[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 27 09:37:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
928488bd by Salvatore Bonaccorso at 2026-08-27T10:37:19+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -68,41 +68,41 @@ CVE-2026-77016 (The Workeera  WordPress plugin before 1.0.6 does not restrict wh
 CVE-2026-76549 (The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75601 (Static Web Server (SWS) is a production-ready web server suitable for  ...)
-	TODO: check
+	NOT-FOR-US: Static Web Server (SWS)
 CVE-2026-75415 (AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommo ...)
-	TODO: check
+	NOT-FOR-US: AntFlow
 CVE-2026-75414 (In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL exp ...)
-	TODO: check
+	NOT-FOR-US: AntFlow
 CVE-2026-75413 (DocSys V2.02.80 is vulnerable to Any File Download. An attacker does n ...)
-	TODO: check
+	NOT-FOR-US: DocSys
 CVE-2026-75411 (JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNo ...)
-	TODO: check
+	NOT-FOR-US: JeecgBoot
 CVE-2026-75364 (Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), th ...)
-	TODO: check
+	NOT-FOR-US: Comfast
 CVE-2026-75363 (An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to e ...)
-	TODO: check
+	NOT-FOR-US: Comfast
 CVE-2026-75340 (The device metadata import interface /device/instance/{productId}/prop ...)
-	TODO: check
+	NOT-FOR-US: jetlinks community
 CVE-2026-75338 (disconf (Distributed Configuration Management Platform) 2.6.36 is vuln ...)
-	TODO: check
+	NOT-FOR-US: disconf (Distributed Configuration Management Platform)
 CVE-2026-75336 (Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool inte ...)
-	TODO: check
+	NOT-FOR-US: Funiture
 CVE-2026-75334 (The report module in the backend of smart-web2 v1.3.1 is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: smart-web2
 CVE-2026-75333 (yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters  ...)
-	TODO: check
+	NOT-FOR-US: yx-image-recognition
 CVE-2026-75332 (Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSR ...)
-	TODO: check
+	NOT-FOR-US: Zyplayer-Doc
 CVE-2026-75331 (tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stor ...)
-	TODO: check
+	NOT-FOR-US: tamguo
 CVE-2026-75330 (The front-end interface /superdiamond/preview/{projectCode}/{module}/{ ...)
-	TODO: check
+	NOT-FOR-US: super-diamond
 CVE-2026-75329 (The Netty configuration distribution service (port 8283) of super-diam ...)
 	TODO: check
 CVE-2026-75328 (In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocS ...)
-	TODO: check
+	NOT-FOR-US: DocSys
 CVE-2026-75327 (In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/ ...)
-	TODO: check
+	NOT-FOR-US: DocSys
 CVE-2026-74774 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Imprope ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-74771 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authori ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/928488bd375693632c663f74f7b358f6251b8dca

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/928488bd375693632c663f74f7b358f6251b8dca
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/5130b4d1/attachment.htm>


More information about the debian-security-tracker-commits mailing list