[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 7 21:58:29 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f5c5dfb9 by Salvatore Bonaccorso at 2026-08-07T22:58:07+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -142,11 +142,11 @@ CVE-2026-47362 (The Datadog Android application stores operationally sensitive c
CVE-2026-47361 (BubbleChatActivity in the Datadog Android application is declared andr ...)
NOT-FOR-US: Datadog Android application
CVE-2026-44965 (Six Android App Widget configuration activities in the Datadog Android ...)
- TODO: check
+ NOT-FOR-US: Datadog Android application
CVE-2026-44964 (The OnCallNotificationActivity in the Datadog Android application is d ...)
- TODO: check
+ NOT-FOR-US: Datadog Android application
CVE-2026-37171 (A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0. ...)
- TODO: check
+ NOT-FOR-US: SuperTokens
CVE-2026-20348 (A vulnerability in the XAR file format parser of ClamAV could allow an ...)
TODO: check
CVE-2026-20347 (A vulnerability in the Mach-O file format parser of ClamAV could allow ...)
@@ -162,7 +162,7 @@ CVE-2026-20338 (A vulnerability in the zip archive parser of ClamAV could allow
CVE-2026-20337 (A vulnerability in the zip archive parser of ClamAV could allow an una ...)
TODO: check
CVE-2026-19264 (Postiz is an open-source social media scheduling tool. The route that ...)
- TODO: check
+ NOT-FOR-US: Postiz
CVE-2026-19231 (A security flaw has been discovered in SourceCodester Simple Doctors A ...)
NOT-FOR-US: SourceCodester
CVE-2026-19230 (A vulnerability was identified in SourceCodester Photo Share Website 1 ...)
@@ -170,9 +170,9 @@ CVE-2026-19230 (A vulnerability was identified in SourceCodester Photo Share Web
CVE-2026-19229 (A vulnerability was determined in SourceCodester Online Clothing Store ...)
NOT-FOR-US: SourceCodester
CVE-2026-19213 (A vulnerability was identified in WonderTrader up to 0.9.9. Affected i ...)
- TODO: check
+ NOT-FOR-US: WonderTrader
CVE-2026-19212 (A vulnerability was determined in WonderTrader up to 0.9.9. This impac ...)
- TODO: check
+ NOT-FOR-US: WonderTrader
CVE-2026-19211 (A vulnerability was found in SourceCodester Photo Share Website 1.0. T ...)
NOT-FOR-US: SourceCodester
CVE-2026-19210 (A vulnerability has been found in SourceCodester Photo Share Website 1 ...)
@@ -217,13 +217,13 @@ CVE-2026-17593 (An account holding the nexus:settings:update permission in Nexus
CVE-2026-17435 (File::Rotate::Simple versions before 0.4.0 for Perl create the target ...)
NOT-FOR-US: File::Rotate::Simple Perl module
CVE-2026-16637 (OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HT ...)
- TODO: check
+ NOT-FOR-US: OPeNDAP Hyrax
CVE-2026-16027 (Server-Side request forgery (SSRF) vulnerability in Revenue Administra ...)
- TODO: check
+ NOT-FOR-US: Turkie's E-Signature
CVE-2026-15816 (A flaw was found in dracut. The die() error-handling function writes i ...)
TODO: check
CVE-2026-15570 (An improper restriction of URL schemes and destinations in the SmartCe ...)
- TODO: check
+ NOT-FOR-US: Telefunken TE24553B45V2DZ Smart TV
CVE-2026-15239 (The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15211 (The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does n ...)
@@ -233,11 +233,11 @@ CVE-2026-15148 (The WP Events Manager WordPress plugin before 2.2.5 does not ver
CVE-2026-14644 (Nexus Repository 3 contained a privilege escalation vulnerability in t ...)
NOT-FOR-US: Sonatype
CVE-2026-12071 (The Webbox of TeamDavid byTobit Laboratories AGconstructs redirect URL ...)
- TODO: check
+ NOT-FOR-US: Tobit
CVE-2026-12070 (Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrar ...)
- TODO: check
+ NOT-FOR-US: Tobit
CVE-2026-11430 (Grav CMS's scheduler-webhook plugin contains an authentication bypass ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2025-71413 (Malformed or out-of-sequence frames at the Aviation Very High Frequenc ...)
TODO: check
CVE-2025-71412 (Injection of false emergency or status messages over CPDLC may lead to ...)
@@ -581,7 +581,7 @@ CVE-2026-43628 (llama.cpp builds b3978 through b9058 contain an integer underflo
CVE-2026-43627 (llama.cpp builds b1283 through b9058 contain an integer overflow vulne ...)
TODO: check
CVE-2026-41861 (Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attack ...)
- TODO: check
+ NOT-FOR-US: BOSH
CVE-2026-3418 (The System REST API accepts user-supplied file uploads without enforci ...)
NOT-FOR-US: WSO2
CVE-2026-3415 (The XML and schema validation functionalities within the SchemaValidat ...)
@@ -593,25 +593,25 @@ CVE-2026-1289 (A maliciously crafted PDF file, when parsed through Autodesk Revi
CVE-2026-19196 (A vulnerability was found in SourceCodester Photo Share Website 1.0. T ...)
NOT-FOR-US: SourceCodester
CVE-2026-19195 (A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. ...)
- TODO: check
+ NOT-FOR-US: V-Secure Jingyun Antivirus
CVE-2026-19193 (A flaw has been found in Jiangmin Antivirus 21. Impacted is the functi ...)
- TODO: check
+ NOT-FOR-US: Jiangmin Antivirus
CVE-2026-19192 (A vulnerability was detected in DeepCool DisplayService 1.2.12. This i ...)
- TODO: check
+ NOT-FOR-US: DeepCool DisplayService
CVE-2026-19191 (A security vulnerability has been detected in StableBit DrivePool 2.3. ...)
- TODO: check
+ NOT-FOR-US: StableBit DrivePool
CVE-2026-19190 (A weakness has been identified in StableBit Scanner 2.6.13.4088. This ...)
- TODO: check
+ NOT-FOR-US: StableBit
CVE-2026-19189 (A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. ...)
- TODO: check
+ NOT-FOR-US: Power Sofware PowerISO
CVE-2026-19127 (An issue in the billing and license activation subsystem allows remote ...)
- TODO: check
+ NOT-FOR-US: GitroomHQ
CVE-2026-19111 (Insecure direct object reference in the mongodb_memory, elasticsearch_ ...)
NOT-FOR-US: Amazon
CVE-2026-19110 (A vulnerability was determined in DataGear up to 5.0.0. The impacted e ...)
- TODO: check
+ NOT-FOR-US: DataGear
CVE-2026-19108 (A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. Th ...)
- TODO: check
+ NOT-FOR-US: mz-automation libiec61850
CVE-2026-19071 (A flaw has been found in itsourcecode Hospital Management System 1.0. ...)
NOT-FOR-US: itsourcecode System
CVE-2026-19070 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
@@ -629,17 +629,17 @@ CVE-2026-19065 (A vulnerability was determined in SourceCodester Online Examinat
CVE-2026-19064 (A vulnerability was found in SourceCodester Online Examination & Learn ...)
NOT-FOR-US: SourceCodester
CVE-2026-19062 (A vulnerability has been found in chiuwingyan house up to dea6bcceaebe ...)
- TODO: check
+ NOT-FOR-US: chiuwingyan house
CVE-2026-19061 (A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected ...)
- TODO: check
+ NOT-FOR-US: Insta InstaKNXServiceApp
CVE-2026-19060 (A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2 ...)
- TODO: check
+ NOT-FOR-US: FoundationAgents MetaGPT
CVE-2026-19059 (A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2 ...)
- TODO: check
+ NOT-FOR-US: FoundationAgents MetaGPT
CVE-2026-19058 (A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The ...)
- TODO: check
+ NOT-FOR-US: FoundationAgents MetaGPT
CVE-2026-19054 (A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5 ...)
- TODO: check
+ NOT-FOR-US: Lspace-io lspace-server
CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser reads web ad ...)
TODO: check
CVE-2026-18367 (A privilege escalation vulnerability allows local users to execute arb ...)
@@ -673,11 +673,11 @@ CVE-2026-16030 (The MStore API WordPress plugin before 4.21.0 does not correctl
CVE-2026-15805
REJECTED
CVE-2026-15734 (A Server-Side Template Injection (SSTI) vulnerability in WGDashboard v ...)
- TODO: check
+ NOT-FOR-US: WGDashboard
CVE-2026-15733 (A Remote Code Execution (RCE) vulnerability exist in WGDashboard versi ...)
- TODO: check
+ NOT-FOR-US: WGDashboard
CVE-2026-15732 (A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboar ...)
- TODO: check
+ NOT-FOR-US: WGDashboard
CVE-2026-15386 (The Meow Gallery WordPress plugin before 5.5.2 does not escape an atta ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15361 (The Content Views WordPress plugin before 4.5 does not perform a capa ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f5c5dfb9c9ef5c4490771e2a8d9cb2711e0aa909
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f5c5dfb9c9ef5c4490771e2a8d9cb2711e0aa909
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/d83ba75b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list