[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 6 21:31:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ce7104ed by Salvatore Bonaccorso at 2026-08-06T22:29:43+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -217,7 +217,7 @@ CVE-2026-5391 (The LatePoint plugin for WordPress is vulnerable to Stored Cross-
CVE-2026-5158 (The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites \u20 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-5134 (Improper neutralization of special elements used in an SQL command ('S ...)
- TODO: check
+ NOT-FOR-US: Loca Software Informatics Technology Ltd. Co. CMS
CVE-2026-57819 (Apache CXF allows to set a limit on the number of form parameters in a ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-57818 (A race condition in JCacheCodeDataProvider allows an attacker to redee ...)
@@ -293,47 +293,47 @@ CVE-2026-25403 (Unauthenticated Broken Access Control in Ultimate Store Kit Elem
CVE-2026-1728 (Tokens issued to a low-privileged user are not sufficiently restricted ...)
NOT-FOR-US: WSO2
CVE-2026-19047 (A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. T ...)
- TODO: check
+ NOT-FOR-US: NocteDefensor LudusMCP
CVE-2026-19046 (A security vulnerability has been detected in NocteDefensor LudusMCP u ...)
- TODO: check
+ NOT-FOR-US: NocteDefensor LudusMCP
CVE-2026-19045 (A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. ...)
- TODO: check
+ NOT-FOR-US: NocteDefensor LudusMCP
CVE-2026-19044 (A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this ...)
- TODO: check
+ NOT-FOR-US: LeeSinLiang godot-mcp
CVE-2026-19041 (A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. T ...)
- TODO: check
+ NOT-FOR-US: MissionSquad mcp-api
CVE-2026-19040 (A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affect ...)
- TODO: check
+ NOT-FOR-US: MissionSquad mcp-api
CVE-2026-19039 (A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8 ...)
- TODO: check
+ NOT-FOR-US: Kino-Kafkaesque ssh-mcp-server
CVE-2026-19038 (A security vulnerability has been detected in MonomythDevelopment la-f ...)
- TODO: check
+ NOT-FOR-US: MonomythDevelopmentla-forge-mcp
CVE-2026-19037 (A weakness has been identified in WonderTrader up to 0.9.9. This vulne ...)
- TODO: check
+ NOT-FOR-US: WonderTrader
CVE-2026-19036 (A security flaw has been discovered in Shibby Tomato 1.28.0000. This a ...)
- TODO: check
+ NOT-FOR-US: Shibby Tomato
CVE-2026-19035 (A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by ...)
- TODO: check
+ NOT-FOR-US: Shibby Tomato
CVE-2026-19034 (A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by ...)
- TODO: check
+ NOT-FOR-US: Shibby Tomato
CVE-2026-19022 (A vulnerability was determined in OpenHands up to 0.62.0. The affected ...)
- TODO: check
+ NOT-FOR-US: OpenHands
CVE-2026-19021 (A security vulnerability has been detected in SourceCodester Computer ...)
NOT-FOR-US: SourceCodester
CVE-2026-19020 (A weakness has been identified in itsourcecode Hospital Management Sys ...)
NOT-FOR-US: itsourcecode System
CVE-2026-19019 (A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. ...)
- TODO: check
+ NOT-FOR-US: poco-ai poco-agent
CVE-2026-19011 (A vulnerability was detected in TinyAGI 0.0.20. The affected element i ...)
- TODO: check
+ NOT-FOR-US: TinyAGI
CVE-2026-19010 (A security vulnerability has been detected in TinyAGI 0.0.20. Impacted ...)
- TODO: check
+ NOT-FOR-US: TinyAGI
CVE-2026-19009 (A weakness has been identified in TinyAGI 0.0.20. This issue affects t ...)
- TODO: check
+ NOT-FOR-US: TinyAGI
CVE-2026-19008 (A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. Thi ...)
- TODO: check
+ NOT-FOR-US: mf-yang openclaw-cn
CVE-2026-18915 (Invocation of process using visible sensitive information vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: eta-otp-lock
CVE-2026-18649 (A flaw was found in the GStreamer gst-plugins-good package. The rtph26 ...)
TODO: check
CVE-2026-18597 (The PDF creation feature of Foxit PDF Services API supports referencin ...)
@@ -341,25 +341,25 @@ CVE-2026-18597 (The PDF creation feature of Foxit PDF Services API supports refe
CVE-2026-18501 (The UsersWP \u2013 Front-end login form, User Registration, User Profi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18427 (@fastify/static before version 10.1.3 contains an incomplete fix for a ...)
- TODO: check
+ NOT-FOR-US: fastify/static
CVE-2026-18359 (Server-side request forgery in the METS and IIIF import URI handling i ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-18277 (Missing authorization in the OcrModelRight create and delete views in ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-18276 (Missing authorization in the websocket consumer in Scripta eScriptoriu ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-18275 (Authorization bypass in the process and annotation taxonomy serializer ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-18258 (Authorization bypass in the Line, LineTranscription, VirtualCollection ...)
- TODO: check
+ NOT-FOR-US: Scripta eScriptorium
CVE-2026-16731 (OMICRON StationScout before version 3.05 contains a cryptographic timi ...)
- TODO: check
+ NOT-FOR-US: OMICRON
CVE-2026-16316 (OMICRON StationGuard 4.00 contains an improper input validation vulner ...)
- TODO: check
+ NOT-FOR-US: OMICRON
CVE-2026-16315 (OMICRON StationGuard before version 4.10 contains a cryptographic timi ...)
- TODO: check
+ NOT-FOR-US: OMICRON
CVE-2026-15599 (Unverified ownership vulnerability in T\xdcB\u0130TAK B\u0130LGEM Soft ...)
- TODO: check
+ NOT-FOR-US: pardus-domain-joiner
CVE-2026-15246 (The RealHomes Memberships WordPress plugin before 3.1.0 does not verif ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12605 (In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in Downl ...)
@@ -719,7 +719,7 @@ CVE-2026-18325 (The Forminator Forms \u2013 Contact Form, Payment Form & Custom
CVE-2026-18050 (The Events Manager WordPress plugin before 7.4 does not perform any a ...)
NOT-FOR-US: WordPress plugin
CVE-2026-17583 (The affected Thermo Fisher Applied Biosystems Genetic Analyzers arevu ...)
- TODO: check
+ NOT-FOR-US: Thermo Fisher
CVE-2026-17556 (A path traversal vulnerability was identified in GitHub Enterprise Ser ...)
NOT-FOR-US: Github Enterprise Server
CVE-2026-16954 (The AI Engine WordPress plugin before 3.6.4 does not redact secret co ...)
@@ -767,9 +767,9 @@ CVE-2026-12713 (The WPCargo Track & Trace WordPress plugin before 8.0.4 does not
CVE-2026-11588 (The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform an ...)
NOT-FOR-US: WordPress plugin
CVE-2025-63823 (My Safetipin Android Application 5.2.1 contains Hardcoded credentials ...)
- TODO: check
+ NOT-FOR-US: My Safetipin Android Application
CVE-2025-63822 (SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access ...)
- TODO: check
+ NOT-FOR-US: SirenGPS Android Application
CVE-2025-15678 (The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize upl ...)
NOT-FOR-US: WordPress plugin
CVE-2023-54389
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ce7104edf21ef862abaf3fd04044f6b474e9e1e1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ce7104edf21ef862abaf3fd04044f6b474e9e1e1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/cc699693/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list