Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
eaad350b by Salvatore Bonaccorso at 2024-11-21T10:15:06+01:00
Process more NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -35,35 +35,35 @@ CVE-2024-52797 (Opencast is free and open source software
for automated video ca
CVE-2024-52796 (Password Pusher, an open source application to communicate
sensitive i ...)
TODO: check
CVE-2024-52771 (DedeBIZ v6.3.0 was discovered to contain an arbitrary file
deletion vu ...)
- TODO: check
+ NOT-FOR-US: DedeBIZ
CVE-2024-52770 (An arbitrary file upload vulnerability in the component
/admin/file_ma ...)
- TODO: check
+ NOT-FOR-US: DedeBIZ
CVE-2024-52769 (An arbitrary file upload vulnerability in the component
/admin/friendl ...)
- TODO: check
+ NOT-FOR-US: DedeBIZ
CVE-2024-52765 (H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code
executio ...)
- TODO: check
+ NOT-FOR-US: H3C GR-1800AX MiniGRW1B0V100R007
CVE-2024-52763 (A cross-site scripting (XSS) vulnerability in the component
/graph_all ...)
TODO: check
CVE-2024-52762 (A cross-site scripting (XSS) vulnerability in the component
/master/he ...)
TODO: check
CVE-2024-52757 (D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer
overflow ...)
- TODO: check
+ NOT-FOR-US: D-LINK
CVE-2024-52755 (D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer
overflow ...)
- TODO: check
+ NOT-FOR-US: D-LINK
CVE-2024-52754 (D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer
overflow ...)
- TODO: check
+ NOT-FOR-US: D-LINK
CVE-2024-52739 (D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple
remote c ...)
- TODO: check
+ NOT-FOR-US: D-LINK
CVE-2024-52725 (SemCms v4.8 was discovered to contain a SQL injection
vulnerability. T ...)
- TODO: check
+ NOT-FOR-US: SemCms
CVE-2024-52702 (A stored cross-site scripting (XSS) vulnerability in the
component ins ...)
TODO: check
CVE-2024-52701 (A stored cross-site scripting (XSS) vulnerability in the
Configuration ...)
TODO: check
CVE-2024-52677 (HkCms <= v2.3.2.240702 is vulnerable to file upload in the
getFileName ...)
- TODO: check
+ NOT-FOR-US: HkCms
CVE-2024-52614 (Use of hard-coded cryptographic key issue exists in "Kura
Sushi Offici ...)
- TODO: check
+ NOT-FOR-US: "Kura Sushi Official App Produced by EPARK" for Android
CVE-2024-52598 (2FAuth is a web app to manage Two-Factor Authentication (2FA)
accounts ...)
TODO: check
CVE-2024-52597 (2FAuth is a web app to manage Two-Factor Authentication (2FA)
accounts ...)
@@ -71,51 +71,51 @@ CVE-2024-52597 (2FAuth is a web app to manage Two-Factor
Authentication (2FA) ac
CVE-2024-52595 (lxml_html_clean is a project for HTML cleaning functionalities
copied ...)
TODO: check
CVE-2024-52581 (Litestar is an Asynchronous Server Gateway Interface (ASGI)
framework. ...)
- TODO: check
+ NOT-FOR-US: Litestar
CVE-2024-52473 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: Sandeep Verma HTML5 Lyrics araoke Player
CVE-2024-52472 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52471 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52470 (Improper Neutralization of Input During Web Page Generation
(XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52451 (Cross-Site Request Forgery (CSRF) vulnerability in Aaron
Robbins Post ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52450 (Improper Control of Filename for Include/Require Statement in
PHP Prog ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52449 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52448 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52447 (Path Traversal: '.../...//' vulnerability in Corporate Zen
Contact Pag ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52446 (Cross-Site Request Forgery (CSRF) vulnerability in Buying
Buddy Buying ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52445 (Deserialization of Untrusted Data vulnerability in Modeltheme
QRMenu R ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52444 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52443 (Deserialization of Untrusted Data vulnerability in Nerijus
Masikonis G ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52442 (Incorrect Privilege Assignment vulnerability in Userplus
UserPlus allo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52441 (Improperly Controlled Modification of Object Prototype
Attributes ('Pr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52440 (Deserialization of Untrusted Data vulnerability in Bueno Labs
Pvt. Ltd ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52439 (Deserialization of Untrusted Data vulnerability in Mark
O\u2019Donnell ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52438 (Missing Authentication for Critical Function vulnerability in
deco.Age ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52437 (Missing Authentication for Critical Function vulnerability in
Saul Mor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52392 (Cross-Site Request Forgery (CSRF) vulnerability in W3speedster
W3SPEED ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-52033 (Exposure of sensitive system information to an unauthorized
control sp ...)
- TODO: check
+ NOT-FOR-US: Rakuten Turbo 5G firmware
CVE-2024-51669 (Cross-Site Request Forgery (CSRF) vulnerability in Vivwebs
Dynamic Wid ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-51209 (Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's
Client Mana ...)
TODO: check
CVE-2024-51208 (File Upload vulnerability in change-image.php in Anuj Kumar's
Boat Boo ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eaad350bf6ae552cb4a45c6624ae54aad5e49fc5
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eaad350bf6ae552cb4a45c6624ae54aad5e49fc5
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits