[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 28 13:42:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
57ed816c by Salvatore Bonaccorso at 2026-08-28T11:20:31+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -813,7 +813,7 @@ CVE-2026-78103 (WatchGuard Dimension provides a client-side lock/unlock UI contr
CVE-2026-78047 (A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimens ...)
NOT-FOR-US: WatchGuard
CVE-2026-78037 (Xiiaozet LK100W is vulnerable to OS command injection through its web ...)
- TODO: check
+ NOT-FOR-US: Xiiaozet LK100W
CVE-2026-78011 (An integer underflow vulnerability in the WatchGuard Fireware OS iked ...)
NOT-FOR-US: WatchGuard
CVE-2026-78010 (A stack-based buffer overflow vulnerability in the WatchGuard Fireware ...)
@@ -823,9 +823,9 @@ CVE-2026-78009 (An out-of-bounds read vulnerability in the WatchGuard Fireware O
CVE-2026-78008 (A buffer overflow vulnerability in the WatchGuard Fireware OS Manageme ...)
NOT-FOR-US: WatchGuard
CVE-2026-77977 (Ebyte gateway product's vendor configuration utility does not require ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-77438 (Trilium is an open-source hierarchical note-taking application. In ver ...)
- TODO: check
+ NOT-FOR-US: Trilium Notes
CVE-2026-77365 (The Optimole \u2013 Optimize Images | Convert WebP & AVIF | CDN & Lazy ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77358 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33. ...)
@@ -833,17 +833,17 @@ CVE-2026-77358 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions
CVE-2026-77341 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0 ...)
TODO: check
CVE-2026-76945 (The affected Ebyte device relies on client-managed authentication toke ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-76943 (Xiiaozet LK100Wt contains an authentication weakness within an admini ...)
- TODO: check
+ NOT-FOR-US: Xiiaozet LK100Wt
CVE-2026-76940 (The affected Ebyte device does not restrict repeated authentication a ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-76640 (Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulner ...)
- TODO: check
+ NOT-FOR-US: Unitree G1 EDU firmware
CVE-2026-76639 (Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remo ...)
- TODO: check
+ NOT-FOR-US: Unitree G1 EDU firmware
CVE-2026-76179 (An improper protection of authentication tokens vulnerability exists i ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-76060 (An authenticated OS command injection vulnerability exists in ZoneMind ...)
TODO: check
CVE-2026-76053 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
@@ -851,33 +851,33 @@ CVE-2026-76053 (The TranslatePress \u2013 Translate Multilingual sites with AI T
CVE-2026-75889 (Grafana Alloy\u2019s prometheus.operator.servicemonitors component all ...)
TODO: check
CVE-2026-75814 (The Ebyte device does not adequately verify the origin or authenticity ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-75813 (Certain configuration endpoints may lack proper server-side authoriza ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-75548 (The affected Ebyte device web management interface does not restrict t ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-75419 (go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerab ...)
- TODO: check
+ NOT-FOR-US: go-wind-cms (GoWind)
CVE-2026-75418 (A path traversal vulnerability exists in the built-in preview/developm ...)
- TODO: check
+ NOT-FOR-US: Lektor CMS
CVE-2026-75417 (A SQL injection vulnerability was found in YzmCMS 7.5. The issue occur ...)
- TODO: check
+ NOT-FOR-US: YzmCMS
CVE-2026-75339 (The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing ...)
- TODO: check
+ NOT-FOR-US: cjbi admin3
CVE-2026-75337 (The static resource interface /api/static/{deployKey}/ of Yu AI Code M ...)
- TODO: check
+ NOT-FOR-US: Yu AI Code Mother
CVE-2026-74820 (ServiceNow has remediated a SQL injection vulnerability that was ident ...)
NOT-FOR-US: ServiceNow
CVE-2026-73839 (Administrative credentials may be exposed in plaintext within the Ebyt ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-73809 (A cleartext transmission of sensitive information vulnerability exists ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-73125 (Ebyte device web management interface does not consistently enforce a ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-71396 (Bendix EC80 Brake ECUuses hard-coded credentials, which could allow an ...)
- TODO: check
+ NOT-FOR-US: Bendix EC80 Brake ECU
CVE-2026-71187 (The Ebyte device relies on client side authentication logic that can b ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-6876 (ServiceNow has remediated a sandbox escape security issue that was ide ...)
NOT-FOR-US: ServiceNow
CVE-2026-69658 (MQTT credentials and control traffic are transmitted in cleartext, ex ...)
@@ -1874,7 +1874,7 @@ CVE-2026-75331 (tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading t
CVE-2026-75330 (The front-end interface /superdiamond/preview/{projectCode}/{module}/{ ...)
NOT-FOR-US: super-diamond
CVE-2026-75329 (The Netty configuration distribution service (port 8283) of super-diam ...)
- TODO: check
+ NOT-FOR-US: super-diamond-server
CVE-2026-75328 (In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocS ...)
NOT-FOR-US: DocSys
CVE-2026-75327 (In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/ ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/57ed816c251470a00417fc14b685fa944ca652fe
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/57ed816c251470a00417fc14b685fa944ca652fe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/b7e83326/attachment.htm>
More information about the debian-security-tracker-commits
mailing list