Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2613fbaa by Salvatore Bonaccorso at 2026-09-14T22:27:03+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -135,35 +135,35 @@ CVE-2026-90792 (A flaw has been found in GPAC up to 
f1219cde. This issue affects
 CVE-2026-90791 (A vulnerability was detected in GPAC up to f1219cde. This 
vulnerabilit ...)
        - gpac <removed>
 CVE-2026-90790 (A security vulnerability has been detected in a2aproject 
a2a-python up ...)
-       TODO: check
+       NOT-FOR-US: a2aproject a2a-python
 CVE-2026-90789 (A weakness has been identified in itsourcecode Leave 
Management System ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-90788 (A security flaw has been discovered in magicblack MacCMS10 
2026.1000.4 ...)
-       TODO: check
+       NOT-FOR-US: magicblack MacCMS10
 CVE-2026-90787 (A vulnerability was identified in Soarkey StudentManagement up 
to e08f ...)
-       TODO: check
+       NOT-FOR-US: Soarkey StudentManagement
 CVE-2026-90786 (A vulnerability was determined in Dvidelabs flatcc up to 
0.6.3. This i ...)
-       TODO: check
+       NOT-FOR-US: Dvidelabs flatcc
 CVE-2026-90785 (A vulnerability was found in Dvidelabs flatcc up to 0.6.3. 
This affect ...)
-       TODO: check
+       NOT-FOR-US: Dvidelabs flatcc
 CVE-2026-90784 (A vulnerability has been found in Dvidelabs flatcc up to 
0.6.3. The im ...)
-       TODO: check
+       NOT-FOR-US: Dvidelabs flatcc
 CVE-2026-90716 (A vulnerability was detected in marcobambini Gravity up to 
0.9.7. This ...)
-       TODO: check
+       NOT-FOR-US: marcobambini Gravity
 CVE-2026-90715 (A security vulnerability has been detected in marcobambini 
Gravity up  ...)
-       TODO: check
+       NOT-FOR-US: marcobambini Gravity
 CVE-2026-90714 (A weakness has been identified in marcobambini Gravity up to 
0.9.7. Th ...)
-       TODO: check
+       NOT-FOR-US: marcobambini Gravity
 CVE-2026-90713 (A security flaw has been discovered in vllm-project vLLM up to 
0.29.0. ...)
        TODO: check
 CVE-2026-90712 (A vulnerability was identified in Gitlawb openclaude up to 
0.30.0. Imp ...)
-       TODO: check
+       NOT-FOR-US: Gitlawb openclaude
 CVE-2026-90710 (A vulnerability was determined in taisan tarzan-cms 1.0.0. 
This issue  ...)
-       TODO: check
+       NOT-FOR-US: taisan tarzan-cms
 CVE-2026-90709 (A security vulnerability has been detected in Yot CMS up to 
3.3.1. Aff ...)
-       TODO: check
+       NOT-FOR-US: Yot CMS
 CVE-2026-90708 (A weakness has been identified in Yot CMS up to 3.3.1. 
Affected by thi ...)
-       TODO: check
+       NOT-FOR-US: Yot CMS
 CVE-2026-90707 (A security flaw has been discovered in Open5GS up to 2.7.x. 
Affected i ...)
        TODO: check
 CVE-2026-90706 (A vulnerability was identified in D-Link DWR-M921 1.1.52. This 
impacts ...)
@@ -203,15 +203,15 @@ CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 
11.8.x <= 11.8.4, 11.7.x <=
 CVE-2026-89321 (Publishing limits the compressed size of a VSIX 
(ovsx.publishing.max-c ...)
        TODO: check
 CVE-2026-89180 (EFence developed by Thinking Software Technology has a SQL 
Injection v ...)
-       TODO: check
+       NOT-FOR-US: Thinking Software Technology
 CVE-2026-89023 (ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 
contain ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-89021 (MikroTik RouterOS before 7.24.2 contains a path traversal 
vulnerabilit ...)
        NOT-FOR-US: MikroTik
 CVE-2026-89020 (MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 
(stable) contai ...)
        NOT-FOR-US: MikroTik
 CVE-2026-88932 (multer is a Node.js middleware for handling 
multipart/form-data upload ...)
-       TODO: check
+       NOT-FOR-US: Node multer
 CVE-2026-88819 (In Siglet current and past versions the refresh token handler 
do not e ...)
        TODO: check
 CVE-2026-87802 (Improper verification of cryptographic signature vulnerability 
in Apac ...)
@@ -275,7 +275,7 @@ CVE-2026-82232 (Improper neutralization of special elements 
used in an SQL comma
 CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a 
path trave ...)
        TODO: check
 CVE-2026-82019 (TripleLift's ad rendering script (video-bundle.js) contains a 
DOM-base ...)
-       TODO: check
+       NOT-FOR-US: TripleLift
 CVE-2026-81566 (Joomla Extension - joomshaper.com - Missing Access Control in 
Menu Ite ...)
        NOT-FOR-US: Joomla
 CVE-2026-81565 (Joomla Extension - joomshaper.com - Missing Directory 
Confinement in M ...)
@@ -283,11 +283,11 @@ CVE-2026-81565 (Joomla Extension - joomshaper.com - 
Missing Directory Confinemen
 CVE-2026-81564 (Joomla Extension - joomshaper.com - Missing Directory 
Confinement in M ...)
        NOT-FOR-US: Joomla
 CVE-2026-81301 (Ekia File Manager 1.2.7 exposes 
com.ekia.filecontrolmanager.OpenFilePr ...)
-       TODO: check
+       NOT-FOR-US: Ekia File Manager
 CVE-2026-7848 (Alior Bank PrestaShop module "raty"for commercial partners is 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: PrestaShop module
 CVE-2026-7208 (Yealink SIP-T33G firmware versions 124.86.x.x prior to 
124.87.0.0 cont ...)
-       TODO: check
+       NOT-FOR-US: Yealink SIP-T33G firmware
 CVE-2026-79701 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA 
Bypass in  ...)
        NOT-FOR-US: Joomla
 CVE-2026-79700 (Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA 
Bypass via ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2613fbaa8d5cb5a5c6c46075564b0adcd808c490

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2613fbaa8d5cb5a5c6c46075564b0adcd808c490
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to