Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
fcf15f44 by Salvatore Bonaccorso at 2026-09-22T21:56:04+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -45,25 +45,25 @@ CVE-2026-95665 (MISP contains a reflected cross-site 
scripting (XSS) vulnerabili
 CVE-2026-95661 (MISP contains a reflected cross-site scripting (XSS) 
vulnerability in  ...)
        - misp <itp> (bug #1144317)
 CVE-2026-95660 (A security flaw has been discovered in Moonshot AI Kimi Code 
up to 0.3 ...)
-       TODO: check
+       NOT-FOR-US: Moonshot AI Kimi Code
 CVE-2026-95659 (MISP contains a reflected cross-site scripting (XSS) 
vulnerability in  ...)
        - misp <itp> (bug #1144317)
 CVE-2026-95658 (MISP's WorkflowsController exposed the 
moduleStatelessExecution action ...)
        - misp <itp> (bug #1144317)
 CVE-2026-95657 (A vulnerability was determined in dgtlmoon Changedetection.io 
up to 0. ...)
-       TODO: check
+       NOT-FOR-US: dgtlmoon Changedetection.io
 CVE-2026-95656 (A vulnerability was found in dgtlmoon changedetection.io up to 
50389b0 ...)
-       TODO: check
+       NOT-FOR-US: dgtlmoon Changedetection.io
 CVE-2026-95655 (Aureus ERP before 1.5.0 fails to scope message lookups to the 
current  ...)
-       TODO: check
+       NOT-FOR-US: Aureus ERP
 CVE-2026-95654 (Databasement before 1.7.14 validates invitation tokens only 
when the a ...)
-       TODO: check
+       NOT-FOR-US: Databasement
 CVE-2026-95653 (Concrete CMS Community Store before 2.7.8 derives digital 
product down ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS Community Store
 CVE-2026-95624 (The Tauri updater plugin's 'check' IPC command accepts an 
allowDowngra ...)
-       TODO: check
+       NOT-FOR-US: Tauri
 CVE-2026-95623 (The Tauri HTTP plugin validates requested URLs against the 
application ...)
-       TODO: check
+       NOT-FOR-US: Tauri
 CVE-2026-95619 (A flaw was found in libstdc++. An integer overflow can occur 
when proc ...)
        TODO: check
 CVE-2026-95511
@@ -73,29 +73,29 @@ CVE-2026-95508 (A heap-based buffer overflow was found in 
the DHCPv6 and TFTP re
 CVE-2026-95503 (A flaw was found in the Kerberos federation provider of 
Keycloak, an o ...)
        TODO: check
 CVE-2026-95501 (A vulnerability was found in mtrano APENCMS up to 
6546096d354153309693 ...)
-       TODO: check
+       NOT-FOR-US: mtrano APENCMS
 CVE-2026-95500 (A vulnerability has been found in JosephChuks 
php-file-manager-with-co ...)
-       TODO: check
+       NOT-FOR-US: JosephChuks php-file-manager-with-code-editor
 CVE-2026-95499 (A flaw has been found in JosephChuks 
php-file-manager-with-code-editor ...)
-       TODO: check
+       NOT-FOR-US: JosephChuks php-file-manager-with-code-editor
 CVE-2026-95396 (A vulnerability was identified in sfturing hosp_order up to 
627f426331 ...)
-       TODO: check
+       NOT-FOR-US: sfturing hosp_order
 CVE-2026-95273 (A vulnerability was determined in dgtlmoon changedetection.io 
up to 0. ...)
-       TODO: check
+       NOT-FOR-US: dgtlmoon changedetection.io
 CVE-2026-95272 (A vulnerability was found in dgtlmoon changedetection.io up to 
0.60.7. ...)
-       TODO: check
+       NOT-FOR-US: dgtlmoon changedetection.io
 CVE-2026-95271 (A vulnerability has been found in dgtlmoon changedetection.io 
up to 0. ...)
-       TODO: check
+       NOT-FOR-US: dgtlmoon changedetection.io
 CVE-2026-95270 (A flaw has been found in dgtlmoon changedetection.io up to 
0.60.7. The ...)
-       TODO: check
+       NOT-FOR-US: dgtlmoon changedetection.io
 CVE-2026-94570 (SGLang contains a DoS vulnerability caused by missing input 
validation ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-94462 (Spree is an open source e-commerce solution built with Ruby on 
Rails.  ...)
-       TODO: check
+       NOT-FOR-US: Spree
 CVE-2026-94456 (Postiz generates security-sensitive credentials using 
`Math.random()`  ...)
-       TODO: check
+       NOT-FOR-US: Postiz
 CVE-2026-94455 (An HTTP endpoint intended for provisioning enterprise and 
reseller org ...)
-       TODO: check
+       NOT-FOR-US: Postiz App
 CVE-2026-94384 (Missing authorization in Amazon 
amazon-connect-salesforce-lambda befor ...)
        NOT-FOR-US: Amazon
 CVE-2026-94127 (When a BIG-IP APM access policy and an OAuth profile is 
configured on  ...)
@@ -113,31 +113,31 @@ CVE-2026-93778 (The WP Yelp Review Slider plugin for 
WordPress is vulnerable to
 CVE-2026-93616 (A directory traversal and file upload vulnerability allows an 
unauthen ...)
        NOT-FOR-US: Check Point
 CVE-2026-93556 (The \u2018/password/guardarClau/recover\u2019 endpoint accepts 
the \u2 ...)
-       TODO: check
+       NOT-FOR-US: Tankuam Places Kompini
 CVE-2026-93345 (MikroTik RouterOS before 7.25beta4 contains an improper input 
validati ...)
        NOT-FOR-US: MikroTik
 CVE-2026-93344 (MarketKing plugin for WordPress before 2.1.72 contains a 
missing autho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-93343 (MarketKing plugin for WordPress before 2.1.72 contains a 
missing autho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-93342 (MarketKing plugin for WordPress before 2.1.72 contains a 
missing autho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-93341 (MarketKing plugin for WordPress before 2.1.72 contains a 
missing autho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-93088 (SGLang's multimodal generation runtime is vulnerable to 
unauthenticate ...)
-       TODO: check
+       NOT-FOR-US: SGLang
 CVE-2026-92969 (The HUSKY \u2013 Products Filter for WooCommerce Professional 
plugin f ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-92882 (Insufficiently protected credentials in the host and folder 
configurat ...)
        NOT-FOR-US: Checkmk
 CVE-2026-92706 (Dark Reader is an accessibility browser extension that makes 
web pages ...)
-       TODO: check
+       NOT-FOR-US: Dark Reader
 CVE-2026-92235 (The The WP Ultimate Review plugin for WordPress is vulnerable 
to arbit ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-91130 (Home Assistant is open source home automation software focused 
on loca ...)
-       TODO: check
+       NOT-FOR-US: Home Assistant
 CVE-2026-91129 (Home Assistant is open source home automation software focused 
on loca ...)
-       TODO: check
+       NOT-FOR-US: Home Assistant
 CVE-2026-91092 (The wpForo Forum plugin for WordPress is vulnerable to 
authorization b ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-90990 (Improper neutralization of newlines in filter values in the 
monitoring ...)
@@ -151,7 +151,7 @@ CVE-2026-8849 (Use After Free vulnerability in RTI Connext 
Professional (Securit
 CVE-2026-89422 (Key Exchange without Entity Authentication vulnerability in 
Erlang/OTP ...)
        TODO: check
 CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive 
mpp allo ...)
-       TODO: check
+       NOT-FOR-US: ZenHive mpp
 CVE-2026-89407 (NumberInput.looksLikeValidNumber() in FasterXML jackson-core 
pre-valid ...)
        TODO: check
 CVE-2026-89277 (CAI Content Credentials is affected by an Integer Overflow or 
Wraparou ...)
@@ -161,41 +161,41 @@ CVE-2026-89276 (Adobe Campaign Classic (ACC) is affected 
by an Improper Control
 CVE-2026-89275 (Adobe Campaign Classic (ACC) is affected by an Improper 
Control of Gen ...)
        NOT-FOR-US: Adobe
 CVE-2026-88415 (MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site 
Scripting  ...)
-       TODO: check
+       NOT-FOR-US: MCMS
 CVE-2026-88414 (MCMS 6.1.1 through 6.2.1 contains a SQL injection 
vulnerability in the ...)
-       TODO: check
+       NOT-FOR-US: MCMS
 CVE-2026-88010 (Traefik is an open source HTTP reverse proxy and load 
balancer. From 3 ...)
        TODO: check
 CVE-2026-87902 (An unauthenticated attacker can make `get_page_template()` 
page-templa ...)
        TODO: check
 CVE-2026-87119 (Authentication Bypass by Capture-replay in ZenHive mpp allows 
an attac ...)
-       TODO: check
+       NOT-FOR-US: ZenHive mpp
 CVE-2026-86698 (Insufficient Session Expiration vulnerability in OAuth token 
issuance  ...)
        TODO: check
 CVE-2026-86062 (LightRAG provides simple and fast retrieval-augmented 
generation. Prio ...)
-       TODO: check
+       NOT-FOR-US: LightRAG
 CVE-2026-86059 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: Dokploy
 CVE-2026-86056 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.8 ...)
-       TODO: check
+       NOT-FOR-US: Notepad++
 CVE-2026-86054 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.8 ...)
-       TODO: check
+       NOT-FOR-US: Notepad++
 CVE-2026-85995 (Notepad++ is a free and open-source source code editor. From 
8.9.7 unt ...)
-       TODO: check
+       NOT-FOR-US: Notepad++
 CVE-2026-85740 (LightRAG provides simple and fast retrieval-augmented 
generation. Prio ...)
-       TODO: check
+       NOT-FOR-US: LightRAG
 CVE-2026-85734 (LightRAG provides simple and fast retrieval-augmented 
generation. Prio ...)
-       TODO: check
+       NOT-FOR-US: LightRAG
 CVE-2026-85725 (LightRAG provides simple and fast retrieval-augmented 
generation. Prio ...)
-       TODO: check
+       NOT-FOR-US: LightRAG
 CVE-2026-85709 (LightRAG provides simple and fast retrieval-augmented 
generation. Prio ...)
-       TODO: check
+       NOT-FOR-US: LightRAG
 CVE-2026-85288 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.8 ...)
-       TODO: check
+       NOT-FOR-US: Notepad++
 CVE-2026-85279 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.8 ...)
-       TODO: check
+       NOT-FOR-US: Notepad++
 CVE-2026-85055 (Twenty is an open-source CRM (customer relationship 
management) platfo ...)
-       TODO: check
+       NOT-FOR-US: Twenty
 CVE-2026-84412 (Adobe Campaign Classic (ACC) is affected by an Improper 
Control of Gen ...)
        NOT-FOR-US: Adobe
 CVE-2026-84396 (InDesign Desktop is affected by a NULL Pointer Dereference 
vulnerabili ...)
@@ -205,7 +205,7 @@ CVE-2026-84395 (Premiere Pro [NEEDS REVIEW: environment 
mismatch \u2014 product
 CVE-2026-84388 (A improper restriction of rendered ui layers or frames 
vulnerability i ...)
        NOT-FOR-US: Fortinet
 CVE-2026-84301 (FastGPT is an open-source LLM platform for building AI 
applications on ...)
-       TODO: check
+       NOT-FOR-US: FastGPT
 CVE-2026-83964 (Adobe Connect is affected by an Improper Certificate 
Validation vulner ...)
        NOT-FOR-US: Adobe
 CVE-2026-83963 (Substance3D - Modeler is affected by an out-of-bounds write 
vulnerabil ...)
@@ -213,7 +213,7 @@ CVE-2026-83963 (Substance3D - Modeler is affected by an 
out-of-bounds write vuln
 CVE-2026-83962 (Substance3D - Modeler is affected by a Stack-based Buffer 
Overflow vul ...)
        NOT-FOR-US: Adobe
 CVE-2026-83803 (Sentry is an error tracking and performance monitoring tool. 
From 23.1 ...)
-       TODO: check
+       NOT-FOR-US: Sentry
 CVE-2026-83660 (Adobe Campaign Classic (ACC) is affected by a Server-Side 
Request Forg ...)
        NOT-FOR-US: Adobe
 CVE-2026-83603 (Netdata is an open source observability tool. Prior to 2.10.4, 
the set ...)
@@ -861,9 +861,9 @@ CVE-2026-88407 (An out-of-bounds read in the 
node_token_count/relation_token_cou
 CVE-2026-88406 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to 
contain a ...)
        NOT-FOR-US: FalkorDB
 CVE-2026-88405 (A remote code execution (RCE) vulnerability in the 
RemoteRegisterFunct ...)
-       TODO: check
+       NOT-FOR-US: Univer
 CVE-2026-88404 (A remote code execution (RCE) vulnerability in the 
UniscriptExecutionS ...)
-       TODO: check
+       NOT-FOR-US: Univer
 CVE-2026-88403 (A Server-Side Request Forgery (SSRF) in the serverRequest 
function of  ...)
        NOT-FOR-US: nocobase
 CVE-2026-88402 (A SQL injection vulnerability in the checkSQL function of 
nocobase v2. ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcf15f446685d9881eeff318e25e4d26a7dfec7e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcf15f446685d9881eeff318e25e4d26a7dfec7e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to