Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2e7b6083 by Salvatore Bonaccorso at 2026-09-22T16:48:27+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -209,51 +209,51 @@ CVE-2026-88806 (A malicious X server could exploit a
buffer overflow in libX11 b
CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not
sanitise and e ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88756 (Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to
perform SQ ...)
- TODO: check
+ NOT-FOR-US: Pagekit CMS
CVE-2026-88746 (idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in
/admin/mak ...)
- TODO: check
+ NOT-FOR-US: idccms
CVE-2026-88745 (EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables
attackers t ...)
- TODO: check
+ NOT-FOR-US: EMLOG Pro
CVE-2026-88738 (Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted
file upl ...)
- TODO: check
+ NOT-FOR-US: Jazzware RT1000 Edge webUI
CVE-2026-88467 (CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a
backend verif ...)
- TODO: check
+ NOT-FOR-US: CRMEB Knowledge-Paid System
CVE-2026-88412 (An integer overflow in the _BulkInsert_ReadProperty component
(/bulk_i ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88411 (Improper error handling in the GRAPH.EFFECT component
(/effects/effect ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88410 (The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is
not reg ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88409 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to
contain a ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88408 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to
contain a ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88407 (An out-of-bounds read in the
node_token_count/relation_token_count com ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88406 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to
contain a ...)
- TODO: check
+ NOT-FOR-US: FalkorDB
CVE-2026-88405 (A remote code execution (RCE) vulnerability in the
RemoteRegisterFunct ...)
TODO: check
CVE-2026-88404 (A remote code execution (RCE) vulnerability in the
UniscriptExecutionS ...)
TODO: check
CVE-2026-88403 (A Server-Side Request Forgery (SSRF) in the serverRequest
function of ...)
- TODO: check
+ NOT-FOR-US: nocobase
CVE-2026-88402 (A SQL injection vulnerability in the checkSQL function of
nocobase v2. ...)
- TODO: check
+ NOT-FOR-US: nocobase
CVE-2026-87858 (Temporal Server decided whether a Workflow completion callback
was int ...)
- TODO: check
+ NOT-FOR-US: Temporal Server
CVE-2026-86802 (The To Do List Member WordPress plugin through 1.6 does not
have autho ...)
NOT-FOR-US: WordPress plugin
CVE-2026-86473 (Apache Airflow: the Core API logout endpoint revokes only a
session to ...)
- airflow <itp> (bug #819700)
CVE-2026-85751 (Mailu is a mail server distributed as a set of Docker images.
From Mai ...)
- TODO: check
+ NOT-FOR-US: Mailu
CVE-2026-85653 (The Contextual Related Posts plugin for WordPress is
vulnerable to Sto ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85220 (A vulnerability in the Thinkst Canary honeypot Redis service
allows an ...)
- TODO: check
+ NOT-FOR-US: Thinkst Canary honeypot Redis service
CVE-2026-85219 (Denial-of-Service in Redis module in Thinkst Canary's
OpenCanary 0.9.9 ...)
- TODO: check
+ NOT-FOR-US: OpenCanary
CVE-2026-85113 (The GiveWP WordPress plugin before 4.16.9 does not remove
shortcode de ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85010 (The RestroPress WordPress plugin before 3.4.6 does not
validate a clie ...)
@@ -261,7 +261,7 @@ CVE-2026-85010 (The RestroPress WordPress plugin before
3.4.6 does not validate
CVE-2026-84990 (ntopng is a web-based network traffic monitoring application.
Prior to ...)
TODO: check
CVE-2026-84298 (Hatchet is a platform for orchestrating background tasks, AI
agents, a ...)
- TODO: check
+ NOT-FOR-US: Hatchet
CVE-2026-84285 (An OS Command Injection vulnerability affecting Tuleap
Enterprise Edit ...)
NOT-FOR-US: Dassault Systemes
CVE-2026-83621 (ntopng is a web-based network traffic monitoring application.
Prior to ...)
@@ -279,23 +279,23 @@ CVE-2026-81469 (Dell Inventory Collector Client, versions
prior to 15.0.0, conta
CVE-2026-79920 (Ajenti is a Linux & BSD modular server admin panel. Prior to
version 2 ...)
TODO: check
CVE-2026-79919 (MaxKB is an open-source AI assistant for enterprise. Prior to
version ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-79918 (MaxKB is an open-source AI assistant for enterprise. Prior to
version ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-79917 (MaxKB is an open-source AI assistant for enterprise. In 2.7.0
through ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-79916 (MaxKB is an open-source AI assistant for enterprise. Prior to
2.10.5-l ...)
- TODO: check
+ NOT-FOR-US: MaxKB
CVE-2026-79320 (Stencil core 4.43.5 contains a DOM-based cross-site scripting
(XSS) vu ...)
- TODO: check
+ NOT-FOR-US: Stencil
CVE-2026-79319 (Stencil core 4.43.5 is vulnerable to Incorrect Access Control.)
- TODO: check
+ NOT-FOR-US: Stencil
CVE-2026-79318 (web2py 3.2.2-stable (commit
a7330a2bf21219fa77860b6665de927dd4f98e6d) ...)
TODO: check
CVE-2026-79317 (A session invalidation flaw exists in x-ui 0.3.2. The full
user object ...)
- TODO: check
+ NOT-FOR-US: x-ui
CVE-2026-79316 (An improper access control vulnerability exists in x-ui 0.3.2.
Any aut ...)
- TODO: check
+ NOT-FOR-US: x-ui
CVE-2026-79079 (An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker
to execu ...)
- xiphos 4.4.0+dfsg1-1
NOTE: https://github.com/crosswire/xiphos/pull/1314
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e7b60831e7dba7afe081bed3982bb8224486c9a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e7b60831e7dba7afe081bed3982bb8224486c9a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits