[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 23 23:16:56 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8bd11420 by Moritz Muehlenhoff at 2026-09-24T00:16:36+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -635,7 +635,7 @@ CVE-2026-81338 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.
CVE-2026-80342 (The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-79767 (Gardener implements the automated management and operation of Kubernet ...)
- TODO: check
+ NOT-FOR-US: Gardener
CVE-2026-77987 (A server-side request forgery (SSRF) vulnerability was identified in t ...)
NOT-FOR-US: Github Enterprise Server
CVE-2026-77912 (A stored cross-site scripting (XSS) vulnerability was identified in Gi ...)
@@ -645,15 +645,15 @@ CVE-2026-77766 (The Directorist: AI-Powered Business Directory, Listings & Class
CVE-2026-77765 (The Better Payment WordPress plugin before 2.3.4 does not validate th ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77426 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
- TODO: check
+ NOT-FOR-US: Unleash
CVE-2026-77425 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
- TODO: check
+ NOT-FOR-US: Unleash
CVE-2026-77322 (SIPGO is a library for writing SIP services in the GO language. Prior ...)
- TODO: check
+ NOT-FOR-US: sipgo
CVE-2026-76910 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
- TODO: check
+ NOT-FOR-US: Unleash
CVE-2026-76909 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
- TODO: check
+ NOT-FOR-US: Unleash
CVE-2026-76717 (A vulnerability exists in the Analytics and Location Engine (ALE) API ...)
NOT-FOR-US: HPE
CVE-2026-76716 (Multiple vulnerabilities exist in the Analytics and Location Engine (A ...)
@@ -683,23 +683,23 @@ CVE-2026-75101 (An authorization bypass vulnerability was identified in GitHub E
CVE-2026-6831 (The Advanced Contact form 7 DB plugin for WordPress is vulnerable to m ...)
NOT-FOR-US: WordPress plugin
CVE-2026-67615 (openEQUELLA before 2026.1.0 contains an authenticated remote code exec ...)
- TODO: check
+ NOT-FOR-US: openEQUELLA
CVE-2026-65829 (MPXJ is an open source library to read and write project plans from a ...)
- TODO: check
+ NOT-FOR-US: MPXJ
CVE-2026-63628 (mppx is a TypeScript interface for machine payments protocol. Prior to ...)
- TODO: check
+ NOT-FOR-US: mppx
CVE-2026-63627 (mppx is a TypeScript interface for machine payments protocol. Prior to ...)
- TODO: check
+ NOT-FOR-US: mppx
CVE-2026-63104 (Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vu ...)
- TODO: check
+ NOT-FOR-US: Kaneo
CVE-2026-62985 (request-filtering-agent is an http(s).Agent implementation that blocks ...)
- TODO: check
+ NOT-FOR-US: Node request-filtering-agent
CVE-2026-62364 (wlc is a Weblate command-line client using Weblate's REST API. Prior t ...)
TODO: check
CVE-2026-61685 (ReactPress is a publishing system for React developers. Prior to versi ...)
- TODO: check
+ NOT-FOR-US: ReactPress
CVE-2026-61570 (MPXJ is an open source library to read and write project plans from a ...)
- TODO: check
+ NOT-FOR-US: MPXJ
CVE-2026-5924 (The Getwid \u2013 Gutenberg Blocks plugin for WordPress is vulnerable ...)
NOT-FOR-US: WordPress plugin
CVE-2026-59991 (psd-tools is a Python package for working with Adobe Photoshop PSD fil ...)
@@ -707,11 +707,11 @@ CVE-2026-59991 (psd-tools is a Python package for working with Adobe Photoshop P
NOTE: https://github.com/psd-tools/psd-tools/security/advisories/GHSA-8q6g-vjhf-jp8m
NOTE: Fixed by: https://github.com/psd-tools/psd-tools/commit/a3d9a53ad51e667b5772a4f636ca6f2e16f4b271 (v1.17.4)
CVE-2026-58268 (SIPGO is a library for writing SIP services in the GO language. Prior ...)
- TODO: check
+ NOT-FOR-US: sipgo
CVE-2026-57576 (plone.app.dexterity is a content-type system for the Plone content man ...)
- TODO: check
+ NOT-FOR-US: plone.app.dexterity
CVE-2026-47116 (LTSecurity LTK3500SF contains a hard-coded credentials vulnerability w ...)
- TODO: check
+ NOT-FOR-US: LTSecurity LTK3500SF
CVE-2026-28325 (SolarWinds Observability Self-Hosted was found to be affected by an un ...)
NOT-FOR-US: SolarWinds
CVE-2026-28324 (SolarWinds Observability Self-Hosted was found to be affected by an un ...)
@@ -719,7 +719,7 @@ CVE-2026-28324 (SolarWinds Observability Self-Hosted was found to be affected by
CVE-2026-19438 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
NOT-FOR-US: ABB group
CVE-2026-19202 (A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-pyth ...)
- TODO: check
+ NOT-FOR-US: mcp-toolbox-sdk-python
CVE-2026-18365 (The zportals WordPress plugin before 6.4.2 does not perform any capabi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18364 (The zportals WordPress plugin before 6.4.2 does not perform any capabi ...)
@@ -1392,7 +1392,7 @@ CVE-2026-7866 (Stack-based Buffer Overflow vulnerability in RTI Connext Professi
CVE-2026-7622 (The ThumbPress plugin for WordPress is vulnerable to unauthorized acce ...)
NOT-FOR-US: WordPress plugin
CVE-2026-79913 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
- TODO: check
+ NOT-FOR-US: Cloudreve
CVE-2026-79906 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
NOT-FOR-US: Adobe
CVE-2026-79315 (A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. T ...)
@@ -1619,7 +1619,7 @@ CVE-2026-65112 (NVIDIA Infrastructure Controller for Linux contains a vulnerabil
CVE-2026-65111 (NVIDIA NeMo Speech for all platforms contains a vulnerability where ma ...)
NOT-FOR-US: NVIDIA
CVE-2026-63386 (js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does n ...)
- TODO: check
+ NOT-FOR-US: Node js-toml
CVE-2026-63279 (LibreOffice can import PICT images, which may be embedded in documents ...)
- libreoffice 4:26.2.5.2-1
NOTE: https://www.libreoffice.org/security/#cve-2026-63279
@@ -1660,7 +1660,7 @@ CVE-2026-43641 (Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contain
CVE-2026-37604 (pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves ...)
NOT-FOR-US: pH7Software pH7Builder
CVE-2026-37603 (Improper Restriction of Excessive Authentication Attempts in the admin ...)
- TODO: check
+ NOT-FOR-US: pH7Software pH7Builder
CVE-2026-34689 (Adobe Connect is affected by an Improper Limitation of a Pathname to a ...)
NOT-FOR-US: Adobe
CVE-2026-25265 (Privilege escalation due to weak configuration while temporary file ha ...)
@@ -1680,7 +1680,7 @@ CVE-2026-24239 (NVIDIA NeMo Speech for all platforms contains a vulnerability wh
CVE-2026-1645 (The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scr ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19915 (A potential security vulnerability has been identified in the HP Suppo ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-19480 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
NOT-FOR-US: Adobe
CVE-2026-18626 (Out-of-bounds Read vulnerability in RTI Connext Professional (Core Lib ...)
@@ -1710,7 +1710,7 @@ CVE-2026-13087 (A heap out-of-bounds write vulnerability was found in the Linux
CVE-2026-12995 (The Custom Field Template plugin for WordPress is vulnerable to Insecu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12718 (Improper neutralization of special elements used in an SQL command ('S ...)
- TODO: check
+ NOT-FOR-US: KarelIPS
CVE-2026-11389 (Out-of-bounds Read, Function Call With Incorrect Number of Arguments, ...)
NOT-FOR-US: RTI Connext
CVE-2026-11388 (Double Free vulnerability in RTI Connext Professional (Core Libraries) ...)
@@ -1904,7 +1904,7 @@ CVE-2026-93340 (Gladys Assistant before 5.1.0 contains a password reset link poi
CVE-2026-93339 (Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a ...)
NOT-FOR-US: Metaphor Creations Ditty (ditty-news-ticker)
CVE-2026-92612 (In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exp ...)
- TODO: check
+ NOT-FOR-US: Eclipse iceoryx2
CVE-2026-92438 (The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92400 (The Payment Gateway for PayPal on WooCommerce WordPress plugin before ...)
@@ -2041,43 +2041,43 @@ CVE-2026-79079 (An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to
NOTE: https://gist.github.com/lggcs/c1f98ce55ced44472651b9590d9f199a
NOTE: Fixed by: https://github.com/crosswire/xiphos/commit/f96ad3273277e7fb24908b40f3aa1e9efeeb4e85 (4.4.0)
CVE-2026-78847 (An issue in gray-matter All versions (verified on 4.0.3) allows the Ja ...)
- TODO: check
+ NOT-FOR-US: Node gray-matter
CVE-2026-78806 (An issue in Matter Standard Specification-Implementation gap v1.5.1 Ma ...)
- TODO: check
+ NOT-FOR-US: Matter Project Chip
CVE-2026-77582 (Tinyauth is an authentication and authorization server. Prior to 5.1.0 ...)
- TODO: check
+ NOT-FOR-US: Tinyauth
CVE-2026-77561 (Tinyauth is an authentication and authorization server. Prior to 5.1.0 ...)
- TODO: check
+ NOT-FOR-US: Tinyauth
CVE-2026-77560 (Tinyauth is an authentication and authorization server. Prior to 5.1.2 ...)
- TODO: check
+ NOT-FOR-US: Tinyauth
CVE-2026-77525 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-77523 (MaxKB is an open-source AI assistant for enterprise. In version 2.10.3 ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-77522 (MaxKB is an open-source AI assistant for enterprise. In version 2.10.3 ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-77521 (MaxKB is an open-source AI assistant for enterprise. Prior to version ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-77520 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-77519 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-77518 (MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-77517 (MaxKB is an open-source AI assistant for enterprise. From version 2.0. ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-77516 (MaxKB is an open-source AI assistant for enterprise. From version 2.0. ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-77166 (The emoji field in the page emoji update endpoint does not properly va ...)
- TODO: check
+ NOT-FOR-US: Nextcloud Collectives
CVE-2026-77165 (File owners were unable to unlock TYPE_TOKEN locks placed by other use ...)
- TODO: check
+ - nextcloud-server <itp> (bug #941708)
CVE-2026-77021 (Improper handling of highly compressed data (data amplification) in Ch ...)
NOT-FOR-US: Checkmk
CVE-2026-76974 (SAP Fiori Launchpad does not sufficiently validate certain user-contro ...)
NOT-FOR-US: SAP
CVE-2026-76898 (draw.io is a configurable diagramming and whiteboarding application. P ...)
- TODO: check
+ NOT-FOR-US: draw.io
CVE-2026-75158 (Apache Airflow's `/assets/events` API returned asset events for every ...)
- airflow <itp> (bug #819700)
CVE-2026-71543 (OpenBao is an open source identity-based secrets management system. Pr ...)
@@ -2085,189 +2085,189 @@ CVE-2026-71543 (OpenBao is an open source identity-based secrets management syst
CVE-2026-69190 (Graylog is a free and open log management platform. From 6.3.0 until 6 ...)
- graylog2 <itp> (bug #652273)
CVE-2026-68919 (GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD do ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-67827 (Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9 ...)
- TODO: check
+ NOT-FOR-US: ZLMediaKit
CVE-2026-66280
REJECTED
CVE-2026-65980 (Chartbrew is an open-source web application that can connect directly ...)
- TODO: check
+ NOT-FOR-US: Chartbrew
CVE-2026-65654 (github.com/temporalio/ringpop-go enforces configured LabelOptions limi ...)
- TODO: check
+ NOT-FOR-US: github.com/temporalio/ringpop-go
CVE-2026-65653 (github.com/temporalio/tchannel-go did not reject TChannel call fragmen ...)
- TODO: check
+ NOT-FOR-US: github.com/temporalio/tchannel-go
CVE-2026-65652 (github.com/temporalio/tchannel-go did not validate the one-byte checks ...)
- TODO: check
+ NOT-FOR-US: github.com/temporalio/tchannel-go
CVE-2026-65651 (temporalio/sqlparser accepts SQL containing deeply nested unary expres ...)
- TODO: check
+ NOT-FOR-US: temporalio/sqlparser
CVE-2026-63416 (draw.io is a configurable diagramming and whiteboarding application. P ...)
- TODO: check
+ NOT-FOR-US: draw.io
CVE-2026-63373 (draw.io is a configurable diagramming and whiteboarding application. P ...)
- TODO: check
+ NOT-FOR-US: draw.io
CVE-2026-63342 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
- TODO: check
+ NOT-FOR-US: Hatchet
CVE-2026-63334 (draw.io is a configurable diagramming and whiteboarding application. P ...)
- TODO: check
+ NOT-FOR-US: draw.io
CVE-2026-63330 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
- TODO: check
+ NOT-FOR-US: Warpgate
CVE-2026-63329 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
- TODO: check
+ NOT-FOR-US: Warpgate
CVE-2026-63116 (deepstream is a server that allows clients and backend services to syn ...)
- TODO: check
+ NOT-FOR-US: deepstream
CVE-2026-62987 (Fabio is an HTTP(S) and TCP router for deploying applications managed ...)
- TODO: check
+ NOT-FOR-US: Fabio
CVE-2026-62866 (Dasel is a command-line tool and library for querying, modifying, and ...)
TODO: check
CVE-2026-62371 (KubeEdge is an open source system for extending native containerized a ...)
- TODO: check
+ NOT-FOR-US: KubeEdge
CVE-2026-62370 (KubeEdge is an open source system for extending native containerized a ...)
- TODO: check
+ NOT-FOR-US: KubeEdge
CVE-2026-62369 (KubeEdge is an open source system for extending native containerized a ...)
- TODO: check
+ NOT-FOR-US: KubeEdge
CVE-2026-62247 (Supabase Realtime provides Broadcast, Presence, and Postgres Changes v ...)
- TODO: check
+ NOT-FOR-US: KubeEdge
CVE-2026-62182 (KubeEdge is an open source system for extending native containerized a ...)
- TODO: check
+ NOT-FOR-US: Supabase
CVE-2026-61852 (Chartbrew is an open-source web application that can connect directly ...)
- TODO: check
+ NOT-FOR-US: Chartbrew
CVE-2026-61851 (Chartbrew is an open-source web application that can connect directly ...)
- TODO: check
+ NOT-FOR-US: Chartbrew
CVE-2026-61749 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
- TODO: check
+ NOT-FOR-US: InvenTree
CVE-2026-61748 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
- TODO: check
+ NOT-FOR-US: InvenTree
CVE-2026-61747 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
- TODO: check
+ NOT-FOR-US: InvenTree
CVE-2026-61746 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
- TODO: check
+ NOT-FOR-US: InvenTree
CVE-2026-61745 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
- TODO: check
+ NOT-FOR-US: InvenTree
CVE-2026-61744 (InvenTree is an Open Source Inventory Management System. Prior to 1.4. ...)
- TODO: check
+ NOT-FOR-US: InvenTree
CVE-2026-61743 (Chartbrew is an open-source web application that can connect directly ...)
- TODO: check
+ NOT-FOR-US: Chartbrew
CVE-2026-61687 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
- TODO: check
+ NOT-FOR-US: Hatchet
CVE-2026-61681 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
- TODO: check
+ NOT-FOR-US: Hatchet
CVE-2026-61674 (Fluent Bit is a fast and lightweight logs, metrics, and traces process ...)
TODO: check
CVE-2026-61652 (Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: Zapros
CVE-2026-61647 (NotebookLM MCP is an MCP server and HTTP service for interacting with ...)
- TODO: check
+ NOT-FOR-US: NotebookLM MCP
CVE-2026-61630 (nginx ignition is a user interface for the nginx web server. In versio ...)
- TODO: check
+ NOT-FOR-US: nginx ignition
CVE-2026-61629 (nginx ignition is a user interface for the nginx web server. In versio ...)
- TODO: check
+ NOT-FOR-US: nginx ignition
CVE-2026-61628 (nginx ignition is a user interface for the nginx web server. Prior to ...)
- TODO: check
+ NOT-FOR-US: nginx ignition
CVE-2026-61612 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
- TODO: check
+ NOT-FOR-US: CKAN MCP Server
CVE-2026-61541 (Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: Zapros
CVE-2026-59830 (Discourse is an open-source discussion platform. Prior to 2026.7.0, th ...)
NOT-FOR-US: Discourse
CVE-2026-59816 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-59815 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-59814 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-59168 (Dasel is a command-line tool and library for querying, modifying, and ...)
TODO: check
CVE-2026-58504 (draw.io is a configurable diagramming and whiteboarding application. P ...)
- TODO: check
+ NOT-FOR-US: draw.io
CVE-2026-58491 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
- TODO: check
+ NOT-FOR-US: Warpgate
CVE-2026-58272 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
- TODO: check
+ NOT-FOR-US: Sync-in Server
CVE-2026-58271 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
- TODO: check
+ NOT-FOR-US: Sync-in Server
CVE-2026-58270 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
- TODO: check
+ NOT-FOR-US: Sync-in Server
CVE-2026-58269 (Sync-in Server is an open-source platform for file storage, sharing, c ...)
- TODO: check
+ NOT-FOR-US: Sync-in Server
CVE-2026-55897 (luci-app-advanced-reboot is a LuCI (web interface) application for Ope ...)
- TODO: check
+ NOT-FOR-US: luci-app-advanced-reboot
CVE-2026-55870 (GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-55625 (GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the int ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-55567 (BleachBit cleans files to free disk space and to maintain privacy. Pri ...)
- TODO: check
+ NOT-FOR-US: BleachBit
CVE-2026-55563 (Feast is the open source feature store for AI and machine learning. Pr ...)
- TODO: check
+ NOT-FOR-US: Feast
CVE-2026-55473 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
- TODO: check
+ NOT-FOR-US: HomeBox
CVE-2026-55210 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-55179 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-55159 (luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-block ...)
- TODO: check
+ NOT-FOR-US: luci-app-adblock-fast
CVE-2026-55105 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-55074 (Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin ...)
- TODO: check
+ NOT-FOR-US: Ansible FreeBSD Jail Connection Plugin
CVE-2026-55071 (MCP-for-Stata is a MCP server for integrating Stata into agent loops w ...)
- TODO: check
+ NOT-FOR-US: MCP-for-Stata
CVE-2026-55060 (GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-54915 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
- TODO: check
+ NOT-FOR-US: Tautulli
CVE-2026-54584 (mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPD ...)
- TODO: check
+ NOT-FOR-US: mport MidnightBSD Package Manager
CVE-2026-53940 (Conda is a system-level binary package and environment manager that ru ...)
- TODO: check
+ NOT-FOR-US: Conda
CVE-2026-52835 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
- TODO: check
+ NOT-FOR-US: Tautulli
CVE-2026-52743 (GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoC ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-52742 (GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-52741 (GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD ca ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-52740 (GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get ...)
- TODO: check
+ NOT-FOR-US: GoCD
CVE-2026-49995 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
- TODO: check
+ NOT-FOR-US: Tautulli
CVE-2026-49811 (Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an In ...)
NOT-FOR-US: Dell / EMC
CVE-2026-49810 (Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 cont ...)
NOT-FOR-US: Dell / EMC
CVE-2026-49453 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-49450 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-49449 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-48976 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
- TODO: check
+ NOT-FOR-US: HomeBox
CVE-2026-48975 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
- TODO: check
+ NOT-FOR-US: HomeBox
CVE-2026-48974 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
- TODO: check
+ NOT-FOR-US: HomeBox
CVE-2026-48826 (HomeBox is a home inventory and organization system. Prior to 0.26.0, ...)
- TODO: check
+ NOT-FOR-US: HomeBox
CVE-2026-46650 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-46649 (Joplin is an open source note-taking and to-do application that organi ...)
- TODO: check
+ - joplin <itp> (bug #931306)
CVE-2026-45381 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
- TODO: check
+ NOT-FOR-US: Tautulli
CVE-2026-36472 (CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper ...)
- TODO: check
+ NOT-FOR-US: CuteNews
CVE-2026-36471 (Deserialization of Untrusted Data of the __post_data parameter in cn_p ...)
- TODO: check
+ NOT-FOR-US: CuteNews
CVE-2026-36470 (CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index. ...)
- TODO: check
+ NOT-FOR-US: CuteNews
CVE-2026-36469 (CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) i ...)
- TODO: check
+ NOT-FOR-US: CuteNews
CVE-2026-36468 (Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows rem ...)
- TODO: check
+ NOT-FOR-US: CuteNews
CVE-2026-36467 (Unrestricted Upload of File with Dangerous Type in core/modules/media. ...)
- TODO: check
+ NOT-FOR-US: CuteNews
CVE-2026-19658 (The Give Tributes plugin for WordPress is vulnerable to PHP Object Inj ...)
NOT-FOR-US: WordPress plugin
CVE-2026-17054 (The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parse ...)
@@ -2281,7 +2281,7 @@ CVE-2026-17050 (The experimental USB host stack allocates a per-device configura
CVE-2026-16652 (Temporal Server did not bound the work performed while searching for a ...)
TODO: check
CVE-2026-16651 (temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNex ...)
- TODO: check
+ NOT-FOR-US: temporalio/sqlparser
CVE-2026-15890 (The default AEAD nonce provider for the PSA Internal Trusted Storage t ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-13355 (The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escal ...)
@@ -2289,13 +2289,13 @@ CVE-2026-13355 (The Meta Box AIO plugin for WordPress is vulnerable to Privilege
CVE-2026-12470 (The CMP \u2013 Coming Soon & Maintenance Plugin by NiteoThemes plugin ...)
NOT-FOR-US: WordPress plugin
CVE-2025-71421 (UVdesk core-framework before 1.1.7 contains an improper privilege mana ...)
- TODO: check
+ NOT-FOR-US: UVdesk core-framework
CVE-2025-71420 (UVdesk core-framework before 1.1.7 contains an authorization bypass vu ...)
- TODO: check
+ NOT-FOR-US: UVdesk core-framework
CVE-2025-71419 (UVdesk core-framework before 1.1.7 contains a stored cross-site script ...)
- TODO: check
+ NOT-FOR-US: UVdesk core-framework
CVE-2025-12999 (UrlUtil.getBaseUrl builds the absolute URLs in a response \u2014 downl ...)
- TODO: check
+ NOT-FOR-US: Open VSX
CVE-2026-80110 (A flaw was found in pki-core. The v2 REST ACL filter selects a tie-bre ...)
- dogtag-pki <removed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523749
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bd11420b2b7994c17de29a684134f183e884710
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bd11420b2b7994c17de29a684134f183e884710
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/a636619f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list