[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 18 06:00:55 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9392760b by Salvatore Bonaccorso at 2026-08-18T07:00:34+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -257,17 +257,17 @@ CVE-2026-50775 (A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacke
 CVE-2026-50774 (An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate ...)
 	NOT-FOR-US: GAPTEQ Designer
 CVE-2026-50773 (An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20  ...)
-	TODO: check
+	NOT-FOR-US: CGM Germany - CompuGroup Medical CGM ISIS MED
 CVE-2026-50772 (An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker ...)
-	TODO: check
+	NOT-FOR-US: Squirro Cognitive Search
 CVE-2026-50771 (Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14. ...)
-	TODO: check
+	NOT-FOR-US: Squirro Cognitive Search
 CVE-2026-50770 (An issue in Squirro Cognitive Search before v.3.14.2 allows a remote a ...)
-	TODO: check
+	NOT-FOR-US: Squirro Cognitive Search
 CVE-2026-50769 (The CRM+ application before and including version 2025.6 from Brainfor ...)
-	TODO: check
+	NOT-FOR-US: Brainformatik
 CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH ImageMaster  ...)
-	TODO: check
+	NOT-FOR-US: T-Systems International GmbH ImageMaster
 CVE-2026-49308 (Permission control vulnerability in the clipboard module.Impact: Succe ...)
 	NOT-FOR-US: Huawei
 CVE-2026-49307 (Permission control vulnerability in the multi-mode input module.Impact ...)
@@ -285,17 +285,17 @@ CVE-2026-49302 (Permission control vulnerability in the notification service mod
 CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact: Success ...)
 	NOT-FOR-US: Huawei
 CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to version 0.19. ...)
-	TODO: check
+	NOT-FOR-US: Kolibri
 CVE-2026-46345 (compliance-trestle is a tooling platform for managing compliance as co ...)
-	TODO: check
+	NOT-FOR-US: compliance-trestle
 CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint Privilege ...)
 	NOT-FOR-US: BeyondTrust
 CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode component of ...)
 	NOT-FOR-US: BeyondTrust
 CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scri ...)
-	TODO: check
+	NOT-FOR-US: OutSystems Service Center
 CVE-2026-33437 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
-	TODO: check
+	NOT-FOR-US: Stirling-PDF
 CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import Librar ...)
@@ -309,9 +309,9 @@ CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the
 CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially vulnerabl ...)
 	NOT-FOR-US: HP
 CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software Technologies  ...)
-	TODO: check
+	NOT-FOR-US: Dolusoft Software Technologies Sonlogger
 CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software Technologies  ...)
-	TODO: check
+	NOT-FOR-US: Fortilogger
 CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and  ...)
 	NOT-FOR-US: Progress Software
 CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and below versi ...)
@@ -319,7 +319,7 @@ CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and below
 CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and below, a pa ...)
 	NOT-FOR-US: Progress Software
 CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost G ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Plugins
 CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10. ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2026-16047 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
@@ -333,7 +333,7 @@ CVE-2026-16044 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail t
 CVE-2026-15754 (Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access cont ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2026-15218 (A flaw was found in the maas-api and maas-controller ServiceAccounts w ...)
-	TODO: check
+	NOT-FOR-US: maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI
 CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim Software ...)
 	TODO: check
 CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows Input D ...)
@@ -465,7 +465,7 @@ CVE-2026-19956 (A vulnerability has been found in gomarble-ai facebook-ads-mcp-s
 CVE-2026-19955 (A vulnerability was detected in TrailDB 0.6. Impacted is the function  ...)
 	NOT-FOR-US: TrailDB
 CVE-2026-15623 (A SQL Injection vulnerability in a legacy dashboard widget API in Goog ...)
-	TODO: check
+	NOT-FOR-US: Google Cloud Google SecOps (Chronicle SOAR)
 CVE-2026-14832 (The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 d ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13700 (The WooMS WordPress plugin through 9.14 does not validate a user-suppl ...)
@@ -8107,7 +8107,7 @@ CVE-2026-18244 (GitLab has remediated an issue in GitLab EE affecting all versio
 CVE-2026-18235 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
 	NOT-FOR-US: IBM
 CVE-2026-18171 (Docker Sandboxes (sbx) applies the read-only intent of a runtime host  ...)
-	TODO: check
+	NOT-FOR-US: Docker Sandboxes
 CVE-2026-18144 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
 	NOT-FOR-US: IBM
 CVE-2026-18106 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
@@ -8611,7 +8611,7 @@ CVE-2026-15039 (The giftware WordPress plugin before 4.2.10 does not validate th
 CVE-2026-14925 (The Import WP  WordPress plugin before 2.14.23 does not perform any au ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14863 (FileRun up to and including version 2026.2.0 contains an OS command in ...)
-	TODO: check
+	NOT-FOR-US: FileRun
 CVE-2026-14859 (The WP Crowdfunding WordPress plugin before 2.2.1 does not check the c ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14858 (The WP Crowdfunding WordPress plugin before 2.2.1 does not verify orde ...)
@@ -10979,7 +10979,7 @@ CVE-2026-19517 (Improper Validation of Specified Quantity in Input and Allocatio
 	NOTE: https://github.com/Samsung/rlottie/pull/596
 	NOTE: Fixed by: https://github.com/Samsung/rlottie/commit/2cab35db755b0e39df40b679969495e90d39c578
 CVE-2026-19516 (A caller-supplied X-Grafana-URL request header controls the destinatio ...)
-	TODO: check
+	NOT-FOR-US: mcp-grafana
 CVE-2026-19425 (Travel Agency Management System developed by Win Men Intermational has ...)
 	NOT-FOR-US: Win Men Intermational
 CVE-2026-19424 (Chiline Cloud developed by Inventec Appliances has a Insecure Direct O ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9392760b8a5755986ac91c962b55de387d4766b9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9392760b8a5755986ac91c962b55de387d4766b9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/52be6e3d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list