[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 12 10:11:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eb41839e by Salvatore Bonaccorso at 2026-09-12T11:10:53+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -127,7 +127,7 @@ CVE-2026-80494 (The Yogeta WP Cloud WordPress plugin through 1.0 does not valida
CVE-2026-80491 (The SAMO Forms WordPress plugin through 1.0.0 does not properly saniti ...)
NOT-FOR-US: WordPress plugin
CVE-2026-79035 (A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.c ...)
- TODO: check
+ NOT-FOR-US: p.rfihub.com component of Zeta Marketing Platform (ZMP)
CVE-2026-78547 (Out-of-bounds write vulnerability in Citrix Citrix Workspace app for W ...)
NOT-FOR-US: Citrix
CVE-2026-78546 (Out-of-bounds read vulnerability in Citirx Workspace app for Windows. ...)
@@ -157,51 +157,51 @@ CVE-2026-68526 (Concrete CMS before 9.5.3 did not validate an anti-CSRF token in
CVE-2026-54258 (ZoneMinder is a free, open source closed-circuit television software a ...)
TODO: check
CVE-2026-54248 (Doco-CD is a GitOps continuous delivery tool that automatically deploy ...)
- TODO: check
+ NOT-FOR-US: Doco-CD
CVE-2026-54174 (melange allows users to build apk packages using declarative pipelines ...)
- TODO: check
+ NOT-FOR-US: Melange
CVE-2026-54166 (Shelf is a platform for tracking physical assets. Prior to version 1.2 ...)
- TODO: check
+ NOT-FOR-US: Shelf
CVE-2026-54165 (Dobase is an open-source, self-hosted workspace with installable tools ...)
- TODO: check
+ NOT-FOR-US: Dobase
CVE-2026-54135 (AirSane is a SANE frontend, and a scanner server that supports Apple's ...)
TODO: check
CVE-2026-53952 (GetSimple CMS is a content management system (CMS), and GetSimple CMS ...)
- TODO: check
+ NOT-FOR-US: GetSimple CMS
CVE-2026-52630 (SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a ...)
- TODO: check
+ NOT-FOR-US: Woltlab WCF
CVE-2026-50025 (Mousehole is a background service to update a seedbox IP for MAM and w ...)
- TODO: check
+ NOT-FOR-US: Mousehole
CVE-2026-50018 (Hoverfly is an open source API simulation tool. Prior to version 1.12. ...)
- TODO: check
+ NOT-FOR-US: Hoverfly
CVE-2026-50013 (Hoverfly is an open source API simulation tool. Prior to version 1.12. ...)
- TODO: check
+ NOT-FOR-US: Hoverfly
CVE-2026-49992 (Kimai is an open-source time tracking application. Versions prior to 2 ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-49865 (Kimai is an open-source time tracking application. Versions prior to 2 ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-49846 (libks provides foundational support for signalwire C products. Prior t ...)
- TODO: check
+ NOT-FOR-US: libks
CVE-2026-49464 (NL Portal Backend Libraries provide backend components for Dutch gover ...)
- TODO: check
+ NOT-FOR-US: NL Portal Backend Libraries
CVE-2026-49463 (NL Portal Backend Libraries provide backend components for Dutch gover ...)
- TODO: check
+ NOT-FOR-US: NL Portal Backend Libraries
CVE-2026-49462 (NL Portal Backend Libraries provide backend components for Dutch gover ...)
- TODO: check
+ NOT-FOR-US: NL Portal Backend Libraries
CVE-2026-49439 (OpenRemote is an open-source internet-of-things platform. Prior to ver ...)
- TODO: check
+ NOT-FOR-US: OpenRemote
CVE-2026-48496 (OpenTelemetry eBPF Profiler is a production-scale agent for profiling ...)
- TODO: check
+ NOT-FOR-US: OpenTelemetry eBPF Profiler
CVE-2026-48490 (ArduinoCore-avr contains the source code and configuration files of th ...)
- TODO: check
+ NOT-FOR-US: ArduinoCore-avr
CVE-2026-47773 (ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduin ...)
- TODO: check
+ NOT-FOR-US: ArduinoBLE
CVE-2026-45057 (matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk ...)
- TODO: check
+ NOT-FOR-US: matrix-sdk-ui
CVE-2026-45056 (matrix-sdk-crypto is a no-network-IO implementation of a state machine ...)
- TODO: check
+ NOT-FOR-US: matrix-sdk-crypto Rust crate
CVE-2026-44715 (OpenMRS is an open source electronic medical record system platform. P ...)
- TODO: check
+ NOT-FOR-US: OpenMRS
CVE-2026-89673 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/
@@ -1960,7 +1960,7 @@ CVE-2026-80462 (A vulnerability in the Chef Automate API gateway and identity va
CVE-2026-7863 (Improper neutralization of special elements used in an OS command ('OS ...)
NOT-FOR-US: Pardus Software
CVE-2026-7298 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: IdeaSoft Software Industry and Trade Inc. Smart E-Commerce
CVE-2026-79396 (Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmw ...)
NOT-FOR-US: Xiongmai IP Camera XM530 firmware
CVE-2026-79395 (An improper authentication vulnerability in the WS-Security (wsse:User ...)
@@ -1995,13 +1995,13 @@ CVE-2026-72708 (SPIP before 4.4.18 contains an unauthenticated blind SQL injecti
NOTE: https://blog.lexfo.fr/casse-spip-sqli-to-rce.html
NOTE: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html
CVE-2026-71646 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected ...)
- TODO: check
+ NOT-FOR-US: Robotics-STAR-Lab
CVE-2026-71644 (An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected ...)
- TODO: check
+ NOT-FOR-US: Robotics-STAR-Lab
CVE-2026-71641 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99 ...)
- TODO: check
+ NOT-FOR-US: ZJU-FAST-Lab EGO-Planner-v2
CVE-2026-71416 (Headroom compresses data before the data reaches a large language mode ...)
- TODO: check
+ NOT-FOR-US: Headroom
CVE-2026-70341 (Use after free in Microsoft Edge (Chromium-based) allows an authorized ...)
NOT-FOR-US: Microsoft
CVE-2026-6642 (The Media Library Assistant plugin for WordPress is vulnerable to Stor ...)
@@ -2061,25 +2061,25 @@ CVE-2026-62089 (Missing Authorization vulnerability in Pixar Labs Master Addons
CVE-2026-62088 (Insertion of Sensitive Information Into Sent Data vulnerability in 10u ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-57843 (NetBSD contains an information disclosure vulnerability in mm_open() w ...)
- TODO: check
+ NOT-FOR-US: NetBSD
CVE-2026-57842 (NetBSD contains a use-after-free and double-free vulnerability in msg_ ...)
- TODO: check
+ NOT-FOR-US: NetBSD
CVE-2026-54072 (Authorizer is an open-source, self-hostable authentication and authori ...)
- TODO: check
+ NOT-FOR-US: Authorizer
CVE-2026-54047 (Laci Synchroni is a decentralized mod and appearance sync server and p ...)
- TODO: check
+ NOT-FOR-US: Laci Synchroni
CVE-2026-47839 (A vulnerability allows users authenticating through a federated OIDC p ...)
- TODO: check
+ NOT-FOR-US: Cloud Foundry Foundation UAA
CVE-2026-3869 (CWE-303 : Incorrect Implementation of Authentication Algorithm vulnera ...)
NOT-FOR-US: Schneider Electric
CVE-2026-38058 (The endpoint on the iDirect iQ200 VSAT terminal returns the complete d ...)
- TODO: check
+ NOT-FOR-US: iDirect
CVE-2026-38056 (A local privilege escalation vulnerability exists in the iDirect iQ200 ...)
- TODO: check
+ NOT-FOR-US: iDirect
CVE-2026-27378 (Unauthenticated Broken Access Control in Deposits and Partial Payments ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-19486 (A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gem ...)
- TODO: check
+ NOT-FOR-US: Google Cloud Gemini Enterprise Agent Platform App Builder
CVE-2026-18495 (A flaw was found in libtiff. A heap-buffer overflow vulnerability exis ...)
TODO: check
CVE-2026-18122 (Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes res ...)
@@ -2093,11 +2093,11 @@ CVE-2026-15710 (An information leakage vulnerability exists in the Endpoint DLP
CVE-2026-15439 (The GamiPress plugin for WordPress is vulnerable to authenticated (Sub ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11765 (Improper neutralization of argument delimiters in a command ('argument ...)
- TODO: check
+ NOT-FOR-US: TUBITAK BILGEM Software Technologies Research Institute Pardus Pen
CVE-2025-69904 (Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which al ...)
- TODO: check
+ NOT-FOR-US: Linkstack
CVE-2025-15679 (Under certain circumstances such as reset to factory default operation ...)
- TODO: check
+ NOT-FOR-US: BullSequana
CVE-2024-12145 (The BuddyPress plugin for WordPress is vulnerable to Insecure Direct O ...)
NOT-FOR-US: WordPress plugin
CVE-2026-9768
@@ -2341,7 +2341,7 @@ CVE-2026-19985 (The Relevanssi \u2013 A Better Search plugin for WordPress is vu
CVE-2026-19646 (IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ...)
NOT-FOR-US: IBM
CVE-2026-19596 (An XML External Entity (XXE) vulnerability exists in the XML collector ...)
- TODO: check
+ NOT-FOR-US: OpenNMS
CVE-2026-19136 (A potential command injection vulnerability was reported in the Tianxi ...)
NOT-FOR-US: Lenovo
CVE-2026-18994 (A potential improper authorization vulnerability was reported in the L ...)
@@ -2387,7 +2387,7 @@ CVE-2026-11496 (The Woo PDF Invoice Builder plugin (also distributed as "PDF Bui
CVE-2026-11446 (The Booktics \u2013 Booking Calendar for Appointments and Service Busi ...)
NOT-FOR-US: WordPress plugin
CVE-2025-57231 (Path Traversal in avatar attachments in Docmost v0.21.0 allows an unau ...)
- TODO: check
+ NOT-FOR-US: Docmost
CVE-2025-15695 (The Translate WordPress with GTranslate WordPress plugin before 3.0.10 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88914 (A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When p ...)
@@ -2878,7 +2878,7 @@ CVE-2026-80352 (Improper Control of Generation of Code ('Code Injection') vulner
CVE-2026-80351 (Improper neutralization of directives in dynamically evaluated code (' ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-7188 (Improper neutralization of special elements used in an SQL command ('S ...)
- TODO: check
+ NOT-FOR-US: Armiya Information Technologies Access Control System
CVE-2026-79987 (A remote, authenticated, non-admin Craft CMS Control Panel user with o ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-78536 (Unauthenticated Broken Access Control in Robokassa payment gateway for ...)
@@ -2908,13 +2908,13 @@ CVE-2026-73694 (FileRun before 2026.3.0 contains an OS command injection vulnera
CVE-2026-73693 (FileRun before 2026.3.0 contains an OS command injection vulnerability ...)
NOT-FOR-US: FileRun
CVE-2026-6285 (Weak Password Recovery Mechanism for Forgotten Password vulnerability ...)
- TODO: check
+ NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
CVE-2026-68527 (Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authori ...)
NOT-FOR-US: Concrete CMS
CVE-2026-68488 (A Time-of-check Time-of-use (TOCTOU) race condition leading to insecur ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-68487 (Path traversal in Plesk's Backup Manager causes arbitrary file write a ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-68006 (An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to exec ...)
TODO: check
CVE-2026-66674 (Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= ...)
@@ -2922,21 +2922,21 @@ CVE-2026-66674 (Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnst
CVE-2026-66632 (Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1. ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65639 (OS command injection in the advanced-rule parser of ConfigServer Secur ...)
- TODO: check
+ NOT-FOR-US: Cpanel ConfigServer Security & Firewall
CVE-2026-65638 (Improper escaping of a request URL in ConfigServer Security & Firewal ...)
- TODO: check
+ NOT-FOR-US: Cpanel ConfigServer Security & Firewall
CVE-2026-64838 (ICEcoder versions through 8.1 fail to properly validate the oldFileNam ...)
- TODO: check
+ NOT-FOR-US: ICEcoder
CVE-2026-64837 (ICEcoder through 8.1 passes an unescaped filesystem path into a shell ...)
- TODO: check
+ NOT-FOR-US: ICEcoder
CVE-2026-64836 (ICEcoder versions through 8.1 contain a path traversal vulnerability i ...)
- TODO: check
+ NOT-FOR-US: ICEcoder
CVE-2026-5399 (The Redux Framework plugin for WordPress is vulnerable to Stored Cross ...)
NOT-FOR-US: WordPress plugin
CVE-2026-52098 (An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrar ...)
NOT-FOR-US: Flowise
CVE-2026-52097 (An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitr ...)
- TODO: check
+ NOT-FOR-US: AppFlowy
CVE-2026-4130 (There is a storage of sensitive information in cleartext vulnerability ...)
NOT-FOR-US: National Instruments
CVE-2026-4129 (There is an improper access control vulnerability in NI SystemLink tha ...)
@@ -2952,9 +2952,9 @@ CVE-2026-42805 (A stack-based buffer overflow vulnerability exists in the Bosch
CVE-2026-42804 (A stack-based buffer overflow vulnerability exists in the Bosch Sensor ...)
NOT-FOR-US: Bosch
CVE-2026-38626 (Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/ ...)
- TODO: check
+ NOT-FOR-US: Garlic-Hub
CVE-2026-17038 (DrEryk Gabinet before 11.5.0uses hard-coded API credentials in its tic ...)
- TODO: check
+ NOT-FOR-US: DrEryk Gabinet
CVE-2026-15889 (The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored C ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15461 (The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, l ...)
@@ -2966,11 +2966,11 @@ CVE-2026-15418 (In the silabser.sys driver for CP210x devices v11.5.0 and earlie
CVE-2026-15417 (In the silabser.sys Windows 8 driver for CP210x devices, a local unpri ...)
NOT-FOR-US: Silicon Labs
CVE-2026-13745 (A vulnerability in the Gemini CLI and associated GitHub Action allowed ...)
- TODO: check
+ NOT-FOR-US: Gemini CLI
CVE-2026-12683 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
CVE-2026-12682 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: Ankaref Innovation and Technology Inc. LIBRID/LIBREF
CVE-2026-88069 (Pandora contains a path traversal vulnerability in its archive extract ...)
NOT-FOR-US: Pandora
CVE-2026-88002 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
@@ -3097,7 +3097,7 @@ CVE-2026-71805 (An arbitrary file upload and path traversal vulnerability exists
CVE-2026-71803 (money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerabili ...)
NOT-FOR-US: money-pos
CVE-2026-71802 (A stored Cross-Site Scripting (XSS) vulnerability exists in the announ ...)
- TODO: check
+ NOT-FOR-US: REBUILD
CVE-2026-71801 (An issue was discovered in s-pms SPMS-Server through v1.0. The applica ...)
NOT-FOR-US: s-pms SPMS-Server
CVE-2026-71616 (An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an at ...)
@@ -536233,7 +536233,7 @@ CVE-2022-26964 (Weak password derivation for export in Devolutions Remote Deskto
CVE-2022-26963
RESERVED
CVE-2022-26962 (Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS- ...)
- TODO: check
+ NOT-FOR-US: Italtel
CVE-2022-26961 (Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_ ...)
NOT-FOR-US: Italtel NetMatch-S
CVE-2022-26960 (connector.minimal.php in std42 elFinder through 2.1.60 is affected by ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb41839e5534d47abf5972836084e125d93b505f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb41839e5534d47abf5972836084e125d93b505f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/c40cfb82/attachment.htm>
More information about the debian-security-tracker-commits
mailing list