Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2e7b6083 by Salvatore Bonaccorso at 2026-09-22T16:48:27+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -209,51 +209,51 @@ CVE-2026-88806 (A malicious X server could exploit a 
buffer overflow in libX11 b
 CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not 
sanitise and e ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-88756 (Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to 
perform SQ ...)
-       TODO: check
+       NOT-FOR-US: Pagekit CMS
 CVE-2026-88746 (idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in 
/admin/mak ...)
-       TODO: check
+       NOT-FOR-US: idccms
 CVE-2026-88745 (EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables 
attackers t ...)
-       TODO: check
+       NOT-FOR-US: EMLOG Pro
 CVE-2026-88738 (Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted 
file upl ...)
-       TODO: check
+       NOT-FOR-US: Jazzware RT1000 Edge webUI
 CVE-2026-88467 (CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a 
backend verif ...)
-       TODO: check
+       NOT-FOR-US: CRMEB Knowledge-Paid System
 CVE-2026-88412 (An integer overflow in the _BulkInsert_ReadProperty component 
(/bulk_i ...)
-       TODO: check
+       NOT-FOR-US: FalkorDB
 CVE-2026-88411 (Improper error handling in the GRAPH.EFFECT component 
(/effects/effect ...)
-       TODO: check
+       NOT-FOR-US: FalkorDB
 CVE-2026-88410 (The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is 
not reg ...)
-       TODO: check
+       NOT-FOR-US: FalkorDB
 CVE-2026-88409 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to 
contain a ...)
-       TODO: check
+       NOT-FOR-US: FalkorDB
 CVE-2026-88408 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to 
contain a ...)
-       TODO: check
+       NOT-FOR-US: FalkorDB
 CVE-2026-88407 (An out-of-bounds read in the 
node_token_count/relation_token_count com ...)
-       TODO: check
+       NOT-FOR-US: FalkorDB
 CVE-2026-88406 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to 
contain a ...)
-       TODO: check
+       NOT-FOR-US: FalkorDB
 CVE-2026-88405 (A remote code execution (RCE) vulnerability in the 
RemoteRegisterFunct ...)
        TODO: check
 CVE-2026-88404 (A remote code execution (RCE) vulnerability in the 
UniscriptExecutionS ...)
        TODO: check
 CVE-2026-88403 (A Server-Side Request Forgery (SSRF) in the serverRequest 
function of  ...)
-       TODO: check
+       NOT-FOR-US: nocobase
 CVE-2026-88402 (A SQL injection vulnerability in the checkSQL function of 
nocobase v2. ...)
-       TODO: check
+       NOT-FOR-US: nocobase
 CVE-2026-87858 (Temporal Server decided whether a Workflow completion callback 
was int ...)
-       TODO: check
+       NOT-FOR-US: Temporal Server
 CVE-2026-86802 (The To Do List Member WordPress plugin through 1.6 does not 
have autho ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-86473 (Apache Airflow: the Core API logout endpoint revokes only a 
session to ...)
        - airflow <itp> (bug #819700)
 CVE-2026-85751 (Mailu is a mail server distributed as a set of Docker images. 
From Mai ...)
-       TODO: check
+       NOT-FOR-US: Mailu
 CVE-2026-85653 (The Contextual Related Posts plugin for WordPress is 
vulnerable to Sto ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-85220 (A vulnerability in the Thinkst Canary honeypot Redis service 
allows an ...)
-       TODO: check
+       NOT-FOR-US: Thinkst Canary honeypot Redis service
 CVE-2026-85219 (Denial-of-Service in Redis module in Thinkst Canary's 
OpenCanary 0.9.9 ...)
-       TODO: check
+       NOT-FOR-US: OpenCanary
 CVE-2026-85113 (The GiveWP WordPress plugin before 4.16.9 does not remove 
shortcode de ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-85010 (The RestroPress WordPress plugin before 3.4.6 does not 
validate a clie ...)
@@ -261,7 +261,7 @@ CVE-2026-85010 (The RestroPress WordPress plugin before 
3.4.6 does not validate
 CVE-2026-84990 (ntopng is a web-based network traffic monitoring application. 
Prior to ...)
        TODO: check
 CVE-2026-84298 (Hatchet is a platform for orchestrating background tasks, AI 
agents, a ...)
-       TODO: check
+       NOT-FOR-US: Hatchet
 CVE-2026-84285 (An OS Command Injection vulnerability affecting Tuleap 
Enterprise Edit ...)
        NOT-FOR-US: Dassault Systemes
 CVE-2026-83621 (ntopng is a web-based network traffic monitoring application. 
Prior to ...)
@@ -279,23 +279,23 @@ CVE-2026-81469 (Dell Inventory Collector Client, versions 
prior to 15.0.0, conta
 CVE-2026-79920 (Ajenti is a Linux & BSD modular server admin panel. Prior to 
version 2 ...)
        TODO: check
 CVE-2026-79919 (MaxKB is an open-source AI assistant for enterprise. Prior to 
version  ...)
-       TODO: check
+       NOT-FOR-US: MaxKB
 CVE-2026-79918 (MaxKB is an open-source AI assistant for enterprise. Prior to 
version  ...)
-       TODO: check
+       NOT-FOR-US: MaxKB
 CVE-2026-79917 (MaxKB is an open-source AI assistant for enterprise. In 2.7.0 
through  ...)
-       TODO: check
+       NOT-FOR-US: MaxKB
 CVE-2026-79916 (MaxKB is an open-source AI assistant for enterprise. Prior to 
2.10.5-l ...)
-       TODO: check
+       NOT-FOR-US: MaxKB
 CVE-2026-79320 (Stencil core 4.43.5 contains a DOM-based cross-site scripting 
(XSS) vu ...)
-       TODO: check
+       NOT-FOR-US: Stencil
 CVE-2026-79319 (Stencil core 4.43.5 is vulnerable to Incorrect Access Control.)
-       TODO: check
+       NOT-FOR-US: Stencil
 CVE-2026-79318 (web2py 3.2.2-stable (commit 
a7330a2bf21219fa77860b6665de927dd4f98e6d)  ...)
        TODO: check
 CVE-2026-79317 (A session invalidation flaw exists in x-ui 0.3.2. The full 
user object ...)
-       TODO: check
+       NOT-FOR-US: x-ui
 CVE-2026-79316 (An improper access control vulnerability exists in x-ui 0.3.2. 
Any aut ...)
-       TODO: check
+       NOT-FOR-US: x-ui
 CVE-2026-79079 (An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker 
to execu ...)
        - xiphos 4.4.0+dfsg1-1
        NOTE: https://github.com/crosswire/xiphos/pull/1314



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e7b60831e7dba7afe081bed3982bb8224486c9a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e7b60831e7dba7afe081bed3982bb8224486c9a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to