Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
72361a09 by Salvatore Bonaccorso at 2026-09-22T09:57:11+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11,37 +11,37 @@ CVE-2026-94623 (vLLM through 0.29.0 contains a denial of
service vulnerability i
CVE-2026-94622 (vLLM versions through 0.29.0 contain a denial of service
vulnerability ...)
- vllm <itp> (bug #1095237)
CVE-2026-94588 (In Proxmox pmg-api, an argument injection vulnerability exists
in the ...)
- TODO: check
+ NOT-FOR-US: Proxmox pmg-api
CVE-2026-94540 (DesktopSMS 1.11.0 by MrPear contains an unauthorized access
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: DesktopSMS
CVE-2026-94536 (lamp-cloud through 5.10.0 fails to validate the employeeId
parameter i ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94535 (lamp-cloud through 5.10.0 contains an authorization bypass
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94534 (lamp-cloud through 5.10.0 fails to validate user identity in
PUT /anyo ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94533 (lamp-cloud through 5.10.0 contains an authorization bypass
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94532 (lamp-cloud through 5.10.0 contains an authorization bypass
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94504 (Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value
and rend ...)
NOT-FOR-US: WordPress plugin
CVE-2026-94501 (jshERP through 3.6 contains an authorization bypass
vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94497 (jshERP through 3.6 fails to validate object ownership in by-id
info, u ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94496 (jshERP through 3.6 fails to validate caller permissions in
role manage ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94495 (jshERP through 3.6 fails to properly validate user privileges
in Syste ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94494 (jshERP through 3.6 contains a tenant isolation bypass
vulnerability th ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94493 (A vulnerability was detected in Gigatech PDV5701
1.0.31_240305_112640. ...)
- TODO: check
+ NOT-FOR-US: Gigatech
CVE-2026-94492 (A security vulnerability has been detected in Yonyou U8cloud
5.x. This ...)
- TODO: check
+ NOT-FOR-US: Yonyou U8cloud
CVE-2026-94491 (A weakness has been identified in Yonyou KSOA 9.0. This
affects an unk ...)
- TODO: check
+ NOT-FOR-US: Yonyou KSOA
CVE-2026-94490 (A security flaw has been discovered in OctoPrint 1.0.0.
Affected by th ...)
- octoprint <itp> (bug #718591)
CVE-2026-94489 (A vulnerability was identified in OctoPrint 1.0.0. Affected by
this vu ...)
@@ -49,23 +49,23 @@ CVE-2026-94489 (A vulnerability was identified in OctoPrint
1.0.0. Affected by t
CVE-2026-94488 (Telegram Desktop before 6.9.4 allows XSS in the HTML exporter.
(The fi ...)
TODO: check
CVE-2026-94426 (A vulnerability was determined in xuxueli xxl-job up to 3.5.0.
The imp ...)
- TODO: check
+ NOT-FOR-US: xuxueli xxl-job
CVE-2026-94425 (A vulnerability was found in Moore Threads MTT S80 Driver
Package 340. ...)
- TODO: check
+ NOT-FOR-US: Moore Threads MTT S80 Driver Package
CVE-2026-94424 (A vulnerability has been found in Moore Threads MTT S80 Driver
Package ...)
- TODO: check
+ NOT-FOR-US: Moore Threads MTT S80 Driver Package
CVE-2026-94414 (jshERP through 3.6 is missing an authorization check on the
POST /user ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94413 (jshERP through 3.6 fails to redact password hashes in the
/user/info e ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94412 (jshERP through 3.6 contains an authorization bypass
vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94411 (jshERP 3.6 contains a privilege escalation vulnerability in
the update ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94404 (MISP has a security issue that could let an attacker change
threat-int ...)
- misp <itp> (bug #1144317)
CVE-2026-94403 (A weakness has been identified in ColorFul iGameCenter
1.0.3.4. This i ...)
- TODO: check
+ NOT-FOR-US: ColorFul iGameCenter
CVE-2026-94401 (MISP has a file-handling vulnerability that could let certain
authenti ...)
- misp <itp> (bug #1144317)
CVE-2026-94394 (When a regular user adds a reference between objects or
attributes, MI ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72361a096b4e348fe47d72081d3a0bb7186df92a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72361a096b4e348fe47d72081d3a0bb7186df92a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits