[Git][security-tracker-team/security-tracker][master] Process some new NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 28 09:58:40 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
747296e2 by Salvatore Bonaccorso at 2026-07-28T10:58:16+02:00
Process some new NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -207,29 +207,29 @@ CVE-2026-59728 (Astro is a web framework for content-driven websites. In version
CVE-2026-59727 (Astro is a web framework for content-driven websites. In versions 3.10 ...)
NOT-FOR-US: Astro
CVE-2026-59240 (The vulnerability involves an Insecure Direct Object Reference (IDOR) ...)
- TODO: check
+ NOT-FOR-US: Roskus prospero-flow-crm
CVE-2026-56748 (Improper validation of symbolic links in the Pack Git import feature i ...)
- TODO: check
+ NOT-FOR-US: Cribl Stream
CVE-2026-56747 (Improper control of generation of code in the JSON Pointer-to-accessor ...)
- TODO: check
+ NOT-FOR-US: Cribl Stream
CVE-2026-55685 (React Router is a router for React. In versions 7.0.0 through 7.17.0, ...)
- TODO: check
+ NOT-FOR-US: React Router
CVE-2026-53669 (React Router is a router for React. Versions 6.0.0 through 7.17.0 are ...)
- TODO: check
+ NOT-FOR-US: React Router
CVE-2026-53668 (React Router is a router for React. In versions 6.30.2 through 6.30.4 ...)
- TODO: check
+ NOT-FOR-US: React Router
CVE-2026-53667 (React Router is a router for React. In versions 7.11.0 through 7.17.0, ...)
- TODO: check
+ NOT-FOR-US: React Router
CVE-2026-53666 (React Router is a router for React. In versions 6.4.0 through 7.17.0, ...)
- TODO: check
+ NOT-FOR-US: React Router
CVE-2026-51565 (Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsControlle ...)
- TODO: check
+ NOT-FOR-US: Milk admin
CVE-2026-51564 (An issue in the redirect parameter in Milk admin <=0.9.8 allows remote ...)
- TODO: check
+ NOT-FOR-US: Milk admin
CVE-2026-51078 (An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sens ...)
- TODO: check
+ NOT-FOR-US: Dede CMS
CVE-2026-51077 (SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote atta ...)
- TODO: check
+ NOT-FOR-US: Dede CMS
CVE-2026-43822 (A use after free issue was addressed with improved memory management. ...)
NOT-FOR-US: Apple
CVE-2026-43821 (An access issue was addressed with improved access restrictions. This ...)
@@ -383,9 +383,9 @@ CVE-2026-43672 (An authorization issue was addressed with improved state managem
CVE-2026-43665 (This issue was addressed with additional entitlement checks. This issu ...)
NOT-FOR-US: Apple
CVE-2026-42017 (An event-handling weakness in JFrog Artifactory could expose privilege ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-42016 (JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerabl ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-39877 (A memory corruption issue was addressed with improved memory handling. ...)
NOT-FOR-US: Apple
CVE-2026-39875 (A permissions issue was addressed with additional restrictions. This i ...)
@@ -423,9 +423,9 @@ CVE-2026-28849 (The issue was addressed with improved checks. This issue is fixe
CVE-2026-20672 (An information disclosure issue was addressed with improved privacy co ...)
NOT-FOR-US: Apple
CVE-2026-17528 (Versions of the package nice-select2 before 2.4.1 are vulnerable to Cr ...)
- TODO: check
+ NOT-FOR-US: nice-select2
CVE-2026-17524 (Versions of the package zip-lib before 1.1.0 are vulnerable to Directo ...)
- TODO: check
+ NOT-FOR-US: zip-lib
CVE-2026-16811 (The ShopLentor \u2013 All-in-One WooCommerce Growth & Store Enhancemen ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16797 (The ShopLentor \u2013 All-in-One WooCommerce Growth & Store Enhancemen ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/747296e22030297691e2ee2fe45896f89862598a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/747296e22030297691e2ee2fe45896f89862598a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/f09124cc/attachment.htm>
More information about the debian-security-tracker-commits
mailing list