[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 15:32:30 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
19e18b55 by Salvatore Bonaccorso at 2026-08-26T16:32:17+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1360,9 +1360,9 @@ CVE-2026-38466 (A Stored XSS vulnerability in the torrent remaster custom title
 CVE-2026-38465 (A Stored XSS vulnerability in the donor avatar mouse-over text feature ...)
 	NOT-FOR-US: GazellePW
 CVE-2026-32637 (Velero is an open source tool for backing up, restoring, and migrating ...)
-	TODO: check
+	NOT-FOR-US: Velero
 CVE-2026-29988 (A cleartext transmission of sensitive information vulnerability in the ...)
-	TODO: check
+	NOT-FOR-US: Milesight
 CVE-2026-19760 (The WP Fastest Cache \u2013 WordPress Cache Plugin plugin for WordPres ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19718 (The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare W ...)
@@ -1414,11 +1414,11 @@ CVE-2026-15917 (Improper Neutralization of Input During Web Page Generation ("Cr
 CVE-2026-15916 (Missing Authorization vulnerability in Drupal Drupal core allows Force ...)
 	NOT-FOR-US: Drupal core and addons
 CVE-2026-15366 (A control logic defect in a specific built-in webpage of Kids Mode all ...)
-	TODO: check
+	NOT-FOR-US: Vivo
 CVE-2026-15365 (A pop-up logic flaw in a certain feature of Kids Mode allows users to  ...)
-	TODO: check
+	NOT-FOR-US: Vivo
 CVE-2026-15203 (Improper access control in debug and engineering interfaces in Danfoss ...)
-	TODO: check
+	NOT-FOR-US: Danfoss
 CVE-2026-15088 (Vulnerability in Drupal Development Environment. This issue affects De ...)
 	NOT-FOR-US: Drupal core and addons
 CVE-2026-14550 (The WPCafe  WordPress plugin before 3.0.18 does not perform an authori ...)
@@ -1944,7 +1944,7 @@ CVE-2026-47626 (NVIDIA DGX Spark contains a vulnerability in the system firmware
 CVE-2026-47624 (NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may ...)
 	NOT-FOR-US: NVIDIA
 CVE-2026-26211 (Ekushey Project Manager CRM stores the administrator-configured system ...)
-	TODO: check
+	NOT-FOR-US: Ekushey Project Manager CRM
 CVE-2026-24263 (NVIDIA DGX Spark contains a vulnerability in the system firmware, wher ...)
 	NOT-FOR-US: NVIDIA
 CVE-2026-24262 (NVIDIA DGX Spark contains a vulnerability in the system firmware, wher ...)
@@ -1970,9 +1970,9 @@ CVE-2026-21753 (HCL Hive is affected by weak software supply chain governance, w
 CVE-2026-19949 (The All-in-One WP Migration and Backup plugin for WordPress is vulnera ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19913 (The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file di ...)
-	TODO: check
+	NOT-FOR-US: Kaltura HTML5 player
 CVE-2026-19912 (The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthentica ...)
-	TODO: check
+	NOT-FOR-US: Kaltura HTML5 player
 CVE-2026-19851 (A Use of Default Password vulnerability affecting Tuleap Enterprise Ed ...)
 	NOT-FOR-US: Dassault Systemes
 CVE-2026-18547 (The Ultimate Member \u2013 User Profile, Registration, Login, Member D ...)
@@ -1998,7 +1998,7 @@ CVE-2026-16601 (The CM Map Locations \u2013 Visualize and share your locations i
 CVE-2026-16599 (GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY auth ...)
 	TODO: check
 CVE-2026-16286 (Unrestricted upload of file with dangerous type vulnerability in TRtek ...)
-	TODO: check
+	NOT-FOR-US: TRtek Software Repository Management
 CVE-2026-16234 (There is a memory corruption vulnerability recently discovered in NI L ...)
 	NOT-FOR-US: National Instruments
 CVE-2026-16233 (There is a memory corruption vulnerability recently discovered in NI L ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/19e18b55786f3ec93ff7e7a6f00db3ddaa91d3d4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/19e18b55786f3ec93ff7e7a6f00db3ddaa91d3d4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/e8fb4b21/attachment.htm>


More information about the debian-security-tracker-commits mailing list