[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 22 21:21:29 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c6b8a1dc by Salvatore Bonaccorso at 2026-07-22T22:20:51+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
CVE-2026-8152 (Unblu Spark contains an open redirect vulnerability that can be escala ...)
- TODO: check
+ NOT-FOR-US: Unblu Spark
CVE-2026-7328 (Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_ML ...)
- TODO: check
+ NOT-FOR-US: Caliptra Core Runtime Firmware
CVE-2026-65650 (Elgg before 7.0.0 does not check image dimensions to prevent denial of ...)
- TODO: check
+ NOT-FOR-US: Elgg
CVE-2026-65603 (The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a ...)
- TODO: check
+ NOT-FOR-US: Grav plugin
CVE-2026-65602 (Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce t ...)
TODO: check
CVE-2026-65601 (Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vul ...)
@@ -41,9 +41,9 @@ CVE-2026-65015 (n8n versions before 2.30.1 contain a privilege escalation vulner
CVE-2026-65014 (n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers t ...)
NOT-FOR-US: n8n
CVE-2026-65013 (Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken obje ...)
- TODO: check
+ NOT-FOR-US: Onlook
CVE-2026-65012 (InvokeAI before 6.13.7 contains an unauthenticated directory enumerati ...)
- TODO: check
+ NOT-FOR-US: InvokeAI
CVE-2026-65011 (Graylog2 Server before commit 46a2eeb contains a missing per-entity pe ...)
TODO: check
CVE-2026-64835 (FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory acce ...)
@@ -59,7 +59,7 @@ CVE-2026-64831 (FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overfl
CVE-2026-64830 (FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vuln ...)
TODO: check
CVE-2026-64828 (Froiden TableTrack through 1.3.10 contains a stored cross-site scripti ...)
- TODO: check
+ NOT-FOR-US: Froiden TableTrack
CVE-2026-63264 (The Joomla extension JoomShopping is vulnerable to an reflected XSS vu ...)
NOT-FOR-US: Joomla
CVE-2026-63048 (The Joomla extension Page Builder CK is vulnerable to an authenticated ...)
@@ -67,9 +67,9 @@ CVE-2026-63048 (The Joomla extension Page Builder CK is vulnerable to an authent
CVE-2026-63047 (The Joomla extension Events Booking prior version 5.0-5.8.1 did not pr ...)
NOT-FOR-US: Joomla
CVE-2026-62145 (A vulnerability in Check Point Gaia Portal allows an authenticated att ...)
- TODO: check
+ NOT-FOR-US: Check Point Gaia Portal
CVE-2026-62144 (An authentication bypass vulnerability in Check Point Security Managem ...)
- TODO: check
+ NOT-FOR-US: Check Point
CVE-2026-61392 (There is a information disclosure vulnerability in some Hikvision came ...)
NOT-FOR-US: Hikvision
CVE-2026-61391 (There is a stack-based buffer overflow vulnerability in some Hikvision ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6b8a1dcbb285ad2015e4748b194180a9cfccb2e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6b8a1dcbb285ad2015e4748b194180a9cfccb2e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/a15a16b4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list