[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 9 16:24:44 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c717408a by Moritz Muehlenhoff at 2026-09-09T17:24:24+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -708,7 +708,7 @@ CVE-2026-81975 (Acrobat Reader is affected by a Use After Free vulnerability tha
CVE-2026-81973 (Acrobat Reader is affected by a Use After Free vulnerability that coul ...)
NOT-FOR-US: Adobe
CVE-2026-81904 (Concrete CMS below 9.5.3 registered view assets for every sub-block of ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-81741 (The Groundhogg \u2014 CRM, Newsletters, and Marketing Automation WordP ...)
NOT-FOR-US: WordPress plugin
CVE-2026-81647 (Out-of-bounds read vulnerability in the graphics module. Impact: Succe ...)
@@ -718,7 +718,7 @@ CVE-2026-81646 (Out-of-bounds read vulnerability in the graphics module. Impact:
CVE-2026-81644 (DoS vulnerability in the preview service module. Impact: Successful ex ...)
NOT-FOR-US: Huawei
CVE-2026-81192 (`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelem ...)
- TODO: check
+ NOT-FOR-US: opentelemetry-dotnet-contrib
CVE-2026-81022 (The SupportCandy WordPress plugin before 3.5.3 does not validate a su ...)
NOT-FOR-US: WordPress plugin
CVE-2026-81021 (The SupportCandy WordPress plugin before 3.5.3 does not perform an au ...)
@@ -754,17 +754,17 @@ CVE-2026-79907 (Acrobat Reader is affected by a Double Free vulnerability that c
CVE-2026-79905 (Adobe Experience Manager is affected by a stored Cross-Site Scripting ...)
NOT-FOR-US: Adobe
CVE-2026-79588 (U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmissi ...)
- TODO: check
+ NOT-FOR-US: U-speed WIFI4 N300
CVE-2026-78971 (In Halo <= 2.25.4, the plugin management feature allows users to insta ...)
- TODO: check
+ NOT-FOR-US: Halo
CVE-2026-78834 (A code execution vulnerability exists in CMSimple 5.22 in the CoAuthor ...)
- TODO: check
+ NOT-FOR-US: CMSimple
CVE-2026-78742 (Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) vi ...)
- TODO: check
+ NOT-FOR-US: Silverpeas
CVE-2026-78741 (Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in ...)
- TODO: check
+ NOT-FOR-US: Silverpeas
CVE-2026-78738 (Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via ...)
- TODO: check
+ NOT-FOR-US: Silverpeas
CVE-2026-78635 (The Okta Privileged Access client URL handler does not insert an optio ...)
NOT-FOR-US: Okta
CVE-2026-78631 (The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to ...)
@@ -800,7 +800,7 @@ CVE-2026-78550 (The Okta Access Gateway management console passes user-supplied
CVE-2026-78545 (The Okta Access Gateway does not sanitize the application label field ...)
NOT-FOR-US: Okta
CVE-2026-77827 (Maono Link 3.8.13 MaonoAiServices Windows service allows local privile ...)
- TODO: check
+ NOT-FOR-US: MaonoAiServicesHalo
CVE-2026-77187 (The My Calendar \u2013 Accessible Event Manager plugin for WordPress i ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77186 (The My Calendar \u2013 Accessible Event Manager plugin for WordPress i ...)
@@ -1020,25 +1020,25 @@ CVE-2026-71356 (Adobe Experience Manager is affected by a DOM-based Cross-Site S
CVE-2026-6485 (UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell ...)
NOT-FOR-US: Insyde
CVE-2026-55250 (Maravel, a PHP framework oriented towards dependency injection, prior ...)
- TODO: check
+ NOT-FOR-US: Maravel
CVE-2026-53939 (OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
TODO: check
CVE-2026-53938 (OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
TODO: check
CVE-2026-53937 (MCP Kotlin SDK is the Kotlin Multiplatform software development kit fo ...)
- TODO: check
+ NOT-FOR-US: MCP Kotlin SDK
CVE-2026-53933 (Maravel, a PHP framework oriented towards dependency injection, prior ...)
- TODO: check
+ NOT-FOR-US: Maravel
CVE-2026-53639 (Sylius is an Open Source eCommerce Framework on Symfony. Starting in v ...)
- TODO: check
+ NOT-FOR-US: Sylius
CVE-2026-53638 (Sylius is an Open Source eCommerce Framework on Symfony. Starting in v ...)
- TODO: check
+ NOT-FOR-US: Sylius
CVE-2026-53637 (Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0. ...)
- TODO: check
+ NOT-FOR-US: Sylius
CVE-2026-53581 (OPNsense is a FreeBSD based firewall and routing platform. Prior to ve ...)
- TODO: check
+ NOT-FOR-US: OPNsense
CVE-2026-52486 (An issue in OpenDDS 3.33.x allows a local attacker to cause a denial o ...)
- TODO: check
+ NOT-FOR-US: OpenDDS
CVE-2026-49883 (In checkReadPermission of PermissionsManager.java, there is a possible ...)
NOT-FOR-US: Android
CVE-2026-49315 (DoS vulnerability in the input device module. Impact: Successful explo ...)
@@ -1066,7 +1066,7 @@ CVE-2026-49153
CVE-2026-48273 (ColdFusion is affected by an Improper Neutralization of Directives in ...)
NOT-FOR-US: Adobe
CVE-2026-47680 (The source-controller is a Kubernetes operator, specialised in artifac ...)
- TODO: check
+ NOT-FOR-US: source-controller Kubernetes operator
CVE-2026-45220
REJECTED
CVE-2026-45219
@@ -1196,7 +1196,7 @@ CVE-2026-11821 (The Eventin \u2013 Event Calendar, Event Registration, Tickets &
CVE-2026-11363 (The Ninja Forms \u2013 The Contact Form Builder That Grows With You pl ...)
NOT-FOR-US: WordPress plugin
CVE-2025-7062 (A stored cross-site scripting (XSS) vulnerability has been identified ...)
- TODO: check
+ NOT-FOR-US: h5p-nodejs-library
CVE-2025-64868 (Adobe Experience Manager is affected by a stored Cross-Site Scripting ...)
NOT-FOR-US: Adobe
CVE-2025-64866 (Adobe Experience Manager is affected by a stored Cross-Site Scripting ...)
@@ -2027,7 +2027,7 @@ CVE-2026-76191 (Animate is affected by an Improper Control of Generation of Code
CVE-2026-75156 (Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not valida ...)
NOT-FOR-US: Apache Airflow provider
CVE-2026-75021 (fastify-cli starts the Node.js Inspector when a debug flag is used, bu ...)
- TODO: check
+ NOT-FOR-US: fastify-cli
CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A remote att ...)
TODO: check
CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts user-supplied ZIP a ...)
@@ -3704,15 +3704,15 @@ CVE-2026-3174 (The Event Tickets and Registration plugin for WordPress is vulner
CVE-2026-34223 (A vulnerability has been identified in Desigo CC ClickOnce Client V6 ( ...)
NOT-FOR-US: Siemens
CVE-2026-33920 (A cross-site request forgery vulnerability was discovered in the login ...)
- TODO: check
+ NOT-FOR-US: Nozomi Networks Guardian
CVE-2026-33391 (An access control vulnerability was discovered in the Smart Polling co ...)
- TODO: check
+ NOT-FOR-US: Nozomi Networks Guardian
CVE-2026-33389 (An improper certificate/host key validation vulnerability was discover ...)
- TODO: check
+ NOT-FOR-US: Nozomi Networks Guardian
CVE-2026-33388 (An access control vulnerability was discovered in the Credentials Mana ...)
- TODO: check
+ NOT-FOR-US: Nozomi Networks Guardian
CVE-2026-33387 (A template injection vulnerability was discovered in the Dashboards fu ...)
- TODO: check
+ NOT-FOR-US: Nozomi Networks Guardian
CVE-2026-33197 (AMI APTIOV contains a vulnerability in BIOS where a privileged user ma ...)
NOT-FOR-US: AMI
CVE-2026-2520 (The Online Scheduling and Appointment Booking System \u2013 Bookly plu ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c717408ae8267a37934ac76ce02401883a0e1a14
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c717408ae8267a37934ac76ce02401883a0e1a14
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/3416a6df/attachment.htm>
More information about the debian-security-tracker-commits
mailing list