[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 20 08:45:28 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a430a260 by Salvatore Bonaccorso at 2026-07-20T09:44:32+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6,11 +6,11 @@ CVE-2026-6656 (Crypt::Password versions through 0.28 for Perl are susceptible to
 	- libcrypt-password-perl <unfixed>
 	NOTE: https://rt.cpan.org/Ticket/Display.html?id=180162
 CVE-2026-45138 (CI4MS is a CodeIgniter 4-based content management system skeleton. Pri ...)
-	TODO: check
+	NOT-FOR-US: CI4MS
 CVE-2026-44359 (Meshtastic is an open source mesh networking solution. Prior to versio ...)
-	TODO: check
+	NOT-FOR-US: Meshtastic
 CVE-2026-42566 (Meshtastic is an open source mesh networking solution. Prior to versio ...)
-	TODO: check
+	NOT-FOR-US: Meshtastic
 CVE-2026-16235 (Crypt::Password versions through 0.28 for Perl generate insecure rando ...)
 	- libcrypt-password-perl <unfixed>
 CVE-2026-13432 (The ThumbPress  WordPress plugin before 6.2.2 does not perform a capab ...)
@@ -3147,7 +3147,7 @@ CVE-2026-15343 (A path traversal vulnerability was identified in GitHub Enterpri
 CVE-2026-15007 (A denial of service vulnerability was identified in GitHub Enterprise  ...)
 	NOT-FOR-US: Github Enterprise Server
 CVE-2026-14871 (osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Au ...)
-	TODO: check
+	NOT-FOR-US: osTicket
 CVE-2026-13410 (Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS v ...)
 	NOT-FOR-US: Dancer::Plugin::Auth::Google Perl module
 CVE-2026-13082 (GD::SecurityImage versions through 1.75 for Perl use rand to generate  ...)
@@ -3677,15 +3677,15 @@ CVE-2026-15610 (The WPBot \u2013 AI ChatBot for Live Support, Lead Generation, A
 CVE-2026-15457 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15449 (A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link  ...)
-	TODO: check
+	NOT-FOR-US: Illumos
 CVE-2026-15422 (The illumos SCTP inbound path performs association lookup for INIT ACK ...)
-	TODO: check
+	NOT-FOR-US: Illumos
 CVE-2026-15407 (The Themify Builder plugin for WordPress is vulnerable to authorizatio ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15395 (The Kali Forms \u2014 Contact Form & Drag-and-Drop Builder plugin for  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15352 (A vulnerability exists in the Health & Safety (HS) application of NASA ...)
-	TODO: check
+	NOT-FOR-US: NASA Health & Safety (HS) application
 CVE-2026-15350 (The The Cache Purger plugin for WordPress is vulnerable to authorizati ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15349 (The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plu ...)
@@ -3717,7 +3717,7 @@ CVE-2026-15005 (The Loco Translate plugin for WordPress is vulnerable to Cross-S
 CVE-2026-14956 (The Bricksforge plugin for WordPress is vulnerable to Privilege Escala ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14890 (SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ  ...)
-	TODO: check
+	NOT-FOR-US: SGLang
 CVE-2026-14782 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14503 (The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive I ...)
@@ -3725,7 +3725,7 @@ CVE-2026-14503 (The pCloud WP Backup plugin for WordPress is vulnerable to Sensi
 CVE-2026-14371 (The Lenovo XClarity Integrator for Windows Admin Center plugin version ...)
 	NOT-FOR-US: Lenovo
 CVE-2026-14254 (A race condition in the account lockout mechanism inDelphixContinousDa ...)
-	TODO: check
+	NOT-FOR-US: Delphix
 CVE-2026-14253
 	REJECTED
 CVE-2026-13767 (The Quiz Master Next plugin for WordPress is vulnerable to SQL Injecti ...)
@@ -4517,9 +4517,9 @@ CVE-2026-15746 (Strands Agents is an open-source Python SDK for building and run
 CVE-2026-15583 (A confused-deputy flaw in Grafana MCP Server allows an unauthenticated ...)
 	NOT-FOR-US: Grafana MCP Server
 CVE-2026-14961 (Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\Tde ...)
-	TODO: check
+	NOT-FOR-US: Pegatron
 CVE-2026-14960 (Pegatron `Tdelo64.sys` improperly exposes privileged hardware access f ...)
-	TODO: check
+	NOT-FOR-US: Pegatron
 CVE-2026-14251 (A flaw was found in the OpenShift GitOps operator. The ClusterRole rec ...)
 	NOT-FOR-US: Argo CD
 CVE-2026-12997 (The Gravity Forms plugin for WordPress is vulnerable to Directory Trav ...)
@@ -6444,9 +6444,9 @@ CVE-2026-15389 (A vulnerability relating to insufficient access control has been
 CVE-2026-15305 (Users were able to upload files with arbitrary MIME types to forms usi ...)
 	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-15265 (A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and  ...)
-	TODO: check
+	NOT-FOR-US: Tenable Agent
 CVE-2026-15183 (Multiple input validation vulnerabilities in the Snowflake Spark Conne ...)
-	TODO: check
+	NOT-FOR-US: Snowflake Spark Connector
 CVE-2026-15076 (In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x bra ...)
 	NOT-FOR-US: Eclipse
 CVE-2026-15075 (In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a430a260264b388ea81b5125aa930842b0b4618f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a430a260264b388ea81b5125aa930842b0b4618f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/d0f1778a/attachment.htm>


More information about the debian-security-tracker-commits mailing list