[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 28 08:27:39 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
90aaeb8d by Salvatore Bonaccorso at 2026-07-28T09:27:14+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,33 +1,33 @@
CVE-2026-6251 (The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time ...)
NOT-FOR-US: WordPress plugin
CVE-2026-66825 (Pivotick contains a cross-site scripting vulnerability in the sidebar ...)
- TODO: check
+ NOT-FOR-US: Pivotick
CVE-2026-66824 (A stored cross-site scripting vulnerability existed in the capture tre ...)
- TODO: check
+ NOT-FOR-US: Lookyloo
CVE-2026-66473 (Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versi ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66018 (Build readers can access another repository's environment properties. ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-66015 (An authenticated privilege-escalation vulnerability in JFrog Platform ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-66014 (JFrog Artifactory contains an authentication handling weakness in inte ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-65925 (A user with JFrog Artifactory Cargo remote repository read access coul ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-65924 (JFrog Artifactory support for Terraform remote repositories was found ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-65923 (A URL validation weakness in JFrog Artifactory Ansible repository hand ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-65922 (An authorization weakness in JFrog Artifactory internal metadata handl ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-65921 (A path validation weakness in archive extraction/write handling allows ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-65618 (Improper URL validation when handling specific URLs, allows an attacke ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-65617 (A deserialization weakness in JFrog Artifactory package handling could ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-65616 (Incorrect authorization validation in refresh token signature allows n ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-65448 (Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list clean ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65447 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0. ...)
@@ -199,13 +199,13 @@ CVE-2026-61957 (Unauthenticated Cross Site Scripting (XSS) in miniorange otp ver
CVE-2026-61953 (Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Dire ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-59730 (Astro is a web framework for content-driven websites. In versions 8.1. ...)
- TODO: check
+ NOT-FOR-US: Astro
CVE-2026-59729 (Astro is a web framework for content-driven websites. Versions prior t ...)
- TODO: check
+ NOT-FOR-US: Astro
CVE-2026-59728 (Astro is a web framework for content-driven websites. In versions 1.0. ...)
- TODO: check
+ NOT-FOR-US: Astro
CVE-2026-59727 (Astro is a web framework for content-driven websites. In versions 3.10 ...)
- TODO: check
+ NOT-FOR-US: Astro
CVE-2026-59240 (The vulnerability involves an Insecure Direct Object Reference (IDOR) ...)
TODO: check
CVE-2026-56748 (Improper validation of symbolic links in the Pack Git import feature i ...)
@@ -537864,15 +537864,15 @@ CVE-2021-32090 (The dashboard component of StackLift LocalStack 0.12.6 allows at
CVE-2021-32089 (An issue was discovered on Zebra (formerly Motorola Solutions) Fixed R ...)
NOT-FOR-US: Zebra
CVE-2021-32088 (An issue was discovered in Quest KACE Systems Deployment Appliance (SM ...)
- TODO: check
+ NOT-FOR-US: Quest KACE Systems Deployment Appliance
CVE-2021-32087 (An issue was discovered in Quest KACE Systems Deployment Appliance (SM ...)
- TODO: check
+ NOT-FOR-US: Quest KACE Systems Deployment Appliance
CVE-2021-32086 (An issue was discovered in Quest KACE Systems Deployment Appliance (SM ...)
- TODO: check
+ NOT-FOR-US: Quest KACE Systems Deployment Appliance
CVE-2021-32085 (An issue was discovered in Quest KACE Systems Deployment Appliance (SM ...)
- TODO: check
+ NOT-FOR-US: Quest KACE Systems Deployment Appliance
CVE-2021-32084 (An issue was discovered in Quest KACE Systems Deployment Appliance (SM ...)
- TODO: check
+ NOT-FOR-US: Quest KACE Systems Deployment Appliance
CVE-2021-32083
RESERVED
CVE-2021-32082
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/90aaeb8d78a91caac044eae666ab400b91e39275
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/90aaeb8d78a91caac044eae666ab400b91e39275
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/08f4f05d/attachment.htm>
More information about the debian-security-tracker-commits
mailing list