Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8a697d4d by Salvatore Bonaccorso at 2024-05-23T22:50:16+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -23,15 +23,15 @@ CVE-2024-4575 (The LayerSlider plugin for WordPress is 
vulnerable to Stored Cros
 CVE-2024-4471 (The 140+ Widgets | Best Addons For Elementor \u2013 FREE for 
WordPress ...)
        NOT-FOR-US: WordPress plugin
 CVE-2024-4378 (The Premium Addons for Elementor plugin for WordPress is 
vulnerable to ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-4365 (The Advanced iFrame plugin for WordPress is vulnerable to 
Stored Cross ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-3997 (The Prime Slider \u2013 Addons For Elementor (Revolution of a 
slider,  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-35570 (An arbitrary file upload vulnerability in the component 
\controller\Im ...)
-       TODO: check
+       NOT-FOR-US: inxedu
 CVE-2024-35375 (There is an arbitrary file upload vulnerability on the media 
add .php  ...)
-       TODO: check
+       NOT-FOR-US: DedeCMS
 CVE-2024-35224 (OpenProject is the leading open source project management 
software. Op ...)
        TODO: check
 CVE-2024-35223 (Dapr is a portable, event-driven, runtime for building 
distributed app ...)
@@ -43,57 +43,57 @@ CVE-2024-35197 (gitoxide is a pure Rust implementation of 
Git. On Windows, fetch
 CVE-2024-35186 (gitoxide is a pure Rust implementation of Git. During 
checkout, `gix-w ...)
        TODO: check
 CVE-2024-35091 (J2EEFAST v2.7.0 was discovered to contain a SQL injection 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: J2EEFAST
 CVE-2024-35090 (J2EEFAST v2.7.0 was discovered to contain a SQL injection 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: J2EEFAST
 CVE-2024-35086 (J2EEFAST v2.7.0 was discovered to contain a SQL injection 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: J2EEFAST
 CVE-2024-35085 (J2EEFAST v2.7.0 was discovered to contain a SQL injection 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: J2EEFAST
 CVE-2024-35084 (J2EEFAST v2.7.0 was discovered to contain a SQL injection 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: J2EEFAST
 CVE-2024-35083 (J2EEFAST v2.7.0 was discovered to contain a SQL injection 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: J2EEFAST
 CVE-2024-35082 (J2EEFAST v2.7.0 was discovered to contain a SQL injection 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: J2EEFAST
 CVE-2024-35081 (LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary 
file delet ...)
-       TODO: check
+       NOT-FOR-US: LuckyFrameWeb
 CVE-2024-35080 (An arbitrary file upload vulnerability in the gok4 method of 
inxedu v2 ...)
-       TODO: check
+       NOT-FOR-US: inxedu
 CVE-2024-35079 (An arbitrary file upload vulnerability in the uploadAudio 
method of in ...)
-       TODO: check
+       NOT-FOR-US: inxedu
 CVE-2024-34936 (A SQL injection vulnerability in /view/event1.php in Campcodes 
Complet ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34935 (A SQL injection vulnerability in 
/view/conversation_history_admin.php  ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34934 (A SQL injection vulnerability in 
/view/emarks_range_grade_update_form. ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34933 (A SQL injection vulnerability in /model/update_grade.php in 
Campcodes  ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34932 (A SQL injection vulnerability in /model/update_exam.php in 
Campcodes C ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34931 (A SQL injection vulnerability in /model/update_subject.php in 
Campcode ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34930 (A SQL injection vulnerability in /model/all_events1.php in 
Campcodes C ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34929 (A SQL injection vulnerability in /view/find_friends.php in 
Campcodes C ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34928 (A SQL injection vulnerability in 
/model/update_subject_routing.php in  ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34927 (A SQL injection vulnerability in /model/update_classroom.php 
in Campco ...)
-       TODO: check
+       NOT-FOR-US: Campcodes Complete Web-Based School Management System
 CVE-2024-34060 (IrisEVTXModule is an interface module for Evtx2Splunk and Iris 
in orde ...)
        TODO: check
 CVE-2024-32969 (vantage6 is an open-source infrastructure for privacy 
preserving analy ...)
        TODO: check
 CVE-2024-31843 (An issue was discovered in Italtel Embrace 1.6.4. The Web 
application  ...)
-       TODO: check
+       NOT-FOR-US: Italtel Embrace
 CVE-2024-30280 (Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier 
are aff ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2024-30279 (Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier 
are aff ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2024-2861 (The ProfilePress plugin for WordPress is vulnerable to Stored 
Cross-Si ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-2301 (Certain HP LaserJet Pro devices are potentially vulnerable to a 
Cross- ...)
        TODO: check
 CVE-2024-28188 (Jupyter Scheduler is collection of extensions for programming 
jobs to  ...)
@@ -173,23 +173,23 @@ CVE-2024-3626 (The Email Subscribers by Icegram Express 
\u2013 Email Marketing,
 CVE-2024-3594 (The IDonate  WordPress plugin through 1.9.0 does not sanitise 
and esca ...)
        NOT-FOR-US: WordPress plugin
 CVE-2024-3201 (The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to 
Stored ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-3065 (The PayPal Pay Now, Buy Now, Donation and Cart Buttons 
Shortcode plugi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2024-2220 (The Button contact VR WordPress plugin through 4.7 does not 
sanitise a ...)
        TODO: check
 CVE-2024-2038 (The Visual Website Collaboration, Feedback & Project Management 
\u2013 ...)
        TODO: check
 CVE-2024-29853 (An authentication bypass vulnerability in Veeam Agent for 
Microsoft Wi ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2024-29852 (Veeam Backup Enterprise Manager allows high-privileged users 
to read b ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2024-29851 (Veeam Backup Enterprise Manager allows high-privileged users 
to steal  ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2024-29850 (Veeam Backup Enterprise Manager allows account takeover via 
NTLM relay ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2024-29849 (Veeam Backup Enterprise Manager allows unauthenticated users 
to log in ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2024-22026 (A local privilege escalation vulnerability in EPMM before 
12.1.0.0 all ...)
        TODO: check
 CVE-2024-1855 (The WPCafe \u2013 Restaurant Menu, Online Ordering for 
WooCommerce, Pi ...)
@@ -299,9 +299,9 @@ CVE-2024-35551 (idccms v1.35 was discovered to contain a 
Cross-Site Request Forg
 CVE-2024-35550 (idccms v1.35 was discovered to contain a Cross-Site Request 
Forgery (C ...)
        NOT-FOR-US: idccms
 CVE-2024-35475 (A Cross-Site Request Forgery (CSRF) vulnerability was 
discovered in Op ...)
-       TODO: check
+       NOT-FOR-US: OpenKM Community Edition
 CVE-2024-35409 (WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.)
-       TODO: check
+       NOT-FOR-US: WeBid
 CVE-2024-35362 (Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via 
ecshop/arti ...)
        NOT-FOR-US: Ecshop
 CVE-2024-34448 (Ghost before 5.82.0 allows CSV Injection during a member CSV 
export.)
@@ -341,7 +341,7 @@ CVE-2024-31617 (OpenLiteSpeed before 1.8.1 mishandles 
chunked encoding.)
 CVE-2024-2036 (The ApplyOnline \u2013 Application Form Builder and Manager 
plugin for ...)
        TODO: check
 CVE-2024-29421 (xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer 
Overflow  ...)
-       TODO: check
+       NOT-FOR-US: xmedcon
 CVE-2024-29392 (Silverpeas Core 6.3 is vulnerable to Cross Site Scripting 
(XSS) via Cl ...)
        NOT-FOR-US: Silverpeas Core
 CVE-2024-27264 (IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow 
a local ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a697d4dc4bb6eb3ce2197e3284edb609508c8da

-- 
This project does not include diff previews in email notifications.
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a697d4dc4bb6eb3ce2197e3284edb609508c8da
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to