[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 12 07:21:23 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
737dc864 by Salvatore Bonaccorso at 2026-08-12T08:21:02+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -278,7 +278,7 @@ CVE-2026-73066 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafte
CVE-2026-72971 (Improper link resolution before file access ('link following') in Wind ...)
NOT-FOR-US: Microsoft
CVE-2026-72925 (SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @s ...)
- TODO: check
+ NOT-FOR-US: SWC
CVE-2026-72922 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
NOT-FOR-US: AutoGPT
CVE-2026-72921 (SeaweedFS is a distributed storage system. Prior to 4.24, the weed/ser ...)
@@ -370,13 +370,13 @@ CVE-2026-72608 (A stored SQL injection vulnerability in Koha through 24.11.17, 2
CVE-2026-72607 (A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.1 ...)
- koha <itp> (bug #702134)
CVE-2026-72606 (A server-side request forgery vulnerability in Pinry through 2.1.13 al ...)
- TODO: check
+ NOT-FOR-US: Pinry
CVE-2026-72605 (A missing authentication vulnerability in Swing Music 3.0.0 allows una ...)
- TODO: check
+ NOT-FOR-US: Swing Music
CVE-2026-72604 (A path traversal vulnerability in Intelliants Subrion CMS through 4.2. ...)
NOT-FOR-US: Subrion CMS
CVE-2026-72603 (An OS command injection vulnerability in wg-easy 15.3.0 allows users w ...)
- TODO: check
+ NOT-FOR-US: wg-easy
CVE-2026-72602 (A path traversal vulnerability in AsyncFuncAI deepwiki-open through co ...)
NOT-FOR-US: AsyncFuncAI deepwiki-open
CVE-2026-72601 (A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthen ...)
@@ -398,9 +398,9 @@ CVE-2026-72563 (A broken access control vulnerability in BadChoice Handesk as of
CVE-2026-72562 (An SQL injection vulnerability in Pimcore admin-ui-classic-bundle thro ...)
NOT-FOR-US: Pimcore admin-ui-classic-bundle
CVE-2026-72561 (A broken access control vulnerability in Peppermint Lab Peppermint thr ...)
- TODO: check
+ NOT-FOR-US: Peppermint Lab Peppermint
CVE-2026-72560 (A server-side request forgery vulnerability in HumanSignal Label Studi ...)
- TODO: check
+ NOT-FOR-US: HumanSignal Label Studio
CVE-2026-72559 (A stored cross-site scripting vulnerability in HortusFox 5.9 allows au ...)
NOT-FOR-US: HortusFox
CVE-2026-72558 (An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows a ...)
@@ -410,9 +410,9 @@ CVE-2026-72557 (An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 a
CVE-2026-72556 (A remote code execution vulnerability in ZoneMinder 1.39.17 allows any ...)
TODO: check
CVE-2026-72555 (A broken access control vulnerability in Peppermint Lab Peppermint thr ...)
- TODO: check
+ NOT-FOR-US: Peppermint Lab Peppermint
CVE-2026-72554 (A broken access control vulnerability in Ladybird Web Solution Faveo H ...)
- TODO: check
+ NOT-FOR-US: Ladybird Web Solution Faveo Helpdesk
CVE-2026-72553 (A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta ...)
NOT-FOR-US: ElkArte Forum
CVE-2026-72552 (A server-side request forgery vulnerability in Dub as of 2026-07-10 al ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/737dc86456f803bd6a22d5ef7d1dd99f537490c4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/737dc86456f803bd6a22d5ef7d1dd99f537490c4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/d8194f93/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list