[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 22 13:39:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0d898e63 by Salvatore Bonaccorso at 2026-08-22T14:37:17+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -105,7 +105,7 @@ CVE-2026-63421 (Keystone is a content management system for Node.js. Prior to 6.
CVE-2026-63135 (YOURLS is a self-hosted, customizable URL shortener written in PHP. Fr ...)
NOT-FOR-US: YOURLS
CVE-2026-62960 (Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, ...)
- TODO: check
+ NOT-FOR-US: Git for Windows
CVE-2026-62316 (Microsoft UFO open-source framework for intelligent automation across ...)
NOT-FOR-US: Microsoft UFO
CVE-2026-62283 (Nezha Monitoring is a self-hostable, lightweight, servers and websites ...)
@@ -5067,7 +5067,7 @@ CVE-2026-52873 (Streambert is a cross-platform Electron Desktop App to stream an
CVE-2026-52872 (Streambert is a cross-platform Electron Desktop App to stream and down ...)
NOT-FOR-US: Streambert
CVE-2026-52854 (Maps is a MediaWiki extension that enables visualization of geographic ...)
- TODO: check
+ NOT-FOR-US: Maps MediaWiki extension
CVE-2026-52829 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an una ...)
NOT-FOR-US: ZEBRA
CVE-2026-52817 (Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, ...)
@@ -6828,7 +6828,7 @@ CVE-2026-15748 (The Forminator Forms plugin for WordPress is vulnerable to Arbit
CVE-2026-15371 (Velociraptor's web GUI allows specifying a custom type for columns in ...)
NOT-FOR-US: Rapid7
CVE-2026-11817 (This vulnerability only affects Grafana stacks configured with multipl ...)
- TODO: check
+ NOT-FOR-US: Grafana
CVE-2026-11801 (The WPAdverts \u2013 Classifieds Plugin plugin for WordPress is vulner ...)
NOT-FOR-US: WordPress plugin
CVE-2026-10080 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
@@ -18547,7 +18547,7 @@ CVE-2026-13206 (Improper neutralization of special elements used in an OS comman
CVE-2026-12984 (Insufficiently Protected Credentials vulnerability in Zyxel Networks W ...)
NOT-FOR-US: Zyxel
CVE-2026-12624 (Vault\u2019s ACL policy engine did not consistently enforce a wildcard ...)
- TODO: check
+ NOT-FOR-US: HashiCorp
CVE-2026-12339 (A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows ...)
NOT-FOR-US: TPLink
CVE-2026-10754 (Pega Platform versions 8.5.0 through 25.1.2 are affected by an imprope ...)
@@ -20650,7 +20650,7 @@ CVE-2026-13600 (The AutoNetTV Relay WordPress plugin before 3.0.14 does not perf
CVE-2026-13170 (The Eventin WordPress plugin before 4.1.20 does not properly validate ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13133 (A vulnerability has been identified in LineInst.exe (LINE for Windows) ...)
- TODO: check
+ NOT-FOR-US: LineInst.exe (LINE for Windows)
CVE-2026-12971 (The LearnPress WordPress plugin before 4.4.4 does not validate a user ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12570 (A vulnerability in keras-team/keras versions <= 3.15.0 allows for a de ...)
@@ -23094,7 +23094,7 @@ CVE-2026-71265 (Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC message
CVE-2026-71264 (WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) c ...)
NOT-FOR-US: WLED
CVE-2026-71263 (The LINUXTCP port of FreeModbus contains an off-by-one bounds check in ...)
- TODO: check
+ NOT-FOR-US: FreeModbus
CVE-2026-71262 (IoTSharp BlobStorageController.cs lacks the [Authorize] attribute appl ...)
NOT-FOR-US: IoTSharp
CVE-2026-71261 (dr_libs dr_wav.h (all versions through current master) contains an int ...)
@@ -23484,7 +23484,7 @@ CVE-2026-14587 (Neo4j's Bolt modern handshake decoder treats an overlong capabil
CVE-2026-14574 (In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `Pr ...)
NOT-FOR-US: Eclipse
CVE-2026-14304 (In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 ( ...)
- TODO: check
+ NOT-FOR-US: Eclipse Accessibility Tools Framework (ACTF)
CVE-2026-13477 (IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Inte ...)
NOT-FOR-US: IBM
CVE-2026-12762 (IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d898e6323e9aa334b012e5b5f330190dd329b26
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d898e6323e9aa334b012e5b5f330190dd329b26
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/3dd1ebfd/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list