Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2ad1c041 by Salvatore Bonaccorso at 2026-06-20T21:34:54+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,49 +1,49 @@
CVE-2026-5366 (Prefect version 3.6.23 is vulnerable to remote code execution
due to i ...)
- TODO: check
+ NOT-FOR-US: Prefect
CVE-2026-56347 (AVideo TopMenu plugin through version 26.0 contains a stored
cross-sit ...)
- TODO: check
+ NOT-FOR-US: AVideo TopMenu plugin
CVE-2026-56346 (AVideo through version 25.0 contains an authentication bypass
vulnerab ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-56345 (AVideo through 29.0 contains an authorization bypass
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-56342 (AVideo through version 27.0 contains a server-side request
forgery vul ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-56341 (AVideo through version 26.0 contains multiple unauthenticated
list.jso ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-56340 (vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor
validat ...)
- TODO: check
+ - vllm <itp> (bug #1095237)
CVE-2026-56332 (Capgo before 12.128.2 contains an open redirect vulnerability
in the c ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56330 (Capgo before 12.128.2 contains an open redirect vulnerability
in strip ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56325 (Capgo before 12.128.2 uses ILIKE pattern matching instead of
exact mat ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56319 (Capgo before 12.128.2 contains an information disclosure
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56317 (Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains
a cross- ...)
- TODO: check
+ NOT-FOR-US: Nuxt
CVE-2026-56307 (Cap-go before 12.128.12 contains a broken cursor pagination
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56304 (picklescan before 1.0.1 contains an unsafe pickle
deserialization vuln ...)
- TODO: check
+ NOT-FOR-US: picklescan
CVE-2026-56295 (Capgo before 12.128.2 contains an authorization bypass
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56294 (capacitor-native-biometric before 12.128.2 contains an
authentication ...)
- TODO: check
+ NOT-FOR-US: capacitor-native-biometric
CVE-2026-56282 (Capgo before 12.128.2 contains an information disclosure
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56276 (Flowise before 3.1.2 contains a mass assignment vulnerability
in the P ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-56267 (Flowise before 3.0.13 contains an information exposure
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-56235 (Cap-go capgo before 12.128.2 contains an authorization bypass
in sever ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56228 (Capgo before 12.128.2 fails to enforce a maximum value on the
minimum ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56227 (Capgo before 12.128.2 contains a server-side request forgery
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-56218 (Capgo before 12.128.2 fails to strip EXIF metadata including
GPS geolo ...)
- TODO: check
+ NOT-FOR-US: Cap-go
CVE-2026-48939 (A vulnerability in the iCagenda extension for Joomla allows
the upload ...)
NOT-FOR-US: Joomla
CVE-2026-48909 (SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes
user-controlled ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ad1c041d0855842e50c6ab5d3d99854bf486911
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ad1c041d0855842e50c6ab5d3d99854bf486911
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits