 1.0 does not valida
 CVE-2026-80491 (The SAMO Forms WordPress plugin through 1.0.0 does not 
properly saniti ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-79035 (A reflected cross-site scripting (XSS) vulnerability in the 
p.rfihub.c ...)
-       TODO: check
+       NOT-FOR-US: p.rfihub.com component of Zeta Marketing Platform (ZMP)
 CVE-2026-78547 (Out-of-bounds write vulnerability in Citrix Citrix Workspace 
app for W ...)
        NOT-FOR-US: Citrix
 CVE-2026-78546 (Out-of-bounds read vulnerability in Citirx Workspace app for 
Windows.  ...)
@@ -157,51 +157,51 @@ CVE-2026-68526 (Concrete CMS before 9.5.3 did not 
validate an anti-CSRF token in
 CVE-2026-54258 (ZoneMinder is a free, open source closed-circuit television 
software a ...)
        TODO: check
 CVE-2026-54248 (Doco-CD is a GitOps continuous delivery tool that 
automatically deploy ...)
-       TODO: check
+       NOT-FOR-US: Doco-CD
 CVE-2026-54174 (melange allows users to build apk packages using declarative 
pipelines ...)
-       TODO: check
+       NOT-FOR-US: Melange
 CVE-2026-54166 (Shelf is a platform for tracking physical assets. Prior to 
version 1.2 ...)
-       TODO: check
+       NOT-FOR-US: Shelf
 CVE-2026-54165 (Dobase is an open-source, self-hosted workspace with 
installable tools ...)
-       TODO: check
+       NOT-FOR-US: Dobase
 CVE-2026-54135 (AirSane is a SANE frontend, and a scanner server that supports 
Apple's ...)
        TODO: check
 CVE-2026-53952 (GetSimple CMS is a content management system (CMS), and 
GetSimple CMS  ...)
-       TODO: check
+       NOT-FOR-US: GetSimple CMS
 CVE-2026-52630 (SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before 
allows a ...)
-       TODO: check
+       NOT-FOR-US: Woltlab WCF
 CVE-2026-50025 (Mousehole is a background service to update a seedbox IP for 
MAM and w ...)
-       TODO: check
+       NOT-FOR-US: Mousehole
 CVE-2026-50018 (Hoverfly is an open source API simulation tool. Prior to 
version 1.12. ...)
-       TODO: check
+       NOT-FOR-US: Hoverfly
 CVE-2026-50013 (Hoverfly is an open source API simulation tool. Prior to 
version 1.12. ...)
-       TODO: check
+       NOT-FOR-US: Hoverfly
 CVE-2026-49992 (Kimai is an open-source time tracking application. Versions 
prior to 2 ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-49865 (Kimai is an open-source time tracking application. Versions 
prior to 2 ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-49846 (libks provides foundational support for signalwire C products. 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: libks
 CVE-2026-49464 (NL Portal Backend Libraries provide backend components for 
Dutch gover ...)
-       TODO: check
+       NOT-FOR-US: NL Portal Backend Libraries
 CVE-2026-49463 (NL Portal Backend Libraries provide backend components for 
Dutch gover ...)
-       TODO: check
+       NOT-FOR-US: NL Portal Backend Libraries
 CVE-2026-49462 (NL Portal Backend Libraries provide backend components for 
Dutch gover ...)
-       TODO: check
+       NOT-FOR-US: NL Portal Backend Libraries
 CVE-2026-49439 (OpenRemote is an open-source internet-of-things platform. 
Prior to ver ...)
-       TODO: check
+       NOT-FOR-US: OpenRemote
 CVE-2026-48496 (OpenTelemetry eBPF Profiler is a production-scale agent for 
profiling  ...)
-       TODO: check
+       NOT-FOR-US: OpenTelemetry eBPF Profiler
 CVE-2026-48490 (ArduinoCore-avr contains the source code and configuration 
files of th ...)
-       TODO: check
+       NOT-FOR-US: ArduinoCore-avr
 CVE-2026-47773 (ArduinoBLE enables Bluetooth Low Energy connectivity on 
certain Arduin ...)
-       TODO: check
+       NOT-FOR-US: ArduinoBLE
 CVE-2026-45057 (matrix-sdk-ui provides GUI-centric utilities on top of 
matrix-rust-sdk ...)
-       TODO: check
+       NOT-FOR-US: matrix-sdk-ui
 CVE-2026-45056 (matrix-sdk-crypto is a no-network-IO implementation of a state 
machine ...)
-       TODO: check
+       NOT-FOR-US: matrix-sdk-crypto Rust crate
 CVE-2026-44715 (OpenMRS is an open source electronic medical record system 
platform. P ...)
-       TODO: check
+       NOT-FOR-US: OpenMRS
 CVE-2026-89673 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux <not-affected> (Vulnerable code not present)
        NOTE: https://git.kernel.org/linus/
@@ -1960,7 +1960,7 @@ CVE-2026-80462 (A vulnerability in the Chef Automate API 
gateway and identity va
 CVE-2026-7863 (Improper neutralization of special elements used in an OS 
command ('OS ...)
        NOT-FOR-US: Pardus Software
 CVE-2026-7298 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: IdeaSoft Software Industry and Trade Inc. Smart E-Commerce
 CVE-2026-79396 (Use of hardcoded default credentials in Xiongmai IP Camera 
XM530 firmw ...)
        NOT-FOR-US: Xiongmai IP Camera XM530 firmware
 CVE-2026-79395 (An improper authentication vulnerability in the WS-Security 
(wsse:User ...)
@@ -1995,13 +1995,13 @@ CVE-2026-72708 (SPIP before 4.4.18 contains an 
unauthenticated blind SQL injecti
        NOTE: https://blog.lexfo.fr/casse-spip-sqli-to-rce.html
        NOTE: 
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html
 CVE-2026-71646 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested 
affected  ...)
-       TODO: check
+       NOT-FOR-US: Robotics-STAR-Lab
 CVE-2026-71644 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested 
affected  ...)
-       TODO: check
+       NOT-FOR-US: Robotics-STAR-Lab
 CVE-2026-71641 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to 
commit 5c99 ...)
-       TODO: check
+       NOT-FOR-US: ZJU-FAST-Lab EGO-Planner-v2
 CVE-2026-71416 (Headroom compresses data before the data reaches a large 
language mode ...)
-       TODO: check
+       NOT-FOR-US: Headroom
 CVE-2026-70341 (Use after free in Microsoft Edge (Chromium-based) allows an 
authorized ...)
        NOT-FOR-US: Microsoft
 CVE-2026-6642 (The Media Library Assistant plugin for WordPress is vulnerable 
to Stor ...)
@@ -2061,25 +2061,25 @@ CVE-2026-62089 (Missing Authorization vulnerability in 
Pixar Labs Master Addons
 CVE-2026-62088 (Insertion of Sensitive Information Into Sent Data 
vulnerability in 10u ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57843 (NetBSD contains an information disclosure vulnerability in 
mm_open() w ...)
-       TODO: check
+       NOT-FOR-US: NetBSD
 CVE-2026-57842 (NetBSD contains a use-after-free and double-free vulnerability 
in msg_ ...)
-       TODO: check
+       NOT-FOR-US: NetBSD
 CVE-2026-54072 (Authorizer is an open-source, self-hostable authentication and 
authori ...)
-       TODO: check
+       NOT-FOR-US: Authorizer
 CVE-2026-54047 (Laci Synchroni is a decentralized mod and appearance sync 
server and p ...)
-       TODO: check
+       NOT-FOR-US: Laci Synchroni
 CVE-2026-47839 (A vulnerability allows users authenticating through a 
federated OIDC p ...)
-       TODO: check
+       NOT-FOR-US: Cloud Foundry Foundation UAA
 CVE-2026-3869 (CWE-303 : Incorrect Implementation of Authentication Algorithm 
vulnera ...)
        NOT-FOR-US: Schneider Electric
 CVE-2026-38058 (The endpoint on the iDirect iQ200 VSAT terminal returns the 
complete d ...)
-       TODO: check
+       NOT-FOR-US: iDirect
 CVE-2026-38056 (A local privilege escalation vulnerability exists in the 
iDirect iQ200 ...)
-       TODO: check
+       NOT-FOR-US: iDirect
 CVE-2026-27378 (Unauthenticated Broken Access Control in Deposits and Partial 
Payments ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-19486 (A Server-Side Request Forgery (SSRF) vulnerability in Google 
Cloud Gem ...)
-       TODO: check
+       NOT-FOR-US: Google Cloud Gemini Enterprise Agent Platform App Builder
 CVE-2026-18495 (A flaw was found in libtiff. A heap-buffer overflow 
vulnerability exis ...)
        TODO: check
 CVE-2026-18122 (Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint 
exposes res ...)
@@ -2093,11 +2093,11 @@ CVE-2026-15710 (An information leakage vulnerability 
exists in the Endpoint DLP
 CVE-2026-15439 (The GamiPress plugin for WordPress is vulnerable to 
authenticated (Sub ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11765 (Improper neutralization of argument delimiters in a command 
('argument ...)
-       TODO: check
+       NOT-FOR-US: TUBITAK BILGEM Software Technologies Research Institute 
Pardus Pen
 CVE-2025-69904 (Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, 
which al ...)
-       TODO: check
+       NOT-FOR-US: Linkstack
 CVE-2025-15679 (Under certain circumstances such as reset to factory default 
operation ...)
-       TODO: check
+       NOT-FOR-US: BullSequana
 CVE-2024-12145 (The BuddyPress plugin for WordPress is vulnerable to Insecure 
Direct O ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-9768
@@ -2341,7 +2341,7 @@ CVE-2026-19985 (The Relevanssi \u2013 A Better Search 
plugin for WordPress is vu
 CVE-2026-19646 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, 
ART 9.0, ...)
        NOT-FOR-US: IBM
 CVE-2026-19596 (An XML External Entity (XXE) vulnerability exists in the XML 
collector ...)
-       TODO: check
+       NOT-FOR-US: OpenNMS
 CVE-2026-19136 (A potential command injection vulnerability was reported in 
the Tianxi ...)
        NOT-FOR-US: Lenovo
 CVE-2026-18994 (A potential improper authorization vulnerability was reported 
in the L ...)
@@ -2387,7 +2387,7 @@ CVE-2026-11496 (The Woo PDF Invoice Builder plugin (also 
distributed as "PDF Bui
 CVE-2026-11446 (The Booktics \u2013 Booking Calendar for Appointments and 
Service Busi ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-57231 (Path Traversal in avatar attachments in Docmost v0.21.0 allows 
an unau ...)
-       TODO: check
+       NOT-FOR-US: Docmost
 CVE-2025-15695 (The Translate WordPress with GTranslate WordPress plugin 
before 3.0.10 ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-88914 (A flaw was found in GStreamer's gst-plugins-good isomp4 
plugin. When p ...)
@@ -2878,7 +2878,7 @@ CVE-2026-80352 (Improper Control of Generation of Code 
('Code Injection') vulner
 CVE-2026-80351 (Improper neutralization of directives in dynamically evaluated 
code (' ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-7188 (Improper neutralization of special elements used in an SQL 
command ('S ...)
-       TODO: check
+       NOT-FOR-US: Armiya Information Technologies Access Control System
 CVE-2026-79987 (A remote, authenticated, non-admin Craft CMS Control Panel 
user with o ...)
        NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-78536 (Unauthenticated Broken Access Control in Robokassa payment 
gateway for ...)
@@ -2908,13 +2908,13 @@ CVE-2026-73694 (FileRun before 2026.3.0 contains an OS 
command injection vulnera
 CVE-2026-73693 (FileRun before 2026.3.0 contains an OS command injection 
vulnerability ...)
        NOT-FOR-US: FileRun
 CVE-2026-6285 (Weak Password Recovery Mechanism for Forgotten Password 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
 CVE-2026-68527 (Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an 
authori ...)
        NOT-FOR-US: Concrete CMS
 CVE-2026-68488 (A Time-of-check Time-of-use (TOCTOU) race condition leading to 
insecur ...)
-       TODO: check
+       NOT-FOR-US: Plesk
 CVE-2026-68487 (Path traversal in Plesk's Backup Manager causes arbitrary file 
write a ...)
-       TODO: check
+       NOT-FOR-US: Plesk
 CVE-2026-68006 (An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker 
to exec ...)
        TODO: check
 CVE-2026-66674 (Unauthenticated Bypass Vulnerability in Simple Cloudflare 
Turnstile <= ...)
@@ -2922,21 +2922,21 @@ CVE-2026-66674 (Unauthenticated Bypass Vulnerability in 
Simple Cloudflare Turnst
 CVE-2026-66632 (Unauthenticated Content Injection in Simple Cloudflare 
Turnstile <= 1. ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65639 (OS command injection in the advanced-rule parser of 
ConfigServer Secur ...)
-       TODO: check
+       NOT-FOR-US: Cpanel ConfigServer Security & Firewall
 CVE-2026-65638 (Improper escaping of a request URL in  ConfigServer Security & 
Firewal ...)
-       TODO: check
+       NOT-FOR-US: Cpanel ConfigServer Security & Firewall
 CVE-2026-64838 (ICEcoder versions through 8.1 fail to properly validate the 
oldFileNam ...)
-       TODO: check
+       NOT-FOR-US: ICEcoder
 CVE-2026-64837 (ICEcoder through 8.1 passes an unescaped filesystem path into 
a shell  ...)
-       TODO: check
+       NOT-FOR-US: ICEcoder
 CVE-2026-64836 (ICEcoder versions through 8.1 contain a path traversal 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: ICEcoder
 CVE-2026-5399 (The Redux Framework plugin for WordPress is vulnerable to 
Stored Cross ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-52098 (An issue in Flowise 3.1.2 allows a remote attacker to execute 
arbitrar ...)
        NOT-FOR-US: Flowise
 CVE-2026-52097 (An issue in AppFlowy 0.11.8 allows a remote attacker to 
execute arbitr ...)
-       TODO: check
+       NOT-FOR-US: AppFlowy
 CVE-2026-4130 (There is a storage of sensitive information in cleartext 
vulnerability ...)
        NOT-FOR-US: National Instruments
 CVE-2026-4129 (There is an improper access control vulnerability in NI 
SystemLink tha ...)
@@ -2952,9 +2952,9 @@ CVE-2026-42805 (A stack-based buffer overflow 
vulnerability exists in the Bosch
 CVE-2026-42804 (A stack-based buffer overflow vulnerability exists in the 
Bosch Sensor ...)
        NOT-FOR-US: Bosch
 CVE-2026-38626 (Garlic-Hub v1.0.1 is vulnerable to SQL Injection in 
src/Modules/Items/ ...)
-       TODO: check
+       NOT-FOR-US: Garlic-Hub
 CVE-2026-17038 (DrEryk Gabinet before 11.5.0uses hard-coded API credentials in 
its tic ...)
-       TODO: check
+       NOT-FOR-US: DrEryk Gabinet
 CVE-2026-15889 (The Aruba HiSpeed Cache plugin for WordPress is vulnerable to 
Stored C ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15461 (The Sierra Wireless HL78xx modem GNSS driver 
(drivers/modem/hl78xx/, l ...)
@@ -2966,11 +2966,11 @@ CVE-2026-15418 (In the silabser.sys driver for CP210x 
devices v11.5.0 and earlie
 CVE-2026-15417 (In the silabser.sys Windows 8 driver for CP210x devices, a 
local unpri ...)
        NOT-FOR-US: Silicon Labs
 CVE-2026-13745 (A vulnerability in the Gemini CLI and associated GitHub Action 
allowed ...)
-       TODO: check
+       NOT-FOR-US: Gemini CLI
 CVE-2026-12683 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
 CVE-2026-12682 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
 CVE-2026-88069 (Pandora contains a path traversal vulnerability in its archive 
extract ...)
        NOT-FOR-US: Pandora
 CVE-2026-88002 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
@@ -3097,7 +3097,7 @@ CVE-2026-71805 (An arbitrary file upload and path 
traversal vulnerability exists
 CVE-2026-71803 (money-pos 1.0 contains a stored Cross-Site Scripting (XSS) 
vulnerabili ...)
        NOT-FOR-US: money-pos
 CVE-2026-71802 (A stored Cross-Site Scripting (XSS) vulnerability exists in 
the announ ...)
-       TODO: check
+       NOT-FOR-US: REBUILD
 CVE-2026-71801 (An issue was discovered in s-pms SPMS-Server through v1.0. The 
applica ...)
        NOT-FOR-US: s-pms SPMS-Server
 CVE-2026-71616 (An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 
allows an at ...)
@@ -536233,7 +536233,7 @@ CVE-2022-26964 (Weak password derivation for export 
in Devolutions Remote Deskto
 CVE-2022-26963
        RESERVED
 CVE-2022-26962 (Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under 
NP_BCCAS- ...)
-       TODO: check
+       NOT-FOR-US: Italtel
 CVE-2022-26961 (Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS 
under NP_ ...)
        NOT-FOR-US: Italtel NetMatch-S
 CVE-2022-26960 (connector.minimal.php in std42 elFinder through 2.1.60 is 
affected by  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb41839e5534d47abf5972836084e125d93b505f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb41839e5534d47abf5972836084e125d93b505f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to