Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ccbb96af by Salvatore Bonaccorso at 2026-09-18T15:00:06+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -107,7 +107,7 @@ CVE-2026-93307 (A vulnerability has been found in O-RAN-SC
SMO OAM 2025-06-10. A
CVE-2026-92991 (The Biggop Library is vulnerable to Cross-Site Scripting via
the \u201 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92757 (Applications built on MongoDB Entity Framework Core Provider
which pla ...)
- TODO: check
+ NOT-FOR-US: MongoDB Entity Framework
CVE-2026-92714 (The Download Manager plugin for WordPress is vulnerable to
Insecure Di ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92619 (The Booking Calendar plugin for WordPress is vulnerable to
Privilege E ...)
@@ -603,11 +603,11 @@ CVE-2026-92912 (AVideo through
c3edcc274c389816d434acadac07ee78eaf330c1 uses cry
CVE-2026-92904 (A flaw was found in the foreman_remote_execution plugin's
template inv ...)
TODO: check
CVE-2026-92903 (Improper input validation in Snowflake CLI versions prior to
3.27.0 al ...)
- TODO: check
+ NOT-FOR-US: nowflake CLI
CVE-2026-92894 (A flaw was found in the foreman_ansible plugin's Ansible
override valu ...)
- TODO: check
+ NOT-FOR-US: rubygem-foreman_remote_execution
CVE-2026-92893 (A flaw was found in the foreman_ansible plugin's Ansible
inventory API ...)
- TODO: check
+ NOT-FOR-US: rubygem-foreman_ansible
CVE-2026-92881 (A security vulnerability has been detected in vgmstream. The
affected ...)
NOT-FOR-US: vgmstream
CVE-2026-92880 (A weakness has been identified in vgmstream up to r2117.
Impacted is t ...)
@@ -617,15 +617,15 @@ CVE-2026-92879 (A security flaw has been discovered in
vgmstream up to r2117. Th
CVE-2026-92860 (A security flaw has been discovered in rcourtman Pulse up to
6.0.4/6.1 ...)
NOT-FOR-US: rcourtman Pulse
CVE-2026-92758 (If logging mode is set to DEBUG or a malformed MongoDB
connection stri ...)
- TODO: check
+ NOT-FOR-US: MongoDB Entity Framework
CVE-2026-92756 (Applications built on MongoDB Entity Framework Core Provider
which com ...)
- TODO: check
+ NOT-FOR-US: MongoDB Entity Framework
CVE-2026-92611 (In Eclipse Ankaios versions 0.6.0 to before 1.0.4,
`LogRule::matches` ...)
TODO: check
CVE-2026-92230 (Apache Karaf's XmlUtils cached XML parser/transformer
factories in sta ...)
TODO: check
CVE-2026-91039 (Authentication Bypass by Spoofing vulnerability in
team-alembic ash_au ...)
- TODO: check
+ NOT-FOR-US: team-alembic ash_authentication
CVE-2026-90997 (A flaw was found in Keycloak. When deployed in stateless mode
with MyS ...)
TODO: check
CVE-2026-90986 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic
Real Tim ...)
@@ -633,17 +633,17 @@ CVE-2026-90986 (Unauthenticated Cross Site Scripting
(XSS) in Visitor Traffic Re
CVE-2026-90887 (Unauthenticated Cross Site Scripting (XSS) in WP Inventory
Manager <= ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-90823 (FatPipe MPVPN, WARP, and IPVPN appliances running the
end-of-life firm ...)
- TODO: check
+ NOT-FOR-US: FatPipe MPVPN, WARP, and IPVPN appliances
CVE-2026-90822 (FatPipe MPVPN, WARP, and IPVPN appliances running the
end-of-life firm ...)
- TODO: check
+ NOT-FOR-US: FatPipe MPVPN, WARP, and IPVPN appliances
CVE-2026-89418 (google-protobuf contains an unbounded recursion when parsing
unknown p ...)
TODO: check
CVE-2026-89038 (Verizon Cloud for Android (com.vcast.mediamanager) before
26.7.10 cont ...)
- TODO: check
+ NOT-FOR-US: Verizon Cloud for Android (com.vcast.mediamanager)
CVE-2026-89036 (Appwrite before 2.0.0 contains an argument injection
vulnerability tha ...)
- TODO: check
+ NOT-FOR-US: Appwrite
CVE-2026-88952 (Improper Authentication vulnerability in team-alembic
AshAuthenticatio ...)
- TODO: check
+ NOT-FOR-US: team-alembic ash_authentication
CVE-2026-87831 (The Checkout Field Manager (Checkout Manager) for WooCommerce
WordPres ...)
NOT-FOR-US: WordPress plugin
CVE-2026-87829 (The Checkout Field Manager (Checkout Manager) for WooCommerce
WordPres ...)
@@ -3346,7 +3346,7 @@ CVE-2026-89082 (HP has identified potential security
vulnerabilities in the HP A
CVE-2026-89064 (The All-in-One WP Migration and Backup plugin for WordPress is
vulnera ...)
NOT-FOR-US: WordPress plugin
CVE-2026-89034 (TCH QRing smart ring model R20_B006 running firmware
RT09R20_1.00.00_2 ...)
- TODO: check
+ NOT-FOR-US: TCH QRing smart ring model R20_B006
CVE-2026-88904 (The PuppyFW WordPress plugin through 0.4.4 does not have
proper author ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88795 (The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4
does no ...)
@@ -3679,7 +3679,7 @@ CVE-2026-92718 (Nuclei versions before 3.11.1 cache
template signature verificat
CVE-2026-92717 (Covenant through 0.6 registers the CovenantHub SignalR hub
without an ...)
NOT-FOR-US: Covenant
CVE-2026-92716 (Shuffle through 2.2.1 contains a cross-tenant privilege
escalation vul ...)
- TODO: check
+ NOT-FOR-US: Shuffle
CVE-2026-92627 (A heap-use-after-free vulnerability exists in H5T__conv_f_f()
in src/H ...)
TODO: check
CVE-2026-92626 (Control iD iDSecure versions prior to4.8.3.0 are affected by
an unauth ...)
@@ -3689,7 +3689,7 @@ CVE-2026-92625 (Control iD iDSecure versions prior
to4.8.3.0 are affected by an
CVE-2026-92616 (FileRise before version 3.28.0 contains a privilege escalation
vulnera ...)
NOT-FOR-US: FileRise
CVE-2026-92615 (A flaw was found in flightctl. The configureRepoHTTPSClient()
function ...)
- TODO: check
+ NOT-FOR-US: flightctl
CVE-2026-92605 (IRIS through 2.4.29 fails to properly validate case
authorization in c ...)
NOT-FOR-US: IRIS
CVE-2026-92604 (Scirius through 3.8.0 contains an arbitrary file write
vulnerability i ...)
@@ -3699,9 +3699,9 @@ CVE-2026-92603 (ContiNew Admin through 4.1.0 contains an
authorization bypass vu
CVE-2026-92602 (TDuck survey form through version 5.3 fails to validate
webhook URLs o ...)
NOT-FOR-US: TDuck survey
CVE-2026-92601 (Guns through 8.3.5 contains an improper access control
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Guns
CVE-2026-92600 (Guns through 8.3.5 contains an information disclosure
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Guns
CVE-2026-92571
REJECTED
CVE-2026-92570 (reNgine through 2.2.0 contains an authorization bypass
vulnerability i ...)
@@ -3805,23 +3805,23 @@ CVE-2026-92355 (In affected versions of Octopus Server,
a user with permission t
CVE-2026-92299 (@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources()
via cont ...)
TODO: check
CVE-2026-92298 (EspoCRM through 10.0.8 uses PHP's rand() function to generate
tokens f ...)
- TODO: check
+ NOT-FOR-US: EspoCRM
CVE-2026-92259 (Integer overflow or wraparound vulnerability in Samsung
Opensource Esc ...)
NOT-FOR-US: Samsung
CVE-2026-92257 (Netcore NR255-V version 1.5.130703 contains a stored
cross-site script ...)
- TODO: check
+ NOT-FOR-US: Netcore NR255-V
CVE-2026-92256 (NR255-V version 1.5.130703 contains a sensitive information
disclosure ...)
- TODO: check
+ NOT-FOR-US: NR255-V
CVE-2026-92255 (Netcore NR255-V version 1.5.130703 contains an out-of-bounds
read vuln ...)
- TODO: check
+ NOT-FOR-US: Netcore NR255-V
CVE-2026-92247 (A security vulnerability has been detected in synaptikcms
synaptik-cms ...)
- TODO: check
+ NOT-FOR-US: synaptikcms synaptik-cms
CVE-2026-92237 (Insertion of sensitive information into log file in the slow
query log ...)
NOT-FOR-US: Devolutions
CVE-2026-92234 (QloApps through 1.7.0 reflects unescaped child feature names
into back ...)
- TODO: check
+ NOT-FOR-US: QloApps
CVE-2026-92221 (A vulnerability was determined in gedelumbung
HospitalManagement up to ...)
- TODO: check
+ NOT-FOR-US: gedelumbung HospitalManagement
CVE-2026-92220 (A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0.
Affected ...)
- vllm <itp> (bug #1095237)
CVE-2026-92217 (A vulnerability was determined in a2ui-project a2ui up to
0.10.6. This ...)
@@ -3922,7 +3922,7 @@ CVE-2026-91097 (HP has identified and remediated multiple
externally reported vu
- hplip <unfixed>
NOTE:
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
CVE-2026-90999 (Sentry Seer is vulnerable to a multi-stage trust-boundary
violation th ...)
- TODO: check
+ NOT-FOR-US: Sentry Seer
CVE-2026-90971 (Server-Side Request Forgery (SSRF) in the VMware
synchronization featu ...)
NOT-FOR-US: Devolutions
CVE-2026-90969 (Improper access control in the vault entry listing feature
inDevolutio ...)
@@ -3942,7 +3942,7 @@ CVE-2026-89186 (Use of Cache Containing Sensitive
Information in ZenHive mpp all
CVE-2026-89063 (The Online Scheduling and Appointment Booking System \u2013
Bookly plu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-89040 (Tencent Mass Service Engine in Cluster (MSEC) allows a remote,
unauthe ...)
- TODO: check
+ NOT-FOR-US: Tencent Mass Service Engine in Cluster (MSEC)
CVE-2026-89031 (Adenion Blog2Social plugin for WordPress before 9.1.0 allows
low-privi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-89030 (Adenion Blog2Social plugin for WordPress before 9.1.0 exposes
the emai ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ccbb96afaeb5390231b1c31bd8ba025ae3446696
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ccbb96afaeb5390231b1c31bd8ba025ae3446696
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits