[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 18 06:00:55 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9392760b by Salvatore Bonaccorso at 2026-08-18T07:00:34+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -257,17 +257,17 @@ CVE-2026-50775 (A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacke
CVE-2026-50774 (An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate ...)
NOT-FOR-US: GAPTEQ Designer
CVE-2026-50773 (An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 ...)
- TODO: check
+ NOT-FOR-US: CGM Germany - CompuGroup Medical CGM ISIS MED
CVE-2026-50772 (An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker ...)
- TODO: check
+ NOT-FOR-US: Squirro Cognitive Search
CVE-2026-50771 (Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14. ...)
- TODO: check
+ NOT-FOR-US: Squirro Cognitive Search
CVE-2026-50770 (An issue in Squirro Cognitive Search before v.3.14.2 allows a remote a ...)
- TODO: check
+ NOT-FOR-US: Squirro Cognitive Search
CVE-2026-50769 (The CRM+ application before and including version 2025.6 from Brainfor ...)
- TODO: check
+ NOT-FOR-US: Brainformatik
CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH ImageMaster ...)
- TODO: check
+ NOT-FOR-US: T-Systems International GmbH ImageMaster
CVE-2026-49308 (Permission control vulnerability in the clipboard module.Impact: Succe ...)
NOT-FOR-US: Huawei
CVE-2026-49307 (Permission control vulnerability in the multi-mode input module.Impact ...)
@@ -285,17 +285,17 @@ CVE-2026-49302 (Permission control vulnerability in the notification service mod
CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact: Success ...)
NOT-FOR-US: Huawei
CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to version 0.19. ...)
- TODO: check
+ NOT-FOR-US: Kolibri
CVE-2026-46345 (compliance-trestle is a tooling platform for managing compliance as co ...)
- TODO: check
+ NOT-FOR-US: compliance-trestle
CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint Privilege ...)
NOT-FOR-US: BeyondTrust
CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode component of ...)
NOT-FOR-US: BeyondTrust
CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scri ...)
- TODO: check
+ NOT-FOR-US: OutSystems Service Center
CVE-2026-33437 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
- TODO: check
+ NOT-FOR-US: Stirling-PDF
CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
NOT-FOR-US: itsourcecode System
CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import Librar ...)
@@ -309,9 +309,9 @@ CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the
CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially vulnerabl ...)
NOT-FOR-US: HP
CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software Technologies ...)
- TODO: check
+ NOT-FOR-US: Dolusoft Software Technologies Sonlogger
CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software Technologies ...)
- TODO: check
+ NOT-FOR-US: Fortilogger
CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and ...)
NOT-FOR-US: Progress Software
CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and below versi ...)
@@ -319,7 +319,7 @@ CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and below
CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and below, a pa ...)
NOT-FOR-US: Progress Software
CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost G ...)
- TODO: check
+ NOT-FOR-US: Mattermost Plugins
CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10. ...)
- mattermost-server <itp> (bug #823556)
CVE-2026-16047 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
@@ -333,7 +333,7 @@ CVE-2026-16044 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail t
CVE-2026-15754 (Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access cont ...)
- mattermost-server <itp> (bug #823556)
CVE-2026-15218 (A flaw was found in the maas-api and maas-controller ServiceAccounts w ...)
- TODO: check
+ NOT-FOR-US: maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI
CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim Software ...)
TODO: check
CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows Input D ...)
@@ -465,7 +465,7 @@ CVE-2026-19956 (A vulnerability has been found in gomarble-ai facebook-ads-mcp-s
CVE-2026-19955 (A vulnerability was detected in TrailDB 0.6. Impacted is the function ...)
NOT-FOR-US: TrailDB
CVE-2026-15623 (A SQL Injection vulnerability in a legacy dashboard widget API in Goog ...)
- TODO: check
+ NOT-FOR-US: Google Cloud Google SecOps (Chronicle SOAR)
CVE-2026-14832 (The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 d ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13700 (The WooMS WordPress plugin through 9.14 does not validate a user-suppl ...)
@@ -8107,7 +8107,7 @@ CVE-2026-18244 (GitLab has remediated an issue in GitLab EE affecting all versio
CVE-2026-18235 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
NOT-FOR-US: IBM
CVE-2026-18171 (Docker Sandboxes (sbx) applies the read-only intent of a runtime host ...)
- TODO: check
+ NOT-FOR-US: Docker Sandboxes
CVE-2026-18144 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
NOT-FOR-US: IBM
CVE-2026-18106 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
@@ -8611,7 +8611,7 @@ CVE-2026-15039 (The giftware WordPress plugin before 4.2.10 does not validate th
CVE-2026-14925 (The Import WP WordPress plugin before 2.14.23 does not perform any au ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14863 (FileRun up to and including version 2026.2.0 contains an OS command in ...)
- TODO: check
+ NOT-FOR-US: FileRun
CVE-2026-14859 (The WP Crowdfunding WordPress plugin before 2.2.1 does not check the c ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14858 (The WP Crowdfunding WordPress plugin before 2.2.1 does not verify orde ...)
@@ -10979,7 +10979,7 @@ CVE-2026-19517 (Improper Validation of Specified Quantity in Input and Allocatio
NOTE: https://github.com/Samsung/rlottie/pull/596
NOTE: Fixed by: https://github.com/Samsung/rlottie/commit/2cab35db755b0e39df40b679969495e90d39c578
CVE-2026-19516 (A caller-supplied X-Grafana-URL request header controls the destinatio ...)
- TODO: check
+ NOT-FOR-US: mcp-grafana
CVE-2026-19425 (Travel Agency Management System developed by Win Men Intermational has ...)
NOT-FOR-US: Win Men Intermational
CVE-2026-19424 (Chiline Cloud developed by Inventec Appliances has a Insecure Direct O ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9392760b8a5755986ac91c962b55de387d4766b9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9392760b8a5755986ac91c962b55de387d4766b9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/52be6e3d/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list