[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu May 23 21:50:49 BST 2024
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8a697d4d by Salvatore Bonaccorso at 2024-05-23T22:50:16+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -23,15 +23,15 @@ CVE-2024-4575 (The LayerSlider plugin for WordPress is vulnerable to Stored Cros
CVE-2024-4471 (The 140+ Widgets | Best Addons For Elementor \u2013 FREE for WordPress ...)
NOT-FOR-US: WordPress plugin
CVE-2024-4378 (The Premium Addons for Elementor plugin for WordPress is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-4365 (The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-3997 (The Prime Slider \u2013 Addons For Elementor (Revolution of a slider, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-35570 (An arbitrary file upload vulnerability in the component \controller\Im ...)
- TODO: check
+ NOT-FOR-US: inxedu
CVE-2024-35375 (There is an arbitrary file upload vulnerability on the media add .php ...)
- TODO: check
+ NOT-FOR-US: DedeCMS
CVE-2024-35224 (OpenProject is the leading open source project management software. Op ...)
TODO: check
CVE-2024-35223 (Dapr is a portable, event-driven, runtime for building distributed app ...)
@@ -43,57 +43,57 @@ CVE-2024-35197 (gitoxide is a pure Rust implementation of Git. On Windows, fetch
CVE-2024-35186 (gitoxide is a pure Rust implementation of Git. During checkout, `gix-w ...)
TODO: check
CVE-2024-35091 (J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35090 (J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35086 (J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35085 (J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35084 (J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35083 (J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35082 (J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35081 (LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file delet ...)
- TODO: check
+ NOT-FOR-US: LuckyFrameWeb
CVE-2024-35080 (An arbitrary file upload vulnerability in the gok4 method of inxedu v2 ...)
- TODO: check
+ NOT-FOR-US: inxedu
CVE-2024-35079 (An arbitrary file upload vulnerability in the uploadAudio method of in ...)
- TODO: check
+ NOT-FOR-US: inxedu
CVE-2024-34936 (A SQL injection vulnerability in /view/event1.php in Campcodes Complet ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34935 (A SQL injection vulnerability in /view/conversation_history_admin.php ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34934 (A SQL injection vulnerability in /view/emarks_range_grade_update_form. ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34933 (A SQL injection vulnerability in /model/update_grade.php in Campcodes ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34932 (A SQL injection vulnerability in /model/update_exam.php in Campcodes C ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34931 (A SQL injection vulnerability in /model/update_subject.php in Campcode ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34930 (A SQL injection vulnerability in /model/all_events1.php in Campcodes C ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34929 (A SQL injection vulnerability in /view/find_friends.php in Campcodes C ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34928 (A SQL injection vulnerability in /model/update_subject_routing.php in ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34927 (A SQL injection vulnerability in /model/update_classroom.php in Campco ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34060 (IrisEVTXModule is an interface module for Evtx2Splunk and Iris in orde ...)
TODO: check
CVE-2024-32969 (vantage6 is an open-source infrastructure for privacy preserving analy ...)
TODO: check
CVE-2024-31843 (An issue was discovered in Italtel Embrace 1.6.4. The Web application ...)
- TODO: check
+ NOT-FOR-US: Italtel Embrace
CVE-2024-30280 (Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are aff ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2024-30279 (Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are aff ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2024-2861 (The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-2301 (Certain HP LaserJet Pro devices are potentially vulnerable to a Cross- ...)
TODO: check
CVE-2024-28188 (Jupyter Scheduler is collection of extensions for programming jobs to ...)
@@ -173,23 +173,23 @@ CVE-2024-3626 (The Email Subscribers by Icegram Express \u2013 Email Marketing,
CVE-2024-3594 (The IDonate WordPress plugin through 1.9.0 does not sanitise and esca ...)
NOT-FOR-US: WordPress plugin
CVE-2024-3201 (The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-3065 (The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-2220 (The Button contact VR WordPress plugin through 4.7 does not sanitise a ...)
TODO: check
CVE-2024-2038 (The Visual Website Collaboration, Feedback & Project Management \u2013 ...)
TODO: check
CVE-2024-29853 (An authentication bypass vulnerability in Veeam Agent for Microsoft Wi ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-29852 (Veeam Backup Enterprise Manager allows high-privileged users to read b ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-29851 (Veeam Backup Enterprise Manager allows high-privileged users to steal ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-29850 (Veeam Backup Enterprise Manager allows account takeover via NTLM relay ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-29849 (Veeam Backup Enterprise Manager allows unauthenticated users to log in ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-22026 (A local privilege escalation vulnerability in EPMM before 12.1.0.0 all ...)
TODO: check
CVE-2024-1855 (The WPCafe \u2013 Restaurant Menu, Online Ordering for WooCommerce, Pi ...)
@@ -299,9 +299,9 @@ CVE-2024-35551 (idccms v1.35 was discovered to contain a Cross-Site Request Forg
CVE-2024-35550 (idccms v1.35 was discovered to contain a Cross-Site Request Forgery (C ...)
NOT-FOR-US: idccms
CVE-2024-35475 (A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Op ...)
- TODO: check
+ NOT-FOR-US: OpenKM Community Edition
CVE-2024-35409 (WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.)
- TODO: check
+ NOT-FOR-US: WeBid
CVE-2024-35362 (Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/arti ...)
NOT-FOR-US: Ecshop
CVE-2024-34448 (Ghost before 5.82.0 allows CSV Injection during a member CSV export.)
@@ -341,7 +341,7 @@ CVE-2024-31617 (OpenLiteSpeed before 1.8.1 mishandles chunked encoding.)
CVE-2024-2036 (The ApplyOnline \u2013 Application Form Builder and Manager plugin for ...)
TODO: check
CVE-2024-29421 (xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow ...)
- TODO: check
+ NOT-FOR-US: xmedcon
CVE-2024-29392 (Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via Cl ...)
NOT-FOR-US: Silverpeas Core
CVE-2024-27264 (IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a697d4dc4bb6eb3ce2197e3284edb609508c8da
--
This project does not include diff previews in email notifications.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a697d4dc4bb6eb3ce2197e3284edb609508c8da
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240523/1150bebc/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list