[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Aug 11 22:47:45 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
502211c7 by Moritz Muehlenhoff at 2026-08-11T23:47:23+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -244,51 +244,51 @@ CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a r
CVE-2026-72693 (`openvt -u` is intended to identify the owner of the current VT and th ...)
TODO: check
CVE-2026-72610 (A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.1 ...)
- TODO: check
+ - koha <itp> (bug #702134)
CVE-2026-72609 (An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25. ...)
- TODO: check
+ - koha <itp> (bug #702134)
CVE-2026-72608 (A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.1 ...)
- TODO: check
+ - koha <itp> (bug #702134)
CVE-2026-72607 (A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.1 ...)
- TODO: check
+ - koha <itp> (bug #702134)
CVE-2026-72606 (A server-side request forgery vulnerability in Pinry through 2.1.13 al ...)
TODO: check
CVE-2026-72605 (A missing authentication vulnerability in Swing Music 3.0.0 allows una ...)
TODO: check
CVE-2026-72604 (A path traversal vulnerability in Intelliants Subrion CMS through 4.2. ...)
- TODO: check
+ NOT-FOR-US: Subrion CMS
CVE-2026-72603 (An OS command injection vulnerability in wg-easy 15.3.0 allows users w ...)
TODO: check
CVE-2026-72602 (A path traversal vulnerability in AsyncFuncAI deepwiki-open through co ...)
- TODO: check
+ NOT-FOR-US: AsyncFuncAI deepwiki-open
CVE-2026-72601 (A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthen ...)
- TODO: check
+ NOT-FOR-US: CSZ CMS
CVE-2026-72600 (A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 a ...)
- TODO: check
+ NOT-FOR-US: Idurar IDURAR ERP CRM
CVE-2026-72599 (An SQL injection vulnerability in e107 2.4.0 allows unauthenticated re ...)
- TODO: check
+ NOT-FOR-US: e107
CVE-2026-72598 (A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allow ...)
- TODO: check
+ NOT-FOR-US: Apioo Fusio
CVE-2026-72597 (A server-side request forgery vulnerability in Friendica through the 2 ...)
- TODO: check
+ NOT-FOR-US: Friendica
CVE-2026-72596 (A broken access control vulnerability in Ghost Foundation Ghost 5.x al ...)
- TODO: check
+ - ghost <itp> (bug #892150)
CVE-2026-72595 (A broken access control vulnerability in BadChoice Handesk as of 2026- ...)
- TODO: check
+ NOT-FOR-US: BadChoice Handesk
CVE-2026-72563 (A broken access control vulnerability in BadChoice Handesk as of 2026- ...)
- TODO: check
+ NOT-FOR-US: BadChoice Handesk
CVE-2026-72562 (An SQL injection vulnerability in Pimcore admin-ui-classic-bundle thro ...)
- TODO: check
+ NOT-FOR-US: Pimcore admin-ui-classic-bundle
CVE-2026-72561 (A broken access control vulnerability in Peppermint Lab Peppermint thr ...)
TODO: check
CVE-2026-72560 (A server-side request forgery vulnerability in HumanSignal Label Studi ...)
TODO: check
CVE-2026-72559 (A stored cross-site scripting vulnerability in HortusFox 5.9 allows au ...)
- TODO: check
+ NOT-FOR-US: HortusFox
CVE-2026-72558 (An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows a ...)
TODO: check
CVE-2026-72557 (An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows ...)
- TODO: check
+ NOT-FOR-US: Cockpit CMS
CVE-2026-72556 (A remote code execution vulnerability in ZoneMinder 1.39.17 allows any ...)
TODO: check
CVE-2026-72555 (A broken access control vulnerability in Peppermint Lab Peppermint thr ...)
@@ -296,47 +296,47 @@ CVE-2026-72555 (A broken access control vulnerability in Peppermint Lab Peppermi
CVE-2026-72554 (A broken access control vulnerability in Ladybird Web Solution Faveo H ...)
TODO: check
CVE-2026-72553 (A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta ...)
- TODO: check
+ NOT-FOR-US: ElkArte Forum
CVE-2026-72552 (A server-side request forgery vulnerability in Dub as of 2026-07-10 al ...)
TODO: check
CVE-2026-72551 (A remote code execution vulnerability in Apioo Fusio 8.8.3 allows auth ...)
TODO: check
CVE-2026-72550 (An SQL injection vulnerability in Friendica through the 2026.08-dev br ...)
- TODO: check
+ NOT-FOR-US: Friendica
CVE-2026-72549 (An information disclosure vulnerability in OpenSignLabs OpenSign throu ...)
- TODO: check
+ NOT-FOR-US: OpenSignLabs OpenSign
CVE-2026-72548 (An information disclosure vulnerability in OpenSignLabs OpenSign throu ...)
- TODO: check
+ NOT-FOR-US: OpenSignLabs OpenSign
CVE-2026-72547 (An insecure direct object reference vulnerability in Attendize through ...)
TODO: check
CVE-2026-72546 (An insecure direct object reference vulnerability in Attendize through ...)
TODO: check
CVE-2026-72545 (An insecure direct object reference vulnerability in OpenSignLabs Open ...)
- TODO: check
+ NOT-FOR-US: OpenSignLabs OpenSign
CVE-2026-72544 (An integrity verification vulnerability in OpenSignLabs OpenSign throu ...)
- TODO: check
+ NOT-FOR-US: OpenSignLabs OpenSign
CVE-2026-72543 (An insecure direct object reference vulnerability in OpenSignLabs Open ...)
- TODO: check
+ NOT-FOR-US: OpenSignLabs OpenSign
CVE-2026-72542 (A missing authorization vulnerability in Windmill Labs Windmill throug ...)
- TODO: check
+ NOT-FOR-US: Windmill
CVE-2026-72541 (A missing authorization vulnerability in Windmill Labs Windmill throug ...)
- TODO: check
+ NOT-FOR-US: Windmill
CVE-2026-72540 (An insecure direct object reference vulnerability in PhotoPrism throug ...)
- TODO: check
+ NOT-FOR-US: PhotoPrism
CVE-2026-72539 (An information disclosure vulnerability in Windmill Labs Windmill thro ...)
- TODO: check
+ NOT-FOR-US: Windmill
CVE-2026-72538 (An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 ...)
TODO: check
CVE-2026-72537 (A privilege escalation vulnerability in Authentik Security authentik t ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-72536 (A missing authentication vulnerability in Chaskiq through commit 46dfd ...)
TODO: check
CVE-2026-72535 (A missing authentication vulnerability in Chaskiq through commit 46dfd ...)
TODO: check
CVE-2026-72534 (A privilege escalation vulnerability in Authentik Security authentik t ...)
- TODO: check
+ NOT-FOR-US: authentik
CVE-2026-72533 (An authentication bypass vulnerability in Portainer CE through 2.44.0 ...)
- TODO: check
+ NOT-FOR-US: Portainer
CVE-2026-71398 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
NOT-FOR-US: Adobe
CVE-2026-71390 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
@@ -1172,9 +1172,9 @@ CVE-2026-57105 (Improper neutralization of input during web page generation ('cr
CVE-2026-57104 (Improper neutralization of input during web page generation ('cross-si ...)
NOT-FOR-US: Microsoft
CVE-2026-56721 (CamaleonCMS version 2.9.2 and earlier contains a privilege escalation ...)
- TODO: check
+ NOT-FOR-US: CamaleonCMS
CVE-2026-56720 (CamaleonCMS version 2.9.2 and earlier contains a missing authorization ...)
- TODO: check
+ NOT-FOR-US: CamaleonCMS
CVE-2026-56179 (Origin validation error in Windows Network Address Translation (NAT) a ...)
NOT-FOR-US: Microsoft
CVE-2026-56174 (Untrusted search path in Windows Narrator Braille allows an authorized ...)
@@ -1230,17 +1230,17 @@ CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO real
CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the open-source datab ...)
TODO: check
CVE-2026-48771 (ishankportfolio is a portfolio website. Prior to version 1.0.1, contac ...)
- TODO: check
+ NOT-FOR-US: ishankportfolio
CVE-2026-48767 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
- TODO: check
+ NOT-FOR-US: TypeBot
CVE-2026-48766 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
- TODO: check
+ NOT-FOR-US: TypeBot
CVE-2026-48495 (TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google ...)
- TODO: check
+ NOT-FOR-US: TypeBot
CVE-2026-48494 (TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated ...)
- TODO: check
+ NOT-FOR-US: TypeBot
CVE-2026-48483 (TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's ...)
- TODO: check
+ NOT-FOR-US: TypeBot
CVE-2026-48447 (Lightroom Classic is affected by an Incorrect Authorization vulnerabil ...)
NOT-FOR-US: Adobe
CVE-2026-48446 (CAI Content Credentials is affected by an Improper Limitation of a Pat ...)
@@ -1322,17 +1322,17 @@ CVE-2026-47940 (Lightroom Classic is affected by an Integer Overflow or Wraparou
CVE-2026-47922 (CAI Content Credentials is affected by a Server-Side Request Forgery ( ...)
NOT-FOR-US: Adobe
CVE-2026-47705 (TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection ...)
- TODO: check
+ NOT-FOR-US: TypeBot
CVE-2026-47704 (TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authent ...)
- TODO: check
+ NOT-FOR-US: TypeBot
CVE-2026-47702 (TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bear ...)
- TODO: check
+ NOT-FOR-US: TypeBot
CVE-2026-47299 (Improper neutralization of special elements used in a command ('comman ...)
NOT-FOR-US: Microsoft
CVE-2026-47285 (Improper neutralization of special elements used in a command ('comman ...)
NOT-FOR-US: Microsoft
CVE-2026-46670 (YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an u ...)
- TODO: check
+ NOT-FOR-US: YesWiki
CVE-2026-43606 (Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256 ...)
TODO: check
CVE-2026-42976 (Missing authentication for critical function in Windows RPC API allows ...)
@@ -1496,63 +1496,63 @@ CVE-2026-18972 (An authenticated attacker can spoof another GUI user's identity
CVE-2026-18860 (Velociraptor allows multi-tenant deployments named "Orgs". By default ...)
TODO: check
CVE-2026-18712 (An issue in MongoDB Server's Queryable Encryption maintenance operatio ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18711 (An issue in MongoDB Server's query execution engine could allow an aut ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18709 (An issue in MongoDB Server could allow an authenticated user with dire ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18708 (An issue in MongoDB Server's JavaScript scripting engine could allow a ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18707 (An issue in MongoDB Server could allow an authenticated user, includin ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18706 (An issue in MongoDB Server's $graphLookup aggregation stage could allo ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18705 (An issue in MongoDB Server's Atlas Vector Search feature could allow a ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18704 (An issue in MongoDB Server's aggregation framework could allow an auth ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18703 (An issue in MongoDB Server could allow a party with a valid client cer ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18702 (An issue in MongoDB Server could allow an authenticated user with limi ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18701 (An issue in MongoDB Server's query subsystem could allow an authentica ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18700 (An issue in MongoDB Server's geospatial validation could allow an auth ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18699 (An issue in MongoDB Server's query planner could allow an authenticate ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18698 (An issue in MongoDB Server could allow an authenticated user with a li ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18697 (An issue in MongoDB Server's aggregation framework could allow an unau ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18696 (An issue in MongoDB Server's applyOps command could allow an authentic ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18695 (An issue in MongoDB Server's handling of certain query predicates agai ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18694 (An issue in MongoDB Server's geospatial query processing could allow a ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18693 (An issue in MongoDB Server's handling of timeseries collections could ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18692 (An issue in MongoDB Server's handling of timeseries bucket lifecycle c ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18691 (An issue in MongoDB Server's intra-cluster connection setup could allo ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18690 (An issue in MongoDB Server could allow an authenticated user with a li ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18688 (An issue in MongoDB Server's aggregation framework could allow an auth ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18687 (MongoDB Server's handling of a Queryable Encryption maintenance operat ...)
- TODO: check
+ - mongodb <removed>
CVE-2026-18640 (The NewNotebook API does not sufficiently sanitize its parameters allo ...)
TODO: check
CVE-2026-18639 (When Velociraptor is configured to use an OIDC IdP for authentication, ...)
- TODO: check
+ NOT-FOR-US: Velociraptor
CVE-2026-18638 (Any authenticated Velociraptor user \u2014 including one holding only ...)
- TODO: check
+ NOT-FOR-US: Velociraptor
CVE-2026-18636 (The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows rea ...)
- TODO: check
+ NOT-FOR-US: Velociraptor
CVE-2026-18635 (Velociraptor's VQL has a query() plugin which allows running a VQL que ...)
- TODO: check
+ NOT-FOR-US: Velociraptor
CVE-2026-18247 (A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc ...)
NOT-FOR-US: Blackberry
CVE-2026-18129 (Cleartext transmission of sensitive information in the Core of Ivanti ...)
@@ -1562,7 +1562,7 @@ CVE-2026-18127 (External control of a filename in the Core of Ivanti Endpoint Ma
CVE-2026-18125 (An out-of-boundsread intheAgent ofIvanti Endpoint Managerbeforeversion ...)
NOT-FOR-US: Ivanti
CVE-2026-17535 (Velociraptor's NTFS parsing library mishandles several out of bound an ...)
- TODO: check
+ NOT-FOR-US: Velociraptor
CVE-2026-17061 (A Deserialization of Untrusted Data vulnerability affecting SIMULIA Ex ...)
NOT-FOR-US: Dassault Systemes
CVE-2026-15567 (A flaw was found in Wildfly. A remote unauthenticated attacker can tri ...)
@@ -1652,7 +1652,7 @@ CVE-2023-54368
CVE-2023-54367
REJECTED
CVE-2022-50997 (Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerab ...)
- TODO: check
+ NOT-FOR-US: Weaver E-cology
CVE-2022-50974
REJECTED
CVE-2021-47995
@@ -1690,7 +1690,7 @@ CVE-2020-37258
CVE-2020-37257
REJECTED
CVE-2016-20097 (Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Weaver E-cology
CVE-2026-20707 (Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon ...)
- intel-microcode <unfixed> (bug #1144158)
[trixie] - intel-microcode <postponed> (As usual fixed top-down, expose first in unstable, then likely point release)
@@ -1915,9 +1915,9 @@ CVE-2026-72873 (Dokploy is a free, self-hostable Platform as a Service (PaaS). P
CVE-2026-72743 (SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cros ...)
NOT-FOR-US: SQLBot
CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated c ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated r ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) ra ...)
NOT-FOR-US: Axis Communication
CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost inflight migra ...)
@@ -1927,7 +1927,7 @@ CVE-2026-6181 (The Device Configuration Framework is vulnerable to an authentica
CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection vulnera ...)
TODO: check
CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering an ...)
- TODO: check
+ NOT-FOR-US: FlyEnv
CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel message ...)
TODO: check
CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path traversal vulne ...)
@@ -2113,17 +2113,17 @@ CVE-2025-30238 (In affected TP-Link Aginet devices, insufficient authorization v
CVE-2025-30237 (The affected TP-Link Aginet devicescontain a flaw in the web managemen ...)
NOT-FOR-US: TPLink
CVE-2025-15683 (TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial ...)
- TODO: check
+ NOT-FOR-US: TBEA TLogger
CVE-2025-15682 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exh ...)
- TODO: check
+ NOT-FOR-US: TBEA TLogger
CVE-2025-15681 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its ...)
- TODO: check
+ NOT-FOR-US: TBEA TLogger
CVE-2025-15680 (TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's ...)
- TODO: check
+ NOT-FOR-US: TBEA TLogger
CVE-2025-13294 (An unauthenticated SQL injection vulnerability exists in the web serve ...)
- TODO: check
+ NOT-FOR-US: TBEA TLogger
CVE-2025-13293 (A hard-coded or default root account credential in TBEA TLogger V2.1.0 ...)
- TODO: check
+ NOT-FOR-US: TBEA TLogger
CVE-2026-19349
- lemonldap-ng 2.23.3+ds-1
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8c6015d6f0b4f1aa78bd54e159a74cd151e8e00d (v2.23.3)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/502211c70a775711b44ab9c85efd1de658f940ec
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/502211c70a775711b44ab9c85efd1de658f940ec
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/971046bf/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list