[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 31 09:25:50 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e8cc8a89 by Salvatore Bonaccorso at 2026-07-31T10:25:08+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -103,35 +103,35 @@ CVE-2026-61893 (A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) an
CVE-2026-61526 (AdonisJS HTTP Server is a package for handling HTTP requests in the Ad ...)
NOT-FOR-US: AdonisJS HTTP Server
CVE-2026-5846 (The affectedWatchfire Controller Softwarecontains self-signed hard-cod ...)
- TODO: check
+ NOT-FOR-US: Watchfire
CVE-2026-56758 (The ACSE layer contains a flaw in the processing of AARQ PDUs during M ...)
- TODO: check
+ NOT-FOR-US: MZ Automation
CVE-2026-56673 (ComfyUI is a modular diffusion model GUI, API, and backend with a grap ...)
- TODO: check
+ NOT-FOR-US: ComfyUI
CVE-2026-56672 (ComfyUI is a node-based diffusion model GUI, API, and backend. Prior t ...)
- TODO: check
+ NOT-FOR-US: ComfyUI
CVE-2026-56671 (ComfyUI is a modular diffusion model GUI, api and backend with a graph ...)
- TODO: check
+ NOT-FOR-US: ComfyUI
CVE-2026-56670 (ComfyUI is a modular diffusion model GUI, api and backend with a graph ...)
- TODO: check
+ NOT-FOR-US: ComfyUI
CVE-2026-55777 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
TODO: check
CVE-2026-55768 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
TODO: check
CVE-2026-55502 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
- TODO: check
+ NOT-FOR-US: Cloudreve
CVE-2026-55499 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
- TODO: check
+ NOT-FOR-US: Cloudreve
CVE-2026-55497 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
- TODO: check
+ NOT-FOR-US: Cloudreve
CVE-2026-55496 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
- TODO: check
+ NOT-FOR-US: Cloudreve
CVE-2026-55495 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
- TODO: check
+ NOT-FOR-US: Cloudreve
CVE-2026-54715 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
TODO: check
CVE-2026-52539 (Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When t ...)
- TODO: check
+ NOT-FOR-US: Outstatic CMS
CVE-2026-43833 (Full details and mitigation steps are currently restricted and will be ...)
TODO: check
CVE-2026-43832 (Full details and mitigation steps are currently restricted and will be ...)
@@ -143,15 +143,15 @@ CVE-2026-43830 (Full details and mitigation steps are currently restricted and w
CVE-2026-43829 (Full details and mitigation steps are currently restricted and will be ...)
TODO: check
CVE-2026-38709 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 ...)
- TODO: check
+ NOT-FOR-US: Cudy
CVE-2026-35847 (An issue in dnsmgr v.2.15 and before allows a local attacker to execut ...)
- TODO: check
+ NOT-FOR-US: dnsmgr
CVE-2026-18452 (DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Cre ...)
- TODO: check
+ NOT-FOR-US: Rich Source
CVE-2026-18157 (A flaw was found in yggdrasil-worker-package-manager. A local attacker ...)
- TODO: check
+ NOT-FOR-US: yggdrasil-worker-package-manager
CVE-2026-18064 (An incomplete fix for CVE-2026-15352 in the NASA core Flight System ( ...)
- TODO: check
+ NOT-FOR-US: NASA HS
CVE-2026-16236 (The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitra ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15381 (The WP Go Maps WordPress plugin before 10.1.04 does not properly sani ...)
@@ -197,15 +197,15 @@ CVE-2026-14830 (The FlxWoo WordPress plugin before 3.1.1 does not verify with th
CVE-2026-14554 (The Check & Log Email WordPress plugin before 2.0.15 does not properl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14541 (An authentication bypass and audience confusion vulnerability exists i ...)
- TODO: check
+ NOT-FOR-US: Google mcp-toolbox
CVE-2026-14540 (A Server-Side Request Forgery (SSRF) vulnerability exists in the gener ...)
- TODO: check
+ NOT-FOR-US: Google mcp-toolbox
CVE-2026-14539 (An allocation of resources without limits vulnerability in the HTTP ha ...)
- TODO: check
+ NOT-FOR-US: Google mcp-toolbox
CVE-2026-14538 (An improper authorization and security-boundary bypass vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Google mcp-toolbox
CVE-2026-14537 (Incorrect Authorization in the direct HTTP API tool invocation endpoin ...)
- TODO: check
+ NOT-FOR-US: Google mcp-toolbox
CVE-2026-14483 (The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14333 (The Demi WordPress plugin before 0.0.7 stores its full-site backup ar ...)
@@ -231,7 +231,7 @@ CVE-2026-12697 (The wpForo Forum WordPress plugin before 3.1.2 does not verify t
CVE-2026-12695 (The miniOrange 2FA WordPress plugin before 6.2.6 does not validate th ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12562 (The RCU II+ and Multiload II+ are vulnerable to an unauthenticated se ...)
- TODO: check
+ NOT-FOR-US: RCU II+ and Multiload II+
CVE-2026-12376 (The Academy LMS WordPress plugin through 3.8.2 does not restrict acces ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12251 (The Ultimate Member WordPress plugin before 2.12.1 does not filter ad ...)
@@ -265,11 +265,11 @@ CVE-2025-69930 (CodeAstro Membership Management System 1.0 is vulnerable to SQL
CVE-2025-65342 (code-projects Blood System 1.0 is vulnerable to Cross Site Scripting ( ...)
NOT-FOR-US: code-projects
CVE-2025-65341 (Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) ...)
- TODO: check
+ NOT-FOR-US: Ecommerce Fruits Bazar
CVE-2025-65336 (Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable t ...)
- TODO: check
+ NOT-FOR-US: Ecommerce-project-with-php-and-mysqli-Fruits-Bazar
CVE-2025-51684 (CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). ...)
- TODO: check
+ NOT-FOR-US: CleverTap Web SDK
CVE-2026-9322 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
NOT-FOR-US: IBM
CVE-2026-7849 (Due to improper neutralization of special elements, an unauthenticated ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8cc8a89f63130c193ab68e927dd7e866f327d65
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8cc8a89f63130c193ab68e927dd7e866f327d65
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/b76b0175/attachment.htm>
More information about the debian-security-tracker-commits
mailing list