[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 30 21:25:49 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
27064b5a by Salvatore Bonaccorso at 2026-07-30T22:25:23+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,73 +1,73 @@
CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
NOT-FOR-US: IBM
CVE-2026-7849 (Due to improper neutralization of special elements, an unauthenticated ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-6540 (Calico's Application Layer Policy (disabled by default), which enforce ...)
- TODO: check
+ NOT-FOR-US: Calico
CVE-2026-67596 (CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak e ...)
- TODO: check
+ NOT-FOR-US: CSL 1010 M2M 3G WiFi Module firmware
CVE-2026-67351 (Serendipity before 2.6.1 contains an authentication context confusion ...)
TODO: check
CVE-2026-67349 (OpenCost before 1.121.0 fails to authenticate the GET /helmValues endp ...)
- TODO: check
+ NOT-FOR-US: OpenCost
CVE-2026-67348 (Julep contains an insecure direct object reference vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: Julep
CVE-2026-67347 (Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-chann ...)
- TODO: check
+ NOT-FOR-US: Vendure
CVE-2026-67346 (Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side ...)
- TODO: check
+ NOT-FOR-US: Swarms
CVE-2026-67345 (MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficie ...)
- TODO: check
+ NOT-FOR-US: Dromara MaxKey
CVE-2026-66416 (Leantime 3.6.2 contains a cross-site request forgery vulnerability tha ...)
- TODO: check
+ NOT-FOR-US: Leantime
CVE-2026-66415 (Leantime 3.6.2 contains a server-side request forgery and local file i ...)
- TODO: check
+ NOT-FOR-US: Leantime
CVE-2026-66414 (Leantime 3.6.2 contains an open redirect vulnerability in the Login co ...)
- TODO: check
+ NOT-FOR-US: Leantime
CVE-2026-65635 (Improper Isolation or Compartmentalization vulnerability in malach-it ...)
- TODO: check
+ NOT-FOR-US: malach-it boruta (Elixir.Boruta.Openid module)
CVE-2026-64870 (MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-62663 (Banks generates meaningful LLM prompts using a simple template languag ...)
- TODO: check
+ NOT-FOR-US: Banks
CVE-2026-61536 (Banks generates meaningful LLM prompts using a simple template languag ...)
- TODO: check
+ NOT-FOR-US: Banks
CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Fo ...)
NOT-FOR-US: WordPress plugin
CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr Information ...)
- TODO: check
+ NOT-FOR-US: E-Commerce Pack
CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
TODO: check
CVE-2026-59310 (VMware vCenter contains a directory traversal vulnerability in the Sys ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-57862 (Kanboard 1.2.52 and prior contains a server-side request forgery vulne ...)
TODO: check
CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution vulnerability in ...)
- TODO: check
+ NOT-FOR-US: e107
CVE-2026-56428 (The SSH service on BSH ELP (Electronic Platform) modules contains a pl ...)
NOT-FOR-US: Bosch
CVE-2026-54885 (Server-Side Request Forgery vulnerability in malach-it Boruta allows a ...)
- TODO: check
+ NOT-FOR-US: malach-it Boruta
CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of utilities and ...)
- TODO: check
+ NOT-FOR-US: DSSRF
CVE-2026-54522 (MessagePack for Ruby is an implementation of the MessagePack binary se ...)
TODO: check
CVE-2026-54368 (CentreStack before 17.4 contains a SQL injection vulnerability in Glad ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54367 (CentreStack before 17.2 contains an authentication bypass vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54366 (CentreStack before 17.4 contains an XML external entity (XXE) injectio ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54365 (CentreStack before 17.3 contains an unauthenticated deserialization vu ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54364 (CentreStack before 17.4 contains a session variable injection vulnerab ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-54363 (CentreStack before 17.5 contains a hardcoded cryptographic key vulnera ...)
- TODO: check
+ NOT-FOR-US: CentreStack
CVE-2026-53431 (Authentication Bypass by Capture-replay vulnerability in malach-it Bor ...)
- TODO: check
+ NOT-FOR-US: malach-it Boruta
CVE-2026-51295 (SQLite 3.41 is vulnerable to use after free in the jsonExtractFunc fun ...)
TODO: check
CVE-2026-51294 (SQLite 3.41 is vulnerable to use after free in the jsonArrayLengthFunc ...)
@@ -81,61 +81,61 @@ CVE-2026-51291 (sqlite 3.41 is vulnerable to use after free in the json.c jsonCa
CVE-2026-51290 (SQLite 3.41 has a use-after-free vulnerability in the shared cache loc ...)
TODO: check
CVE-2026-51272 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
- TODO: check
+ NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-4978 (Improper neutralization of special elements used in an SQL command ('S ...)
- TODO: check
+ NOT-FOR-US: Traffic Analysis System
CVE-2026-48910 (A carefully crafted editing request could trigger an XSS vulnerability ...)
TODO: check
CVE-2026-48499 (Activepieces is an open source AI workflow automation platform. Prior ...)
- TODO: check
+ NOT-FOR-US: Activepieces
CVE-2026-47876 (VMware ESX contains an out-of-bounds write vulnerability in the VMXNET ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-44108 (Due to a flaw in the execution order of scripts during shutdown, the f ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44107 (A reboot of the charging controller can be triggered via Modbus TCP wi ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44106 (A privilege escalation vulnerability in the init-script for user-appli ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44105 (The credentials for the local user "user-app" may be exposed in log fi ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44104 (The firmware update process for the basemodule of the charging control ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44103 (An unauthenticated remote attacker can inject malicious firmware into ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44102 (An unauthenticated remote attacker can trigger a firmware update downl ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44101 (Due to missing authentication the CHARX OCPP Agent service allows an u ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44100 (The CHARX JupiCore service allows an unauthenticated remote attacker t ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44099 (A privilege escalation vulnerability in the system configuration allow ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44098 (This vulnerability allows an unauthenticated remote attacker with cont ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44097 (A low-privileged remote attacker with "operator" access can upload arb ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44096 (A privilege escalation vulnerability in udhcpc allows a local user "ch ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44095 (A privilege escalation vulnerability in a script used for network conf ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44094 (An unauthenticated remote attacker can enforce the system to fall back ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44093 (A local privilege escalation vulnerability in the init-script for user ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44092 (An unauthenticated remote attacker can inject malicious input into the ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44091 (An unauthenticated remote attacker can post a malicious ID to the MQTT ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-44090 (Due to missing authentication, an unauthenticated remote attacker may ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2026-41709 (VMware ESX contains an insufficient logging vulnerability.A malicious ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-41703 (VMware ESX,Workstation, and Fusioncontain an out-of-bounds read vulner ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-41187 (Calico's apiserver wraps tier-scoped resources so that every operation ...)
- TODO: check
+ NOT-FOR-US: Calico
CVE-2026-41186 (When Calico's shared debug server is enabled (disabled by default), th ...)
- TODO: check
+ NOT-FOR-US: Calico
CVE-2026-28814 (Arbitrary Wiki Markup rendering due to lack of authentication in Apach ...)
TODO: check
CVE-2026-28813 (Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which l ...)
@@ -153,21 +153,21 @@ CVE-2026-22621 (Improper input validation in one of the session management inter
CVE-2026-22620 (Improper input validation in the authentication component ofEaton's Tr ...)
NOT-FOR-US: Eaton
CVE-2026-18382 (A flaw was found in koku-metrics-operator. The operator's CostManageme ...)
- TODO: check
+ NOT-FOR-US: koku-metrics-operator
CVE-2026-18381 (A flaw was found in the koku-metrics-operator for Red Hat OpenShift. T ...)
- TODO: check
+ NOT-FOR-US: koku-metrics-operator
CVE-2026-18378 (A flaw was found in koku-metrics-operator. The operator's CostManageme ...)
- TODO: check
+ NOT-FOR-US: koku-metrics-operator
CVE-2026-18369 (A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 chal ...)
TODO: check
CVE-2026-18363 (A logic vulnerability in the password reset token validation routine i ...)
- TODO: check
+ NOT-FOR-US: osTicket
CVE-2026-18362 (The IRIS web application in version 2.4.26 and possibly others does no ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-18361 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-18360 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-18353 (PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks ...)
NOT-FOR-US: Eclipse
CVE-2026-18245 (Improper control of code generation in Amazon @aws-amplify/codegen-ui- ...)
@@ -175,29 +175,29 @@ CVE-2026-18245 (Improper control of code generation in Amazon @aws-amplify/codeg
CVE-2026-18140 (Uncontrolled recursion in the unknown-key skip path of the aws-smithy- ...)
NOT-FOR-US: Amazon
CVE-2026-16971 (The IRIS web application in version 2.4.26 and possibly others does no ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-16970 (The IRIS web application in version 2.4.26 and possibly others contain ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-16969 (The IRIS web application in version 2.4.26 and possibly others is vuln ...)
- TODO: check
+ NOT-FOR-US: IRIS web application
CVE-2026-16308 (IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 ...)
NOT-FOR-US: IBM
CVE-2026-15978 (SGLang contains a model weight exfiltration vulnerability when no API ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15977 (SGLang contains a credential leakage vulnerability in the /server_info ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15976 (SGLang contains a RCE vulnerability when attempting to load model weig ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15974 (SGLang contains an SSRF and local file read in the multimodal generati ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15971 (SGLang contains an RCE vulnerability when the optional dumper subsyste ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15969 (SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tens ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-15658 (A vulnerability in the foreUP customer REST API allows any authenticat ...)
- TODO: check
+ NOT-FOR-US: foreUP customer REST API
CVE-2026-15657 (A vulnerability in the foreUP customer REST API allows any authenticat ...)
- TODO: check
+ NOT-FOR-US: foreUP customer REST API
CVE-2026-15435 (IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 thr ...)
NOT-FOR-US: IBM
CVE-2026-15397 (The Subscriptions for WooCommerce plugin for WordPress is vulnerable t ...)
@@ -231,7 +231,7 @@ CVE-2026-12940 (IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthen
CVE-2026-12733 (IBM DataPower Gateway could allow a remote attacker to cause a denial ...)
NOT-FOR-US: IBM
CVE-2026-12722 (Missing authentication for critical function vulnerability in FTC Soft ...)
- TODO: check
+ NOT-FOR-US: FTC E-Commerce Management Panel
CVE-2026-12118 (IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unaut ...)
NOT-FOR-US: IBM
CVE-2026-11980 (IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code e ...)
@@ -1731,7 +1731,7 @@ CVE-2026-13306 (Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulner
CVE-2026-13305 (Autel MaxiCharger AC Elite Home Software Update Improper Verification ...)
NOT-FOR-US: Autel
CVE-2026-13268 (G DATA Total Security Backup Service Link Following Local Privilege Es ...)
- TODO: check
+ NOT-FOR-US: G DATA
CVE-2026-13178 (The Eventin WordPress plugin before 4.1.16 does not properly authoriz ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13145 (The WP Travel WordPress plugin before 11.8.1 does not verify that the ...)
@@ -1747,7 +1747,7 @@ CVE-2026-12500 (The WP Travel Engine WordPress plugin before 6.8.2 does not per
CVE-2026-12436 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-12357 (Heimdall Data Database Proxy generateFileContent CRLF Injection Remote ...)
- TODO: check
+ NOT-FOR-US: Heimdall
CVE-2026-11881 (The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11870 (The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does n ...)
@@ -1757,15 +1757,15 @@ CVE-2026-11867 (The Frontend Admin by DynamiApps WordPress plugin before 3.29.7
CVE-2026-11782 (The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 ...)
NOT-FOR-US: WordPress plugin
CVE-2025-69949 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-69945 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-69944 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-69943 (kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injectio ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-69942 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-67408 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to ...)
NOT-FOR-US: SourceCodester
CVE-2025-67407 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to ...)
@@ -1779,7 +1779,7 @@ CVE-2025-67404 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerab
CVE-2025-67403 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to ...)
NOT-FOR-US: SourceCodester
CVE-2025-65340 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
- TODO: check
+ NOT-FOR-US: kishan0725 Hospital Management System
CVE-2025-65337 (Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scri ...)
NOT-FOR-US: SourceCodester
CVE-2025-14562 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27064b5af6cdc145a7598c9611edd89f2e02828c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27064b5af6cdc145a7598c9611edd89f2e02828c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/f49006ae/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list