[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 22 15:48:51 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2e7b6083 by Salvatore Bonaccorso at 2026-09-22T16:48:27+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -209,51 +209,51 @@ CVE-2026-88806 (A malicious X server could exploit a buffer overflow in libX11 b
CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not sanitise and e ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88756 (Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQ ...)
- TODO: check
+ NOT-FOR-US: Pagekit CMS
CVE-2026-88746 (idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/mak ...)
- TODO: check
+ NOT-FOR-US: idccms
CVE-2026-88745 (EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers t ...)
- TODO: check
+ NOT-FOR-US: EMLOG Pro
CVE-2026-88738 (Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upl ...)
- TODO: check
+ NOT-FOR-US: Jazzware RT1000 Edge webUI
CVE-2026-88467 (CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verif ...)
- TODO: check
+ NOT-FOR-US: CRMEB Knowledge-Paid System
CVE-2026-88412 (An integer overflow in the _BulkInsert_ReadProperty component (/bulk_i ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88411 (Improper error handling in the GRAPH.EFFECT component (/effects/effect ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88410 (The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not reg ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88409 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88408 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88407 (An out-of-bounds read in the node_token_count/relation_token_count com ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88406 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88405 (A remote code execution (RCE) vulnerability in the RemoteRegisterFunct ...)
TODO: check
CVE-2026-88404 (A remote code execution (RCE) vulnerability in the UniscriptExecutionS ...)
TODO: check
CVE-2026-88403 (A Server-Side Request Forgery (SSRF) in the serverRequest function of ...)
- TODO: check
+ NOT-FOR-US: nocobase
CVE-2026-88402 (A SQL injection vulnerability in the checkSQL function of nocobase v2. ...)
- TODO: check
+ NOT-FOR-US: nocobase
CVE-2026-87858 (Temporal Server decided whether a Workflow completion callback was int ...)
- TODO: check
+ NOT-FOR-US: Temporal Server
CVE-2026-86802 (The To Do List Member WordPress plugin through 1.6 does not have autho ...)
NOT-FOR-US: WordPress plugin
CVE-2026-86473 (Apache Airflow: the Core API logout endpoint revokes only a session to ...)
- airflow <itp> (bug #819700)
CVE-2026-85751 (Mailu is a mail server distributed as a set of Docker images. From Mai ...)
- TODO: check
+ NOT-FOR-US: Mailu
CVE-2026-85653 (The Contextual Related Posts plugin for WordPress is vulnerable to Sto ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85220 (A vulnerability in the Thinkst Canary honeypot Redis service allows an ...)
- TODO: check
+ NOT-FOR-US: Thinkst Canary honeypot Redis service
CVE-2026-85219 (Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 ...)
- TODO: check
+ NOT-FOR-US: OpenCanary
CVE-2026-85113 (The GiveWP WordPress plugin before 4.16.9 does not remove shortcode de ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85010 (The RestroPress WordPress plugin before 3.4.6 does not validate a clie ...)
@@ -261,7 +261,7 @@ CVE-2026-85010 (The RestroPress WordPress plugin before 3.4.6 does not validate
CVE-2026-84990 (ntopng is a web-based network traffic monitoring application. Prior to ...)
TODO: check
CVE-2026-84298 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
- TODO: check
+ NOT-FOR-US: Hatchet
CVE-2026-84285 (An OS Command Injection vulnerability affecting Tuleap Enterprise Edit ...)
NOT-FOR-US: Dassault Systemes
CVE-2026-83621 (ntopng is a web-based network traffic monitoring application. Prior to ...)
@@ -279,23 +279,23 @@ CVE-2026-81469 (Dell Inventory Collector Client, versions prior to 15.0.0, conta
CVE-2026-79920 (Ajenti is a Linux & BSD modular server admin panel. Prior to version 2 ...)
TODO: check
CVE-2026-79919 (MaxKB is an open-source AI assistant for enterprise. Prior to version ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-79918 (MaxKB is an open-source AI assistant for enterprise. Prior to version ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-79917 (MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-79916 (MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-l ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-79320 (Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vu ...)
- TODO: check
+ NOT-FOR-US: Stencil
CVE-2026-79319 (Stencil core 4.43.5 is vulnerable to Incorrect Access Control.)
- TODO: check
+ NOT-FOR-US: Stencil
CVE-2026-79318 (web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) ...)
TODO: check
CVE-2026-79317 (A session invalidation flaw exists in x-ui 0.3.2. The full user object ...)
- TODO: check
+ NOT-FOR-US: x-ui
CVE-2026-79316 (An improper access control vulnerability exists in x-ui 0.3.2. Any aut ...)
- TODO: check
+ NOT-FOR-US: x-ui
CVE-2026-79079 (An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execu ...)
- xiphos 4.4.0+dfsg1-1
NOTE: https://github.com/crosswire/xiphos/pull/1314
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e7b60831e7dba7afe081bed3982bb8224486c9a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e7b60831e7dba7afe081bed3982bb8224486c9a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/5cb56f36/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list