[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 22 08:57:43 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
72361a09 by Salvatore Bonaccorso at 2026-09-22T09:57:11+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11,37 +11,37 @@ CVE-2026-94623 (vLLM through 0.29.0 contains a denial of service vulnerability i
CVE-2026-94622 (vLLM versions through 0.29.0 contain a denial of service vulnerability ...)
- vllm <itp> (bug #1095237)
CVE-2026-94588 (In Proxmox pmg-api, an argument injection vulnerability exists in the ...)
- TODO: check
+ NOT-FOR-US: Proxmox pmg-api
CVE-2026-94540 (DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerabil ...)
- TODO: check
+ NOT-FOR-US: DesktopSMS
CVE-2026-94536 (lamp-cloud through 5.10.0 fails to validate the employeeId parameter i ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94535 (lamp-cloud through 5.10.0 contains an authorization bypass vulnerabili ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94534 (lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyo ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94533 (lamp-cloud through 5.10.0 contains an authorization bypass vulnerabili ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94532 (lamp-cloud through 5.10.0 contains an authorization bypass vulnerabili ...)
- TODO: check
+ NOT-FOR-US: lamp-cloud
CVE-2026-94504 (Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and rend ...)
NOT-FOR-US: WordPress plugin
CVE-2026-94501 (jshERP through 3.6 contains an authorization bypass vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94497 (jshERP through 3.6 fails to validate object ownership in by-id info, u ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94496 (jshERP through 3.6 fails to validate caller permissions in role manage ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94495 (jshERP through 3.6 fails to properly validate user privileges in Syste ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94494 (jshERP through 3.6 contains a tenant isolation bypass vulnerability th ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94493 (A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. ...)
- TODO: check
+ NOT-FOR-US: Gigatech
CVE-2026-94492 (A security vulnerability has been detected in Yonyou U8cloud 5.x. This ...)
- TODO: check
+ NOT-FOR-US: Yonyou U8cloud
CVE-2026-94491 (A weakness has been identified in Yonyou KSOA 9.0. This affects an unk ...)
- TODO: check
+ NOT-FOR-US: Yonyou KSOA
CVE-2026-94490 (A security flaw has been discovered in OctoPrint 1.0.0. Affected by th ...)
- octoprint <itp> (bug #718591)
CVE-2026-94489 (A vulnerability was identified in OctoPrint 1.0.0. Affected by this vu ...)
@@ -49,23 +49,23 @@ CVE-2026-94489 (A vulnerability was identified in OctoPrint 1.0.0. Affected by t
CVE-2026-94488 (Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The fi ...)
TODO: check
CVE-2026-94426 (A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The imp ...)
- TODO: check
+ NOT-FOR-US: xuxueli xxl-job
CVE-2026-94425 (A vulnerability was found in Moore Threads MTT S80 Driver Package 340. ...)
- TODO: check
+ NOT-FOR-US: Moore Threads MTT S80 Driver Package
CVE-2026-94424 (A vulnerability has been found in Moore Threads MTT S80 Driver Package ...)
- TODO: check
+ NOT-FOR-US: Moore Threads MTT S80 Driver Package
CVE-2026-94414 (jshERP through 3.6 is missing an authorization check on the POST /user ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94413 (jshERP through 3.6 fails to redact password hashes in the /user/info e ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94412 (jshERP through 3.6 contains an authorization bypass vulnerability in t ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94411 (jshERP 3.6 contains a privilege escalation vulnerability in the update ...)
- TODO: check
+ NOT-FOR-US: jshERP
CVE-2026-94404 (MISP has a security issue that could let an attacker change threat-int ...)
- misp <itp> (bug #1144317)
CVE-2026-94403 (A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This i ...)
- TODO: check
+ NOT-FOR-US: ColorFul iGameCenter
CVE-2026-94401 (MISP has a file-handling vulnerability that could let certain authenti ...)
- misp <itp> (bug #1144317)
CVE-2026-94394 (When a regular user adds a reference between objects or attributes, MI ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72361a096b4e348fe47d72081d3a0bb7186df92a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72361a096b4e348fe47d72081d3a0bb7186df92a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/6c406e03/attachment.htm>
More information about the debian-security-tracker-commits
mailing list