Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8a697d4d by Salvatore Bonaccorso at 2024-05-23T22:50:16+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -23,15 +23,15 @@ CVE-2024-4575 (The LayerSlider plugin for WordPress is
vulnerable to Stored Cros
CVE-2024-4471 (The 140+ Widgets | Best Addons For Elementor \u2013 FREE for
WordPress ...)
NOT-FOR-US: WordPress plugin
CVE-2024-4378 (The Premium Addons for Elementor plugin for WordPress is
vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-4365 (The Advanced iFrame plugin for WordPress is vulnerable to
Stored Cross ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-3997 (The Prime Slider \u2013 Addons For Elementor (Revolution of a
slider, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-35570 (An arbitrary file upload vulnerability in the component
\controller\Im ...)
- TODO: check
+ NOT-FOR-US: inxedu
CVE-2024-35375 (There is an arbitrary file upload vulnerability on the media
add .php ...)
- TODO: check
+ NOT-FOR-US: DedeCMS
CVE-2024-35224 (OpenProject is the leading open source project management
software. Op ...)
TODO: check
CVE-2024-35223 (Dapr is a portable, event-driven, runtime for building
distributed app ...)
@@ -43,57 +43,57 @@ CVE-2024-35197 (gitoxide is a pure Rust implementation of
Git. On Windows, fetch
CVE-2024-35186 (gitoxide is a pure Rust implementation of Git. During
checkout, `gix-w ...)
TODO: check
CVE-2024-35091 (J2EEFAST v2.7.0 was discovered to contain a SQL injection
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35090 (J2EEFAST v2.7.0 was discovered to contain a SQL injection
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35086 (J2EEFAST v2.7.0 was discovered to contain a SQL injection
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35085 (J2EEFAST v2.7.0 was discovered to contain a SQL injection
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35084 (J2EEFAST v2.7.0 was discovered to contain a SQL injection
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35083 (J2EEFAST v2.7.0 was discovered to contain a SQL injection
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35082 (J2EEFAST v2.7.0 was discovered to contain a SQL injection
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: J2EEFAST
CVE-2024-35081 (LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary
file delet ...)
- TODO: check
+ NOT-FOR-US: LuckyFrameWeb
CVE-2024-35080 (An arbitrary file upload vulnerability in the gok4 method of
inxedu v2 ...)
- TODO: check
+ NOT-FOR-US: inxedu
CVE-2024-35079 (An arbitrary file upload vulnerability in the uploadAudio
method of in ...)
- TODO: check
+ NOT-FOR-US: inxedu
CVE-2024-34936 (A SQL injection vulnerability in /view/event1.php in Campcodes
Complet ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34935 (A SQL injection vulnerability in
/view/conversation_history_admin.php ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34934 (A SQL injection vulnerability in
/view/emarks_range_grade_update_form. ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34933 (A SQL injection vulnerability in /model/update_grade.php in
Campcodes ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34932 (A SQL injection vulnerability in /model/update_exam.php in
Campcodes C ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34931 (A SQL injection vulnerability in /model/update_subject.php in
Campcode ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34930 (A SQL injection vulnerability in /model/all_events1.php in
Campcodes C ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34929 (A SQL injection vulnerability in /view/find_friends.php in
Campcodes C ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34928 (A SQL injection vulnerability in
/model/update_subject_routing.php in ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34927 (A SQL injection vulnerability in /model/update_classroom.php
in Campco ...)
- TODO: check
+ NOT-FOR-US: Campcodes Complete Web-Based School Management System
CVE-2024-34060 (IrisEVTXModule is an interface module for Evtx2Splunk and Iris
in orde ...)
TODO: check
CVE-2024-32969 (vantage6 is an open-source infrastructure for privacy
preserving analy ...)
TODO: check
CVE-2024-31843 (An issue was discovered in Italtel Embrace 1.6.4. The Web
application ...)
- TODO: check
+ NOT-FOR-US: Italtel Embrace
CVE-2024-30280 (Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier
are aff ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2024-30279 (Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier
are aff ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2024-2861 (The ProfilePress plugin for WordPress is vulnerable to Stored
Cross-Si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-2301 (Certain HP LaserJet Pro devices are potentially vulnerable to a
Cross- ...)
TODO: check
CVE-2024-28188 (Jupyter Scheduler is collection of extensions for programming
jobs to ...)
@@ -173,23 +173,23 @@ CVE-2024-3626 (The Email Subscribers by Icegram Express
\u2013 Email Marketing,
CVE-2024-3594 (The IDonate WordPress plugin through 1.9.0 does not sanitise
and esca ...)
NOT-FOR-US: WordPress plugin
CVE-2024-3201 (The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to
Stored ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-3065 (The PayPal Pay Now, Buy Now, Donation and Cart Buttons
Shortcode plugi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-2220 (The Button contact VR WordPress plugin through 4.7 does not
sanitise a ...)
TODO: check
CVE-2024-2038 (The Visual Website Collaboration, Feedback & Project Management
\u2013 ...)
TODO: check
CVE-2024-29853 (An authentication bypass vulnerability in Veeam Agent for
Microsoft Wi ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-29852 (Veeam Backup Enterprise Manager allows high-privileged users
to read b ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-29851 (Veeam Backup Enterprise Manager allows high-privileged users
to steal ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-29850 (Veeam Backup Enterprise Manager allows account takeover via
NTLM relay ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-29849 (Veeam Backup Enterprise Manager allows unauthenticated users
to log in ...)
- TODO: check
+ NOT-FOR-US: Veeam
CVE-2024-22026 (A local privilege escalation vulnerability in EPMM before
12.1.0.0 all ...)
TODO: check
CVE-2024-1855 (The WPCafe \u2013 Restaurant Menu, Online Ordering for
WooCommerce, Pi ...)
@@ -299,9 +299,9 @@ CVE-2024-35551 (idccms v1.35 was discovered to contain a
Cross-Site Request Forg
CVE-2024-35550 (idccms v1.35 was discovered to contain a Cross-Site Request
Forgery (C ...)
NOT-FOR-US: idccms
CVE-2024-35475 (A Cross-Site Request Forgery (CSRF) vulnerability was
discovered in Op ...)
- TODO: check
+ NOT-FOR-US: OpenKM Community Edition
CVE-2024-35409 (WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.)
- TODO: check
+ NOT-FOR-US: WeBid
CVE-2024-35362 (Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via
ecshop/arti ...)
NOT-FOR-US: Ecshop
CVE-2024-34448 (Ghost before 5.82.0 allows CSV Injection during a member CSV
export.)
@@ -341,7 +341,7 @@ CVE-2024-31617 (OpenLiteSpeed before 1.8.1 mishandles
chunked encoding.)
CVE-2024-2036 (The ApplyOnline \u2013 Application Form Builder and Manager
plugin for ...)
TODO: check
CVE-2024-29421 (xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer
Overflow ...)
- TODO: check
+ NOT-FOR-US: xmedcon
CVE-2024-29392 (Silverpeas Core 6.3 is vulnerable to Cross Site Scripting
(XSS) via Cl ...)
NOT-FOR-US: Silverpeas Core
CVE-2024-27264 (IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow
a local ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a697d4dc4bb6eb3ce2197e3284edb609508c8da
--
This project does not include diff previews in email notifications.
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a697d4dc4bb6eb3ce2197e3284edb609508c8da
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits