[Git][security-tracker-team/security-tracker][master] Process some new NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Dec 22 21:46:46 GMT 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
81741661 by Salvatore Bonaccorso at 2025-12-22T22:46:04+01:00
Process some new NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -47,31 +47,31 @@ CVE-2025-68326 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/0e234632e39bd21dd28ffc9ba3ae8eec4deb949c (6.18)
CVE-2025-67826 (An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Pri ...)
- TODO: check
+ NOT-FOR-US: K7 Ultimate Security
CVE-2025-67443 (Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS) ...)
- TODO: check
+ NOT-FOR-US: Schlix CMS
CVE-2025-67418 (ClipBucket 5.5.2 is affected by an improper access control issue where ...)
- TODO: check
+ NOT-FOR-US: ClipBucket
CVE-2025-67291 (A stored cross-site scripting (XSS) vulnerability in the Media module ...)
- TODO: check
+ NOT-FOR-US: Piranha CMS
CVE-2025-67290 (A stored cross-site scripting (XSS) vulnerability in the Page Settings ...)
- TODO: check
+ NOT-FOR-US: Piranha CMS
CVE-2025-67289 (An arbitrary file upload vulnerability in the Attachments module of Fr ...)
- TODO: check
+ NOT-FOR-US: Frappe Framework
CVE-2025-67288 (An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows a ...)
NOT-FOR-US: Umbraco CMS
CVE-2025-65837 (PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in t ...)
- TODO: check
+ NOT-FOR-US: PublicCMS
CVE-2025-65790 (A reflected cross-site scripting (XSS) vulnerability exists in FuguHub ...)
- TODO: check
+ NOT-FOR-US: FuguHub
CVE-2025-65270 (Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC ...)
- TODO: check
+ NOT-FOR-US: ClinCapture EDC
CVE-2025-63664 (Incorrect access control in the /api/v1/conversations/*/messages API o ...)
- TODO: check
+ NOT-FOR-US: GT Edge AI Platform
CVE-2025-63663 (Incorrect access control in the /api/v1/conversations/*/files API of G ...)
- TODO: check
+ NOT-FOR-US: GT Edge AI Platform
CVE-2025-63662 (Insecure permissions in the /api/v1/agents API of GT Edge AI Platform ...)
- TODO: check
+ NOT-FOR-US: GT Edge AI Platform
CVE-2025-62880 (Cross-Site Request Forgery (CSRF) vulnerability in Kunal Nagar Custom ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2025-62107 (Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather L ...)
@@ -87,7 +87,7 @@ CVE-2025-61738 (Under certain circumstances, attacker can capture the network ke
CVE-2025-54890 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
NOT-FOR-US: Centreon
CVE-2025-26787 (An error in the SignServer container startup logic was found in Keyfac ...)
- TODO: check
+ NOT-FOR-US: Keyfactor SignServer
CVE-2025-26379 (Use of a weak pseudo-random number generator, which may allow an attac ...)
TODO: check
CVE-2025-15033 (A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in custo ...)
@@ -95,17 +95,17 @@ CVE-2025-15033 (A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in
CVE-2025-14273 (Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10. ...)
TODO: check
CVE-2025-14018 (Unquoted Search Path or Element vulnerability in NetBT Consulting Serv ...)
- TODO: check
+ NOT-FOR-US: E-Fatura
CVE-2025-12514 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: Centreon
CVE-2025-10021 (A Use of Uninitialized Variable vulnerability exists in Open DesignAll ...)
- TODO: check
+ NOT-FOR-US: Open Design
CVE-2024-35321 (MyNET up to v26.08 was discovered to contain a Reflected cross-site sc ...)
- TODO: check
+ NOT-FOR-US: MyNET
CVE-2024-25814 (MyNET up to v26.05 was discovered to contain a reflected cross-site sc ...)
- TODO: check
+ NOT-FOR-US: MyNET
CVE-2024-25812 (MyNET up to v26.05 was discovered to contain a reflected cross-site sc ...)
- TODO: check
+ NOT-FOR-US: MyNET
CVE-2025-8305 (An authenticated local user can obtain information that allows claimin ...)
NOT-FOR-US: Check Point
CVE-2025-8304 (An authenticated local user can obtain information that allows claimin ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8174166136df196433f637e0286d2e681583172e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8174166136df196433f637e0286d2e681583172e
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251222/740abe39/attachment.htm>
More information about the debian-security-tracker-commits
mailing list