Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
72361a09 by Salvatore Bonaccorso at 2026-09-22T09:57:11+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11,37 +11,37 @@ CVE-2026-94623 (vLLM through 0.29.0 contains a denial of 
service vulnerability i
 CVE-2026-94622 (vLLM versions through 0.29.0 contain a denial of service 
vulnerability ...)
        - vllm <itp> (bug #1095237)
 CVE-2026-94588 (In Proxmox pmg-api, an argument injection vulnerability exists 
in the  ...)
-       TODO: check
+       NOT-FOR-US: Proxmox pmg-api
 CVE-2026-94540 (DesktopSMS 1.11.0 by MrPear contains an unauthorized access 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: DesktopSMS
 CVE-2026-94536 (lamp-cloud through 5.10.0 fails to validate the employeeId 
parameter i ...)
-       TODO: check
+       NOT-FOR-US: lamp-cloud
 CVE-2026-94535 (lamp-cloud through 5.10.0 contains an authorization bypass 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: lamp-cloud
 CVE-2026-94534 (lamp-cloud through 5.10.0 fails to validate user identity in 
PUT /anyo ...)
-       TODO: check
+       NOT-FOR-US: lamp-cloud
 CVE-2026-94533 (lamp-cloud through 5.10.0 contains an authorization bypass 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: lamp-cloud
 CVE-2026-94532 (lamp-cloud through 5.10.0 contains an authorization bypass 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: lamp-cloud
 CVE-2026-94504 (Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value 
and rend ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-94501 (jshERP through 3.6 contains an authorization bypass 
vulnerability in t ...)
-       TODO: check
+       NOT-FOR-US: jshERP
 CVE-2026-94497 (jshERP through 3.6 fails to validate object ownership in by-id 
info, u ...)
-       TODO: check
+       NOT-FOR-US: jshERP
 CVE-2026-94496 (jshERP through 3.6 fails to validate caller permissions in 
role manage ...)
-       TODO: check
+       NOT-FOR-US: jshERP
 CVE-2026-94495 (jshERP through 3.6 fails to properly validate user privileges 
in Syste ...)
-       TODO: check
+       NOT-FOR-US: jshERP
 CVE-2026-94494 (jshERP through 3.6 contains a tenant isolation bypass 
vulnerability th ...)
-       TODO: check
+       NOT-FOR-US: jshERP
 CVE-2026-94493 (A vulnerability was detected in Gigatech PDV5701 
1.0.31_240305_112640. ...)
-       TODO: check
+       NOT-FOR-US: Gigatech
 CVE-2026-94492 (A security vulnerability has been detected in Yonyou U8cloud 
5.x. This ...)
-       TODO: check
+       NOT-FOR-US: Yonyou U8cloud
 CVE-2026-94491 (A weakness has been identified in Yonyou KSOA 9.0. This 
affects an unk ...)
-       TODO: check
+       NOT-FOR-US: Yonyou KSOA
 CVE-2026-94490 (A security flaw has been discovered in OctoPrint 1.0.0. 
Affected by th ...)
        - octoprint <itp> (bug #718591)
 CVE-2026-94489 (A vulnerability was identified in OctoPrint 1.0.0. Affected by 
this vu ...)
@@ -49,23 +49,23 @@ CVE-2026-94489 (A vulnerability was identified in OctoPrint 
1.0.0. Affected by t
 CVE-2026-94488 (Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. 
(The fi ...)
        TODO: check
 CVE-2026-94426 (A vulnerability was determined in xuxueli xxl-job up to 3.5.0. 
The imp ...)
-       TODO: check
+       NOT-FOR-US: xuxueli xxl-job
 CVE-2026-94425 (A vulnerability was found in Moore Threads MTT S80 Driver 
Package 340. ...)
-       TODO: check
+       NOT-FOR-US: Moore Threads MTT S80 Driver Package
 CVE-2026-94424 (A vulnerability has been found in Moore Threads MTT S80 Driver 
Package ...)
-       TODO: check
+       NOT-FOR-US: Moore Threads MTT S80 Driver Package
 CVE-2026-94414 (jshERP through 3.6 is missing an authorization check on the 
POST /user ...)
-       TODO: check
+       NOT-FOR-US: jshERP
 CVE-2026-94413 (jshERP through 3.6 fails to redact password hashes in the 
/user/info e ...)
-       TODO: check
+       NOT-FOR-US: jshERP
 CVE-2026-94412 (jshERP through 3.6 contains an authorization bypass 
vulnerability in t ...)
-       TODO: check
+       NOT-FOR-US: jshERP
 CVE-2026-94411 (jshERP 3.6 contains a privilege escalation vulnerability in 
the update ...)
-       TODO: check
+       NOT-FOR-US: jshERP
 CVE-2026-94404 (MISP has a security issue that could let an attacker change 
threat-int ...)
        - misp <itp> (bug #1144317)
 CVE-2026-94403 (A weakness has been identified in ColorFul iGameCenter 
1.0.3.4. This i ...)
-       TODO: check
+       NOT-FOR-US: ColorFul iGameCenter
 CVE-2026-94401 (MISP has a file-handling vulnerability that could let certain 
authenti ...)
        - misp <itp> (bug #1144317)
 CVE-2026-94394 (When a regular user adds a reference between objects or 
attributes, MI ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72361a096b4e348fe47d72081d3a0bb7186df92a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72361a096b4e348fe47d72081d3a0bb7186df92a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to