[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Jul 26 13:57:28 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
daeb62a2 by Salvatore Bonaccorso at 2026-07-26T14:57:05+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,13 +3,13 @@ CVE-2026-64530 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/a8a02897f2b479127db261de05cbf0c28b98d159 (7.2-rc1)
CVE-2026-63720 (datamodel-code-generator prior to version 0.70.0 contains a code injec ...)
- TODO: check
+ NOT-FOR-US: datamodel-code-generator
CVE-2026-17434 (A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is t ...)
- TODO: check
+ NOT-FOR-US: nanocoai NanoClaw
CVE-2026-17433 (A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This i ...)
- TODO: check
+ NOT-FOR-US: nanocoai NanoClaw
CVE-2026-17432 (A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Af ...)
- TODO: check
+ NOT-FOR-US: NousResearch hermes-agent
CVE-2026-15962 (The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to ...)
NOT-FOR-US: WordPress plugin
CVE-2024-14040 (In the Linux kernel, the following vulnerability has been resolved: n ...)
@@ -22,7 +22,7 @@ CVE-2026-66012 (SiYuan before v3.7.2 contains a missing authorization vulnerabil
CVE-2026-66011 (ImageMagick before 7.1.2-27 contains a memory leak vulnerability in th ...)
TODO: check
CVE-2026-16766 (Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell ...)
- TODO: check
+ NOT-FOR-US: Catalyst::View::Wkhtmltopdf Perl module
CVE-2026-15425 (The Yoast SEO \u2013 Advanced SEO with real-time guidance and built-in ...)
NOT-FOR-US: WordPress plugin
CVE-2026-10818 (The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File U ...)
@@ -1383,21 +1383,21 @@ CVE-2026-66036 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap o
CVE-2026-62835 (Improper authorization in Azure Portal allows an unauthorized attacker ...)
NOT-FOR-US: Microsoft
CVE-2026-61892 (Weintek cMT3092X HMI allows a non-privileged user to modify tokens to ...)
- TODO: check
+ NOT-FOR-US: Weintek cMT3092X HMI
CVE-2026-61886 (Weintek cMT3092X HMI stores user account passwords in plaintext.)
- TODO: check
+ NOT-FOR-US: Weintek cMT3092X HMI
CVE-2026-61884 (The web management interface ofTycon Systems TPDIN-Monitor-WEB2 does ...)
- TODO: check
+ NOT-FOR-US: Tycon Systems
CVE-2026-60135 (An attacker can modify data that should be restricted to read\u2011onl ...)
- TODO: check
+ NOT-FOR-US: Weintek
CVE-2026-60134 (Weintek cMT3092X HMI allows a non-privileged user to modify cookies to ...)
- TODO: check
+ NOT-FOR-US: Weintek
CVE-2026-57531 (Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Milkdown
CVE-2026-57530 (Milkdown before 7.21.3 contains a stored cross-site scripting vulnerab ...)
- TODO: check
+ NOT-FOR-US: Milkdown
CVE-2026-55985 (The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stor ...)
- TODO: check
+ NOT-FOR-US: Tycon Systems
CVE-2026-16280 (An integer overflow when calculating physical offsets for sparse PMRs ...)
NOT-FOR-US: Imagination Technologies
CVE-2026-14955 (The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress i ...)
@@ -1869,13 +1869,13 @@ CVE-2026-12702 (In affected versions of Octopus Deploy Insufficient checks on th
CVE-2026-12654 (The Payment Plugins for Stripe WooCommerce plugin for WordPress is vul ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12504 (Improper Authentication (CWE-287)in the PAM configuration in Loytec LI ...)
- TODO: check
+ NOT-FOR-US: Loytec
CVE-2026-12503 (Improper Link Resolution (CWE-59)in `/usr/bin/larm_starter` in Loytec ...)
- TODO: check
+ NOT-FOR-US: Loytec
CVE-2026-12502 (Improper Privilege Management (CWE-269)in `/usr/bin/ltsudo` in Loytec ...)
- TODO: check
+ NOT-FOR-US: Loytec
CVE-2026-12496 (Stored Cross-Site Scripting (CWE-79)in the OPC XML-DA server statistic ...)
- TODO: check
+ NOT-FOR-US: Loytec
CVE-2026-10610 (Local privilege escalationpotentially allowed an attacker to execute a ...)
TODO: check
CVE-2026-10033 (The EventON Action User plugin for WordPress is vulnerable to authoriz ...)
@@ -2702,7 +2702,7 @@ CVE-2026-15786 (The WP Encryption \u2013 One Click Free SSL Certificate & SSL /
CVE-2026-15761 (The Tickera \u2013 Sell Tickets & Manage Events plugin for WordPress i ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15687 (A security issue was discovered in the Kubernetes Java client library ...)
- TODO: check
+ NOT-FOR-US: Kubernetes Java client
CVE-2026-15647 (The Brands for WooCommerce plugin for WordPress is vulnerable to Store ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15646 (The Brands for WooCommerce plugin for WordPress is vulnerable to Store ...)
@@ -11028,7 +11028,7 @@ CVE-2026-13103 (A potential path traversal vulnerability was reported in Lenovo
CVE-2026-12393 (The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does n ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12391 (An insecure symlink following vulnerability exists in Canonical ubuntu ...)
- TODO: check
+ NOT-FOR-US: Canonical
CVE-2026-12379 (An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC auth ...)
TODO: check
CVE-2026-11966 (The User Registration & Membership WordPress plugin before 5.2.3 does ...)
@@ -11843,7 +11843,7 @@ CVE-2026-14251 (A flaw was found in the OpenShift GitOps operator. The ClusterRo
CVE-2026-12997 (The Gravity Forms plugin for WordPress is vulnerable to Directory Trav ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12382 (A flaw was found in the AAP Gateway Envoy proxy configuration. The non ...)
- TODO: check
+ NOT-FOR-US: AAP Gateway (Red Hat)
CVE-2026-10673 (The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/e ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-32781 (Apollo is a reliable configuration management system suitable for micr ...)
@@ -14624,7 +14624,7 @@ CVE-2026-15540 (A vulnerability was detected in SourceCodester Online Book Store
CVE-2026-14934 (A Missing Authorization vulnerability in the repository creation funct ...)
NOT-FOR-US: Google Cloud BigQuery, Dataform and Colab Enterprise
CVE-2026-14906 (Pages with malicious titles could potentially allow saved PDF content ...)
- TODO: check
+ NOT-FOR-US: Firefox for iOS
CVE-2026-14846 (In version 8.2.1 of PrestaShop, there is a vulnerability relating to t ...)
NOT-FOR-US: PrestaShop
CVE-2026-14453 (This vulnerability is a critical Server-Side Template Injection (SSTI) ...)
@@ -16358,7 +16358,7 @@ CVE-2026-13011 (The ERP: Complete HR, Accounting & CRM Suite with Recruitment an
CVE-2026-12879 (An Improper Input Validation vulnerability in BigQuery DAO in Google C ...)
NOT-FOR-US: Google Cloud Apigee
CVE-2026-12593 (The implementation of an internalandundocumentedDashboardAPI endpoint( ...)
- TODO: check
+ NOT-FOR-US: QT Axivion
CVE-2026-12590 (Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 ( ...)
TODO: check
CVE-2026-12433 (The Hydra Booking \u2013 Appointment Scheduling & Booking Calendar plu ...)
@@ -17329,7 +17329,7 @@ CVE-2026-22927 (Omnissa Workspace ONE\xae Tunnel for Windows addresses a Local
CVE-2026-15067 (Snowflake Terraform Provider versions prior to 2.18.0 contain several ...)
NOT-FOR-US: Snowflake Terraform Provider
CVE-2026-15063 (A flaw was found in the gorch service template, which is part of the t ...)
- TODO: check
+ NOT-FOR-US: Red Hat OpenShift AI (RHOAI)
CVE-2026-15062 (SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (sn ...)
NOT-FOR-US: Snowflake Snowpark Python SDK
CVE-2026-15053 (Tanium addressed a denial of service vulnerability in Tanium Server.)
@@ -17349,7 +17349,7 @@ CVE-2026-15036 (A vulnerability was determined in Harness up to 2.28.2. This vul
CVE-2026-15035 (A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the ...)
NOT-FOR-US: bentoml OpenLLM
CVE-2026-15034 (A vulnerability has been found in flask-dashboard Flask-MonitoringDash ...)
- TODO: check
+ NOT-FOR-US: Flask-MonitoringDashboard
CVE-2026-15033 (A flaw has been found in christopherthielen check-peer-dependencies up ...)
NOT-FOR-US: christopherthielen check-peer-dependencies
CVE-2026-14967 (BBOT's `github_workflows` module could be induced to write a downloade ...)
@@ -98020,7 +98020,7 @@ CVE-2026-26002 (Open OnDemand is an open-source high-performance computing porta
CVE-2026-25750 (Langchain Helm Charts are Helm charts for deploying Langchain applicat ...)
NOT-FOR-US: Langchain Helm Charts
CVE-2026-25702 (A Improper Access Control vulnerability in the kernel of SUSE SUSE Lin ...)
- TODO: check
+ NOT-FOR-US: SUSE
CVE-2026-24963 (Incorrect Privilege Assignment vulnerability in ameliabooking Amelia a ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-24960 (Unrestricted Upload of File with Dangerous Type vulnerability in zozot ...)
@@ -100715,7 +100715,7 @@ CVE-2026-25746 (OpenEMR is a free and open source electronic health records and
CVE-2026-25743 (OpenEMR is a free and open source electronic health records and medica ...)
NOT-FOR-US: OpenEMR
CVE-2026-25701 (An Insecure Temporary File vulnerability in openSUSE sdbootutil allows ...)
- TODO: check
+ NOT-FOR-US: openSUSE sdbootutil package
CVE-2026-25554 (OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (pri ...)
NOT-FOR-US: OpenSIPS
CVE-2026-25476 (OpenEMR is a free and open source electronic health records and medica ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/daeb62a2ca83b78d76aa8059f174df70c230fe64
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/daeb62a2ca83b78d76aa8059f174df70c230fe64
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/412fea49/attachment.htm>
More information about the debian-security-tracker-commits
mailing list