[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Jul 5 11:35:38 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f8e3dd1a by Moritz Muehlenhoff at 2026-07-05T12:33:24+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,29 +1,29 @@
 CVE-2026-14781 (A flaw exists in the org.keycloak.broker.oidc package where the OIDC b ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-14717 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-14716 (A security vulnerability has been detected in nextlevelbuilder GoClaw  ...)
-	TODO: check
+	NOT-FOR-US: GoClaw
 CVE-2026-14714 (A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent  ...)
-	TODO: check
+	NOT-FOR-US: chatgpt-on-wechat
 CVE-2026-14713 (A security flaw has been discovered in SourceCodester Pizzafy E-Commer ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-14706 (A vulnerability was identified in code-projects Online Examination 1.0 ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-14705 (A vulnerability was determined in code-projects Online Examination 1.0 ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-14704 (A vulnerability was found in stephen-kruger bluebox up to 4.5.12. Affe ...)
-	TODO: check
+	NOT-FOR-US: stephen-kruger bluebox
 CVE-2026-14703 (A vulnerability has been found in itsourcecode Hospital Management Sys ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-14702 (A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This im ...)
-	TODO: check
+	NOT-FOR-US: markdownify-mcp
 CVE-2026-14701 (A vulnerability was detected in code-projects Internship Management Sy ...)
 	NOT-FOR-US: code-projects
 CVE-2026-14700 (A security vulnerability has been detected in code-projects Internship ...)
 	NOT-FOR-US: code-projects
 CVE-2026-14699 (A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0 ...)
-	TODO: check
+	NOT-FOR-US: markdownify-mcp
 CVE-2026-14698 (A security flaw has been discovered in SourceCodester Syllabus-Aligned ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-14695 (A vulnerability was found in SourceCodester Multi-Vendor Online Grocer ...)
@@ -43,7 +43,7 @@ CVE-2026-14689 (A security flaw has been discovered in CodeAstro Apartment Visit
 CVE-2026-14688 (A vulnerability was identified in itsourcecode Online Hotel Management ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-14687 (A vulnerability was determined in 666ghj BettaFish up to 1.2.1. Impact ...)
-	TODO: check
+	NOT-FOR-US: BettaFish
 CVE-2026-14686 (A vulnerability was found in HdrHistogram up to 2.2.2. This issue affe ...)
 	TODO: check
 CVE-2026-14685 (A vulnerability has been found in HdrHistogram up to 2.2.2. This vulne ...)
@@ -53,13 +53,13 @@ CVE-2026-14684 (A flaw has been found in HdrHistogram up to 2.2.2. This affects
 CVE-2026-14683 (A vulnerability was detected in HdrHistogram up to 2.2.2. Affected by  ...)
 	TODO: check
 CVE-2026-14660 (A vulnerability was found in code-projects Online Job Portal 1.0. The  ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-14659 (A vulnerability has been found in itsourcecode Hospital Management Sys ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-14658 (A vulnerability was detected in code-projects Assessment Management 1. ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-14657 (A flaw has been found in code-projects Assessment Management 1.0. This ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-14656 (A security vulnerability has been detected in code-projects Assessment ...)
 	NOT-FOR-US: code-projects
 CVE-2026-14655 (A weakness has been identified in code-projects Assessment Management  ...)
@@ -1926,9 +1926,9 @@ CVE-2026-10096 (The Qi Blocks plugin for WordPress is vulnerable to Insecure Dir
 CVE-2026-10095 (The WP Photo Album Plus plugin for WordPress is vulnerable to Stored C ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-23351 (NVIDIA ConnectX and BlueField contain a vulnerability in the command i ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2025-23350 (NVIDIA ConnectX and BlueField contain a vulnerability in the command i ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-53351 (In the Linux kernel, the following vulnerability has been resolved:  r ...)
 	- linux 7.0.13-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8e3dd1a79682e2f748014b63cf28fbe5ca75665

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8e3dd1a79682e2f748014b63cf28fbe5ca75665
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260705/7068dbc4/attachment.htm>


More information about the debian-security-tracker-commits mailing list