[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 19 21:59:12 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8dd812f4 by Salvatore Bonaccorso at 2026-08-19T22:58:48+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -260,7 +260,7 @@ CVE-2026-69159 (FreeRDP is a free implementation of the Remote Desktop Protocol.
- freerdp2 <removed>
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qrxx-7g3c-j6w3
CVE-2026-67581 (Authentication Bypass by Capture-replay in ZenHive mpp allows an unaut ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-67364 (Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balboo ...)
NOT-FOR-US: Joomla
CVE-2026-67363 (Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in ...)
@@ -272,7 +272,7 @@ CVE-2026-67267 (Dell Command Update (DCU), versions prior to 5.7.1, contain an E
CVE-2026-67266 (Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorre ...)
NOT-FOR-US: Dell / EMC
CVE-2026-66794 (A flaw was found in the `cluster-proxy-addon` component of Multicluste ...)
- TODO: check
+ NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
CVE-2026-66668 (Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66613 (Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 ver ...)
@@ -288,11 +288,11 @@ CVE-2026-65610 (nnn stores homelen variable as uchar_t, which can only represent
CVE-2026-65609 (nnn is vulnerable to Out-of-Bound write vulnerability.Due to lack of v ...)
TODO: check
CVE-2026-64852 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-64851 (Grav Shortcode Core Plugin allows for the development shortcode plugin ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-64850 (Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dyn ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-63652 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
TODO: check
CVE-2026-63633 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
@@ -1840,11 +1840,11 @@ CVE-2026-70666 (Lemur manages TLS certificate creation. Prior to 1.9.3, an autho
CVE-2026-70408 (An incorrect authorization vulnerability exists in acmailer, which may ...)
NOT-FOR-US: acmailer
CVE-2026-67443 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
- TODO: check
+ NOT-FOR-US: FUXA
CVE-2026-67442 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
- TODO: check
+ NOT-FOR-US: FUXA
CVE-2026-67440 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
- TODO: check
+ NOT-FOR-US: FUXA
CVE-2026-66603 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66602 (Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar \u ...)
@@ -1854,11 +1854,11 @@ CVE-2026-66591 (Improper Neutralization of Input During Web Page Generation ('Cr
CVE-2026-66589 (Missing Authorization vulnerability in Kings Plugins B2BKing allows Ex ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66358 (A cross-site scripting vulnerability exists in acmailer, which may all ...)
- TODO: check
+ NOT-FOR-US: acmailer
CVE-2026-65985 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
- TODO: check
+ NOT-FOR-US: FUXA
CVE-2026-65984 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
- TODO: check
+ NOT-FOR-US: FUXA
CVE-2026-62988 (Froxlor is open source server administration software. From 2.3.7 unti ...)
TODO: check
CVE-2026-62640 (Vulnerability in the Oracle Reports Developer product of Oracle Fusion ...)
@@ -3506,13 +3506,13 @@ CVE-2026-68939 (Pyenv provides simple Python version management. Prior to 2.8.0,
NOTE: https://github.com/pyenv/pyenv/security/advisories/GHSA-g478-f579-9vp9
NOTE: Fixed by: https://github.com/pyenv/pyenv/commit/95df7dbc7b34595b47c9b922de198547effda819 (v2.8.0)
CVE-2026-68927 (MobSF is a mobile application security testing tool used. Prior to 4.5 ...)
- TODO: check
+ NOT-FOR-US: MobSF
CVE-2026-68924 (MobSF is a mobile application security testing tool used. Prior to 4.5 ...)
- TODO: check
+ NOT-FOR-US: MobSF
CVE-2026-68923 (MobSF is a mobile application security testing tool used. Prior to 4.5 ...)
- TODO: check
+ NOT-FOR-US: MobSF
CVE-2026-68922 (MobSF is a mobile application security testing tool used. Prior to 4.5 ...)
- TODO: check
+ NOT-FOR-US: MobSF
CVE-2026-68568 (Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-68567 (Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 ver ...)
@@ -3520,9 +3520,9 @@ CVE-2026-68567 (Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0
CVE-2026-68565 (Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 vers ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-67921 (Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS ver ...)
- TODO: check
+ NOT-FOR-US: Halo CMS
CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary ...)
- TODO: check
+ NOT-FOR-US: Halo CMS
CVE-2026-67846 (Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb ...)
TODO: check
CVE-2026-67271 (Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability i ...)
@@ -3584,7 +3584,7 @@ CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability caused ...)
TODO: check
CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling of MySQL ...)
- TODO: check
+ NOT-FOR-US: Vitess
CVE-2026-63643 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)
TODO: check
CVE-2026-63642 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)
@@ -4060,43 +4060,43 @@ CVE-2026-68765 (hashcat master branch builds after v7.1.2 contain a heap buffer
CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to ...)
TODO: check
CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remo ...)
- TODO: check
+ NOT-FOR-US: OSSRS SRS (Simple Realtime Server)
CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an ...)
NOT-FOR-US: Tenda
CVE-2026-67966 (Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthentic ...)
NOT-FOR-US: Tenda
CVE-2026-67965 (An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to e ...)
- TODO: check
+ NOT-FOR-US: Tneda W20E
CVE-2026-67961 (An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary ...)
- TODO: check
+ NOT-FOR-US: O2OA
CVE-2026-67960 (An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary ...)
- TODO: check
+ NOT-FOR-US: PbootCMS
CVE-2026-67926 (An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbi ...)
- TODO: check
+ NOT-FOR-US: JeecgBoot
CVE-2026-67925 (Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remot ...)
- TODO: check
+ NOT-FOR-US: JeecgBoot
CVE-2026-67919 (An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary ...)
- TODO: check
+ NOT-FOR-US: Halo CMS
CVE-2026-67918 (Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a r ...)
- TODO: check
+ NOT-FOR-US: hermes-studio
CVE-2026-67917 (zuraCast versions up to and including 0.23.7 contain a SQL injection v ...)
- TODO: check
+ NOT-FOR-US: AzuraCast
CVE-2026-67868 (A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 i ...)
- TODO: check
+ NOT-FOR-US: Systerel S2OPC
CVE-2026-67854 (SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker t ...)
- TODO: check
+ NOT-FOR-US: Qcms
CVE-2026-67678 (File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a ...)
- TODO: check
+ NOT-FOR-US: RainyGao-Hithub DocSys
CVE-2026-66795 (A flaw was found in the managedcluster-import-controller. The Certific ...)
NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
CVE-2026-65976 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 until contin ...)
TODO: check
CVE-2026-65974 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
- TODO: check
+ NOT-FOR-US: ERPNext
CVE-2026-65832 (Deskflow is a keyboard and mouse sharing app. Prior to continuous buil ...)
TODO: check
CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
- TODO: check
+ NOT-FOR-US: ERPNext
CVE-2026-65640 (WordPress is vulnerable to a remote code execution vulnerability via m ...)
TODO: check
CVE-2026-65351 (This issue was addressed through improved state management. This issue ...)
@@ -4158,13 +4158,13 @@ CVE-2026-64760 (An information leakage was addressed with additional validation.
CVE-2026-64715 (A use-after-free issue was addressed with improved memory management. ...)
NOT-FOR-US: Apple
CVE-2026-64657 (Budibase is an open-source low-code platform. Prior to 3.39.19, the Po ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-63670 (ApostropheCMS is an open-source Node.js content management system. Pri ...)
- TODO: check
+ NOT-FOR-US: ApostropheCMS
CVE-2026-63669 (ApostropheCMS is an open-source Node.js content management system. Pri ...)
- TODO: check
+ NOT-FOR-US: ApostropheCMS
CVE-2026-63667 (ApostropheCMS is an open-source Node.js content management system. Pri ...)
- TODO: check
+ NOT-FOR-US: ApostropheCMS
CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 until contin ...)
TODO: check
CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Ed ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8dd812f45b8504bd3aa95d2f970cc39b384c9467
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8dd812f45b8504bd3aa95d2f970cc39b384c9467
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/befab263/attachment.htm>
More information about the debian-security-tracker-commits
mailing list