[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 3 15:18:19 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3d65ecce by Moritz Muehlenhoff at 2026-09-03T16:17:58+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1621,9 +1621,9 @@ CVE-2026-59696 (Improper Validation of Specified Quantity in Input vulnerability
 	NOTE: Fixed by: https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa (OTP-29.0.6, OTP-28.5.0.6)
 	NOTE: Fixed by: https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d (OTP-27.3.4.17)
 CVE-2026-59681 (A OS command injection vulnerability in yast2-auth-client allows an at ...)
-	TODO: check
+	NOT-FOR-US: SuSE
 CVE-2026-59680 (An OS command injection vulnerability was found in yast2-users. When d ...)
-	TODO: check
+	NOT-FOR-US: SuSE
 CVE-2026-58575 (Dell PowerStore contains an Authentication Bypass by Spoofing vulnerab ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-58572 (Dell PowerStore contains a Code Injection vulnerability. An authentica ...)
@@ -1668,13 +1668,13 @@ CVE-2026-52023 (An issue in kamailio v.6.1.1 and before allows a remote attacker
 CVE-2026-52022 (An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...)
 	TODO: check
 CVE-2026-51974 (An eval() injection vulnerability in the get_list function in modules/ ...)
-	TODO: check
+	NOT-FOR-US: Fooocus
 CVE-2026-51956 (A Broken Object Level Authorization vulnerability exists in Grashjs At ...)
 	TODO: check
 CVE-2026-51934 (Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co ...)
 	NOT-FOR-US: Tenda
 CVE-2026-51788 (An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause ...)
-	TODO: check
+	NOT-FOR-US: cleverange_auth
 CVE-2026-51770 (Incorrect access control in the sendToMasterQosConfig function of TOTO ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-51769 (Incorrect access control in the remoteCloudUpdateCheck function of TOT ...)
@@ -1724,11 +1724,11 @@ CVE-2026-51742 (Incorrect access control in the discoverWan function of TOTOLINK
 CVE-2026-51741 (Incorrect access control in the clearDiagnosisLog function of TOTOLINK ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-4813 (A vulnerability in the Lutece Core XSL export management module up to  ...)
-	TODO: check
+	NOT-FOR-US: Lutece Core
 CVE-2026-49329 (A flaw was found in openshift/oauth-server. The OAuth login and error  ...)
 	NOT-FOR-US: Red Hat OpenShift Container Platform
 CVE-2026-25706 (Improper neutralization of special elements used in an OS command in y ...)
-	TODO: check
+	NOT-FOR-US: SuSE
 CVE-2026-19914 (The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cr ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19593 (OpenAI Codex Desktop for Windows and macOS automatically inspected Git ...)
@@ -1746,21 +1746,21 @@ CVE-2026-19472 (A denial-of-service security issue exists within ArmorStart\xae
 CVE-2026-19471 (Multiple stored cross-site scripting security issues exist within Armo ...)
 	NOT-FOR-US: Rockwell Automation
 CVE-2026-18931 (Use of Hard-coded Credentials vulnerability in TMT Machine Industry an ...)
-	TODO: check
+	NOT-FOR-US: TMT Machine Industry and Trade
 CVE-2026-18808 (Improper Control of Generation of Code ('Code Injection') vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Klemsan Electrical Electronics
 CVE-2026-18780 (Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industr ...)
-	TODO: check
+	NOT-FOR-US: TMT Machine Industry and Trade
 CVE-2026-18771 (Missing authentication for critical function vulnerability in TMT Mach ...)
-	TODO: check
+	NOT-FOR-US: TMT Machine Industry and Trade
 CVE-2026-18765 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: Teracity Software Technologies
 CVE-2026-18630 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: TMT Machine Industry and Trade
 CVE-2026-18550 (The Nokri - Job Board WordPress Theme for WordPress is vulnerable to P ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18210 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: Klemsan Electrical Electronics
 CVE-2026-16788 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16786 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
@@ -1788,7 +1788,7 @@ CVE-2026-10420 (Untrusted pointer dereference vulnerability in Samsung Open Sour
 CVE-2026-10195 (The FS-Poster plugin for WordPress is vulnerable to Remote Code Execut ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-15613 (Kyverno before v1.13.4 is vulnerable to server-side request forgery (S ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2025-12768 (A security issue exists within FactoryTalk\xae Historian Machine Editi ...)
 	NOT-FOR-US: Rockwell Automation
 CVE-2024-7953 (A vulnerability exists in the affected products that allows a threat a ...)
@@ -1796,11 +1796,11 @@ CVE-2024-7953 (A vulnerability exists in the affected products that allows a thr
 CVE-2024-7952 (A data exposure vulnerability exists in the affected product. There ar ...)
 	NOT-FOR-US: Rockwell Automation
 CVE-2024-14047 (A local vulnerability in the Winlogbeat Windows installer caused runti ...)
-	TODO: check
+	NOT-FOR-US: Elastic Security
 CVE-2024-10085 (CWE-770: Allocation of Resources Without Limits or Throttlingvulnerabi ...)
 	NOT-FOR-US: Schneider Electric
 CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-84145 (Internally found bugs present in Thunderbird 154, Thunderbird ESR 153. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d65eccef1989f1894edf170ada507e6d6f613df

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d65eccef1989f1894edf170ada507e6d6f613df
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/2a3bc655/attachment.htm>


More information about the debian-security-tracker-commits mailing list