[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 4 13:41:59 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2b171171 by Salvatore Bonaccorso at 2026-09-04T14:41:27+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -228,17 +228,17 @@ CVE-2026-79631 (The WPFunnels WordPress plugin before 3.13.0 does not restrict
CVE-2026-79630 (The WPFunnels WordPress plugin before 3.13.0 does not verify that the ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77465 (toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0 ...)
- TODO: check
+ NOT-FOR-US: toml-node
CVE-2026-75754 (Missing Authentication for Critical Function, Server-Side Request Forg ...)
NOT-FOR-US: ASUS
CVE-2026-74853 (The Pods WordPress plugin before 3.3.9.2 does not restrict which func ...)
NOT-FOR-US: WordPress plugin
CVE-2026-71429 (stream-json is a micro-library of stream components for processing JSO ...)
- TODO: check
+ NOT-FOR-US: stream-json
CVE-2026-71216 (PagerDuty alarm hook transmits the integration routing key over cleart ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-70403 (XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Any ...)
- TODO: check
+ NOT-FOR-US: XING CPTrans-ME-X
CVE-2026-70352 (Missing authentication for critical function in Azure AI Language allo ...)
NOT-FOR-US: Microsoft
CVE-2026-70178 (Missing authorization in Microsoft Fabric allows an authorized attacke ...)
@@ -246,15 +246,15 @@ CVE-2026-70178 (Missing authorization in Microsoft Fabric allows an authorized a
CVE-2026-69857 (Authorization bypass through user-controlled key in Azure Cosmos DB al ...)
NOT-FOR-US: Microsoft
CVE-2026-69657 (XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyon ...)
- TODO: check
+ NOT-FOR-US: XING CPTrans-ME-X
CVE-2026-67402 (An insecure Apache configuration in ConfigServer Security & Firewall m ...)
- TODO: check
+ NOT-FOR-US: ConfigServer Security & Firewall
CVE-2026-67398 (Missing authorization vulnerability has been discovered in 2Checkout p ...)
- TODO: check
+ NOT-FOR-US: WHMCS
CVE-2026-67397 (Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0 ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-66840 (XING CPTrans-ME-X contains an Exposure of Sensitive System Information ...)
- TODO: check
+ NOT-FOR-US: XING CPTrans-ME-X
CVE-2026-65818 (Server-side request forgery (ssrf) in Power Automate allows an authori ...)
NOT-FOR-US: Microsoft
CVE-2026-64200 (There is an out-of-bounds read vulnerability in DASYLab due to imprope ...)
@@ -703,11 +703,11 @@ CVE-2026-82299 (Incorrect Authorization (CWE-863) in Kibana can lead to informat
CVE-2026-82298 (Incorrect Authorization (CWE-863) in Kibana can lead to denial of serv ...)
- kibana <itp> (bug #700337)
CVE-2026-82180 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is ...)
- TODO: check
+ NOT-FOR-US: Eclipse Arrowhead
CVE-2026-82024 (LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site ...)
- TODO: check
+ NOT-FOR-US: WordPress Plugin
CVE-2026-82023 (LearnPress WordPress Plugin before 4.4.6 contains a broken object-leve ...)
- TODO: check
+ NOT-FOR-US: WordPress Plugin
CVE-2026-81776 (Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 v ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81773 (Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Upload ...)
@@ -723,13 +723,13 @@ CVE-2026-81282 (Subscriber Cross Site Scripting (XSS) in Product Variations Swat
CVE-2026-81281 (Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-80515 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-autho ...)
- TODO: check
+ NOT-FOR-US: Eclipse Arrowhead
CVE-2026-80465 (A vulnerability has been identified in Mendix SAML (Mendix 10 compatib ...)
NOT-FOR-US: Siemens
CVE-2026-80254 (Authorization bypass through user-controlled key issue exists in Shize ...)
- TODO: check
+ NOT-FOR-US: ShizenBox2 (edge-app)
CVE-2026-80253 (An improper physical access control issue exists in ShizenBox2 (dev-co ...)
- TODO: check
+ NOT-FOR-US: ShizenBox2
CVE-2026-79679 (Use of Weak Credentials vulnerability in B&R Industrial Automation Gmb ...)
NOT-FOR-US: ABB group
CVE-2026-78596 (Missing Authorization in Kibana Leading to Unauthorized Modification o ...)
@@ -765,23 +765,23 @@ CVE-2026-76175 (SQL injection vulnerability in the del_check parameter of the /o
CVE-2026-76174 (Unrestricted file upload vulnerability in the CSV file upload function ...)
TODO: check
CVE-2026-75602 (OpenList a file list program that supports multiple storage. Prior to ...)
- TODO: check
+ NOT-FOR-US: OpenList
CVE-2026-75137 (UpSignOn for Windows before 7.19.0 contains a sensitive data exposure ...)
- TODO: check
+ NOT-FOR-US: UpSignOn
CVE-2026-75136 (UpSignOn for Windows before 7.19.0 contains an insecure credential sto ...)
- TODO: check
+ NOT-FOR-US: UpSignOn
CVE-2026-75135 (UpSignOn for Windows before 7.19.0 contains a sensitive data exposure ...)
- TODO: check
+ NOT-FOR-US: UpSignOn
CVE-2026-75134 (SEOWriting plugin for WordPress through 1.12.5 contains a stored cross ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75036 (A security vulnerability was discovered in Fleet's Helm template prepr ...)
- TODO: check
+ NOT-FOR-US: Rancher Fleet
CVE-2026-75035 (A flaw was found in Rancher Manager. When a non-administrative caller ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-75034 (A flaw was found in Rancher Manager. The SAML assertion replay protect ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-75033 (A flaw was found in Rancher Manager. Project Secrets were propagated i ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-74769 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
NOT-FOR-US: Dell / EMC
CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
@@ -789,11 +789,11 @@ CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, con
CVE-2026-73600 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
NOT-FOR-US: Dell / EMC
CVE-2026-71963 (Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains ...)
- TODO: check
+ NOT-FOR-US: Hermes Agent
CVE-2026-71404 (A flaw was found in Rancher Manager. The GlobalRole controller derived ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-71403 (A flaw was found in Rancher Manager. The /v3/users update path did not ...)
- TODO: check
+ NOT-FOR-US: Rancher
CVE-2026-71224 (A stack overflow vulnerability was found in gfs2-utils. The metadata w ...)
- gfs2-utils <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511397
@@ -3643,7 +3643,7 @@ CVE-2026-71257 (Apache Wicket enforces the upload limits configured on a form or
CVE-2026-70449 (Improper validation of resource URL attributes in Apache Wicket allows ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-63083
REJECTED
CVE-2026-5956 (Improper neutralization of special elements used in an SQL command ('S ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b171171ddda81673ab3aefd94ed1c99f715b649
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b171171ddda81673ab3aefd94ed1c99f715b649
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/6d04fcdc/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list