[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 4 20:33:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1f43d44e by Salvatore Bonaccorso at 2026-08-04T21:33:11+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,25 +9,25 @@ CVE-2026-70471 (Flowise is a drag-and-drop user interface for building customize
CVE-2026-70470 (Flowise is a drag & drop user interface to build a customized large la ...)
NOT-FOR-US: Flowise
CVE-2026-70373 (Koha's reports/issues_stats.pl (the circulation statistics report) bui ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70372 (Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate b ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70371 (Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70370 (Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70369 (Koha's reports/acquisitions_stats.pl builds its per-cell statistics qu ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-70368 (A stack-based out-of-bounds read vulnerability exists in the "s_vlog" ...)
TODO: check
CVE-2026-70367 (A Server-Side Request Forgery (SSRF) bypass vulnerability exists in \u ...)
TODO: check
CVE-2026-69704 (Atals-Livre contains a SQL injection vulnerability that allows attacke ...)
- TODO: check
+ NOT-FOR-US: Atals-Livre
CVE-2026-69703 (Atlas-Livre contains an improper access control vulnerability in the a ...)
- TODO: check
+ NOT-FOR-US: Atals-Livre
CVE-2026-69702 (SnailJob 1.7.0 contains a denial of service vulnerability in the FuryU ...)
- TODO: check
+ NOT-FOR-US: SnailJob
CVE-2026-69264 (Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled s ...)
NOT-FOR-US: Flowise
CVE-2026-69263 (Flowise is a drag & drop user interface to build a customized large la ...)
@@ -55,43 +55,43 @@ CVE-2026-69251 (Flowise is a drag & drop user interface to build a customized la
CVE-2026-69250 (Flowise is a drag & drop user interface to build a customized large la ...)
NOT-FOR-US: Flowise
CVE-2026-69110 (OpenCode Studio before 2.4.4 contains a missing authentication vulnera ...)
- TODO: check
+ NOT-FOR-US: OpenCode Studio
CVE-2026-69100 (LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27 ...)
- TODO: check
+ NOT-FOR-US: LAMP Rapid Development Platform
CVE-2026-69098 (kotaemon through 0.12.0 contains an insecure deserialization vulnerabi ...)
- TODO: check
+ NOT-FOR-US: kotaemon
CVE-2026-68743 (A flaw was found in SSSD. The extract_authtok_v1() function in the PAM ...)
TODO: check
CVE-2026-68494 (The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 ...)
TODO: check
CVE-2026-67618 (marimo before 0.23.15 contains a configuration injection vulnerability ...)
- TODO: check
+ NOT-FOR-US: marimo
CVE-2026-67243 (freo2 provided by refirio contains an unrestricted upload of file with ...)
- TODO: check
+ NOT-FOR-US: freo2
CVE-2026-67200 (Perspective 5.0.0 contains a path traversal vulnerability that allows ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-67199 (Perspective 5.0.0 contains a denial of service vulnerability that allo ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-67198 (Perspective 5.0.0 contains a denial-of-service vulnerability in the Vi ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-67196 (Perspective 5.0.0 contains a cross-site scripting vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-67195 (Perspective 5.0.0 contains a remote code execution vulnerability that ...)
- TODO: check
+ NOT-FOR-US: Perspective
CVE-2026-66884 (Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundatio ...)
TODO: check
CVE-2026-66883 (Improper Handling of Case Sensitivity vulnerability in Erlang Ecosyste ...)
TODO: check
CVE-2026-66300 (SNOMED International Snowstorm contains a reflected XSS vulnerability ...)
- TODO: check
+ NOT-FOR-US: SNOMED International Snowstorm
CVE-2026-64634 (A vulnerability allowing local privilege escalation to the Reporter se ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-64633 (A vulnerability allowing remote unauthenticated code execution on the ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-64631 (A vulnerability allowing a low-privileged user to inject SQL and extra ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-64630 (A vulnerability allowing a low-privileged user to retrieve report data ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-63456 (Multiple vulnerabilities in the REST API interface of HPE Networking S ...)
NOT-FOR-US: HPE
CVE-2026-63455 (Multiple vulnerabilities in the REST API interface of HPE Networking S ...)
@@ -103,9 +103,9 @@ CVE-2026-63248 (In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diag
CVE-2026-62927 (In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatc ...)
TODO: check
CVE-2026-61515 (Puwell IP Camera firmware versions 2.x through 4.x contains an unauthe ...)
- TODO: check
+ NOT-FOR-US: Puwell IP Camera firmware
CVE-2026-61514 (Puwell IP Camera firmware versions 2.x through 4.x contains an authent ...)
- TODO: check
+ NOT-FOR-US: Puwell IP Camera firmware
CVE-2026-61387 (In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota acc ...)
TODO: check
CVE-2026-60007 (In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processin ...)
@@ -113,21 +113,21 @@ CVE-2026-60007 (In Eclipse Milo versions 0.6.0 through 1.1.4, username-token pro
CVE-2026-58080 (In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy( ...)
TODO: check
CVE-2026-58075 (A vulnerability allowing an unauthenticated attacker to read arbitrary ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58074 (A vulnerability allowing a high-privileged user to execute arbitrary c ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58073 (A vulnerability in Veeam Service Provider Console allowing an unauthen ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58072 (A vulnerability in Veeam Service Provider Console allowing arbitrary f ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58071 (A vulnerability in Veeam Service Provider Console allowing an unauthen ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-58067 (A vulnerability in Veeam Service Provider Console allowing an unauthen ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2026-49435 (Keysight IxChariot Endpoint and associated products contain a stack-ba ...)
- TODO: check
+ NOT-FOR-US: Keysight
CVE-2026-48121 (@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js Checkp ...)
- TODO: check
+ NOT-FOR-US: langchain/langgraph-checkpoint-mongodb
CVE-2026-47781 (PDM is a Python package and dependency manager. In versions up to and ...)
TODO: check
CVE-2026-47764 (pdm is a Python package and dependency manager supporting the latest P ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f43d44e5906d79f219d35217120c0fe7be7553e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f43d44e5906d79f219d35217120c0fe7be7553e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/bc952395/attachment.htm>
More information about the debian-security-tracker-commits
mailing list