[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Jul 2 10:25:48 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
106ce016 by Moritz Muehlenhoff at 2026-07-02T11:25:31+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -981,9 +981,9 @@ CVE-2026-54896 (Oj (Optimized JSON) is a JSON parser and Object marshaller packa
CVE-2026-54696 (Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2. ...)
TODO: check
CVE-2026-54673 (electron-updater allows for automatic updates for Electron apps. Prior ...)
- TODO: check
+ NOT-FOR-US: electron-updater
CVE-2026-54672 (electron-updater allows for automatic updates for Electron apps. Prior ...)
- TODO: check
+ NOT-FOR-US: electron-updater
CVE-2026-54592 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
TODO: check
CVE-2026-54502 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
@@ -1005,9 +1005,9 @@ CVE-2026-52193 (Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-21091
CVE-2026-50254 (An unauthenticated remote attacker can repeatedly send a single crafte ...)
TODO: check
CVE-2026-50110 (Storage Concentrator (SC & SCVM) contains hardcoded credentials for nu ...)
- TODO: check
+ NOT-FOR-US: Storage Concentrator
CVE-2026-50040 (Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site ...)
- TODO: check
+ NOT-FOR-US: Storage Concentrator
CVE-2026-50003 (A malicious or compromised server can make a DCMTK client using bit-pr ...)
TODO: check
CVE-2026-44628 (An unauthenticated attacker can crash the worklist server with a singl ...)
@@ -1065,7 +1065,7 @@ CVE-2026-13443 (The Tutor LMS \u2013 eLearning and online course solution plugin
CVE-2026-13246 (The GiveWP \u2013 Donation Plugin and Fundraising Platform plugin for ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13207 (FUXA versions 1.3.1 and prior contain an authentication bypass vulnera ...)
- TODO: check
+ NOT-FOR-US: FUXA
CVE-2026-13015 (The Wp Google Places Review Slider plugin for WordPress is vulnerable ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12923 (The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary F ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/106ce0166209ebba95bad6404c24f4cab2a24287
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/106ce0166209ebba95bad6404c24f4cab2a24287
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260702/46abdf35/attachment.htm>
More information about the debian-security-tracker-commits
mailing list