[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 1 09:03:48 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cb3f2e5f by Salvatore Bonaccorso at 2026-08-01T10:03:23+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,67 +3,67 @@ CVE-2026-9044 (An OS command injection vulnerability exists in the VPN module of
CVE-2026-7623 (The SureForms \u2013 Contact Form, Payment Form & Other Custom Form Bu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-68771 (ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: ComfyUI
CVE-2026-68770 (sentence-transformers contains a security control bypass vulnerability ...)
- TODO: check
+ NOT-FOR-US: sentence-transformers
CVE-2026-65981 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
TODO: check
CVE-2026-65841 (Jodit Editor is a WYSIWYG editor with a built-in file browser & image ...)
- TODO: check
+ NOT-FOR-US: Jodit Editor
CVE-2026-62999 (Copier is a library and CLI app for rendering project templates. From ...)
- TODO: check
+ NOT-FOR-US: Copier library and CLI app
CVE-2026-62959 (Coturn is a free open source implementation of TURN and STUN Server. F ...)
TODO: check
CVE-2026-62324 (Jodit Editor is a WYSIWYG editor with a built-in file browser & image ...)
- TODO: check
+ NOT-FOR-US: Jodit Editor
CVE-2026-55825 (Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an auth ...)
- TODO: check
+ NOT-FOR-US: Contao CMS
CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAdd ...)
TODO: check
CVE-2026-54787 (sigstore-go is a Go library for Sigstore signing and verification. Pri ...)
TODO: check
CVE-2026-54785 (gemini-bridge is a lightweight MCP server bridging AI agents to Google ...)
- TODO: check
+ NOT-FOR-US: gemini-bridge
CVE-2026-54768 (WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until ...)
- TODO: check
+ NOT-FOR-US: WPGraphQL
CVE-2026-53599 (REDAXO is a PHP-based content management system. From 5.18.2 until 5.2 ...)
- TODO: check
+ NOT-FOR-US: REDAXO CMS
CVE-2026-53573 (GeoNetwork is a catalog application to manage spatially referenced res ...)
- TODO: check
+ NOT-FOR-US: GeoNetwork
CVE-2026-53551 (free5GC is an open-source implementation of the 5G core network. Prior ...)
- TODO: check
+ NOT-FOR-US: free5GC
CVE-2026-53510 (Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .al ...)
- TODO: check
+ NOT-FOR-US: Savon Ruby SOAP client
CVE-2026-52371 (A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trig ...)
- TODO: check
+ NOT-FOR-US: xxl-job
CVE-2026-52232 (A reflected cross-site scripting (XSS) vulnerability in the /logo.asp ...)
- TODO: check
+ NOT-FOR-US: FS Inc S3150-8T2F Switch 2.2.0D
CVE-2026-52134 (An issue in the parseGoosePayload() function (/goose/goose_receiver.c) ...)
- TODO: check
+ NOT-FOR-US: MZ Automation libiec61850
CVE-2026-51953 (An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges ...)
- TODO: check
+ NOT-FOR-US: FeehiCMS
CVE-2026-51785 (An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote at ...)
- TODO: check
+ NOT-FOR-US: Hugo Leisink Hiawatha
CVE-2026-50986 (PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cr ...)
- TODO: check
+ NOT-FOR-US: PrestaShop module
CVE-2026-45377 (Decidim is a participatory democracy framework. Prior to 0.30.9, from ...)
- TODO: check
+ NOT-FOR-US: Decidim
CVE-2026-45376 (Decidim is a participatory democracy framework. Prior to 0.30.9, from ...)
- TODO: check
+ NOT-FOR-US: Decidim
CVE-2026-45330 (Decidim is a participatory democracy framework. Prior to 0.30.9, from ...)
- TODO: check
+ NOT-FOR-US: Decidim
CVE-2026-45086 (Decidim is a participatory democracy framework. From 0.31.1 before 0.3 ...)
- TODO: check
+ NOT-FOR-US: Decidim
CVE-2026-3141 (The FormGent plugin for WordPress is vulnerable to unauthorized arbitr ...)
NOT-FOR-US: WordPress plugin
CVE-2026-38713 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 ...)
- TODO: check
+ NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
CVE-2026-38711 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 ...)
- TODO: check
+ NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
CVE-2026-38710 (TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command ...)
- TODO: check
+ NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
CVE-2026-38708 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 ...)
- TODO: check
+ NOT-FOR-US: AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0
CVE-2026-34641 (Premiere Pro is affected by an out-of-bounds write vulnerability that ...)
NOT-FOR-US: Adobe
CVE-2026-18394 (Incorrect authorization in the http_request tool in Strands Agents Too ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb3f2e5f110d2795abc5be97a544ef82aa489e3c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb3f2e5f110d2795abc5be97a544ef82aa489e3c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/b3b07605/attachment.htm>
More information about the debian-security-tracker-commits
mailing list