CNA Duplicates

The CVE program consists of multiple CVE Numbering Authorities (CNA) which feed their data into the stream. Once in a while irregularities happen, like duplicate assignments of CVEs for the same vulnerability. Our moderation team identifies these and lists them here. This helps CVE users to determine them quickly and to handle them properly. In most cases CNAs should detect such a duplicate assignment and reject the later CVE entry.

Vendor

Identifying all affected vendors is a good starting point for an overview. This makes it possible to determine an homogeneous landscape or the most important hotspots in heterogeneous landscapes.

Product

FlatPress4
Tenda AC183
openSUSE libeconf2
TPCMS2
annyshow DuxCMS2

Grouping vulnerabilities by products helps to get an overview. This makes it possible to determine an homogeneous landscape or the most important hotspots in heterogeneous landscapes.

IDVulnerabilityCreatedUpdatedCVEDuplicate
209431Tenda AC15/AC18 PowerSaveSet setSmartPowerManagement stack-based overflow09/23/202203/29/2024CVE-2022-40864CVE-2024-30613
200818Tenda AC18 form_fast_setting_wifi_set stack-based overflow05/26/202203/26/2024CVE-2022-30473CVE-2024-28551
228048Tenda AC18 setUsbUnload command injection05/05/202303/26/2024CVE-2023-30135CVE-2024-28545
252184Byzoro Smart S210 Management Platform uploadfile.php unrestricted upload01/26/202404/09/2024CVE-2024-0939CVE-2024-28520
248374Apache Superset ZIP File resource consumption12/19/202302/14/2024CVE-2023-46104CVE-2024-23952
240326yt-dlp os command injection09/26/202304/09/2024CVE-2023-40581CVE-2024-22423
169663Monitorr upload.php unrestricted upload02/10/202104/25/2024CVE-2020-28871CVE-2024-0713
244080EventPrime Plugin cross-site request forgery10/31/202310/31/2023CVE-2023-4251CVE-2023-5519
239475Google WebP libwebp heap-based overflow09/12/202304/29/2024CVE-2023-4863CVE-2023-5129
191328mingSoft MCMS New Template Module unrestricted upload01/21/202201/16/2024CVE-2022-22929CVE-2023-51282
188960Ajax.NET Professional Javascript Object cross site scripting12/23/202112/05/2023CVE-2021-43853CVE-2023-49289
237404cockpit cross site scripting08/17/202309/13/2023CVE-2023-4395CVE-2023-4433
236213EmpowerID Multi-Factor Authentication Code information disclosure08/05/202308/30/2023CVE-2023-4177CVE-2023-40260
231594Grav special elements used in a template engine06/15/202307/19/2023CVE-2023-34253CVE-2023-37897
241944Elenos ETG150 FM Transmitter resource injection10/11/202311/07/2023CVE-2023-45396CVE-2023-37835
231547OBS-Studio missing encryption06/14/202307/04/2023CVE-2023-34585CVE-2023-36262
232891LangChain Python PALChain code injection07/04/202307/22/2023CVE-2023-36258CVE-2023-36188
232105bishopfox sliver channel accessible06/22/202308/28/2023CVE-2023-34758CVE-2023-35170
231502UJCMS ZIP Package information disclosure06/14/202307/13/2023CVE-2023-3231CVE-2023-34878
230799SourceCodester Service Provider Management System view_service.php sql injection06/06/202306/30/2023CVE-2023-3120CVE-2023-34581
229953PHPOK unrestricted upload05/25/202306/17/2023CVE-2023-2888CVE-2023-33601
232918fastify oauth2 cross-site request forgery07/04/202307/04/2023CVE-2023-35935CVE-2023-31999
227401World Wide Broadcast Network AVideo Video Link os command injection04/25/202307/04/2023CVE-2023-25313CVE-2023-30842
230464openSUSE libeconf Config File buffer overflow06/01/202308/23/2023CVE-2023-22652CVE-2023-30079
230465openSUSE libeconf Configuration File buffer overflow06/01/202308/23/2023CVE-2023-32181CVE-2023-30078
194217pimcore cross site scripting03/04/202205/16/2023CVE-2022-0832CVE-2023-2730
222388ehuacui bbs cross site scripting03/06/202305/13/2023CVE-2023-1200CVE-2023-27089
227684Wangmarket CMS tableView.do sql injection04/28/202305/13/2023CVE-2023-30183CVE-2023-26813
228597XPDF readPageLabelTree2 stack-based overflow05/10/202306/02/2023CVE-2023-31554CVE-2023-2663
216869FlatPress Media Manager Plugin panel.mediamanager.file.php main cross site scripting12/27/202205/13/2023CVE-2022-4755CVE-2023-1107
217001FlatPress Setup main.lib.php cross site scripting12/28/202205/13/2023CVE-2022-4822CVE-2023-1106
216861FlatPress File Delete panel.mediamanager.file.php doItemActions path traversal12/27/202205/13/2023CVE-2022-4748CVE-2023-1105
217000FlatPress XML File Handler/MD File admin.uploader.php onupload cross site scripting12/28/202207/04/2023CVE-2022-4821CVE-2023-1103
220865GitLab Community Edition/Enterprise Edition Issue Description resource consumption02/14/202307/04/2023CVE-2022-3411CVE-2023-0886
227219p7zip Zip.cpp FindCd heap-based overflow04/22/202308/23/2023CVE-2023-1576CVE-2022-47069
196500TPCMS cross site scripting04/05/202205/13/2023CVE-2022-27441CVE-2021-36545
196410TPCMS information disclosure04/05/202205/13/2023CVE-2022-27442CVE-2021-36544
194564Panorama Tools libpano13 parser.c panoParserFindOLine out-of-bounds03/11/202207/08/2023CVE-2021-33293CVE-2021-33798
168743node-red-contrib-huemagic API hue-magic.js res.sendFile path traversal01/27/202108/11/2023CVE-2021-25864CVE-2021-26504
230185Emby Server request smuggling05/30/202306/29/2023CVE-2023-33193CVE-2021-25827
215115annyshow DuxCMS Article edit cross site scripting12/08/202207/31/2023CVE-2020-36609CVE-2020-36763
166829BloofoxCMS Content-Type pathname traversal12/26/202008/11/2023CVE-2020-35709CVE-2020-36082
215116annyshow DuxCMS cross-site request forgery12/08/202207/31/2023CVE-2020-36610CVE-2020-21881
207919Feehi CMS unrestricted upload09/07/202206/20/2023CVE-2020-21516CVE-2020-21489
215909Netgate pf Sense ACME Package acme_certificate_edit.php cross site scripting12/16/202205/13/2023CVE-2020-21219CVE-2020-21487
183507Wuzhi CMS index.php Privilege Escalation09/29/202106/20/2023CVE-2020-20124CVE-2020-21325
182732Feehi CMS unrestricted upload09/16/202106/20/2023CVE-2020-21322CVE-2020-21174
177092ZrLog Admin Panel cross site scripting06/16/202106/20/2023CVE-2020-21316CVE-2020-21052
180811LJCMS move_uploaded_file unrestricted upload08/13/202106/20/2023CVE-2020-20979CVE-2020-20735
183472GilaCMS cross-site request forgery09/28/202106/20/2023CVE-2020-20693CVE-2020-20726

3 more entries are not shown

Want to stay up to date on a daily basis?

Enable the mail alert feature now!