[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Sep 6 08:19:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a8ac0cca by Salvatore Bonaccorso at 2026-09-06T09:18:57+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
CVE-2026-86218 (N-central is vulnerable to a pre-auth remote code execution This issue ...)
- TODO: check
+ NOT-FOR-US: N-central
CVE-2026-86207 (An authentication bypass in N-central < 2026.3 HF 3 leads to authentic ...)
- TODO: check
+ NOT-FOR-US: N-central
CVE-2026-86206 (A vulnerability in the N-central internal API access control filter al ...)
- TODO: check
+ NOT-FOR-US: N-central
CVE-2026-86171 (A security vulnerability has been detected in DefaultFuction CRM 1.0.0 ...)
- TODO: check
+ NOT-FOR-US: DefaultFuction CRM
CVE-2026-86170 (A weakness has been identified in DefaultFuction CRM 1.0.0. The impact ...)
- TODO: check
+ NOT-FOR-US: DefaultFuction CRM
CVE-2026-86168 (A security flaw has been discovered in code-projects Content Managemen ...)
NOT-FOR-US: code-projects
CVE-2026-86167 (A vulnerability was identified in Tenda HG10 300001138. Impacted is th ...)
@@ -41,7 +41,7 @@ CVE-2026-86149 (A weakness has been identified in Tenda CP3 27.5.57.101. This is
CVE-2026-86148 (A security flaw has been discovered in Tenda CP3 27.5.57.101. This vul ...)
NOT-FOR-US: Tenda
CVE-2026-86060 (RouterOS contains an argument-handling flaw in the SSH login path invo ...)
- TODO: check
+ NOT-FOR-US: RouterOS
CVE-2026-85038 (The B2BKing \u2014 Ultimate WooCommerce B2B and Wholesale Plugin \u201 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84219 (The Kirki WordPress plugin before 6.3.0 does not hold back every spel ...)
@@ -57,15 +57,15 @@ CVE-2026-75816 (The Frontend Admin by DynamiApps plugin for WordPress is vulnera
CVE-2026-75793 (The SureCart WordPress plugin before 4.7.0 does not consult the site' ...)
NOT-FOR-US: WordPress plugin
CVE-2026-67281 (RouterOS WebFig contains an unauthenticated file-read vulnerability in ...)
- TODO: check
+ NOT-FOR-US: RouterOS
CVE-2026-67279 (RouterOS SSH enters the connection protocol after a client-requested r ...)
- TODO: check
+ NOT-FOR-US: RouterOS
CVE-2026-67278 (MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during ...)
NOT-FOR-US: MikroTik
CVE-2026-67277 (RouterOS accepts a "related" btest connection before the corresponding ...)
- TODO: check
+ NOT-FOR-US: RouterOS
CVE-2026-67276 (RouterOS does not compare the complete RSA public key when matching an ...)
- TODO: check
+ NOT-FOR-US: RouterOS
CVE-2026-18480 (The SureCart WordPress plugin before 4.6.3 does not ensure that the a ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18056 (The HivePress Authentication plugin for WordPress is vulnerable to Aut ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8ac0ccaa86b23e8bb97bbe3262b540b2ee32e98
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8ac0ccaa86b23e8bb97bbe3262b540b2ee32e98
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/063c1b10/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list