Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
fcf15f44 by Salvatore Bonaccorso at 2026-09-22T21:56:04+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -45,25 +45,25 @@ CVE-2026-95665 (MISP contains a reflected cross-site
scripting (XSS) vulnerabili
CVE-2026-95661 (MISP contains a reflected cross-site scripting (XSS)
vulnerability in ...)
- misp <itp> (bug #1144317)
CVE-2026-95660 (A security flaw has been discovered in Moonshot AI Kimi Code
up to 0.3 ...)
- TODO: check
+ NOT-FOR-US: Moonshot AI Kimi Code
CVE-2026-95659 (MISP contains a reflected cross-site scripting (XSS)
vulnerability in ...)
- misp <itp> (bug #1144317)
CVE-2026-95658 (MISP's WorkflowsController exposed the
moduleStatelessExecution action ...)
- misp <itp> (bug #1144317)
CVE-2026-95657 (A vulnerability was determined in dgtlmoon Changedetection.io
up to 0. ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon Changedetection.io
CVE-2026-95656 (A vulnerability was found in dgtlmoon changedetection.io up to
50389b0 ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon Changedetection.io
CVE-2026-95655 (Aureus ERP before 1.5.0 fails to scope message lookups to the
current ...)
- TODO: check
+ NOT-FOR-US: Aureus ERP
CVE-2026-95654 (Databasement before 1.7.14 validates invitation tokens only
when the a ...)
- TODO: check
+ NOT-FOR-US: Databasement
CVE-2026-95653 (Concrete CMS Community Store before 2.7.8 derives digital
product down ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS Community Store
CVE-2026-95624 (The Tauri updater plugin's 'check' IPC command accepts an
allowDowngra ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95623 (The Tauri HTTP plugin validates requested URLs against the
application ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95619 (A flaw was found in libstdc++. An integer overflow can occur
when proc ...)
TODO: check
CVE-2026-95511
@@ -73,29 +73,29 @@ CVE-2026-95508 (A heap-based buffer overflow was found in
the DHCPv6 and TFTP re
CVE-2026-95503 (A flaw was found in the Kerberos federation provider of
Keycloak, an o ...)
TODO: check
CVE-2026-95501 (A vulnerability was found in mtrano APENCMS up to
6546096d354153309693 ...)
- TODO: check
+ NOT-FOR-US: mtrano APENCMS
CVE-2026-95500 (A vulnerability has been found in JosephChuks
php-file-manager-with-co ...)
- TODO: check
+ NOT-FOR-US: JosephChuks php-file-manager-with-code-editor
CVE-2026-95499 (A flaw has been found in JosephChuks
php-file-manager-with-code-editor ...)
- TODO: check
+ NOT-FOR-US: JosephChuks php-file-manager-with-code-editor
CVE-2026-95396 (A vulnerability was identified in sfturing hosp_order up to
627f426331 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-95273 (A vulnerability was determined in dgtlmoon changedetection.io
up to 0. ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon changedetection.io
CVE-2026-95272 (A vulnerability was found in dgtlmoon changedetection.io up to
0.60.7. ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon changedetection.io
CVE-2026-95271 (A vulnerability has been found in dgtlmoon changedetection.io
up to 0. ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon changedetection.io
CVE-2026-95270 (A flaw has been found in dgtlmoon changedetection.io up to
0.60.7. The ...)
- TODO: check
+ NOT-FOR-US: dgtlmoon changedetection.io
CVE-2026-94570 (SGLang contains a DoS vulnerability caused by missing input
validation ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-94462 (Spree is an open source e-commerce solution built with Ruby on
Rails. ...)
- TODO: check
+ NOT-FOR-US: Spree
CVE-2026-94456 (Postiz generates security-sensitive credentials using
`Math.random()` ...)
- TODO: check
+ NOT-FOR-US: Postiz
CVE-2026-94455 (An HTTP endpoint intended for provisioning enterprise and
reseller org ...)
- TODO: check
+ NOT-FOR-US: Postiz App
CVE-2026-94384 (Missing authorization in Amazon
amazon-connect-salesforce-lambda befor ...)
NOT-FOR-US: Amazon
CVE-2026-94127 (When a BIG-IP APM access policy and an OAuth profile is
configured on ...)
@@ -113,31 +113,31 @@ CVE-2026-93778 (The WP Yelp Review Slider plugin for
WordPress is vulnerable to
CVE-2026-93616 (A directory traversal and file upload vulnerability allows an
unauthen ...)
NOT-FOR-US: Check Point
CVE-2026-93556 (The \u2018/password/guardarClau/recover\u2019 endpoint accepts
the \u2 ...)
- TODO: check
+ NOT-FOR-US: Tankuam Places Kompini
CVE-2026-93345 (MikroTik RouterOS before 7.25beta4 contains an improper input
validati ...)
NOT-FOR-US: MikroTik
CVE-2026-93344 (MarketKing plugin for WordPress before 2.1.72 contains a
missing autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93343 (MarketKing plugin for WordPress before 2.1.72 contains a
missing autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93342 (MarketKing plugin for WordPress before 2.1.72 contains a
missing autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93341 (MarketKing plugin for WordPress before 2.1.72 contains a
missing autho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-93088 (SGLang's multimodal generation runtime is vulnerable to
unauthenticate ...)
- TODO: check
+ NOT-FOR-US: SGLang
CVE-2026-92969 (The HUSKY \u2013 Products Filter for WooCommerce Professional
plugin f ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92882 (Insufficiently protected credentials in the host and folder
configurat ...)
NOT-FOR-US: Checkmk
CVE-2026-92706 (Dark Reader is an accessibility browser extension that makes
web pages ...)
- TODO: check
+ NOT-FOR-US: Dark Reader
CVE-2026-92235 (The The WP Ultimate Review plugin for WordPress is vulnerable
to arbit ...)
NOT-FOR-US: WordPress plugin
CVE-2026-91130 (Home Assistant is open source home automation software focused
on loca ...)
- TODO: check
+ NOT-FOR-US: Home Assistant
CVE-2026-91129 (Home Assistant is open source home automation software focused
on loca ...)
- TODO: check
+ NOT-FOR-US: Home Assistant
CVE-2026-91092 (The wpForo Forum plugin for WordPress is vulnerable to
authorization b ...)
NOT-FOR-US: WordPress plugin
CVE-2026-90990 (Improper neutralization of newlines in filter values in the
monitoring ...)
@@ -151,7 +151,7 @@ CVE-2026-8849 (Use After Free vulnerability in RTI Connext
Professional (Securit
CVE-2026-89422 (Key Exchange without Entity Authentication vulnerability in
Erlang/OTP ...)
TODO: check
CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive
mpp allo ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-89407 (NumberInput.looksLikeValidNumber() in FasterXML jackson-core
pre-valid ...)
TODO: check
CVE-2026-89277 (CAI Content Credentials is affected by an Integer Overflow or
Wraparou ...)
@@ -161,41 +161,41 @@ CVE-2026-89276 (Adobe Campaign Classic (ACC) is affected
by an Improper Control
CVE-2026-89275 (Adobe Campaign Classic (ACC) is affected by an Improper
Control of Gen ...)
NOT-FOR-US: Adobe
CVE-2026-88415 (MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site
Scripting ...)
- TODO: check
+ NOT-FOR-US: MCMS
CVE-2026-88414 (MCMS 6.1.1 through 6.2.1 contains a SQL injection
vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: MCMS
CVE-2026-88010 (Traefik is an open source HTTP reverse proxy and load
balancer. From 3 ...)
TODO: check
CVE-2026-87902 (An unauthenticated attacker can make `get_page_template()`
page-templa ...)
TODO: check
CVE-2026-87119 (Authentication Bypass by Capture-replay in ZenHive mpp allows
an attac ...)
- TODO: check
+ NOT-FOR-US: ZenHive mpp
CVE-2026-86698 (Insufficient Session Expiration vulnerability in OAuth token
issuance ...)
TODO: check
CVE-2026-86062 (LightRAG provides simple and fast retrieval-augmented
generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-86059 (Dokploy is a free, self-hostable Platform as a Service (PaaS).
Prior t ...)
- TODO: check
+ NOT-FOR-US: Dokploy
CVE-2026-86056 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.8 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-86054 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.8 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-85995 (Notepad++ is a free and open-source source code editor. From
8.9.7 unt ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-85740 (LightRAG provides simple and fast retrieval-augmented
generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-85734 (LightRAG provides simple and fast retrieval-augmented
generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-85725 (LightRAG provides simple and fast retrieval-augmented
generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-85709 (LightRAG provides simple and fast retrieval-augmented
generation. Prio ...)
- TODO: check
+ NOT-FOR-US: LightRAG
CVE-2026-85288 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.8 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-85279 (Notepad++ is a free and open-source source code editor. Prior
to 8.9.8 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-85055 (Twenty is an open-source CRM (customer relationship
management) platfo ...)
- TODO: check
+ NOT-FOR-US: Twenty
CVE-2026-84412 (Adobe Campaign Classic (ACC) is affected by an Improper
Control of Gen ...)
NOT-FOR-US: Adobe
CVE-2026-84396 (InDesign Desktop is affected by a NULL Pointer Dereference
vulnerabili ...)
@@ -205,7 +205,7 @@ CVE-2026-84395 (Premiere Pro [NEEDS REVIEW: environment
mismatch \u2014 product
CVE-2026-84388 (A improper restriction of rendered ui layers or frames
vulnerability i ...)
NOT-FOR-US: Fortinet
CVE-2026-84301 (FastGPT is an open-source LLM platform for building AI
applications on ...)
- TODO: check
+ NOT-FOR-US: FastGPT
CVE-2026-83964 (Adobe Connect is affected by an Improper Certificate
Validation vulner ...)
NOT-FOR-US: Adobe
CVE-2026-83963 (Substance3D - Modeler is affected by an out-of-bounds write
vulnerabil ...)
@@ -213,7 +213,7 @@ CVE-2026-83963 (Substance3D - Modeler is affected by an
out-of-bounds write vuln
CVE-2026-83962 (Substance3D - Modeler is affected by a Stack-based Buffer
Overflow vul ...)
NOT-FOR-US: Adobe
CVE-2026-83803 (Sentry is an error tracking and performance monitoring tool.
From 23.1 ...)
- TODO: check
+ NOT-FOR-US: Sentry
CVE-2026-83660 (Adobe Campaign Classic (ACC) is affected by a Server-Side
Request Forg ...)
NOT-FOR-US: Adobe
CVE-2026-83603 (Netdata is an open source observability tool. Prior to 2.10.4,
the set ...)
@@ -861,9 +861,9 @@ CVE-2026-88407 (An out-of-bounds read in the
node_token_count/relation_token_cou
CVE-2026-88406 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to
contain a ...)
NOT-FOR-US: FalkorDB
CVE-2026-88405 (A remote code execution (RCE) vulnerability in the
RemoteRegisterFunct ...)
- TODO: check
+ NOT-FOR-US: Univer
CVE-2026-88404 (A remote code execution (RCE) vulnerability in the
UniscriptExecutionS ...)
- TODO: check
+ NOT-FOR-US: Univer
CVE-2026-88403 (A Server-Side Request Forgery (SSRF) in the serverRequest
function of ...)
NOT-FOR-US: nocobase
CVE-2026-88402 (A SQL injection vulnerability in the checkSQL function of
nocobase v2. ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcf15f446685d9881eeff318e25e4d26a7dfec7e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcf15f446685d9881eeff318e25e4d26a7dfec7e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits