[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 27 09:37:43 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
928488bd by Salvatore Bonaccorso at 2026-08-27T10:37:19+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -68,41 +68,41 @@ CVE-2026-77016 (The Workeera WordPress plugin before 1.0.6 does not restrict wh
CVE-2026-76549 (The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before ...)
NOT-FOR-US: WordPress plugin
CVE-2026-75601 (Static Web Server (SWS) is a production-ready web server suitable for ...)
- TODO: check
+ NOT-FOR-US: Static Web Server (SWS)
CVE-2026-75415 (AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommo ...)
- TODO: check
+ NOT-FOR-US: AntFlow
CVE-2026-75414 (In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL exp ...)
- TODO: check
+ NOT-FOR-US: AntFlow
CVE-2026-75413 (DocSys V2.02.80 is vulnerable to Any File Download. An attacker does n ...)
- TODO: check
+ NOT-FOR-US: DocSys
CVE-2026-75411 (JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNo ...)
- TODO: check
+ NOT-FOR-US: JeecgBoot
CVE-2026-75364 (Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), th ...)
- TODO: check
+ NOT-FOR-US: Comfast
CVE-2026-75363 (An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to e ...)
- TODO: check
+ NOT-FOR-US: Comfast
CVE-2026-75340 (The device metadata import interface /device/instance/{productId}/prop ...)
- TODO: check
+ NOT-FOR-US: jetlinks community
CVE-2026-75338 (disconf (Distributed Configuration Management Platform) 2.6.36 is vuln ...)
- TODO: check
+ NOT-FOR-US: disconf (Distributed Configuration Management Platform)
CVE-2026-75336 (Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool inte ...)
- TODO: check
+ NOT-FOR-US: Funiture
CVE-2026-75334 (The report module in the backend of smart-web2 v1.3.1 is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: smart-web2
CVE-2026-75333 (yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters ...)
- TODO: check
+ NOT-FOR-US: yx-image-recognition
CVE-2026-75332 (Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSR ...)
- TODO: check
+ NOT-FOR-US: Zyplayer-Doc
CVE-2026-75331 (tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stor ...)
- TODO: check
+ NOT-FOR-US: tamguo
CVE-2026-75330 (The front-end interface /superdiamond/preview/{projectCode}/{module}/{ ...)
- TODO: check
+ NOT-FOR-US: super-diamond
CVE-2026-75329 (The Netty configuration distribution service (port 8283) of super-diam ...)
TODO: check
CVE-2026-75328 (In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocS ...)
- TODO: check
+ NOT-FOR-US: DocSys
CVE-2026-75327 (In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/ ...)
- TODO: check
+ NOT-FOR-US: DocSys
CVE-2026-74774 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Imprope ...)
NOT-FOR-US: Dell / EMC
CVE-2026-74771 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authori ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/928488bd375693632c663f74f7b358f6251b8dca
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/928488bd375693632c663f74f7b358f6251b8dca
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/5130b4d1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list