Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e8781b77 by Salvatore Bonaccorso at 2026-09-16T08:45:02+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -280,31 +280,31 @@ CVE-2026-89308 (An unauthenticated OS command injection
vulnerability exists in
CVE-2026-89307 (The "Firma Circolare" feature in the "Design Scuole Italia"
WordPress ...)
NOT-FOR-US: WordPress theme
CVE-2026-89026 (The Issabel Framework, the web framework supporting Issabel
PBX softwa ...)
- TODO: check
+ NOT-FOR-US: Issabel Framework
CVE-2026-89025 (Hirschmann HiOS Switch Platform devices contain a
denial-of-service vu ...)
- TODO: check
+ NOT-FOR-US: Hirschmann HiOS Switch Platform devices
CVE-2026-89022 (BookStack before 26.05.5 contains an authentication bypass
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: BookStack
CVE-2026-88765 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-88621 (OneNav v1.2.4 contains an authenticated arbitrary file
deletion vulner ...)
- TODO: check
+ NOT-FOR-US: OneNav
CVE-2026-88620 (SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an
improper ...)
- TODO: check
+ NOT-FOR-US: SmartAdmin API Java17 SpringBoot3
CVE-2026-88619 (1024-lab SmartAdmin v3.30.0 contains a missing authorization
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: 1024-lab SmartAdmin
CVE-2026-88618 (1024-lab SmartAdmin v3.30.0 contains a stored cross-site
scripting vul ...)
- TODO: check
+ NOT-FOR-US: 1024-lab SmartAdmin
CVE-2026-88617 (SmartAdmin v3.30.0 contains an authorization flaw in the
configuration ...)
- TODO: check
+ NOT-FOR-US: 1024-lab SmartAdmin
CVE-2026-88616 (An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to
execute a ...)
- TODO: check
+ NOT-FOR-US: RuoYi-Vue-Plus
CVE-2026-87793 (The "Design Scuole Italia" WordPress theme is affected by a
Reflected ...)
- TODO: check
+ NOT-FOR-US: WordPress theme
CVE-2026-87792 (The "Design Scuole Italia" WordPress theme is affected by
multiple Aut ...)
- TODO: check
+ NOT-FOR-US: WordPress theme
CVE-2026-87791 (A path traversal vulnerability exists in the
reserved_file_check funct ...)
- TODO: check
+ NOT-FOR-US: WordPress theme
CVE-2026-87730
REJECTED
CVE-2026-86818 (fast-uri is a dependency-free RFC 3986 URI parser for Node.js,
used by ...)
@@ -1508,7 +1508,7 @@ CVE-2026-86870 (A heap buffer overflow was addressed with
improved bounds checki
CVE-2026-86869 (An out-of-bounds write issue was addressed with improved
bounds checki ...)
NOT-FOR-US: Apple
CVE-2026-86701 (Android application "ManabiPocket for Parents" contains an
improper ac ...)
- TODO: check
+ NOT-FOR-US: Android application "ManabiPocket for Parents"
CVE-2026-85657 (The Co-Authors, Multiple Authors and Guest Authors in an
Author Box wi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85575 (The ShopEngine Elementor WooCommerce Builder Addon \u2013 All
in One W ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8781b77065e3f18184fe6d9e637433b30075f5d
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8781b77065e3f18184fe6d9e637433b30075f5d
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits