[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 20 21:50:30 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a70f7710 by Moritz Muehlenhoff at 2026-09-20T22:48:46+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,41 +1,41 @@
 CVE-2026-94113 (Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contai ...)
-	TODO: check
+	NOT-FOR-US: Frappe ERPNext
 CVE-2026-94112 (mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes ...)
-	TODO: check
+	NOT-FOR-US: ezBookkeeping
 CVE-2026-94111 (Tencent BrowserSkill through 0.3.0 contains an authentication bypass v ...)
-	TODO: check
+	NOT-FOR-US: Tencent
 CVE-2026-94109 (openEQUELLA versions before 2026.1.0 contain a remote code execution v ...)
-	TODO: check
+	NOT-FOR-US: openEQUELLA
 CVE-2026-94108 (getID3 through 1.9.26 contains an XML external entity injection vulner ...)
 	TODO: check
 CVE-2026-94107 (NivoCart through 2.4.0 contains a predictable password reset token vul ...)
-	TODO: check
+	NOT-FOR-US: NivoCart
 CVE-2026-94106 (getID3 before 1.9.26 contains an OS command injection vulnerability in ...)
 	TODO: check
 CVE-2026-94105 (NivoCart through 2.4.0 contains a destructive configuration write vuln ...)
-	TODO: check
+	NOT-FOR-US: NivoCart
 CVE-2026-94104 (NivoCart through 2.4.0 contains an arbitrary file upload vulnerability ...)
-	TODO: check
+	NOT-FOR-US: NivoCart
 CVE-2026-94046 (A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. ...)
-	TODO: check
+	NOT-FOR-US: ACE-MCP
 CVE-2026-94045 (A security flaw has been discovered in newbee-ltd newbee-mall up to 1. ...)
-	TODO: check
+	NOT-FOR-US: newbee-mall
 CVE-2026-94044 (A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c ...)
-	TODO: check
+	NOT-FOR-US: 03-lovepreetSingh MCP
 CVE-2026-94043 (A vulnerability was determined in Free5GC up to 4.2.3. This vulnerabil ...)
 	NOT-FOR-US: Free5GC
 CVE-2026-94042 (A vulnerability was found in AdithyaYelloju Restaurant Management Syst ...)
-	TODO: check
+	NOT-FOR-US: Restaurant Management System
 CVE-2026-94041 (A vulnerability has been found in AdithyaYelloju Restaurant-Management ...)
-	TODO: check
+	NOT-FOR-US: Restaurant Management System
 CVE-2026-94040 (A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this ...)
-	TODO: check
+	NOT-FOR-US: vas3k TaxHacker
 CVE-2026-94039 (A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected  ...)
-	TODO: check
+	NOT-FOR-US: vas3k TaxHacker
 CVE-2026-94038 (A security vulnerability has been detected in NonceGeek dim-sum-app. T ...)
-	TODO: check
+	NOT-FOR-US: dim-sum-app
 CVE-2026-94037 (A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 8 ...)
-	TODO: check
+	NOT-FOR-US: mcp-file-analyzer
 CVE-2026-94036 (A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z ...)
 	NOT-FOR-US: D-Link
 CVE-2026-94035 (A vulnerability was determined in SourceCodester Drug Recommendation S ...)
@@ -47,11 +47,11 @@ CVE-2026-94033 (A vulnerability has been found in SourceCodester Drug Recommenda
 CVE-2026-94032 (A flaw has been found in itsourcecode Leave Management System 1.0. Thi ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-94031 (A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc ...)
-	TODO: check
+	NOT-FOR-US: nexus-mcp
 CVE-2026-94030 (A security vulnerability has been detected in SerenityOS up to 3d83e45 ...)
-	TODO: check
+	NOT-FOR-US: SerenityOS
 CVE-2026-94028 (A weakness has been identified in mealie-recipes Mealie up to 3.25.1.  ...)
-	TODO: check
+	NOT-FOR-US: Mealie
 CVE-2026-94016 (A security flaw has been discovered in SourceCodester Drug Recommendat ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-94015 (A vulnerability was identified in SourceCodester Drug Recommendation S ...)
@@ -59,7 +59,7 @@ CVE-2026-94015 (A vulnerability was identified in SourceCodester Drug Recommenda
 CVE-2026-94004 (A vulnerability was found in DedeCMS up to 5.7.118. The affected eleme ...)
 	NOT-FOR-US: DedeCMS
 CVE-2026-94003 (A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is ...)
-	TODO: check
+	NOT-FOR-US: Comfast CF-N1-S
 CVE-2026-93997 (A weakness has been identified in SourceCodester Drug Recommendation S ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-93980 (A weakness has been identified in code-projects Internship Management  ...)
@@ -81,9 +81,9 @@ CVE-2026-93973 (A vulnerability was detected in SourceCodester Online Reviewer M
 CVE-2026-93972 (A security vulnerability has been detected in SourceCodester Online Re ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-93971 (A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted ...)
-	TODO: check
+	NOT-FOR-US: SxDevOps
 CVE-2026-93970 (A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. Thi ...)
-	TODO: check
+	NOT-FOR-US: SxDevOps
 CVE-2026-92254 (Missing Authorization in the IOCTL handlers of thewsdkd.syskernel driv ...)
 	TODO: check
 CVE-2026-92253 (Improper link resolution before file access in the quarantine restorat ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a70f77106bb81400a378f29fac6851da181caed2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a70f77106bb81400a378f29fac6851da181caed2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/2e6ad9cc/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list