[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 19 21:29:17 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
caf2ddb4 by Salvatore Bonaccorso at 2026-08-19T22:28:47+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -66,35 +66,35 @@ CVE-2026-76217 (GitPython versions before 3.1.58 fail to validate options passed
- python-git <unfixed>
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc
CVE-2026-76216 (Vikunja through 2.4.0 contains a principal-type confusion vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Vikunja
CVE-2026-76215 (phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks befo ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76214 (phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist th ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76213 (phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two- ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76212 (phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the nativ ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76211 (phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT per ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76210 (phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ answers ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76209 (phpMyFAQ versions before v4.1.6 fail to validate the security.enableRe ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76208 (phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76207 (phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vuln ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76206 (phpMyFAQ versions before 4.1.7 fail to validate active status in the P ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76205 (phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the gl ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-76203 (Incorrect Behavior Order: Validate Before Canonicalize in the report t ...)
- TODO: check
+ NOT-FOR-US: maalfer Pentestify
CVE-2026-76166 (A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.mod ...)
- TODO: check
+ NOT-FOR-US: Red Hat org.jboss.modcluster core module
CVE-2026-76164 (AIL Framework contains a server-side request forgery (SSRF) vulnerabil ...)
- TODO: check
+ NOT-FOR-US: AIL framework
CVE-2026-75956 (Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter ...)
NOT-FOR-US: Joomla
CVE-2026-75955 (Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J- ...)
@@ -112,11 +112,11 @@ CVE-2026-75950 (Joomla Extension - cmsjunkie.com - Unauthenticated listing owner
CVE-2026-75949 (Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion ( ...)
NOT-FOR-US: Joomla
CVE-2026-75920 (phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-a ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-75919 (phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-75918 (phpMyFAQ before 4.1.7 stores password reset tokens in a publicly acces ...)
- TODO: check
+ NOT-FOR-US: phpMyFAQ
CVE-2026-75917 (SiYuan before v3.7.4 contains a cross-site scripting vulnerability in ...)
NOT-FOR-US: SiYuan
CVE-2026-75916 (SiYuan through 3.7.3 contains a cross-site scripting vulnerability in ...)
@@ -126,11 +126,11 @@ CVE-2026-75619 (Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerab
CVE-2026-75618 (Tapo C100/C101 V5 contains a null pointer dereference vulnerability in ...)
NOT-FOR-US: TPLink
CVE-2026-75583 (keeper.sh's calendar module version prior to 2.18.14 contains a server ...)
- TODO: check
+ NOT-FOR-US: keeper.sh
CVE-2026-75149 (marimo before 0.23.15 contains a code injection vulnerability in the n ...)
- TODO: check
+ NOT-FOR-US: marimo
CVE-2026-75148 (cgltf through 1.15 contains an integer overflow vulnerability in the n ...)
- TODO: check
+ NOT-FOR-US: cgltf
CVE-2026-75147 (FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 ...)
TODO: check
CVE-2026-75146 (FFmpeg before commit 65b0dab contains an out-of-bounds read in the DAS ...)
@@ -152,9 +152,9 @@ CVE-2026-74804 (Joomla Extension - yootheme.com - Unauthenticated SQL injection
CVE-2026-74803 (Joomla Extension - yootheme.com - Unauthenticated arbitrary file uploa ...)
NOT-FOR-US: Joomla
CVE-2026-73829 (Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allow ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-73541 (Allocation of Resources Without Limits or Throttling in ZenHive mpp al ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-73394 (Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versi ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73391 (Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.)
@@ -190,41 +190,41 @@ CVE-2026-73183 (Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 version
CVE-2026-73182 (Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73136 (Authentication Bypass by Capture-replay in ZenHive mpp allows an unaut ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-72717 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-72716 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-72530 (A remote unauthorized attacker with network access via port 4307/TCP t ...)
- TODO: check
+ NOT-FOR-US: TrueConf server
CVE-2026-72529 (A remote unauthorized attacker with network access via port 4307/TCP t ...)
- TODO: check
+ NOT-FOR-US: TrueConf server
CVE-2026-71961 (Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command ...)
- TODO: check
+ NOT-FOR-US: Cudy
CVE-2026-71960 (Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded J ...)
- TODO: check
+ NOT-FOR-US: Cudy
CVE-2026-71871 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-71869 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-71868 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-71867 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-71866 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-71865 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-71864 (Orval generates type-safe JavaScript clients in TypeScript from OpenAP ...)
- TODO: check
+ NOT-FOR-US: Orval
CVE-2026-71694 (An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchm ...)
- TODO: check
+ NOT-FOR-US: Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark
CVE-2026-71470 (A flaw was found in the search-v2-operator. This vulnerability allows ...)
- TODO: check
+ NOT-FOR-US: search-v2-operator
CVE-2026-71176 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
NOT-FOR-US: Dell / EMC
CVE-2026-70496 (A flaw was found in search-v2-operator. The operator's ClusterRole has ...)
- TODO: check
+ NOT-FOR-US: search-v2-operator
CVE-2026-70424 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
NOT-FOR-US: Dell / EMC
CVE-2026-70423 (Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Impro ...)
@@ -1814,7 +1814,7 @@ CVE-2026-70668 (Vulnerability in the Oracle Reports Developer product of Oracle
CVE-2026-70666 (Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-r ...)
TODO: check
CVE-2026-70408 (An incorrect authorization vulnerability exists in acmailer, which may ...)
- TODO: check
+ NOT-FOR-US: acmailer
CVE-2026-67443 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
TODO: check
CVE-2026-67442 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/caf2ddb462b80d0ec0e1eddbfff82b4822a4f664
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/caf2ddb462b80d0ec0e1eddbfff82b4822a4f664
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/4564c8b8/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list