[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 2 21:14:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d4cc664a by Salvatore Bonaccorso at 2026-09-02T22:14:05+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
CVE-2026-8151 (The Simple Membership MailChimp Integration WordPress plugin before 1. ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84841 (A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5 ...)
- TODO: check
+ NOT-FOR-US: tsi-coop tsi-dpdp-cms
CVE-2026-84840 (A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. T ...)
- TODO: check
+ NOT-FOR-US: tsi-coop tsi-dpdp-cms
CVE-2026-84839 (A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. A ...)
- TODO: check
+ NOT-FOR-US: tsi-coop tsi-dpdp-cms
CVE-2026-84838 (A flaw was found in rpmuncompress. This command injection vulnerabilit ...)
TODO: check
CVE-2026-84837 (A flaw was found in rpm. An attacker can exploit a command injection v ...)
@@ -13,23 +13,23 @@ CVE-2026-84837 (A flaw was found in rpm. An attacker can exploit a command injec
CVE-2026-84835 (Missing Authorization vulnerability in DimaFreund Rentsyst allows Expl ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-84833 (A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa ...)
- TODO: check
+ NOT-FOR-US: ntegrals openbrowser
CVE-2026-84811 (agentverus-scanner fails to analyze compiled Python bytecode files in ...)
- TODO: check
+ NOT-FOR-US: agentverus-scanner
CVE-2026-84810 (claude-skill-antivirus fails to analyze executable files when scanning ...)
- TODO: check
+ NOT-FOR-US: claude-skill-antivirus
CVE-2026-84809 (Tencent AI-Infra-Guard's skill-scan component excludes compiled Python ...)
- TODO: check
+ NOT-FOR-US: Tencent AI-Infra-Guard
CVE-2026-84808 (Kimai versions before 2.65.0 contain an authorization bypass vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84807 (Kimai (kimai/kimai) through 2.65.0 contains a business logic / imprope ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84806 (Kimai before 2.63.0 contains an improper authorization vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84805 (Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only wo ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84804 (Kimai before 2.65.0 fails to properly validate permissions when removi ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-84803 (SiYuan before v3.8.2 contains a stored cross-site scripting vulnerabil ...)
NOT-FOR-US: SiYuan
CVE-2026-84802 (Craft CMS versions from 5.7.0 before 5.10.12 contain an information di ...)
@@ -149,9 +149,9 @@ CVE-2026-84379 (HTTPX2 is a next generation HTTP client for Python. Prior to 2.1
CVE-2026-84378 (HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2 ...)
TODO: check
CVE-2026-84377 (LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or ...)
- TODO: check
+ NOT-FOR-US: LiteLLM
CVE-2026-84376 (Astro is a web framework for content-driven websites. Prior to 7.2.4, ...)
- TODO: check
+ NOT-FOR-US: Astro
CVE-2026-84217 (Missing Authorization vulnerability in Mamunur Rashid Classified Listi ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-84175 (In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches W ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4cc664a08fea27aa51977d1b12d5a29d68ae37a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d4cc664a08fea27aa51977d1b12d5a29d68ae37a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/28dcf6c2/attachment.htm>
More information about the debian-security-tracker-commits
mailing list