[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Sep 21 15:29:35 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
14af6fbb by Moritz Muehlenhoff at 2026-09-21T16:22:53+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2006,7 +2006,7 @@ CVE-2026-54343 (Frappe Learning Management System (LMS) is a learning system tha
CVE-2026-54339 (Glean is a self-hosted RSS reader and personal knowledge management to ...)
NOT-FOR-US: Glean
CVE-2026-54237 (Wavelog is web-based amateur radio logging software. From 1.8 until 2. ...)
- TODO: check
+ NOT-FOR-US: Wavelog
CVE-2026-53557 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
NOT-FOR-US: SQLBot
CVE-2026-53556 (SQLBot is an intelligent Text-to-SQL system based on large language mo ...)
@@ -2558,7 +2558,7 @@ CVE-2026-62101 (Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4
CVE-2026-61793 (Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0 ...)
NOT-FOR-US: Nuxt OG Image
CVE-2026-61700 (MariaDB Connector/J is used to connect applications developed in Java ...)
- TODO: check
+ NOT-FOR-US: MariaDB Connector/J
CVE-2026-56795 (Dell Server Update Utility, versions prior to 26.07.01, contains an Un ...)
NOT-FOR-US: Dell / EMC
CVE-2026-55062 (uniget is a universal installer and updater for (container) tools. Pri ...)
@@ -2628,7 +2628,7 @@ CVE-2026-52852 (Traccar is an open source GPS tracking system. Prior to 6.14.0,
CVE-2026-52851 (Traccar is an open source GPS tracking system. Prior to 6.14.0, an aut ...)
NOT-FOR-US: Traccar
CVE-2026-52836 (OpenDDS is an open source C++ implementation of the Object Management ...)
- TODO: check
+ NOT-FOR-US: OpenDDS
CVE-2026-52727 (lxc-ci contains continuous integration and image-build scripts for LXC ...)
TODO: check
CVE-2026-50610 (A vulnerability has been identified in the Acer System Monitoring comp ...)
@@ -2646,7 +2646,7 @@ CVE-2026-50605 (A vulnerability has been identified in the Acer Agent Service co
CVE-2026-49292 (Kiwi TCMS is an open source test management system. Prior to 16.0, the ...)
NOT-FOR-US: Kiwi TCMS
CVE-2026-47252 (Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ...)
- TODO: check
+ NOT-FOR-US: Anyquery
CVE-2026-28326 (SolarWinds Access Rights Manager was reported to be affected by an una ...)
NOT-FOR-US: SolarWinds
CVE-2026-26950 (Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insuffi ...)
@@ -7554,13 +7554,13 @@ CVE-2026-66789
CVE-2026-66372 (The affected products use insufficiently random values, which allows w ...)
NOT-FOR-US: Watchdog
CVE-2026-63671 (MDC is a tool to take regular Markdown and write documents interacting ...)
- TODO: check
+ NOT-FOR-US: MDC
CVE-2026-63128 (RMCP is an official Rust SDK for the Model Context Protocol. Prior to ...)
NOT-FOR-US: RCMP
CVE-2026-63127 (RMCP is an official Rust SDK for the Model Context Protocol. Prior to ...)
NOT-FOR-US: RCMP
CVE-2026-63126 (Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, an ...)
- TODO: check
+ NOT-FOR-US: Wire
CVE-2026-62597 (Vulnerability in the Oracle Enterprise Manager Base Platform product o ...)
NOT-FOR-US: Oracle
CVE-2026-61709 (OpenFGA is an authorization and permission engine built for developers ...)
@@ -7606,17 +7606,17 @@ CVE-2026-57173 (vLLM is an inference and serving engine for large language model
CVE-2026-56719 (MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerabi ...)
NOT-FOR-US: MikroTik
CVE-2026-54544 (Fireshare facilitates self-hosted media and link sharing. Prior to ver ...)
- TODO: check
+ NOT-FOR-US: Fireshare
CVE-2026-54337 (Fireshare facilitates self-hosted media and link sharing. Prior to ver ...)
- TODO: check
+ NOT-FOR-US: Fireshare
CVE-2026-51990 (An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.34 ...)
- TODO: check
+ NOT-FOR-US: Sogou Sogou Input Method
CVE-2026-51134 (The C-MOR Video Surveillance web interface (up to version 6.0104) is v ...)
- TODO: check
+ NOT-FOR-US: C-MOR Video Surveillance
CVE-2026-51133 (Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Sur ...)
- TODO: check
+ NOT-FOR-US: C-MOR Video Surveillance
CVE-2026-47094 (SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vu ...)
- TODO: check
+ NOT-FOR-US: SIMAC MyPHR
CVE-2026-40857 (WNC T-Mobile 5G Box IDU router contains a cross-site request forgery ( ...)
NOT-FOR-US: WNC T-Mobile 5G Box
CVE-2026-40856 (WNC T-Mobile 5G Box IDU router is vulnerable to improper access contro ...)
@@ -7628,55 +7628,55 @@ CVE-2026-40854 (WNC T-Mobile 5G Box IDU router contains an authentication bypass
CVE-2026-3855 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-38999 (A Null Pointer Dereference in the mk_sched_event_close function (mk_se ...)
- TODO: check
+ NOT-FOR-US: Monkey
CVE-2026-32599 (Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `s ...)
- TODO: check
+ NOT-FOR-US: Netmaker
CVE-2026-2380 (On affected platforms running Arista EOS with OpenConfig-related servi ...)
NOT-FOR-US: Arista Networks
CVE-2026-27565 (An unauthenticated remote attacker can upload a malicious IODD file th ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27564 (A high-privileged remote attacker can exploit a command injection vuln ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27563 (A high-privileged remote attacker can exploit a command injection vuln ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27562 (A high-privileged remote attacker can exploit a command injection vuln ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27561 (A high-privileged remote attacker can exploit a command injection vuln ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27560 (A high-privileged remote attacker can exploit a command injection vuln ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27559 (A low-privileged remote attacker can exploit a command injection vulne ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27558 (A low-privileged remote attacker can exploit a command injection vulne ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27557 (An unauthenticated remote attacker can exploit a path traversal vulner ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27556 (A low-privileged remote attacker can exploit a local file inclusion vu ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27555 (A low-privileged remote attacker can exploit a local file inclusion vu ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27554 (A low-privileged remote attacker can exploit a command injection vulne ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27553 (A low-privileged remote attacker can manipulate the schema path parame ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27552 (A low-privileged remote attacker can exploit improper authorization in ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27551 (A low-privileged remote attacker can exploit a command injection vulne ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27550 (A low-privileged remote attacker can exploit a command injection vulne ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27549 (A low-privileged remote attacker can exploit a command injection vulne ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27548 (A low-privileged remote attacker can exploit a command injection vulne ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27547 (A low-privileged remote attacker can exploit a command injection vulne ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-27546 (An unauthenticated remote attacker can exploit an authentication bypas ...)
- TODO: check
+ NOT-FOR-US: ICE2-8IOL1-G65L-V1D
CVE-2026-26947 (Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versio ...)
NOT-FOR-US: Dell / EMC
CVE-2026-20331 (As part of Cisco's ongoing commitment to proactive security and produc ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-20307 (A vulnerability in the web-based management interface of Cisco ISE cou ...)
NOT-FOR-US: Cisco
CVE-2026-20306 (A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow a ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/14af6fbbf9e89c0e40d0a827544f3d2ee672de3c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/14af6fbbf9e89c0e40d0a827544f3d2ee672de3c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260921/7755e7dc/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list