[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Jul 26 20:09:48 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
74903349 by Salvatore Bonaccorso at 2026-07-26T21:09:27+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2098,9 +2098,9 @@ CVE-2026-12688 (The ProfileGrid WordPress plugin before 5.9.9.7 does not verify
CVE-2026-12497 (The Paid Membership Plugin, Ecommerce, User Registration Form, Login F ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12353 (An unauthenticated attacker could trigger an Out of Memory condition t ...)
- TODO: check
+ NOT-FOR-US: Red Hat Certificate System
CVE-2026-11922 (A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allow ...)
- TODO: check
+ NOT-FOR-US: zenml
CVE-2026-11354 (The Participants Database plugin for WordPress is vulnerable to Sensit ...)
NOT-FOR-US: WordPress plugin
CVE-2026-10697 (Improper Authentication vulnerability in Progress MOVEit Transfer. Th ...)
@@ -6243,7 +6243,7 @@ CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials without
- libsoup2.4 <removed>
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506
CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ...)
- TODO: check
+ NOT-FOR-US: zenml
CVE-2025-68640 (The Apple Find My backend service through 2025-12-17 allows an attacke ...)
TODO: check
CVE-2025-66390 (In Microsoft Azure API Management through 2025-10-17, when self-servic ...)
@@ -7247,7 +7247,7 @@ CVE-2026-13724 (Client-Side Enforcement of Server-Side Security vulnerability in
CVE-2026-12701 (A path traversal vulnerability was found in pulpcore. The relative_pat ...)
NOT-FOR-US: pulpcore
CVE-2026-12341 (This vulnerability impacts all versions of IdentityIQ and allows an un ...)
- TODO: check
+ NOT-FOR-US: SailPoint Technologies
CVE-2026-12080 (A flaw was found in the QEMU Guest Agent (qga). A local unprivileged u ...)
TODO: check
CVE-2026-64207 (In the Linux kernel, the following vulnerability has been resolved: n ...)
@@ -7443,7 +7443,7 @@ CVE-2026-16151 (A vulnerability has been found in CartoDB carto-api-client 0.5.2
CVE-2026-16150 (A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affec ...)
NOT-FOR-US: RobinHerbots Inputmask
CVE-2026-12228 (A stored cross-site scripting (XSS) vulnerability exists in the `POST ...)
- TODO: check
+ NOT-FOR-US: parisneo/lollms
CVE-2026-10130 (QueryWeaver contains an authentication bypass vulnerability that allow ...)
TODO: check
CVE-2026-64186 (In the Linux kernel, the following vulnerability has been resolved: i ...)
@@ -10497,7 +10497,7 @@ CVE-2026-12692 (Unverified password change vulnerability in Vimesoft Inc. Enterp
CVE-2026-12691 (Missing authentication for critical function vulnerability in Vimesoft ...)
NOT-FOR-US: Enterprise Video Platform
CVE-2026-11763 (Authorization bypass through User-Controlled key vulnerability in Gis ...)
- TODO: check
+ NOT-FOR-US: GisLab Laboratory Management System:
CVE-2025-60357 (AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQ ...)
TODO: check
CVE-2025-59866 (The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ...)
@@ -11090,13 +11090,13 @@ CVE-2026-12393 (The WPS Bookings for WooCommerce WordPress plugin before 3.11.7
CVE-2026-12391 (An insecure symlink following vulnerability exists in Canonical ubuntu ...)
NOT-FOR-US: Canonical
CVE-2026-12379 (An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC auth ...)
- TODO: check
+ NOT-FOR-US: QT Axivion
CVE-2026-11966 (The User Registration & Membership WordPress plugin before 5.2.3 does ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11961 (The User Registration & Membership WordPress plugin before 5.2.3 does ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11889 (SALTO ProAccess Space software using the tenancy feature / logical pa ...)
- TODO: check
+ NOT-FOR-US: SALTO ProAccess Space software
CVE-2026-11740
REJECTED
CVE-2026-11575 (The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not p ...)
@@ -13897,7 +13897,7 @@ CVE-2026-12478 (The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed
CVE-2026-12281 (The Shibboleth WordPress plugin before 2.5.4 does not fail closed when ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11944 (openSIS Classic 9.3 contains an authenticated path traversal vulnerabi ...)
- TODO: check
+ NOT-FOR-US: OpenSIS
CVE-2026-11917 (A path traversal security issue exists within Rockwell AutomationThinM ...)
NOT-FOR-US: Rockwell Automation
CVE-2026-11851 (Improper Neutralization of Special Elements used in an SQL Command ("S ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7490334986462582ce192b49f8108ee6e6ebf8d7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7490334986462582ce192b49f8108ee6e6ebf8d7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/c840a8a5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list