[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 20:35:12 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f9175441 by Salvatore Bonaccorso at 2026-08-14T21:32:54+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5,13 +5,13 @@ CVE-2026-73849 (Emlog is an open source website building system. In 2.6.26 and e
CVE-2026-73847 (Emlog is an open source website building system. In 2.6.26 and earlier ...)
NOT-FOR-US: Emlog
CVE-2026-73846 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
- TODO: check
+ NOT-FOR-US: CKAN MCP Server
CVE-2026-73845 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
- TODO: check
+ NOT-FOR-US: CKAN MCP Server
CVE-2026-73844 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
- TODO: check
+ NOT-FOR-US: CKAN MCP Server
CVE-2026-73673 (Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated fir ...)
- TODO: check
+ NOT-FOR-US: Netis NC63 router
CVE-2026-73633 (Uncontrolled resource consumption vulnerability in the JSON plugin of ...)
TODO: check
CVE-2026-73630 (SiYuan before v3.7.4 contains an information disclosure vulnerability ...)
@@ -27,47 +27,47 @@ CVE-2026-73048 (SiYuan versions before v3.7.4 contain an information disclosure
CVE-2026-72970 (Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows a ...)
NOT-FOR-US: Microsoft
CVE-2026-72859 (Budibase versions 3.39.4 before 3.40.0 contain an authorization regres ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-72838 (FileBrowser versions before 2.63.19 fail to enforce the declared Uploa ...)
- TODO: check
+ NOT-FOR-US: FileBrowser
CVE-2026-72837 (File Browser versions before 2.63.20 fail to honor the createUserDir i ...)
- TODO: check
+ NOT-FOR-US: FileBrowser
CVE-2026-72836 (FileBrowser before 2.63.19 does not account for case-insensitive files ...)
- TODO: check
+ NOT-FOR-US: FileBrowser
CVE-2026-72835 (filebrowser versions before v2.63.21 fail to canonicalize paths before ...)
- TODO: check
+ NOT-FOR-US: FileBrowser
CVE-2026-72834 (filebrowser before 2.63.19 contains a permission bypass in the /api/re ...)
- TODO: check
+ NOT-FOR-US: FileBrowser
CVE-2026-72833 (The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= ...)
- TODO: check
+ NOT-FOR-US: Grav API plugin
CVE-2026-72832 (Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site sc ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-72831 (The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) conta ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72830 (Grav API plugin versions before 1.0.13 fail to enforce API key scope c ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72829 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains a ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72828 (Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enfor ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72827 (Grav CMS before 2.0.13 contains a server-side template injection vulne ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-72826 (The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate tha ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72825 (The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key s ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72824 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains a ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72823 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains a ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72822 (The getgrav/grav-plugin-api Composer package before 1.0.13 (affected < ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72821 (Grav Form plugin versions before 9.1.15 contain a stored cross-site sc ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-72820 (Grav versions before 2.0.13 fail to properly validate backup profile r ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-72819 (Grav CMS before 2.0.13 contains a remote code execution vulnerability ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-72817 (go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnera ...)
TODO: check
CVE-2026-72816 (go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9175441e4a666012f02af511a536c27e863350f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9175441e4a666012f02af511a536c27e863350f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/141219cf/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list