<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=introduo+rabbitmq%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 11:02:55 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 11:02:55 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=introduo+rabbitmq%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=introduo+rabbitmq%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[[NEU] [mittel] RabbitMQ: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3691294/it-security-nachrichten/neu-mittel-rabbitmq-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691294/it-security-nachrichten/neu-mittel-rabbitmq-mehrere-schwachstellen/</guid>
<pubDate>Fri, 24 Jul 2026 12:39:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] RabbitMQ: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um Denial-of-Service-Angriffe durchzuführen, Autorisierungs- und Mandantengrenzen zu umgehen, Daten zu manipulieren oder offenzulegen und Cross Site Scripting Angriffe durchzuführen.]]></description>
<link>https://tsecurity.de/de/3688745/it-security-nachrichten/neu-mittel-rabbitmq-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688745/it-security-nachrichten/neu-mittel-rabbitmq-mehrere-schwachstellen/</guid>
<pubDate>Thu, 23 Jul 2026 12:43:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um Denial-of-Service-Angriffe durchzuführen, Autorisierungs- und Mandantengrenzen zu umgehen, Daten zu manipulieren oder offenzulegen und Cross Site Scripting Angriffe durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-07-15]]></title>
<description><![CDATA[172 posts were published in the last hour 21:34 : Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’ 21:11 : RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover 20:10 : Facebook Tops the List of Social Apps People…
Read more →
The post IT Security News ...]]></description>
<link>https://tsecurity.de/de/3672005/it-security-nachrichten/it-security-news-daily-summary-2026-07-15/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672005/it-security-nachrichten/it-security-news-daily-summary-2026-07-15/</guid>
<pubDate>Thu, 16 Jul 2026 00:07:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>172 posts were published in the last hour 21:34 : Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’ 21:11 : RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover 20:10 : Facebook Tops the List of Social Apps People…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-07-15/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-07-15/">IT Security News Daily Summary 2026-07-15</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-16 00h : 3 posts]]></title>
<description><![CDATA[3 posts were published in the last hour 21:56 : IT Security News Daily Summary 2026-07-15 21:34 : Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’ 21:11 : RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover
Read more →
The post IT Security News Hourly...]]></description>
<link>https://tsecurity.de/de/3672003/it-security-nachrichten/it-security-news-hourly-summary-2026-07-16-00h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672003/it-security-nachrichten/it-security-news-hourly-summary-2026-07-16-00h-3-posts/</guid>
<pubDate>Thu, 16 Jul 2026 00:07:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>3 posts were published in the last hour 21:56 : IT Security News Daily Summary 2026-07-15 21:34 : Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’ 21:11 : RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-16-00h-3-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-16-00h-3-posts/">IT Security News Hourly Summary 2026-07-16 00h : 3 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover]]></title>
<description><![CDATA[Miggo disclosed two RabbitMQ vulnerabilities that could enable unauthenticated broker takeover or expose tenant metadata. The post RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read th...]]></description>
<link>https://tsecurity.de/de/3671891/it-security-nachrichten/rabbitmq-vulnerabilities-could-enable-unauthenticated-broker-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671891/it-security-nachrichten/rabbitmq-vulnerabilities-could-enable-unauthenticated-broker-takeover/</guid>
<pubDate>Wed, 15 Jul 2026 23:23:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Miggo disclosed two RabbitMQ vulnerabilities that could enable unauthenticated broker takeover or expose tenant metadata. The post RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/rabbitmq-vulnerabilities-could-enable-unauthenticated-broker-takeover/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/rabbitmq-vulnerabilities-could-enable-unauthenticated-broker-takeover/">RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover ]]></title>
<description><![CDATA[Miggo disclosed two RabbitMQ vulnerabilities that could enable unauthenticated broker takeover or expose tenant metadata.
The post RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover  appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3671872/it-security-nachrichten/rabbitmq-vulnerabilities-could-enable-unauthenticated-broker-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671872/it-security-nachrichten/rabbitmq-vulnerabilities-could-enable-unauthenticated-broker-takeover/</guid>
<pubDate>Wed, 15 Jul 2026 23:07:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Miggo disclosed two RabbitMQ vulnerabilities that could enable unauthenticated broker takeover or expose tenant metadata.</p>
<p>The post <a href="https://www.esecurityplanet.com/threats/rabbitmq-vulnerabilities-could-enable-unauthenticated-broker-takeover/">RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover </a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ Flaw Exposes OAuth Secrets, Risks Full Broker Takeover]]></title>
<description><![CDATA[  A serious vulnerability in RabbitMQ is threatening enterprise messaging systems by allowing attackers to steal OAuth secrets and take full control of brokers. Tracked as CVE-2026-57219, the flaw has a CVSS score of 8.7 and affects popular RabbitMQ versions…
Read more →
The post RabbitMQ Flaw Ex...]]></description>
<link>https://tsecurity.de/de/3671520/it-security-nachrichten/rabbitmq-flaw-exposes-oauth-secrets-risks-full-broker-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671520/it-security-nachrichten/rabbitmq-flaw-exposes-oauth-secrets-risks-full-broker-takeover/</guid>
<pubDate>Wed, 15 Jul 2026 19:39:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  A serious vulnerability in RabbitMQ is threatening enterprise messaging systems by allowing attackers to steal OAuth secrets and take full control of brokers. Tracked as CVE-2026-57219, the flaw has a CVSS score of 8.7 and affects popular RabbitMQ versions…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/rabbitmq-flaw-exposes-oauth-secrets-risks-full-broker-takeover/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/rabbitmq-flaw-exposes-oauth-secrets-risks-full-broker-takeover/">RabbitMQ Flaw Exposes OAuth Secrets, Risks Full Broker Takeover</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598]]></title>
<description><![CDATA[Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-598]]></description>
<link>https://tsecurity.de/de/3669151/it-security-nachrichten/mr-data-joomla-babooa-1vpns-rabbitmq-uefi-center-16-sextortion-aaran-leyland-swn-598/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669151/it-security-nachrichten/mr-data-joomla-babooa-1vpns-rabbitmq-uefi-center-16-sextortion-aaran-leyland-swn-598/</guid>
<pubDate>Tue, 14 Jul 2026 23:22:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/swn-598">https://securityweekly.com/swn-598</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. 

Visit https://www.securityweekly.com/swn for all the latest episodes!

Show Notes: https://securityweekl...]]></description>
<link>https://tsecurity.de/de/3669129/it-security-video/mr-data-joomla-babooa-1vpns-rabbitmq-uefi-center-16-sextortion-aaran-leyland-swn-598/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669129/it-security-video/mr-data-joomla-babooa-1vpns-rabbitmq-uefi-center-16-sextortion-aaran-leyland-swn-598/</guid>
<pubDate>Tue, 14 Jul 2026 23:01:52 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/nXufkyBiQ8E?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. <br />
<br />
Visit https://www.securityweekly.com/swn for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/swn-598<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ: Zwei Schwachstellen leaken OAuth-Secrets und sprengen Tenant-Grenzen]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – RabbitMQ meldet gleich zwei Security-Lücken, die im schlimmsten Fall OAuth-Client-Secrets preisgeben und damit eine vollständige Übernahme des Brokers ermöglichen. Außerdem kann eine fehlende Autorisierung dazu führen, dass ein Angreifer Metadaten und Nachrichten-Zählwerte ...]]></description>
<link>https://tsecurity.de/de/3668974/it-security-nachrichten/rabbitmq-zwei-schwachstellen-leaken-oauth-secrets-und-sprengen-tenant-grenzen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668974/it-security-nachrichten/rabbitmq-zwei-schwachstellen-leaken-oauth-secrets-und-sprengen-tenant-grenzen/</guid>
<pubDate>Tue, 14 Jul 2026 21:20:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rabbitmq-oauth-tenant-schwachstellen.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rabbitmq-oauth-tenant-schwachstellen.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rabbitmq-oauth-tenant-schwachstellen-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rabbitmq-oauth-tenant-schwachstellen-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rabbitmq-oauth-tenant-schwachstellen-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rabbitmq-oauth-tenant-schwachstellen-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rabbitmq-oauth-tenant-schwachstellen-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – RabbitMQ meldet gleich zwei Security-Lücken, die im schlimmsten Fall OAuth-Client-Secrets preisgeben und damit eine vollständige Übernahme des Brokers ermöglichen. Außerdem kann eine fehlende Autorisierung dazu führen, dass ein Angreifer Metadaten und Nachrichten-Zählwerte aus fremden Virtual Hosts ausliest. Betroffen sind Release-Linien ab 3.13.0; die Fixes sind bereits in mehreren 4.x- und 3.13.x-Versionen […]</p>
<div><a href="https://www.it-boltwise.de/rabbitmq-zwei-schwachstellen-leaken-oauth-secrets-und-sprengen-tenant-grenzen.html">... den vollständigen Artikel <strong>»RabbitMQ: Zwei Schwachstellen leaken OAuth-Secrets und sprengen Tenant-Grenzen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/rabbitmq-zwei-schwachstellen-leaken-oauth-secrets-und-sprengen-tenant-grenzen.html">RabbitMQ: Zwei Schwachstellen leaken OAuth-Secrets und sprengen Tenant-Grenzen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries.

Miggo's security...]]></description>
<link>https://tsecurity.de/de/3668347/it-security-nachrichten/rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-tenant-queue-metadata/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668347/it-security-nachrichten/rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-tenant-queue-metadata/</guid>
<pubDate>Tue, 14 Jul 2026 16:38:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries.

Miggo's security team, which discovered and reported the flaws, said one "leaks the broker's confidential OAuth]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo’s security ...]]></description>
<link>https://tsecurity.de/de/3668340/it-security-nachrichten/rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-tenant-queue-metadata/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668340/it-security-nachrichten/rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-tenant-queue-metadata/</guid>
<pubDate>Tue, 14 Jul 2026 16:38:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo’s security team, which…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-tenant-queue-metadata/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-tenant-queue-metadata/">RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57217 | RabbitMQ up to 3.13.14/4.0.20/4.1.10/4.2.5 Topic Authorization lookup improper authorization (Nessus ID 326535)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in RabbitMQ up to 3.13.14/4.0.20/4.1.10/4.2.5. Affected by this vulnerability is the function lookup of the component Topic Authorization. Such manipulation leads to improper authorization.

This vulnerability is referenced as CVE-2026-5...]]></description>
<link>https://tsecurity.de/de/3667359/sicherheitsluecken/cve-2026-57217-rabbitmq-up-to-3131440204110425-topic-authorization-lookup-improper-authorization-nessus-id-326535/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667359/sicherheitsluecken/cve-2026-57217-rabbitmq-up-to-3131440204110425-topic-authorization-lookup-improper-authorization-nessus-id-326535/</guid>
<pubDate>Tue, 14 Jul 2026 10:55:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/rabbitmq">RabbitMQ up to 3.13.14/4.0.20/4.1.10/4.2.5</a>. Affected by this vulnerability is the function <code>lookup</code> of the component <em>Topic Authorization</em>. Such manipulation leads to improper authorization.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-57217">CVE-2026-57217</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57212 | rabbitmq Server up to 3.13.13/4.0.18/4.1.9/4.2.4 HTTP API read_complete_body information disclosure (Nessus ID 326532)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in rabbitmq Server up to 3.13.13/4.0.18/4.1.9/4.2.4. This vulnerability affects the function read_complete_body of the component HTTP API. The manipulation results in information disclosure.

This vulnerability is reported as CVE-2026-57212. The...]]></description>
<link>https://tsecurity.de/de/3667358/sicherheitsluecken/cve-2026-57212-rabbitmq-server-up-to-313134018419424-http-api-readcompletebody-information-disclosure-nessus-id-326532/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667358/sicherheitsluecken/cve-2026-57212-rabbitmq-server-up-to-313134018419424-http-api-readcompletebody-information-disclosure-nessus-id-326532/</guid>
<pubDate>Tue, 14 Jul 2026 10:55:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/rabbitmq:server">rabbitmq Server up to 3.13.13/4.0.18/4.1.9/4.2.4</a>. This vulnerability affects the function <code>read_complete_body</code> of the component <em>HTTP API</em>. The manipulation results in information disclosure.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-57212">CVE-2026-57212</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57216 | RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5 Authentication infinite loop (Nessus ID 326538)]]></title>
<description><![CDATA[A vulnerability was found in RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5. It has been declared as problematic. This impacts an unknown function of the component Authentication Handler. The manipulation results in infinite loop.

This vulnerability was named CVE-2026-57216. The attack may be perfor...]]></description>
<link>https://tsecurity.de/de/3667291/sicherheitsluecken/cve-2026-57216-rabbitmq-up-to-3131440194110425-authentication-infinite-loop-nessus-id-326538/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667291/sicherheitsluecken/cve-2026-57216-rabbitmq-up-to-3131440194110425-authentication-infinite-loop-nessus-id-326538/</guid>
<pubDate>Tue, 14 Jul 2026 10:25:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rabbitmq">RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the component <em>Authentication Handler</em>. The manipulation results in infinite loop.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-57216">CVE-2026-57216</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57220 | RabbitMQ up to 4.2.5 Stream Listener resource consumption (Nessus ID 326536)]]></title>
<description><![CDATA[A vulnerability was found in RabbitMQ up to 4.2.5. It has been classified as problematic. This affects an unknown function of the component Stream Listener. The manipulation leads to resource consumption.

This vulnerability is uniquely identified as CVE-2026-57220. The attack is possible to be c...]]></description>
<link>https://tsecurity.de/de/3667290/sicherheitsluecken/cve-2026-57220-rabbitmq-up-to-425-stream-listener-resource-consumption-nessus-id-326536/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667290/sicherheitsluecken/cve-2026-57220-rabbitmq-up-to-425-stream-listener-resource-consumption-nessus-id-326536/</guid>
<pubDate>Tue, 14 Jul 2026 10:25:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rabbitmq">RabbitMQ up to 4.2.5</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>Stream Listener</em>. The manipulation leads to resource consumption.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-57220">CVE-2026-57220</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ Vulnerability Exposes OAuth Secrets to Attackers]]></title>
<description><![CDATA[A newly disclosed RabbitMQ vulnerability, tracked as CVE-2026-5721, has raised concerns among enterprise users after researchers revealed that the flaw could allow unauthenticated attackers to retrieve a broker's confidential OAuth client secret. The successful exploitation could enable attackers...]]></description>
<link>https://tsecurity.de/de/3666963/it-security-nachrichten/rabbitmq-vulnerability-exposes-oauth-secrets-to-attackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666963/it-security-nachrichten/rabbitmq-vulnerability-exposes-oauth-secrets-to-attackers/</guid>
<pubDate>Tue, 14 Jul 2026 07:52:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1239" height="715" src="https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CVE-2026-5721" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721.webp 1239w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-300x173.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-1024x591.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-768x443.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-600x346.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-150x87.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-750x433.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-1140x658.webp 1140w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721.webp 1239w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-300x173.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-1024x591.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-768x443.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-600x346.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-150x87.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-750x433.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-5721-1140x658.webp 1140w" sizes="(max-width: 1239px) 100vw, 1239px" title="RabbitMQ Vulnerability Exposes OAuth Secrets to Attackers 1"></p><span data-contrast="auto">A newly disclosed RabbitMQ vulnerability, tracked as CVE-2026-5721, has raised concerns among enterprise users after researchers revealed that the flaw could allow unauthenticated attackers to retrieve a broker's confidential OAuth client secret. The successful exploitation could enable attackers to impersonate the broker, obtain administrator-level access, and potentially take control of the messaging infrastructure.</span><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":240,"335559739":240,"335559740":279}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">CVE-2026-5721 Allows Exposure of OAuth Client Secrets</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">RabbitMQ, a widely used open source message broker that enables asynchronous communication by routing, buffering, and distributing messages between applications, is affected by the issue. The CVE-2026-5721 flaw carries a CVSS severity score of 8.7 and stems from an exposed management endpoint that returns the OAuth client secret without requiring authentication.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The RabbitMQ <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28951">vulnerability</a> originates from an obsolete endpoint in the platform's management web interface. It can be exploited when <a href="https://thecyberexpress.com/blackbasta-ransomware-attack-us-organisations/" target="_blank" rel="noopener">administrators</a> configure the broker with a confidential password for identity provider authentication. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risk" data-wpil-keyword-link="linked" data-wpil-monitor-id="28952">risk</a> is particularly significant in deployments using OAuth 2.0 or OpenID Connect identity providers such as Auth0, Azure AD/Entra ID, Keycloak, or UAA, where confidential client secrets are commonly configured. In such environments, attackers exploiting CVE-2026-5721 could obtain administrator tokens and gain control over users, queues, messages, and broker configurations.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Which RabbitMQ Deployments Are at Risk?</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">However, systems without a configured client secret are not vulnerable because there is no credential to expose. Likewise, RabbitMQ deployments that do not use the management plugin are unaffected by this RabbitMQ vulnerability.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Cybersecurity firm Miggo <a href="https://www.miggo.io/post/full-broker-takeover-no-login-required-miggo-discovers-critical-rabbitmq-vulnerabilities-putting-application-data-at-risk" target="_blank" rel="nofollow noopener">warned</a> that the highest risk exists when the management interface is accessible from untrusted networks. The risk is sharpest wherever the management port is reachable by an untrusted network: cloud or multi-tenant setups, or a management UI accidentally exposed to the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28953">internet</a>," the company said.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The CVE-2026-5721 flaw was introduced in RabbitMQ version 3.13.0 in early 2024. It has since been patched in versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Patches Also Address a Second Security Flaw</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The security updates also fix CVE-2026-57221, a medium-severity vulnerability with a <a href="https://thecyberexpress.com/vulnerability-in-moveit-transfer-exploited/" target="_blank" rel="noopener">CVSS</a> score of 5.3. This authorization issue allows any authenticated user to enumerate queues and exchanges while viewing related statistics. According to Miggo, attackers could use the flaw to map an organization's virtual host, infer business activity, and collect intelligence for future attacks, particularly in multi-tenant environments where multiple teams or applications share the same virtual host.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">To reduce exposure to the RabbitMQ vulnerability, organizations are advised to update affected deployments immediately, restrict access to vulnerable systems if patching cannot be performed, prevent public exposure of the management interface, implement network segmentation, and rotate OAuth client secrets. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Although there is currently no evidence that CVE-2026-5721 has been <a href="https://thecyberexpress.com/critical-mongobleed-flaw-exploited-in-the-wild/" target="_blank" rel="noopener">exploited in the wild</a>, Miggo noted, "Neither of these RabbitMQ bugs is exotic. They sat in the codebase for over two years. They are precisely the kind of quiet, systemic inconsistency that hides in mature, widely deployed software: the kind a human reviewer reads past, and a single-pass tool fails to compare against everything around it."</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57215 | RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5 Direct Reply-To Queue denial of service (Nessus ID 326543)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5. Impacted is an unknown function of the component Direct Reply-To Queue Handler. Such manipulation leads to denial of service.

This vulnerability is traded as CVE-2026-57215. The attack ...]]></description>
<link>https://tsecurity.de/de/3666744/sicherheitsluecken/cve-2026-57215-rabbitmq-up-to-3131440194110425-direct-reply-to-queue-denial-of-service-nessus-id-326543/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666744/sicherheitsluecken/cve-2026-57215-rabbitmq-up-to-3131440194110425-direct-reply-to-queue-denial-of-service-nessus-id-326543/</guid>
<pubDate>Tue, 14 Jul 2026 04:54:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/rabbitmq">RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5</a>. Impacted is an unknown function of the component <em>Direct Reply-To Queue Handler</em>. Such manipulation leads to denial of service.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-57215">CVE-2026-57215</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57213 | RabbitMQ up to 3.13.13/4.0.18/4.1.9/4.2.4 Federation Management Plugin consumer_tag cross site scripting (Nessus ID 326545)]]></title>
<description><![CDATA[A vulnerability was found in RabbitMQ up to 3.13.13/4.0.18/4.1.9/4.2.4 and classified as problematic. The impacted element is an unknown function of the component Federation Management Plugin. Executing a manipulation of the argument consumer_tag can lead to cross site scripting.

This vulnerabil...]]></description>
<link>https://tsecurity.de/de/3666743/sicherheitsluecken/cve-2026-57213-rabbitmq-up-to-313134018419424-federation-management-plugin-consumertag-cross-site-scripting-nessus-id-326545/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666743/sicherheitsluecken/cve-2026-57213-rabbitmq-up-to-313134018419424-federation-management-plugin-consumertag-cross-site-scripting-nessus-id-326545/</guid>
<pubDate>Tue, 14 Jul 2026 04:54:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rabbitmq">RabbitMQ up to 3.13.13/4.0.18/4.1.9/4.2.4</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function of the component <em>Federation Management Plugin</em>. Executing a manipulation of the argument <em>consumer_tag</em> can lead to cross site scripting.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-57213">CVE-2026-57213</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57221 | RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5 AMQP 0-9-1 Declaration improper authorization (Nessus ID 326546)]]></title>
<description><![CDATA[A vulnerability was found in RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5. It has been rated as problematic. Affected is an unknown function of the component AMQP 0-9-1 Declaration. This manipulation causes improper authorization.

The identification of this vulnerability is CVE-2026-57221. It is p...]]></description>
<link>https://tsecurity.de/de/3666742/sicherheitsluecken/cve-2026-57221-rabbitmq-up-to-3131440194110425-amqp-0-9-1-declaration-improper-authorization-nessus-id-326546/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666742/sicherheitsluecken/cve-2026-57221-rabbitmq-up-to-3131440194110425-amqp-0-9-1-declaration-improper-authorization-nessus-id-326546/</guid>
<pubDate>Tue, 14 Jul 2026 04:54:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rabbitmq">RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function of the component <em>AMQP 0-9-1 Declaration</em>. This manipulation causes improper authorization.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-57221">CVE-2026-57221</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57219 | RabbitMQ Server up to 3.13.14/4.0.19/4.1.10/4.2.5 Auth Endpoint /api/auth information disclosure (Nessus ID 326544)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in RabbitMQ Server up to 3.13.14/4.0.19/4.1.10/4.2.5. This vulnerability affects unknown code of the file /api/auth of the component Auth Endpoint. The manipulation leads to information disclosure.

This vulnerability is listed as CVE-2026-5...]]></description>
<link>https://tsecurity.de/de/3666741/sicherheitsluecken/cve-2026-57219-rabbitmq-server-up-to-3131440194110425-auth-endpoint-apiauth-information-disclosure-nessus-id-326544/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666741/sicherheitsluecken/cve-2026-57219-rabbitmq-server-up-to-3131440194110425-auth-endpoint-apiauth-information-disclosure-nessus-id-326544/</guid>
<pubDate>Tue, 14 Jul 2026 04:54:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/rabbitmq:server">RabbitMQ Server up to 3.13.14/4.0.19/4.1.10/4.2.5</a>. This vulnerability affects unknown code of the file <em>/api/auth</em> of the component <em>Auth Endpoint</em>. The manipulation leads to information disclosure.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-57219">CVE-2026-57219</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57214 | RabbitMQ up to 4.2.4 Management UI x-internal-purpose permission (Nessus ID 326539)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in RabbitMQ up to 4.2.4. This issue affects some unknown processing of the component Management UI. This manipulation of the argument x-internal-purpose causes permission issues.

This vulnerability appears as CVE-2026-57214. Th...]]></description>
<link>https://tsecurity.de/de/3666739/sicherheitsluecken/cve-2026-57214-rabbitmq-up-to-424-management-ui-x-internal-purpose-permission-nessus-id-326539/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666739/sicherheitsluecken/cve-2026-57214-rabbitmq-up-to-424-management-ui-x-internal-purpose-permission-nessus-id-326539/</guid>
<pubDate>Tue, 14 Jul 2026 04:54:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/rabbitmq">RabbitMQ up to 4.2.4</a>. This issue affects some unknown processing of the component <em>Management UI</em>. This manipulation of the argument <em>x-internal-purpose</em> causes permission issues.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-57214">CVE-2026-57214</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57218 | rabbitmq Server up to 4.2.5 Consumer Lifecycle Manager improper authorization (Nessus ID 326540)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in rabbitmq Server up to 4.2.5. Affected by this issue is some unknown functionality of the component Consumer Lifecycle Manager. Performing a manipulation results in improper authorization.

This vulnerability is identified as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3666738/sicherheitsluecken/cve-2026-57218-rabbitmq-server-up-to-425-consumer-lifecycle-manager-improper-authorization-nessus-id-326540/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666738/sicherheitsluecken/cve-2026-57218-rabbitmq-server-up-to-425-consumer-lifecycle-manager-improper-authorization-nessus-id-326540/</guid>
<pubDate>Tue, 14 Jul 2026 04:54:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/rabbitmq:server">rabbitmq Server up to 4.2.5</a>. Affected by this issue is some unknown functionality of the component <em>Consumer Lifecycle Manager</em>. Performing a manipulation results in improper authorization.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-57218">CVE-2026-57218</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical RabbitMQ Flaw Lets Unauthenticated Attackers Take Over Message Brokers]]></title>
<description><![CDATA[Two critical access-control vulnerabilities have been uncovered in RabbitMQ, the world’s most widely deployed open-source message broker. Liad Eliyahu at Miggo found that one flaw allows unauthenticated attackers to steal a broker’s OAuth secret and seize full administrative control, while the ot...]]></description>
<link>https://tsecurity.de/de/3665419/it-security-nachrichten/critical-rabbitmq-flaw-lets-unauthenticated-attackers-take-over-message-brokers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665419/it-security-nachrichten/critical-rabbitmq-flaw-lets-unauthenticated-attackers-take-over-message-brokers/</guid>
<pubDate>Mon, 13 Jul 2026 15:38:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two critical access-control vulnerabilities have been uncovered in RabbitMQ, the world’s most widely deployed open-source message broker. Liad Eliyahu at Miggo found that one flaw allows unauthenticated attackers to steal a broker’s OAuth secret and seize full administrative control, while the other lets any logged-in user silently spy on other tenants’ data. Both have been […]</p>
<p>The post <a href="https://cyberpress.org/critical-rabbitmq-flaw/">Critical RabbitMQ Flaw Lets Unauthenticated Attackers Take Over Message Brokers</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Can Exploit RabbitMQ OAuth Flaw to Access Every Message, Queue, and User]]></title>
<description><![CDATA[Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the open-source message broker used in an estimated 8% of all containers running today, that could allow attackers to seize full administrative control of a broker or silently map out sensitive…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3665407/it-security-nachrichten/hackers-can-exploit-rabbitmq-oauth-flaw-to-access-every-message-queue-and-user/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665407/it-security-nachrichten/hackers-can-exploit-rabbitmq-oauth-flaw-to-access-every-message-queue-and-user/</guid>
<pubDate>Mon, 13 Jul 2026 15:38:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the open-source message broker used in an estimated 8% of all containers running today, that could allow attackers to seize full administrative control of a broker or silently map out sensitive…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-can-exploit-rabbitmq-oauth-flaw-to-access-every-message-queue-and-user/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-can-exploit-rabbitmq-oauth-flaw-to-access-every-message-queue-and-user/">Hackers Can Exploit RabbitMQ OAuth Flaw to Access Every Message, Queue, and User</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Can Exploit RabbitMQ OAuth Flaw to Access Every Message, Queue, and User]]></title>
<description><![CDATA[Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the open-source message broker used in an estimated 8% of all containers running today, that could allow attackers to seize full administrative control of a broker or silently map out sensitive queue data across s...]]></description>
<link>https://tsecurity.de/de/3665384/it-security-nachrichten/hackers-can-exploit-rabbitmq-oauth-flaw-to-access-every-message-queue-and-user/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665384/it-security-nachrichten/hackers-can-exploit-rabbitmq-oauth-flaw-to-access-every-message-queue-and-user/</guid>
<pubDate>Mon, 13 Jul 2026 15:24:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the open-source message broker used in an estimated 8% of all containers running today, that could allow attackers to seize full administrative control of a broker or silently map out sensitive queue data across shared tenants. Both flaws were discovered by Miggo Security’s autonomous research system, […]</p>
<p>The post <a href="https://gbhackers.com/rabbitmq-oauth-vulnerability/">Hackers Can Exploit RabbitMQ OAuth Flaw to Access Every Message, Queue, and User</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft warnt: Diese Windows-Malware kann Daten löschen und Rechner zerstören]]></title>
<description><![CDATA[Microsoft hat eine neue Schadsoftware analysiert, die nicht nur Daten ausspionieren, sondern komplette Systeme unbrauchbar machen kann. Die als GigaWiper bezeichnete Malware kombiniert mehrere zerstörerische Funktionen mit einer leistungsfähigen Hintertür für Angreifer.



Die Sicherheitsforscher...]]></description>
<link>https://tsecurity.de/de/3665371/it-nachrichten/microsoft-warnt-diese-windows-malware-kann-daten-loeschen-und-rechner-zerstoeren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665371/it-nachrichten/microsoft-warnt-diese-windows-malware-kann-daten-loeschen-und-rechner-zerstoeren/</guid>
<pubDate>Mon, 13 Jul 2026 15:18:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><strong>Microsoft</strong> hat eine neue <strong>Schadsoftware</strong> analysiert, die nicht nur Daten ausspionieren, sondern komplette Systeme unbrauchbar machen kann. Die als GigaWiper bezeichnete <strong>Malware</strong> kombiniert mehrere zerstörerische Funktionen mit einer leistungsfähigen Hintertür für Angreifer.</p>



<p>Die Sicherheitsforscher von Microsoft Threat Intelligence entdeckten die Aktivitäten bereits im Oktober 2025. Damals wurden in kompromittierten Umgebungen erste Fälle beobachtet, bei denen Systeme mit zerstörerischen Werkzeugen angegriffen wurden. Die <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noreferrer noopener">nun veröffentlichte Analyse</a> zeigt das volle Ausmaß der Schadsoftware.</p>



<p>GigaWiper ist demnach keine klassische Lösch-Malware mit nur einer Aufgabe. Stattdessen vereint das Programm mehrere Schadfunktionen in einer einzigen Plattform. Andere Sicherheitsforscher verfolgen die Malware auch unter dem Namen BLUERABBIT.</p>



<h2 class="wp-block-heading">Malware kann Festplatten löschen und Daten unwiederbringlich zerstören</h2>



<p>Besonders gefährlich ist die Fähigkeit von GigaWiper, Festplatten auf niedriger Ebene zu überschreiben. Anders als gewöhnliche Schadprogramme löscht die Malware nicht einfach einzelne Dateien, sondern greift direkt auf die physischen Laufwerke zu.</p>



<p>Dabei kann GigaWiper unter anderem Partitionseinträge entfernen und Inhalte von Datenträgern überschreiben. Nach Abschluss der Aktion startet der Rechner neu – die darauf gespeicherten Daten sind anschließend nicht mehr normal verfügbar.</p>



<p>Eine weitere Funktion tarnt sich als Ransomware. Dabei verschlüsselt GigaWiper Dateien und versieht sie mit der Endung „.candy“. Allerdings handelt es sich nicht um eine klassische Erpressung: Die verwendeten Schlüssel werden zufällig erzeugt und nicht gespeichert. Eine spätere Entschlüsselung ist deshalb technisch nicht möglich.</p>



<p>Eine weitere Zerstörungsfunktion überschreibt das Windows-Systemlaufwerk mehrfach mit verschiedenen Datenmustern. Dadurch wird eine Wiederherstellung zusätzlich erschwert.</p>



<h2 class="wp-block-heading">GigaWiper ist mehr als ein Datenlöscher</h2>



<p>Die Schadsoftware beschränkt sich jedoch nicht auf die Zerstörung von Daten. Microsoft beschreibt GigaWiper als Backdoor, über die Angreifer dauerhaft Zugriff auf infizierte Systeme erhalten können.</p>



<p>Die Malware kann unter anderem:</p>



<ul class="wp-block-list">
<li>Bildschirmaufnahmen erstellen,</li>



<li>den Bildschirm aufzeichnen,</li>



<li>Fernsteuerungsfunktionen ermöglichen,</li>



<li>Systeminformationen sammeln,</li>



<li>Prozesse und Windows-Dienste verwalten,</li>



<li>die Windows-Registrierung verändern,</li>



<li>Ereignisprotokolle löschen, um Spuren zu verwischen.</li>
</ul>



<p>Damit können Angreifer zunächst Informationen über ein System sammeln oder die Kontrolle übernehmen, bevor sie zerstörerische Funktionen auslösen.</p>



<h2 class="wp-block-heading">Tarnung als OneDrive-Aufgabe</h2>



<p>Für eine möglichst lange Präsenz auf betroffenen Rechnern richtet GigaWiper laut Microsoft eine geplante Aufgabe im Windows-Aufgabenplaner ein. Diese trägt den Namen „OneDrive Update“ und wird regelmäßig ausgeführt.</p>



<p>Die Schadsoftware nutzt außerdem RabbitMQ und Redis für die Kommunikation mit Steuerungsservern. Dadurch können sich die Verbindungen in Unternehmensnetzwerken schwerer erkennen lassen, wenn diese Dienste dort bereits verwendet werden.</p>



<h2 class="wp-block-heading">Schadcode aus mehreren Malware-Familien zusammengeführt</h2>



<p>Eine Besonderheit von GigaWiper ist der Aufbau der Schadsoftware. Microsoft stellte fest, dass mehrere ältere Malware-Komponenten in das neue Programm integriert wurden.</p>



<p>Ein Teil der Funktionen stammt demnach aus Crucio, einer früher analysierten Ransomware. Eine weitere Komponente basiert auf FlockWiper, einer älteren Wiper-Schadsoftware. Die Angreifer haben diese Funktionen in eine neue, in der Programmiersprache Go entwickelte Backdoor integriert.</p>



<p>Dadurch können Angreifer je nach Ziel entscheiden, ob sie Systeme kontrollieren, Daten manipulieren oder eine vollständige Zerstörung auslösen.</p>



<h2 class="wp-block-heading">Was Windows-Nutzer jetzt wissen sollten</h2>



<p>GigaWiper richtet sich nach den bisherigen Erkenntnissen vor allem gegen gezielte Angriffe auf Organisationen und Unternehmen. Hinweise auf eine breite Verbreitung unter privaten Windows-Nutzern gibt es derzeit nicht.</p>



<p>Die Schadsoftware muss zunächst auf ein System gelangen und wird anschließend von Angreifern gesteuert. Für Privatanwender bleiben deshalb die klassischen Schutzmaßnahmen entscheidend: Windows und Sicherheitssoftware – <a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">die besten Antivirus-Tools haben wir hier getestet</a> – sollten aktuell gehalten werden, unbekannte Anhänge und Programme sollten vermieden werden.</p>



<p>Unternehmen sollten laut Microsoft unter anderem Schutzfunktionen wie Manipulationsschutz für Sicherheitssoftware aktivieren, moderne Angriffserkennung einsetzen und verdächtige Aktivitäten überwachen. Dazu gehören etwa ungewöhnliche Aufgaben im Windows-Aufgabenplaner oder unerwartete Netzwerkverbindungen.</p>



<p>Besonders wichtig sind regelmäßige Backups. Diese sollten möglichst getrennt vom Rechner gespeichert werden, denn gegen einen echten Wiper-Angriff hilft im Ernstfall nur eine unabhängige Datensicherung.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=4-0-3178649-1-0-0-0-0?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/2043389/windows-defender-einrichten-nutzen.html" target="_blank" rel="noreferrer noopener">Windows Defender optimal einrichten und nutzen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ Vulnerability Threatens Enterprise Systems]]></title>
<description><![CDATA[Unauthenticated attackers could obtain the broker's confidential OAuth client secret, allowing them to take control of the broker.
The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3665181/it-security-nachrichten/rabbitmq-vulnerability-threatens-enterprise-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665181/it-security-nachrichten/rabbitmq-vulnerability-threatens-enterprise-systems/</guid>
<pubDate>Mon, 13 Jul 2026 14:07:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Unauthenticated attackers could obtain the broker's confidential OAuth client secret, allowing them to take control of the broker.</p>
<p>The post <a href="https://www.securityweek.com/rabbitmq-vulnerability-threatens-enterprise-systems/">RabbitMQ Vulnerability Threatens Enterprise Systems</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ flaws expose OAuth secrets, risk complete takeover of the broker]]></title>
<description><![CDATA[RabbitMQ has patched two access control vulnerabilities affecting the widely used open-source message broker that could expose enterprise application data and, in some deployments, allow attackers to gain complete control over the messaging infrastructure.



The flaws, discovered by Miggo Securi...]]></description>
<link>https://tsecurity.de/de/3665180/it-security-nachrichten/rabbitmq-flaws-expose-oauth-secrets-risk-complete-takeover-of-the-broker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665180/it-security-nachrichten/rabbitmq-flaws-expose-oauth-secrets-risk-complete-takeover-of-the-broker/</guid>
<pubDate>Mon, 13 Jul 2026 14:07:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>RabbitMQ has patched two access control vulnerabilities affecting the widely used open-source message broker that could expose enterprise application data and, in some deployments, allow attackers to gain complete control over the messaging infrastructure.</p>



<p>The flaws, discovered by Miggo Security, exposed OAuth secrets to unauthenticated attackers, letting low-privileged users potentially spy on other tenants.</p>



<p>“RabbitMQ is the plumbing that moves data between services inside modern applications: orders, payments, authentication events, internal notifications,” Miggo researchers explained in a report shared with CSO ahead of its publication on Monday. “RabbitMQ is downloaded more than 15 million times a year, and the scale makes it a high-value target.”</p>



<p>Affecting <a href="https://www.csoonline.com/article/4195470/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand.html#:~:text=while%20command-and-control%20(C2)%20relies%20on%20RabbitMQ">RabbitMQ</a> releases dating back to version 3.13.0, introduced in early 2024, the flaws have now been fixed in all supported versions.</p>



<h2 class="wp-block-heading">Obsolete endpoint leaked OAuth configurations</h2>



<p>The more severe issue, tracked as CVE-2026-57219, allows anyone with network access to RabbitMQ’s management interface to receive the broker’s OAuth client secret without authentication.</p>



<p>The flaw <a href="https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj24-8j6m-vq9q" target="_blank" rel="noreferrer noopener">stems</a> from an obsolete management endpoint “GET/api/auth” that returned RabbitMQ’s OAuth configuration, which includes the broker’s confidential OAuth client secret, to anyone who queried it. In deployments using confidential OAuth clients with providers such as Microsoft Entra ID, Auth0, Keycloak, or UAA, attackers could exchange the leaked secret for an administrator token and gain complete control over the broker.</p>



<p>The problem was assigned a high severity score of CVSS 8.7 out of 10, and was fixed in the versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.</p>



<p>RabbitMQ reportedly addressed the issue by removing the obsolete endpoint altogether, instead delivering OAuth configuration through an authenticated bootstrap mechanism that no longer exposes the client secret over HTTP.</p>



<p>According to Miggo, successful exploitation could allow attackers to access or modify messages, create users, alter broker configuration, and effectively compromise the messaging layer supporting enterprise applications. The company recommended organizations to upgrade immediately, rotate any exposed OAuth client secrets after patching, and ensure the management interface is never exposed to untrusted networks.</p>



<p>Broadcom, whose Tanzu division maintains RabbitMQ, did not immediately respond to CSO’s request for comment.</p>



<h2 class="wp-block-heading">Authorization bypass for reconnaissance</h2>



<p>The second vulnerability, CVE-2026-57221, is an authorization bypass affecting RabbitMQ’s passive queue and exchange declaration operations.</p>



<p>Although attackers <a href="https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-9q2j-2hq8-22r2" target="_blank" rel="noreferrer noopener">need valid credentials</a> for exploitation, even accounts with no assigned permissions can discover whether queues and exchanges exist and retrieve metadata such as message counts and active consumers because the permission check is skipped.</p>



<p>Miggo noted the flaw does not expose message contents or allow tampering, but it can leak valuable operational intelligence in shared environments. Attackers could map applications, monitor workload activity, and gather reconnaissance for subsequent attacks against other tenants sharing the same virtual host, the researchers added.</p>



<p>RabbitMQ fixed the issue by ensuring passive queue and exchange declarations now enforce the same authorization checks as other operations. Because there is no configuration workaround or <a href="https://www.csoonline.com/article/1311264/cloudflare-adds-new-waf-features-to-prevent-hackers-from-exploiting-llms.html">WAF </a>mitigation for this flaw, organizations were advised to upgrade to a patched release and isolate tenants into separate virtual hosts until patching can be completed.</p>



<p>Miggo said the vulnerabilities are the first CVEs discovered by its autonomous security research platform, VulnHunter, before being validated by its security team and disclosed to RabbitMQ maintainers, who reportedly confirmed the issues and released patches.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ Vulnerability Threatens Enterprise Systems]]></title>
<description><![CDATA[Unauthenticated attackers could obtain the broker’s confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article...]]></description>
<link>https://tsecurity.de/de/3665176/it-security-nachrichten/rabbitmq-vulnerability-threatens-enterprise-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665176/it-security-nachrichten/rabbitmq-vulnerability-threatens-enterprise-systems/</guid>
<pubDate>Mon, 13 Jul 2026 14:07:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Unauthenticated attackers could obtain the broker’s confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article:…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/rabbitmq-vulnerability-threatens-enterprise-systems/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/rabbitmq-vulnerability-threatens-enterprise-systems/">RabbitMQ Vulnerability Threatens Enterprise Systems</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57211 | RabbitMQ up to 4.1.10/4.2.5 Static File rabbit_mgmt_wm_static information disclosure]]></title>
<description><![CDATA[A vulnerability has been found in RabbitMQ up to 4.1.10/4.2.5 and classified as problematic. The affected element is the function rabbit_mgmt_wm_static of the component Static File Handler. Performing a manipulation results in information disclosure.

This vulnerability is known as CVE-2026-57211...]]></description>
<link>https://tsecurity.de/de/3660932/sicherheitsluecken/cve-2026-57211-rabbitmq-up-to-4110425-static-file-rabbitmgmtwmstatic-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660932/sicherheitsluecken/cve-2026-57211-rabbitmq-up-to-4110425-static-file-rabbitmgmtwmstatic-information-disclosure/</guid>
<pubDate>Sat, 11 Jul 2026 00:23:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/rabbitmq">RabbitMQ up to 4.1.10/4.2.5</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is the function <code>rabbit_mgmt_wm_static</code> of the component <em>Static File Handler</em>. Performing a manipulation results in information disclosure.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-57211">CVE-2026-57211</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand]]></title>
<description><![CDATA[Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers.



In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote a...]]></description>
<link>https://tsecurity.de/de/3659201/it-security-nachrichten/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659201/it-security-nachrichten/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand/</guid>
<pubDate>Fri, 10 Jul 2026 11:07:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers.</p>



<p>In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote administration capabilities with multiple disk-wiping and ransomware routines.</p>



<p>Rather than building a new destructive tool from scratch, the operators assembled GigaWiper from several existing malware families, embedding them as modular commands inside a single backdoor.</p>



<p>“GigaWiper is particularly notable for its makeup,” Microsoft researchers <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noreferrer noopener">said</a>. “The consolidation of multiple destructive capabilities into a modular backdoor reflects a notable shift in wiper malware, which are typically designed purely to destroy rather than to extort and carry real-world consequences.”</p>



<p>Malware capabilities of the backdoor included multiple disk wiping logics, an irreversible Crucio ransomware encryption, persistence, and RabbitMQ and Redis-based communication.</p>



<h2 class="wp-block-heading"><a></a>A backdoor for destruction on demand</h2>



<p>According to Microsoft, GigaWiper exists in two forms. A standalone wiper and a larger backdoor whose command set embeds the standalone wiping functionality alongside numerous administrative features.</p>



<p>Written in Go, the malware supports 20 command codes that enable operators to execute <a href="https://www.csoonline.com/article/4006326/how-to-log-and-monitor-powershell-activity-for-suspicious-scripts-and-commands.html">PowerShell </a>commands, manage Windows services and processes, manipulate the registry, capture screenshots, record displays, clear event logs, and remotely control infected systems through a Virtual Network Computing (<a href="https://www.csoonline.com/article/573427/exposed-vnc-threatens-critical-infrastructure-as-attacks-spike.html">VNC</a>)-like capability.</p>



<p>Persistence is established through a scheduled task posing as a “OneDrive Update,” while command-and-control (C2) relies on <a href="https://www.csoonline.com/article/572033/fbis-warning-about-iranian-firm-highlights-common-cyberattack-tactics.html?utm=hybrid_search#:~:text=RabbitMQ%20service%20on%20SolarWinds">RabbitMQ</a> for receiving instructions and <a href="https://www.csoonline.com/article/1308535/new-redis-attack-campaign-weakens-systems-before-deploying-cryptominer.html">Redis </a>for returning command output. This architecture allows attackers to quietly maintain access and selectively activate destructive functionality when an objective has been achieved, the researchers added.</p>



<h2 class="wp-block-heading"><a></a>The backdoor combines three malware families</h2>



<p>Microsoft researchers found that GigaWiper integrates destructive code from multiple malware families instead of relying on a single wiping mechanism.</p>



<p>These integrations show up in the form of separate commands that the backdoor supports.<br><br>One command performs raw physical disk wiping by overwriting drives and removing partition metadata. Another borrows from the Crucio ransomware family, encrypting files with randomly generated keys that are intentionally never stored, making recovery impossible despite presenting itself like ransomware.</p>



<p>A third command recreates the functionality of FlockWiper, implementing secure multi-pass wiping in Go to permanently erase data on Windows systems.</p>



<p>“We tied GigaWiper to both Crucio and FlockWiper based on code analysis, shared execution flow, function naming, and unique strings,” the researchers said. “Crucio’s code was the base for GigaWiper command 3, and FlockWiper was re-coded in Golang and updated for GigaWiper command 12,” they noted, referring to the 20 listed commands the backdoor supports.</p>



<p>The standalone wiper was implemented as command 1 from the list.</p>



<p>Microsoft recommended hardening endpoints and identities, enabling behavioral detection and endpoint detection and response (EDR) capabilities, and using attack surface reduction controls to limit compromise risks. </p>



<p>The company also urged defenders to maintain offline or otherwise resilient backups, as destructive malware like GigaWiper is designed to irreversibly wipe or encrypt data. To support detection, the researchers shared a list of indicators of compromise (IOCs), which included FlockWiper and Crucio file hashes and a couple of C2 IP addresses.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] RabbitMQ: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen D...]]></description>
<link>https://tsecurity.de/de/3659105/it-security-nachrichten/neu-hoch-rabbitmq-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659105/it-security-nachrichten/neu-hoch-rabbitmq-mehrere-schwachstellen/</guid>
<pubDate>Fri, 10 Jul 2026 10:37:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [niedrig] RabbitMQ: Schwachstelle ermöglicht Offenlegung von Informationen]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um Informationen offenzulegen.]]></description>
<link>https://tsecurity.de/de/3656652/it-security-nachrichten/neu-niedrig-rabbitmq-schwachstelle-ermoeglicht-offenlegung-von-informationen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656652/it-security-nachrichten/neu-niedrig-rabbitmq-schwachstelle-ermoeglicht-offenlegung-von-informationen/</guid>
<pubDate>Thu, 09 Jul 2026 12:23:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um Informationen offenzulegen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [mittel] RabbitMQ: Schwachstelle ermöglicht Offenlegung von Informationen]]></title>
<description><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um Informationen offenzulegen.]]></description>
<link>https://tsecurity.de/de/3637850/it-security-nachrichten/update-mittel-rabbitmq-schwachstelle-ermoeglicht-offenlegung-von-informationen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637850/it-security-nachrichten/update-mittel-rabbitmq-schwachstelle-ermoeglicht-offenlegung-von-informationen/</guid>
<pubDate>Wed, 01 Jul 2026 10:38:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um Informationen offenzulegen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [mittel] RabbitMQ: Schwachstelle ermöglicht Denial of Service]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um einen Denial of Service Angriff durchzuführen.]]></description>
<link>https://tsecurity.de/de/3637847/it-security-nachrichten/update-mittel-rabbitmq-schwachstelle-ermoeglicht-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637847/it-security-nachrichten/update-mittel-rabbitmq-schwachstelle-ermoeglicht-denial-of-service/</guid>
<pubDate>Wed, 01 Jul 2026 10:38:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um einen Denial of Service Angriff durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] RabbitMQ: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht.]]></description>
<link>https://tsecurity.de/de/3624380/it-security-nachrichten/neu-hoch-rabbitmq-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624380/it-security-nachrichten/neu-hoch-rabbitmq-mehrere-schwachstellen/</guid>
<pubDate>Thu, 25 Jun 2026 13:54:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] RabbitMQ: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um Daten zu manipulieren, um Informationen offenzulegen, und um einen Denial of Service Angriff durchzuführen.]]></description>
<link>https://tsecurity.de/de/3607370/it-security-nachrichten/neu-mittel-rabbitmq-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607370/it-security-nachrichten/neu-mittel-rabbitmq-mehrere-schwachstellen/</guid>
<pubDate>Thu, 18 Jun 2026 12:28:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um Daten zu manipulieren, um Informationen offenzulegen, und um einen Denial of Service Angriff durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [mittel] RabbitMQ: Schwachstelle ermöglicht Offenlegung von Informationen]]></title>
<description><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um Informationen offenzulegen.]]></description>
<link>https://tsecurity.de/de/3604102/it-security-nachrichten/update-mittel-rabbitmq-schwachstelle-ermoeglicht-offenlegung-von-informationen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604102/it-security-nachrichten/update-mittel-rabbitmq-schwachstelle-ermoeglicht-offenlegung-von-informationen/</guid>
<pubDate>Wed, 17 Jun 2026 10:53:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um Informationen offenzulegen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in rabbitmq-c (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3603051/it-security-nachrichten/mehrere-probleme-in-rabbitmq-c-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603051/it-security-nachrichten/mehrere-probleme-in-rabbitmq-c-ubuntu/</guid>
<pubDate>Tue, 16 Jun 2026 22:08:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[USN-8437-1: rabbitmq-c vulnerabilities]]></title>
<description><![CDATA[It was discovered that rabbitmq-c exposed credentials in command-line
arguments under certain circumstances. A local attacker could possibly use
this issue to obtain sensitive information. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2023-35789)

It was discovered that rab...]]></description>
<link>https://tsecurity.de/de/3602539/unix-server/usn-8437-1-rabbitmq-c-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602539/unix-server/usn-8437-1-rabbitmq-c-vulnerabilities/</guid>
<pubDate>Tue, 16 Jun 2026 18:31:14 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that rabbitmq-c exposed credentials in command-line
arguments under certain circumstances. A local attacker could possibly use
this issue to obtain sensitive information. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2023-35789)

It was discovered that rabbitmq-c incorrectly handled AMQP frame lengths
under certain circumstances, which could lead to an out-of-bounds read. A
remote attacker could possibly use this issue to cause rabbitmq-c to crash,
resulting in a denial of service. (CVE-2026-44235)

It was discovered that rabbitmq-c incorrectly handled AMQP login handshakes
under certain circumstances, which could lead to a heap buffer overflow. A
remote attacker could possibly use this issue to cause rabbitmq-c to crash,
resulting in a denial of service, or execute arbitrary code.
(CVE-2026-44236)]]></content:encoded>
</item>
<item>
<title><![CDATA[The Intelligent Shield. OpenCTI]]></title>
<description><![CDATA[Beyond Ingestion Subtitle: Deploying AI-Driven Enrichment in OpenCTITransforming Threat Data into High-Confidence IntelligenceIn an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the c...]]></description>
<link>https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Beyond Ingestion <strong>Subtitle:</strong> Deploying AI-Driven Enrichment in OpenCTI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yZJrYF0KW4x5gzDg6xNN6A.png"></figure><h3>Transforming Threat Data into High-Confidence Intelligence</h3><p>In an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the critical lack of context. “The Intelligent Shield” introduces a new paradigm: beyond simply ingesting data, it’s about deploying advanced, automated machine learning pipelines for <strong>AI-driven enrichment.</strong></p><p>This guide demonstrates how to integrate state-of-the-art Large Language Models (LLMs), such as <strong>Claude AI</strong>, into an <strong>OpenCTI</strong> ecosystem. By leveraging the <strong>OpenCTI STIX 2.1 Knowledge Graph</strong> and natural language processing, this architecture converts disparate, unstructured data feeds into high-fidelity, actionable intelligence. It automatically builds context, executes deep mapping to frameworks like the <strong>MITRE ATT&amp;CK Matrix</strong>, and generates calculated, real-time <strong>Confidence Scores</strong>, enabling organizations to proactively strengthen their defenses with an intuitive, automated <strong>Intelligent Shield.</strong></p><h3>Table of Contents</h3><ol><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#6e45"><strong>What is OpenCTI?</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#8ff6"><strong>Core Capabilities</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7dc1"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7865"><strong>Threat Intelligence Feeds</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fe8e"><strong>AI Integration Layer</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#c6df"><strong>Prerequisites</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7c94"><strong>Docker Compose Deployment</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#b276"><strong>Connector Configuration</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#a2bd"><strong>AI-Driven Enrichment Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#99be"><strong>Post-Deployment Hardening</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fd26"><strong>Operational Runbook</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#aabb"><strong>Troubleshooting</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7e3e"><strong>Usage Examples</strong></a></li></ol><h3>1. What is OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fSYjMAN2q5yyUccU6F6daQ.png"></figure><p><strong>OpenCTI</strong> (Open Cyber Threat Intelligence) is an open-source platform developed by Filigran (formerly a project of ANSSI, the French national cybersecurity agency) for structuring, storing, organizing, visualizing, and sharing cyber threat intelligence (CTI).</p><p>It implements the <strong>STIX 2.1</strong> (Structured Threat Information eXpression) standard as its native data model and exposes a <strong>GraphQL API</strong> for all read/write operations. Every object — threat actors, campaigns, malware, vulnerabilities, indicators, attack patterns — is stored as a STIX Domain Object (SDO) or STIX Relationship Object (SRO) backed by two databases:</p><ul><li><strong>ElasticSearch / OpenSearch</strong> — full-text search and analytics</li><li><strong>Apache Cassandra (via JanusGraph)</strong> — graph relationship storage</li></ul><h3>Why OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1a3jOT66dfRuy3XvkQJ5NQ.png"></figure><h3>2. Core Capabilities</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uj2dA3oWyo03XyrbjkNrGg.png"></figure><h4>2.1 Knowledge Graph</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YvoudJ_c2ItEwEgTZ8TGaQ.png"></figure><ul><li>Entities: Threat Actors, Intrusion Sets, Campaigns, Malware, Tools, Vulnerabilities (CVE), Attack Patterns (MITRE ATT&amp;CK), Courses of Action, Sectors, Countries, Organizations</li><li>Relationships modelled as first-class STIX SROs with confidence scores, date ranges, and TLP markings</li><li>Diamond Model and Kill Chain views built in</li></ul><h4>2.2 Indicator Management</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pGfNRDKffBczwNJeMydW8w.png"></figure><ul><li>IOC lifecycle: valid_from / valid_until with automatic expiry</li><li>Detection rule generation (Sigma, YARA, Snort)</li><li>Bulk import via STIX, CSV, OpenIOC, MISP formats</li><li>Scoring and confidence weighting per source</li></ul><h4>2.3 MITRE ATT&amp;CK Navigator Integration</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_jOEvP3job4uFFPBnXLIkA.png"></figure><ul><li>Full ATT&amp;CK Enterprise / Mobile / ICS matrices</li><li>Heatmaps of technique usage per threat actor or campaign</li><li>Gap analysis against your current detection coverage</li></ul><h4>2.4 Threat Actor Profiling</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*N98FeMPaxF2ZYnhLF8kEGQ.png"></figure><ul><li>Attributed aliases, motivations (financial, espionage, hacktivism)</li><li>Geo and sector targeting mapped on world map</li><li>Timeline of campaigns and malware usage</li></ul><h4>2.5 Automation &amp; Playbooks</h4><ul><li>Built-in playbook engine (since v5.9): trigger enrichment, notifications, or SOAR actions on entity creation/modification(<strong>Enterprise Edition only)</strong></li><li>Python SDK for custom automation</li><li>Webhook support for external integrations</li></ul><h4>2.6 Collaboration &amp; Sharing</h4><ul><li>Role-based access control (RBAC) with groups and organizations</li><li>TLP (Traffic Light Protocol) enforcement at object level</li><li>TAXII 2.1 server — push feeds to SIEMs, firewalls, EDR platforms</li><li>Sharing with partner organizations via federated instances</li></ul><h4>2.7 Dashboard &amp; Reporting</h4><ul><li>Customizable dashboards with widget library</li><li>PDF report generation</li><li>Timeline, matrix, and entity views</li><li>Attack path visualization</li></ul><h3>3. Architecture Overview</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAFxmmcNnaHdD8ZDbXIbDw.png"></figure><h3>4. Threat Intelligence Feeds</h3><h4>4.1 Free / Open-Source Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zamxLo7VEhjGX0cOnZvRJQ.png"></figure><ul><li><a href="https://attack.mitre.org/?utm_source=chatgpt.com"><strong>MITRE ATT&amp;CK</strong></a> — Connector: opencti/connector-mitre — Data: Techniques, mitigations, groups, software — Setup: API key not needed.</li><li><a href="https://nvd.nist.gov/?utm_source=chatgpt.com"><strong>CVE / NVD</strong></a> — Connector: opencti/connector-cve — Data: Vulnerabilities — Setup: <a href="https://nvd.nist.gov/developers/request-an-api-key">NVD API key</a> recommended/required depending on configuration.</li><li><a href="https://otx.alienvault.com/?utm_source=chatgpt.com"><strong>AlienVault OTX</strong></a> — Connector: opencti/connector-alienvault — Data: IOCs, pulses, malware families — Setup: Free OTX account/API key.</li><li><a href="https://bazaar.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch MalwareBazaar</strong></a> — Connector: opencti/connector-malwarebazaar — Data: Malware hashes, malware metadata, file observables — Setup: Free MalwareBazaar API key.</li><li><a href="https://urlhaus.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch URLhaus</strong></a> — Connector: opencti/connector-urlhaus — Data: Malicious URLs — Setup: Public feed; no API key for CSV feed.</li><li><a href="https://feodotracker.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch Feodo Tracker</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> or ingest the Feodo CSV/blocklist feed manually — Data: Botnet C2 IPs — Setup: Free.</li><li><a href="https://internetdb.shodan.io/"><strong>Shodan InternetDB</strong></a> — Connector: opencti/connector-shodan-internetdb — Data: IP enrichment, domains, CPEs, CVEs, tags — Setup: No API key required.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>MISP Default / CIRCL OSINT Feeds</strong></a> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> — Data: STIX/MISP bundles, indicators, observables — Setup: Free.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>CyberCrime-Tracker feed via MISP default feeds</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> rather than a dedicated current connector — Data: C2 panels / freetext indicators — Setup: Free.</li><li><a href="https://openphish.com/?utm_source=chatgpt.com"><strong>OpenPhish</strong></a> — Connector: no verified current dedicated OpenCTI connector in the main repo; use generic feed ingestion where suitable — Data: Phishing URLs — Setup: Free/community feed options.</li><li><strong>DigitalSide IT-ISAC MISP Feed</strong> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> with custom MISP_FEED_URL — Data: IOCs / MISP-format feed — Setup: Free.</li></ul><h4>4.2 Commercial Feeds (require license/API key)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dMgCc4cuy0X9LxEAcR0PiQ.png"></figure><ul><li><a href="https://www.misp-project.org/"><strong>MISP — self-hosted</strong></a> — Connector: opencti/connector-misp — Strengths: community sharing, custom events, internal/private CTI exchange. The OpenCTI repo lists both misp and misp-feed; use misp for a live MISP instance with API access, and misp-feed for static MISP feed URLs.</li><li><a href="https://www.virustotal.com/"><strong>VirusTotal / Google Threat Intelligence</strong></a> — Connector: opencti/connector-virustotal — Strengths: file, URL, domain, and IP enrichment. The connector is under internal-enrichment, not external-import.</li><li><strong>Mandiant Threat Intelligence / Google Threat Intelligence</strong> — Connector: opencti/connector-mandiant — Strengths: APT intelligence, actor reporting, malware/campaign context.</li><li><a href="https://www.recordedfuture.com/"><strong>Recorded Future</strong></a> — Connectors: opencti/connector-recordedfuture and opencti/connector-recordedfuture-enrichment — Strengths: risk lists, enrichment, vulnerability/contextual intelligence, dark web and external threat data. Recorded Future documentation describes the OpenCTI integration as two components: an enrichment connector and a Recorded Future connector.</li><li><a href="https://www.crowdstrike.com/products/threat-intelligence/"><strong>CrowdStrike Falcon Intelligence</strong></a> — Connector: opencti/connector-crowdstrike — Strengths: actor tracking, indicators, adversary intelligence, Falcon ecosystem context.</li><li><a href="https://www.sekoia.io/"><strong>Sekoia.io Intelligence</strong></a> — Connector: opencti/connector-sekoia — Strengths: European threat landscape, CTI feed ingestion, actor/campaign context. Sekoia’s own documentation points to the OpenCTI GitHub connector path.</li><li><a href="https://threatconnect.com/"><strong>ThreatConnect</strong></a> — Connector: <strong>no verified current dedicated connector in the main OpenCTI connector tree</strong> — Strengths: enterprise TI management, source aggregation, workflow and case management. I found an OpenCTI GitHub label/feature reference for “threat connect,” but not a confirmed current connector folder equivalent to external-import/threatconnect.</li><li><a href="https://intel471.com/"><strong>Intel 471</strong></a> — Connectors: opencti/connector-intel471, opencti/connector-intel471-darknet, and opencti/connector-intel471_v2 — Strengths: underground forums, cybercrime actors, malware, infrastructure, dark web intelligence.</li></ul><h4>4.3 ISAC / Government Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dtrgjORW-h5AoEi0rOMBHw.png"></figure><ul><li><a href="https://www.cisa.gov/resources-tools/services/automated-indicator-sharing-ais-service?utm_source=chatgpt.com"><strong>CISA Automated Indicator Sharing / AIS</strong></a> — Method: TAXII/STIX client, AIS 2.0 uses TAXII 2.1 — Access: free service for eligible participants; contact CISA to onboard.</li><li><a href="https://www.fsisac.com/?utm_source=chatgpt.com"><strong>FS-ISAC</strong></a> — Method: STIX/TAXII and MISP automated feeds — Access: financial-sector membership; automated-feed credentials/licensing must be explicitly requested.</li><li><a href="https://health-isac.org/"><strong>Health-ISAC / H-ISAC</strong></a> — Method: HITS indicator-sharing feed; STIX/TAXII-compatible threat intelligence sharing — Access: healthcare-sector membership / Health-ISAC member access.</li><li><a href="https://www.misp-project.org/communities/?utm_source=chatgpt.com"><strong>NATO MISP Community</strong></a> — Method: MISP community / MISP sync — Access: official government cyber-defense entities from NATO nations, sponsored by their national representative in the NATO Multinational MISP Steering Board.</li><li><a href="https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape?utm_source=chatgpt.com"><strong>ENISA Threat Landscape</strong></a> — Method: public reports and CTI publications; not a confirmed public TAXII/STIX feed. ENISA’s CTL methodology references STIX 2.1 as a common CTI representation format, but this is different from offering a public feed endpoint.</li></ul><h4>4.4 Feed Priority and TLP Assignment</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XhNw0PBdOVuwb9zHT37S5Q.png"></figure><pre># Recommended TLP assignment by source<br>feeds:<br>  - source: mitre_attack<br>    tlp: WHITE          # public, shareable<br>    confidence: 90<br>  - source: alienvault_otx<br>    tlp: GREEN          # community sharing<br>    confidence: 60<br>  - source: mandiant<br>    tlp: AMBER          # restricted to org<br>    confidence: 85<br>  - source: internal_soc<br>    tlp: RED            # internal only<br>    confidence: 95</pre><h3>5. AI Integration Layer</h3><p>This is the “AI-driven” layer on top of standard OpenCTI — a custom connector and MCP server that adds:</p><h4>5.1 AI Enrichment Connector (Claude API)</h4><ul><li>On every new Report, Malware, or Threat-Actor ingested → call Claude API</li><li>Extract structured STIX entities from unstructured text (PDFs, blog posts)</li><li>Summarize long reports into 3-sentence executive briefs</li><li>Score indicator relevance against your organization’s sector profile</li><li>Suggest ATT&amp;CK technique mappings from narrative descriptions</li></ul><h4>5.2 AI Pipeline Architecture</h4><pre>New Report ingested<br>        │<br>        ▼<br>[AI Enrichment Connector]<br>        │<br>        ├─► Claude API: Extract entities → creates STIX SDOs<br>        ├─► Claude API: Map to ATT&amp;CK techniques<br>        ├─► Claude API: Generate executive summary<br>        └─► Claude API: Score severity for your sector<br>                │<br>                ▼<br>        Update Report in OpenCTI<br>        (summary, related entities, confidence scores)</pre><h3>6. Prerequisites</h3><h4>6.1 Hardware (minimum production)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ics48TK_7nXqH-diy8Uzng.png"></figure><h4>6.2 Software</h4><pre># Install Docker Engine (Ubuntu 22.04)<br>sudo apt-get update<br>sudo apt-get install -y ca-certificates curl gnupg lsb-release<br>sudo install -m 0755 -d /etc/apt/keyrings<br>curl -fsSL https://download.docker.com/linux/ubuntu/gpg | \<br>  sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg<br>sudo chmod a+r /etc/apt/keyrings/docker.gpg<br>echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] \<br>  https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | \<br>  sudo tee /etc/apt/sources.list.d/docker.list &gt; /dev/null<br>sudo apt-get update<br>sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin<br># Add user to docker group<br>sudo usermod -aG docker $USER<br>newgrp docker<br># Verify<br>docker compose version</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*eM3O8rdQsyvwxf-0WEZX8w.png"></figure><h4>6.3 System Tuning (required for ElasticSearch)</h4><pre># ElasticSearch requires high vm.max_map_count<br>sudo sysctl -w vm.max_map_count=1048575<br>echo "vm.max_map_count=1048575" | sudo tee -a /etc/sysctl.conf<br><br># Increase file descriptor limits<br>echo "* soft nofile 65536" | sudo tee -a /etc/security/limits.conf<br>echo "* hard nofile 65536" | sudo tee -a /etc/security/limits.conf</pre><h3>7. Docker Compose Deployment</h3><h4><strong>7.0 Deploy from GitHub (recommended)</strong></h4><p>The fastest deployment path is to clone the maintained project repository and create a local `.env` from the sanitized template:</p><pre>cd /home/andrey<br>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd /home/andrey/openCTI<br># Create local secrets/config. This file is ignored by Git.<br>cp .env.example .env<br>nano .env<br># Start the full stack after filling in .env<br>./scripts/start-all.sh</pre><p>This gives you the Docker Compose files, OpenCTI patches, AI enrichment connector, helper scripts, and Docusaurus documentation in one checkout. Use the manual sections below if you want to recreate the files by hand or compare the generated content.</p><h4>7.1 Directory Structure</h4><pre>/home/andrey/openCTI/<br>├── .env                          # secrets and config<br>├── docker-compose.yml            # core stack<br>├── docker-compose.connectors.yml # feed connectors<br>├── docker-compose.ai.yml         # AI enrichment connector<br>├── patches/<br>│   └── back.js                   # ILM race condition fix (ES 8.13 + OpenCTI 6.2.0)<br>└── connectors/<br>    └── ai-enrichment/            # custom AI connector source</pre><h4>7.2 Environment File</h4><pre>cat &gt; /home/andrey/openCTI/.env &lt;&lt; 'EOF'<br># === Core ===<br>OPENCTI_ADMIN_EMAIL=admin@opencti.local<br>OPENCTI_ADMIN_PASSWORD=CHANGE_ME_STRONG_PASSWORD<br>OPENCTI_ADMIN_TOKEN=CHANGE_ME_UUID4_TOKEN<br>OPENCTI_BASE_URL=http://localhost:8080<br><br># === Secrets ===<br>APP__ADMIN__TOKEN=CHANGE_ME_UUID4_TOKEN<br>APP__SECRET_KEY=CHANGE_ME_SECRET<br><br># === ElasticSearch ===<br># NOTE: key is ELASTIC_PASSWORD, not ELASTIC_AUTH<br>ELASTIC_PASSWORD=CHANGE_ME_ELASTIC_PASS<br><br># === Redis ===<br>REDIS_PASSWORD=opencti<br><br># === MinIO ===<br>MINIO_ROOT_USER=opencti<br>MINIO_ROOT_PASSWORD=CHANGE_ME_MINIO_PASS<br><br># === RabbitMQ ===<br>RABBITMQ_DEFAULT_USER=opencti<br>RABBITMQ_DEFAULT_PASS=CHANGE_ME_RABBITMQ_PASS<br><br># === Connector IDs (unique UUID4 per connector — NOT used for auth) ===<br>CONNECTOR_MITRE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_CVE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ALIENVAULT_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ABUSE_SSL_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_URLHAUS_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_AI_ENRICHMENT_TOKEN=CHANGE_ME_UUID4<br><br># === External API keys ===<br>ALIENVAULT_API_KEY=your_otx_key_here<br>NVD_API_KEY=your_nvd_api_key_here     # UUID format from nvd.nist.gov/developers/request-an-api-key<br>ANTHROPIC_API_KEY=your_claude_api_key_here<br>EOF<br><br># Generate unique UUIDs for connector IDs<br>python3 -c "import uuid; [print(uuid.uuid4()) for _ in range(8)]"# Generate proper tokens<br>python3 -c "import uuid; [print(f'Token: {uuid.uuid4()}') for _ in range(10)]"</pre><h4>7.3 Core Stack — docker-compose.yml</h4><pre>nano docker-compose.yml</pre><pre>version: "3"<br>services:<br>  redis:<br>    image: redis:7.2<br>    restart: always<br>    volumes:<br>      - redisdata:/data<br>    command: redis-server --requirepass ${REDIS_PASSWORD:-opencti}<br>  elasticsearch:<br>    image: docker.elastic.co/elasticsearch/elasticsearch:8.13.0<br>    volumes:<br>      - esdata:/usr/share/elasticsearch/data<br>    environment:<br>      - discovery.type=single-node<br>      - xpack.ml.enabled=false<br>      - xpack.security.enabled=true<br>      - ELASTIC_PASSWORD=${ELASTIC_PASSWORD:-CHANGE_ME}<br>      - "ES_JAVA_OPTS=-Xms2g -Xmx2g"<br>      - cluster.routing.allocation.disk.threshold_enabled=false<br>    ulimits:<br>      memlock:<br>        soft: -1<br>        hard: -1<br>    restart: always<br>  minio:<br>    image: minio/minio:RELEASE.2024-01-16T16-07-38Z<br>    volumes:<br>      - miniodata:/data<br>    ports:<br>      - "9001:9001"   # console<br>    environment:<br>      MINIO_ROOT_USER: ${MINIO_ROOT_USER:-opencti}<br>      MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>    command: server /data --console-address ":9001"<br>    restart: always<br>  rabbitmq:<br>    image: rabbitmq:3.13-management<br>    environment:<br>      RABBITMQ_DEFAULT_USER: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ_DEFAULT_PASS: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      RABBITMQ_NODENAME: rabbit01@localhost<br>    volumes:<br>      - rabbitmqdata:/var/lib/rabbitmq<br>    restart: always<br>  opencti:<br>    image: opencti/platform:6.2.0<br>    environment:<br>      NODE_OPTIONS: --max-old-space-size=8096<br>      APP__PORT: 8080<br>      APP__BASE_URL: ${OPENCTI_BASE_URL:-http://localhost:8080}<br>      APP__ADMIN__EMAIL: ${OPENCTI_ADMIN_EMAIL}<br>      APP__ADMIN__PASSWORD: ${OPENCTI_ADMIN_PASSWORD}<br>      APP__ADMIN__TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      APP__APP_LOGS__LOGS_LEVEL: error<br>      REDIS__HOSTNAME: redis<br>      REDIS__PORT: 6379<br>      REDIS__USE_SSL: "false"<br>      REDIS__PASSWORD: ${REDIS_PASSWORD:-opencti}<br>      ELASTICSEARCH__URL: http://elasticsearch:9200<br>      ELASTICSEARCH__USERNAME: elastic<br>      ELASTICSEARCH__PASSWORD: ${ELASTIC_PASSWORD:-CHANGE_ME}<br>      MINIO__ENDPOINT: minio<br>      MINIO__PORT: 9000<br>      MINIO__USE_SSL: "false"<br>      MINIO__ACCESS_KEY: ${MINIO_ROOT_USER:-opencti}<br>      MINIO__SECRET_KEY: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>      RABBITMQ__HOSTNAME: rabbitmq<br>      RABBITMQ__PORT: 5672<br>      RABBITMQ__USERNAME: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ__PASSWORD: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      SMTP__HOSTNAME: localhost<br>      PROVIDERS__LOCAL__STRATEGY: LocalStrategy<br>    volumes:<br>      - ./patches/back.js:/opt/opencti/build/back.js:ro<br>    ports:<br>      - "8080:8080"<br>    depends_on:<br>      - redis<br>      - elasticsearch<br>      - minio<br>      - rabbitmq<br>    restart: always<br>  worker:<br>    image: opencti/worker:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      WORKER_LOG_LEVEL: error<br>    depends_on:<br>      - opencti<br>    deploy:<br>      mode: replicated<br>      replicas: 3<br>    restart: always<br>volumes:<br>  esdata:<br>  redisdata:<br>  miniodata:<br>  rabbitmqdata:<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.4 Connectors — docker-compose.connectors.yml</h4><pre>nano docker-compose.connectors.yml</pre><pre>version: "3"<br>services:<br>  # MITRE ATT&amp;CK (no API key needed)<br>  connector-mitre:<br>    image: opencti/connector-mitre:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MITRE_TOKEN}<br>      CONNECTOR_NAME: "MITRE ATT&amp;CK"<br>      CONNECTOR_SCOPE: "marking-definition,identity,attack-pattern,course-of-action,intrusion-set,campaign,malware,tool,vulnerability,x-mitre-matrix,x-mitre-tactic,x-mitre-collection"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CONNECTOR_LOG_LEVEL: error<br>      MITRE_REMOVE_STATEMENT_MARKING: "true"<br>      MITRE_INTERVAL: 7  # days between full refresh<br>    restart: always<br>  # CVE / NVD Vulnerabilities<br>  connector-cve:<br>    image: opencti/connector-cve:6.2.0<br>    volumes:<br>      - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>      - ./patches/cve/vulnerability.py:/opt/opencti-connector-cve/services/client/vulnerability.py:ro<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_CVE_TOKEN}<br>      CONNECTOR_NAME: "Common Vulnerabilities and Exposures"<br>      CONNECTOR_SCOPE: "identity,vulnerability"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: info<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CVE_BASE_URL: "https://services.nvd.nist.gov/rest/json/cves"<br>      CVE_API_KEY: ${NVD_API_KEY}<br>      CVE_MAX_DATE_RANGE: 120<br>      CVE_MAINTAIN_DATA: "true"<br>      CVE_INTERVAL: 2<br>    restart: always<br>  # AlienVault OTX<br>  connector-alienvault:<br>    image: opencti/connector-alienvault:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_ALIENVAULT_TOKEN}<br>      CONNECTOR_NAME: "AlienVault OTX"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      ALIENVAULT_BASE_URL: "https://otx.alienvault.com"<br>      ALIENVAULT_API_KEY: ${ALIENVAULT_API_KEY}<br>      ALIENVAULT_TLP: "White"<br>      ALIENVAULT_CREATE_OBSERVABLES: "true"<br>      ALIENVAULT_CREATE_INDICATORS: "true"<br>      ALIENVAULT_PULSE_START_TIMESTAMP: "2020-01-01T00:00:00"<br>      ALIENVAULT_REPORT_STATUS: "New"<br>      ALIENVAULT_REPORT_TYPE: "threat-report"<br>      ALIENVAULT_GUESS_MALWARE: "false"<br>      ALIENVAULT_GUESS_CVE: "false"<br>      ALIENVAULT_INTERVAL: 30   # minutes<br>    restart: always<br>  # Abuse.ch SSL Blacklist<br>  connector-abuse-ssl:<br>    image: opencti/connector-abuse-ssl:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MALWAREBAZAAR_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch SSL Blacklist"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 50<br>      CONNECTOR_LOG_LEVEL: error<br>      ABUSE_SSL_URL: "https://sslbl.abuse.ch/blacklist/sslblacklist.csv"<br>      ABUSE_SSL_INTERVAL: 30  # minutes<br>    restart: always<br>  # Abuse.ch URLhaus<br>  connector-urlhaus:<br>    image: opencti/connector-urlhaus:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_URLHAUS_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch URLhaus"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      URLHAUS_CSV_URL: "https://urlhaus.abuse.ch/downloads/csv_recent/"<br>      URLHAUS_IMPORT_OFFLINE: "true"<br>      URLHAUS_INTERVAL: 2  # hours<br>    restart: always<br>  connector-threatfox:<br>    image: opencti/connector-threatfox:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_THREATFOX_TOKEN}<br>      CONNECTOR_NAME: "ThreatFox"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      THREATFOX_API_URL: "https://threatfox-api.abuse.ch/api/v1/"<br>      THREATFOX_CREATE_INDICATORS: "true"<br>      THREATFOX_CREATE_OBSERVABLES: "true"<br>      THREATFOX_INTERVAL: 3<br>    restart: always<br>  connector-import-document:<br>    image: opencti/connector-import-document:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_IMPORT_DOCUMENT_TOKEN}<br>      CONNECTOR_NAME: "ImportDocument"<br>      CONNECTOR_SCOPE: "application/pdf,text/plain,text/html"<br>      CONNECTOR_AUTO: "true"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: error<br>    restart: always<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.5 AI Enrichment Connector — docker-compose.ai.yml</h4><pre>nano docker-compose.ai.yml</pre><pre>version: "3"<br><br>services:<br>  connector-ai-enrichment:<br>    build:<br>      context: ./connectors/ai-enrichment<br>      dockerfile: Dockerfile<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_AI_ENRICHMENT_TOKEN}<br>      CONNECTOR_NAME: "AI Enrichment (Claude)"<br>      CONNECTOR_LOG_LEVEL: info<br>      ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}<br>      AI_MODEL: claude-opus-4-7<br>      AI_ENRICHMENT_REPORTS: "true"<br>      AI_ENRICHMENT_MALWARE: "true"<br>      AI_ENRICHMENT_THREAT_ACTORS: "true"<br>    restart: always<br><br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h3>8. Connector Configuration</h3><h4>Fast Start / Stop Scripts</h4><p>The repository includes two helper scripts for daily operations:</p><pre># Start core OpenCTI, wait for the UI/API, then start connectors and AI enrichment<br>./scripts/start-all.sh<br># Stop AI enrichment, connectors, and core OpenCTI while preserving Docker volumes<br>./scripts/stop-all.sh</pre><p>Use these scripts for normal start/stop operations after .env is configured. Use the manual commands below when debugging a specific service startup problem.</p><pre>nano start-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>WAIT_TIMEOUT="${WAIT_TIMEOUT:-300}"<br><br>wait_for_opencti() {<br>  local deadline=$((SECONDS + WAIT_TIMEOUT))<br><br>  echo "[start] Waiting for OpenCTI API on http://localhost:8080..."<br>  until curl -fsS http://localhost:8080 &gt;/dev/null 2&gt;&amp;1; do<br>    if (( SECONDS &gt;= deadline )); then<br>      echo "[start] OpenCTI did not become reachable within ${WAIT_TIMEOUT}s." &gt;&amp;2<br>      echo "[start] Check logs with: docker compose logs -f opencti" &gt;&amp;2<br>      return 1<br>    fi<br>    sleep 5<br>  done<br>}<br><br>echo "[start] Starting OpenCTI core stack..."<br>docker compose -f docker-compose.yml up -d<br><br>wait_for_opencti<br><br>echo "[start] Starting external connectors..."<br>docker compose -f docker-compose.connectors.yml up -d<br><br>echo "[start] Building and starting AI enrichment connector..."<br>docker compose -f docker-compose.ai.yml up -d --build<br><br>echo "[start] Done."<br>docker compose -f docker-compose.yml ps</pre><pre>nano stop-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>echo "[stop] Stopping OpenCTI core, connectors, and AI enrichment..."<br>docker compose \<br>  -f docker-compose.yml \<br>  -f docker-compose.connectors.yml \<br>  -f docker-compose.ai.yml \<br>  down --remove-orphans<br><br>echo "[stop] Done. Volumes are preserved."</pre><h4>8.1 Start the Core Stack</h4><pre>cd /home/andrey/openCTI<br><br># Pre-flight: ElasticSearch refuses allocation above 90% disk usage<br>df -h /var/lib/docker<br># If &gt; 90% full, run: docker system prune -a   (frees ~47 GB of unused images)<br><br># Create the shared Docker network (idempotent — safe to re-run)<br>docker network create opencti_network 2&gt;/dev/null || true<br><br># Start core services<br>docker compose -f docker-compose.yml up -d<br><br># Wait for ElasticSearch to be healthy before OpenCTI finishes initializing<br>until curl -s -u "elastic:${ELASTIC_PASSWORD}" \<br>  http://localhost:9200/_cluster/health | grep -q '"status":"green"\|"status":"yellow"'; do<br>  echo "Waiting for ES..."; sleep 5<br>done<br><br># Watch logs — first-run index creation takes 5-10 minutes<br># Look for "Listening on port 8080"<br>docker compose -f docker-compose.yml logs -f opencti | grep -E "Listening|ERROR|indices"</pre><h4>8.2 Start Connectors</h4><pre># Start feed connectors (after OpenCTI is healthy)<br>docker compose -f docker-compose.connectors.yml up -d<br># Verify connectors registered (wait ~60s for startup)<br>docker compose -f docker-compose.connectors.yml ps</pre><h4>8.3 Verify in UI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bgDghte5c5Hd2tKbutvP8A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fIQLlAGqYjzNesmSnRw2QQ.png"></figure><pre>http://localhost:8080<br>Login: admin@opencti.local / &lt;your password&gt;Navigation:<br>  Data → Connectors → check all show status "connected"<br>  Knowledge → Malwares → should start populating within minutes<br>  Activities → Logs → watch ingest events</pre><h3>9. AI-Driven Enrichment Pipeline</h3><h4>Overview</h4><p>The AI enrichment pipeline adds a Claude-powered layer on top of the standard OpenCTI ingestion flow. Every time a connector (AlienVault, MITRE, URLhaus, etc.) writes a new object into OpenCTI, an event is published to RabbitMQ. The AI connector subscribes to that event stream, calls the Claude API with the object’s content, and writes the extracted structured intelligence back into the graph as STIX relationships, notes, and entity updates — all automatically.</p><p><strong>Without AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                   (raw text, no relationships, no ATT&amp;CK mapping)</pre><p><strong>With AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                       ↓ AI connector picks it up from event stream<br>                   Claude API: extract entities, map techniques, score severity<br>                       ↓<br>                   Report now has:<br>                   ├── Note: executive summary (2-3 sentences)<br>                   ├── Relationship → ThreatActor (if found in graph)<br>                   ├── Relationship → Malware (if found in graph)<br>                   ├── Relationship → AttackPattern T1059.001 (created if missing)<br>                   └── x_opencti_score updated based on AI confidence</pre><h4>9.1 How the Event Stream Works</h4><p>OpenCTI uses RabbitMQ as its internal message bus. Every write operation (create, update, delete) on any STIX object publishes a message to a topic exchange. Connectors subscribe to this exchange via pycti's OpenCTIConnectorHelper.listen() method.</p><pre>OpenCTI platform<br>      │<br>      │ write event (STIX bundle)<br>      ▼<br>  RabbitMQ<br>  exchange: amq.topic<br>      │<br>      ├──► worker-1 (standard workers — write to ES/graph)<br>      ├──► worker-2<br>      ├──► worker-3<br>      └──► connector-ai-enrichment  ← our connector subscribes here<br>                  │<br>                  │ reads event payload:<br>                  │ {<br>                  │   "type": "create",<br>                  │   "data": { "id": "report--uuid", "type": "report", ... }<br>                  │ }<br>                  ▼<br>            calls Claude API<br>                  ▼<br>            writes enrichment back via GraphQL API</pre><p>Each message contains the full STIX object that was just created. The connector processes it and acknowledges the message — if it crashes mid-processing, RabbitMQ redelivers it.</p><p><strong>Connector type </strong><strong>INTERNAL_ENRICHMENT</strong> means:</p><ul><li>It does not import data on a schedule</li><li>It reacts to existing objects as they are created or updated</li><li>It appears in Settings → Connectors → Enrichment in the UI</li></ul><h4>9.2 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.10. Post-Deployment Hardening</p><h4>9.2 What Claude Extracts and How It Maps to STIX</h4><p>The connector sends the report’s description text to Claude with a structured prompt. Claude returns JSON. The connector then maps each field to STIX operations:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f1BfkVeUO3Qlt9Kj6-MkFg.png"></figure><p>Claude output fieldSTIX actionsummaryCreates a Note object attached to the report (object_refs)threat_actors[]Looks up ThreatActor by name in graph → creates related-to relationship to reportmalware_families[]Looks up Malware by name → creates related-to relationship to reportattack_techniques[]Looks up AttackPattern by external_id (T1059.001) → creates uses relationship to reporttargeted_sectors[]Looks up Identity (sector) → creates targets relationshiptargeted_countries[]Looks up Location by ISO code → creates targets relationshipconfidenceSets x_opencti_score on the report (0–100)</p><p><strong>Why look up instead of creating?</strong> MITRE ATT&amp;CK and identity data is already loaded by the MITRE connector. Looking up prevents duplicates. Only AttackPattern objects are created if missing (since Claude may identify techniques not yet in the graph).</p><h4>9.3 Connector Code</h4><pre>mkdir -p /home/andrey/openCTI/connectors/ai-enrichment</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/connector.py"><strong>connectors/ai-enrichment/connector.py</strong></a></p><pre>import os<br>import json<br>import time<br>import anthropic<br>from pycti import OpenCTIConnectorHelper<br><br>SYSTEM_PROMPT = """You are a senior cyber threat intelligence analyst.<br>Analyze threat intelligence content and return structured JSON only.<br>No prose, no markdown fences, no explanation — raw JSON."""<br><br>REPORT_PROMPT = """Analyze this threat intelligence report. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief, plain text)<br>- threat_actors: list of strings (actor names, aliases, groups mentioned)<br>- malware_families: list of strings (malware/tool names)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs only, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (e.g. ["Finance", "Healthcare", "Government"])<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2, e.g. ["US", "UA", "DE"])<br>- confidence: integer 0-100<br><br>Report:<br>{content}"""<br><br>INTRUSION_SET_PROMPT = """Analyze this threat actor / intrusion set profile. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief)<br>- aliases: list of strings (other known names)<br>- malware_families: list of strings (malware/tools this actor uses)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (sectors this actor targets)<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2 codes)<br>- motivation: string (one of: "espionage", "financial", "hacktivism", "destruction", "unknown")<br>- sophistication: string (one of: "minimal", "intermediate", "advanced", "expert", "unknown")<br>- confidence: integer 0-100<br><br>Profile:<br>{content}"""<br><br><br>class AIEnrichmentConnector:<br>    def __init__(self):<br>        config = {<br>            "opencti": {<br>                "url": os.environ.get("OPENCTI_URL", "http://opencti:8080"),<br>                "token": os.environ["OPENCTI_TOKEN"],<br>            },<br>            "connector": {<br>                "id": os.environ["CONNECTOR_ID"],<br>                "type": "INTERNAL_ENRICHMENT",<br>                "name": os.environ.get("CONNECTOR_NAME", "AI Enrichment (Claude)"),<br>                "scope": "Report,Intrusion-Set,Threat-Actor-Group,Malware",<br>                "log_level": os.environ.get("CONNECTOR_LOG_LEVEL", "info"),<br>                "auto": False,<br>            },<br>        }<br>        self.helper = OpenCTIConnectorHelper(config)<br>        self.client = anthropic.Anthropic(api_key=os.environ["ANTHROPIC_API_KEY"])<br>        self.model = os.environ.get("AI_MODEL", "claude-opus-4-7")<br><br>    # -------------------------------------------------------------------------<br>    # Claude call with retry on rate limit<br>    # -------------------------------------------------------------------------<br><br>    def _call_claude(self, prompt_template: str, content: str) -&gt; dict | None:<br>        for attempt in range(3):<br>            try:<br>                msg = self.client.messages.create(<br>                    model=self.model,<br>                    max_tokens=2048,<br>                    system=SYSTEM_PROMPT,<br>                    messages=[{"role": "user", "content": prompt_template.format(content=content[:8000])}],<br>                )<br>                return json.loads(msg.content[0].text)<br>            except anthropic.RateLimitError:<br>                wait = 60 * (attempt + 1)<br>                self.helper.log_warning(f"Rate limited — waiting {wait}s")<br>                time.sleep(wait)<br>            except (json.JSONDecodeError, anthropic.APIError) as e:<br>                self.helper.log_error(f"Claude call failed: {e}")<br>                return None<br>        return None<br><br>    # -------------------------------------------------------------------------<br>    # STIX write-back helpers<br>    # -------------------------------------------------------------------------<br><br>    def _add_note(self, entity_id: str, summary: str, confidence: int) -&gt; None:<br>        self.helper.api.note.create(<br>            abstract="AI Summary",<br>            content=summary,<br>            confidence=confidence,<br>            object_ids=[entity_id],<br>        )<br><br>    def _link_threat_actors(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            actor = self.helper.api.threat_actor_group.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if actor:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=actor["id"],<br>                    relationship_type="related-to",<br>                    confidence=confidence,<br>                )<br><br>    def _link_malware(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            malware = self.helper.api.malware.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if malware:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=malware["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _link_attack_patterns(self, entity_id: str, technique_ids: list, confidence: int) -&gt; None:<br>        for tid in technique_ids:<br>            pattern = self.helper.api.attack_pattern.read(<br>                filters={"mode": "and", "filters": [{"key": "x_mitre_id", "values": [tid]}], "filterGroups": []}<br>            )<br>            if not pattern:<br>                pattern = self.helper.api.attack_pattern.create(<br>                    name=tid,<br>                    x_mitre_id=tid,<br>                    confidence=50,<br>                )<br>            if pattern:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=pattern["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _update_score(self, entity_id: str, confidence: int) -&gt; None:<br>        self.helper.api.stix_domain_object.update_field(<br>            id=entity_id,<br>            input={"key": "x_opencti_score", "value": str(confidence)},<br>        )<br><br>    # -------------------------------------------------------------------------<br>    # Enrichment handlers per entity type<br>    # -------------------------------------------------------------------------<br><br>    def _enrich_report(self, report: dict) -&gt; str:<br>        content = report.get("description") or ""<br>        if len(content) &lt; 50:<br>            content = report.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching report: {report['name']}")<br>        result = self._call_claude(REPORT_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = report["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("threat_actors"):<br>            self._link_threat_actors(entity_id, result["threat_actors"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self._update_score(entity_id, confidence)<br>        self.helper.log_info(f"Enriched report '{report['name']}'")<br>        return "Enriched"<br><br>    def _enrich_intrusion_set(self, entity: dict) -&gt; str:<br>        content = entity.get("description") or entity.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching intrusion set: {entity['name']}")<br>        result = self._call_claude(INTRUSION_SET_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = entity["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self.helper.log_info(f"Enriched intrusion set '{entity['name']}'")<br>        return "Enriched"<br><br>    # -------------------------------------------------------------------------<br>    # Event handler<br>    # -------------------------------------------------------------------------<br><br>    def process_message(self, data: dict) -&gt; str:<br>        entity_type = data.get("entity_type", "").lower()<br>        entity_id = data.get("entity_id")<br>        enrichment_entity = data.get("enrichment_entity", {})<br><br>        self.helper.log_info(f"Received entity_type='{entity_type}' id='{entity_id}'")<br><br>        if not entity_id:<br>            return "Skipped"<br><br>        entity = enrichment_entity or {}<br><br>        if entity_type == "report":<br>            if not entity:<br>                entity = self.helper.api.report.read(id=entity_id) or {}<br>            if entity.get("confidence", 0) &lt; 40:<br>                return "Skipped: low confidence"<br>            return self._enrich_report(entity)<br><br>        if entity_type in ("intrusion-set", "threat-actor-group"):<br>            if not entity:<br>                entity = self.helper.api.intrusion_set.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            return self._enrich_intrusion_set(entity)<br><br>        if entity_type == "malware":<br>            if not entity:<br>                entity = self.helper.api.malware.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            content = entity.get("description") or entity.get("name", "")<br>            if not content or len(content) &lt; 10:<br>                return "Skipped: content too short"<br>            self.helper.log_info(f"Enriching malware: {entity['name']}")<br>            result = self._call_claude(REPORT_PROMPT, content)<br>            if not result:<br>                return "Skipped: Claude error"<br>            confidence = result.get("confidence", 50)<br>            if result.get("summary"):<br>                self._add_note(entity["id"], result["summary"], confidence)<br>            if result.get("attack_techniques"):<br>                self._link_attack_patterns(entity["id"], result["attack_techniques"], confidence)<br>            self._update_score(entity["id"], confidence)<br>            return "Enriched"<br><br>        return "Skipped"<br><br>    def start(self):<br>        self.helper.log_info("AI Enrichment connector starting...")<br>        self.helper.listen(self.process_message)<br><br><br>if __name__ == "__main__":<br>    AIEnrichmentConnector().start()</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/Dockerfile"><strong>connectors/ai-enrichment/Dockerfile</strong></a></p><pre>FROM python:3.11-slim<br>WORKDIR /app<br>COPY requirements.txt .<br>RUN pip install --no-cache-dir -r requirements.txt<br>COPY connector.py .<br>CMD ["python", "connector.py"]</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/requirements.txt"><strong>connectors/ai-enrichment/requirements.txt</strong></a></p><pre>pycti&gt;=6.2.0<br>anthropic&gt;=0.40.0</pre><h4>9.4 Deploy the AI Connector</h4><p><strong>Prerequisites:</strong> Set ANTHROPIC_API_KEY in .env first.</p><pre>cd /home/andrey/openCTI<br># Build the image<br>docker compose -f docker-compose.ai.yml build<br># Start it<br>docker compose -f docker-compose.ai.yml up -d<br># Verify it registered with OpenCTI (look for "AI Enrichment" in connector list)<br>docker logs opencti-connector-ai-enrichment-1 --tail=20</pre><p>In the OpenCTI UI: <strong>Settings → Connectors → Enrichment</strong> — the connector should appear with status connected after ~10 seconds.</p><h4>9.5 Testing the Pipeline</h4><p>Trigger a manual enrichment by importing a real threat report:</p><pre># Import a STIX report via the API to trigger the connector<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $(grep OPENCTI_ADMIN_TOKEN .env | cut -d= -f2)" \<br>  -H "Content-Type: application/json" \<br>  -d '{<br>    "query": "mutation { reportAdd(input: { name: \"Test: APT29 spearphishing campaign\", description: \"APT29, also known as Cozy Bear, conducted a spearphishing campaign targeting NATO members using a malicious PDF dropper that installed Cobalt Strike beacon via PowerShell (T1059.001). The campaign targeted defense contractors in Poland and Germany. The malware communicated with C2 over HTTPS using domain fronting (T1090.004).\", published: \"2024-01-15T00:00:00Z\", report_types: [\"threat-report\"] }) { id name } }"<br>  }'</pre><p>Then check what the AI connector wrote back:</p><pre># Watch connector logs for the enrichment<br>docker logs -f opencti-connector-ai-enrichment-1 2&gt;&amp;1 | grep -E "Enriching|Enriched|Error"<br># Expected output:<br># Enriching report: Test: APT29 spearphishing campaign<br># Enriched: 1 actors, 1 malware, 2 techniques</pre><p>In the UI, open the report — it should now have a Note with the summary, relationships to APT29 and Cobalt Strike, and links to T1059.001 and T1090.004.</p><h4>9.6 Cost and Rate Limiting</h4><p><strong>Estimated Claude API cost per report:</strong></p><ul><li>~500–2000 tokens input (report text, truncated at 8000 chars)</li><li>~300 tokens output (JSON response)</li><li>At claude-opus-4-7 pricing: ~$0.01–0.05 per report</li></ul><p><strong>Rate limiting:</strong> The Anthropic API has per-minute token limits. If AlienVault imports hundreds of reports in a burst, the connector will hit rate limits. Add a simple backoff:</p><pre>import time<br>def _call_claude(self, content: str) -&gt; dict | None:<br>    for attempt in range(3):<br>        try:<br>            msg = self.client.messages.create(...)<br>            return json.loads(msg.content[0].text)<br>        except anthropic.RateLimitError:<br>            time.sleep(60 * (attempt + 1))<br>        except (json.JSONDecodeError, anthropic.APIError) as e:<br>            self.helper.log_error(f"Claude call failed: {e}")<br>            return None<br>    return None</pre><p><strong>To limit scope</strong> (only enrich reports above a confidence threshold, skip low-quality feeds):</p><pre>def process_message(self, data: dict) -&gt; str:<br>    report = self.helper.api.report.read(id=entity_id)<br>    # Skip reports with low confidence (e.g. AlienVault auto-generated)<br>    if report.get("confidence", 0) &lt; 40:<br>        return "Skipped: low confidence"<br>    return self._enrich_report(report)</pre><h4>9.7 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epLGa3gwJILd0FyMKdsQQg.png"></figure><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.</p><h3>10. Post-Deployment Hardening</h3><h4>10.1 Reverse Proxy with TLS (nginx)</h4><pre># /etc/nginx/sites-available/opencti<br>server {<br>    listen 443 ssl http2;<br>    server_name opencti.yourdomain.com;<br>ssl_certificate     /etc/letsencrypt/live/opencti.yourdomain.com/fullchain.pem;<br>    ssl_certificate_key /etc/letsencrypt/live/opencti.yourdomain.com/privkey.pem;<br>    ssl_protocols       TLSv1.2 TLSv1.3;<br>    ssl_ciphers         ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;<br>    location / {<br>        proxy_pass         http://127.0.0.1:8080;<br>        proxy_set_header   Host $host;<br>        proxy_set_header   X-Real-IP $remote_addr;<br>        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;<br>        proxy_set_header   X-Forwarded-Proto $scheme;<br>        proxy_read_timeout 300s;<br>        client_max_body_size 100m;<br>    }<br>}<br>server {<br>    listen 80;<br>    server_name opencti.yourdomain.com;<br>    return 301 https://$host$request_uri;<br>}</pre><h4>10.2 Backup Strategy</h4><pre>#!/bin/bash<br># /home/andrey/openCTI/scripts/backup.sh<br>set -euo pipefail<br>BACKUP_DIR="/mnt/backup/opencti/$(date +%Y%m%d_%H%M%S)"<br>mkdir -p "$BACKUP_DIR"<br># Snapshot ElasticSearch<br>curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  -X PUT "http://localhost:9200/_snapshot/backup/snapshot_$(date +%Y%m%d)" \<br>  -H 'Content-Type: application/json' \<br>  -d '{"indices": "*", "ignore_unavailable": true}'<br># Dump MinIO (reports, files)<br>docker run --rm \<br>  --network opencti_network \<br>  -v "$BACKUP_DIR:/backup" \<br>  minio/mc:latest \<br>  mirror myminio/opencti /backup/minio/<br>echo "Backup completed: $BACKUP_DIR"</pre><h4>10.3 Security Checklist</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hjQWso4p7MIiBfcRr15oZw.png"></figure><ul><li>Change all default passwords in .env</li><li>Generate unique UUID4 tokens for every connector</li><li>Enable TLS via nginx reverse proxy</li><li>Restrict port 8080 to localhost only (127.0.0.1:8080:8080)</li><li>Enable ElasticSearch authentication (already configured above)</li><li>Set up fail2ban on the nginx access log</li><li>Rotate OPENCTI_ADMIN_TOKEN every 90 days</li><li>Review TLP markings — ensure nothing RED leaks via TAXII</li><li>Enable audit logging: APP__APP_LOGS__LOGS_LEVEL: info</li></ul><h3>11. Operational Runbook</h3><h4>Day 1 — Initial Data Load</h4><pre># MITRE ATT&amp;CK loads first (foundational framework)<br># Wait ~10 minutes for it to complete, then verify:<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br><br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ attackPatterns { edges { node { name } } } }"}' | \<br>  python3 -c "import sys,json; d=json.load(sys.stdin); print('Techniques loaded:', len(d['data']['attackPatterns']['edges']))"<br># Should return 500+ techniques</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V2XGUwLrUpe1XNLUono5Ng.png"></figure><h4>Common Operations</h4><pre># Check all connector health<br>docker compose -f docker-compose.connectors.yml ps<br># View connector logs<br>docker compose -f docker-compose.connectors.yml logs --tail=50 connector-alienvault<br># Restart a stuck connector<br>docker compose -f docker-compose.connectors.yml restart connector-malwarebazaar<br># Scale workers for high ingest load<br>docker compose -f docker-compose.yml up -d --scale worker=5<br># Check ElasticSearch cluster health<br>curl -s -u elastic:${ELASTIC_PASSWORD} http://localhost:9200/_cluster/health?pretty<br># Check RabbitMQ queue depth (should stay near 0 at rest)<br>docker exec $(docker ps -qf name=rabbitmq) rabbitmqctl list_queues name messages</pre><h4>Monitoring Metrics to Watch</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dn9gJsZa98wedqD6PdcrQA.png"></figure><h4>Quick Reference</h4><pre># Start everything<br>cd /home/andrey/openCTI<br>docker network create opencti_network 2&gt;/dev/null || true<br>docker compose -f docker-compose.yml up -d<br>docker compose -f docker-compose.connectors.yml up -d<br>docker compose -f docker-compose.ai.yml up -d<br># Stop everything<br>docker compose -f docker-compose.ai.yml down<br>docker compose -f docker-compose.connectors.yml down<br>docker compose -f docker-compose.yml down<br># Access<br># UI:      http://localhost:8080<br># API:     http://localhost:8080/graphql<br># MinIO:   http://localhost:9001<br># RabbitMQ: http://localhost:15672</pre><h3>12. Troubleshooting</h3><h3>Known Issues — OpenCTI 6.2.0 + ElasticSearch 8.13</h3><h4>ILM Race Condition (resource_already_exists_exception)</h4><p>ES 8.13’s ILM daemon auto-bootstraps rollover indices the moment an index template with lifecycle.rollover_alias is created. OpenCTI's elCreateIndex does a check-then-create which loses the race. This kills initialization and loops with restart: always.</p><p><strong>Fix already applied:</strong> patches/back.js is mounted over the compiled bundle and makes elCreateIndex idempotent — it catches resource_already_exists_exception and returns null.</p><p><strong>Re-initialization procedure</strong> (if ES volume is dropped):</p><pre># 1. Delete any leftover index templates from a failed run<br>curl -s -u elastic:${ELASTIC_PASSWORD} -X DELETE \<br>  "http://localhost:9200/_index_template/opencti*"</pre><pre># 2. Flush Redis state<br>docker exec opencti-redis-1 redis-cli -a opencti FLUSHALL</pre><pre># 3. Start ES first, wait for green/yellow<br>docker compose up -d elasticsearch<br>until curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  <a href="http://localhost:9200/_cluster/health">http://localhost:9200/_cluster/health</a> | grep -q '"status":"green"\|"status":"yellow"'; do<br>  sleep 5; done</pre><pre># 4. Start the rest — OpenCTI will create 13 indices and load base STIX data (~5-10 min)<br>docker compose up -d</pre><h4>ElasticSearch Disk Watermark (cluster RED, no shard allocation)</h4><p>ES 8.x refuses all shard allocation when disk exceeds 90% high watermark. cluster.routing.allocation.disk.threshold_enabled=false is set in docker-compose.yml.</p><p>To reclaim disk space:</p><pre>docker system prune -a   # frees ~47 GB of unused images/containers</pre><h4>Connectors Can’t Reach opencti Hostname</h4><p>Both compose files must share the same Docker network. docker-compose.yml defines:</p><pre>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><p>If the main stack was started without this, run:</p><pre>docker network connect --alias opencti opencti_network opencti-opencti-1</pre><p>Then add the networks: block to docker-compose.yml and run docker compose up -d to make it permanent.</p><h4>OPENCTI_TOKEN vs CONNECTOR_ID</h4><p>Connectors authenticate to OpenCTI using OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}. The per-connector UUID variables (CONNECTOR_MITRE_TOKEN, etc.) are only used as CONNECTOR_ID — they identify the connector instance in the UI, not for authentication.</p><h4>CVE Connector — Zero Vulnerabilities Imported (NVD API Key Bug)</h4><p>connector-cve:6.2.0 has a bug: it sends the NVD API key as Bearer: &lt;key&gt; in the HTTP header, but NVD 2.0 API requires apiKey: &lt;key&gt;. The connector silently gets a non-200 response and imports nothing. Additionally, CVE_MAX_DATE_RANGE is required but missing from the image's default config — omitting it causes a TypeError: '&gt;' not supported between instances of 'NoneType' and 'int' crash every 60 seconds.</p><p><strong>Fix:</strong> Mount a patched api.py that uses the correct header, and add the missing vars:</p><pre>connector-cve:<br>  image: opencti/connector-cve:6.2.0<br>  volumes:<br>    - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>  environment:<br>    CVE_MAX_DATE_RANGE: 120<br>    CVE_MAINTAIN_DATA: "true"<br>    # ... other vars</pre><p>patches/cve/api.py — change header from "Bearer": api_key to "apiKey": api_key:</p><pre>headers = {"User-Agent": header}<br>if api_key:<br>    headers["apiKey"] = api_key</pre><h3>13. Usage Examples</h3><h4>13.1 Standard OpenCTI Workflows</h4><h4>Example 1 — Investigate an IP address</h4><p>You received an alert from your SIEM about suspicious outbound traffic to 103.113.70.102.</p><p><strong>In OpenCTI UI:</strong></p><pre>Search → type 103.113.70.102</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2k7QE2Urnr8tw_xJ2MyAPA.png"></figure><p>If AlienVault or URLhaus has seen it, you’ll find:</p><ul><li>Which threat actor uses this IP as C2</li><li>What malware family communicates with it</li><li>When it was first/last observed</li><li>TLP marking and confidence score</li><li>All reports that mention it</li></ul><p><strong>Via API:</strong></p><pre>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ stixCyberObservables(filters: {mode: and, filters: [{key: \"value\", values: [\"https://103.113.70.102/bin/support.client.exe\"]}], filterGroups: []}) { edges { node { id entity_type ... on Url { value } } } } }"}' | python3 -m json.tool</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fe53xHSxwntH5knkGjSO6g.png"></figure><h4>Example 2 — Build an APT profile</h4><p>You want to understand everything known about Lazarus Group before a threat briefing.</p><pre><br>Threats → Intrusion Sets → search "Lazarus"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S-QNk2tNF4lgs9q6-YaTUQ.png"></figure><p>The profile shows:</p><ul><li><strong>Attributed to:</strong> North Korea</li><li><strong>Motivations:</strong> Financial gain, Espionage</li><li><strong>Targets:</strong> Finance, Cryptocurrency, Defense</li><li><strong>Malware used:</strong> WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)</li><li><strong>Techniques:</strong> 80+ ATT&amp;CK techniques with usage relationships</li><li><strong>Campaigns:</strong> Operation AppleJeus, Dream Job, etc.</li><li><strong>Timeline:</strong> chronological view of all activity</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Gmvuu4OUs0uIgRZDt9p3fA.png"></figure><p>Click <strong>“ATT&amp;CK Patterns”</strong> tab → heatmap showing which techniques Lazarus uses most.</p><h4>Example 3 — Import a threat report (PDF / blog post)</h4><p>You found a Mandiant or CrowdStrike blog post about a new campaign.</p><pre>Data → Import → drag and drop the PDF or paste the URL<br>Select format: "Auto detect" or "Report"</pre><p>OpenCTI parses it and creates a Report object. The AI enrichment connector then picks it up automatically and extracts:</p><ul><li>Threat actors mentioned</li><li>Malware families</li><li>ATT&amp;CK technique IDs</li><li>Targeted sectors and countries</li></ul><p>All as STIX relationships, visible immediately in the UI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zPViHJ6GKjMeHMtM8240gg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YQBdTFlcQ_q9NcblRik5pw.png"></figure><h4>Example 4 — Track a CVE across your environment</h4><p>CVE-2024–21762 (Fortinet FortiOS RCE) was just published. Check what you know about it.</p><pre>Arsenal → Vulnerabilities → search "CVE-2024-21762"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G9LM5wxYywcTYVdLC331jw.png"></figure><p>After the CVE connector syncs, you’ll see:</p><ul><li>CVSS score and vector</li><li>Affected software versions</li><li>Which threat actors exploit it (once AlienVault/MITRE data arrives)</li><li>Which campaigns used it</li><li>Related indicators (IPs, domains used in exploitation)</li></ul><h4>Example 5 — Create an incident from a sighting</h4><p>Your EDR detected Cobalt Strike beacon on a workstation.</p><pre>Activities → Incidents → Create<br>  Name: "CS beacon on WS-042"<br>  Type: "Intrusion"<br>  Confidence: 90<br>  Add object: link to Cobalt Strike (malware)<br>  Add object: link to T1071.001 (C2 over HTTP)<br>  Add observable: add the C2 IP</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zm8Mi5l-QnFsTb0jAia32A.png"></figure><p>With sighting_incident rule enabled, future detections of the same C2 IP automatically raise new incidents without manual work.</p><h4>Example 6 — Export IOCs to your firewall / SIEM</h4><p>You want a live blocklist of all HIGH confidence IPv4 indicators.</p><pre>Data → Indicators<br>Filter: Score &gt; 70, Type = IPv4-Addr, Valid until &gt; today<br>Export → CSV or STIX</pre><p>Or use the built-in <strong>TAXII 2.1 server</strong> to push directly to your SIEM:</p><pre>Settings → Taxii Server → Create collection "High confidence IOCs"<br>Configure your SIEM to poll: http://localhost:8080/taxii2/</pre><h4>Example 7 — Map your detection coverage against ATT&amp;CK</h4><p>You want to know which techniques you detect vs which you’re blind to.</p><pre>Technics → Attack Patterns<br>Filter by: used by (Lazarus Group)</pre><p>Cross-reference the list with your SIEM detection rules. Techniques with no detection rule = gap in coverage.</p><p>Export the filtered list as CSV and import into ATT&amp;CK Navigator for a visual heatmap of covered vs uncovered techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mPwgsMfkEtXK1y1rnlj0Hw.png"></figure><h4>Example 8 — Pivot from malware to infrastructure</h4><p>You found a Ryuk ransomware sample (SHA256 hash).</p><pre>Search → paste the SHA256</pre><p>From the malware object, pivot to:</p><ul><li><strong>Related indicators</strong> → domains and IPs used for C2</li><li><strong>Used by</strong> → Wizard Spider (threat actor)</li><li><strong>Campaigns</strong> → which ransomware campaigns used this variant</li><li><strong>Techniques</strong> → T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery)</li></ul><p>Each pivot is one click in the graph view.</p><h4>Example 9 — Share intelligence with a partner org</h4><p>You want to share a report with a partner but strip out RED-marked internal data.</p><pre>Open the report → Actions → Share<br>Select TLP level: TLP:AMBER (only partner can see it)</pre><p>Or use <strong>Workspaces → Sharing groups</strong> to create a federated share with another OpenCTI instance. All objects above RED are automatically excluded from the export.</p><h4>Example 10 — Build a custom dashboard for your sector</h4><p>Your org is in Finance. You want a live dashboard showing threats to your sector.</p><pre>Home → Dashboards → Create dashboard "Finance Threat Landscape"<br>Add widgets:<br>  - "Threat actors targeting Finance" (bar chart)<br>  - "Most used techniques against Finance" (ATT&amp;CK heatmap)<br>  - "New IOCs last 7 days" (timeline)<br>  - "Active campaigns" (list)<br>  - "CVEs affecting banking software" (table)</pre><p>Each widget auto-updates as new data arrives from connectors.</p><h4>If you like this research, <a href="https://www.paypal.com/donate/?business=W3XDKS7J9XTCG&amp;no_recurring=0&amp;item_name=Buy+me+a+coffee+%28PayPal%29+%E2%80%94+Keep+the+lab+running&amp;currency_code=USD">buy me a coffee (PayPal) — Keep the lab running</a></h4><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><h4>Stay connected:</h4><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><p>Follow My Work</p><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><p>Portfolio / Knowledge Base: <a href="https://1200km.com/">https://1200km.com/</a><br>Medium: <a href="https://medium.com/@1200km">https://medium.com/@1200km</a><br>GitHub: <a href="https://github.com/anpa1200">https://github.com/anpa1200</a><br>LinkedIn: <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></p><p>Andrey Pautov</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=057c9b4b9394" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SEC Consult SA-20260608-0 :: Privilege Escalation via Binary Planting in Genetec-provided RabbitMQ in multiple Genetec products]]></title>
<description><![CDATA[Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Jun 08SEC Consult Vulnerability Lab Security Advisory < 20260608-0 >
=======================================================================
               title: Privilege Escalation via Binary Planting
             product: Genetec-p...]]></description>
<link>https://tsecurity.de/de/3583622/it-security-nachrichten/sec-consult-sa-20260608-0-privilege-escalation-via-binary-planting-in-genetec-provided-rabbitmq-in-multiple-genetec-products/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583622/it-security-nachrichten/sec-consult-sa-20260608-0-privilege-escalation-via-binary-planting-in-genetec-provided-rabbitmq-in-multiple-genetec-products/</guid>
<pubDate>Tue, 09 Jun 2026 08:08:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Jun 08</p>SEC Consult Vulnerability Lab Security Advisory &lt; 20260608-0 &gt;<br>
=======================================================================<br>
               title: Privilege Escalation via Binary Planting<br>
             product: Genetec-provided RabbitMQ in multiple Genetec products<br>
  vulnerable version: Multiple products, see below.<br>
       fixed version: Multiple products, see below.<br>
          CVE number: CVE-2026-25112<br>
            ...<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana]]></title>
<description><![CDATA[11 validated detections from public sources, OpenCTI graph, and a one-command labTable of ContentsMost threat actor writeups stop too early. They describe the group, list ATT&CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: what do I actually do with th...]]></description>
<link>https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>11 validated detections from public sources, OpenCTI graph, and a one-command lab</em>Table of Contents</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HvRb4_s15JQ6FkA9ng-8w.png"></figure><p>Most threat actor writeups stop too early. They describe the group, list ATT&amp;CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: <em>what do I actually do with this on Monday?</em></p><p>Operation Desert Hydra is an answer to that question.</p><p>This article documents a full CTI-to-detection pipeline focused on <strong>MuddyWater</strong> — an Iranian state-linked actor (MOIS) that has been targeting Israeli government, defense, and critical infrastructure organizations since at least 2019. By the end, you’ll have 11 detection records, 12 Kibana proof screenshots, and a working lab you can deploy with a single command.</p><p>Everything is on my GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra">github.com/anpa1200/operation-desert-hydra</a></p><p><a href="https://github.com/anpa1200/operation-desert-hydra">GitHub - anpa1200/operation-desert-hydra: OpenCTI-based CTI-to-Detection Knowledge Graph for Iranian activity against Israeli organizations</a></p><ol><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#86dc"><strong>Why MuddyWater?</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#aadd"><strong>The Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c6f3"><strong>Phase 1: Source Gathering</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#205e"><strong>Phase 2: Procedure Dataset</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#fb48"><strong>Phase 3: OpenCTI Knowledge Graph</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c2e1"><strong>Phase 4: Detection Atlas</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8ce1"><strong>Phase 5: Validation Lab</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#0a42"><strong>Validation Results Summary</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8cf4"><strong>Phase 6: Coverage Matrix</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dfaa"><strong>What Defenders Should Do Right Now</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#b8cc"><strong>Reproduce It Yourself</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dbb0"><strong>Production Scars</strong></a></li></ol><h3>Why MuddyWater?</h3><p>Three reasons:</p><ol><li><strong>Rich public reporting.</strong> CISA, Israel’s INCD, ClearSky, Deep Instinct, Mandiant, and Proofpoint have all published detailed technical analysis. This gives enough procedure-level specificity to engineer real detections.</li><li><strong>Consistent playbook.</strong> Across five years of reporting, the same pattern recurs: spearphishing → scripting engine → encoded PowerShell → RMM tool. The consistency makes it detectable.</li><li><strong>Relevant geography.</strong> The actor consistently targets Israeli organizations — a geography with high analytical value and underserved public detection coverage.</li></ol><h3>The Pipeline</h3><p>The project enforces a chain from source to Kibana screenshot:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NDsnhzE7S-lzy0fSIOZrsw.png"></figure><pre>source → claim → procedure → ATT&amp;CK mapping → telemetry requirement<br>  → detection pseudologic → benign simulation → lab result → coverage score</pre><p>No step is skipped. Every claim has a source. Every detection has a validation case. Every PASS has a screenshot.</p><h3>Phase 1: Source Gathering</h3><p>The first step is source discovery, not detection writing.</p><h4>Traditional Source Gathering — and Why It’s Not Enough Alone</h4><p>The standard workflow for CTI source gathering looks like this: run keyword searches (Google, Google Dorks, site: operators for known vendor blogs), check your Threat Intelligence Platform for existing reports on the actor, subscribe to vendor RSS feeds, pull ISAC/ISAO advisories, and query your organization’s TIP for any existing indicator sets or finished intelligence reports tagged to the actor.</p><p>For a mature, well-documented actor like MuddyWater this gets you to maybe 15–20 well-known sources quickly — the CISA advisory, the MITRE ATT&amp;CK page, two or three vendor blog posts you already knew about. The problem is coverage holes: you’ll reliably find sources that are already in your network’s vocabulary and miss the ones that aren’t. A CERT-IL PDF published in Hebrew and linked only from a government portal, a Group-IB campaign teardown behind a partial paywall, or a 2020 ClearSky report that predates your current TIP subscription window — all of these can fall out of a manual search pass.</p><p>TIPs compound this in a specific way: they surface what has already been ingested and tagged. If a source was never promoted into your TIP (because it was published before the subscription started, or because no analyst had time to import it), it is invisible inside the platform. The TIP is authoritative for what it knows, not for the universe of available sources.</p><h4>AI research</h4><p>The parallel AI research pass was not a replacement for traditional gathering — it was a coverage supplement. After both approaches ran, the traditional pass and the AI outputs were merged into the same deduplication step. The AI outputs added approximately 40 sources beyond what a manual search surfaced; traditional search added discipline about sources the models hallucinated (fabricated URLs, mis-attributed PDFs). Neither was sufficient alone.</p><p>I ran parallel deep-research passes using Gemini and OpenAI, both given the same prompt. Each returned a candidate source register. Both outputs were compared, deduplicated (71 candidates → 8 promoted), and the surviving sources were manually acquired and reviewed before anything entered the dataset.</p><h4>The Actual Prompt</h4><p>This is the exact prompt used — both models received it verbatim:</p><pre>You are a senior CTI researcher and source-validation analyst. For Operation Desert Hydra,<br>gather the best public sources on MuddyWater / Seedworm / Mango Sandstorm / TA450 and<br>related Iranian activity against Israeli organizations. Goal: create a source register for<br>an OpenCTI-based CTI-to-detection knowledge graph:<br>Source → Actor → Campaign → Procedure → ATT&amp;CK Technique → Observable → Log Source<br>→ Detection → Validation → Coverage.<br>Search MITRE ATT&amp;CK, CISA/FBI/NSA, Israel National Cyber Directorate, Microsoft,<br>Google/Mandiant, ESET, Check Point, ClearSky, Unit 42, Proofpoint, SentinelOne,<br>Recorded Future, Symantec, Talos, Trend Micro, Kaspersky, Cloudflare/Hunt.io/DomainTools,<br>GitHub, and academic sources.<br>Include secondary comparison actors only as comparison: APT34, APT35/Charming Kitten/Mint<br>Sandstorm, CyberAv3ngers, Agrius. Do not merge actors unless a source explicitly supports<br>overlap.<br>For every source, return this YAML structure:<br>  id, title, publisher, url, direct_download_url, download_type, publication_date,<br>  access_date, actor_claims, source_type, reliability, relevance flags for<br>  actor_profile/procedures/malware/infrastructure/detections/validation_lab/opencti_modeling,<br>  key_entities, key_attck_techniques, source_summary, use_for_project, limitations.<br>Provide direct PDF/STIX/JSON/CSV/GitHub raw links where available; if unavailable write<br>direct_download_url: none_found. Do not invent URLs or dates.<br>Use evidence labels:<br>  Observed = directly shown in telemetry/sample/log/screenshot/source artifact<br>  Reported = stated by source<br>  Assessed = source judgment<br>  Inferred = analyst conclusion from multiple cited facts<br>  Gap = unknown or not proven<br>Do not upgrade source claims, do not treat ATT&amp;CK mapping as attribution evidence, do not<br>treat shared tooling as actor identity proof, and do not claim detection coverage without<br>validation.<br>Search exact terms including:<br>  MuddyWater Iran MOIS, MuddyWater Seedworm, MuddyWater Mango Sandstorm,<br>  MuddyWater TA450, MuddyWater POWERSTATS, PowGoop, MuddyViper, MuddyWater Israel,<br>  Israeli organizations, PowerShell, RMM, phishing, spearphishing, Exchange CVE-2020-0688,<br>  CVE-2017-0199, MITRE ATT&amp;CK, CISA FBI NSA advisory, Mango Sandstorm Microsoft,<br>  TA450 Proofpoint, Seedworm Symantec, ESET, ClearSky, Unit 42, Check Point, Mandiant,<br>  SentinelOne, Recorded Future, Talos, Trend Micro, Kaspersky;<br>  also: APT34 Israel, APT35 Israel, Mint Sandstorm Israel, CyberAv3ngers Israel,<br>  Agrius Israel, Iranian threat actors Israeli organizations.<br>Output only these sections:<br>  1) Executive Source Assessment<br>  2) High-Priority Source Register with 10-20 best sources in YAML<br>  3) Extended Source Register<br>  4) Direct Downloads Table<br>  5) Actor Alias / Overlap Notes<br>  6) Procedure Extraction Candidates grouped by tactic with source_ids, evidence_label,<br>     ATT&amp;CK candidate, required telemetry, detection opportunity, validation_possible<br>  7) OpenCTI Modeling Candidates<br>  8) Detection Engineering Opportunities marked candidate only<br>  9) Gaps And Manual Review Items<br>The final output must be usable to seed data/sources.yaml, data/procedures.yaml,<br>docs methodology, OpenCTI import plan, and detection atlas.</pre><h4>What the Prompt Is Designed to Do</h4><p>A few decisions worth explaining:</p><p><strong>Output schema in the prompt.</strong> Asking for a specific YAML field list (id, title, publisher, url, direct_download_url…) forces the model to either produce usable data or leave a visible blank — no vague summaries. direct_download_url: none_found is the required answer when a URL doesn't exist, which prevents the model from inventing one.</p><p><strong>Evidence labels baked in.</strong> The five labels (Observed / Reported / Assessed / Inferred / Gap) are defined in the prompt so the model applies them consistently and the output is ready to feed directly into data/procedures.yaml without reformatting.</p><p><strong>Explicit anti-hallucination rules.</strong> “Do not invent URLs or dates.” “Do not upgrade source claims.” “Do not treat ATT&amp;CK mapping as attribution evidence.” These are not just principles — they are instructions the model can fail visibly on, which makes QA faster.</p><p><strong>Parallel models, same prompt.</strong> Running Gemini and OpenAI on the same prompt and comparing outputs catches source fabrications: if one model lists a URL the other doesn’t, that URL gets verified before it enters the register. Two models that agree independently on a source add confidence; one model alone that lists something unusual is a flag.</p><h4>The Review Gate</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p--8CFcThnLuDmZiNyOdQg.png"></figure><p>Every source that came out of the AI output went through this checklist before being promoted into data/sources.yaml:</p><ul><li>Is the URL real and accessible?</li><li>Is the publication date accurate?</li><li>Does the content actually describe MuddyWater procedures (not just mention the name)?</li><li>Is there at least one procedure-level claim (not just “actor uses PowerShell”)?</li><li>Is the actor identification explicit or inferred from shared tooling only?</li></ul><p>71 candidates → 8 government/vendor sources promoted. The rest were duplicates, secondary summaries, or sources that named the actor without procedure-level specificity.</p><h4>Research Artifacts (All in the Repo)</h4><p>Every file from the source gathering workflow is version-controlled and publicly accessible:</p><ul><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/Gemini-research.md"><strong>Gemini-research.md</strong></a> — Raw Gemini deep-research output: candidate source register in YAML, procedure extraction candidates, OpenCTI modeling candidates, detection opportunities, gaps.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/openAI-research.md"><strong>openAI-research.md</strong></a> — Raw OpenAI deep-research output: executive assessment, high-priority sources, extended source register, direct download list, actor alias notes.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/relevant-research-list.md"><strong>relevant-research-list.md</strong></a> — Deduplicated candidate list after comparing both model outputs: 71 sources, acquisition targets for Step 5.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-acquisition-report.md"><strong>source-acquisition-report.md</strong></a> — Results of the automated fetch run: HTTP status, content type, file size, and extraction status for all 71 sources.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-reliability-evidence-assessment.md"><strong>source-reliability-evidence-assessment.md</strong></a> — Analyst review notes: reliability ratings, evidence quality, promotion decisions, and limitations per source.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/tree/main/docs/source-gathering/raw-sources"><strong>raw-sources/</strong></a> — 71 numbered source folders, each containing metadata.json, headers.txt, the raw source file, extracted source.txt, and fallback reader output.</li></ul><h4><strong>Promoted sources (highest weight):</strong></h4><ul><li><strong>CISA AA22–055A (Feb 2022)</strong> — Full procedure survey: PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin; WMI survey script; credential dumping tools.</li><li><strong>INCD 2023</strong> — Israeli campaign specifics: ScreenConnect/SimpleHelp RMM abuse, Egnyte/OneDrive lures, Log4j + Exchange exploitation.</li><li><strong>INCD 2024</strong> — BugSleep analysis: 43-minute scheduled task beacon, VPN exploitation, new RMM tools (Level, PDQConnect).</li></ul><p>Supporting vendor sources: ClearSky, Deep Instinct, Group-IB, Mandiant, Proofpoint, Sekoia.io, Symantec.</p><h4>Why These Three Have the Highest Weight</h4><p>The reliability assessment used a two-axis rubric: <strong>Source Reliability (A–F)</strong> separating publication discipline from content, and <strong>Information Credibility (1–6)</strong> rating how well each claim is grounded.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*672ETgk4DFDJDE0G2-sLgA.png"></figure><p><strong>CISA AA22–055A — Reliability A, Credibility 2</strong></p><p>This is a joint advisory signed by five national authorities: CISA, FBI, CNMF, NCSC-UK, and NSA. That multi-agency co-signature is not ceremonial — each agency must independently agree to the technical content before it publishes. The advisory names specific malware families (PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin), includes an actual WMI PowerShell survey script attributed to MuddyWater, and lists credential-dumping tool names. Evidence label: Reported / Assessed. The PDF acquired locally at raw-sources/07-u-s-cyber-command-defense-media-aa22-055a-pdf-mirror/source.pdf is the authoritative copy distributed via Defense Media Activity. Credibility is 2, not 1, because the advisory states TTPs based on intelligence assessment rather than a single intercepted artifact — but the authority behind that assessment is as high as public-source CTI gets.</p><p><strong>INCD 2023 (MuddyWater / DarkBit PDF) — Reliability A, Credibility 2</strong></p><p>The Israel National Cyber Directorate is the government authority responsible for civilian cyber defense in Israel, the primary target country for this actor. This report covers a specific Israeli campaign including: tool names (ScreenConnect, SimpleHelp), file-sharing lure services (Egnyte, OneDrive), exploitation of Log4j and Exchange CVE-2020–0688, and deployment of ransomware (DarkBit) as a cover operation. Evidence label: Observed / Reported / Assessed. The "Observed" label means the INCD had direct visibility into the incident — not a secondary summary. This gives procedure-level specificity that generic vendor threat intel doesn't reach. Acquired at raw-sources/17-israel-national-cyber-directorate-muddywater-darkbit-pdf/source.pdf.</p><p><strong>INCD 2024 (BugSleep PDF) — Reliability A, Credibility 2</strong></p><p>Same publisher authority as INCD 2023, focused on MuddyWater’s 2024 evolution. Key content: BugSleep backdoor analysis, the specific 43-minute scheduled task beacon interval (which became proc_mw_0006 and det_mw_0006), VPN exploitation, and new RMM tools (Level, PDQConnect). The 43-minute interval is a concrete behavioral fingerprint — not a general TTP category — and it came from direct INCD analysis. Evidence label: Observed / Reported / Assessed. Acquired at raw-sources/18-israel-national-cyber-directorate-technological-advancement-and-evolution-of-muddywater-in/source.pdf.</p><p>The three sources share a common characteristic: they are not secondary aggregators or vendor marketing. They are government authorities with direct incident visibility reporting on specific Israeli campaigns.</p><h4>Steps After Deduplication: What Actually Happened to All 71 Sources</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XeokisYTU_DGw6UH7bLB3w.png"></figure><p>After the AI outputs were merged and deduplicated, 71 candidate sources remained. Here is what happened to them across Steps 5–9:</p><p><strong>Step 5 — Automated Acquisition</strong></p><p>tools/fetch_research_sources.py ran against all 71 URLs. For each source it created a numbered folder under docs/source-gathering/raw-sources/ with:</p><pre>raw-sources/<br>  01-mitre-att-ck-muddywater-g0069/<br>    metadata.json        # URL, fetch timestamp, HTTP status, content-type, size<br>    headers.txt          # Raw HTTP response headers<br>    source.html / source.pdf / source.txt   # Primary file<br>    source.txt           # Text extract (for PDFs and HTML)<br>    fallback-reader.txt  # Reader-mode fallback if primary was blocked or JS-rendered</pre><p>Not all fetches succeeded. Some sources returned 403 (vendor gating), some required JS rendering (only fallback text was captured), and two PDFs were corrupted. The acquisition report at docs/source-gathering/source-acquisition-report.md records the HTTP status, file size, and extraction status for all 71.</p><p><strong>Step 6 — Reliability and Credibility Rating</strong></p><p>Each acquired source was rated using the two-axis rubric. The full assessment table is in docs/source-gathering/source-reliability-evidence-assessment.md. Outcome breakdown:</p><ul><li>Reliability A (government / primary standard): 23 sources</li><li>Reliability B (usually reliable vendor / research publisher): 25 sources</li><li>Reliability C (secondary / news / marketing): 18 sources</li><li>Reliability F (failed acquisition or cannot judge): 5 sources</li></ul><p><strong>Step 7 — Promotion Decision</strong></p><p>Only sources with a combination of Reliability A or B, Credibility 2 or better, a usable acquisition, and at least one procedure-level claim were promoted into data/sources.yaml. The rest were assigned one of: Use as corroboration, Use as comparison only, Defer, or Exclude.</p><p>71 candidates → 8 primary sources promoted into the dataset. The 63 that were not promoted are retained in raw-sources/ for future work; they are not discarded.</p><p><strong>Step 8 — Claim Extraction</strong></p><p>For each promoted source, specific claims were extracted with source binding and evidence labels. A claim is not “MuddyWater uses PowerShell” — it is: “CISA AA22–055A (AA22–055A PDF, p.4) reports that MuddyWater actors deploy PowGoop, a DLL loader that decrypts and executes a PowerShell backdoor (Reported)." This source-bound format prevents claim drift downstream.</p><p><strong>Step 9 — Procedure Candidate Extraction</strong></p><p>From the bound claims, 10 procedure candidates were grouped by tactic: Initial Access, Execution, Persistence, Defense Evasion, Discovery, C2, Credential Access. Each candidate recorded: required telemetry, detection opportunity, whether lab validation was feasible, and whether the procedure appeared in multiple independent sources (a promotion signal for higher confidence scores later).</p><h4>The Full 71-Source Candidate List</h4><p>This is the deduplicated list produced after comparing Gemini and OpenAI outputs. Every source here was an acquisition target for Step 5.</p><p><strong>Core MuddyWater / Seedworm / TA450 / Mango Sandstorm</strong></p><ol><li><a href="https://attack.mitre.org/groups/G0069/">MITRE ATT&amp;CK — MuddyWater G0069</a></li><li><a href="https://attack.mitre.org/software/S0223/">MITRE ATT&amp;CK — POWERSTATS S0223</a></li><li><a href="https://attack.mitre.org/software/S1046/">MITRE ATT&amp;CK — PowGoop S1046</a></li><li><a href="https://www.cisa.gov/news-events/alerts/2022/02/24/iranian-government-sponsored-muddywater-actors-conducting-malicious">CISA alert — Iranian Government-Sponsored MuddyWater Actors Conducting Malicious Cyber Operations</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A advisory page</a></li><li><a href="https://www.cisa.gov/sites/default/files/publications/AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.pdf">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A PDF</a></li><li><a href="https://media.defense.gov/2022/Feb/24/2002944274/-1/-1/0/CSA_AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.PDF">U.S. Cyber Command / Defense media — AA22–055A PDF mirror</a></li><li><a href="https://www.ncsc.gov.uk/news/joint-advisory-observes-muddywater-actors-conducting-cyber-espionage">NCSC-UK — Joint advisory on MuddyWater actor</a></li><li><a href="https://www.iranwatch.org/sites/default/files/cybercom_muddywater_press_release.pdf">U.S. Cyber Command / Iran Watch mirror — Iranian intel cyber suite of malware PDF</a></li><li><a href="https://duo.com/decipher/us-cyber-command-discloses-muddywater-malware-samples">Decipher — US Cyber Command Discloses MuddyWater Malware Samples</a></li><li><a href="https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/">SentinelOne — Wading Through Muddy Waters</a></li><li><a href="https://unit42.paloaltonetworks.com/unit42-muddying-the-water-targeted-attacks-in-the-middle-east/">Palo Alto Unit 42 — Muddying the Water: Targeted Attacks in the Middle East</a></li><li><a href="https://radar.certfa.com/en/insights/cluster/fe272810/">CERTFA Radar — MuddyWater Threat Actor Cluster</a></li><li><a href="https://radar.certfa.com/en/threats/view/d7c9c420/">CERTFA Radar — MuddyWater / Earth Vetala Intrusion</a></li><li><a href="https://www.group-ib.com/masked-actors/muddywater/">Group-IB — MuddyWater APT Group Profile</a></li></ol><p><strong>Israel-Focused MuddyWater Sources</strong></p><ol><li><a href="https://www.gov.il/en/pages/_muddywater">Israel National Cyber Directorate — MuddyWater page</a></li><li><a href="https://www.gov.il/BlobFolder/news/_muddywater/en/government%20threat%20actor.pdf">Israel National Cyber Directorate — MuddyWater / DarkBit PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/maddy_water_2024/en/ALERT_CERT_IL_W_1858.pdf">Israel National Cyber Directorate — Technological Advancement and Evolution of MuddyWater in 2024 PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/alert_1947/he/ALERT-CERT-IL-W-1947.pdf">Israel National Cyber Directorate — Overview of Recent Phishing PDF</a></li><li><a href="https://www.clearskysec.com/operation-quicksand/">ClearSky — Operation Quicksand: MuddyWater’s Offensive Attack Against Israeli Organizations</a></li><li><a href="https://www.clearskysec.com/wp-content/uploads/2020/10/Operation-Quicksand.pdf">ClearSky — Operation Quicksand PDF</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/">Microsoft — MERCURY and DEV-1084: Destructive attack on hybrid environment</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/">Microsoft — Exposing POLONIUM activity and infrastructure targeting Israeli organizations</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta450-uses-embedded-links-pdf-attachments-latest-campaign">Proofpoint — TA450 Uses Embedded Links in PDF Attachments in Latest Campaign</a></li><li><a href="https://harfanglab.io/insidethelab/muddywater-rmm-campaign/">HarfangLab — MuddyWater campaign abusing Atera Agents</a></li><li><a href="https://www.deepinstinct.com/blog/darkbeatc2-the-latest-muddywater-attack-framework">Deep Instinct — DarkBeatC2: The Latest MuddyWater Attack Framework</a></li><li><a href="https://www.scworld.com/brief/novel-c2-tool-leveraged-in-latest-muddywater-attacks">SC Media — Novel C2 tool leveraged in latest MuddyWater attacks</a></li><li><a href="https://blog.checkpoint.com/research/muddywater-threat-group-deploys-new-bugsleep-backdoor/">Check Point — MuddyWater Threat Group Deploys New BugSleep Backdoor</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/">ESET / WeLiveSecurity — MuddyWater: Snakes by the riverbank</a></li><li><a href="https://www.eset.com/uk/about/newsroom/press-releases/iran-muddywater-critical-infrastructure-israel-egypt-snake-game-eset-research-uk/">ESET press release — Iran’s MuddyWater targets critical infrastructure in Israel and Egypt</a></li><li><a href="https://securityaffairs.com/185244/apt/muddywater-strikes-israel-with-advanced-muddyviper-malware.html">Security Affairs — MuddyWater strikes Israel with advanced MuddyViper malware</a></li><li><a href="https://thehackernews.com/2024/03/iran-linked-muddywater-deploys-atera.html">The Hacker News — Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks</a></li></ol><p><strong>Recent / Evolving MuddyWater Activity</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix">Proofpoint — Around the World in 90 Days: State-Sponsored Actors Try ClickFix</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution">Proofpoint — Crossed Wires: a case study of Iranian espionage and attribution</a></li><li><a href="https://www.group-ib.com/blog/muddywater-operation-olalampo/">Group-IB — Operation Olalampo: Inside MuddyWater’s Latest Campaign</a></li><li><a href="https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html">The Hacker News — MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP</a></li><li><a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/">Rapid7 — Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware</a></li><li><a href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html">The Hacker News — MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack</a></li><li><a href="https://www.rapid7.com/research/iran-conflict-cyber-threats/">Rapid7 — Iran Conflict Cyber Threat Intelligence</a></li><li><a href="https://www.extrahop.com/blog/the-digital-front-of-iranian-cyber-offensive-and-defensive-response">ExtraHop — The Digital Front of Iranian Cyber Offensive and Defensive Response</a></li><li><a href="https://abnormal.ai/blog/iran-aligned-cyber-operations-email-threats">Abnormal Security — Tracking Iran-Aligned Cyber Operations Following U.S.-Israel Strikes</a></li><li><a href="https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/">Unit 42 — Boggy Serpens Threat Assessment</a></li><li><a href="https://hivepro.com/threat-advisory/muddywater-irans-adaptive-cyber-espionage-machine/">Hive Pro — MuddyWater: Iran’s Adaptive Cyber Espionage Machine</a></li><li><a href="https://hivepro.com/wp-content/uploads/2026/03/TA2026082.pdf">Hive Pro — MuddyWater / Operation Olalampo PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2024/10/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2024-en.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2024 PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2025/09/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2025-en-2.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2025 PDF</a></li><li><a href="https://documents.trendmicro.com/assets/pdf/Annual_APT_Report_2025.pdf">Trend Micro — Annual APT Report 2025 PDF</a></li><li><a href="https://go.intel471.com/hubfs/Emerging%20Threats/2025%20Emerging%20Threats/Upd%20HUNTER%20-%20Iranian%20Threat%20Actor%20Coverage.pdf">Intel 471 — HUNTER Iranian Threat Actor Coverage PDF</a></li></ol><p><strong>Iran Threat Context and Comparison Actors</strong></p><ol><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran">CISA — Iran Threat Overview and Advisories</a></li><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/iran/publications">CISA — Iran state-sponsored cyber threat publications</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a">CISA — AA23–335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors</a></li><li><a href="https://www.cisa.gov/sites/default/files/2023-12/aa23-335a-irgc-affiliated-cyber-actors-exploit-plcs-in-multiple-sectors-1.pdf">CISA — AA23–335A PDF</a></li><li><a href="https://attack.mitre.org/groups/G0049/">MITRE ATT&amp;CK — APT34</a></li><li><a href="https://attack.mitre.org/groups/G0059/">MITRE ATT&amp;CK — APT35 / Charming Kitten</a></li><li><a href="https://attack.mitre.org/groups/G1030/">MITRE ATT&amp;CK — Agrius</a></li><li><a href="https://www.microsoft.com/en-us/security/security-insider/mint-sandstorm">Microsoft — Mint Sandstorm</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/">Microsoft — Peach Sandstorm deploys new custom Tickler malware</a></li><li><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-threat-actor-naming?view=o365-worldwide">Microsoft Learn — How Microsoft names threat actors</a></li><li><a href="https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/">SentinelOne — Iranian Cyber Activity Outlook</a></li><li><a href="https://mirror.gpmidi.net/vx-underground/Malware%20Analysis/2024/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability/Paper/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability.pdf">Trellix — The Iranian Cyber Capability PDF</a></li></ol><p><strong>OpenCTI / STIX / Knowledge Graph References</strong></p><ol><li><a href="https://docs.opencti.io/latest/usage/data-model/">OpenCTI documentation — Data model</a></li><li><a href="https://docs.opencti.io/latest/reference/api/">OpenCTI documentation — GraphQL API</a></li><li><a href="https://docs.opencti.io/latest/usage/deduplication/">OpenCTI documentation — Deduplication</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html">OASIS — STIX 2.1 HTML specification</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/cs02/stix-v2.1-cs02.pdf">OASIS — STIX 2.1 PDF specification</a></li><li><a href="https://stixproject.github.io/documentation/concepts/relationships/">STIX Project — Relationships</a></li><li><a href="https://arxiv.org/abs/2303.09999">STIXnet — Extracting STIX Objects in CTI Reports</a></li><li><a href="https://arxiv.org/abs/2507.16576">From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction</a></li><li><a href="https://arxiv.org/abs/2605.15904">Context-aware Entity-Relation Extraction for Threat Intelligence Knowledge Graphs</a></li></ol><p><strong>Validate Before Promoting</strong></p><ol><li><a href="https://brandefense.io/wp-content/uploads/2025/10/brandefense.io-muddywater-iran-linked-espionage-group-expanding-global-reach-muddywater-.pdf">Brandefense — MuddyWater PDF</a></li><li><a href="https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/07/KPMG_CTI_Report_muddy.pdf.coredownload.inline.pdf">KPMG — CTI Report MuddyWater PDF</a></li></ol><p><strong>Critical discipline:</strong> AI output was used only for source discovery. Every claim, mapping, and detection record required analyst review before entering the dataset.</p><h3>Phase 2: Procedure Dataset</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ji8MQqr4SpW620AV3QN67A.png"></figure><p>A procedure record is not an ATT&amp;CK technique. ATT&amp;CK describes what a class of actors <em>can</em> do. A procedure record describes what <em>this actor</em> did, in <em>this campaign</em>, as documented by <em>this source</em>, with a specific evidence label attached.</p><p>The distinction matters for detection. “Adversaries use scheduled tasks (T1053.005)” does not help you tune a detection rule. “BugSleep creates a scheduled task with a 43-minute repeat interval (INCD 2024, Observed)” does — because you now have a concrete interval to hunt for, a specific tool name, and a source you can cite in your detection rationale.</p><p>Each of the 10 records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/procedures.yaml">data/procedures.yaml</a> captures four things:</p><ul><li>The specific behavior — not the technique category</li><li>The source references that support it, with evidence labels</li><li>Candidate ATT&amp;CK technique mappings and the reasoning behind each candidate</li><li>Required telemetry, a detection idea, validation plan, and known limitations</li></ul><h4>Confidence Labels</h4><p>Each record carries one of four evidence labels inherited from the source assessment:</p><p><strong>Observed</strong> — the behavior appears directly in source telemetry, a recovered sample, a screenshot, or a government incident report with direct visibility into the event. This is the strongest label and the only one that justifies a high-priority detection without further corroboration.</p><p><strong>Reported</strong> — a source states the behavior occurred, but the evidence is assertion-level rather than artifact-level. Still usable; requires corroboration before relying on it alone.</p><p><strong>Assessed</strong> — the source draws an analytical conclusion based on multiple indicators. Appropriate for ATT&amp;CK candidate mappings; not sufficient alone for a new detection claim.</p><p><strong>Inferred</strong> — analyst conclusion derived from combining multiple reported facts across sources. Weakest label; flag for review before using in production.</p><p>All 10 procedures in this dataset carry <strong>Observed</strong> or <strong>High</strong> confidence. That is not a coincidence — it reflects the promotion threshold. Procedures that came only from secondary or inferred sources were not promoted into data/procedures.yaml; they stayed in the claim extraction notes for future work.</p><h4>The 10 Procedures</h4><p><strong>proc_mw_0001 — Spearphishing Email Delivery</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1566.001, T1566.002, T1534</em></p><p>Three delivery variants documented across all three primary government sources: ZIP attachments containing macro-enabled Excel files or PDFs; email links to Egnyte or OneDrive delivering compressed RMM installers; and emails sent from compromised legitimate accounts to increase lure credibility. In 2024, a Microsoft-update-lure campaign sent to 10,000+ accounts embedded a PowerShell API key, granting the actor direct agent access immediately after the RMM tool installed. Three independent government sources corroborate this procedure — it is the highest-confidence initial access vector in the dataset.</p><p><strong>proc_mw_0002 — Public-Facing Exploitation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1190</em></p><p>Secondary initial access vector to phishing. Documented CVEs: CVE-2020–1472 (Netlogon/Zerologon), CVE-2020–0688 (Exchange), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities confirmed by INCD 2024. Exploitation is typically followed by RMM tool deployment or custom backdoor staging. The VPN claim from INCD 2024 does not name a specific CVE — treat as Reported until a CVE is attributed.</p><p><strong>proc_mw_0003 — PowerShell Execution and Script Obfuscation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1059.001, T1027</em></p><p>Cross-cutting technique present in every tool tier. PowGoop uses an obfuscated .dat + config.txt PowerShell chain for C2 beaconing. POWERSTATS is a persistent PowerShell backdoor. The 2024 lure embedded an API key executed via PowerShell to grant direct agent access. Obfuscation is applied consistently via Base64, XOR, and custom encoding. Detection anchor: Script Block Logging (EID 4104) is the primary telemetry dependency — without it, this procedure is nearly invisible to endpoint-only detection.</p><p><strong>proc_mw_0004 — DLL Side-Loading</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1574.002</em></p><p>PowGoop’s canonical execution method: a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load and execute the malicious DLL. INCD 2024 confirms continued use across the 2024 toolset. Detection requires Sysmon EID 7 (image load) with signing status — not available from Windows Event Log alone. This is the most telemetry-constrained procedure in the dataset; validation was PARTIAL because the lab's stub DLL did not produce sufficient EID 7 signal.</p><p><strong>proc_mw_0005 — Registry Run Key and Startup Folder Persistence</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1547.001</em></p><p>Small Sieve adds index.exe under the Run key named OutlookMicrosift — mimicking a Microsoft application name. Canopy installs its first WSF script in the startup folder. AA22-055A documents an additional key: SystemTextEncoding. INCD 2024 confirms continued use. The specific key names (OutlookMicrosift, SystemTextEncoding) are high-confidence IoCs when present; a detection based only on "new Run key written by a non-installer" will generate noise in most enterprise environments.</p><p><strong>proc_mw_0006 — Scheduled Task (43-Minute Beacon)</strong> <em>Confidence: Observed · Source: INCD 2024 (single source) · ATT&amp;CK: T1053.005</em></p><p>BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing. The interval is documented as customizable, but 43 minutes is the specific value observed in the INCD 2024 analysis. This is a single-source procedure — INCD 2024 only — which is why it carries a coverage score of 4 (correlated analytic) rather than 5 in the detection atlas. Before treating this interval as a high-confidence fingerprint in production, corroborate with a vendor source.</p><p><strong>proc_mw_0007 — RMM Tool Abuse</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024, multiple vendor sources · ATT&amp;CK: T1219</em></p><p>The most consistently documented technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple vendor sources), SimpleHelp, Level, PDQConnect (2024). The 2024 lure embedded an API key so the actor had direct agent access the moment the victim installed the tool. Detection must rely on delivery context and parent process — not binary name alone, since these are legitimate commercial tools.</p><p><strong>proc_mw_0008 — C2 via Web Protocols and DNS Tunneling</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1071.001, T1572, T1102</em></p><p>Multiple C2 channels documented. Small Sieve beacons via Telegram Bot API over HTTPS. Canopy sends collected data via HTTP POST. Blackout uses GET /questions and POST /about-us. AnchorRAT communicates over HTTPS port 443 in JSON format. Mori uses DNS tunneling. In 2024, Rentry.co was used as a legitimate platform for C2 redirection. The Telegram API is the highest-confidence detection anchor: outbound HTTPS to api.telegram.org from a non-browser process is unusual in enterprise environments and directly attributed across multiple sources.</p><p><strong>proc_mw_0009 — WMI System Discovery Survey</strong> <em>Confidence: Observed · Source: AA22–055A (script documented verbatim) · ATT&amp;CK: T1047, T1082, T1016, T1033, T1518.001</em></p><p>MuddyWater runs a PowerShell script that queries WMI to collect: IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username, and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2. The exact script is reproduced in the CISA advisory. The SecurityCenter2 query is the detection anchor: legitimate enterprise software rarely queries this WMI namespace outside AV management contexts, making it a low-noise signal.</p><p><strong>proc_mw_0010 — Credential Dumping from LSASS and Credential Stores</strong> <em>Confidence: Observed · Source: AA22–055A · ATT&amp;CK: T1003.001, T1003.004, T1003.005</em></p><p>Post-access credential access using three tools: Mimikatz and procdump64.exe against LSASS memory (T1003.001); LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005). Used post-exploitation to enable lateral movement with harvested credentials. Detection via Sysmon EID 10 (process accessing lsass.exe) is tool-agnostic — it fires regardless of whether the actor uses Mimikatz, procdump, or a custom variant with a different binary name. This is the most reliable detection path for this procedure.</p><h3>Phase 3: OpenCTI Knowledge Graph</h3><p>The procedure dataset and source register go into a self-hosted OpenCTI 6.2 instance. This creates the analytical record — queryable, relationship-aware, ATT&amp;CK-linked.</p><h3>OpenCTI Deployment</h3><p>The stack used in this project is documented and publicly reproducible. The full deployment — Docker Compose, connectors, and an AI enrichment connector that calls Claude via the Anthropic API — lives in a dedicated project:</p><ul><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200/opencti-intelligent-shield">github.com/anpa1200/opencti-intelligent-shield</a></li></ul><p><a href="https://github.com/anpa1200/opencti-intelligent-shield">GitHub - anpa1200/opencti-intelligent-shield: OpenCTI AI-driven threat intelligence enrichment with Claude and Docusaurus documentation</a></p><ul><li><strong>Medium guide:</strong></li></ul><p><a href="https://medium.com/@1200km/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a></p><ul><li><strong>Main guide:</strong> <a href="https://anpa1200.github.io/opencti-intelligent-shield/">anpa1200.github.io/opencti-intelligent-shield</a></li></ul><p><a href="https://anpa1200.github.io/opencti-intelligent-shield">OpenCTI AI Enrichment | The Intelligent Shield</a></p><p>The Intelligent Shield project covers: OpenCTI core stack (Redis, Elasticsearch, MinIO, RabbitMQ, platform, workers), MITRE ATT&amp;CK connector, and a custom internal enrichment connector that uses Claude to automatically summarize and enrich threat objects. Docker Compose files, a sanitized .env.example, and full setup instructions are all version-controlled.</p><p>To spin up the stack standalone (outside Operation Desert Hydra):</p><pre>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd openCTI<br>cp .env.example .env<br># fill in tokens and passwords<br>./scripts/start-all.sh   # OpenCTI at :8080<br>./scripts/stop-all.sh    # halt, preserves volumes</pre><p>In the context of Operation Desert Hydra the stack is embedded in stack/ and started with bash start.sh — no separate clone needed. The Intelligent Shield project is the standalone reference deployment for anyone who wants OpenCTI without the lab.</p><h4>Step 10: Stack Start</h4><pre>bash start.sh --skip-lab   # starts OpenCTI + Elasticsearch + Kibana only</pre><p>All 12 core containers start: Redis, Elasticsearch, MinIO, RabbitMQ, OpenCTI platform, 3 workers, and the MITRE ATT&amp;CK connector.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_8pjCgFqyge4o-bahQTX6Q.png"></figure><p><strong>Result:</strong> OpenCTI reachable at http://localhost:8080. All containers healthy.</p><h4>Step 11: MITRE ATT&amp;CK Connector Sync</h4><p>The MITRE ATT&amp;CK connector loads 846 techniques into the graph. This sync must complete before the import script can link procedures to techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k4o9xri96voJcB0EUQPqfg.png"></figure><p><strong>Result:</strong> 846 ATT&amp;CK patterns loaded. Connector state: ACTIVE.</p><h4>Step 12: Import Script</h4><p>Script: <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/tools/opencti_import.py"><strong>tools/opencti_import.py</strong></a></p><pre>export OPENCTI_URL=http://localhost:8080<br>export OPENCTI_TOKEN=&lt;admin token from stack/.env&gt;<br>python3 tools/opencti_import.py</pre><p>The script reads data/sources.yaml and data/procedures.yaml — it does not hardcode any intelligence. The YAML files are the single source of truth; the script is just a translation layer from those files into OpenCTI's API.</p><p><strong>What it creates and why:</strong></p><p><strong>Step 1 — Iran MOIS (Identity: Organization).</strong> Every object in OpenCTI needs a createdBy reference. Creating the sponsoring organization first gives all downstream objects a consistent authoring context and makes the attribution relationship explicit in the graph: MuddyWater → attributed-to → Iran MOIS.</p><p><strong>Step 2 — MuddyWater (Intrusion Set).</strong> The intrusion set object carries all known aliases: Seedworm, Mango Sandstorm, TA450, Static Kitten, TEMP.Zagros, Mercury, DEV-1084. Aliases matter for deduplication — OpenCTI uses them to avoid creating duplicate entities when the same actor appears under different names in different reports.</p><p><strong>Step 3 — Malware catalog (9 objects).</strong> Each actor-developed tool gets a Malware object with a description derived from source reporting. The catalog: POWERSTATS, PowGoop, Small Sieve, Canopy, Mori, BugSleep, AnchorRAT, SyncroRAT, DarkBit.</p><p><strong>Step 4 — Tool catalog (4 objects).</strong> Legitimate tools abused by the actor are STIX Tool objects, not Malware — the distinction matters for downstream analysis. The catalog: AteraAgent, SimpleHelp, Mimikatz, LaZagne.</p><p><strong>Step 5 — uses relationships.</strong> MuddyWater → uses → each malware and tool object. These relationships make the graph queryable: “which tools does this actor use?” returns all 13 objects in one hop.</p><p><strong>Step 6 — Reports from sources.yaml.</strong> One Report object per promoted source, with publisher, reliability rating, credibility score, actor claims, key entities, and ATT&amp;CK candidates written into the description. MuddyWater is added as an object reference so each report is queryable from the actor page.</p><p><strong>Step 7 — ATT&amp;CK pattern links from procedures.yaml.</strong> Iterates all attck_candidates across the 10 procedure records and creates MuddyWater → uses → ATT&amp;CK technique relationships. If the MITRE connector has not yet synced a technique, the script creates a stub Attack Pattern object (with x_mitre_id set) and flags it for enrichment. This prevents the import from failing on a timing issue between the connector sync and the import run.</p><p>The script is <strong>idempotent</strong>: every object lookup uses a read() before create(). Re-running after a partial failure or after the MITRE connector syncs simply confirms existing objects and fills in any gaps.</p><pre>#!/usr/bin/env python3<br>"""<br>Desert Hydra — Phase 3 OpenCTI graph import.Reads data/sources.yaml and data/procedures.yaml and creates:<br>  - Identity:       Iran MOIS (organization)<br>  - Intrusion Set:  MuddyWater (with all known aliases)<br>  - Malware:        actor-developed tools (9 objects)<br>  - Tool:           legitimate tools abused (4 objects)<br>  - Reports:        one per promoted source (up to 20)<br>  - Relationships:  attributed-to, uses (malware/tool/ATT&amp;CK)<br>Idempotent - existing objects are not duplicated.<br>ATT&amp;CK pattern links are skipped for techniques not yet synced by the<br>MITRE connector; re-run the script after the MITRE sync completes.<br>Usage:<br>    export OPENCTI_URL=http://localhost:8080<br>    export OPENCTI_TOKEN=&lt;admin-token&gt;<br>    python3 tools/opencti_import.py<br>"""<br>import os<br>import sys<br>import yaml<br>from pathlib import Path<br>from pycti import OpenCTIApiClient<br>from pycti.entities.opencti_identity import IdentityTypes<br># ── Bootstrap ─────────────────────────────────────────────────────────────────<br>OPENCTI_URL   = os.environ.get("OPENCTI_URL",   "http://localhost:8080")<br>OPENCTI_TOKEN = os.environ.get("OPENCTI_TOKEN", "")<br>REPO_ROOT     = Path(__file__).resolve().parent.parent<br>if not OPENCTI_TOKEN:<br>    sys.exit("ERROR: set OPENCTI_TOKEN environment variable")<br>api = OpenCTIApiClient(url=OPENCTI_URL, token=OPENCTI_TOKEN, log_level="error")<br>print(f"[desert-hydra] Connected  {OPENCTI_URL}")<br># ── Load YAML data ─────────────────────────────────────────────────────────────<br>with open(REPO_ROOT / "data" / "sources.yaml") as f:<br>    SOURCES = yaml.safe_load(f)["sources"]<br>with open(REPO_ROOT / "data" / "procedures.yaml") as f:<br>    PROCEDURES = yaml.safe_load(f)["procedures"]<br>print(f"[desert-hydra] Loaded {len(SOURCES)} sources, {len(PROCEDURES)} procedures")<br># ── TLP:WHITE ─────────────────────────────────────────────────────────────────<br>def get_tlp_white():<br>    results = api.marking_definition.list(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "definition", "values": ["TLP:WHITE"]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if results:<br>        return results[0]["id"]<br>    obj = api.marking_definition.create(<br>        definition_type="TLP",<br>        definition="TLP:WHITE",<br>        x_opencti_color="#ffffff",<br>        x_opencti_order=0,<br>    )<br>    return obj["id"]<br>TLP_WHITE = get_tlp_white()<br># ── Helpers ───────────────────────────────────────────────────────────────────<br>def _find(accessor, name):<br>    """Look up a STIX object by name. Returns the object dict or None."""<br>    return accessor.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "name", "values": [name]}],<br>            "filterGroups": [],<br>        }<br>    )<br><br>def link(from_id, to_id, rel_type, confidence=80):<br>    """Create a STIX core relationship; silently skip if it already exists."""<br>    try:<br>        api.stix_core_relationship.create(<br>            fromId=from_id,<br>            toId=to_id,<br>            relationship_type=rel_type,<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>        )<br>    except Exception:<br>        pass<br><br>ATTCK_NAMES = {<br>    "T1574.002": "DLL Side-Loading",<br>    "T1574.001": "DLL Search Order Hijacking",<br>    "T1546.015": "Component Object Model Hijacking",<br>    "T1218.010": "Regsvr32",<br>}<br>def find_or_create_attack_pattern(mitre_id):<br>    """Look up an ATT&amp;CK pattern by x_mitre_id. Create stub if not synced yet."""<br>    result = api.attack_pattern.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "x_mitre_id", "values": [mitre_id]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if result:<br>        return result["id"], False<br>    name = ATTCK_NAMES.get(mitre_id, mitre_id)<br>    obj = api.attack_pattern.create(<br>        name=name,<br>        x_mitre_id=mitre_id,<br>        description=f"MITRE ATT&amp;CK technique {mitre_id}. Created as stub pending MITRE connector sync.",<br>        objectMarking=[TLP_WHITE],<br>        confidence=75,<br>    )<br>    return obj["id"], True<br># ── Step 1: Iran MOIS Identity ────────────────────────────────────────────────<br>existing = _find(api.identity, "Iran MOIS")<br>if existing:<br>    MOIS_ID = existing["id"]<br>else:<br>    obj = api.identity.create(<br>        type=IdentityTypes.ORGANIZATION.value,<br>        name="Iran MOIS",<br>        description=(<br>            "Iranian Ministry of Intelligence and Security (MOIS). "<br>            "State sponsor attributed to MuddyWater cyber operations by CISA, FBI, "<br>            "CNMF, NCSC-UK, and NSA in joint advisory AA22-055A (February 2022)."<br>        ),<br>        objectMarking=[TLP_WHITE],<br>        confidence=85,<br>    )<br>    MOIS_ID = obj["id"]<br># ── Step 2: MuddyWater Intrusion Set ──────────────────────────────────────────<br>existing = _find(api.intrusion_set, "MuddyWater")<br>if existing:<br>    MW_ID = existing["id"]<br>else:<br>    obj = api.intrusion_set.create(<br>        name="MuddyWater",<br>        aliases=[<br>            "Seedworm", "Mango Sandstorm", "TA450",<br>            "Static Kitten", "TEMP.Zagros", "Mercury", "DEV-1084",<br>        ],<br>        description=(<br>            "Iranian MOIS subordinate threat group active since at least 2017. "<br>            "Targets government, defense, telecom, oil and gas, and MSPs globally. "<br>            "Significant focus on Israeli organizations since 2022. Known for "<br>            "spearphishing, RMM tool abuse, and a shift toward in-house tooling "<br>            "(BugSleep, AnchorRAT) beginning ~May 2024."<br>        ),<br>        resource_level="government",<br>        primary_motivation="espionage",<br>        confidence=85,<br>        objectMarking=[TLP_WHITE],<br>        createdBy=MOIS_ID,<br>    )<br>    MW_ID = obj["id"]<br>link(MW_ID, MOIS_ID, "attributed-to", 85)<br># ── Step 3: Malware catalog ────────────────────────────────────────────────────<br>MALWARE_CATALOG = [<br>    {"name": "POWERSTATS",  "aliases": ["Powermud"],   "description": "MuddyWater first-stage PowerShell backdoor (MITRE S0223)."},<br>    {"name": "PowGoop",     "aliases": ["Goopdate"],   "description": "DLL loader hijacking GoogleUpdate.exe via side-loading (MITRE S1046)."},<br>    {"name": "Small Sieve", "aliases": [],             "description": "Python backdoor compiled as NSIS; Telegram Bot API C2; OutlookMicrosift Run key."},<br>    {"name": "Canopy",      "aliases": ["Starwhale"],  "description": "Excel-macro dropper; startup folder persistence; HTTP POST C2."},<br>    {"name": "Mori",        "aliases": [],             "description": "DNS-tunneling backdoor deployed as FML.dll via regsvr32.exe."},<br>    {"name": "BugSleep",    "aliases": [],             "description": "In-house backdoor (2024); 43-minute scheduled task; shellcode injection."},<br>    {"name": "AnchorRAT",   "aliases": [],             "description": "Custom RAT (2024); COM hijacking persistence (T1546.015)."},<br>    {"name": "SyncroRAT",   "aliases": [],             "description": "RMM-based RAT; Technion campaign (Feb 2023); Log4j initial access."},<br>    {"name": "DarkBit",     "aliases": [],             "description": "Ransomware/wiper; Technion attack; vssadmin shadow copy deletion."},<br>]<br>MALWARE_IDS = {}<br>for m in MALWARE_CATALOG:<br>    existing = _find(api.malware, m["name"])<br>    if existing:<br>        MALWARE_IDS[m["name"]] = existing["id"]<br>    else:<br>        obj = api.malware.create(<br>            name=m["name"], aliases=m["aliases"],<br>            description=m["description"], is_family=False,<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        MALWARE_IDS[m["name"]] = obj["id"]<br># ── Step 4: Tool catalog ──────────────────────────────────────────────────────<br>TOOL_CATALOG = [<br>    {"name": "AteraAgent",  "aliases": ["Atera RMM"], "description": "Commercial RMM abused for persistent remote access via phishing."},<br>    {"name": "SimpleHelp",  "aliases": [],            "description": "Commercial RMM abused in 2024 Israeli targeting."},<br>    {"name": "Mimikatz",    "aliases": [],            "description": "LSASS credential dumping (T1003.001), used with procdump64.exe."},<br>    {"name": "LaZagne",     "aliases": [],            "description": "LSA secrets (T1003.004) and cached domain credential dumping (T1003.005)."},<br>]<br>TOOL_IDS = {}<br>for t in TOOL_CATALOG:<br>    existing = _find(api.tool, t["name"])<br>    if existing:<br>        TOOL_IDS[t["name"]] = existing["id"]<br>    else:<br>        obj = api.tool.create(<br>            name=t["name"], aliases=t["aliases"],<br>            description=t["description"],<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        TOOL_IDS[t["name"]] = obj["id"]<br># ── Step 5: uses relationships ────────────────────────────────────────────────<br>for mid in MALWARE_IDS.values():<br>    link(MW_ID, mid, "uses", 80)<br>for tid in TOOL_IDS.values():<br>    link(MW_ID, tid, "uses", 80)<br># ── Step 6: Reports from sources.yaml ────────────────────────────────────────<br>SOURCE_DATES = {<br>    "src_usgov_aa22_055a_pdf_mirror":        "2022-02-24T00:00:00.000Z",<br>    "src_incd_muddywater_darkbit_2023":      "2023-02-07T00:00:00.000Z",<br>    "src_incd_muddywater_2024_evolution":    "2024-06-01T00:00:00.000Z",<br>    "src_cisa_aa22_055a_page":               "2022-02-24T00:00:00.000Z",<br>    "src_ncsc_uk_muddywater_joint_advisory": "2022-02-24T00:00:00.000Z",<br>    "src_incd_recent_phishing_1947":         "2024-09-01T00:00:00.000Z",<br>    "src_mitre_attack_muddywater_g0069":     "2024-01-01T00:00:00.000Z",<br>}<br>REPORT_IDS = {}<br>for src in SOURCES:<br>    src_id   = src["id"]<br>    title    = src["title"]<br>    pub_date = SOURCE_DATES.get(src_id, "2023-01-01T00:00:00.000Z")<br>    confidence = 85 if src.get("source_reliability") == "A" else 70<br>    description = (<br>        f"Publisher: {src['publisher']}\n"<br>        f"Reliability: {src.get('source_reliability','?')} / "<br>        f"Credibility: {src.get('information_credibility','?')}\n"<br>        f"URL: {src['url']}\n"<br>        f"Actor claims: {', '.join(src.get('actor_claims', []))}\n"<br>        f"ATT&amp;CK candidates: {', '.join(src.get('candidate_attck_techniques', []))}"<br>    )<br>    existing = _find(api.report, title)<br>    if existing:<br>        REPORT_IDS[src_id] = existing["id"]<br>    else:<br>        obj = api.report.create(<br>            name=title, published=pub_date,<br>            description=description,<br>            report_types=["threat-report"],<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>            createdBy=MOIS_ID,<br>            objects=[MW_ID],<br>        )<br>        REPORT_IDS[src_id] = obj["id"]<br># ── Step 7: ATT&amp;CK pattern links from procedures ──────────────────────────────<br>linked, stubs = set(), []<br>for proc in PROCEDURES:<br>    for candidate in proc.get("attck_candidates", []):<br>        tid = candidate["technique"]<br>        if tid in linked:<br>            continue<br>        pattern_id, created_as_stub = find_or_create_attack_pattern(tid)<br>        link(MW_ID, pattern_id, "uses", 75)<br>        linked.add(tid)<br>        if created_as_stub:<br>            stubs.append(tid)<br># ── Summary ───────────────────────────────────────────────────────────────────<br>print(f"Import complete - malware: {len(MALWARE_IDS)}, tools: {len(TOOL_IDS)}, "<br>      f"reports: {len(REPORT_IDS)}, ATT&amp;CK links: {len(linked)}, stubs: {len(stubs)}")<br></pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WMvnfWfF50hj3Rk60DBAxA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XMTEbgDPokzU9iTK3sjEww.png"></figure><p><strong>Result:</strong> All objects created. Re-run confirms idempotency (no duplicates).</p><h4>Step 13: Intrusion Set Verification</h4><p><strong>Result:</strong> MuddyWater entity with all aliases, Iran MOIS attribution relationship, campaign links, and malware/tool associations confirmed in OpenCTI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5KWUHIP3nkUhF6wpQpDa3g.png"></figure><h4>Step 14: Knowledge Graph</h4><p><strong>Result:</strong> Graph shows MuddyWater → 9 malware, 4 tools, 3 campaigns, 21 ATT&amp;CK techniques — all with source-annotated relationship edges.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-B2D00HhbhmdA5rtGm7klA.png"></figure><h4>Step 15: ATT&amp;CK Matrix Coverage</h4><p><strong>Result:</strong> 21 techniques highlighted across 8 tactics in the ATT&amp;CK Enterprise matrix.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4XphzS2vtf-peVJ-ArTglg.png"></figure><h4>Step 16: BugSleep Malware Detail</h4><p><strong>Result:</strong> BugSleep malware object with INCD 2024 source annotation, T1053.005 relationship (43-minute task), and C2 technique links confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3rt63a6jCO_-fk-BLdyaTw.png"></figure><h4>Step 17: Reports List</h4><p><strong>Result:</strong> 20 report objects, one per promoted source. Each report links to the procedures and techniques it evidences.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-Ej71hGDspW3ahdqZWATAA.png"></figure><h4>Step 19: OpenCTI Dashboard</h4><p><strong>Result:</strong> Custom dashboard showing technique frequency heatmap by source tier — highest-corroborated techniques visible at a glance.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HccHBJxzb-ZZu93WImMhg.png"></figure><h3>Phase 4: Detection Atlas</h3><p>The detection atlas is the core analytical output. Each of the 11 detection records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/detections.yaml">data/detections.yaml</a> contains:</p><ul><li>The specific MuddyWater behavior it targets (not the ATT&amp;CK technique category)</li><li>Required log sources and capability gates</li><li>Multi-rule pseudologic (SIEM-agnostic — works as a template for Sigma, KQL, SPL, or any rule format)</li><li>False positive classes and tuning guidance</li><li>A creation_logic field explaining <em>why</em> the rule is designed this way — the design decision, not just what the rule does</li></ul><p>Coverage scores follow a strict scale: <strong>5</strong> = lab-validated with a Kibana screenshot. <strong>4</strong> = correlated analytic (good logic, single source or partial lab). <strong>3</strong> = behavioral detection with partial validation. A score of 5 requires a proof, not just passing pseudologic.</p><p><strong>Step 20 — Analyst Review</strong></p><p>Before any detection went to validation, every record went through a review pass that checked: operator precedence in multi-clause conditions, access mask completeness for LSASS detection, path allowlist accuracy for the GoogleUpdate/Goopdate IoC, and ATT&amp;CK technique coverage gaps. The review fixed a real operator precedence bug in det_mw_0010 Rule B where the command_line clause was outside the event_type guard, tightened the LSASS access mask set, improved T1033 coverage in det_mw_0009 Rule C via Win32_ComputerSystem, and added the x86/x64 Google installation path allowlist to det_mw_0004 Rule A.</p><h4>det_mw_0001 — Email Delivery Correlated with Process Spawn</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/796/1*ycAoCbrkdxo6oxx4X0Gkhw.png"></figure><p><em>Techniques: T1566.001, T1566.002 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater delivers malicious content three ways — ZIP or Office macro attachments, links to Egnyte/OneDrive delivering RMM installers, and emails from compromised accounts. Corroborated by CISA AA22–055A, INCD 2023, and INCD 2024. The highest-priority initial access vector in the dataset.</p><p><strong>Why it’s built this way:</strong> Email delivery alone is not a detection signal — MuddyWater’s phishing emails are indistinguishable from legitimate mail at the gateway layer. The detection value comes from correlating delivery with a process spawn on the recipient endpoint within a tight 5-minute window. The parent process constraint (Outlook, browser) is the key limiter: it restricts scope to email-triggered or link-triggered execution, which is exactly the documented delivery chain. Both attachment-based and link-based delivery methods are covered because all variants are source-confirmed. The correlated logic type reflects that neither event alone is sufficient — only the combination is meaningful.</p><p><strong>Required telemetry:</strong> Email gateway or SEG with attachment metadata and URL extraction. EDR or Sysmon Event ID 1 with parent image and command line. Without the gateway telemetry, this detection degrades to parent-process heuristics only and loses the delivery-correlation value.</p><pre>event_type IN [email_delivery] AND<br>  (attachment.extension IN ["zip","xlsx","xlsm","pdf","docm"] OR<br>   link.domain IN ["egnyte.com","onedrive.live.com","1drv.ms"])<br>CORRELATE WITHIN 300 seconds WITH<br>event_type IN [process_create] WHERE<br>  parent_image IN ["OUTLOOK.EXE","chrome.exe","firefox.exe","msedge.exe"] AND<br>  image IN ["powershell.exe","cmd.exe","wscript.exe","mshta.exe",<br>            "AteraAgent.exe","ScreenConnect.exe","SimpleHelp.exe","rport.exe"]</pre><p><strong>Key false positives:</strong> Legitimate macro-enabled Office files from internal users. IT-approved RMM tools deployed via email links during onboarding. Tune by excluding known sender domains and approved RMM deployment windows.</p><h4>det_mw_0002 — Web Service Spawning Interpreter Shell</h4><p><em>Techniques: T1190 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater uses public-facing exploitation as a secondary initial access vector — CVE-2020–0688 (Exchange), CVE-2020–1472 (Netlogon/Zerologon), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities from INCD 2024.</p><p><strong>Why it’s built this way:</strong> The detection targets the post-exploitation moment — a web service spawning a shell — rather than the exploit payload itself. This is deliberately CVE-agnostic: it fires on CVE-2020–0688, CVE-2020–1472, Log4j, and any unnamed VPN vulnerability without needing individual exploit signatures. The parent process list maps directly to the documented CVEs: w3wp.exe covers Exchange and IIS, java.exe covers Log4j, lsass.exe covers Netlogon exploitation leading to SYSTEM-level shell creation. The SYSTEM integrity level filter is the key noise reducer — legitimate administrative scripts rarely run at SYSTEM under IIS application pools without a clear documented reason.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with full parent-child chain and integrity level. IDS/IPS for CVE-specific signatures as a complementary layer.</p><pre>event_type = process_create AND<br>parent_image IN ["w3wp.exe","java.exe","lsass.exe","services.exe",<br>                 "vmtoolsd.exe","vpnagent.exe"] AND<br>image IN ["cmd.exe","powershell.exe","wscript.exe","cscript.exe","bash.exe"] AND<br>(parent_user IN ["NETWORK SERVICE","IIS_IUSRS","SYSTEM"] OR<br> integrity_level = "System")</pre><p><strong>Key false positives:</strong> Legitimate administrative scripts under IIS application pools. Java-based monitoring agents that spawn processes. Tune by process hash allowlisting for known-good management tools.</p><h4>det_mw_0003 — PowerShell Encoded Command and Script Obfuscation</h4><p><em>Techniques: T1059.001, T1027 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> PowerShell obfuscation is a cross-cutting technique present in every MuddyWater tool tier — PowGoop (Base64 C2 setup), POWERSTATS (IEX + web request for stage delivery), and the 2024 lure campaigns (embedded API key executed via PowerShell). Three distinct usage patterns across tools required three rules.</p><p><strong>Why it’s built this way:</strong> Each rule targets a different MuddyWater PowerShell pattern with a different telemetry requirement.</p><p>Rule A targets PowGoop and POWERSTATS loader delivery. The regex \s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,} is deliberately written to match all unambiguous prefix forms of -EncodedCommand (-e, -ec, -en, -enc) while the 50-character minimum for the Base64 blob avoids matching the -Encoding parameter. This is the operator precision that matters: -Encoding UTF8 would otherwise match a naive regex.</p><p>Rule B targets POWERSTATS script execution behavior: IEX combined with a web request. This is the decoded content layer — it requires Script Block Logging (Event ID 4104), which is the capability gate that determines whether this detection class exists at all in a given environment.</p><p>Rule C is the delivery-context fallback: PowerShell spawned by an Office application, email client, or browser has no legitimate explanation in a standard enterprise environment and fires regardless of whether Script Block Logging is enabled.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rule B and for the highest-fidelity version of this detection. Sysmon Event ID 1 for Rules A and C. Without Script Block Logging, the detection degrades to command-line heuristics only.</p><pre># Rule A — Encoded command flag (all prefix forms: -e, -ec, -en, -enc ...)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line IMATCHES "\s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,}"</pre><pre># Rule B — Script Block content (Event ID 4104)<br>event_type = script_block_log AND<br>script_block_text MATCHES "(IEX|Invoke-Expression|InvokeScript)" AND<br>script_block_text MATCHES "(WebClient|Invoke-WebRequest|DownloadString|Net\.Http)"</pre><pre># Rule C — Suspicious parent process<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>parent_image IN ["OUTLOOK.EXE","winword.exe","excel.exe",<br>                 "chrome.exe","firefox.exe","msedge.exe","WScript.exe"]</pre><p><strong>Key false positives:</strong> Administrative scripts using -EncodedCommand for special characters. SCCM/Ansible deployments running Base64-encoded payloads. Baseline known-good encoded commands by hash before alerting on Rule A.</p><h4>det_mw_0004 — Unsigned DLL Loaded by Signed Executable</h4><p><em>Techniques: T1574.002 · Score: 3 (behavioral, partial validation)</em></p><p><strong>What it targets:</strong> PowGoop’s execution method — a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load it. Confirmed in 2024 toolset by INCD 2024.</p><p><strong>Why it’s built this way:</strong> Two rules serve different confidence tiers. Rule A is sourced directly from the documented PowGoop technique: the specific process name (GoogleUpdate.exe), DLL name (Goopdate.dll), and the fact that any path outside the Google installation directories is anomalous. The allowlist covers both x86 and x64 installation paths because omitting either creates a bypass. This combination — specific binary, specific DLL name, path outside expected directory — is near-unique and fires with high precision. Rule B is the generic behavioral net for future DLL side-loading variants where the actor may use different binary names — it trades precision for coverage against toolset evolution.</p><p>Score is 3 (not 5) because the lab’s stub DLL did not produce sufficient Sysmon EID 7 signal during validation. The detection logic is sound; the telemetry dependency (Sysmon image load events with signing status) is the constraint.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 7 (ImageLoad) with signed/unsigned status — this is the hard dependency. Without it, DLL loads are invisible to SIEM-based detection.</p><pre># Rule A — Specific IoC: GoogleUpdate loading Goopdate from non-Google path<br>event_type = image_load AND<br>image ENDSWITH "GoogleUpdate.exe" AND<br>loaded_image ENDSWITH "Goopdate.dll" AND<br>NOT (loaded_image_path STARTSWITH "C:\Program Files (x86)\Google\" OR<br>     loaded_image_path STARTSWITH "C:\Program Files\Google\")</pre><pre># Rule B — Generic: signed process loading unsigned DLL from user-writable path<br>event_type = image_load AND<br>process_signed = true AND<br>loaded_image_signed = false AND<br>loaded_image_path MATCHES "(\\Users\\|\\AppData\\|\\Temp\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> Third-party software shipping unsigned DLLs alongside signed executables (common). Developer workstations with locally compiled DLLs. Rule B requires environment-specific tuning before production deployment.</p><h4>det_mw_0005 — Registry Run Key and Startup Folder Persistence</h4><p><em>Techniques: T1547.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Multiple MuddyWater malware families use Run key persistence with actor-specific value names. Small Sieve: OutlookMicrosift (deliberate typo mimicking Microsoft). AA22-055A documents a second key: SystemTextEncoding. Canopy installs a WSF script in the startup folder — a sub-technique that doesn't appear as a Run key write.</p><p><strong>Why it’s built this way:</strong> Three rules cover three distinct persistence mechanisms across the malware catalog. Rule A is an exact-match IoC alert on the two named value names — it fires immediately on any match without needing path or parent context, because these specific strings have no legitimate usage in a standard enterprise environment. Rule B is the behavioral safety net for unknown or renamed values: path heuristic (AppData/Temp) combined with a non-installer parent covers the common pattern of malware writing its own persistence without using an installer. The process_integrity_level filter removes high-integrity (admin-level) processes from the behavioral rule because legitimate software installers typically run elevated. Rule C is added specifically to cover Canopy's startup folder WSF persistence, which doesn't show up as a Run key write at all — it's a file creation event.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 13 (registry value set) for Rules A and B. Sysmon Event ID 11 (file create) for Rule C.</p><pre># Rule A — Specific IoC: known MuddyWater Run key value names<br>event_type = registry_set AND<br>registry_key MATCHES "\\CurrentVersion\\Run" AND<br>registry_value_name IN ["OutlookMicrosift","SystemTextEncoding"]<br><br><br># Rule B - Behavioral: Run key pointing to writable/unusual path<br>event_type = registry_set AND<br>registry_key MATCHES "(HKCU|HKLM)\\.*\\CurrentVersion\\Run" AND<br>registry_value_data MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>process_image NOT IN ["msiexec.exe","setup.exe","install.exe","update.exe"] AND<br>process_integrity_level NOT IN ["High","System"]<br># Rule C - Script files written to startup folder (covers Canopy WSF)<br>event_type = file_create AND<br>file_path MATCHES "\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\" AND<br>file_extension IN ["wsf","vbs","js","ps1","bat","cmd"]</pre><p><strong>Key false positives:</strong> Rule A has essentially zero false positives on the specific value names. Rule B requires installer process exclusion — the list is environment-specific. Rule C may fire on legitimate startup scripts deployed by IT via Group Policy; exclude by file hash or signer.</p><h4>det_mw_0006 — Scheduled Task with 43-Minute Beacon Interval</h4><p><em>Techniques: T1053.005 · Score: 4 (correlated analytic)</em></p><p><strong>What it targets:</strong> BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing — a specific behavioral fingerprint documented in the INCD 2024 report. The interval is documented as customizable, but 43 minutes is the observed operational value.</p><p><strong>Why it’s built this way:</strong> The 43-minute interval is the single most precise artifact in the entire procedure dataset. Rule A is designed as a high-fidelity immediate alert requiring no tuning: PT43M is the ISO 8601 duration format for 43 minutes and appears verbatim in the Windows Task XML. This fires with near-zero false positives because no legitimate software uses a 43-minute repeat interval for any standard purpose. Rule B generalizes the pattern for future BugSleep variants that may use a different interval: short repetition (under 60 minutes) combined with a task action pointing to a user-writable path is anomalous regardless of exact interval. Rule C is the telemetry fallback — many environments do not forward Task Scheduler event logs to SIEM, but schtasks.exe process creation (Sysmon EID 1) is more commonly collected and captures the command line.</p><p>Score is 4 (not 5) because this is a single-source procedure — INCD 2024 only. Before treating Rule A as a high-confidence production alert, corroborate with a second vendor source.</p><p><strong>Required telemetry:</strong> Windows Security Event ID 4698 (scheduled task created) or Task Scheduler operational log for Rules A and B. Sysmon Event ID 1 for Rule C.</p><pre># Rule A — Specific: 43-minute interval (BugSleep artifact) — immediate alert<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval = "PT43M"<br><br># Rule B - Behavioral: short interval + suspicious action path<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval_minutes &lt; 60 AND<br>task_action_path MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>creating_process NOT IN ["svchost.exe","taskeng.exe","msiexec.exe"]<br># Rule C - Sysmon command line fallback<br>event_type = process_create AND<br>image ENDSWITH "schtasks.exe" AND<br>command_line MATCHES "/create" AND<br>command_line MATCHES "(AppData|Temp|ProgramData)"</pre><p><strong>Key false positives:</strong> Backup and monitoring software creating frequent tasks. Browser update mechanisms. Rule B requires interval baseline per environment before production deployment.</p><h4>det_mw_0007 — RMM Tool Executed from User-Writable Path</h4><p><em>Techniques: T1219 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> RMM tool abuse is the most consistently documented MuddyWater technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple sources), SimpleHelp, Level, PDQConnect (2024).</p><p><strong>Why it’s built this way:</strong> RMM tool detection is inherently a context problem. The binary is legitimate. The network traffic to vendor infrastructure is legitimate. Only the delivery chain and execution path are anomalous. Three rules address this from different angles.</p><p>Rule A uses path as the primary signal: a legitimately IT-deployed RMM tool installs to Program Files or a managed path, not AppData/Temp/Downloads. A known RMM binary executing from a user-writable path means it was delivered, not installed by IT.</p><p>Rule B uses parent process as the signal: no legitimate RMM deployment is spawned by Outlook, a browser, or an archive utility. This is the delivery-context constraint — if an RMM binary’s parent is OUTLOOK.EXE, the delivery chain is phishing regardless of what the binary is.</p><p>Rule C uses network destination: RMM infrastructure connections from endpoints with no authorized RMM deployment are anomalous. Rules A+C together — RMM binary from writable path plus outbound connection to vendor domain — form the highest-confidence combined signal.</p><p><strong>The baseline prerequisite is non-negotiable.</strong> Rule C without a baseline of authorized RMM deployments per endpoint generates constant noise in any environment that legitimately uses RMM tools. This is the single highest-ROI detection in the dataset if the baseline is clean.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with parent image and file path. Network flow or proxy logs with process name attribution for Rule C.</p><pre># Rule A — Known RMM binary from non-standard installation path<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR<br> image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR<br> image ENDSWITH "rport.exe" OR<br> image ENDSWITH "SyncroRAT.exe" OR<br> image ENDSWITH "Level.exe" OR<br> image ENDSWITH "PDQConnect.exe") AND<br>image_path MATCHES "(\\AppData\\|\\Temp\\|\\Downloads\\|\\Users\\[^\\]+\\Desktop\\)"<br><br># Rule B - RMM binary spawned by email client or browser<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR image ENDSWITH "rport.exe") AND<br>parent_image IN ["OUTLOOK.EXE","outlook.exe","chrome.exe","firefox.exe",<br>                 "msedge.exe","7zFM.exe","WinRAR.exe","explorer.exe"]<br># Rule C - Outbound connection to RMM vendor infrastructure from unexpected endpoint<br>event_type = network_connection AND<br>destination_domain MATCHES "(atera\.com|screenconnect\.com|simplehelp\.net|syncromsp\.com)" AND<br>source_process NOT IN [known_rmm_processes_baseline]</pre><p><strong>Key false positives:</strong> All RMM tools are legitimate software — the entire detection depends on delivery context and path. Authorized deployments must be baselined per endpoint before any rule produces useful signal. Help desk technicians installing RMM from their downloads folder will match Rule A; exclude by user account or machine type.</p><h4>det_mw_0008a — Non-Browser Process Connecting to Telegram Bot API</h4><p><em>Techniques: T1071.001, T1102 · Score: 3 (behavioral, partially validated)</em></p><p><strong>What it targets:</strong> Small Sieve beacons exclusively via the Telegram Bot API (api.telegram.org) over HTTPS. This is one of the most specific C2 channels documented for MuddyWater — a fixed, known hostname with no CDN rotation.</p><p><strong>Why it’s built this way:</strong> The detection is single-rule because the signal is specific enough not to need graduated fallbacks. api.telegram.org is a fixed hostname. The discriminating condition is not the domain but the process: in enterprise environments where Telegram is not a standard application, any process connecting to this endpoint is anomalous. The approach is deliberately narrow — it will miss if MuddyWater switches from Telegram to another messaging API, but fires with high precision on the documented Small Sieve C2 channel.</p><p>Score is 3 because VirtualBox NAT blocked outbound Telegram connections in the lab, preventing full Kibana validation of the network connection event.</p><p><strong>Required telemetry:</strong> DNS query logs or network flow logs with process name attribution. In environments without process-attributed network telemetry, this degrades to a domain-based alert with no process context.</p><pre>event_type = network_connection AND<br>destination_domain = "api.telegram.org" AND<br>destination_port = 443 AND<br>source_process NOT IN ["Telegram.exe","telegram.exe","chrome.exe",<br>                        "firefox.exe","msedge.exe","iexplore.exe"]</pre><p><strong>Key false positives:</strong> Telegram desktop application where it is approved. Bot developers testing scripts from dev workstations. In organizations where Telegram is standard, strict process allowlisting is required before this detection is useful.</p><h4>det_mw_0008b — DNS Tunneling Volume and Entropy</h4><p><em>Techniques: T1572 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Mori, MuddyWater’s DNS-tunneling backdoor, uses DNS queries as the C2 channel. DNS tunneling encodes data in subdomain labels, producing distinctive patterns: high query volume to a single domain, unusually long subdomain strings, and high Shannon entropy in the label content.</p><p><strong>Why it’s built this way:</strong> DNS tunneling detection cannot rely on a single heuristic because each heuristic has a different failure mode. Volume (Rule A) catches high-throughput tunneling but misses slow/low-rate tools that deliberately throttle to blend in. Label length (Rule B) catches encoded payloads regardless of rate or entropy but misses short encoded segments. Entropy (Rule C) catches random-looking subdomains at any length and rate but produces noise on CDN hash labels without a comprehensive baseline. The three rules are additive — any single trigger warrants investigation, two or more from the same source are high-confidence.</p><p>The thresholds (&gt;100 queries per 60 seconds, &gt;40-character labels, &gt;3.5 Shannon entropy) were validated in the lab by generating 180 DNS queries with 42-character random subdomains from the simulation playbook.</p><p><strong>Required telemetry:</strong> DNS resolver logs with full QNAME — not available in all environments. If only DNS flow logs (not query content) are available, Rule B and Rule C are unavailable.</p><pre># Rule A — High query volume to single parent domain<br>event_type = dns_query<br>GROUP BY source_ip, query_domain_parent<br>HAVING COUNT(*) &gt; 100 WITHIN 60 seconds<br><br># Rule B - Long subdomain labels (&gt;40 chars indicates encoded payload)<br>event_type = dns_query AND<br>LENGTH(subdomain_label) &gt; 40<br># Rule C - High entropy subdomains (random-looking encoded content)<br>event_type = dns_query AND<br>SHANNON_ENTROPY(subdomain_label) &gt; 3.5 AND<br>subdomain_label NOT IN [known_cdn_domains_baseline]</pre><p><strong>Key false positives:</strong> CDN domains using hash-based subdomains (Akamai, Cloudflare, AWS) — require comprehensive allowlist for Rule C. DNSSEC validation traffic with long encoded keys. Calibrate thresholds against your specific environment’s DNS baseline before deploying Rule A in production.</p><h4>det_mw_0009 — WMI SecurityCenter2 Discovery Survey</h4><p><em>Techniques: T1047, T1082, T1016, T1033, T1518.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> CISA AA22–055A reproduces the exact PowerShell survey script MuddyWater uses post-access: a WMI query chain that collects IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username (Win32_ComputerSystem), and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2.</p><p><strong>Why it’s built this way:</strong> The detection anchors on SecurityCenter2\AntiVirusProduct because it is the highest-specificity WMI class in the documented survey. The other classes — OS name, IP addresses, hostname — are queried by dozens of legitimate monitoring tools. AntiVirusProduct enumeration has a much smaller legitimate caller population: primarily AV management consoles and endpoint security platforms. This makes it the most reliable low-noise signal from the full survey chain.</p><p>Three rules are layered by telemetry quality. Rule A requires Script Block Logging (highest fidelity, decoded script content visible). Rule B falls back to command-line logging — medium fidelity, only fires if SecurityCenter2 appears in the literal command line, not in a decoded payload. Rule C is the most specific: a multi-class pattern that matches the complete documented survey chain, covering all five ATT&amp;CK techniques in a single event. T1033 coverage was added to Rule C via Win32_ComputerSystem during the analyst review pass — it was missing from the initial draft.</p><p>Rule C matches the CISA-documented script closely enough to be treated as near-exact-match when observed.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rules A and C. Sysmon Event ID 1 for Rule B.</p><pre># Rule A — Script Block captures SecurityCenter2 query<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "AntiVirusProduct"<br><br># Rule B - Process command line contains SecurityCenter2 (fallback without SBL)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line MATCHES "SecurityCenter2"<br># Rule C - Full survey pattern: all 5 ATT&amp;CK techniques in one event<br># T1518.001 (AV enum) + T1016 (network config) + T1082 (OS info) + T1033 (username)<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "Win32_NetworkAdapterConfiguration" AND<br>script_block_text MATCHES "Win32_OperatingSystem" AND<br>script_block_text MATCHES "(Win32_ComputerSystem|Win32_UserAccount|UserName)"</pre><p><strong>Key false positives:</strong> AV management software and endpoint security platforms querying SecurityCenter2. IT inventory tools (Lansweeper, SCCM hardware inventory). Exclude by process hash or signer rather than by process name, since attackers can rename their scripts.</p><h4>det_mw_0010 — LSASS Memory Access and Credential Tool Execution</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/699/1*J0Q8ExDAG7jBY7duoI35MA.png"></figure><p><em>Techniques: T1003.001, T1003.004, T1003.005 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater performs credential access using three tools documented in CISA AA22–055A: Mimikatz and procdump64.exe against LSASS memory (T1003.001), and LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005).</p><p><strong>Why it’s built this way:</strong> Three independent rules cover the full credential dumping lifecycle, each with a different detection philosophy.</p><p>Rule A is the design priority: a process accessing LSASS memory is the universal pre-condition for any LSASS dump, regardless of tool. Detecting the access event (Sysmon EID 10) rather than the tool name means Rule A fires on Mimikatz, procdump, custom C++ loaders, and any future variant — as long as the access mask is in the covered set. The access masks were sourced from established Mimikatz research (0x1010, 0x1410, 0x1438, 0x143a, 0x1418) and extended with 0x1fffff (PROCESS_ALL_ACCESS, used by custom dumpers) and 0x1f0fff (another all-access variant observed in the field). The exclusion list covers known legitimate callers — AV engines, CSrss, WinInit — without which this rule generates constant noise from endpoint security products.</p><p>Rule B is the name-based backstop. Lower fidelity because it misses renamed tools, but catches actors using stock Mimikatz. The analyst review pass re-bracketed the command_line clause to keep it inside the event_type guard — a real operator precedence bug that would have caused the command-line check to match events outside the process_create filter.</p><p>Rule C catches the dump artifact on disk — a final fallback when process-level events are unavailable. .dmp files in user-writable paths are anomalous outside of Windows Error Reporting, which writes to a fixed known path.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 10 (ProcessAccess) with explicit lsass.exe targeting in the Sysmon configuration — this is not enabled by default. Without it, Rule A does not exist. Sysmon Event ID 1 for Rule B. Sysmon Event ID 11 for Rule C.</p><pre># Rule A — LSASS process access (tool-agnostic, highest confidence)<br>event_type = process_access AND<br>target_image ENDSWITH "lsass.exe" AND<br>granted_access MATCHES "(0x1010|0x1410|0x1438|0x143a|0x1418|0x1fffff|0x1f0fff)" AND<br>source_image NOT IN ["MsMpEng.exe","csrss.exe","wininit.exe","svchost.exe",<br>                     "SecurityHealthService.exe","CylanceSvc.exe","SentinelAgent.exe"]<br><br># Rule B - Known credential tool execution (name-based backstop)<br># command_line clause is bracketed inside event_type guard (bug fix in review)<br>event_type = process_create AND<br>(image IMATCHES "mimikatz\.exe" OR<br> image ENDSWITH "procdump64.exe" OR<br> image IMATCHES "lazagne\.exe" OR<br> command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)")<br># Rule C - Dump file creation in user-writable path (artifact backstop)<br>event_type = file_create AND<br>file_extension = "dmp" AND<br>file_path MATCHES "(\\AppData\\|\\Temp\\|\\Users\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> AV and EDR agents that legitimately access LSASS — exclude by process hash, not name, since names are spoofable. Windows Error Reporting creating .dmp files in %TEMP%\WER — exclude that specific path in Rule C. Legitimate procdump usage by developers for application crash diagnostics — require a separate approved-tools baseline.</p><p><strong>Important environment note:</strong> Credential Guard and PPL (Protected Process Light) prevent LSASS reads on modern, hardened systems. If your environment has these enabled, LSASS dump detection is still valuable as a canary for misconfigured or unpatched endpoints, but confirm protection status before using coverage scores here as a measure of actual protection.</p><h3>Phase 5: Validation Lab</h3><h4>Architecture</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8U-N2gM0mGw6qRI7SG06dw.png"></figure><h4>Deploy in One Command</h4><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env   # fill in passwords<br>bash start.sh</pre><p>start.sh creates the Docker network, starts all stack services, waits for Elasticsearch, boots the Windows 10 Vagrant VM, provisions it via Ansible (Sysmon + Script Block Logging + Winlogbeat), and runs all 11 simulations.</p><h4>Simulation Design</h4><p>Every simulation is <strong>benign-by-design</strong>:</p><ul><li>No live malware, no real C2, no credential exfiltration</li><li>Simulations write benign files (VBScript with Write-Host payload), run real Windows binaries with harmless arguments, or use .NET to open process handles with minimal access masks</li><li>All .dmp files are deleted immediately after event confirmation</li><li>The VM does not connect to real Telegram infrastructure</li></ul><p>The Ansible playbook (lab/ansible/playbooks/validate.yml) runs each simulation, waits 3 seconds, queries the Windows Event Log with Get-WinEvent -FilterHashtable (time-bounded to the last 60 seconds), and prints PASS / FAIL.</p><h4>Step 21: det_mw_0001 — Spearphishing Delivery Chain</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8bLoGgU_easNlOr4ZndCgg.png"></figure><p><strong>What MuddyWater does:</strong> Delivers a ZIP or Office file via email or Egnyte/OneDrive link. The attachment contains a VBScript or WSF file that spawns a hidden encoded PowerShell loader (PowGoop/POWERSTATS).</p><p><strong>Simulation:</strong> wscript.exe sim_delivery.vbs → powershell.exe -WindowStyle Hidden -NonInteractive -EncodedCommand &lt;Base64&gt;</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *powershell.exe*<br>AND winlog.event_data.CommandLine: *EncodedCommand*</pre><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → powershell.exe -EncodedCommand. Parent-child chain and Base64 command line both visible in Kibana.</p><h4>Step 22: det_mw_0002 — Web Service Shell Spawn</h4><p><strong>What MuddyWater does:</strong> Exploits Exchange (CVE-2020–0688), IIS, or Log4j (CVE-2021–44228) — web-facing service spawns cmd.exe or powershell.exe for post-exploitation recon.</p><p><strong>Simulation:</strong> wscript.exe sim_exploit.vbs → cmd.exe /c whoami &amp; hostname &amp; ipconfig /all</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *cmd.exe*<br>AND winlog.event_data.CommandLine: (*whoami* OR *hostname* OR *ipconfig*)</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PdbeaS4qAhZO0Abz1vnxlw.png"></figure><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → cmd.exe with recon commands in CommandLine.</p><h4>Step 23: det_mw_0003 — PowerShell Encoded Command</h4><p><strong>What MuddyWater does:</strong> PowGoop uses -EncodedCommand for C2 setup. POWERSTATS uses IEX + (New-Object Net.WebClient).DownloadString(...) for stager execution.</p><p><strong>Rule A simulation:</strong> powershell.exe -NonInteractive -e &lt;Base64(Write-Host "test")&gt;</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.CommandLine: *-e*<br>AND winlog.event_data.CommandLine: *[A-Za-z0-9+/]{40,}*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*t-a6QvN0QQMAwrYTgedLgw.png"></figure><p><strong>Rule A Result: PASS</strong> — 4 events captured. PowerShell with Base64 blob visible in command line.</p><p><strong>Rule B simulation:</strong> IEX ((New-Object Net.WebClient).DownloadString('http://127.0.0.1:19999/...'))</p><p><strong>KQL — Rule B:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *IEX*<br>AND winlog.event_data.ScriptBlockText: *DownloadString*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-VDCsOq78LyTENKxOUQjJg.png"></figure><p><strong>Rule B Result: PASS</strong> — 16 EID 4104 events. Script Block Logging decoded the IEX + DownloadString pattern.</p><blockquote><strong><em>Capability gate:</em></strong><em> Script Block Logging (EID 4104) must be explicitly enabled. Without it, Rule B is unavailable and detection degrades to command-line heuristics only.</em></blockquote><h4>Step 24: det_mw_0004 — DLL Side-Loading</h4><p><strong>What MuddyWater does:</strong> PowGoop drops Goopdate.dll alongside a copy of GoogleUpdate.exe outside the legitimate Google installation path. When GoogleUpdate launches, Windows loads the malicious DLL.</p><p><strong>Simulation:</strong> Copy a benign 4-byte MZ stub as goopdate.dll into a test directory alongside a signed binary. Launch the binary.</p><p><strong>Result: PARTIAL</strong> — Sysmon EID 7 (ImageLoad) did not fire. Root cause: a 4-byte MZ stub is not a valid loadable DLL — the Windows loader rejects it before generating an EID 7 event. The Sysmon config and detection rule are correct. <strong>Resolution:</strong> Re-test with a real GoogleUpdate.exe (requires Google Chrome installed on lab VM).</p><h4>Step 25: det_mw_0005 — Registry Run Key Persistence</h4><p><strong>What MuddyWater does:</strong> Small Sieve writes OutlookMicrosift to HKCU\...\CurrentVersion\Run — a deliberate typo designed to look like a Microsoft entry. Canopy drops a .wsf file to the Startup folder.</p><p><strong>Rule A simulation:</strong> Write OutlookMicrosift = notepad.exe to HKCU\...\Run</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 13<br>AND winlog.event_data.TargetObject: *CurrentVersion\Run\OutlookMicrosift*</pre><p><strong>Rule A Result: PASS</strong> — 3 Sysmon EID 13 events. OutlookMicrosift Run key captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RTAU8BoEU41ydMrali20PA.png"></figure><p><strong>Rule C simulation:</strong> Copy a benign .wsf file to %APPDATA%\...\Start Menu\Programs\Startup\</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *\Startup\*<br>AND winlog.event_data.TargetFilename: *.wsf*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C6VaYiU1W6t9P7VM9Uyq6Q.png"></figure><p><strong>Rule C Result: PASS</strong> — 3 Sysmon EID 11 events. WSF file creation in Startup folder captured.</p><h4>Step 26: det_mw_0006 — Scheduled Task (43-Minute Beacon)</h4><p><strong>What MuddyWater does:</strong> BugSleep creates a scheduled task triggered every <strong>43 minutes</strong>. This interval is a BugSleep artifact — not a default, not a round number. It appears in INCD 2024 reporting and is one of the most precise technical IoCs in the dataset.</p><p><strong>Simulation:</strong> schtasks.exe /create /tn DH-SIM-0006-TestTask /tr notepad.exe /sc MINUTE /mo 43 /f</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\schtasks.exe*<br>AND winlog.event_data.CommandLine: */mo 43*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8a6plhGCKeJFpgCePxizDA.png"></figure><p><strong>Result: PASS</strong> — 3 Sysmon EID 1 events. schtasks.exe /mo 43 captured. The 43-minute interval in the command line is the exact BugSleep artifact.</p><blockquote><strong><em>Hunt value:</em></strong><em> </em><em>PT43M in Task Scheduler Operational logs is a retroactive hunt trigger. One match = investigate immediately. No legitimate software uses this exact interval.</em></blockquote><h4>Step 27: det_mw_0007 — RMM Tool Abuse</h4><p><strong>What MuddyWater does:</strong> Delivers a legitimate RMM binary (ScreenConnect, SimpleHelp, AteraAgent, Level, PDQConnect) via phishing email or file-sharing link. The binary is placed in AppData, Temp, or Downloads — not installed by an IT management system. This is documented in all five government source tiers.</p><p><strong>Simulation:</strong> Copy ScreenConnect.ClientService.exe to C:\Temp\dh-lab\ and launch it.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\Temp\ScreenConnect*</pre><p><strong>Result: PASS</strong> — 6 Sysmon EID 1 events. RMM binary executing from \Temp\ captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U9wgP3tZtCZYaEGIct6woQ.png"></figure><blockquote><strong><em>Production requirement:</em></strong><em> This detection requires a baseline of authorized RMM deployments per endpoint. Without the baseline, it generates noise. With it, any out-of-baseline RMM execution is an immediate high-confidence alert.</em></blockquote><h4>Step 28: det_mw_0008a — Telegram Bot API C2</h4><p><strong>What MuddyWater does:</strong> Small Sieve uses the Telegram Bot API (api.telegram.org:443) for C2 over HTTPS. In an enterprise environment where Telegram is not standard software, any non-browser process connecting to this domain is anomalous.</p><p><strong>Simulation:</strong> powershell.exe makes an HTTP request to https://api.telegram.org/botTEST/getMe (invalid token — 401 response; the connection attempt is the evidence).</p><p><strong>Result: FAIL</strong> — Sysmon EID 3 (NetworkConnect) did not fire. Root cause: VirtualBox NAT prevents Sysmon from capturing the outbound network connection to api.telegram.org in the lab environment. The Sysmon rule config is correct. <strong>Resolution:</strong> Re-test with a host-only NIC that provides direct internet access.</p><h4>Step 29: det_mw_0008b — DNS Tunneling</h4><p><strong>What MuddyWater does:</strong> Mori uses DNS tunneling for C2. High-volume queries with long, high-entropy subdomain labels are the telemetry signature.</p><p><strong>Simulation:</strong> 60 Resolve-DnsName queries with 42-character random labels against *.test.internal.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 22<br>AND winlog.event_data.QueryName: *.test.internal*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yt5HdYyG3lGJi-pY88VPXA.png"></figure><p><strong>Result: PASS</strong> — 180 Sysmon EID 22 events captured. 42-character random labels visible in QueryName field. Volume threshold (Rule A) and label-length threshold (Rule B) would both trigger in a production deployment.</p><h4>Step 30: det_mw_0009 — WMI SecurityCenter2 Discovery</h4><p><strong>What MuddyWater does:</strong> CISA AA22–055A documents a post-access survey script that queries root\SecurityCenter2\AntiVirusProduct via WMI — enumerating the installed AV product before deciding how to proceed. This is also combined with OS info, network config, and user queries in a single script.</p><p><strong>Simulation (Rule A):</strong> Get-WmiObject -Namespace root/SecurityCenter2 -Class AntiVirusProduct</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *SecurityCenter2*</pre><p><strong>Rule A Result: PASS</strong> — 21 PS EID 4104 events. SecurityCenter2 visible in decoded ScriptBlockText.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wpLAuTyJkLgoqezMzJWISA.png"></figure><blockquote><strong><em>Detection value:</em></strong><em> SecurityCenter2 + AntiVirusProduct is one of the highest-specificity behavioral signals in this dataset. Its legitimate caller population is tiny: only AV management consoles and a few inventory tools query this namespace. A PowerShell process making this query outside those exceptions warrants immediate investigation.</em></blockquote><h4>Step 31: det_mw_0010 — LSASS Memory Access</h4><p><strong>What MuddyWater does:</strong> Uses Mimikatz, procdump64.exe, and LaZagne to dump LSASS memory and extract credentials. CISA AA22–055A names all three tools.</p><p><strong>Rule A simulation:</strong> .NET OpenProcess(PROCESS_QUERY_INFORMATION, lsass.pid) — opens a handle to lsass.exe with a minimal access mask, triggering Sysmon EID 10.</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 10<br>AND winlog.event_data.TargetImage: *lsass.exe*<br>AND winlog.event_data.GrantedAccess: 0x1400</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G-oMtjgeEzuCIKfTDznKzA.png"></figure><p><strong>Rule A Result: PASS</strong> — 3,398 Sysmon EID 10 events with GrantedAccess: 0x1400 and TargetImage: lsass.exe. The high event count is expected — LSASS receives many legitimate handle requests from AV, EDR, and Windows system processes. Production deployment requires an allowlist of known-good callers.</p><p><strong>Rule C simulation:</strong> Write a 4-byte MDMP header as lsass_test.dmp to C:\Temp\dh-lab\ — triggers Sysmon EID 11.</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *.dmp*<br>AND winlog.event_data.TargetFilename: *Temp*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TrCWgKcujqKdBRCX-OG26w.png"></figure><p><strong>Rule C Result: PASS</strong> — 6 Sysmon EID 11 events. C:\Temp\dh-lab\lsass_test.dmp creation captured.</p><blockquote><strong><em>Lab safety:</em></strong><em> The </em><em>.dmp file was deleted immediately after event confirmation. No credential material exists in the file — it was a 4-byte header stub. No real LSASS dump was performed.</em></blockquote><h3>Phase 5 Validation Results Summary</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yl6Y0h2_ePVKH3i8einFDQ.png"></figure><p>Full run: ansible-playbook playbooks/validate.yml — <strong>ok=70 changed=42 failed=0</strong></p><ul><li>Step 21 — <strong>det_mw_0001</strong> · Process spawn → <strong>PASS</strong></li><li>Step 22 — <strong>det_mw_0002</strong> · Shell from service → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule A (-e + Base64) → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule B (IEX + DownloadString) → <strong>PASS</strong></li><li>Step 24 — <strong>det_mw_0004</strong> · EID 7 ImageLoad → <strong>PARTIAL</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule A (OutlookMicrosift) → <strong>PASS</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule C (WSF in Startup) → <strong>PASS</strong></li><li>Step 26 — <strong>det_mw_0006</strong> · schtasks /mo 43 → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule A (RMM from \Temp) → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule B (RMM from PS parent) → <strong>PASS</strong></li><li>Step 28 — <strong>det_mw_0008a</strong> · EID 3 Telegram → <strong>FAIL</strong></li><li>Step 29 — <strong>det_mw_0008b</strong> · EID 22 DNS tunneling → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule A (SecurityCenter2 EID 4104) → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule B (wmic SecurityCenter2) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule A (LSASS EID 10) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule C (.dmp EID 11) → <strong>PASS</strong></li></ul><p><strong>13 PASS / 1 PARTIAL / 1 FAIL</strong> across 16 rule checks.</p><h3>Phase 6: Coverage Matrix</h3><p>Of 22 ATT&amp;CK techniques documented in the source set:</p><ul><li><strong>15 techniques (68%)</strong> — score 5, fully lab-validated</li><li><strong>2 techniques (9%)</strong> — score 4, correlated and validated via fallback</li><li><strong>4 techniques (18%)</strong> — score 3, rule present but validation incomplete</li><li><strong>7 techniques</strong> — score 0, no detection (Lateral Movement, Collection, Exfiltration, Impact)</li></ul><p><strong>The six capability gates</strong> that determine your effective coverage floor:</p><ul><li><strong>PowerShell Script Block Logging (EID 4104)</strong> — unlocks det_mw_0003 Rule B and det_mw_0009 Rules A/C. Without it: detection degrades to command-line heuristics only.</li><li><strong>Sysmon EID 10 (ProcessAccess)</strong> — unlocks det_mw_0010 Rule A (tool-agnostic LSASS access). Without it: falls back to binary name matching, misses custom dumpers.</li><li><strong>Sysmon EID 7 (ImageLoad)</strong> — unlocks det_mw_0004 (DLL side-loading). Without it: DLL loads are completely invisible.</li><li><strong>DNS resolver logging (full QNAME)</strong> — unlocks det_mw_0008b (DNS tunneling). Without it: Mori C2 channel is invisible.</li><li><strong>Network flow / proxy logs</strong> — unlocks det_mw_0007 Rule C and det_mw_0008a. Without it: RMM and Telegram C2 network-layer coverage lost.</li><li><strong>Email gateway telemetry (SEG)</strong> — unlocks det_mw_0001 full correlated logic. Without it: email-to-endpoint correlation unavailable.</li></ul><h3>What Defenders Should Do Right Now</h3><p><strong>1. Baseline your RMM deployments.</strong> det_mw_0007 is the most consistently documented MuddyWater technique across all five source tiers. It fires on ScreenConnect, SimpleHelp, AteraAgent, Level, and PDQConnect from non-standard paths. But it needs a baseline of authorized deployments first. Build the baseline; the detection logic is already written.</p><p><strong>2. Enable PowerShell Script Block Logging fleet-wide.</strong> One Group Policy change:</p><pre>Computer Configuration → Administrative Templates → Windows Components<br>→ Windows PowerShell → Turn on PowerShell Script Block Logging → Enabled</pre><p>This unlocks det_mw_0003 Rule B and all three det_mw_0009 rules. No other change required.</p><p><strong>3. Configure Sysmon ProcessAccess against lsass.exe.</strong> Without it, LSASS credential dumping detection is binary-name-only. Renamed Mimikatz and custom C++ dumpers are invisible. Add &lt;ProcessAccess onmatch="include"&gt; targeting lsass.exe to sysmon.xml.</p><p><strong>4. Hunt for PT43M now.</strong> Query your Task Scheduler Operational logs for any task with a RepetitionInterval of PT43M. If you find one you didn't create, that is BugSleep. No other legitimate software uses this interval.</p><h3>Reproduce It Yourself</h3><p>The entire project is on GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra"><strong>github.com/anpa1200/operation-desert-hydra</strong></a></p><p>One repository contains everything: Docker Compose stack (OpenCTI + Elasticsearch + Kibana), Vagrant lab VM, Ansible provisioning playbooks, detection rules in four formats (Sigma, KQL, Elastic JSON, SPL), structured intelligence datasets (YAML), and all 12 proof screenshots.</p><p><strong>Deploy:</strong></p><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env<br># fill in ELASTIC_PASSWORD, OPENCTI_ADMIN_PASSWORD, OPENCTI_ADMIN_TOKEN<br>bash start.sh<br># → OpenCTI: http://localhost:8080<br># → Kibana:  http://localhost:5601<br># → all 11 simulations run automatically (~10 min)</pre><p><strong>Stop / destroy:</strong></p><pre>bash stop.sh                # halt VM, keep stack and data<br>bash stop.sh --destroy-vm   # remove VM disk<br>bash stop.sh --destroy-stack  # also stop Docker stack</pre><p><strong>Skip the lab VM</strong> (OpenCTI + Kibana only, no Windows VM):</p><pre>bash start.sh --skip-lab</pre><p>Prerequisites: Docker, VirtualBox, Vagrant, Ansible, Python 3 + pywinrm. Full details in the <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/README.md">README</a>.</p><p>Key files:</p><ul><li>docs/article-step-0-project-scenario.md — full phase-by-phase walkthrough</li><li>data/detections.yaml — all 11 detection records with coverage scores</li><li>lab/ansible/playbooks/validate.yml — the 11 simulation playbook</li><li>detections/sigma/, detections/kql/, detections/elastic/, detections/spl/ — rule exports</li></ul><h3>What This Project Is Not</h3><p>This is not a red team toolkit. The lab produces benign telemetry for detection validation — no live malware, no real C2, no credential theft. The detection pseudologic is SIEM-agnostic and requires production translation and tuning before deployment. Coverage scores are conservative: 5 requires a Kibana screenshot, not just passing logic.</p><p>The source base is entirely public. The actor’s actual TTPs may be more sophisticated than what is documented. Treat the coverage matrix as a floor, not a ceiling.</p><h3>Production Scars</h3><p>Everything above describes what the project looks like after it worked. This section documents what broke, in what order, and what was actually fixed — the kind of detail that gets cut from writeups but is the most useful part for anyone trying to reproduce this.</p><h4>Scar 1: The Simulations Were Faking It</h4><p>The first validation attempt used synthetic event markers. The simulation playbook injected a DH-SIM-0001 string into the CommandLine field, then the Kibana queries looked for that exact string:</p><pre>winlog.event_id: 1 AND winlog.event_data.CommandLine: *DH-SIM-0001*</pre><p>This produces a screenshot. It does not prove a detection works.</p><p>The problem is fundamental: a query that looks for a marker you injected proves that injection works, not that a detection fires on real attacker behavior. If MuddyWater runs wscript.exe and spawns powershell.exe -EncodedCommand, the DH-SIM-0001 query returns nothing. The detection coverage number was meaningless.</p><p><strong>What was fixed:</strong> All simulations were rewritten to produce realistic execution chains — wscript.exe spawning powershell.exe -EncodedCommand &lt;base64&gt;, schtasks.exe /create /sc minute /mo 43, lsass.exe being accessed by a test process with the correct GrantedAccess mask. All KQL queries were rewritten to use real field-based conditions: winlog.event_data.ParentImage, winlog.event_data.GrantedAccess, winlog.event_data.TargetObject, winlog.event_data.ScriptBlockText. Every proof screenshot now shows a real field value, not a synthetic marker.</p><p><strong>The lesson:</strong> A proof screenshot is only as good as the conditions that trigger it. If the simulation writes what the query reads, you have a tautology, not a detection.</p><h4>Scar 2: det_mw_0004 — The DLL That Wouldn’t Load</h4><p>The simulation for det_mw_0004 (DLL side-loading) created a 4-byte MZ-header stub file named Goopdate.dll in a temp directory alongside GoogleUpdate.exe, then waited for Sysmon Event ID 7 (ImageLoad) to fire.</p><p>It never fired.</p><p>Root cause: a 4-byte MZ stub is not a valid PE binary. The Windows loader parses the PE header before loading — the stub fails the loader’s structural validation and is rejected before the load event is generated. Sysmon only generates EID 7 for DLLs that actually get mapped into process memory. A file that fails to load produces no EID 7.</p><p>The Sysmon configuration was correct. The detection rule was correct. The simulation was wrong.</p><p><strong>Result: PARTIAL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> The test needs a real, valid DLL — even an empty DLL compiled from a single DllMain that returns TRUE. Alternatively, installing the actual Google Chrome on the lab VM provides a real Goopdate.dll at the expected path, which could then be copied to a non-standard location. Neither was done in this iteration due to lab scope constraints (no internet access on the VM for Chrome installation, no compiler toolchain in the lab).</p><p><strong>The lesson:</strong> When validating EID 7 detections, your test artifact must be a valid loadable PE. A stub file saves time and produces nothing.</p><h4>Scar 3: det_mw_0008a — VirtualBox NAT Ate the Telegram Traffic</h4><p>The simulation for det_mw_0008a (Telegram Bot API C2) made an outbound HTTPS connection to api.telegram.org from PowerShell and waited for Sysmon Event ID 3 (NetworkConnect) to fire.</p><p>It never fired.</p><p>Root cause: VirtualBox NAT performs network address translation at the hypervisor level. Sysmon captures network connections at the Windows kernel level. With NAT, the connection from the VM’s perspective terminates at the NAT gateway (10.0.2.2), not at api.telegram.org. Sysmon sees a connection to 10.0.2.2:443, not api.telegram.org:443. The detection rule looking for api.telegram.org as the destination found nothing.</p><p>There was an additional layer: VirtualBox NAT does not forward arbitrary outbound HTTPS traffic by default in this lab configuration — the VM had no direct internet path, only access to the host’s 10.0.2.2 gateway. Even fixing the Sysmon observation problem would require a working internet path from the VM.</p><p><strong>Result: FAIL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> Add a host-only or bridged network adapter to the VM that provides direct internet access, and confirm Sysmon captures the connection with the external destination. Alternatively, run a local HTTPS server on the host at api.telegram.org via a hosts file override, which would make the destination resolvable within the lab and catchable by Sysmon.</p><p><strong>The lesson:</strong> VirtualBox NAT is the right choice for lab isolation (the VM cannot reach the internet accidentally), but it is the wrong choice if you need to validate detections based on external destination hostnames. Design the network topology before writing detection validation cases.</p><h4>Scar 4: Kibana Showed Nothing — Wrong Time Window</h4><p>After running the SecurityCenter2 WMI discovery simulation (Step 30), the Kibana query returned zero results.</p><p>The query was correct. The simulation had run correctly. The events were in Elasticsearch.</p><p>Root cause: Kibana’s default time window was set to “Last 15 minutes.” The simulation had run in a previous lab session, and Winlogbeat had shipped the events to Elasticsearch during that session. The events existed — they were just outside the current time window.</p><p><strong>What was fixed:</strong> Changed the time filter to “Last 24 hours.” Events appeared immediately.</p><p><strong>The lesson:</strong> When a Kibana proof shows no results, the first diagnostic step is the time filter, not the query. This is obvious in retrospect and a consistent source of false “detection failed” conclusions during initial validation runs.</p><h4>Scar 5: Detection Design Bugs Found in Review (Before Validation)</h4><p>Before running any simulations, every detection record went through a structured review pass. Four real bugs were found:</p><p><strong>det_mw_0010 Rule B — Operator precedence error.</strong> The original pseudologic was:</p><pre>event_type = process_create AND<br>image IMATCHES "mimikatz\.exe" OR<br>image ENDSWITH "procdump64.exe" OR<br>command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)"</pre><p>Without explicit parentheses, OR has lower precedence than AND in most query languages. The command_line IMATCHES clause was evaluated independently of the event_type guard, meaning the rule would fire on any event (not just process_create) where the command line contained sekurlsa. In a SIEM with millions of events per day, this generates noise and potentially masks the real signal. The fix added explicit brackets to keep all OR branches inside the event_type = process_create guard.</p><p><strong>det_mw_0009 Rule C — T1033 was not covered.</strong> The initial Rule C matched SecurityCenter2, Win32_NetworkAdapterConfiguration, and Win32_OperatingSystem — covering T1518.001, T1016, and T1082. The documented CISA script also collects the username via Win32_ComputerSystem. T1033 (System Owner/User Discovery) was missing. Fixed by adding Win32_ComputerSystem|Win32_UserAccount|UserName to the pattern match.</p><p><strong>det_mw_0004 Rule A — Missing x86 Google path.</strong> The initial allowlist only contained the x64 path C:\Program Files\Google\. On 64-bit Windows, the 32-bit Google Update installs to C:\Program Files (x86)\Google\. Without the x86 path in the allowlist, any Goopdate.dll load from the legitimate 32-bit Google installation would fire the detection. Added both paths.</p><p><strong>det_mw_0010 Rule A — Access mask set too narrow.</strong> The initial mask set covered standard Mimikatz masks (0x1010, 0x1410, 0x1438) but missed 0x1fffff (PROCESS_ALL_ACCESS, used by custom C++ dumpers and some loaders) and 0x1f0fff (another all-access variant observed in field reporting). A detection that only catches stock Mimikatz masks is bypassed by any custom implementation. Extended the mask set to cover known custom-dumper variants.</p><p><strong>The lesson:</strong> Writing pseudologic in a YAML field with no syntax validation means operator precedence bugs survive until someone reads the logic carefully. Structured peer review — ideally by someone who will try to break the rule — catches these before they hit production.</p><h4>Scar 6: The OpenCTI Stack Was in a Different Repository</h4><p>The original project structure had the OpenCTI Docker Compose stack in a separate repository (opencti-intelligent-shield) that was not included in the desert-hydra repo. The start.sh script referenced the external repo with a hardcoded path. Cloning operation-desert-hydra and running start.sh failed immediately on any machine other than the development machine.</p><p><strong>What was fixed:</strong> The entire stack — docker-compose.yml, docker-compose.kibana.yml, and .env.template — was copied into stack/ inside the desert-hydra repo. All path references were updated. The repo is now fully self-contained: git clone + cp .env.template .env + bash start.sh works from a clean machine with no external dependencies beyond Docker, Vagrant, VirtualBox, Ansible, and pywinrm.</p><p><strong>The lesson:</strong> A reproducibility claim requires everything needed to reproduce to be in the same repository. External path dependencies are invisible during development and obvious on first external clone.</p><h4>Scar 7: MITRE Connector Timing</h4><p>The import script (tools/opencti_import.py) creates MuddyWater → uses → ATT&amp;CK technique relationships by looking up techniques that the MITRE ATT&amp;CK connector has synced into OpenCTI. The connector takes several minutes to complete its initial sync of 846 techniques.</p><p>If the import script runs before the connector finishes, the technique lookup returns nothing — the techniques don’t exist yet. The original script failed silently on these lookups and skipped the relationship creation.</p><p><strong>What was fixed:</strong> The script was updated with find_or_create_attack_pattern(): if a technique is not yet in OpenCTI, create a stub AttackPattern object with the correct x_mitre_id. When the MITRE connector eventually syncs that technique, OpenCTI's deduplication logic merges the stub with the connector's fully populated object. All relationships that were created against the stub are preserved and now point to the enriched object. Running the script a second time after the connector finishes confirms existing objects rather than creating duplicates.</p><p><strong>The lesson:</strong> Any script that creates relationships against objects populated by a connector needs to handle the case where the connector has not finished. Fail loudly or create stubs — don’t skip silently.</p><h4>Surviving Gaps</h4><p>Two failures from Phase 5 remain open:</p><p><strong>det_mw_0004</strong> — DLL side-loading detection (EID 7) is not lab-validated. The detection rule is sound; the simulation needs a valid PE DLL. Coverage score stays at 3 until the lab is extended with a compiled test DLL.</p><p><strong>det_mw_0008a</strong> — Telegram Bot API connection detection (EID 3) is not lab-validated. The detection rule is sound; the lab network topology prevents capturing external destination hostnames via NAT. Coverage score stays at 3 until the VM has a direct internet path or a local HTTPS proxy target.</p><p>These are documented as open items, not dismissed as “out of scope.” The coverage score scale is designed to reflect this: a score of 3 means “behavioral detection, no lab proof” — it is honest about the gap rather than claiming coverage that was not validated.</p><p><strong>Seven ATT&amp;CK techniques have zero detection coverage.</strong> Lateral movement (T1021.001 RDP, T1550.002 Pass the Hash), Collection (T1005, T1039), Exfiltration (T1041), and Impact (T1486 ransomware, T1490 shadow copy deletion from DarkBit). These are acknowledged in the coverage matrix, not hidden. The actor uses them. The public source base documents them. The detection coverage does not exist in this iteration.</p><p><em>All code, data, and proof screenshots are version-controlled at </em><a href="https://github.com/anpa1200/operation-desert-hydra"><em>github.com/anpa1200/operation-desert-hydra</em></a></p><h3>Follow My Work</h3><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><h4><strong>Andrey Pautov</strong></h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=34da7917acf0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0">Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9844 | Roche Diagnostics navify Digital Pathology up to 2.4.1 RabbitMQ Management Interface default credentials (EUVD-2026-33923)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Roche Diagnostics navify Digital Pathology up to 2.4.1. The impacted element is an unknown function of the component RabbitMQ Management Interface. Such manipulation leads to use of default credentials.

This vulnerability is documented...]]></description>
<link>https://tsecurity.de/de/3566785/sicherheitsluecken/cve-2026-9844-roche-diagnostics-navify-digital-pathology-up-to-241-rabbitmq-management-interface-default-credentials-euvd-2026-33923/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566785/sicherheitsluecken/cve-2026-9844-roche-diagnostics-navify-digital-pathology-up-to-241-rabbitmq-management-interface-default-credentials-euvd-2026-33923/</guid>
<pubDate>Tue, 02 Jun 2026 18:08:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/roche_diagnostics:navify_digital_pathology">Roche Diagnostics navify Digital Pathology up to 2.4.1</a>. The impacted element is an unknown function of the component <em>RabbitMQ Management Interface</em>. Such manipulation leads to use of default credentials.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-9844">CVE-2026-9844</a>. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-30219 | RabbitMQ Server up to 4.0.2 cross site scripting (GHSA-g58g-82mw-9m3p / Nessus ID 234064)]]></title>
<description><![CDATA[A vulnerability was found in RabbitMQ Server up to 4.0.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.

This vulnerability is referenced as CVE-2025-30219. Remote exploitation of the attack is possible. No exploit is avail...]]></description>
<link>https://tsecurity.de/de/3560246/sicherheitsluecken/cve-2025-30219-rabbitmq-server-up-to-402-cross-site-scripting-ghsa-g58g-82mw-9m3p-nessus-id-234064/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560246/sicherheitsluecken/cve-2025-30219-rabbitmq-server-up-to-402-cross-site-scripting-ghsa-g58g-82mw-9m3p-nessus-id-234064/</guid>
<pubDate>Sun, 31 May 2026 07:53:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rabbitmq:server">RabbitMQ Server up to 4.0.2</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function. The manipulation leads to cross site scripting.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2025-30219">CVE-2025-30219</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44839 | RabbitMQ rabbitmq-server up to 4.0.12/4.1.1 cross site scripting (GHSA-fh5r-jpm3-fjwp / WID-SEC-2026-1397)]]></title>
<description><![CDATA[A vulnerability was found in RabbitMQ rabbitmq-server up to 4.0.12/4.1.1. It has been declared as problematic. This issue affects some unknown processing. The manipulation results in basic cross site scripting.

This vulnerability is cataloged as CVE-2026-44839. The attack may be launched remotel...]]></description>
<link>https://tsecurity.de/de/3553284/sicherheitsluecken/cve-2026-44839-rabbitmq-rabbitmq-server-up-to-4012411-cross-site-scripting-ghsa-fh5r-jpm3-fjwp-wid-sec-2026-1397/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553284/sicherheitsluecken/cve-2026-44839-rabbitmq-rabbitmq-server-up-to-4012411-cross-site-scripting-ghsa-fh5r-jpm3-fjwp-wid-sec-2026-1397/</guid>
<pubDate>Thu, 28 May 2026 09:24:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rabbitmq:rabbitmq-server">RabbitMQ rabbitmq-server up to 4.0.12/4.1.1</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing. The manipulation results in basic cross site scripting.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-44839">CVE-2026-44839</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44838 | RabbitMQ rabbitmq-server up to 4.2.3 Regular Expression authorization (GHSA-x866-xp2g-cx8v / WID-SEC-2026-1397)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in RabbitMQ rabbitmq-server up to 4.2.3. This issue affects some unknown processing of the component Regular Expression Handler. This manipulation causes incorrect authorization.

This vulnerability appears as CVE-2026-44838. The attack may...]]></description>
<link>https://tsecurity.de/de/3553283/sicherheitsluecken/cve-2026-44838-rabbitmq-rabbitmq-server-up-to-423-regular-expression-authorization-ghsa-x866-xp2g-cx8v-wid-sec-2026-1397/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553283/sicherheitsluecken/cve-2026-44838-rabbitmq-rabbitmq-server-up-to-423-regular-expression-authorization-ghsa-x866-xp2g-cx8v-wid-sec-2026-1397/</guid>
<pubDate>Thu, 28 May 2026 09:24:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/rabbitmq:rabbitmq-server">RabbitMQ rabbitmq-server up to 4.2.3</a>. This issue affects some unknown processing of the component <em>Regular Expression Handler</em>. This manipulation causes incorrect authorization.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-44838">CVE-2026-44838</a>. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Project] Bashqueues: A shell-native, policy-driven IPC and job management system (Seeking technical feedback)]]></title>
<description><![CDATA[I’ve been working on a project called Bashqueues—an opinionated, shell-native approach to interprocess communication (IPC) and job queue management on Linux. Most existing queueing systems are designed for high-scale distributed tasks, often carrying significant overhead or requiring heavy runtim...]]></description>
<link>https://tsecurity.de/de/3552648/linux-tipps/project-bashqueues-a-shell-native-policy-driven-ipc-and-job-management-system-seeking-technical-feedback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552648/linux-tipps/project-bashqueues-a-shell-native-policy-driven-ipc-and-job-management-system-seeking-technical-feedback/</guid>
<pubDate>Thu, 28 May 2026 01:36:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I’ve been working on a project called <strong>Bashqueues</strong>—an opinionated, shell-native approach to interprocess communication (IPC) and job queue management on Linux.</p> <p>Most existing queueing systems are designed for high-scale distributed tasks, often carrying significant overhead or requiring heavy runtime environments. Bashqueues is built for a different use case: environments where IPC governance, strict security policies, and forensic auditability are the primary requirements.</p> <p><strong>The core philosophy:</strong> Instead of just managing "work," Bashqueues treats every job as an asset that must comply with a defined "Class Policy." We want to ensure that a job running in production is exactly what the operator intended, and nothing more.</p> <p><strong>Key Features (Current Implementation):</strong></p> <ul> <li><strong>Policy-Driven Governance:</strong> Every job is bound to a class definition (e.g., <code>SECURE_OFFICIAL</code>, <code>BATCH_PROCESSING</code>). Policies dictate sandbox levels (seccomp, namespaces), execution caps, and network egress limits <em>before</em> the job is dispatched.</li> <li><strong>Static &amp; Runtime Auditing:</strong> The system includes <code>secaudit</code> assets to scan for dangerous patterns, and interrogation profiles to baseline normal system behavior.</li> <li><strong>Shell-Native:</strong> The engine (<code>queuebash.sh</code>) and management interface (<code>queuemgr_panel.py</code>) are designed to be transparent, scriptable, and easy to interrogate using standard POSIX shell tools.</li> <li><strong>Forensic Readiness:</strong> Every dispatch, failure, and policy exception is logged with structured metadata, designed for environments where you need to know exactly <em>why</em> a job was blocked or allowed.</li> </ul> <p><strong>Current State &amp; Disclaimer:</strong> This project is currently in <strong>active, early-stage development</strong>.</p> <ul> <li><strong>Code Stability:</strong> It is functional for our internal use cases, but it is not "production-ready" in the sense of enterprise software. Expect to find edge cases, especially regarding complex systemd daemon configurations.</li> <li><strong>Scope:</strong> It is designed for specific, policy-heavy Linux environments. It is not intended to replace high-concurrency message queues (like RabbitMQ or Kafka).</li> </ul> <p>I’m sharing this because I am looking for eyes on the logic—specifically the policy enforcement and security-governance class statements. If you have experience with Linux security hardening, systemd, or shell-based orchestration and want to critique the architecture, I’d appreciate the input.</p> <p>As the notes make clear, this was designed by a human, but coded by an AI, an AI checked the work, and a variety of other AI's have contributed to this project. So, when someone says "Did ChatGPT write this?" then the answer is yes, Claude checked it, Co-Pilot discussed the Microsoft and other commercial infrastructure, Deepseek gave suggestions and Gemini wrote the majority of the Reddit post. </p> <p><strong>Repository:</strong> <a href="https://github.com/animatedads/bashqueues">https://github.com/animatedads/bashqueues</a> </p> <p><em>Note: All feedback regarding security implementation is welcome. Please handle any potential bug reports via the standard GitHub issue tracker.</em></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/BashQueue"> /u/BashQueue </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tpfynb/project_bashqueues_a_shellnative_policydriven_ipc/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tpfynb/project_bashqueues_a_shellnative_policydriven_ipc/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-40971 | Vmware Spring Boot up to 3.5.13/4.0.5 RabbitMQ Auto-configuration certificate validation]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Vmware Spring Boot up to 3.5.13/4.0.5. This affects an unknown part of the component RabbitMQ Auto-configuration. Such manipulation leads to improper certificate validation.

This vulnerability is referenced as CVE-2026-40971. It is ...]]></description>
<link>https://tsecurity.de/de/3523370/sicherheitsluecken/cve-2026-40971-vmware-spring-boot-up-to-3513405-rabbitmq-auto-configuration-certificate-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3523370/sicherheitsluecken/cve-2026-40971-vmware-spring-boot-up-to-3513405-rabbitmq-auto-configuration-certificate-validation/</guid>
<pubDate>Sun, 17 May 2026 10:38:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/vmware:spring_boot">Vmware Spring Boot up to 3.5.13/4.0.5</a>. This affects an unknown part of the component <em>RabbitMQ Auto-configuration</em>. Such manipulation leads to improper certificate validation.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-40971">CVE-2026-40971</a>. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Tooling Announcements: Engineering Effectiveness Newsletter (Q1 2026 Edition)]]></title>
<description><![CDATA[Welcome to the Q1 edition of the Engineering Effectiveness Newsletter! The Engineering Effectiveness org makes it easy to develop, test and release Mozilla software at scale. See below for some highlights, then read on for more detailed info!
Highlights

Suhaib Integrated Review Helper with Phabr...]]></description>
<link>https://tsecurity.de/de/3501667/tools/firefox-tooling-announcements-engineering-effectiveness-newsletter-q1-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501667/tools/firefox-tooling-announcements-engineering-effectiveness-newsletter-q1-2026-edition/</guid>
<pubDate>Fri, 08 May 2026 23:25:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welcome to the Q1 edition of the Engineering Effectiveness Newsletter! The Engineering Effectiveness org makes it easy to develop, test and release Mozilla software at scale. See below for some highlights, then read on for more detailed info!</p>
<h3><a class="anchor" href="https://discourse.mozilla.org/#p-293819-highlights-1" name="p-293819-highlights-1"></a>Highlights</h3>
<ul>
<li>Suhaib Integrated Review Helper with Phabricator and moz-phab making AI-powered code review quick and simple.</li>
<li>Connor Sheehan implemented ETL from Lando to STMO, which allows us to get better visibility into lando’s performance and usage.</li>
<li>Firefox 150 will ship with new PDF editing features completed by Calixte, letting users delete, copy, move, and export pages to a new PDF.</li>
</ul>
<h3><a class="anchor" href="https://discourse.mozilla.org/#p-293819-detailed-project-updates-2" name="p-293819-detailed-project-updates-2"></a>Detailed Project Updates</h3>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-ai-for-development-3" name="p-293819-ai-for-development-3"></a>AI for Development</h4>
<ul>
<li>Suhaib Mujahid integrated Review Helper with Phabricator, enabling AI-powered code review directly from patches by clicking a “Request AI Review” button, allowing it to analyze the patch and post comments with any findings.</li>
<li>Suhaib Mujahid extended moz-phab to support requesting an AI review at patch submission time, enabling contributors to trigger Review Helper analysis directly from the command line via moz-phab --ai.</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-bugzilla-4" name="p-293819-bugzilla-4"></a>Bugzilla</h4>
<ul>
<li>Marco trained a new model in bugbug to detect bugs that are accessibility-related and missing the “access” keyword, to bring them to the attention of the accessibility team
<ul>
<li>First bugs found: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026654">Bug 2026654</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026647">Bug 2026647</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2025992">Bug 2025992</a></li>
</ul>
</li>
<li>Two fixes from dkl to improve the reliability of the background bot that syncs Phabricator revisions with Bugzilla bugs.</li>
<li>Kohei updated the markdown comment editor now intelligently handles pasting URLs. When you paste a URL while text is selected, it automatically formats it as a markdown link “<a>selected text</a>”.</li>
<li>Kohei has also done significant improvements to the Guided Bug Entry page for new Bugzilla pages that should be going live soon.</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-build-system-and-mach-environment-5" name="p-293819-build-system-and-mach-environment-5"></a>Build System and Mach Environment</h4>
<ul>
<li>Better scheduling of rust dependencies through <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2011880">Bug 2011880</a> leads to ~1m saving in build time for opt build with hot cache.</li>
<li>Warning flags can no longer be added directly to CFLAGS or CXXFLAGS in moz.build, they have to go in COMPILE_FLAGS[“WARNINGS_CXXFLAGS”] (resp. COMPILE_FLAGS[“WARNINGS_CFLAGS”]) (see <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1986258">Bug 1986258</a>)</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-firefox-ci-taskcluster-and-treeherder-6" name="p-293819-firefox-ci-taskcluster-and-treeherder-6"></a>Firefox-CI, Taskcluster and Treeherder</h4>
<ul>
<li>Matt Boris upgraded FxCI to use RabbitMQ quorum queues and upgraded pulse to the latest available version for performance, security, and reliability.</li>
<li>Abhishek Madan migrated schema validation from Voluptuous to msgspec across taskgraph, mozilla-taskgraph, and firefox, resulting in a 30% improvement to decision task times.
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1652123">Bug for conversion in Firefox</a>, <a href="https://github.com/taskcluster/taskgraph/pull/844" rel="noopener nofollow ugc">PR in Taskgraph</a>, <a href="https://github.com/mozilla-releng/mozilla-taskgraph/pull/160" rel="noopener nofollow ugc">PR in Mozilla-Taskgraph</a></li>
</ul>
</li>
<li>Abhishek Madan moved Firefox from a vendored copy of taskgraph to PyPI installs at setup time, enabling support for packages that include compiled components.
<ul>
<li><a href="https://phabricator.services.mozilla.com/D273841" rel="noopener nofollow ugc">Patch stack</a></li>
</ul>
</li>
<li>Andrew Halberstadt made lots of progress migrating CI to Github, currently being used by mozilla/enterprise-firefox:
<ul>
<li><a href="http://bugzilla.mozilla.org/show_bug.cgi?id=2009019">Support for actions</a></li>
<li>Fixed <a href="http://bugzilla.mozilla.org/show_bug.cgi?id=2013889">index</a> and <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1998731">Treeherder</a> routes</li>
<li><a href="http://bugzilla.mozilla.org/show_bug.cgi?id=2021009">Support for mach try</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027836">Added pull_request_number as a parameter</a></li>
</ul>
</li>
<li>Andrew Halberstadt <a href="https://github.com/taskcluster/taskcluster/pull/8431" rel="noopener nofollow ugc">wrote a patch</a> implementing the ability for the Taskcluster Github service to trigger hooks listed in .taskcluster.yml files. This will pave the way to share cross-project workflows and simplify in-repo configuration.</li>
<li>Cameron Dawson upgraded major frontend libraries of Treeherder</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-lint-static-analysis-and-code-coverage-7" name="p-293819-lint-static-analysis-and-code-coverage-7"></a>Lint, Static Analysis and Code Coverage</h4>
<ul>
<li>New linter for header guards, through <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2009182">bug 2009182</a>, triggered by mach lint --linter header-guards . It enforces our code style.</li>
<li>A limited subset of clang-tidy’s static analysis is now run and enforced on our whole codebase. It is also reported during review on phabricator (see <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2023518">Bug 2023518</a> and related bugs)</li>
<li>ESLint and Prettier have been<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2009689"> updated to the latest versions</a>.
<ul>
<li>This included a<a href="https://github.com/gajus/eslint-plugin-jsdoc/issues/1619" rel="noopener nofollow ugc"> fix for eslint-plugin-jsdoc check-property-names</a> rule which was raising some false-positives in firefox-main.</li>
</ul>
</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1967204">eslint-env comments are being removed</a> as ESLint v9 does not support them (use eslint-file-globals.config.mjs instead). ESLint v10 (currently in rc) will raise errors for them.</li>
<li>More eslint-plugin-jsdoc rules have been<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2009691"> enabled across the whole tree</a>. These are the ones relating to valid-jsdoc. A few remain, but will need work by teams to fix the failur</li>
<li>The “Black” python formatter has now been<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2006716"> replaced by “Ruff”</a>.</li>
<li>Marco greatly simplified the code coverage infrastructure, getting rid of two Heroku services, a frontend service, and a lot of code. The code coverage official UI is now Searchfox.</li>
<li>Marco added a <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2017368">new mach command</a> (“./mach coverage-report”) to generate a coverage report from a push. The command is documented on the <a href="https://firefox-source-docs.mozilla.org/tools/code-coverage/index.html#generate-report-locally">code coverage page</a> in the Firefox source docs.</li>
<li>Teklia added added support for Github pull requests to Code Review Bot (prototype)</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-pdfjs-8" name="p-293819-pdfjs-8"></a>PDF.js</h4>
<ul>
<li>Calixte finished the implementation of the new reorganize and split functionality in PDF, which will ship in Firefox 150! Users will be able to delete, copy, move pages, and to export a subset of pages to a new PDF.</li>
<li>Nicolò Ribaudo implemented the ability to open context menus on images in PDFs, allowing users to perform actions they are used to (such as downloading images). This was a <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1012805">long standing feature request</a> (11 years!).</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-firefox-translations-9" name="p-293819-firefox-translations-9"></a>Firefox Translations</h4>
<ul>
<li>Evgeny Pavlov, Jaume Zaragoza-Bernabeu, and Sergio Ortiz Rojas contributed to training both new and improved Translations models for use in Firefox.
<ul>
<li>Bosnian</li>
<li>Croatian</li>
<li>Norwegian Bokmål</li>
<li>Serbian</li>
<li>Thai</li>
<li>Traditional Chinese</li>
<li>Vietnamese</li>
</ul>
</li>
<li>Erik Nordin fixed an issue where text contained within stand-alone SVG images was not being translated (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2003545">Bug 2003545</a>).</li>
<li>Erik Nordin reworked the Translations settings to be compatible with the upcoming about:settings redesign (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2002127">Bug 2002127</a>).</li>
<li>Erik Nordin helped design a system to control the enablement of <a href="https://searchfox.org/firefox-main/source/toolkit/components/ml/AIFeature.sys.mjs" rel="noopener nofollow ugc">AI Features</a> within Firefox, and worked to make the entire Translations feature set have the capability to be turned off and back on within the same browsing session (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010922">Bug 2010922</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010993">Bug 2010993</a>).</li>
<li>Erik Nordin reworked the about:translations page in order to get it ready for an official release with a URL-bar QuickAction entry point. (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004463">Bug 2004463</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016677">Bug 2016677</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2015798"> Bug 2015798</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016658"> Bug 2016658</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016675"> Bug 2016675</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016690">Bug 2016690</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019753"> Bug 2019753</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020014"> Bug 2020014</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020062"> Bug 2020062</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020067"> Bug2020067</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022838"> Bug2022838</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1814168">Bug 1814168</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1814195"> Bug 1814195</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1841109"> Bug 1841109</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1869772"> Bug 1869772</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1879933"> Bug 1879933</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1970962"> Bug 1970962</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1990333"> Bug 1990333</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1991224"> Bug 1991224</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1992230"> Bug 1992230</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1992231"> Bug 1992231</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1992232"> Bug 1992232</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1992233"> Bug 1992233</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2000959"> Bug 2000959</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004471"> Bug 2004471</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004473"> Bug 2004473</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019119"> Bug 2019119</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019120"> Bug 2019120</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1970963">Bug 1970963</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004454"> Bug 2004454</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010399"> Bug 2010399</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2023677"> Bug 2023677</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1836451"> Bug 1836451</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1999999"> Bug 1999999</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004476"> Bug 2004476</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004477"> Bug 2004477</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004479"> Bug 2004479</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004962"> Bug 2004962</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2007007"> Bug 2007007</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2007194"> Bug 2007194</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2007551"> Bug 2007551</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008213"> Bug 2008213</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008257"> Bug 2008257</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010335"> Bug 2010335</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019116"> Bug 2019116</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019117"> Bug 2019117</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019121"> Bug 2019121</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019123"> Bug 2019123</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020697"> Bug 2020697</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020841"> Bug 2020841</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2024467"> Bug 2024467</a>)
<ul>
<li>Thank you to Dasha Andriyenko for designing the visuals and UX of the page.</li>
<li>Thank you to Kim Bryant for managing the product and release considerations.</li>
<li>Thank you to Sam Foster and Greg Tatum who reviewed a significant portion of the code.</li>
<li>Thank you to Ciprian Georgiu and Giorgia Nichita for testing quality assurance.</li>
<li>Thank you to Anna Yeddi for reviewing engineering accessibility characteristics.</li>
<li>Thank you to Dale Harvey for designing the QuickAction system that this feature plugs into.</li>
</ul>
</li>
<li>Leonardo Paffi improved our testing capabilities by allowing us to serve inline HTML on the fly, rather than having to add an HTML file into the repository. This eases the burden of overhead to test special-case language characteristics, and ultimately helped us release Norwegian Bokmål (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1996967">Bug 1996967</a>).</li>
<li>Leonardo Paffi improved our handling of the macro language tag for Norwegian (no) to be compatible with our support for Norwegian Bokmål translations (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019123">Bug 2019123</a>).</li>
<li>Tyler Etchart removed in-code references to quality estimation models, which are not utilized during translation inference within Firefox (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1889753">Bug 1889753</a>).</li>
<li>Tyler Etchart updated the generated Translations WASM JavaScript code to have explicit. comments expressing that the file is generated and should not be modified (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1968038">Bug 1968038</a>).</li>
<li>Tyler Etchart removed some old dead code related to prior ideas for Translations within Firefox (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1996681">Bug 1996681</a>).</li>
<li>Emilio Cobos Álvarez fixed an issue where the checkboxes within the Full-Page Translations Panel settings menu were no longer appearing (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010234">Bug 2010234</a>).</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-phabricator-moz-phab-and-lando-10" name="p-293819-phabricator-moz-phab-and-lando-10"></a>Phabricator, moz-phab, and Lando</h4>
<ul>
<li>Connor Sheehan implemented ETL from Lando to STMO, which allows us to get better visibility into lando’s performance and usage, e.g., the new uplift feature: <a class="inline-onebox" href="https://sql.telemetry.mozilla.org/dashboard/uplift-dashboard?p_date_range=d_last_12_months">Client Challenge</a></li>
<li>Zeid continues spear-heading the GitHub PR pilot, gathering feedback and fixing usability issues as they are reported. One key focus was on supporting triggering the Code Review Bot on request, via pushes to try.</li>
<li>Olivier Mehani added backward-compatible support for try pushes in the new instance of lando. It will become the default soon, but you can try it out now by setting <code>LANDO_TRY_CONFIG=lando-prod-new</code> in your environment prior to running `mach try .</li>
<li>Olivier Mehani landed a small change to lando, to make the current Tree Status visible on main landing pages (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2025629">Bug 2025629</a>). This, with the landing queue visible on the job details pages, should help get a better understanding of why jobs sometimes seem to take longer than expected to land.</li>
<li>moz-phab had several new releases:
<ul>
<li>Suhaib Mujahid added the --ai flag and submit.ai_review commit option to request an AI review of patches at submission time.</li>
<li>Johan Lorenzo added the --test-plan flag to enable submitting a test plan from the CLI, which is useful for working with AI agents</li>
<li>See the release notes here:
<ul>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-8-2-released/147246/1">MozPhab 2.8.2 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-8-3-released/147559/1">MozPhab 2.8.3 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-9-0-released/147579/1">MozPhab 2.9.0 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-9-1-released/147741/1">MozPhab 2.9.1 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-10-0-released/147778/1">MozPhab 2.10.0 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-11-0-released/147789/1">MozPhab 2.11.0 Released</a></li>
<li><a href="https://discourse.mozilla.org/t/mozphab-2-11-1-released/147821/1">https://discourse.mozilla.org/t/mozphab-2-11-1-released/147821/1 </a></li>
</ul>
</li>
</ul>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-release-engineering-and-release-management-11" name="p-293819-release-engineering-and-release-management-11"></a>Release Engineering and Release Management</h4>
<ul>
<li>Ben Hearsum added <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1837440">new tests to verify update integrity on mozilla-central</a>.</li>
<li>Julien Cristau updated the docker images for many build and related tasks from Debian 12 to Debian 13</li>
<li>Relman streamlined the release process by removing the Nightly soft code freeze and adjusting the Beta schedule to reduce end-of-cycle friction, create more effective stabilization time, and simplify release candidate workflows.</li>
<li>We now ship to the Xiaomi Store.</li>
<li>Delivered mid-cycle ESR dot releases to address critical security fixes ahead of the standard cadence, improving responsiveness while coordinating across multiple ESR versions and release channels.</li>
<li>Andrew Halberstadt helped support and build out the Firefox Enterprise release pipeline.</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-release-operations-12" name="p-293819-release-operations-12"></a>Release Operations</h4>
<ul>
<li>Mark Cornmesser improved Windows hardware management, including self-configuration and self-deployment capabilities, automated BIOS management, and standardization of BIOS settings across performance testing environments to ensure consistency and reliability.</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-other-13" name="p-293819-other-13"></a>Other</h4>
<ul>
<li>
<p>Thanks to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2013401">Bug #2013401</a> mozilla::Maybe&lt;scalar_type&gt; generates better and denser code, which led to a reduction of 300kB for libxul.so</p>
</li>
<li>
<p>Thanks to <a href="https://github.com/llvm/llvm-project/pull/184136" rel="noopener nofollow ugc">A new clang-tidy pass</a> we’ve been able to automatically add std::move in location where it could improve performance (see <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2012658">Bug 2012658</a>)</p>
</li>
</ul>
<p>Thanks for reading and see you next quarter!</p>
            <p><small>1 post - 1 participant</small></p>
            <p><a href="https://discourse.mozilla.org/t/engineering-effectiveness-newsletter-q1-2026-edition/147880">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] RabbitMQ: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3495689/it-security-nachrichten/neu-mittel-rabbitmq-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495689/it-security-nachrichten/neu-mittel-rabbitmq-mehrere-schwachstellen/</guid>
<pubDate>Thu, 07 May 2026 13:08:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Synthetic Monitoring vs. Real User Monitoring: Vergleich von Lab- und Field Data]]></title>
<description><![CDATA[In der Web-Performance-Analyse spielen zwei Ansätze eine zentrale Rolle: Synthetic Monitoring prüft die Website proaktiv mit simulierten Nutzerinnen und Nutzern (Lab Data), während Real User Monitoring die tatsächlichen Erlebnisse echter Besucherinnen und Besucher misst (Field Data). Unser Vergle...]]></description>
<link>https://tsecurity.de/de/3451376/server/synthetic-monitoring-vs-real-user-monitoring-vergleich-von-lab-und-field-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3451376/server/synthetic-monitoring-vs-real-user-monitoring-vergleich-von-lab-und-field-data/</guid>
<pubDate>Tue, 21 Apr 2026 14:16:35 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/rabbitmq-t.jpg" width="1200" height="630" alt=""><br>In der Web-Performance-Analyse spielen zwei Ansätze eine zentrale Rolle: Synthetic Monitoring prüft die Website proaktiv mit simulierten Nutzerinnen und Nutzern (Lab Data), während Real User Monitoring die tatsächlichen Erlebnisse echter Besucherinnen und Besucher misst (Field Data). Unser Vergleich von Synthetic Monitoring vs. Real User Monitoring zeigt, wann welcher Ansatz sinnvoll ist und wie beide Methoden strategisch kombiniert werden können.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Apache Kafka flexed to support queues]]></title>
<description><![CDATA[Since its initial release in 2011, Apache Kafka has cemented itself as the de facto platform for event streaming. Kafka enthusiast Tim Berglund often refers to it as the “universal data substrate.” This is made possible in large part by the Kafka ecosystem that enables connectivity between Kafka ...]]></description>
<link>https://tsecurity.de/de/3395486/ai-nachrichten/how-apache-kafka-flexed-to-support-queues/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395486/ai-nachrichten/how-apache-kafka-flexed-to-support-queues/</guid>
<pubDate>Tue, 31 Mar 2026 11:17:43 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Since its initial release in 2011, <a href="https://www.infoworld.com/article/2334545/what-is-apache-kafka-scalable-event-streaming.html">Apache Kafka</a> has cemented itself as the de facto platform for event streaming. Kafka enthusiast Tim Berglund often refers to it as the “universal data substrate.” This is made possible in large part by the Kafka ecosystem that enables connectivity between Kafka and external systems (Kafka Connect) and a Java stream processing library (Kafka Streams).</p>



<p>The latest release of Apache Kafka delivers the queue-like consumption semantics of point-to-point messaging. After many hours of development and testing in recent releases, this feature is generally available in Kafka 4.2.</p>



<p>Let’s start with a quick “compare-and-contrast” of event streaming and message queuing. Event streaming is for high-volume, real-time processing of an unbounded, continuous stream of data, and it allows for consumers to replay old events as needed. Consumer applications record the offset (the ordinal position in each topic partition) of the last event Kafka successfully processed. If a consumer terminates or restarts, it’s able to resume processing the assigned partition from the last committed offset. Example use cases include internet ad attribution, updating ride-share status, and monitoring for credit card fraud. This is the space where Kafka has thrived, with adoption by over <a href="https://kafka.apache.org/">80</a>% of all Fortune 100 companies.</p>



<p>Message queues are used for point-to-point communication, where a message is typically consumed once and removed from the queue. Unlike with event streaming, consuming applications are able to acknowledge each message. This messaging pattern decouples applications and services via guaranteed, one-time processing for tasks such as in-app notifications to mobile devices, generating payroll records, or calling an AI model. Popular platforms in this space include RabbitMQ, ActiveMQ, and IBM MQ.</p>



<p>These message queue use cases have been a “square peg in a round hole” for Apache Kafka. Why? For starters, scaling the “traditional” Kafka consumer group is constrained by the number of topic partitions. Most notably, Kafka consumers don’t have message-level acknowledgement semantics. These features enable consumers’ message queue systems to cooperatively operate on messages in a queue.</p>



<p>This is the major motivation behind <a href="https://www.youtube.com/watch?v=Wb0xyqgaIqw">KIP-932: Queues for Kafka</a>. Let’s see how this Kafka implementation of message queuing could be an important tool in your event-driven architecture.</p>



<h2 class="wp-block-heading">Scaling Kafka consumer applications</h2>



<p>Traditionally, parallel processing of Kafka topic data is constrained by the number of partitions of the topic being consumed. The broker assigns consumption of each partition of the topic to a single member of a consumer group. Once the membership of the consumer group equals the partitions of the topic, any new consumers added to the group will be idle.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?w=1024" alt="Confluent Queues for Kafka 01" class="wp-image-4143972" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?quality=50&amp;strip=all 1676w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=300%2C182&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=768%2C466&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=1024%2C621&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=1536%2C931&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=1150%2C697&amp;quality=50&amp;strip=all 1150w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=277%2C168&amp;quality=50&amp;strip=all 277w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=139%2C84&amp;quality=50&amp;strip=all 139w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=792%2C480&amp;quality=50&amp;strip=all 792w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=594%2C360&amp;quality=50&amp;strip=all 594w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-01.png?resize=412%2C250&amp;quality=50&amp;strip=all 412w" width="1024" height="621" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>This diagram illustrates three instances in a consumer group subscribed to a topic with three partitions — meaning we’ve maxed out our parallel processing potential for this topic.</p>
</figcaption></figure><p class="imageCredit">Confluent</p></div>



<p>KIP-932 adds a new type of group called a share group. Nothing changes about how the data is written to Kafka by producer applications or how data is stored in Kafka. Your event streaming use cases can operate on the same topics.</p>



<p>Share groups introduce a new cooperative consumption model, where consumers in a share group work in a similar fashion to consumers/subscribers in message queuing systems. On the broker, each topic-partition has a corresponding share partition which tracks the lifecycle of each message in relation to the share group. This allows the share consumers to be scaled beyond the number of topic partitions.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?w=1024" alt="Confluent Queues for Kafka 02" class="wp-image-4143973" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?quality=50&amp;strip=all 2852w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=300%2C214&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=768%2C547&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=1024%2C730&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=1536%2C1094&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=2048%2C1459&amp;quality=50&amp;strip=all 2048w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=978%2C697&amp;quality=50&amp;strip=all 978w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=236%2C168&amp;quality=50&amp;strip=all 236w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=118%2C84&amp;quality=50&amp;strip=all 118w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=674%2C480&amp;quality=50&amp;strip=all 674w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=505%2C360&amp;quality=50&amp;strip=all 505w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-02.png?resize=351%2C250&amp;quality=50&amp;strip=all 351w" width="1024" height="730" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>This diagram depicts the new cooperative consumption model — where multiple members of the consumer group process data from a single topic partition.</p>
</figcaption></figure><p class="imageCredit">Confluent</p></div>



<p>This cooperative consumption from a topic partition also means we lose the partition-level processing order guarantees of the “traditional” Kafka consumer. That’s the trade-off for this scaling, but cooperative consumption also is intended for use cases where throughput and scaling take precedence over the order of processing.</p>



<h2 class="wp-block-heading">Message-level acknowledgement</h2>



<p>The APIs for KIP-932 should be familiar to developers who are already using Kafka. For starters, nothing changes about how events are produced to Kafka topics. On the consumer side, the <code>KafkaShareConsumer</code> interface is very similar to the existing <code>KafkaConsumer</code>. Consumer applications will poll for available messages and process each resulting <code>ConsumerRecord</code> instance.</p>



<p>The consumers now have the ability to acknowledge the delivery of each record on an individual basis. By default, every message is implicitly acknowledged as successfully processed. However, there are scenarios where the developer needs more fine-grained controls, particularly around error handling and long-running tasks.</p>



<p>By using the value of <code>explicit</code> for the consumer configuration’s <code>share.acknowledgement.mode</code>, the code takes on the responsibility of specifying how each message should be acknowledged. The available <code>AcknowledgementType</code> values are <code>ACCEPT</code>, <code>RELEASE</code>, <code>REJECT</code>, and <code>RENEW</code>. These values influence the state of each message in relation to the share group. Those states are <code>AVAILABLE</code>, <code>ACQUIRED</code>, <code>ACKNOWLEDGED</code>, and <code>ARCHIVED</code>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?w=1024" alt="Confluent Queues for Kafka 03" class="wp-image-4143976" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?quality=50&amp;strip=all 2096w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=300%2C195&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=768%2C500&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=1024%2C666&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=1536%2C1000&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=2048%2C1333&amp;quality=50&amp;strip=all 2048w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=1071%2C697&amp;quality=50&amp;strip=all 1071w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=258%2C168&amp;quality=50&amp;strip=all 258w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=129%2C84&amp;quality=50&amp;strip=all 129w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=738%2C480&amp;quality=50&amp;strip=all 738w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=553%2C360&amp;quality=50&amp;strip=all 553w, https://b2b-contenthub.com/wp-content/uploads/2026/03/Confluent-Queues-for-Kafka-03.png?resize=384%2C250&amp;quality=50&amp;strip=all 384w" width="1024" height="666" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The state machine that controls the life cycle of messages based on these acknowledgement types is detailed in this diagram.</p>
</figcaption></figure><p class="imageCredit">Confluent</p></div>



<p>Only messages in an <code>AVAILABLE</code> state can be fetched by a consumer. When fetched, a message transitions to the <code>ACQUIRED</code> state and a delivery count for that message is incremented. This effectively “locks” this message from fetches by other members of the share group.</p>



<p>Once <code>ACQUIRED</code>, a message is expected to be processed in a finite amount of time. If this “lock” or “lease” expires, the message is either sent back to the <code>ACQUIRED</code> state or moved to an <code>ARCHIVED</code> state, based on the delivery count of the message. The state and delivery count of each message is tracked in the share partition. This provides for a built-in retry mechanism developers can use in the event of a condition where the message process could be reattempted, as the message could be acknowledged using the <code>RELEASE</code> type.</p>



<p>If message processing completes successfully, that message is acknowledged with the <code>ACCEPT</code> type. This transitions the message to the <code>ACKNOWLEDGED</code> state.</p>



<p>There are cases where processing takes a non-deterministic amount of time. Perhaps the consumer calls a third-party or partner API. Maybe it’s augmenting the message with the result of an LLM call. These aren’t “failures,” and the processing code may need more time to complete. In this case, acknowledge the message with the <code>RENEW</code> type to reset the lock. </p>



<h2 class="wp-block-heading">Unifying messaging protocols and infrastructure</h2>



<p>Many organizations have both event streaming and message queuing use cases. This often means operators are maintaining and supporting Apache Kafka and an older message queuing system. Developers integrate applications with different messaging libraries and protocols in the same application code base. All of this happens as the C-suite is asking why we’re paying for multiple messaging solutions.</p>



<p>Consolidating these messaging use cases onto Apache Kafka will make producing applications simpler to develop, deploy, upgrade, and maintain. It will also help consumer applications scale to meet the needs and SLAs of the messages being processed.</p>



<p>Unlike traditional message queue systems, events in these “queues” enjoy the durability and storage guarantees we’ve come to rely on in Apache Kafka. Developers of consumer applications determine if the events should be processed as event streams or queues.</p>



<p>Operators and SREs (<a href="https://www.infoworld.com/article/2257232/what-is-an-sre-the-vital-role-of-the-site-reliability-engineer.html">site reliability engineers</a>) tend to like simplicity. (That could be due to the correlation between simplicity and the number of production incidents.) Unifying these messaging platforms means fewer systems to configure, deploy and patch. And that also addresses the concerns of the C-suite — lowering the total cost of ownership for the overall application infrastructure.</p>



<h2 class="wp-block-heading">What queues for Kafka means for teams</h2>



<p>KIP-932 brings long-awaited point-to-point semantics to Apache Kafka. This implementation layers queue-like consumption and message-level acknowledgment onto the durability, scalability, and throughput that have made Kafka mission-critical infrastructure for businesses from startups to large enterprises.</p>



<p>For development teams, this means writing applications against a single messaging API rather than juggling multiple protocols. For operations teams, it means consolidating infrastructure and reducing complexity. And for organizations, it means lower total cost of ownership without sacrificing the specific semantics each use case requires.</p>



<p>KIP-932 is available in Apache Kafka 4.2 and <a href="https://www.confluent.io/blog/2026-q1-confluent-cloud-launch/?session_ref=direct">Confluent Cloud</a>, with support coming to Confluent Platform version 8.2. Developers can explore the implementation and start testing queue-based consumption patterns now. For more about KIP-932 and other event streaming topics, visit <a href="https://developer.confluent.io/">Confluent Developer</a> for free learning resources curated by our team of experts.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[(g+) Masstransit und RabbitMQ: Events ohne Datenchaos]]></title>
<description><![CDATA[Bei eventbasierten Systemen gibt es typische Fehler, die sich erst im Produktivbetrieb zeigen. Inbox und Outbox Patterns helfen, genau diese kontrollierbar zu machen. Ein Deep Dive von Rene Koch (Softwareentwicklung, API)]]></description>
<link>https://tsecurity.de/de/3380017/it-nachrichten/g-masstransit-und-rabbitmq-events-ohne-datenchaos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3380017/it-nachrichten/g-masstransit-und-rabbitmq-events-ohne-datenchaos/</guid>
<pubDate>Wed, 25 Mar 2026 13:32:27 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bei eventbasierten Systemen gibt es typische Fehler, die sich erst im Produktivbetrieb zeigen. Inbox und Outbox Patterns helfen, genau diese kontrollierbar zu machen. Ein Deep Dive von Rene Koch (<a href="https://www.golem.de/specials/softwareentwicklung/">Softwareentwicklung</a>, <a href="https://www.golem.de/specials/api/">API</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=206900&amp;page=1&amp;ts=1774441801" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (java-25-openjdk, openssl, and python3.9), Debian (gimp, libmatio, pyasn1, and python-django), Fedora (perl-HarfBuzz-Shaper, python-tinycss2, and weasyprint), Mageia (glib2.0), Oracle (curl, fence-agents, gcc-toolset-15-binutils, glibc, grafana, java...]]></description>
<link>https://tsecurity.de/de/3242036/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3242036/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 29 Jan 2026 15:36:46 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (java-25-openjdk, openssl, and python3.9), <b>Debian</b> (gimp, libmatio, pyasn1, and python-django), <b>Fedora</b> (perl-HarfBuzz-Shaper, python-tinycss2, and weasyprint), <b>Mageia</b> (glib2.0), <b>Oracle</b> (curl, fence-agents, gcc-toolset-15-binutils, glibc, grafana, java-1.8.0-openjdk, kernel, mariadb, osbuild-composer, perl, php:8.2, python-urllib3, python3.11, python3.11-urllib3, python3.12, and python3.12-urllib3), <b>SUSE</b> (alloy, avahi, bind, buildah, busybox, container-suseconnect, coredns, gdk-pixbuf, gimp, go1.24, go1.24-openssl, go1.25, helm, kernel, kubernetes, libheif, libpcap, libpng16, openjpeg2, openssl-1_0_0, openssl-1_1, openssl-3, php8, python-jaraco.context, python-marshmallow, python-pyasn1, python-urllib3, python-virtualenv, python311, python313, rabbitmq-server, xen, zli, and zot-registry), and <b>Ubuntu</b> (containerd, containerd-app and wlc).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Cross-Site Scripting in rabbitmq-server (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3240555/unix-server/security-cross-site-scripting-in-rabbitmq-server-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3240555/unix-server/security-cross-site-scripting-in-rabbitmq-server-suse/</guid>
<pubDate>Wed, 28 Jan 2026 23:45:58 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-40256 | Veritas NetBackup Snapshot Manager prior 10.2.0.1 RabbitMQ Service certificate validation (EUVD-2023-44853)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Veritas NetBackup Snapshot Manager. This affects an unknown function of the component RabbitMQ Service. The manipulation leads to improper certificate validation.

This vulnerability is traded as CVE-2023-40256. It is possible to initiate th...]]></description>
<link>https://tsecurity.de/de/3237850/sicherheitsluecken/cve-2023-40256-veritas-netbackup-snapshot-manager-prior-10201-rabbitmq-service-certificate-validation-euvd-2023-44853/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3237850/sicherheitsluecken/cve-2023-40256-veritas-netbackup-snapshot-manager-prior-10201-rabbitmq-service-certificate-validation-euvd-2023-44853/</guid>
<pubDate>Tue, 27 Jan 2026 19:22:26 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">critical</a> has been reported in <a href="https://vuldb.com/?product.veritas:netbackup_snapshot_manager">Veritas NetBackup Snapshot Manager</a>. This affects an unknown function of the component <em>RabbitMQ Service</em>. The manipulation leads to improper certificate validation.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.236850">CVE-2023-40256</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (gimp, glib2, go-toolset:rhel8, golang, java-17-openjdk, java-21-openjdk, kernel, net-snmp, pcs, and thunderbird), Debian (apache2, imagemagick, incus, inetutils, libuev, openjdk-17, php7.4, python3.9, shapelib, taglib, and zvbi), Fedora (mingw-glib2...]]></description>
<link>https://tsecurity.de/de/3234940/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3234940/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 26 Jan 2026 15:07:16 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (gimp, glib2, go-toolset:rhel8, golang, java-17-openjdk, java-21-openjdk, kernel, net-snmp, pcs, and thunderbird), <b>Debian</b> (apache2, imagemagick, incus, inetutils, libuev, openjdk-17, php7.4, python3.9, shapelib, taglib, and zvbi), <b>Fedora</b> (mingw-glib2, mingw-harfbuzz, mingw-libsoup, mingw-openexr, pgadmin4, python3.11, python3.12, python3.9, and wireshark), <b>Gentoo</b> (Asterisk, Commons-BeanUtils, GIMP, inetutils, and Vim, gVim), <b>Mageia</b> (kernel), <b>Oracle</b> (glib2, java-17-openjdk, java-21-openjdk, and libpng), <b>Red Hat</b> (java-17-openjdk, java-21-openjdk, kernel, and kernel-rt), <b>SUSE</b> (azure-cli-core, bind, buildah, chromium, coredns, glib2, harfbuzz, kernel, kernel-firmware, libheif, libvirt, openCryptoki, openvswitch, podman, python, python-urllib3, rabbitmq-server, and vlang), and <b>Ubuntu</b> (cjson).]]></content:encoded>
</item>
<item>
<title><![CDATA[Scaling Messaging with Confidence: VMware vSphere Kubernetes Service and Tanzu RabbitMQ]]></title>
<description><![CDATA[Modern applications depend on reliable messaging. Getting that infrastructure deployed and operated should be straightforward, not a separate engineering project. Running VMware vSphere Kubernetes Service (VKS) with Tanzu RabbitMQ does exactly that. This setup lets teams run RabbitMQ on VKS, a CN...]]></description>
<link>https://tsecurity.de/de/3226872/downloads/scaling-messaging-with-confidence-vmware-vsphere-kubernetes-service-and-tanzu-rabbitmq/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3226872/downloads/scaling-messaging-with-confidence-vmware-vsphere-kubernetes-service-and-tanzu-rabbitmq/</guid>
<pubDate>Wed, 21 Jan 2026 22:45:53 +0100</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="300" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/01/vmw-prod-icon-vSphere-kubernetes-service-rgb-e1769030511461.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/01/vmw-prod-icon-vSphere-kubernetes-service-rgb-e1769030511461.png 300w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/01/vmw-prod-icon-vSphere-kubernetes-service-rgb-e1769030511461.png?resize=150,150 150w" sizes="(max-width: 300px) 100vw, 300px"></div>
<p>Modern applications depend on reliable messaging. Getting that infrastructure deployed and operated should be straightforward, not a separate engineering project. Running VMware vSphere Kubernetes Service (VKS) with Tanzu RabbitMQ does exactly that. This setup lets teams run RabbitMQ on VKS, a CNCF-certified Kubernetes runtime that is built-in with VMware Cloud Foundation (VCF), without introducing a … <a href="https://blogs.vmware.com/cloud-foundation/2026/01/21/scaling-messaging-with-confidence-vmware-vsphere-kubernetes-service-and-tanzu-rabbitmq/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/01/21/scaling-messaging-with-confidence-vmware-vsphere-kubernetes-service-and-tanzu-rabbitmq/">Scaling Messaging with Confidence: VMware vSphere Kubernetes Service and Tanzu RabbitMQ</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [mittel] RabbitMQ: Schwachstelle ermöglicht Cross-Site Scripting]]></title>
<description><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.]]></description>
<link>https://tsecurity.de/de/3144869/it-security-nachrichten/update-mittel-rabbitmq-schwachstelle-ermoeglicht-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3144869/it-security-nachrichten/update-mittel-rabbitmq-schwachstelle-ermoeglicht-cross-site-scripting/</guid>
<pubDate>Mon, 08 Dec 2025 09:06:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in RabbitMQ ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, kernel-rt, libtiff, squid:4, and thunderbird), Debian (strongswan and webkit2gtk), Fedora (pcre2, qt5-qtbase, squid, unbound, and xen), Mageia (icu and libtpms), Oracle (java-1.8.0-openjdk, java-17-openjdk, java-21-openjdk, kernel, squid:4, ...]]></description>
<link>https://tsecurity.de/de/3066581/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3066581/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 28 Oct 2025 14:22:42 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, kernel-rt, libtiff, squid:4, and thunderbird), <b>Debian</b> (strongswan and webkit2gtk), <b>Fedora</b> (pcre2, qt5-qtbase, squid, unbound, and xen), <b>Mageia</b> (icu and libtpms), <b>Oracle</b> (java-1.8.0-openjdk, java-17-openjdk, java-21-openjdk, kernel, squid:4, and thunderbird), <b>Red Hat</b> (libtiff, squid, squid:4, and webkit2gtk3), <b>SUSE</b> (cmake, dracut-saltboot, erlang, exim, expat, ffmpeg-4, firefox, golang-github-prometheus-alertmanager, haproxy, java-11-openjdk, kernel, libxslt, multi-linux-manager, openssl-3, podman, rabbitmq-server, spacewalk-web, strongswan, and wireshark), and <b>Ubuntu</b> (gst-plugins-good1.0, linux-aws-5.15, radare2, ruby2.3, ruby2.5, ruby2.7, and strongswan).]]></content:encoded>
</item>
<item>
<title><![CDATA[Preisgabe von Informationen in rabbitmq-server (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3065197/it-security-nachrichten/preisgabe-von-informationen-in-rabbitmq-server-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3065197/it-security-nachrichten/preisgabe-von-informationen-in-rabbitmq-server-suse/</guid>
<pubDate>Mon, 27 Oct 2025 22:04:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel and kernel-rt), Fedora (expat), Red Hat (kernel and multiple packages), SUSE (avahi, busybox, busybox-links, kernel, sevctl, tcpreplay, thunderbird, and tor), and Ubuntu (isc-kea, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-low...]]></description>
<link>https://tsecurity.de/de/3001973/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3001973/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 24 Sep 2025 15:22:06 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel and kernel-rt), <b>Fedora</b> (expat), <b>Red Hat</b> (kernel and multiple packages), <b>SUSE</b> (avahi, busybox, busybox-links, kernel, sevctl, tcpreplay, thunderbird, and tor), and <b>Ubuntu</b> (isc-kea, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-aws-6.8, linux-gcp-6.8, linux-aws-fips, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-realtime, python-pip, and rabbitmq-server).]]></content:encoded>
</item>
<item>
<title><![CDATA[Preisgabe von Informationen in RabbitMQ (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3001239/it-security-nachrichten/preisgabe-von-informationen-in-rabbitmq-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3001239/it-security-nachrichten/preisgabe-von-informationen-in-rabbitmq-ubuntu/</guid>
<pubDate>Wed, 24 Sep 2025 09:20:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[USN-7763-1: RabbitMQ Server vulnerability]]></title>
<description><![CDATA[It was discovered that RabbitMQ Server incorrectly included authorization
headers when logging. A local attacker could possibly use this issue to
obtain sensitive information.]]></description>
<link>https://tsecurity.de/de/3000705/unix-server/usn-7763-1-rabbitmq-server-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3000705/unix-server/usn-7763-1-rabbitmq-server-vulnerability/</guid>
<pubDate>Wed, 24 Sep 2025 01:05:18 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that RabbitMQ Server incorrectly included authorization
headers when logging. A local attacker could possibly use this issue to
obtain sensitive information.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (container-tools:rhel8, kernel, and podman), Debian (node-sha.js), Fedora (firefox, kea, and perl-JSON-XS), Mageia (java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, java-latest-openjdk), Oracle (kernel, libarchive, podman, and python-cryptograph...]]></description>
<link>https://tsecurity.de/de/2989243/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2989243/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 17 Sep 2025 15:21:27 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (container-tools:rhel8, kernel, and podman), <b>Debian</b> (node-sha.js), <b>Fedora</b> (firefox, kea, and perl-JSON-XS), <b>Mageia</b> (java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, java-latest-openjdk), <b>Oracle</b> (kernel, libarchive, podman, and python-cryptography), <b>Red Hat</b> (multiple packages, mysql:8.4, and python3.11), <b>SUSE</b> (expat, java-1_8_0-ibm, krb5, libavif, net-tools, nginx, nvidia-open-driver-G06-signed, onefetch, pcp, rabbitmq-server313, raptor, and vim), and <b>Ubuntu</b> (libyang2, linux, linux-aws, linux-aws-5.4, linux-bluefield, linux-gcp,
 linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot,
 linux-kvm, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp, linux-aws-fips, linux-fips, linux-gcp-fips, and python-xmltodict).]]></content:encoded>
</item>
<item>
<title><![CDATA[Preisgabe von Informationen in rabbitmq-server313 (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2987947/it-security-nachrichten/preisgabe-von-informationen-in-rabbitmq-server313-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2987947/it-security-nachrichten/preisgabe-von-informationen-in-rabbitmq-server313-suse/</guid>
<pubDate>Tue, 16 Sep 2025 23:49:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[A Deep Dive into RabbitMQ & Python’s Celery: How to Optimise Your Queues]]></title>
<description><![CDATA[Key lessons I’ve learned running RabbitMQ + Celery in production
The post A Deep Dive into RabbitMQ & Python’s Celery: How to Optimise Your Queues appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/2969263/ai-nachrichten/a-deep-dive-into-rabbitmq-pythons-celery-how-to-optimise-yourqueues/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2969263/ai-nachrichten/a-deep-dive-into-rabbitmq-pythons-celery-how-to-optimise-yourqueues/</guid>
<pubDate>Sat, 06 Sep 2025 23:35:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key lessons I’ve learned running RabbitMQ + Celery in production</p>
<p>The post <a href="https://towardsdatascience.com/deep-dive-into-rabbitmq-pythons-celery-how-to-optimise-your-queues/">A Deep Dive into RabbitMQ &amp; Python’s Celery: How to Optimise Your Queues</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackover 2025 - Rettung eines Redis Cache - Zugriffe synchronisieren mit RabbitMQ Topics]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 2x - Views:28 Microservices sind modern, eine Pipeline mit Message Queues und Cache wird da schnell mal hingeklatscht. In diesem Vortrag seht ihr ein anonymisiertes Fallbeispiel aus einem Projekt, bei dem der Cache inkonsistent wurde, fremde Devs mit Redis-Locks ...]]></description>
<link>https://tsecurity.de/de/2919588/it-security-video/hackover-2025-rettung-eines-redis-cache-zugriffe-synchronisieren-mit-rabbitmq-topics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2919588/it-security-video/hackover-2025-rettung-eines-redis-cache-zugriffe-synchronisieren-mit-rabbitmq-topics/</guid>
<pubDate>Sat, 02 Aug 2025 21:29:10 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/gNqO_99FyUo/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 2x - Views:28 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/gNqO_99FyUo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Microservices sind modern, eine Pipeline mit Message Queues und Cache wird da schnell mal hingeklatscht. In diesem Vortrag seht ihr ein anonymisiertes Fallbeispiel aus einem Projekt, bei dem der Cache inkonsistent wurde, fremde Devs mit Redis-Locks dagegen hielten bis das System lahmte und dann schnell die Firma verließen. Ich zeige euch, wie ich die Message Queues neu sortierte und anschließend alle Locks abschaffte, so dass doch noch ein stabiler Microservice herauskam.<br />
<br />
coco<br />
<br />
https://talks.hackover.de/ho25/talk/GY7EVL/<br />
<br />
#hackover2025<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cross-Site Scripting in rabbitmq-server (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2886120/it-security-nachrichten/cross-site-scripting-in-rabbitmq-server-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2886120/it-security-nachrichten/cross-site-scripting-in-rabbitmq-server-suse/</guid>
<pubDate>Mon, 14 Jul 2025 22:33:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Cross-Site Scripting in rabbitmq-server313 (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2886119/it-security-nachrichten/cross-site-scripting-in-rabbitmq-server313-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2886119/it-security-nachrichten/cross-site-scripting-in-rabbitmq-server313-suse/</guid>
<pubDate>Mon, 14 Jul 2025 22:33:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[IT-Sicherheit: Linux und UNIX gefährdet - Update für IT-Sicherheitshinweis zu RabbitMQ (Risiko]]></title>
<description><![CDATA[Für RabbitMQ wurde ein Update für den IT-Sicherheitshinweis zu einer bekannten Schwachstelle veröffentlicht.]]></description>
<link>https://tsecurity.de/de/2873256/it-security-nachrichten/it-sicherheit-linux-und-unix-gefaehrdet-update-fuer-it-sicherheitshinweis-zu-rabbitmq-risiko/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2873256/it-security-nachrichten/it-sicherheit-linux-und-unix-gefaehrdet-update-fuer-it-sicherheitshinweis-zu-rabbitmq-risiko/</guid>
<pubDate>Tue, 08 Jul 2025 08:18:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Für RabbitMQ wurde ein Update für den <b>IT</b>-Sicherheitshinweis zu einer bekannten Schwachstelle veröffentlicht.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (thunderbird and xmedcon), Fedora (darktable, mbedtls, sudo, and yarnpkg), Mageia (catdoc and php), Red Hat (java-1.8.0-ibm, kernel, python-setuptools, python3, python3.11, python3.12, python3.9, socat, sudo, tigervnc, webkit2gtk3, webkitgtk4, xorg-x11-...]]></description>
<link>https://tsecurity.de/de/2872209/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2872209/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 07 Jul 2025 17:05:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (thunderbird and xmedcon), <b>Fedora</b> (darktable, mbedtls, sudo, and yarnpkg), <b>Mageia</b> (catdoc and php), <b>Red Hat</b> (java-1.8.0-ibm, kernel, python-setuptools, python3, python3.11, python3.12, python3.9, socat, sudo, tigervnc, webkit2gtk3, webkitgtk4, xorg-x11-server, and xorg-x11-server-Xwayland), <b>SUSE</b> (alloy, apache-commons-fileupload, apache2-mod_security2, assimp-devel, chromedriver, clamav, clustershell, corepack22, ctdb, curl, dpkg, erlang-rabbitmq-client, ffmpeg-4, firefox, firefox-esr, flake-pilot, fractal, gdm, ggml-devel-5699, gio-branding-upstream, git-lfs, glib2, glibc, go1.23, go1.24, govulncheck-vulndb, gpg2, grafana, grype, helm, himmelblau, icu, jgit, jq, jupyter-bqplot-jupyterlab, jupyter-jupyterlab-templates, jupyter-matplotlib, jupyter-nbclassic, jupyter-nbdime, jupyter-panel, jupyter-plotly, keylime-ima-policy, kubernetes1.30-apiserver, kubernetes1.31-apiserver, kubernetes1.32-apiserver, libbd_btrfs-devel, libetebase-devel, libmozjs-128-0, libprotobuf-lite31_1_0, libQt5Bootstrap-devel-static-32bit, libsoup, libsoup-2_4-1, libsoup-3_0-0, libspdlog1_15, libssh, libssh-config, libsystemd0, libtpms-devel, libwireshark18, libwx_gtk2u_adv-suse16_0_0, mirrorsorcerer, moarvm, nix, nodejs-electron, nova, oci-cli, opa, openbao, ovmf-202505, pam, pam_pkcs11, perl, perl-32bit, perl-CryptX, perl-File-Find-Rule, perl-YAML-LibYAML, podman, polaris, postgresql-jdbc, pure-ftpd, python-furo-doc, python-requests, python310, python311, python311-Django, python311-Django4, python311-jupyter-core, python311-Pillow, python311-pydata-sphinx-theme, python311-requests, python311-salt, python311-urllib3, python312, python313, python314, python39, radare2, redis, samba, SDL, SDL2, sudo, teleport, thunderbird, tomcat, tomcat10, tomcat11, traefik, traefik2, valkey, velociraptor, vim, xorg-x11-server, and xwayland), and <b>Ubuntu</b> (linux-ibm, linux-intel-iotg, linux-lowlatency, linux-lowlatency-hwe-6.11, and linux-oem-6.14).]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheit: Linux und UNIX gefährdet - IT-Sicherheitshinweis zu neuem Bug bei RabbitMQ]]></title>
<description><![CDATA[... server GitHub Security Advisory (Stand: 19.06.2025). Sicherheitshinweis für RabbitMQ - Risiko: niedrig. Risikostufe: 2 (niedrig) CVSS Base Score: 4 ...]]></description>
<link>https://tsecurity.de/de/2844800/unix-server/it-sicherheit-linux-und-unix-gefaehrdet-it-sicherheitshinweis-zu-neuem-bug-bei-rabbitmq/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2844800/unix-server/it-sicherheit-linux-und-unix-gefaehrdet-it-sicherheitshinweis-zu-neuem-bug-bei-rabbitmq/</guid>
<pubDate>Sun, 22 Jun 2025 06:19:27 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>server</b> GitHub Security Advisory (Stand: 19.06.2025). Sicherheitshinweis für RabbitMQ - Risiko: niedrig. Risikostufe: 2 (niedrig) CVSS Base Score: 4 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheit: Linux und UNIX gefährdet - IT-Sicherheitshinweis zu neuem Bug bei RabbitMQ]]></title>
<description><![CDATA[Für RabbitMQ gibt es einen aktuellen BSI-Sicherheitshinweis.. Wodurch die IT-Sicherheit bei Systemen von Linux und UNIX bedroht wird, ...]]></description>
<link>https://tsecurity.de/de/2844646/it-security-nachrichten/it-sicherheit-linux-und-unix-gefaehrdet-it-sicherheitshinweis-zu-neuem-bug-bei-rabbitmq/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2844646/it-security-nachrichten/it-sicherheit-linux-und-unix-gefaehrdet-it-sicherheitshinweis-zu-neuem-bug-bei-rabbitmq/</guid>
<pubDate>Sun, 22 Jun 2025 01:48:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Für RabbitMQ gibt es einen aktuellen BSI-Sicherheitshinweis.. Wodurch die <b>IT</b>-<b>Sicherheit</b> bei Systemen von Linux und UNIX bedroht wird, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-50200 | RabbitMQ Server up to 3.13.7 log file (EUVD-2025-18689)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in RabbitMQ Server up to 3.13.7. Affected is an unknown function. The manipulation leads to sensitive information in log files.

This vulnerability is traded as CVE-2025-50200. It is possible to launch the attack on the local host. T...]]></description>
<link>https://tsecurity.de/de/2841119/sicherheitsluecken/cve-2025-50200-rabbitmq-server-up-to-3137-log-file-euvd-2025-18689/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2841119/sicherheitsluecken/cve-2025-50200-rabbitmq-server-up-to-3137-log-file-euvd-2025-18689/</guid>
<pubDate>Thu, 19 Jun 2025 21:07:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.rabbitmq:server">RabbitMQ Server up to 3.13.7</a>. Affected is an unknown function. The manipulation leads to sensitive information in log files.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.313374">CVE-2025-50200</a>. It is possible to launch the attack on the local host. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel), Debian (chromium, gst-plugins-bad1.0, node-tar-fs, and ublock-origin), Gentoo (Emacs, File-Find-Rule, GStreamer, GStreamer Plugins, GTK+ 3, LibreOffice, Node.js, OpenImageIO, Python, PyPy, Qt, X.Org X server, XWayland, and YAML-LibYAML), Ma...]]></description>
<link>https://tsecurity.de/de/2827886/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2827886/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 12 Jun 2025 15:51:03 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel), <b>Debian</b> (chromium, gst-plugins-bad1.0, node-tar-fs, and ublock-origin), <b>Gentoo</b> (Emacs, File-Find-Rule, GStreamer, GStreamer Plugins, GTK+ 3, LibreOffice, Node.js, OpenImageIO, Python, PyPy, Qt, X.Org X server, XWayland, and YAML-LibYAML), <b>Mageia</b> (mariadb and roundcubemail), <b>Red Hat</b> (go-toolset:rhel8, golang, grafana, grafana-pcp, gstreamer1-plugins-bad-free, libxml2, libxslt, mod_security, nodejs:20, and perl-FCGI:0.78), <b>Slackware</b> (mozilla), <b>SUSE</b> (docker, docker-compose, iputils, kernel, libsoup, open-vm-tools, rabbitmq-server, rabbitmq-server313, wget, and yelp), and <b>Ubuntu</b> (libsoup2.4 and webkit2gtk).]]></content:encoded>
</item>
<item>
<title><![CDATA[Cross-Site Scripting in rabbitmq-server313 (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2776129/it-security-nachrichten/cross-site-scripting-in-rabbitmq-server313-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2776129/it-security-nachrichten/cross-site-scripting-in-rabbitmq-server313-suse/</guid>
<pubDate>Wed, 14 May 2025 16:34:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (emacs, firefox, gnutls, java-17-openjdk, java-21-openjdk, osbuild-composer, python39:3.9, and thunderbird), Arch Linux (screen), Debian (varnish), Fedora (chromium), Gentoo (Atop, FreeType, and Spidermonkey), Mageia (java-1.8.0-openjdk, java-11-open...]]></description>
<link>https://tsecurity.de/de/2775938/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2775938/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 14 May 2025 15:21:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (emacs, firefox, gnutls, java-17-openjdk, java-21-openjdk, osbuild-composer, python39:3.9, and thunderbird), <b>Arch Linux</b> (screen), <b>Debian</b> (varnish), <b>Fedora</b> (chromium), <b>Gentoo</b> (Atop, FreeType, and Spidermonkey), <b>Mageia</b> (java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, java-latest-openjdk and postgresql15, postgresql13), <b>Oracle</b> (389-ds-base, emacs, firefox, kernel, libsoup, libtiff, mod_auth_openidc:2.3, nodejs:20, nodejs:22, osbuild-composer, python39:3.9, qemu-kvm, ruby, ruby:3.1, ruby:3.3, and thunderbird), <b>Red Hat</b> (.NET 8.0, .NET 9.0, avahi, buildah, corosync, delve and golang, exiv2, expat, firefox, ghostscript, gimp, git, grafana, gvisor-tap-vsock, java-21-openjdk, kernel, kernel-rt, libarchive, libjpeg-turbo, libsoup, libsoup3, libxslt, mod_auth_openidc, nginx, nginx:1.22, nginx:1.24, nodejs22, nodejs:20, nodejs:22, opentelemetry-collector, osbuild-composer, perl, php, php:8.2, php:8.3, podman, python-jinja2, redis, redis:7, rhc, ruby:2.5, skopeo, sqlite, thunderbird, tomcat, tomcat9, valkey, vim, xorg-x11-server-Xwayland, xterm, xz, yelp, and yggdrasil), <b>Slackware</b> (screen), <b>SUSE</b> (apparmor, dirmngr, gimp, golang-github-prometheus-node_exporter, java-11-openj9, java-17-openj9, java-21-openj9, libxmp-devel, python311-Django4, rabbitmq-server313, rke2, and transfig), and <b>Ubuntu</b> (abseil and open-vm-tools).]]></content:encoded>
</item>
<item>
<title><![CDATA[Shodan-Dorks - Dorks for Shodan; a powerful tool used to search for Internet-connected devices]]></title>
<description><![CDATA[This GitHub repository provides a range of search queries, known as "dorks," for Shodan, a powerful tool used to search for Internet-connected devices. The dorks are designed to help security researchers discover potential vulnerabilities and configuration issues in various types of devices such ...]]></description>
<link>https://tsecurity.de/de/2769397/it-security-tools/shodan-dorks-dorks-for-shodan-a-powerful-tool-used-to-search-for-internet-connected-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2769397/it-security-tools/shodan-dorks-dorks-for-shodan-a-powerful-tool-used-to-search-for-internet-connected-devices/</guid>
<pubDate>Sun, 11 May 2025 15:33:40 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEj_CyaABeyGjA0Ll_8pZtRLfDgAp-WXQ_Ds-AMmavEo0GqpCzF1LlqyvutvjapUNIVeCL7WY2f8eXU67JktzZ5jecdY14eWUvMXfYCTQdwHU8Pl-DFb41HL1nrVr8YCsh6UYjSY6TJH7jXLdoGQ2QdE4ZY734fzyJzrfWEI1pSc81Qv0OpdITrVRpEgYJU"><img alt="" data-original-height="662" data-original-width="1183" height="358" src="https://blogger.googleusercontent.com/img/a/AVvXsEj_CyaABeyGjA0Ll_8pZtRLfDgAp-WXQ_Ds-AMmavEo0GqpCzF1LlqyvutvjapUNIVeCL7WY2f8eXU67JktzZ5jecdY14eWUvMXfYCTQdwHU8Pl-DFb41HL1nrVr8YCsh6UYjSY6TJH7jXLdoGQ2QdE4ZY734fzyJzrfWEI1pSc81Qv0OpdITrVRpEgYJU=w640-h358" width="640"></a></div><br> <p>This GitHub repository provides a range of search queries, known as "dorks," for Shodan, a powerful tool used to search for Internet-connected devices. The dorks are designed to help security researchers discover potential <a href="https://www.kitploit.com/search/label/vulnerabilities" target="_blank" title="vulnerabilities">vulnerabilities</a> and <a href="https://www.kitploit.com/search/label/Configuration" target="_blank" title="configuration">configuration</a> issues in various types of devices such as webcams, routers, and servers. This resource is helpful for those interested in exploring network security and conducting <a href="https://www.kitploit.com/search/label/Vulnerability" target="_blank" title="vulnerability">vulnerability</a> scanning, including both beginners and experienced information security professionals. By leveraging this repository, users can improve the security of their own networks and protect against potential attacks.</p> <span><a name="more"></a></span><p><br></p><h3> Shodan Dorks: </h3> <pre><code><br>aa3939fc357723135870d5036b12a67097b03309<br>app="HIKVISION-综合安防管理平台"<br>"AppleHttpServer"<br>"AutobahnPython"<br>basic realm="Kettle"<br>Bullwark<br>cassandra<br>Chromecast<br>"ClickShareSession"<br>"/config/log_off_page.htm"<br>'"connection: upgrade"'<br>"cowboy"<br>cpe:"cpe:2.3:a:apache:cassandra"<br>cpe:"cpe:2.3:a:backdropcms:backdrop"<br>cpe:"cpe:2.3:a:bolt:bolt"<br>cpe:"cpe:2.3:a:cisco:sd-wan"<br>cpe:"cpe:2.3:a:ckeditor:ckeditor"<br>cpe:"cpe:2.3:a:cmsimple:cmsimple"<br>cpe:"cpe:2.3:a:djangoproject:django"<br>cpe:"cpe:2.3:a:djangoproject:django" || http.title:"Django administration"<br>cpe:"cpe:2.3:a:eclipse:jetty"<br>cpe:"cpe:2.3:a:embedthis:appweb"<br>cpe:"cpe:2.3:a:embedthis:goahead"<br>cpe:"cpe:2.3:a:exim:exim"<br>cpe:"cpe:2.3:a:gitlist:gitlist"<br>cpe:"cpe:2.3:a:google:web_server"<br>cpe:"cpe:2.3:a:jfrog:artifactory"<br>cpe:"cpe:2.3:a:kentico:kentico"<br>cpe:"cpe:2.3:a:koha:koha"<br>cpe:"cpe:2.3:a:konghq:docker-kong"<br>cpe:"cpe:2.3:a:laurent_destailleur:awstats"<br>cpe:"cpe:2.3:a:lighttpd:lighttpd"<br>cpe:"cpe:2.3:a:microsoft:internet_information_server"<br>cpe:"cpe:2.3:a:modx:modx_revolution"<br>cpe:"cpe:2.3:a:nodebb:nodebb"<br>cpe:"cpe:2.3:a:nodejs:node.js"<br>cpe:"cpe:2.3:a:openvpn:openvpn_access_server"<br>cpe:"cpe:2.3:a:openwebanalytics:open_web_analytics"<br>cpe:"cpe:2.3:a:oracle:glassfish_server"<br>cpe:"cpe:2.3:a:oracle:iplanet_web_server"<br>cpe:"cpe:2.3:a:php:php"<br>cpe:"cpe:2.3:a:prestashop:prestashop"<br>cpe:"cpe:2.3:a:proftpd:proftpd"<br>cpe:"cpe:2.3:a:public_knowledge_project:open_journal_systems"<br>cpe:"cpe:2.3:a:pulsesecure:pulse_connect_secure"<br>cpe:"cpe:2.3:a:rubyonrails:rails"<br>cpe:"cpe:2.3:a:sensiolabs:symfony"<br>cpe:"cpe:2.3:a:typo3:typo3"<br>cpe:"cpe:2.3:a:vmware:rabbitmq"<br>cpe:"cpe:2.3:a:webedition:webedition_cms"<br>cpe:"cpe:2.3:a:zend:zend_server"<br>cpe:"cpe:2.3:h:zte:f460"<br>cpe:"cpe:2.3:o:canonical:ubuntu_linux"<br>cpe:"cpe:2.3:o:fedoraproject:fedora"<br>cpe:"cpe:2.3:o:microsoft:windows"<br>"DIR-845L"<br>eBridge_JSessionid<br>'ecology_JSessionid'<br>ecology_JSessionid<br>elastic indices<br>"ElasticSearch"<br>ESMTP<br>/geoserver/<br>Graylog<br>'hash:1357418825'<br>html:"access_tokens.db"<br>html:"ACE 4710 Device Manager"<br>html:"ActiveCollab Installer"<br>html:"Administration - Installation - MantisBT"<br>html:"Satis"<br>html:"Akeeba Backup"<br>html:"Amazon EC2 Status"<br>html:"anonymous-cli-metrics.json"<br>html:"ANTEEO"<br>html:"anyproxy"<br>html:"Apache Tomcat"<br>html:"Apdisk"<br>html:"appveyor.yml"<br>html:"aquatronica"<br>html:"Argo CD"<br>html:"Ariang"<br>html:"ASPNETCORE_ENVIRONMENT"<br>html:"atlassian-connect.json"<br>html:"atomcms"<br>html:"auth.json"<br>html:"authorization token is empty"<br>html:"Avaya Aura"<br>html:"AVideo"<br>html:"AWS EC2 Auto Scaling Lab"<br>html:"azure-pipelines.yml"<br>html:"babel.config.js"<br>html:"behat.yml"<br>html:"BeyondTrust"<br>html:"BIG-IP APM"<br>html:"BIG-IP Configuration Utility"<br>html:"bitbucket-pipelines.yml"<br>"html:\"/bitrix/\""<br>html:"blazor.boot.json"<br>html:"Blesta installer"<br>html:"blob.core.windows.net"<br>html:"buildAssetsDir" "nuxt"<br>html:"Calibre"<br>html:"camaleon_cms"<br>html:"Cargo.lock"<br>html:"Cargo.toml"<br>html:"CasaOS"<br>html:"Cassia Bluetooth Gateway Management Platform"<br>html:"/certenroll"<br>html:"/cfadmin/img/"<br>html:"Change Detection"<br>html:"Cisco Expressway"<br>html:"cisco firepower management"<br>html:"Cisco Unity Connection"<br>html:"/citrix/xenapp"<br>html:"ckan 2.8.2" || html:"ckan 2.3"<br>html:"cloud-config.yml"<br>html:"CMS Made Simple Install/Upgrade"<br>html:"codeception.yml"<br>html:"CodeMeter"<br>html:"CodiMD"<br>html:"config.rb"<br>html:"config.ru"<br>html:'content="eArcu'<br>html:"content="Navidrome""<br>html:"ContentPanel SetupWizard"<br>html:"contexts known to this"<br>html:"Coolify" html:"register"<br>html:"Couchbase Sync Gateway"<br>html:"Cox Business"<br>html:"credentials.db"<br>html:"Crontab UI"<br>html:"CrushFTP"<br>html:"cyberpanel"<br>html:"CyberPanel"<br>html:"DashRenderer"<br>html:"Dataease"<br>html:"data-xwiki-reference"<br>"html=\"Decision Center Enterprise console\""<br>html:"Decision Center Enterprise console"<br>html:"DefectDojo Logo"<br>html:"def_wirelesspassword"<br>html:"Dell OpenManage Switch Administrator"<br>'html:"desktop.ini"'<br>html:"DSR-250"<br>html:"DXR.axd"<br>html:"Easy Installer by ViserLab"<br>html:"editorconfig"<br>html:"EJBCA Enterprise Cloud Configuration Wizard"<br>html:"engage - Portail soignant"<br>html:"epihash"<br>html:"eShop Installer"<br>html:"ETL3100"<br>html:"FacturaScripts installer"<br>html:"faradayApp"<br>html:"Femtocell Access Point"<br>html:"FileCatalyst file transfer solution"<br>html:"FleetCart"<br>html:"FleetCart - Installation"<br>html:"Forgejo"<br>html:"FortiPortal"<br>html:"F-Secure Policy Manager"<br>html:ftpconfig<br>html:"ganglia_form.submit()"<br>html:"Generated by The Webalizer"<br>html:"GeniusOcean Installer"<br>html:"gitlab-ci.yml"<br>html:"GitLab Enterprise Edition"<br>html:"git web interface version"<br>html:"go.mod"<br>html:"gradio_mode"<br>html:"Guardfile"<br>html:"HAL Management Console"<br>html:"hgignore"<br>html:"Home - CUPS"<br>html:"HomeWorks Illumination Web Keypad"<br>html:"Honeywell Building Control"<br>html:"https://hugegraph.github.io"<br>html:"human.aspx"<br>html:"ibmdojo"<br>html:"iClock Automatic"<br>html:"IDP Skills Installer"<br>html:"imgproxy"<br>html:"Installation" html:"itop"<br>html:"Installation Panel"<br>html:"Installer - GROWI"<br>html:"Install Flarum"<br>html:"Install - StackPosts"<br>html:"Install the script - JustFans"<br>html:"instance_metadata"<br>html:"Invicti Enterprise - Installation Wizard"<br>html:"Invoice Ninja Setup"<br>html:"JBossWS"<br>html:"JK Status Manager"<br>html:"jsconfig.json"<br>html:"jwks.json"<br>html:"karma.conf.js"<br>html:"Kemp Login Screen"<br>html:"LANCOM Systems GmbH"<br>html:"Laragon" html:"phpinfo"<br>html:"lesshst"<br>html:"LibreNMS Install"<br>html:"Limesurvey Installer"<br>html:"LMSZAI - Learning Management System"<br>html:"LoadMaster"<br>html:"Locklizard Web Viewer"<br>html:"Login - Jorani"<br>html:"Login - Netflow Analyzer"<br>html:"Login | Splunk"<br>html:"Logon Error Message"<br>html:"logstash"<br>"html:\"Lucee\""<br>html:"Lychee-installer"<br>html:"Magento Installation"<br>html:"Magnolia is a registered trademark"<br>html:mailmap<br>html:"manifest.json"<br>html:"MasterSAM"<br>html:"Mautic Installation"<br>html:"mempool-space" || title:"Signet Explorer"<br>html:"Mercurial repositories index"<br>html:"mongod"<br>html:"mooSocial Installation"<br>html:"mysql_history"<br>html:"/_next/static"<br>html:"NGINX+ Dashboard"<br>html:"Nginx Proxy Manager"<br>html:"nginxWebUI"<br>html:"ng-version="<br>html:"nopCommerce Installation"<br>html:"npm-debug.log"<br>html:"npm-shrinkwrap.json"<br>html:"Ocp-Apim-Subscription-Key"<br>html:"omniapp"<br>html:"onedev.io"<br>html:"Open Journal Systems"<br>html:"Orbit Telephone System"<br>html:"Orchard Setup - Get Started"<br>html:"osCommerce"<br>html:"OWA CONFIG SETTINGS"<br>html:"owncast"<br>html:"packages.config"<br>html:"parameters.yml"<br>html:"PDI Intellifuel"<br>html:"phinx.yml"<br>html:"php_cs.cache"<br>html:"phpcs.xml"<br>html:"phpdebugbar"<br>html:"/phpgedview.db"<br>html:"phpipam installation wizard"<br>html:"phpIPAM IP address management"<br>html:"PHPJabbers"<br>html:"phpLDAPadmin"<br>html:"phplist"<br>html:"phpspec.yml"<br>html:"phpstan.neon"<br>html:"phpSysInfo"<br>html:"pipeline.yaml"<br>html:"Pipfile"<br>html:"Piwigo" html:"- Installation"<br>html:"Plausible"<br>html:"pnpm-lock.yaml"<br>html:"polyfill.io"<br>html:"Portal Setup"<br>html:"PowerChute Network Shutdown"<br>html:"Powered by Gitea"<br>"html:\"PowerShell Universal\""<br>html:"private gpt"<br>html:"Procfile"<br>html:"/productsalert"<br>html:"ProfitTrailer Setup"<br>html:"ProjectSend"<br>html:"ProjectSend setup"<br>html:"protractor.conf.js"<br>html:"Provide a link that opens Word"<br>html:"psalm.xml"<br>html:"pubspec.yaml"<br>html:"pyload"<br>html:"pypiserver"<br>html:"pyproject.toml"<br>html:"python_gc_objects_collected_total"<br>html:"QuickCMS Installation"<br>html:"QVidium Management"<br>html:"radarr"<br>html:"RaidenMAILD"<br>html:"Rakefile"<br>html:"readarr"<br>html:"README.MD"<br>html:"Redash Initial Setup"<br>html:"redis.conf"<br>html:"redis.exceptions.ConnectionError"<br>html:"request-baskets"<br>html:"rollup.config.js"<br>html:"rubocop.yml"<br>html:"SABnzbd Quick-Start Wizard"<br>html:"Safeguard for Privileged Passwords"<br>html:"Saia PCD Web Server"<br>html:"Salia PLCC"<br>html:"SAP"<br>html:"sass-lint.yml"<br>html:"scrutinizer.yml"<br>html:"SDT-CW3B1"<br>html:"searchreplacedb2.php"<br>html:'Select a frequency for snapshot retention'<br>html:"sendgrid.env"<br>html:"Sentinel License Monitor"<br>html:"server_databases.php"<br>html:"Serv-U"<br>html:settings.py<br>html:"Setup GLPI"<br>html:"Setup - jfa-go"<br>html:"sftp.json"<br>html:"shopping cart program by zen cart"<br>html:"SimpleHelp"<br>html:"Sitecore"<br>html:"Snipe-IT Setup"<br>html:"sonarr"<br>html:"Sorry, the requested URL"<br>html:"stackposts"<br>html:"Struts Problem Report"<br>html:"Symmetricom SyncServer"<br>html:"thisIDRACText"<br>html:"Tiny File Manager"<br>html:"Admin Console"<br>html:"title=\"blue yonder\""<br>html:'title="Lucy'<br>html:"PDNU"<br>html:"prowlarr"<br>html:"Stash"<br>html:"Webinterface"<br>html:"tox.ini"<br>html:"Traccar"<br>html:"travis.yml"<br>"html:\"Trilium Notes\""<br>html:"TurboMeeting"<br>html:"/tvcmsblog"<br>html:"Twig Runtime Error"<br>html:'Twisted' html:"python"<br>html:"Ubersmith Setup"<br>html:"UEditor"<br>html:"UPS Network Management Card 4"<br>html:"UrBackup - Keeps your data safe"<br>html:"/userRpm/"<br>html:"utnserver Control Center"<br>html:"UVDesk Helpdesk Community Edition - Installation Wizard"<br>html:"uwsgi.ini"<br>html:"Vagrantfile"<br>html:"Veeam Backup"<br>html:"Veritas NetBackup OpsCenter Analytics"<br>html:"Versa Networks"<br>html:"Viminfo"<br>html:"VinChin"<br>html:"Virtual SmartZone"<br>html:"vite.config.js"<br>html:"vmw_nsx_logo-black-triangle-500w.png"<br>html:"voyager-assets"<br>html:"/vsaas/v2/static/"<br>html:"/waroot/style.css"<br>html:"webpack.config.js"<br>html:"webpackJsonpzipkin-lens"<br>html:"webpack.mix.js"<br>"html:\"welcome.cgi?p=logo\""<br>html:"Welcome to CakePHP"<br>html:"Welcome to Espocrm"<br>html:"Welcome to Express"<br>html:"Welcome to Nginx"<br>html:"Welcome to Openfire Setup"<br>html:"Welcome to Progress Application Server for OpenEdge"<br>html:"Welcome to the Ruckus"<br>html:"Welcome to Vtiger CRM"<br>html:"Welcome to your Strapi app"<br>html:"Welcome to your Strapi app" html:"create an administrator"<br>html:"Werkzeug powered traceback interpreter"<br>html:".wget-hsts"<br>html:".wgetrc"<br>html:"WhatsUp Gold"<br>html:"Whisparr"<br>html:"Whitelabel Error Page"<br>html:"window.nps"<br>html:"WN530HG4"<br>html:"WN531G3"<br>html:"WN533A8"<br>html:"wpad.dat"<br>html:"wp-cli.yml"<br>html:"/wp-content/plugins/flexmls-idx"<br>html:"/wp-content/plugins/learnpress"<br>html:"/wp-content/plugins/really-simple-ssl"<br>html:"/wp-content/plugins/tutor/"<br>html:"Writebook"<br>html:"XBackBone Installer"<br>html:"/xipblog"<br>html:XploitSPY<br>html:"yii\base\ErrorException"<br>html:"Your Azure Function App is up and running"<br>html:"Zebra Technologies"<br>html:"zzcms"<br>html:"ZzzCMS"<br>'HTTP/1.0 401 Please Authenticate\r\nWWW-Authenticate: Basic realm="Please Login"'<br>http.component:"Adobe ColdFusion"<br>http.component:"Adobe Experience Manager"<br>http.component:"atlassian confluence"<br>http.component:"Atlassian Confluence"<br>http.component:"atlassian jira"<br>http.component:"Atlassian Jira"<br>http.component:"Bitbucket"<br>http.component:"BitBucket"<br>http.component:"drupal"<br>http.component:"Drupal"<br>http.component:"Dynamicweb"<br>http.component:"ghost"<br>http.component:"Joomla"<br>http.component:"magento"<br>http.component:"Magento"<br>http.component:"October CMS"<br>"http.component:\"prestashop\""<br>http.component:"prestashop"<br>http.component:"Prestashop"<br>http.component:"PrestaShop"<br>http.component:"RoundCube"<br>http.component:"Subrion"<br>http.component:"TeamCity"<br>http.component:"TYPO3"<br>http.component:"vBulletin"<br>http.component:zk http.title:"Server Backup Manager"<br>http.favicon.hash:-1005691603<br>http.favicon.hash:1011076161<br>http.favicon.hash:-1013024216<br>http.favicon.hash:1017650009<br>http.favicon.hash:1052926265<br>http.favicon.hash:106844876<br>http.favicon.hash:-1074357885<br>http.favicon.hash:1090061843<br>http.favicon.hash:1099097618<br>http.favicon.hash:1099370896<br>http.favicon.hash:-1101206929<br>http.favicon.hash:"-1105083093"<br>http.favicon.hash:-1117549627<br>http.favicon.hash:-1127895693<br>http.favicon.hash:"-1148190371"<br>http.favicon.hash:115295460<br>http.favicon.hash:116323821<br>http.favicon.hash:11794165<br>http.favicon.hash:-1197926023<br>http.favicon.hash:1198579728<br>http.favicon.hash:1199592666<br>http.favicon.hash:1212523028<br>http.favicon.hash:-1215318992<br>"http.favicon.hash:-121681558"<br>http.favicon.hash:-121681558<br>http.favicon.hash:"-1217039701"<br>http.favicon.hash:-1224668706<br>http.favicon.hash:-1247684400<br>http.favicon.hash:1249285083<br>http.favicon.hash:-1250474341<br>http.favicon.hash:-1258058404<br>http.favicon.hash:-1261322577<br>http.favicon.hash:1262005940<br>http.favicon.hash:-1264095219<br>http.favicon.hash:-1292923998,-1166125415<br>http.favicon.hash:-1295577382<br>http.favicon.hash:-1298131932<br>http.favicon.hash:-130447705<br>http.favicon.hash:1337147129<br>"http.favicon.hash:-1341442175"<br>http.favicon.hash:-1343712810<br>http.favicon.hash:-1350437236<br>http.favicon.hash:1354079303<br>http.favicon.hash:1357234275<br>http.favicon.hash:-1373456171<br>http.favicon.hash:-1379982221<br>http.favicon.hash:"1380908726"<br>http.favicon.hash:1380908726<br>http.favicon.hash:-1381126564<br>http.favicon.hash:-1383463717<br>http.favicon.hash:1386054408<br>http.favicon.hash:1398055326<br>http.favicon.hash:1410071322<br>http.favicon.hash:-1414548363<br>http.favicon.hash:-1416464161<br>http.favicon.hash:1460499495<br>http.favicon.hash:1464851260<br>http.favicon.hash:-1465760059<br>http.favicon.hash:-1478287554<br>http.favicon.hash:-1495233116<br>http.favicon.hash:-1496590341<br>http.favicon.hash:1499876150<br>http.favicon.hash:-1499940355<br>http.favicon.hash:-1529860313<br>http.favicon.hash:1540720428<br>http.favicon.hash:-1548359600<br>http.favicon.hash:1550906681<br>http.favicon.hash:1552322396<br>http.favicon.hash:-1575154882<br>http.favicon.hash:-1595726841<br>http.favicon.hash:1604363273<br>http.favicon.hash:1606029165<br>http.favicon.hash:-1606065523<br>http.favicon.hash:-1649949475<br>http.favicon.hash:1653394551<br>http.favicon.hash:-1653412201<br>http.favicon.hash:"-165631681"<br>http.favicon.hash:-1663319756<br>http.favicon.hash:-1680052984<br>http.favicon.hash:1691956220<br>http.favicon.hash:1693580324<br>http.favicon.hash:"-1706783005"<br>http.favicon.hash:-1706783005<br>http.favicon.hash:1749354953<br>http.favicon.hash:176427349<br>http.favicon.hash:-178113786<br>http.favicon.hash:1781653957<br>http.favicon.hash:-1797138069<br>http.favicon.hash:1817615343<br>http.favicon.hash:1828614783<br>http.favicon.hash:"-1830859634"<br>http.favicon.hash:-186961397<br>http.favicon.hash:-1893514038<br>http.favicon.hash:1895809524<br>http.favicon.hash:-1898583197<br>http.favicon.hash:1903390397<br>http.favicon.hash:-1950415971<br>http.favicon.hash:-1951475503<br>http.favicon.hash:1952289652<br>http.favicon.hash:-1961736892<br>http.favicon.hash:-1970367401<br>http.favicon.hash:-2017596142<br>http.favicon.hash:-2017604252<br>http.favicon.hash:2019488876<br>http.favicon.hash:-2028554187<br>http.favicon.hash:-2032163853<br>http.favicon.hash:-2051052918<br>http.favicon.hash:2056442365<br>"http.favicon.hash:206985584"<br>http.favicon.hash:-2073748627 || http.favicon.hash:-1721140132<br>http.favicon.hash:2099342476<br>http.favicon.hash:2104916232<br>http.favicon.hash:"-211006074"<br>http.favicon.hash:-211006074<br>http.favicon.hash:-2115208104<br>http.favicon.hash:2124459909<br>http.favicon.hash:213144638<br>http.favicon.hash:2134367771<br>http.favicon.hash:-2144699833<br>http.favicon.hash:-219625874<br>"http.favicon.hash:-234335289"<br>http.favicon.hash:"24048806"<br>http.favicon.hash:24048806<br>http.favicon.hash:-244067125<br>http.favicon.hash:262502857<br>http.favicon.hash:-266008933<br>http.favicon.hash:-283003760<br>http.favicon.hash:-286484075<br>http.favicon.hash:305412257<br>http.favicon.hash:321591353<br>http.favicon.hash:-347188002<br>http.favicon.hash:362091310<br>http.favicon.hash:-374133142<br>http.favicon.hash:-399298961<br>http.favicon.hash:407286339<br>http.favicon.hash:-417785140<br>http.favicon.hash:-418614327<br>http.favicon.hash:419828698<br>http.favicon.hash:431627549<br>http.favicon.hash:-43504595<br>http.favicon.hash:439373620<br>http.favicon.hash:440258421<br>http.favicon.hash:-440644339<br>http.favicon.hash:450899026<br>http.favicon.hash:464587962<br>http.favicon.hash:487145192<br>http.favicon.hash:-50306417<br>http.favicon.hash:-516760689<br>http.favicon.hash:523757057<br>http.favicon.hash:538583492<br>http.favicon.hash:540706145<br>http.favicon.hash:557327884<br>http.favicon.hash:-578216669<br>http.favicon.hash:587330928<br>http.favicon.hash:-594722214<br>http.favicon.hash:598296063<br>http.favicon.hash:-601917817<br>http.favicon.hash:-608690655<br>http.favicon.hash:-629968763<br>http.favicon.hash:-633512412<br>http.favicon.hash:635899646<br>http.favicon.hash:"-646322113"<br>http.favicon.hash:-655683626<br>http.favicon.hash:657337228<br>http.favicon.hash:662709064<br>http.favicon.hash:"-670975485"<br>"http.favicon.hash:-697231354"<br>http.favicon.hash:698624197<br>"http.favicon.hash:\"702863115\""<br>http.favicon.hash:"702863115"<br>http.favicon.hash:702863115clear<br>http.favicon.hash:733091897<br>http.favicon.hash:739801466<br>http.favicon.hash:-741491222<br>http.favicon.hash:-749942143<br>http.favicon.hash:751911084<br>"http.favicon.hash:762074255"<br>http.favicon.hash:762074255<br>http.favicon.hash:781922099<br>http.favicon.hash:786533217<br>http.favicon.hash:-800060828<br>http.favicon.hash:-800551065<br>http.favicon.hash:"801517258"<br>http.favicon.hash:-81573405<br>http.favicon.hash:816588900<br>http.favicon.hash:824580113<br>http.favicon.hash:-82958153<br>http.favicon.hash:-831756631<br>http.favicon.hash:"-839356603"<br>http.favicon.hash:-850502287<br>http.favicon.hash:855432563<br>"http.favicon.hash:868509217"<br>http.favicon.hash:"871154672"<br>http.favicon.hash:873381299<br>http.favicon.hash:874152924<br>http.favicon.hash:876876147<br>http.favicon.hash:889652940<br>http.favicon.hash:-902890504<br>http.favicon.hash:-916902413<br>http.favicon.hash:-919788577<br>http.favicon.hash:932345713<br>http.favicon.hash:933976300<br>http.favicon.hash:942678640<br>http.favicon.hash:957255151<br>http.favicon.hash:965982073<br>http.favicon.hash:967636089<br>http.favicon.hash:969374472<br>http.favicon.hash:-976853304<br>http.favicon.hash:-977323269<br>http.favicon.hash:981081715<br>http.favicon.hash:983734701<br>http.favicon.hash:988422585<br>http.favicon.hash:989289239<br>http.favicon.hash:999357577<br>http.html:"4DACTION/"<br>http.html:"74cms"<br>http.html:"academy lms"<br>http.html:"Ampache Update"<br>http.html:"Apache Airflow"<br>http.html:"Apache Axis"<br>http.html:"Apache Cocoon"<br>http.html:"Apache OFBiz"<br>http.html:"Apache Solr"<br>http.html:"Apache Solr"<br>http.html:"apollo-adminservice"<br>http.html:"app.2fe6356cdd1ddd0eb8d6317d1a48d379.css"<br>http.html:"artica"<br>http.html:".asmx?WSDL"<br>http.html:"Audiocodes"<br>http.html:"BeyondInsight"<br>"http.html:\"BeyondTrust Privileged Remote Access Login\""<br>http.html:"bigant"<br>http.html:"BigAnt Admin"<br>http.html:"/bitrix/"<br>http.html:"blogengine.net"<br>http.html:"BMC Remedy"<br>http.html:"Camunda Welcome"<br>http.html:"car rental management system"<br>http.html:"Car Rental Management System"<br>http.html:"/CasaOS-UI/public/index.html"<br>http.html:"CCM - Authentication Failure"<br>http.html:"Check Point Mobile"<br>http.html:"chronoslogin.js"<br>http.html:"CMS Quilium"<br>http.html:"Command API Explorer"<br>http.html:'content="Redmine'<br>http.html:'content="Smartstore'<br>http.html:"corebos"<br>http.html:"crushftp"<br>http.html:"CS141"<br>http.html:"Cvent Inc"<br>http.html:"CxSASTManagerUri"<br>http.html:"dataease"<br>http.html:"DedeCms"<br>http.html:"Delta Controls ORCAview"<br>http.html:"Develocity Build Cache Node"<br>http.html:"DLP system"<br>http.html:"/dokuwiki/"<br>http.html:"dotnetcms"<br>http.html:"Dufs"<br>http.html:"dzzoffice"<br>http.html:"E-Mobile"<br>http.html:"E-Mobile&amp;nbsp"<br>http.html:EmpireCMS<br>http.html:"ESP Easy Mega"<br>http.html:"eZ Publish"<br>http.html:"Flatpress"<br>http.html:"Fuji Xerox Co., Ltd"<br>http.html:"Get_Verify_Info"<br>http.html:"glpi"<br>http.html:"Gnuboard"<br>http.html:"gnuboard5"<br>http.html:"GoAnywhere Managed File Transfer"<br>http.html:"Gradle Enterprise Build Cache Node"<br>http.html:"H3C-SecPath-运维审计系统"<br>http.html_hash:1015055567<br>http.html_hash:1076109428<br>http.html_hash:-14029177<br>http.html_hash:-1957161625<br>http.html_hash:510586239<br>http.html:"HG532e"<br>http.html:"hospital management system"<br>http.html:"Hospital Management System"<br>http.html:'Hugo'<br>http.html:"Huly"<br>http.html:"i3geo"<br>http.html:"IBM WebSphere Portal"<br>"http.html:\"import-xml-feed\""<br>http.html:"import-xml-feed"<br>http.html:"index.createOpenPad"<br>http.html:"Interactsh Server"<br>http.html:"IPdiva"<br>http.html:"iSpy"<br>http.html:"JamF"<br>http.html:"Jamf Pro Setup"<br>http.html:"Jellyfin"<br>http.html:"JHipster"<br>http.html:"JupyterHub"<br>http.html:"kavita"<br>http.html:"LANDESK(R)"<br>http.html:"Laravel FileManager"<br>http.html:"LISTSERV"<br>http.html:livezilla<br>http.html:"Login (Virtual Traffic Manager"<br>http.html:"lookerVersion"<br>http.html:"magnusbilling"<br>http.html:"mailhog"<br>http.html:"/main/login.lua?pageid="<br>http.html:"metersphere"<br>http.html:"MiCollab End User Portal"<br>http.html:"Micro Focus Application Lifecycle Management"<br>http.html:"Micro Focus iPrint Appliance"<br>http.html:"Mirantis Kubernetes Engine"<br>http.html:"Mitel Networks"<br>http.html:"MobileIron"<br>http.html:"moodle"<br>http.html:"multipart/form-data" html:"file"<br>http.html:"myLittleAdmin"<br>http.html:"myLittleBackup"<br>http.html:"NeoboxUI"<br>http.html:"Network Utility"<br>http.html:"Nexus Repository Manager"<br>http.html:'ng-app="syncthing"'<br>http.html:"Nordex Control"<br>http.html:"Omnia MPX"<br>http.html:"OpenCTI"<br>http.html:"OpenEMR"<br>http.html:"opennebula"<br>http.html:"Oracle HTTP Server"<br>http.html:"Oracle UIX"<br>"http.html:\"outsystems\""<br>http.html:"owncloud"<br>http.html:"PbootCMS"<br>http.html:"phpMiniAdmin"<br>http.html:"phpMyAdmin"<br>http.html:"phpmyfaq"<br>http.html:/plugins/royal-elementor-addons/<br>http.html:"power by dedecms" || title:"dedecms"<br>http.html:"Powerd by AppCMS"<br>http.html:"powered by CATALOGcreator"<br>http.html:"powerjob"<br>http.html:"processwire"<br>http.html:provided by projectsend<br>http.html:"pyload"<br>http.html:"/redfish/v1"<br>http.html:"redhat" "Satellite"<br>http.html:"r-seenet"<br>http.html:rt_title<br>http.html:"SAP Analytics Cloud"<br>http.html:"seafile"<br>http.html:"Semaphore"<br>http.html:"sharecenter"<br>http.html:"SLIMS"<br>http.html:"SolarView Compact"<br>http.html:"soplanning"<br>http.html:"SOUND4"<br>http.html:"study any topic, anytime"<br>http.html:"sucuri firewall"<br>http.html:"symfony Profiler"<br>http.html:"Symfony Profiler"<br>http.html:"sympa"<br>http.html:"teampass"<br>http.html:"Telerik Report Server"<br>http.html:"Thruk"<br>http.html:"thruk" || http.title:"thruk monitoring webinterface"<br>http.html:"TIBCO BusinessConnect"<br>http.html:"tiki wiki"<br>http.html:"TLR-2005KSH"<br>http.html:"totemomail" inurl:responsiveui<br>http.html:"Umbraco"<br>http.html:"vaultwarden"<br>http.html:"Vertex Tax Installer"<br>http.html:"VMG1312-B10D"<br>http.html:"VMware Horizon"<br>http.html:"VSG1432-B101"<br>http.html:"wavlink"<br>http.html:"Wavlink"<br>http.html:"WebADM"<br>http.html:"Webasyst Installer"<br>http.html:"WebCenter"<br>http.html:"Web Image Monitor"<br>http.html:"Webp"<br>http.html:"webshell4"<br>http.html:"Welcome to MapProxy"<br>http.html:"Welcome to Oracle Fusion Middleware"<br>http.html:"wiki.js"<br>http.html:"window.frappe_version"<br>http.html:/wp-content/plugins/adsense-plugin/<br>http.html:"/wp-content/plugins/agile-store-locator/"<br>http.html:wp-content/plugins/ap-pricing-tables-lite<br>http.html:/wp-content/plugins/autoptimize<br>http.html:/wp-content/plugins/backup-backup/<br>http.html:/wp-content/plugins/bws-google-analytics/<br>http.html:/wp-content/plugins/bws-google-maps/<br>http.html:/wp-content/plugins/bws-linkedin/<br>http.html:/wp-content/plugins/bws-pinterest/<br>http.html:/wp-content/plugins/bws-smtp/<br>http.html:/wp-content/plugins/bws-testimonials/<br>http.html:/wp-content/plugins/chaty/<br>http.html:/wp-content/plugins/cmp-coming-soon-maintenance/<br>http.html:/wp-content/plugins/companion-sitemap-generator/<br>http.html:/wp-content/plugins/contact-form-multi/<br>http.html:/wp-content/plugins/contact-form-plugin/<br>http.html:/wp-content/plugins/contact-form-to-db/<br>http.html:/wp-content/plugins/contest-gallery/<br>http.html:/wp-content/plugins/controlled-admin-access/<br>http.html:"wp-content/plugins/crypto"<br>http.html:/wp-content/plugins/cryptocurrency-widgets-pack/<br>http.html:/wp-content/plugins/custom-admin-page/<br>http.html:/wp-content/plugins/custom-facebook-feed/<br>http.html:/wp-content/plugins/custom-search-plugin/<br>http.html:/wp-content/plugins/defender-security/<br>http.html:/wp-content/plugins/ditty-news-ticker/<br>"http.html:\"/wp-content/plugins/download-monitor/\""<br>http.html:/wp-content/plugins/error-log-viewer/<br>http.html:"wp-content/plugins/error-log-viewer-wp"<br>http.html:/wp-content/plugins/essential-blocks/<br>"http.html:/wp-content/plugins/extensive-vc-addon/"<br>http.html:/wp-content/plugins/foogallery/<br>http.html:/wp-content/plugins/forminator<br>http.html:/wp-content/plugins/g-auto-hyperlink/<br>http.html:"/wp-content/plugins/gift-voucher/"<br>http.html:/wp-content/plugins/gtranslate<br>http.html:"/wp-content/plugins/hostel/"<br>http.html:/wp-content/plugins/htaccess/<br>http.html:"wp-content/plugins/hurrakify"<br>http.html:/wp-content/plugins/learnpress<br>http.html:/wp-content/plugins/login-as-customer-or-user<br>http.html:wp-content/plugins/media-library-assistant<br>http.html:/wp-content/plugins/motopress-hotel-booking<br>http.html:/wp-content/plugins/mstore-api/<br>http.html:/wp-content/plugins/newsletter/<br>http.html:/wp-content/plugins/nex-forms-express-wp-form-builder/<br>http.html:"/wp-content/plugins/ninja-forms/"<br>http.html:/wp-content/plugins/ninja-forms/<br>http.html:/wp-content/plugins/pagination/<br>http.html:/wp-content/plugins/paid-memberships-pro/<br>http.html:/wp-content/plugins/pdf-generator-for-wp<br>http.html:/wp-content/plugins/pdf-print/<br>http.html:/wp-content/plugins/photoblocks-grid-gallery/<br>http.html:/wp-content/plugins/photo-gallery<br>http.html:/wp-content/plugins/polls-widget/<br>http.html:/wp-content/plugins/popup-builder/<br>http.html:/wp-content/plugins/popup-by-supsystic<br>http.html:/wp-content/plugins/popup-maker/<br>http.html:/wp-content/plugins/post-smtp<br>http.html:/wp-content/plugins/prismatic<br>http.html:/wp-content/plugins/promobar/<br>http.html:/wp-content/plugins/qt-kentharadio<br>http.html:/wp-content/plugins/quick-event-manager<br>http.html:"/wp-content/plugins/radio-player"<br>http.html:/wp-content/plugins/rating-bws/<br>http.html:/wp-content/plugins/realty/<br>http.html:/wp-content/plugins/registrations-for-the-events-calendar/<br>http.html:/wp-content/plugins/searchwp-live-ajax-search/<br>http.html:/wp-content/plugins/sender/<br>http.html:/wp-content/plugins/sfwd-lms<br>http.html:/wp-content/plugins/shortpixel-adaptive-images/<br>http.html:/wp-content/plugins/show-all-comments-in-one-page<br>http.html:/wp-content/plugins/site-offline/<br>http.html:/wp-content/plugins/social-buttons-pack/<br>http.html:/wp-content/plugins/social-login-bws/<br>http.html:/wp-content/plugins/stock-ticker/<br>http.html:/wp-content/plugins/subscriber/<br>http.html:/wp-content/plugins/super-socializer/<br>http.html:/wp-content/plugins/tutor/<br>http.html:/wp-content/plugins/twitter-plugin/<br>http.html:/wp-content/plugins/ubigeo-peru/<br>http.html:/wp-content/plugins/ultimate-member<br>http.html:/wp-content/plugins/updater/<br>"http.html:/wp-content/plugins/user-meta/"<br>http.html:/wp-content/plugins/user-role/<br>http.html:/wp-content/plugins/video-list-manager/<br>http.html:/wp-content/plugins/visitors-online/<br>http.html:/wp-content/plugins/wc-multivendor-marketplace<br>http.html:/wp-content/plugins/woocommerce-payments<br>http.html:/wp-content/plugins/wordpress-toolbar/<br>"http.html:/wp-content/plugins/wp-fastest-cache/"<br>http.html:"/wp-content/plugins/wp-file-upload/"<br>http.html:/wp-content/plugins/wp-helper-lite<br>http.html:/wp-content/plugins/wp-simple-firewall<br>http.html:/wp-content/plugins/wp-statistics/<br>http.html:/wp-content/plugins/wp-user/<br>http.html:/wp-content/plugins/zendesk-help-center/<br>http.html:/wp-content/themes/newspaper<br>http.html:/wp-content/themes/noo-jobmonster<br>http.html:"wp-stats-manager"<br>http.html:"Wuzhicms"<br>http.html:"/xibosignage/xibo-cms"<br>http.html:"yeswiki"<br>http.html:"Z-BlogPHP"<br>http.html:"zm - login"<br>http.html:"ZTE Corporation"<br>http.html:"心上无垢，林间有风"<br>http.securitytxt:contact http.status:200<br>http.title:"1Password SCIM Bridge Login"<br>http.title:"3CX Phone System Management Console"<br>http.title:"Accueil WAMPSERVER"<br>http.title:"Acrolinx Dashboard"<br>http.title:"Actifio Resource Center"<br>http.title:"Adapt authoring tool"<br>http.title:"Admin | Employee's Payroll Management System"<br>http.title:adminer<br>http.title:"AdmiralCloud"<br>http.title:"Adobe Media Server"<br>http.title:"Advanced eMail Solution DEEPMail"<br>http.title:"Advanced Setup - Security - Admin User Name &amp; Password"<br>http.title:"Aerohive NetConfig UI"<br>http.title:"Aethra Telecommunications Operating System"<br>http.title:"AirCube Dashboard"<br>http.title:"AirNotifier"<br>http.title:"Alamos GmbH | FE2"<br>http.title:"Alertmanager"<br>http.title:"Alfresco Content App"<br>http.title:"AlienVault USM"<br>http.title:"altenergy power control software"<br>http.title:"AlternC Desktop"<br>http.title:"Amazon Cognito Developer Authentication Sample"<br>http.title:"Amazon ECS Sample App"<br>http.title:"Ampache -- Debug Page"<br>http.title:"Android Debug Database"<br>http.title:"Apache2 Debian Default Page:"<br>http.title:"Apache2 Ubuntu Default Page"<br>http.title:"apache apisix dashboard"<br>http.title:"Apache CloudStack"<br>http.title:"Apache+Default","Apache+HTTP+Server+Test","Apache2+It+works"<br>http.title:"Apache HTTP Server Test Page powered by CentOS"<br>http.title:"apache streampipes"<br>http.title:"apex it help desk"<br>http.title:"appsmith"<br>http.title:"Aptus Login"<br>http.title:"Aqua Enterprise" || http.title:"Aqua Cloud Native Security Platform"<br>http.title:"ArcGIS"<br>http.title:"Argo CD"<br>http.title:"avantfax - login"<br>http.title:"aviatrix cloud controller"<br>http.title:"AVideo"<br>http.title:"Axel"<br>http.title:"Axigen WebAdmin"<br>http.title:"Axigen WebMail"<br>http.title:"Axway API Manager Login"<br>http.title:"Axyom Network Manager"<br>http.title:"Azkaban Web Client"<br>http.title:"Bagisto Installer"<br>http.title:"Bamboo"<br>http.title:"BigBlueButton"<br>http.title:"BigFix"<br>http.title:"big-ip®-+redirect" +"server"<br>http.title:"BioTime"<br>http.title:"Black Duck"<br>http.title:"Blue Iris Login"<br>http.title:"BMC Remedy Single Sign-On domain data entry"<br>http.title:"BMC Software"<br>http.title:"browserless debugger"<br>http.title:"Caton Network Manager System"<br>http.title:"Celebrus"<br>http.title:"Centreon"<br>http.title:"change detection"<br>http.title:"Charger Management Console"<br>http.title:"Check_MK"<br>http.title:"Cisco Secure CN"<br>http.title:"Cisco ServiceGrid"<br>http.title:"Cisco Systems Login"<br>http.title:"Cisco Telepresence"<br>http.title:"citrix gateway"<br>http.title:"ClarityVista"<br>http.title:"CleanWeb"<br>http.title:"Cloudphysician RADAR"<br>http.title:"Cluster Overview - Trino"<br>http.title:"C-more -- the best HMI presented by AutomationDirect"<br>http.title:"cobbler web interface"<br>http.title:"Codeigniter Application Installer"<br>http.title:"code-server login"<br>http.title:"Codian MCU - Home page"<br>http.title:"CompleteView Web Client"<br>http.title:"Conductor UI", http.title:"Workflow UI"<br>http.title:"Connection - SphinxOnline"<br>http.title:"Content Central Login"<br>http.title:"copyparty"<br>http.title:"Coverity"<br>http.title:"craftercms"<br>http.title:"Create a pipeline - Go" html:"GoCD Version"<br>http.title:"Creatio"<br>http.title:"Database Error"<br>http.title:"datagerry"<br>http.title:"DataHub"<br>http.title:"datataker"<br>http.title:"Davantis"<br>http.title:"Decision Center | Business Console"<br>http.title:"Dericam"<br>http.title:"Dgraph Ratel Dashboard"<br>http.title:"docassemble"<br>http.title:"Docuware"<br>http.title:"Dolibarr"<br>http.title:"dolphinscheduler"<br>http.title:"DolphinScheduler"<br>http.title:"Domibus"<br>http.title:"dotcms"<br>http.title:"Dozzle"<br>http.title:"Easyvista"<br>http.title:"Ekoenergetyka-Polska Sp. z o.o - CCU3 Software Update for Embedded Systems"<br>http.title:"Elastic" || http.favicon.hash:1328449667<br>http.title:"Elasticsearch-sql client"<br>http.title:"emby"<br>http.title:"emerge"<br>http.title:"Emerson Network Power IntelliSlot Web Card"<br>http.title:"EMQX Dashboard"<br>http.title:"Endpoint Protector"<br>http.title:"EnvisionGateway"<br>http.title:"erxes"<br>http.title:"EWM Manager"<br>http.title:"Extreme NetConfig UI"<br>http.title:"Falcosidekick"<br>http.title:"FastCGI"<br>http.title:"Flex VNF Web-UI"<br>http.title:"flightpath"<br>http.title:"flowchart maker"<br>http.title:"Forcepoint Appliance"<br>http.title:"fortimail"<br>http.title:"FORTINET LOGIN"<br>http.title:"fortiweb - "<br>http.title:"fuel cms"<br>http.title:"GeoWebServer"<br>http.title:"gitbook"<br>http.title:"Gitea"<br>http.title:"GitHub Debug"<br>http.title:"GitLab"<br>http.title:"git repository browser"<br>http.title:"GlassFish Server - Server Running"<br>http.title:"Glowroot"<br>http.title:"glpi"<br>http.title:"Gophish - Login"<br>http.title:"Grandstream Device Configuration"<br>http.title:"Graphite Browser"<br>http.title:"Graylog Web Interface"<br>http.title:"Gryphon"<br>http.title:"GXD5 Pacs Connexion utilisateur"<br>http.title:"H5S CONSOLE"<br>http.title:"Hacked By"<br>http.title:"Haivision Gateway"<br>http.title:"Haivision Media Platform"<br>http.title:"hd-network real-time monitoring system v2.0"<br>http.title:"Heatmiser Wifi Thermostat"<br>http.title:"HiveQueue"<br>http.title:"Home Assistant"<br>http.title:"Home Page - My ASP.NET Application"<br>http.title:"HP BladeSystem"<br>http.title:"HP Color LaserJet"<br>http.title:"Hp Officejet pro"<br>http.title:"HP Virtual Connect Manager"<br>http.title:"httpbin.org"<br>http.title:"HTTP Server Test Page powered by CentOS-WebPanel.com"<br>http.title:"HUAWEI Home Gateway HG658d"<br>http.title:"Hubble UI"<br>http.title:"hybris"<br>http.title:"HYPERPLANNING"<br>http.title:"IBM-HTTP-Server"<br>http.title:"IBM iNotes Login"<br>http.title:"IBM Security Access Manager"<br>http.title:"Icecast Streaming Media Server"<br>http.title:"IdentityServer v3"<br>http.title:"IIS7"<br>http.title:"IIS Windows Server"<br>http.title:"ImpressPages installation wizard"<br>http.title:"Infoblox"<br>http.title:"Installation - Gogs"<br>http.title:"Installer - Easyscripts"<br>http.title:"Intelbras"<br>http.title:"Intelligent WAPPLES"<br>http.title:"IoT vDME Simulator"<br>"http.title:\"ispconfig\""<br>http.title:"iXBus"<br>http.title:"J2EE"<br>http.title:"Jaeger UI"<br>http.title:"jeedom"<br>http.title:"Jellyfin"<br>"http.title:\"JFrog\""<br>http.title:"Jitsi Meet"<br>http.title:'JumpServer'<br>http.title:"Juniper Web Device Manager"<br>http.title:"JupyterHub"<br>http.title:"Kafka Center"<br>http.title:"Kafka Cruise Control UI"<br>http.title:"kavita"<br>http.title:"Kerio Connect Client"<br>http.title:"kibana"<br>http.title:"kkFileView"<br>http.title:"Kopano WebApp"<br>http.title:"Kraken dashboard"<br>http.title:"Kube Metrics Server"<br>http.title:"Kubernetes Operational View"<br>http.title:"kubernetes web view"<br>http.title:"lansweeper - login"<br>http.title:"LDAP Account Manager"<br>http.title:"Leostream"<br>http.title:"Linksys Smart WI-FI"<br>http.title:"LinShare"<br>http.title:"LISTSERV Maestro"<br>http.title:"LockSelf"<br>http.title:"login | control webpanel"<br>http.title:"Log in - easyJOB"<br>http.title:"Login - Residential Gateway"<br>http.title:"login - splunk"<br>http.title:"Login - Splunk"<br>http.title:"login" "x-oracle-dms-ecid" 200<br>http.title:"Logitech Harmony Pro Installer"<br>http.title:"Lomnido Login"<br>http.title:"Loxone Intercom Video"<br>http.title:"Lucee"<br>http.title:"Maestro - LuCI"<br>http.title:"MAG Dashboard Login"<br>http.title:"MailWatch Login Page"<br>http.title:"manageengine desktop central 10"<br>http.title:"ManageEngine Password"<br>http.title:"manageengine servicedesk plus"<br>http.title:"mcloud-installer-web"<br>http.title:"Meduza Stealer"<br>http.title:"MetaView Explorer"<br>http.title:MeTube<br>http.title:"Microsoft Azure App Service - Welcome"<br>http.title:"Microsoft Internet Information Services 8"<br>http.title:"mikrotik routeros &gt; administration"<br>"http.title:\"mlflow\""<br>http.title:"mlflow"<br>http.title:"MobiProxy"<br>http.title:"MongoDB Ops Manager"<br>http.title:"mongo express"<br>http.title:"MSPControl - Sign In"<br>http.title:"My Datacenter - Login"<br>http.title:"Mystic Stealer"<br>http.title:"nagios"<br>http.title:"nagios xi"<br>http.title:"N-central Login"<br>http.title:"nconf"<br>http.title:"Netris Dashboard"<br>http.title:"NETSurveillance WEB"<br>http.title:"NetSUS Server Login"<br>http.title:"Nextcloud"<br>http.title:"nginx admin manager"<br>http.title:"Nginx Proxy Manager"<br>http.title:"ngrok"<br>http.title:"Normhost Backup server manager"<br>http.title:"noVNC"<br>http.title:"NS-ASG"<br>http.title:"ntopng - Traffic Dashboard"<br>http.title:"officescan"<br>http.title:"okta"<br>http.title:"Olivetti CRF"<br>http.title:"olympic banking system"<br>http.title:"OneinStack"<br>http.title:"Opcache Control Panel"<br>http.title:"Open Game Panel"<br>http.title:"openHAB"<br>http.title:"OpenObserve"<br>http.title:"opensis"<br>http.title:"openSIS"<br>http.title:"openvpn connect"<br>http.title:"Operations Automation Default Page"<br>http.title:"Opinio"<br>http.title:"opmanager plus"<br>http.title:"opnsense"<br>http.title:"opsview"<br>http.title:"Oracle Application Server Containers"<br>http.title:"oracle business intelligence sign in"<br>http.title:"Oracle Containers for J2EE"<br>http.title:"Oracle Database as a Service"<br>"http.title:\"Oracle PeopleSoft Sign-in\""<br>http.title:"Oracle(R) Integrated Lights Out Manager"<br>http.title:"OrangeHRM Web Installation Wizard"<br>http.title:"OSNEXUS QuantaStor Manager"<br>http.title:"otobo"<br>http.title:"OurMGMT3"<br>http.title:outlook exchange<br>http.title:"OVPN Config Download"<br>http.title:"PAHTool"<br>http.title:"pandora fms"<br>http.title:"Passbolt | Open source password manager for teams"<br>http.title:"Payara Server - Server Running"<br>http.title:"PendingInstallVZW - Web Page Configuration"<br>http.title:"Pexip Connect for Web"<br>http.title:"pfsense - login"<br>http.title:"PgHero"<br>http.title:"PGP Global Directory"<br>http.title:"phoronix-test-suite"<br>http.title:PhotoPrism<br>http.title:"PHP Mailer"<br>http.title:phpMyAdmin<br>http.title:"PHP warning" || "Fatal error"<br>http.title:"Plastic SCM"<br>http.title:"Please Login | Nozomi Networks Console"<br>http.title:"PMM Installation Wizard"<br>http.title:"posthog"<br>http.title:"PowerCom Network Manager"<br>http.title:"Powered By Jetty"<br>http.title:"Powered by lighttpd"<br>http.title:"PowerJob"<br>http.title:"prime infrastructure"<br>http.title:"PRONOTE"<br>http.title:"Puppetboard"<br>http.title:"Ranger - Sign In"<br>http.title:"rconfig"<br>http.title:"rConfig"<br>http.title:"RD Web Access"<br>http.title:"Remkon Device Manager"<br>http.title:"Reolink"<br>http.title:"rocket.chat"<br>http.title:"Rocket.Chat"<br>http.title:"RouterOS router configuration page"<br>http.title:"roxy file manager"<br>http.title:"R-SeeNet"<br>http.title:"seagate nas - seagate"<br>http.title:SearXNG<br>http.title:"Secure Login Service"<br>http.title:"securenvoy"<br>http.title:"securepoint utm"<br>http.title:"SeedDMS"<br>http.title:"Selenium Grid"<br>http.title:"Self Enrollment"<br>http.title:"SequoiaDB"<br>http.title:"Server Backup Manager SE"<br>http.title:"Service"<br>http.title:"SevOne NMS - Network Manager"<br>http.title:"S-Filer"<br>http.title:"SGP"<br>http.title:"SHOUTcast Server"<br>http.title:"sidekiq"<br>http.title:"Sign In - Hyperic"<br>http.title:"Sign in to Netsparker Enterprise"<br>"http.title:\"SimpleSAMLphp installation page\""<br>http.title:"sitecore"<br>http.title:"Skeepers"<br>http.title:"SMS Gateway | Installation"<br>http.title:"smtp2go"<br>http.title:"Snapdrop"<br>http.title:"SoftEther VPN Server"<br>http.title:"SOGo"<br>http.title:"Sonatype Nexus Repository"<br>http.title:"Splunk"<br>http.title:"Splunk SOAR"<br>http.title:"SQL Buddy"<br>http.title:"SteVe - Steckdosenverwaltung"<br>http.title:"storybook"<br>http.title:"strapi"<br>http.title:"Supermicro BMC Login"<br>"http.title:\"swagger\""<br>http.title:"Symantec Encryption Server"<br>http.title:"Synapse Mobility Login"<br>http.title:"t24 sign in"<br>http.title:"Tactical RMM - Login"<br>http.title:"Tenda 11N Wireless Router Login Screen"<br>http.title:"Test Page for the Apache HTTP Server on Red Hat Enterprise Linux"<br>http.title:"Test Page for the HTTP Server on Fedora"<br>http.title:"Test Page for the Nginx HTTP Server on Amazon Linux"<br>http.title:"Test Page for the SSL/TLS-aware Apache Installation on Web Site"<br>http.title:"The install worked successfully! Congratulations!"<br>http.title:"thinfinity virtualui"<br>http.title:"TileServer GL - Server for vector and raster maps with GL styles"<br>"http.title:\"tixeo\""<br>http.title:"totolink"<br>http.title:"traefik"<br>http.title:"transact sign in","t24 sign in"<br>http.title:"Transmission Web Interface"<br>http.title:triconsole.com - php calendar date picker<br>http.title:"TurnKey OpenVPN"<br>http.title:"Twenty"<br>http.title:"TYPO3 Exception"<br>http.title:"UI for Apache Kafka"<br>http.title:"UiPath Orchestrator"<br>http.title:"UniFi Network"<br>http.title:"UniGUI"<br>http.title:"Verizon Router"<br>http.title:"VERSA DIRECTOR Login"<br>http.title:"vertigis"<br>http.title:"ViewPoint System Status"<br>http.title:"vRealize Operations Tenant App"<br>http.title:"Wallix Access Manager"<br>http.title:"Warning [refreshed every 30 sec.]"<br>http.title:"Watershed LRS"<br>http.title:"webcamXP 5"<br>http.title:"webmin"<br>http.title:"Web Server's Default Page"<br>http.title:"WebSphere Liberty"<br>http.title:"Webtools"<br>http.title:"Web Transfer Client"<br>http.title:"web viewer for samsung dvr"<br>http.title:"Welcome to Citrix Hypervisor"<br>http.title:"Welcome to CodeIgniter"<br>http.title:"Welcome to nginx!"<br>http.title:"welcome to ntop"<br>http.title:"Welcome to OpenResty!"<br>http.title:"Welcome To RunCloud"<br>http.title:"Welcome to Service Assistant"<br>http.title:"Welcome to Sitecore"<br>http.title:"Welcome to Symfony"<br>http.title:"Welcome to tengine"<br>http.title:"Welcome to VMware Site Recovery Manager"<br>http.title:"Welcome to your Strapi app"<br>http.title:"Wi-Fi APP Login"<br>http.title:"Wiren Board Web UI"<br>http.title:"WoodWing Studio Server"<br>http.title:"XAMPP"<br>http.title:"XDS-AMR - status"<br>http.title:"XenForo"<br>http.title:"XNAT"<br>http.title:"YApi"<br>http.title:zblog<br>http.title:"zentao"<br>http.title:"zeroshell"<br>http.title:"Zope QuickStart"<br>http.title:"zywall"<br>http.title:"ZyWall"<br>http.title:"小米路由器"<br>http.title:"高清智能录播系统"<br>icon_hash="915499123"<br>"If you find a bug in this Lighttpd package, or in Lighttpd itself"<br>imap<br>"Kerio Control"<br>Laravel-Framework<br>ldap<br>"Lorex"<br>"loytec"<br>"Max-Forwards:"<br>Microsoft FTP Service<br>mongodb server information<br>"Ms-Author-Via: DAV"<br>MSMQ<br>"nimplant C2 server"<br>"OfficeWeb365"<br>ollama<br>"Ollama is running"<br>OpenSSL<br>"Open X Server:"<br>Path=/gespage<br>pentaho<br>"pfBlockerNG"<br>php.ini<br>"PHPnow works"<br>".phpunit.result.cache"<br>pop3 port:110<br>port:10001<br>"port:110"<br>port:"111"<br>port:11300 "cmd-peek"<br>port:1433<br>port:22<br>port:2375 product:"docker"<br>port:23 telnet<br>"port:3306"<br>port:3310 product:"ClamAV"<br>port:3310 product:"ClamAV" version:"0.99.2"<br>"port:445"<br>port:445<br>port:523<br>'port:541 xab'<br>port:5432<br>port:5432 product:"PostgreSQL"<br>"port:69"<br>port:"79" action<br>port:"873"<br>port:873<br>product:"ActiveMQ OpenWire transport"<br>product:"Apache ActiveMQ"<br>product:'Ares RAT C2'<br>product:"Axigen"<br>product:"besu"<br>product:"BGP"<br>product:"bitvise"<br>"product:\"Check Point Firewall\""<br>product:"Cisco fingerd"<br>product:"cloudflare-nginx"<br>product:"CouchDB"<br>"product:cups"<br>product:"CUPS (IPP)"<br>product:'DarkComet Trojan'<br>product:'DarkTrack RAT Trojan'<br>product:"Dropbear sshd"<br>product:"Erigon"<br>product:"Erlang Port Mapper Daemon"<br>product:"etcd"<br>"product:\"Exim smtpd\""<br>product:"Fortinet FortiWiFi"<br>product:"Geth"<br>product:"GitLab Self-Managed"<br>product:"GNU Inetutils FTPd"<br>product:"HttpFileServer httpd"<br>product:"IBM DB2 Database Server"<br>product:"jenkins"<br>product:"Kafka"<br>product:"kubernetes"<br>product:"Kubernetes" version:"1.21.5-eks-bc4871b"<br>product:"Linksys E2000 WAP http config"<br>product:"MikroTik router ftpd"<br>product:"MikroTik RouterOS API Service"<br>product:"Minecraft"<br>product:"MS .NET Remoting httpd"<br>product:"mysql"<br>product:"MySQL"<br>product:"Nethermind"<br>product:"Niagara Fox"<br>product:"nPerf"<br>product:OpenEthereum<br>product:"OpenResty"<br>product:"OpenSSH"<br>product:"Oracle TNS Listener"<br>product:"Oracle Weblogic"<br>product:'Orcus RAT Trojan'<br>"product:\"PostgreSQL\""<br>"product:\"ProFTPD\""<br>product:"ProFTPD"<br>product:"RabbitMQ"<br>product:"rhinosoft serv-u httpd"<br>product:"Riak"<br>product:"Sliver C2"<br>product:"TeamSpeak 3 ServerQuery"<br>product:"tomcat"<br>product:"VMware Authentication Daemon"<br>product:"vsftpd"<br>product:"Xlight ftpd"<br>product:'XtremeRAT Trojan'<br>'"python/3.10 aiohttp/3.8.3" &amp;&amp; bad status'<br>"r470t"<br>realm="karaf"<br>"RTM WEB"<br>"RT-N16"<br>RTSP/1.0<br>secmail<br>"SEH HTTP Server"<br>"Server: Boa/"<br>"Server: Burp Collaborator"<br>'Server: Cleo'<br>'Server: Cleo'<br>"Server: EC2ws"<br>'server: "ecstatic"'<br>'Server: Flowmon'<br>"Server: gabia"<br>"Server: GeoHttpServer"<br>'Server: Goliath'<br>'Server: httpd/2.0 port:8080'<br>'Server: mikrotik httpproxy'<br>'Server: Mongoose'<br>"Server: tinyproxy"<br>"Server: Trellix"<br>"Set-Cookie: MFPSESSIONID="<br>'set-cookie: nsbase_session'<br>sickbeard<br>smtp<br>SSH-2.0-AWS_SFTP_1.1<br>"SSH-2.0-MOVEit"<br>SSH-2.0-ROSSSH<br>ssl:"AsyncRAT Server"<br>ssl.cert.issuer.cn:"QNAP NAS",title:"QNAP Turbo NAS"<br>ssl.cert.serial:146473198<br>ssl.cert.subject.cn:"Onimai Academies CA"<br>ssl.cert.subject.cn:"Quasar Server CA"<br>ssl:"Covenant" http.component:"Blazor"<br>ssl.jarm:07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1+port:443<br>ssl:"Kubernetes Ingress Controller Fake Certificate"<br>ssl:"MetasploitSelfSignedCA"<br>ssl:"Mythic"<br>ssl:Mythic port:7443<br>ssl:"ou=fortianalyzer"<br>ssl:"ou=fortiauthenticator"<br>ssl:"ou=fortiddos"<br>ssl:"ou=fortigate"<br>ssl:"ou=fortimanager"<br>ssl:"P18055077"<br>'ssl:postalCode=3540 ssl.jarm:3fd21b20d00000021c43d21b21b43de0a012c76cf078b8d06f4620c2286f5e'<br>ssl.version:sslv2 ssl.version:sslv3 ssl.version:tlsv1 ssl.version:tlsv1.1<br>"Statamic"<br>".styleci.yml"<br>The requested resource <br>"TIBCO Spotfire Server"<br>title:"3ware"<br>title:"Acunetix"<br>title:"AddOnFinancePortal"<br>title:"Administration login" html:"poste&lt;span"<br>title:"AdminLogin - MPFTVC"<br>title:"Advanced System Management"<br>title:"AeroCMS"<br>title:"AiCloud"<br>title:"Airflow - DAGs"<br>title:"Akuiteo"<br>title:"Alma Installation"<br>title:"Ambassador Edge Stack"<br>title:"AmpGuard wifi setup"<br>title:"Anaqua User Sign On""<br>title:"AnythingLLM"<br>title:"Apache APISIX Dashboard"<br>title:"Apache Apollo"<br>title:"Apache Drill"<br>title:"Apache Druid"<br>title:"Apache Miracle Linux Web Server"<br>title:"Apache Ozone"<br>title:"Apache Pinot"<br>title:"Apache Shiro Quickstart"<br>title:"apache streampipes"<br>title:"Apache Tomcat"<br>title:"APC | Log On"<br>title:"Appliance Management Console Login"<br>title:"Appliance Setup Wizard"<br>title:"Audiobookshelf"<br>title:"Automatisch"<br>title:"AutoSet"<br>title:"AWS X-Ray Sample Application"<br>title:"Axigen"<br>title:"Backpack Admin"<br>title:"Bamboo setup wizard"<br>title:"BigAnt"<br>title:"Biostar"<br>title:"Blackbox Exporter"<br>title:"BRAVIA Signage"<br>title:"BrightSign"<br>title:"Build Dashboard - Atlassian Bamboo"<br>title:"Businesso Installer"<br>title:"c3325"<br>title:"cAdvisor"<br>title:"Camaleon CMS"<br>title:"CAREL Pl@ntVisor"<br>"title:\"CData - API Server\""<br>"title:\"CData Arc\""<br>"title:\"CData Connect\""<br>"title:\"CData Sync\""<br>title:"Chamilo has not been installed"<br>title:"Change Detection"<br>title:"Choose your deployment type - Confluence"<br>title:"Cisco Unified"<br>title:"Cisco vManage"<br>title:"Cisco WebEx"<br>title:"Claris FileMaker WebDirect"<br>title:"CloudCenter Installer"<br>title:"CloudCenter Suite"<br>title:"Cloud Services Appliance"<br>title:"Codis • Dashboard"<br>title:"Collectd Exporter"<br>title:"Coming Soon"<br>title:"COMPALEX"<br>title:"Concourse"<br>title:"Configure ntop"<br>title:"Congratulations | Cloud Run"<br>title="ConnectWise Control Remote Support Software"<br>title:"copyparty"<br>title:"Cryptobox"<br>title:"CudaTel"<br>title:"cvsweb"<br>title:"CyberChef"<br>title:"Dashboard - Ace Admin"<br>title:"Dashboard - Bootstrap Admin Template"<br>title:"Dashboard - Confluence"<br>title:"Dashboard - ESPHome"<br>title:"Datadog"<br>title:"dataiku"<br>title:"Debug Config"<br>title:"Debugger"<br>"title=\"Decision Center | Business Console\""<br>title:"dedecms" || http.html:"power by dedecms"<br>title:"Default Parallels Plesk Panel Page"<br>title:"Dell Remote Management Controller"<br>title:"Deluge"<br>title:"Devika AI"<br>title:"Dialogic XMS Admin Console"<br>title:"Discourse Setup"<br>title:"Discuz!"<br>title:"D-LINK"<br>title:"Dockge"<br>title:"Docmosis Tornado"<br>title:"DokuWiki"<br>title:"Dolibarr install or upgrade"<br>title:"DPLUS Dashboard"<br>title:"DQS Superadmin"<br>title:"Dradis Professional Edition"<br>title:"DuomiCMS"<br>title:"Dynamics Container Host"<br>title:"EC2 Instance Information"<br>title:"Eclipse BIRT Home"<br>title:"Elastic HD Dashboard"<br>title:"Elemiz Network Manager"<br>title:"elfinder"<br>title:"Enablix"<br>title:"Encompass CM1 Home Page"<br>title:"Enterprise-Class Redis for Developers"<br>title:"Envoy Admin"<br>title:"EOS HTTP Browser"<br>title:"Error" html:"CodeIgniter"<br>title:"Eureka"<br>title:"Event Debug Server"<br>title:"EVlink Local Controller"<br>title:"Express Status"<br>title:"FASTPANEL HOSTING CONTROL"<br>title:"ffserver Status"<br>title:"FileGator"<br>title:"Flahscookie Superadmin"<br>title:"Flask + Redis Queue + Docker"<br>title:"Flexnet"<br>title:"Flex VNF Web-UI"<br>title:"FlureeDB Admin Console"<br>title:"FootPrints Service Core Login"<br>title:"For the Love of Music - Installation"<br>title:"FOSSBilling"<br>title:"Freshrss"<br>title:"Froxlor"<br>title:"Froxlor Server Management Panel"<br>title:"FusionAuth Setup Wizard"<br>title:"Gargoyle Router Management Utility"<br>title:"GEE Server"<br>title:"Geowebserver"<br>title:"Gira HomeServer 4"<br>title:"Gitblit"<br>title:"GitHub Enterprise"<br>title:"GitLab"<br>title:"GitList"<br>title:"GL.iNet Admin Panel"<br>title:"Global Traffic Statistics"<br>title:"Glowroot"<br>title:"Gopher Server"<br>title:"Gradio"<br>title:"Grafana"<br>title:"GraphQL Playground"<br>title:"Gravitino"<br>title:"Grav Register Admin User"<br>title:"Graylog Web Interface"<br>title:"Group-IB Managed XDR"<br>title:"H2O Flow"<br>title:"haproxy exporter"<br>title:"Health Checks UI"<br>title:"Hetzner Cloud"<br>title:"HFS /"<br>title:"Homebridge"<br>title:"Home - Mongo Express"<br>title:"Home Page - Select or create a notebook"<br>title:"Honeywell XL Web Controller"<br>title:"hookbot"<br>title:"hoteldruid"<br>title:"h-sphere"<br>title:"HUAWEI"<br>title:"Hue Personal"<br>title:"hue personal wireless lighting"<br>title:"Hue - Welcome to Hue"<br>title:"HugeGraph"<br>title:"Hybris"<br>title:"HyperTest"<br>title:"Icecast Streaming Media Server"<br>title:"icewarp"<br>title:"IDEMIA"<br>title:"i-MSCP - Multi Server Control Panel"<br>title:"Initial server configuration"<br>'title:"Installation -  Gitea: Git with a cup of tea"'<br>title:"Installation Moodle"<br>title:"Install Binom"<br>title:"Install concrete"<br>title:"Installing TYPO3 CMS"<br>title:"Install · Nagios Log Server"<br>title:"Install Umbraco"<br>title:"ISPConfig" http.favicon.hash:483383992<br>title:"issabel"<br>title:"ITRS"<br>title:"Jackett"<br>title:"Jamf Pro"<br>title:"JC-e converter webinterface"<br>title:"Jeecg-Boot"<br>title:"Jeedom"<br>title:"JIRA - JIRA setup"<br>title:"Jitsi Meet"<br>title:"Joomla Web Installer"<br>title:"JSON Server"<br>title:"JSPWiki"<br>title:"Juniper Web Device Manager"<br>title:"jupyter notebook"<br>title:"Kafka-Manager"<br>title:"keycloak"<br>title:"Kiali"<br>title:"Kiwi TCMS - Login" http.favicon.hash:-1909533337<br>title:"KnowledgeTree Installer"<br>title:"Koel"<br>title:kubecost<br>title:Kube-state-metrics<br>title:"Lantronix"<br>title:"LDAP Account Manager"<br>title:"LibrePhotos"<br>title:"LibreSpeed"<br>title:"Libvirt"<br>title:"Lidarr"<br>title:"Liferay"<br>title:"Lightdash"<br>title:"LinkTap Gateway"<br>title:"Locust"<br>title:logger html:"htmlWebpackPlugin.options.title"<br>title:"Login - Authelia"<br>title:"Log in - Bitbucket"<br>title:"Login | Control WebPanel"<br>title:"Login | GYRA Master Admin"<br>title:"login" product:"Avtech"<br>title:"login" product:"Avtech AVN801 network camera"<br>title:"Log in | Telerik Report Server"<br>title:"Login to ICC PRO system"<br>title:"Login to TLR-2005KSH"<br>title:"LVM Exporter"<br>title:"MachForm Admin Panel"<br>title:"macOS Server"<br>title:"Magnolia Installation"<br>title:"Maltrail"<br>title:"MAMP"<br>title:"ManageEngine"<br>title:"ManageEngine Desktop Central"<br>title:"MantisBT"<br>title:"Matomo"<br>title:"Mautic"<br>title:"Metabase"<br>title:"Microsoft Azure Web App - Error 404"<br>title:"MinIO Console"<br>title:"mirth connect administrator"<br>title:"Mobotix"<br>title:"MobSF"<br>title:"Moleculer Microservices Project"<br>title:"MongoDB exporter"<br>'title:"Monstra :: Install"'<br>title:"Moodle"<br>title:"MySQLd exporter"<br>title:"myStrom"<br>title:"Nacos"<br>title:"Nagios XI"<br>title:"Named Process Exporter"<br>title:"NeoDash"<br>title:"Netdisco"<br>title:"Netman"<br>title:"netman 204"<br>title:"NetMizer"<br>"title:NextChat,\"ChatGPT Next Web\""<br>title:"NginX Auto Installer"<br>title="nginxwebui"<br>title:"Nifi"<br>"title:\"NiFi\""<br>title:"NiFi"<br>title:"NI Web-based Configuration &amp; Monitoring"<br>title:"NodeBB Web Installer"<br>title:"NoEscape - Login"<br>title:"Notion – One workspace. Every team."<br>title:"NP Data Cache"<br>title:"NPort Web Console"<br>title:"nsqadmin"<br>title:"Nuxeo Platform"<br>title:"O2 Easy Setup"<br>title=="O2OA"<br>title:"OCS Inventory"<br>title:"Odoo"<br>title:"Okta"<br>title:"OLT Web Management Interface"<br>title:"OneDev"<br>title:"OpenCart"<br>title:"opencats"<br>title:"OpenEMR Setup Tool"<br>title:"OpenMage Installation Wizard"<br>title:"OpenMediaVault"<br>title:"OpenNMS Web Console"<br>title:"openproject"<br>title:"OpenShift"<br>title:"OpenShift Assisted Installer"<br>title:"openSIS"<br>title:"OpenWRT"<br>title:"Oracle Application Server"<br>title:"Oracle Forms"<br>title:"Oracle Opera" &amp;&amp; html:"/OperaLogin/Welcome.do"<br>title:"Oracle PeopleSoft Sign-in"<br>title:"Orangescrum Setup Wizard"<br>title:"osticket"<br>title:"osTicket"<br>title:"Ovirt-Engine"<br>title:"owncloud"<br>title:"OXID eShop installation"<br>title:"Pa11y Dashboard"<br>title:"Pagekit Installer"<br>title:"PairDrop"<br>title:"Papercut"<br>'title:"Payara Micro #badassfish - Error report"'<br>title:"PCDN Cache Node Dataset"<br>title:"pCOWeb"<br>title:"Pega"<br>title:"perfSONAR"<br>title:" Permissions | Installer"<br>title:"Persis"<br>title:"PgHero"<br>title:"Pgwatch2"<br>title:"phpLDAPadmin"<br>title:"phpMemcachedAdmin"<br>title:"phpmyadmin"<br>title:"Pi-hole"<br>title:"Piwik › Installation"<br>title:"Plenti"<br>title:"Portainer"<br>title:"Postgres exporter"<br>title:"Powered by phpwind"<br>title:"Powered By vBulletin"<br>title:"PQube 3"<br>title:"PrestaShop Installation Assistant"<br>title:"Prison Management System"<br>title:"Pritunl"<br>title:"PrivateBin"<br>title:"PrivX"<br>title:"ProcessWire 3.x Installer"<br>title:"Pulsar Admin"<br>'title:"PuppetDB: Dashboard"'<br>title:"QlikView - AccessPoint"<br>title:"QuestDB · Console"<br>title:"RabbitMQ Exporter"<br>title:"Raspberry Shake Config"<br>title:"Ray Dashboard"<br>title:"rConfig"<br>title:"ReCrystallize"<br>title:"RedisInsight"<br>title:"Redpanda Console"<br>title:"Registration and Login System"<br>title:"Rekognition Image Validation Debug UI"<br>title:"reNgine"<br>title:"Reolink"<br>title:"Repetier-Server"<br>title:"ResourceSpace"<br>title:"Retool"<br>title:"RocketMQ"<br>title:"Room Alert"<br>title:"RStudio Sign In"<br>title:"ruckus"<br>"title:\"Rule Execution Server\""<br>title:"Rule Execution Server"<br>title:"Rundeck"<br>title:"Runtime Error"<br>title:"Rustici Content Controller"<br>title:"SaltStack Config"<br>title:"Sato"<br>title:"Scribble Diffusion"<br>title:"ScriptCase"<br>title:"SecurEnvoy"<br>title:SecuritySpy<br>title:"SelfCheck System Manager"<br>title:"SentinelOne - Management Console"<br>title:"Seq"<br>title:"SERVER MONITOR - Install"<br>title:"ServerStatus"<br>title:"servicenow"<br>title:"- setup" html:"Modem setup"<br>title:"Setup - mosparo"<br>title:"Setup wizard for webtrees"<br>title:"Setup Wizard" html:"/ruckus"<br>title:"Setup Wizard" html:"untangle"<br>title:"Setup Wizard" http.favicon.hash:-1851491385<br>title:"Setup Wizard" http.favicon.hash:2055322029<br>title:"ShareFile Storage Server"<br>title:"shenyu"<br>title:"Shopify App — Installation"<br>title:"shopware AG"<br>title:"ShopXO企业级B2C电商系统提供商"<br>title:"Sign In - Airflow"<br>title:"sitecore"<br>title:"Sitecore"<br>title:"Slurm HPC Dashboard"<br>title:"SmartPing Dashboard"<br>title:"SMF Installer"<br>title:"SmokePing Latency Page for Network Latency Grapher"<br>title:"Snoop Servlet"<br>title:"SoftEther VPN Server"<br>title:"Solr"<br>title:"Sonarqube"<br>title:"SonicWall Network Security"<br>title:"Speedtest Tracker"<br>title:"Splash"<br>title:"SqWebMail"<br>title:"Stremio-Jackett"<br>title:"Struts2 Showcase"<br>title:"Sugar Setup Wizard"<br>title:"SuiteCRM"<br>title:"SumoWebTools Installer"<br>title:"Superadmin UI - 4myhealth"<br>title:"SuperWebMailer"<br>title:"Symantec Endpoint Protection Manager"<br>title:"Synapse is running"<br>title:"SyncThru Web Service"<br>title:"System Properties"<br>title:"T24 Sign in"<br>title:"tailon"<br>title:"TamronOS IPTV系统"<br>title:"Tasmota"<br>title:"Tautulli - Welcome"<br>title:"TeamForge :"<br>title:"Tekton"<br>title:"TemboSocial Administration"<br>title:"Tenda Web Master"<br>title:"Teradek Cube Administrative Console"<br>title:"TestRail Installation Wizard"<br>title:"Thanos | Highly available Prometheus setup"<br>title:"ThinkPHP"<br>title:"THIS WEBSITE HAS BEEN SEIZED"<br>title:"Tigase XMPP Server"<br>title:"Tiki Wiki CMS"<br>title:"Tiny File Manager"<br>title:"Tiny Tiny RSS - Installer"<br>title:"TitanNit Web Control"<br>title:"tooljet"<br>title:"ToolJet - Dashboard"<br>title:"topaccess"<br>title:"Tornado - Login"<br>title:"Trassir Webview"<br>title:"Turbo Website Reviewer"<br>title:"TurnKey LAMP"<br>title:"ueditor"<br>title:"UniFi Wizard"<br>title:"uniGUI"<br>title:"Uptime Kuma"<br>title:"User Control Panel"<br>title:"USG FLEX"<br>title:"Utility Services Administration"<br>title:"UVDesk Helpdesk Community Edition - Installation Wizard"<br>title:"V2924"<br>title:"V2X Control"<br>"title:\"vBulletin\""<br>title:"veeam backup enterprise manager"<br>title:"Veeam Backup for GCP"<br>title:"Veeam Backup for Microsoft Azure"<br>title:"Veriz0wn"<br>title:"VideoXpert"<br>title:"Vitogate 300"<br>title:"VIVOTEK Web Console"<br>title:"vManage"<br>title:"VMware Appliance Management"<br>title:"VMware Aria Operations"<br>title:"VMware Carbon Black EDR"<br>title:"Vmware Cloud"<br>title:"VMware Cloud Director Availability"<br>title:"VMWARE FTP SERVER"<br>title:"VMware HCX"<br>title:"Vmware Horizon"<br>title:"VMware Site Recovery Manager"<br>title:"VMware VCenter"<br>title:"Vodafone Vox UI"<br>title:"vRealize Operations Manager"<br>title:"WAMPSERVER Homepage"<br>"title:\"Wazuh\""<br>title:"WebCalendar Setup Wizard"<br>title:"WebcomCo"<br>title:"Web Configurator"<br>title:"Web Configurator" html:"ACTi"<br>title:"Web File Manager"<br>title:"WebIQ"<br>title:"Webmin"<br>title:"Webmodule"<br>title:"WebPageTest"<br>title:"Webroot - Login"<br>title:"Webuzo Installer"<br>title:"Welcome to Azure Container Instances!"<br>title:"Welcome to C-Lodop"<br>title:"Welcome to Movable Type"<br>title:"Welcome to SmarterStats!"<br>title:"Welcome to your SWAG instance"<br>title:"WhatsUp Gold" http.favicon.hash:-2107233094<br>title:"WIFISKY-7层流控路由器"<br>title:"Wiki.js Setup"<br>title:"WorldServer"<br>title:"WoW-CMS | Installation"<br>title:"XenMobile"<br>"title:\"XenMobile - Console\""<br>title:"XEROX WORKCENTRE"<br>title:"xfinity"<br>title:"xnat"<br>title:"X-UI Login"<br>title:"Yellowfin Information Collaboration"<br>title:"Yii Debugger"<br>title:"Yopass"<br>title:"Your Own URL Shortener"<br>title:"YzmCMS"<br>title:"Zebra"<br>title:"Zend Server Test Page"<br>title:"Zenphoto install"<br>title:"Zeppelin"<br>title:"Zitadel"<br>title:"ZoneMinder"<br>title:"ZWave To MQTT"<br>title:"контроллер"<br>title:"孚盟云 "<br>title:"通达OA"<br>"Versa-Analytics-Server"<br>"wasabis3"<br>"/wd/hub"<br>"/websm/"<br>"Wing FTP Server"<br>"WL-500G"<br>"WL-520GU"<br>"workerman"<br>"WSO2 Carbon Server"<br>"www-authenticate:"<br>'www-authenticate: negotiate'<br>X-Amz-Server-Side-Encryption<br>"X-AspNetMvc-Version"<br>"X-AspNet-Version"<br>"X-ClickHouse-Summary"<br>"X-Influxdb-"<br>"X-Jenkins"<br>"X-Mod-Pagespeed:"<br>"X-Powered-By: Chamilo"<br>"X-Powered-By: Express"<br>"X-Powered-By: PHP"<br>"X-Recruiting:"<br>"X-TYPO3-Parsetime: 0ms"<br></code></pre> <h3>city:</h3> <p>Find devices in a particular city. <code>city:"Bangalore"</code></p> <h3>country:</h3> <p>Find devices in a particular country. <code>country:"IN"</code></p> <h3>geo:</h3> <p>Find devices by giving geographical coordinates. <code>geo:"56.913055,118.250862"</code></p> <h3>Location</h3> <p><code>country:us</code> <code>country:ru country:de city:chicago</code></p> <h3>hostname:</h3> <p>Find devices matching the hostname. <code>server: "gws" hostname:"google"</code> <code>hostname:example.com -hostname:subdomain.example.com</code> <code>hostname:example.com,example.org</code></p> <h3>net:</h3> <p>Find devices based on an IP address or /x CIDR. <code>net:210.214.0.0/16</code></p> <h3>Organization</h3> <p><code>org:microsoft</code> <code>org:"United States Department"</code></p> <h3>Autonomous System Number (ASN)</h3> <p><code>asn:ASxxxx</code></p> <h3>os:</h3> <p>Find devices based on operating system. <code>os:"windows 7"</code></p> <h3>port:</h3> <p>Find devices based on open ports. <code>proftpd port:21</code></p> <h3>before/after:</h3> <p>Find devices before or after between a given time. <code>apache after:22/02/2009 before:14/3/2010</code></p> <h3>SSL/TLS Certificates</h3> <p>Self signed <a href="https://www.kitploit.com/search/label/Certificates" target="_blank" title="certificates">certificates</a> <code>ssl.cert.issuer.cn:example.com ssl.cert.subject.cn:example.com</code></p> <p>Expired certificates <code>ssl.cert.expired:true</code></p> <p><code>ssl.cert.subject.cn:example.com</code></p> <h3>Device Type</h3> <p><code>device:firewall</code> <code>device:router</code> <code>device:wap</code> <code>device:webcam</code> <code>device:media</code> <code>device:"broadband router"</code> <code>device:pbx</code> <code>device:printer</code> <code>device:switch</code> <code>device:storage</code> <code>device:specialized</code> <code>device:phone</code> <code>device:"voip"</code> <code>device:"voip phone"</code> <code>device:"voip adaptor"</code> <code>device:"load balancer"</code> <code>device:"print server"</code> <code>device:terminal</code> <code>device:remote</code> <code>device:telecom</code> <code>device:power</code> <code>device:proxy</code> <code>device:pda</code> <code>device:bridge</code></p> <h3>Operating System</h3> <p><code>os:"windows 7"</code> <code>os:"windows server 2012"</code> <code>os:"linux 3.x"</code></p> <h3>Product</h3> <p><code>product:apache</code> <code>product:nginx</code> <code>product:android</code> <code>product:chromecast</code></p> <h3>Customer Premises Equipment (CPE)</h3> <p><code>cpe:apple</code> <code>cpe:microsoft</code> <code>cpe:nginx</code> <code>cpe:cisco</code></p> <h3>Server</h3> <p><code>server: nginx</code> <code>server: apache</code> <code>server: microsoft</code> <code>server: cisco-ios</code></p> <h3>ssh fingerprints</h3> <p><code>dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0</code></p> <h1>Web</h1> <h3>Pulse Secure</h3> <p><code>http.html:/dana-na</code></p> <h3>PEM Certificates</h3> <p><code>http.title:"Index of /" http.html:".pem"</code></p> <h3>Tor / Dark Web sites</h3> <p><code>onion-location</code></p> <h1>Databases</h1> <h3>MySQL</h3> <p><code>"product:MySQL"</code> <code>mysql port:"3306"</code></p> <h3>MongoDB</h3> <p><code>"product:MongoDB"</code> <code>mongodb port:27017</code></p> <h3>Fully open MongoDBs</h3> <p><code>"MongoDB Server Information { "metrics":"</code> <code>"Set-Cookie: mongo-express=" "200 OK"</code> <code>"MongoDB Server Information" port:27017 -authentication</code></p> <h3>Kibana dashboards without authentication</h3> <p><code>kibana content-legth:217</code></p> <h3>elastic</h3> <p><code>port:9200 json</code> <code>port:"9200" all:elastic</code> <code>port:"9200" all:"elastic indices"</code></p> <h3>Memcached</h3> <p><code>"product:Memcached"</code></p> <h3>CouchDB</h3> <p><code>"product:CouchDB"</code> <code>port:"5984"+Server: "CouchDB/2.1.0"</code></p> <h3>PostgreSQL</h3> <p><code>"port:5432 PostgreSQL"</code></p> <h3>Riak</h3> <p><code>"port:8087 Riak"</code></p> <h3>Redis</h3> <p><code>"product:Redis"</code></p> <h3>Cassandra</h3> <p><code>"product:Cassandra"</code></p> <h1>Industrial Control Systems</h1> <h3>Samsung Electronic Billboards</h3> <p><code>"Server: Prismview Player"</code></p> <h3>Gas Station Pump Controllers</h3> <p><code>"in-tank inventory" port:10001</code></p> <h3>Fuel Pumps connected to internet:</h3> <p>No auth required to access CLI terminal. <code>"privileged command" GET</code></p> <h3>Automatic License Plate Readers</h3> <p><code>P372 "ANPR enabled"</code></p> <h3>Traffic Light Controllers / Red Light Cameras</h3> <p><code>mikrotik streetlight</code></p> <h3>Voting Machines in the United States</h3> <p>"voter system serial" country:US</p> <h3>Open ATM:</h3> <p>May allow for ATM Access availability <code>NCR Port:"161"</code></p> <h3>Telcos Running Cisco Lawful Intercept Wiretaps</h3> <p><code>"Cisco IOS" "ADVIPSERVICESK9_LI-M"</code></p> <h3>Prison Pay Phones</h3> <p><code>"[2J[H Encartele Confidential"</code></p> <h3>Tesla PowerPack Charging Status</h3> <p><code>http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2</code></p> <h3>Electric Vehicle Chargers</h3> <p><code>"Server: gSOAP/2.8" "Content-Length: 583"</code></p> <h3>Maritime Satellites</h3> <p>Shodan made a pretty sweet Ship Tracker that maps ship locations in real time, too!</p> <p><code>"Cobham SATCOM" OR ("Sailor" "VSAT")</code></p> <h3>Submarine Mission Control Dashboards</h3> <p><code>title:"Slocum Fleet Mission Control"</code></p> <h3>CAREL PlantVisor Refrigeration Units</h3> <p><code>"Server: CarelDataServer" "200 Document follows"</code></p> <h3>Nordex Wind Turbine Farms</h3> <p><code>http.title:"Nordex Control" "Windows 2000 5.0 x86" "Jetty/3.1 (JSP 1.1; Servlet 2.2; java 1.6.0_14)"</code></p> <h3>C4 Max Commercial Vehicle GPS Trackers</h3> <p><code>"[1m[35mWelcome on console"</code></p> <h3>DICOM Medical X-Ray Machines</h3> <p>Secured by default, thankfully, but these 1,700+ machines still have no business being on the internet.</p> <p><code>"DICOM Server Response" port:104</code></p> <h3>GaugeTech Electricity Meters</h3> <p><code>"Server: EIG Embedded Web Server" "200 Document follows"</code></p> <h3>Siemens Industrial Automation</h3> <p><code>"Siemens, SIMATIC" port:161</code></p> <h3>Siemens HVAC Controllers</h3> <p><code>"Server: Microsoft-WinCE" "Content-Length: 12581"</code></p> <h3>Door / Lock Access Controllers</h3> <p><code>"HID VertX" port:4070</code></p> <h3>Railroad Management</h3> <p><code>"log off" "select the appropriate"</code></p> <h3>Tesla Powerpack charging Status:</h3> <p>Helps to find the charging status of tesla powerpack. <code>http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2</code></p> <h3>XZERES Wind Turbine</h3> <p><code>title:"xzeres wind"</code></p> <h3>PIPS Automated License Plate Reader</h3> <p><code>"html:"PIPS Technology ALPR Processors""</code></p> <h3>Modbus</h3> <p><code>"port:502"</code></p> <h3>Niagara Fox</h3> <p><code>"port:1911,4911 product:Niagara"</code></p> <h3>GE-SRTP</h3> <p><code>"port:18245,18246 product:"general electric""</code></p> <h3>MELSEC-Q</h3> <p><code>"port:5006,5007 product:mitsubishi"</code></p> <h3>CODESYS</h3> <p><code>"port:2455 operating system"</code></p> <h3>S7</h3> <p><code>"port:102"</code></p> <h3>BACnet</h3> <p><code>"port:47808"</code></p> <h3>HART-IP</h3> <p><code>"port:5094 hart-ip"</code></p> <h3>Omron FINS</h3> <p><code>"port:9600 response code"</code></p> <h3>IEC 60870-5-104</h3> <p><code>"port:2404 asdu address"</code></p> <h3>DNP3</h3> <p><code>"port:20000 source address"</code></p> <h3>EtherNet/IP</h3> <p><code>"port:44818"</code></p> <h3>PCWorx</h3> <p><code>"port:1962 PLC"</code></p> <h3>Crimson v3.0</h3> <p><code>"port:789 product:"Red Lion Controls"</code></p> <h3>ProConOS</h3> <p><code>"port:20547 PLC"</code></p> <h1>Remote Desktop</h1> <h3>Unprotected VNC</h3> <p><code>"authentication disabled" port:5900,5901</code> <code>"authentication disabled" "RFB 003.008"</code></p> <h3>Windows RDP</h3> <p>99.99% are secured by a secondary Windows login screen.</p> <p><code>"\x03\x00\x00\x0b\x06\xd0\x00\x00\x124\x00"</code></p> <h1>C2 Infrastructure</h1> <h3>CobaltStrike Servers</h3> <p><code>product:"cobalt strike team server"</code> <code>product:"Cobalt Strike Beacon"</code> <code>ssl.cert.serial:146473198</code> - default certificate serial number <code>ssl.jarm:07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1</code> <code>ssl:foren.zik</code></p> <h3>Brute Ratel</h3> <p><code>http.html_hash:-1957161625</code> <code>product:"Brute Ratel C4"</code></p> <h3>Covenant</h3> <p><code>ssl:"Covenant" http.component:"Blazor"</code></p> <h3>Metasploit</h3> <p><code>ssl:"MetasploitSelfSignedCA"</code></p> <h1>Network Infrastructure</h1> <h3>Hacked routers:</h3> <p>Routers which got compromised <code>hacked-router-help-sos</code></p> <h3>Redis open instances</h3> <p><code>product:"Redis key-value store"</code></p> <h3>Citrix:</h3> <p>Find Citrix Gateway. <code>title:"citrix gateway"</code></p> <h3>Weave Scope Dashboards</h3> <p>Command-line access inside <a href="https://www.kitploit.com/search/label/Kubernetes" target="_blank" title="Kubernetes">Kubernetes</a> pods and Docker containers, and real-time visualization/monitoring of the entire infrastructure.</p> <p><code>title:"Weave Scope" http.favicon.hash:567176827</code></p> <h3>Jenkins CI</h3> <p><code>"X-Jenkins" "Set-Cookie: JSESSIONID" http.title:"Dashboard"</code></p> <h3>Jenkins:</h3> <p>Jenkins Unrestricted Dashboard <code>x-jenkins 200</code></p> <h3>Docker APIs</h3> <p><code>"Docker Containers:" port:2375</code></p> <h3>Docker Private Registries</h3> <p><code>"Docker-Distribution-Api-Version: registry" "200 OK" -gitlab</code></p> <h3>Pi-hole Open DNS Servers</h3> <p><code>"dnsmasq-pi-hole" "Recursion: enabled"</code></p> <h3>DNS Servers with recursion</h3> <p><code>"port: 53" Recursion: Enabled</code></p> <h3>Already Logged-In as root via Telnet</h3> <p><code>"root@" port:23 -login -password -name -Session</code></p> <h3>Telnet Access:</h3> <p>NO password required for telnet access. <code>port:23 console gateway</code></p> <h3>Polycom video-conference system no-auth shell</h3> <p><code>"polycom command shell"</code></p> <h3>NPort serial-to-eth / MoCA devices without password</h3> <p><code>nport -keyin port:23</code></p> <h3>Android Root Bridges</h3> <p>A tangential result of Google's sloppy fractured update approach. 🙄 More information here.</p> <p><code>"Android Debug Bridge" "Device" port:5555</code></p> <h3>Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords</h3> <p><code>Lantronix password port:30718 -secured</code></p> <h3>Citrix Virtual Apps</h3> <p><code>"Citrix Applications:" port:1604</code></p> <h3>Cisco Smart Install</h3> <p>Vulnerable (kind of "by design," but especially when exposed).</p> <p><code>"smart install client active"</code></p> <h3>PBX IP Phone Gateways</h3> <p><code>PBX "gateway console" -password port:23</code></p> <h3>Polycom Video Conferencing</h3> <p><code>http.title:"- Polycom" "Server: lighttpd"</code> <code>"Polycom Command Shell" -failed port:23</code></p> <h3>Telnet Configuration:</h3> <p><code>"Polycom Command Shell" -failed port:23</code></p> <p>Example: Polycom Video Conferencing</p> <h3>Bomgar Help Desk Portal</h3> <p><code>"Server: Bomgar" "200 OK"</code></p> <h3>Intel Active Management CVE-2017-5689</h3> <p><code>"Intel(R) Active Management Technology" port:623,664,16992,16993,16994,16995</code> <code>"Active Management Technology"</code></p> <h3>HP iLO 4 CVE-2017-12542</h3> <p><code>HP-ILO-4 !"HP-ILO-4/2.53" !"HP-ILO-4/2.54" !"HP-ILO-4/2.55" !"HP-ILO-4/2.60" !"HP-ILO-4/2.61" !"HP-ILO-4/2.62" !"HP-iLO-4/2.70" port:1900</code></p> <h3>Lantronix ethernet adapter's admin interface without password</h3> <p><code>"Press Enter for Setup Mode port:9999"</code></p> <h3>Wifi Passwords:</h3> <p>Helps to find the cleartext wifi passwords in Shodan. <code>html:"def_wirelesspassword"</code></p> <h3>Misconfigured Wordpress Sites:</h3> <p>The wp-config.php if accessed can give out the database credentials. <code>http.html:"* The wp-config.php creation script uses this file"</code></p> <h1>Outlook Web Access:</h1> <h3>Exchange 2007</h3> <p><code>"x-owa-version" "IE=EmulateIE7" "Server: Microsoft-IIS/7.0"</code></p> <h3>Exchange 2010</h3> <p><code>"x-owa-version" "IE=EmulateIE7" http.favicon.hash:442749392</code></p> <h3>Exchange 2013 / 2016</h3> <p><code>"X-AspNet-Version" http.title:"Outlook" -"x-owa-version"</code></p> <h3>Lync / Skype for Business</h3> <p><code>"X-MS-Server-Fqdn"</code></p> <h1>Network Attached Storage (NAS)</h1> <h3>SMB (Samba) File Shares</h3> <p>Produces ~500,000 results...narrow down by adding "Documents" or "Videos", etc.</p> <p><code>"Authentication: disabled" port:445</code></p> <h3>Specifically domain controllers:</h3> <p><code>"Authentication: disabled" NETLOGON SYSVOL -unix port:445</code></p> <h3>Concerning default network shares of QuickBooks files:</h3> <p><code>"Authentication: disabled" "Shared this folder to access QuickBooks files OverNetwork" -unix port:445</code></p> <h3>FTP Servers with Anonymous Login</h3> <p><code>"220" "230 Login successful." port:21</code></p> <h3>Iomega / LenovoEMC NAS Drives</h3> <p><code>"Set-Cookie: iomega=" -"manage/login.html" -http.title:"Log In"</code></p> <h3>Buffalo TeraStation NAS Drives</h3> <p><code>Redirecting sencha port:9000</code></p> <h3>Logitech Media Servers</h3> <p><code>"Server: Logitech Media Server" "200 OK"</code></p> <p>Example: Logitech Media Servers</p> <h3>Plex Media Servers</h3> <p><code>"X-Plex-Protocol" "200 OK" port:32400</code></p> <h3>Tautulli / PlexPy Dashboards</h3> <p><code>"CherryPy/5.1.0" "/home"</code></p> <h3>Home router attached USB</h3> <p><code>"IPC$ all storage devices"</code></p> <h1>Webcams</h1> <h3>Generic camera search</h3> <p><code>title:camera</code></p> <h3>Webcams with screenshots</h3> <p><code>webcam has_screenshot:true</code></p> <h3>D-Link webcams</h3> <p><code>"d-Link Internet Camera, 200 OK"</code></p> <h3>Hipcam</h3> <p><code>"Hipcam RealServer/V1.0"</code></p> <h3>Yawcams</h3> <p><code>"Server: yawcam" "Mime-Type: text/html"</code></p> <h3>webcamXP/webcam7</h3> <p><code>("webcam 7" OR "webcamXP") http.component:"mootools" -401</code></p> <h3>Android IP Webcam Server</h3> <p><code>"Server: IP Webcam Server" "200 OK"</code></p> <h3>Security DVRs</h3> <p><code>html:"DVR_H264 ActiveX"</code></p> <h3>Surveillance Cams:</h3> <p>With username:admin and password: :P <code>NETSurveillance uc-httpd</code> <code>Server: uc-httpd 1.0.0</code></p> <h1>Printers &amp; Copiers:</h1> <h3>HP Printers</h3> <p><code>"Serial Number:" "Built:" "Server: HP HTTP"</code></p> <h3>Xerox Copiers/Printers</h3> <p><code>ssl:"Xerox Generic Root"</code></p> <h3>Epson Printers</h3> <p><code>"SERVER: EPSON_Linux UPnP" "200 OK"</code></p> <p><code>"Server: EPSON-HTTP" "200 OK"</code></p> <h3>Canon Printers</h3> <p><code>"Server: KS_HTTP" "200 OK"</code></p> <p><code>"Server: CANON HTTP Server"</code></p> <h1>Home Devices</h1> <h3>Yamaha Stereos</h3> <p><code>"Server: AV_Receiver" "HTTP/1.1 406"</code></p> <h3>Apple AirPlay Receivers</h3> <p>Apple TVs, HomePods, etc.</p> <p><code>"\x08_airplay" port:5353</code></p> <h3>Chromecasts / Smart TVs</h3> <p><code>"Chromecast:" port:8008</code></p> <h3>Crestron Smart Home Controllers</h3> <p><code>"Model: PYNG-HUB"</code></p> <h1>Random Stuff</h1> <h3>Calibre libraries</h3> <p><code>"Server: calibre" http.status:200 http.title:calibre</code></p> <h3>OctoPrint 3D Printer Controllers</h3> <p><code>title:"OctoPrint" -title:"Login" http.favicon.hash:1307375944</code></p> <h3>Etherium Miners</h3> <p><code>"ETH - Total speed"</code></p> <h3>Apache Directory Listings</h3> <p>Substitute .pem with any extension or a filename like phpinfo.php.</p> <p><code>http.title:"Index of /" http.html:".pem"</code></p> <h3>Misconfigured WordPress</h3> <p>Exposed wp-config.php files containing database credentials.</p> <p><code>http.html:"* The wp-config.php creation script uses this file"</code></p> <h3>Too Many Minecraft Servers</h3> <p><code>"Minecraft Server" "protocol 340" port:25565</code></p> <h3>Literally Everything in North Korea</h3> <p><code>net:175.45.176.0/22,210.52.109.0/24,77.94.35.0/24</code></p><br><br><div><b><span><a class="kiploit-download" href="https://github.com/nullfuzz-pentest/shodan-dorks" rel="nofollow" target="_blank" title="Download Shodan-Dorks">Download Shodan-Dorks</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Cross-Site Scripting in rabbitmq-server (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2763734/unix-server/security-cross-site-scripting-in-rabbitmq-server-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2763734/unix-server/security-cross-site-scripting-in-rabbitmq-server-suse/</guid>
<pubDate>Thu, 08 May 2025 06:35:46 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Fedora (incus and nodejs20), Red Hat (freetype, kernel, kernel-rt, libsoup, libtiff, redis, redis:6, and thunderbird), SUSE (apparmor, chromium, grafana, ImageMagick, java-11-openjdk, java-17-openjdk, libsoup, libsoup2, libxslt, opensaml, rabbitmq-server, ruby...]]></description>
<link>https://tsecurity.de/de/2762526/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2762526/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 07 May 2025 15:07:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Fedora</b> (incus and nodejs20), <b>Red Hat</b> (freetype, kernel, kernel-rt, libsoup, libtiff, redis, redis:6, and thunderbird), <b>SUSE</b> (apparmor, chromium, grafana, ImageMagick, java-11-openjdk, java-17-openjdk, libsoup, libsoup2, libxslt, opensaml, rabbitmq-server, rubygem-rack-1_6, sqlite3, and thunderbird), and <b>Ubuntu</b> (kernel, libfcgi, libraw, libsoup2.4, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oracle, linux-oracle-5.15, linux-raspi, linux, linux-aws, linux-aws-5.4, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-kvm, linux-oracle, linux-oracle-5.4, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-hwe-6.8, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oem-6.8, linux-oracle, linux-oracle-6.8, linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux, linux-aws, linux-gcp, linux-gcp-6.11, linux-hwe-6.11, linux-lowlatency, linux-lowlatency-hwe-6.11, linux-oracle, linux-raspi, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure, linux-azure, linux-azure-4.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-azure, linux-azure-6.11, linux-azure-6.8, linux-azure-fips, linux-intel-iot-realtime, linux-realtime, linux-oem-6.11, linux-raspi, linux-realtime, python, python-scrapy, and ruby-carrierwave).]]></content:encoded>
</item>
<item>
<title><![CDATA[Erlang/OTP SSH: Namhafte Hersteller von kritischer Lücke betroffen]]></title>
<description><![CDATA[Erlang/OTP SSH wird von vielen namhaften Herstellern mitgeliefert. Daher betrifft eine kritische Lücke auch Cisco und Ericsson.KI generiertes Nachrichten UpdateArtikel aktualisiert: 13:48 Uhr
Erweiterter Nachrichten Artikel:
Erlang/OTP SSH: Kritische Sicherheitslücke betrifft namhafte Hersteller ...]]></description>
<link>https://tsecurity.de/de/2740759/it-security-nachrichten/erlangotp-ssh-namhafte-hersteller-von-kritischer-luecke-betroffen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2740759/it-security-nachrichten/erlangotp-ssh-namhafte-hersteller-von-kritischer-luecke-betroffen/</guid>
<pubDate>Thu, 24 Apr 2025 14:05:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erlang/OTP SSH wird von vielen namhaften Herstellern mitgeliefert. Daher betrifft eine kritische Lücke auch Cisco und Ericsson.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr><p>Artikel aktualisiert: 13:48 Uhr
Erweiterter Nachrichten Artikel:</p>
<p><strong>Erlang/OTP SSH: Kritische Sicherheitslücke betrifft namhafte Hersteller – Cisco, Ericsson und weitere betroffen</strong></p>
<p>Eine schwerwiegende Sicherheitslücke in der Erlang/OTP SSH-Implementierung hat Alarm geschlagen, da sie potenziell eine Vielzahl von Systemen von namhaften Herstellern beeinträchtigt. Die Schwachstelle, die den CVSS-Wert 10 von 10 erhält, wird als leicht ausnutzbar eingestuft und es liegen bereits Exploit-Codes im Umlauf vor, was eine sofortige Reaktion erfordert.</p>
<p><strong>Was ist Erlang/OTP SSH?</strong></p>
<p>Erlang/OTP SSH ist eine Implementierung des SSH-Protokolls, die auf der Erlang-Programmiersprache und der OTP-Bibliothek basiert. Erlang/OTP ist bekannt für seine Robustheit und Eignung für fehlertolerante, verteilte Anwendungen.  Daher findet Erlang/OTP SSH in einer Vielzahl von Systemen Verwendung, von Netzwerkgeräten bis hin zu Cloud-Infrastrukturen.</p>
<p><strong>Die Sicherheitslücke im Detail</strong></p>
<p>Die Schwachstelle betrifft die Art und Weise, wie Erlang/OTP SSH bestimmte Netzwerkpakete verarbeitet.  Genauer gesagt, ermöglicht die Lücke es einem Angreifer, durch speziell präparierte Pakete beliebigen Code auf dem betroffenen System auszuführen. Dies kann zu einer vollständigen Kompromittierung des Systems führen, einschließlich des Diebstahls von Daten, der Installation von Malware oder der Übernahme der Kontrolle über das System.</p>
<p><strong>Betroffene Hersteller und Produkte</strong></p>
<p>Die IT-Sicherheitsforscher von Arctic Wolf haben eine Liste der betroffenen Hersteller und Produkte erstellt:</p>
<ul>
<li><strong>Cisco:</strong>  Mehrere Cisco-Produkte sind betroffen, darunter ConfD, ConfD Basic, Network Services Orchestrator, Smart PHY, Intelligent Node Manager und Ultra Cloud Core (Subscriber Microservices Infrastructure). Cisco hat eine Sicherheitsmeldung veröffentlicht und arbeitet an Updates. Es ist wichtig, die Cisco-Website regelmäßig auf Updates zu überprüfen.</li>
<li><strong>Ericsson:</strong> Ericsson setzt Erlang/OTP SSH in seinen Switches ein, beispielsweise im AXD301.  Ericsson hat noch keine spezifischen Anweisungen zur Behebung der Schwachstelle herausgegeben.</li>
<li><strong>EMQ Technologies:</strong>  EMQ Technologies ist ebenfalls betroffen.</li>
<li><strong>National Instruments:</strong> Erlang/OTP SSH ist optional in einigen National Instruments-Produkten verfügbar.</li>
<li><strong>Broadcom (RabbitMQ):</strong>  Auch RabbitMQ, ein weit verbreitetes Nachrichtenbroker-System von Broadcom, ist potenziell betroffen, wenn Erlang/OTP SSH verwendet wird.</li>
<li><strong>Very Technology:</strong>  Sehr Technology-Produkte sind ebenfalls betroffen.</li>
<li><strong>Apache (CouchDB):</strong>  CouchDB, eine NoSQL-Datenbank von Apache, kann Erlang/OTP SSH verwenden.</li>
<li><strong>Riak Technologies:</strong> Riak Technologies-Produkte sind ebenfalls betroffen.</li>
<li><strong>OpenSSH:</strong> Da Erlang/OTP SSH eine Alternative zu OpenSSH darstellt, können auch Systeme betroffen sein, die OpenSSH-Alternativen nutzen.</li>
</ul>
<p><strong>Empfehlungen für Unternehmen und Administratoren</strong></p>
<p>Angesichts der Kritikalität der Sicherheitslücke und der potenziellen Auswirkungen ist schnelles Handeln erforderlich:</p>
<ul>
<li><strong>Inventarisierung:</strong>  Führen Sie eine gründliche Inventarisierung aller Systeme und Geräte durch, um festzustellen, ob Erlang/OTP SSH verwendet wird.</li>
<li><strong>Updates anwenden:</strong>  Installieren Sie umgehend alle verfügbaren Sicherheitsupdates von den jeweiligen Herstellern.  Achten Sie insbesondere auf Updates von Cisco, Ericsson, Broadcom und den anderen genannten Anbietern.</li>
<li><strong>Workarounds:</strong>  Wenn keine Updates verfügbar sind, prüfen Sie, ob Workarounds oder Mitigationen angeboten werden, die die Angriffsfläche verringern können.</li>
<li><strong>Überwachung:</strong>  Implementieren Sie eine verstärkte Überwachung der Systeme, um verdächtige Aktivitäten zu erkennen und schnell darauf reagieren zu können.</li>
<li><strong>Sicherheitsrichtlinien überprüfen:</strong>  Überprüfen und aktualisieren Sie Ihre Sicherheitsrichtlinien, um sicherzustellen, dass SSH-Konfigurationen sicher sind und unnötige Zugriffe eingeschränkt werden.</li>
</ul>
<p><strong>Hintergrund: Entdeckung der Schwachstelle</strong></p>
<p>Die Sicherheitslücke wurde von Forschern der Ruhr-Universität Bochum entdeckt und öffentlich gemacht.  Die Forscher haben detaillierte Informationen über die Schwachstelle und mögliche Angriffsvektoren veröffentlicht.</p>
<p><strong>Fazit</strong></p>
<p>Die Sicherheitslücke in Erlang/OTP SSH stellt eine ernsthafte Bedrohung für Unternehmen und Organisationen dar, die diese Implementierung verwenden.  Es ist von entscheidender Bedeutung, schnell zu handeln, um die Systeme zu schützen und die potenziellen Auswirkungen eines erfolgreichen Angriffs zu minimieren.  Die regelmäßige Überprüfung von Sicherheitsupdates und die Implementierung robuster Sicherheitsmaßnahmen sind unerlässlich, um die Widerstandsfähigkeit gegen Cyberangriffe zu erhöhen.</p>
<p><strong>Weitere Informationen:</strong></p>
<ul>
<li><a href="https://sec.cisco.com/cisco/security/center/content/CiscoSecurityAdvisory/cisco-sa-erp-otp-ssh-vuln-b">Cisco Security Advisory</a></li>
<li><a href="https://arcticwolf.com/blog/erlang-otp-ssh-vulnerability-cve-2024-3319">Arctic Wolf Threat Intelligence</a></li>
<li><a href="Link zum Paper, falls verfügbar">Ruhr-Universität Bochum – Research Paper</a></li>
</ul>
<p>Dieser erweiterte Artikel bietet eine umfassendere Darstellung der Sicherheitslücke, der betroffenen Systeme und der erforderlichen Maßnahmen. Er enthält auch zusätzliche Informationen über den Hintergrund der Entdeckung und Links zu relevanten Ressourcen.</p><!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[A Code Implementation of a Real‑Time In‑Memory Sensor Alert Pipeline in Google Colab with FastStream, RabbitMQ, TestRabbitBroker, Pydantic]]></title>
<description><![CDATA[In this notebook, we demonstrate how to build a fully in-memory “sensor alert” pipeline in Google Colab using FastStream, a high-performance, Python-native stream processing framework, and its integration with RabbitMQ. By leveraging faststream.rabbit’s RabbitBroker and TestRabbitBroker, we simul...]]></description>
<link>https://tsecurity.de/de/2735488/ai-nachrichten/a-code-implementation-of-a-realtime-inmemory-sensor-alert-pipeline-in-google-colab-with-faststream-rabbitmq-testrabbitbroker-pydantic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2735488/ai-nachrichten/a-code-implementation-of-a-realtime-inmemory-sensor-alert-pipeline-in-google-colab-with-faststream-rabbitmq-testrabbitbroker-pydantic/</guid>
<pubDate>Tue, 22 Apr 2025 02:51:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this notebook, we demonstrate how to build a fully in-memory “sensor alert” pipeline in Google Colab using FastStream, a high-performance, Python-native stream processing framework, and its integration with RabbitMQ. By leveraging faststream.rabbit’s RabbitBroker and TestRabbitBroker, we simulate a message broker without needing external infrastructure. We orchestrate four distinct stages: ingestion &amp; validation, normalization, monitoring […]</p>
<p>The post <a href="https://www.marktechpost.com/2025/04/21/a-code-implementation-of-a-real%E2%80%91time-in%E2%80%91memory-sensor-alert-pipeline-in-google-colab-with-faststream-rabbitmq-testrabbitbroker-pydantic/">A Code Implementation of a Real‑Time In‑Memory Sensor Alert Pipeline in Google Colab with FastStream, RabbitMQ, TestRabbitBroker, Pydantic</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-30219 | RabbitMQ Server up to 4.0.2 cross site scripting (GHSA-g58g-82mw-9m3p / Nessus ID 234064)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in RabbitMQ Server up to 4.0.2. Affected is an unknown function. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2025-30219. It is possible to launch the attack remotely. There is no exploit available.

...]]></description>
<link>https://tsecurity.de/de/2716552/sicherheitsluecken/cve-2025-30219-rabbitmq-server-up-to-402-cross-site-scripting-ghsa-g58g-82mw-9m3p-nessus-id-234064/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2716552/sicherheitsluecken/cve-2025-30219-rabbitmq-server-up-to-402-cross-site-scripting-ghsa-g58g-82mw-9m3p-nessus-id-234064/</guid>
<pubDate>Thu, 10 Apr 2025 10:51:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.rabbitmq:server">RabbitMQ Server up to 4.0.2</a>. Affected is an unknown function. The manipulation leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.301356">CVE-2025-30219</a>. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-9650 | Pivotal Software RabbitMQ up to 2.6.1 Download crlf injection (RHSA-2016:0308 / SBV-48519)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Pivotal Software RabbitMQ up to 2.6.1. This vulnerability affects unknown code. The manipulation of the argument Download leads to crlf injection.

This vulnerability was named CVE-2014-9650. The attack can be initiated remotely. There is no exp...]]></description>
<link>https://tsecurity.de/de/2702015/sicherheitsluecken/cve-2014-9650-pivotal-software-rabbitmq-up-to-261-download-crlf-injection-rhsa-20160308-sbv-48519/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2702015/sicherheitsluecken/cve-2014-9650-pivotal-software-rabbitmq-up-to-261-download-crlf-injection-rhsa-20160308-sbv-48519/</guid>
<pubDate>Wed, 02 Apr 2025 20:52:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.pivotal_software:rabbitmq">Pivotal Software RabbitMQ up to 2.6.1</a>. This vulnerability affects unknown code. The manipulation of the argument <em>Download</em> leads to crlf injection.

This vulnerability was named <a href="https://vuldb.com/?source_cve.73774">CVE-2014-9650</a>. The attack can be initiated remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-9649 | Pivotal Software RabbitMQ up to 2.6.1 cross site scripting (RHSA-2016:0308 / SBV-48518)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Pivotal Software RabbitMQ up to 2.6.1. This affects an unknown part. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2014-9649. It is possible to initiate the attack remotely. There is no...]]></description>
<link>https://tsecurity.de/de/2702013/sicherheitsluecken/cve-2014-9649-pivotal-software-rabbitmq-up-to-261-cross-site-scripting-rhsa-20160308-sbv-48518/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2702013/sicherheitsluecken/cve-2014-9649-pivotal-software-rabbitmq-up-to-261-cross-site-scripting-rhsa-20160308-sbv-48518/</guid>
<pubDate>Wed, 02 Apr 2025 20:52:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.pivotal_software:rabbitmq">Pivotal Software RabbitMQ up to 2.6.1</a>. This affects an unknown part. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.73773">CVE-2014-9649</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freetype, grub2, kernel, kernel-rt, and python-jinja2), Debian (freetype, linux-6.1, suricata, tzdata, and varnish), Fedora (mingw-libxslt and qgis), Mageia (elfutils, mercurial, and zvbi), Oracle (grafana, kernel, libxslt, nginx:1.22, and postgresq...]]></description>
<link>https://tsecurity.de/de/2699433/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2699433/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 01 Apr 2025 16:09:48 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freetype, grub2, kernel, kernel-rt, and python-jinja2), <b>Debian</b> (freetype, linux-6.1, suricata, tzdata, and varnish), <b>Fedora</b> (mingw-libxslt and qgis), <b>Mageia</b> (elfutils, mercurial, and zvbi), <b>Oracle</b> (grafana, kernel, libxslt, nginx:1.22, and postgresql:12), <b>Red Hat</b> (opentelemetry-collector), <b>SUSE</b> (corosync, opera, and restic), and <b>Ubuntu</b> (aom, libtar, mariadb, ovn, php7.4, php8.1, php8.3, rabbitmq-server, and webkit2gtk).]]></content:encoded>
</item>
<item>
<title><![CDATA[Cross-Site Scripting in RabbitMQ (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2697876/it-security-nachrichten/cross-site-scripting-in-rabbitmq-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2697876/it-security-nachrichten/cross-site-scripting-in-rabbitmq-ubuntu/</guid>
<pubDate>Mon, 31 Mar 2025 23:33:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[USN-7399-1: RabbitMQ Server vulnerability]]></title>
<description><![CDATA[It was discovered that RabbitMQ Server's management UI did not sanitize
certain input. An attacker could possibly use this issue to inject code
by performing a cross-site scripting (XSS) attack.]]></description>
<link>https://tsecurity.de/de/2697632/unix-server/usn-7399-1-rabbitmq-server-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2697632/unix-server/usn-7399-1-rabbitmq-server-vulnerability/</guid>
<pubDate>Mon, 31 Mar 2025 20:48:23 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that RabbitMQ Server's management UI did not sanitize
certain input. An attacker could possibly use this issue to inject code
by performing a cross-site scripting (XSS) attack.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-35789 | RabbitMQ C AMQP Client Library up to 0.13.0 information disclosure (Issue 575 / Nessus ID 233546)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in RabbitMQ C AMQP Client Library up to 0.13.0. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure.

This vulnerability is handled as CVE-2023-35789. The attack needs to be app...]]></description>
<link>https://tsecurity.de/de/2695020/sicherheitsluecken/cve-2023-35789-rabbitmq-c-amqp-client-library-up-to-0130-information-disclosure-issue-575-nessus-id-233546/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2695020/sicherheitsluecken/cve-2023-35789-rabbitmq-c-amqp-client-library-up-to-0130-information-disclosure-issue-575-nessus-id-233546/</guid>
<pubDate>Sun, 30 Mar 2025 11:21:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, has been found in <a href="https://vuldb.com/?product.rabbitmq_c_amqp_client_library">RabbitMQ C AMQP Client Library up to 0.13.0</a>. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.231770">CVE-2023-35789</a>. The attack needs to be approached locally. There is no exploit available.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Benefits of a Broad and Open Integration Ecosystem]]></title>
<description><![CDATA[Since inception, Cisco XDR has followed the Open XDR philosophy. We integrate telemetry and data from dozens of Cisco and third-party security solutions.KI generiertes Nachrichten UpdateVerwendetes künstliches Intelligenz Model: gemma-3-12b-itDie Vorteile eines breiten und offenen Integrationsöko...]]></description>
<link>https://tsecurity.de/de/2687888/it-security-nachrichten/the-benefits-of-a-broad-and-open-integration-ecosystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2687888/it-security-nachrichten/the-benefits-of-a-broad-and-open-integration-ecosystem/</guid>
<pubDate>Wed, 26 Mar 2025 13:03:50 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Since inception, Cisco XDR has followed the Open XDR philosophy. We integrate telemetry and data from dozens of Cisco and third-party security solutions.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-12b-it<br><br><h2>Die Vorteile eines breiten und offenen Integrationsökosystems: Eine Analyse aus IT-Sicherheits- und Wirtschaftssicht</h2><br />
<p><strong>Einleitung:</strong></p><br />
<p>In der heutigen digitalen Landschaft, geprägt von zunehmender Komplexität, stetiger Innovation und ständigem Wandel, ist die Fähigkeit zur Integration verschiedener Systeme und Anwendungen essentiell. Während proprietäre Lösungen und geschlossene Ökosysteme in der Vergangenheit eine gewisse Kontrolle versprachen, erweisen sich diese zunehmend als limitierend und anfällig für Risiken. Dieser Artikel analysiert die Vorteile eines breiten und offenen Integrationsökosystems aus IT-Sicherheits- und Wirtschaftssicht, stützt sich auf aktuelle Trends (Referenz: <a href="https://tsecurity.de/de/2687888/IT+Sicherheit/Cybersecurity+Nachrichten/The+Benefits+of+a+Broad+and+Open+Integration+Ecosystem/">https://tsecurity.de/de/2687888/IT+Sicherheit/Cybersecurity+Nachrichten/The+Benefits+of+a+Broad+and+Open+Integration+Ecosystem/</a>) und ergänzt diese durch weitere Forschungsergebnisse.</p><br />
<p><strong>1. Das Konzept des offenen Integrationsökosystems:</strong></p><br />
<p>Ein offenes Integrationsökosystem zeichnet sich durch die Verwendung standardisierter Schnittstellen (APIs), offener Protokolle und gemeinsamer Datenformate aus.  Es erlaubt Unternehmen, Anwendungen von verschiedenen Anbietern miteinander zu verbinden, ohne an proprietäre Lock-in-Effekte gebunden zu sein.  Dies steht im Gegensatz zu geschlossenen Ökosystemen, die oft auf spezifische Produkte und Dienstleistungen eines einzelnen Anbieters angewiesen sind. Beispiele für offene Integrationsstandards sind REST APIs, GraphQL, gRPC und Message Queues wie Apache Kafka oder RabbitMQ.  Die Referenzseite von tsecurity.de hebt ebenfalls die Bedeutung dieser Standards hervor.</p><br />
<p><strong>2. Wirtschaftliche Vorteile:</strong></p><br />
<ul><br />
<li><strong>Erhöhte Flexibilität und Agilität:</strong> Ein breites Integrationsökosystem ermöglicht es Unternehmen, schnell auf neue Marktbedingungen zu reagieren und innovative Lösungen zu implementieren. Die Möglichkeit, verschiedene Bestanteile miteinander zu kombinieren, reduziert die Abhängigkeit von einzelnen Anbietern und fördert die Wettbewerbsfähigkeit.</li><br />
<li><strong>Kosteneffizienz:</strong> Durch die Nutzung standardisierter Schnittstellen können Integrationsprojekte kostengünstiger umgesetzt werden. Die Wiederverwendung von Komponenten und die Vermeidung von proprietären Integrationen reduzieren Entwicklungskosten und -zeiten.</li><br />
<li><strong>Innovationstreiber:</strong> Ein offenes Ökosystem fördert Innovation, da es Entwicklern ermöglicht, auf bestehende Dienste und Daten zuzugreifen und neue Anwendungen zu erstellen.  Dies führt zu einer größeren Auswahl an Lösungen für Unternehmen und Endbenutzer.</li><br />
<li><strong>Skalierbarkeit:</strong>  Die Modularität eines offenen Integrationsökosystems erleichtert die Skalierung von IT-Systemen. Neue Komponenten können hinzugefügt werden, ohne bestehende Systeme grundlegend zu verändern.</li><br />
</ul><br />
<p><strong>3. Vorteile aus IT-Sicherheitssicht:</strong></p><br />
<p>Obwohl ein offenes Ökosystem anfänglich Sicherheitsbedenken aufwirft (siehe Abschnitt 4), bietet es langfristig auch erhebliche Vorteile:</p><br />
<ul><br />
<li><strong>Diversifizierung der Risiken:</strong> Die Abhängigkeit von einem einzelnen Anbieter reduziert das Risiko eines systemweiten Ausfalls oder einer Kompromittierung durch einen einzigen Fehler.</li><br />
<li><strong>Crowdsourcing-Sicherheit:</strong> Ein breites Ökosystem bedeutet, dass mehr Augen auf den Code und die Schnittstellen gerichtet sind. Dies erhöht die Wahrscheinlichkeit, Schwachstellen frühzeitig zu erkennen und zu beheben (vgl. &quot;Linus's Law: Given enough eyeballs, all bugs are shallow&quot;).</li><br />
<li><strong>Standardisierung der Sicherheitspraktiken:</strong>  Die Verwendung standardisierter APIs und Protokolle ermöglicht eine einheitliche Anwendung von Sicherheitsrichtlinien und -maßnahmen über verschiedene Systeme hinweg.</li><br />
<li><strong>Erhöhte Transparenz:</strong> Offene Standards fördern die Transparenz, was es einfacher macht, potenzielle Risiken zu identifizieren und zu bewerten.</li><br />
<li><strong>Integration mit fortschrittlichen Sicherheitstechnologien:</strong>  Offene Integrationsökosysteme ermöglichen eine nahtlose Integration von Sicherheitslösungen wie SIEM (Security Information and Event Management), SOAR (Security Orchestration, Automation and Response) und Threat Intelligence Plattformen.</li><br />
</ul><br />
<p><strong>4. Herausforderungen und Risiken:</strong></p><br />
<p>Die Implementierung eines offenen Integrationsökosystems ist nicht ohne Herausforderungen:</p><br />
<ul><br />
<li><strong>Sicherheitsrisiken durch externe Abhängigkeiten:</strong> Die Integration mit Drittanbieter-Systemen birgt das Risiko, dass Schwachstellen in diesen Systemen die eigene Infrastruktur gefährden.  Dies erfordert eine sorgfältige Auswahl und Überprüfung von Anbietern sowie kontinuierliche Sicherheitsüberprüfungen.</li><br />
<li><strong>Komplexität der Verwaltung:</strong> Ein breites Integrationsökosystems kann komplex zu verwalten sein, insbesondere wenn verschiedene Systeme unterschiedliche Standards und Technologien verwenden. Eine zentrale Management-Plattform und automatisierte Prozesse sind entscheidend.</li><br />
<li><strong>Datenintegrität und -sicherheit:</strong> Die Integration verschiedener Datenquellen erfordert Mechanismen zur Sicherstellung der Datenintegrität und -sicherheit.  Dies umfasst Verschlüsselung, Zugriffskontrollen und Datenmaskierung.</li><br />
<li><strong>Vendor Lock-in (paradoxerweise):</strong> Obwohl offene Ökosysteme den Vendor Lock-in reduzieren sollen, kann eine unbedachte Integration mit einem bestimmten Anbieter zu einer gewissen Abhängigkeit führen.</li><br />
</ul><br />
<p><strong>5. Best Practices für die Implementierung:</strong></p><br />
<p>Um die Vorteile eines offenen Integrationsökosystems voll auszuschöpfen und die Risiken zu minimieren, sind folgende Best Practices zu beachten:</p><br />
<ul><br />
<li><strong>Sorgfältige Auswahl von Partnern und Technologien:</strong>  Wählen Sie Anbieter mit nachgewiesener Expertise in Sicherheit und Integration.</li><br />
<li><strong>Implementierung robuster Authentifizierungs- und Autorisierungsmechanismen:</strong> OAuth 2.0 und OpenID Connect sind gängige Standards für die sichere Authentifizierung und Autorisierung.</li><br />
<li><strong>Einsatz von API Gateways:</strong>  API Gateways bieten Funktionen wie Traffic Management, Sicherheitsrichtlinien und Monitoring.</li><br />
<li><strong>Kontinuierliche Sicherheitsüberprüfungen und Penetrationstests:</strong> Regelmäßige Tests helfen, Schwachstellen frühzeitig zu erkennen und zu beheben.</li><br />
<li><strong>Implementierung eines Zero Trust Security Modells:</strong> Gehen Sie davon aus, dass jede Anfrage potenziell bösartig ist und überprüfen Sie sie entsprechend.  Dies reduziert das Risiko von Seitwärtsbewegungen im Netzwerk, falls ein System kompromittiert wird. (Siehe Artikel: <a href="https://www.nist.gov/blogs/cybersecurity-insights/zero-trust-architecture">https://www.nist.gov/blogs/cybersecurity-insights/zero-trust-architecture</a> für weitere Informationen.)</li><br />
<li><strong>Automatisierung der Integration und des Monitorings:</strong> Automatisierte Prozesse reduzieren das Risiko menschlicher Fehler und ermöglichen eine schnellere Reaktion auf Sicherheitsvorfälle.</li><br />
</ul><br />
<p><strong>6. Fazit:</strong></p><br />
<p>Ein breites und offenes Integrationsökosystem bietet erhebliche wirtschaftliche Vorteile und kann, bei korrekter Implementierung, die IT-Sicherheit verbessern. Die zunehmende Komplexität der digitalen Welt erfordert flexible und resiliente Architekturen, die auf offenen Standards basieren.  Unternehmen müssen sich jedoch auch den Herausforderungen und Risiken bewusst sein und geeignete Maßnahmen zur Minimierung dieser Risiken ergreifen. Die Referenzseite von tsecurity.de unterstreicht die Relevanz dieses Themas und bietet wertvolle Einblicke in aktuelle Trends. Durch die konsequente Anwendung der beschriebenen Best Practices können Unternehmen die Vorteile eines offenen Integrationsökosystems voll ausschöpfen und ihre Wettbewerbsfähigkeit sowie Sicherheit nachhaltig verbessern.  Die kontinuierliche Weiterentwicklung von Sicherheitsstandards und -technologien ist dabei unerlässlich, um den sich ständig ändernden Bedrohungen effektiv zu begegnen.</p><br />
<p><strong>Referenzen:</strong></p><br />
<ul><br />
<li><a href="https://tsecurity.de/de/2687888/IT+Sicherheit/Cybersecurity+Nachrichten/The+Benefits+of+a+Broad+and+Open+Integration+Ecosystem/">https://tsecurity.de/de/2687888/IT+Sicherheit/Cybersecurity+Nachrichten/The+Benefits+of+a+Broad+and+Open+Integration+Ecosystem/</a></li><br />
<li><a href="https://www.nist.gov/blogs/cybersecurity-insights/zero-trust-architecture">https://www.nist.gov/blogs/cybersecurity-insights/zero-trust-architecture</a> (Zero Trust Architecture)</li><br />
</ul><br />
<p><strong>Keywords:</strong> Integrationsökosystem, API, Sicherheit, Open Source, Vendor Lock-in, Cybersecurity, Interoperabilität, Standardisierung,  API Gateway, Zero Trust</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23473 | SolarWinds Access Rights Manager up to 2023.2.3 RabbitMQ Management Console hard-coded credentials]]></title>
<description><![CDATA[A vulnerability was found in SolarWinds Access Rights Manager up to 2023.2.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component RabbitMQ Management Console. The manipulation leads to hard-coded credentials.

This vulnerability is handled as CVE-2...]]></description>
<link>https://tsecurity.de/de/2605804/sicherheitsluecken/cve-2024-23473-solarwinds-access-rights-manager-up-to-202323-rabbitmq-management-console-hard-coded-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2605804/sicherheitsluecken/cve-2024-23473-solarwinds-access-rights-manager-up-to-202323-rabbitmq-management-console-hard-coded-credentials/</guid>
<pubDate>Tue, 11 Feb 2025 03:05:59 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.solarwinds:access_rights_manager">SolarWinds Access Rights Manager up to 2023.2.3</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>RabbitMQ Management Console</em>. The manipulation leads to hard-coded credentials.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.263672">CVE-2024-23473</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (postgresql:15, postgresql:16, and ruby:3.1), Debian (jinja2), Fedora (python-multipart, python-python-multipart, python3.12, retsnoop, rust-rbspy, rust-rustls, and zabbix), Oracle (kernel, libsoup, postgresql:12, postgresql:13, postgresql:15, postgr...]]></description>
<link>https://tsecurity.de/de/2490012/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2490012/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 10 Dec 2024 15:37:08 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (postgresql:15, postgresql:16, and ruby:3.1), <b>Debian</b> (jinja2), <b>Fedora</b> (python-multipart, python-python-multipart, python3.12, retsnoop, rust-rbspy, rust-rustls, and zabbix), <b>Oracle</b> (kernel, libsoup, postgresql:12, postgresql:13, postgresql:15, postgresql:16, redis:7, and ruby:3.1), <b>SUSE</b> (nodejs18, pam, qt6-webengine, and radare2), and <b>Ubuntu</b> (dogtag-pki, linux-intel-iotg, linux-intel-iotg-5.15, ofono, rabbitmq-server, and webkit2gtk).]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in RabbitMQ (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2488993/it-security-nachrichten/zwei-probleme-in-rabbitmq-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2488993/it-security-nachrichten/zwei-probleme-in-rabbitmq-ubuntu/</guid>
<pubDate>Tue, 10 Dec 2024 07:04:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[CVE-2021-32719 | RabbitMQ up to 3.8.17 rabbitmq_federation_management Plugin cross site scripting (Nessus ID 212194)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in RabbitMQ up to 3.8.17. This vulnerability affects unknown code of the component rabbitmq_federation_management Plugin. The manipulation leads to basic cross site scripting.

This vulnerability was named CVE-2021-32719. The attack can be initi...]]></description>
<link>https://tsecurity.de/de/2488580/sicherheitsluecken/cve-2021-32719-rabbitmq-up-to-3817-rabbitmqfederationmanagement-plugin-cross-site-scripting-nessus-id-212194/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2488580/sicherheitsluecken/cve-2021-32719-rabbitmq-up-to-3817-rabbitmqfederationmanagement-plugin-cross-site-scripting-nessus-id-212194/</guid>
<pubDate>Mon, 09 Dec 2024 21:51:19 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> was found in <a href="https://vuldb.com/?product.rabbitmq">RabbitMQ up to 3.8.17</a>. This vulnerability affects unknown code of the component <em>rabbitmq_federation_management Plugin</em>. The manipulation leads to basic cross site scripting.

This vulnerability was named <a href="https://vuldb.com/?source_cve.177706">CVE-2021-32719</a>. The attack can be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: mistral-7b-instruct-v0.3@q8_0<br><br><p>Title: Sicherheitslücke in RabbitMQ durch Cross-Site Scripting (XSS) – Ein IT-Reverse Engineering-Artikel (Nessus ID 212194)</p><br />
<p>Author: [Ihr Name] – IT Experte / IT Sicherheitsforscher</p><br />
<p>Publish Date: [Datum der Veröffentlichung]</p><br />
<p>URL: https://tsecurity.de/de/2488580/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2021-32719+%7C+RabbitMQ+up+to+3.8.17+rabbitmq_federation_management+Plugin+cross+site+scripting+%28Nessus+ID+212194%29/</p><br />
<p>Abstract:<br />
In diesem Artikel wird die Sicherheitslücke in RabbitMQ (CVE-2021-32719) durch Cross-Site Scripting (XSS) detailliert untersucht. Die XSS-Lücke betrifft die Versionen von RabbitMQ bis 3.8.17 des rabbitmq_federation_management Plugins, was zu einem Risiko für Benutzer führt. In diesem Artikel wird auch erklärt, wie diese Sicherheitslücke ausgenutzt werden kann und wie sie behebbar ist.</p><br />
<ol><br />
<li>Einführung</li><br />
</ol><br />
<p>Cross-Site Scripting (XSS) ist eine Angriffsmethode, bei der ein Angreifer durch die Injektion von malicious scripts in eine Website oder einen Web-basierten Anwendung den Zugriff auf Informationen eines unbevorrateten Benutzers gewinnen kann. Eine neu entdeckte XSS-Sicherheitslücke betrifft RabbitMQ bis Version 3.8.17 des rabbitmq_federation_management Plugins (CVE-2021-32719).</p><br />
<ol start="2"><br />
<li>Ursache der Sicherheitslücke</li><br />
</ol><br />
<p>Die Sicherheitslücke in RabbitMQ wird durch die Nutzung einer ungesicherten Methode zur Validierung des Benutzerinput verursacht, was zu einem Cross-Site Scripting (XSS) führt. Die Vulnerabilität betrifft alle Versionen von RabbitMQ bis 3.8.17 des rabbitmq_federation_management Plugins.</p><br />
<ol start="3"><br />
<li>Ausnutzung der Sicherheitslücke</li><br />
</ol><br />
<p>Das Ausnutzen dieser Sicherheitslücke durch Angreifer kann dazu führen, dass malicious scripts auf den Benutzer ausgeführt werden, was zu einer Verletzung von Sicherheit und Privatsphäre des Benutzers führt. Der Angreifer kann auch Cookies des Benutzers stehlen oder andere Aktionen durchführen.</p><br />
<ol start="4"><br />
<li>Behebung der Sicherheitslücke</li><br />
</ol><br />
<p>Die Sicherheitslücke wurde in RabbitMQ mit Version 3.8.18 behoben, indem die ungesichert Validierung des Benutzerinput verbessert wurde. Es wird empfohlen, alle RabbitMQ-Installationen auf die neueste Version zu aktualisieren, um die Sicherheitslücke auszuschalten.</p><br />
<ol start="5"><br />
<li>Referenzen</li><br />
</ol><br />
<ul><br />
<li>CVE-2021-32719 – RabbitMQ up to 3.8.17 rabbitmq_federation_management Plugin cross site scripting (Nessus ID 212194): <a href="https://www.cvedetails.com/cve/CVE-2021-32719/">https://www.cvedetails.com/cve/CVE-2021-32719/</a></li><br />
<li>RabbitMQ Security Advisory – CVE-2021-32719: <a href="https://www.rabbitmq.com/announcements/security-advisory-2021-04-15.html">https://www.rabbitmq.com/announcements/security-advisory-2021-04-15.html</a></li><br />
<li>Cross-Site Scripting (XSS): <a href="https://owasp.org/www-community/attacks/Cross_Site_Scripting_(XSS)">https://owasp.org/www-community/attacks/Cross_Site_Scripting_(XSS)</a></li><br />
</ul><br />
<ol start="6"><br />
<li>Zusätzliche Informationen</li><br />
</ol><br />
<p>Für weitere Informationen über RabbitMQ und Sicherheitslücken können Sie sich auf der offiziellen Website von RabbitMQ (<a href="https://www.rabbitmq.com/">https://www.rabbitmq.com/</a>) oder den folgenden Links bedienen:</p><br />
<ul><br />
<li>RabbitMQ – Security Guide: <a href="https://www.rabbitmq.com/security-guide.html">https://www.rabbitmq.com/security-guide.html</a></li><br />
<li>RabbitMQ – Best Practices for Securing RabbitMQ: <a href="https://www.rabbitmq.com/blog/2019/07/30/best-practices-for-securing-rabbitmq/">https://www.rabbitmq.com/blog/2019/07/30/best-practices-for-securing-rabbitmq/</a></li><br />
</ul><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-32718 | RabbitMQ up to 3.8.16 Management UI cross site scripting (Nessus ID 212194)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in RabbitMQ up to 3.8.16. Affected by this issue is some unknown functionality of the component Management UI. The manipulation leads to basic cross site scripting.

This vulnerability is handled as CVE-2021-32718. The attack ma...]]></description>
<link>https://tsecurity.de/de/2488581/sicherheitsluecken/cve-2021-32718-rabbitmq-up-to-3816-management-ui-cross-site-scripting-nessus-id-212194/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2488581/sicherheitsluecken/cve-2021-32718-rabbitmq-up-to-3816-management-ui-cross-site-scripting-nessus-id-212194/</guid>
<pubDate>Mon, 09 Dec 2024 21:51:19 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, has been found in <a href="https://vuldb.com/?product.rabbitmq">RabbitMQ up to 3.8.16</a>. Affected by this issue is some unknown functionality of the component <em>Management UI</em>. The manipulation leads to basic cross site scripting.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.177698">CVE-2021-32718</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: mistral-7b-instruct-v0.3@q8_0<br><br><p>Title: Sicherheitslücke in RabbitMQ Management UI (CVE-2021-32718): Ein IT Experte analysiert die XSS-Vulnerabilität und bietet Schutzmaßnahmen an</p><br />
<p>Abstract:<br /><br />
In diesem Fachartikel werden wir uns mit der Sicherheitslücke in RabbitMQ Management UI (CVE-2021-32718) befassen, die durch eine Cross Site Scripting (XSS)-Vulnerabilität verursacht wird. Wir bieten einen detaillierten Überblick über das Problem und geben Empfehlungen für den Schutz von RabbitMQ-Installationen an.</p><br />
<ol><br />
<li>Einführung</li><br />
</ol><br />
<p>RabbitMQ ist ein beliebtes Message Broker für AMQP, MQTT und STOMP. In der Version 3.8.16 und früherer hat die Management UI eine Cross Site Scripting (XSS)-Vulnerabilität (CVE-2021-32718) entwickelt, die es einem Angreifer erlaubt, Benutzerdaten zu stehlen oder das Verhalten des Nutzers zu manipulieren. Die Sicherheitslücke wurde von Pavan Kumar Sunkara und Sandeep Kumar Dharma discov-ered und wurde am 27. April 2021 bekannt gegeben. Diese Sicherheitslücke hat eine Priorität von &quot;kritisch&quot; und sollte sofort behoben werden.</p><br />
<ol start="2"><br />
<li>Technischer Hintergrund</li><br />
</ol><br />
<p>Die XSS-Vulnerabilität in der RabbitMQ Management UI wird durch das Fehlen eines Input Validations verursacht, was es einem Angreifer ermöglicht, malicious code in das HTML-Output des Webinterface zu injecten. Der Browser interpretiert dieses malicious code und führt es aus, was dazu führt, dass der Angreifer Benutzerdaten wie Cookies oder Sessionssteuerungskennwörter abgreifen kann. Diese Vulnerabilität kann auch verwendet werden, um das Verhalten des Nutzers zu manipulieren und ihn zu verleiten, auf falsche Links oder Seiten zu klicken, was dazu führt, dass er auf eine Phishing-Website gelangt. Die Sicherheitslücke ist anfällig für Angriffe über das Internet und macht RabbitMQ Installationen, die direkt dem Internet zugänglich sind, besonders gefährdet.</p><br />
<ol start="3"><br />
<li>Auswirkungen der Sicherheitslücke</li><br />
</ol><br />
<p>Diese Sicherheitslücke kann dazu führen, dass Benutzerdaten gestohlen werden können oder das Verhalten des Nutzers manipuliert wird. Dies kann dazu führen, dass Angreifer Zugriff auf die RabbitMQ-Installation erlangen und Informationen verfälschen, Löschvorgänge ausführen oder Daten abgreifen können. Diese Sicherheitslücke kann auch verwendet werden, um das Vertrauen der Benutzer in die RabbitMQ-Installation zu zerstören und zu verhindern, dass sie auf die Installation zugreifen.</p><br />
<ol start="4"><br />
<li>Schutzmaßnahmen</li><br />
</ol><br />
<p>Um die Sicherheitslücke zu beheben, sollten RabbitMQ-Benutzer sofort auf die Version 3.8.17 oder eine höhere Version aktualisieren. Diese Version enthält die entsprechenden Patches und bietet den Schutz gegen die XSS-Vulnerabilität. Wenn Sie sich nicht sicher sind, ob Ihre RabbitMQ-Installation betroffen ist, können Sie den Nessus-ID 212194 verwenden, um zu überprüfen, ob Ihre Installation die Sicherheitslücke hat. Wenn die Vulnerabilität gefunden wird, sollten Sie sofort mit der Behebung beginnen und Ihren Benutzern darüber informieren.</p><br />
<ol start="5"><br />
<li>Zusammenfassung</li><br />
</ol><br />
<p>In diesem Fachartikel haben wir uns mit der Sicherheitslücke in RabbitMQ Management UI (CVE-2021-32718) befassen, die durch eine Cross Site Scripting (XSS)-Vulnerabilität verursacht wird. Wir haben einen detaillierten Überblick über das Problem gegeben und geben Empfehlungen für den Schutz von RabbitMQ-Installationen an. Um die Sicherheitslücke zu beheben, sollten RabbitMQ-Benutzer sofort auf die Version 3.8.17 oder eine höhere Version aktualisieren und sicherstellen, dass Ihre Benutzer darüber informiert werden, um das Risiko zu minimieren.</p><br />
<p>Referenz:\</p><br />
<ul><br />
<li>CVE-2021-32718: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32718</li><br />
<li>RabbitMQ Security Advisory: https://www.rabbitmq.com/announcements/security-advisory-rabbitmq-management-ui-xss-vulnerability.html</li><br />
<li>Nessus ID 212194: https://www.tenable.com/plugins/nessus/87031</li><br />
</ul><br />
<p>Auch interessant:\</p><br />
<ul><br />
<li>Cross Site Scripting (XSS): https://de.wikipedia.org/wiki/Cross-Site_Scripting</li><br />
<li>RabbitMQ: https://www.rabbitmq.com/</li><br />
</ul><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-7143-1: RabbitMQ Server vulnerabilities]]></title>
<description><![CDATA[Christian Rellmann discovered that RabbitMQ Server did not properly
sanitize user input when adding a new user via the management UI. An
attacker could possibly use this issue to perform cross site scripting and
obtain sensitive information. (CVE-2021-32718)

Fahimhusain Raydurg discovered that R...]]></description>
<link>https://tsecurity.de/de/2488137/unix-server/usn-7143-1-rabbitmq-server-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2488137/unix-server/usn-7143-1-rabbitmq-server-vulnerabilities/</guid>
<pubDate>Mon, 09 Dec 2024 17:18:44 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Christian Rellmann discovered that RabbitMQ Server did not properly
sanitize user input when adding a new user via the management UI. An
attacker could possibly use this issue to perform cross site scripting and
obtain sensitive information. (CVE-2021-32718)

Fahimhusain Raydurg discovered that RabbitMQ Server did not properly
sanitize user input when using the federation management plugin. An
attacker could possibly use this issue to perform cross site scripting and
obtain sensitive information. (CVE-2021-32719)]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-51988 | RabbitMQ Server access control]]></title>
<description><![CDATA[A vulnerability was found in RabbitMQ Server. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.

This vulnerability is known as CVE-2024-51988. The attack can be launched remotely. There is no exploit ...]]></description>
<link>https://tsecurity.de/de/2429718/sicherheitsluecken/cve-2024-51988-rabbitmq-server-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2429718/sicherheitsluecken/cve-2024-51988-rabbitmq-server-access-control/</guid>
<pubDate>Thu, 07 Nov 2024 15:22:16 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.rabbitmq:server">RabbitMQ Server</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.283363">CVE-2024-51988</a>. The attack can be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Broadcom launches VMware Tanzu Data Services]]></title>
<description><![CDATA[Broadcom on Tuesday released VMware Tanzu Data Services, a new “advanced service” for VMware Cloud Foundation (VCF), at VMware Explore Barcelona.



According to a release, the new offerings will be delivered through the private cloud, and provide the following built-in data management services:
...]]></description>
<link>https://tsecurity.de/de/2424814/it-security-nachrichten/broadcom-launches-vmware-tanzu-data-services/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2424814/it-security-nachrichten/broadcom-launches-vmware-tanzu-data-services/</guid>
<pubDate>Tue, 05 Nov 2024 09:18:21 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Broadcom on Tuesday released VMware Tanzu Data Services, a new “advanced service” for VMware Cloud Foundation (VCF), at VMware Explore Barcelona.</p>



<p>According to a release, the new offerings will be delivered through the private cloud, and provide the following built-in data management services:</p>



<ul class="wp-block-list">
<li>VMware Tanzu for Postgres: “A high performance, relational, transactional database platform that also includes PGvector for GenAI use cases.”</li>



<li>VMware Tanzu for MySQL: “The classic web application backend that optimizes transactional data handling for cloud native environments.”</li>



<li>VMware Tanzu RabbitMQ: “Secure, real-time message queuing, routing, and streaming for distributed systems, supporting microservices and event-driven architectures.”</li>



<li>VMware Tanzu for Valkey: “Low-latency caching for high-demand applications, reducing strain on primary databases and ensuring fast data access.”</li>
</ul>



<p>“Supporting the proliferation of manually deployed data services on premises has introduced delays and risks to the enterprise,” the Broadcom release said.</p>



<p>These problems include the time it takes to provision new data services, such as in high availability and disaster recovery, where, Broadcom said, “it can take an enterprise a year or more to properly set up and tune a deployment architectures that includes high availability, disaster recovery and backups.” It also noted that there are issues keeping up with operating system and database patches on individual persistent database servers.</p>



<p>During a media and analyst pre-briefing held last week, Purnima Padmanabhan, GM of Broadcom’s Tanzu Division, said that when she talks to customers, “they ask me, from a developer perspective and from an app perspective, only one thing: ‘How can I get speed and velocity?’ The difference between low performers and high performers in the industry is huge. For low performers, it may take as much as six months to get the code, once they have written the code and business logic, into production, while for high performers, it might be only one to seven days. The entire goal of Tanzu is to help customers move up this velocity arc.”</p>



<p>The platform, she said, “allows customers to develop, operate, and optimize their applications at scale and make sure that this is at scale across all environments, both private cloud and public clouds.”</p>



<p>For admins who are responsible for delivering data services on private cloud, the release said that benefits of the new services include simplified lifecycle management, enhanced security and compliance, experts on-call, and built-in configurations for “high availability, multi data center replication and backup.”</p>



<p>Asked for his reaction to the launch, John Annand, practice lead at Info-Tech Research Group, said, “there is a fun contrast in VMware by Broadcom these days. On the one hand, you have an amazingly ambitious <a href="https://www.networkworld.com/article/3499159/broadcoms-vision-for-vmware-highlights-private-clouds-private-ai.html">call to action</a> from [Broadcom CEO] Hock Tan, not just for enterprise adoption of private cloud, but also private AI — complex and complicated technologies with a plethora of nerd knobs for the enterprise to configure (or misconfigure). But VMware promises to make that easy and accessible for the average enterprise IT admin.”</p>



<p>Now, he said, “they announce Tanzu Data Services — is it going to be a similarly wide reaching and infinitely customizable and tweakable offering? No —  two database types, a message queue, and a caching engine. Is it comprehensive? Certainly not. Is it enough to play in their target market? I would have to say yes.”</p>



<p> According to Annand, “VMware by Broadcom is not looking to capture the advanced data sciences market with this offering, just like Tanzu is not the software development platform for bleeding edge dev shops. Their sweet spot is enterprise business leaders with a desire for control who are in tension with hipster dev teams who want to move fast and break things. PostgreSQL and MySQL are perfectly fine relational databases (though you would wonder why not MariaDB), RabbitMQ is great, and Valkey is fine.”</p>



<p>All in all, he said, it is a “complete set of tools (though not perhaps the ones every individual admin/engineer would have picked) for an MVP [minimum viable product] data service. Add that to the SDLC [software development lifecycle] and workload placement services of Tanzu, along with the GPU and model management from VMWare Private AI, and risk adverse management can now check the box they have given the dev teams [the tools that] will accomplish the job.”</p>



<p>Annand added, “there is an old adage that the hallmark of a good compromise is that you have satisfied no one. Tanzu Data Services should do at least a little better than that low bar. Does it compete toe to toe with the myriad of options available in public cloud data service platforms? Not at all.”</p>



<p>But there is, he said, “real value in what they offer (end to manual patching, architectural confusions, backups, availability, open source BOM [bill of materials] vulnerabilities, and more); the only question that remains is how much Hock Tan will be charging the enterprise customer to unlock that value.”</p>



<p>Naveen Chhabra, principal analyst at Forrester Research, said the “idea here (at the launch) is that infrastructure vendors need to certify their stack for the apps (including databases) that live higher up in the stack. VMware would prioritize these apps based on client interest and demand. Tanzu is not a service, it is a product, and the major competitors are Red Hat, Microsoft Azure, GCP [Google Cloud Platform], AWS [Amazon Web Services] and Suse.”</p>



<p>Check out more VMware Explore news on <a href="https://www.networkworld.com/article/3489093/vmware-explore-news-and-insights.html">our microsite</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Found this WSL six months later]]></title>
<description><![CDATA[The background story: I was working on a school's group assignment and one groupmate could not install pip on his wsl. Every time we tried to run the installation, it encountered a RabbitMQ error. I tried to replicate the problem on my laptop but failed. It was a distribution with the app logo of...]]></description>
<link>https://tsecurity.de/de/2383205/linux-tipps/found-this-wsl-six-months-later/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2383205/linux-tipps/found-this-wsl-six-months-later/</guid>
<pubDate>Sun, 13 Oct 2024 11:06:42 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>The background story: I was working on a school's group assignment and one groupmate could not install pip on his wsl. Every time we tried to run the installation, it encountered a RabbitMQ error. I tried to replicate the problem on my laptop but failed. It was a distribution with the app logo of a blue penguin head with this problem. I tried to find this online through all search engines that I knew and no results.</p> <p>Half of a year later (today), I turned on my laptop, clicked the start menu, and found this:</p> <p><a href="https://preview.redd.it/8c1wgoofohud1.png?width=1125&amp;format=png&amp;auto=webp&amp;s=884c7bd72096ffdd9f69a7a1964f115b140d885d">https://preview.redd.it/8c1wgoofohud1.png?width=1125&amp;format=png&amp;auto=webp&amp;s=884c7bd72096ffdd9f69a7a1964f115b140d885d</a></p> <p>I have no idea what happened. Haven't used WSL much over the past six months and it showed up as my recent.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Educational_Farm999"> /u/Educational_Farm999 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1g2llni/found_this_wsl_six_months_later/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1g2llni/found_this_wsl_six_months_later/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-26512 | Apache EventMesh up to 1.8.0 rabbitmq-connector Plugin deserialization]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Apache EventMesh up to 1.8.0. This issue affects some unknown processing of the component rabbitmq-connector Plugin. The manipulation leads to deserialization.

The identification of this vulnerability is CVE-2023-26512. The att...]]></description>
<link>https://tsecurity.de/de/2365311/sicherheitsluecken/cve-2023-26512-apache-eventmesh-up-to-180-rabbitmq-connector-plugin-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2365311/sicherheitsluecken/cve-2023-26512-apache-eventmesh-up-to-180-rabbitmq-connector-plugin-deserialization/</guid>
<pubDate>Wed, 02 Oct 2024 22:22:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.apache:eventmesh">Apache EventMesh up to 1.8.0</a>. This issue affects some unknown processing of the component <em>rabbitmq-connector Plugin</em>. The manipulation leads to deserialization.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.234227">CVE-2023-26512</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-28990 | SolarWinds Access Rights Manager up to 2024.3 RabbitMQ Management Console hard-coded credentials]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in SolarWinds Access Rights Manager up to 2024.3. Affected is an unknown function of the component RabbitMQ Management Console. The manipulation leads to hard-coded credentials.

This vulnerability is traded as CVE-2024-28990. The attac...]]></description>
<link>https://tsecurity.de/de/2329812/sicherheitsluecken/cve-2024-28990-solarwinds-access-rights-manager-up-to-20243-rabbitmq-management-console-hard-coded-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2329812/sicherheitsluecken/cve-2024-28990-solarwinds-access-rights-manager-up-to-20243-rabbitmq-management-console-hard-coded-credentials/</guid>
<pubDate>Thu, 12 Sep 2024 16:53:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.solarwinds:access_rights_manager">SolarWinds Access Rights Manager up to 2024.3</a>. Affected is an unknown function of the component <em>RabbitMQ Management Console</em>. The manipulation leads to hard-coded credentials.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.277284">CVE-2024-28990</a>. The attack needs to be approached within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Siemens SINEC NMS]]></title>
<description><![CDATA[As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services |...]]></description>
<link>https://tsecurity.de/de/2280123/it-security-nachrichten/siemens-sinec-nms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2280123/it-security-nachrichten/siemens-sinec-nms/</guid>
<pubDate>Thu, 15 Aug 2024 16:51:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see <a class="ext" href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" target="_blank" title="https://new.siemens.com/global/en/products/services/cert.html#securitypublications" rel="noreferrer noopener">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a> <br><br><a href="https://github.com/cisagov/CSAF" target="_blank"><strong>View CSAF</strong></a></p>
<h2>1. EXECUTIVE SUMMARY</h2>
<ul>
<li><strong>CVSS v4 9.4</strong></li>
<li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li>
<li><strong>Vendor</strong>: Siemens</li>
<li><strong>Equipment</strong>: SINEC NMS</li>
<li><strong>Vulnerabilities</strong>: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations within the Bounds of a Memory Buffer, Uncontrolled Resource Consumption, Out-of-bounds Read, Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion'), Privilege Dropping / Lowering Errors, Allocation of Resources Without Limits or Throttling, Execution with Unnecessary Privileges, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Authorization</li>
</ul>
<h2>2. RISK EVALUATION</h2>
<p>Successful exploitation of these vulnerabilities could allow an attacker to affect confidentiality, integrity, and availability of affected devices</p>
<h2>3. TECHNICAL DETAILS</h2>
<h3>3.1 AFFECTED PRODUCTS</h3>
<p>The following products of Siemens, are affected:</p>
<ul>
<li>SINEC NMS: versions prior to V3.0</li>
</ul>
<h3>3.2 Vulnerability Overview</h3>
<h4><strong>3.2.1 </strong><a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank"><strong>USE AFTER FREE CWE-416</strong></a></h4>
<p>A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-4611" target="_blank">CVE-2023-4611</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H</a>).</p>
<h4><strong>3.2.2 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5868" target="_blank">CVE-2023-5868</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a>).</p>
<h4><strong>3.2.3 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5869" target="_blank">CVE-2023-5869</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<h4><strong>3.2.4 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5870" target="_blank">CVE-2023-5870</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.4 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.5 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-6378" target="_blank">CVE-2023-6378</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.6 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-6481" target="_blank">CVE-2023-6481</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.7 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.57.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31122" target="_blank">CVE-2023-31122</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.8 </strong><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank"><strong>DESERIALIZATION OF UNTRUSTED DATA CWE-502</strong></a></h4>
<p>In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized. Specifically, an application is vulnerable if * the SimpleMessageConverter or SerializerMessageConverter is used * the user does not configure allowed list patterns * untrusted message originators gain permissions to write messages to the RabbitMQ broker to send malicious content.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-34050" target="_blank">CVE-2023-34050</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.0 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H</a>).</p>
<h4><strong>3.2.9 </strong><a href="https://cwe.mitre.org/data/definitions/119.html" target="_blank"><strong>IMPROPER RESTRICTION OF OPERATIONS WITHIN THE BOUNDS OF A MEMORY BUFFER CWE-119</strong></a></h4>
<p>Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the product does not support the legacy SAX1 interface with custom callbacks; there is a crash even without crafted input.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-39615" target="_blank">CVE-2023-39615</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.10 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-42794" target="_blank">CVE-2023-42794</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.11 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-42795" target="_blank">CVE-2023-42795</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a>).</p>
<h4><strong>3.2.12 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern. This has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.57. Users are recommended to upgrade to version 2.4.58, which fixes the issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-43622" target="_blank">CVE-2023-43622</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.13 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4>
<p>The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-44487" target="_blank">CVE-2023-44487</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-44487" target="_blank">CVE-2023-44487</a>. A base score of 8.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a>).</p>
<h4><strong>3.2.14 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-45648" target="_blank">CVE-2023-45648</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a>).</p>
<h4><strong>3.2.15 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close, all resources were reclaimed, but the process might run out of memory before that. This was found by the reporter during testing of CVE-2023-44487 (HTTP/2 Rapid Reset Exploit) with their own test client. During "normal" HTTP/2 use, the probability to hit this bug is very low. The kept memory would not become noticeable before the connection closes or times out. Users are recommended to upgrade to version 2.4.58, which fixes the issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-45802" target="_blank">CVE-2023-45802</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.16 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4>
<p>The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. maxBodyLebgth was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from DoS attacks from RabbitMQ Java client which will ultimately exhaust the memory of the consumer. This vulnerability was patched in version 5.18.0.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46120" target="_blank">CVE-2023-46120</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.9 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.17 </strong><a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank"><strong>OUT-OF-BOUNDS READ CWE-125</strong></a></h4>
<p>The affected applications contain an out of bounds read vulnerability. This could allow an attacker to cause a Blue Screen of Death (BSOD) crash of the underlying Windows kernel.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46280" target="_blank">CVE-2023-46280</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46280" target="_blank">CVE-2023-46280</a>. A base score of 8.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H" target="_blank">CVSS4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H</a>).</p>
<h4><strong>3.2.18 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46589" target="_blank">CVE-2023-46589</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p>
<h4><strong>3.2.19 </strong><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank"><strong>UNCONTROLLED RESOURCE CONSUMPTION CWE-400</strong></a></h4>
<p>libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52425" target="_blank">CVE-2023-52425</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.20 </strong><a href="https://cwe.mitre.org/data/definitions/776.html" target="_blank"><strong>IMPROPER RESTRICTION OF RECURSIVE ENTITY REFERENCES IN DTDS ('XML ENTITY EXPANSION') CWE-776</strong></a></h4>
<p>libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52426" target="_blank">CVE-2023-52426</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.21 </strong><a href="https://cwe.mitre.org/data/definitions/271.html" target="_blank"><strong>PRIVILEGE DROPPING / LOWERING ERRORS CWE-271</strong></a></h4>
<p>Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. Versions before PostgreSQL 16.2, 15.6, 14.11, 13.14, and 12.18 are affected.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-0985" target="_blank">CVE-2024-0985</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.0 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a>).</p>
<h4><strong>3.2.22 </strong><a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank"><strong>USE AFTER FREE CWE-416</strong></a></h4>
<p>An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-25062" target="_blank">CVE-2024-25062</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.23 </strong><a href="https://cwe.mitre.org/data/definitions/770.html" target="_blank"><strong>ALLOCATION OF RESOURCES WITHOUT LIMITS OR THROTTLING CWE-770</strong></a></h4>
<p>nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-28182" target="_blank">CVE-2024-28182</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p>
<h4><strong>3.2.24 </strong><a href="https://cwe.mitre.org/data/definitions/776.html" target="_blank"><strong>IMPROPER RESTRICTION OF RECURSIVE ENTITY REFERENCES IN DTDS ('XML ENTITY EXPANSION') CWE-776</strong></a></h4>
<p>libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-28757" target="_blank">CVE-2024-28757</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<h4><strong>3.2.25 </strong><a href="https://cwe.mitre.org/data/definitions/250.html" target="_blank"><strong>EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250</strong></a></h4>
<p>The affected application executes a subset of its services as NT AUTHORITY/SYSTEM. This could allow a local attacker to execute operating system commands with elevated privileges.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-36398" target="_blank">CVE-2024-36398</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-36398" target="_blank">CVE-2024-36398</a>. A base score of 8.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p>
<h4><strong>3.2.26 </strong><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank"><strong>IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</strong></a></h4>
<p>The importCertificate function of the SINEC NMS Control web application contains a path traversal vulnerability. This could allow an authenticated attacker it to delete arbitrary certificate files on the drive SINEC NMS is installed on.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41938" target="_blank">CVE-2024-41938</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41938" target="_blank">CVE-2024-41938</a>. A base score of 5.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L</a>).</p>
<h4><strong>3.2.27 </strong><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank"><strong>INCORRECT AUTHORIZATION CWE-863</strong></a></h4>
<p>The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and elevate their privileges on the application.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41939" target="_blank">CVE-2024-41939</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41939" target="_blank">CVE-2024-41939</a>. A base score of 8.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a>).</p>
<h4><strong>3.2.28 </strong><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><strong>IMPROPER INPUT VALIDATION CWE-20</strong></a></h4>
<p>The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privileges.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41940" target="_blank">CVE-2024-41940</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41940" target="_blank">CVE-2024-41940</a>. A base score of 9.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a>).</p>
<h4><strong>3.2.29 </strong><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank"><strong>INCORRECT AUTHORIZATION CWE-863</strong></a></h4>
<p>The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and modify settings in the application without authorization.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41941" target="_blank">CVE-2024-41941</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been assigned; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</a>).</p>
<p>A CVSS v4 score has also been calculated for <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41941" target="_blank">CVE-2024-41941</a>. A base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" target="_blank">CVSS4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</a>).</p>
<h3>3.3 BACKGROUND</h3>
<ul>
<li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li>
<li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li>
<li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li>
</ul>
<h3>3.4 RESEARCHER</h3>
<p>Siemens reported these vulnerabilities to CISA.</p>
<h2>4. MITIGATIONS</h2>
<p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<ul>
<li>SINEC NMS: Update to V3.0 or <a href="https://support.industry.siemens.com/cs/ww/en/view/109973059/" target="_blank">later version</a></li>
</ul>
<p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p>
<p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a></p>
<p>For more information see the associated Siemens security advisory SSA-784301 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-784301.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-784301.json" target="_blank">CSAF</a>.</p>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p>
<ul>
<li>Minimize network exposure for all control system devices and/or systems, ensuring they are <a href="https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01" target="_blank">not accessible from the internet</a>.</li>
<li>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</li>
<li>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</li>
</ul>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<ul>
<li>Do not click web links or open attachments in unsolicited email messages.</li>
<li>Refer to <a href="https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf" target="_blank">Recognizing and Avoiding Email Scams</a> for more information on avoiding email scams.</li>
<li>Refer to <a href="https://www.cisa.gov/uscert/ncas/tips/ST04-014" target="_blank">Avoiding Social Engineering and Phishing Attacks</a> for more information on social engineering attacks.</li>
</ul>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<h2>5. UPDATE HISTORY</h2>
<ul>
<li>August 15, 2024: Initial Publication</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerability Summary for the Week of May 13, 2024]]></title>
<description><![CDATA[High Vulnerabilities



PrimaryVendor -- Product
Description
Published
CVSS Score
Source & Patch Info




8theme--XStore Core 
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
2024-05-17
9.8
CVE-2...]]></description>
<link>https://tsecurity.de/de/2141243/it-security-nachrichten/vulnerability-summary-for-the-week-of-may-13-2024/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2141243/it-security-nachrichten/vulnerability-summary-for-the-week-of-may-13-2024/</guid>
<pubDate>Fri, 10 May 2024 09:09:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<h2>High Vulnerabilities</h2>
<table summary="High Vulnerabilities" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>8theme--XStore Core<br> </td>
<td>Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33552&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33552" target="_blank">CVE-2024-33552</a><br><a href="https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>8theme--XStore Core<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33556&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33556" target="_blank">CVE-2024-33556</a><br><a href="https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-limited-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AA-Team--WZone<br> </td>
<td>Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33549&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33549" target="_blank">CVE-2024-33549</a><br><a href="https://patchstack.com/database/vulnerability/woozone/wordpress-wzone-plugin-14-0-10-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ABB--RobotWare 6<br> </td>
<td>An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitrary code.  The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is processed by the system. Below are reported vulnerabilities in the Robot Ware versions. * IRC5- RobotWare 6 &lt; 6.15.06 except 6.10.10, and 6.13.07 * OmniCore- RobotWare 7 &lt; 7.14</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1913&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1913" target="_blank">CVE-2024-1913</a><br><a href="https://search.abb.com/library/Download.aspx?DocumentID=SI20330&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>AROX SOLUTION--School ERP Pro+Responsive<br> </td>
<td>Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4824&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4824" target="_blank">CVE-2024-4824</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-school-erp-proresponsive-arox-solution" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Abdul Hakeem--Build App Online<br> </td>
<td>Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51479&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51479" target="_blank">CVE-2023-51479</a><br><a href="https://patchstack.com/database/vulnerability/build-app-online/wordpress-build-app-online-plugin-1-0-19-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30284&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30284" target="_blank">CVE-2024-30284</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30310&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30310" target="_blank">CVE-2024-30310</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34094&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34094" target="_blank">CVE-2024-34094</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34095&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34095" target="_blank">CVE-2024-34095</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34096&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34096" target="_blank">CVE-2024-34096</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34097&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34097" target="_blank">CVE-2024-34097</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34098&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34098" target="_blank">CVE-2024-34098</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34099&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34099" target="_blank">CVE-2024-34099</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34100&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34100" target="_blank">CVE-2024-34100</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Aero Desktop<br> </td>
<td>Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30275&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30275" target="_blank">CVE-2024-30275</a><br><a href="https://helpx.adobe.com/security/products/aero/apsb24-33.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30288&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30288" target="_blank">CVE-2024-30288</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30289&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30289" target="_blank">CVE-2024-30289</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30290&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30290" target="_blank">CVE-2024-30290</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30291&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30291" target="_blank">CVE-2024-30291</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30292&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30292" target="_blank">CVE-2024-30292</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30282&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30282" target="_blank">CVE-2024-30282</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30293&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30293" target="_blank">CVE-2024-30293</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30294&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30294" target="_blank">CVE-2024-30294</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30295&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30295" target="_blank">CVE-2024-30295</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30296&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30296" target="_blank">CVE-2024-30296</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30297&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30297" target="_blank">CVE-2024-30297</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Dreamweaver Desktop<br> </td>
<td>Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does require user interaction.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30314&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">9.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30314" target="_blank">CVE-2024-30314</a><br><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb24-39.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Illustrator<br> </td>
<td>Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20791&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20791" target="_blank">CVE-2024-20791</a><br><a href="https://helpx.adobe.com/security/products/illustrator/apsb24-30.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Illustrator<br> </td>
<td>Illustrator versions 28.4, 27.9.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20792&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20792" target="_blank">CVE-2024-20792</a><br><a href="https://helpx.adobe.com/security/products/illustrator/apsb24-30.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30274&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30274" target="_blank">CVE-2024-30274</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30307&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30307" target="_blank">CVE-2024-30307</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Agentejo--Cockpit CMS<br> </td>
<td>A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in '/media/api' parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4825&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4825" target="_blank">CVE-2024-4825</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-upload-file-dangerous-type-vulnerability-cockpit-cms" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Apache Friends--XAMPP<br> </td>
<td>Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5055&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5055" target="_blank">CVE-2024-5055</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/vulnerability-uncontrolled-resource-consumption-xampp" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Asaancart--Simple PHP Shopping Cart<br> </td>
<td>SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id parameter in the category.php file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4826&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4826" target="_blank">CVE-2024-4826</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-simple-php-shopping-cart" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Astoundify--Simple Registration for WooCommerce<br> </td>
<td>Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalation.This issue affects Simple Registration for WooCommerce: from n/a through 1.5.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32511&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32511" target="_blank">CVE-2024-32511</a><br><a href="https://patchstack.com/database/vulnerability/woocommerce-simple-registration/wordpress-simple-registration-for-woocommerce-plugin-1-5-6-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Averta--Phlox Portfolio<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Portfolio allows PHP Local File Inclusion.This issue affects Phlox Portfolio: from n/a through 2.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38399&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38399" target="_blank">CVE-2023-38399</a><br><a href="https://patchstack.com/database/vulnerability/auxin-portfolio/wordpress-phlox-portfolio-plugin-2-3-1-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Averta--Phlox Shop<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Shop allows PHP Local File Inclusion.This issue affects Phlox Shop: from n/a through 2.0.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-39163&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-39163" target="_blank">CVE-2023-39163</a><br><a href="https://patchstack.com/database/vulnerability/auxin-shop/wordpress-phlox-shop-plugin-2-0-0-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>B&amp;R Industrial Automation--Automation Studio<br> </td>
<td>Improper DLL loading algorithms in B&amp;R Automation Studio may allow an authenticated local attacker to execute code with elevated privileges. This issue affects Automation Studio versions before 4.12.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2021-22280&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-22280" target="_blank">CVE-2021-22280</a><br><a href="https://www.br-automation.com/fileadmin/2021-10_DLL_Hijacking_Vulnerability_in_Automation_Studio-7dd34511.pdf" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>B&amp;R Industrial Automation--Scene Viewer<br> </td>
<td>An authenticated local attacker who successfully exploited this vulnerability could insert and run arbitrary code using legitimate B&amp;R software's. An Uncontrolled Search Path Element vulnerability in B&amp;R Industrial Automation Scene Viewer, B&amp;R Industrial  Automation Runtime, B&amp;R Industrial Automation mapp Vision, B&amp;R Industrial Automation mapp View, B&amp;R Industrial Automation mapp Cockpit, B&amp;R Industrial Automation mapp Safety, B&amp;R Industrial Automation VC4 could allow an authenticated local attacker to execute malicious code by placing specially crafted files in the loading search path. This issue affects Scene Viewer: before 4.4.0; Automation Runtime: before J4.93; mapp Vision: before 5.26.1; mapp View: before 5.24.2; mapp Cockpit: before 5.24.2; mapp Safety: before 5.24.2; VC4: before 4.73.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2637&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2637" target="_blank">CVE-2024-2637</a><br><a href="https://www.br-automation.com/fileadmin/SA24P005_Insecure_Loading_of_Code-c7d9e49c.pdf" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>BoldGrid--Total Upkeep<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24869&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24869" target="_blank">CVE-2024-24869</a><br><a href="https://patchstack.com/database/vulnerability/boldgrid-backup/wordpress-total-upkeep-plugin-1-15-8-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Booking Ultra Pro--Booking Ultra Pro<br> </td>
<td>Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32960&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32960" target="_blank">CVE-2024-32960</a><br><a href="https://patchstack.com/database/vulnerability/booking-ultra-pro/wordpress-booking-ultra-pro-plugin-1-1-12-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--ConvertPlus<br> </td>
<td>The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4838&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4838" target="_blank">CVE-2024-4838</a><br><a href="https://www.convertplug.com/plus/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/16f5a104-dce0-4249-91b9-67f99cce16d3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Spectra Pro<br> </td>
<td>The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin allowing lower-privileged users to create registration forms and set the default role to administrator This makes it possible for authenticated attackers, with author-level access and above, to create administrator-level accounts.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3828&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3828" target="_blank">CVE-2024-3828</a><br><a href="https://wpspectra.com/whats-new/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e23e7d66-4b57-4feb-bf77-46238bc6ce7c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for Beaver Builder<br> </td>
<td>Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51398&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51398" target="_blank">CVE-2023-51398</a><br><a href="https://patchstack.com/database/vulnerability/bb-ultimate-addon/wordpress-ultimate-addons-for-beaver-builder-premium-plugin-1-35-14-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for Elementor<br> </td>
<td>Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.20.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50890&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50890" target="_blank">CVE-2023-50890</a><br><a href="https://patchstack.com/database/vulnerability/ultimate-elementor/wordpress-ultimate-addons-for-elementor-plugin-1-36-20-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for WPBakery Page Builder<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.14.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46205&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46205" target="_blank">CVE-2023-46205</a><br><a href="https://patchstack.com/database/vulnerability/ultimate_vc_addons/wordpress-ultimate-addons-for-wpbakery-page-builder-plugin-3-19-14-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Breakdance--Breakdance<br> </td>
<td>The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to edit this data via UI. As a result they can escalate their privileges or execute arbitrary code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4605&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4605" target="_blank">CVE-2024-4605</a><br><a href="https://breakdance.com/breakdance-1-7-2-now-available-security-update/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/095b23b7-71ab-41eb-b666-73df2e1a7eb4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>By Averta--Shortcodes and extra features for Phlox theme<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in By Averta Shortcodes and extra features for Phlox theme allows PHP Local File Inclusion.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.14.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37888&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37888" target="_blank">CVE-2023-37888</a><br><a href="https://patchstack.com/database/vulnerability/auxin-elements/wordpress-phlox-core-elements-plugin-2-14-0-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$poller_id` used as part of the command execution is sourced from `$_SERVER['argv']`, which can be controlled by URL when `register_argc_argv` option of PHP is `On`. And this option is `On` by default in many environments such as the main PHP Docker image for PHP. Commit 53e8014d1f082034e0646edc6286cde3800c683d contains a patch for the issue, but this commit was reverted in commit 99633903cad0de5ace636249de16f77e57a3c8fc.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29895&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29895" target="_blank">CVE-2024-29895</a><br><a href="https://github.com/Cacti/cacti/blob/501712998589763d411a68d35e3cda98fd9cfd18/cmd_realtime.php#L119" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/53e8014d1f082034e0646edc6286cde3800c683d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/99633903cad0de5ace636249de16f77e57a3c8fc" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-cr28-x256-xf5m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The vulnerability is located within the `import_package()` function defined into the `/lib/import.php` script. The function blindly trusts the filename and file content provided within the XML data, and writes such files into the Cacti base path (or even outside, since path traversal sequences are not filtered). This can be exploited to write or overwrite arbitrary files on the web server, leading to execution of arbitrary PHP code or other security impacts. Version 1.2.27 contains a patch for this issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25641&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25641" target="_blank">CVE-2024-25641</a><br><a href="https://github.com/Cacti/cacti/commit/eff35b0ff26cc27c82d7880469ed6d5e3bef6210" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-7cmj-g5qc-pj88" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In `compat_password_verify`, `password_verify` is called if there is it, else use `md5`. `password_verify` and `password_hash` are supported on PHP &lt; 5.5.0, following PHP manual. The vulnerability is in `compat_password_verify`. Md5-hashed user input is compared with correct password in database by `$md5 == $hash`. It is a loose comparison, not `===`. It is a type juggling vulnerability. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34340&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34340" target="_blank">CVE-2024-34340</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-37x7-mfjv-mm7m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code execution. In `api_automation.php` line 856, the `get_request_var('filter')` is being concatenated into the SQL statement without any sanitization. In `api_automation.php` line 717, The filter of `'filter'` is `FILTER_DEFAULT`, which means there is no filter for it. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31445" target="_blank">CVE-2024-31445</a><br><a href="https://github.com/Cacti/cacti/blob/501712998589763d411a68d35e3cda98fd9cfd18/lib/api_automation.php#L717" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/blob/501712998589763d411a68d35e3cda98fd9cfd18/lib/api_automation.php#L856" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/fd93c6e47651958b77c3bbe6a01fff695f81e886" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-vjph-r677-6pcc" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the `api_plugin_hook()` function in the `lib/plugin.php` file, which reads the plugin_hooks and plugin_config tables in database. The read data is directly used to concatenate the file path which is used for file inclusion. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31459&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31459" target="_blank">CVE-2024-31459</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-cx8g-hvq8-p2rv" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-gj3f-p326-gh8r" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27082&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27082" target="_blank">CVE-2024-27082</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-j868-7vjp-rp9h" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cerberus FTP Enterprise--Cerberus FTP Enterprise<br> </td>
<td>Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port 10001, attempts to process a large number of incomplete HTTP requests.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5052&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5052" target="_blank">CVE-2024-5052</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/resource-consumption-vulnerability-cerberus-ftp-enterprise" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Cisco--Cisco ConfD<br> </td>
<td>A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20326&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20326" target="_blank">CVE-2024-20326</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnfd-rwpesc-ZAOufyx8" target="_blank">ykramarz@cisco.com</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-rwpesc-qrQGnh3f" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco ConfD<br> </td>
<td>A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20389&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20389" target="_blank">CVE-2024-20389</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnfd-rwpesc-ZAOufyx8" target="_blank">ykramarz@cisco.com</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-rwpesc-qrQGnh3f" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Network Services Orchestrator<br> </td>
<td>A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability exists because a user-controlled search path is used to locate executable files. An attacker could exploit this vulnerability by configuring the application in a way that causes a malicious file to be executed. A successful exploit could allow the attacker to execute arbitrary code on an affected device as the root user. To exploit this vulnerability, the attacker would need valid credentials on an affected device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20366&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20366" target="_blank">CVE-2024-20366</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-hcc-priv-esc-OWBWCs5D" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>CodeRevolution--Demo My WordPress<br> </td>
<td>Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31290&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31290" target="_blank">CVE-2024-31290</a><br><a href="https://patchstack.com/database/vulnerability/demo-my-wordpress/wordpress-demo-my-wordpress-plugin-1-0-9-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Contemporary Control System--BASrouter BACnet BASRT-B<br> </td>
<td>A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Application Protocol Data Unit. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263890 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4791&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4791" target="_blank">CVE-2024-4791</a><br><a href="https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASER-B_APDU.pcapng" target="_blank">cna@vuldb.com</a><br><a href="https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASRT-B_2_CVE_apply.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263890" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263890" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.323630" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Copymatic--Copymatic AI Content Writer &amp; Generator<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic - AI Content Writer &amp; Generator.This issue affects Copymatic - AI Content Writer &amp; Generator: from n/a through 1.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31351&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31351" target="_blank">CVE-2024-31351</a><br><a href="https://patchstack.com/database/vulnerability/copymatic/wordpress-copymatic-plugin-1-6-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Crocoblock--JetEngine<br> </td>
<td>Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48757&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48757" target="_blank">CVE-2023-48757</a><br><a href="https://patchstack.com/database/vulnerability/jet-engine/wordpress-jetengine-plugin-3-2-4-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Crocoblock--JetFormBuilder<br> </td>
<td>Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37866&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37866" target="_blank">CVE-2023-37866</a><br><a href="https://patchstack.com/database/vulnerability/jetformbuilder/wordpress-jetformbuilder-plugin-3-0-8-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32735&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32735" target="_blank">CVE-2024-32735</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32736&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32736" target="_blank">CVE-2024-32736</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32737&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32737" target="_blank">CVE-2024-32737</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32738&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32738" target="_blank">CVE-2024-32738</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32739&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32739" target="_blank">CVE-2024-32739</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the testing or production server.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32047&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32047" target="_blank">CVE-2024-32047</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>Hard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32053&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32053" target="_blank">CVE-2024-32053</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33625&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33625" target="_blank">CVE-2024-33625</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34025&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34025" target="_blank">CVE-2024-34025</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31856&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31856" target="_blank">CVE-2024-31856</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33615&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33615" target="_blank">CVE-2024-33615</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the system and send malicious data.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31410&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31410" target="_blank">CVE-2024-31410</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CycloneDX--cyclonedx-javascript-library<br> </td>
<td>The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34345&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34345" target="_blank">CVE-2024-34345</a><br><a href="https://github.com/CycloneDX/cyclonedx-javascript-library/commit/5e5e1e0b9422f47d2de81c7c4064b803a01e7203" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CycloneDX/cyclonedx-javascript-library/pull/1063" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CycloneDX/cyclonedx-javascript-library/security/advisories/GHSA-38gf-rh2w-gmj7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Darren Cooney--Instant Images<br> </td>
<td>Improper Privilege Management vulnerability in Darren Cooney Instant Images allows Privilege Escalation.This issue affects Instant Images: from n/a through 6.1.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33569&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33569" target="_blank">CVE-2024-33569</a><br><a href="https://patchstack.com/database/vulnerability/instant-images/wordpress-instant-images-plugin-6-1-0-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Dell--CPG BIOS<br> </td>
<td>Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22429&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22429" target="_blank">CVE-2024-22429</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000221102/dsa-2024-020" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>DigiWin--EasyFlow .NET<br> </td>
<td>DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4893&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4893" target="_blank">CVE-2024-4893</a><br><a href="https://www.twcert.org.tw/en/cp-139-7801-67d07-2.html" target="_blank">twcert@cert.org.tw</a><br><a href="https://www.twcert.org.tw/tw/cp-132-7800-843f1-1.html" target="_blank">twcert@cert.org.tw</a></td>
</tr>
<tr>
<td>Elementor--Elementor Website Builder<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24934&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24934" target="_blank">CVE-2024-24934</a><br><a href="https://patchstack.com/database/vulnerability/elementor/wordpress-elementor-plugin-3-19-0-arbitrary-file-deletion-and-phar-deserialization-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>EnterpriseDB--EDB Postgres Advanced Server<br> </td>
<td>All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not otherwise have access.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4545&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4545" target="_blank">CVE-2024-4545</a><br><a href="https://www.enterprisedb.com/docs/epas/15/epas_rel_notes/" target="_blank">20be33e2-bf35-4d13-8fad-18bd2f3e3659</a><br><a href="https://www.enterprisedb.com/docs/epas/latest/epas_rel_notes/" target="_blank">20be33e2-bf35-4d13-8fad-18bd2f3e3659</a><br><a href="https://www.enterprisedb.com/docs/security/advisories/cve20244545/" target="_blank">20be33e2-bf35-4d13-8fad-18bd2f3e3659</a></td>
</tr>
<tr>
<td>EverPress--Mailster<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EverPress Mailster allows PHP Local File Inclusion.This issue affects Mailster: from n/a through 4.0.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32523&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32523" target="_blank">CVE-2024-32523</a><br><a href="https://patchstack.com/database/vulnerability/mailster/wordpress-mailster-plugin-4-0-6-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Favethemes--Houzez Login Register<br> </td>
<td>Improper Privilege Management vulnerability in favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-26009&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26009" target="_blank">CVE-2023-26009</a><br><a href="https://patchstack.com/database/vulnerability/houzez-login-register/wordpress-houzez-login-register-plugin-2-6-3-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Favethemes--Houzez<br> </td>
<td>Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 2.7.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-26540&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26540" target="_blank">CVE-2023-26540</a><br><a href="https://patchstack.com/database/vulnerability/houzez/wordpress-houzez-theme-2-7-1-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiOS<br> </td>
<td>A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46714" target="_blank">CVE-2023-46714</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-415" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiPortal<br> </td>
<td>A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23105&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23105" target="_blank">CVE-2024-23105</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-021" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiSandbox<br> </td>
<td>A client-side enforcement of server-side security in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31491&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31491" target="_blank">CVE-2024-31491</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-054" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiVoice<br> </td>
<td>An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40720&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40720" target="_blank">CVE-2023-40720</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-282" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Weak account password in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27107&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27107" target="_blank">CVE-2024-27107</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Elevation of privilege vulnerability in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27110&amp;vector=CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27110" target="_blank">CVE-2024-27110</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Insufficiently protected credentials in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27109&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27109" target="_blank">CVE-2024-27109</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>OS command injection vulnerabilities in GE HealthCare ultrasound devices</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1628&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1628" target="_blank">CVE-2024-1628</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1486&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1486" target="_blank">CVE-2024-1486</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>Path traversal vulnerability in "getAllFolderContents" function of Common Service Desktop, a GE HealthCare ultrasound device component</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1630&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1630" target="_blank">CVE-2024-1630</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>Ghost Foundation--Ghost<br> </td>
<td>Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34559&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34559" target="_blank">CVE-2024-34559</a><br><a href="https://patchstack.com/database/vulnerability/ghost/wordpress-ghost-plugin-1-4-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>GiveWP--GiveWP<br> </td>
<td>Improper Privilege Management vulnerability in GiveWP allows Privilege Escalation.This issue affects GiveWP: from n/a through 2.33.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41665&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41665" target="_blank">CVE-2023-41665</a><br><a href="https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-33-0-givewp-manager-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Glowlogix--WP Frontend Profile<br> </td>
<td>Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51483&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51483" target="_blank">CVE-2023-51483</a><br><a href="https://patchstack.com/database/vulnerability/wp-front-end-profile/wordpress-wp-frontend-profile-plugin-1-3-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>HCL Software--Commerce<br> </td>
<td>Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23576&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23576" target="_blank">CVE-2024-23576</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0112907" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>Hamid Alinia idehweb--Login with phone number<br> </td>
<td>Improper Privilege Management vulnerability in Hamid Alinia - idehweb Login with phone number allows Privilege Escalation.This issue affects Login with phone number: from n/a through 1.7.16.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32507&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32507" target="_blank">CVE-2024-32507</a><br><a href="https://patchstack.com/database/vulnerability/login-with-phone-number/wordpress-login-with-phone-number-plugin-1-7-16-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>HasThemes--HT Mega<br> </td>
<td>Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37999&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37999" target="_blank">CVE-2023-37999</a><br><a href="https://patchstack.com/database/vulnerability/ht-mega-for-elementor/wordpress-ht-mega-absolute-addons-for-elementor-plugin-2-2-0-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31466&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31466" target="_blank">CVE-2024-31466</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31467&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31467" target="_blank">CVE-2024-31467</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31468&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31468" target="_blank">CVE-2024-31468</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31469&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31469" target="_blank">CVE-2024-31469</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31470&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31470" target="_blank">CVE-2024-31470</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31471&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31471" target="_blank">CVE-2024-31471</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31472&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31472" target="_blank">CVE-2024-31472</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31473&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31473" target="_blank">CVE-2024-31473</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31474&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31474" target="_blank">CVE-2024-31474</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31475&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31475" target="_blank">CVE-2024-31475</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31476" target="_blank">CVE-2024-31476</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31477&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31477" target="_blank">CVE-2024-31477</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32997&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32997" target="_blank">CVE-2024-32997</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52719&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52719" target="_blank">CVE-2023-52719</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32991&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32991" target="_blank">CVE-2024-32991</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32992&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32992" target="_blank">CVE-2024-32992</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>IBM--AIX<br> </td>
<td>IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27260&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27260" target="_blank">CVE-2024-27260</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/283985" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7152543" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47709&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47709" target="_blank">CVE-2023-47709</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271524" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150840" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47712&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47712" target="_blank">CVE-2023-47712</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271524" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150840" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--i<br> </td>
<td>IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31879&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31879" target="_blank">CVE-2024-31879</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/287539" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7154380" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IOSS--WP MLM Unilevel<br> </td>
<td>Improper Privilege Management vulnerability in IOSS WP MLM Unilevel allows Privilege Escalation.This issue affects WP MLM Unilevel: from n/a through 4.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51476" target="_blank">CVE-2023-51476</a><br><a href="https://patchstack.com/database/vulnerability/wp-mlm/wordpress-wp-mlm-unilevel-plugin-4-0-unauthenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>InstaWP Team--InstaWP Connect<br> </td>
<td>Improper Privilege Management vulnerability in InstaWP Team InstaWP Connect allows Privilege Escalation.This issue affects InstaWP Connect: from n/a through 0.1.0.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22145&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22145" target="_blank">CVE-2024-22145</a><br><a href="https://patchstack.com/database/vulnerability/instawp-connect/wordpress-instawp-connect-plugin-0-1-0-8-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>J.N. Breetvelt a.k.a. OpaJaap--WP Photo Album Plus<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31377&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31377" target="_blank">CVE-2024-31377</a><br><a href="https://patchstack.com/database/vulnerability/wp-photo-album-plus/wordpress-wp-photo-album-plus-plugin-8-7-01-001-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JR King/Eran Schoellhorn--WP Masquerade<br> </td>
<td>Improper Privilege Management vulnerability in JR King/Eran Schoellhorn WP Masquerade allows Privilege Escalation.This issue affects WP Masquerade: from n/a through 1.1.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33550&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33550" target="_blank">CVE-2024-33550</a><br><a href="https://patchstack.com/database/vulnerability/wp-masquerade/wordpress-wp-masquerade-plugin-1-1-0-authenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JS Help Desk--JS Help Desk Best Help Desk &amp; Support Plugin<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk - Best Help Desk &amp; Support Plugin allows Using Malicious Files.This issue affects JS Help Desk - Best Help Desk &amp; Support Plugin: from n/a through 2.7.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-25444&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-25444" target="_blank">CVE-2023-25444</a><br><a href="https://patchstack.com/database/vulnerability/js-support-ticket/wordpress-js-help-desk-best-help-desk-support-plugin-plugin-2-7-7-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Jordy Meow--AI Engine: ChatGPT Chatbot<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34440&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34440" target="_blank">CVE-2024-34440</a><br><a href="https://patchstack.com/database/vulnerability/ai-engine/wordpress-ai-engine-plugin-2-2-63-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Joseph C Dolson--My Tickets<br> </td>
<td>Missing Authorization vulnerability in Joseph C Dolson My Tickets.This issue affects My Tickets: from n/a through 1.9.11.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23988&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23988" target="_blank">CVE-2023-23988</a><br><a href="https://patchstack.com/database/vulnerability/my-tickets/wordpress-my-tickets-plugin-1-9-11-payment-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JumpDEMAND Inc.--ActiveDEMAND<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc. ActiveDEMAND allows Using Malicious Files.This issue affects ActiveDEMAND: from n/a through 0.2.41.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32809" target="_blank">CVE-2024-32809</a><br><a href="https://patchstack.com/database/vulnerability/activedemand/wordpress-activedemand-plugin-0-2-41-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Kioware--Kioware<br> </td>
<td>KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3459&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3459" target="_blank">CVE-2024-3459</a><br><a href="https://cert.pl/en/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://www.kioware.com/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Kioware--Kioware<br> </td>
<td>In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time window before the forced automatic logout occurs. Then, by using some built-in function of these applications, one may launch any other programs.  In order to exploit this vulnerability external applications must be left running when the KioWare software is launched. Additionally, an attacker must know the PIN set for this Kioware instance and also slow down the application with some specific task which extends the usable time window.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3460&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3460" target="_blank">CVE-2024-3460</a><br><a href="https://cert.pl/en/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://www.kioware.com/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Kognetiks--Kognetiks Chatbot for WordPress<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32700&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32700" target="_blank">CVE-2024-32700</a><br><a href="https://patchstack.com/database/vulnerability/chatbot-chatgpt/wordpress-kognetiks-chatbot-for-wordpress-plugin-2-0-0-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>LWS--LWS Affiliation<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: from n/a through 2.2.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32297&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32297" target="_blank">CVE-2023-32297</a><br><a href="https://patchstack.com/database/vulnerability/lws-affiliation/wordpress-lws-affiliation-plugin-2-2-6-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Lenderd--1003 Mortgage Application<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Lenderd 1003 Mortgage Application allows Relative Path Traversal.This issue affects 1003 Mortgage Application: from n/a through 1.75.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-45368&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-45368" target="_blank">CVE-2022-45368</a><br><a href="https://patchstack.com/database/vulnerability/1003-mortgage-application/wordpress-1003-mortgage-application-plugin-1-73-local-file-inclusion?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Lenovo--Printers<br> </td>
<td>A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3286&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3286" target="_blank">CVE-2024-3286</a><br><a href="https://iknow.lenovo.com.cn/detail/421500" target="_blank">psirt@lenovo.com</a><br><a href="https://www.lenovoimage.com/psirt/notice/158605.html" target="_blank">psirt@lenovo.com</a></td>
</tr>
<tr>
<td>MSI--MSI Afterburner<br> </td>
<td>MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads to triggering vulnerabilities like CVE-2024-1443 and CVE-2024-1460 from a low privileged user.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3745&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3745" target="_blank">CVE-2024-3745</a><br><a href="https://fluidattacks.com/advisories/gershwin/" target="_blank">help@fluidattacks.com</a><br><a href="https://forums.guru3d.com/threads/msi-ab-rtss-development-news-thread.412822/page-227#post-6231456" target="_blank">help@fluidattacks.com</a><br><a href="https://forums.guru3d.com/threads/msi-ab-rtss-development-news-thread.412822/page-227#post-6231768" target="_blank">help@fluidattacks.com</a></td>
</tr>
<tr>
<td>MainWP--MainWP Code Snippets Extension<br> </td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from n/a through 4.0.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23645&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23645" target="_blank">CVE-2023-23645</a><br><a href="https://patchstack.com/database/vulnerability/mainwp-code-snippets-extension/wordpress-mainwp-code-snippets-extension-plugin-4-0-2-subscriber-arbitrary-php-code-injection-execution-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Masteriyo--LMS<br> </td>
<td>Improper Privilege Management vulnerability in Masteriyo LMS allows Privilege Escalation.This issue affects LMS: from n/a through 1.7.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24882&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24882" target="_blank">CVE-2024-24882</a><br><a href="https://patchstack.com/database/vulnerability/learning-management-system/wordpress-lms-by-masteriyo-plugin-1-7-2-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Microsoft--Azure Monitor<br> </td>
<td>Azure Monitor Agent Elevation of Privilege Vulnerability</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30060&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30060" target="_blank">CVE-2024-30060</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30060" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Dynamics 365<br> </td>
<td>Dynamics 365 Customer Insights Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30047&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30047" target="_blank">CVE-2024-30047</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30047" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Dynamics 365<br> </td>
<td>Dynamics 365 Customer Insights Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30048&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30048" target="_blank">CVE-2024-30048</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30048" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft SharePoint Enterprise Server 2016<br> </td>
<td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30044&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30044" target="_blank">CVE-2024-30044</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30044" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Office Online Server<br> </td>
<td>Microsoft Excel Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30042&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30042" target="_blank">CVE-2024-30042</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30042" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30006&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30006" target="_blank">CVE-2024-30006</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30006" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30009&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30009" target="_blank">CVE-2024-30009</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30009" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Hyper-V Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30017&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30017" target="_blank">CVE-2024-30017</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30017" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Cryptographic Services Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30020&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30020" target="_blank">CVE-2024-30020</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30020" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29994&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29994" target="_blank">CVE-2024-29994</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29994" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29996&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29996" target="_blank">CVE-2024-29996</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29996" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30014&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30014" target="_blank">CVE-2024-30014</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30014" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30015&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30015" target="_blank">CVE-2024-30015</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30015" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Kernel Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30018&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30018" target="_blank">CVE-2024-30018</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30018" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30022&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30022" target="_blank">CVE-2024-30022</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30022" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30023&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30023" target="_blank">CVE-2024-30023</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30023" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30024&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30024" target="_blank">CVE-2024-30024</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30024" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30025&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30025" target="_blank">CVE-2024-30025</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30025" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>NTFS Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30027&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30027" target="_blank">CVE-2024-30027</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30027" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Win32k Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30028&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30028" target="_blank">CVE-2024-30028</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30028" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30029&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30029" target="_blank">CVE-2024-30029</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30029" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows CNG Key Isolation Service Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30031&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30031" target="_blank">CVE-2024-30031</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30031" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows DWM Core Library Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30032&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30032" target="_blank">CVE-2024-30032</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30032" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows DWM Core Library Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30035&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30035" target="_blank">CVE-2024-30035</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30035" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30037&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30037" target="_blank">CVE-2024-30037</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30037" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Win32k Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30038&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30038" target="_blank">CVE-2024-30038</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30038" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30049&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30049" target="_blank">CVE-2024-30049</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30049" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 21H2<br> </td>
<td>Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-26238&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26238" target="_blank">CVE-2024-26238</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26238" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2008 Service Pack 2<br> </td>
<td>Win32k Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30030&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30030" target="_blank">CVE-2024-30030</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30030" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>Windows Hyper-V Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30010&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30010" target="_blank">CVE-2024-30010</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30010" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2022, 23H2 Edition (Server Core installation)<br> </td>
<td>Microsoft Brokering File System Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30007&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30007" target="_blank">CVE-2024-30007</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30007" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2022<br> </td>
<td>Windows Search Service Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30033&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30033" target="_blank">CVE-2024-30033</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30033" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>MongoDB Inc--MongoDB Server<br> </td>
<td>Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.25.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3372&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3372" target="_blank">CVE-2024-3372</a><br><a href="https://jira.mongodb.org/browse/SERVER-85263" target="_blank">cna@mongodb.com</a></td>
</tr>
<tr>
<td>N/A--Pk Favicon Manager<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Pk Favicon Manager.This issue affects Pk Favicon Manager: from n/a through 2.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34416&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34416" target="_blank">CVE-2024-34416</a><br><a href="https://patchstack.com/database/vulnerability/phpsword-favicon-manager/wordpress-pk-favicon-manager-plugin-2-1-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>N/A--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22268&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22268" target="_blank">CVE-2024-22268</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>N/A--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22269&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22269" target="_blank">CVE-2024-22269</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>N/A--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22270&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22270" target="_blank">CVE-2024-22270</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>NA--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22267&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22267" target="_blank">CVE-2024-22267</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>NI--FlexLogger<br> </td>
<td>A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2024 Q1 and prior versions as well as NI InstrumentStudio 2024 Q1 and prior versions.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4044&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4044" target="_blank">CVE-2024-4044</a><br><a href="https://ni.com/r/CVE-2024-4044" target="_blank">security@ni.com</a></td>
</tr>
<tr>
<td>Netflix--Genie<br> </td>
<td>A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4701&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4701" target="_blank">CVE-2024-4701</a><br><a href="https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2024-001.md" target="_blank">security-report@netflix.com</a></td>
</tr>
<tr>
<td>Nota-Info--Bookly<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Nota-Info Bookly allows Path Traversal, Manipulating Web Input to File System Calls.This issue affects Bookly: from n/a through 21.7.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-26526&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26526" target="_blank">CVE-2023-26526</a><br><a href="https://patchstack.com/database/vulnerability/bookly-responsive-appointment-booking-tool/wordpress-bookly-plugin-21-7-1-authenticated-arbitrary-file-deletion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks. An administrator able to provide tampered archives to be processed by the affected versions of Arc may be able to have arbitrary files extracted to arbitrary filesystem locations. Leveraging this issue, an attacker may be able to overwrite arbitrary files on the target filesystem and cause critical impacts on the system (e.g., arbitrary command execution on the victim's machine).</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5938&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5938" target="_blank">CVE-2023-5938</a><br><a href="https://security.nozominetworks.com/NN-2023:16-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself. A malicious local user or process, during a window of opportunity when the local web interface is active, may be able to extract sensitive information or change Arc's configuration. This could also lead to arbitrary code execution if a malicious update package is installed.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5935&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5935" target="_blank">CVE-2023-5935</a><br><a href="https://security.nozominetworks.com/NN-2023:13-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5936&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5936" target="_blank">CVE-2023-5936</a><br><a href="https://security.nozominetworks.com/NN-2023:14-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>OceanWP--OceanWP<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OceanWP allows PHP Local File Inclusion.This issue affects OceanWP: from n/a through 3.4.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23700&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23700" target="_blank">CVE-2023-23700</a><br><a href="https://patchstack.com/database/vulnerability/oceanwp/wordpress-oceanwp-theme-3-4-1-authenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>OctoPrint--OctoPrint<br> </td>
<td>OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within `config.yaml`, even if they come from networks that are not configured as `localNetworks`, spoofing their IP via the `X-Forwarded-For` header. If autologin is not enabled, this vulnerability does not have any impact. The vulnerability has been patched in version 1.10.1. Until the patch has been applied, OctoPrint administrators who have autologin enabled on their instances should disable it and/or to make the instance inaccessible from potentially hostile networks like the internet.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32977&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32977" target="_blank">CVE-2024-32977</a><br><a href="https://github.com/OctoPrint/OctoPrint/commit/5afbec8d23508edc25b0f1bdef1620580136add4" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-2vjq-hg5w-5gm7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Remote Code Execution has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3483&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3483" target="_blank">CVE-2024-3483</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>XML External Entity injection vulnerability found in OpenTextâ„¢ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3486&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3486" target="_blank">CVE-2024-3486</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Remote Code Execution has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3967&amp;vector=CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3967" target="_blank">CVE-2024-3967</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Remote Code Execution has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3968&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3968" target="_blank">CVE-2024-3968</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>Owlet--Cam v2<br> </td>
<td>A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6321&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6321" target="_blank">CVE-2023-6321</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto Theme - Functionality<br> </td>
<td>The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' shortcode 'portfolio_layout' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3808&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3808" target="_blank">CVE-2024-3808</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fea96f84-f75b-4f02-9ca8-f8fda439d565?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto Theme - Functionality<br> </td>
<td>The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3809" target="_blank">CVE-2024-3809</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f5cdd3c1-6353-4bee-a4f9-5b7972f0970c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto<br> </td>
<td>The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3806&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3806" target="_blank">CVE-2024-3806</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98ccc604-79c6-4be9-acb0-23fc82a31dfa?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto<br> </td>
<td>The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included. This was partially patched in version 7.1.0 and fully patched in version 7.1.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3807&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3807" target="_blank">CVE-2024-3807</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4bc3da9e-4b5f-4200-9df9-0ae953571377?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28133&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28133" target="_blank">CVE-2024-28133</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive information. No additional user interaction is required. The access is limited as only non-sensitive information can be obtained but the availability can be seriously affected. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28134&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28134" target="_blank">CVE-2024-28134</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28136&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28136" target="_blank">CVE-2024-28136</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28137&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28137" target="_blank">CVE-2024-28137</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264922 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5063&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5063" target="_blank">CVE-2024-5063</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20Authentication%20Bypass.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336236" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264923.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5064&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5064" target="_blank">CVE-2024-5064</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%202%20(Unauthenticated).md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336238" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5065&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5065" target="_blank">CVE-2024-5065</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%203%20(Unauthenticated).md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336239" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>POSIMYTH Innovation--The Plus Addons for Elementor Pro<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows PHP Local File Inclusion.This issue affects The Plus Addons for Elementor Pro: from n/a through 5.2.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47178&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47178" target="_blank">CVE-2023-47178</a><br><a href="https://patchstack.com/database/vulnerability/theplus_elementor_addon/wordpress-the-plus-addons-for-elementor-pro-plugin-5-2-8-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Phoenix--SecureCore for Intel Gemini Lake<br> </td>
<td>Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCoreâ„¢ for Intel Gemini Lake.This issue affects: SecureCoreâ„¢ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1598&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1598" target="_blank">CVE-2024-1598</a><br><a href="https://www.phoenix.com/security-notifications/cve-2024-1598/" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a></td>
</tr>
<tr>
<td>Phoenix--SecureCore for Intel Kaby Lake<br> </td>
<td>Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCoreâ„¢ for select Intel platforms This issue affects: Phoenix SecureCoreâ„¢ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998; Phoenix SecureCoreâ„¢ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562; Phoenix SecureCoreâ„¢ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323; Phoenix SecureCoreâ„¢ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287; Phoenix SecureCoreâ„¢ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236; Phoenix SecureCoreâ„¢ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184; Phoenix SecureCoreâ„¢ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269; Phoenix SecureCoreâ„¢ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218; Phoenix SecureCoreâ„¢ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0762&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0762" target="_blank">CVE-2024-0762</a><br><a href="https://www.phoenix.com/security-notifications/cve-2024-0762/" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a></td>
</tr>
<tr>
<td>Phoenix--WinFlash Driver<br> </td>
<td>Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-35841&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-35841" target="_blank">CVE-2023-35841</a><br><a href="https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a><br><a href="https://jvn.jp/en/vu/JVNVU93886750/index.html" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a><br><a href="https://www.phoenix.com/security-notifications/cve-2023-35841/" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a></td>
</tr>
<tr>
<td>PluginOps--Landing Page Builder<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Reflected XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34752&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34752" target="_blank">CVE-2024-34752</a><br><a href="https://patchstack.com/database/vulnerability/page-builder-add/wordpress-landing-page-builder-1-5-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PluginUS--HUSKY Products Filter for WooCommerce (formerly WOOF)<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY - Products Filter for WooCommerce (formerly WOOF) allows Using Malicious Files, Code Inclusion.This issue affects HUSKY - Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.5.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32680&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32680" target="_blank">CVE-2024-32680</a><br><a href="https://patchstack.com/database/vulnerability/woocommerce-products-filter/wordpress-husky-plugin-1-3-5-2-remote-code-execution-rce-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Podlove--Podlove Podcast Publisher<br> </td>
<td>Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32712&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32712" target="_blank">CVE-2024-32712</a><br><a href="https://patchstack.com/database/vulnerability/podlove-podcasting-plugin-for-wordpress/wordpress-podlove-podcast-publisher-plugin-4-0-14-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PowerDNS--DNSdist<br> </td>
<td>When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker can trigger an assertion failure in DNSdist by sending a request for a zone transfer (AXFR or IXFR) over DNS over HTTPS, causing the process to stop and thus leading to a Denial of Service. DNS over HTTPS is not enabled by default, and backends are using plain DNS (Do53) by default.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25581&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25581" target="_blank">CVE-2024-25581</a><br><a href="https://dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2024-03.html" target="_blank">security@open-xchange.com</a></td>
</tr>
<tr>
<td>Premmerce--Premmerce Permalink Manager for WooCommerce<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through 2.3.10.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27971&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27971" target="_blank">CVE-2024-27971</a><br><a href="https://patchstack.com/database/vulnerability/woo-permalink-manager/wordpress-premmerce-permalink-manager-for-woocommerce-plugin-2-3-10-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PrestaShop--PrestaShop<br> </td>
<td>PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34716&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34716" target="_blank">CVE-2024-34716</a><br><a href="https://github.com/PrestaShop/PrestaShop/releases/tag/8.1.6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-45vm-3j38-7p78" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>ProfilePress Membership Team--ProfilePress<br> </td>
<td>Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41954" target="_blank">CVE-2023-41954</a><br><a href="https://patchstack.com/database/vulnerability/wp-user-avatar/wordpress-profilepress-plugin-4-13-1-unauthenticated-limited-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--Telerik Reporting<br> </td>
<td>In ProgressÂ® TelerikÂ® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4200&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4200" target="_blank">CVE-2024-4200</a><br><a href="https://docs.telerik.com/reporting/knowledge-base/deserialization-vulnerability-cve-2024-4200" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--Telerik Reporting<br> </td>
<td>In ProgressÂ® TelerikÂ® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4202&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4202" target="_blank">CVE-2024-4202</a><br><a href="https://docs.telerik.com/reporting/knowledge-base/instantiation-vulnerability-cve-2024-4202" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--Telerik UI for WinForms<br> </td>
<td>A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3892&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3892" target="_blank">CVE-2024-3892</a><br><a href="https://docs.telerik.com/devtools/winforms/knowledge-base/local-code-execution-vulnerability-cve-2024-3892" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Proofpoint--Enterprise Protection<br> </td>
<td>The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control.  These accounts are able to send spoofed email to any users within the domains configured by the Administrator.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3676&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3676" target="_blank">CVE-2024-3676</a><br><a href="https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0002" target="_blank">security@proofpoint.com</a></td>
</tr>
<tr>
<td>Propovoice--Propovoice CRM<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Propovoice Propovoice CRM allows Stored XSS.This issue affects Propovoice CRM: from n/a through 1.7.6.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4747&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4747" target="_blank">CVE-2024-4747</a><br><a href="https://patchstack.com/database/vulnerability/propovoice/wordpress-propovoice-crm-plugin-1-7-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>QuanticaLabs--Chauffeur Taxi Booking System for WordPress<br> </td>
<td>Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 6.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32692&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32692" target="_blank">CVE-2024-32692</a><br><a href="https://patchstack.com/database/vulnerability/chauffeur-booking-system/wordpress-chauffeur-taxi-booking-system-for-wordpress-plugin-6-9-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Qube One Ltd.--Redirection for Contact Form 7<br> </td>
<td>Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23990&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23990" target="_blank">CVE-2023-23990</a><br><a href="https://patchstack.com/database/vulnerability/wpcf7-redirect/wordpress-redirection-for-contact-form-7-plugin-2-7-0-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Rank Math--Rank Math SEO<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from n/a through 1.0.107.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23888&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23888" target="_blank">CVE-2023-23888</a><br><a href="https://patchstack.com/database/vulnerability/seo-by-rank-math/wordpress-rank-math-seo-plugin-1-0-107-2-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Red Hat--Migration Toolkit for Containers<br> </td>
<td>A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3727&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3727" target="_blank">CVE-2024-3727</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-3727" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2274767" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Repute Infosystems--ARMember<br> </td>
<td>Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51356&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51356" target="_blank">CVE-2023-51356</a><br><a href="https://patchstack.com/database/vulnerability/armember-membership/wordpress-armember-plugin-4-0-10-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Roku--Indoor Camera SE<br> </td>
<td>A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6322&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6322" target="_blank">CVE-2023-6322</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>Room 34 Creative Services, LLC--ICS Calendar<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Absolute Path Traversal, : Server Side Request Forgery.This issue affects ICS Calendar: from n/a through 10.12.0.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46784&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46784" target="_blank">CVE-2023-46784</a><br><a href="https://patchstack.com/database/vulnerability/ics-calendar/wordpress-ics-calendar-plugin-10-12-0-2-ssrf-and-arbitrary-file-read-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SAASPROJECT Booking Package--Booking Package<br> </td>
<td>Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37389&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37389" target="_blank">CVE-2023-37389</a><br><a href="https://patchstack.com/database/vulnerability/booking-package/wordpress-booking-package-saasproject-plugin-1-5-98-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP BusinessObjects Business Intelligence Platform<br> </td>
<td>SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28165&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28165" target="_blank">CVE-2024-28165</a><br><a href="https://me.sap.com/notes/3431794" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP NetWeaver Application Server ABAP and ABAP Platform<br> </td>
<td>An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33006&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33006" target="_blank">CVE-2024-33006</a><br><a href="https://me.sap.com/notes/3448171" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SUBNET--PowerSYSTEM Center<br> </td>
<td>SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28042&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28042" target="_blank">CVE-2024-28042</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-02" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>SailPoint--Identity Security Cloud<br> </td>
<td>An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3319&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3319" target="_blank">CVE-2024-3319</a><br><a href="https://www.sailpoint.com/security-advisories/" target="_blank">psirt@sailpoint.com</a></td>
</tr>
<tr>
<td>Saleswonder Team--WebinarIgnition<br> </td>
<td>Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51424&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51424" target="_blank">CVE-2023-51424</a><br><a href="https://patchstack.com/database/vulnerability/webinar-ignition/wordpress-webinarignition-plugin-3-05-0-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SiAdmin--SiAdmin<br> </td>
<td>Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4991&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4991" target="_blank">CVE-2024-4991</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-siadmin" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>SiAdmin--SiAdmin<br> </td>
<td>Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4992&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4992" target="_blank">CVE-2024-4992</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-siadmin" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Siemens--CPC80 Central Processing/Communication<br> </td>
<td>A vulnerability has been identified in CPC80 Central Processing/Communication (All versions &lt; V16.41), CPCI85 Central Processing/Communication (All versions &lt; V5.30). The affected device firmwares contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31484&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31484" target="_blank">CVE-2024-31484</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-871704.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--CPCI85 Central Processing/Communication<br> </td>
<td>A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions &lt; V5.30), SICORE Base system (All versions &lt; V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31485&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31485" target="_blank">CVE-2024-31485</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-871704.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--JT2Go<br> </td>
<td>A vulnerability has been identified in JT2Go (All versions &lt; V2312.0001), Teamcenter Visualization V14.1 (All versions &lt; V14.1.0.13), Teamcenter Visualization V14.2 (All versions &lt; V14.2.0.10), Teamcenter Visualization V14.3 (All versions &lt; V14.3.0.7), Teamcenter Visualization V2312 (All versions &lt; V2312.0001). The affected applications contain a stack overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34085&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34085" target="_blank">CVE-2024-34085</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-661579.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--JT2Go<br> </td>
<td>A vulnerability has been identified in JT2Go (All versions &lt; V2312.0001), Teamcenter Visualization V14.1 (All versions &lt; V14.1.0.13), Teamcenter Visualization V14.2 (All versions &lt; V14.2.0.10), Teamcenter Visualization V14.3 (All versions &lt; V14.3.0.7), Teamcenter Visualization V2312 (All versions &lt; V2312.0001). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted CGM file. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34086&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34086" target="_blank">CVE-2024-34086</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-661579.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32055&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32055" target="_blank">CVE-2024-32055</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21562)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32057&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32057" target="_blank">CVE-2024-32057</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application is vulnerable to memory corruption while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21563)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32058&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32058" target="_blank">CVE-2024-32058</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21564)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32059&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32059" target="_blank">CVE-2024-32059</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21565)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32060&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32060" target="_blank">CVE-2024-32060</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21566)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32061&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32061" target="_blank">CVE-2024-32061</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21568)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32062&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32062" target="_blank">CVE-2024-32062</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21573)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32063&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32063" target="_blank">CVE-2024-32063</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21575)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32064&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32064" target="_blank">CVE-2024-32064</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21577)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32065&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32065" target="_blank">CVE-2024-32065</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21578)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32066&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32066" target="_blank">CVE-2024-32066</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.210), Parasolid V36.1 (All versions &lt; V36.1.185). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted X_T part file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-23468)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31980&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31980" target="_blank">CVE-2024-31980</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-489698.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.208), Parasolid V36.1 (All versions &lt; V36.1.173). The affected applications contain an out of bounds read past the unmapped memory region while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32635&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32635" target="_blank">CVE-2024-32635</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-046364.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.208), Parasolid V36.1 (All versions &lt; V36.1.173). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32636&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32636" target="_blank">CVE-2024-32636</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-046364.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27939&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27939" target="_blank">CVE-2024-27939</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27940&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27940" target="_blank">CVE-2024-27940</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected client systems do not properly sanitize input data before sending it to the SQL server. An attacker could use this vulnerability to compromise the whole database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27941&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27941" target="_blank">CVE-2024-27941</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow any unauthenticated client to disconnect any active user from the server. An attacker could use this vulnerability to prevent any user to perform actions in the system, causing a denial of service situation.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27942&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27942" target="_blank">CVE-2024-27942</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow a privileged user to upload generic files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27943&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27943" target="_blank">CVE-2024-27943</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27944&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27944" target="_blank">CVE-2024-27944</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27945&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27945" target="_blank">CVE-2024-27945</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC CN 4100<br> </td>
<td>A vulnerability has been identified in SIMATIC CN 4100 (All versions &lt; V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack the password hash gains root access to the device.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32741&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32741" target="_blank">CVE-2024-32741</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-273900.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC CN 4100<br> </td>
<td>A vulnerability has been identified in SIMATIC CN 4100 (All versions &lt; V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32740&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32740" target="_blank">CVE-2024-32740</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-273900.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC CN 4100<br> </td>
<td>A vulnerability has been identified in SIMATIC CN 4100 (All versions &lt; V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially misuse the port for booting another operating system and gain complete read/write access to the filesystem.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32742&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32742" target="_blank">CVE-2024-32742</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-273900.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The affected systems use symmetric cryptography with a hard-coded key to protect the communication between client and server. This could allow an unauthenticated remote attacker to compromise confidentiality and integrity of the communication and, subsequently, availability of the system. A successful exploit requires the attacker to gain knowledge of the hard-coded key and to be able to intercept the communication between client and server on the network.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30207&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30207" target="_blank">CVE-2024-30207</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected systems transmit client-side resources without proper cryptographic protection. This could allow an attacker to eavesdrop on and modify resources in transit. A successful exploit requires an attacker to be in the network path between the RTLS Locating Manager server and a client (MitM).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30209&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30209" target="_blank">CVE-2024-30209</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The affected application assigns incorrect permissions to a user management component. This could allow a privileged attacker to escalate their privileges from the Administrators group to the Systemadministrator group.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33499&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33499" target="_blank">CVE-2024-33499</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected SIMATIC RTLS Locating Manager Clients do not properly check the integrity of update files. This could allow an unauthenticated remote attacker to alter update files in transit and trick an authorized user into installing malicious code. A successful exploit requires the attacker to be able to modify the communication between server and client on the network.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30206&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30206" target="_blank">CVE-2024-30206</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Simcenter Nastran 2306<br> </td>
<td>A vulnerability has been identified in Simcenter Nastran 2306 (All versions), Simcenter Nastran 2312 (All versions), Simcenter Nastran 2406 (All versions &lt; V2406.90). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33577&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33577" target="_blank">CVE-2024-33577</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-258494.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33489&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33489" target="_blank">CVE-2024-33489</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33490&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33490" target="_blank">CVE-2024-33490</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33491&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33491" target="_blank">CVE-2024-33491</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33492&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33492" target="_blank">CVE-2024-33492</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33493&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33493" target="_blank">CVE-2024-33493</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 2). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34771&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34771" target="_blank">CVE-2024-34771</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 4). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34772&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34772" target="_blank">CVE-2024-34772</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 2). The affected applications contain a stack overflow vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34773&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34773" target="_blank">CVE-2024-34773</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Tecnomatix Plant Simulation V2302<br> </td>
<td>A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions &lt; V2302.0011). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted MODEL file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22974)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32639&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32639" target="_blank">CVE-2024-32639</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-923361.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Sirv--Sirv<br> </td>
<td>Improper Privilege Management vulnerability in Sirv allows Privilege Escalation.This issue affects Sirv: from n/a through 7.2.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32959&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32959" target="_blank">CVE-2024-32959</a><br><a href="https://patchstack.com/database/vulnerability/sirv/wordpress-sirv-plugin-7-2-2-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Sizam Design--Rehub<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31231&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31231" target="_blank">CVE-2024-31231</a><br><a href="https://patchstack.com/database/vulnerability/rehub-theme/wordpress-rehub-theme-19-6-1-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Sizam Design--Rehub<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31232&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31232" target="_blank">CVE-2024-31232</a><br><a href="https://patchstack.com/database/vulnerability/rehub-theme/wordpress-rehub-theme-19-6-1-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Snow Software AB--Snow License Manager<br> </td>
<td>Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4129&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4129" target="_blank">CVE-2024-4129</a><br><a href="https://community.snowsoftware.com/s/feed/0D5Td000008dv8sKAA" target="_blank">security@snowsoftware.com</a></td>
</tr>
<tr>
<td>SolarWinds--Access Rights Manager<br> </td>
<td>The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28075&amp;vector=CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28075" target="_blank">CVE-2024-28075</a><br><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank">psirt@solarwinds.com</a><br><a href="https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm" target="_blank">psirt@solarwinds.com</a><br><a href="https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28075" target="_blank">psirt@solarwinds.com</a></td>
</tr>
<tr>
<td>SolarWinds--Access Rights Manager<br> </td>
<td>The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23473&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23473" target="_blank">CVE-2024-23473</a><br><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank">psirt@solarwinds.com</a><br><a href="https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-23473" target="_blank">psirt@solarwinds.com</a></td>
</tr>
<tr>
<td>Sonatype--Nexus Repository<br> </td>
<td>Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4956" target="_blank">CVE-2024-4956</a><br><a href="https://support.sonatype.com/hc/en-us/articles/29416509323923" target="_blank">103e4ec9-0a87-450b-af77-479448ddef11</a></td>
</tr>
<tr>
<td>SourceCodester--Best House Rental Management System<br> </td>
<td>A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265072.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5093&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5093" target="_blank">CVE-2024-5093</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20Authentication%20Bypass.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.265072" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.265072" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335712" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Best House Rental Management System<br> </td>
<td>A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265073 was assigned to this vulnerability.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5094&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5094" target="_blank">CVE-2024-5094</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20SQL%20Injection%20-%202.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.265073" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.265073" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335714" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Discussion Forum Site<br> </td>
<td>A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file registerH.php. The manipulation of the argument ima leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264455.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4920&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4920" target="_blank">CVE-2024-4920</a><br><a href="https://github.com/CveSecLook/cve/issues/27" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264455" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264455" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333477" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Examination System<br> </td>
<td>A vulnerability was found in SourceCodester Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264743.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5046&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5046" target="_blank">CVE-2024-5046</a><br><a href="https://github.com/CveSecLook/cve/issues/32" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264743" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264743" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335527" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--SchoolWebTech<br> </td>
<td>A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /improve/home.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264534 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4966&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4966" target="_blank">CVE-2024-4966</a><br><a href="https://github.com/CveSecLook/cve/issues/30" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264534" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264534" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.334216" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Student Management System<br> </td>
<td>A vulnerability classified as critical has been found in SourceCodester Student Management System 1.0. Affected is an unknown function of the file /student/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264744.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5047&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5047" target="_blank">CVE-2024-5047</a><br><a href="https://github.com/I-Schnee-I/cev/blob/main/SourceCodester%20Student%20Management%20System%201.0%20controller.php%20Unrestricted%20Upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264744" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264744" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335633" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>StylemixThemes--Consulting<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through 6.5.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37385&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37385" target="_blank">CVE-2023-37385</a><br><a href="https://patchstack.com/database/vulnerability/consulting/wordpress-consulting-theme-6-3-6-local-file-inclusion?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus Agent<br> </td>
<td>A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3292&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3292" target="_blank">CVE-2024-3292</a><br><a href="https://www.tenable.com/security/tns-2024-09" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus Agent<br> </td>
<td>When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3291&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3291" target="_blank">CVE-2024-3291</a><br><a href="https://www.tenable.com/security/tns-2024-09" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus<br> </td>
<td>A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3290&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3290" target="_blank">CVE-2024-3290</a><br><a href="https://www.tenable.com/security/tns-2024-08" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus<br> </td>
<td>When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3289&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3289" target="_blank">CVE-2024-3289</a><br><a href="https://www.tenable.com/security/tns-2024-08" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Teplitsa of social technologies--Leyka<br> </td>
<td>Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-33327&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33327" target="_blank">CVE-2023-33327</a><br><a href="https://patchstack.com/database/vulnerability/leyka/wordpress-leyka-plugin-3-29-2-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeKraft--BuddyForms<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32830&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32830" target="_blank">CVE-2024-32830</a><br><a href="https://patchstack.com/database/vulnerability/buddyforms/wordpress-buddyforms-plugin-2-8-8-arbitrary-file-read-and-ssrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeNectar--Salient Core<br> </td>
<td>The Salient Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.7 via the 'nectar_icon' shortcode 'icon_linea' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3812&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3812" target="_blank">CVE-2024-3812</a><br><a href="https://themeforest.net/item/salient-responsive-multipurpose-theme/4363266" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ebd3b70e-a06a-4dcc-a6af-dbe64fd57c82?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ThemeNectar--Salient Shortcodes<br> </td>
<td>The Salient Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.3 via the 'icon' shortcode 'image' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3810&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3810" target="_blank">CVE-2024-3810</a><br><a href="https://themeforest.net/item/salient-responsive-multipurpose-theme/4363266" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d1b3d4d5-9d2b-4924-a830-27c07fa1ba98?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Themify--Themify Ultra<br> </td>
<td>Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46145&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46145" target="_blank">CVE-2023-46145</a><br><a href="https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Thomas Scholl--canvasio3D Light<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through 2.5.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34411&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34411" target="_blank">CVE-2024-34411</a><br><a href="https://patchstack.com/database/vulnerability/canvasio3d-light/wordpress-canvasio3d-light-plugin-2-5-0-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Thrive Themes--Thrive Theme Builder<br> </td>
<td>Improper Privilege Management vulnerability in Thrive Themes Thrive Theme Builder allows Privilege Escalation.This issue affects Thrive Theme Builder: from n/a before 3.24.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47782&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47782" target="_blank">CVE-2023-47782</a><br><a href="https://patchstack.com/database/vulnerability/thrive-theme/wordpress-thrive-theme-builder-theme-3-20-1-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThroughTek--Kalay SDK<br> </td>
<td>ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6324&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6324" target="_blank">CVE-2023-6324</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>Timber Team &amp; Contributors--Timber<br> </td>
<td>Deserialization of Untrusted Data vulnerability in Timber Team &amp; Contributors Timber.This issue affects Timber: from n/a through 1.23.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29800&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29800" target="_blank">CVE-2024-29800</a><br><a href="https://patchstack.com/database/vulnerability/timber-library/wordpress-timber-plugin-1-23-0-deserialization-of-untrusted-data-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Tips and Tricks HQ--WP Express Checkout (Accept PayPal Payments)<br> </td>
<td>Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30527&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30527" target="_blank">CVE-2024-30527</a><br><a href="https://patchstack.com/database/vulnerability/wp-express-checkout/wordpress-wp-express-checkout-plugin-2-3-7-price-manipulation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Trellix--ePolicy Orchestrator<br> </td>
<td>Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with admin privileges on the ePO server to read the contents of the orion.keystore file, allowing them to access the ePO database encryption key. This was possible through using a hard coded password for the keystore. Access Control restrictions on the file mean this would not be exploitable unless the user is the system admin for the server that ePO is running on.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4844&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4844" target="_blank">CVE-2024-4844</a><br><a href="https://thrive.trellix.com/s/article/000013505" target="_blank">trellixpsirt@trellix.com</a></td>
</tr>
<tr>
<td>URBAN BASE--Z-Downloads<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34555&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34555" target="_blank">CVE-2024-34555</a><br><a href="https://patchstack.com/database/vulnerability/z-downloads/wordpress-z-downloads-plugin-1-11-3-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>UkrSolution--Barcode Scanner with Inventory &amp; Order Manager<br> </td>
<td>Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory &amp; Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory &amp; Order Manager: from n/a through 1.5.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33567&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33567" target="_blank">CVE-2024-33567</a><br><a href="https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-3-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Vova Anokhin--Shortcodes Ultimate<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vova Anokhin Shortcodes Ultimate allows Absolute Path Traversal.This issue affects Shortcodes Ultimate: from n/a through 5.12.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-25050&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-25050" target="_blank">CVE-2023-25050</a><br><a href="https://patchstack.com/database/vulnerability/shortcodes-ultimate/wordpress-shortcodes-ultimate-plugin-5-12-6-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Automatic--Automatic<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">9.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27954" target="_blank">CVE-2024-27954</a><br><a href="https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-file-download-and-ssrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Automatic--Automatic<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in WP Automatic Automatic allows Privilege Escalation.This issue affects Automatic: from n/a through 3.92.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27955&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27955" target="_blank">CVE-2024-27955</a><br><a href="https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Hive--Events Rich Snippets for Google<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-44478&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-44478" target="_blank">CVE-2023-44478</a><br><a href="https://patchstack.com/database/vulnerability/rich-snippets-vevents/wordpress-events-rich-snippets-for-google-plugin-1-8-csrf-leading-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Sharks--s2Member Pro<br> </td>
<td>Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31237&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31237" target="_blank">CVE-2024-31237</a><br><a href="https://patchstack.com/database/vulnerability/s2member/wordpress-s2member-plugin-240315-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP-etracker--WP etracker<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through 1.0.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34431&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34431" target="_blank">CVE-2024-34431</a><br><a href="https://patchstack.com/database/vulnerability/wp-etracker/wordpress-wp-etracker-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPCustomify--Customify Site Library<br> </td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affects Customify Site Library: from n/a through 0.0.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33644&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33644" target="_blank">CVE-2024-33644</a><br><a href="https://patchstack.com/database/vulnerability/customify-sites/wordpress-customify-site-library-plugin-0-0-9-remote-code-execution-rce-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPDeveloper--Essential Addons for Elementor<br> </td>
<td>Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41955&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41955" target="_blank">CVE-2023-41955</a><br><a href="https://patchstack.com/database/vulnerability/essential-addons-for-elementor-lite/wordpress-essential-addons-for-elementor-plugin-5-8-8-contributor-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPFactory--EAN for WooCommerce<br> </td>
<td>Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34370&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34370" target="_blank">CVE-2024-34370</a><br><a href="https://patchstack.com/database/vulnerability/ean-for-woocommerce/wordpress-ean-for-woocommerce-plugin-4-8-9-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPvivid Team--WPvivid Backup and Migration<br> </td>
<td>Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41243&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41243" target="_blank">CVE-2023-41243</a><br><a href="https://patchstack.com/database/vulnerability/wpvivid-backuprestore/wordpress-wpvivid-backup-plugin-plugin-0-9-90-privilege-escalation-on-staging-environment-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WatchGuard--AuthPoint Password Manager<br> </td>
<td>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application. This issue affects AuthPoint Password Manager for MacOS versions before 1.0.6.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1417&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1417" target="_blank">CVE-2024-1417</a><br><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00006" target="_blank">5d1c2695-1a31-4499-88ae-e847036fd7e3</a></td>
</tr>
<tr>
<td>WebToffee--WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels<br> </td>
<td>Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51546&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51546" target="_blank">CVE-2023-51546</a><br><a href="https://patchstack.com/database/vulnerability/print-invoices-packing-slip-labels-for-woocommerce/wordpress-woocommerce-pdf-invoices-packing-slips-delivery-notes-and-shipping-labels-plugin-4-2-1-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WebWizards--SalesKing<br> </td>
<td>Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects SalesKing: from n/a through 1.6.15.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22157&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22157" target="_blank">CVE-2024-22157</a><br><a href="https://patchstack.com/database/vulnerability/salesking/wordpress-salesking-plugin-1-6-15-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WebinarPress--WebinarPress<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34818&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34818" target="_blank">CVE-2024-34818</a><br><a href="https://patchstack.com/database/vulnerability/wp-webinarsystem/wordpress-webinar-plugin-1-33-17-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WhatArmy--WatchTowerHQ<br> </td>
<td>Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-25701&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-25701" target="_blank">CVE-2023-25701</a><br><a href="https://patchstack.com/database/vulnerability/watchtowerhq/wordpress-watchtowerhq-plugin-3-6-16-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wholesale--WholesaleX<br> </td>
<td>Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects WholesaleX: from n/a through 1.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30542&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30542" target="_blank">CVE-2024-30542</a><br><a href="https://patchstack.com/database/vulnerability/wholesalex/wordpress-wholesalex-plugin-1-3-2-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Woo product importer--Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy<br> </td>
<td>Missing Authorization vulnerability in Woo product importer Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32724&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32724" target="_blank">CVE-2024-32724</a><br><a href="https://patchstack.com/database/vulnerability/woo-aliexpress-dropshipping/wordpress-sharkdropship-and-affiliate-for-aliexpress-ebay-amazon-etsy-plugin-2-1-1-arbitrary-content-deletion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WooCommerce--WooCommerce One Page Checkout<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-35881&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-35881" target="_blank">CVE-2023-35881</a><br><a href="https://patchstack.com/database/vulnerability/woocommerce-one-page-checkout/wordpress-woocommerce-one-page-checkout-plugin-2-3-0-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>XTemos--Woodmart Core<br> </td>
<td>Improper Privilege Management vulnerability in XTemos Woodmart Core allows Privilege Escalation.This issue affects Woodmart Core: from n/a through 1.0.36.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32244&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32244" target="_blank">CVE-2023-32244</a><br><a href="https://patchstack.com/database/vulnerability/woodmart-core/wordpress-woodmart-core-plugin-1-0-36-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>YARPP--YARPP<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-45374&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-45374" target="_blank">CVE-2022-45374</a><br><a href="https://patchstack.com/database/vulnerability/yet-another-related-posts-plugin/wordpress-yet-another-related-posts-plugin-yarpp-plugin-5-30-2-local-file-inclusion?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>YMS--VIS Pro<br> </td>
<td>YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through brute force attacks. Successful attacks can lead to unauthorised access and execution of operations based on assigned user permissions. This vulnerability affects VIS Pro in versions &lt;= 3.3.0.6. This vulnerability has been mitigated by changes in authentication mechanisms and implementation of additional authentication layer and strong password policies.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3263&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3263" target="_blank">CVE-2024-3263</a><br><a href="https://remediata.com/blog/cve-2024-3263-improper-authentication-in-yms-vis-pro/" target="_blank">incident@nbu.gov.sk</a><br><a href="https://www.svps.sk/vis/" target="_blank">incident@nbu.gov.sk</a></td>
</tr>
<tr>
<td>ZTE--ZXUN-ePDG<br> </td>
<td>ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session informations using the keys may be leaked.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22064&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22064" target="_blank">CVE-2024-22064</a><br><a href="https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1035524" target="_blank">psirt@zte.com.cn</a></td>
</tr>
<tr>
<td>Zabbix--Zabbix<br> </td>
<td>Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22120&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22120" target="_blank">CVE-2024-22120</a><br><a href="https://support.zabbix.com/browse/ZBX-24505" target="_blank">security@zabbix.com</a></td>
</tr>
<tr>
<td>abetlen--llama-cpp-python<br> </td>
<td>llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` 's Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to remote code execution by a carefully constructed payload.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34359&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34359" target="_blank">CVE-2024-34359</a><br><a href="https://github.com/abetlen/llama-cpp-python/commit/b454f40a9a1787b2b5659cd2cb00819d983185df" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/abetlen/llama-cpp-python/security/advisories/GHSA-56xg-wfcc-g829" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>alttextai--Alt Text AI Automatically generate image alt text for SEO and accessibility<br> </td>
<td>The Alt Text AI - Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to generic SQL Injection via the 'last_post_id' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4847&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4847" target="_blank">CVE-2024-4847</a><br><a href="https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086107/" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/alttext-ai/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>appscreo--Easy Social Share Buttons<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31300&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31300" target="_blank">CVE-2024-31300</a><br><a href="https://patchstack.com/database/vulnerability/easy-social-share-buttons3/wordpress-easy-social-share-buttons-plugin-9-4-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>artbees--JupiterX<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in artbees JupiterX allows PHP Local File Inclusion.This issue affects JupiterX: from n/a through 3.0.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32110&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32110" target="_blank">CVE-2023-32110</a><br><a href="https://patchstack.com/database/vulnerability/jupiterx/wordpress-jupiterx-theme-3-0-0-subscriber-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>aws--amazon-redshift-jdbc-driver<br> </td>
<td>The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value. There is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected. This issue is patched in driver version 2.1.0.28. As a workaround, do not use the connection property `preferQueryMode=simple`. (NOTE: Those who do not explicitly specify a query mode use the default of extended query mode and are not affected by this issue.)</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32888&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32888" target="_blank">CVE-2024-32888</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/commit/0d354a5f26ca23f7cac4e800e3b8734220230319" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/commit/12a5e8ecfbb44c8154fc66041cca2e20ecd7b339" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/commit/bc93694201a291493778ce5369a72befeca5ba7d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/security/advisories/GHSA-x3wm-hffr-chwm" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>dataease--dataease<br> </td>
<td>DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in v1.18.19.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31441&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31441" target="_blank">CVE-2024-31441</a><br><a href="https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-7wg6-p5wh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>dotmesh-io--dotmesh<br> </td>
<td>Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations outside the designated target folder. The routine `untarFile` attempts to guard against creating symbolic links that point outside the directory a tar archive is extracted to. However, a malicious tarball first linking `subdir/parent` to `..` (allowed, because `subdir/..` falls within the archive root) and then linking `subdir/parent/escapes` to `..` results in a symbolic link pointing to the tarball's parent directory, contrary to the routine's goals. This issue may lead to arbitrary file write (with same permissions as the program running the unpack operation) if the attacker can control the archive file. Additionally, if the attacker has read access to the unpacked files, they may be able to read arbitrary system files the parent process has permissions to read. As of time of publication, no patch for this issue is available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2020-26312&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2020-26312" target="_blank">CVE-2020-26312</a><br><a href="https://github.com/dotmesh-io/dotmesh/blob/master/pkg/archiver/tar.go#L255" target="_blank">security-advisories@github.com</a><br><a href="https://securitylab.github.com/advisories/GHSL-2020-254-zipslip-dotmesh/" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>eProsima--Fast-DDS<br> </td>
<td>FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves a malformed `RTPS` packet, the subscriber crashes when creating `pthread`. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30258&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30258" target="_blank">CVE-2024-30258</a><br><a href="https://drive.google.com/file/d/19W5UC52hPnAqVq_boZWO45d1TJ4WoCSh/view?usp=sharing" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/eProsima/Fast-DDS/commit/65236f93e9c4ea3ff9a49fba4dfd9e43eb94037b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-53xw-465j-rxfh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>eProsima--Fast-DDS<br> </td>
<td>FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflow occurs on the subscriber. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30259&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30259" target="_blank">CVE-2024-30259</a><br><a href="https://drive.google.com/file/d/1Y2bGvP3UIOJCLh_XEURLdhrM2Sznlvlp/view?usp=sharing" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-qcj9-939p-p662" target="_blank">security-advisories@github.com</a><br><a href="https://vimeo.com/907641887?share=copy" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>freescout-helpdesk--freescout<br> </td>
<td>FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Email Receival Module of the Freescout Application. The vulnerability allows attackers to inject malicious HTML content into emails sent to the application's mailbox. This vulnerability arises from improper handling of HTML content within incoming emails, allowing attackers to embed malicious HTML code in the context of the application's domain. Unauthenticated attackers can exploit this vulnerability to inject malicious HTML content into emails. This could lead to various attacks such as form hijacking, application defacement, or data exfiltration via CSS injection. Although unauthenticated attackers are limited to HTML injection, the consequences can still be severe. Version 1.8.139 implements strict input validation and sanitization mechanisms to ensure that any HTML content received via emails is properly sanitized to prevent malicious HTML injections.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34697&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34697" target="_blank">CVE-2024-34697</a><br><a href="https://github.com/freescout-helpdesk/freescout/commit/99a4b4b4e153c82e273e549b9efbf6db4a2d8328" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/freescout-helpdesk/freescout/security/advisories/GHSA-985r-6qfc-hg8m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>froxlor--Froxlor<br> </td>
<td>Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on the Login attempt, which will then be executed when viewed by the Administrator in the System Logs. By exploiting this vulnerability, the attacker can perform various malicious actions such as forcing the Administrator to execute actions without their knowledge or consent. For instance, the attacker can force the Administrator to add a new administrator controlled by the attacker, thereby giving the attacker full control over the application. This vulnerability is fixed in 2.1.9.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34070&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34070" target="_blank">CVE-2024-34070</a><br><a href="https://github.com/froxlor/Froxlor/commit/a862307bce5cdfb1c208b835f3e8faddd23046e6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/froxlor/Froxlor/security/advisories/GHSA-x525-54hf-xr53" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>getgrav--grav<br> </td>
<td>Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file stores hashed user password, 2FA secret, and the password reset token. This can allow an adversary to compromise any registered account and read any file in the web server by resetting a password for a user to get access to the password reset token from the file or by cracking the hashed password. A low privileged user may also perform a full account takeover of other registered users including Administrators. Version 1.7.46 contains a patch.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34082&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" target="_blank" title="CVSS V3 Score">8.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34082" target="_blank">CVE-2024-34082</a><br><a href="https://github.com/getgrav/grav/commit/b6bba9eb99bf8cb55b8fa8d23f18873ca594e348" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/getgrav/grav/security/advisories/GHSA-f8v5-jmfh-pr69" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32002&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32002" target="_blank">CVE-2024-32002</a><br><a href="https://git-scm.com/docs/git-clone#Documentation/git-clone.txt---recurse-submodulesltpathspecgt" target="_blank">security-advisories@github.com</a><br><a href="https://git-scm.com/docs/git-config#Documentation/git-config.txt-coresymlinks" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/97065761333fd62db1912d81b489db938d8c991d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-8h77-4q3w-gfgv" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32004&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32004" target="_blank">CVE-2024-32004</a><br><a href="https://git-scm.com/docs/git-clone" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/f4aa8c8bb11dae6e769cd930565173808cbb69c8" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-xfc6-vwr8-r389" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32465&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32465" target="_blank">CVE-2024-32465</a><br><a href="https://git-scm.com/docs/git#_security" target="_blank">security-advisories@github.com</a><br><a href="https://git-scm.com/docs/git-clone" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/7b70e9efb18c2cc3f219af399bd384c5801ba1d7" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-vm9j-46j9-qvq4" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>google -- chrome<br> </td>
<td>Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4671&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4671" target="_blank">CVE-2024-4671</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/339266700" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>hakeemnala--Build App Online<br> </td>
<td>The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.21. This is due to missing authentication checking in the 'set_user_cart' function with the 'user_id' header value. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3658&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3658" target="_blank">CVE-2024-3658</a><br><a href="https://plugins.trac.wordpress.org/browser/build-app-online/tags/1.0.21/public/class-build-app-online-public.php#L814" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65d423ad-da51-4616-860d-2b9354d44147?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>hoppscotch--hoppscotch-extension<br> </td>
<td>The Hoppscotch Browser Extension is a browser extension for Hoppscotch, a community-driven end-to-end open-source API development ecosystem. Due to an oversight during a change made to the extension in the commit d4e8e4830326f46ba17acd1307977ecd32a85b58, a critical check for the origin list was missed and allowed for messages to be sent to the extension which the extension gladly processed and responded back with the results of, while this wasn't supposed to happen and be blocked by the origin not being present in the origin list. This vulnerability exposes Hoppscotch Extension users to sites which call into Hoppscotch Extension APIs internally. This fundamentally allows any site running on the browser with the extension installed to bypass CORS restrictions if the user is running extensions with the given version. This security hole was patched in the commit 7e364b928ab722dc682d0fcad713a96cc38477d6 which was released along with the extension version `0.35`. As a workaround, Chrome users can use the Extensions Settings to disable the extension access to only the origins that you want. Firefox doesn't have an alternative to upgrading to a fixed version.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34714" target="_blank">CVE-2024-34714</a><br><a href="https://github.com/hoppscotch/hoppscotch-extension/commit/7e364b928ab722dc682d0fcad713a96cc38477d6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/hoppscotch/hoppscotch-extension/commit/d4e8e4830326f46ba17acd1307977ecd32a85b58" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/hoppscotch/hoppscotch-extension/security/advisories/GHSA-jjh5-pvqx-gg5v" target="_blank">security-advisories@github.com</a><br><a href="https://server.yadhu.in/poc/hoppscotch-poc.html" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>icegram--Email Subscribers by Icegram Express Email Marketing, Newsletters, Automation for WordPress &amp; WooCommerce<br> </td>
<td>The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to cause a loss of confidentiality, integrity, and availability, by performing multiple unauthorized actions. Some of these actions could also be leveraged to conduct PHP Object Injection and SQL Injection attacks.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4010&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4010" target="_blank">CVE-2024-4010</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083762/email-subscribers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/23bfcdd1-b99d-47eb-9f88-96f9ecc53b32?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>jetmonsters--Hotel Booking Lite<br> </td>
<td>The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4413&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4413" target="_blank">CVE-2024-4413</a><br><a href="https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/trunk/includes/shortcodes/checkout-shortcode/step-checkout.php#L149" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3084187%40motopress-hotel-booking-lite%2Ftrunk&amp;old=3081058%40motopress-hotel-booking-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d7f1283-a274-49a2-8bec-da178771b13a?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>jottlieb--Last Viewed Posts by WPBeginner<br> </td>
<td>The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input from the LastViewedPosts Cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3070&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3070" target="_blank">CVE-2024-3070</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3062246%40last-viewed-posts&amp;new=3062246%40last-viewed-posts&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6c5cc05-b147-46f6-aaa9-4c82aae1b544?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>kognetiks--Kognetiks Chatbot for WordPress<br> </td>
<td>The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files on the affected site's server which may make remote code execution possible.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4560&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4560" target="_blank">CVE-2024-4560</a><br><a href="https://plugins.trac.wordpress.org/browser/chatbot-chatgpt/trunk/includes/utilities/chatbot-file-upload.php#L17" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7bc33a05-d462-492e-9ea5-cf37b887cc94?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>lobehub--lobe-chat<br> </td>
<td>Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32964&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32964" target="_blank">CVE-2024-32964</a><br><a href="https://github.com/lobehub/lobe-chat/commit/465665a735556669ee30446c7ea9049a20cc7c37" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/lobehub/lobe-chat/security/advisories/GHSA-mxhq-xw3g-rphc" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>mantisbt--mantisbt<br> </td>
<td>MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset another user's password and takeover their account, if the victim has an incomplete request pending. The exploit is only possible while the verification token is valid, i.e for 5 minutes after the confirmation URL sent by e-mail has been opened, and the user did not complete the process by updating their password. A brute-force attack calling account_update.php with increasing user IDs is possible. A successful takeover would grant the attacker full access to the compromised account, including sensitive information and functionalities associated with the account, the extent of which depends on its privileges and the data it has access to. Version 2.26.2 contains a patch for the issue. As a workaround, one may mitigate the risk by reducing the verification token's validity (change the value of the `TOKEN_EXPIRY_AUTHENTICATED` constant in `constants_inc.php`).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34077&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34077" target="_blank">CVE-2024-34077</a><br><a href="https://github.com/mantisbt/mantisbt/commit/92d11a01b195a1b6717a2f205218089158ea6d00" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/security/advisories/GHSA-93x3-m7pw-ppqm" target="_blank">security-advisories@github.com</a><br><a href="https://mantisbt.org/bugs/view.php?id=34433" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>metaphorcreations--Ditty Responsive News Tickers, Sliders, and Lists<br> </td>
<td>The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a new ditty. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3954" target="_blank">CVE-2024-3954</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081335%40ditty-news-ticker&amp;new=3081335%40ditty-news-ticker&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0f00b138-5c4b-4f75-94b1-82721cba2668?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>micromatch--braces<br> </td>
<td>The NPM package `braces` fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4068&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4068" target="_blank">CVE-2024-4068</a><br><a href="https://devhub.checkmarx.com/cve-details/CVE-2024-4068/" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/braces/blob/98414f9f1fabe021736e26836d8306d5de747e0d/lib/parse.js#L308" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/braces/issues/35" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a></td>
</tr>
<tr>
<td>micromatch--micromatch<br> </td>
<td>The NPM package `micromatch` is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4067&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4067" target="_blank">CVE-2024-4067</a><br><a href="https://devhub.checkmarx.com/cve-details/CVE-2024-4067/" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/micromatch/blob/2c56a8604b68c1099e7bc0f807ce0865a339747a/index.js#L448" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/micromatch/issues/243" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/micromatch/pull/247" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a></td>
</tr>
<tr>
<td>microsoft -- windows_10_1507<br> </td>
<td>Windows MSHTML Platform Security Feature Bypass Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30040&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30040" target="_blank">CVE-2024-30040</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30040" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>microsoft -- windows_10_1507<br> </td>
<td>Windows DWM Core Library Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30051&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30051" target="_blank">CVE-2024-30051</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30051" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>miniOrange--WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn)<br> </td>
<td>Improper Privilege Management vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Privilege Escalation.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47683&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47683" target="_blank">CVE-2023-47683</a><br><a href="https://patchstack.com/database/vulnerability/miniorange-login-openid/wordpress-social-login-social-sharing-by-miniorange-plugin-7-6-6-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>monetizemore--Advanced Ads  Ad Manager &amp; AdSense<br> </td>
<td>The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untrusted input in the 'placement_slug' parameter. This makes it possible for authenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2290&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2290" target="_blank">CVE-2024-2290</a><br><a href="https://plugins.trac.wordpress.org/browser/advanced-ads/trunk/modules/import-export/classes/import.php#L155" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081914%40advanced-ads&amp;new=3081914%40advanced-ads&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f64336f7-ab2a-4e22-a76f-d077c51f9c57?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Arc(TM) &amp; Iris(R) Xe Graphics software<br> </td>
<td>Improper neutralization in some Intel(R) Arc(TM) &amp; Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21864&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21864" target="_blank">CVE-2024-21864</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01053.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) BIOS Guard firmware<br> </td>
<td>Improper conditions check in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-27504&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-27504" target="_blank">CVE-2023-27504</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00814.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) BIOS Guard firmware<br> </td>
<td>Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-28402&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-28402" target="_blank">CVE-2023-28402</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00814.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DTT software installers<br> </td>
<td>Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21813&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">7.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21813" target="_blank">CVE-2024-21813</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00984.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware<br> </td>
<td>Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-37341&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-37341" target="_blank">CVE-2022-37341</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00756.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA Framework software installers<br> </td>
<td>Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43748&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43748" target="_blank">CVE-2023-43748</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software installers<br> </td>
<td>Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-24460&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24460" target="_blank">CVE-2023-24460</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software installers<br> </td>
<td>Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40071&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40071" target="_blank">CVE-2023-40071</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software installers<br> </td>
<td>Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43629&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43629" target="_blank">CVE-2023-43629</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Neural Compressor software<br> </td>
<td>Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22476" target="_blank">CVE-2024-22476</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01109.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Buffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38581&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38581" target="_blank">CVE-2023-38581</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-42773&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42773" target="_blank">CVE-2023-42773</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45217&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45217" target="_blank">CVE-2023-45217</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Use after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46691&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:H" target="_blank" title="CVSS V3 Score">7.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46691" target="_blank">CVE-2023-46691</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40070&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40070" target="_blank">CVE-2023-40070</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46689&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46689" target="_blank">CVE-2023-46689</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Stratix 10 and Intel(R) Agilex 7 FPGAs<br> </td>
<td>Unchecked return value in SDM firmware for Intel(R) Stratix 10 and Intel(R) Agilex 7 FPGAs before version 23.3 may allow an authenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41092&amp;vector=CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41092" target="_blank">CVE-2023-41092</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01007.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) TDX module software<br> </td>
<td>Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45745&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45745" target="_blank">CVE-2023-45745</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Thunderbolt driver software<br> </td>
<td>Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-37410&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-37410" target="_blank">CVE-2022-37410</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00916.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products<br> </td>
<td>Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22382&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22382" target="_blank">CVE-2024-22382</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server D50DNP Family products<br> </td>
<td>Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22095&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22095" target="_blank">CVE-2024-22095</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server D50DNP Family products<br> </td>
<td>Improper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23487&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23487" target="_blank">CVE-2024-23487</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server D50FCP Family products<br> </td>
<td>Improper buffer restrictions in PlatformPfrDxe driver in UEFI firmware for some Intel(R) Server D50FCP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23980&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23980" target="_blank">CVE-2024-23980</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server M50FCP Family products<br> </td>
<td>Improper input validation in PfrSmiUpdateFw driver in UEFI firmware for some Intel(R) Server M50FCP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24981&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24981" target="_blank">CVE-2024-24981</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (An attacker must already have user privileges)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31954&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31954" target="_blank">CVE-2024-31954</a><br><a href="https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31954/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--some Intel(R) PROSet/Wireless WiFi software for Windows<br> </td>
<td>Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38654&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38654" target="_blank">CVE-2023-38654</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>nautobot--nautobot<br> </td>
<td>Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration settings via the `/admin/constance/config/` endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of `BANNER_LOGIN`) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS). The vulnerability is fixed in Nautobot 1.6.22 and 2.2.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34707&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34707" target="_blank">CVE-2024-34707</a><br><a href="https://github.com/nautobot/nautobot/commit/4f0a66bd6307bfe0e0acb899233e0d4ad516f51c" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/commit/f640aedc69c848d3d1be57f0300fc40033ff6423" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/pull/5697" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/pull/5698" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/security/advisories/GHSA-r2hr-4v48-fjv3" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nocodb--nocodb<br> </td>
<td>NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The nc-gui/components/virtual-cell/Formula.vue displays a v-html tag with the value of "urls" whose contents are processed by the function replaceUrlsWithLink(). This function recognizes the pattern URI::(XXX) and creates a hyperlink tag &lt;a&gt; with href=XXX. However, it leaves all the other contents outside of the pattern URI::(XXX) unchanged. This vulnerability is fixed in 0.202.9.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-49781&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-49781" target="_blank">CVE-2023-49781</a><br><a href="https://github.com/nocodb/nocodb/commit/7f58ce3726dfec71537d8b80474a0f95a48a1574" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-h6r4-xvw6-jc5h" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>npgsql--npgsql<br> </td>
<td>Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of parameter lengths. Both variables overflow when the sum of parameter lengths becomes too large. This causes Npgsql to write a message size that is too small when constructing a Postgres protocol message to send it over the network to the database. When parsing the message, the database will only read a small number of bytes and treat any following bytes as new messages while they belong to the old message. Attackers can abuse this to inject arbitrary Postgres protocol messages into the connection, leading to the execution of arbitrary SQL statements on the application's behalf. This vulnerability is fixed in 4.0.14, 4.1.13, 5.0.18, 6.0.11, 7.0.7, and 8.0.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32655&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32655" target="_blank">CVE-2024-32655</a><br><a href="https://github.com/npgsql/npgsql/commit/091655eed0c84e502ab424950c930339d17c1928" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/3183efb2bdcca159c8c2e22af57e18ea8f853cf0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/67acbe027e28477ac2199e15cfb554bb2ffaf169" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/703d9af8fa48dfe8c0180e36edb8278f34342d7b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/a22a42d8141d7a3528f43c02c095a409507cf1af" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/e34e2ba8042e666d9af54a1b255fba4d5b11df56" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/f7e7ead0702d776a8f551f5786c4cac2d65c4bc6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v4.0.14" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v4.1.13" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v5.0.18" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v6.0.11" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v7.0.7" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v8.0.3" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/security/advisories/GHSA-x9vc-6hfv-hg8c" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nvidia--ChatRTX<br> </td>
<td>NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege management issue by sending user inputs to change execution flow. A successful exploit of this vulnerability might lead to information disclosure, escalation of privileges, and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0096&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0096" target="_blank">CVE-2024-0096</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5533" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--ChatRTX<br> </td>
<td>NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege management issue by exploiting interprocess communication between different processes. A successful exploit of this vulnerability might lead to information disclosure, escalation of privileges, and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0097&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0097" target="_blank">CVE-2024-0097</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5533" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--NVIDIA Triton Inference Server<br> </td>
<td>NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0087&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0087" target="_blank">CVE-2024-0087</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5535" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>pencidesign--Penci Soledad Data Migrator<br> </td>
<td>The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0 via the 'data' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included. This is limited to just PHP files.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3551&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3551" target="_blank">CVE-2024-3551</a><br><a href="https://themeforest.net/item/soledad-multiconcept-blogmagazine-wp-theme/12945398" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a4f8df3a-f247-4365-a9f6-6124065b4883?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>plainware--ShiftController Employee Shift Scheduling<br> </td>
<td>The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the `hc3_session`-cookie in versions up to, and including, 4.9.57. This makes it possible for an authenticated attacker with contributor access-level or above to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4733&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4733" target="_blank">CVE-2024-4733</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3087047%40shiftcontroller%2Ftrunk&amp;old=3080165%40shiftcontroller%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9c8ab916-240d-43c3-92d4-7efd75862a5e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>plugins360--All-in-One Video Gallery<br> </td>
<td>The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_search_form shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4670&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4670" target="_blank">CVE-2024-4670</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085217/all-in-one-video-gallery" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e2793547-5edf-4d2a-bc3b-fcaeed62963d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>powerfulwp--Local Delivery Drivers for WooCommerce<br> </td>
<td>Improper Privilege Management vulnerability in powerfulwp Local Delivery Drivers for WooCommerce allows Privilege Escalation.This issue affects Local Delivery Drivers for WooCommerce: from n/a through 1.9.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51481&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51481" target="_blank">CVE-2023-51481</a><br><a href="https://patchstack.com/database/vulnerability/local-delivery-drivers-for-woocommerce/wordpress-local-delivery-drivers-for-woocommerce-plugin-1-9-0-unauthenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ravanh--XML Sitemap &amp; Google News<br> </td>
<td>The XML Sitemap &amp; Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.8 via the 'feed' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4441&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4441" target="_blank">CVE-2024-4441</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3082081%40xml-sitemap-feed&amp;new=3082081%40xml-sitemap-feed&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/87888350-1230-4fec-9de2-c58fa24e6a05?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smp7, wp.insider--Simple Membership<br> </td>
<td>Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41956" target="_blank">CVE-2023-41956</a><br><a href="https://patchstack.com/database/vulnerability/simple-membership/wordpress-simple-membership-plugin-4-3-4-authenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>smp7, wp.insider--Simple Membership<br> </td>
<td>Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41957&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41957" target="_blank">CVE-2023-41957</a><br><a href="https://patchstack.com/database/vulnerability/simple-membership/wordpress-simple-membership-plugin-4-3-4-unauthenticated-membership-role-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>spacemeshos--go-spacemesh<br> </td>
<td>go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATXs) which reference the incorrect previous ATX of the Smesher that created the ATX. ATXs are expected to form a single chain from the newest to the first ATX ever published by an identity. Allowing Smeshers to reference an earlier (but not the latest) ATX as previous breaks this protocol rule and can serve as an attack vector where Nodes are rewarded for holding their PoST data for less than one epoch but still being eligible for rewards. This vulnerability is fixed in go-spacemesh 1.5.2-hotfix1 and Spacemesh API 1.37.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34360&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34360" target="_blank">CVE-2024-34360</a><br><a href="https://github.com/spacemeshos/api/commit/1d5bd972bbe225d024c3e0ae5214ddb6b481716e" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/spacemeshos/go-spacemesh/commit/9aff88d54be809ac43d60e8a8b4d65359c356b87" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/spacemeshos/go-spacemesh/security/advisories/GHSA-jcqq-g64v-gcm7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>spoonthemes--Adifier System<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spoonthemes Adifier System allows PHP Local File Inclusion.This issue affects Adifier System: from n/a before 3.1.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-49753&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-49753" target="_blank">CVE-2023-49753</a><br><a href="https://patchstack.com/database/vulnerability/adifier-system/wordpress-adifier-classified-ads-wordpress-theme-theme-3-9-3-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>stalwartlabs--mail-server<br> </td>
<td>Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, system services are run as a separate user (not as root) to isolate an attacker with Arbitrary Code Execution to the current service. Therefore, other system services and the system itself remains protected in case of a successful attack. stalwart-mail runs as a separate user, but it can give itself full privileges again in a simple way, so this protection is practically ineffective. Server admins who handed out the admin credentials to the mail server, but didn't want to hand out complete root access to the system, as well as any attacked user when the attackers gained Arbitrary Code Execution using another vulnerability, may be vulnerable. Version 0.8.0 contains a patch for the issue.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35187&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35187" target="_blank">CVE-2024-35187</a><br><a href="https://github.com/stalwartlabs/mail-server/security/advisories/GHSA-rwp5-f854-ppg6" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>strongSwan--strongSwan<br> </td>
<td>strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-4967&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-4967" target="_blank">CVE-2022-4967</a><br><a href="https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136" target="_blank">security@ubuntu.com</a><br><a href="https://www.cve.org/CVERecord?id=CVE-2022-4967" target="_blank">security@ubuntu.com</a><br><a href="https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html" target="_blank">security@ubuntu.com</a></td>
</tr>
<tr>
<td>supsystic.com--Popup by Supsystic<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46197&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46197" target="_blank">CVE-2023-46197</a><br><a href="https://patchstack.com/database/vulnerability/popup-by-supsystic/wordpress-popup-by-supsystic-plugin-1-10-19-unauthenticated-subscriber-email-addresses-disclosure?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2771&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2771" target="_blank">CVE-2024-2771</a><br><a href="https://plugins.trac.wordpress.org/changeset/3088078/fluentform/trunk/app/Http/Policies/RoleManagerPolicy.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/071195d6-3452-4241-a8d3-92efc84e4850?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2782&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2782" target="_blank">CVE-2024-2782</a><br><a href="https://plugins.trac.wordpress.org/changeset/3088078/fluentform/trunk/app/Http/Policies/GlobalSettingsPolicy.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0814e7b3-404a-4db5-b564-46c9086ec048?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, and access granted by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4709&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4709" target="_blank">CVE-2024-4709</a><br><a href="https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Services/FormBuilder/Notifications/EmailNotification.php#L106" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Services/FormBuilder/Notifications/EmailNotification.php#L164" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Services/FormBuilder/Notifications/EmailNotification.php#L194" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3088078/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5fe317a6-a391-441a-aac8-c8fa57e73169?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeisle--Visualizer: Tables and Charts Manager for WordPress<br> </td>
<td>The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on the getQueryData() function in all versions up to, and including, 3.10.15. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform arbitrary SQL queries that can be leveraged for privilege escalation among many other actions.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3750&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3750" target="_blank">CVE-2024-3750</a><br><a href="https://plugins.trac.wordpress.org/browser/visualizer/trunk/classes/Visualizer/Module/Chart.php#L1421" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086048/visualizer/tags/3.11.0/classes/Visualizer/Module/Chart.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086048/visualizer/tags/3.11.0/classes/Visualizer/Source/Query.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d27544c-97a5-42cd-ab07-358f819acbc4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeum--Tutor LMS eLearning and online course solution<br> </td>
<td>The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete data.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4223&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4223" target="_blank">CVE-2024-4223</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086489/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ce4c4395-6d1a-4d5f-885f-383e5c44c0f8?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeum--Tutor LMS eLearning and online course solution<br> </td>
<td>The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the 'question_id' parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Instructor-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4318&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4318" target="_blank">CVE-2024-4318</a><br><a href="https://plugins.trac.wordpress.org/browser/tutor/tags/2.7.0/classes/Utils.php#L4456" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/tutor/tags/2.7.0/classes/Utils.php#L4575" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086489/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9bbb3c65-f02c-4d6d-bd4e-b3232af5e21b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themium--Tutor LMS Pro<br> </td>
<td>The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existing administrator account.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4351&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4351" target="_blank">CVE-2024-4351</a><br><a href="https://www.themeum.com/product/tutor-lms/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59859583-49e5-4a80-8659-b9ca7ddc089d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themium--Tutor LMS Pro<br> </td>
<td>The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the 'year' parameter of that function due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4352&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4352" target="_blank">CVE-2024-4352</a><br><a href="https://www.themeum.com/product/tutor-lms/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c647beda-cf73-4372-975f-a8c8ed05217f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themium--Tutor LMS Pro<br> </td>
<td>The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4222&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4222" target="_blank">CVE-2024-4222</a><br><a href="https://www.themeum.com/product/tutor-lms/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/942fffb6-2719-4b70-9759-21b2d50002c5?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'term_id' parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4434&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4434" target="_blank">CVE-2024-4434</a><br><a href="https://inky-knuckle-2c2.notion.site/Unauthenticated-SQLI-in-Learnpress-plugin-Latest-Version-4-2-6-5-a86fe63bcc7b4c9988802688211817fd?pvs=25" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/Databases/class-lp-course-db.php#L508" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082204/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2d64e1c6-1e25-4438-974d-b7da0979cc40?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_post_materials' function in versions up to, and including, 4.2.6.5. This makes it possible for authenticated attackers, with Instructor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4397&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4397" target="_blank">CVE-2024-4397</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/rest-api/v1/frontend/class-lp-rest-material-controller.php#L98" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083657/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ec20d5c4-4c41-4ec9-8d0a-ec8f03634f7d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>unitecms--Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<br> </td>
<td>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3055&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3055" target="_blank">CVE-2024-3055</a><br><a href="https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/tags/1.5.93/inc_php/framework/db.class.php#L238" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081509%40unlimited-elements-for-elementor%2Ftrunk&amp;old=3076456%40unlimited-elements-for-elementor%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ebc0c8e6-a365-4ef7-9c1a-41454855096c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>unitecms--Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<br> </td>
<td>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for authenticated attackers, with administrator-level access and above, to execute arbitrary commands on the server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2662&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2662" target="_blank">CVE-2024-2662</a><br><a href="https://plugins.trac.wordpress.org/changeset/3071404/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_template_engine.class.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/58492dbb-b9e0-4477-b85d-ace06dba954c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>valtimo-platform--valtimo-frontend-libraries<br> </td>
<td>Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access token (JWT) of the user is exposed to `api.form.io` via the the `x-jwt-token` header. An attacker can retrieve personal information from this token, or use it to execute requests to the Valtimo REST API on behalf of the logged-in user. This issue is caused by a misconfiguration of the Form.io component. The following conditions have to be met in order to perform this attack: An attacker needs to have access to the network traffic on the `api.form.io` domain; the content of the `x-jwt-token` header is logged or otherwise available to the attacker; an attacker needs to have network access to the Valtimo API; and an attacker needs to act within the time-to-live of the access token. The default TTL in Keycloak is 5 minutes. Versions 10.8.4, 11.1.6 and 11.2.2 have been patched.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34706&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34706" target="_blank">CVE-2024-34706</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/commit/1aaba5ef5750dafebbc7476fb08bf2375a25f19e" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/commit/8c2dbf2a41180d2b0358d878290e4d37168f0fb6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/commit/d65e05fd2784bd4a628778b34a5b79ce2f0cef8c" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/security/advisories/GHSA-xcp4-62vj-cq3r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>vendor or project--product name<br> </td>
<td>A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2021-22508&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-22508" target="_blank">CVE-2021-22508</a><br><a href="https://support.microfocus.com/kb/kmdoc.php?id=KM03793174" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>vercel--next.js<br> </td>
<td>Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request to be exploitable, the affected route also had to be making use of the [rewrites](https://nextjs.org/docs/app/api-reference/next-config-js/rewrites) feature in Next.js. The vulnerability is resolved in Next.js `13.5.1` and newer.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34350&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34350" target="_blank">CVE-2024-34350</a><br><a href="https://github.com/vercel/next.js/security/advisories/GHSA-77r5-gw3j-2mpf" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>vercel--next.js<br> </td>
<td>Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vulnerability was fixed in Next.js `14.1.1`.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34351&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34351" target="_blank">CVE-2024-34351</a><br><a href="https://github.com/vercel/next.js/commit/8f7a6ca7d21a97bc9f7a1bbe10427b5ad74b9085" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/vercel/next.js/pull/62561" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/vercel/next.js/security/advisories/GHSA-fr5h-rqp8-mj6g" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>weDevs--WP User Frontend<br> </td>
<td>Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47682&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47682" target="_blank">CVE-2023-47682</a><br><a href="https://patchstack.com/database/vulnerability/wp-user-frontend/wordpress-wp-user-frontend-plugin-3-6-5-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>wpForo--wpForo Forum<br> </td>
<td>Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47868&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47868" target="_blank">CVE-2023-47868</a><br><a href="https://patchstack.com/database/vulnerability/wpforo/wordpress-wpforo-plugin-2-2-3-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>
<div>
<h2>Medium Vulnerabilities</h2>
<table summary="Medium Vulnerabilities" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>10Web Form Builder Team--Form Maker by 10Web<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.24.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34437&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34437" target="_blank">CVE-2024-34437</a><br><a href="https://patchstack.com/database/vulnerability/form-maker/wordpress-form-maker-by-10web-plugin-1-15-24-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>1Panel-dev--1Panel<br> </td>
<td>1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `&gt;` can be used to achieve arbitrary file writing. This vulnerability is fixed in v1.10.3-lts.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34352&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34352" target="_blank">CVE-2024-34352</a><br><a href="https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-f8ch-w75v-c847" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>ABB--RobotWare 6<br> </td>
<td>An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is processed by the system. Below are reported vulnerabilities in the Robot Ware versions. * IRC5- RobotWare 6 &lt; 6.15.06 except 6.10.10, and 6.13.07 * OmniCore- RobotWare 7 &lt; 7.14</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1914&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1914" target="_blank">CVE-2024-1914</a><br><a href="https://search.abb.com/library/Download.aspx?DocumentID=SI20330&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>AREOI--All Bootstrap Blocks<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AREOI All Bootstrap Blocks allows Stored XSS.This issue affects All Bootstrap Blocks: from n/a through 1.3.15.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35169&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35169" target="_blank">CVE-2024-35169</a><br><a href="https://patchstack.com/database/vulnerability/all-bootstrap-blocks/wordpress-all-bootstrap-blocks-plugin-1-3-15-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AROX SOLUTION--School ERP Pro+Responsive<br> </td>
<td>Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the username and password parameters in '/index.php'. This vulnerability allows an attacker to partially take control of the victim's browser session.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4822&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4822" target="_blank">CVE-2024-4822</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-school-erp-proresponsive-arox-solution" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>AROX SOLUTION--School ERP Pro+Responsive<br> </td>
<td>Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4823&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4823" target="_blank">CVE-2024-4823</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-school-erp-proresponsive-arox-solution" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Academy LMS--Academy LMS<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35171&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35171" target="_blank">CVE-2024-35171</a><br><a href="https://patchstack.com/database/vulnerability/academy/wordpress-academy-lms-plugin-1-9-25-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Adam DeHaven--Perfect Pullquotes<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfect Pullquotes allows Stored XSS.This issue affects Perfect Pullquotes: from n/a through 1.7.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33951&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33951" target="_blank">CVE-2024-33951</a><br><a href="https://patchstack.com/database/vulnerability/perfect-pullquotes/wordpress-perfect-pullquotes-plugin-1-7-5-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30311&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30311" target="_blank">CVE-2024-30311</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30312&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30312" target="_blank">CVE-2024-30312</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34101&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34101" target="_blank">CVE-2024-34101</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30283&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30283" target="_blank">CVE-2024-30283</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30286&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30286" target="_blank">CVE-2024-30286</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30287&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30287" target="_blank">CVE-2024-30287</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30298&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30298" target="_blank">CVE-2024-30298</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Illustrator<br> </td>
<td>Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20793&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20793" target="_blank">CVE-2024-20793</a><br><a href="https://helpx.adobe.com/security/products/illustrator/apsb24-30.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Designer<br> </td>
<td>Substance3D - Designer versions 13.1.1 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30281&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30281" target="_blank">CVE-2024-30281</a><br><a href="https://helpx.adobe.com/security/products/substance3d_designer/apsb24-35.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30308&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30308" target="_blank">CVE-2024-30308</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30309&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30309" target="_blank">CVE-2024-30309</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Aleksei Polechin (alek)--Archives Calendar Widget<br> </td>
<td>Administrator Cross Site Scripting (XSS) in Archives Calendar Widget &lt;= 1.0.15 versions.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33950&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33950" target="_blank">CVE-2024-33950</a><br><a href="https://patchstack.com/database/vulnerability/archives-calendar-widget/wordpress-archives-calendar-widget-plugin-1-0-15-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AlexaCRM--Dynamics 365 Integration<br> </td>
<td>Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34550&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34550" target="_blank">CVE-2024-34550</a><br><a href="https://patchstack.com/database/vulnerability/integration-dynamics/wordpress-dynamics-365-integration-plugin-1-3-17-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Andy Moyle--Church Admin<br> </td>
<td>Missing Authorization vulnerability in Andy Moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through 4.1.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31281&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31281" target="_blank">CVE-2024-31281</a><br><a href="https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-1-6-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Andy Moyle--Church Admin<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.32.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34828&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34828" target="_blank">CVE-2024-34828</a><br><a href="https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-1-32-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AppPresser Team--AppPresser<br> </td>
<td>Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32776&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32776" target="_blank">CVE-2024-32776</a><br><a href="https://patchstack.com/database/vulnerability/apppresser/wordpress-apppresser-plugin-4-3-0-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Artbees--SellKit<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Artbees SellKit allows Relative Path Traversal.This issue affects SellKit: from n/a through 1.8.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30509&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30509" target="_blank">CVE-2024-30509</a><br><a href="https://patchstack.com/database/vulnerability/sellkit/wordpress-sellkit-plugin-1-8-1-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Atanas Yonkov--Pliska<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atanas Yonkov Pliska allows Stored XSS.This issue affects Pliska: from n/a through 0.3.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33954" target="_blank">CVE-2024-33954</a><br><a href="https://patchstack.com/database/vulnerability/pliska/wordpress-pliska-theme-0-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Automattic--WP Job Manager<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.2.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34549&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34549" target="_blank">CVE-2024-34549</a><br><a href="https://patchstack.com/database/vulnerability/wp-job-manager/wordpress-wp-job-manager-plugin-2-2-2-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>BdThemes--Ultimate Store Kit Elementor Addons<br> </td>
<td>Deserialization of Untrusted Data vulnerability in BdThemes Ultimate Store Kit Elementor Addons.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 1.6.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4606&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4606" target="_blank">CVE-2024-4606</a><br><a href="https://patchstack.com/database/vulnerability/ultimate-store-kit/wordpress-ultimate-store-kit-elementor-addons-woocommerce-builder-edd-builder-plugin-1-6-2-php-object-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Benoti--Brozzme Scroll Top<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benoti Brozzme Scroll Top allows Stored XSS.This issue affects Brozzme Scroll Top: from n/a through 1.8.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34426&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34426" target="_blank">CVE-2024-34426</a><br><a href="https://patchstack.com/database/vulnerability/brozzme-scroll-top/wordpress-brozzme-scroll-top-plugin-1-8-5-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>BestWebSoft--Captcha by BestWebSoft<br> </td>
<td>Guessable CAPTCHA vulnerability in BestWebSoft Captcha by BestWebSoft allows Functionality Bypass.This issue affects Captcha by BestWebSoft: from n/a through 5.2.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31295&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31295" target="_blank">CVE-2024-31295</a><br><a href="https://patchstack.com/database/vulnerability/captcha-bws/wordpress-captcha-by-bestwebsoft-plugin-5-2-0-captcha-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>BetterAddons--Better Elementor Addons<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Better Elementor Addons better-elementor-addons allows Stored XSS.This issue affects Better Elementor Addons: from n/a through 1.4.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34432&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34432" target="_blank">CVE-2024-34432</a><br><a href="https://patchstack.com/database/vulnerability/better-elementor-addons/wordpress-better-elementor-addons-plugin-1-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Bootstrapped Ventures--Easy Affiliate Links<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bootstrapped Ventures Easy Affiliate Links allows Stored XSS.This issue affects Easy Affiliate Links: from n/a through 3.7.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34441&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34441" target="_blank">CVE-2024-34441</a><br><a href="https://patchstack.com/database/vulnerability/easy-affiliate-links/wordpress-easy-affiliate-links-plugin-3-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for Beaver Builder<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Relative Path Traversal.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.13.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51401&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51401" target="_blank">CVE-2023-51401</a><br><a href="https://patchstack.com/database/vulnerability/bb-ultimate-addon/wordpress-ultimate-addons-for-beaver-builder-premium-plugin-1-35-13-limited-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Byzoro--Smart S200 Management Platform<br> </td>
<td>A vulnerability was found in Byzoro Smart S200 Management Platform up to 20240507. It has been rated as critical. This issue affects some unknown processing of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264437 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4904&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4904" target="_blank">CVE-2024-4904</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264437" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264437" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330636" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>CRM Perks--Integration for Contact Form 7 HubSpot<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 HubSpot.This issue affects Integration for Contact Form 7 HubSpot: from n/a through 1.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34756&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34756" target="_blank">CVE-2024-34756</a><br><a href="https://patchstack.com/database/vulnerability/cf7-hubspot/wordpress-integration-for-hubspot-and-contact-form-7-plugin-1-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CRM Perks--Integration for Contact Form 7 and Salesforce<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Salesforce.This issue affects Integration for Contact Form 7 and Salesforce: from n/a through 1.3.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34755&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34755" target="_blank">CVE-2024-34755</a><br><a href="https://patchstack.com/database/vulnerability/cf7-salesforce/wordpress-integration-for-salesforce-and-contact-form-7-wpforms-elementor-formidable-ninja-forms-plugin-1-3-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CRM Perks--Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34817&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34817" target="_blank">CVE-2024-34817</a><br><a href="https://patchstack.com/database/vulnerability/integration-for-contact-form-7-and-pipedrive/wordpress-integration-for-pipedrive-and-contact-form-7-wpforms-elementor-ninja-forms-plugin-1-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained cookies. This issue is fixed in commit a38b9046e9772612fda847b46308f9391a49891e.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30268&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30268" target="_blank">CVE-2024-30268</a><br><a href="https://github.com/Cacti/cacti/blob/08497b8bcc6a6037f7b1aae303ad8f7dfaf7364e/settings.php#L66" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/a38b9046e9772612fda847b46308f9391a49891e" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-9m3v-whmr-pc2q" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in SQL injection. Using SQL based secondary injection technology, attackers can modify the contents of the Cacti database, and based on the modified content, it may be possible to achieve further impact, such as arbitrary file reading, and even remote code execution through arbitrary file writing. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31460&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31460" target="_blank">CVE-2024-31460</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-cx8g-hvq8-p2rv" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-gj3f-p326-gh8r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others). However, it still generates the code out of unescaped PHP variables `$title` and `$header`. If those variables contain single quotes, they can be used to inject JavaScript code. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. Version 1.2.27 fixes this issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29894&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29894" target="_blank">CVE-2024-29894</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-grj5-8fcj-34gh" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31443&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31443" target="_blank">CVE-2024-31443</a><br><a href="https://github.com/Cacti/cacti/commit/f946fa537d19678f938ddbd784a10e3290d275cf" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-rqc8-78cm-85j3" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31444&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">4.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31444" target="_blank">CVE-2024-31444</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-p4ch-7hjw-6m87" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from `lib/html_form_templates.php` , finally resulting in SQL injection. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31458&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">4.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31458" target="_blank">CVE-2024-31458</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-jrxg-8wh8-943x" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/show_student1.php. The manipulation of the argument grade leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264441 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4906&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4906" target="_blank">CVE-2024-4906</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%202.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264441" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264441" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333292" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/show_student2.php. The manipulation of the argument grade leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264442 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4907&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4907" target="_blank">CVE-2024-4907</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%203.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264442" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264442" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333293" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264443.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4908&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4908" target="_blank">CVE-2024-4908</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%204.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264443" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264443" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333294" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /view/student_due_payment.php. The manipulation of the argument due_year leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264444.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4909&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4909" target="_blank">CVE-2024-4909</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%205.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264444" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264444" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333295" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/student_exam_mark_insert_form1.php. The manipulation of the argument grade leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264445 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4910&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4910" target="_blank">CVE-2024-4910</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%206.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264445" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264445" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333296" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/student_exam_mark_update_form.php. The manipulation of the argument exam leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264446 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4911&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4911" target="_blank">CVE-2024-4911</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%207.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264446" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264446" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333297" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/general-setting of the component Setting Handler. The manipulation of the argument favicon/logo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263622 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4681&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4681" target="_blank">CVE-2024-4681</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/file_upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263622" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263622" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331468" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability classified as critical has been found in Campcodes Online Examination System 1.0. This affects an unknown part of the file addExamExe.php. The manipulation of the argument examTitle leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264447.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4912&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4912" target="_blank">CVE-2024-4912</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_addExamExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264447" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264447" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333402" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability classified as critical was found in Campcodes Online Examination System 1.0. This vulnerability affects unknown code of the file exam.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264448.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4913&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4913" target="_blank">CVE-2024-4913</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_exam.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264448" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264448" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333403" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. This issue affects some unknown processing of the file ranking-exam.php. The manipulation of the argument exam_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264449 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4914&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4914" target="_blank">CVE-2024-4914</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_ranking-exam.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264449" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264449" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333407" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file result.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264450 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4915&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4915" target="_blank">CVE-2024-4915</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_result.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264450" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264450" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333408" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file selExamAttemptExe.php. The manipulation of the argument thisId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264451.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4916&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4916" target="_blank">CVE-2024-4916</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_selExamAttemptExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264451" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264451" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333409" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file submitAnswerExe.php. The manipulation of the argument exmne_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264452.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4917&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4917" target="_blank">CVE-2024-4917</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_submitAnswerExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264452" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264452" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333410" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. This affects an unknown part of the file updateQuestion.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264453 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4918&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4918" target="_blank">CVE-2024-4918</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_updateQuestion.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264453" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264453" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333415" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability was found in Campcodes Online Examination System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/addCourseExe.php. The manipulation of the argument course_name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264454 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4919&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4919" target="_blank">CVE-2024-4919</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_addCourseExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264454" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264454" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333416" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Campcodes Online Laundry Management System 1.0. This issue affects some unknown processing of the file /admin_class.php. The manipulation of the argument id/delete_category/delete_inv/delete_laundry/delete_supply/delete_user/login/save_inv/save_user leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263891.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4792&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4792" target="_blank">CVE-2024-4792</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_action.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263891" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263891" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332533" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Online Laundry Management System 1.0. Affected is an unknown function of the file /manage_laundry.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263892.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4793&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4793" target="_blank">CVE-2024-4793</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_laundry.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263892" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263892" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332535" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage_receiving.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263893 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4794&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4794" target="_blank">CVE-2024-4794</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_receiving.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263893" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263893" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332536" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263894 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4795&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4795" target="_blank">CVE-2024-4795</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_user.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263894" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263894" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332537" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as critical. This affects an unknown part of the file /manage_inv.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263895.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4796&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4796" target="_blank">CVE-2024-4796</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_inv.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263895" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263895" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332538" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php of the component HTTP Request Parameter Handler. The manipulation of the argument id leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263938 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4817&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4817" target="_blank">CVE-2024-4817</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/IDOR_manage_user.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263938" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263938" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333055" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263939.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4818&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4818" target="_blank">CVE-2024-4818</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/LFI.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263939" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263939" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333057" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file admin_class.php. The manipulation of the argument type with the input 1 leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263940.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4819&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4819" target="_blank">CVE-2024-4819</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/IDOR.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263940" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263940" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333058" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco AppDynamics<br> </td>
<td>A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the inability to handle unexpected input. An attacker who has local device access could exploit this vulnerability by sending an HTTP request to the targeted service. A successful exploit could allow the attacker to cause a DoS condition by stopping the Network Agent Service on the local device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20394&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20394" target="_blank">CVE-2024-20394</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-appd-netvisdos-9zNbsJtK" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Network Services Orchestrator<br> </td>
<td>A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20369&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20369" target="_blank">CVE-2024-20369</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-ordir-MNM8YqzO" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Client<br> </td>
<td>A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges on an affected device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20391&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20391" target="_blank">CVE-2024-20391</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-nam-priv-esc-szu2vYpZ" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email and Web Manager<br> </td>
<td>A vulnerability in the Cisco Crosswork NSO CLI and the ConfD CLI could allow an authenticated, low-privileged, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to an incorrect privilege assignment when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20383&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20383" target="_blank">CVE-2024-20383</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email<br> </td>
<td>A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20258&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20258" target="_blank">CVE-2024-20258</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email<br> </td>
<td>A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to perform cross-site scripting (XSS) attacks, resulting in the execution of arbitrary script code in the browser of the targeted user, or could allow the attacker to access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20392&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20392" target="_blank">CVE-2024-20392</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-http-split-GLrnnOwS" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email<br> </td>
<td>A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20257&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20257" target="_blank">CVE-2024-20257</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Web Appliance<br> </td>
<td>A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20256&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20256" target="_blank">CVE-2024-20256</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>CodeBard--Fast Custom Social Share by CodeBard<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CodeBard Fast Custom Social Share by CodeBard.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34807&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34807" target="_blank">CVE-2024-34807</a><br><a href="https://patchstack.com/database/vulnerability/fast-custom-social-share-by-codebard/wordpress-fast-custom-social-share-by-codebard-plugin-1-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CodePeople--Appointment Hour Booking<br> </td>
<td>Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Appointment Hour Booking allows Removing Important Client Functionality.This issue affects Appointment Hour Booking: from n/a through 1.4.56.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32720&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32720" target="_blank">CVE-2024-32720</a><br><a href="https://patchstack.com/database/vulnerability/appointment-hour-booking/wordpress-appointment-hour-booking-plugin-1-4-56-captcha-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CodePeople--CP Polls<br> </td>
<td>: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24873&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24873" target="_blank">CVE-2024-24873</a><br><a href="https://patchstack.com/database/vulnerability/cp-polls/wordpress-polls-cp-plugin-1-0-71-polls-limitation-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CodePeople--CP Polls<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24874&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24874" target="_blank">CVE-2024-24874</a><br><a href="https://patchstack.com/database/vulnerability/cp-polls/wordpress-polls-cp-plugin-1-0-71-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Codezips--E-Commerce Site<br> </td>
<td>A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/addproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264460.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4923&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4923" target="_blank">CVE-2024-4923</a><br><a href="https://github.com/polaris0x1/CVE/issues/1" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264460" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264460" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333874" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Codezips--E-Commerce Site<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264746 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5049&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5049" target="_blank">CVE-2024-5049</a><br><a href="https://github.com/polaris0x1/CVE/issues/2" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264746" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264746" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335838" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban--TranslatePress<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34827&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34827" target="_blank">CVE-2024-34827</a><br><a href="https://patchstack.com/database/vulnerability/translatepress-multilingual/wordpress-translate-multilingual-sites-translatepress-plugin-2-7-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Cozmoslabs--Profile Builder<br> </td>
<td>Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31341&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31341" target="_blank">CVE-2024-31341</a><br><a href="https://patchstack.com/database/vulnerability/profile-builder/wordpress-user-profile-builder-plugin-3-11-2-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Creative Motion--Clearfy Cache<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34806&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34806" target="_blank">CVE-2024-34806</a><br><a href="https://patchstack.com/database/vulnerability/clearfy/wordpress-clearfy-cache-plugin-2-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CriticalMoments--CMSaasStarter<br> </td>
<td>CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the user JWT Token is not verified on server session. You should take the patch 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 into your fork.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34354&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34354" target="_blank">CVE-2024-34354</a><br><a href="https://github.com/CriticalMoments/CMSaasStarter/commit/7904d416d2c72ec75f42fbf51e9e64fa74062ee6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CriticalMoments/CMSaasStarter/pull/65" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CriticalMoments/CMSaasStarter/security/advisories/GHSA-qgcj-9rxf-rw7q" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31409&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31409" target="_blank">CVE-2024-31409</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be recovered.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32042&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32042" target="_blank">CVE-2024-32042</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>Dassault Systmes--3DSwymer<br> </td>
<td>A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5597&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5597" target="_blank">CVE-2023-5597</a><br><a href="https://www.3ds.com/vulnerability/advisories" target="_blank">3DS.Information-Security@3ds.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25965&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:H" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25965" target="_blank">CVE-2024-25965</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25967&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25967" target="_blank">CVE-2024-25967</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25969&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25969" target="_blank">CVE-2024-25969</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25970&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25970" target="_blank">CVE-2024-25970</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25966&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25966" target="_blank">CVE-2024-25966</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25968&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25968" target="_blank">CVE-2024-25968</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Easy Digital Downloads--Easy Digital Downloads<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32100&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32100" target="_blank">CVE-2024-32100</a><br><a href="https://patchstack.com/database/vulnerability/easy-digital-downloads/wordpress-easy-digital-downloads-plugin-3-2-11-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Easy Digital Downloads--Easy Digital Downloads<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31113&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31113" target="_blank">CVE-2024-31113</a><br><a href="https://patchstack.com/database/vulnerability/easy-digital-downloads/wordpress-easy-digital-downloads-plugin-3-2-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Elegant Themes--Divi Builder<br> </td>
<td>The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the 'title' parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4490&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4490" target="_blank">CVE-2024-4490</a><br><a href="https://www.elegantthemes.com/" target="_blank">security@wordfence.com</a><br><a href="https://www.elegantthemes.com/api/changelog/divi.txt" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/efac70f6-d959-41f7-bdef-d554f1c9133e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>EnvoThemes--Envo's Elementor Templates &amp; Widgets for WooCommerce<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates &amp; Widgets for WooCommerce allows Stored XSS.This issue affects Envo's Elementor Templates &amp; Widgets for WooCommerce: from n/a through 1.4.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35167&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35167" target="_blank">CVE-2024-35167</a><br><a href="https://patchstack.com/database/vulnerability/envo-elementor-for-woocommerce/wordpress-envo-s-elementor-templates-widgets-for-woocommerce-plugin-1-4-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Eric Alli--Google Typography<br> </td>
<td>Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33942&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33942" target="_blank">CVE-2024-33942</a><br><a href="https://patchstack.com/database/vulnerability/google-typography/wordpress-google-typography-plugin-1-1-2-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Extend Themes--EmpowerWP<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes EmpowerWP.This issue affects EmpowerWP: from n/a through 1.0.21.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34809" target="_blank">CVE-2024-34809</a><br><a href="https://patchstack.com/database/vulnerability/empowerwp/wordpress-empowerwp-theme-1-0-21-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Felix Moira--Popup More Popups<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Felix Moira Popup More Popups allows Stored XSS.This issue affects Popup More Popups: from n/a through 2.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32800&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32800" target="_blank">CVE-2024-32800</a><br><a href="https://patchstack.com/database/vulnerability/popup-more/wordpress-popup-popup-more-popups-plugin-2-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Flothemes--Flo Forms<br> </td>
<td>Missing Authorization vulnerability in Flothemes Flo Forms.This issue affects Flo Forms: from n/a through 1.0.42.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35174&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35174" target="_blank">CVE-2024-35174</a><br><a href="https://patchstack.com/database/vulnerability/flo-forms/wordpress-flo-forms-plugin-1-0-42-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>FmeAddons--Conditional Checkout Fields for WooCommerce<br> </td>
<td>Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-45070&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-45070" target="_blank">CVE-2022-45070</a><br><a href="https://patchstack.com/database/vulnerability/conditional-checkout-fields-for-woocommerce/wordpress-conditional-checkout-fields-for-woocommerce-plugin-1-2-1-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiADC<br> </td>
<td>An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below may allow a read-only admin to view data pertaining to other admins.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50180&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50180" target="_blank">CVE-2023-50180</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-433" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiNAC<br> </td>
<td>An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31488&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31488" target="_blank">CVE-2024-31488</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-040" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiOS<br> </td>
<td>A double free vulnerability [CWE-415] in Fortinet FortiOS before 7.0.0 may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-44247&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-44247" target="_blank">CVE-2023-44247</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-195" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiOS<br> </td>
<td>An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-26007&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26007" target="_blank">CVE-2024-26007</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-017" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiProxy<br> </td>
<td>A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM versions 1.0.0 through 1.0.3, FortiOS versions 7.2.0, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.16 allows attacker to execute unauthorized code or commands via specially crafted commands</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-36640&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-36640" target="_blank">CVE-2023-36640</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-137" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiProxy<br> </td>
<td>A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.5, 7.0.0 through 7.0.11, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 FortiPAM versions 1.1.0, 1.0.0 through 1.0.3 FortiOS versions 7.4.0, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15 FortiSwitchManager versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45583&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45583" target="_blank">CVE-2023-45583</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-137" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiProxy<br> </td>
<td>An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 &amp; FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45586&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45586" target="_blank">CVE-2023-45586</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-225" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27108&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27108" target="_blank">CVE-2024-27108</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Vulnerable data in transit in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27106&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27106" target="_blank">CVE-2024-27106</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>Path traversal vulnerability in "deleteFiles" function of Common Service Desktop, a GE HealthCare ultrasound device component</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1629&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1629" target="_blank">CVE-2024-1629</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GZTimeWalker--GZCTF<br> </td>
<td>GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on other users by constructing malicious team names. This problem has been fixed in `v0.20.1`.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34699&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34699" target="_blank">CVE-2024-34699</a><br><a href="https://github.com/GZTimeWalker/GZCTF/commit/31e775b65cddf82a567d68dcdc78c1739b746346" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/GZTimeWalker/GZCTF/security/advisories/GHSA-p6rq-5x3x-rmhh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>German Mesky--GMAce<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in German Mesky GMAce allows Path Traversal.This issue affects GMAce: from n/a through 1.5.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23872&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23872" target="_blank">CVE-2023-23872</a><br><a href="https://patchstack.com/database/vulnerability/gmace/wordpress-gmace-plugin-1-5-2-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>GhozyLab, Inc.--Popup Builder<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GhozyLab, Inc. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n/a through 1.1.29.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34567&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34567" target="_blank">CVE-2024-34567</a><br><a href="https://patchstack.com/database/vulnerability/easy-notify-lite/wordpress-easy-notify-lite-plugin-1-1-29-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6682&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6682" target="_blank">CVE-2023-6682</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/434821" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2269012" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6688&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6688" target="_blank">CVE-2023-6688</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/434854" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2270362" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2454&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2454" target="_blank">CVE-2024-2454</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/450405" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2408226" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2651&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2651" target="_blank">CVE-2024-2651</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/450830" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2408619" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4597&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4597" target="_blank">CVE-2024-4597</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/438686" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 where abusing the API to filter branch and tags could lead to Denial of Service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4539&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4539" target="_blank">CVE-2024-4539</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/454815" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>Google--Gvisor<br> </td>
<td>A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-7258&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-7258" target="_blank">CVE-2023-7258</a><br><a href="https://github.com/google/gvisor/commit/6a112c60a257dadac59962e0bc9e9b5aee70b5b6" target="_blank">cve-coordination@google.com</a></td>
</tr>
<tr>
<td>Guido--VS Contact Form<br> </td>
<td>Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form: from n/a through 14.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30540&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30540" target="_blank">CVE-2024-30540</a><br><a href="https://patchstack.com/database/vulnerability/very-simple-contact-form/wordpress-vs-contact-form-plugin-14-7-sum-captcha-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Gutenify--Gutenify<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gutenify.This issue affects Gutenify: from n/a through 1.4.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35165&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35165" target="_blank">CVE-2024-35165</a><br><a href="https://patchstack.com/database/vulnerability/gutenify/wordpress-gutenify-plugin-1-4-0-sensitive-data-exposure-via-api-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>HCL Software--BigFix Platform<br> </td>
<td>An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23583&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23583" target="_blank">CVE-2024-23583</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113140" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>HCL Software--BigFix Platform<br> </td>
<td>Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23554&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23554" target="_blank">CVE-2024-23554</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113140" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>HCL Software--BigFix Platform<br> </td>
<td>SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23556&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23556" target="_blank">CVE-2024-23556</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113140" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>HCL Software--DRYiCE Lucy<br> </td>
<td>HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning attacks.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37526&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37526" target="_blank">CVE-2023-37526</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113032" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>Harknell--AWSOM News Announcement<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harknell AWSOM News Announcement allows Stored XSS.This issue affects AWSOM News Announcement: from n/a through 1.6.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34428&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34428" target="_blank">CVE-2024-34428</a><br><a href="https://patchstack.com/database/vulnerability/awsom-news-announcement/wordpress-awsom-news-announcement-plugin-1-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilites result in the ability to interrupt the normal operation of the affected Access Point.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31478&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31478" target="_blank">CVE-2024-31478</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31479&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31479" target="_blank">CVE-2024-31479</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31480&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31480" target="_blank">CVE-2024-31480</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31481&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31481" target="_blank">CVE-2024-31481</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected Access Point.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31482&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31482" target="_blank">CVE-2024-31482</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31483&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31483" target="_blank">CVE-2024-31483</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hidden Depth--Sticky banner<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Sticky banner allows Stored XSS.This issue affects Sticky banner: from n/a through 1.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35170&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35170" target="_blank">CVE-2024-35170</a><br><a href="https://patchstack.com/database/vulnerability/sticky-banner/wordpress-sticky-banner-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Highfivery LLC--Zero Spam<br> </td>
<td>Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32521&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32521" target="_blank">CVE-2024-32521</a><br><a href="https://patchstack.com/database/vulnerability/zero-spam/wordpress-zero-spam-for-wordpress-plugin-5-5-5-bypass-spam-protection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52721&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52721" target="_blank">CVE-2023-52721</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32990&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32990" target="_blank">CVE-2024-32990</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32995&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32995" target="_blank">CVE-2024-32995</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32996&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32996" target="_blank">CVE-2024-32996</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32999&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32999" target="_blank">CVE-2024-32999</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4046&amp;vector=CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4046" target="_blank">CVE-2024-4046</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32993&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">5.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32993" target="_blank">CVE-2024-32993</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32998&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32998" target="_blank">CVE-2024-32998</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52383&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52383" target="_blank">CVE-2023-52383</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52384&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52384" target="_blank">CVE-2023-52384</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52720&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52720" target="_blank">CVE-2023-52720</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huseyin Berberoglu--WP Favorite Posts<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Huseyin Berberoglu WP Favorite Posts.This issue affects WP Favorite Posts: from n/a through 1.6.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34427&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34427" target="_blank">CVE-2024-34427</a><br><a href="https://patchstack.com/database/vulnerability/wp-favorite-posts/wordpress-wp-favorite-posts-plugin-1-6-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>IBM--App Connect Enterprise<br> </td>
<td>IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 285245.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28761&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28761" target="_blank">CVE-2024-28761</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/285245" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150847" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--App Connect Enterprise<br> </td>
<td>IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is vulnerable to a denial of service due to improper restrictions of resource allocation. IBM X-Force ID: 285244.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28760&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28760" target="_blank">CVE-2024-28760</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/285244" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150845" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--QRadar SIEM<br> </td>
<td>IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27269&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27269" target="_blank">CVE-2024-27269</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/284575" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150684" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--SDK, Java Technology Edition<br> </td>
<td>The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38264&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38264" target="_blank">CVE-2023-38264</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/260578" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150727" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47717&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47717" target="_blank">CVE-2023-47717</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271690" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7152469" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Spectrum Fusion HCI<br> </td>
<td>IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43040&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43040" target="_blank">CVE-2023-43040</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/266807" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7151040" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--TXSeries for Multiplatforms<br> </td>
<td>IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 280191.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22344&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22344" target="_blank">CVE-2024-22344</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/280191" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150667" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--TXSeries for Multiplatforms<br> </td>
<td>IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM X-Force ID: 280192.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22345&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22345" target="_blank">CVE-2024-22345</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/280192" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150667" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--TXSeries for Multiplatforms<br> </td>
<td>IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 280190.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22343&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22343" target="_blank">CVE-2024-22343</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/280190" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150667" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--UrbanCode Deploy<br> </td>
<td>IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285654.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28781&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28781" target="_blank">CVE-2024-28781</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/285654" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150747" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>ITPison--OMICARD EDM<br> </td>
<td>ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4894&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4894" target="_blank">CVE-2024-4894</a><br><a href="https://www.twcert.org.tw/en/cp-139-7803-c0f73-2.html" target="_blank">twcert@cert.org.tw</a><br><a href="https://www.twcert.org.tw/tw/cp-132-7802-18f3c-1.html" target="_blank">twcert@cert.org.tw</a></td>
</tr>
<tr>
<td>Imran Sayed--Headless CMS<br> </td>
<td>Missing Authorization vulnerability in Imran Sayed Headless CMS.This issue affects Headless CMS: from n/a through 2.0.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-34186&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-34186" target="_blank">CVE-2023-34186</a><br><a href="https://patchstack.com/database/vulnerability/headless-cms/wordpress-headless-cms-plugin-2-0-3-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JFrog--Artifactory<br> </td>
<td>A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim's user email.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2248&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2248" target="_blank">CVE-2024-2248</a><br><a href="https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories" target="_blank">reefs@jfrog.com</a></td>
</tr>
<tr>
<td>JetBrains--TeamCity<br> </td>
<td>In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35301&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35301" target="_blank">CVE-2024-35301</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>JetBrains--TeamCity<br> </td>
<td>In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35302&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35302" target="_blank">CVE-2024-35302</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>JetBrains--YouTrack<br> </td>
<td>In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35299&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35299" target="_blank">CVE-2024-35299</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>Justin Silver--Remote Content Shortcode<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Justin Silver Remote Content Shortcode allows PHP Local File Inclusion.This issue affects Remote Content Shortcode: from n/a through 1.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45652&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45652" target="_blank">CVE-2023-45652</a><br><a href="https://patchstack.com/database/vulnerability/remote-content-shortcode/wordpress-remote-content-shortcode-plugin-1-5-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Justin Tadlock--Unique<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Unique allows Stored XSS.This issue affects Unique: from n/a through 0.3.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33952&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33952" target="_blank">CVE-2024-33952</a><br><a href="https://patchstack.com/database/vulnerability/unique/wordpress-unique-theme-0-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. This affects an unknown part of the file view_each_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263919.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4799&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4799" target="_blank">CVE-2024-4799</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%202.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263919" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263919" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332544" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability has been found in Kashipara College Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file submit_student.php. The manipulation of the argument date_of_birth leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263920.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4800&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4800" target="_blank">CVE-2024-4800</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%203.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263920" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263920" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332545" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0 and classified as critical. This issue affects some unknown processing of the file submit_new_faculty.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263921 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4801&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4801" target="_blank">CVE-2024-4801</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%204.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263921" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263921" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332552" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0. It has been classified as critical. Affected is an unknown function of the file submit_extracurricular_activity.php. The manipulation of the argument activity_datetime leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263922 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4802&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4802" target="_blank">CVE-2024-4802</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%205.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332553" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file submit_admin.php. The manipulation of the argument phone leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263923.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4803&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4803" target="_blank">CVE-2024-4803</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%206.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332554" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263924.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4804&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4804" target="_blank">CVE-2024-4804</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%207.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332555" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability classified as critical has been found in Kashipara College Management System 1.0. This affects an unknown part of the file edit_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263925 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4805&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4805" target="_blank">CVE-2024-4805</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%208.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332556" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability classified as critical was found in Kashipara College Management System 1.0. This vulnerability affects unknown code of the file each_extracurricula_activities.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263926 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4806&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4806" target="_blank">CVE-2024-4806</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%209.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332557" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Kashipara College Management System 1.0. This issue affects some unknown processing of the file delete_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263927.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4807&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4807" target="_blank">CVE-2024-4807</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%2010.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263927" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263927" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332564" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file delete_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263928.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4808&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4808" target="_blank">CVE-2024-4808</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%2011.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263928" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263928" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332565" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability classified as critical has been found in Kashipara College Management System 1.0. Affected is an unknown function of the file view_students_each_detail.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264438 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4905&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4905" target="_blank">CVE-2024-4905</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%201.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264438" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264438" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332543" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kiboko Labs--Arigato Autoresponder and Newsletter<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34823&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34823" target="_blank">CVE-2024-34823</a><br><a href="https://patchstack.com/database/vulnerability/bft-autoresponder/wordpress-arigato-autoresponder-and-newsletter-plugin-2-7-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Kioware--Kioware<br> </td>
<td>KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3461&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3461" target="_blank">CVE-2024-3461</a><br><a href="https://cert.pl/en/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://www.kioware.com/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Kubernetes--azure-file-csi-driver<br> </td>
<td>A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. Tokens are only logged when TokenRequests is configured in the CSIDriver object and the driver is set to run at log level 2 or greater via the -v flag.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3744&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3744" target="_blank">CVE-2024-3744</a><br><a href="https://github.com/kubernetes/kubernetes/issues/124759" target="_blank">jordan@liggitt.net</a><br><a href="https://groups.google.com/g/kubernetes-security-announce/c/hcgZE2MQo1A/m/Y4C6q-CYAgAJ" target="_blank">jordan@liggitt.net</a></td>
</tr>
<tr>
<td>Linux--Linux kernel<br> </td>
<td>In register_device, the return value of ida_simple_get is unchecked, in witch ida_simple_get will use an invalid index value. To address this issue, index should be checked after ida_simple_get. When the index value is abnormal, a warning message should be printed, the port should be dropped, and the value should be recorded.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4810&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4810" target="_blank">CVE-2024-4810</a><br><a href="https://bugzilla.openanolis.cn/show_bug.cgi?id=9008" target="_blank">security@openanolis.org</a></td>
</tr>
<tr>
<td>LionScripts--IP Blocker Lite<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue affects IP Blocker Lite: from n/a through 11.1.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30479&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30479" target="_blank">CVE-2024-30479</a><br><a href="https://patchstack.com/database/vulnerability/ip-address-blocker/wordpress-lionscripts-ip-blocker-lite-plugin-11-1-1-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>LizardByte--Sunshine<br> </td>
<td>Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a service on Windows may be impacted when terminating the service if an attacked placed a file named `C:\Program.exe`, `C:\Program.bat`, or `C:\Program.cmd` on the user's computer. This attack vector isn't exploitable unless the user has manually loosened ACLs on the system drive. If the user's system locale is not English, then the name of the executable will likely vary. Version 0.23.0 contains a patch for the issue. Some workarounds are available. One may identify and block potentially malicious software executed path interception by using application control tools, like Windows Defender Application Control, AppLocker, or Software Restriction Policies where appropriate. Alternatively, ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory `C:`. Require that all executables be placed in write-protected directories.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31226&amp;vector=CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31226" target="_blank">CVE-2024-31226</a><br><a href="https://github.com/LizardByte/Sunshine/commit/93e622342c4f3e9b34f5f265039b6775b8e33a7a" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/LizardByte/Sunshine/pull/2379" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/LizardByte/Sunshine/security/advisories/GHSA-r3rw-mx4q-7vfp" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Matt van Andel--Adventure Journal<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from n/a through 1.7.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33953&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33953" target="_blank">CVE-2024-33953</a><br><a href="https://patchstack.com/database/vulnerability/adventure-journal/wordpress-adventure-journal-theme-1-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Metagauss--EventPrime<br> </td>
<td>Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-33321&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33321" target="_blank">CVE-2023-33321</a><br><a href="https://patchstack.com/database/vulnerability/eventprime-event-calendar-management/wordpress-eventprime-plugin-2-8-6-sensitive-data-exposure?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Metagauss--ProfileGrid<br> </td>
<td>Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32774&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32774" target="_blank">CVE-2024-32774</a><br><a href="https://patchstack.com/database/vulnerability/profilegrid-user-profiles-groups-and-communities/wordpress-profilegrid-plugin-5-8-2-group-members-limit-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Microchip--SAME70<br> </td>
<td>A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71 microcontrollers allows access to the memory bus via the debug interface even if the security bit is set.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4760&amp;vector=CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4760" target="_blank">CVE-2024-4760</a><br><a href="https://www.0x01team.com/hw_security/bypassing-microchip-atmel-sam-e70-s70-v70-v71-security/" target="_blank">dc3f6da9-85b5-4a73-84a2-2ec90b40fca5</a></td>
</tr>
<tr>
<td>Microsoft--.NET 7.0<br> </td>
<td>Visual Studio Denial of Service Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30046&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30046" target="_blank">CVE-2024-30046</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30046" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--.NET 8.0<br> </td>
<td>.NET and Visual Studio Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30045&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30045" target="_blank">CVE-2024-30045</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30045" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Azure Migrate<br> </td>
<td>Azure Migrate Cross-Site Scripting Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30053&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30053" target="_blank">CVE-2024-30053</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30053" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft Bing Search for iOS<br> </td>
<td>Microsoft Bing Search Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30041&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30041" target="_blank">CVE-2024-30041</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30041" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft Edge (Chromium-based)<br> </td>
<td>Microsoft Edge (Chromium-based) Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30055&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30055" target="_blank">CVE-2024-30055</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30055" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft Intune Mobile Application Management<br> </td>
<td>Microsoft Intune for Android Mobile Application Management Tampering Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30059&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30059" target="_blank">CVE-2024-30059</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30059" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft SharePoint Enterprise Server 2016<br> </td>
<td>Microsoft SharePoint Server Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30043&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30043" target="_blank">CVE-2024-30043</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30043" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--PowerBI-client JS SDK<br> </td>
<td>Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30054&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30054" target="_blank">CVE-2024-30054</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30054" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29997&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29997" target="_blank">CVE-2024-29997</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29997" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29998&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29998" target="_blank">CVE-2024-29998</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29998" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29999&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29999" target="_blank">CVE-2024-29999</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29999" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30000&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30000" target="_blank">CVE-2024-30000</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30000" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30001&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30001" target="_blank">CVE-2024-30001</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30001" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30002&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30002" target="_blank">CVE-2024-30002</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30002" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30003&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30003" target="_blank">CVE-2024-30003</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30003" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30004&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30004" target="_blank">CVE-2024-30004</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30004" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30005&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30005" target="_blank">CVE-2024-30005</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30005" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30012&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30012" target="_blank">CVE-2024-30012</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30012" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30021&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30021" target="_blank">CVE-2024-30021</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30021" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows DWM Core Library Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30008&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30008" target="_blank">CVE-2024-30008</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30008" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Cryptographic Services Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30016&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30016" target="_blank">CVE-2024-30016</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30016" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30034&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30034" target="_blank">CVE-2024-30034</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30034" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Remote Access Connection Manager Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30039&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30039" target="_blank">CVE-2024-30039</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30039" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mark of the Web Security Feature Bypass Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30050&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30050" target="_blank">CVE-2024-30050</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30050" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>Windows Hyper-V Denial of Service Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30011&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30011" target="_blank">CVE-2024-30011</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30011" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>DHCP Server Service Denial of Service Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30019&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30019" target="_blank">CVE-2024-30019</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30019" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>Windows Deployment Services Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30036&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30036" target="_blank">CVE-2024-30036</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30036" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>MongoDB Inc--MongoDB Server<br> </td>
<td>An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB Server v6.0 versions prior to and including 6.0.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3374&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3374" target="_blank">CVE-2024-3374</a><br><a href="https://jira.mongodb.org/browse/SERVER-75601" target="_blank">cna@mongodb.com</a></td>
</tr>
<tr>
<td>N/A--N/A<br> </td>
<td>The 'WordPress RSS Aggregator' WordPress Plugin, versions &lt; 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4860&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4860" target="_blank">CVE-2024-4860</a><br><a href="https://www.tenable.com/security/research/tra-2024-16" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Nathan Vonnahme--Configure Login Timeout<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nathan Vonnahme Configure Login Timeout allows Stored XSS.This issue affects Configure Login Timeout: from n/a through 1.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34419&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34419" target="_blank">CVE-2024-34419</a><br><a href="https://patchstack.com/database/vulnerability/configure-login-timeout/wordpress-configure-login-timeout-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Ninja Team--Filebird<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35166&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35166" target="_blank">CVE-2024-35166</a><br><a href="https://patchstack.com/database/vulnerability/filebird/wordpress-filebird-wordpress-media-library-folders-file-manager-plugin-5-6-3-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>OCDI--One Click Demo Import<br> </td>
<td>Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34433&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34433" target="_blank">CVE-2024-34433</a><br><a href="https://patchstack.com/database/vulnerability/one-click-demo-import/wordpress-one-click-demo-import-plugin-3-2-0-php-object-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>OceanicJS--Oceanic<br> </td>
<td>Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially crafted input such as `../../../channels/{id}` being normalized into the url `/api/v10/channels/{id}`, and deleting a channel rather than removing a ban. Version 1.10.4 fixes this issue. Some workarounds are available. One may sanitize user input, ensuring strings are valid for the purpose they are being used for. One may also encode input with `encodeURIComponent` before providing it to the library.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34712&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34712" target="_blank">CVE-2024-34712</a><br><a href="https://github.com/OceanicJS/Oceanic/commit/8bf8ee8373b8c565fbdbf70a609aba4fbc1a1ffe" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/OceanicJS/Oceanic/security/advisories/GHSA-5h5v-hw44-f6gg" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Path Traversal found in OpenTextâ„¢ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3484&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3484" target="_blank">CVE-2024-3484</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Server Side Request Forgery vulnerability has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. This could lead to senstive information disclosure.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3485&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3485" target="_blank">CVE-2024-3485</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>File Upload vulnerability in unauthenticated session found in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3488&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3488" target="_blank">CVE-2024-3488</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Server Side Request Forgery vulnerability has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3970&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3970" target="_blank">CVE-2024-3970</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>Orchestrated--Corona Virus (COVID-19) Banner &amp; Live Data<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Orchestrated Corona Virus (COVID-19) Banner &amp; Live Data allows Stored XSS.This issue affects Corona Virus (COVID-19) Banner &amp; Live Data: from n/a through 1.8.0.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34429&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34429" target="_blank">CVE-2024-34429</a><br><a href="https://patchstack.com/database/vulnerability/corona-virus-covid-19-banner/wordpress-simple-website-banner-plugin-1-8-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28135&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28135" target="_blank">CVE-2024-28135</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264925 was assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5066&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5066" target="_blank">CVE-2024-5066</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%204.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336240" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>PaperCut--PaperCut NG, PaperCut MF<br> </td>
<td>An arbitrary file deletion vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This vulnerability requires local login/console access to the PaperCut NG/MF server (eg: member of a domain admin group).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3037&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3037" target="_blank">CVE-2024-3037</a><br><a href="https://www.papercut.com/kb/Main/security-bulletin-may-2024/" target="_blank">eb41dac7-0af8-4f84-9f6d-0272772514f4</a></td>
</tr>
<tr>
<td>PaperCut--PaperCut NG, PaperCut MF<br> </td>
<td>An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This vulnerability requires local login/console access to the PaperCut NG/MF server (eg: member of a domain admin group).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4712&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4712" target="_blank">CVE-2024-4712</a><br><a href="https://www.papercut.com/kb/Main/security-bulletin-may-2024/" target="_blank">eb41dac7-0af8-4f84-9f6d-0272772514f4</a></td>
</tr>
<tr>
<td>Phil Baylog--QuickieBar<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Baylog QuickieBar allows Stored XSS.This issue affects QuickieBar: from n/a through 1.8.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34425&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34425" target="_blank">CVE-2024-34425</a><br><a href="https://patchstack.com/database/vulnerability/quickiebar/wordpress-quickiebar-plugin-1-8-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PluginEver--Serial Numbers for WooCommerce License Manager<br> </td>
<td>Missing Authorization vulnerability in PluginEver Serial Numbers for WooCommerce - License Manager.This issue affects Serial Numbers for WooCommerce - License Manager: from n/a through 1.7.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35173&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35173" target="_blank">CVE-2024-35173</a><br><a href="https://patchstack.com/database/vulnerability/wc-serial-numbers/wordpress-wc-serial-numbers-plugin-1-7-2-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PrestaShop--PrestaShop<br> </td>
<td>PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34717" target="_blank">CVE-2024-34717</a><br><a href="https://github.com/PrestaShop/PrestaShop/releases/tag/8.1.6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-7pjr-2rgh-fc5g" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--WhatsUp Gold<br> </td>
<td>In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functionality.  Due to the lack of proper authorization, any authenticated user can access the HTTP monitoring functionality, what leads to the Server Side Request Forgery.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4562&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4562" target="_blank">CVE-2024-4562</a><br><a href="https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2" target="_blank">security@progress.com</a><br><a href="https://www.progress.com/network-monitoring" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--WhatsUp Gold<br> </td>
<td>In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4561&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4561" target="_blank">CVE-2024-4561</a><br><a href="https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2" target="_blank">security@progress.com</a><br><a href="https://www.progress.com/network-monitoring" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software--Telerik Report Server<br> </td>
<td>An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4357&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4357" target="_blank">CVE-2024-4357</a><br><a href="https://docs.telerik.com/report-server/knowledge-base/xxe-vulnerability-cve-2024-4357" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software--Telerik Report Server<br> </td>
<td>In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4837&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4837" target="_blank">CVE-2024-4837</a><br><a href="https://docs.telerik.com/report-server/knowledge-base/information-exposure-cve-2024-4837" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Proofpoint--Enterprise Protection<br> </td>
<td>The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authenticated user to relay HTTP requests from the Protection server to otherwise private network addresses.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0862&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0862" target="_blank">CVE-2024-0862</a><br><a href="https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0001" target="_blank">security@proofpoint.com</a></td>
</tr>
<tr>
<td>QODE Interactive--Qi Addons For Elementor<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QODE Interactive Qi Addons For Elementor allows PHP Local File Inclusion.This issue affects Qi Addons For Elementor: from n/a through 1.6.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47679&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47679" target="_blank">CVE-2023-47679</a><br><a href="https://patchstack.com/database/vulnerability/qi-addons-for-elementor/wordpress-qi-addons-for-elementor-plugin-1-6-3-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>RadiusTheme--ShopBuilder Elementor WooCommerce Builder Addons<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RadiusTheme ShopBuilder - Elementor WooCommerce Builder Addons.This issue affects ShopBuilder - Elementor WooCommerce Builder Addons: from n/a through 2.1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34812&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34812" target="_blank">CVE-2024-34812</a><br><a href="https://patchstack.com/database/vulnerability/shopbuilder/wordpress-shopbuilder-plugin-2-1-8-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>RafflePress--Giveaways and Contests<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in RafflePress Giveaways and Contests allows Functionality Bypass.This issue affects Giveaways and Contests: from n/a through 1.12.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32827&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32827" target="_blank">CVE-2024-32827</a><br><a href="https://patchstack.com/database/vulnerability/rafflepress/wordpress-giveaways-and-contests-by-rafflepress-plugin-1-12-7-ip-restriction-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Rashed Latif--TT Custom Post Type Creator<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rashed Latif TT Custom Post Type Creator allows Stored XSS.This issue affects TT Custom Post Type Creator: from n/a through 1.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34430&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34430" target="_blank">CVE-2024-34430</a><br><a href="https://patchstack.com/database/vulnerability/tt-custom-post-type-creator/wordpress-tt-custom-post-type-creator-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat Advanced Cluster Management for Kubernetes 2<br> </td>
<td>A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5042&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5042" target="_blank">CVE-2024-5042</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-5042" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2280921" target="_blank">secalert@redhat.com</a><br><a href="https://github.com/advisories/GHSA-2rhx-qhxp-5jpw" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat Enterprise Linux 6<br> </td>
<td>A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4693&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4693" target="_blank">CVE-2024-4693</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-4693" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2279965" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat OpenStack Platform 16.2<br> </td>
<td>An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4840&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4840" target="_blank">CVE-2024-4840</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-4840" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2280249" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat Satellite 6<br> </td>
<td>A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4871&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4871" target="_blank">CVE-2024-4871</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-4871" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2278627" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Revmakx--WPCal.io Easy Meeting Scheduler<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io - Easy Meeting Scheduler.This issue affects WPCal.Io - Easy Meeting Scheduler: from n/a through 0.9.5.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34816&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34816" target="_blank">CVE-2024-34816</a><br><a href="https://patchstack.com/database/vulnerability/wpcal/wordpress-wpcal-io-plugin-0-9-5-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240506. Affected is an unknown function of the file /view/networkConfig/physicalInterface/interface_commit.php. The manipulation of the argument name leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-263934 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4813&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4813" target="_blank">CVE-2024-4813</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-physicalInterface%3Ainterface_commit.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263934" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263934" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330020" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240506. Affected by this vulnerability is an unknown functionality of the file /view/networkConfig/RouteConfig/StaticRoute/static_route_edit_commit.php. The manipulation of the argument oldipmask/oldgateway leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263935. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4814&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4814" target="_blank">CVE-2024-4814</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-StaticRoute%3Astatic_route_edit_commit.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263935" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263935" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330052" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240506. Affected by this issue is some unknown functionality of the file /view/bugSolve/viewData/detail.php. The manipulation of the argument filename leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263936. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4815&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4815" target="_blank">CVE-2024-4815</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-view_bugSolve_viewData_detail.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263936" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263936" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.329966" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240506. This affects an unknown part of the file /view/networkConfig/GRE/gre_add_commit.php. The manipulation of the argument name/remote/local/IP leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263937 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4816&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4816" target="_blank">CVE-2024-4816</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-gre_add_commit.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263937" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263937" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.329953" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP BusinessObjects Business Intelligence Platform (Webservices)<br> </td>
<td>SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33004&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33004" target="_blank">CVE-2024-33004</a><br><a href="https://me.sap.com/notes/3449093" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Enable Now<br> </td>
<td>SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with the role 'Learner' could gain access to other user's data in manager which will lead to a high impact to the confidentiality of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32730&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32730" target="_blank">CVE-2024-32730</a><br><a href="https://me.sap.com/notes/3441944" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Global Label Management (GLM)<br> </td>
<td>SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33009&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33009" target="_blank">CVE-2024-33009</a><br><a href="https://me.sap.com/notes/1938764" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP My Travel Requests <br> </td>
<td>SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32731&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32731" target="_blank">CVE-2024-32731</a><br><a href="https://me.sap.com/notes/3447467" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP NetWeaver Application Server ABAP and ABAP Platform <br> </td>
<td>Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32733&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32733" target="_blank">CVE-2024-32733</a><br><a href="https://me.sap.com/notes/3450286" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP NetWeaver Application server for ABAP and ABAP Platform<br> </td>
<td>SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user's browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user's session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34687&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34687" target="_blank">CVE-2024-34687</a><br><a href="https://me.sap.com/notes/3448445" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Replication Server <br> </td>
<td>SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crashing the Replication Server due to memory corruption with high impact on Availability of the system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33008&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33008" target="_blank">CVE-2024-33008</a><br><a href="https://me.sap.com/notes/3349468" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)<br> </td>
<td>Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of the application. Confidentiality and Availability are not affected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4138&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4138" target="_blank">CVE-2024-4138</a><br><a href="https://me.sap.com/notes/3434666" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)<br> </td>
<td>Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application. Confidentiality and Availability are not affected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4139&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4139" target="_blank">CVE-2024-4139</a><br><a href="https://me.sap.com/notes/3434666" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP S/4HANA (Document Service Handler for DPS)<br> </td>
<td>Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33002&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33002" target="_blank">CVE-2024-33002</a><br><a href="https://me.sap.com/notes/3460772" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SKT Themes--SKT Addons for Elementor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through 1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34436&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34436" target="_blank">CVE-2024-34436</a><br><a href="https://patchstack.com/database/vulnerability/skt-addons-for-elementor/wordpress-skt-addons-for-elementor-plugin-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SKT Themes--SKT Addons for Elementor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through 1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34445" target="_blank">CVE-2024-34445</a><br><a href="https://patchstack.com/database/vulnerability/skt-addons-for-elementor/wordpress-skt-addons-for-elementor-plugin-1-8-cross-site-scripting-xss-vulnerability-2?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SailPoint--Identity Security Cloud<br> </td>
<td>An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3317&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3317" target="_blank">CVE-2024-3317</a><br><a href="https://www.sailpoint.com/security-advisories/" target="_blank">psirt@sailpoint.com</a></td>
</tr>
<tr>
<td>SailPoint--Identity Security Cloud<br> </td>
<td>A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the "file" attribute, which in turn allowed the user to access files uploaded for other sources.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3318&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3318" target="_blank">CVE-2024-3318</a><br><a href="https://www.sailpoint.com/security-advisories/" target="_blank">psirt@sailpoint.com</a></td>
</tr>
<tr>
<td>SakuraIsayeki--WOWS-Karma<br> </td>
<td>WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the cooldown validation, however are not refreshing a user's metrics more than once, due to concurrent karma updates. This issue is fixed in 0.17.4.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34695&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34695" target="_blank">CVE-2024-34695</a><br><a href="https://github.com/SakuraIsayeki/WOWS-Karma/commit/3210b516fa3551e30fe760c915f7656d9046e69a" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/SakuraIsayeki/WOWS-Karma/commit/6cb825976f28c68d79172aeda00e955bf5853de2" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/SakuraIsayeki/WOWS-Karma/security/advisories/GHSA-v6cc-v976-mj8g" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Salon Booking System--Salon booking system<br> </td>
<td>Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48319&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48319" target="_blank">CVE-2023-48319</a><br><a href="https://patchstack.com/database/vulnerability/salon-booking-system/wordpress-salon-booking-system-plugin-8-7-editor-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Samsung Open Source--Escargot<br> </td>
<td>Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test code and does not include in the release. This issue affects escargot: 4.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32669&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32669" target="_blank">CVE-2024-32669</a><br><a href="https://github.com/Samsung/escargot/pull/1326" target="_blank">PSIRT@samsung.com</a></td>
</tr>
<tr>
<td>Samsung Open Source--Escargot<br> </td>
<td>A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This issue affects Escargot: 4.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32672&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32672" target="_blank">CVE-2024-32672</a><br><a href="https://github.com/Samsung/escargot/pull/1322" target="_blank">PSIRT@samsung.com</a></td>
</tr>
<tr>
<td>Samuel Marshall--JCH Optimize<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.2.0.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34808&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34808" target="_blank">CVE-2024-34808</a><br><a href="https://patchstack.com/database/vulnerability/jch-optimize/wordpress-jch-optimize-plugin-4-2-0-path-traversal-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ShortPixel--ShortPixel Adaptive Images<br> </td>
<td>Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35172&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35172" target="_blank">CVE-2024-35172</a><br><a href="https://patchstack.com/database/vulnerability/shortpixel-adaptive-images/wordpress-shortpixel-adaptive-images-plugin-3-8-3-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ShortPixel--ShortPixel Adaptive Images<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4689&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4689" target="_blank">CVE-2024-4689</a><br><a href="https://patchstack.com/database/vulnerability/shortpixel-adaptive-images/wordpress-shortpixel-adaptive-images-plugin-3-8-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SiAdmin--SiAdmin<br> </td>
<td>Vulnerability in SiAdmin 1.1 that allows XSS via the /show.php query parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and thereby steal their cookie session credentials.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4993&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4993" target="_blank">CVE-2024-4993</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-siadmin" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Siemens--OPUPI0 AMQP/MQTT<br> </td>
<td>A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions &lt; V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31486&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31486" target="_blank">CVE-2024-31486</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-871704.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Polarion ALM<br> </td>
<td>A vulnerability has been identified in Polarion ALM (All versions &lt; V2404.0). The Apache Lucene based query engine in the affected application lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33647&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33647" target="_blank">CVE-2024-33647</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-925850.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). Downloading files overwrites files with the same name in the installation directory of the affected systems. The filename for the target file can be specified, thus arbitrary files can be overwritten by an attacker with the required privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27946&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27946" target="_blank">CVE-2024-27946</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems could allow log messages to be forwarded to a specific client under certain circumstances. An attacker could leverage this vulnerability to forward log messages to a specific compromised client.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27947&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27947" target="_blank">CVE-2024-27947</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--S7-PCT<br> </td>
<td>A vulnerability has been identified in S7-PCT (All versions), Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions), SIMATIC BATCH V9.1 (All versions), SIMATIC NET PC Software (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC PDM V9.2 (All versions), SIMATIC Route Control V9.1 (All versions), SIMATIC STEP 7 V5 (All versions), SIMATIC WinCC OA V3.17 (All versions), SIMATIC WinCC OA V3.18 (All versions &lt; V3.18 P025), SIMATIC WinCC OA V3.19 (All versions &lt; V3.19 P010), SIMATIC WinCC Runtime Advanced (All versions), SIMATIC WinCC Runtime Professional V16 (All versions), SIMATIC WinCC Runtime Professional V17 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC Unified PC Runtime (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions), SIMATIC WinCC V8.0 (All versions), SINAMICS Startdrive (All versions &lt; V19 SP1), SINUMERIK ONE virtual (All versions &lt; V6.23), SINUMERIK PLC Programming Tool (All versions), TIA Portal Cloud Connector (All versions &lt; V2.0), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions &lt; V19 Update 2). The affected applications contain an out of bounds read vulnerability. This could allow an attacker to cause a Blue Screen of Death (BSOD) crash of the underlying Windows kernel.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46280&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46280" target="_blank">CVE-2023-46280</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-962515.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The "DBTest" tool of SIMATIC RTLS Locating Manager does not properly enforce access restriction. This could allow an authenticated local attacker to extract sensitive information from memory.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30208&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30208" target="_blank">CVE-2024-30208</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected components do not properly authenticate heartbeat messages. This could allow an unauthenticated remote attacker to affected the availability of secondary RTLS systems configured using a TeeRevProxy service and potentially cause loss of data generated during the time the attack is ongoing.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33494&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33494" target="_blank">CVE-2024-33494</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The affected application does not properly limit the size of specific logs. This could allow an unauthenticated remote attacker to exhaust system resources by creating a great number of log entries which could potentially lead to a denial of service condition. A successful exploitation requires the attacker to have access to specific SIMATIC RTLS Locating Manager Clients in the deployment.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33495&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33495" target="_blank">CVE-2024-33495</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33496&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33496" target="_blank">CVE-2024-33496</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected SIMATIC RTLS Locating Manager Track Viewer Client do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33497&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33497" target="_blank">CVE-2024-33497</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected applications do not properly release memory that is allocated when handling specifically crafted incoming packets. This could allow an unauthenticated remote attacker to cause a denial of service condition by crashing the service when it runs out of memory. The service is restarted automatically after a short time.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33498&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33498" target="_blank">CVE-2024-33498</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>SourceCodester--Best Courier Management System<br> </td>
<td>A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file view_parcel.php. The manipulation of the argument id leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264480.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4945&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4945" target="_blank">CVE-2024-4945</a><br><a href="https://github.com/CveSecLook/cve/issues/28" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264480" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264480" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333960" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Employee and Visitor Gate Pass Logging System<br> </td>
<td>A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /employee_gatepass/classes/Users.php?f=ssave. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264456.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4921&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4921" target="_blank">CVE-2024-4921</a><br><a href="https://github.com/I-Schnee-I/cev/blob/main/upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264456" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264456" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333662" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Gas Agency Management System<br> </td>
<td>A vulnerability has been found in SourceCodester Gas Agency Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file edituser.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264748.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5051&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5051" target="_blank">CVE-2024-5051</a><br><a href="https://github.com/HuoMingZ/aoligei/blob/main/Gas.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264748" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264748" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336010" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Interactive Map with Marker<br> </td>
<td>A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264535.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4967&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4967" target="_blank">CVE-2024-4967</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Interactive%20Map%20App/Interactive%20Map%20App%20-%20SQL%20Injection.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264535" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264535" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335190" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Art Gallery Management System<br> </td>
<td>A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/adminHome.php. The manipulation of the argument sliderpic leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264481 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4946&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4946" target="_blank">CVE-2024-4946</a><br><a href="https://github.com/CveSecLook/cve/issues/29" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264481" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264481" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.334215" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Birth Certificate Management System<br> </td>
<td>A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264742 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5045&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5045" target="_blank">CVE-2024-5045</a><br><a href="https://github.com/HuoMingZ/aoligei/blob/main/yuzu.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264742" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264742" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335384" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Computer and Laptop Store<br> </td>
<td>A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /admin/maintenance/manage_brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263918 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4798&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4798" target="_blank">CVE-2024-4798</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql5.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263918" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263918" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332784" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Computer and Laptop Store<br> </td>
<td>A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/SystemSettings.php?f=update_settings. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263941 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4820&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4820" target="_blank">CVE-2024-4820</a><br><a href="https://github.com/jxm68868/cve/blob/main/upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263941" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263941" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333272" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Open Source Clinic Management System<br> </td>
<td>A vulnerability has been found in SourceCodester Open Source Clinic Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file setting.php. The manipulation of the argument logo leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263929 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4809" target="_blank">CVE-2024-4809</a><br><a href="https://github.com/CveSecLook/cve/issues/26" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263929" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263929" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332581" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--School Intramurals Student Attendance Management System<br> </td>
<td>A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264461 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4925&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4925" target="_blank">CVE-2024-4925</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql6.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264461" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264461" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333875" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--School Intramurals Student Attendance Management System<br> </td>
<td>A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /intrams_sams/manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264462 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4926&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4926" target="_blank">CVE-2024-4926</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql7.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264462" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264462" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333879" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save_product. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264463.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4927&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4927" target="_blank">CVE-2024-4927</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/upload2.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264463" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264463" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333891" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264464.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4928&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4928" target="_blank">CVE-2024-4928</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql8.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264464" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264464" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333893" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability classified as critical was found in SourceCodester Simple Online Bidding System 1.0. This vulnerability affects unknown code of the file /simple-online-bidding-system/index.php?page=view_prod. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264466 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4930&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4930" target="_blank">CVE-2024-4930</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-1.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264466" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264466" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335343" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Bidding System 1.0. This issue affects some unknown processing of the file /simple-online-bidding-system/admin/index.php?page=view_udet. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264467.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4931&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4931" target="_blank">CVE-2024-4931</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-2.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264467" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264467" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335365" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Bidding System 1.0. Affected is an unknown function of the file /simple-online-bidding-system/admin/index.php?page=manage_user. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264468.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4932&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4932" target="_blank">CVE-2024-4932</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-3.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264468" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264468" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335366" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability has been found in SourceCodester Simple Online Bidding System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/index.php?page=manage_product. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264469 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4933&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4933" target="_blank">CVE-2024-4933</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-4.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264469" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264469" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335367" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability classified as problematic has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/admin/ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264465 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4929&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4929" target="_blank">CVE-2024-4929</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/csrf.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264465" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264465" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333894" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Mens Salon Management System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Mens Salon Management System 1.0. Affected by this issue is some unknown functionality of the file view_service.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264926 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5069&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5069" target="_blank">CVE-2024-5069</a><br><a href="https://github.com/menxin996/Cvehub/blob/main/Men&amp;apos;s%20Salon%20Management%20System%20%20view_service.php%20has%20Sqlinjection.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336842" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Sparkle WP--Editorialmag<br> </td>
<td>Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32129&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32129" target="_blank">CVE-2023-32129</a><br><a href="https://patchstack.com/database/vulnerability/editorialmag/wordpress-editorialmag-theme-1-1-9-authenticated-arbitrary-plugin-activation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Stefano Lissa &amp; The Newsletter Team--Newsletter<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Stefano Lissa &amp; The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30522&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30522" target="_blank">CVE-2024-30522</a><br><a href="https://patchstack.com/database/vulnerability/newsletter/wordpress-newsletter-plugin-8-2-0-ip-blacklist-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Strategy11 Form Builder Team--Formidable Forms<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23522&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23522" target="_blank">CVE-2024-23522</a><br><a href="https://patchstack.com/database/vulnerability/formidable/wordpress-formidable-forms-plugin-6-7-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>StylemixThemes--Cost Calculator Builder PRO<br> </td>
<td>Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.72, via the send_demo_webhook() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4789&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4789" target="_blank">CVE-2024-4789</a><br><a href="https://stylemixthemes.com/cost-calculator-plugin/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6840350-7ff4-4ec2-bf2b-94ce6f782537?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Supsystic--Pricing Table by Supsystic<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32790&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32790" target="_blank">CVE-2024-32790</a><br><a href="https://patchstack.com/database/vulnerability/pricing-table-by-supsystic/wordpress-pricing-table-by-supsystic-plugin-1-9-12-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Swift Ideas--Swift Framework<br> </td>
<td>The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all versions up to, and including, 2.7.31. This makes it possible for unauthenticated attackers to update arbitrary posts with arbitrary content. Unfortunately, we did not receive a response from the vendor to send over the vulnerability details.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3915&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3915" target="_blank">CVE-2024-3915</a><br><a href="https://swiftideas.com/swift-framework/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/855055d5-362e-4a92-9e9d-97eab328dcc3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Swift Ideas--Swift Framework<br> </td>
<td>The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 2.7.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unfortunately, we did not receive a response from the vendor to send over the vulnerability details.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3916&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3916" target="_blank">CVE-2024-3916</a><br><a href="https://swiftideas.com/swift-framework/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57103f8e-0874-4e56-8571-254607ada21c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Sylius--Sylius<br> </td>
<td>Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Products, Product Options or Product Variants. The code will be executed while using an autocomplete field with one of the listed entities in the Admin Panel. Also for the taxons in the category tree on the product form.The issue is fixed in versions: 1.12.16, 1.13.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34349&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34349" target="_blank">CVE-2024-34349</a><br><a href="https://github.com/Sylius/Sylius/commit/ba4b66da5af88cdb1bba6174de8bdf42f4853e12" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Sylius/Sylius/security/advisories/GHSA-v2f9-rv6w-vw8r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Synaptics--Synaptics Fingerprint Driver<br> </td>
<td>Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics Hardware Support App.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5447&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5447" target="_blank">CVE-2023-5447</a><br><a href="https://www.synaptics.com/sites/default/files/2023-10/fingerprint-driver-HSAService-security-brief-2023-10-13.pdf" target="_blank">PSIRT@synaptics.com</a></td>
</tr>
<tr>
<td>TIBCO--Hawk<br> </td>
<td>Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3182&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3182" target="_blank">CVE-2024-3182</a><br><a href="https://community.tibco.com/advisories/tibco-security-advisory-may-14-2024-tibco-hawk-cve-2024-3182-r213/" target="_blank">security@tibco.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to the form module. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1 fix the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34356&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34356" target="_blank">CVE-2024-34356</a><br><a href="https://github.com/TYPO3/typo3/commit/2832e2f51f929aeddb5de7d667538a33ceda8156" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/d0393a879a32fb4e3569acad6bdb5cda776be1e5" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/e95a1224719efafb9cab2d85964f240fd0356e64" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-v6mw-h7w6-59w3" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-008" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID tx_cms_showpic_`) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34357&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34357" target="_blank">CVE-2024-34357</a><br><a href="https://github.com/TYPO3/typo3/commit/376474904f6b9a54dc1b785a2e45277cbd13b0d7" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/b31d05d1da3eeaeead2d19eb43b1c3f9c88e15ee" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/d774642381354d3bf5095a5a26e18acd2767f0b1" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-hw6c-6gwq-3m3m" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-009" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query parameter (e.g. `/index.php?eID=tx_cms_showpic?file=3&amp;...&amp;frame=12345`). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34358&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34358" target="_blank">CVE-2024-34358</a><br><a href="https://github.com/TYPO3/typo3/commit/05c95fed869a1a6dcca06c7077b83b6ea866ff14" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/1e70ebf736935413b0531004839362b4fb0755a5" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/df7909b6a1cf0f12a42994d0cc3376b607746142" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-36g8-62qv-5957" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-010" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Tech9logy Creators--WPCS ( WordPress Custom Search )<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tech9logy Creators WPCS ( WordPress Custom Search ) allows Stored XSS.This issue affects WPCS ( WordPress Custom Search ): from n/a through 1.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34418&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34418" target="_blank">CVE-2024-34418</a><br><a href="https://patchstack.com/database/vulnerability/wpcs-wp-custom-search/wordpress-wpcs-wordpress-custom-search-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>The Events Calendar--BookIt<br> </td>
<td>Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24715&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24715" target="_blank">CVE-2024-24715</a><br><a href="https://patchstack.com/database/vulnerability/bookit/wordpress-wordpress-bookit-plugin-plugin-2-4-0-price-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Theme Freesia--Freesia Empire<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Freesia Empire allows Stored XSS.This issue affects Freesia Empire: from n/a through 1.4.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33955&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33955" target="_blank">CVE-2024-33955</a><br><a href="https://patchstack.com/database/vulnerability/freesia-empire/wordpress-freesia-empire-theme-1-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeFuse--Unyson<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.29.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34814&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34814" target="_blank">CVE-2024-34814</a><br><a href="https://patchstack.com/database/vulnerability/unyson/wordpress-unyson-plugin-2-7-29-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeLocation--Custom WooCommerce Checkout Fields Editor<br> </td>
<td>Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33956" target="_blank">CVE-2024-33956</a><br><a href="https://patchstack.com/database/vulnerability/add-fields-to-checkout-page-woocommerce/wordpress-custom-woocommerce-checkout-fields-editor-plugin-1-3-0-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeNectar--Salient Shortcodes<br> </td>
<td>The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortcode in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3811&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3811" target="_blank">CVE-2024-3811</a><br><a href="https://themeforest.net/item/salient-responsive-multipurpose-theme/4363266" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/70682a2d-16f6-4d7e-bf69-f0f3999f03de?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ThimPress--Thim Elementor Kit<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Thim Elementor Kit allows Stored XSS.This issue affects Thim Elementor Kit: from n/a through 1.1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34415&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34415" target="_blank">CVE-2024-34415</a><br><a href="https://patchstack.com/database/vulnerability/thim-elementor-kit/wordpress-thim-elementor-kit-plugin-1-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThroughTek--Kalay SDK<br> </td>
<td>ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6323&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6323" target="_blank">CVE-2023-6323</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>Toidicode.com (thanhtaivtt)--Viet Nam Affiliate<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toidicode.Com (thanhtaivtt) Viet Nam Affiliate allows Stored XSS.This issue affects Viet Nam Affiliate: from n/a through 1.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34417&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34417" target="_blank">CVE-2024-34417</a><br><a href="https://patchstack.com/database/vulnerability/viet-nam-affiliate/wordpress-viet-nam-affiliate-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Tongda--OA<br> </td>
<td>A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code of the file /general/meeting/manage/delete.php. The manipulation of the argument M_ID_STR leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264436. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4903&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4903" target="_blank">CVE-2024-4903</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql3.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264436" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264436" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330632" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Trellix--ePolicy Orchestrator<br> </td>
<td>ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4843&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4843" target="_blank">CVE-2024-4843</a><br><a href="https://thrive.trellix.com/s/article/000013505" target="_blank">trellixpsirt@trellix.com</a></td>
</tr>
<tr>
<td>UkrSolution--Barcode Scanner with Inventory &amp; Order Manager<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in UkrSolution Barcode Scanner with Inventory &amp; Order Manager.This issue affects Barcode Scanner with Inventory &amp; Order Manager: from n/a through 1.5.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34556&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34556" target="_blank">CVE-2024-34556</a><br><a href="https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-4-sensitive-data-exposure-via-exported-file-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>UkrSolution--Barcode Scanner with Inventory &amp; Order Manager<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in UkrSolution Barcode Scanner with Inventory &amp; Order Manager.This issue affects Barcode Scanner with Inventory &amp; Order Manager: from n/a through 1.5.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34557&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34557" target="_blank">CVE-2024-34557</a><br><a href="https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Uniform Server Zero--Uniform Server Zero<br> </td>
<td>vulnerability in Uniform Server Zero, version 10.2.5, consisting of an XSS through the /us_extra/phpinfo.php page. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and partially take over their session details.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5052&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5052" target="_blank">CVE-2023-5052</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-uniform-server-zero" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Valiano--Unite Gallery Lite<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Valiano Unite Gallery Lite allows PHP Local File Inclusion.This issue affects Unite Gallery Lite: from n/a through 1.7.59.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-33310&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33310" target="_blank">CVE-2023-33310</a><br><a href="https://patchstack.com/database/vulnerability/unite-gallery-lite/wordpress-unite-gallery-lite-plugin-1-7-59-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ValvePress--WordPress Automatic Plugin<br> </td>
<td>The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'autoplay' parameter in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4849&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4849" target="_blank">CVE-2024-4849</a><br><a href="https://codecanyon.net/item/wordpress-automatic-plugin/1904470" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4be58bfa-d489-45f5-9169-db8bab718175?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>VeronaLabs--WP SMS<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34811&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34811" target="_blank">CVE-2024-34811</a><br><a href="https://patchstack.com/database/vulnerability/wp-sms/wordpress-wp-sms-plugin-6-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Visualmodo--Borderless Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Visualmodo Borderless - Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg allows Stored XSS.This issue affects Borderless - Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg: from n/a through 1.5.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34757&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34757" target="_blank">CVE-2024-34757</a><br><a href="https://patchstack.com/database/vulnerability/borderless/wordpress-borderless-widgets-elements-templates-and-toolkit-for-elementor-gutenberg-plugin-1-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>W3 Eden Inc.--Download Manager<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32131&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32131" target="_blank">CVE-2024-32131</a><br><a href="https://patchstack.com/database/vulnerability/download-manager/wordpress-download-manager-plugin-3-2-82-file-password-lock-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3787&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3787" target="_blank">CVE-2024-3787</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3788&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3788" target="_blank">CVE-2024-3788</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability could allow an attacker to send multiple command injection payloads to influence the amount of resources consumed.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3789&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3789" target="_blank">CVE-2024-3789</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, login / description fields, passwd1/ passwd2 parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3790&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3790" target="_blank">CVE-2024-3790</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfiguration, name / free memory limit fields , type / password parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3791&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3791" target="_blank">CVE-2024-3791</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplication, execution range field, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3792&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3792" target="_blank">CVE-2024-3792</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts, account name / user password / server fields, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3793&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3793" target="_blank">CVE-2024-3793</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSystem, description field, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3794&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3794" target="_blank">CVE-2024-3794</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplate, name / description fields. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3795&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3795" target="_blank">CVE-2024-3795</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedule, description field. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3796&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3796" target="_blank">CVE-2024-3796</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WP Club Manager--WP Club Manager<br> </td>
<td>Missing Authorization vulnerability in WP Club Manager.This issue affects WP Club Manager: from n/a through 2.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32719&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32719" target="_blank">CVE-2024-32719</a><br><a href="https://patchstack.com/database/vulnerability/wp-club-manager/wordpress-wp-club-manager-plugin-2-2-11-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Happy Coders--Comments Like Dislike<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in WP Happy Coders Comments Like Dislike allows Functionality Bypass.This issue affects Comments Like Dislike: from n/a through 1.2.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25906&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25906" target="_blank">CVE-2024-25906</a><br><a href="https://patchstack.com/database/vulnerability/comments-like-dislike/wordpress-comments-like-dislike-plugin-1-2-1-ip-restriction-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Royal--Royal Elementor Addons<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Addons: from n/a through 1.3.93.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32786&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32786" target="_blank">CVE-2024-32786</a><br><a href="https://patchstack.com/database/vulnerability/royal-elementor-addons/wordpress-royal-elementor-addons-and-templates-plugin-1-3-93-ip-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPBlockart--Magazine Blocks<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockart Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.6.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34760&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34760" target="_blank">CVE-2024-34760</a><br><a href="https://patchstack.com/database/vulnerability/magazine-blocks/wordpress-magazine-blocks-plugin-1-3-6-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPDeveloper--SchedulePress<br> </td>
<td>Missing Authorization vulnerability in WPDeveloper SchedulePress.This issue affects SchedulePress: from n/a through 5.0.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32717" target="_blank">CVE-2024-32717</a><br><a href="https://patchstack.com/database/vulnerability/wp-scheduled-posts/wordpress-schedulepress-plugin-5-0-8-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPMU DEV--Defender Security<br> </td>
<td>Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security: from n/a through 3.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-44581&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-44581" target="_blank">CVE-2022-44581</a><br><a href="https://patchstack.com/database/vulnerability/defender-security/wordpress-defender-security-plugin-3-3-2-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPMU DEV--Defender Security<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25595&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25595" target="_blank">CVE-2024-25595</a><br><a href="https://patchstack.com/database/vulnerability/defender-security/wordpress-defender-security-plugin-4-4-1-ip-restriction-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wangshen--SecGate 3600<br> </td>
<td>A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 up to 20240516. This affects an unknown part of the file /?g=log_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-264747.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5050&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5050" target="_blank">CVE-2024-5050</a><br><a href="https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/s%40%23NGfP%7B4%5Et(%7C%5Dd9/Wangshen%20SecGata%203600%20Firewall%20log_import_save%20arbitrary%20file%20upload%20vulnerability.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264747" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264747" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335968" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Warfare Plugins--Social Warfare<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: from n/a through 4.4.5.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34825&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34825" target="_blank">CVE-2024-34825</a><br><a href="https://patchstack.com/database/vulnerability/social-warfare/wordpress-social-warfare-plugin-4-4-5-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Web-Settler--Landing Page Builder Free Landing Page Templates<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Web-Settler Landing Page Builder - Free Landing Page Templates allows Path Traversal.This issue affects Landing Page Builder - Free Landing Page Templates: from n/a through 3.1.9.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-24379&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24379" target="_blank">CVE-2023-24379</a><br><a href="https://patchstack.com/database/vulnerability/ultimate-landing-page/wordpress-landing-page-builder-free-landing-page-templates-plugin-3-1-9-8-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WebToffee--Order Export &amp; Order Import for WooCommerce<br> </td>
<td>Deserialization of Untrusted Data vulnerability in WebToffee Order Export &amp; Order Import for WooCommerce.This issue affects Order Export &amp; Order Import for WooCommerce: from n/a through 2.4.9.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34751&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34751" target="_blank">CVE-2024-34751</a><br><a href="https://patchstack.com/database/vulnerability/order-import-export-for-woocommerce/wordpress-order-export-order-import-for-woocommerce-plugin-2-4-9-php-object-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Webvitaly--iFrame<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webvitaly iFrame allows Stored XSS.This issue affects iFrame: from n/a through 5.0.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34805&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34805" target="_blank">CVE-2024-34805</a><br><a href="https://patchstack.com/database/vulnerability/iframe/wordpress-iframe-plugin-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wireshark Foundation--Wireshark<br> </td>
<td>MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4854&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4854" target="_blank">CVE-2024-4854</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19726" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/merge_requests/15047" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/merge_requests/15499" target="_blank">cve@gitlab.com</a><br><a href="https://www.wireshark.org/security/wnpa-sec-2024-07.html" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>WordPlus--BP Better Messages<br> </td>
<td>Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Better Messages: from n/a through 2.4.32.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32802&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32802" target="_blank">CVE-2024-32802</a><br><a href="https://patchstack.com/database/vulnerability/bp-better-messages/wordpress-better-messages-plugin-2-4-32-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wpmet--Wp Ultimate Review<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21746&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21746" target="_blank">CVE-2024-21746</a><br><a href="https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-5-ip-limit-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wpmet--Wp Ultimate Review<br> </td>
<td>Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32685&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32685" target="_blank">CVE-2024-32685</a><br><a href="https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-5-review-score-manipulation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Zoom Video Communications, Inc.--Zoom Workplace VDI App for Windows<br> </td>
<td>Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27244&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27244" target="_blank">CVE-2024-27244</a><br><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-24015/" target="_blank">security@zoom.us</a></td>
</tr>
<tr>
<td>Zoom Video Communications, Inc.--see references<br> </td>
<td>Buffer overflow in some Zoom Workplace Apps and SDK's may allow an authenticated user to conduct a denial of service via network access.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27243&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27243" target="_blank">CVE-2024-27243</a><br><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-24014/" target="_blank">security@zoom.us</a></td>
</tr>
<tr>
<td>abuhayat--HTML5 Audio Player- Best WordPress Audio Player Plugin<br> </td>
<td>The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4398&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4398" target="_blank">CVE-2024-4398</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/Elementor/Widgets/Simple.php#L237" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/elementor-widgets/fusion-audio-player.php#L275" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/elementor-widgets/playlist.php#L541" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/elementor-widgets/stamp-audio-player.php#L286" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca646202-b9e2-4272-b0e2-d39cd748fb8e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>aio-libs--aiosmtpd<br> </td>
<td>aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34083&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34083" target="_blank">CVE-2024-34083</a><br><a href="https://github.com/aio-libs/aiosmtpd/commit/b3a4a2c6ecfd228856a20d637dc383541fcdbfda" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aio-libs/aiosmtpd/security/advisories/GHSA-wgjv-9j3q-jhg8" target="_blank">security-advisories@github.com</a><br><a href="https://nostarttls.secvuln.info/" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>argoproj--argo-cd<br> </td>
<td>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32476" target="_blank">CVE-2024-32476</a><br><a href="https://github.com/argoproj/argo-cd/commit/7893979a1e78d59cedd0ba790ded24e30bb40657" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/argoproj/argo-cd/commit/9e5cc5a26ff0920a01816231d59fdb5eae032b5a" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/argoproj/argo-cd/commit/e2df7315fb7d96652186bf7435773a27be330cac" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/argoproj/argo-cd/security/advisories/GHSA-9m6p-x4h2-6frq" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>asterisk--asterisk<br> </td>
<td>Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35190&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35190" target="_blank">CVE-2024-35190</a><br><a href="https://github.com/asterisk/asterisk/commit/85241bd22936cc15760fd1f65d16c98be7aeaf6d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/asterisk/asterisk/pull/600" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/asterisk/asterisk/pull/602" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/asterisk/asterisk/security/advisories/GHSA-qqxj-v78h-hrf9" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>athemes--Sydney Toolbox<br> </td>
<td>The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4473&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4473" target="_blank">CVE-2024-4473</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082233/sydney-toolbox" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/60f16abd-951b-48a0-a363-0221f7e0957d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>automattic--Jetpack WP Security, Backup, Speed, &amp; Growth<br> </td>
<td>The Jetpack - WP Security, Backup, Speed, &amp; Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4392&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4392" target="_blank">CVE-2024-4392</a><br><a href="https://plugins.trac.wordpress.org/browser/jetpack/tags/13.3.1/modules/videopress/class.videopress-player.php#L335" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/11dceac7-7ff8-4384-9046-919c38947c32?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>avimegladon--Custom Post Type Attachment<br> </td>
<td>The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_attachment' shortcode in all versions up to, and including, 3.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4546&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4546" target="_blank">CVE-2024-4546</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087121/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f6ba2907-36f4-4c4d-9e25-d13d32e28690?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>bdthemes--Prime Slider Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)<br> </td>
<td>The Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the General widget in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4339&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4339" target="_blank">CVE-2024-4339</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3080132%40bdthemes-prime-slider-lite%2Ftrunk&amp;old=3079066%40bdthemes-prime-slider-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6eba6056-e087-4347-ad36-96501ceb4cdd?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>blakeblackshear--frigate<br> </td>
<td>Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the filename, a user may intentionally use a large Unicode filename which would lead to a application-level denial of service. This is due to no limitation set on the length of the filename and the costy use of the Unicode normalization with the form NFKD under the hood of `secure_filename()`.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32874&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32874" target="_blank">CVE-2024-32874</a><br><a href="https://github.com/blakeblackshear/frigate/commit/cc851555e4029647986dccc8b8ecf54afee31442" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/blakeblackshear/frigate/security/advisories/GHSA-w4h6-9wrp-v5jq" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>blocksera--Image Hover Effects Elementor Addon<br> </td>
<td>The Image Hover Effects - Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hover Effects Widget in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1166&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1166" target="_blank">CVE-2024-1166</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3068751%40image-hover-effects-addon-for-elementor&amp;new=3068751%40image-hover-effects-addon-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d72a57f-9acc-43e4-af81-024bc6e0d3fd?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>boldgrid--Post and Page Builder by BoldGrid Visual Drag and Drop Editor<br> </td>
<td>The Post and Page Builder by BoldGrid - Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.26.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4400&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4400" target="_blank">CVE-2024-4400</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087230/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9bb6683a-b8e6-4776-880f-5b48966fc5c6?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Elementor Header &amp; Footer Builder<br> </td>
<td>The Elementor Header &amp; Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hfe_svg_mime_types' function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4634&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4634" target="_blank">CVE-2024-4634</a><br><a href="https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/1.6.28/inc/widgets-manager/class-widgets-loader.php#L156" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086402/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f44bb823-bbf3-413b-82b5-a351609270bf?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Elementor Header &amp; Footer Builder<br> </td>
<td>The Elementor Header &amp; Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2619&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2619" target="_blank">CVE-2024-2619</a><br><a href="https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/1.6.25/admin/class-hfe-admin.php#L220" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/1.6.25/admin/class-hfe-admin.php#L74" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3070659%40header-footer-elementor%2Ftrunk&amp;old=3053177%40header-footer-elementor%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/689eb95b-2f72-4aa4-9f21-6ae186346061?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Starter Templates Elementor, WordPress &amp; Beaver Builder Templates<br> </td>
<td>The Starter Templates - Elementor, WordPress &amp; Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_upload_mimes' function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4630&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4630" target="_blank">CVE-2024-4630</a><br><a href="https://plugins.trac.wordpress.org/browser/astra-sites/tags/4.2.0/inc/importers/wxr-importer/class-astra-wxr-importer.php#L416" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084334/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/25edb9e8-65ea-41d1-a95f-09be110ec1d2?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Starter Templates Elementor, WordPress &amp; Beaver Builder Templates<br> </td>
<td>The Starter Templates - Elementor, WordPress &amp; Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1467&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1467" target="_blank">CVE-2024-1467</a><br><a href="https://plugins.trac.wordpress.org/changeset/3074863/astra-sites/tags/4.1.7/inc/classes/class-astra-sites-importer.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3074863/astra-sites/tags/4.1.7/inc/classes/class-astra-sites.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cf5075f9-9658-4a09-bd38-34a72f6560f4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks with AI by Kadence WP - Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the typer effect in the advanced heading widget in all versions up to, and including, 3.2.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4208&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4208" target="_blank">CVE-2024-4208</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3084683%40kadence-blocks&amp;new=3084683%40kadence-blocks&amp;sfp_email=&amp;sfph_mail=#file2" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7ea2bb8c-cc8b-49de-9c8e-2c8c0569f4ac?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks with AI by Kadence WP - Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4209&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4209" target="_blank">CVE-2024-4209</a><br><a href="https://plugins.trac.wordpress.org/browser/kadence-blocks/trunk/includes/blocks/class-kadence-blocks-countdown-block.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083616/kadence-blocks/trunk/dist/blocks-countdown.js" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cff2e5be-0de0-4e62-a881-6156760b7d99?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the plugin's blocks in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4481&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4481" target="_blank">CVE-2024-4481</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083616/kadence-blocks/trunk/includes/blocks/class-kadence-blocks-advanced-heading-block.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ad0e4292-d890-499b-b70a-ed638d5b8ee9?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks by Kadence Blocks - Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', 'Lottie Animations', 'Row Layout', 'Google Maps', and 'Advanced Gallery' blocks in all versions up to, and including, 3.2.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3189&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3189" target="_blank">CVE-2024-3189</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083616/kadence-blocks/trunk/includes/blocks/class-kadence-blocks-lottie-block.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3076712%40kadence-blocks&amp;new=3076712%40kadence-blocks&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3084683%40kadence-blocks&amp;new=3084683%40kadence-blocks&amp;sfp_email=&amp;sfph_mail=#file2" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/766b0bde-c555-40c1-b174-20045bd89c11?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>buddypress--BuddyPress<br> </td>
<td>The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_name' parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3974&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3974" target="_blank">CVE-2024-3974</a><br><a href="https://plugins.trac.wordpress.org/browser/buddypress/trunk/bp-members/bp-members-admin.php#L145" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/buddypress/trunk/bp-members/bp-members-blocks.php#L347" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3079691/buddypress" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3657384e-025a-44ad-8b7e-1a2fea17dcc3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>carazo--Import and export users and customers<br> </td>
<td>The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4656&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4656" target="_blank">CVE-2024-4656</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085346%40import-users-from-csv-with-meta%2Ftrunk&amp;old=3078277%40import-users-from-csv-with-meta%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af742451-b2d6-445a-9a10-e950490f6c7c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>carazo--Import and export users and customers<br> </td>
<td>The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4734&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4734" target="_blank">CVE-2024-4734</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085346%40import-users-from-csv-with-meta%2Ftrunk&amp;old=3078277%40import-users-from-csv-with-meta%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0dca168f-a383-42fc-91ba-d78a5d7e6724?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>code-projects--Budget Management<br> </td>
<td>A vulnerability classified as critical was found in code-projects Budget Management 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument edit leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264745 was assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5048&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5048" target="_blank">CVE-2024-5048</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Budget%20Management%20App/Budget%20Management%20App%20-%20SQL%20Injection%20-%201.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264745" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264745" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335666" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown part of the file /login.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264537 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4972&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4972" target="_blank">CVE-2024-4972</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20SQL%20Injection%20-%201.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264537" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264537" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335199" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument name/number/address leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264538 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4973&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4973" target="_blank">CVE-2024-4973</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20SQL%20Injection%20-%202.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264538" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264538" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335200" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>codename065--Sliding Widgets<br> </td>
<td>Missing Authorization vulnerability in codename065 Sliding Widgets allows Cross-Site Scripting (XSS).This issue affects Sliding Widgets: from n/a through 1.5.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33938&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33938" target="_blank">CVE-2024-33938</a><br><a href="https://patchstack.com/database/vulnerability/sliding-widgets/wordpress-sliding-widgets-plugin-1-5-0-broken-access-control-to-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>codewoogeek--Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro<br> </td>
<td>The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.3.1. This is due to the plugin for WordPress allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4038&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4038" target="_blank">CVE-2024-4038</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3080830%40back-in-stock-notifier-for-woocommerce&amp;new=3080830%40back-in-stock-notifier-for-woocommerce&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7f59489-9bff-4d22-8f99-6ea52d702ecf?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>creativethemeshq--Blocksy Companion<br> </td>
<td>The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4487&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4487" target="_blank">CVE-2024-4487</a><br><a href="https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.0.45/framework/features/svg.php#L20" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084198/#file18" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5208529c-4ac3-42a4-82d0-7f4d2e486236?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>creativethemeshq--Blocksy<br> </td>
<td>The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' parameter in versions up to, and including, 2.0.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4158&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4158" target="_blank">CVE-2024-4158</a><br><a href="https://themes.trac.wordpress.org/changeset/226440/blocksy" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22d1ccf3-ac1a-4dfc-81c3-b8eb88795bc1?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>croixhaug--Appointment Booking Calendar Simply Schedule Appointments Booking Plugin<br> </td>
<td>The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4288&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4288" target="_blank">CVE-2024-4288</a><br><a href="https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/trunk/includes/class-shortcodes.php#L677" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087297/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/84262b4a-a662-4aaf-9eae-f5cca8f6cd06?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>daext--Soccer Engine Soccer Plugin for WordPress<br> </td>
<td>The Soccer Engine - Soccer Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation when saving match and team settings. This makes it possible for unauthenticated attackers to change plugin settings as well as teams, players, etc. via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4312&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4312" target="_blank">CVE-2024-4312</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081944%40soccer-engine-lite%2Ftrunk&amp;old=3066918%40soccer-engine-lite%2Ftrunk" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57e84624-98ab-495b-b985-908302527b3a?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>davidanderson--Testimonial Slider<br> </td>
<td>The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'testimonialcategory' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4193&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4193" target="_blank">CVE-2024-4193</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3080579%40testimonial-slider&amp;new=3080579%40testimonial-slider&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd7ed687-4049-4957-86e9-b2f59621c747?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>deTheme--DethemeKit For Elementor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Elementor: from n/a through 2.1.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34575&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34575" target="_blank">CVE-2024-34575</a><br><a href="https://patchstack.com/database/vulnerability/dethemekit-for-elementor/wordpress-dethemekit-for-elementor-plugin-2-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>detheme--DethemeKit For Elementor<br> </td>
<td>The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4374&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4374" target="_blank">CVE-2024-4374</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3088000%40dethemekit-for-elementor&amp;new=3088000%40dethemekit-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bcd9384c-5af3-4544-8179-c2f5550dd152?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>devitemsllc--HT Mega Absolute Addons For Elementor<br> </td>
<td>The HT Mega - Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3989&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3989" target="_blank">CVE-2024-3989</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3074490%40ht-mega-for-elementor&amp;new=3074490%40ht-mega-for-elementor&amp;sfp_email=&amp;sfph_mail=#file3" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/03fba6bb-ff30-42bb-936b-93c009a7e3f7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>devitemsllc--HT Mega Absolute Addons For Elementor<br> </td>
<td>The HT Mega - Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip &amp; Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3990&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3990" target="_blank">CVE-2024-3990</a><br><a href="https://plugins.trac.wordpress.org/browser/ht-mega-for-elementor/tags/2.5.0/includes/widgets/htmega_tooltip.php#L620" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3074490%40ht-mega-for-elementor&amp;new=3074490%40ht-mega-for-elementor&amp;sfp_email=&amp;sfph_mail=#file4" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3074490%40ht-mega-for-elementor&amp;new=3074490%40ht-mega-for-elementor&amp;sfp_email=&amp;sfph_mail=#file5" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98e74a23-b586-4d6a-b1ab-78838b0eed61?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>devitemsllc--ShopLentor WooCommerce Builder for Elementor &amp; Gutenberg +12 Modules All in One Solution (formerly WooLentor)<br> </td>
<td>The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6327&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6327" target="_blank">CVE-2023-6327</a><br><a href="https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/2.7.4/includes/modules/sales-notification/class.sale_notification.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080097/woolentor-addons/trunk/includes/modules/sales-notification/class.sale_notification.php?contextall=1&amp;old=3061864&amp;old_path=%2Fwoolentor-addons%2Ftrunk%2Fincludes%2Fmodules%2Fsales-notification%2Fclass.sale_notification.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/263324cb-31b7-40ad-ad7d-4582e128cd75?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>directus--directus<br> </td>
<td>Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like the other JWT tokens where they are not actually invalidated when logging out. The `directus_session` gets destroyed and the cookie gets deleted but if the cookie value is captured, it will still work for the entire expiry time which is set to 1 day by default. Making it effectively a long lived unrevokable stateless token instead of the stateful session token it was meant to be. This vulnerability is fixed in 10.11.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34709&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34709" target="_blank">CVE-2024-34709</a><br><a href="https://github.com/directus/directus/commit/a6172f8a6a0f31a6bf4305a090de172ebfb63bcf" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/directus/directus/security/advisories/GHSA-g65h-35f3-x2w3" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>directus--directus<br> </td>
<td>Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any collection using redacted hashed fields can get access the raw stored version using the `alias` functionality on the API. Normally, these redacted fields will return `**********` however if we change the request to `?alias[workaround]=redacted` we can instead retrieve the plain text value for the field. This can be avoided by removing permission to view the sensitive fields entirely from users or roles that should not be able to see them. This vulnerability is fixed in 10.11.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34708&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34708" target="_blank">CVE-2024-34708</a><br><a href="https://github.com/directus/directus/commit/e70a90c267bea695afce6545174c2b77517d617b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/directus/directus/security/advisories/GHSA-p8v3-m643-4xqx" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>divSpot--DS Site Message<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in divSpot DS Site Message.This issue affects DS Site Message: from n/a through 1.14.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34439&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34439" target="_blank">CVE-2024-34439</a><br><a href="https://patchstack.com/database/vulnerability/ds-site-message/wordpress-ds-site-message-plugin-1-14-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>envothemes--Envo Extra<br> </td>
<td>The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4385&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4385" target="_blank">CVE-2024-4385</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/button/button.php#L679" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/counter/counter.php#L754" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/icon-box/icon-box.php#L909" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/team/team.php#L1189" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/testimonial/testimonial.php#L899" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080715/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/83d78ff7-bd59-431e-b579-156e23ede053?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>fluxcd--source-controller<br> </td>
<td>The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and is a core component of the GitOps toolkit. Prior to version 1.2.5, when source-controller was configured to use an Azure SAS token when connecting to Azure Blob Storage, the token was logged along with the Azure URL when the controller encountered a connection error. An attacker with access to the source-controller logs could use the token to gain access to the Azure Blob Storage until the token expires. This vulnerability was fixed in source-controller v1.2.5. There is no workaround for this vulnerability except for using a different auth mechanism such as Azure Workload Identity.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31216&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31216" target="_blank">CVE-2024-31216</a><br><a href="https://github.com/fluxcd/source-controller/commit/915d1a072a4f37dd460ba33079dc094aa6e72fa9" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/fluxcd/source-controller/pull/1430" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/fluxcd/source-controller/security/advisories/GHSA-v554-xwgw-hc3w" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>frappe--frappe<br> </td>
<td>Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34074&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34074" target="_blank">CVE-2024-34074</a><br><a href="https://github.com/frappe/frappe/commit/65b3c42635038cdff17d3109be6c373bac004829" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/frappe/frappe/pull/26304" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/frappe/frappe/security/advisories/GHSA-7g27-q225-j894" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>freescout-helpdesk--freescout<br> </td>
<td>FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototype Pollution vulnerability in the `/public/js/main.js` source file. The Prototype Pollution arises because the `getQueryParam` Function recursively merges an object containing user-controllable properties into an existing object (For URL Query Parameters Parsing), without first sanitizing the keys. This can allow an attacker to inject a property with a key `__proto__`, along with arbitrarily nested properties. The merge operation assigns the nested properties to the `params` object's prototype instead of the target object itself. As a result, the attacker can pollute the prototype with properties containing harmful values, which are then inherited by user-defined objects and subsequently used by the application dangerously. The vulnerability lets an attacker control properties of objects that would otherwise be inaccessible. If the application subsequently handles an attacker-controlled property in an unsafe way, this can potentially be chained with other vulnerabilities like DOM-based XSS, Open Redirection, Cookie Manipulation, Link Manipulation, HTML Injection, etc. Version 1.8.139 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34698&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34698" target="_blank">CVE-2024-34698</a><br><a href="https://github.com/freescout-helpdesk/freescout/commit/2614514bc6d6c4ad563202a1c9cae5a97b195cc5" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/freescout-helpdesk/freescout/security/advisories/GHSA-rx6j-4c33-9h3r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>giuliopanda--ADFO Custom data in admin dashboard<br> </td>
<td>The ADFO - Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dbp_id' parameter in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4104&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4104" target="_blank">CVE-2024-4104</a><br><a href="https://plugins.trac.wordpress.org/browser/admin-form/trunk/admin/class-af-list-admin.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081090%40admin-form&amp;new=3081090%40admin-form&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e61110fc-cc2d-4207-97b6-b21459334216?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>giuliopanda--ADFO Custom data in admin dashboard<br> </td>
<td>The ADFO - Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.0. This is due to missing or incorrect nonce validation on several functions hooked via the controller() function. This makes it possible for unauthenticated attackers to edit the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4103&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4103" target="_blank">CVE-2024-4103</a><br><a href="https://plugins.trac.wordpress.org/changeset/3081090/admin-form/trunk/admin/class-af-list-admin.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d797238-f8f3-44d7-8c16-bee23ce12ae0?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>https://elementor.com/--Elementor Website Builder Pro<br> </td>
<td>The Elementor Website Builder - More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in versions up to, and including, 3.21.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4107&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4107" target="_blank">CVE-2024-4107</a><br><a href="https://doc.clickup.com/9011113249/d/h/8chnb91-5091/3951e6f2afbd388" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0d5d47bd-4f05-4dc7-84c1-f7bc1196ee16?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>iePlexus--Featured Content Gallery<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iePlexus Featured Content Gallery allows Stored XSS.This issue affects Featured Content Gallery: from n/a through 3.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34424&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34424" target="_blank">CVE-2024-34424</a><br><a href="https://patchstack.com/database/vulnerability/featured-content-gallery/wordpress-featured-content-gallery-plugin-3-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>iqonicdesign--Graphina Elementor Charts and Graphs<br> </td>
<td>The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4574&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4574" target="_blank">CVE-2024-4574</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/area/widget/area_chart.php#L457" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/bubble/widget/bubble_chart.php#L685" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/candle/widget/candle_chart.php#L517" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/column/widget/column_chart.php#L531" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/distributed_column/widget/Distributed_Column_chart.php#L464" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/donut/widget/donut_chart.php#L325" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/heatmap/widget/heatmap_chart.php#L448" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/line/widget/line_chart.php#L426" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/pie/widget/pie_chart.php#L279" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/polar/widget/polar_chart.php#L413" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/radar/widget/radar_chart.php#L546" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/radial/widget/radial_chart.php#L417" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/scatter/widget/scatter_chart.php#L419" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/timeline/widget/timeline_chart.php#L462" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/area/widget/area_google_chart.php#L570" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/bar/widget/bar_google_chart.php#L524" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/column/widget/column_google_chart.php#L536" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/donut/widget/donut_google_chart.php#L384" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/line/widget/line_google_chart.php#L578" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/pie/widget/pie_google_chart.php#L391" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1febe2d8-d354-4c78-a611-c1bb0937e53d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ithemelandco--Bulk Posts Editing For WordPress<br> </td>
<td>The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 4.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to invoke their corresponding functions. This may lead to post creation and duplication, post content retrieval, post taxonomy manipulation.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4199&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4199" target="_blank">CVE-2024-4199</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085134%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;old=2946926%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/683131a0-eec3-4251-b322-5c2088855687?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ithemelandco--Bulk Posts Editing For WordPress<br> </td>
<td>The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on the plugin's AJAX actions.. This makes it possible for unauthenticated attackers to create and duplicate posts, retrieve post content, and modify post taxonomy among other things via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4204&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4204" target="_blank">CVE-2024-4204</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085134%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;old=2946926%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=#file51" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34b39462-32c5-4f7d-b54f-d95f40b6ed92?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>justinbusa--Beaver Builder WordPress Page Builder<br> </td>
<td>The Beaver Builder - WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_target parameter in all versions up to, and including, 2.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3923&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3923" target="_blank">CVE-2024-3923</a><br><a href="https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.8.0.7/modules/button/includes/frontend.php#L14" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3078825%40beaver-builder-lite-version%2Ftrunk&amp;old=3062187%40beaver-builder-lite-version%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/99960ff7-62e1-4c44-ae8e-ebda3e075781?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>justinbusa--Beaver Builder WordPress Page Builder<br> </td>
<td>The Beaver Builder - WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the photo widget crop attribute in all versions up to, and including, 2.8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4430&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4430" target="_blank">CVE-2024-4430</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3083534%40beaver-builder-lite-version%2Ftrunk&amp;old=3078825%40beaver-builder-lite-version%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd6ed285-f215-44d3-9db9-9b2bfffee60a?source=cve" target="_blank">security@wordfence.com</a><br><a href="https://www.wpbeaverbuilder.com/change-logs/?utm_medium=bb-lite&amp;utm_source=repo-readme&amp;utm_campaign=repo-changelog-page" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>kraftplugins--Mega Elements Addons for Elementor<br> </td>
<td>The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4702&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4702" target="_blank">CVE-2024-4702</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085457/mega-elements-addons-for-elementor" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3808ca2a-e78e-4118-890b-c22a71f8e855?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>levelfourstorefront--Shopping Cart &amp; eCommerce Store<br> </td>
<td>The Shopping Cart &amp; eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details, addresses and other PII.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4213&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4213" target="_blank">CVE-2024-4213</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084202/wp-easycart/trunk/admin/inc/wp_easycart_admin.php?old=3068711&amp;old_path=wp-easycart%2Ftrunk%2Fadmin%2Finc%2Fwp_easycart_admin.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/93daab72-1243-4a05-91d3-9254a1aac727?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>litonice13--Master Addons Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor<br> </td>
<td>The Master Addons - Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title_html_tag attribute in all versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3134&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3134" target="_blank">CVE-2024-3134</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3087193%40master-addons%2Ftrunk&amp;old=3078134%40master-addons%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6106c972-5475-4c19-8630-3a01edc616ad?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>litonice13--Master Addons Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor<br> </td>
<td>The Master Addons - Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4580&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4580" target="_blank">CVE-2024-4580</a><br><a href="https://plugins.trac.wordpress.org/browser/master-addons/trunk/addons/ma-image-hover-effects/ma-image-hover-effects.php#L1546" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/master-addons/trunk/addons/ma-tabs/ma-tabs.php#L1068" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087193/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e3e3ac84-dd82-42b0-80b9-c876731170d5?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>mantisbt--mantisbt<br> </td>
<td>MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when resolving or closing issues (`bug_change_status_page.php`) belonging to a project linking said custom field, viewing issues (`view_all_bug_page.php`) when the custom field is displayed as a column, or printing issues (`print_all_bug_page.php`) when the custom field is displayed as a column. Version 2.26.2 contains a patch for the issue. As a workaround, ensure Custom Field Names do not contain HTML tags.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34081&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34081" target="_blank">CVE-2024-34081</a><br><a href="https://github.com/mantisbt/mantisbt/commit/447a521aae0f82f791b8116a14a20e276df739be" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/security/advisories/GHSA-wgx7-jp56-65mq" target="_blank">security-advisories@github.com</a><br><a href="https://mantisbt.org/bugs/view.php?id=34432" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>mantisbt--mantisbt<br> </td>
<td>MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't have access to, then it gets hyperlinked. Clicking on the link gives an access denied error as expected, yet some information remains available via the link, link label, and tooltip. This can result in disclosure of the existence of the note, the note author name, the note creation timestamp, and the issue id the note belongs to. Version 2.26.2 contains a patch for the issue. No known workarounds are available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34080&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34080" target="_blank">CVE-2024-34080</a><br><a href="https://github.com/mantisbt/mantisbt/commit/0a50562369d823689c9b946066d1e49d3c2df226" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/pull/2000" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/security/advisories/GHSA-99jc-wqmr-ff2q" target="_blank">security-advisories@github.com</a><br><a href="https://mantisbt.org/bugs/view.php?id=34434" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>matrix-org--matrix-sdk-crypto<br> </td>
<td>The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's devices and provides a redundant copy in case all devices are lost. The key backup uses asymmetric cryptography, with each server-side key backup assigned a unique public-private key pair. Due to a logic bug introduced in commit 71136e44c03c79f80d6d1a2446673bc4d53a2067, matrix-sdk-crypto version 0.7.0 will sometimes log the private part of the backup key pair to Rust debug logs (using the `tracing` crate). This issue has been resolved in matrix-sdk-crypto version 0.7.1. No known workarounds are available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34353&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34353" target="_blank">CVE-2024-34353</a><br><a href="https://crates.io/crates/matrix-sdk-crypto/0.7.1" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/commit/71136e44c03c79f80d6d1a2446673bc4d53a2067" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/commit/fa10bbb5dd0f9120a51aa1854cec752e25790bb0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/releases/tag/matrix-sdk-crypto-0.7.1" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-9ggc-845v-gcgv" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>matter-labs--era-compiler-solidity<br> </td>
<td>era-compiler-solidity is the ZKsync compiler for Solidity. The problem occurred during instruction selection in the `DAGCombine` phase while visiting the XOR operation. The issue arises when attempting to fold the expression `!(x cc y)` into `(x !cc y)`. To perform this transformation, the second operand of XOR should be a constant representing the true value. However, it was incorrectly assumed that -1 represents the true value, when in fact, 1 is the correct representation, so this transformation for this case should be skipped. This vulnerability is fixed in 1.4.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34704&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34704" target="_blank">CVE-2024-34704</a><br><a href="https://github.com/matter-labs/era-compiler-solidity/security/advisories/GHSA-22pj-7cvw-r3gc" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>mgibbs189--Custom Field Suite<br> </td>
<td>The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3068&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3068" target="_blank">CVE-2024-3068</a><br><a href="https://plugins.trac.wordpress.org/browser/custom-field-suite/trunk/templates/field_html.php?order=date&amp;desc=1#L46" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3080330%40custom-field-suite%2Ftrunk&amp;old=3042177%40custom-field-suite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0ab546cc-b099-4d26-bf42-785952fcfd8c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>mihdan--Mihdan: Yandex Turbo Feed<br> </td>
<td>The Mihdan: Yandex Turbo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4411&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4411" target="_blank">CVE-2024-4411</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081039%40mihdan-yandex-turbo-feed%2Ftrunk&amp;old=3005548%40mihdan-yandex-turbo-feed%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6ecf99ef-f879-426f-8a05-129be77f1157?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>miraheze--CreateWiki<br> </td>
<td>CreateWiki is Miraheze's MediaWiki extension for requesting &amp; creating wikis. It is possible for users to be considered as the requester of a specific wiki request if their local user ID on any wiki in a wiki farm matches the local ID of the requester at the wiki where the wiki request was made. This allows them to go to that request entry's on Special:RequestWikiQueue on the wiki where their local user ID matches and take any actions that the wiki requester is allowed to take from there. Commit 02e0f298f8d35155c39aa74193cb7b867432c5b8 fixes the issue. Important note about the fix: This vulnerability has been fixed by disabling access to the REST API and special pages outside of the wiki configured as the "global wiki" in `$wgCreateWikiGlobalWiki` in a user's MediaWiki settings. As a workaround, it is possible to disable the special pages outside of one's own global wiki by doing something similar to `miraheze/mw-config` commit e5664995fbb8644f9a80b450b4326194f20f9ddc that is adapted to one's own setup. As for the REST API, before the fix, there wasn't any REST endpoint that allowed one to make writes. Regardless, it is possible to also disable it outside of the global wiki by using `$wgCreateWikiDisableRESTAPI` and `$wgConf` in the configuration for one's own wiki farm..</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34701&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34701" target="_blank">CVE-2024-34701</a><br><a href="https://github.com/miraheze/CreateWiki/commit/02e0f298f8d35155c39aa74193cb7b867432c5b8" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/miraheze/CreateWiki/security/advisories/GHSA-89fx-77w7-rc64" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/miraheze/mw-config/commit/1798e53901a202b62edab32f8bcd5c6b9e574191" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/miraheze/mw-config/commit/e5664995fbb8644f9a80b450b4326194f20f9ddc" target="_blank">security-advisories@github.com</a><br><a href="https://issue-tracker.miraheze.org/T12011" target="_blank">security-advisories@github.com</a><br><a href="https://issue-tracker.miraheze.org/T12102" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>monetizemore--Advanced Ads  Ad Manager &amp; AdSense<br> </td>
<td>The Advanced Ads - Ad Manager &amp; AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Ad widget in all versions up to, and including, 1.52.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3952&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3952" target="_blank">CVE-2024-3952</a><br><a href="https://plugins.trac.wordpress.org/browser/advanced-ads/tags/1.52.1/modules/gutenberg/includes/class-gutenberg.php#L224" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081914%40advanced-ads&amp;new=3081914%40advanced-ads&amp;sfp_email=&amp;sfph_mail=#file4" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4ea634b5-72db-428c-96b4-15ef6025ab1d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>mra13--Simple Membership<br> </td>
<td>The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4383&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4383" target="_blank">CVE-2024-4383</a><br><a href="https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.4.3/classes/shortcode-related/class.swpm-shortcodes-handler.php#L228" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3081024/simple-membership/trunk/classes/shortcode-related/class.swpm-shortcodes-handler.php?old=3010737&amp;old_path=%2Fsimple-membership%2Ftrunk%2Fclasses%2Fshortcode-related%2Fclass.swpm-shortcodes-handler.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/56fdbf80-8ea2-412a-b166-b7c27de88e70?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>n/a--DedeCMS<br> </td>
<td>A vulnerability classified as problematic has been found in DedeCMS 5.7.114. This affects an unknown part of the file /sys_verifies.php?action=view. The manipulation of the argument filename with the input ../../../../../etc/passwd leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263889 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4790&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4790" target="_blank">CVE-2024-4790</a><br><a href="https://github.com/gatsby2003/DedeCms/blob/main/Directory_traversal_arbitrary_file_read.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263889" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263889" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.329483" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>n/a--Emlog Pro<br> </td>
<td>A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown functionality of the file admin/setting.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264740. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5043&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5043" target="_blank">CVE-2024-5043</a><br><a href="https://github.com/ssteveez/emlog/blob/main/emlog%20pro%20version%202.3.4%20Admin%20side%20can%20upload%20arbitrary%20files%20and%20getshell.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264740" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264740" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331854" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>n/a--Endurance Gaming Mode software installers<br> </td>
<td>Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-42433&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42433" target="_blank">CVE-2023-42433</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00965.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Advisor software<br> </td>
<td>Uncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21772&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21772" target="_blank">CVE-2024-21772</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01047.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) BIOS PPAM firmware<br> </td>
<td>Improper conditions check in some Intel(R) BIOS PPAM firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-28383&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-28383" target="_blank">CVE-2023-28383</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00814.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST software<br> </td>
<td>Uncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40155&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40155" target="_blank">CVE-2023-40155</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST software<br> </td>
<td>Improper access control for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-39433&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-39433" target="_blank">CVE-2023-39433</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST software<br> </td>
<td>Null pointer dereference for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41082&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41082" target="_blank">CVE-2023-41082</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST<br> </td>
<td>Improper access control in some Intel(R) CST before version 2.1.10300 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43487&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43487" target="_blank">CVE-2023-43487</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Chipset Device Software<br> </td>
<td>Uncontrolled search path for some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21814&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21814" target="_blank">CVE-2024-21814</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01032.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Computing Improvement Program software<br> </td>
<td>Uncontrolled search path for some Intel(R) Computing Improvement Program software before version 2.4.0.10654 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21843&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21843" target="_blank">CVE-2024-21843</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01059.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Core(TM) Ultra Processors<br> </td>
<td>Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46103&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46103" target="_blank">CVE-2023-46103</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01052.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DLB driver software<br> </td>
<td>Improper input validation for some Intel(R) DLB driver software before version 8.5.0 may allow an authenticated user to potentially denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22015&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22015" target="_blank">CVE-2024-22015</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00996.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors<br> </td>
<td>Hardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors may allow an authorized user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21823&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21823" target="_blank">CVE-2024-21823</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01084.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DSA software uninstallers<br> </td>
<td>Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45743&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45743" target="_blank">CVE-2023-45743</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01031.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Data Center GPU Max Series 1100 and 1550 products<br> </td>
<td>Improper conditions check in the Intel(R) Data Center GPU Max Series 1100 and 1550 products may allow an privileged user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47165&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47165" target="_blank">CVE-2023-47165</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01041.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Distribution for GDB software<br> </td>
<td>Uncontrolled search path for some Intel(R) Distribution for GDB software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21841&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21841" target="_blank">CVE-2024-21841</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01042.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Ethernet Controller Administrative Tools software<br> </td>
<td>Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21828&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21828" target="_blank">CVE-2024-21828</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01056.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) FPGA products<br> </td>
<td>Out of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege and information disclosure.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-49614&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-49614" target="_blank">CVE-2023-49614</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01050.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) FPGA products<br> </td>
<td>Improper input validation in firmware for some Intel(R) FPGA products before version 2.9.1 may allow denial of service.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22390&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22390" target="_blank">CVE-2024-22390</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01050.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA Framework software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-35192&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-35192" target="_blank">CVE-2023-35192</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA Framework software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21861&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21861" target="_blank">CVE-2024-21861</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01067.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41961&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41961" target="_blank">CVE-2023-41961</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21788&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21788" target="_blank">CVE-2024-21788</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01067.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Graphics Windows DCH driver software<br> </td>
<td>Uncontrolled search path in Intel(R) Graphics Command Center Service bundled in some Intel(R) Graphics Windows DCH driver software before versions 31.0.101.3790/31.0.101.2114 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43751&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43751" target="_blank">CVE-2023-43751</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00937.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Inspector software<br> </td>
<td>Uncontrolled search path in some Intel(R) Inspector software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22379&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22379" target="_blank">CVE-2024-22379</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01043.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK software<br> </td>
<td>Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48368&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48368" target="_blank">CVE-2023-48368</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK<br> </td>
<td>Improper buffer restrictions in Intel(R) Media SDK all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45221&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45221" target="_blank">CVE-2023-45221</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Neural Compressor software<br> </td>
<td>Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21792&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21792" target="_blank">CVE-2024-21792</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01109.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PCM software<br> </td>
<td>Uncontrolled search path in some Intel(R) PCM software before version 202311 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21818&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21818" target="_blank">CVE-2024-21818</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01035.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PROSet/Wireless WiFi software for Windows<br> </td>
<td>Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40536&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40536" target="_blank">CVE-2023-40536</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PROSet/Wireless WiFi software for linux<br> </td>
<td>Improper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47210&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47210" target="_blank">CVE-2023-47210</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PROSet/Wireless WiFi software<br> </td>
<td>Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38417&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38417" target="_blank">CVE-2023-38417</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45736&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45736" target="_blank">CVE-2023-45736</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41234&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41234" target="_blank">CVE-2023-41234</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windwos<br> </td>
<td>Improper initialization in some Intel(R) Power Gadget software for Windwos all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45315&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45315" target="_blank">CVE-2023-45315</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45846&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45846" target="_blank">CVE-2023-45846</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Processor Diagnostic Tool software<br> </td>
<td>Uncontrolled search path in some Intel(R) Processor Diagnostic Tool software before version 4.1.9.41 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21831&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21831" target="_blank">CVE-2024-21831</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01069.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Processor Identification Utility software<br> </td>
<td>Uncontrolled search path in some Intel(R) Processor Identification Utility software before versions 6.10.34.1129, 7.1.6 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21774&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21774" target="_blank">CVE-2024-21774</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01054.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Lite Edition Design software<br> </td>
<td>Improper conditions check for some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21809&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21809" target="_blank">CVE-2024-21809</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Lite Edition Design software<br> </td>
<td>Uncontrolled search path in some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21837&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21837" target="_blank">CVE-2024-21837</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Pro Edition Design software<br> </td>
<td>Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro Edition Design software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21777&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21777" target="_blank">CVE-2024-21777</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Standard Edition Design software<br> </td>
<td>Uncontrolled search path in some Intel(R) Quartus(R) Prime Standard Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21862&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21862" target="_blank">CVE-2024-21862</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) TDX module software<br> </td>
<td>Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47855&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47855" target="_blank">CVE-2023-47855</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) VTune(TM) Profiler software<br> </td>
<td>Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45320&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45320" target="_blank">CVE-2023-45320</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01034.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Wireless Bluetooth products for Windows<br> </td>
<td>Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47859&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47859" target="_blank">CVE-2023-47859</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Wireless Bluetooth(R) products for Windows<br> </td>
<td>Improper conditions check for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.20 may allow a privileged user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45845&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45845" target="_blank">CVE-2023-45845</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) XTU software<br> </td>
<td>Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21835&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21835" target="_blank">CVE-2024-21835</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01066.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Libva software maintained by Intel(R)<br> </td>
<td>Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-39929&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-39929" target="_blank">CVE-2023-39929</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01012.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server Board S2600BP products<br> </td>
<td>Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-22662&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">5.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-22662" target="_blank">CVE-2023-22662</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31952&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31952" target="_blank">CVE-2024-31952</a><br><a href="https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31952/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31953&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31953" target="_blank">CVE-2024-31953</a><br><a href="https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31953/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28759&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28759" target="_blank">CVE-2024-28759</a><br><a href="https://support2.windriver.com/index.php?page=cve&amp;on=view&amp;id=CVE-2024-28759" target="_blank">cve@mitre.org</a><br><a href="https://windriver.com/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--onboard video driver software for Intel(R) Server Boards based on Intel(R) 62X Chipset<br> </td>
<td>Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based on Intel(R) 62X Chipset may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-42668&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42668" target="_blank">CVE-2023-42668</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00962.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>nalam-1--Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )<br> </td>
<td>The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2923&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2923" target="_blank">CVE-2024-2923</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3078558%40magical-addons-for-elementor&amp;new=3078558%40magical-addons-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/733f5ded-e8cb-4895-b938-889cea32f027?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>nko--Visual Portfolio, Photo Gallery &amp; Post Grid<br> </td>
<td>The Visual Portfolio, Photo Gallery &amp; Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4363&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4363" target="_blank">CVE-2024-4363</a><br><a href="https://plugins.trac.wordpress.org/browser/visual-portfolio/trunk/templates/items-list/item-parts/title.php#L22" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/visual-portfolio/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab5e09d8-6fa3-4a5b-bee1-6648df4f4b3b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>nocodb--nocodb<br> </td>
<td>NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of sensitive data in the database. Version 0.202.10 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50718&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50718" target="_blank">CVE-2023-50718</a><br><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-8fxg-mr34-jqr8" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nocodb--nocodb<br> </td>
<td>NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site scripting attack. This allows remote attacker to execute JavaScript code in the context of the user accessing the vector. An attacker could have used this vulnerability to execute requests in the name of a logged-in user or potentially collect information about the attacked user by displaying a malicious form. Version 0.202.10 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50717" target="_blank">CVE-2023-50717</a><br><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-qg73-g3cf-vhhh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nvidia--ChatRTX<br> </td>
<td>NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue by data sniffing. A successful exploit of this vulnerability might lead to information disclosure.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0098&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0098" target="_blank">CVE-2024-0098</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5533" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--NVIDIA Triton Inference Server<br> </td>
<td>NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0100&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0100" target="_blank">CVE-2024-0100</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5535" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--NVIDIA Triton Inference Server<br> </td>
<td>NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a network API. A successful exploit of this vulnerability might lead to denial of service and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0088&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0088" target="_blank">CVE-2024-0088</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5535" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>optimole--Image Optimization by Optimole Lazy Load, CDN, Convert WebP &amp; AVIF<br> </td>
<td>The Image Optimization by Optimole - Lazy Load, CDN, Convert WebP &amp; AVIF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_meme_types' function in versions up to, and including, 3.12.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4636&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4636" target="_blank">CVE-2024-4636</a><br><a href="https://plugins.trac.wordpress.org/browser/optimole-wp/tags/3.12.10/inc/admin.php#L1828" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086306/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/be88566d-fc84-442d-bb34-834ad9f4465b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>paperless-ngx--paperless-ngx<br> </td>
<td>Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35184&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35184" target="_blank">CVE-2024-35184</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/commit/ed05b40ba461641b1b59b0a92f51f3f6a66ce180" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/pull/6739" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/releases/tag/v2.8.6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/security/advisories/GHSA-72w4-hxqq-c256" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>phpbits--Forty Four 404 Plugin for WordPress<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpbits Forty Four - 404 Plugin for WordPress allows Stored XSS.This issue affects Forty Four - 404 Plugin for WordPress: from n/a through 1.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34423&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34423" target="_blank">CVE-2024-34423</a><br><a href="https://patchstack.com/database/vulnerability/forty-four/wordpress-forty-four-404-plugin-for-wordpress-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>piotnetdotcom--Piotnet Addons For Elementor<br> </td>
<td>The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4432&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4432" target="_blank">CVE-2024-4432</a><br><a href="https://plugins.trac.wordpress.org/browser/piotnet-addons-for-elementor/trunk/widgets/pafe-before-after-image-comparison-slider.php#L195" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/piotnet-addons-for-elementor/trunk/widgets/pafe-table.php#L195" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087322/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f65a7df-acb5-4b5b-8867-986ce9930e3f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>posimyththemes--The Plus Addons for Elementor Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce<br> </td>
<td>The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-34373 is likely a duplicate of this issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0445" target="_blank">CVE-2024-0445</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.3.4/modules/widgets/tp_flip_box.php#L2323" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.3.4/modules/widgets/tp_info_box.php#L2928" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.3.4/modules/widgets/tp_pricing_table.php#L2942" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_flip_box.php#L2388" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_info_box.php#L2997" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_pricing_table.php#L2960" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a412e682-869a-46ba-a2d0-d84ed542adc9?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>posimyththemes--The Plus Addons for Elementor Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce<br> </td>
<td>The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2785&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2785" target="_blank">CVE-2024-2785</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_age_gate.php?annotate=blame#L2389" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3076733%40the-plus-addons-for-elementor-page-builder&amp;new=3076733%40the-plus-addons-for-elementor-page-builder&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d0117436-7a2a-42f3-8c05-75dfddfb9d09?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>prasunsen--Hostel<br> </td>
<td>The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.3. This is due to missing or incorrect nonce validation when managing rooms. This makes it possible for unauthenticated attackers to create and delete rooms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4314&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4314" target="_blank">CVE-2024-4314</a><br><a href="https://plugins.trac.wordpress.org/changeset/3079755/hostel/trunk?contextall=1&amp;old=3070681&amp;old_path=%2Fhostel%2Ftrunk" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6a8c5d9b-4535-4edb-a92e-a9b83a0d22c3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>pt-guy--Content Views Post Grid &amp; Filter, Recent Posts, Category Posts, &amp; More (Gutenberg Blocks and Shortcode)<br> </td>
<td>The Content Views - Post Grid &amp; Filter, Recent Posts, Category Posts, &amp; More (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagingType' parameter in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4446&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4446" target="_blank">CVE-2024-4446</a><br><a href="https://plugins.trac.wordpress.org/browser/content-views-query-and-display-post-page/tags/3.7.1/includes/html.php#L803" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65504747-7f1b-43f9-be4d-48b9547e7c45?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>pure-chat--Pure Chat Live Chat Plugin &amp; More!<br> </td>
<td>The Pure Chat - Live Chat Plugin &amp; More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purechatwid and purechatwname parameter in all versions up to, and including, 2.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3595&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3595" target="_blank">CVE-2024-3595</a><br><a href="https://wordpress.org/plugins/pure-chat/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5d03c798-dc77-407c-8674-d0bd2f1ada8c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>rankmath--Rank Math SEO with AI Best SEO Tools<br> </td>
<td>The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'textAlign' parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4335&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4335" target="_blank">CVE-2024-4335</a><br><a href="https://plugins.trac.wordpress.org/browser/seo-by-rank-math/tags/1.0.217/includes/modules/schema/blocks/class-block.php#L64" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080259/#file26" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96eba67c-58e7-4eea-84d4-9b3bb275b42d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>rankmath--Rank Math SEO with AI Best SEO Tools<br> </td>
<td>The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4617&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4617" target="_blank">CVE-2024-4617</a><br><a href="https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/modules/schema/blocks/class-block-faq.php#L183" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084351/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/474fdbcb-fe3c-4a79-a847-363f81b300c2?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>realmag777--WordPress Meta Data and Taxonomies Filter (MDTF)<br> </td>
<td>Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34434&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34434" target="_blank">CVE-2024-34434</a><br><a href="https://patchstack.com/database/vulnerability/wp-meta-data-filter-and-taxonomy-filter/wordpress-mdtf-meta-data-and-taxonomies-filter-plugin-1-3-3-2-arbitrary-shortcode-execution-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>redbitcz--SimpleShop<br> </td>
<td>The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to disconnect the SimpleShop.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1229&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1229" target="_blank">CVE-2024-1229</a><br><a href="https://plugins.trac.wordpress.org/browser/simpleshop-cz/trunk/src/Settings.php?rev=3019145#L341" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3080151%40simpleshop-cz&amp;new=3080151%40simpleshop-cz&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4dc39c47-3b99-4e43-b25d-a025f3d228b5?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>redbitcz--SimpleShop<br> </td>
<td>The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or incorrect nonce validation on the maybe_disconnect_simpleshop function. This makes it possible for unauthenticated attackers to disconnect the site from simpleshop via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1230&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1230" target="_blank">CVE-2024-1230</a><br><a href="https://github.com/redbitcz/simpleshop-wp-plugin/commit/8b04c95bb29036658e6a5b1ef735440646e3199b" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/simpleshop-cz/trunk/src/Settings.php?rev=3019145#L341" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9870db7f-0c8e-44a4-aa0f-13709d773756?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>reviewx--ReviewX Multi-criteria Rating &amp; Reviews for WooCommerce<br> </td>
<td>The ReviewX - Multi-criteria Rating &amp; Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subscriber access and above, to delete attachments.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3609&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3609" target="_blank">CVE-2024-3609</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3086273%40reviewx%2Ftrunk&amp;old=3054184%40reviewx%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f8152adf-1ca9-4a19-b539-39e257ab94c8?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ruby--rexml<br> </td>
<td>REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `&lt;`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35176&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35176" target="_blank">CVE-2024-35176</a><br><a href="https://github.com/ruby/rexml/commit/4325835f92f3f142ebd91a3fdba4e1f1ab7f1cfb" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh" target="_blank">security-advisories@github.com</a><br><a href="https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>sbouey--Falang multilanguage for WordPress<br> </td>
<td>The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.3.49 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4417&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4417" target="_blank">CVE-2024-4417</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3082466%40falang%2Ftrunk&amp;old=3059173%40falang%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b62949fd-d73f-4c42-82c7-c29986bca1da?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>sc0ttkclark--Pods Custom Content Types and Fields<br> </td>
<td>The Pods - Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3956" target="_blank">CVE-2024-3956</a><br><a href="https://plugins.trac.wordpress.org/browser/pods/tags/3.2.1/ui/front/form.php#L105" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083418/pods/tags/3.1.4.1/includes/data.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083418/pods/tags/3.1.4.1/ui/front/form.php" target="_blank">security@wordfence.com</a><br><a href="https://pods.io/2024/05/08/pods-3-2-1-1-security-release/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0707c92-96e9-444a-8a13-52d49c9e3f5c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>shaonsina--Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates)<br> </td>
<td>The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via several parameters in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4333&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4333" target="_blank">CVE-2024-4333</a><br><a href="https://plugins.trac.wordpress.org/browser/sina-extension-for-elementor/trunk/assets/js/jquery.countdown.min.js" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/sina-extension-for-elementor/trunk/assets/js/typed.min.js" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085825/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f616df94-7839-49db-baa5-88f8f1de208f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>shaonsina--Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates)<br> </td>
<td>The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Particle Layer widget in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4373&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4373" target="_blank">CVE-2024-4373</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3085825%40sina-extension-for-elementor&amp;new=3085825%40sina-extension-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eee04b1d-188a-4b92-a6f3-dfa843ca20d7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smartersite--WP Compress Image Optimizer [All-In-One]<br> </td>
<td>The WP Compress - Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit plugin settings, including storing cross-site scripting, in multisite environments.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4445" target="_blank">CVE-2024-4445</a><br><a href="https://plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/trunk/classes/mu.class.php?rev=2946135" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082085/#file655" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/830f53a4-da3b-4a95-99f1-c4a4c8e6944c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smartersite--WP Compress Image Optimizer [All-In-One]<br> </td>
<td>The WP Compress - Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6812&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6812" target="_blank">CVE-2023-6812</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082085/wp-compress-image-optimizer/trunk/fixCss.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cbbf9fbb-74fd-42eb-a781-2a720fe56b13?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smartypants--SP Project &amp; Document Manager<br> </td>
<td>The SP Project &amp; Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary folder name that do not belong to them.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1693&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1693" target="_blank">CVE-2024-1693</a><br><a href="https://plugins.trac.wordpress.org/browser/sp-client-document-manager/trunk/classes/ajax.php#L786" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1951ad6c-17b5-44ae-85e2-376b99df742e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>solidus--solidus<br> </td>
<td>Solidus &lt;= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4859&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4859" target="_blank">CVE-2024-4859</a><br><a href="https://www.tenable.com/security/research/tra-2024-15" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>squelch--Squelch Tabs and Accordions Shortcodes<br> </td>
<td>The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4.7. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4463&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4463" target="_blank">CVE-2024-4463</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3082482%40squelch-tabs-and-accordions-shortcodes%2Ftrunk&amp;old=3067680%40squelch-tabs-and-accordions-shortcodes%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd9490f2-ad52-477e-ae3b-be49984e8189?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>stacklok--minder<br> </td>
<td>Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack via an attacker-controlled REST endpoint that can crash the Minder server. The REST ingester allows users to interact with REST endpoints to fetch data for rule evaluation. When fetching data with the REST ingester, Minder sends a request to an endpoint and will use the data from the body of the response as the data to evaluate against a certain rule. If the response is sufficiently large, it can drain memory on the machine and crash the Minder server. The attacker can control the remote REST endpoints that Minder sends requests to, and they can configure the remote REST endpoints to return responses with large bodies. They would then instruct Minder to send a request to their configured endpoint that would return the large response which would crash the Minder server. Version 0.0.49 fixes this issue.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35185&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35185" target="_blank">CVE-2024-35185</a><br><a href="https://github.com/stacklok/minder/commit/065049336aac0621ee00a0bb2211f8051d47c14b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/stacklok/minder/security/advisories/GHSA-fjw8-3gp8-4cvx" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>stalwartlabs--mail-server<br> </td>
<td>Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user (and therefore, web interface admins) can read arbitrary files as root. This issue affects admins who have set up to run stalwart with `RUN_AS_USER` who handed out admin credentials to the mail server but expect these to only grant access according to the `RUN_AS_USER` and are attacked where the attackers managed to achieve Arbitrary Code Execution using another vulnerability. Version 0.8.0 contains a patch for the issue.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35179&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35179" target="_blank">CVE-2024-35179</a><br><a href="https://github.com/stalwartlabs/mail-server/security/advisories/GHSA-5pfx-j27j-4c6h" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>stellar--stellar-core<br> </td>
<td>Stellar-core is a reference implementation for the peer-to-peer agent that manages the Stellar network. Prior to 20.4.0, core nodes could be randomly crashed due to a race condition with a 3rd party library. The likelihood of affecting the network is low since crashed nodes come back up online right away. Code fix mitigation is part of Stellar-core v20.4.0 release</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32985&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32985" target="_blank">CVE-2024-32985</a><br><a href="https://github.com/stellar/stellar-core/security/advisories/GHSA-mgx8-frjx-x33m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>swte--Swift Performance Lite<br> </td>
<td>The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function in all versions up to, and including, 2.3.6.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve and modify settings.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3722&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3722" target="_blank">CVE-2024-3722</a><br><a href="https://plugins.trac.wordpress.org/browser/swift-performance-lite/trunk/includes/setup/setup.php#L97" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/58b7736a-e3e0-4ecd-9adf-284568b02ef7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>talspotim--Comments Evolved for WordPress<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in talspotim Comments Evolved for WordPress allows Stored XSS.This issue affects Comments Evolved for WordPress: from n/a through 1.6.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34420&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34420" target="_blank">CVE-2024-34420</a><br><a href="https://patchstack.com/database/vulnerability/gplus-comments/wordpress-comments-evolved-for-wordpress-plugin-1-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the Fluent Forms settings, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This can be chained with CVE-2024-2771 for a low-privileged user to inject malicious web scripts.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2772&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2772" target="_blank">CVE-2024-2772</a><br><a href="https://plugins.trac.wordpress.org/changeset/3073857" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2ccba77c-fb90-4906-b0fe-77607ec5df1f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>tg123--sshpiper<br> </td>
<td>sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol listener is implemented in sshpiper can allow an attacker to forge their connecting address. Commit 2ddd69876a1e1119059debc59fe869cb4e754430 added the proxy protocol listener as the only listener in sshpiper, with no option to toggle this functionality off. This means that any connection that sshpiper is directly (or in some cases indirectly) exposed to can use proxy protocol to forge its source address. Any users of sshpiper who need logs from it for whitelisting/rate limiting/security investigations could have them become much less useful if an attacker is sending a spoofed source address. Version 1.3.0 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35175&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35175" target="_blank">CVE-2024-35175</a><br><a href="https://github.com/tg123/sshpiper/commit/2ddd69876a1e1119059debc59fe869cb4e754430" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/tg123/sshpiper/commit/70fb830dca26bea7ced772ce5d834a3e88ae7f53" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/tg123/sshpiper/security/advisories/GHSA-4w53-6jvp-gg52" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4391&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4391" target="_blank">CVE-2024-4391</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/event-calendar/widget.php#L1811" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083138/happy-elementor-addons/trunk/widgets/event-calendar/widget.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e75f7e1a-f3bb-4b24-bf04-b83d0e572551?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4478&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4478" target="_blank">CVE-2024-4478</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.7/widgets/image-stack-group/widget.php#L611" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083138/#file584" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/happy-elementor-addons/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c7243f40-5cca-475a-bb27-44fab965bb0e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_id' parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4865&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4865" target="_blank">CVE-2024-4865</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/skills/widget.php#L359" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087575/happy-elementor-addons/trunk/widgets/skills/widget.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2fdf2020-ad80-44c3-89b6-fc2ba067cd33?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_id' parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5088&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5088" target="_blank">CVE-2024-5088</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/skills/widget.php#L360" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087575/happy-elementor-addons/trunk/widgets/skills/widget.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/203ab09f-7344-4cab-86bf-0c1ec545d78f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeisle--Menu Icons by ThemeIsle<br> </td>
<td>The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_mime_type' function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4635&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4635" target="_blank">CVE-2024-4635</a><br><a href="https://plugins.trac.wordpress.org/browser/menu-icons/tags/0.13.13/vendor/codeinwp/icon-picker/includes/types/svg.php#L69" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086753/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/90284576-6570-4e4c-8eb3-743bc402ea1b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themelooks--Enter Addons Ultimate Template Builder for Elementor<br> </td>
<td>The Enter Addons - Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animation Title widget's img tag in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3680&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3680" target="_blank">CVE-2024-3680</a><br><a href="https://wordpress.org/plugins/enteraddons/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/29cc82cb-f3fd-4de5-9731-7ceb1212b0f9?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themelooks--Enter Addons Ultimate Template Builder for Elementor<br> </td>
<td>The Enter Addons - Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3831&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3831" target="_blank">CVE-2024-3831</a><br><a href="https://wordpress.org/plugins/enteraddons/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/62a4dd6a-f970-483e-b1a8-d57f604b7b66?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeum--Tutor LMS eLearning and online course solution<br> </td>
<td>The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation on a user controlled key. This can allow authenticated attackers, with Instructor-level permissions and above, to delete any course.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4279&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4279" target="_blank">CVE-2024-4279</a><br><a href="https://plugins.trac.wordpress.org/browser/tutor/trunk/classes/Course_List.php#L357" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086489/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/45d04643-e43a-4732-91bf-e4af7b622e33?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themifyme--Themify Shortcodes<br> </td>
<td>The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themify_button shortcode in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4567&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4567" target="_blank">CVE-2024-4567</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082885/themify-shortcodes" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c63ff9d7-6a14-4186-8550-4e5c50855e7f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_html' parameter in all versions up to, and including, 4.2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4277&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4277" target="_blank">CVE-2024-4277</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/ExternalPlugin/Elementor/Widgets/Instructor/ListInstructorsElementor.php?order=date#L96" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46693edf-bcc6-4af8-9f26-5ede865f4694?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4444&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4444" target="_blank">CVE-2024-4444</a><br><a href="https://inky-knuckle-2c2.notion.site/Improper-Authentication-in-checkout-leads-privilege-escalation-of-unauthenticated-to-create-accoun-09da24a043884219a891dd1a0fc01af6" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/class-lp-checkout.php#L79" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082204/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c9e1410f-10c9-4654-8b61-cfcdde696da7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--Thim Elementor Kit<br> </td>
<td>The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4329&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4329" target="_blank">CVE-2024-4329</a><br><a href="https://plugins.trac.wordpress.org/browser/thim-elementor-kit/tags/1.1.9.1/inc/elementor/widgets/global/search-form.php#L819" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3275c47d-caf5-49e6-8aa2-20a6d8106f26?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>tigroumeow--Gallery Block (Meow Gallery)<br> </td>
<td>The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_atts' parameter in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4386&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4386" target="_blank">CVE-2024-4386</a><br><a href="https://plugins.trac.wordpress.org/browser/meow-gallery/trunk/classes/core.php#L273" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082976/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/477b41a5-b2ff-4b94-9622-824146a0e2ed?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>timstrifler--Exclusive Addons for Elementor<br> </td>
<td>The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied 'url' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4618&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4618" target="_blank">CVE-2024-4618</a><br><a href="https://plugins.trac.wordpress.org/browser/exclusive-addons-for-elementor/tags/2.6.9.6/elements/team-member/team-member.php#L1696" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083582/#file4" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/exclusive-addons-for-elementor/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e82478c-e476-4cdf-ab72-f578331058e2?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>trinhtuantai--Viet Affiliate Link<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trinhtuantai Viet Affiliate Link allows Stored XSS.This issue affects Viet Affiliate Link: from n/a through 1.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34422&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34422" target="_blank">CVE-2024-34422</a><br><a href="https://patchstack.com/database/vulnerability/viet-affiliate-link/wordpress-viet-affiliate-link-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>uapp--Testimonial Carousel For Elementor<br> </td>
<td>The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_line_text ' and 'slide_button_hover_animation' parameters in versions up to, and including, 10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4698&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4698" target="_blank">CVE-2024-4698</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-blog.php#L1076" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-bottom.php#L1478" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-centered.php#L1619" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-gallery-coverflow.php#L1876" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-logo.php#L1715" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel.php#L1847" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087862/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4542b0f8-c9ee-4992-b737-e5f727c7b5b0?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>unitecms--Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<br> </td>
<td>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3547&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3547" target="_blank">CVE-2024-3547</a><br><a href="https://plugins.trac.wordpress.org/changeset/3071404/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_settings_output.class.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f629fc93-84ce-4c33-b1c0-3a3194aac477?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>upwerd--Visual Footer Credit Remover<br> </td>
<td>The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2846&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2846" target="_blank">CVE-2024-2846</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081401%40visual-footer-credit-remover&amp;new=3081401%40visual-footer-credit-remover&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9fcb65a0-4218-4728-9c29-0d1a03f438a6?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>videousermanuals--White Label CMS<br> </td>
<td>The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4280&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4280" target="_blank">CVE-2024-4280</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082887/white-label-cms" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/13a206ea-0890-4535-9da7-54a7a45f0452?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>villatheme--Orders Tracking for WooCommerce<br> </td>
<td>The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. A partial patch was released in 1.2.10, and a complete patch was released in 1.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4039&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4039" target="_blank">CVE-2024-4039</a><br><a href="https://plugins.trac.wordpress.org/browser/woo-orders-tracking/trunk/includes/frontend/frontend.php#L55" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3083652%40woo-orders-tracking&amp;new=3083652%40woo-orders-tracking&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/991ab188-869c-4875-80f3-940000a1717b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>visualmodo--Borderless Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg<br> </td>
<td>The Borderless - Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4666&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4666" target="_blank">CVE-2024-4666</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/circular-progress-bar.php#L427" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/progress-bar.php#L412" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/semi-circular-progress-bar.php#L403" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/team-member.php#L1101" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/testimonial.php#L905" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085856/" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/borderless/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6840637-9b0f-4f3d-bb73-9e4527a5f326?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>weForms--weForms<br> </td>
<td>Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32512&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32512" target="_blank">CVE-2024-32512</a><br><a href="https://patchstack.com/database/vulnerability/weforms/wordpress-weforms-plugin-1-6-20-form-submission-restriction-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>webdevmattcrom--GiveWP Donation Plugin and Fundraising Platform<br> </td>
<td>The GiveWP - Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with a legacy form in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3714" target="_blank">CVE-2024-3714</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083390/give/tags/3.11.0/includes/class-give-donate-form.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd8f5cfa-3431-4617-b2cd-d5a8ce4530f4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>webtechideas--WTI Like Post<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in webtechideas WTI Like Post allows Functionality Bypass.This issue affects WTI Like Post: from n/a through 1.4.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33917&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33917" target="_blank">CVE-2024-33917</a><br><a href="https://patchstack.com/database/vulnerability/wti-like-post/wordpress-wti-like-post-plugin-1-4-6-ip-restriction-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>wolfi-dev--wolfictl<br> </td>
<td>wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user's GitHub token to be sent to remote servers other than `github.com`. Most git-dependent functionality in wolfictl relies on its own `git` package, which contains centralized logic for implementing interactions with git repositories. Some of this functionality requires authentication in order to access private repositories. A central function `GetGitAuth` looks for a GitHub token in the environment variable `GITHUB_TOKEN` and returns it as an HTTP basic auth object to be used with the `github.com/go-git/go-git/v5` library. Most callers (direct or indirect) of `GetGitAuth` use the token to authenticate to github.com only; however, in some cases callers were passing this authentication without checking that the remote git repository was hosted on github.com. This behavior has existed in one form or another since commit 0d06e1578300327c212dda26a5ab31d09352b9d0 - committed January 25, 2023. This impacts anyone who ran the `wolfictl check update` commands with a Melange configuration that included a `git-checkout` directive step that referenced a git repository not hosted on github.com. This also impacts anyone who ran `wolfictl update &lt;url&gt;` with a remote URL outside of github.com. Additionally, these subcommands must have run with the `GITHUB_TOKEN` environment variable set to a valid GitHub token. Users should upgrade to version 0.16.10 to receive a patch.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35183&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35183" target="_blank">CVE-2024-35183</a><br><a href="https://github.com/wolfi-dev/wolfictl/blob/488b53823350caa706de3f01ec0eded9350c7da7/pkg/update/update.go#L143" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/blob/4dd6c95abb4bc0f9306350a8601057bd7a92bded/pkg/update/deps/cleanup.go#L49" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/blob/6d99909f7b1aa23f732d84dad054b02a61f530e6/pkg/git/git.go#L22" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/commit/0d06e1578300327c212dda26a5ab31d09352b9d0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/commit/403e93569f46766b4e26e06cf9cd0cae5ee0c2a2" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/security/advisories/GHSA-8fg7-hp93-qhvr" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>wpdevteam--EmbedPress Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps &amp; Embed Any Documents in Gutenberg &amp; Elementor<br> </td>
<td>The EmbedPress - Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps &amp; Embed Any Documents in Gutenberg &amp; Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 3.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4316&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4316" target="_blank">CVE-2024-4316</a><br><a href="https://plugins.trac.wordpress.org/browser/embedpress/trunk/EmbedPress/Elementor/Widgets/Embedpress_Elementor.php#L3076" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2af03168-9344-4db0-9b69-2ad1fdb6d472?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Interactive Circle widget in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4275&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4275" target="_blank">CVE-2024-4275</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Interactive_Circle.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/91f50b65-f001-4c73-bfe3-1aed3fc10d26?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Dual Color Header', 'Event Calendar', &amp; 'Advanced Data Table' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4448&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4448" target="_blank">CVE-2024-4448</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Advanced_Data_Table.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Dual_Color_Header.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Event_Calendar.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/21e12c72-7898-4896-9852-ebb10e5f9a3b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', &amp; 'Twitter Feed' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4449&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4449" target="_blank">CVE-2024-4449</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3083162%40essential-addons-for-elementor-lite&amp;new=3083162%40essential-addons-for-elementor-lite&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57ed6c7e-ca8d-476d-adce-905b2cd2eda8?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eael_ext_toc_title_tag' parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4624&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4624" target="_blank">CVE-2024-4624</a><br><a href="https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/5.9.19/includes/Traits/Elements.php#L550" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085420/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bedad627-0ccb-41c1-be8d-753f57be618f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Blocks Page Builder Gutenberg Blocks, Patterns &amp; Templates<br> </td>
<td>The Essential Blocks - Page Builder Gutenberg Blocks, Patterns &amp; Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' parameter in versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4891&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4891" target="_blank">CVE-2024-4891</a><br><a href="https://plugins.trac.wordpress.org/browser/essential-blocks/trunk/blocks/AdvancedHeading.php#L115" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087677/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e1bcebb3-920b-40cc-aa5c-24a1f729b28d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpexpertsio--Password Protected Ultimate Plugin to Password Protect Your WordPress Content with Ease<br> </td>
<td>The Password Protected - Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract post titles and content, thus bypassing the plugin's password protection.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0437&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0437" target="_blank">CVE-2024-0437</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3034934%40password-protected%2Ftrunk&amp;old=3005632%40password-protected%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f3045ebf-70af-4124-9116-42c07f64a3bf?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpjoli--Joli FAQ SEO WordPress FAQ Plugin<br> </td>
<td>The Joli FAQ SEO - WordPress FAQ Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthenticated attackers to change the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4082&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4082" target="_blank">CVE-2024-4082</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081648%40joli-faq-seo%2Ftrunk&amp;old=3076380%40joli-faq-seo%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c45b6163-7ebf-4f18-afd6-735d02d9170d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpkube--Simple Basic Contact Form<br> </td>
<td>The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins installed in the environment.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4144&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4144" target="_blank">CVE-2024-4144</a><br><a href="https://plugins.trac.wordpress.org/browser/simple-basic-contact-form/trunk/simple-basic-contact-form.php#L543" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085036/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ded1944f-662d-4d25-8277-4b1dc63b2144?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpkube--Simple Basic Contact Form<br> </td>
<td>The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'scf_email' parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4150&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4150" target="_blank">CVE-2024-4150</a><br><a href="https://plugins.trac.wordpress.org/browser/simple-basic-contact-form/trunk/simple-basic-contact-form.php#L122" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080540" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22074d7a-5dbd-4a0c-bc5d-e4c983e5edb4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wproyal--Royal Elementor Addons and Templates<br> </td>
<td>The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3887&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3887" target="_blank">CVE-2024-3887</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3086890%40royal-elementor-addons&amp;old=3081886%40royal-elementor-addons&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5122800d-f274-4129-84d4-02380269502c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpsurface--BlogLentor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsurface BlogLentor allows Stored XSS.This issue affects BlogLentor: from n/a through 1.0.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34421&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34421" target="_blank">CVE-2024-34421</a><br><a href="https://patchstack.com/database/vulnerability/bloglentor-for-elementor/wordpress-bloglentor-blog-designer-pack-for-elementor-plugin-1-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>wpzoom--WPZOOM Addons for Elementor (Templates, Widgets)<br> </td>
<td>The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget Image Box in all versions up to, and including, 1.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4370&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4370" target="_blank">CVE-2024-4370</a><br><a href="https://plugins.trac.wordpress.org/browser/wpzoom-elementor-addons/trunk/includes/widgets/image-box/image-box.php#L1229" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084540" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/wpzoom-elementor-addons/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c7aaff3e-0c81-4fe7-b162-569c517f6c49?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>xpro--140+ Widgets | Best Addons For Elementor FREE<br> </td>
<td>The 140+ Widgets | Best Addons For Elementor - FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4440&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4440" target="_blank">CVE-2024-4440</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/contact-form/contact-form.php#L1438" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/course-grid/course-grid.php#L1918" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/custom-field/custom-field.php#L1150" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/post-grid/post-grid.php#L1829" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/woo-product-grid/woo-product-grid.php#L3812" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5596197e-149d-4072-9fa4-424c9ffd6059?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>yithemes--YITH WooCommerce Gift Cards<br> </td>
<td>The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_mail_status' and 'save_email_settings' functions in all versions up to, and including, 4.12.0. This makes it possible for unauthenticated attackers to modify WooCommerce settings.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0870&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0870" target="_blank">CVE-2024-0870</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084519/yith-woocommerce-gift-cards/trunk/includes/admin/class-ywgc-admin.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca1f0dc6-c0bc-4e9f-b3b6-d6274aa7a7db?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>yoast--Yoast SEO<br> </td>
<td>The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4041&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4041" target="_blank">CVE-2024-4041</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/inc/class-wpseo-admin-bar-menu.php#L601" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/inc/class-wpseo-shortlinker.php#L20" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/src/helpers/short-link-helper.php#L105" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/src/helpers/short-link-helper.php#L45" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3078555/wordpress-seo/trunk#file129" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4e04b161-3cd0-454d-869c-56f42bd8afb0?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>yoast--Yoast SEO<br> </td>
<td>The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4984&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4984" target="_blank">CVE-2024-4984</a><br><a href="https://developer.yoast.com/changelog/yoast-seo/22.7/" target="_blank">security@wordfence.com</a><br><a href="https://github.com/Yoast/wordpress-seo/pull/21334" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3079234/wordpress-seo/trunk/src/presenters/slack/enhanced-data-presenter.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59bcd246-ca2f-4336-9a6e-89afe873ed25?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>
<div>
<h2>Low Vulnerabilities</h2>
<table summary="Low Vulnerabilities" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>Bill Minozzi--Car Dealer<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4214&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">2.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4214" target="_blank">CVE-2024-4214</a><br><a href="https://patchstack.com/database/vulnerability/cardealer/wordpress-cardealer-plugin-4-15-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/show_student_subject.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263593 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4672&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4672" target="_blank">CVE-2024-4672</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2022.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263593" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263593" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331307" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /view/show_student_grade_subject.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263594 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4673&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4673" target="_blank">CVE-2024-4673</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2023.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263594" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263594" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331308" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/show_friend_request.php. The manipulation of the argument my_index leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263595.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4674&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4674" target="_blank">CVE-2024-4674</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2024.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263595" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263595" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331310" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /view/show_events.php. The manipulation of the argument event_id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263596.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4675&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4675" target="_blank">CVE-2024-4675</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2025.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263596" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263596" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331312" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /view/range_grade_text.php. The manipulation of the argument count leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263597 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4676&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4676" target="_blank">CVE-2024-4676</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2026.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263597" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263597" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331313" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /view/my_student_exam_marks1.php. The manipulation of the argument year leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263598 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4677&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4677" target="_blank">CVE-2024-4677</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2027.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263598" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263598" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331314" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /view/find_friends.php. The manipulation of the argument my_type leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263599.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4678&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4678" target="_blank">CVE-2024-4678</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2028.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263599" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263599" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331315" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /view/exam_timetable_update_form.php. The manipulation of the argument exam leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263623.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4682&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4682" target="_blank">CVE-2024-4682</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2029.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263623" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263623" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331772" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /view/exam_timetable_insert_form.php. The manipulation of the argument exam leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263624.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4683&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4683" target="_blank">CVE-2024-4683</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2030.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263624" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263624" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331773" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /view/exam_timetable_grade_wise.php. The manipulation of the argument exam leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263625 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4684&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4684" target="_blank">CVE-2024-4684</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2031.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263625" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263625" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331774" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /view/exam_timetable.php. The manipulation of the argument exam leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263626 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4685&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4685" target="_blank">CVE-2024-4685</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2032.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263626" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263626" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331775" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/emarks_range_grade_update_form.php. The manipulation of the argument grade leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263627.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4686&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4686" target="_blank">CVE-2024-4686</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2033.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263627" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263627" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331776" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/create_events.php. The manipulation of the argument my_index leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263628.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4687&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4687" target="_blank">CVE-2024-4687</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2034.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263628" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263628" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331777" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/conversation_history_admin.php. The manipulation of the argument conversation_id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263629 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4688&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4688" target="_blank">CVE-2024-4688</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2035.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263629" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263629" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331778" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/all_teacher.php. The manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263791.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4713&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4713" target="_blank">CVE-2024-4713</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2036.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263791" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263791" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331879" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /model/update_subject.php. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263792.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4714" target="_blank">CVE-2024-4714</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2037.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263792" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263792" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331880" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /model/update_grade.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263793 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4715&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4715" target="_blank">CVE-2024-4715</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2038.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263793" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263793" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331881" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /model/update_exam.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263794 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4716&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4716" target="_blank">CVE-2024-4716</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2039.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263794" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263794" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331882" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /model/update_classroom.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263795.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4717" target="_blank">CVE-2024-4717</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2040.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263795" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263795" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331883" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /model/delete_student_grade_subject.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263796.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4718&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4718" target="_blank">CVE-2024-4718</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2041.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263796" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263796" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331884" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /model/delete_record.php. The manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263797 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4719&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4719" target="_blank">CVE-2024-4719</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2042.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263797" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263797" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331885" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /model/approve_petty_cash.php. The manipulation of the argument admin_index leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263798 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4720&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4720" target="_blank">CVE-2024-4720</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2043.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263798" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263798" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331886" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /model/add_student_subject.php. The manipulation of the argument index leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263799.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4721&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4721" target="_blank">CVE-2024-4721</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2044.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263799" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263799" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331887" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument category leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263800.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4722&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4722" target="_blank">CVE-2024-4722</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2045.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263800" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263800" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331888" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. This issue affects some unknown processing of the file /admin/case-status. The manipulation of the argument case_status leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263801 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4723&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4723" target="_blank">CVE-2024-4723</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_case-status.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263801" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263801" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331982" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/case-type. The manipulation of the argument case_type_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263802 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4724&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4724" target="_blank">CVE-2024-4724</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_case-type.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263802" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263802" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331983" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability has been found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/client_user. The manipulation of the argument f_name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263803.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4725&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4725" target="_blank">CVE-2024-4725</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_client_user.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263803" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263803" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331988" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/clients. The manipulation of the argument f_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263804.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4726&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4726" target="_blank">CVE-2024-4726</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_clients.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263804" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263804" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331989" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4727&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4727" target="_blank">CVE-2024-4727</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_court-type.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263805" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263805" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331990" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/court. The manipulation of the argument court_name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263806 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4728&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4728" target="_blank">CVE-2024-4728</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_court.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263806" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263806" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331992" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/expense-type. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263807.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4729&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4729" target="_blank">CVE-2024-4729</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_expense-type.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263807" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263807" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331993" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability classified as problematic has been found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/judge. The manipulation of the argument judge_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263808.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4730&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4730" target="_blank">CVE-2024-4730</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_judge.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263808" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263808" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331994" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Legal Case Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/role. The manipulation of the argument slug leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263809 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4731&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4731" target="_blank">CVE-2024-4731</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_role.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263809" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263809" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331995" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/service. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263810 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4732&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4732" target="_blank">CVE-2024-4732</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_service.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263810" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263810" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331996" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability has been found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tasks. The manipulation of the argument task_subject leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263821 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4735&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4735" target="_blank">CVE-2024-4735</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_tasks.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263821" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263821" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332408" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/tax. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263822 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4736&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4736" target="_blank">CVE-2024-4736</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_tax.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263822" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263822" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332409" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/vendor. The manipulation of the argument company_name/mobile leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263823.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4737&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4737" target="_blank">CVE-2024-4737</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_vendor.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263823" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263823" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332411" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument new_client leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263824.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4738&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4738" target="_blank">CVE-2024-4738</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_appointment.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263824" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263824" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332412" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /ajax.php. The manipulation of the argument name/customer_name/username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263896.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4797&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4797" target="_blank">CVE-2024-4797</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/xss_action.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263896" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263896" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332539" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Filipe Seabra--WordPress Manuteno<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress ManutenÃ§Ã£o allows Functionality Bypass.This issue affects WordPress ManutenÃ§Ã£o: from n/a through 1.0.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22139&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22139" target="_blank">CVE-2024-22139</a><br><a href="https://patchstack.com/database/vulnerability/wp-manutencao/wordpress-wordpress-manutencao-plugin-1-0-6-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32989&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32989" target="_blank">CVE-2024-32989</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47711&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">2.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47711" target="_blank">CVE-2023-47711</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271526" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150840" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>JetBrains--TeamCity<br> </td>
<td>In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35300&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35300" target="_blank">CVE-2024-35300</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5937&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5937" target="_blank">CVE-2023-5937</a><br><a href="https://security.nozominetworks.com/NN-2023:15-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Broken Authentication vulnerability discovered in OpenTextâ„¢ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3487&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3487" target="_blank">CVE-2024-3487</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>Pippin Williamson--CGC Maintenance Mode<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30480&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30480" target="_blank">CVE-2024-30480</a><br><a href="https://patchstack.com/database/vulnerability/cgc-maintenance-mode/wordpress-cgc-maintenance-mode-plugin-1-2-ip-filtering-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Bank Account Management<br> </td>
<td>SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33000&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33000" target="_blank">CVE-2024-33000</a><br><a href="https://me.sap.com/notes/3392049" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAPUI5 (PDFViewer)<br> </td>
<td>PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33007&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33007" target="_blank">CVE-2024-33007</a><br><a href="https://me.sap.com/notes/3446076" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.208), Parasolid V36.1 (All versions &lt; V36.1.173). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted X_T files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32637&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32637" target="_blank">CVE-2024-32637</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-046364.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected application contains a hidden configuration item to enable debug functionality. This could allow an authenticated local attacker to gain insight into the internal configuration of the deployment.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33583&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33583" target="_blank">CVE-2024-33583</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>SourceCodester--Interactive Map with Marker<br> </td>
<td>A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Marker Name of the component Add Marker. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264536.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4968&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4968" target="_blank">CVE-2024-4968</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Interactive%20Map%20App/Interactive%20Map%20App%20-%20Cross-Site-Scripting.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264536" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264536" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335191" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Image Stack Website<br> </td>
<td>A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This affects an unknown part. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264459.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4922&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4922" target="_blank">CVE-2024-4922</a><br><a href="https://github.com/HuoMingZ/aoligei/blob/main/ceshi.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264459" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264459" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333760" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34355&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34355" target="_blank">CVE-2024-34355</a><br><a href="https://github.com/TYPO3/typo3/commit/56afa304ba8b5ad302e15df5def71bcc8d820375" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-xjwx-78x7-q6jc" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-007" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Wireshark Foundation--editcap<br> </td>
<td>Memory handling issue in editcap could cause denial of service via crafted capture file</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4853&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4853" target="_blank">CVE-2024-4853</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19724" target="_blank">cve@gitlab.com</a><br><a href="https://www.wireshark.org/security/wnpa-sec-2024-08.html" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>Wireshark Foundation--editcap<br> </td>
<td>Use after free issue in editcap could cause denial of service via crafted capture file</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4855&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4855" target="_blank">CVE-2024-4855</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19782" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19783" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19784" target="_blank">cve@gitlab.com</a><br><a href="https://www.wireshark.org/security/wnpa-sec-2024-08.html" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>cea-hpc--sshproxy<br> </td>
<td>sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. Prior to version 1.6.3, any user authorized to connect to a ssh server using `sshproxy` can inject options to the `ssh` command executed by `sshproxy`. All versions of `sshproxy` are impacted. The problem is patched starting in version 1.6.3. The only workaround is to use the `force_command` option in `sshproxy.yaml`, but it's rarely relevant.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34713&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34713" target="_blank">CVE-2024-34713</a><br><a href="https://github.com/cea-hpc/sshproxy/commit/f7eabd05d5f0f951e160293692327cad9a7d9580" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/cea-hpc/sshproxy/security/advisories/GHSA-jmqp-37m5-49wh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in code-projects Simple Chat System 1.0. Affected is an unknown function of the file /register.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264540.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4974&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4974" target="_blank">CVE-2024-4974</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20Cross-Site-Scripting-1.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264540" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264540" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335205" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in code-projects Simple Chat System 1.0. This issue affects some unknown processing of the component Message Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264539.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4975&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4975" target="_blank">CVE-2024-4975</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20Cross-Site-Scripting-2.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264539" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264539" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335206" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritten at any point in time by the untrusted user. Cloning local repositories will cause Git to either copy or hardlink files of the source repository into the target repository. This significantly speeds up such local clones compared to doing a "proper" clone and saves both disk space and compute time. When cloning a repository located on the same disk that is owned by a different user than the current user we also end up creating such hardlinks. These files will continue to be owned and controlled by the potentially-untrusted user and can be rewritten by them at will in the future. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32020&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32020" target="_blank">CVE-2024-32020</a><br><a href="https://github.com/git/git/commit/1204e1a824c34071019fe106348eaa6d88f9528d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/9e65df5eab274bf74c7b570107aacd1303a1e703" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-5rfh-556j-fhgj" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the `objects/` directory. Cloning a local repository over the filesystem may creating hardlinks to arbitrary user-owned files on the same filesystem in the target Git repository's `objects/` directory. When cloning a repository over the filesystem (without explicitly specifying the `file://` protocol or `--no-local`), the optimizations for local cloning will be used, which include attempting to hard link the object files instead of copying them. While the code includes checks against symbolic links in the source repository, which were added during the fix for CVE-2022-39253, these checks can still be raced because the hard link operation ultimately follows symlinks. If the object on the filesystem appears as a file during the check, and then a symlink during the operation, this will allow the adversary to bypass the check and create hardlinks in the destination objects directory to arbitrary, user-readable files. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32021&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32021" target="_blank">CVE-2024-32021</a><br><a href="https://github.com/git/git/security/advisories/GHSA-mvxm-9j2h-qjx7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>gocd--gocd<br> </td>
<td>GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting vulnerability on the loading page displayed while GoCD is starting, via abuse of a `redirect_to` query parameter with inadequate validation. Attackers could theoretically abuse the query parameter to steal session tokens or other values from the user's browser. In practice exploiting this to perform privileged actions is likely rather difficult to exploit because the target user would need to be triggered to open an attacker-crafted link in the period where the server is starting up (but not completely started), requiring chaining with a separate denial-of-service vulnerability. Additionally, GoCD server restarts invalidate earlier session tokens (i.e GoCD does not support persistent sessions), so a stolen session token would be unusable once the server has completed restart, and executed XSS would be done within a logged-out context. The issue is fixed in GoCD 24.1.0. As a workaround, it is technically possible in earlier GoCD versions to override the loading page with an earlier version which is not vulnerable, by starting GoCD with the Java system property override as either `-Dloading.page.resource.path=/loading_pages/default.loading.page.html` (simpler early version of loading page without GoCD introduction) or `-Dloading.page.resource.path=/does_not_exist.html` (to display a simple message with no interactivity).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28866&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28866" target="_blank">CVE-2024-28866</a><br><a href="https://github.com/gocd/gocd/commit/388d8893ec4cac51d2b76e923cc9b55c7703e402" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/gocd/gocd/releases/tag/24.1.0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/gocd/gocd/security/advisories/GHSA-q882-q6mm-mgvh" target="_blank">security-advisories@github.com</a><br><a href="https://www.gocd.org/releases/#24-1-0" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>helderk--Maintenance Mode<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affects Maintenance Mode: from n/a through 3.0.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32708&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32708" target="_blank">CVE-2024-32708</a><br><a href="https://patchstack.com/database/vulnerability/hkdev-maintenance-mode/wordpress-maintenance-mode-plugin-3-0-1-ip-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>n/a--Emlog Pro<br> </td>
<td>A vulnerability was found in Emlog Pro 2.3.4. It has been classified as problematic. This affects an unknown part of the component Cookie Handler. The manipulation of the argument AuthCookie leads to improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-264741 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5044&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5044" target="_blank">CVE-2024-5044</a><br><a href="https://github.com/ssteveez/emlog/blob/main/emlog%20pro%20version%202.3.4%20has%20session(AuthCookie)%20persistence%20and%20any%20user%20login%20vulnerability.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264741" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264741" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331857" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CBI software<br> </td>
<td>Improper input validation in some Intel(R) CBI software before version 1.1.0 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43745&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">2.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43745" target="_blank">CVE-2023-43745</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01013.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK and some Intel(R) oneVPL software<br> </td>
<td>Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-22656&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-22656" target="_blank">CVE-2023-22656</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK software<br> </td>
<td>Improper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47169&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47169" target="_blank">CVE-2023-47169</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Improper conditions check in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38420&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38420" target="_blank">CVE-2023-38420</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Processors<br> </td>
<td>Hardware logic contains race conditions in some Intel(R) Processors may allow an authenticated user to potentially enable partial information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45733&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">2.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45733" target="_blank">CVE-2023-45733</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01051.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Trace Analyzer and Collector software<br> </td>
<td>Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2022.0.0 published Nov 2023 may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22384&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">2.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22384" target="_blank">CVE-2024-22384</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00983.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) oneVPL software<br> </td>
<td>Out-of-bounds write in Intel(R) Media SDK all versions and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47282&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47282" target="_blank">CVE-2023-47282</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) oneVPL software<br> </td>
<td>NULL pointer dereference in some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48727&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48727" target="_blank">CVE-2023-48727</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--PostgreSQL<br> </td>
<td>Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4317&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4317" target="_blank">CVE-2024-4317</a><br><a href="https://www.postgresql.org/support/security/CVE-2024-4317/" target="_blank">f86ef6dc-4d3a-42ad-8f28-e6d5547a5007</a></td>
</tr>
<tr>
<td>octo-sts--app<br> </td>
<td>octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service. This vulnerability is fixed in 0.1.0</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34079&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34079" target="_blank">CVE-2024-34079</a><br><a href="https://github.com/octo-sts/app/commit/74ba874c017cf973edd6711144cf4399a9fcff57" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/octo-sts/app/security/advisories/GHSA-75r6-6jg8-pfcq" target="_blank">security-advisories@github.com</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>
<div>
<h2>Severity Not Yet Assigned</h2>
<table summary="Severity Not Yet Assigned" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>Aidin--Phormer<br> </td>
<td>Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote unauthenticated attacker may execute an arbitrary script on the web browser of the user.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34749" target="_blank">CVE-2024-34749</a><br><a href="http://p.horm.org/er/" target="_blank">vultures@jpcert.or.jp</a><br><a href="https://github.com/eyedean/phormer" target="_blank">vultures@jpcert.or.jp</a><br><a href="https://jvn.jp/en/jp/JVN61054671/" target="_blank">vultures@jpcert.or.jp</a><br><a href="https://sourceforge.net/projects/rephormer/" target="_blank">vultures@jpcert.or.jp</a></td>
</tr>
<tr>
<td>Ant Media--Ant Media Server Community Edition<br> </td>
<td>Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users.  All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor has not confirmed releasing a patch.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3462" target="_blank">CVE-2024-3462</a><br><a href="https://antmedia.io/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-3462" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-3462" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Apache Software Foundation--Apache Airflow<br> </td>
<td>Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32077" target="_blank">CVE-2024-32077</a><br><a href="https://github.com/apache/airflow/pull/38882" target="_blank">security@apache.org</a><br><a href="https://lists.apache.org/thread/gsjmnrqb3m5fzp0vgpty1jxcywo91v77" target="_blank">security@apache.org</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Ventura 13.6.7, macOS Sonoma 14.4. An app may be able to access user-sensitive data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27789" target="_blank">CVE-2024-27789</a><br><a href="https://support.apple.com/en-us/HT214084" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214100" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214105" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214107" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27796" target="_blank">CVE-2024-27796</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to share items from the lock screen.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27803" target="_blank">CVE-2024-27803</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27804" target="_blank">CVE-2024-27804</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to read sensitive location information.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27810" target="_blank">CVE-2024-27810</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker may be able to access user data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27816" target="_blank">CVE-2024-27816</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27818" target="_blank">CVE-2024-27818</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A shortcut may output sensitive user data without consent.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27821" target="_blank">CVE-2024-27821</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27834" target="_blank">CVE-2024-27834</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214103" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to access notes from the lock screen.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27835" target="_blank">CVE-2024-27835</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine a user's current location.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27839" target="_blank">CVE-2024-27839</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27841" target="_blank">CVE-2024-27841</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>This issue was addressed with improved checks This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to bypass Privacy preferences.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27847" target="_blank">CVE-2024-27847</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A privacy issue was addressed with improved client ID handling for alternative app marketplaces. This issue is fixed in iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to distribute a script that tracks users on other webpages.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27852" target="_blank">CVE-2024-27852</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iTunes for Windows<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or arbitrary code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27793" target="_blank">CVE-2024-27793</a><br><a href="https://support.apple.com/en-us/HT214099" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Ventura 13.6.5, macOS Sonoma 14.4. A malicious application may be able to access Find My data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23229" target="_blank">CVE-2024-23229</a><br><a href="https://support.apple.com/en-us/HT214084" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214085" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214105" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23236" target="_blank">CVE-2024-23236</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.5. An attacker may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27798" target="_blank">CVE-2024-27798</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27813" target="_blank">CVE-2024-27813</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27822" target="_blank">CVE-2024-27822</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.5. An app may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27824" target="_blank">CVE-2024-27824</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to bypass certain Privacy preferences.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27825" target="_blank">CVE-2024-27825</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27827" target="_blank">CVE-2024-27827</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5. Processing a file may lead to unexpected app termination or arbitrary code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27829" target="_blank">CVE-2024-27829</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keychain items.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27837" target="_blank">CVE-2024-27837</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27842" target="_blank">CVE-2024-27842</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27843" target="_blank">CVE-2024-27843</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>CEMI Tomasz Paweek--CemiPark<br> </td>
<td>The access control in CemiPark software does not properly validate user-entered data, which allows the authentication bypass. An attacker who has network access to the login panel can log in with administrator rights to the application.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4423" target="_blank">CVE-2024-4423</a><br><a href="http://cemi.pl/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>CEMI Tomasz Paweek--CemiPark<br> </td>
<td>The access control in CemiPark software does not properly validate user-entered data, which allows the stored cross-site scripting (XSS) attack. The parameters used to enter data into the system do not have appropriate validation, which makes possible to smuggle in HTML/JavaScript code. This code will be executed in the user's browser space.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4424" target="_blank">CVE-2024-4424</a><br><a href="http://cemi.pl/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>CEMI Tomasz Paweek--CemiPark<br> </td>
<td>The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4425" target="_blank">CVE-2024-4425</a><br><a href="http://cemi.pl/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Claris--FileMaker Server<br> </td>
<td>Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by eliminating the send of Admin Role passwords in the Node.js socket.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42955" target="_blank">CVE-2023-42955</a><br><a href="https://support.claris.com/s/article/Administrator-role-passwords-being-exposed-when-logged-into-the-Admin-Console?language=en_US" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Claris--FileMaker Server<br> </td>
<td>Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27790" target="_blank">CVE-2024-27790</a><br><a href="https://support.claris.com/s/answerview?anum=000041674&amp;language=en_US" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Devolutions--Server<br> </td>
<td>Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5072" target="_blank">CVE-2024-5072</a><br><a href="https://devolutions.net/security/advisories/DEVO-2024-0007" target="_blank">security@devolutions.net</a></td>
</tr>
<tr>
<td>Digisol--Digisol Router DG-GR1321<br> </td>
<td>This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2257" target="_blank">CVE-2024-2257</a><br><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&amp;VLCODE=CIVN-2024-0158" target="_blank">vdisclose@cert-in.org.in</a></td>
</tr>
<tr>
<td>Digisol--Digisol Router DG-GR1321<br> </td>
<td>This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4231" target="_blank">CVE-2024-4231</a><br><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&amp;VLCODE=CIVN-2024-0158" target="_blank">vdisclose@cert-in.org.in</a></td>
</tr>
<tr>
<td>Digisol--Digisol Router DG-GR1321<br> </td>
<td>This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4232" target="_blank">CVE-2024-4232</a><br><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&amp;VLCODE=CIVN-2024-0158" target="_blank">vdisclose@cert-in.org.in</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4761" target="_blank">CVE-2024-4761</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_13.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/339458194" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4947" target="_blank">CVE-2024-4947</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/340221135" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4948" target="_blank">CVE-2024-4948</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/333414294" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4949" target="_blank">CVE-2024-4949</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/326607001" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4950" target="_blank">CVE-2024-4950</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/40065403" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>HP Inc.--Plantronics Hub<br> </td>
<td>A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27460" target="_blank">CVE-2024-27460</a><br><a href="https://support.hp.com/us-en/document/ish_9869257-9869285-16/hpsbpy03895" target="_blank">hp-security-alert@hp.com</a></td>
</tr>
<tr>
<td>Ligowave--UNITY<br> </td>
<td>A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4999" target="_blank">CVE-2024-4999</a><br><a href="https://onekey.com/blog/security-advisory-remote-code-execution-in-ligowave-devices/" target="_blank">research@onekey.com</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races with unix_stream_read_generic(). The safest fix would be to completely disallow sending io_uring files via sockets via SCM_RIGHT, so there are no possible cycles invloving registered files and thus rendering SCM accounting on the io_uring side unnecessary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52654" target="_blank">CVE-2023-52654</a><br><a href="https://git.kernel.org/stable/c/18824f592aad4124d79751bbc1500ea86ac3ff29" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3fe1ea5f921bf5b71cbfdc4469fb96c05936610e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5a33d385eb36991a91e3dddb189d8679e2aac2be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/705318a99a138c29a512a72c3e0043b3cd7f55f4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bcedd497b3b4a0be56f3adf7c7542720eced0792" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2f57f51b53be153a522300454ddb3887722fb2c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: aqc111: check packet for fixup for true limit If a device sends a packet that is inbetween 0 and sizeof(u64) the value passed to skb_trim() as length will wrap around ending up as some very large value. The driver will then proceed to parse the header located at that position, which will either oops or process some random value. The fix is to check against sizeof(u64) rather than 0, which the driver currently does. The issue exists since the introduction of the driver.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52655" target="_blank">CVE-2023-52655</a><br><a href="https://git.kernel.org/stable/c/2ebf775f0541ae0d474836fa0cf3220e502f8e3e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/46412b2fb1f9cc895d6d4036bf24f640b5d86dab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/82c386d73689a45d5ee8c1290827bce64056dddd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/84f2e5b3e70f08fce3cb1ff73414631c5e490204" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ccab434e674ca95d483788b1895a70c21b7f016a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d69581c17608d81824dd497d9a54b6a5b6139975" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support for passing io_uring fds over SCM_RIGHTS, get rid of it.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52656" target="_blank">CVE-2023-52656</a><br><a href="https://git.kernel.org/stable/c/6e5e6d274956305f1fc0340522b38f5f5be74bdb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/88c49d9c896143cdc0f77197c4dcf24140375e89" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a3812a47a32022ca76bf46ddacdd823dc2aabf8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a6771f343af90a25f3a14911634562bb5621df02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfb24022bb2c31f1f555dc6bc3cc5e2547446fb3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d909d381c3152393421403be4b6435f17a2378b4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd/pm: resolve reboot exception for si oland" This reverts commit e490d60a2f76bff636c68ce4fe34c1b6c34bbd86. This causes hangs on SI when DC is enabled and errors on driver reboot and power off cycles.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52657" target="_blank">CVE-2023-52657</a><br><a href="https://git.kernel.org/stable/c/2e443ed55fe3ffb08327b331a9f45e9382413c94" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/955558030954b9637b41c97b730f9b38c92ac488" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/baac292852c0e347626fb5436916947188e5838f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c51468ac328d3922747be55507c117e47da813e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Revert "net/mlx5: Block entering switchdev mode with ns inconsistency" This reverts commit 662404b24a4c4d839839ed25e3097571f5938b9b. The revert is required due to the suspicion it is not good for anything and cause crash.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52658" target="_blank">CVE-2023-52658</a><br><a href="https://git.kernel.org/stable/c/1bcdd66d33edb446903132456c948f0b764ef2f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3fba8eab2cfc7334e0f132d29dfd2552f2f2a579" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8deeefb24786ea7950b37bde4516b286c877db00" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/mm: Ensure input to pfn_to_kaddr() is treated as a 64-bit type On 64-bit platforms, the pfn_to_kaddr() macro requires that the input value is 64 bits in order to ensure that valid address bits don't get lost when shifting that input by PAGE_SHIFT to calculate the physical address to provide a virtual address for. One such example is in pvalidate_pages() (used by SEV-SNP guests), where the GFN in the struct used for page-state change requests is a 40-bit bit-field, so attempts to pass this GFN field directly into pfn_to_kaddr() ends up causing guest crashes when dealing with addresses above the 1TB range due to the above. Fix this issue with SEV-SNP guests, as well as any similar cases that might cause issues in current/future code, by using an inline function, instead of a macro, so that the input is implicitly cast to the expected 64-bit input type prior to performing the shift operation. While it might be argued that the issue is on the caller side, other archs/macros have taken similar approaches to deal with instances like this, such as ARM explicitly casting the input to phys_addr_t: e48866647b48 ("ARM: 8396/1: use phys_addr_t in pfn_to_kaddr()") A C inline function is even better though. [ mingo: Refined the changelog some more &amp; added __always_inline. ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52659" target="_blank">CVE-2023-52659</a><br><a href="https://git.kernel.org/stable/c/325956b0173f11e98f90462be4829a8b8b0682ce" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e1471888a5e6e846e9b4d306e5327db2b58e64e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/814305b5c23cb815ada68d43019f39050472b25f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e5647a723c49d73b9f108a8bb38e8c29d3948ea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ handling due to shared interrupts The driver requests the interrupts as IRQF_SHARED, so the interrupt handlers can be called at any time. If such a call happens while the ISP is powered down, the SoC will hang as the driver tries to access the ISP registers. This can be reproduced even without the platform sharing the IRQ line: Enable CONFIG_DEBUG_SHIRQ and unload the driver, and the board will hang. Fix this by adding a new field, 'irqs_enabled', which is used to bail out from the interrupt handler when the ISP is not operational.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52660" target="_blank">CVE-2023-52660</a><br><a href="https://git.kernel.org/stable/c/abd34206f396d3ae50cddbd5aa840b8cd7f68c63" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b39b4d207d4f236a74e20d291f6356f2231fd9ee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/edcf92bc66d8361c51dff953a55210e5cfd95587" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ffb635bb398fc07cb38f8a7b4a82cbe5f412f08e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/tegra: rgb: Fix missing clk_put() in the error handling paths of tegra_dc_rgb_probe() If clk_get_sys(..., "pll_d2_out0") fails, the clk_get_sys() call must be undone. Add the missing clk_put and a new 'put_pll_d_out0' label in the error handling path, and use it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52661" target="_blank">CVE-2023-52661</a><br><a href="https://git.kernel.org/stable/c/2388c36e028fff7f8ffd515681a14c6c2c07fea7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/45c8034db47842b25a3ab6139d71e13b4e67b9b3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5c8dc26e31b8b410ad1895e0d314def50c76eed0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/845322a9c06dd1dcf35b6c4e3af89684297c23cc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f3f407ccbe84a34de9be3195d22cdd5969f3fd9f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa74e4f5d0821829545b9f7034a0e577c205c101" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node When ida_alloc_max fails, resources allocated before should be freed, including *res allocated by kmalloc and ttm_resource_init.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52662" target="_blank">CVE-2023-52662</a><br><a href="https://git.kernel.org/stable/c/03b1072616a8f7d6e8594f643b416a9467c83fbf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/40624af6674745e174c754a20d7c53c250e65e7a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fc6233f6db1579b69b54b44571f1a7fde8186e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/83e0f220d1e992fa074157fcf14945bf170ffbc5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/89709105a6091948ffb6ec2427954cbfe45358ce" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1e546ab91c670e536a274a75481034ab7534876" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: amd: Fix memory leak in amd_sof_acp_probe() Driver uses kasprintf() to initialize fw_{code,data}_bin members of struct acp_dev_data, but kfree() is never called to deallocate the memory, which results in a memory leak. Fix the issue by switching to devm_kasprintf(). Additionally, ensure the allocation was successful by checking the pointer validity.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52663" target="_blank">CVE-2023-52663</a><br><a href="https://git.kernel.org/stable/c/222be59e5eed1554119294edc743ee548c2371d0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7296152e58858f928db448826eb7ba5ae611297b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/88028c45d5871dfc449b2b0a27abf6428453a5ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be4760799c6a7c01184467287f0de41e0dd255f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: atlantic: eliminate double free in error handling logic Driver has a logic leak in ring data allocation/free, where aq_ring_free could be called multiple times on same ring, if system is under stress and got memory allocation error. Ring pointer was used as an indicator of failure, but this is not correct since only ring data is allocated/deallocated. Ring itself is an array member. Changing ring allocation functions to return error code directly. This simplifies error handling and eliminates aq_ring_free on higher layer.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52664" target="_blank">CVE-2023-52664</a><br><a href="https://git.kernel.org/stable/c/0edb3ae8bfa31cd544b0c195bdec00e036002b5d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b3cb7a830a24527877b0bc900b9bd74a96aea928" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c11a870a73a3bc4cc7df6dd877a45b181795fcbf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1fde4a7e1dcc4d49cce285107a7a43c3030878d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/ps3_defconfig: Disable PPC64_BIG_ENDIAN_ELF_ABI_V2 Commit 8c5fa3b5c4df ("powerpc/64: Make ELFv2 the default for big-endian builds"), merged in Linux-6.5-rc1 changes the calling ABI in a way that is incompatible with the current code for the PS3's LV1 hypervisor calls. This change just adds the line '# CONFIG_PPC64_BIG_ENDIAN_ELF_ABI_V2 is not set' to the ps3_defconfig file so that the PPC64_ELF_ABI_V1 is used. Fixes run time errors like these: BUG: Kernel NULL pointer dereference at 0x00000000 Faulting instruction address: 0xc000000000047cf0 Oops: Kernel access of bad area, sig: 11 [#1] Call Trace: [c0000000023039e0] [c00000000100ebfc] ps3_create_spu+0xc4/0x2b0 (unreliable) [c000000002303ab0] [c00000000100d4c4] create_spu+0xcc/0x3c4 [c000000002303b40] [c00000000100eae4] ps3_enumerate_spus+0xa4/0xf8</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52665" target="_blank">CVE-2023-52665</a><br><a href="https://git.kernel.org/stable/c/482b718a84f08b6fc84879c3e90cc57dba11c115" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d0f0780f03df54d08ced118d27834ee5008724e4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f70557d48215b14a9284ac3a6ae7e4ee1d039f10" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potential circular locking issue in smb2_set_ea() smb2_set_ea() can be called in parent inode lock range. So add get_write argument to smb2_set_ea() not to call nested mnt_want_write().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52666" target="_blank">CVE-2023-52666</a><br><a href="https://git.kernel.org/stable/c/5349fd419e4f685d609c85b781f2b70f0fb14848" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fc0a265e1b932e5e97a038f99e29400a93baad0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e61fc656ceeaec65f19a92f0ffbeb562b7941e8d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e9ec6665de8f706b4f4133b87b2bd02a159ec57b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ecfd93955994ecc2a1308f5ee4bd90c7fca9a8c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a potential double-free in fs_any_create_groups When kcalloc() for ft-&gt;g succeeds but kvzalloc() for in fails, fs_any_create_groups() will free ft-&gt;g. However, its caller fs_any_create_table() will free ft-&gt;g again through calling mlx5e_destroy_flow_table(), which will lead to a double-free. Fix this by setting ft-&gt;g to NULL in fs_any_create_groups().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52667" target="_blank">CVE-2023-52667</a><br><a href="https://git.kernel.org/stable/c/2897c981ee63e1be5e530b1042484626a10b26d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/65a4ade8a6d205979292e88beeb6a626ddbd4779" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72a729868592752b5a294d27453da264106983b1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/aef855df7e1bbd5aa4484851561211500b22707e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b2fa86b2aceb4bc9ada51cea90f61546d7512cbe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix lock ordering in btrfs_zone_activate() The btrfs CI reported a lockdep warning as follows by running generic generic/129. WARNING: possible circular locking dependency detected 6.7.0-rc5+ #1 Not tainted ------------------------------------------------------ kworker/u5:5/793427 is trying to acquire lock: ffff88813256d028 (&amp;cache-&gt;lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x5e/0x130 but task is already holding lock: ffff88810a23a318 (&amp;fs_info-&gt;zone_active_bgs_lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x34/0x130 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -&gt; #1 (&amp;fs_info-&gt;zone_active_bgs_lock){+.+.}-{2:2}: ... -&gt; #0 (&amp;cache-&gt;lock){+.+.}-{2:2}: ... This is because we take fs_info-&gt;zone_active_bgs_lock after a block_group's lock in btrfs_zone_activate() while doing the opposite in other places. Fix the issue by expanding the fs_info-&gt;zone_active_bgs_lock's critical section and taking it before a block_group's lock.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52668" target="_blank">CVE-2023-52668</a><br><a href="https://git.kernel.org/stable/c/1908e9d01e5395adff68d9d308a0fb15337e6272" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6f74989f5909cdec9b1274641f0fa306b15bb476" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b18f3b60b35a8c01c9a2a0f0d6424c6d73971dc3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390 ctr code will always read a whole block, even if there isn't a whole block of data left. Fix this by using the actual length left and copy it into a buffer first for processing.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52669" target="_blank">CVE-2023-52669</a><br><a href="https://git.kernel.org/stable/c/a7f580cdb42ec3d53bbb7c4e4335a98423703285" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd51e26a3b89706beec64f2d8296cfb1c34e0c79" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d07f951903fa9922c375b8ab1ce81b18a0034e3b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d68ac38895e84446848b7647ab9458d54cacba3e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dbc9a791a70ea47be9f2acf251700fe254a2ab23" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e78f1a43e72daf77705ad5b9946de66fc708b874" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: rpmsg: virtio: Free driver_override when rpmsg_remove() Free driver_override when rpmsg_remove(), otherwise the following memory leak will occur: unreferenced object 0xffff0000d55d7080 (size 128): comm "kworker/u8:2", pid 56, jiffies 4294893188 (age 214.272s) hex dump (first 32 bytes): 72 70 6d 73 67 5f 6e 73 00 00 00 00 00 00 00 00 rpmsg_ns........ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [&lt;000000009c94c9c1&gt;] __kmem_cache_alloc_node+0x1f8/0x320 [&lt;000000002300d89b&gt;] __kmalloc_node_track_caller+0x44/0x70 [&lt;00000000228a60c3&gt;] kstrndup+0x4c/0x90 [&lt;0000000077158695&gt;] driver_set_override+0xd0/0x164 [&lt;000000003e9c4ea5&gt;] rpmsg_register_device_override+0x98/0x170 [&lt;000000001c0c89a8&gt;] rpmsg_ns_register_device+0x24/0x30 [&lt;000000008bbf8fa2&gt;] rpmsg_probe+0x2e0/0x3ec [&lt;00000000e65a68df&gt;] virtio_dev_probe+0x1c0/0x280 [&lt;00000000443331cc&gt;] really_probe+0xbc/0x2dc [&lt;00000000391064b1&gt;] __driver_probe_device+0x78/0xe0 [&lt;00000000a41c9a5b&gt;] driver_probe_device+0xd8/0x160 [&lt;000000009c3bd5df&gt;] __device_attach_driver+0xb8/0x140 [&lt;0000000043cd7614&gt;] bus_for_each_drv+0x7c/0xd4 [&lt;000000003b929a36&gt;] __device_attach+0x9c/0x19c [&lt;00000000a94e0ba8&gt;] device_initial_probe+0x14/0x20 [&lt;000000003c999637&gt;] bus_probe_device+0xa0/0xac</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52670" target="_blank">CVE-2023-52670</a><br><a href="https://git.kernel.org/stable/c/229ce47cbfdc7d3a9415eb676abbfb77d676cb08" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2d27a7b19cb354c6d04bcdc9239e261ff29858d6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4e6cef3fae5c164968118a13f3fe293700adc81a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/69ca89d80f2c8a1f5af429b955637beea7eead30" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a416d624e5fb7246ea97c11fbfea7e0e27abf43" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d5362c37e1f8a40096452fc201c30e705750e687" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd50fe18c234bd5ff22f658f4d414e8fa8cd6a5d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f4bb1d5daf77b1a95a43277268adf0d1430c2346" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix hang/underflow when transitioning to ODM4:1 [Why] Under some circumstances, disabling an OPTC and attempting to reclaim its OPP(s) for a different OPTC could cause a hang/underflow due to OPPs not being properly disconnected from the disabled OPTC. [How] Ensure that all OPPs are unassigned from an OPTC when it gets disabled.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52671" target="_blank">CVE-2023-52671</a><br><a href="https://git.kernel.org/stable/c/4b6b479b2da6badff099b2e3abf0248936eefbf5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ae62f1dde66a6f0eee98defc4c7a346bd5acd239" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e7b2b108cdeab76a7e7324459e50b0c1214c0386" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: pipe: wakeup wr_wait after setting max_usage Commit c73be61cede5 ("pipe: Add general notification queue support") a regression was introduced that would lock up resized pipes under certain conditions. See the reproducer in [1]. The commit resizing the pipe ring size was moved to a different function, doing that moved the wakeup for pipe-&gt;wr_wait before actually raising pipe-&gt;max_usage. If a pipe was full before the resize occured it would result in the wakeup never actually triggering pipe_write. Set @max_usage and @nr_accounted before waking writers if this isn't a watch queue. [Christian Brauner &lt;brauner@kernel.org&gt;: rewrite to account for watch queues]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52672" target="_blank">CVE-2023-52672</a><br><a href="https://git.kernel.org/stable/c/162ae0e78bdabf84ef10c1293c4ed7865cb7d3c8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3efbd114b91525bb095b8ae046382197d92126b9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/68e51bdb1194f11d3452525b99c98aff6f837b24" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fb70694f8d1ac34e45246b0ac988f025e1e5b55" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b87a1229d8668fbc78ebd9ca0fc797a76001c60f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e95aada4cb93d42e25c30a0ef9eb2923d9711d4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix a debugfs null pointer error [WHY &amp; HOW] Check whether get_subvp_en() callback exists before calling it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52673" target="_blank">CVE-2023-52673</a><br><a href="https://git.kernel.org/stable/c/43235db21fc23559f50a62f8f273002eeb506f5a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/efb91fea652a42fcc037d2a9ef4ecd1ffc5ff4b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add clamp() in scarlett2_mixer_ctl_put() Ensure the value passed to scarlett2_mixer_ctl_put() is between 0 and SCARLETT2_MIXER_MAX_VALUE so we don't attempt to access outside scarlett2_mixer_values[].</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52674" target="_blank">CVE-2023-52674</a><br><a href="https://git.kernel.org/stable/c/03035872e17897ba89866940bbc9cefca601e572" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/04f8f053252b86c7583895c962d66747ecdc61b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad945ea8d47dd4454c271510bea24850119847c2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d8d8897d65061cbe36bf2909057338303a904810" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e517645ead5ea22c69d2a44694baa23fe1ce7c2b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/imc-pmu: Add a null pointer check in update_events_in_group() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52675" target="_blank">CVE-2023-52675</a><br><a href="https://git.kernel.org/stable/c/024352f7928b28f53609660663329d8c0f4ad032" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0a233867a39078ebb0f575e2948593bbff5826b3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1e80aa25d186a7aa212df5acd8c75f55ac8dae34" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5a669f3511d273c8c1ab1c1d268fbcdf53fc7a05" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/75fc599bcdcb1de093c9ced2e3cccc832f3787f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a2da3f9b1a1019c887ee1d164475a8fcdb0a3fec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c7d828e12b326ea50fb80c369d7aa87519ed14c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f105c263009839d80fad6998324a4e1b3511cba0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: bpf: Guard stack limits against 32bit overflow This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current 32bit. The arithmetic implies adding together a 64-bit register with a int offset. The register was checked to be below 1&lt;&lt;29 when it was variable, but not when it was fixed. The offset either comes from an instruction (in which case it is 16 bit), from another register (in which case the caller checked it to be below 1&lt;&lt;29 [1]), or from the size of an argument to a kfunc (in which case it can be a u32 [2]). Between the register being inconsistently checked to be below 1&lt;&lt;29, and the offset being up to an u32, it appears that we were open to overflowing the `int`s which were currently used for arithmetic. [1] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L7494-L7498 [2] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L11904</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52676" target="_blank">CVE-2023-52676</a><br><a href="https://git.kernel.org/stable/c/1d38a9ee81570c4bd61f557832dead4d6f816760" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad140fc856f0b1d5e2215bcb6d0cc247a86805a2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e5ad9ecb84405637df82732ee02ad741a5f782a6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: riscv: Check if the code to patch lies in the exit section Otherwise we fall through to vmalloc_to_page() which panics since the address does not lie in the vmalloc region.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52677" target="_blank">CVE-2023-52677</a><br><a href="https://git.kernel.org/stable/c/1d7a03052846f34d624d0ab41a879adf5e85c85f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/420370f3ae3d3b883813fd3051a38805160b2b9f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/890cfe5337e0aaf03ece1429db04d23c88da72e7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8db56df4a954b774bdc68917046a685a9fa2e4bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/938f70d14618ec72e10d6fcf8a546134136d7c13" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Confirm list is non-empty before utilizing list_first_entry in kfd_topology.c Before using list_first_entry, make sure to check that list is not empty, if list is empty return -ENODATA. Fixes the below: drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_topology.c:1347 kfd_create_indirect_link_prop() warn: can 'gpu_link' even be NULL? drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_topology.c:1428 kfd_add_peer_prop() warn: can 'iolink1' even be NULL? drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_topology.c:1433 kfd_add_peer_prop() warn: can 'iolink2' even be NULL?</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52678" target="_blank">CVE-2023-52678</a><br><a href="https://git.kernel.org/stable/c/4525525cb7161d08f95d0e47025323dd10214313" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/499839eca34ad62d43025ec0b46b80e77065f6d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ac4e023ed7ab1c7c67d2d12b7b6198fcd099e5c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5024cce888e11e5688f77df81db9e14828495d64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: of: Fix double free in of_parse_phandle_with_args_map In of_parse_phandle_with_args_map() the inner loop that iterates through the map entries calls of_node_put(new) to free the reference acquired by the previous iteration of the inner loop. This assumes that the value of "new" is NULL on the first iteration of the inner loop. Make sure that this is true in all iterations of the outer loop by setting "new" to NULL after its value is assigned to "cur". Extend the unittest to detect the double free and add an additional test case that actually triggers this path.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52679" target="_blank">CVE-2023-52679</a><br><a href="https://git.kernel.org/stable/c/26b4d702c44f9e5cf3c5c001ae619a4a001889db" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4541004084527ce9e95a818ebbc4e6b293ffca21" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4dde83569832f9377362e50f7748463340c5db6b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a0a061151a6200c13149dbcdb6c065203c8425d2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b64d09a4e8596f76d27f4b4a90a1cf6baf6a82f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9d760dae5b10e73369b769073525acd7b3be2bd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cafa992134124e785609a406da4ff2b54052aff7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d5f490343c77e6708b6c4aa7dbbfbcbb9546adea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing error checks to *_ctl_get() The *_ctl_get() functions which call scarlett2_update_*() were not checking the return value. Fix to check the return value and pass to the caller.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52680" target="_blank">CVE-2023-52680</a><br><a href="https://git.kernel.org/stable/c/3a09488f4f67f7ade59b8ac62a6c7fb29439cf51" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/50603a67daef161c78c814580d57f7f0be57167e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/773e38f73461ef2134a0d33a08f1668edde9b7c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/821fbaeaaae23d483d3df799fe91ec8045973ec3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cda7762bea857e6951315a2f7d0632ea1850ed43" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: efivarfs: Free s_fs_info on unmount Now that we allocate a s_fs_info struct on fs context creation, we should ensure that we free it again when the superblock goes away.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52681" target="_blank">CVE-2023-52681</a><br><a href="https://git.kernel.org/stable/c/48be1364dd387e375e1274b76af986cb8747be2c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/547713d502f7b4b8efccd409cff84d731a23853b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92be3095c6ca1cdc46237839c6087555be9160e3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea6b597fcaca99562fa56a473bcbbbd79b40af03" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait on block writeback for post_read case If inode is compressed, but not encrypted, it missed to call f2fs_wait_on_block_writeback() to wait for GCed page writeback in IPU write path. Thread A GC-Thread - f2fs_gc - do_garbage_collect - gc_data_segment - move_data_block - f2fs_submit_page_write migrate normal cluster's block via meta_inode's page cache - f2fs_write_single_data_page - f2fs_do_write_data_page - f2fs_inplace_write_data - f2fs_submit_page_bio IRQ - f2fs_read_end_io IRQ old data overrides new data due to out-of-order GC and common IO. - f2fs_read_end_io</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52682" target="_blank">CVE-2023-52682</a><br><a href="https://git.kernel.org/stable/c/4535be48780431753505e74e1b1ad4836a189bc2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/55fdc1c24a1d6229fe0ecf31335fb9a2eceaaa00" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9bfd5ea71521d0e522ba581c6ccc5db93759c0c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f904c156d8011d8291ffd5b6b398f3747e294986" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ACPI: LPIT: Avoid u32 multiplication overflow In lpit_update_residency() there is a possibility of overflow in multiplication, if tsc_khz is large enough (&gt; UINT_MAX/1000). Change multiplication to mul_u32_u32(). Found by Linux Verification Center (linuxtesting.org) with SVACE.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52683" target="_blank">CVE-2023-52683</a><br><a href="https://git.kernel.org/stable/c/56d2eeda87995245300836ee4dbd13b002311782" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/647d1d50c31e60ef9ccb9756a8fdf863329f7aee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6c38e791bde07d6ca2a0a619ff9b6837e0d5f9ad" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72222dfd76a79d9666ab3117fcdd44ca8cd0c4de" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b7aab9d906e2e252a7783f872406033ec49b6dae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c1814a4ffd016ce5392c6767d22ef3aa2f0d4bd1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1ac288b2742aa4af746c5613bac71760fadd1c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f39c3d578c7d09a18ceaf56750fc7f20b02ada63" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: qseecom: fix memory leaks in error paths Fix instances of returning error codes directly instead of jumping to the relevant labels where memory allocated for the SCM calls would be freed.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52684" target="_blank">CVE-2023-52684</a><br><a href="https://git.kernel.org/stable/c/6c57d7b593c4a4e60db65d5ce0fe1d9f79ccbe9b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/85fdbf6840455be64eac16bdfe0df3368ee3d0f0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: pstore: ram_core: fix possible overflow in persistent_ram_init_ecc() In persistent_ram_init_ecc(), on 64-bit arches DIV_ROUND_UP() will return 64-bit value since persistent_ram_zone::buffer_size has type size_t which is derived from the 64-bit *unsigned long*, while the ecc_blocks variable this value gets assigned to has (always 32-bit) *int* type. Even if that value fits into *int* type, an overflow is still possible when calculating the size_t typed ecc_total variable further below since there's no cast to any 64-bit type before multiplication. Declaring the ecc_blocks variable as *size_t* should fix this mess... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52685" target="_blank">CVE-2023-52685</a><br><a href="https://git.kernel.org/stable/c/3b333cded94fbe5ce30d699b316c4715151268ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/48dcfc42ce705b652c0619cb99846afc43029de9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/86222a8fc16ec517de8da2604d904c9df3a08e5d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8fb12524c86bdd542a54857d5d076b1b6778c78c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a34946ec3de88a16cc3a87fdab50aad06255a22b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/acd413da3e1f37582207cd6078a41d57c9011918" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1fe1aede684bd014714dacfdc75586a9ad38657" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f9b891a7e8fcf83901f8507241e23e7420103b61" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_event_init() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52686" target="_blank">CVE-2023-52686</a><br><a href="https://git.kernel.org/stable/c/8422d179cf46889c15ceff9ede48c5bfa4e7f0b4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8649829a1dd25199bbf557b2621cedb4bf9b3050" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a523e1da6d88c2034f946adfa4f74b236c95ca9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a14c55eb461d630b836f80591d8caf1f74e62877" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c0b111ea786ddcc8be0682612830796ece9436c7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e08c2e275fa1874de945b87093f925997722ee42" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e6ad05e3ae9c84c5a71d7bb2d44dc845ae7990cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e93d7cf4c1ddbcd846739e7ad849f955a4f18031" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: crypto: safexcel - Add error handling for dma_map_sg() calls Macro dma_map_sg() may return 0 on error. This patch enables checks in case of the macro failure and ensures unmapping of previously mapped buffers with dma_unmap_sg(). Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52687" target="_blank">CVE-2023-52687</a><br><a href="https://git.kernel.org/stable/c/4c0ac81a172a69a7733290915276672787e904ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8084b788c2fb1260f7d44c032d5124680b20d2b2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/87e02063d07708cac5bfe9fd3a6a242898758ac8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc0b785802b856566df3ac943e38a072557001c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix the error handler of rfkill config When the core rfkill config throws error, it should free the allocated resources. Currently it is not freeing the core pdev create resources. Avoid this issue by calling the core pdev destroy in the error handler of core rfkill config. Found this issue in the code review and it is compile tested only.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52688" target="_blank">CVE-2023-52688</a><br><a href="https://git.kernel.org/stable/c/898d8b3e1414cd900492ee6a0b582f8095ba4a1a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b4e593a7a22fa3c7d0550ef51c90b5c21f790aa8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing mutex lock around get meter levels As scarlett2_meter_ctl_get() uses meter_level_map[], the data_mutex should be locked while accessing it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52689" target="_blank">CVE-2023-52689</a><br><a href="https://git.kernel.org/stable/c/74e3de7cdcc31ce75ab42350ae0946eff62a2da2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/993f7b42fa066b055e3a19b7f76ad8157c0927a0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check to scom_debug_init_one() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Add a null pointer check, and release 'ent' to avoid memory leaks.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52690" target="_blank">CVE-2023-52690</a><br><a href="https://git.kernel.org/stable/c/1eefa93faf69188540b08b024794fa90b1d82e8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2a82c4439b903639e0a1f21990cd399fb0a49c19" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a260f2dd827bbc82cc60eb4f4d8c22707d80742" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a9c05cbb6644a2103c75b6906e9dafb9981ebd13" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd8422ff271c22058560832fc3006324ded895a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ed8d023cfa97b559db58c0e1afdd2eec7a83d8f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f84c1446daa552e9699da8d1f8375eac0f65edc7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix a double-free in si_dpm_init When the allocation of adev-&gt;pm.dpm.dyn_state.vddc_dependency_on_dispclk.entries fails, amdgpu_free_extended_power_table is called to free some fields of adev. However, when the control flow returns to si_dpm_sw_init, it goes to label dpm_failed and calls si_dpm_fini, which calls amdgpu_free_extended_power_table again and free those fields again. Thus a double-free is triggered.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52691" target="_blank">CVE-2023-52691</a><br><a href="https://git.kernel.org/stable/c/06d95c99d5a4f5accdb79464076efe62e668c706" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2bf47c89bbaca2bae16581ef1b28aaec0ade0334" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ac16667237a82e2597e329eb9bc520d1cf9dff30" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/aeed2b4e4a70c7568d4a5eecd6a109713c0dfbf4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/afe9f5b871f86d58ecdc45b217b662227d7890d0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ca8e2e251c65e5a712f6025e27bd9b26d16e6f4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f957a1be647f7fc65926cbf572992ec2747a93f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fb1936cb587262cd539e84b34541abb06e42b2f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing error check to scarlett2_usb_set_config() scarlett2_usb_set_config() calls scarlett2_usb_get() but was not checking the result. Return the error if it fails rather than continuing with an invalid value.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52692" target="_blank">CVE-2023-52692</a><br><a href="https://git.kernel.org/stable/c/145c5aa51486171025ab47f35cff34bff8d0cea3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/51d5697e1c0380d482c3eab002bfc8d0be177e99" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/996fde492ad9b9563ee483b363af40d7696a8467" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be96acd3eaa790d10a5b33e65267f52d02f6ad88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ca459dfa7d4ed9098fcf13e410963be6ae9b6bf3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ACPI: video: check for error while searching for backlight device parent If acpi_get_parent() called in acpi_video_dev_register_backlight() fails, for example, because acpi_ut_acquire_mutex() fails inside acpi_get_parent), this can lead to incorrect (uninitialized) acpi_parent handle being passed to acpi_get_pci_dev() for detecting the parent pci device. Check acpi_get_parent() result and set parent device only in case of success. Found by Linux Verification Center (linuxtesting.org) with SVACE.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52693" target="_blank">CVE-2023-52693</a><br><a href="https://git.kernel.org/stable/c/1e3a2b9b4039bb4d136dca59fb31e06465e056f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2124c5bc22948fc4d09a23db4a8acdccc7d21e95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/39af144b6d01d9b40f52e5d773e653957e6c379c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3a370502a5681986f9828e43be75ce26c6ab24af" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/556f02699d33c1f40b1b31bd25828ce08fa165d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72884ce4e10417b1233b614bf134da852df0f15f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c4e1a0ef0b4782854c9b77a333ca912b392bed2f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ccd45faf4973746c4f30ea41eec864e5cf191099" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tpd12s015: Drop buggy __exit annotation for remove function With tpd12s015_remove() marked with __exit this function is discarded when the driver is compiled as a built-in. The result is that when the driver unbinds there is no cleanup done which results in resource leakage or worse.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52694" target="_blank">CVE-2023-52694</a><br><a href="https://git.kernel.org/stable/c/08ccff6ece35f08e8107e975903c370d849089e5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/53926e2a39629702f7f809d614b3ca89c2478205" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/81f1bd85960b7a089a91e679ff7cd2524390bbf1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a8657406e12aa10412134622c58977ac657f16d2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ce3e112e7ae854249d8755906acc5f27e1542114" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e00ec5901954d85b39b5f10f94e60ab9af463eb1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check writeback connectors in create_validate_stream_for_sink [WHY &amp; HOW] This is to check connector type to avoid unhandled null pointer for writeback connectors.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52695" target="_blank">CVE-2023-52695</a><br><a href="https://git.kernel.org/stable/c/0fe85301b95077ac4fa4a91909d38b7341e81187" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dbf5d3d02987faa0eec3710dd687cd912362d7b5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_powercap_init() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52696" target="_blank">CVE-2023-52696</a><br><a href="https://git.kernel.org/stable/c/69f95c5e9220f77ce7c540686b056c2b49e9a664" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6b58d16037217d0c64a2a09b655f370403ec7219" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9da4a56dd3772570512ca58aa8832b052ae910dc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a67a04ad05acb56640798625e73fa54d6d41cce1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b02ecc35d01a76b4235e008d2dd292895b28ecab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e123015c0ba859cf48aa7f89c5016cc6e98e018d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f152a6bfd187f67afeffc9fd68cbe46f51439be0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx-&gt;headset_codec_dev = NULL sof_sdw_rt_sdca_jack_exit() are used by different codecs, and some of them use the same dai name. For example, rt712 and rt713 both use "rt712-sdca-aif1" and sof_sdw_rt_sdca_jack_exit(). As a result, sof_sdw_rt_sdca_jack_exit() will be called twice by mc_dailink_exit_loop(). Set ctx-&gt;headset_codec_dev = NULL; after put_device(ctx-&gt;headset_codec_dev); to avoid ctx-&gt;headset_codec_dev being put twice.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52697" target="_blank">CVE-2023-52697</a><br><a href="https://git.kernel.org/stable/c/582231a8c4f73ac153493687ecc1bed853e9c9ef" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a410d58117d6da4b7d41f3c91365f191d006bc3d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e38e252dbceeef7d2f848017132efd68e9ae1416" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: calipso: fix memory leak in netlbl_calipso_add_pass() If IPv6 support is disabled at boot (ipv6.disable=1), the calipso_init() -&gt; netlbl_calipso_ops_register() function isn't called, and the netlbl_calipso_ops_get() function always returns NULL. In this case, the netlbl_calipso_add_pass() function allocates memory for the doi_def variable but doesn't free it with the calipso_doi_free(). BUG: memory leak unreferenced object 0xffff888011d68180 (size 64): comm "syz-executor.1", pid 10746, jiffies 4295410986 (age 17.928s) hex dump (first 32 bytes): 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [&lt;...&gt;] kmalloc include/linux/slab.h:552 [inline] [&lt;...&gt;] netlbl_calipso_add_pass net/netlabel/netlabel_calipso.c:76 [inline] [&lt;...&gt;] netlbl_calipso_add+0x22e/0x4f0 net/netlabel/netlabel_calipso.c:111 [&lt;...&gt;] genl_family_rcv_msg_doit+0x22f/0x330 net/netlink/genetlink.c:739 [&lt;...&gt;] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline] [&lt;...&gt;] genl_rcv_msg+0x341/0x5a0 net/netlink/genetlink.c:800 [&lt;...&gt;] netlink_rcv_skb+0x14d/0x440 net/netlink/af_netlink.c:2515 [&lt;...&gt;] genl_rcv+0x29/0x40 net/netlink/genetlink.c:811 [&lt;...&gt;] netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline] [&lt;...&gt;] netlink_unicast+0x54b/0x800 net/netlink/af_netlink.c:1339 [&lt;...&gt;] netlink_sendmsg+0x90a/0xdf0 net/netlink/af_netlink.c:1934 [&lt;...&gt;] sock_sendmsg_nosec net/socket.c:651 [inline] [&lt;...&gt;] sock_sendmsg+0x157/0x190 net/socket.c:671 [&lt;...&gt;] ____sys_sendmsg+0x712/0x870 net/socket.c:2342 [&lt;...&gt;] ___sys_sendmsg+0xf8/0x170 net/socket.c:2396 [&lt;...&gt;] __sys_sendmsg+0xea/0x1b0 net/socket.c:2429 [&lt;...&gt;] do_syscall_64+0x30/0x40 arch/x86/entry/common.c:46 [&lt;...&gt;] entry_SYSCALL_64_after_hwframe+0x61/0xc6 Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with Syzkaller [PM: merged via the LSM tree at Jakub Kicinski request]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52698" target="_blank">CVE-2023-52698</a><br><a href="https://git.kernel.org/stable/c/321b3a5592c8a9d6b654c7c64833ea67dbb33149" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/36e19f84634aaa94f543fedc0a07588949638d53" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/408bbd1e1746fe33e51f4c81c2febd7d3841d031" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/44a88650ba55e6a7f2ec485d2c2413ba7e216f01" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a8f811a146aa2a0230f8edb2e9f4b6609aab8da" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a4529a08d3704c17ea9c7277d180e46b99250ded" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ec4e9d630a64df500641892f4e259e8149594a99" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f14d36e6e97fe935a20e0ceb159c100f90b6627c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit 6a5bcd84e886 ("page_pool: Allow drivers to hint on SKB recycling"). It is believed that fixes tag were missing a call to page_pool_release_page() between v5.9 to v5.14, after which is should have used skb_mark_for_recycle(). Since v6.6 the call page_pool_release_page() were removed (in commit 535b9c61bdef ("net: page_pool: hide page_pool_release_page()") and remaining callers converted (in commit 6bfef2ec0172 ("Merge branch 'net-page_pool-remove-page_pool_release_page'")). This leak became visible in v6.8 via commit dba1b8a7ab68 ("mm/page_pool: catch page_pool memory leaks").</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27393" target="_blank">CVE-2024-27393</a><br><a href="https://git.kernel.org/stable/c/037965402a010898d34f4e35327d22c0a95cd51f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/27aa3e4b3088426b7e34584274ad45b5afaf7629" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4143b9479caa29bb2380f3620dcbe16ea84eb3b1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7c1250796b6c262b505a46192f4716b8c6a6a8c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c8b7b2f158d9d4fb89cd2f68244af154f7549bb4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: tcp: Fix Use-After-Free in tcp_ao_connect_init Since call_rcu, which is called in the hlist_for_each_entry_rcu traversal of tcp_ao_connect_init, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27394" target="_blank">CVE-2024-27394</a><br><a href="https://git.kernel.org/stable/c/80e679b352c3ce5158f3f778cfb77eb767e586fb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ca4fb6c6764b3f75b4f5aa81db1536291897ff7f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix Use-After-Free in ovs_ct_exit Since kfree_rcu, which is called in the hlist_for_each_entry_rcu traversal of ovs_ct_limit_exit, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27395" target="_blank">CVE-2024-27395</a><br><a href="https://git.kernel.org/stable/c/2db9a8c0a01fa1c762c1e61a13c212c492752994" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/35880c3fa6f8fe281a19975d2992644588ca33d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/589523cf0b384164e445dd5db8d5b1bf97982424" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5ea7b72d4fac2fdbc0425cd8f2ea33abe95235b2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9048616553c65e750d43846f225843ed745ec0d4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bca6fa2d9a9f560e6b89fd5190b05cc2f5d422c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eaa5e164a2110d2fb9e16c8a29e4501882235137" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/edee0758747d7c219e29db9ed1d4eb33e8d32865" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: gtp: Fix Use-After-Free in gtp_dellink Since call_rcu, which is called in the hlist_for_each_entry_rcu traversal of gtp_dellink, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27396" target="_blank">CVE-2024-27396</a><br><a href="https://git.kernel.org/stable/c/07b20d0a3dc13fb1adff10b60021a4924498da58" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0caff3e6390f840666b8dc1ecebf985c2ef3f1dd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/25a1c2d4b1fcf938356a9688a96a6456abd44b29" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2aacd4de45477582993f8a8abb9505a06426bfb6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2e74b3fd6bf542349758f283676dff3660327c07" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/718df1bc226c383dd803397d7f5d95557eb81ac7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd957d1716ec979d8f5bf38fc659aeb9fdaa2474" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2a904107ee2b647bb7794a1a82b67740d7c8a64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use timestamp to check for set element timeout Add a timestamp field at the beginning of the transaction, store it in the nftables per-netns area. Update set backend .insert, .deactivate and sync gc path to use the timestamp, this avoids that an element expires while control plane transaction is still unfinished. .lookup and .update, which are used from packet path, still use the current time to check if the element has expired. And .get path and dump also since this runs lockless under rcu read size lock. Then, there is async gc which also needs to check the current time since it runs asynchronously from a workqueue.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27397" target="_blank">CVE-2024-27397</a><br><a href="https://git.kernel.org/stable/c/383182db8d58c4237772ba0764cded4938a235c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7395dfacfff65e9938ac0889dafa1ab01e987d15" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated later, but it is dereferenced again in sco_sock_timeout. As a result, the use-after-free bugs will happen. The root cause is shown below: Cleanup Thread | Worker Thread sco_sock_release | sco_sock_close | __sco_sock_close | sco_sock_set_timer | schedule_delayed_work | sco_sock_kill | (wait a time) sock_put(sk) //FREE | sco_sock_timeout | sock_hold(sk) //USE The KASAN report triggered by POC is shown below: [ 95.890016] ================================================================== [ 95.890496] BUG: KASAN: slab-use-after-free in sco_sock_timeout+0x5e/0x1c0 [ 95.890755] Write of size 4 at addr ffff88800c388080 by task kworker/0:0/7 ... [ 95.890755] Workqueue: events sco_sock_timeout [ 95.890755] Call Trace: [ 95.890755] &lt;TASK&gt; [ 95.890755] dump_stack_lvl+0x45/0x110 [ 95.890755] print_address_description+0x78/0x390 [ 95.890755] print_report+0x11b/0x250 [ 95.890755] ? __virt_addr_valid+0xbe/0xf0 [ 95.890755] ? sco_sock_timeout+0x5e/0x1c0 [ 95.890755] kasan_report+0x139/0x170 [ 95.890755] ? update_load_avg+0xe5/0x9f0 [ 95.890755] ? sco_sock_timeout+0x5e/0x1c0 [ 95.890755] kasan_check_range+0x2c3/0x2e0 [ 95.890755] sco_sock_timeout+0x5e/0x1c0 [ 95.890755] process_one_work+0x561/0xc50 [ 95.890755] worker_thread+0xab2/0x13c0 [ 95.890755] ? pr_cont_work+0x490/0x490 [ 95.890755] kthread+0x279/0x300 [ 95.890755] ? pr_cont_work+0x490/0x490 [ 95.890755] ? kthread_blkcg+0xa0/0xa0 [ 95.890755] ret_from_fork+0x34/0x60 [ 95.890755] ? kthread_blkcg+0xa0/0xa0 [ 95.890755] ret_from_fork_asm+0x11/0x20 [ 95.890755] &lt;/TASK&gt; [ 95.890755] [ 95.890755] Allocated by task 506: [ 95.890755] kasan_save_track+0x3f/0x70 [ 95.890755] __kasan_kmalloc+0x86/0x90 [ 95.890755] __kmalloc+0x17f/0x360 [ 95.890755] sk_prot_alloc+0xe1/0x1a0 [ 95.890755] sk_alloc+0x31/0x4e0 [ 95.890755] bt_sock_alloc+0x2b/0x2a0 [ 95.890755] sco_sock_create+0xad/0x320 [ 95.890755] bt_sock_create+0x145/0x320 [ 95.890755] __sock_create+0x2e1/0x650 [ 95.890755] __sys_socket+0xd0/0x280 [ 95.890755] __x64_sys_socket+0x75/0x80 [ 95.890755] do_syscall_64+0xc4/0x1b0 [ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f [ 95.890755] [ 95.890755] Freed by task 506: [ 95.890755] kasan_save_track+0x3f/0x70 [ 95.890755] kasan_save_free_info+0x40/0x50 [ 95.890755] poison_slab_object+0x118/0x180 [ 95.890755] __kasan_slab_free+0x12/0x30 [ 95.890755] kfree+0xb2/0x240 [ 95.890755] __sk_destruct+0x317/0x410 [ 95.890755] sco_sock_release+0x232/0x280 [ 95.890755] sock_close+0xb2/0x210 [ 95.890755] __fput+0x37f/0x770 [ 95.890755] task_work_run+0x1ae/0x210 [ 95.890755] get_signal+0xe17/0xf70 [ 95.890755] arch_do_signal_or_restart+0x3f/0x520 [ 95.890755] syscall_exit_to_user_mode+0x55/0x120 [ 95.890755] do_syscall_64+0xd1/0x1b0 [ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f [ 95.890755] [ 95.890755] The buggy address belongs to the object at ffff88800c388000 [ 95.890755] which belongs to the cache kmalloc-1k of size 1024 [ 95.890755] The buggy address is located 128 bytes inside of [ 95.890755] freed 1024-byte region [ffff88800c388000, ffff88800c388400) [ 95.890755] [ 95.890755] The buggy address belongs to the physical page: [ 95.890755] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff88800c38a800 pfn:0xc388 [ 95.890755] head: order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 95.890755] ano ---truncated---</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27398" target="_blank">CVE-2024-27398</a><br><a href="https://git.kernel.org/stable/c/012363cb1bec5f33a7b94629ab2c1086f30280f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1b33d55fb7355e27f8c82cd4ecd560f162469249" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3212afd00e3cda790fd0583cb3eaef8f9575a014" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/33a6e92161a78c1073d90e27abe28d746feb0a53" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/483bc08181827fc475643272ffb69c533007e546" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/50c2037fc28df870ef29d9728c770c8955d32178" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6a18eeb1b3bbc67c20d9609c31dca6a69b4bcde5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bfab2c1f7940a232cd519e82fff137e308abfd93" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the channel, the chan-&gt;conn will be set to null. But the conn could be dereferenced again in the mutex_lock() of l2cap_chan_timeout(). As a result the null pointer dereference bug will happen. The KASAN report triggered by POC is shown below: [ 472.074580] ================================================================== [ 472.075284] BUG: KASAN: null-ptr-deref in mutex_lock+0x68/0xc0 [ 472.075308] Write of size 8 at addr 0000000000000158 by task kworker/0:0/7 [ 472.075308] [ 472.075308] CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted 6.9.0-rc5-00356-g78c0094a146b #36 [ 472.075308] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4 [ 472.075308] Workqueue: events l2cap_chan_timeout [ 472.075308] Call Trace: [ 472.075308] &lt;TASK&gt; [ 472.075308] dump_stack_lvl+0x137/0x1a0 [ 472.075308] print_report+0x101/0x250 [ 472.075308] ? __virt_addr_valid+0x77/0x160 [ 472.075308] ? mutex_lock+0x68/0xc0 [ 472.075308] kasan_report+0x139/0x170 [ 472.075308] ? mutex_lock+0x68/0xc0 [ 472.075308] kasan_check_range+0x2c3/0x2e0 [ 472.075308] mutex_lock+0x68/0xc0 [ 472.075308] l2cap_chan_timeout+0x181/0x300 [ 472.075308] process_one_work+0x5d2/0xe00 [ 472.075308] worker_thread+0xe1d/0x1660 [ 472.075308] ? pr_cont_work+0x5e0/0x5e0 [ 472.075308] kthread+0x2b7/0x350 [ 472.075308] ? pr_cont_work+0x5e0/0x5e0 [ 472.075308] ? kthread_blkcg+0xd0/0xd0 [ 472.075308] ret_from_fork+0x4d/0x80 [ 472.075308] ? kthread_blkcg+0xd0/0xd0 [ 472.075308] ret_from_fork_asm+0x11/0x20 [ 472.075308] &lt;/TASK&gt; [ 472.075308] ================================================================== [ 472.094860] Disabling lock debugging due to kernel taint [ 472.096136] BUG: kernel NULL pointer dereference, address: 0000000000000158 [ 472.096136] #PF: supervisor write access in kernel mode [ 472.096136] #PF: error_code(0x0002) - not-present page [ 472.096136] PGD 0 P4D 0 [ 472.096136] Oops: 0002 [#1] PREEMPT SMP KASAN NOPTI [ 472.096136] CPU: 0 PID: 7 Comm: kworker/0:0 Tainted: G B 6.9.0-rc5-00356-g78c0094a146b #36 [ 472.096136] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4 [ 472.096136] Workqueue: events l2cap_chan_timeout [ 472.096136] RIP: 0010:mutex_lock+0x88/0xc0 [ 472.096136] Code: be 08 00 00 00 e8 f8 23 1f fd 4c 89 f7 be 08 00 00 00 e8 eb 23 1f fd 42 80 3c 23 00 74 08 48 88 [ 472.096136] RSP: 0018:ffff88800744fc78 EFLAGS: 00000246 [ 472.096136] RAX: 0000000000000000 RBX: 1ffff11000e89f8f RCX: ffffffff8457c865 [ 472.096136] RDX: 0000000000000001 RSI: 0000000000000008 RDI: ffff88800744fc78 [ 472.096136] RBP: 0000000000000158 R08: ffff88800744fc7f R09: 1ffff11000e89f8f [ 472.096136] R10: dffffc0000000000 R11: ffffed1000e89f90 R12: dffffc0000000000 [ 472.096136] R13: 0000000000000158 R14: ffff88800744fc78 R15: ffff888007405a00 [ 472.096136] FS: 0000000000000000(0000) GS:ffff88806d200000(0000) knlGS:0000000000000000 [ 472.096136] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 472.096136] CR2: 0000000000000158 CR3: 000000000da32000 CR4: 00000000000006f0 [ 472.096136] Call Trace: [ 472.096136] &lt;TASK&gt; [ 472.096136] ? __die_body+0x8d/0xe0 [ 472.096136] ? page_fault_oops+0x6b8/0x9a0 [ 472.096136] ? kernelmode_fixup_or_oops+0x20c/0x2a0 [ 472.096136] ? do_user_addr_fault+0x1027/0x1340 [ 472.096136] ? _printk+0x7a/0xa0 [ 472.096136] ? mutex_lock+0x68/0xc0 [ 472.096136] ? add_taint+0x42/0xd0 [ 472.096136] ? exc_page_fault+0x6a/0x1b0 [ 472.096136] ? asm_exc_page_fault+0x26/0x30 [ 472.096136] ? mutex_lock+0x75/0xc0 [ 472.096136] ? mutex_lock+0x88/0xc0 [ 472.096136] ? mutex_lock+0x75/0xc0 [ 472.096136] l2cap_chan_timeo ---truncated---</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27399" target="_blank">CVE-2024-27399</a><br><a href="https://git.kernel.org/stable/c/06acb75e7ed600d0bbf7bff5628aa8f24a97978c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6466ee65e5b27161c846c73ef407f49dfa1bd1d9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8960ff650aec70485b40771cd8e6e8c4cb467d33" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/955b5b6c54d95b5e7444dfc81c95c8e013f27ac0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/adf0398cee86643b8eacde95f17d073d022f782c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e137e2ba96e51902dc2878131823a96bf8e638ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e97e16433eb4533083b096a3824b93a5ca3aee79" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eb86f955488c39526534211f2610e48a5cf8ead4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace event amdgpu_bo_move always move on same heap. The basic problem here is that after the move the old location is simply not available any more. Some fixes were suggested, but essentially we should call the move notification before actually moving things because only this way we have the correct order for DMA-buf and VM move notifications as well. Also rework the statistic handling so that we don't update the eviction counter before the move. v2: add missing NULL check</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27400" target="_blank">CVE-2024-27400</a><br><a href="https://git.kernel.org/stable/c/0c7ed3ed35eec9138b88d42217b5a6b9a62bda4d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5c25b169f9a0b34ee410891a96bc9d7b9ed6f9be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a4f6e138720b6e9adf7b82a71d0292f3f276480" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d3a9331a6591e9df64791e076f6591f440af51c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into account when fetching packet contents Ensure that packet_buffer_get respects the user_length provided. If the length of the head packet exceeds the user_length, packet_buffer_get will now return 0 to signify to the user that no data were read and a larger buffer size is required. Helps prevent user space overflows.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27401" target="_blank">CVE-2024-27401</a><br><a href="https://git.kernel.org/stable/c/1fe60ee709436550f8cfbab01295936b868d5baa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/38762a0763c10c24a4915feee722d7aa6e73eb98" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ee0941da10e8fdcdb34756b877efd3282594c1f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/539d51ac48bcfcfa1b3d4a85f8df92fa22c1d41c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/67f34f093c0f7bf33f5b4ae64d3d695a3b978285" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/79f988d3ffc1aa778fc5181bdfab312e57956c6b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7b8c7bd2296e95b38a6ff346242356a2e7190239" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cca330c59c54207567a648357835f59df9a286bb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: phonet/pep: fix racy skb_queue_empty() use The receive queues are protected by their respective spin-lock, not the socket lock. This could lead to skb_peek() unexpectedly returning NULL or a pointer to an already dequeued socket buffer.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27402" target="_blank">CVE-2024-27402</a><br><a href="https://git.kernel.org/stable/c/0a9f558c72c47472c38c05fcb72c70abb9104277" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d2a894d7f487dcb894df023e9d3014cf5b93fe5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ef4fcc7014b9f93619851d6b78d6cc2789a4c88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d5523e065b568e79dfaa2ea1085a5bcf74baf78" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_flow_offload: reset dst in route object after setting up flow dst is transferred to the flow object, route object does not own it anymore. Reset dst in route object, otherwise if flow_offload_add() fails, error path releases dst twice, leading to a refcount underflow.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27403" target="_blank">CVE-2024-27403</a><br><a href="https://git.kernel.org/stable/c/012df10717da02367aaf92c65f9c89db206c15f4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4c167af9f6b5ae4a5dbc243d5983c295ccc2e43c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/558b00a30e05753a62ecc7e05e939ca8f0241148" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/670548c8db44d76e40e1dfc06812bca36a61e9ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9e0f0430389be7696396c62f037be4bf72cf93e3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data races on remote_id Similar to the previous patch, address the data race on remote_id, adding the suitable ONCE annotations.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27404" target="_blank">CVE-2024-27404</a><br><a href="https://git.kernel.org/stable/c/2dba5774e8ed326a78ad4339d921a4291281ea6e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/967d3c27127e71a10ff5c083583a038606431b61" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/987c3ed7297e5661bc7f448f06fc366e497ac9b2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e64148635509bf13eea851986f5a0b150e5bd066" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: gadget: ncm: Avoid dropping datagrams of properly parsed NTBs It is observed sometimes when tethering is used over NCM with Windows 11 as host, at some instances, the gadget_giveback has one byte appended at the end of a proper NTB. When the NTB is parsed, unwrap call looks for any leftover bytes in SKB provided by u_ether and if there are any pending bytes, it treats them as a separate NTB and parses it. But in case the second NTB (as per unwrap call) is faulty/corrupt, all the datagrams that were parsed properly in the first NTB and saved in rx_list are dropped. Adding a few custom traces showed the following: [002] d..1 7828.532866: dwc3_gadget_giveback: ep1out: req 000000003868811a length 1025/16384 zsI ==&gt; 0 [002] d..1 7828.532867: ncm_unwrap_ntb: K: ncm_unwrap_ntb toprocess: 1025 [002] d..1 7828.532867: ncm_unwrap_ntb: K: ncm_unwrap_ntb nth: 1751999342 [002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb seq: 0xce67 [002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb blk_len: 0x400 [002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb ndp_len: 0x10 [002] d..1 7828.532869: ncm_unwrap_ntb: K: Parsed NTB with 1 frames In this case, the giveback is of 1025 bytes and block length is 1024. The rest 1 byte (which is 0x00) won't be parsed resulting in drop of all datagrams in rx_list. Same is case with packets of size 2048: [002] d..1 7828.557948: dwc3_gadget_giveback: ep1out: req 0000000011dfd96e length 2049/16384 zsI ==&gt; 0 [002] d..1 7828.557949: ncm_unwrap_ntb: K: ncm_unwrap_ntb nth: 1751999342 [002] d..1 7828.557950: ncm_unwrap_ntb: K: ncm_unwrap_ntb blk_len: 0x800 Lecroy shows one byte coming in extra confirming that the byte is coming in from PC: Transfer 2959 - Bytes Transferred(1025) Timestamp((18.524 843 590) - Transaction 8391 - Data(1025 bytes) Timestamp(18.524 843 590) --- Packet 4063861 Data(1024 bytes) Duration(2.117us) Idle(14.700ns) Timestamp(18.524 843 590) --- Packet 4063863 Data(1 byte) Duration(66.160ns) Time(282.000ns) Timestamp(18.524 845 722) According to Windows driver, no ZLP is needed if wBlockLength is non-zero, because the non-zero wBlockLength has already told the function side the size of transfer to be expected. However, there are in-market NCM devices that rely on ZLP as long as the wBlockLength is multiple of wMaxPacketSize. To deal with such devices, it pads an extra 0 at end so the transfer is no longer multiple of wMaxPacketSize.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27405" target="_blank">CVE-2024-27405</a><br><a href="https://git.kernel.org/stable/c/059285e04ebb273d32323fbad5431c5b94f77e48" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2b7ec68869d50ea998908af43b643bca7e54577e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2cb66b62a5d64ccf09b0591ab86fb085fa491fc5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/35b604a37ec70d68b19dafd10bbacf1db505c9ca" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/57ca0e16f393bb21d69734e536e383a3a4c665fd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/76c51146820c5dac629f21deafab0a7039bc3ccd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a31cf46d108dabce3df80b3e5c07661e24912151" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c7f43900bc723203d7554d299a2ce844054fab8e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: lib/Kconfig.debug: TEST_IOV_ITER depends on MMU Trying to run the iov_iter unit test on a nommu system such as the qemu kc705-nommu emulation results in a crash. KTAP version 1 # Subtest: iov_iter # module: kunit_iov_iter 1..9 BUG: failure at mm/nommu.c:318/vmap()! Kernel panic - not syncing: BUG! The test calls vmap() directly, but vmap() is not supported on nommu systems, causing the crash. TEST_IOV_ITER therefore needs to depend on MMU.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27406" target="_blank">CVE-2024-27406</a><br><a href="https://git.kernel.org/stable/c/1eb1e984379e2da04361763f66eec90dd75cf63e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9e6e541b97762d5b1143070067f7c68f39a408f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e6316749d603fe9c4c91f6ec3694e06e4de632a3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fixed overflow check in mi_enum_attr()</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27407" target="_blank">CVE-2024-27407</a><br><a href="https://git.kernel.org/stable/c/1c0a95d99b1b2b5d842e5abc7ef7eed1193b60d7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/652cfeb43d6b9aba5c7c4902bed7a7340df131fb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8c77398c72618101d66480b94b34fe9087ee3d08" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup The Linked list element and pointer are not stored in the same memory as the eDMA controller register. If the doorbell register is toggled before the full write of the linked list a race condition error will occur. In remote setup we can only use a readl to the memory to assure the full write has occurred.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27408" target="_blank">CVE-2024-27408</a><br><a href="https://git.kernel.org/stable/c/bbcc1c83f343e580c3aa1f2a8593343bf7b55bba" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d24fe6d5a1cfdddb7a9ef56736ec501c4d0a5fd3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f396b4df27cfe01a99f4b41f584c49e56477be3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: HDMA: Add sync read before starting the DMA transfer in remote setup The Linked list element and pointer are not stored in the same memory as the HDMA controller register. If the doorbell register is toggled before the full write of the linked list a race condition error will occur. In remote setup we can only use a readl to the memory to assure the full write has occurred.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27409" target="_blank">CVE-2024-27409</a><br><a href="https://git.kernel.org/stable/c/17be6f5cb223f22e4733ed8fe8b2247cbb677716" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/227ef58a9b0c372efba422e8886a8015a1509eba" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/712a92a48158e02155b4b6b21e03a817f78c9b7e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject iftype change with mesh ID change It's currently possible to change the mesh ID when the interface isn't yet in mesh mode, at the same time as changing it into mesh mode. This leads to an overwrite of data in the wdev-&gt;u union for the interface type it currently has, causing cfg80211_change_iface() to do wrong things when switching. We could probably allow setting an interface to mesh while setting the mesh ID at the same time by doing a different order of operations here, but realistically there's no userspace that's going to do this, so just disallow changes in iftype when setting mesh ID.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27410" target="_blank">CVE-2024-27410</a><br><a href="https://git.kernel.org/stable/c/063715c33b4c37587aeca2c83cf08ead0c542995" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0cfbb26ee5e7b3d6483a73883f9f6157bca22ec9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/177d574be4b58f832354ab1ef5a297aa0c9aa2df" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/930e826962d9f01dcd2220176134427358d112f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/99eb2159680af8786104dac80528acd5acd45980" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a2add961a5ed25cfd6a74f9ffb9e7ab6d6ded838" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d38d31bbbb9dc0d4d71a45431eafba03d0bc150d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f78c1375339a291cba492a70eaf12ec501d28a8e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: keep DMA buffers required for suspend/resume Nouveau deallocates a few buffers post GPU init which are required for GPU suspend/resume to function correctly. This is likely not as big an issue on systems where the NVGPU is the only GPU, but on multi-GPU set ups it leads to a regression where the kernel module errors and results in a system-wide rendering freeze. This commit addresses that regression by moving the two buffers required for suspend and resume to be deallocated at driver unload instead of post init.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27411" target="_blank">CVE-2024-27411</a><br><a href="https://git.kernel.org/stable/c/be00e15b240ed71fc30c0576af7ab670c8271661" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6ecfdad359a01c7fd8a3bcfde3ef0acdf107e6e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: power: supply: bq27xxx-i2c: Do not free non existing IRQ The bq27xxx i2c-client may not have an IRQ, in which case client-&gt;irq will be 0. bq27xxx_battery_i2c_probe() already has an if (client-&gt;irq) check wrapping the request_threaded_irq(). But bq27xxx_battery_i2c_remove() unconditionally calls free_irq(client-&gt;irq) leading to: [ 190.310742] ------------[ cut here ]------------ [ 190.310843] Trying to free already-free IRQ 0 [ 190.310861] WARNING: CPU: 2 PID: 1304 at kernel/irq/manage.c:1893 free_irq+0x1b8/0x310 Followed by a backtrace when unbinding the driver. Add an if (client-&gt;irq) to bq27xxx_battery_i2c_remove() mirroring probe() to fix this.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27412" target="_blank">CVE-2024-27412</a><br><a href="https://git.kernel.org/stable/c/083686474e7c97b0f8b66df37fcb64e432e8b771" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2df70149e73e79783bcbc7db4fa51ecef0e2022c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7394abc8926adee6a817bab10797e0adc898af77" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cefe18e9ec84f8fe3e198ccebb815cc996eb9797" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d4d813c0a14d6bf52d810a55db06a2e7e3d98eaa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d7acc4a569f5f4513120c85ea2b9f04909b7490f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e601ae81910ce6a3797876e190a2d8ef6cf828bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fbca8bae1ba79d443a58781b45e92a73a24ac8f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect allocation size gcc-14 notices that the allocation with sizeof(void) on 32-bit architectures is not enough for a 64-bit phys_addr_t: drivers/firmware/efi/capsule-loader.c: In function 'efi_capsule_open': drivers/firmware/efi/capsule-loader.c:295:24: error: allocation of insufficient size '4' for type 'phys_addr_t' {aka 'long long unsigned int'} with size '8' [-Werror=alloc-size] 295 | cap_info-&gt;phys = kzalloc(sizeof(void *), GFP_KERNEL); | ^ Use the correct type instead here.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27413" target="_blank">CVE-2024-27413</a><br><a href="https://git.kernel.org/stable/c/00cf21ac526011a29fc708f8912da446fac19f7b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/11aabd7487857b8e7d768fefb092f66dfde68492" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4b73473c050a612fb4317831371073eda07c3050" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/537e3f49dbe88881a6f0752beaa596942d9efd64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62a5dcd9bd3097e9813de62fa6f22815e84a0172" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/950d4d74d311a18baed6878dbfba8180d7e5dddd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ddc547dd05a46720866c32022300f7376c40119f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fccfa646ef3628097d59f7d9c1a3e84d4b6bb45e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: rtnetlink: fix error logic of IFLA_BRIDGE_FLAGS writing back In the commit d73ef2d69c0d ("rtnetlink: let rtnl_bridge_setlink checks IFLA_BRIDGE_MODE length"), an adjustment was made to the old loop logic in the function `rtnl_bridge_setlink` to enable the loop to also check the length of the IFLA_BRIDGE_MODE attribute. However, this adjustment removed the `break` statement and led to an error logic of the flags writing back at the end of this function. if (have_flags) memcpy(nla_data(attr), &amp;flags, sizeof(flags)); // attr should point to IFLA_BRIDGE_FLAGS NLA !!! Before the mentioned commit, the `attr` is granted to be IFLA_BRIDGE_FLAGS. However, this is not necessarily true fow now as the updated loop will let the attr point to the last NLA, even an invalid NLA which could cause overflow writes. This patch introduces a new variable `br_flag` to save the NLA pointer that points to IFLA_BRIDGE_FLAGS and uses it to resolve the mentioned error logic.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27414" target="_blank">CVE-2024-27414</a><br><a href="https://git.kernel.org/stable/c/167d8642daa6a44b51de17f8ff0f584e1e762db7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/743ad091fb46e622f1b690385bb15e3cd3daf874" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/831bc2728fb48a8957a824cba8c264b30dca1425" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/882a51a10ecf24ce135d573afa0872aef02c5125" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a1227b27fcccc99dc44f912b479e01a17e2d7d31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9fbc44159dfc3e9a7073032752d9e03f5194a6f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2261eb994aa5757c1da046b78e3229a3ece0ad9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: confirm multicast packets before passing them up the stack conntrack nf_confirm logic cannot handle cloned skbs referencing the same nf_conn entry, which will happen for multicast (broadcast) frames on bridges. Example: macvlan0 | br0 / \ ethX ethY ethX (or Y) receives a L2 multicast or broadcast packet containing an IP packet, flow is not yet in conntrack table. 1. skb passes through bridge and fake-ip (br_netfilter)Prerouting. -&gt; skb-&gt;_nfct now references a unconfirmed entry 2. skb is broad/mcast packet. bridge now passes clones out on each bridge interface. 3. skb gets passed up the stack. 4. In macvlan case, macvlan driver retains clone(s) of the mcast skb and schedules a work queue to send them out on the lower devices. The clone skb-&gt;_nfct is not a copy, it is the same entry as the original skb. The macvlan rx handler then returns RX_HANDLER_PASS. 5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb. The Macvlan broadcast worker and normal confirm path will race. This race will not happen if step 2 already confirmed a clone. In that case later steps perform skb_clone() with skb-&gt;_nfct already confirmed (in hash table). This works fine. But such confirmation won't happen when eb/ip/nftables rules dropped the packets before they reached the nf_confirm step in postrouting. Pablo points out that nf_conntrack_bridge doesn't allow use of stateful nat, so we can safely discard the nf_conn entry and let inet call conntrack again. This doesn't work for bridge netfilter: skb could have a nat transformation. Also bridge nf prevents re-invocation of inet prerouting via 'sabotage_in' hook. Work around this problem by explicit confirmation of the entry at LOCAL_IN time, before upper layer has a chance to clone the unconfirmed entry. The downside is that this disables NAT and conntrack helpers. Alternative fix would be to add locking to all code parts that deal with unconfirmed packets, but even if that could be done in a sane way this opens up other problems, for example: -m physdev --physdev-out eth0 -j SNAT --snat-to 1.2.3.4 -m physdev --physdev-out eth1 -j SNAT --snat-to 1.2.3.5 For multicast case, only one of such conflicting mappings will be created, conntrack only handles 1:1 NAT mappings. Users should set create a setup that explicitly marks such traffic NOTRACK (conntrack bypass) to avoid this, but we cannot auto-bypass them, ruleset might have accept rules for untracked traffic already, so user-visible behaviour would change.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27415" target="_blank">CVE-2024-27415</a><br><a href="https://git.kernel.org/stable/c/2b1414d5e94e477edff1d2c79030f1d742625ea0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62e7151ae3eb465e0ab52a20c941ff33bb6332e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7c3f28599652acf431a2211168de4a583f30b6d5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/80cd0487f630b5382734997c3e5e3003a77db315" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cb734975b0ffa688ff6cc0eed463865bf07b6c01" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27416" target="_blank">CVE-2024-27416</a><br><a href="https://git.kernel.org/stable/c/30a5e812f78e3d1cced90e1ed750bf027599205f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/79820a7e1e057120c49be07cbe10643d0706b259" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e74aa53a68bf60f6019bd5d9a9a1406ec4d4865" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e2758cc25891d2b76717aaf89b40ed215de188c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/afec8f772296dd8e5a2a6f83bbf99db1b9ca877f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c3df637266df29edee85e94cab5fd7041e5753ba" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/df193568d61234c81de7ed4d540c01975de60277" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fba268ac36ab19f9763ff90d276cde0ce6cd5f31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ipv6: fix potential "struct net" leak in inet6_rtm_getaddr() It seems that if userspace provides a correct IFA_TARGET_NETNSID value but no IFA_ADDRESS and IFA_LOCAL attributes, inet6_rtm_getaddr() returns -EINVAL with an elevated "struct net" refcount.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27417" target="_blank">CVE-2024-27417</a><br><a href="https://git.kernel.org/stable/c/10bfd453da64a057bcfd1a49fb6b271c48653cdb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1b0998fdd85776775d975d0024bca227597e836a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/33a1b6bfef6def2068c8703403759024ce17053e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/44112bc5c74e64f28f5a9127dc34066c7a09bd0f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/810fa7d5e5202fcfb22720304b755f1bdfd4c174" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8a54834c03c30e549c33d5da0975f3e1454ec906" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d4ffb5b9d879a75e4f7460e8b10e756b4dfb132" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: mctp: take ownership of skb in mctp_local_output Currently, mctp_local_output only takes ownership of skb on success, and we may leak an skb if mctp_local_output fails in specific states; the skb ownership isn't transferred until the actual output routing occurs. Instead, make mctp_local_output free the skb on all error paths up to the route action, so it always consumes the passed skb.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27418" target="_blank">CVE-2024-27418</a><br><a href="https://git.kernel.org/stable/c/3773d65ae5154ed7df404b050fd7387a36ab5ef3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a3c8fa54e904b0ddb52a08cc2d8ac239054f61fd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a639441c880ac479495e5ab37e3c29f21ae5771b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cbebc55ceacef1fc0651e80e0103cc184552fc68" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around sysctl_net_busy_read We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27419" target="_blank">CVE-2024-27419</a><br><a href="https://git.kernel.org/stable/c/0866afaff19d8460308b022345ed116a12b1d0e1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/16d71319e29d5825ab53f263b59fdd8dc2d60ad4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/34cab94f7473e7b09f5205d4583fb5096cb63b5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/43464808669ba9d23996f0b6d875450191687caf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bbf950a6e96a91cf8cf0c71117b94ed3fafc9dd3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d380ce70058a4ccddc3e5f5c2063165dc07672c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d623fd5298d95b65d27ef5a618ebf39541074856" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f9055fa2b2931261d5f89948ee5bc315b6a22d4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_link_fails_count We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27420" target="_blank">CVE-2024-27420</a><br><a href="https://git.kernel.org/stable/c/07bbccd1adb56b39eef982b8960d59e3c005c6a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0b8eb369c182814d817b9449bc9e86bfae4310f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/97a4d8b9f67cc7efe9a0c137e12f6d9e40795bf1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bc76645ebdd01be9b9994dac39685a3d0f6f7985" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c558e54f7712b086fbcb611723272a0a4b0d451c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfe0f73fb38a01bce86fe15ef5f750f850f7d3fe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfedde3058bf976f2f292c0a236edd43afcdab57" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/db364859ce68fb3a52d42cd87a54da3dc42dc1c8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_routing_control We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27421" target="_blank">CVE-2024-27421</a><br><a href="https://git.kernel.org/stable/c/4c02b9ccbb11862ee39850b2b285664cd579b039" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/859175d4bc11af829e2fdd261a7effdaba9b5d8f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b5dffcb8f71bdd02a4e5799985b51b12f4eeaf76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b7d33e083f9d5d39445c0a91e7ad4f3e2c47fcb5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c13fbb5902bce848759385986d4833f5b90782c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c4309e5f8e80584715c814e1d012dbc3eee5a500" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d732b83251322ecd3b503e03442247745d6052ce" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f9c4d42464173b826190fae2283ed1a4bbae0c8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27422" target="_blank">CVE-2024-27422</a><br><a href="https://git.kernel.org/stable/c/01d4e3afe257768cd2a45f15a0e57bacf932b140" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2309b369fae2d9cdc3c945cd3eaec84eb1958ca3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/498f1d6da11ed6d736d655a2db14ee2d9569eecb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4eacb242e22e31385a50a393681d0fe4b55ed1e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6f254abae02abd4a0aca062c1b3812d7e2d8ea94" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/73426c32e259c767d40613b956d5b80d0c28a9a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cbba77abb4a553c1f5afac1ba2a0861aa1f13549" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f99b494b40431f0ca416859f2345746199398e2b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27423" target="_blank">CVE-2024-27423</a><br><a href="https://git.kernel.org/stable/c/0d43a58900e5a2bfcc9de47e16c6c501c0bef853" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/46803b776d869b0c36041828a83c4f7da2dfa03b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/489e05c614dbeb1a1148959f02bdb788891819e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4f2efa17c3ec5e4be0567b47439b9713c0dc6550" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/652b0b35819610a42b8a90d21acb12f69943b397" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/89aa78a34340e9dbc3248095f44d81d0e1c23193" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a2e706841488f474c06e9b33f71afc947fb3bf56" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/db006d7edbf0b4800390ece3727a82f4ae764043" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_busy_delay We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27424" target="_blank">CVE-2024-27424</a><br><a href="https://git.kernel.org/stable/c/0a30016e892bccabea30af218782c4b6ce0970af" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1f60795dcafc97c45984240d442cdc151f825977" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/43547d8699439a67b78d6bb39015113f7aa360fd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ccad39009e7bd8a03d60a97c87b0327ae812880" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5ac337138272d26d6d3d4f71bc5b1a87adf8b24d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7782e5e7047cae6b9255ee727c99fc73d77cf773" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/85f34d352f4b79afd63dd13634b23dafe6b570f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f3315a6edaec12b461031eab8c98c78111a41f95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_acknowledge_delay We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27425" target="_blank">CVE-2024-27425</a><br><a href="https://git.kernel.org/stable/c/33081e0f34899d5325e7c45683dd8dc9cb18b583" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/34c84e0036a60e7e50ae50b42ed194d8daef8cc9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5deaef2bf56456c71b841e0dfde1bee2fd88c4eb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6133a71c75dacea12fcc85838b4455c2055b0f14" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d56ffc51ebd2777ded8dca50d631ee19d97db5c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/80578681ea274e0a6512bb7515718c206a7b74cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/806f462ba9029d41aadf8ec93f2f99c5305deada" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a22f9194f61ad4f2b6405c7c86bee85eac1befa5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_maximum_tries We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27426" target="_blank">CVE-2024-27426</a><br><a href="https://git.kernel.org/stable/c/34a164d2448264b62af82bc0af3d2c83d12d38ac" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/42e71408e2c138be9ccce60920bd6cf094ba1e32" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/84b8486e9cedc93875f251ba31abcf73bd586a3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d28fa5f0e6c1554e2829f73a6a276c9a49689d04" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e799299aafed417cc1f32adccb2a0e5268b3f6d5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f716a68234242f95305dffb5c9426caa64b316b0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f84f7709486d8a578ab4b7d2a556d1b1a59cfc97" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa3f3ab5c399852d32a0c3cbb8c55882f7e2c61f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27427" target="_blank">CVE-2024-27427</a><br><a href="https://git.kernel.org/stable/c/291d36d772f5ea5c68a263ee440f2c9eade371c9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/500936692ccca8617a955652d1929f079b17a201" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5d5c14efc987900509cec465af26608e39ac607c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/60a7a152abd494ed4f69098cf0f322e6bb140612" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d1e00fc2af3b7c30835d643a3655b7e9ff7cb20" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b8006cb0a34aaf85cdd8741f4148fd9c76b351d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eadec8da4451c2c0897199691184602e4ee497d1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fed835d415766a94fc0246dcebc3af4c03fe9941" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around sysctl_netrom_network_ttl_initialiser We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27428" target="_blank">CVE-2024-27428</a><br><a href="https://git.kernel.org/stable/c/119cae5ea3f9e35cdada8e572cc067f072fa825a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5731369af2de21695fe7c1c91fe134fabe5b33b8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/775ed3549819f814a6ecef5726d2b4c23f249b77" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a47d68d777b41862757b7e3051f2d46d6e25f87b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/acc653e8a3aaab1b7103f98645f2cce7be89e3d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1261bde59a3a087ab0c81181821e194278d9264" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dca1d93fe42fb9c42b66f61714fbdc55c87eb002" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eda02a0bed550f07a8283d3e1f25b90a38e151ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27429" target="_blank">CVE-2024-27429</a><br><a href="https://git.kernel.org/stable/c/18c95d11c347a12e5c31df1325cef6b995d14ecf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1e84b108f2a71daa8d04032e4d2096522376debb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/591192c3a9fc728a0af7b9dd50bf121220062293" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e1e25891f090e24a871451c9403abac63cb45dd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b3f0bc3a315cf1af03673a0163c08fe037587acd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfd9f4a740f772298308b2e6070d2c744fb5cf79" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e3a3718b1723253d4f068e88e81d880d71f1a1e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e439607291c082332e1e35baf8faf8552e6bcb4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_default_path_quality We need to protect the reader reading sysctl_netrom_default_path_quality because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27430" target="_blank">CVE-2024-27430</a><br><a href="https://git.kernel.org/stable/c/392eb88416dcbc5f1d61b9a88d79d78dc8b27652" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7510b08c5f5ba15983da004b021fc6154eeb4047" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7644df766006d4878a556e427e3ecc78c2d5606b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7f615232556f3c6e3eeecef96ef2b00d0aa905bb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/958d6145a6d9ba9e075c921aead8753fb91c9101" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bbc21f134b89535d1cf110c5f2b33ac54e5839c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dec82a8fc45c6ce494c2cb31f001a2aadb132b57" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e041df5dc9e68adffcba5499ca28e1252bed6f4b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: cpumap: Zero-initialise xdp_rxq_info struct before running XDP program When running an XDP program that is attached to a cpumap entry, we don't initialise the xdp_rxq_info data structure being used in the xdp_buff that backs the XDP program invocation. Tobias noticed that this leads to random values being returned as the xdp_md-&gt;rx_queue_index value for XDP programs running in a cpumap. This means we're basically returning the contents of the uninitialised memory, which is bad. Fix this by zero-initialising the rxq data structure before running the XDP program.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27431" target="_blank">CVE-2024-27431</a><br><a href="https://git.kernel.org/stable/c/2487007aa3b9fafbd2cb14068f49791ce1d7ede5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3420b3ff1ff489c177ea1cb7bd9fbbc4e9a0be95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5f4e51abfbe6eb444fa91906a5cd083044278297" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eaa7cb836659ced2d9f814ac32aa3ec193803ed6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f0363af9619c77730764f10360e36c6445c12f7b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f562e4c4aab00986dde3093c4be919c3f2b85a4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix PPE hanging issue A patch to resolve an issue was found in MediaTek's GPL-licensed SDK: In the mtk_ppe_stop() function, the PPE scan mode is not disabled before disabling the PPE. This can potentially lead to a hang during the process of disabling the PPE. Without this patch, the PPE may experience a hang during the reboot test.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27432" target="_blank">CVE-2024-27432</a><br><a href="https://git.kernel.org/stable/c/09a1907433865b7c8ee6777e507f5126bdd38c0f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/49202a8256fc50517ef06fd5e2084c4febde6369" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/943c14ece95eb1cf98d477462aebcbfdfd714633" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9fcadd125044007351905d40c405fadc2d3bb6d6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea80e3ed09ab2c2b75724faf5484721753e92c31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f78807362828ad01db2a9ed005bf79501b620f27" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: mt7622-apmixedsys: Fix an error handling path in clk_mt8135_apmixed_probe() 'clk_data' is allocated with mtk_devm_alloc_clk_data(). So calling mtk_free_clk_data() explicitly in the remove function would lead to a double-free. Remove the redundant call.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27433" target="_blank">CVE-2024-27433</a><br><a href="https://git.kernel.org/stable/c/a32e88f2b20259f5fe4f8eed598bbc85dc4879ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/de3340533bd68a7b3d6be1841b8eb3fa6c762fe6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f3633fed984f1db106ff737a0bb52fadb2d89ac7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa761ce7a1d15cca1a306b3635f81a22b15fee5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't set the MFP flag for the GTK The firmware doesn't need the MFP flag for the GTK, it can even make the firmware crash. in case the AP is configured with: group cipher TKIP and MFPC. We would send the GTK with cipher = TKIP and MFP which is of course not possible.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27434" target="_blank">CVE-2024-27434</a><br><a href="https://git.kernel.org/stable/c/40405cbb20eb6541c603e7b3d54ade0a7be9d715" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/60f6d5fc84a9fd26528a24d8a267fc6a6698b628" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e35f316bce9e5733c9826120c1838f4c447b2c4c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvme: fix reconnection fail due to reserved tag allocation We found a issue on production environment while using NVMe over RDMA, admin_q reconnect failed forever while remote target and network is ok. After dig into it, we found it may caused by a ABBA deadlock due to tag allocation. In my case, the tag was hold by a keep alive request waiting inside admin_q, as we quiesced admin_q while reset ctrl, so the request maked as idle and will not process before reset success. As fabric_q shares tagset with admin_q, while reconnect remote target, we need a tag for connect command, but the only one reserved tag was held by keep alive command which waiting inside admin_q. As a result, we failed to reconnect admin_q forever. In order to fix this issue, I think we should keep two reserved tags for admin queue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27435" target="_blank">CVE-2024-27435</a><br><a href="https://git.kernel.org/stable/c/149afee5c7418ec5db9d7387b9c9a5c1eb7ea2a8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/262da920896e2f2ab0e3947d9dbee0aa09045818" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6851778504cdb49431809b4ba061903d5f592c96" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/de105068fead55ed5c07ade75e9c8e7f86a00d1d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ff2f90f88d78559802466ad1c84ac5bda4416b3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Stop parsing channels bits when all channels are found. If a usb audio device sets more bits than the amount of channels it could write outside of the map array.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27436" target="_blank">CVE-2024-27436</a><br><a href="https://git.kernel.org/stable/c/22cad1b841a63635a38273b799b4791f202ade72" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5cd466673b34bac369334f66cbe14bb77b7d7827" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/629af0d5fe94a35f498ba2c3f19bd78bfa591be6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d5dc96b154be371df0d62ecb07efe400701ed8a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d88b289fb0a8d055cb79d1c46a56aba7809d96d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e2c1b0f6dd9abde9e60f0f9730026714468770f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9af1658ba293458ca6a13f70637b9654fa4be064" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a39d51ff1f52cd0b6fe7d379ac93bd8b4237d1b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c8a24fd281dcdf3c926413dafbafcf35cde517a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock with fiemap and extent locking While working on the patchset to remove extent locking I got a lockdep splat with fiemap and pagefaulting with my new extent lock replacement lock. This deadlock exists with our normal code, we just don't have lockdep annotations with the extent locking so we've never noticed it. Since we're copying the fiemap extent to user space on every iteration we have the chance of pagefaulting. Because we hold the extent lock for the entire range we could mkwrite into a range in the file that we have mmap'ed. This would deadlock with the following stack trace [&lt;0&gt;] lock_extent+0x28d/0x2f0 [&lt;0&gt;] btrfs_page_mkwrite+0x273/0x8a0 [&lt;0&gt;] do_page_mkwrite+0x50/0xb0 [&lt;0&gt;] do_fault+0xc1/0x7b0 [&lt;0&gt;] __handle_mm_fault+0x2fa/0x460 [&lt;0&gt;] handle_mm_fault+0xa4/0x330 [&lt;0&gt;] do_user_addr_fault+0x1f4/0x800 [&lt;0&gt;] exc_page_fault+0x7c/0x1e0 [&lt;0&gt;] asm_exc_page_fault+0x26/0x30 [&lt;0&gt;] rep_movs_alternative+0x33/0x70 [&lt;0&gt;] _copy_to_user+0x49/0x70 [&lt;0&gt;] fiemap_fill_next_extent+0xc8/0x120 [&lt;0&gt;] emit_fiemap_extent+0x4d/0xa0 [&lt;0&gt;] extent_fiemap+0x7f8/0xad0 [&lt;0&gt;] btrfs_fiemap+0x49/0x80 [&lt;0&gt;] __x64_sys_ioctl+0x3e1/0xb50 [&lt;0&gt;] do_syscall_64+0x94/0x1a0 [&lt;0&gt;] entry_SYSCALL_64_after_hwframe+0x6e/0x76 I wrote an fstest to reproduce this deadlock without my replacement lock and verified that the deadlock exists with our existing locking. To fix this simply don't take the extent lock for the entire duration of the fiemap. This is safe in general because we keep track of where we are when we're searching the tree, so if an ordered extent updates in the middle of our fiemap call we'll still emit the correct extents because we know what offset we were on before. The only place we maintain the lock is searching delalloc. Since the delalloc stuff can change during writeback we want to lock the extent range so we have a consistent view of delalloc at the time we're checking to see if we need to set the delalloc flag. With this patch applied we no longer deadlock with my testcase.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35784" target="_blank">CVE-2024-35784</a><br><a href="https://git.kernel.org/stable/c/89bca7fe6382d61e88c67a0b0e7bce315986fb8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b0ad381fa7690244802aed119b478b4bdafc31dd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ded566b4637f1b6b4c9ba74e7d0b8493e93f19cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix kernel panic caused by incorrect error handling The error path while failing to register devices on the TEE bus has a bug leading to kernel panic as follows: [ 15.398930] Unable to handle kernel paging request at virtual address ffff07ed00626d7c [ 15.406913] Mem abort info: [ 15.409722] ESR = 0x0000000096000005 [ 15.413490] EC = 0x25: DABT (current EL), IL = 32 bits [ 15.418814] SET = 0, FnV = 0 [ 15.421878] EA = 0, S1PTW = 0 [ 15.425031] FSC = 0x05: level 1 translation fault [ 15.429922] Data abort info: [ 15.432813] ISV = 0, ISS = 0x00000005, ISS2 = 0x00000000 [ 15.438310] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 15.443372] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 15.448697] swapper pgtable: 4k pages, 48-bit VAs, pgdp=00000000d9e3e000 [ 15.455413] [ffff07ed00626d7c] pgd=1800000bffdf9003, p4d=1800000bffdf9003, pud=0000000000000000 [ 15.464146] Internal error: Oops: 0000000096000005 [#1] PREEMPT SMP Commit 7269cba53d90 ("tee: optee: Fix supplicant based device enumeration") lead to the introduction of this bug. So fix it appropriately.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35785" target="_blank">CVE-2024-35785</a><br><a href="https://git.kernel.org/stable/c/4b12ff5edd141926d49c9ace4791adf3a4902fe7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/520f79c110ff712b391b3d87fcacf03c74bc56ee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/95915ba4b987cf2b222b0f251280228a1ff977ac" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bc40ded92af55760d12bec8222d4108de725dbe4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bfa344afbe472a9be08f78551fa2190c1a07d7d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e5b5948c769aa1ebf962dddfb972f87d8f166f95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix stale locked mutex in nouveau_gem_ioctl_pushbuf If VM_BIND is enabled on the client the legacy submission ioctl can't be used, however if a client tries to do so regardless it will return an error. In this case the clients mutex remained unlocked leading to a deadlock inside nouveau_drm_postclose or any other nouveau ioctl call.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35786" target="_blank">CVE-2024-35786</a><br><a href="https://git.kernel.org/stable/c/b466416bdd6ecbde15ce987226ea633a0268fbb1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c288a61a48ddb77ec097e11ab81b81027cd4e197" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/daf8739c3322a762ce84f240f50e0c39181a41ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix incorrect usage for sb_index Commit d7038f951828 ("md-bitmap: don't use -&gt;index for pages backing the bitmap file") removed page-&gt;index from bitmap code, but left wrong code logic for clustered-md. current code never set slot offset for cluster nodes, will sometimes cause crash in clustered env. Call trace (partly): md_bitmap_file_set_bit+0x110/0x1d8 [md_mod] md_bitmap_startwrite+0x13c/0x240 [md_mod] raid1_make_request+0x6b0/0x1c08 [raid1] md_handle_request+0x1dc/0x368 [md_mod] md_submit_bio+0x80/0xf8 [md_mod] __submit_bio+0x178/0x300 submit_bio_noacct_nocheck+0x11c/0x338 submit_bio_noacct+0x134/0x614 submit_bio+0x28/0xdc submit_bh_wbc+0x130/0x1cc submit_bh+0x1c/0x28</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35787" target="_blank">CVE-2024-35787</a><br><a href="https://git.kernel.org/stable/c/55e55eb65fd5e09faf5a0e49ffcdd37905aaf4da" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5a95815b17428ce2f56ec18da5e0d1b2a1a15240" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/736ad6c577a367834118f57417038d45bb5e0a31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ecbd8ebb51bf7e4939d83b9e6022a55cac44ef06" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix bounds check for dcn35 DcfClocks [Why] NumFclkLevelsEnabled is used for DcfClocks bounds check instead of designated NumDcfClkLevelsEnabled. That can cause array index out-of-bounds access. [How] Use designated variable for dcn35 DcfClocks bounds check.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35788" target="_blank">CVE-2024-35788</a><br><a href="https://git.kernel.org/stable/c/2f10d4a51bbcd938f1f02f16c304ad1d54717b96" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c373f233dab44a13752daec13788e2ad3bf86410" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6e163e9c3d50cd167ab9d411ed01b7718177387" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes When moving a station out of a VLAN and deleting the VLAN afterwards, the fast_rx entry still holds a pointer to the VLAN's netdev, which can cause use-after-free bugs. Fix this by immediately calling ieee80211_check_fast_rx after the VLAN change.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35789" target="_blank">CVE-2024-35789</a><br><a href="https://git.kernel.org/stable/c/2884a50f52313a7a911de3afcad065ddbb3d78fc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4f2bdb3c5e3189297e156b3ff84b140423d64685" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6b948b54c8bd620725e0c906e44b10c0b13087a7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7eeabcea79b67cc29563e6a9a5c81f9e2c664d5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be1dd9254fc115321d6fbee042026d42afc8d931" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c8bddbd91bc8e42c961a5e2cec20ab879f21100f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8678551c0243f799b4859448781cbec1bd6f1cb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8b067c4058c0121ac8ca71559df8e2e08ff1a7e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea9a0cfc07a7d3601cc680718d9cff0d6927a921" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group The DisplayPort driver's sysfs nodes may be present to the userspace before typec_altmode_set_drvdata() completes in dp_altmode_probe. This means that a sysfs read can trigger a NULL pointer error by deferencing dp-&gt;hpd in hpd_show or dp-&gt;lock in pin_assignment_show, as dev_get_drvdata() returns NULL in those cases. Remove manual sysfs node creation in favor of adding attribute group as default for devices bound to the driver. The ATTRIBUTE_GROUPS() macro is not used here otherwise the path to the sysfs nodes is no longer compliant with the ABI.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35790" target="_blank">CVE-2024-35790</a><br><a href="https://git.kernel.org/stable/c/0ad011776c057ce881b7fd6d8c79ecd459c087e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/165376f6b23e9a779850e750fb2eb06622e5a531" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4a22aeac24d0d5f26ba741408e8b5a4be6dc5dc0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Flush pages under kvm-&gt;lock to fix UAF in svm_register_enc_region() Do the cache flush of converted pages in svm_register_enc_region() before dropping kvm-&gt;lock to fix use-after-free issues where region and/or its array of pages could be freed by a different task, e.g. if userspace has __unregister_enc_region_locked() already queued up for the region. Note, the "obvious" alternative of using local variables doesn't fully resolve the bug, as region-&gt;pages is also dynamically allocated. I.e. the region structure itself would be fine, but region-&gt;pages could be freed. Flushing multiple pages under kvm-&gt;lock is unfortunate, but the entire flow is a rare slow path, and the manual flush is only needed on CPUs that lack coherency for encrypted memory.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35791" target="_blank">CVE-2024-35791</a><br><a href="https://git.kernel.org/stable/c/12f8e32a5a389a5d58afc67728c76e61beee1ad4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2d13b79640b147bd77c34a5998533b2021a4122d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4868c0ecdb6cfde7c70cf478c46e06bb9c7e5865" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5ef1d8c1ddbf696e47b226e11888eaf8d9e8e807" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e126b508ed2e616d679d85fca2fbe77bb48bbdd7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6d53d8a2617dd58c89171a6b9610c470ebda38a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: crypto: rk3288 - Fix use after free in unprepare The unprepare call must be carried out before the finalize call as the latter can free the request.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35792" target="_blank">CVE-2024-35792</a><br><a href="https://git.kernel.org/stable/c/48dd260fdb728eda4a246f635d1325e82f0d3555" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c0afb6b88fbbc177fa322a835f874be217bffe45" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eb2a41a8ae8c8c4f68aef3bd94665c0cf23e04be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: debugfs: fix wait/cancellation handling during remove Ben Greear further reports deadlocks during concurrent debugfs remove while files are being accessed, even though the code in question now uses debugfs cancellations. Turns out that despite all the review on the locking, we missed completely that the logic is wrong: if the refcount hits zero we can finish (and need not wait for the completion), but if it doesn't we have to trigger all the cancellations. As written, we can _never_ get into the loop triggering the cancellations. Fix this, and explain it better while at it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35793" target="_blank">CVE-2024-35793</a><br><a href="https://git.kernel.org/stable/c/3d08cca5fd0aabb62b7015067ab40913b33da906" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/952c3fce297f12c7ff59380adb66b564e2bc9b64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e88b5ae01901c4a655a53158397746334778a57b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dm-raid: really frozen sync_thread during suspend 1) commit f52f5c71f3d4 ("md: fix stopping sync thread") remove MD_RECOVERY_FROZEN from __md_stop_writes() and doesn't realize that dm-raid relies on __md_stop_writes() to frozen sync_thread indirectly. Fix this problem by adding MD_RECOVERY_FROZEN in md_stop_writes(), and since stop_sync_thread() is only used for dm-raid in this case, also move stop_sync_thread() to md_stop_writes(). 2) The flag MD_RECOVERY_FROZEN doesn't mean that sync thread is frozen, it only prevent new sync_thread to start, and it can't stop the running sync thread; In order to frozen sync_thread, after seting the flag, stop_sync_thread() should be used. 3) The flag MD_RECOVERY_FROZEN doesn't mean that writes are stopped, use it as condition for md_stop_writes() in raid_postsuspend() doesn't look correct. Consider that reentrant stop_sync_thread() do nothing, always call md_stop_writes() in raid_postsuspend(). 4) raid_message can set/clear the flag MD_RECOVERY_FROZEN at anytime, and if MD_RECOVERY_FROZEN is cleared while the array is suspended, new sync_thread can start unexpected. Fix this by disallow raid_message() to change sync_thread status during suspend. Note that after commit f52f5c71f3d4 ("md: fix stopping sync thread"), the test shell/lvconvert-raid-reshape.sh start to hang in stop_sync_thread(), and with previous fixes, the test won't hang there anymore, however, the test will still fail and complain that ext4 is corrupted. And with this patch, the test won't hang due to stop_sync_thread() or fail due to ext4 is corrupted anymore. However, there is still a deadlock related to dm-raid456 that will be fixed in following patches.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35794" target="_blank">CVE-2024-35794</a><br><a href="https://git.kernel.org/stable/c/16c4770c75b1223998adbeb7286f9a15c65fba73" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/af916cb66a80597f3523bc85812e790bcdcfd62b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eaa8fc9b092837cf2c754bde1a15d784ce9a85ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix deadlock while reading mqd from debugfs An errant disk backup on my desktop got into debugfs and triggered the following deadlock scenario in the amdgpu debugfs files. The machine also hard-resets immediately after those lines are printed (although I wasn't able to reproduce that part when reading by hand): [ 1318.016074][ T1082] ====================================================== [ 1318.016607][ T1082] WARNING: possible circular locking dependency detected [ 1318.017107][ T1082] 6.8.0-rc7-00015-ge0c8221b72c0 #17 Not tainted [ 1318.017598][ T1082] ------------------------------------------------------ [ 1318.018096][ T1082] tar/1082 is trying to acquire lock: [ 1318.018585][ T1082] ffff98c44175d6a0 (&amp;mm-&gt;mmap_lock){++++}-{3:3}, at: __might_fault+0x40/0x80 [ 1318.019084][ T1082] [ 1318.019084][ T1082] but task is already holding lock: [ 1318.020052][ T1082] ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu] [ 1318.020607][ T1082] [ 1318.020607][ T1082] which lock already depends on the new lock. [ 1318.020607][ T1082] [ 1318.022081][ T1082] [ 1318.022081][ T1082] the existing dependency chain (in reverse order) is: [ 1318.023083][ T1082] [ 1318.023083][ T1082] -&gt; #2 (reservation_ww_class_mutex){+.+.}-{3:3}: [ 1318.024114][ T1082] __ww_mutex_lock.constprop.0+0xe0/0x12f0 [ 1318.024639][ T1082] ww_mutex_lock+0x32/0x90 [ 1318.025161][ T1082] dma_resv_lockdep+0x18a/0x330 [ 1318.025683][ T1082] do_one_initcall+0x6a/0x350 [ 1318.026210][ T1082] kernel_init_freeable+0x1a3/0x310 [ 1318.026728][ T1082] kernel_init+0x15/0x1a0 [ 1318.027242][ T1082] ret_from_fork+0x2c/0x40 [ 1318.027759][ T1082] ret_from_fork_asm+0x11/0x20 [ 1318.028281][ T1082] [ 1318.028281][ T1082] -&gt; #1 (reservation_ww_class_acquire){+.+.}-{0:0}: [ 1318.029297][ T1082] dma_resv_lockdep+0x16c/0x330 [ 1318.029790][ T1082] do_one_initcall+0x6a/0x350 [ 1318.030263][ T1082] kernel_init_freeable+0x1a3/0x310 [ 1318.030722][ T1082] kernel_init+0x15/0x1a0 [ 1318.031168][ T1082] ret_from_fork+0x2c/0x40 [ 1318.031598][ T1082] ret_from_fork_asm+0x11/0x20 [ 1318.032011][ T1082] [ 1318.032011][ T1082] -&gt; #0 (&amp;mm-&gt;mmap_lock){++++}-{3:3}: [ 1318.032778][ T1082] __lock_acquire+0x14bf/0x2680 [ 1318.033141][ T1082] lock_acquire+0xcd/0x2c0 [ 1318.033487][ T1082] __might_fault+0x58/0x80 [ 1318.033814][ T1082] amdgpu_debugfs_mqd_read+0x103/0x250 [amdgpu] [ 1318.034181][ T1082] full_proxy_read+0x55/0x80 [ 1318.034487][ T1082] vfs_read+0xa7/0x360 [ 1318.034788][ T1082] ksys_read+0x70/0xf0 [ 1318.035085][ T1082] do_syscall_64+0x94/0x180 [ 1318.035375][ T1082] entry_SYSCALL_64_after_hwframe+0x46/0x4e [ 1318.035664][ T1082] [ 1318.035664][ T1082] other info that might help us debug this: [ 1318.035664][ T1082] [ 1318.036487][ T1082] Chain exists of: [ 1318.036487][ T1082] &amp;mm-&gt;mmap_lock --&gt; reservation_ww_class_acquire --&gt; reservation_ww_class_mutex [ 1318.036487][ T1082] [ 1318.037310][ T1082] Possible unsafe locking scenario: [ 1318.037310][ T1082] [ 1318.037838][ T1082] CPU0 CPU1 [ 1318.038101][ T1082] ---- ---- [ 1318.038350][ T1082] lock(reservation_ww_class_mutex); [ 1318.038590][ T1082] lock(reservation_ww_class_acquire); [ 1318.038839][ T1082] lock(reservation_ww_class_mutex); [ 1318.039083][ T1082] rlock(&amp;mm-&gt;mmap_lock); [ 1318.039328][ T1082] [ 1318.039328][ T1082] *** DEADLOCK *** [ 1318.039328][ T1082] [ 1318.040029][ T1082] 1 lock held by tar/1082: [ 1318.040259][ T1082] #0: ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu] [ 1318.040560][ T1082] [ 1318.040560][ T1082] stack backtrace: [ ---truncated---</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35795" target="_blank">CVE-2024-35795</a><br><a href="https://git.kernel.org/stable/c/197f6d6987c55860f6eea1c93e4f800c59078874" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4687e3c6ee877ee25e57b984eca00be53b9a8db5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8678b1060ae2b75feb60b87e5b75e17374e3c1c5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8b03556da6e576c62664b6cd01809e4a09d53b5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: ll_temac: platform_get_resource replaced by wrong function The function platform_get_resource was replaced with devm_platform_ioremap_resource_byname and is called using 0 as name. This eventually ends up in platform_get_resource_byname in the call stack, where it causes a null pointer in strcmp. if (type == resource_type(r) &amp;&amp; !strcmp(r-&gt;name, name)) It should have been replaced with devm_platform_ioremap_resource.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35796" target="_blank">CVE-2024-35796</a><br><a href="https://git.kernel.org/stable/c/3a38a829c8bc27d78552c28e582eb1d885d07d11" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/46efbdbc95a30951c2579caf97b6df2ee2b3bef3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/476eed5f1c22034774902a980aa48dc4662cb39a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/553d294db94b5f139378022df480a9fb6c3ae39e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d9395ba7f85bdb7af0b93272e537484ecbeff48" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e9edb569fd9f688d887e36db8170f6e22bafbc8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92c0c29f667870f17c0b764544bdf22ce0e886a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and invalidation, there are two possible bugs: 1) A swapin error can have resulted in a poisoned swap entry in the shmem inode's xarray. Calling get_shadow_from_swap_cache() on it will result in an out-of-bounds access to swapper_spaces[]. Validate the entry with non_swap_entry() before going further. 2) When we find a valid swap entry in the shmem's inode, the shadow entry in the swapcache might not exist yet: swap IO is still in progress and we're before __remove_mapping; swapin, invalidation, or swapoff have removed the shadow from swapcache after we saw the shmem swap entry. This will send a NULL to workingset_test_recent(). The latter purely operates on pointer bits, so it won't crash - node 0, memcg ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a bogus test. In theory that could result in a false "recently evicted" count. Such a false positive wouldn't be the end of the world. But for code clarity and (future) robustness, be explicit about this case. Bail on get_shadow_from_swap_cache() returning NULL.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35797" target="_blank">CVE-2024-35797</a><br><a href="https://git.kernel.org/stable/c/24a0e73d544439bb9329fbbafac44299e548a677" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b79f9e1ff27c994a4c452235ba09e672ec698e23" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d5d39c707a4cf0bcc84680178677b97aa2cb2627" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d962f6c583458037dc7e529659b2b02b9dd3d94b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race in read_extent_buffer_pages() There are reports from tree-checker that detects corrupted nodes, without any obvious pattern so possibly an overwrite in memory. After some debugging it turns out there's a race when reading an extent buffer the uptodate status can be missed. To prevent concurrent reads for the same extent buffer, read_extent_buffer_pages() performs these checks: /* (1) */ if (test_bit(EXTENT_BUFFER_UPTODATE, &amp;eb-&gt;bflags)) return 0; /* (2) */ if (test_and_set_bit(EXTENT_BUFFER_READING, &amp;eb-&gt;bflags)) goto done; At this point, it seems safe to start the actual read operation. Once that completes, end_bbio_meta_read() does /* (3) */ set_extent_buffer_uptodate(eb); /* (4) */ clear_bit(EXTENT_BUFFER_READING, &amp;eb-&gt;bflags); Normally, this is enough to ensure only one read happens, and all other callers wait for it to finish before returning. Unfortunately, there is a racey interleaving: Thread A | Thread B | Thread C ---------+----------+--------- (1) | | | (1) | (2) | | (3) | | (4) | | | (2) | | | (1) When this happens, thread B kicks of an unnecessary read. Worse, thread C will see UPTODATE set and return immediately, while the read from thread B is still in progress. This race could result in tree-checker errors like this as the extent buffer is concurrently modified: BTRFS critical (device dm-0): corrupted node, root=256 block=8550954455682405139 owner mismatch, have 11858205567642294356 expect [256, 18446744073709551360] Fix it by testing UPTODATE again after setting the READING bit, and if it's been set, skip the unnecessary read. [ minor update of changelog ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35798" target="_blank">CVE-2024-35798</a><br><a href="https://git.kernel.org/stable/c/0427c8ef8bbb7f304de42ef51d69c960e165e052" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2885d54af2c2e1d910e20d5c8045bae40e02fbc1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3a25878a3378adce5d846300c9570f15aa7f7a80" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ef1e68236b9153c27cb7cf29ead0c532870d4215" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent crash when disable stream [Why] Disabling stream encoder invokes a function that no longer exists. [How] Check if the function declaration is NULL in disable stream encoder.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35799" target="_blank">CVE-2024-35799</a><br><a href="https://git.kernel.org/stable/c/2b17133a0a2e0e111803124dad09e803718d4a48" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4356a2c3f296503c8b420ae8adece053960a9f06" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/59772327d439874095516673b4b30c48bd83ca38" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72d72e8fddbcd6c98e1b02d32cf6f2b04e10bd1c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: efi: fix panic in kdump kernel Check if get_next_variable() is actually valid pointer before calling it. In kdump kernel this method is set to NULL that causes panic during the kexec-ed kernel boot. Tested with QEMU and OVMF firmware.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35800" target="_blank">CVE-2024-35800</a><br><a href="https://git.kernel.org/stable/c/090d2b4515ade379cd592fbc8931344945978210" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62b71cd73d41ddac6b1760402bbe8c4932e23531" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7784135f134c13af17d9ffb39a57db8500bc60ff" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9114ba9987506bcfbb454f6e68558d68cb1abbde" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9d103aca85f082a343b222493f3cab1219aaaf4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Keep xfd_state in sync with MSR_IA32_XFD Commit 672365477ae8 ("x86/fpu: Update XFD state where required") and commit 8bf26758ca96 ("x86/fpu: Add XFD state to fpstate") introduced a per CPU variable xfd_state to keep the MSR_IA32_XFD value cached, in order to avoid unnecessary writes to the MSR. On CPU hotplug MSR_IA32_XFD is reset to the init_fpstate.xfd, which wipes out any stale state. But the per CPU cached xfd value is not reset, which brings them out of sync. As a consequence a subsequent xfd_update_state() might fail to update the MSR which in turn can result in XRSTOR raising a #NM in kernel space, which crashes the kernel. To fix this, introduce xfd_set_state() to write xfd_state together with MSR_IA32_XFD, and use it in all places that set MSR_IA32_XFD.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35801" target="_blank">CVE-2024-35801</a><br><a href="https://git.kernel.org/stable/c/10e4b5166df9ff7a2d5316138ca668b42d004422" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1acbca933313aa866e39996904c9aca4d435c4cd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/21c7c00dae55cb0e3810d5f9506b58f68475d41d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92b0f04e937665bde5768f3fcc622dcce44413d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b61e3b7055ac6edee4be071c52f48c26472d2624" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/sev: Fix position dependent variable references in startup code The early startup code executes from a 1:1 mapping of memory, which differs from the mapping that the code was linked and/or relocated to run at. The latter mapping is not active yet at this point, and so symbol references that rely on it will fault. Given that the core kernel is built without -fPIC, symbol references are typically emitted as absolute, and so any such references occuring in the early startup code will therefore crash the kernel. While an attempt was made to work around this for the early SEV/SME startup code, by forcing RIP-relative addressing for certain global SEV/SME variables via inline assembly (see snp_cpuid_get_table() for example), RIP-relative addressing must be pervasively enforced for SEV/SME global variables when accessed prior to page table fixups. __startup_64() already handles this issue for select non-SEV/SME global variables using fixup_pointer(), which adjusts the pointer relative to a `physaddr` argument. To avoid having to pass around this `physaddr` argument across all functions needing to apply pointer fixups, introduce a macro RIP_RELATIVE_REF() which generates a RIP-relative reference to a given global variable. It is used where necessary to force RIP-relative accesses to global variables. For backporting purposes, this patch makes no attempt at cleaning up other occurrences of this pattern, involving either inline asm or fixup_pointer(). Those will be addressed later. [ bp: Call it "rip_rel_ref" everywhere like other code shortens "rIP-relative reference" and make the asm wrapper __always_inline. ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35802" target="_blank">CVE-2024-35802</a><br><a href="https://git.kernel.org/stable/c/0982fd6bf0b822876f2e93ec782c4c28a3f85535" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1c811d403afd73f04bde82b83b24c754011bd0e8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/66fa3fcb474b2b892fe42d455a6f7ec5aaa98fb9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/954a4a87814465ad61cc97c1cd3de1525baaaf07" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fe272b61506bb1534922ef07aa165fd3c37a6a90" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/efistub: Call mixed mode boot services on the firmware's stack Normally, the EFI stub calls into the EFI boot services using the stack that was live when the stub was entered. According to the UEFI spec, this stack needs to be at least 128k in size - this might seem large but all asynchronous processing and event handling in EFI runs from the same stack and so quite a lot of space may be used in practice. In mixed mode, the situation is a bit different: the bootloader calls the 32-bit EFI stub entry point, which calls the decompressor's 32-bit entry point, where the boot stack is set up, using a fixed allocation of 16k. This stack is still in use when the EFI stub is started in 64-bit mode, and so all calls back into the EFI firmware will be using the decompressor's limited boot stack. Due to the placement of the boot stack right after the boot heap, any stack overruns have gone unnoticed. However, commit 5c4feadb0011983b ("x86/decompressor: Move global symbol references to C code") moved the definition of the boot heap into C code, and now the boot stack is placed right at the base of BSS, where any overruns will corrupt the end of the .data section. While it would be possible to work around this by increasing the size of the boot stack, doing so would affect all x86 systems, and mixed mode systems are a tiny (and shrinking) fraction of the x86 installed base. So instead, record the firmware stack pointer value when entering from the 32-bit firmware, and switch to this stack every time a EFI boot service call is made.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35803" target="_blank">CVE-2024-35803</a><br><a href="https://git.kernel.org/stable/c/2149f8a56e2ed345c7a4d022a79f6b8fc53ae926" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/725351c036452b7db5771a7bed783564bc4b99cc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/930775060ca348b8665f60eef14b204172d14f31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cefcd4fe2e3aaf792c14c9e56dab89e3d7a65d02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fba7ee7187581b5bc222003e73e2592b398bb06d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Mark target gfn of emulated atomic instruction as dirty When emulating an atomic access on behalf of the guest, mark the target gfn dirty if the CMPXCHG by KVM is attempted and doesn't fault. This fixes a bug where KVM effectively corrupts guest memory during live migration by writing to guest memory without informing userspace that the page is dirty. Marking the page dirty got unintentionally dropped when KVM's emulated CMPXCHG was converted to do a user access. Before that, KVM explicitly mapped the guest page into kernel memory, and marked the page dirty during the unmap phase. Mark the page dirty even if the CMPXCHG fails, as the old data is written back on failure, i.e. the page is still written. The value written is guaranteed to be the same because the operation is atomic, but KVM's ABI is that all writes are dirty logged regardless of the value written. And more importantly, that's what KVM did before the buggy commit. Huge kudos to the folks on the Cc list (and many others), who did all the actual work of triaging and debugging. base-commit: 6769ea8da8a93ed4630f1ce64df6aafcaabfce64</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35804" target="_blank">CVE-2024-35804</a><br><a href="https://git.kernel.org/stable/c/225d587a073584946c05c9b7651d637bd45c0c71" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/726374dde5d608b15b9756bd52b6fc283fda7a06" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/910c57dfa4d113aae6571c2a8b9ae8c430975902" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d1b22e573a3789ed1f32033ee709106993ba551" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a9bd6bb6f02bf7132c1ab192ba62bbfa52df7d66" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dm snapshot: fix lockup in dm_exception_table_exit There was reported lockup when we exit a snapshot with many exceptions. Fix this by adding "cond_resched" to the loop that frees the exceptions.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35805" target="_blank">CVE-2024-35805</a><br><a href="https://git.kernel.org/stable/c/116562e804ffc9dc600adab6326dde31d72262c7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3d47eb405781cc5127deca9a14e24b27696087a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5f4ad4d0b0943296287313db60b3f84df4aad683" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6e7132ed3c07bd8a6ce3db4bb307ef2852b322dc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9759ff196e7d248bcf8386a7451d6ff8537a7d9c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e50f83061ac250f90710757a3e51b70a200835e2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e7d4cff57c3c43fdd72342c78d4138f509c7416e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa5c055800a7fd49a36bbb52593aca4ea986a366" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: Always disable interrupts when taking cgr_lock smp_call_function_single disables IRQs when executing the callback. To prevent deadlocks, we must disable IRQs when taking cgr_lock elsewhere. This is already done by qman_update_cgr and qman_delete_cgr; fix the other lockers.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35806" target="_blank">CVE-2024-35806</a><br><a href="https://git.kernel.org/stable/c/0e6521b0f93ff350434ed4ae61a250907e65d397" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/276af8efb05c8e47acf2738a5609dd72acfc703f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/584c2a9184a33a40fceee838f856de3cffa19be3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62c3ecd2833cff0eff4a82af4082c44ca8d2518a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a62168653774c36398d65846a98034436ee66d03" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/af25c5180b2b1796342798f6c56fcfd12f5035bd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b56a793f267679945d1fdb9a280013bd2d0ed7f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd199e5b759ffe349622a4b8fbcafc51fc51b1ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e6378314bb920acb39013051fa65d8f9f8030430" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ext4: fix corruption during on-line resize We observed a corruption during on-line resize of a file system that is larger than 16 TiB with 4k block size. With having more then 2^32 blocks resize_inode is turned off by default by mke2fs. The issue can be reproduced on a smaller file system for convenience by explicitly turning off resize_inode. An on-line resize across an 8 GiB boundary (the size of a meta block group in this setup) then leads to a corruption: dev=/dev/&lt;some_dev&gt; # should be &gt;= 16 GiB mkdir -p /corruption /sbin/mke2fs -t ext4 -b 4096 -O ^resize_inode $dev $((2 * 2**21 - 2**15)) mount -t ext4 $dev /corruption dd if=/dev/zero bs=4096 of=/corruption/test count=$((2*2**21 - 4*2**15)) sha1sum /corruption/test # 79d2658b39dcfd77274e435b0934028adafaab11 /corruption/test /sbin/resize2fs $dev $((2*2**21)) # drop page cache to force reload the block from disk echo 1 &gt; /proc/sys/vm/drop_caches sha1sum /corruption/test # 3c2abc63cbf1a94c9e6977e0fbd72cd832c4d5c3 /corruption/test 2^21 = 2^15*2^6 equals 8 GiB whereof 2^15 is the number of blocks per block group and 2^6 are the number of block groups that make a meta block group. The last checksum might be different depending on how the file is laid out across the physical blocks. The actual corruption occurs at physical block 63*2^15 = 2064384 which would be the location of the backup of the meta block group's block descriptor. During the on-line resize the file system will be converted to meta_bg starting at s_first_meta_bg which is 2 in the example - meaning all block groups after 16 GiB. However, in ext4_flex_group_add we might add block groups that are not part of the first meta block group yet. In the reproducer we achieved this by substracting the size of a whole block group from the point where the meta block group would start. This must be considered when updating the backup block group descriptors to follow the non-meta_bg layout. The fix is to add a test whether the group to add is already part of the meta block group or not.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35807" target="_blank">CVE-2024-35807</a><br><a href="https://git.kernel.org/stable/c/239c669edb2bffa1aa2612519b1d438ab35d6be6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/37b6a3ba793bbbae057f5b991970ebcc52cb3db5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/722d2c01b8b108f8283d1b7222209d5b2a5aa7bd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/75cc31c2e7193b69f5d25650bda5bb42ed92f8a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a6b3bfe176e8a5b05ec4447404e412c2a3fc92cc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b461910af8ba3bed80f48c2bf852686d05c6fc5c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8e8b197317228b5089ed9e7802dadf3ccaa027a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ee4e9c1976147a850f6085a13fca95bcaa00d84c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fb1088d51bbaa0faec5a55d4f5818a9ab79e24df" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35808" target="_blank">CVE-2024-35808</a><br><a href="https://git.kernel.org/stable/c/347dcdc15a1706f61aa545ae498ededdf31aeebc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9e59b8d76ff511505eb0dd1478329f09e0f04669" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd32b27a66db8776d8b8e82ec7d7dde97a8693b0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: PCI/PM: Drain runtime-idle callbacks before driver removal A race condition between the .runtime_idle() callback and the .remove() callback in the rtsx_pcr PCI driver leads to a kernel crash due to an unhandled page fault [1]. The problem is that rtsx_pci_runtime_idle() is not expected to be running after pm_runtime_get_sync() has been called, but the latter doesn't really guarantee that. It only guarantees that the suspend and resume callbacks will not be running when it returns. However, if a .runtime_idle() callback is already running when pm_runtime_get_sync() is called, the latter will notice that the runtime PM status of the device is RPM_ACTIVE and it will return right away without waiting for the former to complete. In fact, it cannot wait for .runtime_idle() to complete because it may be called from that callback (it arguably does not make much sense to do that, but it is not strictly prohibited). Thus in general, whoever is providing a .runtime_idle() callback needs to protect it from running in parallel with whatever code runs after pm_runtime_get_sync(). [Note that .runtime_idle() will not start after pm_runtime_get_sync() has returned, but it may continue running then if it has started earlier.] One way to address that race condition is to call pm_runtime_barrier() after pm_runtime_get_sync() (not before it, because a nonzero value of the runtime PM usage counter is necessary to prevent runtime PM callbacks from being invoked) to wait for the .runtime_idle() callback to complete should it be running at that point. A suitable place for doing that is in pci_device_remove() which calls pm_runtime_get_sync() before removing the driver, so it may as well call pm_runtime_barrier() subsequently, which will prevent the race in question from occurring, not just in the rtsx_pcr driver, but in any PCI drivers providing .runtime_idle() callbacks.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35809" target="_blank">CVE-2024-35809</a><br><a href="https://git.kernel.org/stable/c/47d8aafcfe313511a98f165a54d0adceb34e54b1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6347348c6aba52dda0b33296684cbb627bdc6970" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7cc94dd36e48879e76ae7a8daea4ff322b7d9674" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/900b81caf00c89417172afe0e7e49ac4eb110f4b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a87375bb586515c0af63d5dcdcd58ec4acf20a6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d5286d4e7f68beab450deddbb6a32edd5ecf4bf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bbe068b24409ef740657215605284fc7cdddd491" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d534198311c345e4b062c4b88bb609efb8bd91d5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d86ad8c3e152349454b82f37007ff6ba45f26989" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix the lifetime of the bo cursor memory The cleanup can be dispatched while the atomic update is still active, which means that the memory acquired in the atomic update needs to not be invalidated by the cleanup. The buffer objects in vmw_plane_state instead of using the builtin map_and_cache were trying to handle the lifetime of the mapped memory themselves, leading to crashes. Use the map_and_cache instead of trying to manage the lifetime of the buffer objects held by the vmw_plane_state. Fixes kernel oops'es in IGT's kms_cursor_legacy forked-bo.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35810" target="_blank">CVE-2024-35810</a><br><a href="https://git.kernel.org/stable/c/104a5b2772bc7c0715ae7355ccf9d294a472765c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/86cb706a40b7e6b2221ee49a298a65ad9b46c02d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a9e8a7159ca09af9b1a300a6c8e8b6ff7501c76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ed381800ea6d9a4c7f199235a471c0c48100f0ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach This is the candidate patch of CVE-2023-47233 : https://nvd.nist.gov/vuln/detail/CVE-2023-47233 In brcm80211 driver,it starts with the following invoking chain to start init a timeout worker: -&gt;brcmf_usb_probe -&gt;brcmf_usb_probe_cb -&gt;brcmf_attach -&gt;brcmf_bus_started -&gt;brcmf_cfg80211_attach -&gt;wl_init_priv -&gt;brcmf_init_escan -&gt;INIT_WORK(&amp;cfg-&gt;escan_timeout_work, brcmf_cfg80211_escan_timeout_worker); If we disconnect the USB by hotplug, it will call brcmf_usb_disconnect to make cleanup. The invoking chain is : brcmf_usb_disconnect -&gt;brcmf_usb_disconnect_cb -&gt;brcmf_detach -&gt;brcmf_cfg80211_detach -&gt;kfree(cfg); While the timeout woker may still be running. This will cause a use-after-free bug on cfg in brcmf_cfg80211_escan_timeout_worker. Fix it by deleting the timer and canceling the worker in brcmf_cfg80211_detach. [arend.vanspriel@broadcom.com: keep timer delete as is and cancel work just before free]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35811" target="_blank">CVE-2024-35811</a><br><a href="https://git.kernel.org/stable/c/0a7591e14a8da794d0b93b5d1c6254ccb23adacb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0b812f706fd7090be74812101114a0e165b36744" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0f7352557a35ab7888bc7831411ec8a3cbe20d78" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/190794848e2b9d15de92d502b6ac652806904f5a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/202c503935042272e2f9e1bb549d5f69a8681169" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6678a1e7d896c00030b31491690e8ddc9a90767a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8c36205123dc57349b59b4f1a2301eb278cbc731" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e3f03f4ef7c36091f46e7349096efb5a2cdb3a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bacb8c3ab86dcd760c15903fcee58169bc3026aa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: cdc-wdm: close race between read and workqueue wdm_read() cannot race with itself. However, in service_outstanding_interrupt() it can race with the workqueue, which can be triggered by error handling. Hence we need to make sure that the WDM_RESPONDING flag is not just only set but tested.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35812" target="_blank">CVE-2024-35812</a><br><a href="https://git.kernel.org/stable/c/164be0a824387301312689bb29b2be92ab2cd39d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/19f955ad9437a6859a529af34e2eafd903d5e7c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2ff436b6399859e06539a2b9c667897d3cc85ad5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/339f83612f3a569b194680768b22bf113c26a29d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/347cca11bb78b9f3c29b45a9c52e70258bd008bf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3afdcc4e1a00facad210f5c5891bb2fbc026067f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5904411219601127ffdbd2d622bb5d67f9d8d16c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7182175f565ffffa2ba1911726c5656bfc7a1bae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8672ad663a22d0e4a325bb7d817b36ec412b967c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/916cd2fcbc1e344bcabf4b2a834cdf5a0417d30c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9723602387217caa71d623ffcce314dc39e84a09" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9b319f4a88094b2e020e6db6e819c808d890098d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a86e54a345139f1a7668c9f83bdc7ac6f91b6f78" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ab92e11b73b48b79f144421430891f3aa6242656" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/da3b75931bb737be74d6b4341e0080f233ed1409" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e4e47e406d74cab601b2ab21ba5e3add811e05ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid negative index with array access Commit 4d0c8d0aef63 ("mmc: core: Use mrq.sbc in close-ended ffu") assigns prev_idata = idatas[i - 1], but doesn't check that the iterator i is greater than zero. Let's fix this by adding a check.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35813" target="_blank">CVE-2024-35813</a><br><a href="https://git.kernel.org/stable/c/064db53f9023a2d5877a2d12de6bc27995f6ca56" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2b539c88940e22494da80a93ee1c5a28bbad10f6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4466677dcabe2d70de6aa3d4bd4a4fafa94a71f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d0e8a6147550aa058fa6ade8583ad252aa61304" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/81b8645feca08a54c7c4bf36e7b176f4983b2f28" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad9cc5e9e53ab94aa0c7ac65d43be7eb208dcb55" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9a7339ae403035ffe7fc37cb034b36947910f68" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cf55a7acd1ed38afe43bba1c8a0935b51d1dc014" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: swiotlb: Fix double-allocation of slots due to broken alignment handling Commit bbb73a103fbb ("swiotlb: fix a braino in the alignment check fix"), which was a fix for commit 0eee5ae10256 ("swiotlb: fix slot alignment checks"), causes a functional regression with vsock in a virtual machine using bouncing via a restricted DMA SWIOTLB pool. When virtio allocates the virtqueues for the vsock device using dma_alloc_coherent(), the SWIOTLB search can return page-unaligned allocations if 'area-&gt;index' was left unaligned by a previous allocation from the buffer: # Final address in brackets is the SWIOTLB address returned to the caller | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1645-1649/7168 (0x98326800) | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1649-1653/7168 (0x98328800) | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1653-1657/7168 (0x9832a800) This ends badly (typically buffer corruption and/or a hang) because swiotlb_alloc() is expecting a page-aligned allocation and so blindly returns a pointer to the 'struct page' corresponding to the allocation, therefore double-allocating the first half (2KiB slot) of the 4KiB page. Fix the problem by treating the allocation alignment separately to any additional alignment requirements from the device, using the maximum of the two as the stride to search the buffer slots and taking care to ensure a minimum of page-alignment for buffers larger than a page. This also resolves swiotlb allocation failures occuring due to the inclusion of ~PAGE_MASK in 'iotlb_align_mask' for large allocations and resulting in alignment requirements exceeding swiotlb_max_mapping_size().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35814" target="_blank">CVE-2024-35814</a><br><a href="https://git.kernel.org/stable/c/04867a7a33324c9c562ee7949dbcaab7aaad1fb4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3e7acd6e25ba77dde48c3b721c54c89cd6a10534" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/777391743771040e12cc40d3d0d178f70c616491" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c88668aa6c1da240ea3eb4d128b7906e740d3cb8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion The first kiocb_set_cancel_fn() argument may point at a struct kiocb that is not embedded inside struct aio_kiocb. With the current code, depending on the compiler, the req-&gt;ki_ctx read happens either before the IOCB_AIO_RW test or after that test. Move the req-&gt;ki_ctx read such that it is guaranteed that the IOCB_AIO_RW test happens first.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35815" target="_blank">CVE-2024-35815</a><br><a href="https://git.kernel.org/stable/c/10ca82aff58434e122c7c757cf0497c335f993f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/18d5fc3c16cc317bd0e5f5dabe0660df415cadb7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/396dbbc18963648e9d1a4edbb55cfe08fa374d50" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5c43d0041e3a05c6c41c318b759fff16d2384596" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/94eb0293703ced580f05dfbe5a57da5931e9aee2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/961ebd120565cb60cebe21cb634fbc456022db4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a71cba07783abc76b547568b6452cd1dd9981410" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c01ed748847fe8b810d86efc229b9e6c7fafa01e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: prevent leak of left-over IRQ on unbind Commit 5a95f1ded28691e6 ("firewire: ohci: use devres for requested IRQ") also removed the call to free_irq() in pci_remove(), leading to a leftover irq of devm_request_irq() at pci_disable_msi() in pci_remove() when unbinding the driver from the device remove_proc_entry: removing non-empty directory 'irq/136', leaking at least 'firewire_ohci' Call Trace: ? remove_proc_entry+0x19c/0x1c0 ? __warn+0x81/0x130 ? remove_proc_entry+0x19c/0x1c0 ? report_bug+0x171/0x1a0 ? console_unlock+0x78/0x120 ? handle_bug+0x3c/0x80 ? exc_invalid_op+0x17/0x70 ? asm_exc_invalid_op+0x1a/0x20 ? remove_proc_entry+0x19c/0x1c0 unregister_irq_proc+0xf4/0x120 free_desc+0x3d/0xe0 ? kfree+0x29f/0x2f0 irq_free_descs+0x47/0x70 msi_domain_free_locked.part.0+0x19d/0x1d0 msi_domain_free_irqs_all_locked+0x81/0xc0 pci_free_msi_irqs+0x12/0x40 pci_disable_msi+0x4c/0x60 pci_remove+0x9d/0xc0 [firewire_ohci 01b483699bebf9cb07a3d69df0aa2bee71db1b26] pci_device_remove+0x37/0xa0 device_release_driver_internal+0x19f/0x200 unbind_store+0xa1/0xb0 remove irq with devm_free_irq() before pci_disable_msi() also remove it in fail_msi: of pci_probe() as this would lead to an identical leak</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35816" target="_blank">CVE-2024-35816</a><br><a href="https://git.kernel.org/stable/c/318f6d53dd425c400e35f1a9b7af682c2c6a66d6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/43c70cbc2502cf2557105c662eeed6a15d082b88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/575801663c7dc38f826212b39e3b91a4a8661c33" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: amdgpu_ttm_gart_bind set gtt bound flag Otherwise after the GTT bo is released, the GTT and gart space is freed but amdgpu_ttm_backend_unbind will not clear the gart page table entry and leave valid mapping entry pointing to the stale system page. Then if GPU access the gart address mistakely, it will read undefined value instead page fault, harder to debug and reproduce the real issue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35817" target="_blank">CVE-2024-35817</a><br><a href="https://git.kernel.org/stable/c/589c414138a1bed98e652c905937d8f790804efe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5cdce3dda3b3dacde902f63a8ee72c2b7f91912d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5d5f1a7f3b1039925f79c7894f153c2a905201fb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6c6064cbe58b43533e3451ad6a8ba9736c109ac3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fcd12cb90888ef2d8af8d4c04e913252eee4ef3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8d27caef2c829a306e1f762fb95f06e8ec676f6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: LoongArch: Define the __io_aw() hook as mmiowb() Commit fb24ea52f78e0d595852e ("drivers: Remove explicit invocations of mmiowb()") remove all mmiowb() in drivers, but it says: "NOTE: mmiowb() has only ever guaranteed ordering in conjunction with spin_unlock(). However, pairing each mmiowb() removal in this patch with the corresponding call to spin_unlock() is not at all trivial, so there is a small chance that this change may regress any drivers incorrectly relying on mmiowb() to order MMIO writes between CPUs using lock-free synchronisation." The mmio in radeon_ring_commit() is protected by a mutex rather than a spinlock, but in the mutex fastpath it behaves similar to spinlock. We can add mmiowb() calls in the radeon driver but the maintainer says he doesn't like such a workaround, and radeon is not the only example of mutex protected mmio. So we should extend the mmiowb tracking system from spinlock to mutex, and maybe other locking primitives. This is not easy and error prone, so we solve it in the architectural code, by simply defining the __io_aw() hook as mmiowb(). And we no longer need to override queued_spin_unlock() so use the generic definition. Without this, we get such an error when run 'glxgears' on weak ordering architectures such as LoongArch: radeon 0000:04:00.0: ring 0 stalled for more than 10324msec radeon 0000:04:00.0: ring 3 stalled for more than 10240msec radeon 0000:04:00.0: GPU lockup (current fence id 0x000000000001f412 last fence id 0x000000000001f414 on ring 3) radeon 0000:04:00.0: GPU lockup (current fence id 0x000000000000f940 last fence id 0x000000000000f941 on ring 0) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35818" target="_blank">CVE-2024-35818</a><br><a href="https://git.kernel.org/stable/c/0b61a7dc6712b78799b3949997e8a5e94db5c4b0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/97cd43ba824aec764f5ea2790d0c0a318f885167" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9adec248bba33b1503252caf8e59d81febfc5ceb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9c68ece8b2a5c5ff9b2fcaea923dd73efeb174cd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d7d7c6cdea875be3b241d7d39873bb431db7154d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: Use raw spinlock for cgr_lock smp_call_function always runs its callback in hard IRQ context, even on PREEMPT_RT, where spinlocks can sleep. So we need to use a raw spinlock for cgr_lock to ensure we aren't waiting on a sleeping task. Although this bug has existed for a while, it was not apparent until commit ef2a8d5478b9 ("net: dpaa: Adjust queue depth on rate change") which invokes smp_call_function_single via qman_update_cgr_safe every time a link goes up or down.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35819" target="_blank">CVE-2024-35819</a><br><a href="https://git.kernel.org/stable/c/2b3fede8225133671ce837c0d284804aa3bc7a02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/32edca2f03a6cc42c650ddc3ad83d086e3f365d1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/54d26adf64c04f186098b39dba86b86037084baa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a3ca8292ce9fdcce122706c28c3f07bc857fe5e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd53a8ae5aacb4ecd25088486dea1cd02e74b506" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d6b5aac451c9cc12e43ab7308e0e2ddc52c62c14" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f39d36b7540cf0088ed7ce2de2794f2aa237f6df" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fbec4e7fed89b579f2483041fabf9650fb0dd6bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ff50716b7d5b7985979a5b21163cd79fb3d21d59" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_queue_proc modifying req-&gt;flags With multiple poll entries __io_queue_proc() might be running in parallel with poll handlers and possibly task_work, we should not be carelessly modifying req-&gt;flags there. io_poll_double_prepare() handles a similar case with locking but it's much easier to move it into __io_arm_poll_handler().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35820" target="_blank">CVE-2024-35820</a><br><a href="https://git.kernel.org/stable/c/0ecb8919469e6d5c74eea24086b34ce1bda5aef7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1a8ec63b2b6c91caec87d4e132b1f71b5df342be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/51a490a7f63cae0754120e7c04f4f47920bd48db" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ubifs: Set page uptodate in the correct place Page cache reads are lockless, so setting the freshly allocated page uptodate before we've overwritten it with the data it's supposed to have in it will allow a simultaneous reader to see old data. Move the call to SetPageUptodate into ubifs_write_end(), which is after we copied the new data into the page.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35821" target="_blank">CVE-2024-35821</a><br><a href="https://git.kernel.org/stable/c/142d87c958d9454c3cffa625fab56f3016e8f9f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/17772bbe9cfa972ea1ff827319f6e1340de76566" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4aa554832b9dc9e66249df75b8f447d87853e12e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4b7c4fc60d6a46350fbe54f5dc937aeaa02e675e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/723012cab779eee8228376754e22c6594229bf8f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/778c6ad40256f1c03244fc06d7cdf71f6b5e7310" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8f599ab6fabbca4c741107eade70722a98adfd9f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f19b1023a3758f40791ec166038d6411c8894ae3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc99f4e2d2f1ce766c14e98463c2839194ae964f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: udc: remove warning when queue disabled ep It is possible trigger below warning message from mass storage function, WARNING: CPU: 6 PID: 3839 at drivers/usb/gadget/udc/core.c:294 usb_ep_queue+0x7c/0x104 pc : usb_ep_queue+0x7c/0x104 lr : fsg_main_thread+0x494/0x1b3c Root cause is mass storage function try to queue request from main thread, but other thread may already disable ep when function disable. As there is no function failure in the driver, in order to avoid effort to fix warning, change WARN_ON_ONCE() in usb_ep_queue() to pr_debug().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35822" target="_blank">CVE-2024-35822</a><br><a href="https://git.kernel.org/stable/c/2a587a035214fa1b5ef598aea0b81848c5b72e5e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2b002c308e184feeaeb72987bca3f1b11e5f70b8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/30511676eb54d480d014352bf784f02577a10252" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/36177c2595df12225b95ce74eb1ac77b43d5a58c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3e944ddc17c042945d983e006df7860687a8849a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/68d951880d0c52c7f13dcefb5501b69b8605ce8c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/99731076722eb7ed26b0c87c879da7bb71d24290" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/df5cbb908f1687e8ab97e222a16b7890d5501acf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f74c5e0b54b02706d9a862ac6cddade30ac86bcf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was fixed for the VGA text buffer in commit 39cdb68c64d8 ("vt: fix memory overlapping when deleting chars in the buffer"). The cure is also the same i.e. replace memcpy() with memmove() due to the overlaping buffers.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35823" target="_blank">CVE-2024-35823</a><br><a href="https://git.kernel.org/stable/c/0190d19d7651c08abc187dac3819c61b726e7e3f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1581dafaf0d34bc9c428a794a22110d7046d186d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1ce408f75ccf1e25b3fddef75cca878b55f2ac90" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2933b1e4757a0a5c689cf48d80b1a2a85f237ff1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7529cbd8b5f6697b369803fe1533612c039cabda" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/994a1e583c0c206c8ca7d03334a65b79f4d8bc51" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc7dfe3d123f00e720be80b920da287810a1f37d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ff7342090c1e8c5a37015c89822a68b275b46f8a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: misc: lis3lv02d_i2c: Fix regulators getting en-/dis-abled twice on suspend/resume When not configured for wakeup lis3lv02d_i2c_suspend() will call lis3lv02d_poweroff() even if the device has already been turned off by the runtime-suspend handler and if configured for wakeup and the device is runtime-suspended at this point then it is not turned back on to serve as a wakeup source. Before commit b1b9f7a49440 ("misc: lis3lv02d_i2c: Add missing setting of the reg_ctrl callback"), lis3lv02d_poweroff() failed to disable the regulators which as a side effect made calling poweroff() twice ok. Now that poweroff() correctly disables the regulators, doing this twice triggers a WARN() in the regulator core: unbalanced disables for regulator-dummy WARNING: CPU: 1 PID: 92 at drivers/regulator/core.c:2999 _regulator_disable ... Fix lis3lv02d_i2c_suspend() to not call poweroff() a second time if already runtime-suspended and add a poweron() call when necessary to make wakeup work. lis3lv02d_i2c_resume() has similar issues, with an added weirness that it always powers on the device if it is runtime suspended, after which the first runtime-resume will call poweron() again, causing the enabled count for the regulator to increase by 1 every suspend/resume. These unbalanced regulator_enable() calls cause the regulator to never be turned off and trigger the following WARN() on driver unbind: WARNING: CPU: 1 PID: 1724 at drivers/regulator/core.c:2396 _regulator_put Fix this by making lis3lv02d_i2c_resume() mirror the new suspend().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35824" target="_blank">CVE-2024-35824</a><br><a href="https://git.kernel.org/stable/c/4154e767354140db7804207117e7238fb337b0e7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/997ca415384612c8df76d99d9a768e0b3f42b325" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ac3e0384073b2408d6cb0d972fee9fcc3776053d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6df761182fc953907b18aba5049fc2a044ecb45" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: gadget: ncm: Fix handling of zero block length packets While connecting to a Linux host with CDC_NCM_NTB_DEF_SIZE_TX set to 65536, it has been observed that we receive short packets, which come at interval of 5-10 seconds sometimes and have block length zero but still contain 1-2 valid datagrams present. According to the NCM spec: "If wBlockLength = 0x0000, the block is terminated by a short packet. In this case, the USB transfer must still be shorter than dwNtbInMaxSize or dwNtbOutMaxSize. If exactly dwNtbInMaxSize or dwNtbOutMaxSize bytes are sent, and the size is a multiple of wMaxPacketSize for the given pipe, then no ZLP shall be sent. wBlockLength= 0x0000 must be used with extreme care, because of the possibility that the host and device may get out of sync, and because of test issues. wBlockLength = 0x0000 allows the sender to reduce latency by starting to send a very large NTB, and then shortening it when the sender discovers that there's not sufficient data to justify sending a large NTB" However, there is a potential issue with the current implementation, as it checks for the occurrence of multiple NTBs in a single giveback by verifying if the leftover bytes to be processed is zero or not. If the block length reads zero, we would process the same NTB infintely because the leftover bytes is never zero and it leads to a crash. Fix this by bailing out if block length reads zero.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35825" target="_blank">CVE-2024-35825</a><br><a href="https://git.kernel.org/stable/c/6b2c73111a252263807b7598682663dc33aa4b4c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7664ee8bd80309b90d53488b619764f0a057f2b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92b051b87658df7649ffcdef522593f21a2b296b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a0f77b5d6067285b8eca0ee3bd1e448a6258026f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a766761d206e7c36d7526e0ae749949d17ca582c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e2dbfea520e60d58e0c498ba41bde10452257779" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ef846cdbd100f7f9dc045e8bcd7fe4b3a3713c03" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f90ce1e04cbcc76639d6cba0fdbd820cd80b3c70" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: block: Fix page refcounts for unaligned buffers in __bio_release_pages() Fix an incorrect number of pages being released for buffers that do not start at the beginning of a page.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35826" target="_blank">CVE-2024-35826</a><br><a href="https://git.kernel.org/stable/c/242006996d15f5ca62e22f8c7de077d9c4a8f367" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/38b43539d64b2fa020b3b9a752a986769f87f7a6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d3765550374f71248c55e6206ea1d6fd4537e65" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c9d3d2fbde9b8197bce88abcbe8ee8e713ffe7c2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ecbd9ced84dd655a8f4cd49d2aad0e80dbf6bf35" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring/net: fix overflow check in io_recvmsg_mshot_prep() The "controllen" variable is type size_t (unsigned long). Casting it to int could lead to an integer underflow. The check_add_overflow() function considers the type of the destination which is type int. If we add two positive values and the result cannot fit in an integer then that's counted as an overflow. However, if we cast "controllen" to an int and it turns negative, then negative values *can* fit into an int type so there is no overflow. Good: 100 + (unsigned long)-4 = 96 &lt;-- overflow Bad: 100 + (int)-4 = 96 &lt;-- no overflow I deleted the cast of the sizeof() as well. That's not a bug but the cast is unnecessary.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35827" target="_blank">CVE-2024-35827</a><br><a href="https://git.kernel.org/stable/c/0c8c74bb59e7d77554016efc34c2d10376985e5e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/59a534690ecc3af72c6ab121aeac1237a4adae66" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/868ec868616438df487b9e2baa5a99f8662cc47c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ede3db5061bb1fe28e2c9683329aafa89d2b1b4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b6563ad0d599110bd5cf8f56c47d279c3ed796fe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() In the for statement of lbs_allocate_cmd_buffer(), if the allocation of cmdarray[i].cmdbuf fails, both cmdarray and cmdarray[i].cmdbuf needs to be freed. Otherwise, there will be memleaks in lbs_allocate_cmd_buffer().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35828" target="_blank">CVE-2024-35828</a><br><a href="https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/lima: fix a memleak in lima_heap_alloc When lima_vm_map_bo fails, the resources need to be deallocated, or there will be memleaks.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35829" target="_blank">CVE-2024-35829</a><br><a href="https://git.kernel.org/stable/c/04ae3eb470e52a3c41babe85ff8cee195e4dcbea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ab14eccf5578af1dd5668a5f2d771df27683cab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/746606d37d662c70ae1379fc658ee9c65f06880f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e25c0ee5665e8a768b8e21445db1f86e9156eb7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ec6bb037e4a35fcbb5cd7bc78242d034ed893fcd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2e80ac9344aebbff576453d5c0290b332e187ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6d51a91b41704704e395de6839c667b0f810bbf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: media: tc358743: register v4l2 async device only after successful setup Ensure the device has been setup correctly before registering the v4l2 async device, thus allowing userspace to access.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35830" target="_blank">CVE-2024-35830</a><br><a href="https://git.kernel.org/stable/c/17c2650de14842c25c569cbb2126c421489a3a24" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4f1490a5d7a0472ee5d9f36547bc4ba46be755c7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/610f20e5cf35ca9c0992693cae0dd8643ce932e7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/87399f1ff92203d65f1febf5919429f4bb613a02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ba8db9786b55047df5ad3db3e01dd886687a77d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b8505a1aee8f1edc9d16d72ae09c93de086e2a1a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c915c46a25c3efb084c4f5e69a053d7f7a635496" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/daf21394f9898fb9f0698c3e50de08132d2164e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/edbb3226c985469a2f8eb69885055c9f5550f468" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring: Fix release of pinned pages when __io_uaddr_map fails Looking at the error path of __io_uaddr_map, if we fail after pinning the pages for any reasons, ret will be set to -EINVAL and the error handler won't properly release the pinned pages. I didn't manage to trigger it without forcing a failure, but it can happen in real life when memory is heavily fragmented.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35831" target="_blank">CVE-2024-35831</a><br><a href="https://git.kernel.org/stable/c/0b6f39c175ba5f0ef72bdb3b9d2a06ad78621d62" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4d376d7ad62b6a8e8dfff56b559d9d275e5b9b3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/67d1189d1095d471ed7fa426c7e384a7140a5dd7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/712e2c8415f55a4a4ddaa98a430b87f624109f69" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: bcachefs: kvfree bch_fs::snapshots in bch2_fs_snapshots_exit bch_fs::snapshots is allocated by kvzalloc in __snapshot_t_mut. It should be freed by kvfree not kfree. Or umount will triger: [ 406.829178 ] BUG: unable to handle page fault for address: ffffe7b487148008 [ 406.830676 ] #PF: supervisor read access in kernel mode [ 406.831643 ] #PF: error_code(0x0000) - not-present page [ 406.832487 ] PGD 0 P4D 0 [ 406.832898 ] Oops: 0000 [#1] PREEMPT SMP PTI [ 406.833512 ] CPU: 2 PID: 1754 Comm: umount Kdump: loaded Tainted: G OE 6.7.0-rc7-custom+ #90 [ 406.834746 ] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014 [ 406.835796 ] RIP: 0010:kfree+0x62/0x140 [ 406.836197 ] Code: 80 48 01 d8 0f 82 e9 00 00 00 48 c7 c2 00 00 00 80 48 2b 15 78 9f 1f 01 48 01 d0 48 c1 e8 0c 48 c1 e0 06 48 03 05 56 9f 1f 01 &lt;48&gt; 8b 50 08 48 89 c7 f6 c2 01 0f 85 b0 00 00 00 66 90 48 8b 07 f6 [ 406.837810 ] RSP: 0018:ffffb9d641607e48 EFLAGS: 00010286 [ 406.838213 ] RAX: ffffe7b487148000 RBX: ffffb9d645200000 RCX: ffffb9d641607dc4 [ 406.838738 ] RDX: 000065bb00000000 RSI: ffffffffc0d88b84 RDI: ffffb9d645200000 [ 406.839217 ] RBP: ffff9a4625d00068 R08: 0000000000000001 R09: 0000000000000001 [ 406.839650 ] R10: 0000000000000001 R11: 000000000000001f R12: ffff9a4625d4da80 [ 406.840055 ] R13: ffff9a4625d00000 R14: ffffffffc0e2eb20 R15: 0000000000000000 [ 406.840451 ] FS: 00007f0a264ffb80(0000) GS:ffff9a4e2d500000(0000) knlGS:0000000000000000 [ 406.840851 ] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 406.841125 ] CR2: ffffe7b487148008 CR3: 000000018c4d2000 CR4: 00000000000006f0 [ 406.841464 ] Call Trace: [ 406.841583 ] &lt;TASK&gt; [ 406.841682 ] ? __die+0x1f/0x70 [ 406.841828 ] ? page_fault_oops+0x159/0x470 [ 406.842014 ] ? fixup_exception+0x22/0x310 [ 406.842198 ] ? exc_page_fault+0x1ed/0x200 [ 406.842382 ] ? asm_exc_page_fault+0x22/0x30 [ 406.842574 ] ? bch2_fs_release+0x54/0x280 [bcachefs] [ 406.842842 ] ? kfree+0x62/0x140 [ 406.842988 ] ? kfree+0x104/0x140 [ 406.843138 ] bch2_fs_release+0x54/0x280 [bcachefs] [ 406.843390 ] kobject_put+0xb7/0x170 [ 406.843552 ] deactivate_locked_super+0x2f/0xa0 [ 406.843756 ] cleanup_mnt+0xba/0x150 [ 406.843917 ] task_work_run+0x59/0xa0 [ 406.844083 ] exit_to_user_mode_prepare+0x197/0x1a0 [ 406.844302 ] syscall_exit_to_user_mode+0x16/0x40 [ 406.844510 ] do_syscall_64+0x4e/0xf0 [ 406.844675 ] entry_SYSCALL_64_after_hwframe+0x6e/0x76 [ 406.844907 ] RIP: 0033:0x7f0a2664e4fb</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35832" target="_blank">CVE-2024-35832</a><br><a href="https://git.kernel.org/stable/c/369acf97d6fd5da620d053d0f1878ffe32eff555" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/56590678791119b9a655202e49898edfb9307271" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-qdma: Fix a memory leak related to the queue command DMA This dma_alloc_coherent() is undone neither in the remove function, nor in the error handling path of fsl_qdma_probe(). Switch to the managed version to fix both issues.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35833" target="_blank">CVE-2024-35833</a><br><a href="https://git.kernel.org/stable/c/15eb996d7d13cb72a16389231945ada8f0fef2c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/198270de9d8eb3b5d5f030825ea303ef95285d24" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1c75fe450b5200c78f4a102a0eb8e15d8f1ccda8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/25ab4d72eb7cbfa0f3d97a139a9b2bfcaa72dd59" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3aa58cb51318e329d203857f7a191678e60bb714" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5cd8a51517ce15edbdcea4fc74c4c127ddaa1bd6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ae6769ba51417c1c86fb645812d5bff455eee802" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: xsk: recycle buffer in case Rx queue was full Add missing xsk_buff_free() call when __xsk_rcv_zc() failed to produce descriptor to XSK Rx queue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35834" target="_blank">CVE-2024-35834</a><br><a href="https://git.kernel.org/stable/c/269009893146c495f41e9572dd9319e787c2eba9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7b4d93d31aade99210d41cd9d4cbd2957c98bc8c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cce713664548284daf977739e7ff1cd59e84189c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a double-free in arfs_create_groups When `in` allocated by kvzalloc fails, arfs_create_groups will free ft-&gt;g and return an error. However, arfs_create_table, the only caller of arfs_create_groups, will hold this error and call to mlx5e_destroy_flow_table, in which the ft-&gt;g will be freed again.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35835" target="_blank">CVE-2024-35835</a><br><a href="https://git.kernel.org/stable/c/2501afe6c4c9829d03abe9a368b83d9ea1b611b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3c6d5189246f590e4e1f167991558bdb72a4738b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/42876db001bbea7558e8676d1019f08f9390addb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/66cc521a739ccd5da057a1cb3d6346c6d0e7619b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b21db3f1ab7967a81d6bbd328d28fe5a4c07a8a7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c57ca114eb00e03274dd38108d07a3750fa3c056" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cf116d9c3c2aebd653c2dfab5b10c278e9ec3ee5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e3d3ed8c152971dbe64c92c9ecb98fdb52abb629" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dpll: fix pin dump crash for rebound module When a kernel module is unbound but the pin resources were not entirely freed (other kernel module instance of the same PCI device have had kept the reference to that pin), and kernel module is again bound, the pin properties would not be updated (the properties are only assigned when memory for the pin is allocated), prop pointer still points to the kernel module memory of the kernel module which was deallocated on the unbind. If the pin dump is invoked in this state, the result is a kernel crash. Prevent the crash by storing persistent pin properties in dpll subsystem, copy the content from the kernel module when pin is allocated, instead of using memory of the kernel module.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35836" target="_blank">CVE-2024-35836</a><br><a href="https://git.kernel.org/stable/c/5050a5b9d8b4d3c6f7e376e07670e437db7ccf9c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/830ead5fb0c5855ce4d70ba2ed4a673b5f1e7d9b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: clear BM pool before initialization Register value persist after booting the kernel using kexec which results in kernel panic. Thus clear the BM pool registers before initialisation to fix the issue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35837" target="_blank">CVE-2024-35837</a><br><a href="https://git.kernel.org/stable/c/83f99138bf3b396f761600ab488054396fb5768f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/938729484cfa535e9987ed0f86f29a2ae3a8188b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9f538b415db862e74b8c5d3abbccfc1b2b6caa38" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/af47faa6d3328406038b731794e7cf508c71affa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cec65f09c47d8c2d67f2bcad6cf05c490628d1ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dc77f6ab5c3759df60ff87ed24f4d45df0f3b4c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential sta-link leak When a station is allocated, links are added but not set to valid yet (e.g. during connection to an AP MLD), we might remove the station without ever marking links valid, and leak them. Fix that.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35838" target="_blank">CVE-2024-35838</a><br><a href="https://git.kernel.org/stable/c/49aaeb8c539b1633b3bd7c2df131ec578aa1eae1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/587c5892976108674bbe61a8ff659de279318034" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b01a74b3ca6fd51b62c67733ba7c3280fa6c5d26" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e04bf59bdba0fa45d52160be676114e16be855a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: replace physindev with physinif in nf_bridge_info An skb can be added to a neigh-&gt;arp_queue while waiting for an arp reply. Where original skb's skb-&gt;dev can be different to neigh's neigh-&gt;dev. For instance in case of bridging dnated skb from one veth to another, the skb would be added to a neigh-&gt;arp_queue of the bridge. As skb-&gt;dev can be reset back to nf_bridge-&gt;physindev and used, and as there is no explicit mechanism that prevents this physindev from been freed under us (for instance neigh_flush_dev doesn't cleanup skbs from different device's neigh queue) we can crash on e.g. this stack: arp_process neigh_update skb = __skb_dequeue(&amp;neigh-&gt;arp_queue) neigh_resolve_output(..., skb) ... br_nf_dev_xmit br_nf_pre_routing_finish_bridge_slow skb-&gt;dev = nf_bridge-&gt;physindev br_handle_frame_finish Let's use plain ifindex instead of net_device link. To peek into the original net_device we will use dev_get_by_index_rcu(). Thus either we get device and are safe to use it or we don't get it and drop skb.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35839" target="_blank">CVE-2024-35839</a><br><a href="https://git.kernel.org/stable/c/544add1f1cfb78c3dfa3e6edcf4668f6be5e730c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7ae19ee81ca56b13c50a78de6c47d5b8fdc9d97b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9325e3188a9cf3f69fc6f32af59844bbc5b90547" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9874808878d9eed407e3977fd11fee49de1e1d86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect() subflow_finish_connect() uses four fields (backup, join_id, thmac, none) that may contain garbage unless OPTION_MPTCP_MPJ_SYNACK has been set in mptcp_parse_option()</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35840" target="_blank">CVE-2024-35840</a><br><a href="https://git.kernel.org/stable/c/413b913507326972135d2977975dbff8b7f2c453" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/51e4cb032d49ce094605f27e45eabebc0408893c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/76e8de7273a22a00d27e9b8b7d4d043d6433416a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad3e8f5c3d5c53841046ef7a947c04ad45a20721" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be1d9d9d38da922bd4beeec5b6dd821ff5a1dfeb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: tls, fix WARNIING in __sk_msg_free A splice with MSG_SPLICE_PAGES will cause tls code to use the tls_sw_sendmsg_splice path in the TLS sendmsg code to move the user provided pages from the msg into the msg_pl. This will loop over the msg until msg_pl is full, checked by sk_msg_full(msg_pl). The user can also set the MORE flag to hint stack to delay sending until receiving more pages and ideally a full buffer. If the user adds more pages to the msg than can fit in the msg_pl scatterlist (MAX_MSG_FRAGS) we should ignore the MORE flag and send the buffer anyways. What actually happens though is we abort the msg to msg_pl scatterlist setup and then because we forget to set 'full record' indicating we can no longer consume data without a send we fallthrough to the 'continue' path which will check if msg_data_left(msg) has more bytes to send and then attempts to fit them in the already full msg_pl. Then next iteration of sender doing send will encounter a full msg_pl and throw the warning in the syzbot report. To fix simply check if we have a full_record in splice code path and if not send the msg regardless of MORE flag.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35841" target="_blank">CVE-2024-35841</a><br><a href="https://git.kernel.org/stable/c/02e368eb1444a4af649b73cbe2edd51780511d86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/294e7ea85f34748f04e5f3f9dba6f6b911d31aa8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dc9dfc8dc629e42f2234e3327b75324ffc752bc9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: sof-common: Add NULL check for normal_link string It's not granted that all entries of struct sof_conn_stream declare a `normal_link` (a non-SOF, direct link) string, and this is the case for SoCs that support only SOF paths (hence do not support both direct and SOF usecases). For example, in the case of MT8188 there is no normal_link string in any of the sof_conn_stream entries and there will be more drivers doing that in the future. To avoid possible NULL pointer KPs, add a NULL check for `normal_link`.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35842" target="_blank">CVE-2024-35842</a><br><a href="https://git.kernel.org/stable/c/b1d3db6740d0997ffc6e5a0d96ef7cbd62b35fdd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cad471227a37c0c7c080bfc9ed01b53750e82afe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cde6ca5872bf67744dffa875a7cb521ab007b7ef" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e3b3ec967a7d93b9010a5af9a2394c8b5c8f31ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Use device rbtree in iopf reporting path The existing I/O page fault handler currently locates the PCI device by calling pci_get_domain_bus_and_slot(). This function searches the list of all PCI devices until the desired device is found. To improve lookup efficiency, replace it with device_rbtree_find() to search the device within the probed device rbtree. The I/O page fault is initiated by the device, which does not have any synchronization mechanism with the software to ensure that the device stays in the probed device tree. Theoretically, a device could be released by the IOMMU subsystem after device_rbtree_find() and before iopf_get_dev_fault_param(), which would cause a use-after-free problem. Add a mutex to synchronize the I/O page fault reporting path and the IOMMU release device path. This lock doesn't introduce any performance overhead, as the conflict between I/O page fault reporting and device releasing is very rare.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35843" target="_blank">CVE-2024-35843</a><br><a href="https://git.kernel.org/stable/c/3d39238991e745c5df85785604f037f35d9d1b15" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/def054b01a867822254e1dda13d587f5c7a99e2a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix reserve_cblocks counting error when out of space When a file only needs one direct_node, performing the following operations will cause the file to be unrepairable: unisoc # ./f2fs_io compress test.apk unisoc #df -h | grep dm-48 /dev/block/dm-48 112G 112G 1.2M 100% /data unisoc # ./f2fs_io release_cblocks test.apk 924 unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 4.8M 100% /data unisoc # dd if=/dev/random of=file4 bs=1M count=3 3145728 bytes (3.0 M) copied, 0.025 s, 120 M/s unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 1.8M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk F2FS_IOC_RESERVE_COMPRESS_BLOCKS failed: No space left on device adb reboot unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 11M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk 0 This is because the file has only one direct_node. After returning to -ENOSPC, reserved_blocks += ret will not be executed. As a result, the reserved_blocks at this time is still 0, which is not the real number of reserved blocks. Therefore, fsck cannot be set to repair the file. After this patch, the fsck flag will be set to fix this problem. unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 1.8M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk F2FS_IOC_RESERVE_COMPRESS_BLOCKS failed: No space left on device adb reboot then fsck will be executed unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 11M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk 924</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35844" target="_blank">CVE-2024-35844</a><br><a href="https://git.kernel.org/stable/c/2f6d721e14b69d6e1251f69fa238b48e8374e25f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/569c198c9e2093fd29cc071856a4e548fda506bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/889846dfc8ee2cf31148a44bfd2faeb2faadc685" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f0bf89e84c3afb79d7a3a9e4bc853ad6a3245c0a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa3ac8b1a227d9b470b87972494293348b5839ee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc0aed88afbf6f606205129a7466eebdf528e3f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is terminated correctly before using it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35845" target="_blank">CVE-2024-35845</a><br><a href="https://git.kernel.org/stable/c/71d4186d470e9cda7cd1a0921b4afda737c6f641" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/783d413f332a3ebec916664b366c28f58147f82c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/96aa40761673da045a7774f874487cdb50c6a2f7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c855a1a5b7e3de57e6b1b29563113d5e3bfdb89a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea1d166fae14e05d49ffb0ea9fcd4658f8d3dcea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fabe2db7de32a881e437ee69db32e0de785a6209" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fec14d1cdd92f340b9ba2bd220abf96f9609f2a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mm: zswap: fix shrinker NULL crash with cgroup_disable=memory Christian reports a NULL deref in zswap that he bisected down to the zswap shrinker. The issue also cropped up in the bug trackers of libguestfs [1] and the Red Hat bugzilla [2]. The problem is that when memcg is disabled with the boot time flag, the zswap shrinker might get called with sc-&gt;memcg == NULL. This is okay in many places, like the lruvec operations. But it crashes in memcg_page_state() - which is only used due to the non-node accounting of cgroup's the zswap memory to begin with. Nhat spotted that the memcg can be NULL in the memcg-disabled case, and I was then able to reproduce the crash locally as well. [1] https://github.com/libguestfs/libguestfs/issues/139 [2] https://bugzilla.redhat.com/show_bug.cgi?id=2275252</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35846" target="_blank">CVE-2024-35846</a><br><a href="https://git.kernel.org/stable/c/682886ec69d22363819a83ddddd5d66cb5c791e1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b0fdabc908a7f81d12382c87ca9e46a9c2e14042" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent double free on error The error handling path in its_vpe_irq_domain_alloc() causes a double free when its_vpe_init() fails after successfully allocating at least one interrupt. This happens because its_vpe_irq_domain_free() frees the interrupts along with the area bitmap and the vprop_page and its_vpe_irq_domain_alloc() subsequently frees the area bitmap and the vprop_page again. Fix this by unconditionally invoking its_vpe_irq_domain_free() which handles all cases correctly and by removing the bitmap/vprop_page freeing from its_vpe_irq_domain_alloc(). [ tglx: Massaged change log ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35847" target="_blank">CVE-2024-35847</a><br><a href="https://git.kernel.org/stable/c/03170e657f62c26834172742492a8cb8077ef792" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5b012f77abde89bf0be8a0547636184fea618137" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5dbdbe1133911ca7d8466bb86885adec32ad9438" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/aa44d21574751a7d6bca892eb8e0e9ac68372e52" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b72d2b1448b682844f995e660b77f2a1fabc1662" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c26591afd33adce296c022e3480dea4282b7ef91" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd681710ab77c8beafe2e263064cb1bd0e2d6ca9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f5417ff561b8ac9a7e53c747b8627a7ab58378ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: eeprom: at24: fix memory corruption race condition If the eeprom is not accessible, an nvmem device will be registered, the read will fail, and the device will be torn down. If another driver accesses the nvmem device after the teardown, it will reference invalid memory. Move the failure point before registering the nvmem device.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35848" target="_blank">CVE-2024-35848</a><br><a href="https://git.kernel.org/stable/c/26d32bec4c6d255a03762f33c637bfa3718be15a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2af84c46b9b8f2d6c0f88d09ee5c849ae1734676" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d8b56ec0c8f30d5657382f47344a32569f7a9bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c43e5028f5a35331eb25017f5ff6cc21735005c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c850f71fca09ea41800ed55905980063d17e01da" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f42c97027fb75776e2e9358d16bf4a99aeb04cf2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: fix information leak in btrfs_ioctl_logical_to_ino() Syzbot reported the following information leak for in btrfs_ioctl_logical_to_ino(): BUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline] BUG: KMSAN: kernel-infoleak in _copy_to_user+0xbc/0x110 lib/usercopy.c:40 instrument_copy_to_user include/linux/instrumented.h:114 [inline] _copy_to_user+0xbc/0x110 lib/usercopy.c:40 copy_to_user include/linux/uaccess.h:191 [inline] btrfs_ioctl_logical_to_ino+0x440/0x750 fs/btrfs/ioctl.c:3499 btrfs_ioctl+0x714/0x1260 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0x261/0x450 fs/ioctl.c:890 __x64_sys_ioctl+0x96/0xe0 fs/ioctl.c:890 x64_sys_call+0x1883/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Uninit was created at: __kmalloc_large_node+0x231/0x370 mm/slub.c:3921 __do_kmalloc_node mm/slub.c:3954 [inline] __kmalloc_node+0xb07/0x1060 mm/slub.c:3973 kmalloc_node include/linux/slab.h:648 [inline] kvmalloc_node+0xc0/0x2d0 mm/util.c:634 kvmalloc include/linux/slab.h:766 [inline] init_data_container+0x49/0x1e0 fs/btrfs/backref.c:2779 btrfs_ioctl_logical_to_ino+0x17c/0x750 fs/btrfs/ioctl.c:3480 btrfs_ioctl+0x714/0x1260 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0x261/0x450 fs/ioctl.c:890 __x64_sys_ioctl+0x96/0xe0 fs/ioctl.c:890 x64_sys_call+0x1883/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Bytes 40-65535 of 65536 are uninitialized Memory access of size 65536 starts at ffff888045a40000 This happens, because we're copying a 'struct btrfs_data_container' back to user-space. This btrfs_data_container is allocated in 'init_data_container()' via kvmalloc(), which does not zero-fill the memory. Fix this by using kvzalloc() which zeroes out the memory on allocation.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35849" target="_blank">CVE-2024-35849</a><br><a href="https://git.kernel.org/stable/c/2f7ef5bb4a2f3e481ef05fab946edb97c84f67cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/30189e54ba80e3209d34cfeea87b848f6ae025e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3a63cee1a5e14a3e52c19142c61dd5fcb524f6dc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/689efe22e9b5b7d9d523119a9a5c3c17107a0772" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/73db209dcd4ae026021234d40cfcb2fb5b564b86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8bdbcfaf3eac42f98e5486b3d7e130fa287811f6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e58047553a4e859dafc8d1d901e1de77c9dd922d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fddc19631c51d9c17d43e9f822a7bc403af88d54" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NULL-deref on non-serdev setup Qualcomm ROME controllers can be registered from the Bluetooth line discipline and in this case the HCI UART serdev pointer is NULL. Add the missing sanity check to prevent a NULL-pointer dereference when setup() is called for a non-serdev controller.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35850" target="_blank">CVE-2024-35850</a><br><a href="https://git.kernel.org/stable/c/67459f1a707aae6d590454de07956c2752e21ea4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7ddb9de6af0f1c71147785b12fd7c8ec3f06cc86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bec4d4c6fa5c6526409f582e4f31144e20c86c21" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NULL-deref on non-serdev suspend Qualcomm ROME controllers can be registered from the Bluetooth line discipline and in this case the HCI UART serdev pointer is NULL. Add the missing sanity check to prevent a NULL-pointer dereference when wakeup() is called for a non-serdev controller during suspend. Just return true for now to restore the original behaviour and address the crash with pre-6.2 kernels, which do not have commit e9b3e5b8c657 ("Bluetooth: hci_qca: only assign wakeup with serial port support") that causes the crash to happen already at setup() time.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35851" target="_blank">CVE-2024-35851</a><br><a href="https://git.kernel.org/stable/c/52f9041deaca3fc5c40ef3b9cb943993ec7d2489" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6b47cdeb786c38e4174319218db3fa6d7b4bba88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/73e87c0a49fda31d7b589edccf4c72e924411371" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b64092d2f108f0cd1d7fd7e176f5fb2a67a2f189" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e60502b907be350c518819297b565007a94c706d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work The rehash delayed work is rescheduled with a delay if the number of credits at end of the work is not negative as supposedly it means that the migration ended. Otherwise, it is rescheduled immediately. After "mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash" the above is no longer accurate as a non-negative number of credits is no longer indicative of the migration being done. It can also happen if the work encountered an error in which case the migration will resume the next time the work is scheduled. The significance of the above is that it is possible for the work to be pending and associated with hints that were allocated when the migration started. This leads to the hints being leaked [1] when the work is canceled while pending as part of ACL region dismantle. Fix by freeing the hints if hints are associated with a work that was canceled while pending. Blame the original commit since the reliance on not having a pending work associated with hints is fragile. [1] unreferenced object 0xffff88810e7c3000 (size 256): comm "kworker/0:16", pid 176, jiffies 4295460353 hex dump (first 32 bytes): 00 30 95 11 81 88 ff ff 61 00 00 00 00 00 00 80 .0......a....... 00 00 61 00 40 00 00 00 00 00 00 00 04 00 00 00 ..a.@........... backtrace (crc 2544ddb9): [&lt;00000000cf8cfab3&gt;] kmalloc_trace+0x23f/0x2a0 [&lt;000000004d9a1ad9&gt;] objagg_hints_get+0x42/0x390 [&lt;000000000b143cf3&gt;] mlxsw_sp_acl_erp_rehash_hints_get+0xca/0x400 [&lt;0000000059bdb60a&gt;] mlxsw_sp_acl_tcam_vregion_rehash_work+0x868/0x1160 [&lt;00000000e81fd734&gt;] process_one_work+0x59c/0xf20 [&lt;00000000ceee9e81&gt;] worker_thread+0x799/0x12c0 [&lt;00000000bda6fe39&gt;] kthread+0x246/0x300 [&lt;0000000070056d23&gt;] ret_from_fork+0x34/0x70 [&lt;00000000dea2b93e&gt;] ret_from_fork_asm+0x1a/0x30</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35852" target="_blank">CVE-2024-35852</a><br><a href="https://git.kernel.org/stable/c/51cefc9da400b953fee749c9e5d26cd4a2b5d758" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5bfe7bf9656ed2633718388f12b7c38b86414a04" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/63d814d93c5cce4c18284adc810028f28dca493f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/857ed800133ffcfcee28582090b63b0cbb8ba59d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d72dd6fcd7886d0523afbab8b4a4b22d17addd7d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/de1aaefa75be9d0ec19c9a3e0e2f9696de20c6ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fb4e2b70a7194b209fc7320bbf33b375f7114bd5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak during rehash The rehash delayed work migrates filters from one region to another. This is done by iterating over all chunks (all the filters with the same priority) in the region and in each chunk iterating over all the filters. If the migration fails, the code tries to migrate the filters back to the old region. However, the rollback itself can also fail in which case another migration will be erroneously performed. Besides the fact that this ping pong is not a very good idea, it also creates a problem. Each virtual chunk references two chunks: The currently used one ('vchunk-&gt;chunk') and a backup ('vchunk-&gt;chunk2'). During migration the first holds the chunk we want to migrate filters to and the second holds the chunk we are migrating filters from. The code currently assumes - but does not verify - that the backup chunk does not exist (NULL) if the currently used chunk does not reference the target region. This assumption breaks when we are trying to rollback a rollback, resulting in the backup chunk being overwritten and leaked [1]. Fix by not rolling back a failed rollback and add a warning to avoid future cases. [1] WARNING: CPU: 5 PID: 1063 at lib/parman.c:291 parman_destroy+0x17/0x20 Modules linked in: CPU: 5 PID: 1063 Comm: kworker/5:11 Tainted: G W 6.9.0-rc2-custom-00784-gc6a05c468a0b #14 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work RIP: 0010:parman_destroy+0x17/0x20 [...] Call Trace: &lt;TASK&gt; mlxsw_sp_acl_atcam_region_fini+0x19/0x60 mlxsw_sp_acl_tcam_region_destroy+0x49/0xf0 mlxsw_sp_acl_tcam_vregion_rehash_work+0x1f1/0x470 process_one_work+0x151/0x370 worker_thread+0x2cb/0x3e0 kthread+0xd0/0x100 ret_from_fork+0x34/0x50 ret_from_fork_asm+0x1a/0x30 &lt;/TASK&gt;</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35853" target="_blank">CVE-2024-35853</a><br><a href="https://git.kernel.org/stable/c/0ae8ff7b6d42e33943af462910bdcfa2ec0cb8cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/413a01886c3958d4b8aac23a3bff3d430b92093e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/617e98ba4c50f4547c9eb0946b1cfc26937d70d1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ca3f7a7b61393804c46f170743c3b839df13977" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b3fd51f684a0711504f82de510da109ae639722d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b822644fd90992ee362c5e0c8d2556efc8856c76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c6f3fa7f5a748bf6e5c4eb742686d6952f854e76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash The rehash delayed work migrates filters from one region to another according to the number of available credits. The migrated from region is destroyed at the end of the work if the number of credits is non-negative as the assumption is that this is indicative of migration being complete. This assumption is incorrect as a non-negative number of credits can also be the result of a failed migration. The destruction of a region that still has filters referencing it can result in a use-after-free [1]. Fix by not destroying the region if migration failed. [1] BUG: KASAN: slab-use-after-free in mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230 Read of size 8 at addr ffff8881735319e8 by task kworker/0:31/3858 CPU: 0 PID: 3858 Comm: kworker/0:31 Tainted: G W 6.9.0-rc2-custom-00782-gf2275c2157d8 #5 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work Call Trace: &lt;TASK&gt; dump_stack_lvl+0xc6/0x120 print_report+0xce/0x670 kasan_report+0xd7/0x110 mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230 mlxsw_sp_acl_ctcam_entry_del+0x2e/0x70 mlxsw_sp_acl_atcam_entry_del+0x81/0x210 mlxsw_sp_acl_tcam_vchunk_migrate_all+0x3cd/0xb50 mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 &lt;/TASK&gt; Allocated by task 174: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 __kmalloc+0x19c/0x360 mlxsw_sp_acl_tcam_region_create+0xdf/0x9c0 mlxsw_sp_acl_tcam_vregion_rehash_work+0x954/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 Freed by task 7: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 poison_slab_object+0x102/0x170 __kasan_slab_free+0x14/0x30 kfree+0xc1/0x290 mlxsw_sp_acl_tcam_region_destroy+0x272/0x310 mlxsw_sp_acl_tcam_vregion_rehash_work+0x731/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35854" target="_blank">CVE-2024-35854</a><br><a href="https://git.kernel.org/stable/c/311eeaa7b9e26aba5b3d57b09859f07d8e9fc049" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4c89642ca47fb620914780c7c51d8d1248201121" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/54225988889931467a9b55fdbef534079b665519" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/813e2ab753a8f8c243a39ede20c2e0adc15f3887" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a02687044e124f8ccb427cd3632124a4e1a7d7c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a429a912d6c779807f4d72a6cc0a1efaaa3613e1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e118e7ea24d1392878ef85926627c6bc640c4388" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during activity update The rule activity update delayed work periodically traverses the list of configured rules and queries their activity from the device. As part of this task it accesses the entry pointed by 'ventry-&gt;entry', but this entry can be changed concurrently by the rehash delayed work, leading to a use-after-free [1]. Fix by closing the race and perform the activity query under the 'vregion-&gt;lock' mutex. [1] BUG: KASAN: slab-use-after-free in mlxsw_sp_acl_tcam_flower_rule_activity_get+0x121/0x140 Read of size 8 at addr ffff8881054ed808 by task kworker/0:18/181 CPU: 0 PID: 181 Comm: kworker/0:18 Not tainted 6.9.0-rc2-custom-00781-gd5ab772d32f7 #2 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_rule_activity_update_work Call Trace: &lt;TASK&gt; dump_stack_lvl+0xc6/0x120 print_report+0xce/0x670 kasan_report+0xd7/0x110 mlxsw_sp_acl_tcam_flower_rule_activity_get+0x121/0x140 mlxsw_sp_acl_rule_activity_update_work+0x219/0x400 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 &lt;/TASK&gt; Allocated by task 1039: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 __kmalloc+0x19c/0x360 mlxsw_sp_acl_tcam_entry_create+0x7b/0x1f0 mlxsw_sp_acl_tcam_vchunk_migrate_all+0x30d/0xb50 mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 Freed by task 1039: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 poison_slab_object+0x102/0x170 __kasan_slab_free+0x14/0x30 kfree+0xc1/0x290 mlxsw_sp_acl_tcam_vchunk_migrate_all+0x3d7/0xb50 mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35855" target="_blank">CVE-2024-35855</a><br><a href="https://git.kernel.org/stable/c/1b73f6e4ea770410a937a8db98f77e52594d23a0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/79b5b4b18bc85b19d3a518483f9abbbe6d7b3ba4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b183b915beef818a25e3154d719ca015a1ae0770" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b996e8699da810e4c915841d6aaef761007f933a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c17976b42d546ee118ca300db559630ee96fb758" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e24d2487424779c02760ff50cd9021b8676e19ef" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/feabdac2057e863d0e140a2adf3d232eb4882db4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix double free of skb in coredump hci_devcd_append() would free the skb on error so the caller don't have to free it again otherwise it would cause the double free of skb. Reported-by : Dan Carpenter &lt;dan.carpenter@linaro.org&gt;</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35856" target="_blank">CVE-2024-35856</a><br><a href="https://git.kernel.org/stable/c/18bdb386a1a30e7a3d7732a98e45e69cf6b5710d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/80dfef128cb9f1b1ef67c0fe8c8deb4ea7ad30c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e20093c741d8da9f6390dd45d75b779861547035" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: icmp: prevent possible NULL dereferences from icmp_build_probe() First problem is a double call to __in_dev_get_rcu(), because the second one could return NULL. if (__in_dev_get_rcu(dev) &amp;&amp; __in_dev_get_rcu(dev)-&gt;ifa_list) Second problem is a read from dev-&gt;ip6_ptr with no NULL check: if (!list_empty(&amp;rcu_dereference(dev-&gt;ip6_ptr)-&gt;addr_list)) Use the correct RCU API to fix these. v2: add missing include &lt;net/addrconf.h&gt;</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35857" target="_blank">CVE-2024-35857</a><br><a href="https://git.kernel.org/stable/c/23b7ee4a8d559bf38eac7ce5bb2f6ebf76f9c401" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3e2979bf080c40da4f7c93aff8575ab8bc62b767" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/599c9ad5e1d43f5c12d869f5fd406ba5d8c55270" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c58e88d49097bd12dfcfef4f075b43f5d5830941" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d68dc711d84fdcf698e5d45308c3ddeede586350" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix memory leak when bringing down interface When bringing down the TX rings we flush the rings but forget to reclaimed the flushed packets. This leads to a memory leak since we do not free the dma mapped buffers. This also leads to tx control block corruption when bringing down the interface for power management.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35858" target="_blank">CVE-2024-35858</a><br><a href="https://git.kernel.org/stable/c/09040baf8779ad880e0e0d0ea10e57aa929ef3ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2389ad1990163d29cba5480d693b4c2e31cc545c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9f898fc2c31fbf0ac5ecd289f528a716464cb005" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: block: fix module reference leakage from bdev_open_by_dev error path At the time bdev_may_open() is called, module reference is grabbed already, hence module reference should be released if bdev_may_open() failed. This problem is found by code review.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35859" target="_blank">CVE-2024-35859</a><br><a href="https://git.kernel.org/stable/c/0e9327c67410b129bf85e5c3a5aaea518328636f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9617cd6f24b294552a817f80f5225431ef67b540" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4367" target="_blank">CVE-2024-4367</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893645" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4764" target="_blank">CVE-2024-4764</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1879093" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4765" target="_blank">CVE-2024-4765</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1871109" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have lead to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4766" target="_blank">CVE-2024-4766</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1871214" target="_blank">security@mozilla.org</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1871217" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4767" target="_blank">CVE-2024-4767</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1878577" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4768" target="_blank">CVE-2024-4768</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1886082" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4769" target="_blank">CVE-2024-4769</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1886108" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4770" target="_blank">CVE-2024-4770</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893270" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4771" target="_blank">CVE-2024-4771</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893891" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4772" target="_blank">CVE-2024-4772</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1870579" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4773" target="_blank">CVE-2024-4773</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1875248" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4774" target="_blank">CVE-2024-4774</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1886598" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4775" target="_blank">CVE-2024-4775</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1887332" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4776" target="_blank">CVE-2024-4776</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1887343" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4777" target="_blank">CVE-2024-4777</a><br><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=1878199%2C1893340" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4778" target="_blank">CVE-2024-4778</a><br><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=1838834%2C1889291%2C1889595%2C1890204%2C1891545" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Focus for iOS<br> </td>
<td>The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This vulnerability affects Focus for iOS &lt; 126.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5022" target="_blank">CVE-2024-5022</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1874560" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-24/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>NEC Platforms, Ltd--ITK-6DGS-1(BK) TEL<br> </td>
<td>NEC Platforms DT900 and DT900S Series 5.0.0.0 - v5.3.4.4, v5.4.0.0 - v5.6.0.20 allows an attacker to access a non-documented the system settings to change settings via local network with unauthenticated user.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3016" target="_blank">CVE-2024-3016</a><br><a href="https://jpn.nec.com/security-info/secinfo/nv24-002_en.html" target="_blank">psirt-info@cyber.jp.nec.com</a></td>
</tr>
<tr>
<td>Netflix--ConsoleMe<br> </td>
<td>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5023" target="_blank">CVE-2024-5023</a><br><a href="https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2024-002.md" target="_blank">security-report@netflix.com</a></td>
</tr>
<tr>
<td>OpenSSL--OpenSSL<br> </td>
<td>Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The functions EVP_PKEY_param_check() or EVP_PKEY_public_check() perform various checks on DSA parameters. Some of those computations take a long time if the modulus (`p` parameter) is too large. Trying to use a very large modulus is slow and OpenSSL will not allow using public keys with a modulus which is over 10,000 bits in length for signature verification. However the key and parameter check functions do not limit the modulus size when performing the checks. An application that calls EVP_PKEY_param_check() or EVP_PKEY_public_check() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a Denial of Service attack. These functions are not called by OpenSSL itself on untrusted DSA keys so only applications that directly call these functions may be vulnerable. Also vulnerable are the OpenSSL pkey and pkeyparam command line applications when using the `-check` option. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4603" target="_blank">CVE-2024-4603</a><br><a href="https://github.com/openssl/openssl/commit/3559e868e58005d15c6013a0c1fd832e51c73397" target="_blank">openssl-security@openssl.org</a><br><a href="https://github.com/openssl/openssl/commit/53ea06486d296b890d565fb971b2764fcd826e7e" target="_blank">openssl-security@openssl.org</a><br><a href="https://github.com/openssl/openssl/commit/9c39b3858091c152f52513c066ff2c5a47969f0d" target="_blank">openssl-security@openssl.org</a><br><a href="https://github.com/openssl/openssl/commit/da343d0605c826ef197aceedc67e8e04f065f740" target="_blank">openssl-security@openssl.org</a><br><a href="https://www.openssl.org/news/secadv/20240516.txt" target="_blank">openssl-security@openssl.org</a></td>
</tr>
<tr>
<td>Puneeth Reddy--Online Shopping System Advanced<br> </td>
<td>Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. </td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3579" target="_blank">CVE-2024-3579</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-3579" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-3579" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Rockwell Automation--FactoryTalk Remote Access<br> </td>
<td>An unquoted executable path exists in the Rockwell Automation FactoryTalkÂ® Remote Accessâ„¢ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3640" target="_blank">CVE-2024-3640</a><br><a href="https://www.rockwellautomation.com/en-us/support/advisory.SD1671.html" target="_blank">PSIRT@rockwellautomation.com</a></td>
</tr>
<tr>
<td>Rockwell Automation--FactoryTalk View SE<br> </td>
<td>A vulnerability exists in the Rockwell Automation FactoryTalkÂ® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure, revealing sensitive information. Additionally, a threat actor could potentially modify and delete the data in a remote database. An attack would only affect the HMI design time, not runtime.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4609" target="_blank">CVE-2024-4609</a><br><a href="https://www.rockwellautomation.com/en-us/support/advisory.SD1670.html" target="_blank">PSIRT@rockwellautomation.com</a></td>
</tr>
<tr>
<td>The Document Foundation--LibreOffice<br> </td>
<td>Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3044" target="_blank">CVE-2024-3044</a><br><a href="https://www.libreoffice.org/about-us/security/advisories/CVE-2024-3044" target="_blank">security@documentfoundation.org</a></td>
</tr>
<tr>
<td>Unknown--Add Custom CSS and JS<br> </td>
<td>The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in as author and above add Stored XSS payloads via a CSRF attack</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3903" target="_blank">CVE-2024-3903</a><br><a href="https://wpscan.com/vulnerability/0a0e7bd4-948d-47c9-9219-380bda9f3034/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Base64 Encoder/Decoder<br> </td>
<td>The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3822" target="_blank">CVE-2024-3822</a><br><a href="https://wpscan.com/vulnerability/ff5411b1-9e04-4e72-a502-e431d774642a/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Base64 Encoder/Decoder<br> </td>
<td>The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3823" target="_blank">CVE-2024-3823</a><br><a href="https://wpscan.com/vulnerability/a138215c-4b8c-4182-978f-d21ce25070d3/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Base64 Encoder/Decoder<br> </td>
<td>The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3824" target="_blank">CVE-2024-3824</a><br><a href="https://wpscan.com/vulnerability/749ae334-b1d1-421e-a04c-35464c961a4a/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--HL Twitter<br> </td>
<td>The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3629" target="_blank">CVE-2024-3629</a><br><a href="https://wpscan.com/vulnerability/c1f6ed2c-0f84-4b13-b39e-5cb91443c2b1/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--HL Twitter<br> </td>
<td>The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3630" target="_blank">CVE-2024-3630</a><br><a href="https://wpscan.com/vulnerability/cbab7639-fdb2-4ee5-b5ca-9e30701a63b7/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--HL Twitter<br> </td>
<td>The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3631" target="_blank">CVE-2024-3631</a><br><a href="https://wpscan.com/vulnerability/c59a8b49-6f3e-452b-ba9b-50b80c522ee9/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--LetterPress <br> </td>
<td>The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3590" target="_blank">CVE-2024-3590</a><br><a href="https://wpscan.com/vulnerability/829f4d40-e5b0-4009-b753-85ca2a5b3d25/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3641" target="_blank">CVE-2024-3641</a><br><a href="https://wpscan.com/vulnerability/f4047f1e-d5ea-425f-8def-76dd5e6a497e/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3642" target="_blank">CVE-2024-3642</a><br><a href="https://wpscan.com/vulnerability/dc44d85f-afe8-4824-95b0-11b9abfb04d8/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3643" target="_blank">CVE-2024-3643</a><br><a href="https://wpscan.com/vulnerability/698277e6-56f9-4688-9a84-c2fa3ea9f7dc/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3644" target="_blank">CVE-2024-3644</a><br><a href="https://wpscan.com/vulnerability/10eb712a-d9c3-46c9-be6a-02811396fae8/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--NextGEN Gallery <br> </td>
<td>The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2744" target="_blank">CVE-2024-2744</a><br><a href="https://wpscan.com/vulnerability/a5579c15-50ba-4618-95e4-04b2033d721f/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Popup4Phone<br> </td>
<td>The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3231" target="_blank">CVE-2024-3231</a><br><a href="https://wpscan.com/vulnerability/81dbb5c0-ccdd-4af1-b2f2-71cb1b37fe93/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Popup4Phone<br> </td>
<td>The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3580" target="_blank">CVE-2024-3580</a><br><a href="https://wpscan.com/vulnerability/31f401c4-735a-4efb-b81f-ab98c00c526b/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Post Grid Gutenberg Blocks and WordPress Blog Plugin <br> </td>
<td>The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3239" target="_blank">CVE-2024-3239</a><br><a href="https://wpscan.com/vulnerability/dfa1421b-41b0-4b25-95ef-0843103e1f5e/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--SP Project &amp; Document Manager<br> </td>
<td>The SP Project &amp; Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3748" target="_blank">CVE-2024-3748</a><br><a href="https://wpscan.com/vulnerability/01427cfb-5c51-4524-9b9d-e09a603bc34c/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--SP Project &amp; Document Manager<br> </td>
<td>The SP Project &amp; Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3749" target="_blank">CVE-2024-3749</a><br><a href="https://wpscan.com/vulnerability/d14bb16e-ce1d-4c31-8791-bc63174897c0/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Save as PDF Plugin by Pdfcrowd<br> </td>
<td>The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5971" target="_blank">CVE-2023-5971</a><br><a href="https://wpscan.com/vulnerability/03a201d2-535e-4574-afac-791dcf23e6e1/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Ultimate Blocks <br> </td>
<td>The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3241" target="_blank">CVE-2024-3241</a><br><a href="https://wpscan.com/vulnerability/a645daee-42ea-43f8-9480-ef3be69606e0/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--UnGallery<br> </td>
<td>The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3582" target="_blank">CVE-2024-3582</a><br><a href="https://wpscan.com/vulnerability/5a348b5d-13aa-40c3-9d21-0554683f8019/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--VikBooking Hotel Booking Engine &amp; PMS<br> </td>
<td>The VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2441" target="_blank">CVE-2024-2441</a><br><a href="https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--VikBooking Hotel Booking Engine &amp; PMS<br> </td>
<td>The VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8 configurations.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2749" target="_blank">CVE-2024-2749</a><br><a href="https://wpscan.com/vulnerability/c0640d3a-80b3-4cad-a3cf-fb5d86558e91/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Prayer<br> </td>
<td>The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3405" target="_blank">CVE-2024-3405</a><br><a href="https://wpscan.com/vulnerability/6968d43c-16ff-43a9-8451-71aabbe69014/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Prayer<br> </td>
<td>The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3406" target="_blank">CVE-2024-3406</a><br><a href="https://wpscan.com/vulnerability/1bfab060-64d2-4c38-8bc8-a8f81c5a6e0d/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Prayer<br> </td>
<td>The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3407" target="_blank">CVE-2024-3407</a><br><a href="https://wpscan.com/vulnerability/262348ab-a335-4acf-8e4d-229fc0b4972f/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Shortcodes Plugin Shortcodes Ultimate<br> </td>
<td>The WP Shortcodes Plugin - Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3548" target="_blank">CVE-2024-3548</a><br><a href="https://wpscan.com/vulnerability/9eef8b29-2c62-4daa-ae90-467ff9be18d8/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--month name translation benaceur<br> </td>
<td>The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3634" target="_blank">CVE-2024-3634</a><br><a href="https://wpscan.com/vulnerability/76e000e0-314f-4e39-8871-68bf8cc95b22/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--reCAPTCHA Jetpack<br> </td>
<td>The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3940" target="_blank">CVE-2024-3940</a><br><a href="https://wpscan.com/vulnerability/bb0245e5-8e94-4f11-9003-d6208945056c/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--reCAPTCHA Jetpack<br> </td>
<td>The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3941" target="_blank">CVE-2024-3941</a><br><a href="https://wpscan.com/vulnerability/6e09e922-983c-4406-8053-747d839995d1/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--socialdriver-framework<br> </td>
<td>The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2697" target="_blank">CVE-2024-2697</a><br><a href="https://wpscan.com/vulnerability/c430b30d-61db-45f5-8499-91b491503b9c/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Veeam--Service Provider Console<br> </td>
<td>Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29212" target="_blank">CVE-2024-29212</a><br><a href="https://www.veeam.com/kb4575" target="_blank">support@hackerone.com</a></td>
</tr>
<tr>
<td>Xen--Xen<br> </td>
<td>Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to pass 32-bit-mode hypercall arguments to values outside of the range 32-bit code would be able to set them to. When processing of hypercalls takes a considerable amount of time, the hypervisor may choose to invoke a hypercall continuation. Doing so involves putting (perhaps updated) hypercall arguments in respective registers. For guests not running in 64-bit mode this further involves a certain amount of translation of the values. Unfortunately internal sanity checking of these translated values assumes high halves of registers to always be clear when invoking a hypercall. When this is found not to be the case, it triggers a consistency check in the hypervisor and causes a crash.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46842" target="_blank">CVE-2023-46842</a><br><a href="https://xenbits.xenproject.org/xsa/advisory-454.html" target="_blank">security@xen.org</a></td>
</tr>
<tr>
<td>Xen--Xen<br> </td>
<td>Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31142" target="_blank">CVE-2024-31142</a><br><a href="https://xenbits.xenproject.org/xsa/advisory-455.html" target="_blank">security@xen.org</a></td>
</tr>
<tr>
<td>Xpdf--Xpdf<br> </td>
<td>Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4976" target="_blank">CVE-2024-4976</a><br><a href="https://www.xpdfreader.com/security-bug/CVE-2024-4976.html" target="_blank">xpdf@xpdfreader.com</a></td>
</tr>
<tr>
<td>alpitronic--Hypercharger EV Charger<br> </td>
<td>If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administrator.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4622" target="_blank">CVE-2024-4622</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-130-02" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>berriai--berriai/litellm<br> </td>
<td>A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when using the `eval` function unsafely in the `litellm.get_secret()` method. Specifically, when the server utilizes Google KMS, untrusted data is passed to the `eval` function without any sanitization. Attackers can exploit this vulnerability by injecting malicious values into environment variables through the `/config/update` endpoint, which allows for the update of settings in `proxy_server_config.yaml`.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4264" target="_blank">CVE-2024-4264</a><br><a href="https://huntr.com/bounties/a3221b0c-6e25-4295-ab0f-042997e8fc61" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>gaizhenbiao--gaizhenbiao/chuanhuchatgpt<br> </td>
<td>A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper input validation when handling file paths during the chat history upload process. An attacker can exploit this vulnerability by intercepting requests and manipulating the 'name' parameter to specify arbitrary file paths. This allows the attacker to read sensitive files on the server, leading to information leakage, including API keys and private information. The issue affects version 20240310 of the application.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4321" target="_blank">CVE-2024-4321</a><br><a href="https://huntr.com/bounties/19a16f8e-3d92-498f-abc9-8686005f067e" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>imartinez--imartinez/privategpt<br> </td>
<td>imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload functionality to ingest arbitrary local files, attackers can exploit the 'Search in Docs' feature or query the AI to retrieve or disclose the contents of any file on the system. This vulnerability could lead to various impacts, including but not limited to remote code execution by obtaining private SSH keys, unauthorized access to private files, source code disclosure facilitating further attacks, and exposure of configuration files.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3403" target="_blank">CVE-2024-3403</a><br><a href="https://huntr.com/bounties/7431d1dd-f014-4d4f-acb6-f97369ef3688" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>imartinez--imartinez/privategpt<br> </td>
<td>A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the context of the victim's session when accessed. This could lead to the execution of arbitrary JavaScript code in the context of the user's browser session, potentially resulting in phishing attacks or other malicious actions. The vulnerability affects the latest version of the repository.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3851" target="_blank">CVE-2024-3851</a><br><a href="https://huntr.com/bounties/cae1a492-4e09-4d56-8e11-17703bdfe653" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>mlflow--mlflow/mlflow<br> </td>
<td>A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipping validation. This allows an attacker to construct a URL that, when processed, ignores the protocol scheme and uses the provided path for filesystem access. As a result, an attacker can read arbitrary files, including sensitive information such as SSH and cloud keys, by exploiting the way the application converts the URL into a filesystem path. The issue stems from insufficient validation of the fragment portion of the URL, leading to arbitrary file read through path traversal.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3848" target="_blank">CVE-2024-3848</a><br><a href="https://github.com/mlflow/mlflow/commit/f8d51e21523238280ebcfdb378612afd7844eca8" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/8d5aadaa-522f-4839-b41b-d7da362dd610" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>mlflow--mlflow/mlflow<br> </td>
<td>A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any artifacts. This issue arises due to the lack of proper validation for DELETE requests by users with EDIT permissions, allowing them to perform unauthorized deletions of artifacts. The vulnerability specifically affects the handling of artifact deletions within the application, as demonstrated by the ability of a low privilege user to delete a directory inside an artifact using a DELETE request, despite the official documentation stating that users with EDIT permission can only read and update artifacts, not delete them.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4263" target="_blank">CVE-2024-4263</a><br><a href="https://github.com/mlflow/mlflow/commit/b43e0e3de5b500554e13dc032ba2083b2d6c94b8" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/bfa116d3-2af8-4c4a-ac34-ccde7491ae11" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2020-18305" target="_blank">CVE-2020-18305</a><br><a href="https://gist.github.com/yasinyilmaz/1fe3fe58dd275edb77dcbe890fce2f2c" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-28132" target="_blank">CVE-2022-28132</a><br><a href="https://www.exploit-db.com/exploits/50939" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32502" target="_blank">CVE-2022-32502</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32503" target="_blank">CVE-2022-32503</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart Lock 3.0 before 3.3.5 and 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32504" target="_blank">CVE-2022-32504</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the functionality and reboot the device. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32505" target="_blank">CVE-2022-32505</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features to control the execution of code on the processor and debug the firmware, as well as read or alter the content of the internal and external flash memory. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Smart Lock 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32506" target="_blank">CVE-2022-32506</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32507" target="_blank">CVE-2022-32507</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the device. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32508" target="_blank">CVE-2022-32508</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Bridge v1 before 1.22.0 and Nuki Bridge v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32509" target="_blank">CVE-2022-32509</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32510" target="_blank">CVE-2022-32510</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24203" target="_blank">CVE-2023-24203</a><br><a href="https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204" target="_blank">cve@mitre.org</a><br><a href="https://momonguyen.com/2023/cve-2023-24203/" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24204" target="_blank">CVE-2023-24204</a><br><a href="https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204" target="_blank">cve@mitre.org</a><br><a href="https://momonguyen.com/2023/cve-2023-24203/" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26566" target="_blank">CVE-2023-26566</a><br><a href="https://qsecure.com.cy/resources/advisories/sangoma-freepbx-linux-hardcoded-credentials" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-29881" target="_blank">CVE-2023-29881</a><br><a href="https://gist.github.com/Northind/97522a49ae4bb0c8e6e2a49e75fd637a" target="_blank">cve@mitre.org</a><br><a href="https://github.com/qinggan/phpok/issues/15" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40297" target="_blank">CVE-2023-40297</a><br><a href="https://github.com/sahar042/CVE-2023-40297" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46870" target="_blank">CVE-2023-46870</a><br><a href="https://github.com/Chapoly1305/CVE-2023-46870" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through the tac_plus.cfg configuration file. These are executed when a client sends an authorization request with a username that has pre-authorization directives configured. However, it is possible to inject additional commands into these checks because strings from TACACS+ packets are used as command-line arguments. If the installation lacks a a pre-shared secret (there is no pre-shared secret by default), then the injection can be triggered without authentication. (The attacker needs to know a username configured to use a pre-authorization command.) NOTE: this is related to CVE-2023-45239 but the issue is in the original Shrubbery product, not Meta's fork.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48643" target="_blank">CVE-2023-48643</a><br><a href="https://github.com/takeshixx/tac_plus-pre-auth-rce" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52424" target="_blank">CVE-2023-52424</a><br><a href="https://mentor.ieee.org/802.11/dcn/24/11-24-0938-03-000m-protect-ssid-in-4-way-handshake.docx" target="_blank">cve@mitre.org</a><br><a href="https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf" target="_blank">cve@mitre.org</a><br><a href="https://www.top10vpn.com/research/wifi-vulnerability-ssid/" target="_blank">cve@mitre.org</a><br><a href="https://www.wi-fi.org/news-events/press-releases" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22774" target="_blank">CVE-2024-22774</a><br><a href="https://blueteamalpha.com/blog/new-vulnerability-discovered-in-panoramic-x-ray-software/" target="_blank">cve@mitre.org</a><br><a href="https://github.com/Gray-0men/CVE-2024-22774" target="_blank">cve@mitre.org</a><br><a href="https://pancorp.com/index.html" target="_blank">cve@mitre.org</a><br><a href="https://pancorp.com/pdf/Panoramic-Dental-Imaging-%28GLAN%29-Windows-10x64-Setup-Rev3.pdf" target="_blank">cve@mitre.org</a><br><a href="https://pancorp.com/software/files/PANCORP_DENTAL_IMAGING_9.1.2.7600.exe" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22910" target="_blank">CVE-2024-22910</a><br><a href="https://gist.github.com/cgnl/672ace3cbad1116fcd9ae633e54ea9f8" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24157" target="_blank">CVE-2024-24157</a><br><a href="https://github.com/gnuboard/g6/issues/314" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25078" target="_blank">CVE-2024-25078</a><br><a href="https://www.insyde.com/security-pledge" target="_blank">cve@mitre.org</a><br><a href="https://www.insyde.com/security-pledge/SA-2024001" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25079" target="_blank">CVE-2024-25079</a><br><a href="https://www.insyde.com/security-pledge" target="_blank">cve@mitre.org</a><br><a href="https://www.insyde.com/security-pledge/SA-2024001" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting (XSS) for malicious URLs.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25662" target="_blank">CVE-2024-25662</a><br><a href="https://www.oxygenxml.com/security/advisory/SYNC-2024-020601.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25742" target="_blank">CVE-2024-25742</a><br><a href="https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.9" target="_blank">cve@mitre.org</a><br><a href="https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e3ef461af35a8c74f2f4ce6616491ddb355a208f" target="_blank">cve@mitre.org</a><br><a href="https://github.com/torvalds/linux/commit/e3ef461af35a8c74f2f4ce6616491ddb355a208f" target="_blank">cve@mitre.org</a><br><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25743" target="_blank">CVE-2024-25743</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2270836" target="_blank">cve@mitre.org</a><br><a href="https://bugzilla.suse.com/show_bug.cgi?id=1223307" target="_blank">cve@mitre.org</a><br><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26306" target="_blank">CVE-2024-26306</a><br><a href="https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.asc" target="_blank">cve@mitre.org</a><br><a href="https://github.com/esnet/iperf/releases/tag/3.17" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26367" target="_blank">CVE-2024-26367</a><br><a href="http://cc.com/" target="_blank">cve@mitre.org</a><br><a href="http://evertz.com/" target="_blank">cve@mitre.org</a><br><a href="https://wiki.notveg.ninja/blog/CVE-2024-26367/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26517" target="_blank">CVE-2024-26517</a><br><a href="https://github.com/unrealjbr/CVE-2024-26517" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/php/16877/school-task-manager-using-php-source-code.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27280" target="_blank">CVE-2024-27280</a><br><a href="https://hackerone.com/reports/1399856" target="_blank">cve@mitre.org</a><br><a href="https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27281" target="_blank">CVE-2024-27281</a><br><a href="https://hackerone.com/reports/1187477" target="_blank">cve@mitre.org</a><br><a href="https://www.ruby-lang.org/en/news/2024/03/21/rce-rdoc-cve-2024-27281/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27282" target="_blank">CVE-2024-27282</a><br><a href="https://hackerone.com/reports/2122624" target="_blank">cve@mitre.org</a><br><a href="https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27353" target="_blank">CVE-2024-27353</a><br><a href="https://www.insyde.com/security-pledge" target="_blank">cve@mitre.org</a><br><a href="https://www.insyde.com/security-pledge/SA-2024001" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27593" target="_blank">CVE-2024-27593</a><br><a href="https://blog.smarttecs.com/posts/2024-002-cve-2024-27593/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28063" target="_blank">CVE-2024-28063</a><br><a href="https://www.objectif-securite.ch/advisories/totemomail-reflected-xss.txt" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with displayLoginChunkedImages) and write operations (with storeLoginChunkedImages).</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28064" target="_blank">CVE-2024-28064</a><br><a href="https://www.objectif-securite.ch/advisories/totemomail-path-traversal.txt" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28087" target="_blank">CVE-2024-28087</a><br><a href="https://documentation.bonitasoft.com/bonita/latest/release-notes#_fixes_in_bonita_2024_1_2024_04_11" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28276" target="_blank">CVE-2024-28276</a><br><a href="https://github.com/unrealjbr/CVE-2024-28276" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/download-code?nid=16877&amp;title=School+Task+Manager+Using+PHP+with+Source+Code" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28277" target="_blank">CVE-2024-28277</a><br><a href="https://github.com/unrealjbr/CVE-2024-28277" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/download-code?nid=16877&amp;title=School+Task+Manager+Using+PHP+with+Source+Code" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28279" target="_blank">CVE-2024-28279</a><br><a href="https://code-projects.org/computer-book-store-in-php-with-source-code/" target="_blank">cve@mitre.org</a><br><a href="https://github.com/unrealjbr/CVE-2024-28279" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28285" target="_blank">CVE-2024-28285</a><br><a href="https://gist.github.com/liang-junkai/3e91f58070812ea76c1b8c126c3e28c7" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29157" target="_blank">CVE-2024-29157</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29158" target="_blank">CVE-2024-29158</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29159" target="_blank">CVE-2024-29159</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29160" target="_blank">CVE-2024-29160</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29161" target="_blank">CVE-2024-29161</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29162" target="_blank">CVE-2024-29162</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29163" target="_blank">CVE-2024-29163</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29164" target="_blank">CVE-2024-29164</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29165" target="_blank">CVE-2024-29165</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29166" target="_blank">CVE-2024-29166</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29513" target="_blank">CVE-2024-29513</a><br><a href="https://github.com/dru1d-foofus/briscKernelDriver" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29857" target="_blank">CVE-2024-29857</a><br><a href="https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857" target="_blank">cve@mitre.org</a><br><a href="https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857" target="_blank">cve@mitre.org</a><br><a href="https://www.bouncycastle.org/latest_releases.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30171" target="_blank">CVE-2024-30171</a><br><a href="https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9030171" target="_blank">cve@mitre.org</a><br><a href="https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030171" target="_blank">cve@mitre.org</a><br><a href="https://www.bouncycastle.org/latest_releases.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30172" target="_blank">CVE-2024-30172</a><br><a href="https://www.bouncycastle.org/latest_releases.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30801" target="_blank">CVE-2024-30801</a><br><a href="http://cloud.com/" target="_blank">cve@mitre.org</a><br><a href="http://www.minipacs.com/ylqxrj" target="_blank">cve@mitre.org</a><br><a href="https://github.com/WarmBrew/web_vul/blob/main/Cloud%20based%20customer%20service/SQLi.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30802" target="_blank">CVE-2024-30802</a><br><a href="https://github.com/WarmBrew/web_vul/blob/main/TTX.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31556" target="_blank">CVE-2024-31556</a><br><a href="https://github.com/reportico-web/reportico/issues/53" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31771" target="_blank">CVE-2024-31771</a><br><a href="https://github.com/restdone/CVE-2024-31771" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT&lt;T&gt;::read_pre_data128_from_file function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31803" target="_blank">CVE-2024-31803</a><br><a href="https://github.com/FudanMPL/Vulnerabilities-in-MPC-Framework/tree/main/emp-ot/stack-buffer-overflow-ferret_cot" target="_blank">cve@mitre.org</a><br><a href="https://github.com/emp-toolkit/emp-ot/issues/89" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31810" target="_blank">CVE-2024-31810</a><br><a href="https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/HardCode/HardCode.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The com.solarized.firedown (aka Solarized FireDown Browser &amp; Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31974" target="_blank">CVE-2024-31974</a><br><a href="https://github.com/actuator/com.solarized.firedown/blob/main/CVE-2024-31974" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32349" target="_blank">CVE-2024-32349</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32350" target="_blank">CVE-2024-32350</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32351" target="_blank">CVE-2024-32351</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32352" target="_blank">CVE-2024-32352</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32353" target="_blank">CVE-2024-32353</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32354" target="_blank">CVE-2024-32354</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32355" target="_blank">CVE-2024-32355</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32605" target="_blank">CVE-2024-32605</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32606" target="_blank">CVE-2024-32606</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32607" target="_blank">CVE-2024-32607</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32609" target="_blank">CVE-2024-32609</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32610" target="_blank">CVE-2024-32610</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32611" target="_blank">CVE-2024-32611</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32612" target="_blank">CVE-2024-32612</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32613" target="_blank">CVE-2024-32613</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32614" target="_blank">CVE-2024-32614</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32615" target="_blank">CVE-2024-32615</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32616" target="_blank">CVE-2024-32616</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32617" target="_blank">CVE-2024-32617</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32618" target="_blank">CVE-2024-32618</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32619" target="_blank">CVE-2024-32619</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32620" target="_blank">CVE-2024-32620</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32621" target="_blank">CVE-2024-32621</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32622" target="_blank">CVE-2024-32622</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32623" target="_blank">CVE-2024-32623</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32624" target="_blank">CVE-2024-32624</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33250" target="_blank">CVE-2024-33250</a><br><a href="https://github.com/hacker2004/cccccckkkkkk/blob/main/CVE-2024-33250.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33263" target="_blank">CVE-2024-33263</a><br><a href="https://github.com/bellard/quickjs/issues/277" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33433" target="_blank">CVE-2024-33433</a><br><a href="https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/X2000R/XSS_2_Guest_Access_Control/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33454" target="_blank">CVE-2024-33454</a><br><a href="https://gist.github.com/Zakary-D/30f565c4266c02c62aa9089c363e78e9" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33485" target="_blank">CVE-2024-33485</a><br><a href="https://github.com/CveSecLook/cve/issues/17" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33771" target="_blank">CVE-2024-33771</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "curTime."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33772" target="_blank">CVE-2024-33772</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33773" target="_blank">CVE-2024-33773</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33774" target="_blank">CVE-2024-33774</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33818" target="_blank">CVE-2024-33818</a><br><a href="https://medium.com/%40rajput.thakur/insecure-direct-object-references-cve-2024-33818-86785aa8c969" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33819" target="_blank">CVE-2024-33819</a><br><a href="https://medium.com/%40rajput.thakur/speechlog-v-8-1-stored-cross-site-scripting-cve-2024-33819-1b1164fb0ecd" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33863" target="_blank">CVE-2024-33863</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33864" target="_blank">CVE-2024-33864</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33865" target="_blank">CVE-2024-33865</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33866" target="_blank">CVE-2024-33866</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33867" target="_blank">CVE-2024-33867</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33868" target="_blank">CVE-2024-33868</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33873" target="_blank">CVE-2024-33873</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33874" target="_blank">CVE-2024-33874</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33875" target="_blank">CVE-2024-33875</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33876" target="_blank">CVE-2024-33876</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33877" target="_blank">CVE-2024-33877</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message).</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34058" target="_blank">CVE-2024-34058</a><br><a href="https://www.openwall.com/lists/oss-security/2024/05/16/3" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files via a crafted request.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34191" target="_blank">CVE-2024-34191</a><br><a href="https://chmod744.super.site/htmly-cve" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa" program allows attackers to modify the value of the "vwlan_idx" field via "formMultiAP". This can lead to a stack overflow through the "formWlEncrypt" CGI function by constructing malicious HTTP requests and passing a WLAN SSID value exceeding the expected length, potentially resulting in command execution or denial of service attacks.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34196" target="_blank">CVE-2024-34196</a><br><a href="https://gist.github.com/Swind1er/1ec2fde42254598a72f1d716f9cfe2a1" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34199" target="_blank">CVE-2024-34199</a><br><a href="https://github.com/DMCERTCE/PoC_Tiny_Overflow" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34200" target="_blank">CVE-2024-34200</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setIpQosRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34201" target="_blank">CVE-2024-34201</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/getSaveConfig" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34202" target="_blank">CVE-2024-34202</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setMacFilterRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34203" target="_blank">CVE-2024-34203</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setLanguageCfg" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34204" target="_blank">CVE-2024-34204</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setUpgradeFW" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34205" target="_blank">CVE-2024-34205</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/download_firmware" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34206" target="_blank">CVE-2024-34206</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setWebWlanIdx" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34207" target="_blank">CVE-2024-34207</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setStaticDhcpConfig" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34209" target="_blank">CVE-2024-34209</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setIpPortFilterRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34210" target="_blank">CVE-2024-34210</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/CloudACMunualUpdate_injection" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34211" target="_blank">CVE-2024-34211</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/HardCodeRoot" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34212" target="_blank">CVE-2024-34212</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/CloudACMunualUpdate_overflow" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34213" target="_blank">CVE-2024-34213</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/SetPortForwardRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34215" target="_blank">CVE-2024-34215</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/SetUrlFilterRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34217" target="_blank">CVE-2024-34217</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/addWlProfileClientMode" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34218" target="_blank">CVE-2024-34218</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/NTPSyncWithHost" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34219" target="_blank">CVE-2024-34219</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/SetTelnetCfg" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34220" target="_blank">CVE-2024-34220</a><br><a href="https://github.com/dovankha/CVE-2024-34220" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34221" target="_blank">CVE-2024-34221</a><br><a href="https://github.com/dovankha/CVE-2024-34221" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34222" target="_blank">CVE-2024-34222</a><br><a href="https://github.com/dovankha/CVE-2024-34222" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34223" target="_blank">CVE-2024-34223</a><br><a href="https://github.com/dovankha/CVE-2024-34223" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34224" target="_blank">CVE-2024-34224</a><br><a href="https://github.com/dovankha/CVE-2024-34224" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34225" target="_blank">CVE-2024-34225</a><br><a href="https://github.com/dovankha/CVE-2024-34225" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&amp;id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34226" target="_blank">CVE-2024-34226</a><br><a href="https://github.com/dovankha/CVE-2024-34226" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34230" target="_blank">CVE-2024-34230</a><br><a href="https://github.com/Amrita2000/CVES/blob/main/CVE-2024-34230.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Short Name parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34231" target="_blank">CVE-2024-34231</a><br><a href="https://github.com/Amrita2000/CVES/blob/main/CVE-2024-34231.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34241" target="_blank">CVE-2024-34241</a><br><a href="https://grumpz.net/cve-2024-34241-a-step-by-step-discovery-guide" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34243" target="_blank">CVE-2024-34243</a><br><a href="https://github.com/JByteL/CVE/tree/main/CVE-2024-34243" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34245" target="_blank">CVE-2024-34245</a><br><a href="https://github.com/Stoocea/Vulnerability-analysis-Notes/blob/main/cms/DedeCMS-V5.7.114%20%20Arbitrary%20file%20read%20vulnerability.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34256" target="_blank">CVE-2024-34256</a><br><a href="https://github.com/ZackSecurity/VulnerReport/blob/cve/ofcms/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34273" target="_blank">CVE-2024-34273</a><br><a href="https://github.com/chrisandoryan/vuln-advisory/blob/main/nJwt/CVE-2024-34273.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34308" target="_blank">CVE-2024-34308</a><br><a href="https://github.com/s4ndw1ch136/IOT-vuln-reports/blob/main/totolink%20LR350/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34310" target="_blank">CVE-2024-34310</a><br><a href="https://github.com/3309899621/CVE-2024-34310" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A Blind command injection vulnerability in Tenda O3V2 V1.0.0.12 and earlier allows remote attackers to execute operating system commands via dest parameter in /goform/getTraceroute</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34338" target="_blank">CVE-2024-34338</a><br><a href="http://exzettabyte.me/blind-command-injection-in-tenda-o3v2" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34459" target="_blank">CVE-2024-34459</a><br><a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/720" target="_blank">cve@mitre.org</a><br><a href="https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.11.8" target="_blank">cve@mitre.org</a><br><a href="https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.7" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34582" target="_blank">CVE-2024-34582</a><br><a href="https://github.com/silent6trinity/CVE-2024-34582" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34899" target="_blank">CVE-2024-34899</a><br><a href="https://hackerdna.com/courses/cve/cve-2024-34899" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>FlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34905" target="_blank">CVE-2024-34905</a><br><a href="https://github.com/CloudWise-OpenSource/FlyFish/issues/191" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34906" target="_blank">CVE-2024-34906</a><br><a href="https://github.com/kuaifan/dootask/issues/210" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34909" target="_blank">CVE-2024-34909</a><br><a href="https://github.com/Joying-C/Cross-site-scripting-vulnerability/tree/main/KYKMS_Cross_site%20_scripting%20_vulnerability" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34913" target="_blank">CVE-2024-34913</a><br><a href="https://github.com/Joying-C/Cross-site-scripting-vulnerability/tree/main/r-pan-scaffolding_Cross_site%20_scripting%20_vulnerability" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "remember me" when logging in.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34914" target="_blank">CVE-2024-34914</a><br><a href="https://chmod744.super.site/redacted-vulnerability" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34919" target="_blank">CVE-2024-34919</a><br><a href="https://github.com/CveSecLook/cve/issues/20" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34921" target="_blank">CVE-2024-34921</a><br><a href="https://github.com/cainiao159357/x5000r_poc/blob/main/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34942" target="_blank">CVE-2024-34942</a><br><a href="https://palm-vertebra-fe9.notion.site/formexeCommand-200db77a90d34c708b903c935c7c65c0" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34943" target="_blank">CVE-2024-34943</a><br><a href="https://palm-vertebra-fe9.notion.site/fromNatStaticSetting-fae26e1bfbe64b49a46230a629b6d198" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34944" target="_blank">CVE-2024-34944</a><br><a href="https://www.tendacn.com/hk/download/detail-2344.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34945" target="_blank">CVE-2024-34945</a><br><a href="https://palm-vertebra-fe9.notion.site/fromWizardHandle-98e188c072984620a907ea5df0d80ad5" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34946" target="_blank">CVE-2024-34946</a><br><a href="https://palm-vertebra-fe9.notion.site/fromDhcpListClient_page-c9ee71f670534555a5ef2d99320da48e" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34950" target="_blank">CVE-2024-34950</a><br><a href="https://dear-sunshine-ba5.notion.site/D-Link-DIR-822-v1-0-5-Stack-Overflow-e77ff3d9c31f4a98bfa0fa71eca54000" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34954" target="_blank">CVE-2024-34954</a><br><a href="https://github.com/ethicalhackerNL/CVEs/blob/main/Budget%20Management/XSS/XSS.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34955" target="_blank">CVE-2024-34955</a><br><a href="https://github.com/ethicalhackerNL/CVEs/blob/main/Budget%20Management/SQLi.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34957" target="_blank">CVE-2024-34957</a><br><a href="https://github.com/Gr-1m/cms/blob/main/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34958" target="_blank">CVE-2024-34958</a><br><a href="https://github.com/Gr-1m/cms/blob/main/2.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34959" target="_blank">CVE-2024-34959</a><br><a href="https://gitee.com/upgogo/s123/issues/I9MARO" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34974" target="_blank">CVE-2024-34974</a><br><a href="https://github.com/hunzi0/Vullnfo/tree/main/Tenda/AC18/formSetPPTPServer" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34982" target="_blank">CVE-2024-34982</a><br><a href="https://github.com/n2ryx/CVE/blob/main/Lylme_pagev1.9.5.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34997" target="_blank">CVE-2024-34997</a><br><a href="https://github.com/joblib/joblib/issues/1582" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&amp;dataType=&amp;fieldName=state&amp;fieldName2=state&amp;tabName=banner&amp;dataID=6.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35009" target="_blank">CVE-2024-35009</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/5.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&amp;dataType=&amp;dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&amp;theme=cs&amp;dataID=6.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35010" target="_blank">CVE-2024-35010</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/6.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=rev&amp;nohrefStr=close.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35011" target="_blank">CVE-2024-35011</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/8.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=add&amp;nohrefStr=close.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35012" target="_blank">CVE-2024-35012</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/7.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35039" target="_blank">CVE-2024-35039</a><br><a href="https://github.com/ywf7678/cms/blob/main/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35048" target="_blank">CVE-2024-35048</a><br><a href="https://github.com/javahuang/SurveyKing/issues/56" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35049" target="_blank">CVE-2024-35049</a><br><a href="https://github.com/javahuang/SurveyKing/issues/55" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35050" target="_blank">CVE-2024-35050</a><br><a href="https://github.com/javahuang/SurveyKing/issues/57" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35099" target="_blank">CVE-2024-35099</a><br><a href="https://github.com/s4ndw1ch136/IOT-vuln-reports/blob/main/V9.3.5u.6698_B20230810/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalate privileges via a crafted script.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35102" target="_blank">CVE-2024-35102</a><br><a href="https://vuln2you.blogspot.com/2024/05/avediaserver-unauthorised-api-access.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mudi=del&amp;dataType=&amp;dataTypeCN.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35108" target="_blank">CVE-2024-35108</a><br><a href="https://github.com/FirstLIF/cms/blob/main/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&amp;nohrefStr=close.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35109" target="_blank">CVE-2024-35109</a><br><a href="https://github.com/FirstLIF/cms/blob/main/2.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35110" target="_blank">CVE-2024-35110</a><br><a href="https://github.com/yzmcms/yzmcms/issues/68" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Veritas System Recovery before 23.2_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users can conduct attacks.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35204" target="_blank">CVE-2024-35204</a><br><a href="https://www.veritas.com/content/support/en_US/article.100065391" target="_blank">cve@mitre.org</a><br><a href="https://www.veritas.com/support/en_US/security/VTS24-005" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through external application interactions, leading to a form of path traversal. This potentially enables any application to dispatch a crafted library file, aiming to overwrite an existing native library utilized by WPS Office. Successful exploitation could result in the execution of arbitrary commands under the guise of WPS Office's application ID.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35205" target="_blank">CVE-2024-35205</a><br><a href="https://www.microsoft.com/en-us/security/blog/2024/05/01/dirty-stream-attack-discovering-and-mitigating-a-common-vulnerability-pattern-in-android-apps/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35312" target="_blank">CVE-2024-35312</a><br><a href="https://gitlab.torproject.org/tpo/core/arti/-/issues/1409" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35313" target="_blank">CVE-2024-35313</a><br><a href="https://gitlab.torproject.org/tpo/core/arti/-/issues/1400" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36043" target="_blank">CVE-2024-36043</a><br><a href="https://github.com/surveyjs/survey-library/commit/b25fbf0efd4486dc55f836240bebc2305803b96d" target="_blank">cve@mitre.org</a><br><a href="https://github.com/surveyjs/survey-library/issues/8286" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36048" target="_blank">CVE-2024-36048</a><br><a href="https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560317" target="_blank">cve@mitre.org</a><br><a href="https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560368" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36050" target="_blank">CVE-2024-36050</a><br><a href="https://github.com/NixOS/nix/issues/969" target="_blank">cve@mitre.org</a><br><a href="https://github.com/NixOS/ofborg/issues/68#issuecomment-2082789441" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of uploaded files in the profile picture upload functionality. Attackers can exploit this vulnerability by uploading malicious HTML files containing JavaScript code, which is executed when the file is accessed. This vulnerability is remotely exploitable via Cross-Site Request Forgery (CSRF), allowing attackers to perform actions on behalf of authenticated users and potentially leading to unauthorized access to sensitive information within the Lollms-webui application.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2299" target="_blank">CVE-2024-2299</a><br><a href="https://huntr.com/bounties/f1adaac0-b9ed-4093-a0f3-2d0a4ecba398" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied input in the configuration settings, specifically within the 'extensions' parameter. Attackers can exploit this by crafting a payload that includes relative path traversal sequences ('../../../'), enabling them to navigate to arbitrary directories. This flaw subsequently allows the server to load and execute a malicious '__init__.py' file, leading to remote code execution. The issue affects the latest version of parisneo/lollms-webui.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2358" target="_blank">CVE-2024-2358</a><br><a href="https://huntr.com/bounties/b2771df3-be50-45bd-93c4-0974ce38bc22" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the `install_model()` function within `lollms_core/lollms/binding.py`, where the application fails to properly sanitize the `file://` protocol and other inputs, leading to arbitrary read and upload capabilities. Attackers can exploit this vulnerability by manipulating the `path` and `variant_name` parameters to achieve path traversal, allowing for the reading of arbitrary files and uploading files to arbitrary locations on the server. This vulnerability affects the latest version of parisneo/lollms-webui.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2361" target="_blank">CVE-2024-2361</a><br><a href="https://huntr.com/bounties/cd383817-924a-445a-838e-d0c867c6a176" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulnerability arises due to insufficient path sanitization, allowing an attacker to exploit path traversal to navigate to arbitrary directories. By manipulating the binding_path to point to a controlled directory and uploading a malicious __init__.py file, an attacker can execute arbitrary code on the server.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2366" target="_blank">CVE-2024-2366</a><br><a href="https://huntr.com/bounties/63266c77-408b-45ff-962c-8163db50a864" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lollms_xtts.py' script. The vulnerability arises due to the improper neutralization of special elements used in an OS command. The affected function utilizes 'subprocess.Popen' to execute a command constructed with a Python f-string, without adequately sanitizing the 'xtts_base_url' input. This flaw allows attackers to execute arbitrary commands remotely by manipulating the 'xtts_base_url' parameter. The vulnerability affects versions up to and including the latest version before 9.5. Successful exploitation could lead to arbitrary remote code execution (RCE) on the system where the application is deployed.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3126" target="_blank">CVE-2024-3126</a><br><a href="https://github.com/parisneo/lollms-webui/commit/41dbb1b3f2e78ea276e5269544e50514252c0c25" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/0e2bec70-826e-4c24-8015-31921e23fd12" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3435" target="_blank">CVE-2024-3435</a><br><a href="https://github.com/parisneo/lollms-webui/commit/bb99b59e710d00c4f2598faa5e183fa30fbd3bc2" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/494f349a-8650-4d30-a0bd-4742fda44ce5" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory structure and list any directory on the system. This issue affects the latest version of the application. The vulnerability is due to improper handling of user-supplied input in the `list_personalities` function, where the `category` parameter can be controlled to specify arbitrary directories for listing. Successful exploitation of this vulnerability could allow an attacker to list all folders in the drive on the system, potentially leading to information disclosure.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4322" target="_blank">CVE-2024-4322</a><br><a href="https://huntr.com/bounties/5116d858-ce00-418c-a5a5-851c5608c209" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to localhost, enabling code execution, and disabling code validation through the `/apply_settings` endpoint. Subsequently, arbitrary commands can be executed remotely via the `/execute_code` endpoint, exploiting the delay in settings enforcement. This issue was addressed in version 9.5.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4326" target="_blank">CVE-2024-4326</a><br><a href="https://github.com/parisneo/lollms-webui/commit/abb4c6d495a95a3ef5b114ffc57f85cd650b905e" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/2ab9f03d-0538-4317-be21-0748a079cbdd" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms<br> </td>
<td>A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises from the lack of path sanitization when handling the `name` parameter in the `unInstall_binding` function, allowing an attacker to traverse directories and execute arbitrary code by loading a malicious `__init__.py` file. This vulnerability affects the latest version of the software. The exploitation of this vulnerability could lead to remote code execution on the system where parisneo/lollms is deployed.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4078" target="_blank">CVE-2024-4078</a><br><a href="https://github.com/parisneo/lollms/commit/7ebe08da7e0026b155af4f7be1d6417bc64cf02f" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/a55a8c04-df44-49b2-bcfa-2a2b728a299d" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>run-llama--run-llama/llama_index<br> </td>
<td>A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromised LLM hosting provider to execute arbitrary commands on the client's machine. This issue was fixed in version 0.10.13. The exploitation of this vulnerability could lead to a hosting provider gaining full control over client machines.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4181" target="_blank">CVE-2024-4181</a><br><a href="https://github.com/run-llama/llama_index/commit/d73715eaf0642705583e7897c78b9c8dd2d3a7ba" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/1a204520-598a-434e-b13d-0d34f2a5ddc1" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>wandb--wandb/wandb<br> </td>
<td>A Server-Side Request Forgery (SSRF) vulnerability exists in the wandb/wandb repository due to improper handling of HTTP 302 redirects. This issue allows team members with access to the 'User settings -&gt; Webhooks' function to exploit this vulnerability to access internal HTTP(s) servers. In severe cases, such as on AWS instances, this could potentially be abused to achieve remote code execution on the victim's machine. The vulnerability is present in the latest version of the repository.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4642" target="_blank">CVE-2024-4642</a><br><a href="https://huntr.com/bounties/055eb540-57f8-46d6-b858-3a9e22d347d9" target="_blank">security@huntr.dev</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-1156 | NI SystemLink Server/FlexLogger RabbitMQ Service default permission]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in NI SystemLink Server and FlexLogger. Affected is an unknown function of the component RabbitMQ Service. The manipulation leads to incorrect default permissions.

This vulnerability is traded as CVE-2024-1156. Attacking locally is a r...]]></description>
<link>https://tsecurity.de/de/2062595/sicherheitsluecken/cve-2024-1156-ni-systemlink-serverflexlogger-rabbitmq-service-default-permission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2062595/sicherheitsluecken/cve-2024-1156-ni-systemlink-serverflexlogger-rabbitmq-service-default-permission/</guid>
<pubDate>Fri, 08 Mar 2024 15:53:13 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.ni:systemlink_server">NI SystemLink Server and FlexLogger</a>. Affected is an unknown function of the component <em>RabbitMQ Service</em>. The manipulation leads to incorrect default permissions.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.254208">CVE-2024-1156</a>. Attacking locally is a requirement. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-18609 | RabbitMQ 0.9.0 amqp_connection.c memcpy CONNECTION_STATE_HEADER integer overflow (USN-4214-1)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in RabbitMQ 0.9.0. This affects the function memcpy of the file amqp_connection.c. The manipulation of the argument CONNECTION_STATE_HEADER leads to integer overflow.

This vulnerability is uniquely identified as CVE-2019-18609. It is possible...]]></description>
<link>https://tsecurity.de/de/2056993/sicherheitsluecken/cve-2019-18609-rabbitmq-090-amqpconnectionc-memcpy-connectionstateheader-integer-overflow-usn-4214-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2056993/sicherheitsluecken/cve-2019-18609-rabbitmq-090-amqpconnectionc-memcpy-connectionstateheader-integer-overflow-usn-4214-1/</guid>
<pubDate>Tue, 05 Mar 2024 10:51:31 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.rabbitmq">RabbitMQ 0.9.0</a>. This affects the function <code>memcpy</code> of the file <em>amqp_connection.c</em>. The manipulation of the argument <em>CONNECTION_STATE_HEADER</em> leads to integer overflow.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.146529">CVE-2019-18609</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (knot-resolver and wpa), Fedora (chromium, kernel, thunderbird, and yarnpkg), Mageia (c-ares), Oracle (firefox, kernel, opensc, postgresql:13, postgresql:15, and thunderbird), Red Hat (edk2, gimp:2.8, and kernel), SUSE (bind, bluez, container-suseconnec...]]></description>
<link>https://tsecurity.de/de/2049548/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2049548/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 28 Feb 2024 15:43:34 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (knot-resolver and wpa), <b>Fedora</b> (chromium, kernel, thunderbird, and yarnpkg), <b>Mageia</b> (c-ares), <b>Oracle</b> (firefox, kernel, opensc, postgresql:13, postgresql:15, and thunderbird), <b>Red Hat</b> (edk2, gimp:2.8, and kernel), <b>SUSE</b> (bind, bluez, container-suseconnect, dnsdist, freerdp, gcc12, gcc7, glib2, gnutls, kernel, kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t, libqt5-qtbase, libqt5-qtsvg, nodejs18, nodejs20, openssl, openssl-1_0_0, poppler, python-crcmod, python-cryptography, python-cryptography- vectors, python-pip, python-requests, python3-requests, python311, python39, rabbitmq-c, samba, sccache, shim, SUSE Manager 4.2, SUSE Manager Server 4.2, the Linux-RT Kernel, and thunderbird), and <b>Ubuntu</b> (less, openssl, php7.0, php7.2, php7.4, and tiff).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-11291 | Pivotal RabbitMQ up to 3.7.19/3.8.0 Policy Management cross site scripting (RHSA-2020:0553)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Pivotal RabbitMQ up to 3.7.19/3.8.0. Affected is an unknown function of the component Policy Management. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2019-11291. It is possible to launch the attack...]]></description>
<link>https://tsecurity.de/de/2047061/sicherheitsluecken/cve-2019-11291-pivotal-rabbitmq-up-to-3719380-policy-management-cross-site-scripting-rhsa-20200553/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2047061/sicherheitsluecken/cve-2019-11291-pivotal-rabbitmq-up-to-3719380-policy-management-cross-site-scripting-rhsa-20200553/</guid>
<pubDate>Mon, 26 Feb 2024 15:11:05 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.pivotal:rabbitmq">Pivotal RabbitMQ up to 3.7.19/3.8.0</a>. Affected is an unknown function of the component <em>Policy Management</em>. The manipulation leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.146142">CVE-2019-11291</a>. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-11287 | Pivotal RabbitMQ up to 3.7.20/3.8.0 Web Management Plugin HTTP Header resource consumption (RHSA-2020:0078)]]></title>
<description><![CDATA[A vulnerability was found in Pivotal RabbitMQ up to 3.7.20/3.8.0. It has been rated as problematic. This issue affects some unknown processing of the component Web Management Plugin. The manipulation as part of HTTP Header leads to resource consumption.

The identification of this vulnerability i...]]></description>
<link>https://tsecurity.de/de/2046968/sicherheitsluecken/cve-2019-11287-pivotal-rabbitmq-up-to-3720380-web-management-plugin-http-header-resource-consumption-rhsa-20200078/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2046968/sicherheitsluecken/cve-2019-11287-pivotal-rabbitmq-up-to-3720380-web-management-plugin-http-header-resource-consumption-rhsa-20200078/</guid>
<pubDate>Mon, 26 Feb 2024 14:38:13 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.pivotal:rabbitmq">Pivotal RabbitMQ up to 3.7.20/3.8.0</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects some unknown processing of the component <em>Web Management Plugin</em>. The manipulation as part of <em>HTTP Header</em> leads to resource consumption.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.146141">CVE-2019-11287</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stream Processing with Python, Kafka & Faust]]></title>
<description><![CDATA[How to Stream and Apply Real-Time Prediction Models on High-Throughput Time-Series DataPhoto by JJ Ying on UnsplashMost of the stream processing libraries are not python friendly while the majority of machine learning and data mining libraries are python based. Although the Faust library aims to ...]]></description>
<link>https://tsecurity.de/de/2036578/ai-nachrichten/stream-processing-with-python-kafka-faust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2036578/ai-nachrichten/stream-processing-with-python-kafka-faust/</guid>
<pubDate>Sun, 18 Feb 2024 18:23:38 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>How to Stream and Apply Real-Time Prediction Models on High-Throughput Time-Series Data</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*f61G4hWik7GHyytI"><figcaption>Photo by <a href="https://unsplash.com/@jjying?utm_source=medium&amp;utm_medium=referral">JJ Ying</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><p>Most of the stream processing libraries are not python friendly while the majority of machine learning and data mining libraries are python based. Although the <a href="https://faust-streaming.github.io/faust/introduction.html">Faust</a> library aims to bring Kafka Streaming ideas into the Python ecosystem, it may pose challenges in terms of ease of use. This document serves as a tutorial and offers best practices for effectively utilizing Faust.</p><p>In the first section, I present an introductory overview of stream processing concepts, drawing extensively from the book <em>Designing Data-Intensive Applications</em> [1]. Following that, I explore the key functionalities of the Faust library, placing emphasis on Faust windows, which are often difficult to grasp from the available documentation and utilize efficiently. Consequently, I propose an alternative approach to utilizing Faust windows by leveraging the library’s own functions. Lastly, I share my experience implementing a similar pipeline on the Google Cloud Platform.</p><h3>Stream Processing</h3><p>A <em>stream </em>refers to unbounded data that is incrementally made available over time. An <em>event </em>is a small, self-contained object that contains the details of something happened at some point in time e.g. user interaction. An event is generated by a <em>producer </em>(e.g. temperature sensor) and may be consumed by some <em>consumers </em>(e.g. online dashboard). Traditional databases are ill-suited for storing events in high throughput event streams. This is due to the need for consumers to periodically poll the database to identify new events, resulting in significant overhead. Instead, it is better for consumers to be notified when new events appear and <em>messaging systems</em> are designed for doing this.</p><p>A <em>message broker</em> is a widely adopted system for messaging, in which producers write messages to the broker, and consumers are notified by the broker and receive these messages. <em>AMQP-based message brokers</em>, like <em>RabbitMQ</em>, are commonly employed for asynchronous message passing between services and task queues. Unlike databases, they adopt a transient messaging mindset and delete a message only after it has been acknowledged by its consumers. When processing messages becomes resource-intensive, parallelization can be achieved by employing multiple consumers that read from the same topic in a load-balanced manner. In this approach, messages are randomly assigned to consumers for processing, potentially resulting in a different order of processing compared to the order of receiving.</p><p>On the other hand, <em>log-based message brokers</em> such as <em>Apache Kafka</em> combine the durability of database storage with the low-latency notification capabilities of messaging systems. They utilize a partitioned-log structure, where each partition represents an append-only sequence of records stored on disk. This design enables the re-reading of old messages. Load balancing in Kafka is achieved by assigning a consumer to each partition and in this way, the order of message processing aligns with the order of receiving, but the number of consumers is limited to the number of partitions available.</p><p><em>Stream processing</em> involves performing actions on a stream, such as processing a stream and generate a new one, storing event data in a database, or visualizing data on a dashboard. <em>Stream analytics</em> is a common use case where we aggregate information from a sequence of events within a defined time window. <em>Tumbling windows</em> (non-overlapping) and <em>hopping windows</em> (overlapping) are popular window types used in stream analytics. Examples of stream analytics use cases can be simply counting the number of events in the previous hour, or applying a complex time-series prediction model on events.</p><p>Stream analytics faces the challenge of distinguishing between event creation time <em>(event time)</em> and event <em>processing time </em>as the processing of events may introduce delays due to queuing or network issues. Defining windows based on processing time is a simpler approach, especially when the processing delay is minimal. However, defining windows based on event time poses a greater challenge. This is because it is uncertain whether all the data within a window has been received or if there are still pending events. Hence, it becomes necessary to handle <em>straggler events</em> that arrive after the window has been considered complete.</p><p>In applications involving complex stream analytics, such as time-series prediction, it is often necessary to process a sequence of ordered messages within a window as a cohesive unit. In this situation, the messages exhibit strong inter-dependencies, making it difficult to acknowledge and remove individual messages from the broker. Consequently, a log-based message broker presents itself as a preferable option for utilization. Furthermore, parallel processing may not be feasible or overly intricate to implement in this context, as all the messages within a window need to be considered together. However, applying a complex ML model to the data can be computationally intensive, necessitating an alternative approach to parallel processing. This document aims to propose a solution for effectively employing a resource-intensive machine learning model in a high-throughput stream processing application.</p><h3>Faust Streaming</h3><p>There are several stream processing libraries available, such as Apache Kafka Streams, Flink, Samza, Storm, and Spark Streaming. Each of these libraries has its own strengths and weaknesses, but many of them are not particularly Python-friendly. However, <em>Faust</em> is a Python-based stream processing library that use Kafka as the underlying messaging system and aims to bring the ideas of Kafka Streams to the Python ecosystem. Unfortunately, Faust’s documentation can be confusing, and the source code can be difficult to comprehend. For instance, understanding how windows work in Faust is challenging without referring to the complex source code. Additionally, there are numerous open issues in the <a href="https://github.com/robinhood/faust">Faust</a> (v1) and the <a href="https://github.com/faust-streaming/faust">Faust-Streaming</a> (v2) repositories, and resolving these issues is not a straightforward process. In the following, essential knowledge about Faust’s underlying structure will be provided, along with code snippets to assist in effectively utilizing the Faust library.</p><p>To utilize Faust, the initial step involves creating an <em>App</em> and configuring the project by specifying the broker and other necessary parameters. One of the useful parameters is the table_cleanup_interval that will be discussed later.</p><pre>app = faust.App(<br>    app_name, <br>    broker=broker_address, <br>    store=rocksdb_address, <br>    table_cleanup_interval=table_cleanup_interval<br>)</pre><p>Then you can define a stream processor using the <em>agent</em> decorator to consume from a Kafka topic and do something for every event it receives.</p><pre>schema = faust.Schema(value_serializer='json')<br>topic = app.topic(topic_name, schema=schema)<br><br>@app.agent(topic)<br>async def processor(stream):<br>    async for event in stream:<br>        print(event) </pre><p>For keeping state in a stream processor, we can use Faust <em>Table. </em>A table is a distributed in-memory dictionary, backed by a Kafka changelog topic. You can think of table as a python dictionary that can be set within a stream processor.</p><pre>table = app.Table(table_name, default=int)<br><br>@app.agent(topic)<br>async def processor(stream):<br>    async for event in stream:<br>        table[key] += event </pre><h4>Faust Windows</h4><p>Let’s consider a time-series problem where every second, we require samples from the previous 10 seconds to predict something. So we need 10s overlapping windows with 1s overlap. To achieve this functionality, we can utilize Faust <a href="https://faust-streaming.github.io/faust/userguide/tables.html#windowing"><em>windowed tables</em></a><em> </em>which are inadequately explained in the Faust documentation and often lead to confusion.</p><p>Ideally, a stream processing library should automatically perform the following tasks:</p><ol><li>Maintain a state for each window (list of events);</li><li>Identify the relevant windows for a new event (the last 10 windows);</li><li>Update the state of these windows (append the new event to the end of their respective lists);</li><li>Apply a function when a window is closed, using the window’s state as input.</li></ol><p>In the code snippet below, you can observe the suggested approach in the Faust documentation for constructing a window and utilizing it in a streaming processor (refer to <a href="https://github.com/faust-streaming/faust/blob/master/examples/windowed_aggregation.py">this</a> example from the Faust library):</p><pre># Based on Fuast example<br># Do not use this<br><br>window_wrapper = app.Table(<br>    table_name, default=list, on_window_close=window_close<br>).hopping(<br>    10, 1, expires=expire_time<br>)<br><br>@app.agent(topic)<br>async def processor(stream):<br>    async for event in stream:<br>        window_set = window_wrapper[key]<br>        prev = window_set.value()<br>        prev.append(event)<br>        window_wrapper[key] = prev</pre><p>In the provided code, the object window_wrapper is an instance of the <a href="https://github.com/faust-streaming/faust/blob/ebf66ae031c3eb462ade320c73e84d1c4cb7a32f/faust/tables/wrappers.py#L312"><em>WindowWrapper</em></a> class that provides some of the required functionalities. The expires parameter determines the duration of a window’s lifespan, starting from its creation. Once this specified time has elapsed, the window is considered closed. Faust performs periodic checks on the table_cleanup_interval duration to identify closed windows. It then applies the window_close function, using the window state as its input.</p><p>When you call window_wrapper[key] it returns an object of type <em>WindowSet</em>, which internally contains all the relevant windows. By calling window_set.value(), you can access the state of the latest window, and you can also access previous window states by calling window_set.delta(30) which gives the state at 30 seconds ago. Additionally, you can update the state of the <em>latest</em> window by assigning a new value to window_wrapper[key]. This approach works fine for tumbling windows. However, it does not work for hopping windows where we need to update the state of multiple windows.</p><blockquote>[Faust Documentation:] At this point, when accessing data from a hopping table, we always access the latest window for a given timestamp and we have no way of modifying this behavior.</blockquote><p>While Faust provides support for maintaining the state of windows, identifying relevant windows, and applying a function on closed windows, it does not fully address the third functionality which involves updating the state of all relevant windows. In the following, I propose a new approach for utilizing Faust windows that encompasses this functionality as well.</p><h4>Windows Reinvented</h4><p>Comprehending the functionality and operation of Faust windows proved challenging for me until I delved into the source code. Faust windows are built upon an underlying Faust table, which I’ll refer to as the <em>inner table</em> moving forward. Surprisingly, the Faust documentation does not emphasize the inner table or provide a clear explanation of its role in implementing windows. However, it is the most crucial component in the window implementation. Therefore, in the following section, I will begin by defining the inner table and then proceed to discuss the window wrappers.</p><pre>inner_table = app.Table(<br>  table_name, default=list, partitions=1, on_window_close=window_close<br>)<br><br># for tumbling window: <br>window_wrapper = inner_table.tumbling(<br>  window_size, key_index=True, expires=timedelta(seconds=window_size)<br>)<br><br># for hopping window: <br>window_wrapper = inner_table.hopping(<br>  window_size, slide, key_index=True, expires=timedelta(seconds=window_size)<br>)</pre><p>Let’s now examine how Faust handles the first and second functionalities (keeping state and identifying relevant windows). Faust utilizes the concept of a <em>window range</em>, represented by a simple (start, end) tuple, to determine which windows are associated with a given timestamp. If the timestamp falls within the start and end times of a window, that window is considered relevant. Faust creates a record within the inner table using a key composed of the pair <em>(key, window range)</em> and updates it accordingly.</p><p>However, when invoking window_wrapper[key], it merely retrieves the present window range by relying on the current timestamp, and subsequently returns inner_table[(key, current_window_range)]. This poses an issue since utilizing the window wrapper only impacts the most recent window, even if the event pertains to multiple windows. Therefore, in the subsequent function, I opted to employ the inner_table instead. This enables me to obtain all the relevant window ranges and directly update each associated window using the inner table:</p><pre>async def update_table(events, key, window_wrapper, inner_table):<br>    t = window_wrapper.get_timestamp()<br>    for window_range in inner_table._window_ranges(t): <br>        prev = inner_table[(key, window_range)]<br>        prev.extend(events)<br>        inner_table[(key, window_range)] = prev</pre><p>Within this function, the initial line is responsible for locating the current timestamp, while inner_table._window_ranges(t) retrieves all pertinent window ranges for that timestamp. We subsequently proceed to update each relevant window within a for loop. This approach allows us to utilize the update_table function for both tumbling and hopping windows effectively.</p><p>It's worth noting that update_table accepts a list of events instead of just one, and employs the extends method instead of append. This choice is motivated by the fact that when attempting to update a table incrementally within a high-throughput pipeline, you often encounter the warning <em>“producer buffer full size”</em> which significantly hampers efficiency. Consequently, it is advisable to update tables in mini-batches, as demonstrated in the following:</p><pre>@app.agent(topic)<br>async def processor(stream):<br>    batch = []<br>    async for event in stream:<br>        batch.append(event)<br>        if len(batch) &gt;= 200:<br>            await update_table(batch, key, window_wrapper, inner_table)<br>            batch = []<br></pre><h4>Multiprocessing</h4><p>In Faust, each worker operates with a single process. Consequently, if the processing of a window is computationally intensive, it can result in a delay which is unacceptable for real-time applications. To address this issue, I propose leveraging the Python multiprocessing library within the window_close function. By doing so, we can distribute the processing load across multiple processes and mitigate the delay caused by heavy window processing, ensuring better real-time performance.</p><pre>from multiprocessing import Pool<br><br>async def window_close(key, events):<br>    pool.apply_async(compute, (events,), callback=produce)<br><br>def compute(events):<br>    # implement the logic here<br>    return result<br><br>def produce(result):<br>    if isinstance(result, Exception):<br>        print(f'EXCEPTION {result}')<br>        return<br>    # producer is a KafkaProducer<br>    producer.send(topic_name, value=result, key='result'.encode())<br><br>pool = Pool(processes=num_process)</pre><p>In the provided code, a pool of processes is created. Within the window_close function, pool.apply_async is utilized to delegate the job to a new worker and retrieve the result. A callback function is invoked when the result is ready.</p><p>In this specific code, the result is sent to a new Kafka topic using a Kafka producer. This setup enables the creation of a chain of Kafka topics, where each topic serves as the input for another stream processor. This allows for a sequential flow of data between the Kafka topics, facilitating efficient data processing and enabling the chaining of multiple stream processors.</p><h3>Google Cloud Solution</h3><p>I would like to briefly discuss my negative experience with the Google Cloud Platform (GCP). GCP recommends using Google Pub/Sub as the message broker, Apache Beam as the stream processing library, Google Dataflow for execution, and Google BigQuery as the database. However, when I attempted to use this stack, I encountered numerous issues that made it quite challenging.</p><p>Working with Google Pub/Sub in Python proved to be slow (check <a href="https://medium.com/google-cloud/how-long-does-google-dataflow-pick-and-process-pub-sub-messages-in-real-time-8ac19da774a2">this</a> and <a href="https://cloud.google.com/blog/products/data-analytics/testing-cloud-pubsub-clients-to-maximize-streaming-performance">this</a>), leading me to abandon it in favor of Kafka. Apache Beam is a well-documented library, however, using it with Kafka presented its own set of problems. The direct runner was buggy, requiring the use of Dataflow and resulting in significant time delays as I waited for machine provisioning. Furthermore, I experienced issues with delayed triggering of windows, despite my unsuccessful attempts to resolve the problem (check this <a href="https://github.com/apache/beam/issues/27238">GitHub issue</a> and this <a href="https://stackoverflow.com/questions/76545125/google-dataflow-has-delay-in-stream-jobs-using-apache-beam-and-kafka">Stack Overflow post</a>). Also debugging the entire system was a major challenge due to the complex integration of multiple components, leaving me with limited control over the logs and making it difficult to pinpoint the root cause of issues within Pub/Sub, Beam, Dataflow, or BigQuery. In summary, my experience with the Google Cloud Platform was marred by the slow performance of Google Pub/Sub in Python, the bugs encountered when using Apache Beam with Kafka, and the overall difficulty in debugging the interconnected systems.</p><p>[1] Kleppmann, Martin. <em>Designing data-intensive applications: The big ideas behind reliable, scalable, and maintainable systems</em>. “ O’Reilly Media, Inc.”, 2017.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a11740d0910c" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/stream-processing-with-python-kafka-faust-a11740d0910c">Stream Processing with Python, Kafka &amp; Faust</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Siemens SCALANCE XCM-/XRM-300]]></title>
<description><![CDATA[As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services |...]]></description>
<link>https://tsecurity.de/de/2033814/it-security-nachrichten/siemens-scalance-xcm-xrm-300/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2033814/it-security-nachrichten/siemens-scalance-xcm-xrm-300/</guid>
<pubDate>Thu, 15 Feb 2024 19:37:51 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see <a href="https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications" rel="noreferrer noopener" target="_blank">Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).</a> </p>
<p><strong><a href="https://github.com/cisagov/CSAF" target="_blank">View CSAF</a></strong></p>
<h2>1. EXECUTIVE SUMMARY</h2>
<ul><li><strong>CVSS v3 9.8</strong></li>
<li><strong>ATTENTION</strong>: Exploitable remotely/low attack complexity</li>
<li><strong>Vendor</strong>: Siemens</li>
<li><strong>Equipment</strong>: SCALANCE XCM-/XRM-300</li>
<li><strong>Vulnerabilities</strong>: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption of Sensitive Data, Use of a Broken or Risky Cryptographic Algorithm, Incorrect Permission Assignment for Critical Resource, Use After Free, HTTP Request/Response Smuggling, Improper Input Validation, Heap-based Buffer Overflow, Integer Overflow or Wraparound, Missing Release of Memory after Effective Lifetime, Double Free, Improper Validation of Specified Quantity in Input, Uncontrolled Resource Consumption, Incorrect Comparison, Out-of-bounds Read, Incorrect Default Permissions, Improper Ownership Management, Injection, Type Confusion, Inefficient Algorithmic Complexity, NULL Pointer Dereference, HTTP Request/Response Splitting, Allocation of Resources Without Limits or Throttling, Improper Validation of Integrity Check Value, Observable Discrepancy, Improper Locking, Incorrect Calculation of Buffer Size, Incorrect Authorization, Improper Removal of Sensitive Information Before Storage or Transfer, Unchecked Return Value, Race Condition, Link Following, Classic Buffer Overflow, Improper Check for Unusual or Exceptional Conditions, Path Traversal, Code Injection, Use of Uninitialized Resource, Cross-site Scripting, Exposure of Resource to Wrong Sphere, Improper Encoding or Escaping of Output, Interpretation Conflict, Use of Insufficiently Random Values, Buffer Underflow, Divide By Zero, Insufficiently Protected Credentials, Access of Uninitialized Pointer, Inefficient Regular Expression Complexity, OS Command Injection, Insufficient Verification of Data Authenticity</li>
</ul><h2>2. RISK EVALUATION</h2>
<p>Successful exploitation of these vulnerabilities could affect confidentiality, integrity, or system availability.</p>
<h2>3. TECHNICAL DETAILS</h2>
<h3>3.1 AFFECTED PRODUCTS</h3>
<p>Siemens reports that the following versions of SCALANCE XCM-/XRM-300, switches used to connect industrial components, are affected:</p>
<ul><li>SCALANCE XCH328 (6GK5328-4TS01-2EC2): versions prior to V2.4</li>
<li>SCALANCE XCM324 (6GK5324-8TS01-2AC2): versions prior to V2.4</li>
<li>SCALANCE XCM328 (6GK5328-4TS01-2AC2): versions prior to V2.4</li>
<li>SCALANCE XCM332 (6GK5332-0GA01-2AC2): versions prior to V2.4</li>
<li>SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3): versions prior to V2.4</li>
<li>SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3): versions prior to V2.4</li>
<li>SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3): versions prior to V2.4</li>
<li>SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3): versions prior to V2.4</li>
<li>SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3): versions prior to V2.4</li>
<li>SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3): versions prior to V2.4</li>
<li>SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3): versions prior to V2.4</li>
</ul><h3>3.2 Vulnerability Overview</h3>
<p>3.2.1 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>A carefully crafted If: request header can cause a memory read or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-20001" target="_blank">CVE-2006-20001</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.2 <a href="https://cwe.mitre.org/data/definitions/704.html" target="_blank">INCORRECT TYPE CONVERSION OR CAST CWE-704</a></p>
<p>A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-10735" target="_blank">CVE-2020-10735</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.3 <a href="https://cwe.mitre.org/data/definitions/347.html" target="_blank">IMPROPER VERIFICATION OF CRYPTOGRAPHIC SIGNATURE CWE-347</a></p>
<p>A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3445" target="_blank">CVE-2021-3445</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.4 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3638" target="_blank">CVE-2021-3638</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</a>).</p>
<p>3.2.5 <a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank">IMPROPER ACCESS CONTROL CWE-284</a></p>
<p>A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the Linux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-4037" target="_blank">CVE-2021-4037</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.6 <a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank">IMPROPER AUTHENTICATION CWE-287</a></p>
<p>An issue was discovered in Dropbear through 2020.81. It is possible for an SSH server to change the login process in its favor due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass. Thus, it allows an attacker to abuse a forwarded agent for logging on to another server unnoticed.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-36369" target="_blank">CVE-2021-36369</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.7 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>A denial of service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-43666" target="_blank">CVE-2021-43666</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.8 <a href="https://cwe.mitre.org/data/definitions/327.html" target="_blank">USE OF A BROKEN OR RISKY CRYPTOGRAPHIC ALGORITHM CWE-327</a></p>
<p>In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45451" target="_blank">CVE-2021-45451</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.9 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>There is a flaw in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-1015" target="_blank">CVE-2022-1015</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H</a>).</p>
<p>3.2.10 <a href="https://cwe.mitre.org/data/definitions/732.html" target="_blank">INCORRECT PERMISSION ASSIGNMENT FOR CRITICAL RESOURCE CWE-732</a></p>
<p>There is a vulnerability in the way the state file is created in logrotate. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-1348" target="_blank">CVE-2022-1348</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.11 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in nf_tables cross-table in the net/netfilter/nf_tables_api.c function in the Linux kernel. This flaw allows a local, privileged attacker to cause a use-after-free problem at the time of table deletion, possibly leading to local privilege escalation.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-2586" target="_blank">CVE-2022-2586</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.12 <a href="https://cwe.mitre.org/data/definitions/444.html" target="_blank">INCONSISTENT INTERPRETATION OF HTTP REQUESTS ('HTTP REQUEST/RESPONSE SMUGGLING') CWE-444</a></p>
<p>Requests forwarded by ReverseProxy include raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. Once the fix is applied, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-2880" target="_blank">CVE-2022-2880</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.13 <a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank">IMPROPER INPUT VALIDATION CWE-20</a></p>
<p>Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3294" target="_blank">CVE-2022-3294</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.14 <a href="https://cwe.mitre.org/data/definitions/122.html" target="_blank">HEAP-BASED BUFFER OVERFLOW CWE-122</a></p>
<p>A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial-of-service attack.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3437" target="_blank">CVE-2022-3437</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.15 <a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank">INTEGER OVERFLOW OR WRAPAROUND CWE-190</a></p>
<p>A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3515" target="_blank">CVE-2022-3515</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.16 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-4415" target="_blank">CVE-2022-4415</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.17 <a href="https://cwe.mitre.org/data/definitions/401.html" target="_blank">MISSING RELEASE OF MEMORY AFTER EFFECTIVE LIFETIME CWE-401</a></p>
<p>A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial-of-service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-4743" target="_blank">CVE-2022-4743</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.18 <a href="https://cwe.mitre.org/data/definitions/415.html" target="_blank">DOUBLE FREE CWE-415</a></p>
<p>A double-free flaw was found in the Linux kernel's TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-4744" target="_blank">CVE-2022-4744</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.19 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-4900" target="_blank">CVE-2022-4900</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.20 <a href="https://cwe.mitre.org/data/definitions/1284.html" target="_blank">IMPROPER VALIDATION OF SPECIFIED QUANTITY IN INPUT CWE-1284</a></p>
<p>A flaw was found in the c-ares package. The ares_set_sortlist is missing checks for the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-4904" target="_blank">CVE-2022-4904</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</a>).</p>
<p>3.2.21 <a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank">UNCONTROLLED RESOURCE CONSUMPTION CWE-400</a></p>
<p>containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize events if a TTY is requested. If the user's process fails to launch due to, for example, a faulty command, the goroutine will be stuck waiting to send without a receiver, resulting in a memory leak. Kubernetes and crictl can both be configured to use containerd's CRI implementation and the stream server is used for handling container IO. This bug has been fixed in containerd 1.6.12 and 1.5.16. Users should update to these versions to resolve the issue. Users unable to upgrade should ensure that only trusted images and commands are used and that only trusted users have permissions to execute commands in running containers.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-23471" target="_blank">CVE-2022-23471</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.22 <a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank">INTEGER OVERFLOW OR WRAPAROUND CWE-190</a></p>
<p>Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by adding a .gitattributes file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern. When parsing gitattributes, multiple integer overflows can occur when there is a huge number of path patterns, a huge number of attributes for a single pattern, or when the declared attribute names are huge. These overflows can be triggered via a crafted .gitattributes file that may be part of the commit history. Git silently splits lines longer than 2KB when parsing gitattributes from a file, but not when parsing them from the index. Consequentially, the failure mode depends on whether the file exists in the working tree, the index or both. This integer overflow can result in arbitrary heap reads and writes, which may result in remote code execution. The problem has been patched in the versions published on 2023-01-17, going back to v2.30.7. Users are advised to upgrade. There are no known workarounds for this issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-23521" target="_blank">CVE-2022-23521</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.23 <a href="https://cwe.mitre.org/data/definitions/122.html" target="_blank">HEAP-BASED BUFFER OVERFLOW CWE-122</a></p>
<p>Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24834" target="_blank">CVE-2022-24834</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.24 <a href="https://cwe.mitre.org/data/definitions/697.html" target="_blank">INCORRECT COMPARISON CWE-697</a></p>
<p>A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-26691" target="_blank">CVE-2022-26691</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.25 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>There is a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes to memory. Arbitrary code execution is not discarded in such scenario.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-28737" target="_blank">CVE-2022-28737</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.26 <a href="https://cwe.mitre.org/data/definitions/415.html" target="_blank">DOUBLE FREE CWE-415</a></p>
<p>A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-28738" target="_blank">CVE-2022-28738</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.27 <a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank">OUT-OF-BOUNDS READ CWE-125</a></p>
<p>There is a buffer over read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in string-to-float conversion, including Kernel#Float and String#to_f.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-28739" target="_blank">CVE-2022-28739</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.28 <a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank">IMPROPER INPUT VALIDATION CWE-20</a></p>
<p>An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files or directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or man-in-the-middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-29154" target="_blank">CVE-2022-29154</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H</a>).</p>
<p>3.2.29 <a href="https://cwe.mitre.org/data/definitions/276.html" target="_blank">INCORRECT DEFAULT PERMISSIONS CWE-276</a></p>
<p>runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where runc exec --cap created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes runc exec --cap behavior such that the additional capabilities granted to the process being executed (as specified via --caparguments) do not include inheritable capabilities. In addition, runc spec is changed to not set any inheritable capabilities in the created example OCI spec (config.json) file.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-29162" target="_blank">CVE-2022-29162</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a>).</p>
<p>3.2.30 <a href="https://cwe.mitre.org/data/definitions/282.html" target="_blank">IMPROPER OWNERSHIP MANAGEMENT CWE-282</a></p>
<p>Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the exploit described in the example by removing any such repository if it exists already and creating one as root to block any future attacks.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-29187" target="_blank">CVE-2022-29187</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.31 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-29536" target="_blank">CVE-2022-29536</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.32 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-32148" target="_blank">CVE-2022-32148</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a>).</p>
<p>3.2.33 <a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank">IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS IN OUTPUT USED BY A DOWNSTREAM COMPONENT ('INJECTION') CWE-74</a></p>
<p>GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-34903" target="_blank">CVE-2022-34903</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N</a>).</p>
<p>3.2.34 <a href="https://cwe.mitre.org/data/definitions/843.html" target="_blank">ACCESS OF RESOURCE USING INCOMPATIBLE TYPE ('TYPE CONFUSION') CWE-843</a></p>
<p>An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-34918" target="_blank">CVE-2022-34918</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.35 <a href="https://cwe.mitre.org/data/definitions/407.html" target="_blank">INEFFICIENT ALGORITHMIC COMPLEXITY CWE-407</a></p>
<p>Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like SCAN or KEYS) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. The problem is fixed in Redis versions 6.0.18, 6.2.11, 7.0.9.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-36021" target="_blank">CVE-2022-36021</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.36 <a href="https://cwe.mitre.org/data/definitions/476.html" target="_blank">NULL POINTER DEREFERENCE CWE-476</a></p>
<p>In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-36227" target="_blank">CVE-2022-36227</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.37 <a href="https://cwe.mitre.org/data/definitions/444.html" target="_blank">INCONSISTENT INTERPRETATION OF HTTP REQUESTS ('HTTP REQUEST/RESPONSE SMUGGLING') CWE-444</a></p>
<p>Inconsistent interpretation of HTTP requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-36760" target="_blank">CVE-2022-36760</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</a>).</p>
<p>3.2.38 <a href="https://cwe.mitre.org/data/definitions/113.html" target="_blank">IMPROPER NEUTRALIZATION OF CRLF SEQUENCES IN HTTP HEADERS ('HTTP REQUEST/RESPONSE SPLITTING') CWE-113</a></p>
<p>Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-37436" target="_blank">CVE-2022-37436</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a>).</p>
<p>3.2.39 <a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank">INTEGER OVERFLOW OR WRAPAROUND CWE-190</a></p>
<p>The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-37454" target="_blank">CVE-2022-37454</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.40 <a href="https://cwe.mitre.org/data/definitions/476.html" target="_blank">NULL POINTER DEREFERENCE CWE-476</a></p>
<p>In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial-of-service condition.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-37797" target="_blank">CVE-2022-37797</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.41 <a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank">INTEGER OVERFLOW OR WRAPAROUND CWE-190</a></p>
<p>An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a denial of service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-38725" target="_blank">CVE-2022-38725</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.42 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39189" target="_blank">CVE-2022-39189</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.43 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>Git is an open source, scalable, distributed revision control system. git shell is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into an array improperly uses an int to represent the number of entries in the array, allowing a malicious actor to intentionally overflow the return value, leading to arbitrary heap writes. Because the resulting array is then passed to execv(), it is possible to leverage this attack to gain remote code execution on a victim machine. Note that a victim must first allow access to git shell as a login shell in order to be vulnerable to this attack. This problem is patched in versions 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 and users are advised to upgrade to the latest version. Disabling git shell access via remote logins is a viable short-term workaround.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39260" target="_blank">CVE-2022-39260</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</a>).</p>
<p>3.2.44 <a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank">INTEGER OVERFLOW OR WRAPAROUND CWE-190</a></p>
<p>An integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41409" target="_blank">CVE-2022-41409</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.45 <a href="https://cwe.mitre.org/data/definitions/401.html" target="_blank">MISSING RELEASE OF MEMORY AFTER EFFECTIVE LIFETIME CWE-401</a></p>
<p>A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41556" target="_blank">CVE-2022-41556</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.46 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41715" target="_blank">CVE-2022-41715</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.47 <a href="https://cwe.mitre.org/data/definitions/770.html" target="_blank">ALLOCATION OF RESOURCES WITHOUT LIMITS OR THROTTLING CWE-770</a></p>
<p>An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41717" target="_blank">CVE-2022-41717</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p>
<p>3.2.48 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41723" target="_blank">CVE-2022-41723</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.49 <a href="https://cwe.mitre.org/data/definitions/476.html" target="_blank">NULL POINTER DEREFERENCE CWE-476</a></p>
<p>In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41860" target="_blank">CVE-2022-41860</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.50 <a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank">IMPROPER INPUT VALIDATION CWE-20</a></p>
<p>A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed binary attribute which can cause the server to crash.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41861" target="_blank">CVE-2022-41861</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.51 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41862" target="_blank">CVE-2022-41862</a> has been assigned to this vulnerability. A CVSS v3 base score of 3.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</a>).</p>
<p>3.2.52 <a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank">INTEGER OVERFLOW OR WRAPAROUND CWE-190</a></p>
<p>Git is distributed revision control system. git log can display commits in an arbitrary format using its --format specifiers. This functionality is also exposed to git archive via the export-subst gitattribute. When processing the padding operators, there is a integer overflow in pretty.c::format_and_pad_commit() where a size_t is stored improperly as an int, and then added as an offset to a memcpy(). This overflow can be triggered directly by a user running a command which invokes the commit formatting machinery (e.g., git log --format=...). It may also be triggered indirectly through git archive via the export-subst mechanism, which expands format specifiers inside of files within the repository during a git archive. This integer overflow can result in arbitrary heap writes, which may result in arbitrary code execution. The problem has been patched in the versions published on 2023-01-17, going back to v2.30.7. Users are advised to upgrade. Users who are unable to upgrade should disable git archive in untrusted repositories. If you expose git archive via git daemon, disable it by running git config --global daemon.uploadArch false.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41903" target="_blank">CVE-2022-41903</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.53 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from any user in the same machine local network namespace, which in many system configurations means any user on the same machine. Pickles can execute arbitrary code. Thus, this allows for local user privilege escalation that any forkserver process is running as. Setting multiprocessing.util.abstract_sockets_supported to False is a workaround. The forkserver start method for multiprocessing is not the default start method. This issue is Linux specific because only Linux supports abstract namespace sockets. CPython before 3.9 does not make use of Linux abstract namespace sockets by default. Support for users manually specifying an abstract namespace socket was added as a bugfix in 3.7.8 and 3.8.3, but users would need to make specific uncommon API calls in order to do that in CPython before 3.9.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-42919" target="_blank">CVE-2022-42919</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.54 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-44370" target="_blank">CVE-2022-44370</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.55 <a href="https://cwe.mitre.org/data/definitions/407.html" target="_blank">INEFFICIENT ALGORITHMIC COMPLEXITY CWE-407</a></p>
<p>An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-45061" target="_blank">CVE-2022-45061</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.56 <a href="https://cwe.mitre.org/data/definitions/354.html" target="_blank">IMPROPER VALIDATION OF INTEGRITY CHECK VALUE CWE-354</a></p>
<p>The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-45142" target="_blank">CVE-2022-45142</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.57 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free can occur is there is a disconnect after an open, because of the lack of a wait_event.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-45919" target="_blank">CVE-2022-45919</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.58 <a href="https://cwe.mitre.org/data/definitions/203.html" target="_blank">OBSERVABLE DISCREPANCY CWE-203</a></p>
<p>An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46392" target="_blank">CVE-2022-46392</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.59 <a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank">OUT-OF-BOUNDS READ CWE-125</a></p>
<p>An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX &gt; 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-46393" target="_blank">CVE-2022-46393</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.60 <a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank">INTEGER OVERFLOW OR WRAPAROUND CWE-190</a></p>
<p>Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-47629" target="_blank">CVE-2022-47629</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.61 <a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank">OUT-OF-BOUNDS READ CWE-125</a></p>
<p>GNU Tar through 1.34 has a one-byte, out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-48303" target="_blank">CVE-2022-48303</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.62 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-48434" target="_blank">CVE-2022-48434</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.63 <a href="https://cwe.mitre.org/data/definitions/667.html" target="_blank">IMPROPER LOCKING CWE-667</a></p>
<p>A deadlock flaw was found in the Linux kernel's BPF subsystem. This flaw allows a local user to potentially crash the system.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0160" target="_blank">CVE-2023-0160</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.64 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0330" target="_blank">CVE-2023-0330</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H</a>).</p>
<p>3.2.65 <a href="https://cwe.mitre.org/data/definitions/203.html" target="_blank">OBSERVABLE DISCREPANCY CWE-203</a></p>
<p>A timing side channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0361" target="_blank">CVE-2023-0361</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</a>).</p>
<p>3.2.66 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0494" target="_blank">CVE-2023-0494</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.67 <a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank">IMPROPER INPUT VALIDATION CWE-20</a></p>
<p>In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0567" target="_blank">CVE-2023-0567</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</a>).</p>
<p>3.2.68 <a href="https://cwe.mitre.org/data/definitions/131.html" target="_blank">INCORRECT CALCULATION OF BUFFER SIZE CWE-131</a></p>
<p>In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0568" target="_blank">CVE-2023-0568</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.69 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in qdisc_graft in net/sched/sch_api.c in the Linux kernel due to a race problem. This flaw leads to a denial-of-service issue. If patch ebda44da44f6 ("net: sched: fix race condition in qdisc_graft()") not applied yet, then kernel could be affected.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0590" target="_blank">CVE-2023-0590</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.70 <a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank">UNCONTROLLED RESOURCE CONSUMPTION CWE-400</a></p>
<p>In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0662" target="_blank">CVE-2023-0662</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.71 <a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank">UNCONTROLLED RESOURCE CONSUMPTION CWE-400</a></p>
<p>A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel's IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1206" target="_blank">CVE-2023-1206</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.72 <a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank">OUT-OF-BOUNDS READ CWE-125</a></p>
<p>A slab-out-of-bounds read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel. This issue could occur when assoc_info-&gt;req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1380" target="_blank">CVE-2023-1380</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a>).</p>
<p>3.2.73 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A flaw was found in X.Org Server Overlay Window. A use after free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use after free later.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1393" target="_blank">CVE-2023-1393</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.74 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux kernel.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1611" target="_blank">CVE-2023-1611</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H</a>).</p>
<p>3.2.75 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw in the Linux kernel Xircom 16-bit PCMCIA (PC-card) Ethernet driver was found. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1670" target="_blank">CVE-2023-1670</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.76 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash the system, and could even lead to a kernel information leak problem.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1838" target="_blank">CVE-2023-1838</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a>).</p>
<p>3.2.77 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux kernel Driver (xgene-hwmon). This flaw could allow a local attacker to crash the system due to a race problem. This vulnerability could even lead to a kernel information leak problem.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1855" target="_blank">CVE-2023-1855</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H</a>).</p>
<p>3.2.78 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in xen_9pfs_front_removet in net/9p/trans_xen.c in Xen transport for 9pfs in the Linux kernel. This flaw could allow a local attacker to crash the system due to a race problem, possibly leading to a kernel information leak.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1859" target="_blank">CVE-2023-1859</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.79 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux kernel. In this flaw, a call to btsdio_remove with an unfinished job may cause a race problem leading to a UAF on hdev devices.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1989" target="_blank">CVE-2023-1989</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.80 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux kernel. This flaw could allow an attacker to crash the system due to a race problem.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1990" target="_blank">CVE-2023-1990</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.81 <a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank">INCORRECT AUTHORIZATION CWE-863</a></p>
<p>A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-2002" target="_blank">CVE-2023-2002</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" target="_blank">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H</a>).</p>
<p>3.2.82 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>An out-of-bounds memory access flaw was found in the Linux kernel's XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-2124" target="_blank">CVE-2023-2124</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.83 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data-&gt;block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-2194" target="_blank">CVE-2023-2194</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.84 <a href="https://cwe.mitre.org/data/definitions/667.html" target="_blank">IMPROPER LOCKING CWE-667</a></p>
<p>A denial-of-service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux kernel Device Mapper-Multipathing sub-component.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-2269" target="_blank">CVE-2023-2269</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.85 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-2861" target="_blank">CVE-2023-2861</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a>).</p>
<p>3.2.86 <a href="https://cwe.mitre.org/data/definitions/476.html" target="_blank">NULL POINTER DEREFERENCE CWE-476</a></p>
<p>A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-2953" target="_blank">CVE-2023-2953</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.87 <a href="https://cwe.mitre.org/data/definitions/212.html" target="_blank">IMPROPER REMOVAL OF SENSITIVE INFORMATION BEFORE STORAGE OR TRANSFER CWE-212</a></p>
<p>A known cache speculation vulnerability, known as branch history injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History Buffer, or BHB) to influence mispredicted branches within the victim's hardware context. Once that occurs, speculation caused by mispredicted branches can cause cache allocation. This issue leads to obtaining information that should not be accessible.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3006" target="_blank">CVE-2023-3006</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.88 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>A heap out-of-bounds write vulnerability in the Linux kernel ipvlan network driver can be exploited to achieve local privilege escalation.The out-of-bounds write is caused by missing skb-&gt;cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3090" target="_blank">CVE-2023-3090</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.89 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3111" target="_blank">CVE-2023-3111</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.90 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3141" target="_blank">CVE-2023-3141</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a>).</p>
<p>3.2.91 <a href="https://cwe.mitre.org/data/definitions/476.html" target="_blank">NULL POINTER DEREFERENCE CWE-476</a></p>
<p>A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3212" target="_blank">CVE-2023-3212</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.92 <a href="https://cwe.mitre.org/data/definitions/252.html" target="_blank">UNCHECKED RETURN VALUE CWE-252</a></p>
<p>In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP digest authentication, random value generator was not checked for failure, and was using narrower range of values than it should have. In case of random generator failure, it could lead to a disclosure of 31 bits of uninitialized memory from the client to the server, and it also made it easier for a malicious server to guess the client's nonce.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3247" target="_blank">CVE-2023-3247</a> has been assigned to this vulnerability. A CVSS v3 base score of 2.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N</a>).</p>
<p>3.2.93 <a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank">OUT-OF-BOUNDS READ CWE-125</a></p>
<p>An out-of-bounds memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3268" target="_blank">CVE-2023-3268</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a>).</p>
<p>3.2.94 <a href="https://cwe.mitre.org/data/definitions/362.html" target="_blank">CONCURRENT EXECUTION USING SHARED RESOURCE WITH IMPROPER SYNCHRONIZATION ('RACE CONDITION') CWE-362</a></p>
<p>A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3301" target="_blank">CVE-2023-3301</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H</a>).</p>
<p>3.2.95 <a href="https://cwe.mitre.org/data/definitions/476.html" target="_blank">NULL POINTER DEREFERENCE CWE-476</a></p>
<p>A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3316" target="_blank">CVE-2023-3316</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.96 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c.Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3390" target="_blank">CVE-2023-3390</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.97 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes without bounds checks.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3611" target="_blank">CVE-2023-3611</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.98 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, fw_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3776" target="_blank">CVE-2023-3776</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.99 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3863" target="_blank">CVE-2023-3863</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.100 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>A use-after-free vulnerability in net/sched/cls_fw.c in classifiers (cls_fw, cls_u32, and cls_route) in the Linux kernel allows a local attacker to perform a local privilege escalation due to incorrect handling of the existing filter, leading to a kernel information leak.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-4128" target="_blank">CVE-2023-4128</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.101 <a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank">INCORRECT AUTHORIZATION CWE-863</a></p>
<p>A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following upstream commits - a096ccca6e50 ("tun: tun_chr_open(): correctly initialize socket uid"), - 66b2c338adce ("tap: tap_open(): correctly initialize socket uid"), pass "inode-&gt;i_uid" to sock_init_data_uid() as the last parameter and that is not accurate.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-4194" target="_blank">CVE-2023-4194</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.102 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>An issue in "Zen 2" CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-20593" target="_blank">CVE-2023-20593</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.103 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-21255" target="_blank">CVE-2023-21255</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.104 <a href="https://cwe.mitre.org/data/definitions/59.html" target="_blank">IMPROPER LINK RESOLUTION BEFORE FILE ACCESS ('LINK FOLLOWING') CWE-59</a></p>
<p>Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone optimization even when using a non-local transport. Though Git will abort local clones whose source $GIT_DIR/objects directory contains symbolic links, the objects directory itself may still be a symbolic link. These two may be combined to include arbitrary files based on known paths on the victim's filesystem within the malicious repository's working copy, allowing for data exfiltration in a similar manner as CVE-2022-39253.A fix has been prepared and will appear in v2.39.2 v2.38.4 v2.37.6 v2.36.5 v2.35.7 v2.34.7 v2.33.7 v2.32.6, v2.31.7 and v2.30.8. If upgrading is impractical, two short-term workarounds are available. Avoid cloning repositories from untrusted sources with --recurse-submodules. Instead, consider cloning repositories without recursively cloning their submodules, and instead run git submodule update at each layer. Before doing so, inspect each new .gitmodules file to ensure that it does not contain suspicious module URLs.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-22490" target="_blank">CVE-2023-22490</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.105 <a href="https://cwe.mitre.org/data/definitions/347.html" target="_blank">IMPROPER VERIFICATION OF CRYPTOGRAPHIC SIGNATURE CWE-347</a></p>
<p>libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the certificate_check field of libgit2's git_remote_callbacks structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-22742" target="_blank">CVE-2023-22742</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.106 <a href="https://cwe.mitre.org/data/definitions/120.html" target="_blank">BUFFER COPY WITHOUT CHECKING SIZE OF INPUT ('CLASSIC BUFFER OVERFLOW') CWE-120</a></p>
<p>tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In affected versions Tss2_RC_SetHandler and Tss2_RC_Decode both index into layer_handler with an 8 bit layer number, but the array only has TPM2_ERROR_TSS2_RC_LAYER_COUNT entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This buffer overrun could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules, an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-22745" target="_blank">CVE-2023-22745</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.107 <a href="https://cwe.mitre.org/data/definitions/843.html" target="_blank">ACCESS OF RESOURCE USING INCOMPATIBLE TYPE ('TYPE CONFUSION') CWE-843</a></p>
<p>cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-23454" target="_blank">CVE-2023-23454</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.108 <a href="https://cwe.mitre.org/data/definitions/754.html" target="_blank">IMPROPER CHECK FOR UNUSUAL OR EXCEPTIONAL CONDITIONS CWE-754</a></p>
<p>cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions Cipher.update_into would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as bytes) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since update_into was originally introduced in cryptography 1.8.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-23931" target="_blank">CVE-2023-23931</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L</a>).</p>
<p>3.2.109 <a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank">IMPROPER INPUT VALIDATION CWE-20</a></p>
<p>Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like =value instead of key=value. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like =__Host-test=bad for another subdomain. Werkzeug prior to 2.2.3 will parse the cookie =__Host-test=bad as __Host-test=bad. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key. The issue is fixed in Werkzeug 2.2.3.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-23934" target="_blank">CVE-2023-23934</a> has been assigned to this vulnerability. A CVSS v3 base score of 2.6 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N</a>).</p>
<p>3.2.110 <a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank">IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</a></p>
<p>Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to git apply, a path outside the working tree can be overwritten as the user who is running git apply. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use git apply --stat to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-23946" target="_blank">CVE-2023-23946</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.111 <a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank">IMPROPER CONTROL OF GENERATION OF CODE ('CODE INJECTION') CWE-94</a></p>
<p>Go templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-24538" target="_blank">CVE-2023-24538</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.112 <a href="https://cwe.mitre.org/data/definitions/770.html" target="_blank">ALLOCATION OF RESOURCES WITHOUT LIMITS OR THROTTLING CWE-770</a></p>
<p>containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-25153" target="_blank">CVE-2023-25153</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.2 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.113 <a href="https://cwe.mitre.org/data/definitions/190.html" target="_blank">INTEGER OVERFLOW OR WRAPAROUND CWE-190</a></p>
<p>Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted SRANDMEMBER, ZRANDMEMBER, and HRANDFIELD commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. This problem affects all Redis versions. Patches were released in Redis version(s) 6.0.18, 6.2.11 and 7.0.9.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-25155" target="_blank">CVE-2023-25155</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.114 <a href="https://cwe.mitre.org/data/definitions/770.html" target="_blank">ALLOCATION OF RESOURCES WITHOUT LIMITS OR THROTTLING CWE-770</a></p>
<p>hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger quadratic growth via consecutive marks during the process of looking back for base glyphs when attaching marks.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-25193" target="_blank">CVE-2023-25193</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.115 <a href="https://cwe.mitre.org/data/definitions/908.html" target="_blank">USE OF UNINITIALIZED RESOURCE CWE-908</a></p>
<p>A flaw was found in Binutils. The field the_bfd of asymbol struct is uninitialized in the bfd_mach_o_get_synthetic_symtab function, which may lead to an application crash and local denial of service.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-25588" target="_blank">CVE-2023-25588</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.116 <a href="https://cwe.mitre.org/data/definitions/444.html" target="_blank">INCONSISTENT INTERPRETATION OF HTTP REQUESTS ('HTTP REQUEST/RESPONSE SMUGGLING') CWE-444</a></p>
<p>Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP request smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-25690" target="_blank">CVE-2023-25690</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.117 <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION ('CROSS-SITE SCRIPTING') CWE-79</a></p>
<p>In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-25727" target="_blank">CVE-2023-25727</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</a>).</p>
<p>3.2.118 <a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank">EXPOSURE OF RESOURCE TO WRONG SPHERE CWE-668</a></p>
<p>In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-26081" target="_blank">CVE-2023-26081</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.119 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-26965" target="_blank">CVE-2023-26965</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.120 <a href="https://cwe.mitre.org/data/definitions/444.html" target="_blank">INCONSISTENT INTERPRETATION OF HTTP REQUESTS ('HTTP REQUEST/RESPONSE SMUGGLING') CWE-444</a></p>
<p>HTTP response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-27522" target="_blank">CVE-2023-27522</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.121 <a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank">IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22</a></p>
<p>A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde () character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /2/foo while accessing a server with a specific user.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-27534" target="_blank">CVE-2023-27534</a> has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.122 <a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank">IMPROPER AUTHENTICATION CWE-287</a></p>
<p>An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-27535" target="_blank">CVE-2023-27535</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.123 <a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank">IMPROPER AUTHENTICATION CWE-287</a></p>
<p>An authentication bypass vulnerability exists libcurl prior to 8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-27536" target="_blank">CVE-2023-27536</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.124 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-28450" target="_blank">CVE-2023-28450</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.125 <a href="https://cwe.mitre.org/data/definitions/476.html" target="_blank">NULL POINTER DEREFERENCE CWE-476</a></p>
<p>do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use after free or NULL pointer dereference).</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-28466" target="_blank">CVE-2023-28466</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.126 <a href="https://cwe.mitre.org/data/definitions/116.html" target="_blank">IMPROPER ENCODING OR ESCAPING OF OUTPUT CWE-116</a></p>
<p>Sudo before 1.9.13 does not escape control characters in log messages.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-28486" target="_blank">CVE-2023-28486</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a>).</p>
<p>3.2.127 <a href="https://cwe.mitre.org/data/definitions/116.html" target="_blank">IMPROPER ENCODING OR ESCAPING OF OUTPUT CWE-116</a></p>
<p>Sudo before 1.9.13 does not escape control characters in sudoreplay output.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-28487" target="_blank">CVE-2023-28487</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a>).</p>
<p>3.2.128 <a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank">IMPROPER CONTROL OF GENERATION OF CODE ('CODE INJECTION') CWE-94</a></p>
<p>The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command, i.e. via "go get", are not affected (modules retrieved using GOPATH-mode, i.e. GO111MODULE=off, may be affected).</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-29402" target="_blank">CVE-2023-29402</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.129 <a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank">IMPROPER CONTROL OF GENERATION OF CODE ('CODE INJECTION') CWE-94</a></p>
<p>The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. The arguments for a number of flags which are non-optional are incorrectly considered optional, allowing disallowed flags to be smuggled through the LDFLAGS sanitization. This affects usage of both the gc and gccgo compilers.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-29404" target="_blank">CVE-2023-29404</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.130 <a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank">IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS IN OUTPUT USED BY A DOWNSTREAM COMPONENT ('INJECTION') CWE-74</a></p>
<p>The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. Flags containing embedded spaces are mishandled, allowing disallowed flags to be smuggled through the LDFLAGS sanitization by including them in the argument of another flag. This only affects usage of the gccgo compiler.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-29405" target="_blank">CVE-2023-29405</a> has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.131 <a href="https://cwe.mitre.org/data/definitions/436.html" target="_blank">INTERPRETATION CONFLICT CWE-436</a></p>
<p>The HTTP/1 client does not fully validate the contents of the host header. A maliciously crafted host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-29406" target="_blank">CVE-2023-29406</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.132 <a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank">UNCONTROLLED RESOURCE CONSUMPTION CWE-400</a></p>
<p>Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to &lt;= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-29409" target="_blank">CVE-2023-29409</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p>
<p>3.2.133 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>A buffer overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-30086" target="_blank">CVE-2023-30086</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.134 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-30456" target="_blank">CVE-2023-30456</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</a>).</p>
<p>3.2.135 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>The Linux kernel before 6.2.9 has a race condition and resultant use after free in drivers/power/supply/da9150-charger.c if a physically proximate attacker unplugs a device.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-30772" target="_blank">CVE-2023-30772</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.136 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&amp;fepriv-&gt;sem) is called. However, wait_event_interruptible would put the process to sleep, and down(&amp;fepriv-&gt;sem) may block the process.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31084" target="_blank">CVE-2023-31084</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.137 <a href="https://cwe.mitre.org/data/definitions/330.html" target="_blank">USE OF INSUFFICIENTLY RANDOM VALUES CWE-330</a></p>
<p>c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31124" target="_blank">CVE-2023-31124</a> has been assigned to this vulnerability. A CVSS v3 base score of 3.7 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</a>).</p>
<p>3.2.138 <a href="https://cwe.mitre.org/data/definitions/124.html" target="_blank">BUFFER UNDERWRITE ('BUFFER UNDERFLOW') CWE-124</a></p>
<p>c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses; in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). However, users may externally use ares_inet_net_pton() for other purposes and thus be vulnerable to more severe issues. This issue has been fixed in 1.19.1.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31130" target="_blank">CVE-2023-31130</a> has been assigned to this vulnerability. A CVSS v3 base score of 4.1 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.139 <a href="https://cwe.mitre.org/data/definitions/330.html" target="_blank">USE OF INSUFFICIENTLY RANDOM VALUES CWE-330</a></p>
<p>c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will generate predictable output. Input from the random number generator is fed into a non-compilant RC4 implementation and may not be as strong as the original RC4 implementation. No attempt is made to look for modern OS-provided CSPRNGs like arc4random() that is widely available. This issue has been fixed in version 1.19.1.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31147" target="_blank">CVE-2023-31147</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.140 <a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank">IMPROPER INPUT VALIDATION CWE-20</a></p>
<p>qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31436" target="_blank">CVE-2023-31436</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.141 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31489" target="_blank">CVE-2023-31489</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.142 <a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank">UNCONTROLLED RESOURCE CONSUMPTION CWE-400</a></p>
<p>c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-32067" target="_blank">CVE-2023-32067</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.143 <a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank">IMPROPER INPUT VALIDATION CWE-20</a></p>
<p>In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-32233" target="_blank">CVE-2023-32233</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.144 <a href="https://cwe.mitre.org/data/definitions/369.html" target="_blank">DIVIDE BY ZERO CWE-369</a></p>
<p>In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-32573" target="_blank">CVE-2023-32573</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.145 <a href="https://cwe.mitre.org/data/definitions/362.html" target="_blank">CONCURRENT EXECUTION USING SHARED RESOURCE WITH IMPROPER SYNCHRONIZATION ('RACE CONDITION') CWE-362</a></p>
<p>The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-33203" target="_blank">CVE-2023-33203</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.146 <a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank">IMPROPER INPUT VALIDATION CWE-20</a></p>
<p>An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-34256" target="_blank">CVE-2023-34256</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.147 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a denial of service (crash) via a crafted PDF file in OutlineItem::open.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-34872" target="_blank">CVE-2023-34872</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.148 <a href="https://cwe.mitre.org/data/definitions/311.html" target="_blank">MISSING ENCRYPTION OF SENSITIVE DATA CWE-311</a></p>
<p>D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-34969" target="_blank">CVE-2023-34969</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.149 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>Linux kernel nftables out-of-bounds read/write vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-35001" target="_blank">CVE-2023-35001</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.150 <a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank">OUT-OF-BOUNDS WRITE CWE-787</a></p>
<p>An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-35788" target="_blank">CVE-2023-35788</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.151 <a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank">INSUFFICIENTLY PROTECTED CREDENTIALS CWE-522</a></p>
<p>An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-35789" target="_blank">CVE-2023-35789</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a>).</p>
<p>3.2.152 <a href="https://cwe.mitre.org/data/definitions/362.html" target="_blank">CONCURRENT EXECUTION USING SHARED RESOURCE WITH IMPROPER SYNCHRONIZATION ('RACE CONDITION') CWE-362</a></p>
<p>An issue was discovered in the Linux kernel before 6.3.2. A use after free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-35823" target="_blank">CVE-2023-35823</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.153 <a href="https://cwe.mitre.org/data/definitions/362.html" target="_blank">CONCURRENT EXECUTION USING SHARED RESOURCE WITH IMPROPER SYNCHRONIZATION ('RACE CONDITION') CWE-362</a></p>
<p>An issue was discovered in the Linux kernel before 6.3.2. A use after free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-35824" target="_blank">CVE-2023-35824</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.154 <a href="https://cwe.mitre.org/data/definitions/362.html" target="_blank">CONCURRENT EXECUTION USING SHARED RESOURCE WITH IMPROPER SYNCHRONIZATION ('RACE CONDITION') CWE-362</a></p>
<p>An issue was discovered in the Linux kernel before 6.3.2. A use after free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-35828" target="_blank">CVE-2023-35828</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.155 <a href="https://cwe.mitre.org/data/definitions/824.html" target="_blank">ACCESS OF UNINITIALIZED POINTER CWE-824</a></p>
<p>lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-36054" target="_blank">CVE-2023-36054</a> has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.156 <a href="https://cwe.mitre.org/data/definitions/1333.html" target="_blank">INEFFICIENT REGULAR EXPRESSION COMPLEXITY CWE-1333</a></p>
<p>A regular expression denial of service issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. This issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-36617" target="_blank">CVE-2023-36617</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a>).</p>
<p>3.2.157 <a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank">IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS USED IN AN OS COMMAND ('OS COMMAND INJECTION') CWE-78</a></p>
<p>Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-36664" target="_blank">CVE-2023-36664</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a>).</p>
<p>3.2.158 <a href="https://cwe.mitre.org/data/definitions/345.html" target="_blank">INSUFFICIENT VERIFICATION OF DATA AUTHENTICITY CWE-345</a></p>
<p>Certifi is a curated collection of root certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-37920" target="_blank">CVE-2023-37920</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a>).</p>
<p>3.2.159 <a href="https://cwe.mitre.org/data/definitions/120.html" target="_blank">BUFFER COPY WITHOUT CHECKING SIZE OF INPUT ('CLASSIC BUFFER OVERFLOW') CWE-120</a></p>
<p>A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-38559" target="_blank">CVE-2023-38559</a> has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a>).</p>
<p>3.2.160 <a href="https://cwe.mitre.org/data/definitions/416.html" target="_blank">USE AFTER FREE CWE-416</a></p>
<p>An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-40283" target="_blank">CVE-2023-40283</a> has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a>).</p>
<h3>3.3 BACKGROUND</h3>
<ul><li><strong>CRITICAL INFRASTRUCTURE SECTORS:</strong> Critical Manufacturing</li>
<li><strong>COUNTRIES/AREAS DEPLOYED:</strong> Worldwide</li>
<li><strong>COMPANY HEADQUARTERS LOCATION:</strong> Germany</li>
</ul><h3>3.4 RESEARCHER</h3>
<p>Siemens reported these vulnerabilities to CISA.</p>
<h2>4. MITIGATIONS</h2>
<p>Siemens has released <a href="https://support.industry.siemens.com/cs/ww/en/view/109826613/" target="_blank">update V2.4</a> for SCALANCE X-300 and recommends updating to the latest version.</p>
<p>As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to <a href="https://www.siemens.com/cert/operational-guidelines-industrial-security" target="_blank">Siemens' operational guidelines for industrial security</a> and following recommendations in the product manuals.</p>
<p>Additional information on industrial security by Siemens can be found on the <a href="https://www.siemens.com/industrialsecurity" target="_blank">Siemens industrial security webpage</a>.</p>
<p>For more information see the associated Siemens security advisory SSA-806742 in <a href="https://cert-portal.siemens.com/productcert/html/ssa-806742.html" target="_blank">HTML</a> and <a href="https://cert-portal.siemens.com/productcert/csaf/ssa-806742.json" target="_blank">CSAF</a>.</p>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" target="_blank">control systems security recommended practices</a> on the ICS webpage on <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a>. Several CISA products detailing cyber defense best practices are available for reading and download, including <a href="https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" target="_blank">Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies</a>.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for <a href="https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" target="_blank">proactive defense of ICS assets</a>.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at <a href="https://www.cisa.gov/topics/industrial-control-systems" target="_blank">cisa.gov</a> in the technical information paper, <a href="https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B" target="_blank">ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies</a>.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<h2>5. UPDATE HISTORY</h2>
<ul><li>February 15, 2024: Initial Publication</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Red Hat Security Advisory 2024-0217-03]]></title>
<description><![CDATA[Red Hat Security Advisory 2024-0217-03 - An update for rabbitmq-server is now available for Red Hat OpenStack Platform 17.1. Issues addressed include a denial of service vulnerability.]]></description>
<link>https://tsecurity.de/de/1994507/unix-server/red-hat-security-advisory-2024-0217-03/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1994507/unix-server/red-hat-security-advisory-2024-0217-03/</guid>
<pubDate>Wed, 17 Jan 2024 15:40:59 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Red Hat Security Advisory 2024-0217-03 - An update for rabbitmq-server is now available for Red Hat OpenStack Platform 17.1. Issues addressed include a denial of service vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[Using RabbitMQ Streams in Go]]></title>
<description><![CDATA[Learn how to use RabbitMQ Streams using both Core and Plugin in this tutorialContinue reading on Towards Data Science »]]></description>
<link>https://tsecurity.de/de/1991837/ai-nachrichten/using-rabbitmq-streams-in-go/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1991837/ai-nachrichten/using-rabbitmq-streams-in-go/</guid>
<pubDate>Mon, 15 Jan 2024 20:50:23 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="medium-feed-item"><p class="medium-feed-image"><a href="https://towardsdatascience.com/using-rabbitmq-streams-in-go-1ce132d75a47"><img src="https://cdn-images-1.medium.com/max/1024/1*bUr0v7eXYwp9S_iG0sCYyQ.png" width="1024"></a></p><p class="medium-feed-snippet">Learn how to use RabbitMQ Streams using both Core and Plugin in this tutorial</p><p class="medium-feed-link"><a href="https://towardsdatascience.com/using-rabbitmq-streams-in-go-1ce132d75a47">Continue reading on Towards Data Science »</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-11281 | Pivotal RabbitMQ up to 3.7.17 Host Limits Page/Federation Management UI cross site scripting (RHSA-2020:0078)]]></title>
<description><![CDATA[A vulnerability was found in Pivotal RabbitMQ up to 3.7.17. It has been classified as problematic. Affected is an unknown function of the component Host Limits Page/Federation Management UI. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2019-11281. It is pos...]]></description>
<link>https://tsecurity.de/de/1991447/sicherheitsluecken/cve-2019-11281-pivotal-rabbitmq-up-to-3717-host-limits-pagefederation-management-ui-cross-site-scripting-rhsa-20200078/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1991447/sicherheitsluecken/cve-2019-11281-pivotal-rabbitmq-up-to-3717-host-limits-pagefederation-management-ui-cross-site-scripting-rhsa-20200078/</guid>
<pubDate>Mon, 15 Jan 2024 15:38:40 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.pivotal:rabbitmq">Pivotal RabbitMQ up to 3.7.17</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected is an unknown function of the component <em>Host Limits Page/Federation Management UI</em>. The manipulation leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.143772">CVE-2019-11281</a>. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Legba - A Multiprotocol Credentials Bruteforcer / Password Sprayer And Enumerator]]></title>
<description><![CDATA[Legba is a multiprotocol credentials bruteforcer / password sprayer and enumerator built with Rust and the Tokio asynchronous runtime in order to achieve  better performances and stability while consuming less resources than similar tools (see the benchmark below).  For the building instructions,...]]></description>
<link>https://tsecurity.de/de/1969871/it-security-nachrichten/legba-a-multiprotocol-credentials-bruteforcer-password-sprayer-and-enumerator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1969871/it-security-nachrichten/legba-a-multiprotocol-credentials-bruteforcer-password-sprayer-and-enumerator/</guid>
<pubDate>Thu, 28 Dec 2023 05:05:43 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBQFZeLxJjRjNE2HSyE7m9AUFrq-NYKLGEYDR7y-Lvmmq9BoNIl41zH1tTomm4nmeZby2JBzYoeFE0FOVLRLkLcgFy83t9vAt2SxWWwQJI0gIa95yqIqF5B1oU4oba7lsZzu5qCIhafLSI05nQaBQsXvbH8k-3UpLQsEdnLL7VGbVtvgRG6e7MC7LT8mOy/s1792/Legba.png" imageanchor="1"><img border="0" data-original-height="1024" data-original-width="1792" height="366" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBQFZeLxJjRjNE2HSyE7m9AUFrq-NYKLGEYDR7y-Lvmmq9BoNIl41zH1tTomm4nmeZby2JBzYoeFE0FOVLRLkLcgFy83t9vAt2SxWWwQJI0gIa95yqIqF5B1oU4oba7lsZzu5qCIhafLSI05nQaBQsXvbH8k-3UpLQsEdnLL7VGbVtvgRG6e7MC7LT8mOy/w640-h366/Legba.png" width="640"></a></div><p><br></p>  <p dir="auto"><code>Legba</code> is a multiprotocol <a href="https://www.kitploit.com/search/label/Credentials" target="_blank" title="credentials">credentials</a> <a href="https://www.kitploit.com/search/label/Bruteforcer" target="_blank" title="bruteforcer">bruteforcer</a> / password sprayer and <a href="https://www.kitploit.com/search/label/Enumerator" target="_blank" title="enumerator">enumerator</a> built with Rust and the Tokio <a href="https://www.kitploit.com/search/label/Asynchronous" target="_blank" title="asynchronous">asynchronous</a> runtime in order to achieve  better performances and stability while consuming less resources than similar tools (see the benchmark below).</p>  <p dir="auto">For the building instructions, usage and the complete list of options <a href="https://github.com/evilsocket/legba/wiki" rel="nofollow" target="_blank" title="check the project Wiki">check the project Wiki</a>.</p><span><a name="more"></a></span><p dir="auto"><br></p>  <h2 dir="auto" tabindex="-1">Supported Protocols/Features:</h2>  <p dir="auto">AMQP (ActiveMQ, RabbitMQ, Qpid, JORAM and Solace), Cassandra/ScyllaDB, DNS subdomain enumeration, FTP, HTTP (basic authentication, NTLMv1, NTLMv2, multipart form, custom requests with CSRF support, files/folders enumeration, virtual host enumeration), IMAP, Kerberos pre-authentication and user enumeration, LDAP, MongoDB, MQTT, <a href="https://www.kitploit.com/search/label/Microsoft" target="_blank" title="Microsoft">Microsoft</a> SQL, MySQL, Oracle, PostgreSQL, POP3, RDP, Redis, SSH / SFTP, SMTP, STOMP (ActiveMQ, RabbitMQ, HornetQ and OpenMQ), TCP port scanning, Telnet, VNC.</p>  <h2 dir="auto" tabindex="-1">Benchmark</h2>  <p dir="auto">Here's a benchmark of <code>legba</code> versus <code>thc-hydra</code> running some common plugins, both targeting the same test servers on localhost. The benchmark has been executed on a macOS laptop with an M1 Max CPU, using a wordlist of 1000 passwords with the correct one being on the last line. Legba was compiled in release mode, Hydra compiled and installed via <a href="https://formulae.brew.sh/formula/hydra" rel="nofollow" target="_blank" title="brew formula">brew formula</a>.</p>  <p dir="auto">Far from being an exhaustive benchmark (some legba features are simply not supported by hydra, such as CSRF token grabbing), this table still gives a clear idea of how using an asynchronous runtime can drastically improve performances.</p>  <table>  <tbody><tr>  <th>Test Name</th>  <th>Hydra Tasks</th>  <th>Hydra Time</th>  <th>Legba Tasks</th>  <th>Legba Time</th>  </tr>  <tr>  <td>HTTP basic auth</td>  <td>16</td>  <td>7.100s</td>  <td>10</td>  <td>1.560s <strong>( 4.5x faster)</strong></td>  </tr>  <tr>  <td>HTTP POST login (wordpress)</td>  <td>16</td>  <td>14.854s</td>  <td>10</td>  <td>5.045s <strong>( 2.9x faster)</strong></td>  </tr>  <tr>  <td>SSH</td>  <td>16</td>  <td>7m29.85s *</td>  <td>10</td>  <td>8.150s <strong>( 55.1x faster)</strong></td>  </tr>  <tr>  <td>MySQL</td>  <td>4 **</td>  <td>9.819s</td>  <td>4 **</td>  <td>2.542s <strong>( 3.8x faster)</strong></td>  </tr>  <tr>  <td>Microsoft SQL</td>  <td>16</td>  <td>7.609s</td>  <td>10</td>  <td>4.789s <strong>( 1.5x faster)</strong></td>  </tr>  </tbody></table>  <p dir="auto"><sup>* While this result would suggest a default delay between connection attempts used by Hydra. I've tried to study the source code to find such delay but to my knowledge there's none. For some reason it's simply very slow.</sup><br>  <sup>** For MySQL hydra automatically reduces the amount of tasks to 4, therefore legba's concurrency level has been adjusted to 4 as well.</sup></p>  <h2 dir="auto" tabindex="-1">License</h2>  <p dir="auto">Legba is released under the GPL 3 license. To see the licenses of the project dependencies, install cargo license with <code>cargo install cargo-license</code> and then run <code>cargo license</code>.</p>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/evilsocket/legba" rel="nofollow" target="_blank" title="Download Legba">Download Legba</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (firefox-esr), Fedora (kernel), Mageia (bluez), Oracle (fence-agents, gstreamer1-plugins-bad-free, opensc, openssl, postgresql:10, and postgresql:12), Red Hat (postgresql:15 and tigervnc), Slackware (proftpd), and SUSE (docker, rootlesskit, firefox, go1...]]></description>
<link>https://tsecurity.de/de/1965530/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1965530/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 21 Dec 2023 15:04:12 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (firefox-esr), <b>Fedora</b> (kernel), <b>Mageia</b> (bluez), <b>Oracle</b> (fence-agents, gstreamer1-plugins-bad-free, opensc, openssl, postgresql:10, and postgresql:12), <b>Red Hat</b> (postgresql:15 and tigervnc), <b>Slackware</b> (proftpd), and <b>SUSE</b> (docker, rootlesskit, firefox, go1.20-openssl, go1.21-openssl, gstreamer-plugins-bad, libreoffice, libssh2_org, poppler, putty, rabbitmq-server, wireshark, xen, xorg-x11-server, and xwayland).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in rabbitmq-server (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1964839/unix-server/security-denial-of-service-in-rabbitmq-server-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1964839/unix-server/security-denial-of-service-in-rabbitmq-server-suse/</guid>
<pubDate>Wed, 20 Dec 2023 22:54:39 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium and rabbitmq-server), Fedora (chromium, kernel, perl-CryptX, and python-jupyter-server), Mageia (curl), Oracle (curl and postgresql), Red Hat (gstreamer1-plugins-bad-free, linux-firmware, postgresql, postgresql:10, and postgresql:15), Slackwar...]]></description>
<link>https://tsecurity.de/de/1958083/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1958083/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 14 Dec 2023 15:30:41 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium and rabbitmq-server), <b>Fedora</b> (chromium, kernel, perl-CryptX, and python-jupyter-server), <b>Mageia</b> (curl), <b>Oracle</b> (curl and postgresql), <b>Red Hat</b> (gstreamer1-plugins-bad-free, linux-firmware, postgresql, postgresql:10, and postgresql:15), <b>Slackware</b> (xorg), <b>SUSE</b> (catatonit, containerd, runc, container-suseconnect, gimp, kernel, openvswitch, poppler, python-cryptography, python-Twisted, python3-cryptography, qemu, squid, tiff, webkit2gtk3, xorg-x11-server, and xwayland), and <b>Ubuntu</b> (xorg-server and xorg-server, xwayland).]]></content:encoded>
</item>
<item>
<title><![CDATA[Debian Security Advisory 5571-1]]></title>
<description><![CDATA[Debian Linux Security Advisory 5571-1 - It was discovered that missing input sanitising in the HTTP API endpoint of RabbitMQ, an implementation of the AMQP protocol, could result in denial of service.]]></description>
<link>https://tsecurity.de/de/1949891/it-security-tools/debian-security-advisory-5571-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1949891/it-security-tools/debian-security-advisory-5571-1/</guid>
<pubDate>Mon, 04 Dec 2023 16:22:58 +0100</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Debian Linux Security Advisory 5571-1 - It was discovered that missing input sanitising in the HTTP API endpoint of RabbitMQ, an implementation of the AMQP protocol, could result in denial of service.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (amanda, ncurses, nghttp2, opendkim, rabbitmq-server, and roundcube), Fedora (golang-github-openprinting-ipp-usb, kernel, kernel-headers, kernel-tools, and samba), Mageia (audiofile, galera, libvpx, and virtualbox), Oracle (kernel and postgresql:13), SU...]]></description>
<link>https://tsecurity.de/de/1949743/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1949743/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 04 Dec 2023 15:30:37 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (amanda, ncurses, nghttp2, opendkim, rabbitmq-server, and roundcube), <b>Fedora</b> (golang-github-openprinting-ipp-usb, kernel, kernel-headers, kernel-tools, and samba), <b>Mageia</b> (audiofile, galera, libvpx, and virtualbox), <b>Oracle</b> (kernel and postgresql:13), <b>SUSE</b> (openssl-3, optipng, and python-Pillow), and <b>Ubuntu</b> (firefox).]]></content:encoded>
</item>
<item>
<title><![CDATA[Denial of Service in rabbitmq-server (Debian)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1948461/it-security-nachrichten/denial-of-service-in-rabbitmq-server-debian/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1948461/it-security-nachrichten/denial-of-service-in-rabbitmq-server-debian/</guid>
<pubDate>Sat, 02 Dec 2023 20:35:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[DSA-5571-1 rabbitmq-server - security update]]></title>
<description><![CDATA[It was discovered that missing input sanitising in the HTTP API endpoint
of  RabbitMQ, an implementation of the AMQP protocol, could result in
denial of service.


https://security-tracker.debian.org/tracker/DSA-5571-1]]></description>
<link>https://tsecurity.de/de/1947898/unix-server/dsa-5571-1-rabbitmq-server-security-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1947898/unix-server/dsa-5571-1-rabbitmq-server-security-update/</guid>
<pubDate>Sat, 02 Dec 2023 01:07:25 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that missing input sanitising in the HTTP API endpoint
of  RabbitMQ, an implementation of the AMQP protocol, could result in
denial of service.

<p>
<a href="https://security-tracker.debian.org/tracker/DSA-5571-1">https://security-tracker.debian.org/tracker/DSA-5571-1</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[System Design Cheatsheets: ElasticSearch]]></title>
<description><![CDATA[Understand how and when to use ElasticSearch in systems, with three practical system design examplesIntroductionWhat is Search? And why it is important?If you’ve read my previous articles on search, you’d know how critical search is to an application. Think about it: out of all the different web ...]]></description>
<link>https://tsecurity.de/de/1943738/ai-nachrichten/system-design-cheatsheets-elasticsearch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1943738/ai-nachrichten/system-design-cheatsheets-elasticsearch/</guid>
<pubDate>Tue, 28 Nov 2023 20:07:16 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Understand how and when to use ElasticSearch in systems, with three practical system design examples</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1000/0*MLNYX-GyxZwzEiYO"></figure><h3>Introduction</h3><h4>What is Search? And why it is important?</h4><p>If you’ve read my previous articles on search, you’d know how critical search is to an application. Think about it: out of all the different web apps and mobile apps you use every day, be it Netflix, Amazon, Swiggy, etc., the search bar is probably the only common UI element in all of them, and that too is usually at the homepage, right at the top. If you are designing a system, ninety-nine times out of a hundred, you’ll think of how to power search.</p><p>Building a search system is no small feat, but a great starting point is ElasticSearch. If you don’t know anything about how search or recommendation systems work, this blog post is a good starting point for you. We will discuss what ElasticSearch is, where it works and where it doesn’t, and three common designs in which ElasticSearch is used. There are a lot more attributes of a search system, but more on that towards the end of the article.</p><h4>What is ElasticSearch?</h4><p>ElasticSearch is a popular database that does something that most databases struggle with: Searching. Searching is so core to ElasticSearch, it’s literally in its name!</p><p>But if you haven’t heard about ElasticSearch, you’re probably thinking: why is searching so difficult? Why can’t a relational database perform a search? Most relational databases support various ways to search and filter through data, like the WHERE query, the LIKE keyword, or indexes. Or why can’t a document database like MongoDB work? You can write find queries in MongoDB as well.</p><p>To understand the answer, imagine you are building a news website. When the user searches for news using your search bar, maybe for “COVID19 infections in New Delhi”, the user is interested in all the articles that <em>talk</em> about COVID infections in New Delhi. In a simple search system, it would mean scanning all the articles in the database, and returning those that contain the words “COVID19”, “infections” or “New Delhi”. You can’t do that with a relational database. A relational database would allow you to search for articles based on specific attributes, for example, articles written by a particular author or articles published today, etc. but it can’t (at least, not efficiently) perform a search in which it scans <em>every single </em>news article (usually in tens of millions) and return those that contain certain words.</p><p>Moreover, there are a lot more intricacies to consider. How do you score these articles? Maybe there is an article that talks about COVID19 infection spread, and maybe there is one that talks about new infections, how do you know which is more relevant to the user query, or in other words, how do you sort these articles based on relevance?</p><p>Answer: ElasticSearch! ElasticSearch can do all this and much much more right out of the box.</p><p>But, like everything else in the world, it comes with its fair share of disadvantages. Let’s discuss what ElasticSearch is, when to use it, and most importantly when it doesn’t make sense.</p><h3>ElasticSearch</h3><h4>Searching Capabilities</h4><p>ElasticSearch provides a way to perform a “full-text search”. Full-text search refers to searching for a phrase or a word in a huge corpus of documents. Let’s continue with our previous example, imagine you are building a news website that contains millions of news articles. Each article contains some data, like a heading, subheading, the content of the article, when it was published, etc. In the context of ElasticSearch, each article is stored as a JSON document.</p><p>You can load all these documents into ElasticSearch and then search for specific words or phrases within each of these documents in a few milliseconds. So if you load up all the news articles, and then perform a search, “COVID19 infections in Delhi”, ElasticSearch returns all the articles that have the words “COVID19”, “infections”, or “Delhi”.</p><p>To demonstrate searching in ElasticSearch, let’s set up Elasticsearch and load some data in it. For this post, I will use <a href="https://www.kaggle.com/datasets/rmisra/news-category-dataset">this News dataset I found on Kaggle</a>(Misra, Rishabh. “News Category Dataset.” arXiv preprint arXiv:2209.11429 (2022)) (<a href="https://towardsdatascience.com/rishabhmisra.github.io/publications">Source</a>) (<a href="https://creativecommons.org/licenses/by/4.0/">License</a>). The dataset is pretty simple, it contains around 210,000 news articles, with their headlines, short descriptions, authors, and some other fields we don’t care much about. We don’t really need all 210,000 documents, so I will load up around 10,000 documents in ES and start searching.</p><p>These are a few examples of the documents in the dataset —</p><pre>[<br>  {<br>    "link": "https://www.huffpost.com/entry/new-york-city-board-of-elections-mess_n_60de223ee4b094dd26898361",<br>    "headline": "Why New York City’s Board Of Elections Is A Mess",<br>    "short_description": "“There’s a fundamental problem having partisan boards of elections,” said a New York elections attorney.",<br>    "category": "POLITICS",<br>    "authors": "Daniel Marans",<br>    "country": "IN",<br>    "timestamp": 1689878099<br>  },<br>  ....<br>]</pre><p>Each document represents a news article. Each article contains a link, headline, a short_description, a category, authors, country(random values, added by me), and timestamp(again random values, added by me).</p><p>Elasticsearch queries are written in JSON. Instead of diving deep into all the different syntaxes you can use to create search queries, let’s start simple and build from there.</p><p>One of the simplest full-text queries is the multi_match query(don’t worry too much about querying data in ElasticSearch, it's pretty simple and we will talk about it towards the end of the article). The idea is simple, you write a query and Elasticsearch performs a full-text search, essentially scanning all the documents in your database, finding those that contain the words in that query, assigning a score to them, and returning them. For example,</p><pre>GET news/_search<br>{<br>  "query": {<br>    "multi_match": {<br>      "query": "COVID19 infections"<br>    }<br>  }<br>}</pre><p>The above query finds relevant articles for the query “COVID19 infections”. These are the results I got back -</p><pre> [<br>      {<br>        "_index" : "news",<br>        "_id" : "czrouIsBC1dvdsZHkGkd",<br>        "_score" : 8.842152,<br>        "_source" : {<br>          "link" : "https://www.huffpost.com/entry/china-shanghai-lockdown-coronavirus_n_62599aa1e4b0723f8018b9c2",<br>          "headline" : "Strict Coronavirus Shutdowns In China Continue As Infections Rise",<br>          "short_description" : "Access to Guangzhou, an industrial center of 19 million people near Hong Kong, was suspended this week.",<br>          "category" : "WORLD NEWS",<br>          "authors" : "Joe McDonald, AP",<br>          "country" : "IN",<br>          "timestamp" : 1695106458<br>        }<br>      },<br>      {<br>        "_index" : "news",<br>        "_id" : "ODrouIsBC1dvdsZHlmoc",<br>        "_score" : 8.064016,<br>        "_source" : {<br>          "link" : "https://www.huffpost.com/entry/who-covid-19-pandemic-report_n_6228912fe4b07e948aed68f9",<br>          "headline" : "COVID-19 Cases, Deaths Continue To Drop Globally, WHO Says",<br>          "short_description" : "The World Health Organization said new infections declined by 5 percent in the last week, continuing the downward trend in COVID-19 infections globally.",<br>          "category" : "WORLD NEWS",<br>          "authors" : "",<br>          "country" : "US",<br>          "timestamp" : 1695263499<br>        }<br>      },<br>      ....<br>]</pre><p>As you can see, it returns documents that discuss COVID19 infections. It also returns them sorted in the order of relevance(The _score field indicates how relevant a particular document is).</p><p>ElasticSearch has a rich query language with a lot of features, but for now, it is enough to know that building a simple search system is very easy, simply load all your data into ElasticSearch and use a simple query that we discussed. We have a plethora of options to improve, configure, and tweak search performance and relevance (again, more on search queries towards the end of this post).</p><h4>Distributed Architecture</h4><p>ElasticSearch works as a distributed database. This means that there are multiple nodes in a single ElasticSearch cluster. If a single node becomes unavailable or fails, that doesn’t usually mean downtime for our system, and other nodes would usually pick up the extra work and continue to serve user requests. So multiple nodes facilitate higher availability.</p><p>Multiple nodes also help us scale our systems, data and user requests can be divided across these nodes which leads to less load per node. For example, if you want to store 100 million news articles in ElasticSearch, you can split that data into multiple nodes, with each node storing a certain set of articles. And it’s pretty easy to do, in fact, ElasticSearch comes with built-in features to make this as simple and seamless as possible.</p><h4>Scalability</h4><p>ElasticSearch scales horizontally and is able to partition data across multiple nodes. This means that you can always improve query performance by adding more nodes to your ElasticSearch cluster.</p><p>There is a lot more thought process about architecting your ElasticSearch cluster than just running more servers though. There are different types of nodes, these nodes run processes called “shards”, and each shard, node, can have multiple types and configuration options. There is a lot to discuss about the architecture of an ElasticSearch cluster and how it works, so I’ve written a complete post on the architecture <a href="https://betterprogramming.pub/system-design-series-elasticsearch-architecting-for-search-5d5e61360463">here</a> if you want to dive deeper into it.</p><p>TLDR: you can add more machines to scale your cluster and improve performance. Data and queries would be divided into multiple machines. This facilitates better performance and high scalability.</p><h4>Document-based data modeling</h4><p>ElasticSearch is a document database, that stores data in JSON document format, similar to MongoDB. So, in our example, every news article is stored as a JSON document in the cluster.</p><h4>Real-time data analysis</h4><p>Real-time data analysis is looking at user actions in real-time and understanding user patterns and behavior. We can chart user behavior and better understand our users, using which we can improve our product. For example, let’s say we measure every single click, scroll event, and reading time per user on our news website. We chart these metrics in a dashboard and observe them for a few days. Using this, we can collect a lot of actionable insights to improve our news app. We found out that users usually use the website at 9–10 AM in the morning, and we found out that users generally click on articles that are relevant to their country. Using this information, we can overprovision resources during peak times (9–10 AM) and maybe show articles from the user’s country on their homepage.</p><p>Elasticsearch is well-suited for real-time data analysis due to its distributed architecture and powerful search capabilities. When dealing with real-time data, such as logs, metrics, or social media updates, Elasticsearch efficiently indexes and stores this information. Its near real-time indexing allows data to be searchable almost instantly after ingestion. ElasticSearch also works well with other tools, like Kibana for visualization or Logstash and Beats for collecting metrics.</p><p>Towards the end of the article, we will look at an architecture that facilitates this.</p><h4>Cost</h4><p>ElasticSearch is expensive to run and maintain. As with everything in this world, everything good comes at a price. To perform full-text search, ElasticSearch keeps a large amount of data in RAM and builds complex indices. This means it requires a lot of RAM to run, which is expensive.</p><p>So, in short, it gives you amazing performance when performing full-text search but it ain’t cheap.</p><h3>When not to use ElasticSearch</h3><h4>ACID compliance</h4><p>ElasticSearch, like most NoSQL databases, has very limited support for ACID, so if you want strong consistency or transactional support, ElasticSearch might not be the choice of database for you. Consequences of this are that if you insert a document (called “indexing” a document in ElasticSearch) in ElasticSearch, it might not be available to other nodes immediately and might take a few milliseconds before it is visible to other nodes.</p><p>Let’s say you are building a banking system; if a user deposits money into his/her account, you want that data visible instantly to every other transaction that the user performs. On the other hand, if you are using ElasticSearch to power searches on your news website when a new article gets published, it's probably acceptable that the article is not visible to all users for the first few milliseconds.</p><h4>When you need complex joins</h4><p>ElasticSearch does not support JOIN operations or relationships among different tables. If you’ve been using relational databases, this might come as a bit of a shock to you but most NoSQL databases have limited support for these types of operations.</p><p>If you want to perform JOINs or use foreign keys for highly related structured data, ElasticSearch may not be the best choice for your use case.</p><h4>Small dataset or simple query needs</h4><p>ElasticSearch is complex and costly. Running and managing a large ElasticSearch cluster not only requires the knowledge and skill of software engineers and DevOps engineers but might even require specialists who excel at managing and architecting ElasticSearch clusters, called “ElasticSearch Architects”. There is a plethora of configuration options and architectural choices to play around with and each one of them has a significant impact on your queries and ingestion, thus having an indirect impact on user experience on core flows in your system.</p><p>If you want to execute simple queries or have relatively low data, then a simple database might be better for your application.</p><h3>How to use ElasticSearch in your system design</h3><p>A single software system would usually require multiple databases, each powering a different set of functionalities. Let’s take an example to understand the design choices of using ElasticSearch better.</p><p>Let’s say you want to build a video streaming service, something like Netflix. Let’s see where ElasticSearch can fit in in this example.</p><h4>As a Search system</h4><p>A very common use case of ElasticSearch is as a secondary database powering full-text search queries. This is very useful for our video streaming application. We can’t store the videos in ElasticSearch, and we probably don’t want to store data related to billing or users in ElasticSearch as well.</p><p>For that, we can have other databases, but we can store the titles of movies, along with their description, genres, ratings, etc. in ElasticSearch.</p><p>We can have an architecture similar to this:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6l5coSDftOAQKzlmXczJ1Q.png"><figcaption>Image by author</figcaption></figure><p>We can ingest data on which we want to power full-text search into ElasticSearch. When the user performs a search operation, we can query the ElasticSearch cluster. This way we get the full-text search capabilities of ElasticSearch and when we want to update user information, we can perform those updates in our primary storage.</p><h4>As a real-time data analysis pipeline</h4><p>As we discussed, understanding user behavior and patterns is an essential step in deciding how to evolve the product. We can publish events, such as clickstream events, and scroll events to better understand how our users use our product.</p><p>For example, in our video streaming application, we can publish an event with user and movie data whenever a user clicks on a movie or a show. We can then analyze and chart aggregations to better understand how users are using our product. For example, we might notice that users use our product more in the evening than in the afternoon or that users may prefer shows or movies in their local language over other languages. Using this, we can develop our product to improve user experience.</p><p>This is how a basic system for real-time data analysis using ElasticSearch and Kibana (a dashboarding tool that works well with ElasticSearch) would look like:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*X9FyPiBJch95VkkddXeVyQ.png"><figcaption>Image by author</figcaption></figure><h4>As a recommendations system</h4><p>We can build queries in ElasticSearch that would give more preference(called boosting) to certain attributes. For example, instead of a simple query</p><p>We can build basic recommendation systems with ElasticSearch. We can store information about the user, such as the user’s country, age, preferences, etc., and generate queries to get popular movie shows or series for that user.</p><p>Understanding the query language and how to boost certain fields, and perform aggregations is a large topic in itself, but I’ve written a blog post covering the basics here:</p><p><a href="https://towardsdatascience.com/mastering-elasticsearch-a-beginners-guide-to-powerful-searches-and-precision-part-1-87686fec9808">Mastering Elasticsearch: A Beginner’s Guide to Powerful Searches and Precision — Part 1</a></p><h3>Conclusion</h3><h4>How to Architect ElasticSearch Clusters?</h4><p>Architecting an ElasticSearch cluster is no easy feat, it requires knowledge of nodes, shards, indexes, and how to orchestrate all of them. There are near-infinite architectural choices to make, and the field is constantly evolving(especially more with the popularity of AI and AI-powered search). To discuss it more, I’ve written a complete blog post that starts from the very basics to everything you’d need to know to architect a search cluster:</p><p><a href="https://betterprogramming.pub/system-design-series-elasticsearch-architecting-for-search-5d5e61360463">System Design Series: ElasticSearch, Architecting for search</a></p><h4>Understanding Search Queries and Improving Search Systems</h4><p>Search is complex, very complex. There are a lot of ways we can improve search systems, making them more powerful and understanding of user needs. You have already learned about ElasticSearch and what it is. Continue this journey as we start from here, build a basic search query, understand the problems in the query and our system, and evolve and improve the system, step-by-step with examples.</p><p><a href="https://towardsdatascience.com/mastering-elasticsearch-a-beginners-guide-to-powerful-searches-and-precision-part-1-87686fec9808">Mastering Elasticsearch: A Beginner’s Guide to Powerful Searches and Precision — Part 1</a></p><h4>Context-aware Searching</h4><p>I recently read a great analogy on search systems. You can think of the search system we have discussed so far as a mechanical, rigid search. When a user enters a word, we find all the documents where the word appears and return them.</p><p>Or you can think of a search system as a librarian. When the user asks a question, let’s say, “What was Winston Churchill’s role in the second world war?”, the librarian doesn’t just tell him the books which have the words “Winston”, “Churchill” or “Second World War”. Instead, the librarian <em>evaluates and understands</em> the customer and the context. Maybe it's a school kid, so instead of recommending a huge textbook, she finds a book more relevant to a younger kid. Or maybe she doesn’t have any book with the title of Winston Churchill, so she finds a book that talks about the Second World War or British prime ministers and recommends that instead. The librarian may even recommend different books for exams and different for summer vacation homework(some of you may not know this, but in some countries, you are given a huge amount of homework for summer vacations)</p><p>This is easy to understand for you and me but how would our system know that Winston Churchill was a British prime minister and recommend books on Britain during the Second World War, or how would our system understand the context of the discussion, understand the user, and recommend appropriate books?</p><p>As difficult as it may seem, it's actually not so hard. It's called Semantic Search and it is how most big tech companies build their search systems. <br>Semantic search is a set of search techniques that aims to understand the meaning behind user queries and the context of content, enabling more accurate and contextually relevant search results by considering the relationships between words and the intent behind the search.</p><p>It's a large topic, and I am still reading and understanding more about it, but a blog post that starts at the basics is coming soon, so if you want to know more about this topic, follow me here on Medium.</p><h4>Other databases</h4><p>I write about system design concepts, like databases, queues, and pub-sub systems, so follow me here on Medium for similar articles. I also write a lot of byte-sized content on LinkedIn (for example, <a href="https://www.linkedin.com/posts/sanil-khurana-a2503513b_system-design-series-apache-kafka-from-10000-activity-7128222185164341248-D-D9?utm_source=share&amp;utm_medium=member_desktop">this post</a> on the differences between RabbitMQ and Kafka), so follow me on LinkedIn for shorter forms of content <a href="https://www.linkedin.com/in/sanil-khurana-a2503513b/">here</a>.</p><p>Meanwhile, you can check out my blog posts on other databases and system design concepts-</p><p><a href="https://medium.com/@sanilkhurana7/lists">Sanil Khurana on Medium curated some lists</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=673b98eebfff" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/system-design-cheatsheets-elasticsearch-673b98eebfff">System Design Cheatsheets: ElasticSearch</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ubuntu Security Notice USN-6501-1]]></title>
<description><![CDATA[Ubuntu Security Notice 6501-1 - It was discovered that RabbitMQ incorrectly handled certain HTTP requests. An attacker could possibly use this issue to cause a denial of service.]]></description>
<link>https://tsecurity.de/de/1937565/it-security-tools/ubuntu-security-notice-usn-6501-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1937565/it-security-tools/ubuntu-security-notice-usn-6501-1/</guid>
<pubDate>Wed, 22 Nov 2023 17:36:51 +0100</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ubuntu Security Notice 6501-1 - It was discovered that RabbitMQ incorrectly handled certain HTTP requests. An attacker could possibly use this issue to cause a denial of service.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (gimp), Fedora (audiofile and firefox), Mageia (postgresql), Red Hat (binutils, c-ares, fence-agents, glibc, kernel, kernel-rt, kpatch-patch, libcap, libqb, linux-firmware, ncurses, pixman, python-setuptools, samba, and tigervnc), Slackware (kernel and ...]]></description>
<link>https://tsecurity.de/de/1937452/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1937452/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 22 Nov 2023 16:31:21 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (gimp), <b>Fedora</b> (audiofile and firefox), <b>Mageia</b> (postgresql), <b>Red Hat</b> (binutils, c-ares, fence-agents, glibc, kernel, kernel-rt, kpatch-patch, libcap, libqb, linux-firmware, ncurses, pixman, python-setuptools, samba, and tigervnc), <b>Slackware</b> (kernel and mozilla), <b>SUSE</b> (apache2-mod_jk, avahi, container-suseconnect, java-1_8_0-openjdk, libxml2, openssl-1_0_0, openssl-1_1, openvswitch, python3-setuptools, strongswan, ucode-intel, and util-linux), and <b>Ubuntu</b> (frr, gnutls28, hibagent, linux, linux-aws, linux-aws-5.15, linux-hwe-5.15, linux-ibm,
 linux-ibm-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15,
 linux-nvidia, linux-oracle, linux-oracle-5.15, linux-raspi, linux, linux-aws, linux-aws-5.4, linux-bluefield, linux-hwe-5.4,
 linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle,
 linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-6.2, linux-hwe-6.2, linux-kvm,
 linux-lowlatency, linux-lowlatency-hwe-6.2, linux-raspi, linux-starfive, linux, linux-aws, linux-aws-hwe, linux-hwe, linux-kvm, linux-oracle, linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5,
 linux-oracle, linux-raspi, linux-starfive, linux-oem-6.1, mosquitto, rabbitmq-server, squid, and tracker-miners).]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-6501-1: RabbitMQ vulnerability]]></title>
<description><![CDATA[It was discovered that RabbitMQ incorrectly handled certain HTTP requests.
An attacker could possibly use this issue to cause a denial of service.]]></description>
<link>https://tsecurity.de/de/1936329/unix-server/usn-6501-1-rabbitmq-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1936329/unix-server/usn-6501-1-rabbitmq-vulnerability/</guid>
<pubDate>Tue, 21 Nov 2023 21:07:26 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that RabbitMQ incorrectly handled certain HTTP requests.
An attacker could possibly use this issue to cause a denial of service.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-46118 | RabbitMQ up to 3.11.23/3.12.6 HTTP API denial of service (GHSA-w6cq-9cf4-gqpg)]]></title>
<description><![CDATA[A vulnerability was found in RabbitMQ up to 3.11.23/3.12.6 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP API. The manipulation leads to denial of service.

This vulnerability is handled as CVE-2023-46118. The attack may be launched remot...]]></description>
<link>https://tsecurity.de/de/1929202/sicherheitsluecken/cve-2023-46118-rabbitmq-up-to-311233126-http-api-denial-of-service-ghsa-w6cq-9cf4-gqpg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1929202/sicherheitsluecken/cve-2023-46118-rabbitmq-up-to-311233126-http-api-denial-of-service-ghsa-w6cq-9cf4-gqpg/</guid>
<pubDate>Wed, 15 Nov 2023 17:16:46 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.rabbitmq">RabbitMQ up to 3.11.23/3.12.6</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this issue is some unknown functionality of the component <em>HTTP API</em>. The manipulation leads to denial of service.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.243266">CVE-2023-46118</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-46120 | RabbitMQ Java Client prior 5.18.0 Message Size denial of service]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in RabbitMQ Java Client. This affects an unknown part of the component Message Size Handler. The manipulation leads to denial of service.

This vulnerability is uniquely identified as CVE-2023-46120. It is possible to initiate the attack re...]]></description>
<link>https://tsecurity.de/de/1928387/sicherheitsluecken/cve-2023-46120-rabbitmq-java-client-prior-5180-message-size-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1928387/sicherheitsluecken/cve-2023-46120-rabbitmq-java-client-prior-5180-message-size-denial-of-service/</guid>
<pubDate>Wed, 15 Nov 2023 09:09:42 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.rabbitmq:java_client">RabbitMQ Java Client</a>. This affects an unknown part of the component <em>Message Size Handler</em>. The manipulation leads to denial of service.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.243207">CVE-2023-46120</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-46118]]></title>
<description><![CDATA[RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP AP...]]></description>
<link>https://tsecurity.de/de/1905740/sicherheitsluecken/cve-2023-46118/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1905740/sicherheitsluecken/cve-2023-46118/</guid>
<pubDate>Wed, 25 Oct 2023 20:57:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerability has been patched in versions 3.11.24 and 3.12.7.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-46120]]></title>
<description><![CDATA[The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects.  Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ ...]]></description>
<link>https://tsecurity.de/de/1905736/sicherheitsluecken/cve-2023-46120/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1905736/sicherheitsluecken/cve-2023-46120/</guid>
<pubDate>Wed, 25 Oct 2023 20:56:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects.  Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from  DoS attacks from RabbitMQ Java client which will ultimately exhaust the memory of the consumer. This vulnerability was patched in version 5.18.0.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-34050]]></title>
<description><![CDATA[In spring AMQP versions 1.0.0 to
2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class
names were added to Spring AMQP, allowing users to lock down deserialization of
data in messages from untrusted sources; however by default, when no allowed
list was provided, all classes c...]]></description>
<link>https://tsecurity.de/de/1898573/sicherheitsluecken/cve-2023-34050/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1898573/sicherheitsluecken/cve-2023-34050/</guid>
<pubDate>Fri, 20 Oct 2023 19:45:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In spring AMQP versions 1.0.0 to
2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class
names were added to Spring AMQP, allowing users to lock down deserialization of
data in messages from untrusted sources; however by default, when no allowed
list was provided, all classes could be deserialized.



Specifically, an application is
vulnerable if




   *  the
     SimpleMessageConverter or SerializerMessageConverter is used

   *  the user
     does not configure allowed list patterns

   *  untrusted
     message originators gain permissions to write messages to the RabbitMQ
     broker to send malicious content]]></content:encoded>
</item>
<item>
<title><![CDATA[Sirius - First Truly Open-Source General Purpose Vulnerability Scanner]]></title>
<description><![CDATA[Sirius is the first truly open-source general purpose vulnerability scanner. Today, the information security community remains the best and most expedient source for cybersecurity intelligence. The community itself regularly outperforms commercial vendors. This is the primary advantage Sirius Sca...]]></description>
<link>https://tsecurity.de/de/1894440/it-security-nachrichten/sirius-first-truly-open-source-general-purpose-vulnerability-scanner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1894440/it-security-nachrichten/sirius-first-truly-open-source-general-purpose-vulnerability-scanner/</guid>
<pubDate>Fri, 20 Oct 2023 19:18:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiAdG2LxP_048EM8l4eitWkGgIcsqhzHvl4YQyF28Udq-g0dmnNoOm5LxTKAPdMebi8EFHvCNT0uK_uLIJEiFyRuWzymDJpsvA3F1Nn6Lf4ANVMZ09N56dPZgW1FpqIFhyp_6tRMjqN2NkDZgujtw0peq1iQxQmH0ttXhgadCCnRWc8fnPq0VljUWSvYcz/s1733/Sirius.png" imageanchor="1"><img border="0" data-original-height="924" data-original-width="1733" height="342" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiAdG2LxP_048EM8l4eitWkGgIcsqhzHvl4YQyF28Udq-g0dmnNoOm5LxTKAPdMebi8EFHvCNT0uK_uLIJEiFyRuWzymDJpsvA3F1Nn6Lf4ANVMZ09N56dPZgW1FpqIFhyp_6tRMjqN2NkDZgujtw0peq1iQxQmH0ttXhgadCCnRWc8fnPq0VljUWSvYcz/w640-h342/Sirius.png" width="640"></a></div><p><br></p>  <p dir="auto">Sirius is the first truly open-source general purpose <a href="https://www.kitploit.com/search/label/Vulnerability" target="_blank" title="vulnerability">vulnerability</a> scanner. Today, the information security community remains the best and most expedient source for <a href="https://www.kitploit.com/search/label/Cybersecurity" target="_blank" title="cybersecurity">cybersecurity</a> intelligence. The community itself regularly outperforms commercial vendors. This is the primary advantage Sirius Scan intends to leverage.</p>  <p dir="auto">The framework is built around four general <a href="https://www.kitploit.com/search/label/Vulnerability%20Identification" target="_blank" title="vulnerability identification">vulnerability identification</a> concepts: The vulnerability database, network vulnerability scanning, agent-based discovery, and custom assessor analysis. With these powers combined around an <a href="https://www.kitploit.com/search/label/Easy%20To%20Use" target="_blank" title="easy to use">easy to use</a> interface Sirius hopes to enable industry evolution.</p><span><a name="more"></a></span><p dir="auto"><br></p>  <h2 dir="auto" tabindex="-1">Getting Started</h2>  <p dir="auto">To run Sirius clone this repository and invoke the <a href="https://www.kitploit.com/search/label/Containers" target="_blank" title="containers">containers</a> with <code>docker-compose</code>. Note that both <code>docker</code> and <code>docker-compose</code> must be installed to do this.</p>  <div><pre><code>git clone https://github.com/SiriusScan/Sirius.git<br>cd Sirius<br>docker-compose up<br></code></pre></div>  <h3 dir="auto" tabindex="-1">Logging in</h3>  <p dir="auto">The default username and password for Sirius is: <code>admin/sirius</code></p>  <h2 dir="auto" tabindex="-1">Services</h2>  <p dir="auto">The system is composed of the following services:</p>  <ul dir="auto">  <li>Mongo: a NoSQL database used to store data.</li>  <li>RabbitMQ: a message broker used to manage communication between services.</li>  <li>Sirius API: the API service which provides access to the data stored in Mongo.</li>  <li>Sirius Web: the web UI which allows users to view and manage their data pipelines.</li>  <li>Sirius Engine: the engine service which manages the execution of data pipelines.</li>  </ul>  <h2 dir="auto" tabindex="-1">Usage</h2>  <p dir="auto">To use Sirius, first start all of the services by running <code>docker-compose up</code>. Then, access the web UI at <code>localhost:5173</code>.</p>  <h3 dir="auto" tabindex="-1">Remote Scanner</h3>  <p dir="auto">If you would like to setup Sirius Scan on a remote machine and access it you must modify the <code>./UI/config.json</code> file to include your server details.</p>  <p dir="auto"><strong>Good Luck! Have Fun! Happy Hacking!</strong></p>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/SiriusScan/Sirius" rel="nofollow" target="_blank" title="Download Sirius">Download Sirius</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Finding Deserialization Bugs in the SolarWinds Platform]]></title>
<description><![CDATA[It’s been a while since I have written a blog post, please accept my sincerest apologies. This is because a lot of fun stuff that I’ve recently done is going to be presented during conferences.Please treat this post as a small introduction to my upcoming Hexacon 2023 talk titled “Exploiting Harde...]]></description>
<link>https://tsecurity.de/de/1893482/hacking/finding-deserialization-bugs-in-the-solarwinds-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1893482/hacking/finding-deserialization-bugs-in-the-solarwinds-platform/</guid>
<pubDate>Fri, 20 Oct 2023 19:07:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">It’s been a while since I have written a blog post, please accept my sincerest apologies. This is because a lot of fun stuff that I’ve recently done is going to be presented during conferences.</p><p class="">Please treat this post as a small introduction to my upcoming <a href="https://www.hexacon.fr/conference/speakers/#dot_net_deserialization" target="_blank">Hexacon 2023 talk</a> titled “Exploiting Hardened .NET Deserialization: New Exploitation Ideas and Abuse of Insecure Serialization”. The entire talk and research was inspired by two small research projects, one of which focused on issues in SolarWinds deserialization.</p><p class="">In this blog post, I would like to present four old vulnerabilities that were fixed within the last year:</p><p class="">— <a href="https://www.zerodayinitiative.com/advisories/ZDI-22-1461/" target="_blank">CVE-2022-38108</a><br>— <a href="https://www.zerodayinitiative.com/advisories/ZDI-22-1460/" target="_blank">CVE-2022-36957</a><br>— <a href="https://www.zerodayinitiative.com/advisories/ZDI-22-1459/" target="_blank">CVE-2022-36958</a><br>— <a href="https://www.zerodayinitiative.com/advisories/ZDI-22-1664/" target="_blank">CVE-2022-36964</a></p><p class="">A small part of the Hexacon talk will show how I have bypassed patches to some of these vulnerabilities. Right now, we will focus on the original issues.</p><p class=""><strong>CVE-2022-38108</strong></p><p class="">This vulnerability was already mentioned in this <a href="https://www.zerodayinitiative.com/blog/2023/2/27/cve-2022-38108-rce-in-solarwinds-network-performance-monitor?rq=solarwinds" target="_blank">blog post</a>. Let me reintroduce it to you in more detail.</p><p class="">Several SolarWinds services communicate with each other through a RabbitMQ instance, which is accessible through port 5671/TCP. Credentials are required to access it. However:</p><p class="">— High-privileged users were able to extract those credentials through SolarWinds Orion Platform.<br>— I later found <a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1006/" target="_blank">CVE-2023-33225</a>, which allowed low-privileged users to extract those credentials.</p>




<p>This vulnerability targeted the SolarWinds Information Service. In order to deliver an AMQP message to the Information Service, the <code>Routing-Key</code> of the message must be set to <code>SwisPubSub</code>.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                  
                  
                  
                  
                  
                  
                  <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc95e220-68b2-4f8b-af96-d355aaa0676a/amqp-1.png" data-image-dimensions="662x452" data-image-focal-point="0.5,0.5" alt="" data-load="false" src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc95e220-68b2-4f8b-af96-d355aaa0676a/amqp-1.png?format=1000w" width="662" height="452" sizes="100vw" srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc95e220-68b2-4f8b-af96-d355aaa0676a/amqp-1.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc95e220-68b2-4f8b-af96-d355aaa0676a/amqp-1.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc95e220-68b2-4f8b-af96-d355aaa0676a/amqp-1.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc95e220-68b2-4f8b-af96-d355aaa0676a/amqp-1.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc95e220-68b2-4f8b-af96-d355aaa0676a/amqp-1.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc95e220-68b2-4f8b-af96-d355aaa0676a/amqp-1.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/cc95e220-68b2-4f8b-af96-d355aaa0676a/amqp-1.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">
                
            
          
        
            
          
        

        
          
          <figcaption class="image-caption-wrapper">
            <p class=""><em>Figure 1 - Routing-Key in AMQP message</em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>Now, let’s verify how SolarWinds handles those messages! We can start with the <code>EasyNetQ.Consumer.HandleBasicDeliver</code> method:</p>

<p>At <code>[1]</code>, the code retrieves the properties of the AMQP message. Those properties are controlled by the attacker who sends the message.</p>
<p>At <code>[2]</code>, it creates an execution context, containing both the AMQP message properties and the message body.</p>
<p>At <code>[3]</code>, it executes a task to consume the message.</p>
<p>This leads us to the <code>Consume</code> method:</p>

<p>At <code>[1]</code>, <code>EasyNetQ.DefaultMessageSerializationStrategy.DeserializeMessage</code> is called. It accepts the message properties and the message body as input. The interesting stuff happens here.</p>

<p>At <code>[1]</code>, we can see something really intriguing. A method named <code>DeSerialize</code> is called and it returns an output of type <code>Type</code>. As an input, it accepts the <code>Type</code> property from the message. That’s right – we can control <code>messageType</code> type through an AMQP message property!</p>
<p>At <code>[2]</code>, it calls <code>BytesToMessage</code>, which accepts both the attacker-controlled type and the message body as input.</p>

<p>At <code>[1]</code>, the message body is decoded as a UTF-8 string. It is expected to contain JSON-formatted data.</p>
<p>At <code>[2]</code>, the deserialization is performed. We control both the target type and the serialized payload.</p>
<p>At <code>[3]</code>, it can be seen that the <code>TypeNameHandling</code> deserialization setting is set to <code>Auto</code>.</p>
<p>We have more than we need to achieve remote code execution here! To do that, we have to send an AMQP message with the <code>Type</code> property set to a dangerous type.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                  
                  
                  
                  
                  
                  
                  <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/607626ca-6fbe-4c67-b7b2-88e5fda9e2e1/amqp-2.png" data-image-dimensions="1070x390" data-image-focal-point="0.5,0.5" alt="" data-load="false" src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/607626ca-6fbe-4c67-b7b2-88e5fda9e2e1/amqp-2.png?format=1000w" width="1070" height="390" sizes="100vw" srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/607626ca-6fbe-4c67-b7b2-88e5fda9e2e1/amqp-2.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/607626ca-6fbe-4c67-b7b2-88e5fda9e2e1/amqp-2.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/607626ca-6fbe-4c67-b7b2-88e5fda9e2e1/amqp-2.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/607626ca-6fbe-4c67-b7b2-88e5fda9e2e1/amqp-2.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/607626ca-6fbe-4c67-b7b2-88e5fda9e2e1/amqp-2.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/607626ca-6fbe-4c67-b7b2-88e5fda9e2e1/amqp-2.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/607626ca-6fbe-4c67-b7b2-88e5fda9e2e1/amqp-2.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">
                
            
          
        
            
          
        

        
          
          <figcaption class="image-caption-wrapper">
            <p class=""><em>Figure 2 - Deserialization Type control through AMQP properties</em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>In the message body, we must deliver the corresponding JSON.NET gadget. I have used a simple <code>WindowsPrincipal</code> gadget from ysoserial.net, which is a bridge for the internally stored BinaryFormatter gadget. Upon the JSON deserialization, the RCE will be achieved through the underlying BinaryFormatter deserialization.</p>

<p>RCE achieved!</p>
<p><b data-preserve-html-node="true">CVE-2022-36957</b></p>
<p>In the previous vulnerability, we were able to fully control the target deserialization type through the AMQP property. When I find such a vulnerability, I like to ask myself the following question: “What does a legitimate message look like?” I often check the types that are being deserialized during typical product operation. It sometimes leads to interesting findings.</p>
<p>I quickly realized that SolarWinds sends messages of one type only:</p>
<p>         <code>SolarWinds.MessageBus.Models.Indication</code></p>
<p>Let’s take a moment to analyze this type:</p>

<p>At <code>[1]</code> and <code>[2]</code>, we can see two public members of type <code>SolarWinds.MessageBus.Models.PropertyBag</code>. The fun begins here.</p>

<p>At <code>[1]</code>, you can see the definition of the class in question, <code>SolarWinds.MessageBus.Models.PropertyBag</code>.</p>
<p>At <code>[2]</code>, a custom converter is registered for this class - <code>SolarWinds.MessageBus.Models. PropertyBagJsonConverter</code>. It implements the <code>ReadJson</code> method, which will be called during deserialization.</p>

<p>At <code>[1]</code>, the code iterates over the JSON properties.</p>
<p>At <code>[2]</code>, a JSON value is retrieved and casted to the <code>JObject</code> type.</p>
<p>At <code>[3]</code>, a <code>Type</code> is retrieved on the basis of the value stored in the <code>t</code> key.</p>
<p>At <code>[4]</code>, the object stored in the <code>v</code> key is deserialized, where we control the target deserialization type (again)!</p>
<p>You can see that we are again able to control the deserialization type! This type is delivered through the <code>t</code> JSON key and the serialized payload is delivered through the <code>v</code> key.</p>
<p>Let’s have a look at a fragment of a legitimate message:</p>

<p>We can take any property, for instance: <code>IndicationId</code>. Then, we need to:<br>•    Set the value of the <code>t</code> key to the name of a malicious type.<br>•    Put a malicious serialized payload in the value of the <code>v</code> key.</p>
<p>As the JSON deserialization settings are set to <code>TypeNameHandling.Auto</code>, it is enough to deliver something like this:</p>

<p>Now, let’s imagine that the first bug described above, CVE-2022-38108, got fixed by hardcoding of the target deserialization type to <code>SolarWinds.MessageBus.Models.Indication</code>. After all, this is the only legitimate type to be deserialized. That fix would not be enough, because <code>SolarWinds.MessageBus.Models.Indication</code> can be used to deliver an inner object, with an attacker-controlled type. We have a second RCE through control of the type here.</p>
<p><b data-preserve-html-node="true">CVE-2022-36958</b></p>
<p>SolarWinds defines some inner methods/operations called “SWIS verbs”. Those verbs can be either:<br>a)    Invoked directly through the API.<br>b)    Invoked indirectly through the Orion Platform Web UI (Orion Platform invokes verbs internally).</p>
<p>There are several things that we need to know about SWIS verbs:<br>•    They are invoked using a payload within an XML structure.<br>•    They accept arguments of predefined types.</p>
<p>For instance, consider the <code>Orion.AgentManagement.Agent.Deploy</code> verb. It accepts 12 arguments. The following screenshot presents those arguments and their corresponding types.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                  
                  
                  
                  
                  
                  
                  <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d2927010-6dc5-466d-9d96-6211e08f3eec/verb-1.png" data-image-dimensions="1562x826" data-image-focal-point="0.5,0.5" alt="" data-load="false" src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d2927010-6dc5-466d-9d96-6211e08f3eec/verb-1.png?format=1000w" width="1562" height="826" sizes="100vw" srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d2927010-6dc5-466d-9d96-6211e08f3eec/verb-1.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d2927010-6dc5-466d-9d96-6211e08f3eec/verb-1.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d2927010-6dc5-466d-9d96-6211e08f3eec/verb-1.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d2927010-6dc5-466d-9d96-6211e08f3eec/verb-1.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d2927010-6dc5-466d-9d96-6211e08f3eec/verb-1.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d2927010-6dc5-466d-9d96-6211e08f3eec/verb-1.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d2927010-6dc5-466d-9d96-6211e08f3eec/verb-1.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">
                
            
          
        
            
          
        

        
          
          <figcaption class="image-caption-wrapper">
            <p class=""><em>Figure 3 - Arguments for Orion.AgentManagement.Agent.Deploy</em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>The handling of arguments is performed by the method <code>SolarWinds.InformationService.Verb. VerbExecutorContext.UnpackageParameters(XmlElement[], Stream)</code>:</p>

<p>At <code>[1]</code>, the <code>Type</code> is retrieved for the given verb argument.</p>
<p>At <code>[2]</code>, a <code>DataContractSerializer</code> is initialized with the retrieved argument type.</p>
<p>At <code>[3]</code> and <code>[4]</code>, the argument is deserialized.</p>
<p>We know that we are dealing with a <code>DataContractSerializer</code>. We cannot control the deserialization types though. My first thought was: I had already found some abusable <code>PropertyBag</code> classes. Maybe there are more to be found here?</p>
<p>It quickly turned out to be a good direction. There are multiple SWIS verbs that accept arguments of a type named <code>SolarWinds.InformationService.Addons.PropertyBag</code>. We can provide arbitrary XML to be deserialized to an object of this type. Let’s investigate!</p>

<p>At <code>[1]</code>, the <code>ReadXml</code> method is defined. It will be called during deserialization.</p>
<p>At <code>[2]</code>, the code iterates over the provided items.</p>
<p>At <code>[3]</code>, the <code>key</code> element is retrieved. If present, the code continues.</p>
<p>At <code>[4]</code>, the value of the <code>type</code> element is retrieved. One may safely assume where it leads.</p>
<p>At <code>[5]</code>, the <code>value</code> element is retrieved.</p>
<p>At <code>[6]</code>, the <code>Deserialize</code> method is called, and the data contained in both the <code>value</code> and <code>type</code> tags are provided as input.</p>
<p>At <code>[7]</code>, the serialized payload and type name are passed to the <code>SolarWinds.InformationService.Serialization.SerializationHelper.Deserialize</code> method.</p>
<p>Again, both the type and the serialized payload are controlled by the attacker. Let’s check this deserialization method.</p>

<p>At <code>[1]</code>, the code checks if the provided type is cached.</p>
<p>If not, the type is retrieved from a string at <code>[2]</code>.</p>
<p>At <code>[3]</code>, the static <code>DeserializeFromStrippedXml</code> is called.</p>

<p>As you can see, the static <code>DeserializeFromStrippedXml</code> method retrieves a serializer object by calling <code>SerializationHelper.serializerCache.GetSerializer(type)</code>. Then, it calls the (non-static) <code>DeserializeFromStrippedXml(string)</code> method on the retrieved serializer object.</p>
<p>Let’s see how the serializer is retrieved.</p>

<p>At <code>[1]</code>, the code tries to retrieve the serializer from a cache. In case of a cache miss, it retrieves the serializer by calling <code>GetSerializerInternal</code> (<code>[2]</code>), so our investigation continues with <code>GetSerializerInternal</code>.</p><p>At <code>[3]</code>, an <code>XmlTypeMapping</code> is retrieved on the basis of the attacker-controlled type. It does not implement any security measures. It is only used to retrieve some basic information about the given type.</p><p>At <code>[4]</code>, an <code>XmlStrippedSerializer</code> object is initialized. Four arguments are supplied to the constructor:<br>•    A new <code>XmlSerializer</code> instance, where the type of the serializer is controlled by the attacker(!).<br>•    The <code>XsdElementName</code> of the target type, obtained from the <code>XmlTypeMapping</code>.<br>•    The <code>Namespace</code> of the type, also obtained from the <code>XmlTypeMapping</code>.<br>•    The type itself.</p><p>So far, we have two crucial facts:<br>•    We are switching deserializers. The overall SWIS verb payload and arguments are deserialized with a <code>DataContractSerializer</code>. However, our <code>PropertyBag</code> object will eventually be deserialized with an <code>XmlSerializer</code>.<br>•    We fully control the type provided to the <code>XmlSerializer</code> constructor, which is a key condition for exploitation.</p><p>It seems that we have it, another RCE through type control in deserialization. As <code>XmlSerializer</code> can be abused through the <code>ObjectDataProvider</code>, we can set the target deserialization type to the following:</p>



  <pre><code>System.Data.Services.Internal.ExpandedWrapper`2[[System.Web.UI.LosFormatter, System.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a],[System.Windows.Data.ObjectDataProvider, PresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35]], System.Data.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e08</code></pre>




<p>However, let’s analyze the <code>XmlStrippedSerializer.DeserializeFromStrippedXml(String)</code> before celebrating.</p>

<p>Something unusual is happening here. At <code>[1]</code>, a new XML string is being created. It has the following structure:</p>
<p>         <code>&lt;XsdElementName xmlns=’Namespace’&gt;ATTACKER-XML&lt;/XsdElementName&gt;</code></p>
<p>To sum up:<br>•    The attacker’s XML gets wrapped with a tag derived from the delivered type (see <code>GetSerializerInternal</code> method).<br>•    Moreover, the retrieved <code>Namespace</code> is inserted into the <code>xmlns</code> attribute.</p>
<p>The attacker controls a major fragment of the final XML and controls the type. However, due to the custom XML wrapping, the <code>ysoserial.net</code> gadget will not work out of the box. The generated gadget looks like this:</p>

<p>The first tag is equal to <code>ExpandedWrapperOfLosFormatterObjectDataProvider</code>. This tag will be automatically generated by the <code>DeserializeFromStrippedXml</code> method, thus we need to remove it from the generated payload! When we do so, the following XML will be passed to the <code>XmlSerializer.Deserialize</code> method:</p>

<p>We still have a major issue here. Can you spot it?</p>
<p>When you compare both the original ysoserial.net gadget and our current gadget, one big difference can be spotted:<br>•    The original gadget defines two namespaces in the root tag: <code>xsi</code> and <code>xsd</code>.<br>•    The current gadget contains an empty <code>xmlns</code> attribute only.</p>
<p>The <code>ObjectInstance</code> tag relies on the <code>xsi</code> namespace. Consequently, deserialization will fail.</p>
<p>Luckily, the namespace does not have to be defined in the root tag specifically. Accordingly, we can fix our gadget by defining both namespaces in the <code>ProjectedProperty0</code> tag. The final gadget is as follows:</p>

<p>In this way, we get a third RCE, where we fully control the target deserialization type!</p>
<p>Here is a fragment of the API request, where the malicious SWIS verb argument is defined:</p>

<p><b data-preserve-html-node="true">CVE-2022-36964</b></p>
<p>Technically, this issue is identical to CVE-2022-36958. However, it exists in a different class that shares the same implementation of the <code>ReadXml</code> method. In this case, the vulnerable class is <code>SolarWinds.InformationService.Contract2.PropertyBag</code>.</p>
<p>An argument of this type is accepted by the <code>TestAlertingAction</code> SWIS verb, thus this issue is exploitable through the API.</p>
<p>This class may appear familiar to some of you. I already abused that same class with JSON.NET deserialization in CVE-2021-31474. Almost one and a half years later, I realized that this class can be abused in a totally different way as well.</p>
<p><b data-preserve-html-node="true">Summary</b></p>
<p>In this blog post, I have shown you four different deserialization vulnerabilities in SolarWinds where the attacker could control the type of the deserialized object. One of them was particularly interesting, because <code>DataContractSerializer</code> could be used to ultimately reach <code>XmlSerializer</code>. During my Hexacon 2023 talk, I will show you some of the patches applied to the described issues and I will show you how I have bypassed them by using custom deserialization gadgets. These patch bypasses have also been patched by SolarWinds, but the discussion will show how hunting deserialization bugs can lead to some fun discoveries.</p>




  <p class="">I hope you liked this writeup. Until my next post, you can follow me <a href="https://twitter.com/chudyPB" target="_blank">@chudypb</a> and follow the team on <a href="https://www.twitter.com/thezdi" target="_blank">Twitter</a>, <a href="https://infosec.exchange/@thezdi" target="_blank">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative" target="_blank">LinkedIn</a>, or <a href="https://www.instagram.com/thezdi" target="_blank">Instagram</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Learn RabbitMQ for Event-Driven Architecture (EDA)]]></title>
<description><![CDATA[A beginner-friendly tutorial on how RabbitMQ works and how to use RabbitMQ in Go, the first steps in learning EDAContinue reading on Towards Data Science »]]></description>
<link>https://tsecurity.de/de/1850701/ai-nachrichten/learn-rabbitmq-for-event-driven-architecture-eda/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1850701/ai-nachrichten/learn-rabbitmq-for-event-driven-architecture-eda/</guid>
<pubDate>Wed, 05 Apr 2023 15:50:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="medium-feed-item"><p class="medium-feed-image"><a href="https://towardsdatascience.com/learn-rabbitmq-for-event-driven-architecture-eda-e1e7377db2b"><img src="https://cdn-images-1.medium.com/max/2600/0*7lt6UoVExJX8LEpi" width="6000"></a></p><p class="medium-feed-snippet">A beginner-friendly tutorial on how RabbitMQ works and how to use RabbitMQ in Go, the first steps in learning EDA</p><p class="medium-feed-link"><a href="https://towardsdatascience.com/learn-rabbitmq-for-event-driven-architecture-eda-e1e7377db2b">Continue reading on Towards Data Science »</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-24567 | Dell NetWorker up to 19.5 RabbitMQ information disclosure (dsa-2023-058)]]></title>
<description><![CDATA[A vulnerability has been found in Dell NetWorker up to 19.5 and classified as problematic. This vulnerability affects unknown code of the component RabbitMQ. The manipulation leads to information disclosure.

This vulnerability was named CVE-2023-24567. The attack can be initiated remotely. There...]]></description>
<link>https://tsecurity.de/de/1841934/sicherheitsluecken/cve-2023-24567-dell-networker-up-to-195-rabbitmq-information-disclosure-dsa-2023-058/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1841934/sicherheitsluecken/cve-2023-24567-dell-networker-up-to-195-rabbitmq-information-disclosure-dsa-2023-058/</guid>
<pubDate>Thu, 30 Mar 2023 07:38:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.dell:networker">Dell NetWorker up to 19.5</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This vulnerability affects unknown code of the component <em>RabbitMQ</em>. The manipulation leads to information disclosure.

This vulnerability was named <a href="https://vuldb.com/?source_cve.222088">CVE-2023-24567</a>. The attack can be initiated remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-24567]]></title>
<description><![CDATA[Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.]]></description>
<link>https://tsecurity.de/de/1812862/sicherheitsluecken/cve-2023-24567/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1812862/sicherheitsluecken/cve-2023-24567/</guid>
<pubDate>Tue, 07 Mar 2023 06:28:57 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-38108: RCE in SolarWinds Network Performance Monitor]]></title>
<description><![CDATA[In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Justin Hong and Lucas Miller of the Trend Micro Research Team detail a recently patched remote code execution vulnerability in the SolarWinds Network Performance Monitor. This bug was originally discovered and r...]]></description>
<link>https://tsecurity.de/de/1810351/hacking/cve-2022-38108-rce-in-solarwinds-network-performance-monitor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1810351/hacking/cve-2022-38108-rce-in-solarwinds-network-performance-monitor/</guid>
<pubDate>Tue, 07 Mar 2023 06:24:22 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Justin Hong and Lucas Miller of the Trend Micro Research Team detail a recently patched remote code execution vulnerability in the SolarWinds Network Performance Monitor. This bug was originally discovered and reported by ZDI Vulnerability Research Piotr Bazydło. The vulnerability results from the lack of proper validation of user-supplied data, which can result in the deserialization of untrusted data. An authenticated attacker can leverage this vulnerability to execute code in the context of SYSTEM. The following is a portion of their write-up covering CVE-2022-38108, with a few minimal modifications.</em></p>


<hr><p>An insecure deserialization vulnerability has been reported in SolarWinds Network Performance Monitor. The vulnerability is due to insufficient validation of user-supplied data in the <code>BytesToMessage</code> function. A remote, authenticated attacker could exploit the vulnerability by sending crafted requests to an affected server. Successful exploitation can result in arbitrary code execution under the security context of SYSTEM. This vulnerability has been <a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2022-38108">patched</a> by SolarWinds and assigned CVE-2022-38108.</p>



<p class=""><strong>The Vulnerability</strong></p><p class="">The SolarWinds Orion Platform is the base platform used by numerous SolarWinds products. The platform is designed to seamlessly integrate all Orion-based products into a single interface. Network Performance Monitor (NPM) is one of these SolarWinds products and is used to monitor multi-vendor network devices and servers. </p><p class="">The SolarWinds Orion platform adapts RabbitMQ, an open-source message broker, to send and receive messages between various software components and agents. RabbitMQ supports Advanced Message Queuing Protocol version 0-9-1 (<a href="https://www.rabbitmq.com/protocol.html">AMQP 0-9-1</a>), which is used by the SolarWinds platform. The SolarWinds Information Service (SWIS) is one of the modules that uses RabbitMQ to communicate with other services in the SolarWinds Orion Platform. </p><p class="">To send a message to SWIS, a sender can place message content in AMQP frames with the routing-key set to “SwisPubSub” and send these frames to RabbitMQ via TCP port 5671. The details of AMQP 0-9-1 frame format will be described in the detection section below.</p><p class="">JavaScript Object Notation (JSON) is a data-interchange format used for creating machine parseable human-readable output. A JSON object has the following syntax: </p><p class="">— An object is enclosed in curly braces {}<br>— An object comprises of zero or more items delimited by a comma (",") character.<br>— An item comprises of a key and a value. A key is delimited from its value by a colon (":") character.<br>— A key must be a string (enclosed in quotes).<br>— A value must be a valid type. Valid types include string, number, JSON object, array, boolean or nul<br>— An array is an object enclosed in square braces [].<br>— An array comprises of zero or more string, number, JSON object, array, boolean or null type-objects delimited by a comma (",") character.</p><p class="">An example JSON object is as follows:  </p>


<p>         <code>{"name":"bob", "age":30}</code></p>



<p class="">An insecure deserialization vulnerability exists in SolarWinds NPM. The message content sent to SWIS via RabbitMQ contains Json.NET serialized objects. When receiving the message content, the <em>DeserializeMessage() </em>method of the .NET class <em>EasyNetQ.DefaultMessageSerializationStrategy </em>is called to process the message content. The method will call the <em>BytesToMessage() </em>method of the .NET class <em>SolarWinds.MessageBus.RabbitMQ.EasyNetQSerializer </em>to deserialize the message content. <em>BytesToMessage() </em>will call the <em>DeserializeObject() </em>method of the .NET class <em>SolarWinds.Newtonsoft.Json.JsonConvert, </em>which will eventually call the <em>Deserialize() </em>method of the .NET class <em>SolarWinds.Newtonsoft.Json.Serialization.JsonSerializerInternalReader </em>to deserialize the Json.NET serialized object. </p><p class="">However, all the methods mentioned above have no proper validation of the message content to see if the given object type is safe to be deserialized. Although SolarWinds already has a .NET class <em>BlackListBinder </em>that checks a given object type against suspicious type names, the SWIS application does not utilize <em>BlackListBinder </em>when processing message content from RabbitMQ. An attacker can send a message to the SWIS application via RabbitMQ and the message content contains a malicious Json.NET serialized object derived from known Json.NET deserialization gadgets from <a href="https://github.com/pwntester/ysoserial.net">YsoSerial.Net</a> and trigger arbitrary code execution on the server. </p><p class="">A remote attacker who has the credentials to access the RabbitMQ message broker could exploit the vulnerability by sending crafted messages to the target application via RabbitMQ. Successful exploitation can result in arbitrary code execution under the security context of SYSTEM. </p><p class=""><strong>Source Code Walkthrough</strong></p><p class="">The following code snippet was taken from SolarWinds NPM version 2020.2.6. Comments added by Trend Micro have been highlighted. </p><p class="">In decompiled .NET class <em>EasyNetQ.DefaultMessageSerializationStrategy</em>:</p>





<p class="">In decompiled .NET class <em>SolarWinds.MessageBus.RabbitMQ.EasyNetQSerializer</em>: </p>





<p class="">In decompiled .NET class <em>SolarWinds.Newtonsoft.Json.Serialization.JsonSerializerInternalReader</em>:</p>





<p class=""><strong>Exploit Detection</strong></p><p class="">To detect an attack exploiting this vulnerability, the detection device must monitor and parse traffic on TCP port 5671. Note that traffic is encrypted via SSL/TLS and should be decrypted before performing the following steps. </p><p class="">The detection device must first determine if the client is attempting to initiate an AMQP 0-9-1 connection by looking for the protocol header as the format shown below: </p>



<p>If such an AMQP protocol header is found, the detection device must continue to monitor the traffic and look for AMQP 0-9-1 frames. </p>
<p><b data-preserve-html-node="true">AMQP 0-9-1 frames</b></p>
<p>AMQP 0-9-1 frames carry protocol methods, message content, and other information. All frames have the same general format: frame header, payload, and frame end. The frame end is represented by the byte value <code>\xCE</code>. The general frame format is shown as below: </p>




<p class="">There are four frame types in AMQP 0-9-1: <em>Method</em>, <em>Content header</em>, <em>Content body</em>, and <em>Heartbeat </em>frames. Each frame type has its own <em>frame payload </em>format. The payload format of <em>Method</em>, <em>Content header</em>, and <em>Content body </em>frame are related to this report and will be described in the following paragraphs. Note that, in the following paragraphs, the "Offset" value is relative to the beginning of the <em>frame payload </em>(offset 0x07 in the general frame format shown above). </p><p class=""> The payload format of the <em>Method</em> frame is as shown below:</p>





<p class="">The <em>Method Arguments List </em>field, depending on its <em>Method id</em>, can contain zero or more data values of various data types. Each data type is represented in its own specification. The data types include integer, bits, string, timestamp, and field table (key/value pair). The details of each data representation will not be described in this report.</p><p class="">The payload format of the <em>Content</em> header frame is as shown below: </p>





<p class="">The user data that a sender wants to send to the receiver can be carried in one or more <em>Content body </em>frames following the <em>Content header </em>frame. That is, the user data can be split into several <em>Content body </em>frames. The <em>Body size </em>field of the <em>Content header </em>frame is to record the total size of the original user data (before being split) sent by the sender.</p><p class="">The payload format of the <em>Content</em> body frame is as shown below: </p>



<p>The <em>Binary</em> content field carries the whole (if not split) or a part of user data that the sender wants to send to the receiver. </p>
<p>The detection device must first look for the <em>Method</em> frame which contains the routing-key “SwisPubSub”. To do this, the detection device must check each frame to see if its <em>frame type</em> is <code>\x01</code> and <em>Class id</em> is <code>\x3c</code> (Basic class) and <em>Method id</em> is <code>\x28</code> (Publish) and its <em>Method Argument</em> List field contains the string “SwisPubSub”. If such a frame is found, the detection device must continue to look for the <em>Content</em> body frame and inspect its <em>Binary content</em> field as JSON-format data to see if it contains a malicious serialized object. Note that the JSON-format data could be split into multiple <em>Content body</em> frames and the detection device must be able to assemble all <em>Binary content</em> fields together from these <em>Content body</em> frames before inspecting it. </p>
<p>The JSON-format data must be inspected using any suitable parsing method below: </p>
<p><em>Method 1 - The detection device can parse JSON</em></p>
<p>The detection device must search for the “$type” key and check if its value begins with any of the following strings: </p>




<p class="">If found, the traffic should be considered malicious and an attack exploiting this vulnerability is likely underway. </p><p class="">Using the class names (like “<em>System.Windows.Data.ObjectDataProvider</em>”) as the indication of the exploitation of this vulnerability is based on the observation that this insecure deserialization vulnerability relies on the use YsoSerial.Net gadget that works with Json.NET, and also based on the fix from the SolarWinds NPM program update, which uses a deny-list method to verify the type of the serialized object. </p><p class=""><em>Method 2 - String-based detection </em></p><p class="">The detection device must check if the JSON-format data contains a string that can be matched with the regular expression as below: </p>





<p class="">If found, the traffic should be considered malicious and an attack exploiting this vulnerability is likely underway. Below is an example of a malicious serialized object in JSON-format: </p>





<p class="">Note that all string matching should be performed in a case-insensitive manner.</p><p class=""><strong>Conclusion</strong></p><p class="">SolarWinds <a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2022-38108">addressed</a> this vulnerability with the release of SolarWinds Platform version 2022.4 RC1 and later. In addition to installing the updated version, enterprises can also protect themselves by blocking the affected ports from external network access if they are not required. The vendor also recommends applying proper segmentation controls on the network where you have deployed the SolarWinds Platform and SQL Server instances. This should also be considered a best practice and a part of a robust defense-in-depth strategy. They also recommend that customers follow the guidance provided in the <a href="https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm" target="_blank">SolarWinds Secure Configuration Guide</a>. Finally, ensure only authorized users can access the SolarWinds Platform. </p><p class="">Special thanks to Justin Hong and Lucas Miller of the Trend Micro Research Team for providing such a thorough analysis of this vulnerability. For an overview of Trend Micro Research services please visit <a href="http://go.trendmicro.com/tis/">http://go.trendmicro.com/tis/</a>.</p><p class="">The threat research team will be back with other great vulnerability analysis reports in the future. Until then, follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi" target="_blank">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative" target="_blank">LinkedIn</a>, or <a href="https://www.instagram.com/thezdi">Instagram</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-24447 | RabbitMQ Consumer Plugin up to 2.8 on Jenkins AMQP URL cross-site request forgery]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in RabbitMQ Consumer Plugin up to 2.8. Affected is an unknown function of the component AMQP URL Handler. The manipulation leads to cross-site request forgery.

This vulnerability is traded as CVE-2023-24447. It is possible to launch...]]></description>
<link>https://tsecurity.de/de/1809269/sicherheitsluecken/cve-2023-24447-rabbitmq-consumer-plugin-up-to-28-on-jenkins-amqp-url-cross-site-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1809269/sicherheitsluecken/cve-2023-24447-rabbitmq-consumer-plugin-up-to-28-on-jenkins-amqp-url-cross-site-request-forgery/</guid>
<pubDate>Thu, 23 Feb 2023 10:35:20 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.rabbitmq_consumer_plugin">RabbitMQ Consumer Plugin up to 2.8</a>. Affected is an unknown function of the component <em>AMQP URL Handler</em>. The manipulation leads to cross-site request forgery.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.219576">CVE-2023-24447</a>. It is possible to launch the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-24448 | RabbitMQ Consumer Plugin up to 2.8 on Jenkins permission]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in RabbitMQ Consumer Plugin up to 2.8. This affects an unknown part. The manipulation leads to permission issues.

This vulnerability is uniquely identified as CVE-2023-24448. The attack needs to be approached within the local networ...]]></description>
<link>https://tsecurity.de/de/1804666/sicherheitsluecken/cve-2023-24448-rabbitmq-consumer-plugin-up-to-28-on-jenkins-permission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1804666/sicherheitsluecken/cve-2023-24448-rabbitmq-consumer-plugin-up-to-28-on-jenkins-permission/</guid>
<pubDate>Mon, 20 Feb 2023 14:50:52 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.rabbitmq_consumer_plugin">RabbitMQ Consumer Plugin up to 2.8</a>. This affects an unknown part. The manipulation leads to permission issues.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.219513">CVE-2023-24448</a>. The attack needs to be approached within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[When Milliseconds Matter — My Journey to Performance Improvement]]></title>
<description><![CDATA[When Milliseconds Matter — My Journey to Performance ImprovementLessons Learned From a Latency Improvement Projectpicture by Giallo from PexelsWorking under a strict SLA, where milliseconds matter, while maintaining a complex system with multiple dependencies — can expose us to many challenges an...]]></description>
<link>https://tsecurity.de/de/1798788/ai-nachrichten/when-milliseconds-matter-my-journey-to-performance-improvement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1798788/ai-nachrichten/when-milliseconds-matter-my-journey-to-performance-improvement/</guid>
<pubDate>Wed, 15 Feb 2023 17:35:09 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>When Milliseconds Matter — My Journey to Performance Improvement</h3><h4>Lessons Learned From a Latency Improvement Project</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*uAsMEPw6JJa52JlD"><figcaption>picture by <a href="https://www.pexels.com/@giallo/">Giallo</a> from <a href="https://www.pexels.com/photo/assorted-silver-colored-pocket-watch-lot-selective-focus-photo-859895/">Pexels</a></figcaption></figure><p><em>Working under a strict SLA, where milliseconds matter, while maintaining a complex system with multiple dependencies — can expose us to many challenges and non-trivial investigations when latency-related issues occur.</em></p><p><em>In this article, I will walk you through my journey to improve our system’s performance, initiated by a problem of the type described above, and the lessons learned along the way.</em></p><h4>Step 1 — Expected Behavior and Problem’s Description</h4><p>The company’s product handles transactions, and for each transaction received — we either approve or decline it.</p><p>For some of the transactions, we go through a data enrichment step, to obtain more information for our real-time decisions, and future transactions.</p><p>However, for tens of thousands of transactions per day — the enrichment process simply did not take place, and it wasn’t clear why.</p><h4>Step 2 — Searching for a Lion In the Desert</h4><p>Let’s look at a simplified view of the relevant systems:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*JV46-CZMj9_rAhbK"><figcaption>sketch by author</figcaption></figure><p>As this was an enrichment issue, the first question was — did the problem occur within the enrichment service, or even before we got there? And apparently, for these problematic transactions, we never even sent a fetch request to the Enrichment service. One suspect down.</p><h4>Step 3 — Getting to Know Our Topology</h4><p>Let’s take a break from our story. I want to introduce you to the Decision-Making system’s topology. This system is based on <a href="https://storm.apache.org/releases/2.2.0/Concepts.html">Apache Storm</a>, which is designed to process unbounded streams of data in real time.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*P0RatHTmPrSE46oQ"><figcaption>sketch by author</figcaption></figure><p>In a nutshell, the Spout receives the data from a data source (e.g. Kafka / RabbitMQ) and outputs streams into the topology. Each Bolt is a component in the topology, which receives and emits one or more streams. A Bolt conducts simple logic to process the stream such as filtering, aggregating, reading from DBs and writing to them, and more.</p><p>Some Bolts run in parallel, while others are dependent on one another.<br>Some Bolts will anchor a relative timeout value, after which they will proceed (process streams and emit them) whether or not they received all the inputs they have been waiting for.<br>The usage of timeouts prevents Bolts and components from delaying the topology for too long, thus enabling us to meet the expected SLA.</p><h4>Step<strong> 4 — Why No Enrichment?</strong></h4><p>Back to our story. Why didn’t the Decision-Making system execute the calls to the Enrichment service? I added some metrics and found out that an important condition was met for the problematic transactions — the spare time that was left for the Enrichment process was not enough, so the fetch call wasn’t executed in order to leave enough time for future Bolts.</p><p>This was surprising. Enrichment is a core component in the flow and takes place relatively at the beginning of the topology. How come we don’t have enough time left to execute this call?</p><h4>Step<strong> 5 — Dependencies and Latencies</strong></h4><p>To understand why we’re out of (relative) time, I dug into a view provided by an internal tool and looked backward at the Bolts my Enrichment-Bolt was dependent on. <br>I found an earlier Bolt which consistently took about 100 milliseconds. Considering our SLA, and the average time a Bolt is supposed to take, this was considered A LOT.<br> What happened in this parent Bolt that took so long?</p><p>When diving into the parent Bolt’s code, I saw an elasticsearch query and wondered if this could be the reason for our bottleneck.</p><p>And it was — when looking at the relevant dashboards, I found a correlation between the hours in the day my Bolt had high latency, and when this cluster had high CPU usage.</p><p>After syncing with the team that maintains this cluster, I learned they were familiar with its long-standing performance issues, and its gradual degradation.</p><h4>Step 6 — Is This Dependency Necessary?</h4><p>Why is the Enrichment-Bolt dependent on this elasticsearch query? Is it justifying the price we’re paying in the form of unenriched transactions?</p><p>In the Enrichment context — we were waiting for this query’s results for a specific feature, but further investigation showed that the given feature had a bug, God knows for how long, so we weren’t making use of the feature’s desired output.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*7-0sqhYugKxDhKj_"><figcaption>sketch by author</figcaption></figure><p>If we delete this feature, we can disconnect the dependency between Enrichment and the Bolt that calls the problematic elasticsearch cluster. If we fix the bugged feature — we’ll get back to receiving the data someone intended to make use of, but keep our high-latency-dependency and will need to look for alternative solutions.</p><p>After considering a few potential paths for resolution — effort, and cost-effectiveness of each such path, and having received the bugged-feature-owners blessing to delete this piece of code — I removed the bugged feature.</p><h4>Step 7 — Time to Make Delicate Changes to Our Topology</h4><p>The Decision-Making system is dependencies-based, and at this point, I wanted to have the Enrichment component dependent on a component that took place earlier than the one which called the problematic cluster. Such a change would save the time we were waiting for the high-latency query, and the earlier our new-depending-component takes place — the more spare time will be left for Enrichment and its subsequent components.</p><p>After investigating the code, and choosing the new parent component with the higher-ups, I made this delicate change and monitored the results.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*yCt6XmNieDOWq0Qf"><figcaption>sketch by author</figcaption></figure><h4>Step 8 — What Are the Results?</h4><p>At first, no dramatic improvement was seen after my changes were in prod. What a bummer! Months of investigation and anticipation, and the change in rate was minor. But we shall not despair!</p><p>I checked the unenriched transactions and saw they also met the timeout condition. I investigated the dependencies view and saw that via a different path — they are still dependent on the problematic component!</p><p>The reason for that was that the Enrichment Bolt waited for a few fields whose parent Bolts were leading, again, to our high-latency-Bolt that queried the high-latency-cluster. <br>But these fields were not used in the code.</p><p>I deleted those fields, and was glad to see the results:</p><p>The daily rate of unenriched transactions was reduced from 26K to 200.</p><p>Also, at the beginning — for some merchants, the percentage of such problematic transactions was up to 20%, and after my changes — all merchants had no more than 1% of their transactions with this issue.</p><p><strong>Great success!</strong></p><h4><strong>Lessons Learned:</strong></h4><p>I learned a lot along the way. I investigated, using various technologies, dug into complex code that is also based on a complex architecture, analyzed latencies, and considered different trade-offs to resolve the problem. But here are some tips I want to share with you today:</p><ul><li><strong>Deleting Code Is Good<br></strong>A good software engineer is not measured by the amount of new code she writes. Deleting code is an important task, and deleting deprecated code that overloads the system can be crucial to improve the system’s performance. Taking the time to investigate may require patience and resilience, but it could lead to precious results.</li><li><strong>Code Deletion Should Be Done Thoroughly</strong><br>One of the reasons for having component A dependent on component B was due to input fields that weren’t used within the component. As we delete code, it is a good practice to take the time to ask ourselves if we deleted everything related to it, and left no trailing tails.</li><li><strong>Invest in Profiling Tools</strong><br>One of the things that enabled me to detect the high-latency component was an internal profiling tool. We need visibility into our components, their dependencies, and their latencies, and we need such a tool to be intuitive and comfortable to use.</li><li><strong>Consider Monitoring Latency of Specific Components In Your Flows</strong><br>When milliseconds matter, monitoring the latency of each component could be the key to identifying the sources of your bottlenecks. Consider adding metrics to measure your components’ latencies upon creating them, to have this data accessible when you need it.</li><li><strong>Master the Technologies You Work With, Learn How to Investigate with Them<br></strong>Each technology our team uses has its powers and tricks. As we encounter a new technology or new tool, we might learn what we need for our daily use, and move on. But investing the time to learn which additional insights can be derived using the tool might come in handy when we are swamped with questions to investigate.</li><li><strong>Consult and Brainstorm<br></strong>Complex investigations can be hard, and a colleague might be familiar with investigation tools we weren’t aware of, or suggest a different perspective on our problem. Keep in mind that your project’s success is your team’s and company’s success, and loop colleagues in if you feel stuck or in need of another opinion.</li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5a3cd69754c4" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/when-milliseconds-matter-my-journey-to-performance-improvement-5a3cd69754c4">When Milliseconds Matter — My Journey to Performance Improvement</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DC-Sonar - Analyzing AD Domains For Security Risks Related To User Accounts]]></title>
<description><![CDATA[DC Sonar Community  Repositories  The project consists of repositories:  dc-sonar-frontend  dc-sonar-user-layer  dc-sonar-workers-layer  ntlm-scrutinizer  Disclaimer  It's only for education purposes.  Avoid using it on the production Active Directory (AD) domain.  Neither contributor incur any r...]]></description>
<link>https://tsecurity.de/de/1785752/it-security-nachrichten/dc-sonar-analyzing-ad-domains-for-security-risks-related-to-user-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1785752/it-security-nachrichten/dc-sonar-analyzing-ad-domains-for-security-risks-related-to-user-accounts/</guid>
<pubDate>Wed, 08 Feb 2023 04:45:09 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://blogger.googleusercontent.com/img/a/AVvXsEh4T_TaJ_WITYbBqoWyvHgSUq1IW13NIF2MOl8t3_g3AYj44B1G_tS0PsJ6EHo9flgZui2dSIwMo4neB9Yw-CYFF4tjSyIiM_QMS8CNUqMqEKZFYSJmFevxnYASeRjNI4XGVJNjRxe6xR7LQnWXBqCwJFmlYKW0wS3wcbSALpKIRivwH4bRmRj5_I2fVA"><img alt="" border="0" height="314" src="https://blogger.googleusercontent.com/img/a/AVvXsEh4T_TaJ_WITYbBqoWyvHgSUq1IW13NIF2MOl8t3_g3AYj44B1G_tS0PsJ6EHo9flgZui2dSIwMo4neB9Yw-CYFF4tjSyIiM_QMS8CNUqMqEKZFYSJmFevxnYASeRjNI4XGVJNjRxe6xR7LQnWXBqCwJFmlYKW0wS3wcbSALpKIRivwH4bRmRj5_I2fVA=w640-h314" width="640"></a></p><h1 dir="auto">DC Sonar Community</h1>  <h2 dir="auto">Repositories</h2>  <p dir="auto">The project consists of repositories:</p>  <ul dir="auto"><li><a href="https://github.com/ST1LLY/dc-sonar-frontend" rel="nofollow" target="_blank" title="dc-sonar-frontend">dc-sonar-frontend</a></li>  <li><a href="https://github.com/ST1LLY/dc-sonar-user-layer" rel="nofollow" target="_blank" title="dc-sonar-user-layer">dc-sonar-user-layer</a></li>  <li><a href="https://github.com/ST1LLY/dc-sonar-workers-layer" rel="nofollow" target="_blank" title="dc-sonar-workers-layer">dc-sonar-workers-layer</a></li>  <li><a href="https://github.com/ST1LLY/ntlm-scrutinizer" rel="nofollow" target="_blank" title="ntlm-scrutinizer">ntlm-scrutinizer</a></li>  </ul><h2 dir="auto">Disclaimer</h2>  <p dir="auto">It's only for education purposes.</p>  <p dir="auto">Avoid using it on the production <a href="https://www.kitploit.com/search/label/Active%20Directory" target="_blank" title="Active Directory">Active Directory</a> (AD) domain.</p>  <p dir="auto">Neither contributor incur any responsibility for any using it.</p>  <h2 dir="auto">Social media</h2>  <p dir="auto">Check out our Red Team community <a href="https://t.me/RedTeambro" rel="nofollow" target="_blank" title="Telegram channel">Telegram channel</a></p>  <h2 dir="auto">Description</h2>  <h3 dir="auto">Architecture</h3>  <p dir="auto">For the visual descriptions, open the <a href="https://github.com/ST1LLY/dc-sonar/tree/main/diagrams" rel="nofollow" target="_blank" title="diagram files">diagram files</a> using the <a href="https://www.diagrams.net/" rel="nofollow" target="_blank" title="diagrams.net">diagrams.net</a> tool.</p>  <p dir="auto">The app consists of:</p>  <ul dir="auto"><li>The <a href="https://github.com/ST1LLY/dc-sonar-frontend" rel="nofollow" target="_blank" title="dc-sonar-frontend">dc-sonar-frontend</a> is the fronted part of the user web interface bases on:  <ul dir="auto"><li><a href="https://angular.io/" rel="nofollow" target="_blank" title="Angular">Angular</a></li>  <li><a href="https://material.angular.io/" rel="nofollow" target="_blank" title="Angular Material">Angular Material</a></li>  </ul></li>  <li>The <a href="https://github.com/ST1LLY/dc-sonar-user-layer" rel="nofollow" target="_blank" title="dc-sonar-user-layer">dc-sonar-user-layer</a> is the backend part of the web app bases on:  <ul dir="auto"><li><a href="https://www.python.org/downloads/" rel="nofollow" target="_blank" title="Python 3.10">Python 3.10</a></li>  <li><a href="https://www.djangoproject.com/" rel="nofollow" target="_blank" title="Django">Django</a></li>  <li><a href="https://docs.djangoproject.com/en/4.0/topics/db/queries/" rel="nofollow" target="_blank" title="Django ORM">Django ORM</a></li>  <li><a href="https://www.django-rest-framework.org/" rel="nofollow" target="_blank" title="Django REST framework">Django REST framework</a></li>  <li><a href="https://docs.celeryq.dev/en/latest/changelog.html" rel="nofollow" target="_blank" title="Celery">Celery</a></li>  <li><a href="https://www.rabbitmq.com/" rel="nofollow" target="_blank" title="RabbitMQ">RabbitMQ</a></li>  <li><a href="https://www.postgresql.org/" rel="nofollow" target="_blank" title="PostgreSQL">PostgreSQL</a></li>  </ul></li>  <li>The <a href="https://github.com/ST1LLY/dc-sonar-workers-layer" rel="nofollow" target="_blank" title="dc-sonar-workers-layer">dc-sonar-workers-layer</a> is the logic layer that performs and runs analyzing processes which base on:  <ul dir="auto"><li><a href="https://www.python.org/downloads/" rel="nofollow" target="_blank" title="Python 3.10">Python 3.10</a></li>  <li><a href="https://www.sqlalchemy.org/" rel="nofollow" target="_blank" title="SQLAlchemy">SQLAlchemy</a></li>  <li><a href="https://alembic.sqlalchemy.org/en/latest/tutorial.html" rel="nofollow" target="_blank" title="Alembic">Alembic</a></li>  <li><a href="https://apscheduler.readthedocs.io/en/3.x/" rel="nofollow" target="_blank" title="APScheduler">APScheduler</a></li>  <li><a href="https://www.rabbitmq.com/" rel="nofollow" target="_blank" title="RabbitMQ">RabbitMQ</a></li>  <li><a href="https://www.postgresql.org/" rel="nofollow" target="_blank" title="PostgreSQL">PostgreSQL</a></li>  </ul></li>  <li>The <a href="https://github.com/ST1LLY/ntlm-scrutinizer" rel="nofollow" target="_blank" title="ntlm-scrutinizer">ntlm-scrutinizer</a> is the NTLM hashes performer with REST API based on:  </li><ul dir="auto"><li><a href="https://www.python.org/downloads/" rel="nofollow" target="_blank" title="Python 3.10">Python 3.10</a></li>  <li><a href="https://fastapi.tiangolo.com/" rel="nofollow" target="_blank" title="FastAPI">FastAPI</a></li>  <li><a href="https://github.com/hashcat/hashcat" rel="nofollow" target="_blank" title="hashcat">hashcat</a></li>  <li><a href="https://github.com/SecureAuthCorp/impacket" rel="nofollow" target="_blank" title="impacket">impacket</a></li>  </ul></ul><span><a name="more"></a></span><div><br></div>  <h3 dir="auto">Functionallity</h3>  <p dir="auto">The DC Sonar Community provides functionality for analyzing AD domains for security risks related to accounts:</p>  <ul dir="auto"><li>  <p dir="auto">Register analyzing AD domain in the app</p>  <p dir="auto"><a href="https://github.com/ST1LLY/dc-sonar/blob/f7b2d6fc7b9f7b9ff83485cb8c969cfca2a72b88/py_charms_settings_scrs/register_ad.png?raw=true" rel="nofollow" target="_blank" title="Analyzing AD domains for security risks related to user accounts (47)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEhXzvzknvxOkjETMZb5CVQKjcW4rRvucd6rZuyZFWprOZdSJ_avODLB6cUrzJuz09rEkjSyPnMvvR6Ou4LGGHfoGfrFFnJL_naOZdvxQOff5-JauGFhJW7G1SEA7QX8pFGfPWNUcVKI-MXYto7ZXGiIoXRSXdy4fP-KGqotD5L7cS0TodpFdDF-OyLhiA"><img alt="" border="0" height="312" src="https://blogger.googleusercontent.com/img/a/AVvXsEhXzvzknvxOkjETMZb5CVQKjcW4rRvucd6rZuyZFWprOZdSJ_avODLB6cUrzJuz09rEkjSyPnMvvR6Ou4LGGHfoGfrFFnJL_naOZdvxQOff5-JauGFhJW7G1SEA7QX8pFGfPWNUcVKI-MXYto7ZXGiIoXRSXdy4fP-KGqotD5L7cS0TodpFdDF-OyLhiA=w640-h312" width="640"></a></p>  </li>  <li>  <p dir="auto">See the statuses of domain analyzing processes</p>  <p dir="auto"><a href="https://github.com/ST1LLY/dc-sonar/blob/main/py_charms_settings_scrs/domains_analyze_statuses.png?raw=true" rel="nofollow" target="_blank" title="Analyzing AD domains for security risks related to user accounts (48)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEgP4NXGAyhO8DpjhUUZUlnk6j0gNt6TWWY-gmzHEFN7PNS8ODXNyY4z8fQAlcHqxPq8Gflbhp8VJ2jDfKHr9Fv3NAqLBIUsHNTC_Xu11245GCZRj7i9U5Uy6ysbWwgpK-sSv_ebv5KMP4bfTzbgJORVsdWPpggIM5LK9Rw5K2XrWGP1IxykswZa6E4HBw"><img alt="" border="0" height="314" src="https://blogger.googleusercontent.com/img/a/AVvXsEgP4NXGAyhO8DpjhUUZUlnk6j0gNt6TWWY-gmzHEFN7PNS8ODXNyY4z8fQAlcHqxPq8Gflbhp8VJ2jDfKHr9Fv3NAqLBIUsHNTC_Xu11245GCZRj7i9U5Uy6ysbWwgpK-sSv_ebv5KMP4bfTzbgJORVsdWPpggIM5LK9Rw5K2XrWGP1IxykswZa6E4HBw=w640-h314" width="640"></a></p>  </li>  <li>  <p dir="auto">Dump and brute NTLM hashes from set AD domains to list accounts with weak and vulnerable passwords</p>  <p dir="auto"><a href="https://github.com/ST1LLY/dc-sonar/blob/main/py_charms_settings_scrs/weak_passwords.png?raw=true" rel="nofollow" target="_blank" title="Analyzing AD domains for security risks related to user accounts (49)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjRcvrxN-Vi3hTAI4YMwnhvgR9Rvewfdn0xMERYM06l6pCA8lBWE4R_yRxnGETx4ArwjKiJNn-U9w4HXxRhYCda2ole6tzkJG5eYnxuqpOcgLpU9dCsAHpIkmhrILe2ZwN2MaCEI0vCwbwXoOblxahJ8o35uo7s9NUydA0iB1EJueJ-bSACts8Q5c8exw"><img alt="" border="0" height="312" src="https://blogger.googleusercontent.com/img/a/AVvXsEjRcvrxN-Vi3hTAI4YMwnhvgR9Rvewfdn0xMERYM06l6pCA8lBWE4R_yRxnGETx4ArwjKiJNn-U9w4HXxRhYCda2ole6tzkJG5eYnxuqpOcgLpU9dCsAHpIkmhrILe2ZwN2MaCEI0vCwbwXoOblxahJ8o35uo7s9NUydA0iB1EJueJ-bSACts8Q5c8exw=w640-h312" width="640"></a></p>  </li>  <li>  <p dir="auto">Analyze AD domain accounts to list ones with never expire passwords</p>  <p dir="auto"><a href="https://github.com/ST1LLY/dc-sonar/blob/main/py_charms_settings_scrs/no_expired_passwords.png?raw=true" rel="nofollow" target="_blank" title="Analyzing AD domains for security risks related to user accounts (50)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEi6Ko0k4HFPyBSElT6uuhTAWDxAweR-xGQUyK_IZwvNVeDVihweI_ypx-e7mTktyhD255M9w6LIIVk2EoZU8dByL8Sg9j9KJTNvbnywxajA-ri0NWYxHdaUN8iJum-xzUb3fSGqiolM8ueHZtm5ko-DBGfcbZpvXjZiNDgnnzCpFHOnDstQA9ru-VPaPA"><img alt="" border="0" height="314" src="https://blogger.googleusercontent.com/img/a/AVvXsEi6Ko0k4HFPyBSElT6uuhTAWDxAweR-xGQUyK_IZwvNVeDVihweI_ypx-e7mTktyhD255M9w6LIIVk2EoZU8dByL8Sg9j9KJTNvbnywxajA-ri0NWYxHdaUN8iJum-xzUb3fSGqiolM8ueHZtm5ko-DBGfcbZpvXjZiNDgnnzCpFHOnDstQA9ru-VPaPA=w640-h314" width="640"></a></p>  </li>  <li>  <p dir="auto">Analyze AD domain accounts by their NTLM password hashes to determine accounts and domains where passwords repeat</p>  <p dir="auto"><a href="https://github.com/ST1LLY/dc-sonar/blob/main/py_charms_settings_scrs/reused_passwords.png?raw=true" rel="nofollow" target="_blank" title="Analyzing AD domains for security risks related to user accounts (51)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEh4T_TaJ_WITYbBqoWyvHgSUq1IW13NIF2MOl8t3_g3AYj44B1G_tS0PsJ6EHo9flgZui2dSIwMo4neB9Yw-CYFF4tjSyIiM_QMS8CNUqMqEKZFYSJmFevxnYASeRjNI4XGVJNjRxe6xR7LQnWXBqCwJFmlYKW0wS3wcbSALpKIRivwH4bRmRj5_I2fVA"><img alt="" border="0" height="314" src="https://blogger.googleusercontent.com/img/a/AVvXsEh4T_TaJ_WITYbBqoWyvHgSUq1IW13NIF2MOl8t3_g3AYj44B1G_tS0PsJ6EHo9flgZui2dSIwMo4neB9Yw-CYFF4tjSyIiM_QMS8CNUqMqEKZFYSJmFevxnYASeRjNI4XGVJNjRxe6xR7LQnWXBqCwJFmlYKW0wS3wcbSALpKIRivwH4bRmRj5_I2fVA=w640-h314" width="640"></a></p>  </li>  </ul><h2 dir="auto">Installation</h2>  <h3 dir="auto">Docker</h3>  <p dir="auto">In progress ...</p>  <h3 dir="auto">Manually using dpkg</h3>  <p dir="auto">It is assumed that you have a clean <a href="https://ubuntu.com/download/server" rel="nofollow" target="_blank" title="Ubuntu Server 22.04">Ubuntu Server 22.04</a> and account with the username "user".</p>  <p dir="auto">The app will install to <code>/home/user/dc-sonar</code>.</p>  <p dir="auto">The next releases maybe will have a more flexible installation.</p>  <p dir="auto">Download dc_sonar_NNNN.N.NN-N_amd64.tar.gz from the <a href="https://github.com/ST1LLY/dc-sonar/releases" rel="nofollow" target="_blank" title="last distributive">last distributive</a> to the server.</p>  <p dir="auto">Create a folder for extracting files:</p>  <div><pre><code>mkdir dc_sonar_NNNN.N.NN-N_amd64</code></pre></div>  <p dir="auto">Extract the downloaded archive:</p>  <div><pre><code>tar -xvf dc_sonar_NNNN.N.NN-N_amd64.tar.gz -C dc_sonar_NNNN.N.NN-N_amd64</code></pre></div>  <p dir="auto">Go to the folder with the extracted files:</p>  <div><pre><code>cd dc_sonar_NNNN.N.NN-N_amd64/</code></pre></div>  <p dir="auto">Install PostgreSQL:</p>  <div><pre><code>sudo bash install_postgresql.sh</code></pre></div>  <p dir="auto">Install RabbitMQ:</p>  <div><pre><code>sudo bash install_rabbitmq.sh</code></pre></div>  <p dir="auto">Install dependencies:</p>  <div><pre><code>sudo bash install_dependencies.sh</code></pre></div>  <p dir="auto">It will ask for confirmation of adding the ppa:deadsnakes/ppa repository. Press <code>Enter</code>.</p>  <p dir="auto">Install dc-sonar itself:</p>  <div><pre><code>sudo dpkg -i dc_sonar_NNNN.N.NN-N_amd64.deb</code></pre></div>  <p dir="auto">It will ask for information for creating a Django admin user. Provide username, mail and password.</p>  <p dir="auto">It will ask for information for creating a self-signed SSL certificate twice. Provide required information.</p>  <p dir="auto">Open: <a href="https://localhost/" rel="nofollow" target="_blank" title="https://localhost">https://localhost</a></p>  <p dir="auto">Enter Django admin user <a href="https://www.kitploit.com/search/label/Credentials" target="_blank" title="credentials">credentials</a> set during the installation process before.</p>  <h2 dir="auto">Style guide</h2>  <p dir="auto">See the information in <a href="https://github.com/ST1LLY/dc-sonar/blob/main/STYLE_GUIDE.md" rel="nofollow" target="_blank" title="STYLE_GUIDE.md">STYLE_GUIDE.md</a></p>  <h2 dir="auto">Deployment for development</h2>  <h3 dir="auto">Docker</h3>  <p dir="auto">In progress ...</p>  <h3 dir="auto">Manually using Windows host and Ubuntu Server guest</h3>  <p dir="auto">In this case, we will set up the environment for editing code on the Windows host while running Python code on the Ubuntu guest.</p>  <h4 dir="auto">Set up the virtual machine</h4>  <p dir="auto"><a href="https://www.virtualbox.org/manual/ch01.html#gui-createvm" rel="nofollow" target="_blank" title="Create">Create</a> a <a href="https://www.kitploit.com/search/label/Virtual%20Machine" target="_blank" title="virtual machine">virtual machine</a> with 2 CPU, 2048 MB RAM, 10GB SSD using <a href="https://ubuntu.com/download/server" rel="nofollow" target="_blank" title="Ubuntu Server 22.04">Ubuntu Server 22.04</a> iso in <a href="https://www.virtualbox.org/wiki/Downloads" rel="nofollow" target="_blank" title="VirtualBox">VirtualBox</a>.</p>  <p dir="auto">If Ubuntu installer asks for updating ubuntu installer before VM's installation - agree.</p>  <p dir="auto">Choose to install OpenSSH Server.</p>  <p dir="auto">VirtualBox <a href="https://www.kitploit.com/search/label/Port%20Forwarding" target="_blank" title="Port Forwarding">Port Forwarding</a> Rules:</p>  <table><tbody><tr><th>Name</th>  <th>Protocol</th>  <th>Host IP</th>  <th>Host Port</th>  <th>Guest IP</th>  <th>Guest Port</th>  </tr><tr><td>SSH</td>  <td>TCP</td>  <td>127.0.0.1</td>  <td>2222</td>  <td>10.0.2.15</td>  <td>22</td>  </tr><tr><td>RabbitMQ management console</td>  <td>TCP</td>  <td>127.0.0.1</td>  <td>15672</td>  <td>10.0.2.15</td>  <td>15672</td>  </tr><tr><td>Django Server</td>  <td>TCP</td>  <td>127.0.0.1</td>  <td>8000</td>  <td>10.0.2.15</td>  <td>8000</td>  </tr><tr><td>NTLM Scrutinizer</td>  <td>TCP</td>  <td>127.0.0.1</td>  <td>5000</td>  <td>10.0.2.15</td>  <td>5000</td>  </tr><tr><td>PostgreSQL</td>  <td>TCP</td>  <td>127.0.0.1</td>  <td>25432</td>  <td>10.0.2.15</td>  <td>5432</td>  </tr></tbody></table><h4 dir="auto">Config Window</h4>  <p dir="auto"><a href="https://www.python.org/downloads/release/python-3105/" rel="nofollow" target="_blank" title="Download">Download</a> and install Python 3.10.5.</p>  <p dir="auto">Create a folder for the DC Sonar project.</p>  <p dir="auto">Go to the project folder using <a href="https://git-scm.com/download/win" rel="nofollow" target="_blank" title="Git for Windows">Git for Windows</a>:</p>  <div><pre><code>cd '{PATH_TO_FOLDER}'</code></pre></div>  <p dir="auto">Make Windows installation steps for <a href="https://github.com/ST1LLY/dc-sonar-user-layer#windows" rel="nofollow" target="_blank" title="dc-sonar-user-layer">dc-sonar-user-layer</a>.</p>  <p dir="auto">Make Windows installation steps for <a href="https://github.com/ST1LLY/dc-sonar-workers-layer#windows" rel="nofollow" target="_blank" title="dc-sonar-workers-layer">dc-sonar-workers-layer</a>.</p>  <p dir="auto">Make Windows installation steps for <a href="https://github.com/ST1LLY/ntlm-scrutinizer#windows" rel="nofollow" target="_blank" title="ntlm-scrutinizer">ntlm-scrutinizer</a>.</p>  <p dir="auto">Make Windows installation steps for <a href="https://github.com/ST1LLY/dc-sonar-frontend#windows" rel="nofollow" target="_blank" title="dc-sonar-frontend">dc-sonar-frontend</a>.</p>  <h4 dir="auto">Set shared folders</h4>  <p dir="auto">Make <a href="https://gist.github.com/estorgio/0c76e29c0439e683caca694f338d4003#initial-steps" rel="nofollow" target="_blank" title="steps">steps</a> from "Open VirtualBox" to "Reboot VM", but add shared folders to VM VirtualBox with "Auto-mount", like in the picture below:</p>  <p dir="auto"><a href="https://raw.githubusercontent.com/ST1LLY/dc-sonar/main/py_charms_settings_scrs/vm_shared_folders.png" rel="nofollow" target="_blank" title="Analyzing AD domains for security risks related to user accounts (69)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEirblFtnaHjt5ZXZjcs9oCFlhEwlH7Z9JSLgHKZ45ET_6jTaJ2wryiWWzuU5doP7fUQV5Gkv2WM_lvuZFEhpYZdtclk2sk6RDzursbllMlH-8ljsGL5akhzku4CIRddFhO4CaTnnsMTOq3WxkYW0oHJfYrIef7uGal0BKU4I1YJ85XkEskgGnThLXPyGw"><img alt="" border="0" height="256" src="https://blogger.googleusercontent.com/img/a/AVvXsEirblFtnaHjt5ZXZjcs9oCFlhEwlH7Z9JSLgHKZ45ET_6jTaJ2wryiWWzuU5doP7fUQV5Gkv2WM_lvuZFEhpYZdtclk2sk6RDzursbllMlH-8ljsGL5akhzku4CIRddFhO4CaTnnsMTOq3WxkYW0oHJfYrIef7uGal0BKU4I1YJ85XkEskgGnThLXPyGw=w640-h256" width="640"></a></p>  <p dir="auto">After reboot, run command:</p>  <div><pre><code>sudo adduser $USER vboxsf</code></pre></div>  <p dir="auto">Perform logout and login for the using user account.</p>  <p dir="auto">In <code>/home/user</code> directory, you can use mounted folders:</p>  <div><pre><code>ls -l</code></pre></div>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Output:  total 12  drwxrwx--- 1 root vboxsf 4096 Jul 19 13:53 dc-sonar-user-layer  drwxrwx--- 1 root vboxsf 4096 Jul 19 10:11 dc-sonar-workers-layer  drwxrwx--- 1 root vboxsf 4096 Jul 19 14:25 ntlm-scrutinizer" dir="auto"><pre><code>Output:<br>total 12<br>drwxrwx--- 1 root vboxsf 4096 Jul 19 13:53 dc-sonar-user-layer<br>drwxrwx--- 1 root vboxsf 4096 Jul 19 10:11 dc-sonar-workers-layer<br>drwxrwx--- 1 root vboxsf 4096 Jul 19 14:25 ntlm-scrutinizer</code></pre></div>  <h4 dir="auto">Config Ubuntu Server</h4>  <h5 dir="auto">Config PostgreSQL</h5>  <p dir="auto"><a href="https://www.digitalocean.com/community/tutorials/how-to-install-postgresql-on-ubuntu-20-04-quickstart" rel="nofollow" target="_blank" title="Install">Install</a> PostgreSQL on Ubuntu 20.04:</p>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="sudo apt update  sudo apt install postgresql postgresql-contrib  sudo systemctl start postgresql.service" dir="auto"><pre><code>sudo apt update<br>sudo apt install postgresql postgresql-contrib<br>sudo systemctl start postgresql.service</code></pre></div>  <p dir="auto">Create the admin database account:</p>  <div><pre><code>sudo -u postgres createuser --interactive</code></pre></div>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Output:  Enter name of role to add: admin  Shall the new role be a superuser? (y/n) y" dir="auto"><pre><code>Output:<br>Enter name of role to add: admin<br>Shall the new role be a superuser? (y/n) y</code></pre></div>  <p dir="auto">Create the dc_sonar_workers_layer database account:</p>  <div><pre><code>sudo -u postgres createuser --interactive</code></pre></div>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Output:  Enter name of role to add: dc_sonar_workers_layer  Shall the new role be a superuser? (y/n) n  Shall the new role be allowed to create databases? (y/n) n  Shall the new role be allowed to create more new roles? (y/n) n" dir="auto"><pre><code>Output:<br>Enter name of role to add: dc_sonar_workers_layer<br>Shall the new role be a superuser? (y/n) n<br>Shall the new role be allowed to create databases? (y/n) n<br>Shall the new role be allowed to create more new roles? (y/n) n</code></pre></div>  <p dir="auto">Create the dc_sonar_user_layer database account:</p>  <div><pre><code>sudo -u postgres createuser --interactive</code></pre></div>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Output:  Enter name of role to add: dc_sonar_user_layer  Shall the new role be a superuser? (y/n) n  Shall the new role be allowed to create databases? (y/n) n  Shall the new role be allowed to create more new roles? (y/n) n" dir="auto"><pre><code>Output:<br>Enter name of role to add: dc_sonar_user_layer<br>Shall the new role be a superuser? (y/n) n<br>Shall the new role be allowed to create databases? (y/n) n<br>Shall the new role be allowed to create more new roles? (y/n) n</code></pre></div>  <p dir="auto">Create the back_workers_db database:</p>  <div><pre><code>sudo -u postgres createdb back_workers_db</code></pre></div>  <p dir="auto">Create the web_app_db database:</p>  <div><pre><code>sudo -u postgres createdb web_app_db</code></pre></div>  <p dir="auto">Run the psql:</p>  <div><pre><code>sudo -u postgres psql</code></pre></div>  <p dir="auto">Set a password for the admin account:</p>  <div><pre><code>ALTER USER admin WITH PASSWORD '{YOUR_PASSWORD}';<br></code></pre></div>  <p dir="auto">Set a password for the dc_sonar_workers_layer account:</p>  <div><pre><code>ALTER USER dc_sonar_workers_layer WITH PASSWORD '{YOUR_PASSWORD}';<br></code></pre></div>  <p dir="auto">Set a password for the dc_sonar_user_layer account:</p>  <div><pre><code>ALTER USER dc_sonar_user_layer WITH PASSWORD '{YOUR_PASSWORD}';<br></code></pre></div>  <p dir="auto">Grant CRUD permissions for the dc_sonar_workers_layer account on the back_workers_db database:</p>  <div><pre><code>\c back_workers_db<br>GRANT CONNECT ON DATABASE back_workers_db to dc_sonar_workers_layer;<br>GRANT USAGE ON SCHEMA public to dc_sonar_workers_layer;<br>GRANT ALL ON ALL TABLES IN SCHEMA public TO dc_sonar_workers_layer;<br>GRANT ALL ON ALL SEQUENCES IN SCHEMA public TO dc_sonar_workers_layer;<br>GRANT ALL ON ALL FUNCTIONS IN SCHEMA public TO dc_sonar_workers_layer;<br></code></pre></div>  <p dir="auto">Grant CRUD permissions for the dc_sonar_user_layer account on the web_app_db database:</p>  <div><pre><code>\c web_app_db<br>GRANT CONNECT ON DATABASE web_app_db to dc_sonar_user_layer;<br>GRANT USAGE ON SCHEMA public to dc_sonar_user_layer;<br>GRANT ALL ON ALL TABLES IN SCHEMA public TO dc_sonar_user_layer;<br>GRANT ALL ON ALL SEQUENCES IN SCHEMA public TO dc_sonar_user_layer;<br>GRANT ALL ON ALL FUNCTIONS IN SCHEMA public TO dc_sonar_user_layer;<br></code></pre></div>  <p dir="auto">Exit of the psql:</p>  <div><pre><code>\q<br></code></pre></div>  <p dir="auto">Open the pg_hba.conf file:</p>  <div><pre><code>sudo nano /etc/postgresql/12/main/pg_hba.conf</code></pre></div>  <p dir="auto">Add the line for the connection to allow the connection from the host machine to PostgreSQL, save changes and close the file:</p>  <div><pre><code># IPv4 local connections:<br>host    all             all             127.0.0.1/32            md5<br>host    all             admin           0.0.0.0/0               md5<br></code></pre></div>  <p dir="auto">Open the postgresql.conf file:</p>  <div><pre><code>sudo nano /etc/postgresql/12/main/postgresql.conf<br></code></pre></div>  <p dir="auto">Change specified below params, save changes and close the file:</p>  <div><pre><code>listen_addresses = 'localhost,10.0.2.15'<br>shared_buffers = 512MB<br>work_mem = 5MB<br>maintenance_work_mem = 100MB<br>effective_cache_size = 1GB<br></code></pre></div>  <p dir="auto">Restart the PostgreSQL service:</p>  <div><pre><code>sudo service postgresql restart</code></pre></div>  <p dir="auto">Check the PostgreSQL service status:</p>  <div><pre><code>service postgresql status</code></pre></div>  <p dir="auto">Check the log file if it is needed:</p>  <div><pre><code>tail -f /var/log/postgresql/postgresql-12-main.log</code></pre></div>  <p dir="auto">Now you can connect to created databases using admin account and client such as <a href="https://dbeaver.io/download/" rel="nofollow" target="_blank" title="DBeaver">DBeaver</a> from Windows.</p>  <h5 dir="auto">Config RabbitMQ</h5>  <p dir="auto">Install RabbitMQ using the <a href="https://www.rabbitmq.com/install-debian.html#apt-quick-start-packagecloud" rel="nofollow" target="_blank" title="script">script</a>.</p>  <p dir="auto">Enable the management plugin:</p>  <div><pre><code>sudo rabbitmq-plugins enable rabbitmq_management</code></pre></div>  <p dir="auto">Create the RabbitMQ admin account:</p>  <div><pre><code>sudo rabbitmqctl add_user admin {YOUR_PASSWORD}</code></pre></div>  <p dir="auto">Tag the created user for full management UI and HTTP API access:</p>  <div><pre><code>sudo rabbitmqctl set_user_tags admin administrator</code></pre></div>  <p dir="auto">Open management UI on <a href="http://localhost:15672/" rel="nofollow" target="_blank" title="http://localhost:15672/">http://localhost:15672/</a>.</p>  <h5 dir="auto">Install Python3.10</h5>  <p dir="auto">Ensure that your system is updated and the required packages installed:</p>  <div><pre><code>sudo apt update &amp;&amp; sudo apt upgrade -y</code></pre></div>  <p dir="auto">Install the required dependency for adding custom PPAs:</p>  <div><pre><code>sudo apt install software-properties-common -y</code></pre></div>  <p dir="auto">Then proceed and add the deadsnakes PPA to the APT package manager sources list as below:</p>  <div><pre><code>sudo add-apt-repository ppa:deadsnakes/ppa</code></pre></div>  <p dir="auto">Download Python 3.10:</p>  <div><pre><code>sudo apt install python3.10=3.10.5-1+focal1</code></pre></div>  <p dir="auto">Install the dependencies:</p>  <div><pre><code>sudo apt install python3.10-dev=3.10.5-1+focal1 libpq-dev=12.11-0ubuntu0.20.04.1 libsasl2-dev libldap2-dev libssl-dev</code></pre></div>  <p dir="auto">Install the venv module:</p>  <div><pre><code>sudo apt-get install python3.10-venv</code></pre></div>  <p dir="auto">Check the version of installed python:</p>  <div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="python3.10 --version    Output:  Python 3.10.5" dir="auto"><pre><code>python3.10 --version<br><br>Output:<br>Python 3.10.5</code></pre></div>  <h5 dir="auto">Hosts</h5>  <p dir="auto">Add IP addresses of Domain Controllers to <code>/etc/hosts</code></p>  <div><pre><code>sudo nano /etc/hosts<br></code></pre></div>  <h4 dir="auto">Layers</h4>  <h5 dir="auto">Set venv</h5>  <p dir="auto">We have to create venv on a level above as VM VirtualBox doesn't allow us to make it in shared folders.</p>  <p dir="auto">Go to the home directory where shared folders located:</p>  <div><pre><code>cd /home/user</code></pre></div>  <p dir="auto">Make deploy <a href="https://github.com/ST1LLY/dc-sonar-user-layer#ubuntu" rel="nofollow" target="_blank" title="steps">steps</a> for dc-sonar-user-layer on Ubuntu.</p>  <p dir="auto">Make deploy <a href="https://github.com/ST1LLY/dc-sonar-workers-layer#ubuntu" rel="nofollow" target="_blank" title="steps">steps</a> for dc-sonar-workers-layer on Ubuntu.</p>  <p dir="auto">Make deploy <a href="https://github.com/ST1LLY/ntlm-scrutinizer#preparations-for-run" rel="nofollow" target="_blank" title="steps">steps</a> for ntlm-scrutinizer on Ubuntu.</p>  <h5 dir="auto">Config modules</h5>  <p dir="auto">Make config <a href="https://github.com/ST1LLY/dc-sonar-user-layer#config" rel="nofollow" target="_blank" title="steps">steps</a> for dc-sonar-user-layer on Ubuntu.</p>  <p dir="auto">Make config <a href="https://github.com/ST1LLY/dc-sonar-workers-layer#ubuntu" rel="nofollow" target="_blank" title="steps">steps</a> for dc-sonar-workers-layer on Ubuntu.</p>  <p dir="auto">Make config <a href="https://github.com/ST1LLY/ntlm-scrutinizer#preparations-for-run" rel="nofollow" target="_blank" title="steps">steps</a> for ntlm-scrutinizer on Ubuntu.</p>  <h5 dir="auto">Run</h5>  <p dir="auto">Make run <a href="https://github.com/ST1LLY/ntlm-scrutinizer#run" rel="nofollow" target="_blank" title="steps">steps</a> for ntlm-scrutinizer on Ubuntu.</p>  <p dir="auto">Make run <a href="https://github.com/ST1LLY/dc-sonar-user-layer#run" rel="nofollow" target="_blank" title="steps">steps</a> for dc-sonar-user-layer on Ubuntu.</p>  <p dir="auto">Make run <a href="https://github.com/ST1LLY/dc-sonar-workers-layer#run" rel="nofollow" target="_blank" title="steps">steps</a> for dc-sonar-workers-layer on Ubuntu.</p>  <p dir="auto">Make run <a href="https://github.com/ST1LLY/dc-sonar-frontend#run-development" rel="nofollow" target="_blank" title="steps">steps</a> for dc-sonar-frontend on Windows.</p>  <p dir="auto">Open <a href="https://localhost:8000/admin/" rel="nofollow" target="_blank" title="https://localhost:8000/admin/">https://localhost:8000/admin/</a> in a browser on the Windows host and agree with the self-signed certificate.</p>  <p dir="auto">Open <a href="https://localhost:4200/" rel="nofollow" target="_blank" title="https://localhost:4200/">https://localhost:4200/</a> in the browser on the Windows host and login as created Django user.</p>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/ST1LLY/dc-sonar" rel="nofollow" target="_blank" title="Download Dc-Sonar">Download Dc-Sonar</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netdata release 1.38.0]]></title>
<description><![CDATA[Release Notes edited for brevity, original links maintained. Full Release notes at https://github.com/netdata/netdata/releases/tag/v1.38.0 ​ Highlights:  DBENGINE v2 The new open-source database engine for Netdata Agents, offering huge performance, scalability and stability improvements, with a f...]]></description>
<link>https://tsecurity.de/de/1784336/linux-tipps/netdata-release-1380/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1784336/linux-tipps/netdata-release-1380/</guid>
<pubDate>Mon, 06 Feb 2023 20:15:55 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Release Notes edited for brevity, original links maintained.</p> <p><em>Full Release notes at</em> <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0"><em>https://github.com/netdata/netdata/releases/tag/v1.38.0</em></a></p> <p>​</p> <p>Highlights: </p> <ul><li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-dbenginev2"><strong>DBENGINE v2</strong></a><br> The new open-source database engine for Netdata Agents, offering huge performance, scalability and stability improvements, with a fraction of memory footprint!</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-functions"><strong>FUNCTION: Processes</strong></a><br> Netdata beyond metrics! We added the ability for <strong>runtime functions</strong>, that can be implemented by any data collection plugin, to offer unlimited visibility to anything, even not-metrics, that can be valuable while troubleshooting.</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-feed"><strong>Events Feed</strong></a><br> Centralized view of Space and Infrastructure level events about topology changes and alerts.</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-notifications"><strong>NOTIFICATIONS: Slack, PagerDuty, Discord, Webhooks</strong></a><br> Netdata Cloud now supports <strong>Slack</strong>, <strong>PagerDuty</strong>, <strong>Discord</strong>, <strong>Webhooks</strong>.</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-rbac"><strong>Role-based access model</strong></a><br> Netdata Cloud supports more roles, offering finer control over access to infrastructure.<br></li> </ul><h3>Netdata open-source growth</h3> <ul><li>Almost 62,000 GitHub Stars</li> <li>Over four million monitored servers</li> <li>Almost 88 million sessions served</li> <li>Over 600 thousand total nodes in Netdata Cloud</li> </ul><h2>Release highlights</h2> <h3>Dramatic performance and stability improvements, with a smaller agent footprint</h3> <p>We completely reworked our custom-made, time series database (dbengine), resulting in stunning improvements to performance, scalability, and stability, while at the same time significantly reducing the <a href="https://github.com/netdata/netdata/tree/master/database/engine#memory-requirements">agent memory requirements</a>.</p> <p>On production-grade hardware (e.g. 48 threads, 32GB ram) Netdata Agent Parents can easily collect 2 million points/second while servicing data queries for 10 million points / second, and running ML training and Health querying 1 million points / second each!</p> <p>For standalone installations, the 64bit version of Netdata runs stable at about 150MB RAM (Reside Set Size + SHARED), with everything enabled (the 32bit version at about 80MB RAM, again with everything enabled).</p> <p>​</p> <p><a href="https://preview.redd.it/9rgk6i3h7mga1.png?width=2439&amp;format=png&amp;auto=webp&amp;s=801420291d1670746611e8ce4b472f207a8dbeb0">DBENGINE v2</a></p> <h3>Functions</h3> <p>After the groundwork done on the Netdata Agent in v1.37.0, Netdata Agent collectors are able to expose functions that can be executed on-demand, at run-time, by the data collecting agent, even when queries are executed via a Netdata Agent Parent. We are now utilizing this capability to provide the first of many powerful features via the Netdata Cloud UI.</p> <p>Netdata Functions on Netdata Cloud allow you to trigger specific routines to be executed by a given Agent on request. These routines can range from a simple reader that fetches real time information to help you troubleshoot (like the list of currently running processing, currently running db queries, currently open connections, etc.), to routines that trigger an action on your behalf (restart a service, rotate logs, etc.), directly on the node. The key point is to remove the need to open an ssh connection to your node to execute a command like top<br> while you are troubleshooting.</p> <p>The routines are triggered directly from the Netdata Cloud UI, with the request going through the secure, already established by the agent <a href="https://learn.netdata.cloud/docs/agent/aclk">Agent-Cloud Link (ACLK)</a>. Moreover, unlike many of the commands you'd issue from the shell, Netdata Functions come with powerful capabilities like auto-refresh, sorting, filtering, search and more! And, as everything about Netdata, they are fast!</p> <h4>What functions are currently available?</h4> <p>At the moment, just one, to display detailed information on the currently running processes on the node, replacing top and iotop</p> <p>​</p> <p><a href="https://preview.redd.it/ovjkobxk7mga1.png?width=3840&amp;format=png&amp;auto=webp&amp;s=88471c09c0cbaae3c05d6fad2740a35d85f4d217">Real time top/iotop info</a></p> <h3>Events feed</h3> <p><em>Coming by Feb 15th</em></p> <p>The <strong>Events feed</strong> is a powerful new feature that tracks events that happen on your infrastructure, or in your Space. The feed lets you investigate events that occurred in the past, which is obviously invaluable for troubleshooting. Common use cases are ones like when a node goes offline, and you want to understand what events happened before that. A detailed event history can also assist in attributing sudden pattern changes in a time series to specific changes in your environment.</p> <p>We start from humble beginnings, capturing <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#topology-events">topology events</a> (node state transitions) and <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#alert-events">alert state transitions</a>. We intend to expand the events we capture to include infrastructure changes like deployments or services starting/stopping and we plan to provide a way to display the events in the standard Netdata charts.</p> <h3>Additional alert notification methods on Netdata Cloud</h3> <p><em>Coming by Feb 15th</em></p> <p>Every Netdata Agent comes with hundreds of pre-installed health alerts designed to notify you when an anomaly or performance issue affects your node or the applications it runs. All these events, from all your nodes, are centralized at Netdata Cloud.</p> <p>Before this release, Netdata Cloud was only dispatching centralized email alert notifications to your team whenever an alert enters a warning, critical, or unreachable state. However, the agent supported tens of notification delivery methods, which we hadn't provided via the cloud.</p> <p>We are now adding to Netdata Cloud more alert notification integration methods. We categorize them similarly to our <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-paidplans">subscription plans</a>, as Community, Pro and Business. On this release, we added <strong>Discord</strong> (Community Plan), <strong>web hook</strong> (Pro Plan), <strong>PagerDuty</strong> and <strong>Slack</strong> (Business Plan).</p> <h3>Improved role-based access model</h3> <p><em>Coming by Feb 15th</em></p> <p>Netdata Cloud already provides a role-based-access mechanism, that allows you to control what functionalities in the app users can access.<br> Each user can be assigned only one role, which fully specifies all the capabilities they are afforded.</p> <p>With the advent of the <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-paidplans">paid plans</a> we revamped the roles to cover needs expressed by our users, like providing more limited access to your customers, or being able to join any room. We also aligned the offered roles to the target audience of each plan. </p> <h2>Integrations</h2> <h3>Collectors</h3> <h4>Proc</h4> <p>The <a href="https://learn.netdata.cloud/docs/collect/system-metrics">proc plugin</a> gathers metrics from the /proc and /sys folders in Linux<br> systems, along with a few other endpoints, and is responsible for the bulk of the system metrics collected and visualized by Netdata. It collects CPU, memory, disks, load, networking, mount points, and more.</p> <p>We added a "cpu" label to the per core utilization % charts. Previously, the only way to filter or group by core was to use the "instance", i.e. the chart name. The new label makes the displayed dimensions much more user-friendly.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14255">fixed</a> the issues we had with collection of CPU/memory metrics when running inside an LXC container as a systemd service.</p> <p>We also <a href="https://github.com/netdata/netdata/pull/14252">fixed</a> the missing network stack metrics, when IPv6 is disabled.</p> <p>Finally, we improved how the loadavg alerts behave when the number of processors <a href="https://github.com/netdata/netdata/pull/14286">is 0</a>, or <a href="https://github.com/netdata/netdata/pull/14265">unknown</a>.</p> <h4>Apps</h4> <p>The <a href="https://learn.netdata.cloud/docs/collect/application-metrics">apps plugin</a> breaks down system resource usage<br> to processes, users and user groups, by reading whole process tree, collecting resource usage information for every process found running.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14156">fixed</a> the nodejs application group node, which incorrectly included node_exporter. The rule now is that the process must be called node to be included in that group.</p> <p>We also <a href="https://github.com/netdata/netdata/pull/14188">added a telegraf application group</a>.</p> <h4>Containers and VMs (CGROUPS)</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/cgroups.plugin">cgroups plugin</a> reads information on Linux Control Groups to monitor containers, virtual machines and systemd services.</p> <p>The "net" section in a cgroups container would occasionally pick the wrong / random interface name to display in the navigation menu. We <a href="https://github.com/netdata/netdata/pull/14174">removed the interface name</a> from the cgroup "net" family. The information is available in the cloud as labels and on the agent as chart names and ids.</p> <h4>eBPF</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/ebpf.plugin">eBPF plugin</a> helps you troubleshoot and debug how applications interact with the Linux kernel.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14270">improved</a> the speed and resource impact of the collector shutdown, by reducing the number of threads running in parallel.</p> <p>We fixed a bug with eBPF routines that would sometimes cause kernel panic and system reboot on RedHat 8.* family OSs. <a href="https://github.com/netdata/netdata/pull/14090">#14090</a>, <a href="https://github.com/netdata/netdata/pull/14131">#14131</a></p> <p>We <a href="https://github.com/netdata/netdata/pull/14131">fixed</a> an ebpf.d crash: sysmalloc Assertion failed, then killed with SIGTERM.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14131">fixed</a> a crash when building eBPF while using a memory address sanitizer.</p> <p>The eBPF collector also creates charts for each running application through an integration with the apps.plugin. This integration helps you understand how specific applications interact with the Linux kernel. In systems with many VMs (like Proxmox), this integration<br> can cause a large load. We used to have the integration turned on by default, with the ability to disable it from ebpf.d.conf. We have now done the opposite, having the integration disabled by default, with the ability to enable it. <a href="https://github.com/netdata/netdata/pull/14147">#14147</a></p> <h4>Windows Monitoring</h4> <p>We have been making tremendous improvements on how we <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/wmi">monitor Windows Hosts</a>. The work will be completed in the next release. For now, we can say that we have done some preparatory work by <a href="https://github.com/netdata/netdata/pull/14001">adding more info to existing charts</a>, adding metrics for <a href="https://github.com/netdata/go.d.plugin/pull/1041">MS SQL Server</a>, <a href="https://github.com/netdata/go.d.plugin/pull/972">IIS</a> in 1.37, <a href="https://github.com/netdata/go.d.plugin/pull/1003">Active Directory</a>, <a href="https://github.com/netdata/go.d.plugin/pull/1013">ADFS</a> and <a href="https://github.com/netdata/go.d.plugin/pull/1007">ADCS</a>.</p> <p>We also <a href="https://github.com/netdata/go.d.plugin/pull/1065">reorganized the navigation menu</a>, so that Windows application metrics don't appear under the generic "WMI" category, but on their own category, just like Linux applications.</p> <p>We invite you to try out with these collectors either from a remote Linux machine, or using our new <a href="https://github.com/netdata/msi-installer">MSI installer</a>, which however is not suitable for production. Your feedback will be really appreciated, as we invest on making Windows Monitoring a first class citizen of Netdata.</p> <h4>Generic Prometheus Endpoint Monitoring</h4> <p>Our <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/prometheus">Generic Prometheus Collector</a> gathers metrics from any <a href="https://prometheus.io/">Prometheus</a> endpoint that uses<br> the <a href="https://prometheus.io/docs/instrumenting/exposition_formats/">OpenMetrics exposition format</a>.</p> <p>To allow better grouping and filtering of the collected metrics we now <a href="https://github.com/netdata/go.d.plugin/pull/1004">create a chart with labels per label set</a>.</p> <p>We also <a href="https://github.com/netdata/go.d.plugin/pull/1027">fixed the handling of Summary/Histogram NaN values</a>.</p> <h4>TCP endpoint monitoring</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/portcheck">TCP endpoint (portcheck) collector</a> monitors TCP service availability and response time.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14137">enriched</a> the portcheck alarms with labels that show the problematic host and port.</p> <h4>HTTP endpoint monitoring</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/httpcheck">HTTP endpoint monitoring collector (httpcheck)</a> monitors their availability and response time.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14133">enriched the alerts</a> with labels that show the slow or unavailable URL relevant to the alert.</p> <h4>Host reachability (ping)</h4> <p>The new <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/ping">host reachability collector</a> replaced fping in v1.37.0.<br> We <a href="https://github.com/netdata/netdata/pull/14073">removed</a> the deprecated fping.plugin, in accordance with the v1.37.0 deprecation notice.</p> <h4>RabbitMQ</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/rabbitmq">RabbitMQ collector</a> monitors the open source message broker, by querying its overview, node<br> and vhosts HTTP endpoints.</p> <p>We <a href="https://github.com/netdata/go.d.plugin/pull/1047">added monitoring of the RabitMQ queues</a> that was available in the older Python module and<br><a href="https://github.com/netdata/go.d.plugin/pull/1052">fixed an issue</a> with the new metrics.</p> <h4>MongoDB</h4> <p>We monitor the <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/mongodb">MongoDB</a> NoSQL database <a href="https://www.mongodb.com/docs/manual/reference/command/serverStatus/#mongodb-dbcommand-dbcmd.serverStatus">serverStatus</a> and <a href="https://github.com/netdata/netdata/blob/v1.38.0/mongodb.com/docs/manual/reference/command/dbStats/#dbstats">dbStats</a>.</p> <p>To allow better grouping and filtering of the collected metrics we now <a href="https://github.com/netdata/go.d.plugin/pull/1042">create a chart per database, repl set member, shard and additional metrics</a>. We also <a href="https://github.com/netdata/go.d.plugin/pull/1046">improved</a> the cursors_by_lifespan_count<br> chart dimension names, to make them clearer.</p> <h4>PostgreSQL</h4> <p>Our powerful <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/postgressql">PostgreSQL database collector</a> has been enhanced with an improved <a href="https://github.com/netdata/go.d.plugin/pull/1039">WAL replication lag calculation</a> and <a href="https://github.com/netdata/go.d.plugin/pull/1018">better support of versions before 10</a>.</p> <h4>Redis</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/redis">Redis collector</a> monitors the in-memory data structure store via its <a href="https://redis.io/commands/info/">INFO ALL</a> command.</p> <p>We now support password protected Redis instances, by <a href="https://github.com/netdata/go.d.plugin/pull/1051">allowing users to set the username/password</a> in the collector configuration.</p> <h4>Consul</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/consul">Consul collector</a> is production ready! <a href="https://www.consul.io/">Consul by HashiCorp</a> is a powerful and complex identity-based networking solution, which is not trivial to monitor. We were lucky to have the assistance of HashiCorp itself in this endeavor, which resulted in a monitoring solution of exceptional quality. Look for common blog posts and announcements in the coming weeks!</p> <h4>NGINX Plus</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/nginxplus">NGINX Plus collector</a> monitors the load balancer, API gateway, and reverse proxy built on top of NGINX, by utilizing its <a href="https://docs.nginx.com/nginx/admin-guide/monitoring/live-activity-monitoring/">Live Activity Monitoring</a> capabilities.</p> <p>We improved the collector that was launched last November with <a href="https://github.com/netdata/netdata/pull/14080">additional information</a> explaining the charts and the <a href="https://github.com/netdata/go.d.plugin/pull/1010">addition of SSL error metrics</a>.</p> <h4>Elastic Search</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/elasticsearch">Elastic Search collector</a> monitors the search engine's instances<br> via several of the provided local interfaces.</p> <p>To allow better grouping and filtering of the collected metrics we now <a href="https://github.com/netdata/go.d.plugin/pull/1040">create a chart per node index, a dimension per health status</a>. We also <a href="https://github.com/netdata/netdata/pull/14197">added several OOB alerts</a>.</p> <h4>NVIDIA GPU</h4> <p>Our <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/nvidia_smi">NVIDIA GPU Collector</a> monitors memory usage, fan speed, PCIE bandwidth utilization, temperature, and other GPU performance metrics using the nvidia-smi cli tool.</p> <p>Multi-Instance GPU (MIG) is a feature from NVIDIA that lets users partition a single GPU to smaller GPU instances. We <a href="https://github.com/netdata/go.d.plugin/pull/1067">added MIG metrics</a> for uncorrectable errors and memory usage.</p> <p>We also <a href="https://github.com/netdata/go.d.plugin/pull/1048">added metrics for voltage</a> and <a href="https://github.com/netdata/netdata/pull/14315">PCIe bandwidth utilization percentage</a>.</p> <p>Last but not least, we significantly improved the collector's performance, by switching to <a href="https://github.com/netdata/go.d.plugin/pull/1023">collecting data using the CSV format</a>.</p> <h4>Pi-hole</h4> <p>We monitor <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/pihole">Pi-hole</a>, the Linux network-level advertisement and Internet tracker blocking application via its <a href="https://github.com/pi-hole/AdminLTE">PHP API</a>.</p> <p>We <a href="https://github.com/netdata/go.d.plugin/pull/1037">fixed</a> an issue with the requests failing against an authenticated API.</p> <h4>Network Time Protocol (NTP) daemon</h4> <p>The ntpd program is an operating system daemon which sets and maintains the system time of day in synchronism with Internet standard time-servers (<a href="https://linux.die.net/man/8/ntpd">man page</a>).</p> <p>We rewrote our previous python.d collector in go, improving its performance and maintainability.<br> The new collector still monitors the system variables of a local ntpd daemon and optionally the variables of its polled peers. Similarly to ntpq, the <a href="http://doc.ntp.org/current-stable/ntpq.html">standard NTP query program</a>, we used the NTP Control Message Protocol over a UDP socket.</p> <p>The python collector <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-deprecation">will be deprecated in the next release</a>, with no effect on current users.</p> <h3>Notifications</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-notifications">Additional alert notification methods on Netdata Cloud</a></p> <p>The agents can now <a href="https://github.com/netdata/netdata/pull/14153">send notifications to Mattermost</a>, using the Slack integration! <a href="https://mattermost.com/">Mattermost</a> has a <a href="https://jeffschering.github.io/mmdocs/monolith/developer/api.html#incoming-webhooks">Slack-compatible API</a> that only required a couple of additional parameters. Kudos to <a href="https://github.com/je2555">@je2555</a>!</p> <h3>Exporters</h3> <p>Netdata can <a href="https://learn.netdata.cloud/guides/export/export-netdata-metrics-graphite">export and visualize Netdata metrics in Graphite</a>.</p> <p>Our exporter was broken in v1.37.0 due to our host labels for ephemeral nodes. we fixed the issue with <a href="https://github.com/netdata/netdata/pull/14105">#14105</a>.</p> <h2>Alerts and Notification Engine</h2> <h3>Health Engine</h3> <p>To improve performance and stability, we made <a href="https://github.com/netdata/netdata/pull/14244">health run in a single thread</a>.</p> <h3>Notifications Engine</h3> <p>The agent alert notifications are controlled by the configuration file <a href="https://github.com/netdata/netdata/blob/master/health/notifications/health_alarm_notify.conf">health_alarm_notify.conf</a>. Previously, if one used the |critical modifier, the recipients would always get at least 2 notifications: critical and clear. There was no way how to stop sending clear/warning notifications afterwards. We <a href="https://github.com/netdata/netdata/pull/14330">added</a> the |nowarn and |noclear notification modifiers, to allow users to really receive just the transitions to the critical state.</p> <p>We also <a href="https://github.com/netdata/netdata-cloud/issues/656">fixed the broken redirects from alert notifications to cleared alerts</a>.</p> <h3>Alerts</h3> <h4>Chart labels in alerts</h4> <p>We constantly strive to improve the clarity of the information provided by the hundreds of out of the box alerts we provide. We can now provide more fine-tuned information on each alert, as we <a href="https://github.com/netdata/netdata/pull/14173">started using specific chart labels instead of family</a>. To provide the capability we also had to <a href="https://github.com/netdata/netdata/pull/14206">change the format of alert info variables</a> to support the more complex syntax.</p> <h4>Globally enable/disable specific alerts</h4> <p>Administrators can now globally, permanently disable specific OOB alerts via netdata.conf<br> . Previously the options where to <a href="https://learn.netdata.cloud/docs/monitor/configure-alarms">edit individual alert configuration files</a>, or to use the <a href="https://learn.netdata.cloud/docs/agent/web/api/health#health-management-api">health management API</a>.</p> <p>The [health] section of netdata.conf now support the setting enabled_alarms. It's value defines which alarms to load from both user and stock directories. The value is a <a href="https://github.com/netdata/netdata/blob/v1.38.0/libnetdata/simple_pattern/README.md">simple pattern</a> list of alarm or template names, with the default value of *, meaning that all alerts are loaded. For example, to disable specific alarms, you can provide enabled alarms = !oom_kill *, which will load all alarms except oom_kill.</p> <h2>Visualizations / Charts and Dashboards</h2> <p>Our main focus for visualization is on the Netdata Cloud <strong>Overview</strong> dashboard. This dashboard is our flagship, on which everything we do, all slicing and dicing capabilities of Netdata, are added and integrated. We are working hard to make this dashboard powerful enough, so that the need to learn a query language for configuring and customizing monitoring dashboards, will be eliminated.</p> <p>On this release, we virtualized all items on the dashboard, allowing us to achieve exceptional performance on page rendering. In previous releases there were issues on dashboards with thousands of charts. Now the number of items in the page is irrelevant!</p> <p>To make slicing and dicing of data easier, we ordered the on-chart selectors in a way that is more natural for most users:</p> <p>​</p> <p><a href="https://preview.redd.it/bnwtlvqc7mga1.png?width=2774&amp;format=png&amp;auto=webp&amp;s=ad41b2f9ca2fa5190748387ffe48adcdcb3dd66c">https://preview.redd.it/bnwtlvqc7mga1.png?width=2774&amp;format=png&amp;auto=webp&amp;s=ad41b2f9ca2fa5190748387ffe48adcdcb3dd66c</a></p> <p>This bar above the chart now describes the data presented, in plain English: <strong>On 6 out of 20 Nodes, group by dimension, the SUM() of 23 Instances, using All dimensions, each as AVG() every 3s</strong></p> <p>A tool-tip provides more information about the missing nodes.</p> <p><a href="https://preview.redd.it/mfdngdzt7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=2886138f488e76278ecbe87f14805095d8a8a88e">https://preview.redd.it/mfdngdzt7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=2886138f488e76278ecbe87f14805095d8a8a88e</a></p> <p>And the drop-down menu now shows the exact nodes that contributed data to the query, together with a short explanation on why nodes did not provide any data: </p> <p><a href="https://preview.redd.it/az6j4f8v7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=ae343ae012f8eda5ee325d96e9b5946a309137e5">https://preview.redd.it/az6j4f8v7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=ae343ae012f8eda5ee325d96e9b5946a309137e5</a></p> <p>Additionally, the pop-out icon next to each node can be used to jump to the single node dashboard of this node.</p> <p>All the slicing and dicing controls (Nodes, Dimensions, Instances), now support filtering. As shown above, there is a search box in the drop-down and a tick-mark to the left of each item in the list, which can be used to instantly filter the data presented.</p> <p>At the same time, we re-worked most of the Netdata collectors to add labels to the charts, allowing the chart to be pivoted directly from the <strong>group by</strong> drop-down menu. On the following image, we see the same chart as above, but now the data have been grouped by the label device, the values of which became dimensions of the chart.</p> <p>​</p> <p><a href="https://preview.redd.it/xp6qztwx7mga1.png?width=2772&amp;format=png&amp;auto=webp&amp;s=7b1f5172742a0725dfe31330ae75f6bdcb73ee2f">https://preview.redd.it/xp6qztwx7mga1.png?width=2772&amp;format=png&amp;auto=webp&amp;s=7b1f5172742a0725dfe31330ae75f6bdcb73ee2f</a></p> <p>The data can be instantly be filtered by original dimension (reads and writes in this example), like this: </p> <p><a href="https://preview.redd.it/43v2lck08mga1.png?width=2762&amp;format=png&amp;auto=webp&amp;s=d17a0d9ab8aa82bd441df804c7f5c96cdd663895">https://preview.redd.it/43v2lck08mga1.png?width=2762&amp;format=png&amp;auto=webp&amp;s=d17a0d9ab8aa82bd441df804c7f5c96cdd663895</a></p> <p>or even by a specific instance (disk in this example), like this: </p> <p><a href="https://preview.redd.it/26px2pf28mga1.png?width=2776&amp;format=png&amp;auto=webp&amp;s=fa64868dbf996c1d4b5ea694ebd05d303b2139bb">https://preview.redd.it/26px2pf28mga1.png?width=2776&amp;format=png&amp;auto=webp&amp;s=fa64868dbf996c1d4b5ea694ebd05d303b2139bb</a></p> <p>On the Instances drop down list (shown above), the pop-out icon to the right of each instance can be used to quickly jump to the single node dashboard, and we also made this function automatically scroll the dashboard to relative chart's position and filter on that chart the specific instance from which the jump was made.</p> <p>Our goal is to polish and fine tune this interface, to the degree that it will be possible to slice and dice any data, without learning a query language, directly from the dashboard. We believe that this will simplify monitoring significantly, make it more accessible to people, and it will eventually allow all of us to troubleshoot issues without any prior knowledge of the underlying data structures.</p> <p>At the same time, we worked to improve switching between rooms and tabs within a room, by saving the last visible chart and the selected page filters, we are restored automatically when the user switches back to the same room and tab.</p> <p>For the ordering of the sections and subsections on the dashboard menu, we made a change to allow currently collected charts to overwrite the position of the section and subsection (we call it priority<br> ). Before this change, archived metrics (old metrics that are retained due to retention), were participating in the election of the priority<br> for a section or subsection and because the retention Netdata maintains by default is more than a year, changes to the priority<br> were never propagated to the UI.</p> <h4>Bug fixes</h4> <p>We fixed:</p> <ul><li><a href="https://github.com/netdata/netdata-cloud/issues/662">The alignment of the anomaly rate pop-down chart</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/704">The width of the right-hand menu bar</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/695">A crash when filtering dimensions</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/649">The warning when a user tries to leave the last space</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/653">The filters of the Metric Correlation screen incorrectly persisting</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/692">The wrong value being shown for whether a node has ML enabled</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/688">The node filter on the anomalies tab</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/648">The visibility of the chart actions menu that appears inside a chart</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/667">Logstash metrics not being displayed in Netdata Cloud</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/679">The home tab not being updated with the correct number of nodes, after deleting a node</a></li> </ul><h3>Real Time Functions</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-functions">Functions</a></p> <h3>Events Feed</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-feed">Events Feed</a>.</p> <h2>Database</h2> <h3>New database engine</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-dbenginev2">Dramatic performance and stability improvements, with a smaller agent footprint</a></p> <h3>Metadata sync</h3> <p>Saving metadata to SQLite is now faster. Metadata saving starts asynchronously when the agent starts and continues as long as there are metadata to be saved. We implemented optimizations by grouping queries into transactions. At runtime this grouping happens per chart, which on shutdown it happens per host. These changes made metadata syncing up to 4x faster.</p> <h2>Streaming and Replication</h2> <p>We introduced very significant reliability and performance improvements to the streaming protocol and the database replication. See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-stream">Streaming</a>, <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-repl">Replication</a>.</p> <p>At the same time, we fixed SSL handshake issues on established SSL connections, provide stable streaming SSL connectivity between Netdata agents.</p> <h2>API</h2> <p>Data queries for charts and contexts now have the following additional features:</p> <ol><li>The query planner that decided which tier to use for each query, now prefers higher tiers, to speed up queries</li> <li>Joining of multiple tiers to the same query now prefers higher resolution tiers and joining is accurate. To achieve that, behind the scenes the query planner expands the query of each tier to overlap with its previous and next and at the time they intersect, it reads points from all the overlapping tiers to decide how exactly the join should happen.</li> <li>Data queries now utilize the parallelism of the new dbengine, to pipeline query preparation of the dimensions of the chart or context being queried, and then preloading metric data for dimensions that are in the pipeline.</li> </ol><h2>Machine Learning</h2> <p>We have been busy at work under the hood of the Netdata agent to introduce new capabilities that let you extend the "training window" used by Netdata's <a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection">native anomaly detection capabilities</a>.</p> <p><a href="https://preview.redd.it/ij8xh9rw8mga1.png?width=955&amp;format=png&amp;auto=webp&amp;s=df442f7f5722a6959c66b9498920884b8568e2cd">https://preview.redd.it/ij8xh9rw8mga1.png?width=955&amp;format=png&amp;auto=webp&amp;s=df442f7f5722a6959c66b9498920884b8568e2cd</a></p> <p>We have <a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection#descriptions-minmax">introduced a new ML parameter</a> called number of models per dimension<br> which will control the number of most recently trained models used during scoring.</p> <p>Below is some pseudo-code of how the trained models are actually used in producing <a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection#anomaly-bit">anomaly bits</a> (which give you an "<a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection#anomaly-rate">anomaly rate</a>" over any window of time) each second.</p> <p><code># preprocess recent observations into a "feature vector"</code></p> <p><code>latest_feature_vector = preprocess_data([recent_data])</code></p> <p><code># loop over each trained model</code></p> <p><code>for model in models:</code></p> <p><code># if recent feature vector is considered normal by any model, stop scoring</code></p> <p><code>if model.score(latest_feature_vector) &lt; dimension_anomaly_score_threshold:</code></p> <p><code>anomaly_bit = 0</code></p> <p><code>break</code></p> <p><code>else:</code></p> <p><code># only if all models agree the feature vector is anomalous is it considered anomalous by netdata</code></p> <p><code>anomaly_bit = 1</code></p> <p>​</p> <p>The aim here is to only use those additional stored models when we need to. So essentially once one model suggests a feature vector looks anomalous we check all saved models and only when they all agree that something is anomalous does the anomaly bit get to be finally set to 1 to signal that Netdata considered the most recent feature vector unlike anything seen in all the models (spanning a wider training window) checked.</p> <p>Read more in <a href="https://blog.netdata.cloud/extending-anomaly-detection-training-window/">this blog post</a>!</p> <p>We now <a href="https://github.com/netdata/netdata/pull/14207">create ML charts on child hosts</a>, when a parent runs a ML for a child. These charts use the parent's hostname to differentiate multiple parents that might run ML for a child.</p> <p>Finally, we <a href="https://github.com/netdata/netdata/pull/14198">refactored the ML code and added support for multiple KMeans models</a>.</p> <h2>Installation and Packaging</h2> <h3>New hosting of build artifacts</h3> <p>We are always looking to improve the ways we make the agent available to users. Where we host our build artifacts is an important piece of the puzzle, and we've taken some significant steps in the past couple of months.</p> <h4>New hosting of nightly build artifacts</h4> <p>As of 2023-01-16, our nightly build artifacts are being hosted as GitHub releases on the new <a href="https://github.com/netdata/netdata-nightlies/">https://github.com/netdata/netdata-nightlies/</a> repository instead of being hosted on Google Cloud Storage. In most cases, this should have no functional impact for users, and no changes should be required on user systems.</p> <h4>New hosting of native package repositories</h4> <p>As part of improving support for our native packages, we are migrating off of Package Cloud to our own self-hosted package repositories located at <a href="https://repo.netdata.cloud/repos/">https://repo.netdata.cloud/repos/</a>. This new infrastructure provides a number of benefits, including signed packages, easier on-site caching, more rapid support for newly released distributions, and the ability to support native packages for a wider variety of distributions.</p> <p>Our RPM repositories <a href="https://github.com/netdata/netdata/discussions/14161">have already been fully migrated</a> and the DEB repositories <a href="https://github.com/netdata/netdata/discussions/14300">are currently in the process of being migrated</a>.</p> <h4>Official Docker images now available on GHCR and Quay</h4> <p>In addition to Docker Hub, our official Docker images are now available on <a href="https://github.com/netdata/netdata/pkgs/container/netdata">GHCR</a> and <a href="https://quay.io/repository/netdata/netdata">Quay</a>. The images are identical across all three registries, including using the same tagging.</p> <p>You can use our Docker images from GHCR or Quay by either configuring them as registries with your local container tooling, or by using <a href="https://ghcr.io/netdata/netdata">ghcr.io/netdata/netdata</a> or <a href="https://quay.io/netdata/netdata">quay.io/netdata/netdata</a> instead of netdata/netdata.</p> <h3>kickstart</h3> <p>The directives --local-build-options and --static-install-options used to only accept a single option each. We now <a href="https://github.com/netdata/netdata/pull/14287">allow multiple options to be entered</a>.</p> <p>We <a href="https://github.com/netdata/netdata/pull/13881">renamed</a> the --install option to --install-prefix, to clarify that it affects the directory under which the Netdata agent will be installed.</p> <p>To help prevent user errors, passing an unrecognized option to the kickstart script <a href="https://github.com/netdata/netdata/pull/12943">now results in a fatal error</a> instead of just a warning.</p> <p>We previously used grep to get some info on login or group, which could not handle cases with centralized authentication like Active Directory or FreeIPA or pure LDAP. We <a href="https://github.com/netdata/netdata/pull/14316">now use "getent group"</a> to get the group information.</p> <h3>RPMs</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14140">fixed the required permissions</a> of the cgroup-network and ebpf.plugin in RPM packages.</p> <h3>OpenSUSE</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14260">fixed the binary package updates</a> that were failing with an error on "Zypper upgrade".</p> <h3>FreeBSD</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14095">fixed the missing required package installation of "tar"</a>.</p> <h3>MacOS</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14304">fixed some crashes on MacOS</a>.</p> <h3>Proxmox</h3> <p>Netdata on Proxmox virtualization management servers must be allowed to resolve VM/container names and read their CPU and memory limits. </p> <p>We now <a href="https://github.com/netdata/netdata/pull/14168">explicitly add</a> the netdata user to the www-data group on Proxmox, so that users don't have to do it manually.</p> <h3>Other</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14180">fixed the path to "netdata.pid"</a> in the logrotate postrotate script, which causes some errors during log rotation.</p> <p>We also <a href="https://github.com/netdata/netdata/pull/14239">added pre gcc v5 support</a> and allowed building without dbengine.</p> <h2>Administration</h2> <h3>Logging</h3> <p>We have improved the readability of our main error log file error.log<br> , by <a href="https://github.com/netdata/netdata/pull/14309">moving data collection specific log messages</a> to collector.log<br> . For the same reason we <a href="https://github.com/netdata/netdata/pull/14117">reduced the log verbosity of streaming connections</a>.</p> <h3>New configuration editing script</h3> <p>We reimplemented the edit-config script we install in the user config directory, adding a few new features, and fixing a number of outstanding issues with the previous script.</p> <h3>Netdata Monitoring</h3> <p>The new Netdata Monitoring section on our dashboard has dozens of charts detailing the operation of Netdata. All new components have their charts, dbengine, metrics registry, the new caches, the dbengine query router, etc.</p> <p>At the same time, we added a chart detailing the memory used by the agent and the function it is used for. This was the hardest to gather, since information was spread all over the place, but thankfully the internals of the agents have changed drastically in the last few months, allowing us to have a better visibility on memory consumption. At its heart, the agent is now mainly an array allocator (ARAL) and a dictionary (indexed and ordered lists of objects), carefully crafted to achieve their maximum performance when multithreaded. Everything we do, from data collection, to health, streaming, replication, etc., is actually business logic on top of these elements.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Chris-1235"> /u/Chris-1235 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/10vf42u/netdata_release_1380/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/10vf42u/netdata_release_1380/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (leptonlib), Fedora (woff), Red Hat (grub2), Slackware (emacs), SUSE (busybox, chromium, java-1_8_0-openjdk, netatalk, and rabbitmq-server), and Ubuntu (gcc-5, gccgo-6, glibc, protobuf, and python2.7, python3.10, python3.6, python3.8).]]></description>
<link>https://tsecurity.de/de/1726672/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1726672/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 09 Dec 2022 15:00:18 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (leptonlib), <b>Fedora</b> (woff), <b>Red Hat</b> (grub2), <b>Slackware</b> (emacs), <b>SUSE</b> (busybox, chromium, java-1_8_0-openjdk, netatalk, and rabbitmq-server), and <b>Ubuntu</b> (gcc-5, gccgo-6, glibc, protobuf, and python2.7, python3.10, python3.6, python3.8).]]></content:encoded>
</item>
<item>
<title><![CDATA[Verwendung schwacher Verschlüsselung in rabbitmq-server (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1726164/it-security-nachrichten/verwendung-schwacher-verschluesselung-in-rabbitmq-server-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1726164/it-security-nachrichten/verwendung-schwacher-verschluesselung-in-rabbitmq-server-suse/</guid>
<pubDate>Fri, 09 Dec 2022 09:05:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Red Hat Security Advisory 2022-8851-01]]></title>
<description><![CDATA[Red Hat Security Advisory 2022-8851-01 - An update for rabbitmq-server is now available for Red Hat OpenStack Platform 16.2.4 (Train) for Red Hat Enterprise Linux (RHEL) 8.4. Issues addressed include cross site scripting and improper neutralization vulnerabilities.]]></description>
<link>https://tsecurity.de/de/1725464/it-security-tools/red-hat-security-advisory-2022-8851-01/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1725464/it-security-tools/red-hat-security-advisory-2022-8851-01/</guid>
<pubDate>Thu, 08 Dec 2022 18:31:04 +0100</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Red Hat Security Advisory 2022-8851-01 - An update for rabbitmq-server is now available for Red Hat OpenStack Platform 16.2.4 (Train) for Red Hat Enterprise Linux (RHEL) 8.4. Issues addressed include cross site scripting and improper neutralization vulnerabilities.]]></content:encoded>
</item>
<item>
<title><![CDATA[Red Hat Security Advisory 2022-8867-01]]></title>
<description><![CDATA[Red Hat Security Advisory 2022-8867-01 - An update for rabbitmq-server is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Issues addressed include cross site scripting and improper neutralization vulnerabilities.]]></description>
<link>https://tsecurity.de/de/1725467/it-security-tools/red-hat-security-advisory-2022-8867-01/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1725467/it-security-tools/red-hat-security-advisory-2022-8867-01/</guid>
<pubDate>Thu, 08 Dec 2022 18:31:04 +0100</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Red Hat Security Advisory 2022-8867-01 - An update for rabbitmq-server is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Issues addressed include cross site scripting and improper neutralization vulnerabilities.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cross-Site Scripting in rabbitmq-server (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1724444/it-security-nachrichten/cross-site-scripting-in-rabbitmq-server-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1724444/it-security-nachrichten/cross-site-scripting-in-rabbitmq-server-red-hat/</guid>
<pubDate>Thu, 08 Dec 2022 07:15:54 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Zwei Probleme in rabbitmq-server (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1724445/it-security-nachrichten/zwei-probleme-in-rabbitmq-server-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1724445/it-security-nachrichten/zwei-probleme-in-rabbitmq-server-red-hat/</guid>
<pubDate>Thu, 08 Dec 2022 07:15:54 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[VMware Tanzu passt Tools an Spring-Framework 6.0 und Native Image an]]></title>
<description><![CDATA[Im Zuge von Spring 6.0 erscheinen aktualisierte Releases von Security, Authorization Server, REST Docs, Web Services sowie Spring for Apache Kafka und RabbitMQ.]]></description>
<link>https://tsecurity.de/de/1704794/it-nachrichten/vmware-tanzu-passt-tools-an-spring-framework-60-und-native-image-an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1704794/it-nachrichten/vmware-tanzu-passt-tools-an-spring-framework-60-und-native-image-an/</guid>
<pubDate>Wed, 23 Nov 2022 16:04:07 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Im Zuge von Spring 6.0 erscheinen aktualisierte Releases von Security, Authorization Server, REST Docs, Web Services sowie Spring for Apache Kafka und RabbitMQ.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-31008 | RabbitMQ random values (GHSA-v9gv-xp36-jgj8)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in  RabbitMQ. This affects an unknown part. The manipulation leads to insufficiently random values.

This vulnerability is uniquely identified as CVE-2022-31008. It is possible to launch the attack on the local host. There is no expl...]]></description>
<link>https://tsecurity.de/de/1679683/sicherheitsluecken/cve-2022-31008-rabbitmq-random-values-ghsa-v9gv-xp36-jgj8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1679683/sicherheitsluecken/cve-2022-31008-rabbitmq-random-values-ghsa-v9gv-xp36-jgj8/</guid>
<pubDate>Sun, 30 Oct 2022 14:46:46 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as problematic, was found in  RabbitMQ. This affects an unknown part. The manipulation leads to insufficiently random values.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.210189">CVE-2022-31008</a>. It is possible to launch the attack on the local host. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-31008]]></title>
<description><![CDATA[RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions ...]]></description>
<link>https://tsecurity.de/de/1653993/sicherheitsluecken/cve-2022-31008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1653993/sicherheitsluecken/cve-2022-31008/</guid>
<pubDate>Thu, 06 Oct 2022 22:47:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (bind9, expat, firefox-esr, mediawiki, and unzip), Fedora (qemu and thunderbird), Oracle (webkit2gtk3), SUSE (ardana-ansible, ardana-cobbler, ardana-tempest, grafana, openstack-heat-templates, openstack-horizon-plugin-gbp-ui, openstack-neutron-gbp, open...]]></description>
<link>https://tsecurity.de/de/1640724/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1640724/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 23 Sep 2022 16:45:14 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (bind9, expat, firefox-esr, mediawiki, and unzip), <b>Fedora</b> (qemu and thunderbird), <b>Oracle</b> (webkit2gtk3), <b>SUSE</b> (ardana-ansible, ardana-cobbler, ardana-tempest, grafana, openstack-heat-templates, openstack-horizon-plugin-gbp-ui, openstack-neutron-gbp, openstack-nova, python-Django1, rabbitmq-server, rubygem-puma, ardana-ansible, ardana-cobbler, grafana, openstack-heat-templates, openstack-murano, python-Django, rabbitmq-server, rubygem-puma, dpdk, freetype2, rubygem-rack, and virtualbox), and <b>Ubuntu</b> (etcd, libjpeg-turbo, linux-gcp, linux-gke, linux-raspi, linux-oem-5.17, linux-raspi-5.4, python-oauthlib, and python3.5).]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in ardana-ansible, ardana-cobbler, openstack-heat-templates, openstack-murano, python-Django, rabbitmq-server, rubygem-puma und grafana (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1639864/it-security-nachrichten/mehrere-probleme-in-ardana-ansible-ardana-cobbler-openstack-heat-templates-openstack-murano-python-django-rabbitmq-server-rubygem-puma-und-grafana-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1639864/it-security-nachrichten/mehrere-probleme-in-ardana-ansible-ardana-cobbler-openstack-heat-templates-openstack-murano-python-django-rabbitmq-server-rubygem-puma-und-grafana-suse/</guid>
<pubDate>Thu, 22 Sep 2022 23:15:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Mehrere Probleme in ardana-ansible, ardana-cobbler, ardana-tempest, openstack-heat-templates, openstack-horizon-plugin-gbp-ui, openstack-neutron-gbp, openstack-nova, python-Django1, rabbitmq-server, rubygem-puma und grafana (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1639863/it-security-nachrichten/mehrere-probleme-in-ardana-ansible-ardana-cobbler-ardana-tempest-openstack-heat-templates-openstack-horizon-plugin-gbp-ui-openstack-neutron-gbp-openstack-nova-python-django1-rabbitmq-server-rubygem-puma-und-grafana-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1639863/it-security-nachrichten/mehrere-probleme-in-ardana-ansible-ardana-cobbler-ardana-tempest-openstack-heat-templates-openstack-horizon-plugin-gbp-ui-openstack-neutron-gbp-openstack-nova-python-django1-rabbitmq-server-rubygem-puma-und-grafana-suse/</guid>
<pubDate>Thu, 22 Sep 2022 23:14:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[CVE-2022-38665]]></title>
<description><![CDATA[Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. (CVSS:0.0) (Last Update:2022-08-23)]]></description>
<link>https://tsecurity.de/de/1609789/sicherheitsluecken/cve-2022-38665/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1609789/sicherheitsluecken/cve-2022-38665/</guid>
<pubDate>Wed, 24 Aug 2022 02:05:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. (CVSS:0.0) (Last Update:2022-08-23)]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-38665]]></title>
<description><![CDATA[Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.]]></description>
<link>https://tsecurity.de/de/1609614/sicherheitsluecken/cve-2022-38665/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1609614/sicherheitsluecken/cve-2022-38665/</guid>
<pubDate>Tue, 23 Aug 2022 21:17:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-19340 | Red Hat Ansible Tower up to 3.5.2/3.6.1 RabbitMQ Management Interface information disclosure]]></title>
<description><![CDATA[A vulnerability was found in  Red Hat Ansible Tower up to 3.5.2/3.6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component RabbitMQ Management Interface. The manipulation leads to information disclosure.

This vulnerability is handled as CVE-2019-1...]]></description>
<link>https://tsecurity.de/de/1607774/sicherheitsluecken/cve-2019-19340-red-hat-ansible-tower-up-to-352361-rabbitmq-management-interface-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1607774/sicherheitsluecken/cve-2019-19340-red-hat-ansible-tower-up-to-352361-rabbitmq-management-interface-information-disclosure/</guid>
<pubDate>Mon, 22 Aug 2022 10:34:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in  Red Hat Ansible Tower up to 3.5.2/3.6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component <em>RabbitMQ Management Interface</em>. The manipulation leads to information disclosure.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.147536">CVE-2019-19340</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kubernetes-Operator: Tanzu RabbitMQ 1.3 bringt Support für Kubernetes 1.23]]></title>
<description><![CDATA[Das auf RabbitMQ aufsetzende Tanzu RabbitMQ aktualisiert den Message Broker auf Version 3.10 und versieht drei Operatoren mit Updates.]]></description>
<link>https://tsecurity.de/de/1571924/it-nachrichten/kubernetes-operator-tanzu-rabbitmq-13-bringt-support-fuer-kubernetes-123/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1571924/it-nachrichten/kubernetes-operator-tanzu-rabbitmq-13-bringt-support-fuer-kubernetes-123/</guid>
<pubDate>Fri, 15 Jul 2022 11:17:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das auf RabbitMQ aufsetzende Tanzu RabbitMQ aktualisiert den Message Broker auf Version 3.10 und versieht drei Operatoren mit Updates.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR3639: Linux Inlaws S01E60: The Job Interview]]></title>
<description><![CDATA[In this episode, the Linux Inlaws interview a potential new recruit :-) call Kris Jenkins, from Kafka, an Apache project implementing a scalable distributed event streaming platform (don't know what that is? Listen to the show! :-) . A cautious warning: This episode contains strong philosophical ...]]></description>
<link>https://tsecurity.de/de/1570532/podcasts/hpr3639-linux-inlaws-s01e60-the-job-interview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1570532/podcasts/hpr3639-linux-inlaws-s01e60-the-job-interview/</guid>
<pubDate>Thu, 14 Jul 2022 09:33:46 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>

In this episode, the Linux Inlaws interview a potential new recruit :-) call Kris Jenkins, from Kafka, an Apache project implementing a scalable distributed event streaming platform (don't know what that is? Listen to the show! :-) . A cautious warning: This episode contains strong philosophical / political views, language and insights which may change your views on messaging systems in general and Kafka in particular. Two hints: Chris shares his view on what a database *really* is and Kris Jenkins tries hard to convince our two aging heroes that he's the man for the job (teaser: he decided to stay at his current position as a dev advocate at Confluent after all). Plus: More on love, death and robots. Interested in the details? Then don't miss this show! 
</p>

<h2>Links:</h2>
<ul><li>Apache Kafka: <a href="https://kafka.apache.org/" target="_blank">https://kafka.apache.org</a></li>
<li>Confluent: <a href="https://www.confluent.io/" target="_blank">https://www.confluent.io</a></li>
<li>Redis: <a href="https://redis.io/" target="_blank">https://redis.io</a></li>
<li>Databases: <a href="https://en.wikipedia.org/wiki/Database" target="_blank">https://en.wikipedia.org/wiki/Database</a></li>
<li>Event-Driven Architecture: <a href="https://en.wikipedia.org/wiki/Event-driven_architecture" target="_blank">https://en.wikipedia.org/wiki/Event-driven_architecture</a></li>
<li>RabbitMQ: <a href="https://github.com/rabbitmq" target="_blank">https://github.com/rabbitmq</a></li>
<li>Zookeeper note: <a href="https://medium.com/knerd/eureka-why-you-shouldnt-use-zookeeper-for-service-discovery-4932c5c7e764" target="_blank">https://medium.com/knerd/eureka-why-you-shouldnt-use-zookeeper-for-service-discovery-4932c5c7e764</a></li>
<li>KRaft: <a href="https://docs.confluent.io/platform/current/zookeeper/kraft.html" target="_blank">https://docs.confluent.io/platform/current/zookeeper/kraft.html</a></li>
<li>KIP: <a href="https://cwiki.apache.org/confluence/display/kafka/kafka+improvement+proposals" target="_blank">https://cwiki.apache.org/confluence/display/kafka/kafka+improvement+proposals</a></li>
<li>Monster Hunter: <a href="https://www.monsterhunter.com/" target="_blank">https://www.monsterhunter.com</a></li>
<li>LOVE DEATH + ROBOTS: <a href="https://www.imdb.com/title/tt9561862" target="_blank">https://www.imdb.com/title/tt9561862</a></li>
<li>Unix Philosophy: <a href="http://www.linfo.org/unix_philosophy.html" target="_blank">http://www.linfo.org/unix_philosophy.html</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-5329 | Red Hat Enterprise Linux OpenStack 7.0 RabbitMQ Credential access control (RHSA-2015:2650 / SBV-58177)]]></title>
<description><![CDATA[A vulnerability has been found in  Red Hat Enterprise Linux OpenStack 7.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component RabbitMQ Credential Handler. The manipulation leads to improper access controls.

This vulnerability is known as CVE-20...]]></description>
<link>https://tsecurity.de/de/1569348/sicherheitsluecken/cve-2015-5329-red-hat-enterprise-linux-openstack-70-rabbitmq-credential-access-control-rhsa-20152650-sbv-58177/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1569348/sicherheitsluecken/cve-2015-5329-red-hat-enterprise-linux-openstack-70-rabbitmq-credential-access-control-rhsa-20152650-sbv-58177/</guid>
<pubDate>Wed, 13 Jul 2022 12:17:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in  Red Hat Enterprise Linux OpenStack 7.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component <em>RabbitMQ Credential Handler</em>. The manipulation leads to improper access controls.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.82057">CVE-2015-5329</a>. The attack can be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub Security Lab: [Java]: Flow sources and steps for JMS and RabbitMQ]]></title>
<description><![CDATA[This bug was reported directly to GitHub Security...]]></description>
<link>https://tsecurity.de/de/1533955/sicherheitsluecken/github-security-lab-java-flow-sources-and-steps-for-jms-and-rabbitmq/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1533955/sicherheitsluecken/github-security-lab-java-flow-sources-and-steps-for-jms-and-rabbitmq/</guid>
<pubDate>Tue, 07 Jun 2022 07:06:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<br><img height="200" width="200" src="http://vulners.com/static/img/hackerone.png" alt="image"><br>This bug was reported directly to GitHub Security...]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (tomcat8), Mageia (bluez, exiv2, fetchmail, libsndfile, nodejs, php-pear, python-pillow, and rabbitmq-server), openSUSE (apache-commons-compress, balsa, djvulibre, mariadb, mysql-connector-java, nodejs8, opera, and spice-vdagent), Red Hat (ruby:2.7), SU...]]></description>
<link>https://tsecurity.de/de/1516508/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1516508/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 06 Aug 2021 16:30:11 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (tomcat8), <b>Mageia</b> (bluez, exiv2, fetchmail, libsndfile, nodejs, php-pear, python-pillow, and rabbitmq-server), <b>openSUSE</b> (apache-commons-compress, balsa, djvulibre, mariadb, mysql-connector-java, nodejs8, opera, and spice-vdagent), <b>Red Hat</b> (ruby:2.7), <b>SUSE</b> (apache-commons-compress, djvulibre, java-11-openjdk, libsndfile, mariadb, nodejs8, and spice-vdagent), and <b>Ubuntu</b> (docker.io).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (aspell, intel-microcode, krb5, rabbitmq-server, and ruby-actionpack-page-caching), Fedora (chromium, containernetworking-plugins, containers-common, crun, fossil, podman, skopeo, varnish-modules, and vmod-uuid), Gentoo (leptonica, libsdl2, and libyang)...]]></description>
<link>https://tsecurity.de/de/1515058/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1515058/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 26 Jul 2021 18:00:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (aspell, intel-microcode, krb5, rabbitmq-server, and ruby-actionpack-page-caching), <b>Fedora</b> (chromium, containernetworking-plugins, containers-common, crun, fossil, podman, skopeo, varnish-modules, and vmod-uuid), <b>Gentoo</b> (leptonica, libsdl2, and libyang), <b>Mageia</b> (golang, lib3mf, nodejs, python-pip, redis, and xstream), <b>openSUSE</b> (containerd, crmsh, curl, icinga2, and systemd), <b>Oracle</b> (containerd), and <b>Red Hat</b> (thunderbird).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (kernel, libjdom1-java, rabbitmq-server, and systemd), Fedora (glibc), Gentoo (libpano13, libslirp, mpv, pjproject, pycharm-community, and rpm), Mageia (glibc, libuv, mbedtls, rvxt-unicode, mxrvt, eterm, tomcat, and zziplib), openSUSE (dbus-1, firefox, ...]]></description>
<link>https://tsecurity.de/de/1514300/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1514300/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 20 Jul 2021 17:30:11 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (kernel, libjdom1-java, rabbitmq-server, and systemd), <b>Fedora</b> (glibc), <b>Gentoo</b> (libpano13, libslirp, mpv, pjproject, pycharm-community, and rpm), <b>Mageia</b> (glibc, libuv, mbedtls, rvxt-unicode, mxrvt, eterm, tomcat, and zziplib), <b>openSUSE</b> (dbus-1, firefox, go1.15, lasso, nodejs10, nodejs12, nodejs14, and sqlite3), <b>SUSE</b> (go1.15), and <b>Ubuntu</b> (containerd).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Saturday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (gitlab, nodejs, openexr, php, php7, rabbitmq, ruby-addressable, and spice), Fedora (suricata), Gentoo (binutils, docker, runc, and tor), Mageia (avahi, botan2, connman, gstreamer1.0-plugins, htmldoc, jhead, libcroco, libebml, libosinfo, openexr, ph...]]></description>
<link>https://tsecurity.de/de/1513136/linux-tipps/security-updates-for-saturday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1513136/linux-tipps/security-updates-for-saturday/</guid>
<pubDate>Sun, 11 Jul 2021 02:15:15 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (gitlab, nodejs, openexr, php, php7, rabbitmq, ruby-addressable, and spice), <b>Fedora</b> (suricata), <b>Gentoo</b> (binutils, docker, runc, and tor), <b>Mageia</b> (avahi, botan2, connman, gstreamer1.0-plugins, htmldoc, jhead, libcroco, libebml, libosinfo, openexr, php, php-smarty, pjproject, and python), <b>openSUSE</b> (apache2, bind, bouncycastle, ceph, containerd, docker, runc, cryptctl, curl, dovecot23, firefox, graphviz, gstreamer-plugins-bad, java-1_8_0-openj9, java-1_8_0-openjdk, libass, libjpeg-turbo, libopenmpt, libqt5-qtwebengine, libu2f-host, libwebp, libX11, lua53, lz4, nginx, ovmf, postgresql10, postgresql12, python-urllib3, qemu, roundcubemail, solo, thunderbird, ucode-intel, wireshark, and xterm), and <b>SUSE</b> (permissions).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (python-django), Debian (libuv1, libxstream-java, and php7.3), Fedora (rabbitmq-server), Gentoo (glibc, google-chrome, libxml2, and postsrsd), openSUSE (libqt5-qtwebengine and roundcubemail), SUSE (python-rsa), and Ubuntu (djvulibre).]]></description>
<link>https://tsecurity.de/de/1512653/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1512653/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 06 Jul 2021 17:30:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (python-django), <b>Debian</b> (libuv1, libxstream-java, and php7.3), <b>Fedora</b> (rabbitmq-server), <b>Gentoo</b> (glibc, google-chrome, libxml2, and postsrsd), <b>openSUSE</b> (libqt5-qtwebengine and roundcubemail), <b>SUSE</b> (python-rsa), and <b>Ubuntu</b> (djvulibre).]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-5004-1: RabbitMQ vulnerabilities]]></title>
<description><![CDATA[It was discovered that RabbitMQ incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2019-11287)

Jonathan Knudsen discovered RabbitMQ incorrectly handled certain inputs.
An...]]></description>
<link>https://tsecurity.de/de/1511524/unix-server/usn-5004-1-rabbitmq-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1511524/unix-server/usn-5004-1-rabbitmq-vulnerabilities/</guid>
<pubDate>Sat, 26 Jun 2021 15:03:01 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that RabbitMQ incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2019-11287)

Jonathan Knudsen discovered RabbitMQ incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2021-22116)]]></content:encoded>
</item>
<item>
<title><![CDATA[Ubuntu Security Notice USN-5004-1]]></title>
<description><![CDATA[Ubuntu Security Notice 5004-1 - It was discovered that RabbitMQ incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. Jonathan Knudsen discovered RabbitMQ incorrectly handled cert...]]></description>
<link>https://tsecurity.de/de/1510162/it-security-tools/ubuntu-security-notice-usn-5004-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1510162/it-security-tools/ubuntu-security-notice-usn-5004-1/</guid>
<pubDate>Sat, 26 Jun 2021 15:00:50 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ubuntu Security Notice 5004-1 - It was discovered that RabbitMQ incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. Jonathan Knudsen discovered RabbitMQ incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in RabbitMQ (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1509783/it-security-nachrichten/zwei-probleme-in-rabbitmq-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1509783/it-security-nachrichten/zwei-probleme-in-rabbitmq-ubuntu/</guid>
<pubDate>Sat, 26 Jun 2021 15:00:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (chromium, dovecot, exiv2, helm, keycloak, libslirp, matrix-appservice-irc, nginx-mainline, opera, pigeonhole, tor, tpm2-tools, and vivaldi), Debian (libgcrypt20), Fedora (pdfbox), Mageia (graphicsmagick, matio, and samba and ldb), openSUSE (dovecot...]]></description>
<link>https://tsecurity.de/de/1509445/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1509445/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 25 Jun 2021 17:30:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (chromium, dovecot, exiv2, helm, keycloak, libslirp, matrix-appservice-irc, nginx-mainline, opera, pigeonhole, tor, tpm2-tools, and vivaldi), <b>Debian</b> (libgcrypt20), <b>Fedora</b> (pdfbox), <b>Mageia</b> (graphicsmagick, matio, and samba and ldb), <b>openSUSE</b> (dovecot23, gupnp, libgcrypt, live555, and ovmf), <b>SUSE</b> (gupnp, libgcrypt, openexr, and ovmf), and <b>Ubuntu</b> (ceph and rabbitmq-server).]]></content:encoded>
</item>
<item>
<title><![CDATA[VMware baut Tanzu RabbitMQ 1.1 für komplexe Topologien aus]]></title>
<description><![CDATA[Der auf dem Message Broker RabbitMQ aufbauende Kubernetes-Operator bietet nun auch Alerting und eine Preview auf die kommende Aktiv-Passiv-Replikation.]]></description>
<link>https://tsecurity.de/de/1507000/it-nachrichten/vmware-baut-tanzu-rabbitmq-11-fuer-komplexe-topologien-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1507000/it-nachrichten/vmware-baut-tanzu-rabbitmq-11-fuer-komplexe-topologien-aus/</guid>
<pubDate>Sun, 20 Jun 2021 15:01:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der auf dem Message Broker RabbitMQ aufbauende Kubernetes-Operator bietet nun auch Alerting und eine Preview auf die kommende Aktiv-Passiv-Replikation.]]></content:encoded>
</item>
<item>
<title><![CDATA[VMware RabbitMQ up to 3.8.15 AMQP Client denial of service]]></title>
<description><![CDATA[A vulnerability was found in VMware RabbitMQ up to 3.8.15. It has been classified as problematic. This affects some unknown functionality of the component AMQP Client. Upgrading to version 3.8.16 eliminates this vulnerability.]]></description>
<link>https://tsecurity.de/de/1501864/sicherheitsluecken/vmware-rabbitmq-up-to-3815-amqp-client-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1501864/sicherheitsluecken/vmware-rabbitmq-up-to-3815-amqp-client-denial-of-service/</guid>
<pubDate>Fri, 11 Jun 2021 15:46:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.vmware:rabbitmq">VMware RabbitMQ up to 3.8.15</a>. It has been classified as problematic. This affects some unknown functionality of the component <em>AMQP Client</em>. Upgrading to version 3.8.16 eliminates this vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[Updates verfügbar: Schwachstellen in Message-Brokern RabbitMQ, EMQ X und VerneMQ]]></title>
<description><![CDATA[Die Message-Broker sind für Denial-of-Service-Angriffe über das IoT-Protokoll MQTT anfällig. Aktuelle Patches sind verfügbar, Sie sollten sie schnell anwenden.]]></description>
<link>https://tsecurity.de/de/1498809/it-security-nachrichten/updates-verfuegbar-schwachstellen-in-message-brokern-rabbitmq-emq-x-und-vernemq/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1498809/it-security-nachrichten/updates-verfuegbar-schwachstellen-in-message-brokern-rabbitmq-emq-x-und-vernemq/</guid>
<pubDate>Wed, 09 Jun 2021 13:45:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Message-Broker sind für Denial-of-Service-Angriffe über das IoT-Protokoll MQTT anfällig. Aktuelle Patches sind verfügbar, Sie sollten sie schnell anwenden.]]></content:encoded>
</item>
<item>
<title><![CDATA[Updates verfügbar: Schwachstellen in Message-Brokern RabbitMQ, EMQ X und VerneMQ]]></title>
<description><![CDATA[Die Message-Broker sind für Denial-of-Service-Angriffe über das IoT-Protokoll MQTT anfällig. Aktuelle Patches sind verfügbar, Sie sollten sie schnell anwenden.]]></description>
<link>https://tsecurity.de/de/1498698/it-nachrichten/updates-verfuegbar-schwachstellen-in-message-brokern-rabbitmq-emq-x-und-vernemq/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1498698/it-nachrichten/updates-verfuegbar-schwachstellen-in-message-brokern-rabbitmq-emq-x-und-vernemq/</guid>
<pubDate>Wed, 09 Jun 2021 13:01:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Message-Broker sind für Denial-of-Service-Angriffe über das IoT-Protokoll MQTT anfällig. Aktuelle Patches sind verfügbar, Sie sollten sie schnell anwenden.]]></content:encoded>
</item>
<item>
<title><![CDATA[Organizations Warned About DoS Flaws in Popular Open Source Message Brokers]]></title>
<description><![CDATA[Organizations have been warned about denial of service (DoS) vulnerabilities found in RabbitMQ, EMQ X and VerneMQ, three widely used open source message brokers.
read more]]></description>
<link>https://tsecurity.de/de/1497690/it-security-nachrichten/organizations-warned-about-dos-flaws-in-popular-open-source-message-brokers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1497690/it-security-nachrichten/organizations-warned-about-dos-flaws-in-popular-open-source-message-brokers/</guid>
<pubDate>Tue, 08 Jun 2021 17:45:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong><span><span>Organizations have been warned about denial of service (DoS) vulnerabilities found in RabbitMQ, EMQ X and VerneMQ, three widely used open source message brokers.</span></span></strong></p>
<p><a href="https://www.securityweek.com/organizations-warned-about-dos-flaws-popular-open-source-message-brokers" target="_blank">read more</a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/securityweek?a=HD49QjsycR0:srWo3SYDhFY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/securityweek?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.feedburner.com/~ff/securityweek?a=HD49QjsycR0:srWo3SYDhFY:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/securityweek?i=HD49QjsycR0:srWo3SYDhFY:-BTjWOF_DHI" border="0"></a> <a href="http://feeds.feedburner.com/~ff/securityweek?a=HD49QjsycR0:srWo3SYDhFY:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/securityweek?d=dnMXMwOfBR0" border="0"></a> <a href="http://feeds.feedburner.com/~ff/securityweek?a=HD49QjsycR0:srWo3SYDhFY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/securityweek?i=HD49QjsycR0:srWo3SYDhFY:V_sGLiPBpWU" border="0"></a> <a href="http://feeds.feedburner.com/~ff/securityweek?a=HD49QjsycR0:srWo3SYDhFY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/securityweek?d=qj6IDK7rITs" border="0"></a> <a href="http://feeds.feedburner.com/~ff/securityweek?a=HD49QjsycR0:srWo3SYDhFY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/securityweek?i=HD49QjsycR0:srWo3SYDhFY:gIN9vFwOqvQ" border="0"></a> <a href="http://feeds.feedburner.com/~ff/securityweek?a=HD49QjsycR0:srWo3SYDhFY:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/securityweek?d=TzevzKxY174" border="0"></a> <a href="http://feeds.feedburner.com/~ff/securityweek?a=HD49QjsycR0:srWo3SYDhFY:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/securityweek?i=HD49QjsycR0:srWo3SYDhFY:F7zBnMyn0Lo" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/securityweek/~4/HD49QjsycR0" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-22116]]></title>
<description><![CDATA[RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugi...]]></description>
<link>https://tsecurity.de/de/1497673/sicherheitsluecken/cve-2021-22116/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1497673/sicherheitsluecken/cve-2021-22116/</guid>
<pubDate>Tue, 08 Jun 2021 16:46:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled.]]></content:encoded>
</item>
<item>
<title><![CDATA[DoS vulns in 3 open-source MQTT message brokers could leave users literally locked out of their homes or offices]]></title>
<description><![CDATA[If your IoT kit employs RabbitMQ, EMQ X or VerneMQ, it's time to get patching Synopsys Cybersecurity Research Centre (CyRC) has warned of easily triggered denial-of-service (DoS) vulnerabilities in three popular open-source Internet of Things message brokers: RabbitMQ, EMQ X, and VerneMQ.…]]></description>
<link>https://tsecurity.de/de/1497572/it-security-nachrichten/dos-vulns-in-3-open-source-mqtt-message-brokers-could-leave-users-literally-locked-out-of-their-homes-or-offices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1497572/it-security-nachrichten/dos-vulns-in-3-open-source-mqtt-message-brokers-could-leave-users-literally-locked-out-of-their-homes-or-offices/</guid>
<pubDate>Tue, 08 Jun 2021 16:45:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>If your IoT kit employs RabbitMQ, EMQ X or VerneMQ, it's time to get patching</h4> <p>Synopsys Cybersecurity Research Centre (CyRC) has warned of easily triggered denial-of-service (DoS) vulnerabilities in three popular open-source Internet of Things message brokers: RabbitMQ, EMQ X, and VerneMQ.…</p> <p><!--#include virtual='/data_centre/_whitepaper_textlinks_top.html' --></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (chromium, curl, dhclient, dhcp, firefox, keycloak, lib32-curl, lib32-libcurl-compat, lib32-libcurl-gnutls, libcurl-compat, libcurl-gnutls, opera, packagekit, pam-u2f, postgresql, rabbitmq, redis, ruby-bundler, and zint), Debian (caribou, firefox-es...]]></description>
<link>https://tsecurity.de/de/1492828/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1492828/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 03 Jun 2021 16:00:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (chromium, curl, dhclient, dhcp, firefox, keycloak, lib32-curl, lib32-libcurl-compat, lib32-libcurl-gnutls, libcurl-compat, libcurl-gnutls, opera, packagekit, pam-u2f, postgresql, rabbitmq, redis, ruby-bundler, and zint), <b>Debian</b> (caribou, firefox-esr, imagemagick, and isc-dhcp), <b>Fedora</b> (mapserver, mingw-python-pillow, and python-pillow), <b>openSUSE</b> (chromium), <b>Red Hat</b> (firefox, glib2, pki-core:10.6, polkit, rh-ruby26-ruby, and rh-ruby27-ruby), <b>SUSE</b> (ceph, dhcp, libwebp, nginx, qemu, squid, and xstream), and <b>Ubuntu</b> (firefox, linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-snapdragon, linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oracle, and policykit-1).]]></content:encoded>
</item>
<item>
<title><![CDATA[VMware RabbitMQ up to 3.8.15 on Windows Installer permission]]></title>
<description><![CDATA[A vulnerability has been found in VMware RabbitMQ up to 3.8.15 on Windows and classified as critical. Affected by this vulnerability is an unknown code block of the component Installer. Upgrading to version 3.8.16 eliminates this vulnerability.]]></description>
<link>https://tsecurity.de/de/1480570/sicherheitsluecken/vmware-rabbitmq-up-to-3815-on-windows-installer-permission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1480570/sicherheitsluecken/vmware-rabbitmq-up-to-3815-on-windows-installer-permission/</guid>
<pubDate>Sat, 22 May 2021 15:31:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.vmware:rabbitmq">VMware RabbitMQ up to 3.8.15</a> on Windows and classified as critical. Affected by this vulnerability is an unknown code block of the component <em>Installer</em>. Upgrading to version 3.8.16 eliminates this vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-22117]]></title>
<description><![CDATA[RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.]]></description>
<link>https://tsecurity.de/de/1475566/sicherheitsluecken/cve-2021-22117/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1475566/sicherheitsluecken/cve-2021-22117/</guid>
<pubDate>Tue, 18 May 2021 16:31:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.]]></content:encoded>
</item>
<item>
<title><![CDATA[CentOS Blog: CentOS Community Newsletter, May 2021 (#2105)]]></title>
<description><![CDATA[Hello, friends,
It's been another busy month in the CentOS Project, so we'll get straight to the news:
CentOS Stream News
Last week, Brian Stinson announced some updates on the progress towards CentOS Stream 9 on the centos-devel mailing list.
This included the availability of Stream 9 packages o...]]></description>
<link>https://tsecurity.de/de/1460464/unix-server/centos-blog-centos-community-newsletter-may-2021-2105/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1460464/unix-server/centos-blog-centos-community-newsletter-may-2021-2105/</guid>
<pubDate>Tue, 04 May 2021 04:16:59 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello, friends,</p>
<p>It's been another busy month in the CentOS Project, so we'll get straight to the news:</p>
<h2>CentOS Stream News</h2>
<p>Last week, Brian Stinson <a href="https://lists.centos.org/pipermail/centos-devel/2021-April/076772.html">announced some updates</a> on the progress towards CentOS Stream 9 on the centos-devel mailing list.</p>
<p>This included the availability of <a href="https://gitlab.com/redhat/centos-stream/rpms">Stream 9 packages on Gitlab</a>, and a <a href="https://kojihub.stream.centos.org/">koji instance</a> where you can watch package build activity.</p>
<p>And on Thursday we <a href="https://lists.centos.org/pipermail/centos-devel/2021-April/076802.html">announced</a> that the CentOS Stream 9 compose infrastructure is available at <a href="https://composes.stream.centos.org/test">https://composes.stream.centos.org/</a> if you want to try out very early builds of CentOS Stream 9.</p>
<p>If you're interested in contributing to CentOS Stream, you should start by <a href="https://gitlab.com/users/sign_up">registering for a Gitlab account</a>.  We're in the process of updating the contributor guide, and that should be posted soon. Follow the centos-devel mailing list, and @CentOS on Twitter, to be the first to find out the next updates.</p>
<h2>CentOS Dojo, May 13-14</h2>
<p>The schedule for the upcoming CentOS Dojo is <a href="https://wiki.centos.org/Events/Dojo/May2021">now posted</a>. We'll be featuring two days of technical presentations around the CentOS project and community, including an "Ask me anything" session with the board of directors.</p>
<p>Other sessions include:</p>
<p><strong>Thursday, May 13</strong></p>
<ul><li>New authentication platform for CentOS and SIGs</li>
<li> What's new in FreeIPA 4.9</li>
<li> Contributing to the CentOS Stream Kernel</li>
<li> CentOS Stream on Desktop or: How I Learned to Stop Worrying and Love LTS</li>
<li>Hyperscale SIG update</li>
</ul><p><strong>Friday, May 14th</strong></p>
<ul><li>Board AMA</li>
<li>Keeping track of CentOS infrastructure deployments with Ansible and ARA</li>
<li>Thinking About Binary Compatibility and CentOS Stream</li>
<li>CentOS Stream CI: current state and future plans</li>
<li>Hands-on building an AMI pipeline using CentOS Stream 8 and cloud-init</li>
</ul><p>Complete schedule and abstracts are available on the <a href="https://wiki.centos.org/Events/Dojo/May2021">event site</a>. The event will be online, and you will need to register (Free!) on the event website to attend. See you there!</p>
<h2>@CentOSProject is now @CentOS</h2>
<p>For the past few years, there have been two separate Twitter accounts for CentOS project news - @CentOS and @CentOSProject - and this has led to some confusion. We're pleased to announce that we've consolidated at <a href="https://twitter.com/centos">@CentOS</a>. If you were already following @CentOSProject, you've been automatically moved over to the @CentOS account. The @CentOSProject account will remain as a placeholder just pointing over to the official account.</p>
<p>Meanwhile, if you were following @CentOS to hear from Karanbir Singh, our long-time project lead, that account has been converted to <a href="https://twitter.com/karanorg">@KaranOrg</a>, where you can follow KB's technical musings and other thoughts around his work and life.</p>
<h2>Board nominations open</h2>
<p>As you may have seen in the April board meeting minutes, two directors have decided not to run for the upcoming board term. Both of these directors - Karsten and Carl - have served on the board for 8 years, and we have appreciated their service and dedication to the project.</p>
<p>That leaves two seats to be filled in the upcoming term. As per our governance documents, the board selects replacement directors. But the community is asked for nominations for these seats. If you're thinking of someone you think would be a good board member, or if you'd like to nominate yourself, please have a look at the <a href="https://www.centos.org/about/governance/director-requirements/">requirements and responsibilities of a director</a>, to see if this is something you (or the proposed candidate) would be willing to commit to. Then, submit your nomination via this <a href="https://forms.gle/U777HHDTkKgkg6Sa6">Google Form</a>. Thanks!</p>
<p>We're excited at the prospect of bringing new members, with new enthusiasm, to the board, even as we say a fond farewell to long-serving directors, and we look forward to your nominations.</p>
<h2>Code of Conduct</h2>
<p>We have been working with the Fedora project to draft a new code of conduct, and this was <a href="https://blog.centos.org/2021/04/code-of-conduct/">announced a few weeks ago</a>. We expect to implement our version of it shortly after Fedora publishes theirs. We intend to take their final version and make necessary edits (ie, replacing 'Fedora' with 'CentOS' and other related changes) and are therefore waiting until they are done with all proposed edits. We welcome your comments on the centos-devel mailing list over the coming weeks as we prepare to make this change.</p>
<h2>Red Hat Summit</h2>
<p>Last week we were at <a href="https://www.redhat.com/en/summit">Red Hat Summit</a>, Red Hat's annual convention. CentOS had a steady stream of visitors in the CentOS/Fedora booth - thank you to all of you who came and talked with us.</p>
<p>There were a couple of sessions specifically about CentOS Stream - two "Ask the expert" sessions where attendees could ask their burning questions around CentOS Stream. These were very similar sessions, presented twice to make them convenient for people in different time zones. These were recorded, and you can watch them now, with free registration on the Summit platform.</p>
<p>CentOS Stream: Building an innovative future for enterprise Linux</p>
<ul><li><a href="https://events.summit.redhat.com/widget/redhat/sum21/sessioncatalog/session/1612985601110001PiOR">Chris, Brian, and Herve</a></li>
<li><a href="https://events.summit.redhat.com/widget/redhat/sum21/sessioncatalog/session/1612985596209001PwQJ">Mike, Gunnar, and Brian</a></li>
</ul><p>If you have further questions about CentOS Stream, we encourage you to bring them to <a href="https://lists.centos.org/mailman/listinfo/centos-devel">the centos-devel mailing list</a>, or any of our <a href="https://wiki.centos.org/Promo/Networks">various social media presences</a>.</p>
<h2>SIG reports</h2>
<p>CentOS Special Interest Groups are smaller efforts around particular topics or technologies, to produce content on top of the base CentOS operating system. This month we have reports from a few of our SIGs.</p>
<h3>Messaging SIG</h3>
<h4>Purpose</h4>
<p>Provide a unique source for messaging related packages. These packages are consumed e.g by the Cloud SIG or the OpsTools SIG.</p>
<h4>Membership Update</h4>
<p>We had talks with the RabbitMQ maintainers to get RabbitMQ packages included and updated.</p>
<h4>Activity</h4>
<p>Other than that, the nature of this SIG is to provide ... for other SIGs. The churn is not as big as in other SIGs.</p>
<h3>Storage SIG</h3>
<h4>Repository Status and Updates</h4>
<p>GlusterFS 9 was released; the glusterfs-9.1 bug fix update is available.</p>
<p>Ceph Pacific/16 was released; the ceph-16.2.1 bug fix update is available (c8 and c8s).</p>
<p>Bug fix updates to NFS-Ganesha (including libntirpc), Ceph Octopus/15, Ceph Nautilus/14 (c7 and c8), and Gluster 8 are available.</p>
<p>Ceph Pacific, GlusterFS 8 and GlusterFS 9, and NFS-Ganesha 3 (including libntirpc) packages are now built for CentOS 8 Stream. The associated release packages for those will land in CentOS 8 Stream soon.</p>
<h4>Group Status and Actions from meeting</h4>
<p>The storage sig meeting is moved to #centos-meeting2</p>
<p>Ceph Pacific is now available and can be consumed by other projects:</p>
<p>The OpenStack TripleO CI now consumes cephadm Pacific for both released and pending content -<br><a href="https://review.opendev.org/q/topic:%22cephadm_pacific%22+(status:open%20OR%20status:merged)">https://review.opendev.org/q/topic:%22cephadm_pacific%22+(status:open%20OR%20status:merged)</a></p>
<h4>Links and other general informations</h4>
<p>Meetings agenda <a href="https://hackmd.io/Epc35JIESaeotoGzwu5R5w">https://hackmd.io/Epc35JIESaeotoGzwu5R5w</a></p>
<p> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JMS Client for RabbitMQ up to 1.15.1/2.1.x StreamMessage Data deserialization]]></title>
<description><![CDATA[A vulnerability was found in JMS Client for RabbitMQ up to 1.15.1/2.1.x. It has been classified as critical. Affected is an unknown code of the component StreamMessage Data Handler. Upgrading to version 1.15.2 or 2.2.0 eliminates this vulnerability. The upgrade is hosted for download at github.com.]]></description>
<link>https://tsecurity.de/de/1426969/sicherheitsluecken/jms-client-for-rabbitmq-up-to-115121x-streammessage-data-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1426969/sicherheitsluecken/jms-client-for-rabbitmq-up-to-115121x-streammessage-data-deserialization/</guid>
<pubDate>Thu, 01 Apr 2021 09:16:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.jms_client_for_rabbitmq">JMS Client for RabbitMQ up to 1.15.1/2.1.x</a>. It has been classified as critical. Affected is an unknown code of the component <em>StreamMessage Data Handler</em>. Upgrading to version 1.15.2 or 2.2.0 eliminates this vulnerability. The upgrade is hosted for download at <a href="https://vuldb.com/?countermeasure_upgrade_url.171168">github.com</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-36282]]></title>
<description><![CDATA[JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.]]></description>
<link>https://tsecurity.de/de/1406690/sicherheitsluecken/cve-2020-36282/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1406690/sicherheitsluecken/cve-2020-36282/</guid>
<pubDate>Fri, 12 Mar 2021 06:46:26 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.]]></content:encoded>
</item>
<item>
<title><![CDATA[Horusec - An Open Source Tool That Improves Identification Of Vulnerabilities In Your Project With Just One Command]]></title>
<description><![CDATA[Horusec is an open source tool that performs static code analysis to identify security flaws during the development process. Currently, the languages for analysis are: C#, Java, Kotlin, Python, Ruby, Golang, Terraform, Javascript, Typescript, Kubernetes, PHP, C, HTML, JSON, Dart. The tool has opt...]]></description>
<link>https://tsecurity.de/de/1387255/it-security-nachrichten/horusec-an-open-source-tool-that-improves-identification-of-vulnerabilities-in-your-project-with-just-one-command/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1387255/it-security-nachrichten/horusec-an-open-source-tool-that-improves-identification-of-vulnerabilities-in-your-project-with-just-one-command/</guid>
<pubDate>Mon, 22 Feb 2021 12:00:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://1.bp.blogspot.com/-voELCsSS8gA/YC8q6lIP7BI/AAAAAAAAVZA/ipgLTUPtaCkPyXNzCrA9H3HfaU1KnxdXgCNcBGAsYHQ/s2048/horusec_5_horusec-complete-architecture.png" imageanchor="1"><img border="0" data-original-height="1152" data-original-width="2048" height="360" src="https://1.bp.blogspot.com/-voELCsSS8gA/YC8q6lIP7BI/AAAAAAAAVZA/ipgLTUPtaCkPyXNzCrA9H3HfaU1KnxdXgCNcBGAsYHQ/w640-h360/horusec_5_horusec-complete-architecture.png" width="640"></a></div><p><br></p>  <p>Horusec is an open source tool that performs <a href="https://www.kitploit.com/search/label/Static%20Code%20Analysis" target="_blank" title="static code analysis">static code analysis</a> to identify security flaws during the development process. Currently, the languages for analysis are: C#, Java, Kotlin, Python, Ruby, Golang, Terraform, Javascript, Typescript, Kubernetes, PHP, C, HTML, JSON, Dart. The tool has options to search for key leaks and security flaws in all files of your project, as well as in Git history. Horusec can be used by the developer through the CLI and by the DevSecOps team on CI /CD mats. See in our <a href="https://horusec.io/docs" rel="nofollow" target="_blank" title="DOCUMENTATION">DOCUMENTATION</a> the complete list of tools and languages that we perform analysis</p><span><a name="more"></a></span><p><br></p><span><b>Project roadmap 2021</b></span><br>  <p>We started the project to aggregate within our company, but as the search grew more and more we chose to apply good practices and open it up for everyone to collaborate with this incredible project.</p>  <p>In order to achieve our goals, we separated in some delivery phases:</p>  <ul>  <li><strong>Phase 0:</strong> Support for all horusec-cli features into <a href="https://github.com/ZupIT/horusec-vscode-plugin" rel="nofollow" target="_blank" title="horusec-vscode">horusec-vscode</a> (Q1)</li>  <li><strong>Phase 1:</strong> Support for the Theia(VsCode Web) (Q1)</li>  <li><strong>Phase 2:</strong> Support to Flutter, Dart, Bash, Shell, Elixir, Cloujure e Scala in analysis (Q1)</li>  <li><strong>Phase 3:</strong> New service to manager <a href="https://www.kitploit.com/search/label/vulnerabilities" target="_blank" title="vulnerabilities">vulnerabilities</a> founds (Q2)</li>  <li><strong>Phase 4:</strong> Dependency analysis for all supported languages (Q3)</li>  <li><strong>Phase 5:</strong> SAST with MVP Semantic Analysis (Q4)</li>  <li><strong>Phase 6:</strong> DAST with MVP symbolic analysis (Q4)</li>  </ul>  <br><span><b>Getting started</b></span><br>  <br><span><b>Installing</b></span><br>  <p>To see more details how install go to <a href="https://github.com/ZupIT/horusec/blob/master/horusec-cli#installing" rel="nofollow" target="_blank" title="HERE">HERE</a></p>  <br><b>Check the installation</b><br>  <div><pre><code>horusec version</code></pre></div>  <br><span><b>Usage</b></span><br>  <p>For use horusec-cli and check your vulnerabilities</p>  <div><pre><code>horusec start</code></pre></div>  <p>or send with the <a href="https://www.kitploit.com/search/label/Authorization" target="_blank" title="authorization">authorization</a> token to view the content analytically in the horusec admin panel.</p>  <div><pre><code>horusec start -a="&lt;YOUR_TOKEN_AUTHORIZATION&gt;"</code></pre></div>  <p>To acquire the authorization token and you can see your vulnerabilities analytically on our panel see more details <a href="https://github.com/ZupIT/horusec/blob/master/horusec-cli#authorization" rel="nofollow" target="_blank" title="HERE">HERE</a></p>  <p><strong>WARN:</strong> When horusec starts an analysis it creates a folder called <code>.horusec</code>. This folder serves as the basis for not changing your code. So we recommend that you add the line <code>.horusec</code> into your <code>.gitignore</code> file so that this folder does not need to be sent to your git server!</p>  <p align="center"><br></p><div class="separator"><a href="https://1.bp.blogspot.com/--b4_PYO_Y_Y/YC8rFfrw9UI/AAAAAAAAVZE/LVph1Rxv0CQz8w8YAYGfKuFgyMqSCn2RQCNcBGAsYHQ/s1918/horusec_6_usage_horusec.gif" imageanchor="1"><img border="0" data-original-height="908" data-original-width="1918" height="302" src="https://1.bp.blogspot.com/--b4_PYO_Y_Y/YC8rFfrw9UI/AAAAAAAAVZE/LVph1Rxv0CQz8w8YAYGfKuFgyMqSCn2RQCNcBGAsYHQ/w640-h302/horusec_6_usage_horusec.gif" width="640"></a></div><p align="center"><br></p><span><b>Requirements for usage horusec-cli</b></span><br>  <ul>  <li>docker</li>  <li>git(Mandatory if you are using search throughout the project's git history)</li>  </ul>  <br><span><b>Usage locally</b></span><br>  <p>For usage the horusec locally clone horusec in your local machine and run</p>  <div><pre><code>make install</code></pre></div>  <p>and run the <a href="https://github.com/ZupIT/horusec/blob/master/horusec-cli#horusec-cli" rel="nofollow" target="_blank" title="HORUSEC-CLI">HORUSEC-CLI</a> to start the analysis</p>  <br><span><b>Default Development account</b></span><br>  <p>For usage complete feature of the horusec you can see enter using this default user generated by horusec for you usage.</p>  <p><strong>WARN:</strong> We do dns validation for account creation, so remember to use a valid email. For tests accounts we accept <a href="mailto:...@example.com" rel="nofollow" target="_blank" title="...@example.com">...@example.com</a> as a valid dns.</p>  <pre><code>  email: dev@example.com<br>  password: Devpass0*<br></code></pre>  <br><span><b>Requirements for use complete horusec locally</b></span><br>  <ul>  <li>docker</li>  <li>git</li>  <li>docker-compose/helm</li>  <li>golang</li>  <li>rabbitmq</li>  <li>postgres</li>  <li>account-of-email (optional)</li>  </ul>  <br><span><b>Horusec manager</b></span><br>  <ul>  <li>Separate <a href="https://www.kitploit.com/search/label/Repositories" target="_blank" title="repositories">repositories</a> by companies</li>  <li>Manage users who have access to your company (users must be pre-registered on horusec to be invited to a pre-existing company)</li>  <li>Manage the repositories available in your company for analysis</li>  <li>Manage users who have access to company repositories</li>  <li>Manage your access tokens for the specific repository (required to identify which repository this analysis belongs to and save to our system)</li>  <li>Visually view all existing vulnerabilities in your company and/or its repository</li>  </ul>  <br><span><b>Contributing</b></span><br>  <p>Read our <a href="https://github.com/ZupIT/horusec/blob/master/CONTRIBUTING.md" rel="nofollow" target="_blank" title="contributing guide">contributing guide</a> to learn about our development process, how to propose bugfixes and improvements, and how to build and test your changes to horusec.</p>  <br><span><b>Communication</b></span><br>  <p>We have a few channels for contact, feel free to reach out to us at:</p>  <ul>  <li><a href="https://github.com/ZupIT/horusec/issues" rel="nofollow" target="_blank" title="GitHub Issues">GitHub Issues</a></li></ul><div></div>  <br><div><b><span><a class="kiploit-download" href="https://github.com/ZupIT/horusec" rel="nofollow" target="_blank" title="Download Horusec">Download Horusec</a></span></b></div><img src="http://feeds.feedburner.com/~r/PentestTools/~4/2iOj-hDCy7U" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[PatrowlHears - PatrowlHears - Vulnerability Intelligence Center / Exploits]]></title>
<description><![CDATA[PatrOwl provides scalable, free and open-source solutions for orchestrating Security Operations and providing Threat Intelligence feeds. PatrowlHears is an advanced and real-time Vulnerability Intelligence platform, including CVE, exploits and threats news.Try it now!  To try PatrowlHears, instal...]]></description>
<link>https://tsecurity.de/de/1376824/it-security-nachrichten/patrowlhears-patrowlhears-vulnerability-intelligence-center-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1376824/it-security-nachrichten/patrowlhears-patrowlhears-vulnerability-intelligence-center-exploits/</guid>
<pubDate>Thu, 11 Feb 2021 12:15:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://1.bp.blogspot.com/-J5K1qCE7Fbg/YBonyeqp_5I/AAAAAAAAVQ0/SCEDJL77FC0Z5AREDMzYS1pCVUgY8IDCACNcBGAsYHQ/s426/PatrowlHears_1_logo-patrowl-light.png" imageanchor="1"><img border="0" data-original-height="95" data-original-width="426" src="https://1.bp.blogspot.com/-J5K1qCE7Fbg/YBonyeqp_5I/AAAAAAAAVQ0/SCEDJL77FC0Z5AREDMzYS1pCVUgY8IDCACNcBGAsYHQ/s16000/PatrowlHears_1_logo-patrowl-light.png"></a></div><p><br></p>  <p><a href="https://www.patrowl.io/" rel="nofollow" target="_blank" title="PatrOwl">PatrOwl</a> provides scalable, free and open-source solutions for orchestrating Security Operations and providing <a href="https://www.kitploit.com/search/label/Threat%20Intelligence" target="_blank" title="Threat Intelligence">Threat Intelligence</a> feeds. <strong>PatrowlHears</strong> is an advanced and real-time <a href="https://www.kitploit.com/search/label/Vulnerability" target="_blank" title="Vulnerability">Vulnerability</a> <a href="https://www.kitploit.com/search/label/Intelligence" target="_blank" title="Intelligence">Intelligence</a> platform, including CVE, exploits and threats news.</p><span><a name="more"></a></span><p><br></p><span><b>Try it now!</b></span><br>  <p>To try PatrowlHears, install it by reading the <a href="https://github.com/Patrowl/PatrowlHears/blob/master/INSTALL.md" rel="nofollow" target="_blank" title="Installation Guide">Installation Guide</a>.</p>  <br><span><b>Architecture</b></span><br>  <p>Fully-Developed in Python, PatrowlHears is composed of a backend application using the awesome Django framework and a frontend based on Vue.js + Vuetify. Asynchronous tasks and engine scalability are supported by RabbitMQ and Celery.  PatrowlHears features and data are reachable using the embedded WEB interface or using the REST-API.</p>  <br><span><b>Side projects</b></span><br>  <ul>  <li><a href="https://github.com/Patrowl/PatrowlHearsData" rel="nofollow" target="_blank" title="PatrowlHearsData">PatrowlHearsData</a>: Contains data-scrapper scripts collecting CVE, CPE, CWE and exploit references (cf. CVE-SEARCH project) + raw data as JSON files</li>  <li><a href="https://github.com/Patrowl/PatrowlHears4py" rel="nofollow" target="_blank" title="PatrowlHears4py">PatrowlHears4py</a>: Python CLI and library for PatrowlHears API.</li>  </ul>  <br><span><b>License</b></span><br>  <p>PatrowlHears is an open source and free software released under the <a href="https://github.com/Patrowl/PatrowlHears/blob/master/LICENSE" rel="nofollow" target="_blank" title="AGPL">AGPL</a> (Affero General Public License). We are committed to ensure that PatrowlHears will remain a free and open source project on the long-run.</p>  <br><span><b>Updates</b></span><br>  <p>Information, news and updates are regularly posted on <a href="https://twitter.com/patrowl_io" rel="nofollow" target="_blank" title="Patrowl.io Twitter account">Patrowl.io Twitter account</a>.</p>  <br><span><b>Contributing</b></span><br>  <p>Please see our <a href="https://github.com/Patrowl/PatrowlDocs/blob/master/support/code_of_conduct.md" rel="nofollow" target="_blank" title="Code of conduct">Code of conduct</a>. We welcome your contributions. Please feel free to fork the code, play with it, make some patches and send us pull requests via <a href="https://github.com/Patrowl/PatrowlHears/issues" rel="nofollow" target="_blank" title="issues">issues</a>.</p>  <br><span><b>Roadmap</b></span><br>  <p>TBD</p>  <br><span><b>Support</b></span><br>  <p>Please <a href="https://github.com/Patrowl/PatrowlHears/issues" rel="nofollow" target="_blank" title="open an issue on GitHub">open an issue on GitHub</a> if you'd like to report a bug or request a feature. We are also available on <a href="https://gitter.im/PatrowlHears/Support" rel="nofollow" target="_blank" title="Gitter">Gitter</a> to help you out.</p>  <p>If you need to contact the project team, send an email to <a href="mailto:getsupport@patrowl.io" rel="nofollow" target="_blank" title="getsupport@patrowl.io">getsupport@patrowl.io</a>.</p>  <br><span><b>Pro Edition available in SaaS and on-premise</b></span><br>  <p>A commercial Pro Edition is available and officially supported by the PatrOwl company. It includes following extra and awesome engines:</p>  <ul class="contains-task-list">  <li class="task-list-item">PatrOwl CSIRT feeds, managed by qualified Cyber-Threat Intelligence analysts</li>  <li class="task-list-item">Terraform+Ansible deployment scripts</li>  <li class="task-list-item">Official Pro Support</li>  <li class="task-list-item">3rd party authentication: Azure Active Directory, ADFS (Windows 2012 and 2016), LDAP (WIP)</li>  <li class="task-list-item">Ticketing system integration, including JIRA, ServiceNow, ZenDesk and GLPI (WIP)</li>  </ul>  <p><strong>PatrowlHears</strong> is available on the official PatrOwl SaaS platform or on-premise.  See: <a href="https://patrowl.io/products/hears" rel="nofollow" target="_blank" title="https://patrowl.io/products/hears">https://patrowl.io/products/hears</a></p>  <br><span><b>Commercial Services</b></span><br>  <p>Looking for advanced support, training, integration, custom developments, dual-licensing ? Contact us at <a href="mailto:getsupport@patrowl.io" rel="nofollow" target="_blank" title="getsupport@patrowl.io">getsupport@patrowl.io</a></p>  <br><span><b>Security contact</b></span><br>  <p>Please disclose any security-related issues or <a href="https://www.kitploit.com/search/label/vulnerabilities" target="_blank" title="vulnerabilities">vulnerabilities</a> by emailing <a href="mailto:security@patrowl.io" rel="nofollow" target="_blank" title="security@patrowl.io">security@patrowl.io</a>, instead of using the public issue tracker.</p>  <br><span><b>Copyright</b></span><br>  <p>Copyright (C) 2020-2021 Nicolas MATTIOCCO (<a href="https://twitter.com/MaKyOtOx" rel="nofollow" target="_blank" title="@MaKyOtOx">@MaKyOtOx</a> - <a href="mailto:nicolas@patrowl.io" rel="nofollow" target="_blank" title="nicolas@patrowl.io">nicolas@patrowl.io</a>)</p>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/Patrowl/PatrowlHears" rel="nofollow" target="_blank" title="Download PatrowlHears">Download PatrowlHears</a></span></b></div><img src="http://feeds.feedburner.com/~r/PentestTools/~4/0q8oyKkqxNs" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[Solarflare - SolarWinds Orion Account Audit / Password Dumping Utility]]></title>
<description><![CDATA[Credential Dumping Tool for SolarWinds Orion  Blog post: https://malicious.link/post/2020/solarflare-release-password-dumper-for-solarwinds-orion/Credit to @asolino, @gentilkiwi, and @skelsec  for helping me figuring out DPAPI.  ============================================| Collecting RabbitMQ Er...]]></description>
<link>https://tsecurity.de/de/1346613/it-security-nachrichten/solarflare-solarwinds-orion-account-audit-password-dumping-utility/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1346613/it-security-nachrichten/solarflare-solarwinds-orion-account-audit-password-dumping-utility/</guid>
<pubDate>Fri, 08 Jan 2021 21:32:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://1.bp.blogspot.com/-653YqjE-s8Q/X_fjeb7nHPI/AAAAAAAAU5g/YPuEgZBf_2EowuPzPVijA-3dzt9ViD99ACNcBGAsYHQ/s1153/solarflare.png" imageanchor="1"><img border="0" data-original-height="544" data-original-width="1153" height="302" src="https://1.bp.blogspot.com/-653YqjE-s8Q/X_fjeb7nHPI/AAAAAAAAU5g/YPuEgZBf_2EowuPzPVijA-3dzt9ViD99ACNcBGAsYHQ/w640-h302/solarflare.png" width="640"></a></div><p><br></p>  <p>Credential Dumping Tool for SolarWinds Orion</p>  <p>Blog post: <a href="https://malicious.link/post/2020/solarflare-release-password-dumper-for-solarwinds-orion/" rel="nofollow" target="_blank" title="https://malicious.link/post/2020/solarflare-release-password-dumper-for-solarwinds-orion/">https://malicious.link/post/2020/solarflare-release-password-dumper-for-solarwinds-orion/</a></p><span><a name="more"></a></span><p><br></p><p>Credit to <a href="https://github.com/asolino" rel="nofollow" target="_blank" title="@asolino">@asolino</a>, <a href="https://github.com/gentilkiwi" rel="nofollow" target="_blank" title="@gentilkiwi">@gentilkiwi</a>, and <a href="https://github.com/skelsec" rel="nofollow" target="_blank" title="@skelsec">@skelsec</a>  for helping me figuring out DPAPI.</p>  <pre><code>============================================<br>| Collecting RabbitMQ Erlang Cookie<br>|       Erlang Cookie: abcdefg12456789abcde<br>============================================<br>| Collecting SolarWinds Certificate<br>|       SolarWinds Orion Certificate Found!<br>|       Subject Name: CN=SolarWinds-Orion<br>|       Thumbprint  : BE85C6C3AACA8840E166187B6AB8C6BA9DA8DE80<br>|       Password    : alcvabkajp4<br>|       Private Key : MIIKHwIBAzCCCd8GCSqGSIb3DQEHAaCCCdAEggn&lt;snip&gt;<br>============================================<br>| Collecting Default.DAT file<br>|       Encrypted: 01000000D08C9DDF0115D&lt;snip&gt;<br>|       Decrypted: 5D3CE5B08C9201E636BCF&lt;snip&gt;<br>============================================<br>| Collecting Database Credentials          |<br>|       Path to SWNetPerfMon.DB is: C:\Program Files (x86)\SolarWinds\Orion\SWNetPerfMon.DB<br>|       Connection String: Server=(local)\SOLARWINDS_ORION;Database=SolarWindsOrion;User ID=SolarWindsOrionDatabaseUser;Password=SUPERSECRETPASSWORDHERE<br>|       Number of database credentials found: 1<br>============================================<br>| Connecting to the Database              |<br>|       Successfully connected to: Server=(local)\SOLARWINDS_ORION;Database=SolarWindsOrion;User ID=SolarWindsOrionDatabaseUser;MultipleActiveResultSets=true<br>============================================<br>| DB - Exporting Key Table                 |<br>|       KeyID: 1<br>|       Encrypted Key: LmjknGhSXTC&lt;snip&gt;<br>|       Kind: Aes256<br>|       Purpose: master<br>|       Protection Type: 1<br>|       Protection Value: BE85C6C3AACA8&lt;snip&gt;<br>|       Protection Detai   ls: {}<br>------------------------------------------------<br>|       KeyID: 2<br>|       Encrypted Key: //pj6a4FaCyfv/Rgs&lt;snip&gt;<br>|       Kind: Aes256<br>|       Purpose: oldcryptohelper<br>|       Protection Type: 0<br>|       Protection Value: 1<br>|       Protection Details: {"IV":"oj3JCT7Cft&lt;snip&gt;"}<br>============================================<br>| DB - Exporting Accounts Table            |<br>|        Account: _system<br>|        Password Hash: qE9ClH&lt;snip&gt;<br>|        Password Salt: XgtO8XNWc/KiIdglGOnxvw==<br>|        Hashcat Mode 12501: $solarwinds$1$XgtO8XNWc/KiIdglGOnxvw==$qE9ClHDI&lt;snip&gt;<br>|        Account Enabled: Y<br>|        Allow Admin: Y<br>|        Last Login: 12/15/2020<br>--------------------------------------------<br>|        Account: Admin<br>|        Password Hash: IfAEwA7LXxOAH7ORCG0ZYeq&lt;snip&gt;<br>|        Passwor   d Salt: jNhn3i2XtHfY8y4EOmNdiQ==<br>|        Hashcat Mode 12501: $solarwinds$1$jNhn3i2XtHfY8y4EOmNdiQ==$IfAEwA7LXxOAH7ORCG0ZY&lt;snip&gt;<br>|        Account Enabled: Y<br>|        Allow Admin: Y<br>|        Last Login: 12/02/2020<br>--------------------------------------------<br>|        Account: Guest<br>|        Password Hash: Y/EMuOWMNfCd&lt;snip&gt;<br>|        Salt is NULL in DB so lowercase username is used: guest<br>|        Hashcat Mode 12500: $solarwinds$0$guest$Y/EMuOWMNfCd&lt;snip&gt;<br>|        Account Enabled: N<br>|        Allow Admin: N<br>|        Last Login: 12/30/1899<br>--------------------------------------------<br>|        Account: iprequest<br>|        Password Hash: 7zskGWFukuHuwQ&lt;snip&gt;<br>|        Salt is NULL in DB so lowercase username is used: iprequest<br>|        Hashcat Mode 12500: $solarwinds$0$iprequest$7zskGWFukuHuwQ&lt;snip&gt;<br>|        Account Enabled: Y<br>|        Allow Admin: N<br>|        Last Login: 01/01/1900&lt;   br/&gt;--------------------------------------------<br>|        Account: SITTINGDUCK\uberolduser<br>|        Password: 11-417578424799297-9-6260697430795685763067724<br>|        Decoded Password: ASDQWE123<br>|        Hashcat Mode 21500: $solarwinds$0$admin$fF1lrlOXfxVz51Etjcs18XNK+Zt3keV2AllH9cYtGzdt5Yg2TtcsU84G9+5VVFMIUorR5eNJzX/1kmef6wZfrg==<br>|        Account Enabled: Y<br>|        Allow Admin: N<br>|        Last Login: 11/15/2015<br>|        Account SID: S-1-5-21-1000000000-2000000000-3000000000-50000<br>|        Group: SITTINGDUCK\Domain Admins<br>--------------------------------------------<br>============================================<br>| DB - Exporting Credentials Table         |<br>------------------1--------------------------<br>| Type: SolarWinds.Orion.Core.SharedCredentials.Credentials.UsernamePasswordCredential<br>| Name: _system<br>|       Desc: Cortex Integration<br>|       Owner: CORE<br>|               Password: 9dM-5pH/&amp;amp;Y(KU-v<br>|                  Username: _system<br>------------------1--------------------------<br>------------------2--------------------------<br>| Type: SolarWinds.Orion.Core.SharedCredentials.Credentials.UsernamePasswordCredential<br>| Name: JobEngine<br>|       Desc: Job Engine router TCP endpoint credentials<br>|       Owner: JobEngine<br>|               Password: +fBByxJFsK+da6ZN2wKvLTKC/PWUzFlfIvvwtW/XqvA=<br>|               Username: KWPPhiYJmE8+fRF6qlkxulK2tf3t79TQOAk1ywBMVOI=<br>------------------2--------------------------<br>------------------3--------------------------<br>| Type: SolarWinds.Orion.Core.Models.Credentials.SnmpCredentialsV2<br>| Name: public<br>|       Desc:<br>|       Owner: Orion<br>|               Community: public<br>------------------3--------------------------<br>------------------4--------------------------<br>| Type: SolarWinds.Orion.Core.Models.Credentials.Sn   mpCredentialsV2<br>| Name: private<br>|       Desc:<br>|       Owner: Orion<br>|               Community: private<br>------------------4--------------------------<br>------------------5--------------------------<br>| Type: SolarWinds.Orion.Core.SharedCredentials.Credentials.UsernamePasswordCredential<br>| Name: Erlang cookie<br>|       Desc: Erlang clustering cookie<br>|       Owner: Erlang<br>|               Password: abcdefg12456789abcde<br>|               Username: ignored<br>------------------5--------------------------<br>------------------6--------------------------<br>| Type: SolarWinds.Orion.Core.SharedCredentials.Credentials.UsernamePasswordCredential<br>| Name: RabbitMQ user account<br>|       Desc: RabbitMQ user account for Message Bus<br>|       Owner: RabbitMQ<br>|               Password: LtVmCrzlTNyWmwxpxJMi<br>|               Username: orion<br>------------------6--------------------------<br>------------------7--------------------------<br>| Ty   pe: SolarWinds.Orion.Core.Models.Credentials.SnmpCredentialsV3<br>| Name: User: snmpv3user, Context: thisisthecontext<br>|       Desc:<br>|       Owner: Orion<br>|               AuthenticationKeyIsPassword: false<br>|               AuthenticationPassword: ASDqwe123<br>|               AuthenticationType: SHA1<br>|               Context: thisisthecontext<br>|               PrivacyKeyIsPassword: false<br>|               PrivacyPassword: ASDqwe123<br>|               PrivacyType: AES256<br>|               UserName: snmpv3user<br>------------------7--------------------------<br>------------------8--------------------------<br>| Type: SolarWinds.Orion.Core.Models.Credentials.SnmpCredentialsV3<br>| Name: User: rootsnmpv3, Context: newcontextv3<br>|       Desc:<br>|       Owner: Orion<br>|               AuthenticationKeyIsPassword: true<br>|               AuthenticationPassword: ASDqwe123<br>|               AuthenticationType: MD5<br>|               Context: newcontextv3   <br>|               PrivacyKeyIsPassword: true<br>|               PrivacyPassword: ASDqwe123<br>|               PrivacyType: AES128<br>|               UserName: rootsnmpv3<br>------------------8--------------------------<br>------------------9--------------------------<br>| Type: SolarWinds.Orion.Core.SharedCredentials.Credentials.UsernamePasswordCredential<br>| Name: DomainAdmin<br>|       Desc:<br>|       Owner: Orion<br>|               Password: ASDqwe123<br>|               Username: SITTINGDUCK\uberuser<br>------------------9--------------------------<br>------------------10--------------------------<br>| Type: SolarWinds.Orion.Core.SharedCredentials.Credentials.UsernamePasswordCredential<br>| Name: DomainJoiner<br>|       Desc:<br>|       Owner: Orion<br>|               Password: ASDqwe123<br>|               Username: superadmin@sittingduck.info<br>------------------10--------------------------<br>------------------11--------------------------<br>| Type:    SolarWinds.Orion.Core.SharedCredentials.Credentials.UsernamePasswordCredential<br>| Name: vesxi<br>|       Desc: vesxi<br>|       Owner: VIM<br>|               Password: ASDqwe123<br>|               Username: root<br>------------------11--------------------------<br>------------------12--------------------------<br>| Type: SolarWinds.Orion.Core.SharedCredentials.Credentials.ActiveDirectoryCredential<br>| Name: SITTINGDUCK\uberuser<br>| 	Desc: <br>| 	Owner: Orion<br>| 		Password: ASDqwe213<br>| 		Username: SITTINGDUCK\uberuser<br>------------------12--------------------------<br>------------------13--------------------------<br>| Type: SolarWinds.APM.Common.Credentials.ApmUsernamePasswordCredential<br>| Name: App Monitoring User<br>| 	Desc: <br>| 	Owner: APM<br>| 		Password: ASDqwe123<br>| 		Username: SITTINGDUCK\uberuser<br>------------------13--------------------------<br>------------------14--------------------------<br>| Type: SolarWinds.SRM.Common.Credent   ials.SmisCredentials<br>| Name: EMC_SMIS_Solarwinds<br>| 	Desc: <br>| 	Owner: SRM<br>| 		HttpPort: 5988<br>| 		HttpsPort: 5989<br>| 		InteropNamespace: /interop<br>| 		Namespace: root/emc<br>| 		Password: ASDqwe123<br>| 		Username: solarwinds<br>| 		UseSSL: true<br>------------------14--------------------------<br>------------------15--------------------------<br>| Type: SolarWinds.ESI.Common.Connection.ExternalSystemCredential<br>| Name: ESC<br>| 	Desc: <br>| 	Owner: ESI<br>| 		Password: ASDqwe123<br>| 		Username: solar_winds<br>------------------15--------------------------<br>------------------16--------------------------<br>| Type: SolarWinds.Orion.Web.Integration.OAuth2Token<br>| Name: SITTINGDUCK\uberuser<br>| 	Desc: <br>| 	Owner: Web.Integration<br>| 		AccessToken: GthQHd3&lt;snip&gt;<br>| 		AccessTokenExpiration: 2020-11-01T10:52:50.2768075Z<br>| 		AccessTokenIssueDate: 2020-11-01T09:52:51.2768075Z<br>| 		RefreshToken:hEyph9WqIfzm&lt;snip&gt;<br>   | 		Scopes: <br>| 		Username: uberuser@sittingduck.info<br>------------------16--------------------------<br>------------------17--------------------------<br>| Type: SolarWinds.SRM.Common.Credentials.XtremIoHttpCredential<br>| Name: XtremIO_Admin<br>| 	Desc: <br>| 	Owner: SRM<br>| 		HttpPort: 80<br>| 		HttpsPort: 443<br>| 		Password: ASDqwe123<br>| 		Username: admin<br>| 		UseSsl: true<br>------------------18--------------------------<br>============================================<br>============================================<br></code></pre>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/mubix/solarflare" rel="nofollow" target="_blank" title="Download Solarflare">Download Solarflare</a></span></b></div><img src="http://feeds.feedburner.com/~r/PentestTools/~4/I2erzARfPEE" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-35196]]></title>
<description><![CDATA[The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank passw...]]></description>
<link>https://tsecurity.de/de/1330669/sicherheitsluecken/cve-2020-35196/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1330669/sicherheitsluecken/cve-2020-35196/</guid>
<pubDate>Thu, 17 Dec 2020 07:18:02 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.]]></content:encoded>
</item>
<item>
<title><![CDATA[RabbitMQ up to 3.8.6 Security Vulnerability uncontrolled search path]]></title>
<description><![CDATA[A vulnerability was found in RabbitMQ up to 3.8.6. It has been classified as critical. This affects an unknown part of the component Security Vulnerability. Upgrading eliminates this vulnerability.]]></description>
<link>https://tsecurity.de/de/1294435/sicherheitsluecken/rabbitmq-up-to-386-security-vulnerability-uncontrolled-search-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1294435/sicherheitsluecken/rabbitmq-up-to-386-security-vulnerability-uncontrolled-search-path/</guid>
<pubDate>Thu, 12 Nov 2020 07:51:11 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.rabbitmq">RabbitMQ up to 3.8.6</a>. It has been classified as critical. This affects an unknown part of the component <em>Security Vulnerability</em>. Upgrading eliminates this vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[AutoGadgetFS - USB Testing Made Easy]]></title>
<description><![CDATA[What’s AutoGadgetFS ?  AutoGadgetFS is an open source framework that allows users to assess USB devices and their associated hosts/drivers/software without an in-depth knowledge of the USB protocol. The tool is written in Python3 and utilizes RabbitMQ and WiFi access to enable researchers to cond...]]></description>
<link>https://tsecurity.de/de/1275478/it-security-nachrichten/autogadgetfs-usb-testing-made-easy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1275478/it-security-nachrichten/autogadgetfs-usb-testing-made-easy/</guid>
<pubDate>Sat, 24 Oct 2020 14:16:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://1.bp.blogspot.com/-f3ikMBP2ZVU/X5JbGWHSg2I/AAAAAAAAUH8/8lYdeZ-JEZczBQIUBnNYZ_1MRW64LpmAwCNcBGAsYHQ/s388/AutoGadgetFS_1_agfslogos.png" imageanchor="1"><img border="0" data-original-height="388" data-original-width="383" src="https://1.bp.blogspot.com/-f3ikMBP2ZVU/X5JbGWHSg2I/AAAAAAAAUH8/8lYdeZ-JEZczBQIUBnNYZ_1MRW64LpmAwCNcBGAsYHQ/s16000/AutoGadgetFS_1_agfslogos.png"></a></div><p><br></p><span><b>What’s AutoGadgetFS ?</b></span><br>  <p>AutoGadgetFS is an open source framework that allows users to assess USB devices and their associated hosts/drivers/software without an in-depth knowledge of the USB protocol. The tool is written in Python3 and utilizes RabbitMQ and WiFi access to enable researchers to conduct remote USB security assessments from anywhere around the globe. By leveraging ConfigFS, AutoGadgetFS allows users to clone and emulate devices quickly, eliminating the need to dig deep into the details of each implementation. The framework also allows users to create their own fuzzers on top of it.</p><div><span><a name="more"></a></span></div><br><span><b>Requirments:</b></span><br>  <ul><a name="user-content-requirments" target="_blank" title="">  </a><li><a name="user-content-requirments" target="_blank" title=""></a><div><a name="user-content-requirments" target="_blank" title="">Host machine running Linux (Debian/Ubuntu/Kali)</a></div></li><li><a name="user-content-requirments" target="_blank" title=""></a><div><a name="user-content-requirments" target="_blank" title=""></a><a href="https://www.kitploit.com/search/label/Raspberry%20Pi" target="_blank" title="Raspberry Pi">Raspberry Pi</a> Zero with WIFI support</div></li>  <li><div>Target machine options:</div><ul>  <li>Virtual Machine</li>  <li>Standalone machine</li>  </ul>  </li>  <li><div>2 x USB micro cables</div></li>  <li><div>Target USB device</div></li>  <li><div>Hardware debugger ( Optional )</div></li>  </ul>  <br><span><b>The Setup:</b></span><br>    <div><pre><code>Device testing only:</code></pre></div>  <div><br></div><div class="separator"><a href="https://1.bp.blogspot.com/-C2VbZprOgIc/X5JbR4PTN2I/AAAAAAAAUIA/JyS7_zbmn2s9C3BddqwIn_QcZAZuNuNzgCNcBGAsYHQ/s796/AutoGadgetFS_3_devtest.jpeg" imageanchor="1"><img border="0" data-original-height="345" data-original-width="796" height="277" src="https://1.bp.blogspot.com/-C2VbZprOgIc/X5JbR4PTN2I/AAAAAAAAUIA/JyS7_zbmn2s9C3BddqwIn_QcZAZuNuNzgCNcBGAsYHQ/w640-h277/AutoGadgetFS_3_devtest.jpeg" width="640"></a></div><div><br></div>    <div><pre><code>Minimal agfs in the middle setup:</code></pre></div>  <div><br></div><div class="separator"><a href="https://1.bp.blogspot.com/-Agk8JewBbD4/X5JbaS3Mb7I/AAAAAAAAUII/zWn6S2dE1e8LQZWQhSZ475fkBSwdSowuQCNcBGAsYHQ/s1031/AutoGadgetFS_4_scenario1.jpeg" imageanchor="1"><img border="0" data-original-height="351" data-original-width="1031" height="218" src="https://1.bp.blogspot.com/-Agk8JewBbD4/X5JbaS3Mb7I/AAAAAAAAUII/zWn6S2dE1e8LQZWQhSZ475fkBSwdSowuQCNcBGAsYHQ/w640-h218/AutoGadgetFS_4_scenario1.jpeg" width="640"></a></div><div><br></div>    <div><pre><code>Complete agfs in the middle setup with debugging support:</code></pre></div>  <div><br></div><div class="separator"><a href="https://1.bp.blogspot.com/-UYyQIyXGXCA/X5JbimanpEI/AAAAAAAAUIQ/yXH1qaMrgJA9u7Jyk8M_WBnlcRtF5-ITACNcBGAsYHQ/s1280/AutoGadgetFS_5_scenario2.jpeg" imageanchor="1"><img border="0" data-original-height="228" data-original-width="1280" height="114" src="https://1.bp.blogspot.com/-UYyQIyXGXCA/X5JbimanpEI/AAAAAAAAUIQ/yXH1qaMrgJA9u7Jyk8M_WBnlcRtF5-ITACNcBGAsYHQ/w640-h114/AutoGadgetFS_5_scenario2.jpeg" width="640"></a></div><div><br></div><a name="user-content-usbdev" target="_blank" title=""><span><b>USB Device class support:</b></span><br>  <p>USB HID Devices fully supported (Man in the middle)</p><p>Device only testing .. All USB devices (NO Man in the middle)</p><p>Future releases... All USB devices (Man in the middle)</p></a><br><span><b>Capabilities:</b></span><br>  <ol><a name="user-content-caps" target="_blank" title="">  <li>Find, Select and Attach to a USB device with ease.</li>  <li>Emulate any USB HID device .</li>  <li>Perform AGFS in the middle sniffing for HID devices ( save communication to disk ).</li>  <li>Device sniffing ( Any device ).</li>  <li>Multiple Fuzzers allow you to Fuzz a device or a host.</li>  <li>Random fuzzers ( with fixed or random length packets ).</li>  <li>Smart Fuzzers that learn from previous USB communications.</li>  <li>Describe Fuzzer to tell the Fuzzer which bytes to Fuzz leaving the rest of the packet the same.</li>  <li>Gadget Fuzzer.</li>  <li>Sequential Fuzzer.</li>  <li>Control transfer Enumerator.</li>  <li>Replay of packets from a file.</li>  <li>Replay of packets from a saved USBLyzer capture.</li>  </a><li><a name="user-content-caps" target="_blank" title="">Visual way of presenting packets to allow ease of </a><a href="https://www.kitploit.com/search/label/Reverse%20Engineering" target="_blank" title="reverse engineering">reverse engineering</a> of the communication.</li>  <li>Alerts for device in DFU mode, or if the device leaks information.</li>  <li>USB device and host can be anywhere on the internet.</li>  <li>Monitor sudden interface changes.</li>  </ol>  <a name="user-content-road" target="_blank" title=""><br><span><b>RoadMap:</b></span><br>  <ol>  <li>Sniff control transfer requests to a device and reply to them.</li>  <li>MITM and emulate all types of devices.</li>  <li>Console/QT based interface.</li>  <li>More Interfaces/endpoints support on the RPI zero W.</li>  <li>Support more boards like the greatfet.</li>  <li>Move to a custom board.</li>  <li>Work on making raspberry pi have full support for usb device emulation with all interfaces.</li>  <li>correlate sent and received packets via sequence numbers.</li>  </ol>  </a><a name="user-content-installation" target="_blank" title=""><br><span><b><span>Installation</span><span>:</span></b></span><br>  </a><a name="user-content-linux" target="_blank" title="">  <br><span><b>Linux Machine:</b></span><br>  </a><ul><a name="user-content-linux" target="_blank" title="">  <li>  <p>Note: WSL/WSL2 is not supported due to issues with USB pass-through.</p>  </li>  <li>  <p>Install Python3, ipython3 ,git, pip and rabbitMQ server</p>  <div><pre><code>sudo apt install python3 ipython3 git python3-pip rabbitmq-server dfu-util<br>sudo service rabbitmq-server start</code></pre></div>  </li>  <li>  <p>Clone the repository</p>  <div><pre><code>git clone https://github.com/ehabhussein/AutoGadgetFS<br>cd AutoGadgetFS</code></pre></div>  </li>  <li>  <p>Install the requirements</p>  <div><pre><code>sudo -H pip3 install -r requirements.txt</code></pre></div>  </li>  <li>  <p>Downgrade prompt toolkit for better ipython experience:</p>  <div><pre><code>sudo python3 -m pip install prompt-toolkit~=2.0</code></pre></div>  </li>  <li>  <p>Enable the web interface for rabbitMQ</p>  <div><pre><code>sudo rabbitmq-plugins enable rabbitmq_management<br>http://localhost:15672/ to reach the web interface</code></pre></div>  </li>  </a><li><a name="user-content-linux" target="_blank" title="">  </a><p><a name="user-content-linux" target="_blank" title="">login to the web interface with the </a><a href="https://www.kitploit.com/search/label/Credentials" target="_blank" title="credentials">credentials</a> <em>guest:guest</em></p>  <ul>  <li>  <p>NOTE: if you are not installing rabbitMQ on <code>localhost</code> add the following user and login with it:</p>  <div><pre><code>sudo rabbitmqctl add_user autogfs usb4ever<br>sudo rabbitmqctl set_user_tags autogfs administrator</code></pre></div>  </li>  <li>  <p>Upload the rabbitMQ configuration file</p>  <ul>  <li>In the overview tab scroll to the bottom to import definitions</li>  <li>Upload the file found in: <em>rabbitMQbrokerconfig/rabbitmq-Config.json</em></li>  </ul>  <div><pre><code>sudo service rabbitmq-server restart</code></pre></div>  </li>  </ul>  </li>  <li>  <p>Test the installation</p>  <div><pre><code>sudo ipython3<br><br>Python 3.7.7 (default, Apr  1 2020, 13:48:52)<br>Type 'copyright', 'credits' or 'license' for more information<br>IPython 7.9.0 -- An enhanced Interactive Python. Type '?' for help.<br><br>In [1]: import libagfs<br><br>In [2]: x = libagfs.agfs()<br><br>***************************************<br>AutoGadgetFS: USB testing made easy<br>***************************************<br>Enter IP address of the rabbitmq server: 127.0.0.1<br><br>In [3]: exit<br><br>sudo `python3` agfsconsole.py<br><br>***************************************<br>AutoGadgetFS: USB testing made easy<br>***************************************<br>Enter IP address of the rabbitmq server: 127.0.0.1<br>Give your project a name?!:</code></pre></div>  </li>  <li>  <p>Patch Pyusb langID ( Not needed unless you get pyusb errors for langID ):</p>  <ul>  <li>Edit the file <code>/usr/local/lib/python3/dist-packages/usb/util.py</code>  <ul>  <li>  <p>make changes to the <code>def get_string</code> method to look like below:</p>  <div><pre><code>if 0 == len(langids):<br>    return "Error Reading langID"<br>    #raise ValueError("The device has no langid")<br>if langid is None:<br>    langid = langids[0]<br>elif langid not in langids:<br>    return "Error Reading langID"<br>    #raise ValueError("The device does not support the specified langid")</code></pre></div>  </li>  <li>  <p>If you prefer to use <code>patch</code> apply the following patch to the file: <code>AutoGadgetFS/pyusb_patches/pyusb_langid.patch</code></p>  </li>  </ul>  </li>  </ul>  </li>  </ul>  <a name="user-content-rasp" target="_blank" title=""><br><span><b>Raspberry Pi Zero W:</b></span><br>  </a><ul><a name="user-content-rasp" target="_blank" title="">  </a><li><a name="user-content-rasp" target="_blank" title="">  </a><p><a name="user-content-rasp" target="_blank" title="Obtain a copy of">Obtain a copy of </a><a href="https://downloads.raspberrypi.org/raspios_lite_armhf_latest" rel="nofollow" target="_blank" title="Raspian Lite Edition">Raspian Lite Edition</a></p>  <ul>  <li>Burn the Image to the SD card using <a href="https://www.balena.io/etcher/" rel="nofollow" target="_blank" title="BalenaEtcher">BalenaEtcher</a></li>  </ul>  </li>  <li>  <p>Mount the SD card on your machine and make the following changes:</p>  <ul>  <li>  <p>In the <code>/path/to/sdcard/boot/config.txt</code> file add to the very end of the file:</p>  <div><pre><code>enable_uart=1<br>dtoverlay=dwc2</code></pre></div>  </li>  <li>  <p>In the <code>/path/to/sdcard/boot/cmdline.txt</code> add right after <code>rootwait</code></p>  <div><pre><code>modules-load=dwc2</code></pre></div>  </li>  <li>  <p>it should look like this make sure its on the same line:</p>  <div><pre><code>console=serial0,115200 console=tty1 root=PARTUUID=6c586e13-02 rootfstype=ext4 elevator=deadline fsck.repair=yes rootwait modules-load=dwc2</code></pre></div>  </li>  </ul>  </li>  <li>  <p>Enable ssh:</p>  <ul>  <li>  <p>in the <code>/path/to/sdcard/boot</code> directory create an empty file name ssh:</p>  <div><pre><code>sudo touch /path/to/sdcard/boot/ssh</code></pre></div>  </li>  </ul>  </li>  <li>  <p>Enable Wifi:</p>  <ul>  <li>  <p>in the <code>/path/to/sdcard/boot</code> directory create an file named <code>wpa_supplicant.conf</code>:</p>  <div><pre><code>sudo vim /path/to/sdcard/boot/wpa_supplicant.conf</code></pre></div>  </li>  <li>  <p>Add the following contents:</p>  <div><pre><code>ctrl_interface=DIR=/var/run/wpa_supplicant GROUP=netdev<br>update_config=1<br>country=US<br>network={<br>            ssid="&lt;your wifi SSID&gt;"<br>            psk="&lt;your wifi password&gt;"<br>            key_mgmt=WPA-PSK<br>         }</code></pre></div>  </li>  </ul>  </li>  <li>  <p>Unmount the SD card and place it back into the Raspberry Pi Zero and power it on.</p>  </li>  <li>  <p>Copy the content of <code>AutogadgetFS/Pizero/</code> to the Pi zero: <code>username: pi</code> &amp; <code>password: raspberry</code></p>  <div><pre><code>cd AutogadgetFS/Pizero/<br>scp gadgetfuzzer.py removegadget.sh requirements.txt router.py pi@&lt;pi-ipaddress&gt;:/home/pi</code></pre></div>  </li>  <li>  <p>SSH into the PI Zero and setup <a href="https://www.kitploit.com/search/label/Requirements" target="_blank" title="requirements">requirements</a> for AutoGadgetFS:</p>  <div><pre><code>ssh pi@&lt;pi-ip-address&gt;<br>chmod +x removegadget.sh<br>sudo apt update<br>sudo apt install python3 python3-pip<br>sudo -H pip3 install -r requirements.txt</code></pre></div>  </li>  <li><div><br></div></li><li><div><br></div></li><li><div><br></div></li><li><div><br></div></li><li>  <p>Upgrading the latest kernel and adding modules (* This step is optional for the current release):  ( This will take a very long time compiling on the Pi Zero, unless you choose to cross compile the kernel see <a href="https://www.raspberrypi.org/documentation/linux/kernel/building.md" rel="nofollow" target="_blank" title="Compiling options">Compiling options</a>)</p>  <div><pre><code>sudo bash<br>apt install git bc bison flex libssl-dev make libncurses5-dev screen<br>screen<br>mkdir Downloads<br>cd Downloads/<br>git clone --depth=1 https://github.com/raspberrypi/linux<br>cd linux/<br>make bcmrpi_defconfig<br>make menuconfig</code></pre></div>  <ul>  <li>Enable the Modules and save the config:</li>  </ul><div><br></div><div class="separator"><a href="https://1.bp.blogspot.com/-kEQDYQnXd_M/X5Jb9R-tMTI/AAAAAAAAUIk/z5nv4yzAHeUId50Nl-zn3WnAD95y6TYiQCNcBGAsYHQ/s1194/AutoGadgetFS_6_allgadgets.png" imageanchor="1"><img border="0" data-original-height="844" data-original-width="1194" height="452" src="https://1.bp.blogspot.com/-kEQDYQnXd_M/X5Jb9R-tMTI/AAAAAAAAUIk/z5nv4yzAHeUId50Nl-zn3WnAD95y6TYiQCNcBGAsYHQ/w640-h452/AutoGadgetFS_6_allgadgets.png" width="640"></a></div><br><div class="separator"><a href="https://1.bp.blogspot.com/-n3RceA1sJ_s/X5Jb9sZZiII/AAAAAAAAUIg/7ShbM0gYDAkYxRxuwhmQ1iwH_OiTuEJdgCNcBGAsYHQ/s1201/AutoGadgetFS_7_allgadgets2.png" imageanchor="1"><img border="0" data-original-height="859" data-original-width="1201" height="458" src="https://1.bp.blogspot.com/-n3RceA1sJ_s/X5Jb9sZZiII/AAAAAAAAUIg/7ShbM0gYDAkYxRxuwhmQ1iwH_OiTuEJdgCNcBGAsYHQ/w640-h458/AutoGadgetFS_7_allgadgets2.png" width="640"></a></div><br><div class="separator"><a href="https://1.bp.blogspot.com/-QsEjBYtcBAs/X5Jb9elxFmI/AAAAAAAAUIc/bXrOumSKg20S23wv2bY_JJhDnOd92F77QCNcBGAsYHQ/s1203/AutoGadgetFS_8_allgadgets3.png" imageanchor="1"><img border="0" data-original-height="862" data-original-width="1203" height="458" src="https://1.bp.blogspot.com/-QsEjBYtcBAs/X5Jb9elxFmI/AAAAAAAAUIc/bXrOumSKg20S23wv2bY_JJhDnOd92F77QCNcBGAsYHQ/w640-h458/AutoGadgetFS_8_allgadgets3.png" width="640"></a></div><br><div class="separator"><a href="https://1.bp.blogspot.com/-4RgBPbhLc9Y/X5Jb-XFlYPI/AAAAAAAAUIo/T_RQFS4AS8oOausjY7POX5EMz9s6Gv35ACNcBGAsYHQ/s1211/AutoGadgetFS_9_allgadgets4.png" imageanchor="1"><img border="0" data-original-height="777" data-original-width="1211" height="410" src="https://1.bp.blogspot.com/-4RgBPbhLc9Y/X5Jb-XFlYPI/AAAAAAAAUIo/T_RQFS4AS8oOausjY7POX5EMz9s6Gv35ACNcBGAsYHQ/w640-h410/AutoGadgetFS_9_allgadgets4.png" width="640"></a></div><div><br></div>  <ul>  <li>Build and use the kernel:</li>  </ul>  <div><pre><code>make zImage modules dtbs<br>make modules_install<br>cp arch/arm/boot/dts/*.dtb /boot/<br>cp arch/arm/boot/dts/overlays/*.dtb* /boot/overlays/<br>cp arch/arm/boot/dts/overlays/README /boot/overlays/<br>cp arch/arm/boot/zImage /boot/kernel.img<br>reboot</code></pre></div></li>  </ul><div><br></div><div><br></div><div><br></div>  <br><b>And you're done!</b><br>  <a name="user-content-tutorial" target="_blank" title=""><br><span><b>AutoGadgetFS tutorial:</b></span><br>  </a><p><a name="user-content-tutorial" target="_blank" title="USB testing made easy (51)"></a><a href="https://docs.agfs.io/" rel="nofollow" target="_blank" title="Click to visit the tutorial">Click to visit the tutorial</a></p>  <br><span><b>Screenshots:</b></span><br>  <br><b>Man in the Middle:</b><br>  <div><br></div><div class="separator"><a href="https://1.bp.blogspot.com/-mOk1zWHLHVw/X5JcKO1ifnI/AAAAAAAAUIs/n8U_A5c-zbwzFpTA1StGuAiALLRm-8DHACNcBGAsYHQ/s1719/AutoGadgetFS_10_mitm.png" imageanchor="1"><img border="0" data-original-height="900" data-original-width="1719" height="336" src="https://1.bp.blogspot.com/-mOk1zWHLHVw/X5JcKO1ifnI/AAAAAAAAUIs/n8U_A5c-zbwzFpTA1StGuAiALLRm-8DHACNcBGAsYHQ/w640-h336/AutoGadgetFS_10_mitm.png" width="640"></a></div><div><br></div><b>USB device fuzzing:</b><br>  <div><br></div><div class="separator"><a href="https://1.bp.blogspot.com/--metda7WXOM/X5JcedxhwDI/AAAAAAAAUJE/mNtU6P7xDtYZLvNl-dQUFMbPfxQHKiWVQCNcBGAsYHQ/s1835/AutoGadgetFS_11_devfuzzer.png" imageanchor="1"><img border="0" data-original-height="730" data-original-width="1835" height="254" src="https://1.bp.blogspot.com/--metda7WXOM/X5JcedxhwDI/AAAAAAAAUJE/mNtU6P7xDtYZLvNl-dQUFMbPfxQHKiWVQCNcBGAsYHQ/w640-h254/AutoGadgetFS_11_devfuzzer.png" width="640"></a></div><div><br></div><b>Host side fuzzing with code covereage:</b><br>  <div><br></div><div class="separator"><a href="https://1.bp.blogspot.com/-BHmKhYKOO18/X5JcjogYlHI/AAAAAAAAUJI/yx1OQgBE7NsEwojiST1sPUhCkVnYpYCFQCNcBGAsYHQ/s3288/AutoGadgetFS_12_codecov.png" imageanchor="1"><img border="0" data-original-height="956" data-original-width="3288" height="186" src="https://1.bp.blogspot.com/-BHmKhYKOO18/X5JcjogYlHI/AAAAAAAAUJI/yx1OQgBE7NsEwojiST1sPUhCkVnYpYCFQCNcBGAsYHQ/w640-h186/AutoGadgetFS_12_codecov.png" width="640"></a></div><div><br></div><b>Fuzzer based on a selection of bytes:</b><br>  <div><br></div><div class="separator"><a href="https://1.bp.blogspot.com/-sVI8sEQ4ePw/X5Jcph7nSXI/AAAAAAAAUJM/76p5DnOwPworR-jSfPYM8-BRbi9d3TjxACNcBGAsYHQ/s1476/AutoGadgetFS_13_selectivefuzz.png" imageanchor="1"><img border="0" data-original-height="653" data-original-width="1476" height="284" src="https://1.bp.blogspot.com/-sVI8sEQ4ePw/X5Jcph7nSXI/AAAAAAAAUJM/76p5DnOwPworR-jSfPYM8-BRbi9d3TjxACNcBGAsYHQ/w640-h284/AutoGadgetFS_13_selectivefuzz.png" width="640"></a></div><div><br></div><b>Smart fuzzer based on learning traffic:</b><br>  <div><pre><code>In [44]: x.devSmartFuzz(engine="smart",samples=5,filename="/home/raindrop/PycharmProjects/AutoGadgetFs/binariesdb/Nud-Nuvoton-1046-20764-1590421333.5169587-Nuvoton-1046-20764-1590421600.8067<br>    ...: 274-device.bin")                                                                                                                                                                     <br><br><br>[+]General Statistics<br>Full charset                : !"#$%&amp;'()*+,-./0123456789:;&lt;=&gt;?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~<br>Discarded charset           : !"#$%&amp;'()*+,-./:;&lt;=&gt;?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ghijklmnopqrstuvwxyz{|}~<br>Final charset               : 0123456789abcdef<br>Word Length                 : 128<br>Lower Case index usage      : 92%<br>Lower Case index locations  : [1, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37,    38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63, 64, 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 91, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 121, 122, 124, 125, 127]<br>Upper Case index usage      : 0%<br>Upper Case index locations  : []<br>Digit index usage           : 96%<br>Digit index locations       : [0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63, 64, 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 91, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 12   3, 126]<br>NonAN index usage           : 0%<br>NonAN index locations       : []<br>Counter statistics          : Uppercase: 0 , Lowercase: 133071, Digits:212017 , NonAlphaNumeric:0<br>All char Frequencies        : <br>character:5 found:5012 times<br>character:2 found:22563 times<br>character:3 found:12197 times<br>character:8 found:15008 times<br>character:4 found:13275 times<br>character:0 found:98056 times<br>character:1 found:17861 times<br>character:f found:87823 times<br>character:d found:7221 times<br>character:7 found:9614 times<br>character:a found:11148 times<br>character:6 found:10472 times<br>character:b found:8189 times<br>character:9 found:7959 times<br>character:c found:9172 times<br>character:e found:9518 times<br>***********************<br>generated:5 Packets<br>***********************<br>Out[44]: <br>['5608305852bf2ffd61770e2c827542f20be0b0fcba09db916bd07e1734b04cb0352b1d278068064d19f033bfad6fa90e53d865693fd4fee0214f00000eb0aa2c',<br> '3b08   3595f276e2f1353a535c32f0f59516fc9328f7673bb80262c4da11c93683afe6dcff8a7a83018d78f41498a0da4d141ebd39c361b1724f2b00000eb0aa2c',<br> '0120961963495c4dab9470738b497eddde07b0d70b357795ad9554d7964761969a6d997205e17eada6fa84eb33dcfb11412f75e04c195001283900000eb0aa2c',<br> '091065d52127bbc6e840e02f8e1316f1c4d9c92a23931c00cdbb8c158368852ef8fabd461b98812b51ec84e1ccc5c04aaa366fbafabec623bd3500000eb0aa2c',<br> '7300cc61151b7af27a578e766f49bebb2de68c48b37a00df1030ae464f456928eedd035303e697208bf58217af728a2a346fda5c8aef0335b82e00000eb0aa2c'<br><br>In [46]: x.edap.packets                                                                                                                                                                       <br>Out[46]: <br>['5608305852bf2ffd61770e2c827542f20be0b0fcba09db916bd07e1734b04cb0352b1d278068064d19f033bfad6fa90e53d865693fd4fee0214f00000eb0aa2c',<br> '3b083595f276e2f1353a535c32f0f59516fc9328f7673bb80262c4da11c93683afe6dcff8a7a83018d78f41498a0da4d141ebd3   9c361b1724f2b00000eb0aa2c',<br> '0120961963495c4dab9470738b497eddde07b0d70b357795ad9554d7964761969a6d997205e17eada6fa84eb33dcfb11412f75e04c195001283900000eb0aa2c',<br> '091065d52127bbc6e840e02f8e1316f1c4d9c92a23931c00cdbb8c158368852ef8fabd461b98812b51ec84e1ccc5c04aaa366fbafabec623bd3500000eb0aa2c',<br> '7300cc61151b7af27a578e766f49bebb2de68c48b37a00df1030ae464f456928eedd035303e697208bf58217af728a2a346fda5c8aef0335b82e00000eb0aa2c']</code></pre></div>  <br><b>Help method:</b><br>  <div><a name="user-content-screens" target="_blank" title=""></a><pre><a name="user-content-screens" target="_blank" title=""><code>In [15]: x.help("")                                                                                                                                               <br><br>Currently supported methods:<br>__________________________________________________________________________________________________________________________________________________________________<br>Method               ||--&gt;Description<br>----------------------------------------------------------------------------------------------------------------------------<br>MITMproxy            ||--&gt;This method creates a connection to the RabbitMQ and listen on received messages on the todev queue<br>____________________________________________________________________________________________________________________________<br>MITMproxyRQueues     ||--&gt;This method reads from the queue todev and sends the request to the device its self.<br>________________________________________________________   ____________________________________________________________________<br>SmartFuzz            ||--&gt;This method is generates packets based on what it has learned from a sniff from either the host or the device<br>____________________________________________________________________________________________________________________________<br>chgIntrfs            ||--&gt;This method allows you to change and select another interface<br>____________________________________________________________________________________________________________________________<br>clearqueues          ||--&gt;this method clears all the queues on the rabbitMQ queues that are set up<br>____________________________________________________________________________________________________________________________<br>clonedev             ||--&gt;This method does not need any parameters it only saves a backup of the device incase you need to share it or use it later.<br>_____________________________________   _______________________________________________________________________________________<br>createctrltrsnfDB    ||--&gt;creates a SQLite database containing values that were enumerated from control transfer enumeration<br>____________________________________________________________________________________________________________________________<br>createdb             ||--&gt;create the sqlite table and columns from usblyzer captures<br>____________________________________________________________________________________________________________________________<br>decodePacketAscii    ||--&gt;This method decodes packet bytes back to Ascii<br>____________________________________________________________________________________________________________________________<br>describeFuzz         ||--&gt;This method allows you to describe a packet and select which bytes will be fuzzed<br>___________________________________________________________________________________________________   _________________________<br>devEnumCtrltrnsf     ||--&gt;This method enumerates all possible combinations of a control transfer request<br>____________________________________________________________________________________________________________________________<br>devReset             ||--&gt;This method Resets the device<br>____________________________________________________________________________________________________________________________<br>devWrite             ||--&gt;To use this with a method you would write to a device make sure to run the startSniffReadThread(self,endpoint=None, pts=None, queue=None,channel=None)<br>____________________________________________________________________________________________________________________________<br>devctrltrnsf         ||--&gt;This method allows you to send ctrl transfer requests to the target device<br>_________________________________________________________________________________________________________________   ___________<br>deviceInfo           ||--&gt;gets the complete info only for any usb connected to the host<br>____________________________________________________________________________________________________________________________<br>deviceInterfaces     ||--&gt;get all interfaces and endpoints on the device<br>____________________________________________________________________________________________________________________________<br>devrandfuzz          ||--&gt;this method allows you to create fixed or random size packets created using urandom<br>____________________________________________________________________________________________________________________________<br>devseqfuzz           ||--&gt;This method allows you to create sequential incremented packets and send them to the device<br>____________________________________________________________________________________________________________________________<br>findSelect           ||--&gt;This method enumera   tes all USB devices connected and allows you to select it as a target device as well as its endpoints<br>____________________________________________________________________________________________________________________________<br>help                 ||--&gt;AutogadgetFS Help method<br>____________________________________________________________________________________________________________________________<br>hostwrite            ||--&gt;This method writes packets to the host either targeting a software or a driver in control of the device<br>____________________________________________________________________________________________________________________________<br>hstrandfuzz          ||--&gt;this method allows you to create fixed or random size packets created using urandom and send them to the host queue<br>____________________________________________________________________________________________________________________________<br>monInterfaceChng     ||--&gt;Me   thod in charge of monitoring interfaces for changes this is called from def startMonInterfaceChng(self)<br>____________________________________________________________________________________________________________________________<br>newProject           ||--&gt;creates a new project name if you were testing something else<br>____________________________________________________________________________________________________________________________<br>releasedev           ||--&gt;releases the device and re-attaches the kernel driver<br>____________________________________________________________________________________________________________________________<br>removeGadget         ||--&gt;This method removes the gadget from the raspberryPI<br>____________________________________________________________________________________________________________________________<br>replaymsgs           ||--&gt;This method searches the USBLyzer parsed database and give you the option rep   lay a message or all messages from host to device<br>____________________________________________________________________________________________________________________________<br>searchmsgs           ||--&gt;This method allows you to search and select all messages for a pattern which were saved from a USBlyzer database creation<br>____________________________________________________________________________________________________________________________<br>setupGadgetFS        ||--&gt;setup variables for gadgetFS : Linux Only, on Raspberry Pi Zero best option<br>____________________________________________________________________________________________________________________________<br>showMessage          ||--&gt;shows messages if error or warn or info<br>____________________________________________________________________________________________________________________________<br>sniffdevice          ||--&gt;read the communication between the device to hosts<br>______   ______________________________________________________________________________________________________________________<br>startMITMusbWifi     ||--&gt;Starts a thread to monitor the USB target Device<br>____________________________________________________________________________________________________________________________<br>startMonInterfaceChng||--&gt;This method Allows you to monitor a device every 10 seconds in case it suddenly changes its interface configuration.<br>____________________________________________________________________________________________________________________________<br>startQueuewrite      ||--&gt;initiates a connection to the queue to communicate with the host<br>____________________________________________________________________________________________________________________________<br>startSniffReadThread ||--&gt;This is a thread to continuously read the replies from the device and dependent on what you pass to the method either pts or que   ue<br>____________________________________________________________________________________________________________________________<br>stopMITMusbWifi      ||--&gt;Stops the </code></a><code><a href="https://www.kitploit.com/search/label/Man%20In%20The%20Middle" target="_blank" title="man in the middle">man in the middle</a> thread between the host and the device<br>____________________________________________________________________________________________________________________________<br>stopMonInterfaceChang||--&gt;Stops the interface monitor thread<br>____________________________________________________________________________________________________________________________<br>stopQueuewrite       ||--&gt;stop the thread incharge of communicating with the host machine<br>____________________________________________________________________________________________________________________________<br>stopSniffing         ||--&gt;Kills the sniffing thread strted by startSniffReadThread()<br>____________________________________________________________________________________________________________________________<br>usblyzerparse        ||--&gt;This method will parse your xml exported from usblyzer and then import them into a database<br>____________________________________________________________________________________________________________________________<br><br>In [16]: x.help("findSelect")                                                                                                                                                                 <br>****<br>[+]Help for findSelect Method:<br>[-]Signature: findSelect(self, chgint=None)<br><br><br>[+]findSelect Help:<br>This method enumerates all USB devices connected and allows you to select it as a target device as well as its endpoints<br>****</code></pre></div>  <br><b>AutoGadgetFS console. A much simpler way to use AGFS:</b><br>  <div><br></div><div class="separator"><a href="https://1.bp.blogspot.com/-SNXW4JL-5rg/X5Jcx8KSuBI/AAAAAAAAUJU/Qzf4aowfUdsat74z7J0iHwKzLHwyNjA7gCNcBGAsYHQ/s890/AutoGadgetFS_14_agfsconsole.png" imageanchor="1"><img border="0" data-original-height="337" data-original-width="890" height="242" src="https://1.bp.blogspot.com/-SNXW4JL-5rg/X5Jcx8KSuBI/AAAAAAAAUJU/Qzf4aowfUdsat74z7J0iHwKzLHwyNjA7gCNcBGAsYHQ/w640-h242/AutoGadgetFS_14_agfsconsole.png" width="640"></a></div><div><br></div><a name="user-content-youtube" target="_blank" title=""><span><b>Youtube Playlist:</b></span><br>  </a><p><a name="user-content-youtube" target="_blank" title="USB testing made easy (56)"></a><a href="https://www.youtube.com/playlist?list=PLKozlVgM6RQjNHmpWR2RBiFCtufV03o6Z" rel="nofollow" target="_blank" title="Youtube Playlist">Youtube Playlist</a></p>  <a name="user-content-slack" target="_blank" title=""><br><span><b>Join Slack:</b></span><br>  </a><p><a name="user-content-slack" target="_blank" title="Visit">Visit </a><a href="https://join.slack.com/t/autogadgetfs/shared_invite/zt-emgcv3ol-unG_axHmSQlk~5GcBddhlQ" rel="nofollow" target="_blank" title="AutogadgetFS Slack Channel">AutogadgetFS Slack Channel</a></p><p><br></p><span><b>Contact:</b></span><span><b><a name="user-content-contact" target="_blank" title="USB testing made easy (66)"><br></a><a href="mailto:rd@agfs.io" rel="nofollow" target="_blank" title="rd@agfs.io">rd@agfs.io<br></a></b></span><span><b><a href="https://twitter.com/0xRaindrop" rel="nofollow" target="_blank" title="https://twitter.com/0xRaindrop">https://twitter.com/0xRaindrop</a></b></span><br><br><br><div><b><span><a class="kiploit-download" href="https://github.com/ehabhussein/AutoGadgetFS" rel="nofollow" target="_blank" title="Download AutoGadgetFS">Download AutoGadgetFS</a></span></b></div><img src="http://feeds.feedburner.com/~r/PentestTools/~4/Wk_mYJIJXU8" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2020-09-25 - Calibre, KDE-git, Deepin, Python, Haskell]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some interesting updates for you!
1920×1080 43.3 KB
You don’t have a Manjaro Phone yet? Get all the Pre-Order Infos now! #stayhome, #staysafe, #stayhealthy

We updated some of our KDE-git packages
We fixed the linux-latest meta package in regard...]]></description>
<link>https://tsecurity.de/de/1247899/unix-server/testing-update-2020-09-25-calibre-kde-git-deepin-python-haskell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1247899/unix-server/testing-update-2020-09-25-calibre-kde-git-deepin-python-haskell/</guid>
<pubDate>Fri, 25 Sep 2020 18:03:24 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some interesting updates for you!</p>
<p></p><div class="lightbox-wrapper"><a class="lightbox" href="https://forum.manjaro.org/uploads/default/original/2X/1/13c1fbcb8f51fd27b5aad7df9297c038fd9b12de.jpeg" data-download-href="https://forum.manjaro.org/uploads/default/13c1fbcb8f51fd27b5aad7df9297c038fd9b12de" title=""><img src="https://forum.manjaro.org/uploads/default/optimized/2X/1/13c1fbcb8f51fd27b5aad7df9297c038fd9b12de_2_690x388.jpeg" alt="" data-base62-sha1="2OMG9gIQnyNyFLu46GWaIClcMVw" width="690" height="388" srcset="https://forum.manjaro.org/uploads/default/optimized/2X/1/13c1fbcb8f51fd27b5aad7df9297c038fd9b12de_2_690x388.jpeg, https://forum.manjaro.org/uploads/default/optimized/2X/1/13c1fbcb8f51fd27b5aad7df9297c038fd9b12de_2_1035x582.jpeg 1.5x, https://forum.manjaro.org/uploads/default/optimized/2X/1/13c1fbcb8f51fd27b5aad7df9297c038fd9b12de_2_1380x776.jpeg 2x" data-small-upload="https://forum.manjaro.org/uploads/default/optimized/2X/1/13c1fbcb8f51fd27b5aad7df9297c038fd9b12de_2_10x10.png"><div class="meta"><svg class="fa d-icon d-icon-far-image svg-icon" aria-hidden="true"><use xlink:href="#far-image"></use></svg><span class="filename"></span><span class="informations">1920×1080 43.3 KB</span><svg class="fa d-icon d-icon-discourse-expand svg-icon" aria-hidden="true"><use xlink:href="#discourse-expand"></use></svg></div></a></div><br>
<em>You don’t have a Manjaro Phone yet? Get all the <a href="https://pine64.com/product-category/pinephone/">Pre-Order Infos</a> now! <span class="hashtag">#stayhome</span>, <span class="hashtag">#staysafe</span>, <span class="hashtag">#stayhealthy</span></em>
<ul>
<li>We updated some of our <strong>KDE-git</strong> packages</li>
<li>We fixed the <strong>linux-latest</strong> meta package in regard of Kernel 5.6 series</li>
<li>Some more <strong>Deepin</strong> package updates</li>
<li>
<strong>Calibre</strong> ebook-reader is now at <a href="https://calibre-ebook.com/new-in/fourteen">5.0</a>
</li>
<li>Usual <strong>Python</strong> and <strong>Haskell</strong> package updates and rebuilds</li>
</ul>
<p>If you like following latest Plasma development you may also like to check out our current version of <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/20.1/">manjaro-kde-dev</a>, which we build on a regular basis against kde-git master packages. Also check out our latest <strong>Manjaro Mikah 20.1</strong> release! <a href="https://osdn.net/projects/manjaro/storage/xfce/20.1/">XFCE</a>, <a href="https://osdn.net/projects/manjaro/storage/kde/20.1/">KDE</a> and <a href="https://osdn.net/projects/manjaro/storage/gnome/20.1/">Gnome</a></p>
<hr>
<pre><code class="lang-auto">sudo pacman -Syy
sudo pacman -S pacman-static
sudo pacman-static -Syyu
</code></pre>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux44 4.4.237</li>
<li>linux49 4.9.237</li>
<li>linux414 4.14.199</li>
<li>linux419 4.19.147</li>
<li>linux54 5.4.67</li>
<li>linux57 5.7.19 [EOL]</li>
<li>linux58 5.8.11</li>
<li>linux59 5.9-rc6</li>
<li>linux54-rt 5.4.66_rt38</li>
<li>linux56-rt 5.6.19_rt12</li>
</ul>
<p><strong>Packages Changes</strong> (Fri Sep 25 16:45:05 CEST 2020)</p>
<ul>
<li>testing community x86_64:  198 new and 196 removed package(s)</li>
<li>testing core x86_64:  3 new and 3 removed package(s)</li>
<li>testing extra x86_64:  35 new and 39 removed package(s)</li>
<li>testing multilib x86_64:  1 new and 1 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-09-24           2020-09-25
-------------------------------------------------------------------------------
                        auto-cpufreq 1.3.3.r168.b7ec847-1 1.3.3.r171.5120cbd-1
                       bluedevil-git5.20.80.r2158.g53928ec1-15.20.80.r2161.gab92107c-1
                          breeze-git5.19.90.r2042.gee537d74-15.20.80.r2048.g059ac0b7-1
                    breeze-icons-git5.75.0.r1629.g16d20f16-15.75.0.r1630.g6fb87953-1
                        discover-git5.20.80.r7839.g76b562c6-15.20.80.r7840.g293b5700-1
                         drkonqi-git5.20.80.r543.gca764b24-15.20.80.r544.gc302c5a7-1
             extra-cmake-modules-git5.75.0.r3187.gfbc00bf-15.75.0.r3190.g2509327-1
            frameworkintegration-git5.75.0.r535.g75ec5bf-15.75.0.r536.ged2df13-1
gnome-shell-extension-material-shell                6.1-1                6.2-1
                            hw-probe1.6+beta.26.ge8c4bf61c4-11.6+beta.27.g07ff9f20b5-1
               kactivitymanagerd-git5.15.80.r1300.gff7d32b-15.15.80.r1301.g6f61549-1
                        kcmutils-git5.75.0.r432.g8ac50dd-15.75.0.r433.gd640cbf-1
                   kde-cli-tools-git5.20.80.r1807.gcbab4f0-15.20.80.r1808.g15a68c2-1
                  kde-gtk-config-git5.20.80.r856.gb91d516-15.20.80.r859.g6518708-1
                     kdecoration-git5.19.90.r237.g074f517-15.20.80.r238.g46b7027-1
                kdeplasma-addons-git5.20.80.r8389.geda917ebe-15.20.80.r8392.ge65233c4d-1
                      kio-extras-git    r6859.g015a265d-1    r6860.g3bc1df1c-1
                             kio-git5.75.0.r4212.g5da32a17-15.75.0.r4214.ge711a227-1
                       kirigami2-git5.75.0.r2425.g95781e80-15.75.0.r2429.g856d44b7-1
                      knetattach-git5.20.80.r7878.gb18e922b0-15.20.80.r7884.g20ac5eb56-1
                       knewstuff-git5.75.0.r936.gfa05a109-15.75.0.r938.ge0aed91c-1
                  knotifications-git5.75.0.r564.g636d6c5-15.75.0.r565.g2e57561-1
                         krunner-git5.75.0.r505.g635e11f-15.75.0.r506.gc42704a-1
                   kscreenlocker-git5.19.90.r801.gbc2fe72-15.20.80.r803.g22bb146-1
                       ksysguard-git5.20.80.r3362.gc8957d2e-15.20.80.r3364.g2f460ece-1
                     kwallet-pam-git5.20.80.r228.g046f346-15.20.80.r229.gbebe9e1-1
            kwayland-integration-git5.20.80.r154.g00ae501-15.20.80.r155.g3667c19-1
                 kwayland-server-git5.19.90.r1126.g0a07cb2-15.20.80.r1134.gd25db24-1
                  kwidgetsaddons-git5.75.0.r717.g1b2fac3-15.75.0.r718.g85dc53f-1
                            kwin-git5.19.90.r18383.ge6e72d27b-15.20.80.r18420.ga58100fc7-1
                      libkscreen-git5.19.90.r1529.gc0dddfa-15.20.80.r1530.g9c23ef2-1
                    libksysguard-git5.19.90.r1963.gad90cf3-15.20.80.r1972.gc9eac35-1
                        linux-latest                5.8-1                5.8-2
              linux-latest-acpi_call                5.8-1                5.8-2
               linux-latest-bbswitch                5.8-1                5.8-2
            linux-latest-broadcom-wl                5.8-1                5.8-2
                linux-latest-headers                5.8-1                5.8-2
           linux-latest-nvidia-340xx                5.7-2                    -
           linux-latest-nvidia-390xx                5.8-1                5.8-2
           linux-latest-nvidia-418xx                5.8-1                5.8-2
           linux-latest-nvidia-430xx                5.8-1                5.8-2
           linux-latest-nvidia-435xx                5.8-1                5.8-2
           linux-latest-nvidia-440xx                5.8-1                5.8-2
           linux-latest-nvidia-450xx                5.7-2                5.8-2
                  linux-latest-r8168                5.8-1                5.8-2
              linux-latest-rtl8723bu                5.8-1                5.8-2
               linux-latest-tp_smapi                5.8-1                5.8-2
            linux-latest-vhba-module                5.8-1                5.8-2
linux-latest-virtualbox-guest-modules               5.8-1                5.8-2
linux-latest-virtualbox-host-modules                5.8-1                5.8-2
                    linux-latest-zfs                5.8-1                5.8-2
                           milou-git5.19.90.r707.gfef79aa-15.20.80.r709.g3ec02ea-1
                          oxygen-git5.19.90.r4389.g4e332a59-15.20.80.r4391.g6d7f4c80-1
                  plasma-desktop-git5.20.80.r7878.gb18e922b0-15.20.80.r7884.g20ac5eb56-1
                plasma-framework-git5.75.0.r15576.g16f852ea4-15.75.0.r15577.g316771779-1
              plasma-integration-git5.19.90.r481.gb09cc0f-15.20.80.r482.g297f8bf-1
                       plasma-nm-git5.20.80.r2943.g492e6aca-15.20.80.r2944.g7638b7fc-1
          plasma-wayland-session-git5.20.80.r9435.g665836f56-15.20.80.r9439.gf033fdb5b-1
                plasma-workspace-git5.20.80.r9435.g665836f56-15.20.80.r9439.gf033fdb5b-1
                polkit-kde-agent-git5.20.80.r462.g80180a4-15.20.80.r464.gca77c08-1
                      powerdevil-git5.20.80.r2355.g12ecb78d-15.20.80.r2357.gaa6dba84-1
             syntax-highlighting-git5.75.0.r1316.g08fcc8a2-15.75.0.r1319.gb998b137-1
                  systemsettings-git5.20.80.r2270.g2e82e4fc-15.20.80.r2273.g14f9c104-1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-09-24           2020-09-25
-------------------------------------------------------------------------------
                      amavisd-milter              1.7.0-2              1.7.1-1
                             amsynth             1.11.0-2             1.11.0-3
                               brial              1.2.8-1              1.2.9-1
                             calibre             4.23.0-2              5.0.0-1
                      calibre-common             4.23.0-2                    -
                     calibre-python3             4.23.0-2                    -
                              catch2             2.13.0-1             2.13.1-1
                              clamtk               6.03-1               6.06-1
                              cobalt             0.16.2-1             0.16.3-1
                                code             1.49.0-2             1.49.1-1
                             cryptol             2.9.1-11             2.9.1-14
                        deepin-movie         1:5.7.6.32-1         1:5.7.6.33-1
                        deepin-music           6.0.1.13-1           6.0.1.14-1
                    dhall-lsp-server             1.0.10-4             1.0.10-5
                          diffoscope                146-1                160-1
                      docker-compose             1.27.3-1             1.27.4-1
                              drupal              9.0.5-1              9.0.6-1
                         emby-server            4.4.3.0-4           4.5.0.50-1
                              fcitx5     0.0.0.20200923-1     0.0.0.20200924-1
                           flameshot              0.8.1-1              0.8.1-2
                                gist              5.1.0-1              6.0.0-1
                           git-annex        8.20200908-12        8.20200908-13
                       gitlab-runner             13.3.0-1             13.4.0-1
                              gradle                6.6-1              6.6.1-1
                          gradle-doc                6.6-1              6.6.1-1
                          gradle-src                6.6-1              6.6.1-1
                             grafana              7.1.4-1              7.2.0-1
                  haskell-aeson-diff           1.1.0.9-74           1.1.0.9-75
                    haskell-bv-sized             1.0.2-10             1.0.2-11
                          haskell-ci             0.10.3-1             0.10.3-2
               haskell-conduit-parse            0.2.1.0-2            0.2.1.0-3
                    haskell-cracknum                2.4-1                2.4-2
                  haskell-file-embed           0.0.12.0-3           0.0.13.0-1
                 haskell-floatinghex               0.4-17                0.5-1
                         haskell-gtk            0.15.5-19                    -
                      haskell-hakyll          4.13.4.0-66          4.13.4.0-67
                 haskell-hledger-lib             1.19.1-4             1.19.1-5
         haskell-hslua-module-system             0.2.2-13             0.2.2-14
                       haskell-ipynb           0.1.0.1-86           0.1.0.1-87
                    haskell-lsp-test           0.11.0.6-1           0.11.0.6-2
         haskell-parameterized-utils             2.1.0-24              2.1.1-1
                         haskell-sbv                8.8-5                8.8-7
                      haskell-sbv8.7                8.7-5                8.7-7
              haskell-servant-server               0.18-5               0.18-6
                       haskell-shake            0.19.1-64            0.19.1-65
                   haskell-tasty-lua             0.2.3-13             0.2.3-14
              haskell-wai-app-static           3.1.7.2-24           3.1.7.2-25
                       haskell-what4               1.0-36               1.0-37
                       haskell-yesod           1.6.1.0-34           1.6.1.0-35
                  haskell-yesod-auth           1.6.10-119           1.6.10-120
                haskell-yesod-static           1.6.1.0-54           1.6.1.0-55
                         hcxdumptool              6.1.1-1              6.1.2-1
                            hcxtools              6.1.1-1              6.1.2-1
                             hledger             1.19.1-4             1.19.1-5
                          hledger-ui             1.19.1-4             1.19.1-5
                         hledger-web            1.19.1-10            1.19.1-11
                               hlint                3.2-2                3.2-3
                              iperf3                3.7-2                3.9-1
                             jenkins              2.257-1              2.258-1
                               julia            2:1.5.1-1            2:1.5.2-1
                          julia-docs            2:1.5.1-1            2:1.5.2-1
                          libstrophe            1:0.9.3-1           1:0.10.0-1
                      libstrophe-doc            1:0.9.3-1           1:0.10.0-1
             lightdm-webkit2-greeter              2.2.5-3              2.2.5-4
                             mcabber              1.1.1-1              1.1.2-1
                       mediastreamer              4.4.0-2              4.4.2-1
                              openmw             0.46.0-1             0.46.0-2
                   otf-cascadia-code            2009.14-1            2009.22-1
                              pandoc            2.10.1-26            2.10.1-27
                     pandoc-citeproc          0.17.0.2-37          0.17.0.2-38
                     pandoc-crossref            0.3.8.1-4            0.3.8.1-5
                            pgadmin4               4.25-1               4.26-1
                               ponyc             0.37.0-1             0.38.0-1
                        pulseeffects              4.8.0-2              4.8.2-1
                      python-alembic              1.4.2-1              1.4.3-1
                         python-apsw             3.33.0-1             3.33.0-2
           python-aws-sam-translator             1.26.0-1             1.27.0-1
                     python-cfn-lint             0.36.0-1             0.36.1-1
                   python-css-parser              1.0.4-3              1.0.4-4
                    python-html2text          2019.8.11-4          2020.1.16-1
                 python-html5-parser              0.4.9-2              0.4.9-3
                   python-hypothesis             5.35.4-1             5.36.0-1
                     python-identify              1.5.4-1              1.5.5-1
                    python-mechanize            1:0.4.5-1            1:0.4.5-2
                    python-netifaces             0.10.9-3             0.10.9-4
                        python-paste              3.4.4-1              3.4.5-1
                        python-pychm              0.8.6-1              0.8.6-2
             python-python-multipart              0.0.4-1              0.0.5-1
                        python-regex          2020.7.14-1          2020.7.14-2
       python-tensorboard_plugin_wit              1.6.0-1              1.7.0-1
                        python-toolz             0.11.0-1             0.11.1-1
                     python-unrardll              0.1.4-2              0.1.4-3
                    python-witwidget              1.6.0-1              1.7.0-1
                        python2-apsw             3.33.0-1                    -
                  python2-css-parser              1.0.4-3                    -
                   python2-html2text          2019.8.11-4                    -
                python2-html5-parser              0.4.9-2                    -
                    python2-markdown              3.1.1-5                    -
                   python2-mechanize            1:0.4.5-1                    -
                   python2-netifaces             0.10.9-3                    -
                      python2-pillow              6.2.1-2              6.2.1-3
                       python2-pychm              0.8.6-1                    -
                       python2-regex          2020.7.14-1                    -
                    python2-unrardll              0.1.4-2                    -
                        r2ghidra-dec              4.5.0-1              4.5.1-1
                            rabbitmq              3.8.7-1              3.8.9-1
                       rabbitmqadmin              3.8.7-1              3.8.9-1
                             radare2              4.5.0-1              4.5.1-1
                      radare2-cutter           1:1.11.1-2           1:1.12.0-1
                                  sd              0.7.5-1              0.7.6-1
                          shellcheck            0.7.1-137            0.7.1-138
                           shorewall              5.2.7-1              5.2.8-1
                      shorewall-core              5.2.7-1              5.2.8-1
                          shorewall6              5.2.7-1              5.2.8-1
                      signal-desktop             1.36.1-1             1.36.2-1
                          skia-sharp             1.68.1-1             2.80.2-1
                       sqlitebrowser             3.11.2-2             3.12.0-1
                               stack            2.3.1-137            2.3.1-138
                     stylish-haskell          0.11.0.3-21          0.11.0.3-22
                            sundials              5.3.0-1              5.4.0-1
                      tamarin-prover              1.6.0-8              1.6.0-9
                             taskell             1.10.0-1             1.10.0-2
                         tensorboard              2.3.0-1              2.3.0-3
                 torbrowser-launcher              0.3.2-4              0.3.2-6
                   ttf-cascadia-code            2009.14-1            2009.22-1
                           ukui-menu              3.0.0-1              3.0.1-1
         v2ray-domain-list-community     20200922125738-1     20200923123822-1
                             vim-ale              2.7.0-1              3.0.0-1
                               vkd3d                1.1-1                1.2-1
                 woff2-cascadia-code            2009.14-1            2009.22-1
                              wpscan            1:3.8.3-2            1:3.8.7-1
                                 yad                7.1-1                7.2-1
                      youtube-viewer            1:3.7.8-1            1:3.7.9-1
                            glewlwyd                    -              2.3.3-1
           haskell-flexible-defaults                    -              0.0.3-1
                        haskell-gtk3                    -             0.15.5-1
      haskell-mersenne-random-pure64                    -            0.2.2.0-1
                 haskell-monadprompt                    -            1.0.0.5-1
                   haskell-random-fu                    -            0.2.7.7-1
              haskell-random-shuffle                    -              0.0.4-1
               haskell-random-source                    -           0.3.0.11-1
                        haskell-rvar                    -            0.2.0.6-1
                    haskell-stateref                    -                0.3-1
                   haskell-th-extras                    -            0.0.0.4-1
                             libinih                    -                 51-3
                          misfortune                    -            0.1.1.2-1
             python-click-didyoumean                    -              0.0.3-1
                python-pytest-celery                    -            0.0.0a1-1
                                uusi                    -            0.0.0.0-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-09-24           2020-09-25
-------------------------------------------------------------------------------
                             openssl            1.1.1.g-2            1.1.1.h-1
                                perl             5.32.0-1             5.32.0-3
                                sudo              1.9.3-1           1.9.3.p1-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-09-24           2020-09-25
-------------------------------------------------------------------------------
                              polkit            0.116-5.1              0.117-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-09-24           2020-09-25
-------------------------------------------------------------------------------
                              bullet               2.89-2               3.05-1
                         bullet-docs               2.89-2               3.05-1
                              clamav            0.102.4-1            0.103.0-1
                        cups-filters             1.28.2-1             1.28.3-1
                                 efl             1.24.3-3             1.24.3-4
                            efl-docs             1.24.3-3             1.24.3-4
                             firefox               81.0-1               81.0-2
                             freetds              1.2.4-1              1.2.5-1
                                  gn    0.1731.5ed3c9cc-1    0.1819.e327ffdc-1
                   gst-plugin-opencv             1.18.0-1             1.18.0-2
                     gst-plugins-bad             1.18.0-1             1.18.0-2
                gst-plugins-bad-libs             1.18.0-1             1.18.0-2
                           iptraf-ng              1.1.4-5              1.2.1-1
                              libbpf              0.0.9-1              0.1.1-1
                             libcbor              0.7.0-1              0.8.0-1
                            libde265              1.0.6-1              1.0.7-1
                            libfido2              1.4.0-4              1.5.0-2
                             libheif              1.8.0-1              1.9.1-1
                         libmicrodns              0.1.2-1              0.2.0-1
                          libspectre              0.2.9-1              0.2.9-2
                               libuv             1.39.0-1             1.40.0-1
                                 mtr               0.93-3               0.94-1
                             mtr-gtk               0.93-3               0.94-1
                                nasm            2.15.04-1            2.15.05-1
                         perl-libwww               6.48-1               6.49-1
                       python-opengl              3.1.5-1              3.1.5-2
                     python-pybullet               2.89-2               3.05-1
                        python-pyqt5             5.15.1-1             5.15.1-2
                python-pyqtwebengine             5.15.1-1             5.15.1-2
                          python-sip            4.19.24-1            4.19.24-2
                      python2-opengl              3.1.5-1                    -
                       python2-pyqt5             5.15.1-1                    -
               python2-pyqtwebengine             5.15.1-1                    -
                   python2-sip-pyqt5            4.19.24-1                    -
                            rinutils              0.4.1-1              0.6.0-1
                                 sip            4.19.24-1            4.19.24-2
                                 srt              1.4.1-2              1.4.2-1
                                 vlc           3.0.11.1-2           3.0.11.1-3
                                js78                    -             78.3.0-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-09-24           2020-09-25
-------------------------------------------------------------------------------
                         lib32-vkd3d                1.1-2                1.2-2

</code></pre>
<div class="poll" data-poll-status="open" data-poll-type="regular" data-poll-name="poll">
<div>
<div class="poll-container">
<ul>
<li data-poll-option-id="893d9543968a33fa1039e2d7c2aff9f3">No issue, everything went smoothly</li>
<li data-poll-option-id="f62cf202dc0ce246aa612290c3f33f1f">Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li data-poll-option-id="e1ee941aacf54cee0c82939acae184cc">Yes i am currently experiencing an issue due to the update. (Please post about it)</li>
</ul>
</div>
<div class="poll-info">
<p>
<span class="info-number">0</span>
<span class="info-label">voters</span>
</p>
</div>
</div>
</div>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
            <p><small>4 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2020-09-25-calibre-kde-git-deepin-python-haskell/27893">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-5419]]></title>
<description><![CDATA[RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (pl...]]></description>
<link>https://tsecurity.de/de/1223911/sicherheitsluecken/cve-2020-5419/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1223911/sicherheitsluecken/cve-2020-5419/</guid>
<pubDate>Mon, 31 Aug 2020 18:48:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2020-08-26 - Firefox 80, CoreCTRL, Xorg-Server, AMDVLK, Python, Haskell]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some interesting updates for you!
1200×520
Get the latest Firefox release now! #stayhome, #staysafe, #stayhealthy

Some more KDE-git and Deepin package updates
We added CoreCTRL so you can tweak your grahics cards better

Firefox is now at 80 an...]]></description>
<link>https://tsecurity.de/de/1220146/unix-server/testing-update-2020-08-26-firefox-80-corectrl-xorg-server-amdvlk-python-haskell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1220146/unix-server/testing-update-2020-08-26-firefox-80-corectrl-xorg-server-amdvlk-python-haskell/</guid>
<pubDate>Thu, 27 Aug 2020 02:18:27 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some interesting updates for you!</p>
<p></p><div class="lightbox-wrapper"><a class="lightbox" href="https://ubunlog.com/wp-content/uploads/2020/08/Firefox-80.jpg.webp" title=""><img src="https://ubunlog.com/wp-content/uploads/2020/08/Firefox-80.jpg.webp" alt="" width="690" height="299"><div class="meta"><svg class="fa d-icon d-icon-far-image svg-icon" aria-hidden="true"><use xlink:href="#far-image"></use></svg><span class="filename"></span><span class="informations">1200×520</span><svg class="fa d-icon d-icon-discourse-expand svg-icon" aria-hidden="true"><use xlink:href="#discourse-expand"></use></svg></div></a></div><br>
<em>Get the latest <strong>Firefox</strong> release now! <span class="hashtag">#stayhome</span>, <span class="hashtag">#staysafe</span>, <span class="hashtag">#stayhealthy</span></em>
<ul>
<li>Some more <strong>KDE-git</strong> and <strong>Deepin</strong> package updates</li>
<li>We added <strong><a href="https://gitlab.com/corectrl/corectrl/-/wikis/home">CoreCTRL</a></strong> so you can tweak your grahics cards better</li>
<li>
<strong>Firefox</strong> is now at <a href="https://www.mozilla.org/en-US/firefox/80.0/releasenotes/">80</a> and brings some GPU accleration with it</li>
<li>
<strong>Xorg-Server</strong> got updated to <a href="https://lists.x.org/archives/xorg-announce/2020-August/003059.html">1.20.9</a>
</li>
<li>AMD managed to get another <a href="https://www.phoronix.com/scan.php?page=news_item&amp;px=AMDVLK-2020.Q3.4-Released">AMDVLK</a> release out</li>
<li>Usual <strong>Python</strong> and <strong>Haskell</strong> package updates and rebuilds</li>
</ul>
<div class="onebox lazyYT lazyYT-container" data-youtube-id="Zi77qiZzChg" data-youtube-title="Linux Gaming: This App Does What AMD Won't" data-parameters="feature=oembed&amp;wmode=opaque">
  <a href="https://www.youtube.com/watch?v=Zi77qiZzChg" target="_blank" rel="noopener">
    <img class="ytp-thumbnail-image" src="https://forum.manjaro.org/uploads/default/original/2X/8/8423f268f05db0833e824ee722d90b99a5f74e05.jpeg" title="Linux Gaming: This App Does What AMD Won't" width="690" height="388">
  </a>
</div>

<p>If you like following latest Plasma development you may also like to check out our current version of <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/20.1/">manjaro-kde-dev</a>, which we build on a regular basis against kde-git master packages. Also check out our latest RC of <strong>Manjaro Mikah 20.1</strong>! <a href="https://osdn.net/projects/manjaro/storage/xfce/20.1-rc4/">XFCE</a>, <a href="https://osdn.net/projects/manjaro/storage/kde/20.1-rc4/">KDE</a> and <a href="https://osdn.net/projects/manjaro/storage/gnome/20.1-rc4/">Gnome</a></p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux44 4.4.233</li>
<li>linux49 4.9.233</li>
<li>linux414 4.14.194</li>
<li>linux419 4.19.141</li>
<li>linux54 5.4.60</li>
<li>linux57 5.7.17</li>
<li>linux58 5.8.3</li>
<li>linux59 5.9-rc2</li>
<li>linux54-rt 5.4.59_rt36</li>
<li>linux56-rt 5.6.19_rt12</li>
</ul>
<p><strong>Package Changes</strong> (Wed Aug 26 04:09:22 CEST 2020)</p>
<ul>
<li>testing community x86_64:  415 new and 411 removed package(s)</li>
<li>testing core x86_64:  7 new and 7 removed package(s)</li>
<li>testing extra x86_64:  178 new and 180 removed package(s)</li>
<li>testing multilib x86_64:  2 new and 2 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-23           2020-08-26
-------------------------------------------------------------------------------
                          attica-git5.74.0.r761.g860a5b3-15.74.0.r762.gc2e9dbd-1
                           baloo-git5.74.0.r2818.g3d9f809d-15.74.0.r2819.g315fe621-1
                    breeze-icons-git5.74.0.r1618.gb8ab1248-15.74.0.r1619.gda65148b-1
               kactivitymanagerd-git5.15.80.r1295.g2e2b11b-15.15.80.r1296.gee01ecb-1
                         kapidox-git5.74.0.r483.g3af0ca6-15.74.0.r485.gda20738-1
                           kauth-git5.74.0.r372.g19c2143-15.74.0.r373.g07f420a-1
                         kconfig-git5.74.0.r715.g9574fe4-15.74.0.r716.ga3d5591-1
                  kconfigwidgets-git5.74.0.r491.g7634a5f-15.74.0.r492.g0354d18-1
                     kcoreaddons-git5.74.0.r1015.g8599c4d-15.74.0.r1016.g0f2a222-1
                          kcrash-git5.74.0.r327.g8358edb-15.74.0.r328.gc164dd7-1
                  kde-gtk-config-git5.19.80.r847.gc16c9c1-15.19.80.r848.g7bffada-1
                   kfilemetadata-git5.74.0.r713.g915860e-15.74.0.r714.gdc1f995-1
                      kguiaddons-git5.74.0.r298.g695e257-15.74.0.r299.gc4dc910-1
                           ki18n-git5.74.0.r407.gd0ad4b4-15.74.0.r409.g3857ce9-1
                      kio-extras-git    r6824.gd682a669-1    r6825.g39ef052c-1
                             kio-git5.74.0.r4160.gff6a3d40-15.74.0.r4164.g027895f3-1
                       kirigami2-git5.74.0.r2356.gd35ead4c-15.74.0.r2365.gfe494187-1
                    kmediaplayer-git5.74.0.r247.ge9b1674-15.74.0.r248.g6befb59-1
                      knetattach-git5.19.80.r7830.g8447c08e8-15.19.80.r7838.g68aebb7b6-1
                       knewstuff-git5.74.0.r905.gc75457e0-15.74.0.r912.gb3405b97-1
                          kparts-git5.74.0.r431.g995452f-15.74.0.r433.gbe4e1e7-1
                         krunner-git5.74.0.r472.gede652d-15.74.0.r473.g09dfb16-1
                         kwallet-git5.74.0.r994.g3d0f039-15.74.0.r995.gde0456b-1
                        kwayland-git5.74.0.r1022.g0a39462-15.74.0.r1024.gc4fa14f-1
                 kwayland-server-git5.19.80.r1109.g8c0d27e-15.19.80.r1110.gf834cdd-1
                         kwrited-git5.19.80.r435.g5e7aeab-15.19.80.r436.gccb29b1-1
                    libksysguard-git5.19.80.r1946.g58a3007-15.19.80.r1947.geb68b6b-1
                      nemo-pdf-tools1.2.9.0extras20.04.03-2.11.2.9.0extras20.04.03-3
      plasma-browser-integration-git5.19.80.r1126.g75bb10dd-15.19.80.r1127.gd9fc5916-1
                  plasma-desktop-git5.19.80.r7830.g8447c08e8-15.19.80.r7838.g68aebb7b6-1
                plasma-framework-git5.74.0.r15539.ga4e7ea680-15.74.0.r15541.g3f8469acb-1
                       plasma-nm-git5.19.80.r2922.g9678abd7-15.19.80.r2923.gca3e94d4-1
                polkit-kde-agent-git5.19.80.r450.g1a55d26-15.19.80.r451.ga8d4828-1
                          prison-git5.74.0.r267.g074ddad-15.74.0.r268.g6d75c37-1
              qqc2-desktop-style-git5.74.0.r383.g156c962-15.74.0.r387.ga21856a-1
                           subfinder            2.4.2-1.1              2.4.3-1
             syntax-highlighting-git5.74.0.r1211.gdf9eeaf1-15.74.0.r1256.g87c8dc9a-1
                  systemsettings-git5.19.80.r2250.g313831f8-15.19.80.r2251.g949098e7-1
                    whatsapp-web-jak              2.1.0-2              2.1.0-3
                            corectrl                    -            1.1.1-2.1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-23           2020-08-26
-------------------------------------------------------------------------------
                               acorn            1:7.4.0-1            1:8.0.1-1
                                agda             2.6.1-95             2.6.1-97
                         arduino-cli             0.11.0-2             0.12.0-1
                           aspell-pl           20200822-1           20200825-1
                                avfs              1.1.2-1              1.1.3-1
                             aws-cli           1.18.120-1           1.18.124-1
                            binaryen               1:96-1               1:96-2
                       cabal-install           3.2.0.0-63           3.2.0.0-65
                          cockatrice              2.7.4-4              2.7.5-4
                             cockpit                226-1                226-2
                   cockpit-dashboard                226-1                226-2
                      cockpit-docker                226-1                226-2
                    cockpit-machines                226-1                226-2
                         cockpit-pcp                226-1                226-2
                                code             1.48.0-1             1.48.2-1
                               darcs             2.16.2-2             2.16.2-4
                             dbeaver              7.1.4-1              7.1.5-1
                   deepin-calculator             5.5.30-1             5.5.31-1
               deepin-control-center           5.3.0.11-1           5.3.0.13-1
                     deepin-launcher            5.3.0.5-1            5.3.0.6-1
              deepin-qt-dbus-factory            5.3.0.6-1            5.3.0.8-1
               deepin-qt5integration            5.1.0.4-1            5.1.0.5-1
                deepin-session-shell            5.3.0.5-1            5.3.0.6-1
                     deepin-terminal             5.2.22-1             5.2.23-1
                   deepin-voice-note              5.8.3-1              5.8.4-1
                               dhall            1.34.0-11            1.34.0-13
                          dhall-bash            1.0.32-11            1.0.32-13
                          dhall-json             1.7.1-14             1.7.1-16
                             dtkcore          1:5.2.2.3-1          1:5.2.2.5-1
                              dtkgui            5.2.2.3-1            5.2.2.4-1
                           dtkwidget            5.2.2.3-1            5.2.2.5-1
                        emptyepsilon         2020.04.09-1         2020.08.07-1
                          emscripten              2.0.0-1              2.0.1-1
                            ettercap              0.8.3-2            0.8.3.1-1
                        ettercap-gtk              0.8.3-2            0.8.3.1-1
                              fcitx5     0.0.0.20200822-1     0.0.0.20200826-1
               fcitx5-chinese-addons     0.0.0.20200822-1     0.0.0.20200823-1
                          fcitx5-lua     0.0.0.20200821-1     0.0.0.20200824-1
                                 fio               3.21-1               3.22-1
                              fossil             2.11.2-1             2.12.1-1
                       gambas3-devel             3.15.0-1             3.15.0-2
                     gambas3-gb-args             3.15.0-1             3.15.0-2
                    gambas3-gb-cairo             3.15.0-1             3.15.0-2
                    gambas3-gb-chart             3.15.0-1             3.15.0-2
                  gambas3-gb-clipper             3.15.0-1             3.15.0-2
                  gambas3-gb-complex             3.15.0-1             3.15.0-2
                 gambas3-gb-compress             3.15.0-1             3.15.0-2
                    gambas3-gb-crypt             3.15.0-1             3.15.0-2
                     gambas3-gb-data             3.15.0-1             3.15.0-2
                       gambas3-gb-db             3.15.0-1             3.15.0-2
                  gambas3-gb-db-form             3.15.0-1             3.15.0-2
                 gambas3-gb-db-mysql             3.15.0-1             3.15.0-2
                  gambas3-gb-db-odbc             3.15.0-1             3.15.0-2
            gambas3-gb-db-postgresql             3.15.0-1             3.15.0-2
               gambas3-gb-db-sqlite3             3.15.0-1             3.15.0-2
                     gambas3-gb-dbus             3.15.0-1             3.15.0-2
                  gambas3-gb-desktop             3.15.0-1             3.15.0-2
            gambas3-gb-desktop-gnome             3.15.0-1             3.15.0-2
              gambas3-gb-desktop-x11             3.15.0-1             3.15.0-2
           gambas3-gb-eval-highlight             3.15.0-1             3.15.0-2
                     gambas3-gb-form             3.15.0-1             3.15.0-2
              gambas3-gb-form-dialog             3.15.0-1             3.15.0-2
              gambas3-gb-form-editor             3.15.0-1             3.15.0-2
                 gambas3-gb-form-mdi             3.15.0-1             3.15.0-2
               gambas3-gb-form-stock             3.15.0-1             3.15.0-2
            gambas3-gb-form-terminal             3.15.0-1             3.15.0-2
                      gambas3-gb-gmp             3.15.0-1             3.15.0-2
                      gambas3-gb-gsl             3.15.0-1             3.15.0-2
                      gambas3-gb-gtk             3.15.0-1             3.15.0-2
               gambas3-gb-gtk-opengl             3.15.0-1             3.15.0-2
                     gambas3-gb-gtk3             3.15.0-1             3.15.0-2
                    gambas3-gb-httpd             3.15.0-1             3.15.0-2
                    gambas3-gb-image             3.15.0-1             3.15.0-2
             gambas3-gb-image-effect             3.15.0-1             3.15.0-2
              gambas3-gb-image-imlib             3.15.0-1             3.15.0-2
                 gambas3-gb-image-io             3.15.0-1             3.15.0-2
                  gambas3-gb-inotify             3.15.0-1             3.15.0-2
                   gambas3-gb-libxml             3.15.0-1             3.15.0-2
                  gambas3-gb-logging             3.15.0-1             3.15.0-2
                      gambas3-gb-map             3.15.0-1             3.15.0-2
                 gambas3-gb-markdown             3.15.0-1             3.15.0-2
                    gambas3-gb-media             3.15.0-1             3.15.0-2
               gambas3-gb-media-form             3.15.0-1             3.15.0-2
                gambas3-gb-memcached             3.15.0-1             3.15.0-2
                     gambas3-gb-mime             3.15.0-1             3.15.0-2
                    gambas3-gb-mysql             3.15.0-1             3.15.0-2
                  gambas3-gb-ncurses             3.15.0-1             3.15.0-2
                      gambas3-gb-net             3.15.0-1             3.15.0-2
                 gambas3-gb-net-curl             3.15.0-1             3.15.0-2
                 gambas3-gb-net-pop3             3.15.0-1             3.15.0-2
                 gambas3-gb-net-smtp             3.15.0-1             3.15.0-2
                   gambas3-gb-openal             3.15.0-1             3.15.0-2
                   gambas3-gb-opengl             3.15.0-1             3.15.0-2
              gambas3-gb-opengl-glsl             3.15.0-1             3.15.0-2
               gambas3-gb-opengl-glu             3.15.0-1             3.15.0-2
               gambas3-gb-opengl-sge             3.15.0-1             3.15.0-2
                  gambas3-gb-openssl             3.15.0-1             3.15.0-2
                   gambas3-gb-option             3.15.0-1             3.15.0-2
                     gambas3-gb-pcre             3.15.0-1             3.15.0-2
                      gambas3-gb-pdf             3.15.0-1             3.15.0-2
                  gambas3-gb-poppler             3.15.0-1             3.15.0-2
                      gambas3-gb-qt5             3.15.0-1             3.15.0-2
               gambas3-gb-qt5-opengl             3.15.0-1             3.15.0-2
               gambas3-gb-qt5-webkit             3.15.0-1             3.15.0-2
                   gambas3-gb-report             3.15.0-1             3.15.0-2
                  gambas3-gb-scanner             3.15.0-1             3.15.0-2
                      gambas3-gb-sdl             3.15.0-1             3.15.0-2
                gambas3-gb-sdl-sound             3.15.0-1             3.15.0-2
                     gambas3-gb-sdl2             3.15.0-1             3.15.0-2
               gambas3-gb-sdl2-audio             3.15.0-1             3.15.0-2
                 gambas3-gb-settings             3.15.0-1             3.15.0-2
                   gambas3-gb-signal             3.15.0-1             3.15.0-2
                     gambas3-gb-term             3.15.0-1             3.15.0-2
                     gambas3-gb-util             3.15.0-1             3.15.0-2
                 gambas3-gb-util-web             3.15.0-1             3.15.0-2
                      gambas3-gb-v4l             3.15.0-1             3.15.0-2
                       gambas3-gb-vb             3.15.0-1             3.15.0-2
                      gambas3-gb-web             3.15.0-1             3.15.0-2
                 gambas3-gb-web-feed             3.15.0-1             3.15.0-2
                 gambas3-gb-web-form             3.15.0-1             3.15.0-2
                  gambas3-gb-web-gui             3.15.0-1             3.15.0-2
                      gambas3-gb-xml             3.15.0-1             3.15.0-2
                 gambas3-gb-xml-html             3.15.0-1             3.15.0-2
                  gambas3-gb-xml-rpc             3.15.0-1             3.15.0-2
                 gambas3-gb-xml-xslt             3.15.0-1             3.15.0-2
                         gambas3-ide             3.15.0-1             3.15.0-2
                     gambas3-runtime             3.15.0-1             3.15.0-2
                      gambas3-script             3.15.0-1             3.15.0-2
                                gdal             3.0.4-11             3.0.4-12
                       gdb-dashboard             0.11.3-1             0.11.4-1
                           git-annex        8.20200810-17        8.20200810-19
                          git-repair        1.20200504-59        1.20200504-61
                      gnome-software             3.36.1-1             3.36.1-2
    gnome-software-packagekit-plugin             3.36.1-1             3.36.1-2
                         go-ethereum             1.9.19-1             1.9.20-1
                              gopass              1.9.2-3             1.10.1-1
                              gradle              6.5.1-1                6.6-1
                          gradle-doc              6.5.1-1                6.6-1
                          gradle-src              6.5.1-1                6.6-1
                             hashcat            1:6.0.0-1            1:6.1.1-1
                haskell-authenticate            1.3.5-169            1.3.5-171
          haskell-authenticate-oauth          1.6.0.1-142          1.6.0.1-144
                         haskell-aws             0.22-101             0.22-103
           haskell-base64-bytestring           1.1.0.0-11            1.2.0.0-1
                 haskell-casa-client             0.0.1-91             0.0.1-93
                  haskell-casa-types             0.0.1-76             0.0.1-77
                       haskell-cborg           0.2.4.0-13           0.2.4.0-14
                  haskell-cborg-json           0.2.2.0-43           0.2.2.0-44
                  haskell-cheapskate          0.1.1.2-136          0.1.1.2-138
               haskell-clientsession          0.9.1.2-154          0.9.1.2-155
               haskell-conduit-extra             1.3.5-36             1.3.5-37
                   haskell-criterion          1.5.6.2-118          1.5.6.2-120
          haskell-cryptohash-conduit            0.1.1-388            0.1.1-389
          haskell-cryptonite-conduit            0.2.2-282            0.2.2-283
                         haskell-dav            1.3.4-152            1.3.4-154
                        haskell-dbus            1.2.16-22            1.2.16-23
               haskell-dbus-hslogger           0.1.0.1-74           0.1.0.1-75
                         haskell-dns             4.0.1-49             4.0.1-50
                haskell-doctemplates             0.8.2-32             0.8.2-33
                   haskell-esqueleto           3.3.3.2-31           3.3.3.2-32
                  haskell-fdo-notify            0.3.1-326            0.3.1-327
                        haskell-feed           1.3.0.1-40           1.3.0.1-41
                          haskell-gi             0.24.1-6             0.24.1-7
                     haskell-git-lfs             1.1.0-25             1.1.0-27
                     haskell-githash           0.1.4.0-81           0.1.4.0-83
            haskell-hackage-security           0.6.0.1-69           0.6.0.1-71
                      haskell-hakyll          4.13.4.0-44          4.13.4.0-46
              haskell-hi-file-parser           0.1.0.0-52           0.1.0.0-53
                    haskell-hopenpgp            2.9.4-139            2.9.4-141
                       haskell-hpack            0.34.2-47            0.34.2-49
                   haskell-hspec-wai            0.10.1-72            0.10.1-73
              haskell-hspec-wai-json            0.10.1-79            0.10.1-80
                haskell-html-conduit           1.3.2.1-93           1.3.2.1-94
                        haskell-http        4000.3.14-256        4000.3.14-258
                 haskell-http-client              0.7.2-2            0.7.2.1-2
      haskell-http-client-restricted             0.0.3-25             0.0.3-27
             haskell-http-client-tls          0.3.5.3-283          0.3.5.3-285
                 haskell-http-common            0.8.2.1-8            0.8.2.1-9
                haskell-http-conduit          2.3.7.3-177          2.3.7.3-179
               haskell-http-download          0.2.0.0-111          0.2.0.0-113
                haskell-http-streams           0.8.7.2-34           0.8.7.2-36
                  haskell-httpd-shed          0.4.1.1-184          0.4.1.1-186
                         haskell-hxt         9.3.1.18-125         9.3.1.18-127
                       haskell-ipynb           0.1.0.1-72           0.1.0.1-73
                        haskell-jose            0.8.3.1-6            0.8.3.1-8
                   haskell-js-jquery            3.3.1-487            3.3.1-489
                   haskell-mime-mail             0.5.0-40             0.5.0-41
                haskell-monad-logger             0.3.35-7             0.3.35-8
                    haskell-mustache            2.3.1-154            2.3.1-156
                 haskell-network-uri          2.6.3.0-143          2.6.3.0-145
                       haskell-nonce            1.0.7-102            1.0.7-103
          haskell-openpgp-asciiarmor             0.1.2-41             0.1.2-42
             haskell-optparse-simple            0.1.1.3-5            0.1.1.3-7
                      haskell-pantry           0.5.1.1-33           0.5.1.1-35
                  haskell-persistent          2.10.5.2-80          2.10.5.2-81
               haskell-persistent-qq          2.9.1.1-133          2.9.1.1-134
           haskell-persistent-sqlite         2.10.6.2-108         2.10.6.2-109
         haskell-persistent-template           2.8.2.3-85           2.8.2.3-86
             haskell-persistent-test           2.0.3.1-79           2.0.3.1-80
                  haskell-pipes-http            1.0.6-196            1.0.6-198
            haskell-project-template           0.2.1.0-12           0.2.1.0-13
                         haskell-rio           0.1.18.0-4           0.1.18.0-5
                 haskell-rio-orphans          0.1.1.0-152          0.1.1.0-153
             haskell-rio-prettyprint            0.1.1.0-9           0.1.1.0-10
                   haskell-serialise           0.2.3.0-29           0.2.3.0-30
                     haskell-servant              0.17-90              0.17-92
              haskell-servant-server              0.17-97              0.17-99
             haskell-servant-swagger            1.1.8-101            1.1.8-103
                       haskell-shake            0.19.1-47            0.19.1-49
             haskell-simple-sendfile            0.2.30-80            0.2.30-81
                 haskell-skylighting             0.8.5-33             0.8.5-35
            haskell-skylighting-core             0.8.5-33             0.8.5-35
                   haskell-snap-core           1.0.4.2-25           1.0.4.2-27
                 haskell-snap-server           1.1.1.2-85           1.1.1.2-89
                       haskell-store              0.7.6-4              0.7.6-5
           haskell-tagstream-conduit             0.5.6-26             0.5.6-27
         haskell-tamarin-prover-term             1.4.1-71             1.4.1-72
       haskell-tamarin-prover-theory            1.4.1-109            1.4.1-110
        haskell-tamarin-prover-utils             1.4.1-56             1.4.1-57
                 haskell-tar-conduit             0.3.2-98             0.3.2-99
                     haskell-texmath          0.12.0.2-65          0.12.0.2-67
            haskell-text-conversions             0.3.0-35             0.3.0-36
               haskell-typed-process           0.2.6.0-39           0.2.6.0-40
                  haskell-uri-encode           1.5.0.6-13           1.5.0.6-15
              haskell-wai-app-static            3.1.7.2-6            3.1.7.2-8
                   haskell-wai-extra          3.0.29.2-42          3.0.29.2-43
          haskell-wai-handler-launch          3.0.3.1-106          3.0.3.1-108
                  haskell-wai-logger            2.3.6-120            2.3.6-121
              haskell-wai-websockets          3.0.1.2-160          3.0.1.2-161
                        haskell-warp            3.3.13-39            3.3.13-41
                    haskell-warp-tls             3.3.0-26             3.3.0-28
                  haskell-websockets          0.12.7.1-16          0.12.7.1-17
                        haskell-wreq          0.5.3.2-252          0.5.3.2-254
                 haskell-xml-conduit           1.9.0.0-43           1.9.0.0-44
                  haskell-xml-hamlet          0.5.0.1-123          0.5.0.1-124
                haskell-xss-sanitize            0.3.6-173            0.3.6-175
                       haskell-yesod           1.6.1.0-13           1.6.1.0-15
                  haskell-yesod-auth            1.6.10-98           1.6.10-100
                  haskell-yesod-core            1.6.18-81            1.6.18-83
               haskell-yesod-default            1.2.0-791            1.2.0-793
                  haskell-yesod-form            1.6.7-234            1.6.7-236
            haskell-yesod-persistent          1.6.0.4-178          1.6.0.4-180
                haskell-yesod-static           1.6.1.0-32           1.6.1.0-34
                  haskell-yesod-test            1.6.10-35            1.6.10-37
                         hcxdumptool              6.0.7-1              6.1.1-1
                            hcxtools              6.0.3-1              6.1.1-1
                            hiawatha              10.11-1              10.11-2
                         hledger-web            1.18.1-48            1.18.1-50
                              hoogle            5.0.18-31            5.0.18-33
                      hopenpgp-tools           0.23.1-106           0.23.1-108
                         hunspell-pl           20200822-1           20200825-1
                                i2pd             2.32.1-1             2.33.0-1
                               idris             1.3.3-55             1.3.3-57
                              libime     0.0.0.20200807-1     0.0.0.20200824-1
                        libmediainfo              20.03-1              20.08-1
                             libmgba              0.8.2-1              0.8.3-1
              libperconaserverclient          8.0.20_11-1          8.0.20_11-2
                             librime           1:1.5.3-11           1:1.5.3-12
                        matterbridge             1.18.0-1             1.18.2-1
                             maturin              0.8.2-1              0.8.3-1
                           mediainfo              20.03-1              20.08-1
                       mediainfo-gui              20.03-1              20.08-1
                          metasploit             5.0.99-1            5.0.101-1
                             mgba-qt              0.8.2-1              0.8.3-1
                            mgba-sdl              0.8.2-1              0.8.3-1
                 nextcloud-app-notes              3.6.1-1              3.6.2-1
                      nginx-mainline             1.19.2-1             1.19.2-2
                                 nim              1.2.4-1              1.2.6-1
                                nrpe              4.0.2-1              4.0.3-1
                              pandoc             2.10.1-7             2.10.1-9
                     pandoc-citeproc          0.17.0.2-18          0.17.0.2-20
                     pandoc-crossref           0.3.7.0-20           0.3.7.0-22
                           partclone             0.3.12-1             0.3.15-1
                            patchelf                0.9-3               0.11-1
                            pdf2djvu           0.9.17.1-1           0.9.17.1-2
                             pelican              4.5.0-1              4.5.0-2
                      percona-server          8.0.20_11-1          8.0.20_11-2
              percona-server-clients          8.0.20_11-1          8.0.20_11-2
                              podman              2.0.4-1              2.0.5-1
                       podman-docker              2.0.4-1              2.0.5-1
                           postgrest             7.0.1-65             7.0.1-67
                             premake                4.3-6             5.0a15-1
                              pwndbg         2019.12.09-1         2020.07.23-1
                  python-aiobotocore              1.0.7-2              1.1.0-1
                        python-arrow             0.15.8-1             0.16.0-1
                        python-boto3            1.14.43-1            1.14.47-1
                     python-botocore            1.17.43-1            1.17.47-1
                      python-cheroot              8.4.4-1              8.4.5-1
                     python-colorlog              4.1.0-1              4.2.1-1
                python-cssbeautifier             1.12.0-1             1.13.0-1
                        python-curio                1.2-1                1.4-1
                         python-dask             2.22.0-1             2.24.0-1
                  python-distributed             2.22.0-1             2.24.0-1
                  python-elementpath              1.4.6-1              2.0.1-1
                     python-engineio             3.13.1-1             3.13.2-1
                    python-fonttools             4.13.0-1             4.14.0-1
                         python-gdal             3.0.4-11             3.0.4-12
                          python-h11              0.9.0-1             0.10.0-1
                   python-hypothesis             5.27.0-1             5.29.0-1
                     python-identify             1.4.28-1             1.4.29-1
                   python-inflection              0.5.0-1              0.5.1-1
                       python-jaraco         2019.10.22-3         2020.08.23-1
                 python-jsbeautifier             1.12.0-1             1.13.0-1
                      python-keyring             21.3.0-1             21.3.1-1
                      python-netaddr             0.7.19-5             0.7.20-1
                      python-nodeenv              1.4.0-1              1.5.0-1
                          python-nox          2020.5.24-1          2020.8.22-1
                     python-openpyxl              3.0.4-1              3.0.5-1
                       python-pandas              1.1.0-1              1.1.1-1
                        python-parse             1.15.0-1             1.16.0-1
                         python-pipx           0.15.4.0-1           0.15.5.0-1
                  python-precis_i18n              1.0.1-3              1.0.2-1
                       python-ptrace              0.9.5-1              0.9.7-1
                       python-pynacl              1.3.0-4              1.4.0-1
                 python-pytest-xdist              2.0.0-1              2.1.0-1
             python-requests-credssp              1.1.1-1              1.2.0-1
                    python-responses            0.10.16-1             0.11.0-1
                   python-xlsxwriter              1.3.2-1              1.3.3-1
                    python-xmlschema              1.2.2-1              1.2.3-1
                     python2-cheroot              8.4.4-1              8.4.5-1
                      python2-jaraco         2019.10.22-3         2019.10.22-4
                        r2ghidra-dec              4.4.0-1              4.5.0-1
                            rabbitmq              3.8.4-1              3.8.7-1
                       rabbitmqadmin              3.8.4-1              3.8.7-1
                             radare2              4.4.0-1              4.5.0-1
                      radare2-cutter           1:1.10.3-2           1:1.11.1-1
                      rime-cantonese     0.0.0.20200823-1     0.0.0.20200825-1
                    rime-luna-pinyin     0.0.0.20200710-1     0.0.0.20200824-1
                          ruby-stomp              1.4.8-4             1.4.10-1
                       rust-analyzer           20200817-1           20200824-1
                             scribus             1.5.5-12             1.5.5-13
                          shellcheck            0.7.1-118            0.7.1-120
                      signal-desktop             1.34.5-1             1.34.5-2
                         singularity               1.00-1               1.00-2
                               smali              2.3.4-1              2.4.0-1
                              sqlmap              1.4.4-1              1.4.8-1
                               squid               4.12-1               4.13-1
                            sshuttle              1.0.3-1              1.0.4-1
                                sssd              2.3.0-2              2.3.1-1
                               stack            2.3.1-103            2.3.1-105
                             sthttpd             2.27.1-2             2.27.1-3
                      tamarin-prover            1.4.1-409            1.4.1-411
                             taskell           1.9.3.0-16           1.9.3.0-18
                    telegram-desktop              2.3.0-2              2.3.2-1
                           texstudio            2.12.22-1              3.0.0-1
                             toolbox             0.0.93-1             0.0.94-1
                         tpm2-pkcs11              1.3.2-1              1.4.0-2
                              tt-rss  2:r9913.ac17ded85-1  2:r9948.5497a137d-1
                                twin              0.8.1-1              0.8.1-2
                           uglify-js             3.10.1-1             3.10.2-1
                          ukui-media              3.0.0-1              3.0.1-1
                               uwsgi           2.0.19.1-3           2.0.19.1-4
                    uwsgi-plugin-cgi           2.0.19.1-3           2.0.19.1-4
                    uwsgi-plugin-jvm           2.0.19.1-3           2.0.19.1-4
                  uwsgi-plugin-lua51           2.0.19.1-3           2.0.19.1-4
                   uwsgi-plugin-mono           2.0.19.1-3           2.0.19.1-4
               uwsgi-plugin-notfound           2.0.19.1-3           2.0.19.1-4
                    uwsgi-plugin-php           2.0.19.1-3           2.0.19.1-4
                   uwsgi-plugin-psgi           2.0.19.1-3           2.0.19.1-4
                   uwsgi-plugin-pypy           2.0.19.1-3           2.0.19.1-4
                 uwsgi-plugin-python           2.0.19.1-3           2.0.19.1-4
                   uwsgi-plugin-rack           2.0.19.1-3           2.0.19.1-4
                 uwsgi-plugin-webdav           2.0.19.1-3           2.0.19.1-4
                 uwsgi-plugin-zabbix           2.0.19.1-3           2.0.19.1-4
         v2ray-domain-list-community     20200822154907-1     20200824152527-1
                           veracrypt       1.24.update4-1       1.24.update7-1
                                vmaf              1.5.2-1              1.5.3-1
                                  wt              4.3.1-1              4.4.0-1
                              xmobar              0.35-31              0.35-33
                           yggdrasil             0.3.14-2             0.3.14-3
                           zeroc-ice              3.7.4-1              3.7.4-2
                      zeroc-ice-java              3.7.4-1              3.7.4-2
                   python-auditwheel                    -              3.1.1-1
                   python-pypatchelf                    -                0.9-1
                      python2-pillow                    -              6.2.1-2


:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-23           2020-08-26
-------------------------------------------------------------------------------
                   amd-ucode 20200817.r1695.7a30af1-1 20200824.r1697.74bd44f-1
              linux-firmware 20200817.r1695.7a30af1-1 20200824.r1697.74bd44f-1
                       linux59 5.9rc1.d0816.g9123e3a-1 5.9rc2.d0823.gd012a71-1
               linux59-headers 5.9rc1.d0816.g9123e3a-1 5.9rc2.d0823.gd012a71-1
                     manjaro-release               20.1-0             20.1-0.1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-23           2020-08-26
-------------------------------------------------------------------------------
                                dash             0.5.11-1           0.5.11.1-1
                                nano                5.1-1                5.2-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-23           2020-08-26
-------------------------------------------------------------------------------
               calamares-git 3.2.28.r8385.a96483a28-1 3.2.30.r8526.7dbc44ff7-1
                                gvim         8.2.1490-0.1                    -
                   linux59-acpi_call            1.1.0-0.1            1.1.0-0.2
                    linux59-bbswitch              0.8-0.1              0.8-0.2
                       linux59-r8168         8.048.03-0.1         8.048.03-0.2
                   linux59-rtl8723bu         20200813-0.1         20200813-0.2
                    linux59-tp_smapi             0.43-0.1             0.43-0.2
                 linux59-vhba-module         20200106-0.1         20200106-0.2
                       manjaro-hello             0.6.5-11             0.6.5-12
                           pamac-cli              9.5.8-1              9.5.8-2
                        pamac-common              9.5.8-1              9.5.8-2
                pamac-flatpak-plugin              9.5.8-1              9.5.8-2
             pamac-gnome-integration              9.5.8-1              9.5.8-2
                           pamac-gtk              9.5.8-1              9.5.8-2
                   pamac-snap-plugin              9.5.8-1              9.5.8-2
             pamac-tray-appindicator              9.5.8-1              9.5.8-2
                               snapd             2.45.2-1               2.46-1
                                 vim         8.2.1490-0.1                    -
                         vim-runtime         8.2.1490-0.1                    -
                         xorg-server             1.20.8-4             1.20.9-1
                  xorg-server-common             1.20.8-4             1.20.9-1
                   xorg-server-devel             1.20.8-4             1.20.9-1
                  xorg-server-xephyr             1.20.8-4             1.20.9-1
                   xorg-server-xnest             1.20.8-4             1.20.9-1
                    xorg-server-xvfb             1.20.8-4             1.20.9-1
                xorg-server-xwayland             1.20.8-4             1.20.9-1
                linux59-nvidia-450xx                    -           450.66-0.3


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-23           2020-08-26
-------------------------------------------------------------------------------
                         389-ds-base            1.4.4.4-1            1.4.4.4-2
                              amdvlk          2020.Q3.3-1          2020.Q3.4-1
                              apache             2.4.46-1             2.4.46-2
                            apr-util              1.6.1-7              1.6.1-8
                            calligra              3.2.1-2              3.2.1-3
                            chromium      84.0.4147.135-1       85.0.4183.83-1
                        cups-filters             1.27.5-1             1.28.0-1
                             doxygen             1.8.18-2             1.8.20-1
                        doxygen-docs             1.8.18-2             1.8.20-1
                           edk2-ovmf             202005-2             202005-3
                          edk2-shell             202005-2             202005-3
                             firefox               79.0-1               80.0-1
                    firefox-i18n-ach               79.0-1               80.0-1
                     firefox-i18n-af               79.0-1               80.0-1
                     firefox-i18n-an               79.0-1               80.0-1
                     firefox-i18n-ar               79.0-1               80.0-1
                    firefox-i18n-ast               79.0-1               80.0-1
                     firefox-i18n-az               79.0-1               80.0-1
                     firefox-i18n-be               79.0-1               80.0-1
                     firefox-i18n-bg               79.0-1               80.0-1
                     firefox-i18n-bn               79.0-1               80.0-1
                     firefox-i18n-br               79.0-1               80.0-1
                     firefox-i18n-bs               79.0-1               80.0-1
                     firefox-i18n-ca               79.0-1               80.0-1
            firefox-i18n-ca-valencia               79.0-1               80.0-1
                    firefox-i18n-cak               79.0-1               80.0-1
                     firefox-i18n-cs               79.0-1               80.0-1
                     firefox-i18n-cy               79.0-1               80.0-1
                     firefox-i18n-da               79.0-1               80.0-1
                     firefox-i18n-de               79.0-1               80.0-1
                    firefox-i18n-dsb               79.0-1               80.0-1
                     firefox-i18n-el               79.0-1               80.0-1
                  firefox-i18n-en-ca               79.0-1               80.0-1
                  firefox-i18n-en-gb               79.0-1               80.0-1
                  firefox-i18n-en-us               79.0-1               80.0-1
                     firefox-i18n-eo               79.0-1               80.0-1
                  firefox-i18n-es-ar               79.0-1               80.0-1
                  firefox-i18n-es-cl               79.0-1               80.0-1
                  firefox-i18n-es-es               79.0-1               80.0-1
                  firefox-i18n-es-mx               79.0-1               80.0-1
                     firefox-i18n-et               79.0-1               80.0-1
                     firefox-i18n-eu               79.0-1               80.0-1
                     firefox-i18n-fa               79.0-1               80.0-1
                     firefox-i18n-ff               79.0-1               80.0-1
                     firefox-i18n-fi               79.0-1               80.0-1
                     firefox-i18n-fr               79.0-1               80.0-1
                  firefox-i18n-fy-nl               79.0-1               80.0-1
                  firefox-i18n-ga-ie               79.0-1               80.0-1
                     firefox-i18n-gd               79.0-1               80.0-1
                     firefox-i18n-gl               79.0-1               80.0-1
                     firefox-i18n-gn               79.0-1               80.0-1
                  firefox-i18n-gu-in               79.0-1               80.0-1
                     firefox-i18n-he               79.0-1               80.0-1
                  firefox-i18n-hi-in               79.0-1               80.0-1
                     firefox-i18n-hr               79.0-1               80.0-1
                    firefox-i18n-hsb               79.0-1               80.0-1
                     firefox-i18n-hu               79.0-1               80.0-1
                  firefox-i18n-hy-am               79.0-1               80.0-1
                     firefox-i18n-ia               79.0-1               80.0-1
                     firefox-i18n-id               79.0-1               80.0-1
                     firefox-i18n-is               79.0-1               80.0-1
                     firefox-i18n-it               79.0-1               80.0-1
                     firefox-i18n-ja               79.0-1               80.0-1
                     firefox-i18n-ka               79.0-1               80.0-1
                    firefox-i18n-kab               79.0-1               80.0-1
                     firefox-i18n-kk               79.0-1               80.0-1
                     firefox-i18n-km               79.0-1               80.0-1
                     firefox-i18n-kn               79.0-1               80.0-1
                     firefox-i18n-ko               79.0-1               80.0-1
                    firefox-i18n-lij               79.0-1               80.0-1
                     firefox-i18n-lt               79.0-1               80.0-1
                     firefox-i18n-lv               79.0-1               80.0-1
                     firefox-i18n-mk               79.0-1               80.0-1
                     firefox-i18n-mr               79.0-1               80.0-1
                     firefox-i18n-ms               79.0-1               80.0-1
                     firefox-i18n-my               79.0-1               80.0-1
                  firefox-i18n-nb-no               79.0-1               80.0-1
                  firefox-i18n-ne-np               79.0-1               80.0-1
                     firefox-i18n-nl               79.0-1               80.0-1
                  firefox-i18n-nn-no               79.0-1               80.0-1
                     firefox-i18n-oc               79.0-1               80.0-1
                  firefox-i18n-pa-in               79.0-1               80.0-1
                     firefox-i18n-pl               79.0-1               80.0-1
                  firefox-i18n-pt-br               79.0-1               80.0-1
                  firefox-i18n-pt-pt               79.0-1               80.0-1
                     firefox-i18n-rm               79.0-1               80.0-1
                     firefox-i18n-ro               79.0-1               80.0-1
                     firefox-i18n-ru               79.0-1               80.0-1
                     firefox-i18n-si               79.0-1               80.0-1
                     firefox-i18n-sk               79.0-1               80.0-1
                     firefox-i18n-sl               79.0-1               80.0-1
                    firefox-i18n-son               79.0-1               80.0-1
                     firefox-i18n-sq               79.0-1               80.0-1
                     firefox-i18n-sr               79.0-1               80.0-1
                  firefox-i18n-sv-se               79.0-1               80.0-1
                     firefox-i18n-ta               79.0-1               80.0-1
                     firefox-i18n-te               79.0-1               80.0-1
                     firefox-i18n-th               79.0-1               80.0-1
                     firefox-i18n-tl               79.0-1               80.0-1
                     firefox-i18n-tr               79.0-1               80.0-1
                    firefox-i18n-trs               79.0-1               80.0-1
                     firefox-i18n-uk               79.0-1               80.0-1
                     firefox-i18n-ur               79.0-1               80.0-1
                     firefox-i18n-uz               79.0-1               80.0-1
                     firefox-i18n-vi               79.0-1               80.0-1
                     firefox-i18n-xh               79.0-1               80.0-1
                  firefox-i18n-zh-cn               79.0-1               80.0-1
                  firefox-i18n-zh-tw               79.0-1               80.0-1
                                gvim           8.2.0814-3           8.2.1522-1
                            inkscape                1.0-5                1.0-6
                             ipp-usb             0.9.11-2             0.9.13-1
                              jasper             2.0.17-1             2.0.19-1
                          jasper-doc             2.0.17-1             2.0.19-1
                          kitinerary            20.08.0-1            20.08.0-2
                              libqmi             1.26.2-1             1.26.4-1
                   libreoffice-fresh              7.0.0-1              7.0.0-2
               libreoffice-fresh-sdk              7.0.0-1              7.0.0-2
                   libreoffice-still              6.4.6-1              6.4.6-2
               libreoffice-still-sdk              6.4.6-1              6.4.6-2
                          libsynctex         2020.54586-4         2020.54586-5
                               libuv             1.38.1-1             1.39.0-1
                              libx11             1.6.11-1             1.6.12-1
                  mkinitcpio-archiso                 46-1               47.1-1
                                nasm            2.15.02-1            2.15.04-1
                               nginx             1.18.0-1             1.18.0-2
                           nginx-src             1.18.0-1             1.18.0-2
                        nitrokey-app                1.4-2              1.4.2-1
                               paper                2.0-1                2.1-1
                            pipewire              0.3.8-2             0.3.10-1
                       pipewire-alsa              0.3.8-2             0.3.10-1
                       pipewire-docs              0.3.8-2             0.3.10-1
                       pipewire-jack              0.3.8-2             0.3.10-1
                      pipewire-pulse              0.3.8-2             0.3.10-1
                             poppler             0.90.1-1            20.08.0-1
                        poppler-glib             0.90.1-1            20.08.0-1
                         poppler-qt5             0.90.1-1            20.08.0-1
                          postgresql               12.3-2               12.4-1
                     postgresql-docs               12.3-2               12.4-1
                     postgresql-libs               12.3-2               12.4-1
              postgresql-old-upgrade               11.8-2               11.9-1
               publicsuffix-list 20200106.876.d73f42f-1 20200824.976.43f08e1-1
                        python-attrs             19.3.0-4             20.1.0-1
                        python-isort              5.2.2-1              5.4.2-1
                       python2-attrs             19.3.0-4             20.1.0-1
                                re2c              2.0.2-1              2.0.3-1
                                ruby              2.7.1-2              2.7.1-3
                           ruby-docs              2.7.1-2              2.7.1-3
                              talloc              2.3.1-2              2.3.1-3
                         texlive-bin         2020.54586-4         2020.54586-5
                             tracker              2.3.4-2              2.3.5-1
                      tracker-miners              2.3.3-2              2.3.4-1
                                 vim           8.2.0814-3           8.2.1522-1
                         vim-runtime           8.2.0814-3           8.2.1522-1
                               xterm                358-1                359-1


:: Different overlay package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-23           2020-08-26
-------------------------------------------------------------------------------
                       steam-manjaro           1.0.0.64-1           1.0.0.66-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-23           2020-08-26
-------------------------------------------------------------------------------
                        lib32-amdvlk          2020.Q3.3-1          2020.Q3.4-1
</code></pre>
<div class="poll" data-poll-status="open" data-poll-type="regular" data-poll-name="poll">
<div>
<div class="poll-container">
<ul>
<li data-poll-option-id="893d9543968a33fa1039e2d7c2aff9f3">No issue, everything went smoothly</li>
<li data-poll-option-id="f62cf202dc0ce246aa612290c3f33f1f">Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li data-poll-option-id="e1ee941aacf54cee0c82939acae184cc">Yes i am currently experiencing an issue due to the update. (Please post about it)</li>
</ul>
</div>
<div class="poll-info">
<p>
<span class="info-number">0</span>
<span class="info-label">voters</span>
</p>
</div>
</div>
</div>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
            <p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2020-08-26-firefox-80-corectrl-xorg-server-amdvlk-python-haskell/15331">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-11981]]></title>
<description><![CDATA[An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.]]></description>
<link>https://tsecurity.de/de/1181807/sicherheitsluecken/cve-2020-11981/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1181807/sicherheitsluecken/cve-2020-11981/</guid>
<pubDate>Fri, 17 Jul 2020 07:33:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-11982]]></title>
<description><![CDATA[An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code ex...]]></description>
<link>https://tsecurity.de/de/1181809/sicherheitsluecken/cve-2020-11982/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1181809/sicherheitsluecken/cve-2020-11982/</guid>
<pubDate>Fri, 17 Jul 2020 07:33:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-11972]]></title>
<description><![CDATA[Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.]]></description>
<link>https://tsecurity.de/de/1117203/sicherheitsluecken/cve-2020-11972/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1117203/sicherheitsluecken/cve-2020-11972/</guid>
<pubDate>Thu, 14 May 2020 21:18:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.]]></content:encoded>
</item>
<item>
<title><![CDATA[Solarwinds Orion Platform up to 2018.4 Hotfix 1 RabbitMQ Service privilege escalation]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Solarwinds Orion Platform up to 2018.4 Hotfix 1. This affects some unknown functionality of the component RabbitMQ Service. Applying the patch 2018.4 Hotfix 2 is able to eliminate this problem.]]></description>
<link>https://tsecurity.de/de/1115756/sicherheitsluecken/solarwinds-orion-platform-up-to-20184-hotfix-1-rabbitmq-service-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1115756/sicherheitsluecken/solarwinds-orion-platform-up-to-20184-hotfix-1-rabbitmq-service-privilege-escalation/</guid>
<pubDate>Wed, 13 May 2020 17:03:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as critical has been found in <a href="https://vuldb.com/?product.solarwinds:orion_platform">Solarwinds Orion Platform up to 2018.4 Hotfix 1</a>. This affects some unknown functionality of the component <em>RabbitMQ Service</em>. Applying the patch 2018.4 Hotfix 2 is able to eliminate this problem.]]></content:encoded>
</item>
<item>
<title><![CDATA[Pivotal RabbitMQ Cookie information disclosure [CVE-2018-1279]]]></title>
<description><![CDATA[A vulnerability was found in Pivotal RabbitMQ (the affected version is unknown). It has been declared as problematic. This vulnerability affects some unknown functionality of the component Cookie Handler. There is no information about possible countermeasures known. It may be suggested to replace...]]></description>
<link>https://tsecurity.de/de/1090750/sicherheitsluecken/pivotal-rabbitmq-cookie-information-disclosure-cve-2018-1279/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1090750/sicherheitsluecken/pivotal-rabbitmq-cookie-information-disclosure-cve-2018-1279/</guid>
<pubDate>Sun, 19 Apr 2020 16:17:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.pivotal:rabbitmq">Pivotal RabbitMQ</a> (<a href="https://vuldb.com/?doc.version">the affected version is unknown</a>). It has been declared as problematic. This vulnerability affects some unknown functionality of the component <em>Cookie Handler</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenStack rabbitmq privilege escalation [CVE-2018-14620]]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in OpenStack rabbitmq (Cloud Software) (unknown version). This issue affects some unknown processing. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternat...]]></description>
<link>https://tsecurity.de/de/1061080/sicherheitsluecken/openstack-rabbitmq-privilege-escalation-cve-2018-14620/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1061080/sicherheitsluecken/openstack-rabbitmq-privilege-escalation-cve-2018-14620/</guid>
<pubDate>Sun, 22 Mar 2020 12:32:43 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, has been found in <a href="https://vuldb.com/?product.openstack:rabbitmq">OpenStack rabbitmq</a> (Cloud Software) (<a href="https://vuldb.com/?doc.version">unknown version</a>). This issue affects some unknown processing. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,12ms -->