[Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 3 07:34:23 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4e729860 by Salvatore Bonaccorso at 2026-09-03T08:28:00+02:00
Process NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1425,7 +1425,7 @@ CVE-2026-79682 (Dell PowerStore contains a Command Injection vulnerability. An a
CVE-2026-78363 (The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcod ...)
NOT-FOR-US: WordPress plugin
CVE-2026-78012 (An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow ...)
- TODO: check
+ NOT-FOR-US: NetStaX
CVE-2026-77194 (The Simple Membership plugin for WordPress is vulnerable to Authentica ...)
NOT-FOR-US: WordPress plugin
CVE-2026-76111 (Dell PowerStore contains an Incorrect Authorization vulnerability. An ...)
@@ -1445,7 +1445,7 @@ CVE-2026-73276 (Gracefulness code ignored cases that should be rejected, resulti
CVE-2026-73270 (Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inet ...)
TODO: check
CVE-2026-71562 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
- TODO: check
+ NOT-FOR-US: fosrl/pangolin
CVE-2026-71380 (Missing Release of Resource after Effective Lifetime vulnerability in ...)
TODO: check
CVE-2026-70409 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
@@ -2400,9 +2400,9 @@ CVE-2026-75132 (WAPT Server versions 2.6.1.17834 and earlier contains a SQL inje
CVE-2026-74010 (Missing Authorization vulnerability in John James Jacoby bbPress allow ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73819 (The affectedEbyte product's vendor configuration utility permits acc ...)
- TODO: check
+ NOT-FOR-US: Ebyte
CVE-2026-72001 (Pangolin before 1.22.0 contains an authentication bypass vulnerability ...)
- TODO: check
+ NOT-FOR-US: fosrl/pangolin
CVE-2026-71378 (ResourceIsolationRequestCycleListener protects a Wicket application ag ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-71257 (Apache Wicket enforces the upload limits configured on a form or uploa ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e7298607869d4c756e175abdd4a5dc04c21abc4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e7298607869d4c756e175abdd4a5dc04c21abc4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/e1d1dee4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list