[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 28 21:50:28 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
90d12d8c by Salvatore Bonaccorso at 2026-08-28T22:50:02+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -154,7 +154,7 @@ CVE-2026-76581 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to Aut
CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard library al ...)
TODO: check
CVE-2026-73827 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
- TODO: check
+ NOT-FOR-US: SOY
CVE-2026-73209 (An attacker that has valid credentials can send crafted compressed dat ...)
- dovecot <unfixed>
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73209-imap-login-crash-self-recursion-on-zero-output-decompress-chunks
@@ -172,7 +172,7 @@ CVE-2026-5953 (Improper neutralization of input during web page generation ('cro
CVE-2026-5934 (The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site ...)
NOT-FOR-US: WordPress plugin
CVE-2026-5800 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: ayneks Software Industry and Trade Inc. E-Commerce Platform
CVE-2026-5510 (The GiveWP \u2013 Donation Plugin and Fundraising Platform plugin for ...)
NOT-FOR-US: WordPress plugin
CVE-2026-5097 (The wpForo Forum plugin for WordPress is vulnerable to SQL Injection v ...)
@@ -192,9 +192,9 @@ CVE-2026-52681 (Sieve CPU resource usage is tracked in the compiled script, so a
- dovecot <unfixed>
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52681-sieve-resource-usage-tracking-lost-when-active-script-changes
CVE-2026-50979 (A command injection vulnerability in the 'advanced/curl' component of ...)
- TODO: check
+ NOT-FOR-US: Osbil Technology oPanel
CVE-2026-4378 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: Akilli Ticaret Software TechnologiesLtd. E-Commerce Pack
CVE-2026-4246 (The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross ...)
NOT-FOR-US: WordPress plugin
CVE-2026-42395 (A host listed as a trusted proxy can send forwarding information conta ...)
@@ -247,7 +247,7 @@ CVE-2026-40013 (An attacker that has valid credentials can submit a Sieve script
CVE-2026-3423 (The Envira Gallery plugin for WordPress is vulnerable to Stored Cross- ...)
NOT-FOR-US: WordPress plugin
CVE-2026-38725 (xipblog module v2.0.1 and before for PrestaShop allows unauthenticated ...)
- TODO: check
+ NOT-FOR-US: PrestaShop module
CVE-2026-38638 (An issue in the with_argv function (/unistd/mod.rs) of relibc commit 6 ...)
TODO: check
CVE-2026-38636 (An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 6 ...)
@@ -255,11 +255,11 @@ CVE-2026-38636 (An issue in the seekdir() function (/dirent/mod.rs) of relibc co
CVE-2026-38093 (file_picker (aka flutter_file_picker) for Flutter, all versions throug ...)
TODO: check
CVE-2026-37751 (An OS command injection vulnerability in the killSessionSync function ...)
- TODO: check
+ NOT-FOR-US: 23blocks-OS ai-maestro
CVE-2026-37736 (An issue in the JsonSanitizer.sanitize() component of OWASP json-sanit ...)
TODO: check
CVE-2026-37710 (Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote ...)
- TODO: check
+ NOT-FOR-US: Omeka S
CVE-2026-37237 (vLLM up to and including 0.17.0 allows remote attackers to cause a Den ...)
TODO: check
CVE-2026-37236 (grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The ap ...)
@@ -1357,39 +1357,39 @@ CVE-2026-38343 (An integer overflow in the libavfilter/vf_scale.c component of F
CVE-2026-37198 (An integer overflow in the SMF component of Open5GS v2.7.6 allows atta ...)
TODO: check
CVE-2026-37073 (Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37072 (Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerabl ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37071 (Arbitrary File Rename Leading to Privilege Escalation in Actions::rena ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37070 (Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37069 (Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativ ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37068 (Arbitrary file write in /vfm-admin/index.php?section=translations&acti ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37067 (Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php i ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37066 (Path traversal leading to Arbitrary File Read in /vfm-admin/index.php ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37065 (Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deleti ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37064 (User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager ...)
- TODO: check
+ NOT-FOR-US: Veno File Manager Project
CVE-2026-37012 (A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 all ...)
- TODO: check
+ NOT-FOR-US: PentestGPT
CVE-2026-37009 (A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 ...)
- TODO: check
+ NOT-FOR-US: crewai-tools
CVE-2026-37007 (A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows ...)
- TODO: check
+ NOT-FOR-US: crewai-tools
CVE-2026-37006 (A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 an ...)
- TODO: check
+ NOT-FOR-US: gpt-researcher
CVE-2026-37004 (BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injecti ...)
- TODO: check
+ NOT-FOR-US: BerriAI litellm
CVE-2026-37003 (Agno up to and including 2.5.8 is vulnerable to Remote Code Execution ...)
- TODO: check
+ NOT-FOR-US: Agno
CVE-2026-36102 (An issue in the inviteController.js component in Bluewave Labs Checkma ...)
- TODO: check
+ NOT-FOR-US: Bluewave Labs Checkmate
CVE-2026-35869 (A Command Injection vulnerability exists in the bs_SetLimitCli_info fu ...)
TODO: check
CVE-2026-35868 (A Command Injection vulnerability exists in the bs_SetLimitCli_info fu ...)
@@ -1399,9 +1399,9 @@ CVE-2026-34620 (DNG SDK versions 1.7.1 2502 and earlier are affected by an out-o
CVE-2026-34616 (DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-boun ...)
NOT-FOR-US: Adobe
CVE-2026-30612 (An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for ...)
- TODO: check
+ NOT-FOR-US: Time4Popcorn
CVE-2026-25250 (EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missin ...)
- TODO: check
+ NOT-FOR-US: EAZ EazyFix
CVE-2026-19318 (A stack-based buffer overflow vulnerability in the WatchGuard Fireware ...)
NOT-FOR-US: WatchGuard
CVE-2026-19317 (An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked ...)
@@ -2377,17 +2377,17 @@ CVE-2026-45694 (LibreNMS is a network monitoring system. In versions up to and i
CVE-2026-43621 (Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, co ...)
NOT-FOR-US: Simple Machines Forum (SMF)
CVE-2026-39275 (Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before ...)
- TODO: check
+ NOT-FOR-US: Cockpit CMS
CVE-2026-26449 (In Stomper 5e2741e when a client sends a SEND frame missing the destin ...)
- TODO: check
+ NOT-FOR-US: Stomper
CVE-2026-26448 (Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends m ...)
- TODO: check
+ NOT-FOR-US: Stomper
CVE-2026-26447 (Stomper 5e2741e is vulnerable to Use-After-Free. When a single client ...)
- TODO: check
+ NOT-FOR-US: Stomper
CVE-2026-26446 (Stomper 5e2741e is vulnerable to Denial of Service. When a broker send ...)
- TODO: check
+ NOT-FOR-US: Stomper
CVE-2026-26445 (stomper 5e2741e is vulnerable to Denial of Service. A malicious client ...)
- TODO: check
+ NOT-FOR-US: Stomper
CVE-2026-21810 (HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external r ...)
NOT-FOR-US: HCL
CVE-2026-21809 (HCL BigFix Quantum Risk Analyzer has a certain validation process that ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/90d12d8c479b93cbea813969c23ff8430f4cf357
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/90d12d8c479b93cbea813969c23ff8430f4cf357
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/40879a30/attachment.htm>
More information about the debian-security-tracker-commits
mailing list