[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 22 20:56:31 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fcf15f44 by Salvatore Bonaccorso at 2026-09-22T21:56:04+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -45,25 +45,25 @@ CVE-2026-95665 (MISP contains a reflected cross-site scripting (XSS) vulnerabili
CVE-2026-95661 (MISP contains a reflected cross-site scripting (XSS) vulnerability in ...)
- misp <itp> (bug #1144317)
CVE-2026-95660 (A security flaw has been discovered in Moonshot AI Kimi Code up to 0.3 ...)
- TODO: check
+ NOT-FOR-US: Moonshot AI Kimi Code
CVE-2026-95659 (MISP contains a reflected cross-site scripting (XSS) vulnerability in ...)
- misp <itp> (bug #1144317)
CVE-2026-95658 (MISP's WorkflowsController exposed the moduleStatelessExecution action ...)
- misp <itp> (bug #1144317)
CVE-2026-95657 (A vulnerability was determined in dgtlmoon Changedetection.io up to 0. ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon Changedetection.io
CVE-2026-95656 (A vulnerability was found in dgtlmoon changedetection.io up to 50389b0 ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon Changedetection.io
CVE-2026-95655 (Aureus ERP before 1.5.0 fails to scope message lookups to the current ...)
- TODO: check
+ NOT-FOR-US: Aureus ERP
CVE-2026-95654 (Databasement before 1.7.14 validates invitation tokens only when the a ...)
- TODO: check
+ NOT-FOR-US: Databasement
CVE-2026-95653 (Concrete CMS Community Store before 2.7.8 derives digital product down ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS Community Store
CVE-2026-95624 (The Tauri updater plugin's 'check' IPC command accepts an allowDowngra ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95623 (The Tauri HTTP plugin validates requested URLs against the application ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95619 (A flaw was found in libstdc++. An integer overflow can occur when proc ...)
TODO: check
CVE-2026-95511
@@ -73,29 +73,29 @@ CVE-2026-95508 (A heap-based buffer overflow was found in the DHCPv6 and TFTP re
CVE-2026-95503 (A flaw was found in the Kerberos federation provider of Keycloak, an o ...)
TODO: check
CVE-2026-95501 (A vulnerability was found in mtrano APENCMS up to 6546096d354153309693 ...)
- TODO: check
+ NOT-FOR-US: mtrano APENCMS
CVE-2026-95500 (A vulnerability has been found in JosephChuks php-file-manager-with-co ...)
- TODO: check
+ NOT-FOR-US: JosephChuks php-file-manager-with-code-editor
CVE-2026-95499 (A flaw has been found in JosephChuks php-file-manager-with-code-editor ...)
- TODO: check
+ NOT-FOR-US: JosephChuks php-file-manager-with-code-editor
CVE-2026-95396 (A vulnerability was identified in sfturing hosp_order up to 627f426331 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-95273 (A vulnerability was determined in dgtlmoon changedetection.io up to 0. ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon changedetection.io
CVE-2026-95272 (A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon changedetection.io
CVE-2026-95271 (A vulnerability has been found in dgtlmoon changedetection.io up to 0. ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon changedetection.io
CVE-2026-95270 (A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon changedetection.io
CVE-2026-94570 (SGLang contains a DoS vulnerability caused by missing input validation ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-94462 (Spree is an open source e-commerce solution built with Ruby on Rails. ...)
- TODO: check
+ NOT-FOR-US: Spree
CVE-2026-94456 (Postiz generates security-sensitive credentials using `Math.random()` ...)
- TODO: check
+ NOT-FOR-US: Postiz
CVE-2026-94455 (An HTTP endpoint intended for provisioning enterprise and reseller org ...)
- TODO: check
+ NOT-FOR-US: Postiz App
CVE-2026-94384 (Missing authorization in Amazon amazon-connect-salesforce-lambda befor ...)
NOT-FOR-US: Amazon
CVE-2026-94127 (When a BIG-IP APM access policy and an OAuth profile is configured on ...)
@@ -113,31 +113,31 @@ CVE-2026-93778 (The WP Yelp Review Slider plugin for WordPress is vulnerable to
CVE-2026-93616 (A directory traversal and file upload vulnerability allows an unauthen ...)
NOT-FOR-US: Check Point
CVE-2026-93556 (The \u2018/password/guardarClau/recover\u2019 endpoint accepts the \u2 ...)
- TODO: check
+ NOT-FOR-US: Tankuam Places Kompini
CVE-2026-93345 (MikroTik RouterOS before 7.25beta4 contains an improper input validati ...)
NOT-FOR-US: MikroTik
CVE-2026-93344 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93343 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93342 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93341 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93088 (SGLang's multimodal generation runtime is vulnerable to unauthenticate ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-92969 (The HUSKY \u2013 Products Filter for WooCommerce Professional plugin f ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92882 (Insufficiently protected credentials in the host and folder configurat ...)
NOT-FOR-US: Checkmk
CVE-2026-92706 (Dark Reader is an accessibility browser extension that makes web pages ...)
- TODO: check
+ NOT-FOR-US: Dark Reader
CVE-2026-92235 (The The WP Ultimate Review plugin for WordPress is vulnerable to arbit ...)
NOT-FOR-US: WordPress plugin
CVE-2026-91130 (Home Assistant is open source home automation software focused on loca ...)
- TODO: check
+ NOT-FOR-US: Home Assistant
CVE-2026-91129 (Home Assistant is open source home automation software focused on loca ...)
- TODO: check
+ NOT-FOR-US: Home Assistant
CVE-2026-91092 (The wpForo Forum plugin for WordPress is vulnerable to authorization b ...)
NOT-FOR-US: WordPress plugin
CVE-2026-90990 (Improper neutralization of newlines in filter values in the monitoring ...)
@@ -151,7 +151,7 @@ CVE-2026-8849 (Use After Free vulnerability in RTI Connext Professional (Securit
CVE-2026-89422 (Key Exchange without Entity Authentication vulnerability in Erlang/OTP ...)
TODO: check
CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-89407 (NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-valid ...)
TODO: check
CVE-2026-89277 (CAI Content Credentials is affected by an Integer Overflow or Wraparou ...)
@@ -161,41 +161,41 @@ CVE-2026-89276 (Adobe Campaign Classic (ACC) is affected by an Improper Control
CVE-2026-89275 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
NOT-FOR-US: Adobe
CVE-2026-88415 (MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting ...)
- TODO: check
+ NOT-FOR-US: MCMS
CVE-2026-88414 (MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: MCMS
CVE-2026-88010 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
TODO: check
CVE-2026-87902 (An unauthenticated attacker can make `get_page_template()` page-templa ...)
TODO: check
CVE-2026-87119 (Authentication Bypass by Capture-replay in ZenHive mpp allows an attac ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-86698 (Insufficient Session Expiration vulnerability in OAuth token issuance ...)
TODO: check
CVE-2026-86062 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-86059 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
- TODO: check
+ NOT-FOR-US: Dokploy
CVE-2026-86056 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-86054 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-85995 (Notepad++ is a free and open-source source code editor. From 8.9.7 unt ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-85740 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-85734 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-85725 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-85709 (LightRAG provides simple and fast retrieval-augmented generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-85288 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-85279 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-85055 (Twenty is an open-source CRM (customer relationship management) platfo ...)
- TODO: check
+ NOT-FOR-US: Twenty
CVE-2026-84412 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
NOT-FOR-US: Adobe
CVE-2026-84396 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
@@ -205,7 +205,7 @@ CVE-2026-84395 (Premiere Pro [NEEDS REVIEW: environment mismatch \u2014 product
CVE-2026-84388 (A improper restriction of rendered ui layers or frames vulnerability i ...)
NOT-FOR-US: Fortinet
CVE-2026-84301 (FastGPT is an open-source LLM platform for building AI applications on ...)
- TODO: check
+ NOT-FOR-US: FastGPT
CVE-2026-83964 (Adobe Connect is affected by an Improper Certificate Validation vulner ...)
NOT-FOR-US: Adobe
CVE-2026-83963 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
@@ -213,7 +213,7 @@ CVE-2026-83963 (Substance3D - Modeler is affected by an out-of-bounds write vuln
CVE-2026-83962 (Substance3D - Modeler is affected by a Stack-based Buffer Overflow vul ...)
NOT-FOR-US: Adobe
CVE-2026-83803 (Sentry is an error tracking and performance monitoring tool. From 23.1 ...)
- TODO: check
+ NOT-FOR-US: Sentry
CVE-2026-83660 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
NOT-FOR-US: Adobe
CVE-2026-83603 (Netdata is an open source observability tool. Prior to 2.10.4, the set ...)
@@ -861,9 +861,9 @@ CVE-2026-88407 (An out-of-bounds read in the node_token_count/relation_token_cou
CVE-2026-88406 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
NOT-FOR-US: FalkorDB
CVE-2026-88405 (A remote code execution (RCE) vulnerability in the RemoteRegisterFunct ...)
- TODO: check
+ NOT-FOR-US: Univer
CVE-2026-88404 (A remote code execution (RCE) vulnerability in the UniscriptExecutionS ...)
- TODO: check
+ NOT-FOR-US: Univer
CVE-2026-88403 (A Server-Side Request Forgery (SSRF) in the serverRequest function of ...)
NOT-FOR-US: nocobase
CVE-2026-88402 (A SQL injection vulnerability in the checkSQL function of nocobase v2. ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcf15f446685d9881eeff318e25e4d26a7dfec7e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcf15f446685d9881eeff318e25e4d26a7dfec7e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/c9d50315/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list