[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 3 15:40:33 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
feaff430 by Moritz Muehlenhoff at 2026-09-03T16:32:59+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -482,7 +482,7 @@ CVE-2026-19475 (An authenticated user with permission to query a SQL data source
 CVE-2026-19219 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812, insuffic ...)
 	NOT-FOR-US: Progress Software
 CVE-2026-19117 (Under specific conditions, an attacker can register an attacker-contro ...)
-	TODO: check
+	NOT-FOR-US: Delinea
 CVE-2026-18986 (Improper Neutralization of Input During Web Page Generation ("Cross-si ...)
 	NOT-FOR-US: Drupal core and addons
 CVE-2026-18672 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812, insuffic ...)
@@ -963,7 +963,7 @@ CVE-2026-63137 (Incorrect Authorization (CWE-863) in Kibana can lead to privileg
 CVE-2026-56143 (Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-45221 (Konga before 2.1.0 contains a privilege escalation vulnerability that  ...)
-	TODO: check
+	NOT-FOR-US: Konga
 CVE-2026-3851 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-3850 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
@@ -973,7 +973,7 @@ CVE-2026-33465 (Allocation of Resources Without Limits or Throttling (CWE-770) i
 CVE-2026-19766 (An authentication bypass vulnerability exists in the underlying operat ...)
 	NOT-FOR-US: HPE
 CVE-2026-19754 (Baserow 2.3.3 contains a SQL injection vulnerability in the index() fo ...)
-	TODO: check
+	NOT-FOR-US: Baserow
 CVE-2026-19723 (The Social Media Share Buttons & Social Sharing Icons WordPress plugin ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19719 (The Social Media Share Buttons & Social Sharing Icons WordPress plugin ...)
@@ -1662,7 +1662,7 @@ CVE-2026-52131 (llama.cpp b5693 and before has a Reachable Assertion via the ggu
 CVE-2026-52130 (llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in  ...)
 	TODO: check
 CVE-2026-52111 (An issue in fast-note-sync-service <=2.13.7 allows a remote attacker t ...)
-	TODO: check
+	NOT-FOR-US: fast-note-sync-service
 CVE-2026-52023 (An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...)
 	TODO: check
 CVE-2026-52022 (An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...)
@@ -1670,7 +1670,7 @@ CVE-2026-52022 (An issue in kamailio v.6.1.1 and before allows a remote attacker
 CVE-2026-51974 (An eval() injection vulnerability in the get_list function in modules/ ...)
 	NOT-FOR-US: Fooocus
 CVE-2026-51956 (A Broken Object Level Authorization vulnerability exists in Grashjs At ...)
-	TODO: check
+	NOT-FOR-US: Grashjs Atlas CMMS
 CVE-2026-51934 (Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co ...)
 	NOT-FOR-US: Tenda
 CVE-2026-51788 (An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause ...)
@@ -2169,7 +2169,7 @@ CVE-2026-54598 (Wallos is an open-source, self-hostable personal subscription tr
 CVE-2026-54179 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
 	TODO: check
 CVE-2026-52730 (Xibo is an open source digital signage platform with a web content man ...)
-	TODO: check
+	NOT-FOR-US: Xibo
 CVE-2026-51740 (Incorrect access control in the killProcess function of TOTOLINK T6 4. ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-51739 (Incorrect access control in the CloudSrvVersionCheck function of TOTOL ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/feaff430d33aa44d58e813eb92dd55b567c365f2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/feaff430d33aa44d58e813eb92dd55b567c365f2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/539adb13/attachment.htm>


More information about the debian-security-tracker-commits mailing list