Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ccbb96af by Salvatore Bonaccorso at 2026-09-18T15:00:06+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -107,7 +107,7 @@ CVE-2026-93307 (A vulnerability has been found in O-RAN-SC 
SMO OAM 2025-06-10. A
 CVE-2026-92991 (The Biggop Library is vulnerable to Cross-Site Scripting via 
the \u201 ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-92757 (Applications built on MongoDB Entity Framework Core Provider 
which pla ...)
-       TODO: check
+       NOT-FOR-US: MongoDB Entity Framework
 CVE-2026-92714 (The Download Manager plugin for WordPress is vulnerable to 
Insecure Di ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-92619 (The Booking Calendar plugin for WordPress is vulnerable to 
Privilege E ...)
@@ -603,11 +603,11 @@ CVE-2026-92912 (AVideo through 
c3edcc274c389816d434acadac07ee78eaf330c1 uses cry
 CVE-2026-92904 (A flaw was found in the foreman_remote_execution plugin's 
template inv ...)
        TODO: check
 CVE-2026-92903 (Improper input validation in Snowflake CLI versions prior to 
3.27.0 al ...)
-       TODO: check
+       NOT-FOR-US: nowflake CLI
 CVE-2026-92894 (A flaw was found in the foreman_ansible plugin's Ansible 
override valu ...)
-       TODO: check
+       NOT-FOR-US: rubygem-foreman_remote_execution
 CVE-2026-92893 (A flaw was found in the foreman_ansible plugin's Ansible 
inventory API ...)
-       TODO: check
+       NOT-FOR-US: rubygem-foreman_ansible
 CVE-2026-92881 (A security vulnerability has been detected in vgmstream. The 
affected  ...)
        NOT-FOR-US: vgmstream
 CVE-2026-92880 (A weakness has been identified in vgmstream up to r2117. 
Impacted is t ...)
@@ -617,15 +617,15 @@ CVE-2026-92879 (A security flaw has been discovered in 
vgmstream up to r2117. Th
 CVE-2026-92860 (A security flaw has been discovered in rcourtman Pulse up to 
6.0.4/6.1 ...)
        NOT-FOR-US: rcourtman Pulse
 CVE-2026-92758 (If logging mode is set to DEBUG or a malformed MongoDB 
connection stri ...)
-       TODO: check
+       NOT-FOR-US: MongoDB Entity Framework
 CVE-2026-92756 (Applications built on MongoDB Entity Framework Core Provider 
which com ...)
-       TODO: check
+       NOT-FOR-US: MongoDB Entity Framework
 CVE-2026-92611 (In Eclipse Ankaios versions 0.6.0 to before 1.0.4, 
`LogRule::matches`  ...)
        TODO: check
 CVE-2026-92230 (Apache Karaf's XmlUtils cached XML parser/transformer 
factories in sta ...)
        TODO: check
 CVE-2026-91039 (Authentication Bypass by Spoofing vulnerability in 
team-alembic ash_au ...)
-       TODO: check
+       NOT-FOR-US: team-alembic ash_authentication
 CVE-2026-90997 (A flaw was found in Keycloak. When deployed in stateless mode 
with MyS ...)
        TODO: check
 CVE-2026-90986 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic 
Real Tim ...)
@@ -633,17 +633,17 @@ CVE-2026-90986 (Unauthenticated Cross Site Scripting 
(XSS) in Visitor Traffic Re
 CVE-2026-90887 (Unauthenticated Cross Site Scripting (XSS) in WP Inventory 
Manager <=  ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-90823 (FatPipe MPVPN, WARP, and IPVPN appliances running the 
end-of-life firm ...)
-       TODO: check
+       NOT-FOR-US: FatPipe MPVPN, WARP, and IPVPN appliances
 CVE-2026-90822 (FatPipe MPVPN, WARP, and IPVPN appliances running the 
end-of-life firm ...)
-       TODO: check
+       NOT-FOR-US: FatPipe MPVPN, WARP, and IPVPN appliances
 CVE-2026-89418 (google-protobuf contains an unbounded recursion when parsing 
unknown p ...)
        TODO: check
 CVE-2026-89038 (Verizon Cloud for Android (com.vcast.mediamanager) before 
26.7.10 cont ...)
-       TODO: check
+       NOT-FOR-US: Verizon Cloud for Android (com.vcast.mediamanager)
 CVE-2026-89036 (Appwrite before 2.0.0 contains an argument injection 
vulnerability tha ...)
-       TODO: check
+       NOT-FOR-US: Appwrite
 CVE-2026-88952 (Improper Authentication vulnerability in team-alembic 
AshAuthenticatio ...)
-       TODO: check
+       NOT-FOR-US: team-alembic ash_authentication
 CVE-2026-87831 (The Checkout Field Manager (Checkout Manager) for WooCommerce 
WordPres ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-87829 (The Checkout Field Manager (Checkout Manager) for WooCommerce 
WordPres ...)
@@ -3346,7 +3346,7 @@ CVE-2026-89082 (HP has identified potential security 
vulnerabilities in the HP A
 CVE-2026-89064 (The All-in-One WP Migration and Backup plugin for WordPress is 
vulnera ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-89034 (TCH QRing smart ring model R20_B006 running firmware 
RT09R20_1.00.00_2 ...)
-       TODO: check
+       NOT-FOR-US: TCH QRing smart ring model R20_B006
 CVE-2026-88904 (The PuppyFW WordPress plugin through 0.4.4 does not have 
proper author ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-88795 (The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 
does no ...)
@@ -3679,7 +3679,7 @@ CVE-2026-92718 (Nuclei versions before 3.11.1 cache 
template signature verificat
 CVE-2026-92717 (Covenant through 0.6 registers the CovenantHub SignalR hub 
without an  ...)
        NOT-FOR-US: Covenant
 CVE-2026-92716 (Shuffle through 2.2.1 contains a cross-tenant privilege 
escalation vul ...)
-       TODO: check
+       NOT-FOR-US: Shuffle
 CVE-2026-92627 (A heap-use-after-free vulnerability exists in H5T__conv_f_f() 
in src/H ...)
        TODO: check
 CVE-2026-92626 (Control iD iDSecure versions prior to4.8.3.0 are affected by 
an unauth ...)
@@ -3689,7 +3689,7 @@ CVE-2026-92625 (Control iD iDSecure versions prior 
to4.8.3.0 are affected by an
 CVE-2026-92616 (FileRise before version 3.28.0 contains a privilege escalation 
vulnera ...)
        NOT-FOR-US: FileRise
 CVE-2026-92615 (A flaw was found in flightctl. The configureRepoHTTPSClient() 
function ...)
-       TODO: check
+       NOT-FOR-US: flightctl
 CVE-2026-92605 (IRIS through 2.4.29 fails to properly validate case 
authorization in c ...)
        NOT-FOR-US: IRIS
 CVE-2026-92604 (Scirius through 3.8.0 contains an arbitrary file write 
vulnerability i ...)
@@ -3699,9 +3699,9 @@ CVE-2026-92603 (ContiNew Admin through 4.1.0 contains an 
authorization bypass vu
 CVE-2026-92602 (TDuck survey form through version 5.3 fails to validate 
webhook URLs o ...)
        NOT-FOR-US: TDuck survey
 CVE-2026-92601 (Guns through 8.3.5 contains an improper access control 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Guns
 CVE-2026-92600 (Guns through 8.3.5 contains an information disclosure 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: Guns
 CVE-2026-92571
        REJECTED
 CVE-2026-92570 (reNgine through 2.2.0 contains an authorization bypass 
vulnerability i ...)
@@ -3805,23 +3805,23 @@ CVE-2026-92355 (In affected versions of Octopus Server, 
a user with permission t
 CVE-2026-92299 (@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() 
via cont ...)
        TODO: check
 CVE-2026-92298 (EspoCRM through 10.0.8 uses PHP's rand() function to generate 
tokens f ...)
-       TODO: check
+       NOT-FOR-US: EspoCRM
 CVE-2026-92259 (Integer overflow or wraparound vulnerability in Samsung 
Opensource Esc ...)
        NOT-FOR-US: Samsung
 CVE-2026-92257 (Netcore NR255-V version 1.5.130703 contains a stored 
cross-site script ...)
-       TODO: check
+       NOT-FOR-US: Netcore NR255-V
 CVE-2026-92256 (NR255-V version 1.5.130703 contains a sensitive information 
disclosure ...)
-       TODO: check
+       NOT-FOR-US: NR255-V
 CVE-2026-92255 (Netcore NR255-V version 1.5.130703 contains an out-of-bounds 
read vuln ...)
-       TODO: check
+       NOT-FOR-US: Netcore NR255-V
 CVE-2026-92247 (A security vulnerability has been detected in synaptikcms 
synaptik-cms ...)
-       TODO: check
+       NOT-FOR-US: synaptikcms synaptik-cms
 CVE-2026-92237 (Insertion of sensitive information into log file in the slow 
query log ...)
        NOT-FOR-US: Devolutions
 CVE-2026-92234 (QloApps through 1.7.0 reflects unescaped child feature names 
into back ...)
-       TODO: check
+       NOT-FOR-US: QloApps
 CVE-2026-92221 (A vulnerability was determined in gedelumbung 
HospitalManagement up to ...)
-       TODO: check
+       NOT-FOR-US: gedelumbung HospitalManagement
 CVE-2026-92220 (A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. 
Affected ...)
        - vllm <itp> (bug #1095237)
 CVE-2026-92217 (A vulnerability was determined in a2ui-project a2ui up to 
0.10.6. This ...)
@@ -3922,7 +3922,7 @@ CVE-2026-91097 (HP has identified and remediated multiple 
externally reported vu
        - hplip <unfixed>
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-90999 (Sentry Seer is vulnerable to a multi-stage trust-boundary 
violation th ...)
-       TODO: check
+       NOT-FOR-US: Sentry Seer
 CVE-2026-90971 (Server-Side Request Forgery (SSRF) in the VMware 
synchronization featu ...)
        NOT-FOR-US: Devolutions
 CVE-2026-90969 (Improper access control in the vault entry listing feature 
inDevolutio ...)
@@ -3942,7 +3942,7 @@ CVE-2026-89186 (Use of Cache Containing Sensitive 
Information in ZenHive mpp all
 CVE-2026-89063 (The Online Scheduling and Appointment Booking System \u2013 
Bookly plu ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-89040 (Tencent Mass Service Engine in Cluster (MSEC) allows a remote, 
unauthe ...)
-       TODO: check
+       NOT-FOR-US: Tencent Mass Service Engine in Cluster (MSEC)
 CVE-2026-89031 (Adenion Blog2Social plugin for WordPress before 9.1.0 allows 
low-privi ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-89030 (Adenion Blog2Social plugin for WordPress before 9.1.0 exposes 
the emai ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ccbb96afaeb5390231b1c31bd8ba025ae3446696

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ccbb96afaeb5390231b1c31bd8ba025ae3446696
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to