From 2902e1172b123e7bac3df7319bd96f17e76ab610 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 20 Mar 2024 15:33:24 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-f6g6-pjgc-5cj5.json | 58 +++++++++++++++++++ .../GHSA-2647-rch5-5qg9.json | 43 ++++++++++++++ .../GHSA-26p4-rg6r-f676.json | 35 +++++++++++ .../GHSA-27hg-5398-wvrh.json | 35 +++++++++++ .../GHSA-28f4-f5wq-36wr.json | 42 ++++++++++++++ .../GHSA-292v-q449-fgpm.json | 35 +++++++++++ .../GHSA-29pw-vrcf-rqvp.json | 35 +++++++++++ .../GHSA-2ccx-3vjx-pj7f.json | 42 ++++++++++++++ .../GHSA-2jc7-rj7p-gqwv.json | 46 +++++++++++++++ .../GHSA-2m7r-x6hh-8373.json | 46 +++++++++++++++ .../GHSA-324p-3f7r-2rf5.json | 39 +++++++++++++ .../GHSA-32p2-vr3j-c4gw.json | 50 ++++++++++++++++ .../GHSA-3pm4-9c7g-c576.json | 46 +++++++++++++++ .../GHSA-3v58-fff7-9hpf.json | 42 ++++++++++++++ .../GHSA-3w7c-xcfc-fcwc.json | 46 +++++++++++++++ .../GHSA-42mp-pxm4-v723.json | 42 ++++++++++++++ .../GHSA-4835-5c9f-45c7.json | 42 ++++++++++++++ .../GHSA-4855-75hx-mc35.json | 38 ++++++++++++ .../GHSA-4gqf-hq99-2fwr.json | 42 ++++++++++++++ .../GHSA-4hpj-ch92-m6cq.json | 42 ++++++++++++++ .../GHSA-54jw-2926-jvc7.json | 35 +++++++++++ .../GHSA-54rq-qv6g-7g5h.json | 46 +++++++++++++++ .../GHSA-597f-xh85-qc2h.json | 46 +++++++++++++++ .../GHSA-5c2q-g9wc-9gf6.json | 42 ++++++++++++++ .../GHSA-5g2x-f4gh-hcvj.json | 42 ++++++++++++++ .../GHSA-5hgf-whx9-j59m.json | 35 +++++++++++ .../GHSA-5hrr-2wgf-37hj.json | 35 +++++++++++ .../GHSA-5vqc-63mj-rggw.json | 35 +++++++++++ .../GHSA-5w5g-r8w6-wjxw.json | 38 ++++++++++++ .../GHSA-636r-h4xv-42wh.json | 42 ++++++++++++++ .../GHSA-676v-cr2h-h86m.json | 35 +++++++++++ .../GHSA-6g94-9vj8-jm74.json | 46 +++++++++++++++ .../GHSA-6h7g-9qv9-mrpp.json | 46 +++++++++++++++ .../GHSA-76jf-phxv-6m5c.json | 35 +++++++++++ .../GHSA-782v-93vg-549q.json | 46 +++++++++++++++ .../GHSA-7cqc-9qrm-q9vh.json | 42 ++++++++++++++ .../GHSA-7ph5-37r4-fwh8.json | 35 +++++++++++ .../GHSA-7rg9-mm6v-qwrq.json | 35 +++++++++++ .../GHSA-7rm7-qc42-px2v.json | 35 +++++++++++ .../GHSA-7x54-8vhv-9frj.json | 35 +++++++++++ .../GHSA-858p-q38q-g87r.json | 35 +++++++++++ .../GHSA-8f65-fxmq-vvpx.json | 35 +++++++++++ .../GHSA-8jxj-x793-v7xm.json | 35 +++++++++++ .../GHSA-8pxm-658r-r9j2.json | 35 +++++++++++ .../GHSA-8x7g-6cjv-9w4w.json | 39 +++++++++++++ .../GHSA-9424-h2gv-g6wc.json | 46 +++++++++++++++ .../GHSA-95wg-jpqm-5g5h.json | 42 ++++++++++++++ .../GHSA-9gc2-35h9-mhj5.json | 35 +++++++++++ .../GHSA-9h2h-gpqp-6qgg.json | 46 +++++++++++++++ .../GHSA-9p5f-8c7x-7c7j.json | 46 +++++++++++++++ .../GHSA-9v27-xwh4-23q8.json | 35 +++++++++++ .../GHSA-c6qx-hfcq-g673.json | 35 +++++++++++ .../GHSA-c7gv-5x7r-f2g7.json | 35 +++++++++++ .../GHSA-c94c-g2hm-xg4p.json | 46 +++++++++++++++ .../GHSA-cmpj-67j4-5rq7.json | 46 +++++++++++++++ .../GHSA-cr67-8hmx-xg5c.json | 42 ++++++++++++++ .../GHSA-cwwg-grjw-cmp5.json | 35 +++++++++++ .../GHSA-cxqp-32c8-ch8c.json | 38 ++++++++++++ .../GHSA-f6g6-pjgc-5cj5.json | 35 ----------- .../GHSA-fcwm-gx7c-6hgc.json | 35 +++++++++++ .../GHSA-fhff-594f-mqr9.json | 35 +++++++++++ .../GHSA-fp7w-7c45-949q.json | 39 +++++++++++++ .../GHSA-fwx6-53vm-r73w.json | 35 +++++++++++ .../GHSA-g5jh-5qmm-vgjw.json | 46 +++++++++++++++ .../GHSA-g6f3-g3wm-f7p5.json | 35 +++++++++++ .../GHSA-g6gj-xwhj-g7rm.json | 39 +++++++++++++ .../GHSA-g7jh-36w6-x3c4.json | 46 +++++++++++++++ .../GHSA-gm3p-cxxm-phr6.json | 35 +++++++++++ .../GHSA-gwcc-j6r9-59p8.json | 46 +++++++++++++++ .../GHSA-gxjr-v6fw-49mr.json | 42 ++++++++++++++ .../GHSA-h396-qp5c-h728.json | 50 ++++++++++++++++ .../GHSA-h3f7-4pq5-5jqm.json | 38 ++++++++++++ .../GHSA-h5fw-99jv-5c89.json | 35 +++++++++++ .../GHSA-h8c2-5xf3-fx2x.json | 35 +++++++++++ .../GHSA-h8p2-55fh-ggc4.json | 46 +++++++++++++++ .../GHSA-h8v5-8g7h-c9mq.json | 46 +++++++++++++++ .../GHSA-hpmw-vh9j-2pxc.json | 35 +++++++++++ .../GHSA-hqf6-9hf3-qr68.json | 39 +++++++++++++ .../GHSA-hrq6-7x78-h4mh.json | 46 +++++++++++++++ .../GHSA-hvcf-gc35-33ww.json | 46 +++++++++++++++ .../GHSA-j4v2-46x2-2r5q.json | 46 +++++++++++++++ .../GHSA-j6j6-pgrh-8gmh.json | 35 +++++++++++ .../GHSA-j6w7-v73w-6pw3.json | 42 ++++++++++++++ .../GHSA-j9jf-hh2m-m3g7.json | 46 +++++++++++++++ .../GHSA-jh7h-6rpx-g936.json | 42 ++++++++++++++ .../GHSA-jpj7-3cxp-mwxp.json | 39 +++++++++++++ .../GHSA-m2v2-rjrw-p6c5.json | 46 +++++++++++++++ .../GHSA-m8qw-mppg-7364.json | 35 +++++++++++ .../GHSA-mc39-65g2-x85c.json | 46 +++++++++++++++ .../GHSA-mxh6-2xpg-m77w.json | 35 +++++++++++ .../GHSA-p4h9-hj8v-r54m.json | 46 +++++++++++++++ .../GHSA-p94v-hr2q-pvmg.json | 35 +++++++++++ .../GHSA-p97v-hh3c-f8mq.json | 35 +++++++++++ .../GHSA-pcj3-p7wg-9c68.json | 35 +++++++++++ .../GHSA-pm3j-v9mg-55rh.json | 46 +++++++++++++++ .../GHSA-prfm-p99w-7gm2.json | 35 +++++++++++ .../GHSA-q3mq-cvp5-qxcr.json | 35 +++++++++++ .../GHSA-qcc3-2x2p-6v35.json | 35 +++++++++++ .../GHSA-qmw9-5q6h-hjxj.json | 35 +++++++++++ .../GHSA-qq8f-9mh8-5973.json | 46 +++++++++++++++ .../GHSA-r26g-5xh6-pgwp.json | 46 +++++++++++++++ .../GHSA-rf45-g4gv-fh4v.json | 42 ++++++++++++++ .../GHSA-rpqx-wxvq-jh8m.json | 46 +++++++++++++++ .../GHSA-rrf2-65m6-wmqp.json | 35 +++++++++++ .../GHSA-v82h-9xhx-c8hg.json | 38 ++++++++++++ .../GHSA-vcwc-59rg-8254.json | 35 +++++++++++ .../GHSA-vh6v-96hr-r3rq.json | 46 +++++++++++++++ .../GHSA-vhg5-jp6p-2pcw.json | 35 +++++++++++ .../GHSA-vjpg-wm6m-cjg7.json | 42 ++++++++++++++ .../GHSA-vx26-qhj3-h8j2.json | 46 +++++++++++++++ .../GHSA-w853-6hc5-89h2.json | 35 +++++++++++ .../GHSA-whxq-h93c-wvrx.json | 46 +++++++++++++++ .../GHSA-wprm-8qf4-xrc8.json | 46 +++++++++++++++ .../GHSA-ww3j-pv6x-2fh2.json | 46 +++++++++++++++ .../GHSA-wwvg-qmhg-chgp.json | 35 +++++++++++ .../GHSA-x637-x8p3-5p22.json | 38 ++++++++++++ .../GHSA-x99w-3523-r792.json | 42 ++++++++++++++ .../GHSA-xhh5-7x8q-mcj7.json | 46 +++++++++++++++ 118 files changed, 4727 insertions(+), 35 deletions(-) create mode 100644 advisories/github-reviewed/2024/03/GHSA-f6g6-pjgc-5cj5/GHSA-f6g6-pjgc-5cj5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-2647-rch5-5qg9/GHSA-2647-rch5-5qg9.json create mode 100644 advisories/unreviewed/2024/03/GHSA-26p4-rg6r-f676/GHSA-26p4-rg6r-f676.json create mode 100644 advisories/unreviewed/2024/03/GHSA-27hg-5398-wvrh/GHSA-27hg-5398-wvrh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-28f4-f5wq-36wr/GHSA-28f4-f5wq-36wr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-292v-q449-fgpm/GHSA-292v-q449-fgpm.json create mode 100644 advisories/unreviewed/2024/03/GHSA-29pw-vrcf-rqvp/GHSA-29pw-vrcf-rqvp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-2ccx-3vjx-pj7f/GHSA-2ccx-3vjx-pj7f.json create mode 100644 advisories/unreviewed/2024/03/GHSA-2jc7-rj7p-gqwv/GHSA-2jc7-rj7p-gqwv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-2m7r-x6hh-8373/GHSA-2m7r-x6hh-8373.json create mode 100644 advisories/unreviewed/2024/03/GHSA-324p-3f7r-2rf5/GHSA-324p-3f7r-2rf5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-32p2-vr3j-c4gw/GHSA-32p2-vr3j-c4gw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3pm4-9c7g-c576/GHSA-3pm4-9c7g-c576.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3v58-fff7-9hpf/GHSA-3v58-fff7-9hpf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3w7c-xcfc-fcwc/GHSA-3w7c-xcfc-fcwc.json create mode 100644 advisories/unreviewed/2024/03/GHSA-42mp-pxm4-v723/GHSA-42mp-pxm4-v723.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4835-5c9f-45c7/GHSA-4835-5c9f-45c7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4855-75hx-mc35/GHSA-4855-75hx-mc35.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4gqf-hq99-2fwr/GHSA-4gqf-hq99-2fwr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4hpj-ch92-m6cq/GHSA-4hpj-ch92-m6cq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-54jw-2926-jvc7/GHSA-54jw-2926-jvc7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-54rq-qv6g-7g5h/GHSA-54rq-qv6g-7g5h.json create mode 100644 advisories/unreviewed/2024/03/GHSA-597f-xh85-qc2h/GHSA-597f-xh85-qc2h.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5c2q-g9wc-9gf6/GHSA-5c2q-g9wc-9gf6.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5g2x-f4gh-hcvj/GHSA-5g2x-f4gh-hcvj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5hgf-whx9-j59m/GHSA-5hgf-whx9-j59m.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5hrr-2wgf-37hj/GHSA-5hrr-2wgf-37hj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5vqc-63mj-rggw/GHSA-5vqc-63mj-rggw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5w5g-r8w6-wjxw/GHSA-5w5g-r8w6-wjxw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-636r-h4xv-42wh/GHSA-636r-h4xv-42wh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-676v-cr2h-h86m/GHSA-676v-cr2h-h86m.json create mode 100644 advisories/unreviewed/2024/03/GHSA-6g94-9vj8-jm74/GHSA-6g94-9vj8-jm74.json create mode 100644 advisories/unreviewed/2024/03/GHSA-6h7g-9qv9-mrpp/GHSA-6h7g-9qv9-mrpp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-76jf-phxv-6m5c/GHSA-76jf-phxv-6m5c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-782v-93vg-549q/GHSA-782v-93vg-549q.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7cqc-9qrm-q9vh/GHSA-7cqc-9qrm-q9vh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7ph5-37r4-fwh8/GHSA-7ph5-37r4-fwh8.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7rg9-mm6v-qwrq/GHSA-7rg9-mm6v-qwrq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7rm7-qc42-px2v/GHSA-7rm7-qc42-px2v.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7x54-8vhv-9frj/GHSA-7x54-8vhv-9frj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-858p-q38q-g87r/GHSA-858p-q38q-g87r.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8f65-fxmq-vvpx/GHSA-8f65-fxmq-vvpx.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8jxj-x793-v7xm/GHSA-8jxj-x793-v7xm.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8pxm-658r-r9j2/GHSA-8pxm-658r-r9j2.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8x7g-6cjv-9w4w/GHSA-8x7g-6cjv-9w4w.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9424-h2gv-g6wc/GHSA-9424-h2gv-g6wc.json create mode 100644 advisories/unreviewed/2024/03/GHSA-95wg-jpqm-5g5h/GHSA-95wg-jpqm-5g5h.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9gc2-35h9-mhj5/GHSA-9gc2-35h9-mhj5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9h2h-gpqp-6qgg/GHSA-9h2h-gpqp-6qgg.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9p5f-8c7x-7c7j/GHSA-9p5f-8c7x-7c7j.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9v27-xwh4-23q8/GHSA-9v27-xwh4-23q8.json create mode 100644 advisories/unreviewed/2024/03/GHSA-c6qx-hfcq-g673/GHSA-c6qx-hfcq-g673.json create mode 100644 advisories/unreviewed/2024/03/GHSA-c7gv-5x7r-f2g7/GHSA-c7gv-5x7r-f2g7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-c94c-g2hm-xg4p/GHSA-c94c-g2hm-xg4p.json create mode 100644 advisories/unreviewed/2024/03/GHSA-cmpj-67j4-5rq7/GHSA-cmpj-67j4-5rq7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-cr67-8hmx-xg5c/GHSA-cr67-8hmx-xg5c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-cwwg-grjw-cmp5/GHSA-cwwg-grjw-cmp5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-cxqp-32c8-ch8c/GHSA-cxqp-32c8-ch8c.json delete mode 100644 advisories/unreviewed/2024/03/GHSA-f6g6-pjgc-5cj5/GHSA-f6g6-pjgc-5cj5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fcwm-gx7c-6hgc/GHSA-fcwm-gx7c-6hgc.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fhff-594f-mqr9/GHSA-fhff-594f-mqr9.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fp7w-7c45-949q/GHSA-fp7w-7c45-949q.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fwx6-53vm-r73w/GHSA-fwx6-53vm-r73w.json create mode 100644 advisories/unreviewed/2024/03/GHSA-g5jh-5qmm-vgjw/GHSA-g5jh-5qmm-vgjw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-g6f3-g3wm-f7p5/GHSA-g6f3-g3wm-f7p5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-g6gj-xwhj-g7rm/GHSA-g6gj-xwhj-g7rm.json create mode 100644 advisories/unreviewed/2024/03/GHSA-g7jh-36w6-x3c4/GHSA-g7jh-36w6-x3c4.json create mode 100644 advisories/unreviewed/2024/03/GHSA-gm3p-cxxm-phr6/GHSA-gm3p-cxxm-phr6.json create mode 100644 advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json create mode 100644 advisories/unreviewed/2024/03/GHSA-gxjr-v6fw-49mr/GHSA-gxjr-v6fw-49mr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-h396-qp5c-h728/GHSA-h396-qp5c-h728.json create mode 100644 advisories/unreviewed/2024/03/GHSA-h3f7-4pq5-5jqm/GHSA-h3f7-4pq5-5jqm.json create mode 100644 advisories/unreviewed/2024/03/GHSA-h5fw-99jv-5c89/GHSA-h5fw-99jv-5c89.json create mode 100644 advisories/unreviewed/2024/03/GHSA-h8c2-5xf3-fx2x/GHSA-h8c2-5xf3-fx2x.json create mode 100644 advisories/unreviewed/2024/03/GHSA-h8p2-55fh-ggc4/GHSA-h8p2-55fh-ggc4.json create mode 100644 advisories/unreviewed/2024/03/GHSA-h8v5-8g7h-c9mq/GHSA-h8v5-8g7h-c9mq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hpmw-vh9j-2pxc/GHSA-hpmw-vh9j-2pxc.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hqf6-9hf3-qr68/GHSA-hqf6-9hf3-qr68.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hrq6-7x78-h4mh/GHSA-hrq6-7x78-h4mh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hvcf-gc35-33ww/GHSA-hvcf-gc35-33ww.json create mode 100644 advisories/unreviewed/2024/03/GHSA-j4v2-46x2-2r5q/GHSA-j4v2-46x2-2r5q.json create mode 100644 advisories/unreviewed/2024/03/GHSA-j6j6-pgrh-8gmh/GHSA-j6j6-pgrh-8gmh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-j6w7-v73w-6pw3/GHSA-j6w7-v73w-6pw3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-j9jf-hh2m-m3g7/GHSA-j9jf-hh2m-m3g7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-jh7h-6rpx-g936/GHSA-jh7h-6rpx-g936.json create mode 100644 advisories/unreviewed/2024/03/GHSA-jpj7-3cxp-mwxp/GHSA-jpj7-3cxp-mwxp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-m2v2-rjrw-p6c5/GHSA-m2v2-rjrw-p6c5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-m8qw-mppg-7364/GHSA-m8qw-mppg-7364.json create mode 100644 advisories/unreviewed/2024/03/GHSA-mc39-65g2-x85c/GHSA-mc39-65g2-x85c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p4h9-hj8v-r54m/GHSA-p4h9-hj8v-r54m.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p94v-hr2q-pvmg/GHSA-p94v-hr2q-pvmg.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p97v-hh3c-f8mq/GHSA-p97v-hh3c-f8mq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-pcj3-p7wg-9c68/GHSA-pcj3-p7wg-9c68.json create mode 100644 advisories/unreviewed/2024/03/GHSA-pm3j-v9mg-55rh/GHSA-pm3j-v9mg-55rh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json create mode 100644 advisories/unreviewed/2024/03/GHSA-q3mq-cvp5-qxcr/GHSA-q3mq-cvp5-qxcr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qcc3-2x2p-6v35/GHSA-qcc3-2x2p-6v35.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qmw9-5q6h-hjxj/GHSA-qmw9-5q6h-hjxj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qq8f-9mh8-5973/GHSA-qq8f-9mh8-5973.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r26g-5xh6-pgwp/GHSA-r26g-5xh6-pgwp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rf45-g4gv-fh4v/GHSA-rf45-g4gv-fh4v.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rpqx-wxvq-jh8m/GHSA-rpqx-wxvq-jh8m.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rrf2-65m6-wmqp/GHSA-rrf2-65m6-wmqp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-v82h-9xhx-c8hg/GHSA-v82h-9xhx-c8hg.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vcwc-59rg-8254/GHSA-vcwc-59rg-8254.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vh6v-96hr-r3rq/GHSA-vh6v-96hr-r3rq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vhg5-jp6p-2pcw/GHSA-vhg5-jp6p-2pcw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vjpg-wm6m-cjg7/GHSA-vjpg-wm6m-cjg7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vx26-qhj3-h8j2/GHSA-vx26-qhj3-h8j2.json create mode 100644 advisories/unreviewed/2024/03/GHSA-w853-6hc5-89h2/GHSA-w853-6hc5-89h2.json create mode 100644 advisories/unreviewed/2024/03/GHSA-whxq-h93c-wvrx/GHSA-whxq-h93c-wvrx.json create mode 100644 advisories/unreviewed/2024/03/GHSA-wprm-8qf4-xrc8/GHSA-wprm-8qf4-xrc8.json create mode 100644 advisories/unreviewed/2024/03/GHSA-ww3j-pv6x-2fh2/GHSA-ww3j-pv6x-2fh2.json create mode 100644 advisories/unreviewed/2024/03/GHSA-wwvg-qmhg-chgp/GHSA-wwvg-qmhg-chgp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-x637-x8p3-5p22/GHSA-x637-x8p3-5p22.json create mode 100644 advisories/unreviewed/2024/03/GHSA-x99w-3523-r792/GHSA-x99w-3523-r792.json create mode 100644 advisories/unreviewed/2024/03/GHSA-xhh5-7x8q-mcj7/GHSA-xhh5-7x8q-mcj7.json diff --git a/advisories/github-reviewed/2024/03/GHSA-f6g6-pjgc-5cj5/GHSA-f6g6-pjgc-5cj5.json b/advisories/github-reviewed/2024/03/GHSA-f6g6-pjgc-5cj5/GHSA-f6g6-pjgc-5cj5.json new file mode 100644 index 00000000000..d35e55ad402 --- /dev/null +++ b/advisories/github-reviewed/2024/03/GHSA-f6g6-pjgc-5cj5/GHSA-f6g6-pjgc-5cj5.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6g6-pjgc-5cj5", + "modified": "2024-03-20T15:31:47Z", + "published": "2024-03-19T09:30:33Z", + "aliases": [ + "CVE-2024-24683" + ], + "summary": "Improper Input Validation vulnerability in Apache Hop Engine", + "details": "Improper Input Validation vulnerability in Apache Hop Engine. This issue affects Apache Hop Engine: before 2.8.0.\n\nUsers are recommended to upgrade to version 2.8.0, which fixes the issue.\n\nWhen Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly escaped.\nThe variable not properly escaped is the \"id\", which is not directly accessible by users creating pipelines making the risk of exploiting this low.\n\nThis issue only affects users using the Hop Server component and does not directly affect the client.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.hop:hop" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.8.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24683" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/hop" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/ts203zssv1n9qth1wdlhk2bhos3vcq6t" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-03-20T15:31:47Z", + "nvd_published_at": "2024-03-19T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2647-rch5-5qg9/GHSA-2647-rch5-5qg9.json b/advisories/unreviewed/2024/03/GHSA-2647-rch5-5qg9/GHSA-2647-rch5-5qg9.json new file mode 100644 index 00000000000..a7343f05b30 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2647-rch5-5qg9/GHSA-2647-rch5-5qg9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2647-rch5-5qg9", + "modified": "2024-03-20T15:32:58Z", + "published": "2024-03-20T15:32:58Z", + "aliases": [ + "CVE-2024-28735" + ], + "details": "An incorrect access control issue in Unit4 Financials by Coda v.2023Q4 allows a remote attacker to escalate privileges via a crafted script to the change password function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28735" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html" + }, + { + "type": "WEB", + "url": "http://financials.com" + }, + { + "type": "WEB", + "url": "http://unit4.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-26p4-rg6r-f676/GHSA-26p4-rg6r-f676.json b/advisories/unreviewed/2024/03/GHSA-26p4-rg6r-f676/GHSA-26p4-rg6r-f676.json new file mode 100644 index 00000000000..56f8664d45a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-26p4-rg6r-f676/GHSA-26p4-rg6r-f676.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26p4-rg6r-f676", + "modified": "2024-03-20T15:32:46Z", + "published": "2024-03-20T15:32:46Z", + "aliases": [ + "CVE-2024-28583" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the readLine() function when reading images in XPM format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28583" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-27hg-5398-wvrh/GHSA-27hg-5398-wvrh.json b/advisories/unreviewed/2024/03/GHSA-27hg-5398-wvrh/GHSA-27hg-5398-wvrh.json new file mode 100644 index 00000000000..53be3ef221f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-27hg-5398-wvrh/GHSA-27hg-5398-wvrh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27hg-5398-wvrh", + "modified": "2024-03-20T15:32:29Z", + "published": "2024-03-20T15:32:29Z", + "aliases": [ + "CVE-2024-0856" + ], + "details": "The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0856" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/eb383600-0cff-4f24-8127-1fb118f0565a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-28f4-f5wq-36wr/GHSA-28f4-f5wq-36wr.json b/advisories/unreviewed/2024/03/GHSA-28f4-f5wq-36wr/GHSA-28f4-f5wq-36wr.json new file mode 100644 index 00000000000..a531b9307e9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-28f4-f5wq-36wr/GHSA-28f4-f5wq-36wr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28f4-f5wq-36wr", + "modified": "2024-03-20T15:32:28Z", + "published": "2024-03-20T15:32:28Z", + "aliases": [ + "CVE-2024-2384" + ], + "details": "The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and above, to view potentially sensitive information about other users by leveraging their order id", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2384" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3053833%40woocommerce-pos&new=3053833%40woocommerce-pos&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d6b8ba69-aa8b-436f-990c-39e283f5d2f2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-292v-q449-fgpm/GHSA-292v-q449-fgpm.json b/advisories/unreviewed/2024/03/GHSA-292v-q449-fgpm/GHSA-292v-q449-fgpm.json new file mode 100644 index 00000000000..f2de258ef4b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-292v-q449-fgpm/GHSA-292v-q449-fgpm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-292v-q449-fgpm", + "modified": "2024-03-20T15:32:43Z", + "published": "2024-03-20T15:32:43Z", + "aliases": [ + "CVE-2024-28569" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in EXR format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28569" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-29pw-vrcf-rqvp/GHSA-29pw-vrcf-rqvp.json b/advisories/unreviewed/2024/03/GHSA-29pw-vrcf-rqvp/GHSA-29pw-vrcf-rqvp.json new file mode 100644 index 00000000000..fdb89aa8f77 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-29pw-vrcf-rqvp/GHSA-29pw-vrcf-rqvp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29pw-vrcf-rqvp", + "modified": "2024-03-20T15:32:23Z", + "published": "2024-03-20T15:32:23Z", + "aliases": [ + "CVE-2024-28283" + ], + "details": "There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28283" + }, + { + "type": "WEB", + "url": "https://d05004.notion.site/Linksys-E1000-BOF-37b98eec45ea4fc991b9b5bea3db091d?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2ccx-3vjx-pj7f/GHSA-2ccx-3vjx-pj7f.json b/advisories/unreviewed/2024/03/GHSA-2ccx-3vjx-pj7f/GHSA-2ccx-3vjx-pj7f.json new file mode 100644 index 00000000000..5d35e3d2cb8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2ccx-3vjx-pj7f/GHSA-2ccx-3vjx-pj7f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ccx-3vjx-pj7f", + "modified": "2024-03-20T15:32:58Z", + "published": "2024-03-20T15:32:58Z", + "aliases": [ + "CVE-2024-2291" + ], + "details": "\nIn Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2291" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-March-2024" + }, + { + "type": "WEB", + "url": "https://www.progress.com/moveit" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-778" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2jc7-rj7p-gqwv/GHSA-2jc7-rj7p-gqwv.json b/advisories/unreviewed/2024/03/GHSA-2jc7-rj7p-gqwv/GHSA-2jc7-rj7p-gqwv.json new file mode 100644 index 00000000000..0921edc75c3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2jc7-rj7p-gqwv/GHSA-2jc7-rj7p-gqwv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jc7-rj7p-gqwv", + "modified": "2024-03-20T15:32:28Z", + "published": "2024-03-20T15:32:28Z", + "aliases": [ + "CVE-2024-2670" + ], + "details": "A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/vacancy/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257370 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2670" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%203.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257370" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257370" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2m7r-x6hh-8373/GHSA-2m7r-x6hh-8373.json b/advisories/unreviewed/2024/03/GHSA-2m7r-x6hh-8373/GHSA-2m7r-x6hh-8373.json new file mode 100644 index 00000000000..dc47e20ebaa --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2m7r-x6hh-8373/GHSA-2m7r-x6hh-8373.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m7r-x6hh-8373", + "modified": "2024-03-20T15:32:53Z", + "published": "2024-03-20T15:32:53Z", + "aliases": [ + "CVE-2024-2677" + ], + "details": "A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/category/controller.php. The manipulation of the argument CATEGORYID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257377 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2677" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2012.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257377" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257377" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-324p-3f7r-2rf5/GHSA-324p-3f7r-2rf5.json b/advisories/unreviewed/2024/03/GHSA-324p-3f7r-2rf5/GHSA-324p-3f7r-2rf5.json new file mode 100644 index 00000000000..2a6680453a7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-324p-3f7r-2rf5/GHSA-324p-3f7r-2rf5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-324p-3f7r-2rf5", + "modified": "2024-03-20T15:32:21Z", + "published": "2024-03-20T15:32:21Z", + "aliases": [ + "CVE-2024-2169" + ], + "details": "Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2169" + }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/417980" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/417980" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-32p2-vr3j-c4gw/GHSA-32p2-vr3j-c4gw.json b/advisories/unreviewed/2024/03/GHSA-32p2-vr3j-c4gw/GHSA-32p2-vr3j-c4gw.json new file mode 100644 index 00000000000..86895bbaaeb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-32p2-vr3j-c4gw/GHSA-32p2-vr3j-c4gw.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32p2-vr3j-c4gw", + "modified": "2024-03-20T15:32:27Z", + "published": "2024-03-20T15:32:26Z", + "aliases": [ + "CVE-2024-1995" + ], + "details": "The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 4.2.2. This makes it possible for authenticated attackers, with subscrber-level access and above, to retrieve post content that is password protected and/or private.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1995" + }, + { + "type": "WEB", + "url": "https://github.com/inc2734/smart-custom-fields/commit/67cb6d75bd8189668f721dbd2dc7a3036851be1b" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/smart-custom-fields/trunk/classes/fields/class.field-related-posts.php#L78" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3052172%40smart-custom-fields&new=3052172%40smart-custom-fields&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e966a266-4265-4a72-8a50-e872805219a7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3pm4-9c7g-c576/GHSA-3pm4-9c7g-c576.json b/advisories/unreviewed/2024/03/GHSA-3pm4-9c7g-c576/GHSA-3pm4-9c7g-c576.json new file mode 100644 index 00000000000..8f982ebe451 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3pm4-9c7g-c576/GHSA-3pm4-9c7g-c576.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pm4-9c7g-c576", + "modified": "2024-03-20T15:32:54Z", + "published": "2024-03-20T15:32:54Z", + "aliases": [ + "CVE-2024-2687" + ], + "details": "A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/applicants/index.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257387.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2687" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2011.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257387" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3v58-fff7-9hpf/GHSA-3v58-fff7-9hpf.json b/advisories/unreviewed/2024/03/GHSA-3v58-fff7-9hpf/GHSA-3v58-fff7-9hpf.json new file mode 100644 index 00000000000..8d229f617d0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3v58-fff7-9hpf/GHSA-3v58-fff7-9hpf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v58-fff7-9hpf", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2023-35888" + ], + "details": "IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 258375.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35888" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/258375" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7144228" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3w7c-xcfc-fcwc/GHSA-3w7c-xcfc-fcwc.json b/advisories/unreviewed/2024/03/GHSA-3w7c-xcfc-fcwc/GHSA-3w7c-xcfc-fcwc.json new file mode 100644 index 00000000000..c01723f18f1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3w7c-xcfc-fcwc/GHSA-3w7c-xcfc-fcwc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w7c-xcfc-fcwc", + "modified": "2024-03-20T15:32:48Z", + "published": "2024-03-20T15:32:48Z", + "aliases": [ + "CVE-2024-1325" + ], + "details": "The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.3. This is due to missing or incorrect nonce validation on the 'ajax_cancel_review' function. This makes it possible for unauthenticated attackers to reset the site's review count via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1325" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woomotiv/tags/3.4.1/lib/class-backend.php#L495" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/woomotiv" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ca1c1b43-def2-4f9f-b5c7-075ca188f6e7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-42mp-pxm4-v723/GHSA-42mp-pxm4-v723.json b/advisories/unreviewed/2024/03/GHSA-42mp-pxm4-v723/GHSA-42mp-pxm4-v723.json new file mode 100644 index 00000000000..d61834f80c4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-42mp-pxm4-v723/GHSA-42mp-pxm4-v723.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42mp-pxm4-v723", + "modified": "2024-03-20T15:32:49Z", + "published": "2024-03-20T15:32:49Z", + "aliases": [ + "CVE-2024-1711" + ], + "details": "The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1711" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/mediavine-create" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fcc78fa6-a5f0-4f29-ae19-8e783698b19e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4835-5c9f-45c7/GHSA-4835-5c9f-45c7.json b/advisories/unreviewed/2024/03/GHSA-4835-5c9f-45c7/GHSA-4835-5c9f-45c7.json new file mode 100644 index 00000000000..56de3d6d87d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4835-5c9f-45c7/GHSA-4835-5c9f-45c7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4835-5c9f-45c7", + "modified": "2024-03-20T15:32:52Z", + "published": "2024-03-20T15:32:52Z", + "aliases": [ + "CVE-2024-2304" + ], + "details": "The Animated Headline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animated-headline' shortcode in all versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2304" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/animated-headline" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6f589b5d-9cdb-4521-bc60-c8f19d0ef982?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4855-75hx-mc35/GHSA-4855-75hx-mc35.json b/advisories/unreviewed/2024/03/GHSA-4855-75hx-mc35/GHSA-4855-75hx-mc35.json new file mode 100644 index 00000000000..53630257dba --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4855-75hx-mc35/GHSA-4855-75hx-mc35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4855-75hx-mc35", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2023-52229" + ], + "details": "Missing Authorization vulnerability in Save as PDF plugin by Pdfcrowd Word Replacer Pro.This issue affects Word Replacer Pro: from n/a through 1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52229" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/word-replacer-ultra/wordpress-word-replacer-pro-plugin-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4gqf-hq99-2fwr/GHSA-4gqf-hq99-2fwr.json b/advisories/unreviewed/2024/03/GHSA-4gqf-hq99-2fwr/GHSA-4gqf-hq99-2fwr.json new file mode 100644 index 00000000000..c3bdf688303 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4gqf-hq99-2fwr/GHSA-4gqf-hq99-2fwr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gqf-hq99-2fwr", + "modified": "2024-03-20T15:32:48Z", + "published": "2024-03-20T15:32:48Z", + "aliases": [ + "CVE-2024-1379" + ], + "details": "The Website Article Monetization By MageNet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'abp_auth_key' parameter in all versions up to, and including, 1.0.11 due to insufficient input sanitization and output escaping and a missing authorization check. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1379" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/website-article-monetization-by-magenet/trunk/admin/article-backlinks-admin.php#L110" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b8564dbb-6be8-4999-be65-d28609e05451?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4hpj-ch92-m6cq/GHSA-4hpj-ch92-m6cq.json b/advisories/unreviewed/2024/03/GHSA-4hpj-ch92-m6cq/GHSA-4hpj-ch92-m6cq.json new file mode 100644 index 00000000000..0853e6541fb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4hpj-ch92-m6cq/GHSA-4hpj-ch92-m6cq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hpj-ch92-m6cq", + "modified": "2024-03-20T15:32:33Z", + "published": "2024-03-20T15:32:33Z", + "aliases": [ + "CVE-2024-2474" + ], + "details": "The Standout Color Boxes and Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'color-button' shortcode in all versions up to, and including, 0.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2474" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/standout-color-boxes-and-buttons" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a826dff8-60ae-4e25-9d3e-be93f192aaca?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-54jw-2926-jvc7/GHSA-54jw-2926-jvc7.json b/advisories/unreviewed/2024/03/GHSA-54jw-2926-jvc7/GHSA-54jw-2926-jvc7.json new file mode 100644 index 00000000000..49a35ea9273 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-54jw-2926-jvc7/GHSA-54jw-2926-jvc7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54jw-2926-jvc7", + "modified": "2024-03-20T15:32:43Z", + "published": "2024-03-20T15:32:43Z", + "aliases": [ + "CVE-2024-28570" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the processMakerNote() function when reading images in JPEG format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28570" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-54rq-qv6g-7g5h/GHSA-54rq-qv6g-7g5h.json b/advisories/unreviewed/2024/03/GHSA-54rq-qv6g-7g5h/GHSA-54rq-qv6g-7g5h.json new file mode 100644 index 00000000000..e548b3c721d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-54rq-qv6g-7g5h/GHSA-54rq-qv6g-7g5h.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54rq-qv6g-7g5h", + "modified": "2024-03-20T15:32:47Z", + "published": "2024-03-20T15:32:47Z", + "aliases": [ + "CVE-2024-1119" + ], + "details": "The Order Tip for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_tips_to_csv() function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to export the plugin's order fees.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1119" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/order-tip-woo/trunk/admin/controllers/reports.class.php#L359" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3052259%40order-tip-woo&new=3052259%40order-tip-woo&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6f837d6b-d1fa-4019-892a-dca3c0f29ca7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-597f-xh85-qc2h/GHSA-597f-xh85-qc2h.json b/advisories/unreviewed/2024/03/GHSA-597f-xh85-qc2h/GHSA-597f-xh85-qc2h.json new file mode 100644 index 00000000000..9718b5ba8c4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-597f-xh85-qc2h/GHSA-597f-xh85-qc2h.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-597f-xh85-qc2h", + "modified": "2024-03-20T15:32:47Z", + "published": "2024-03-20T15:32:47Z", + "aliases": [ + "CVE-2024-2538" + ], + "details": "The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_permalink' function in all versions up to, and including, 2.4.3.1. This makes it possible for authenticated attackers, with author access and above, to modify the permalinks of arbitrary posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2538" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/b1eec00e844932c6f2f30a63024b404e" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3052848#file35" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/70cd028d-122d-4e3c-ac09-150dec07a2cd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5c2q-g9wc-9gf6/GHSA-5c2q-g9wc-9gf6.json b/advisories/unreviewed/2024/03/GHSA-5c2q-g9wc-9gf6/GHSA-5c2q-g9wc-9gf6.json new file mode 100644 index 00000000000..a14b3b0b95e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5c2q-g9wc-9gf6/GHSA-5c2q-g9wc-9gf6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c2q-g9wc-9gf6", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2024-1801" + ], + "details": "\nIn Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1801" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/reporting/knowledge-base/deserialization-vulnerability-cve-2024-1801-cve-2024-1856" + }, + { + "type": "WEB", + "url": "https://www.telerik.com/products/reporting.aspx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5g2x-f4gh-hcvj/GHSA-5g2x-f4gh-hcvj.json b/advisories/unreviewed/2024/03/GHSA-5g2x-f4gh-hcvj/GHSA-5g2x-f4gh-hcvj.json new file mode 100644 index 00000000000..e5d86fa9ccb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5g2x-f4gh-hcvj/GHSA-5g2x-f4gh-hcvj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g2x-f4gh-hcvj", + "modified": "2024-03-20T15:32:48Z", + "published": "2024-03-20T15:32:48Z", + "aliases": [ + "CVE-2024-1473" + ], + "details": "The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page contents via REST API thus bypassing maintenance mode protection provided by the plugin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1473" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/colorlib-coming-soon-maintenance" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/48dc10a9-7bb9-401f-befd-1bf620858825?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5hgf-whx9-j59m/GHSA-5hgf-whx9-j59m.json b/advisories/unreviewed/2024/03/GHSA-5hgf-whx9-j59m/GHSA-5hgf-whx9-j59m.json new file mode 100644 index 00000000000..6db18c4410e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5hgf-whx9-j59m/GHSA-5hgf-whx9-j59m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hgf-whx9-j59m", + "modified": "2024-03-20T15:32:45Z", + "published": "2024-03-20T15:32:45Z", + "aliases": [ + "CVE-2024-28576" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_tcp_destroy() function when reading images in J2K format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28576" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5hrr-2wgf-37hj/GHSA-5hrr-2wgf-37hj.json b/advisories/unreviewed/2024/03/GHSA-5hrr-2wgf-37hj/GHSA-5hrr-2wgf-37hj.json new file mode 100644 index 00000000000..745d8301b24 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5hrr-2wgf-37hj/GHSA-5hrr-2wgf-37hj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hrr-2wgf-37hj", + "modified": "2024-03-20T15:32:38Z", + "published": "2024-03-20T15:32:38Z", + "aliases": [ + "CVE-2024-28562" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::copyIntoFrameBuffer() component when reading images in EXR format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28562" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5vqc-63mj-rggw/GHSA-5vqc-63mj-rggw.json b/advisories/unreviewed/2024/03/GHSA-5vqc-63mj-rggw/GHSA-5vqc-63mj-rggw.json new file mode 100644 index 00000000000..149c873cb54 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5vqc-63mj-rggw/GHSA-5vqc-63mj-rggw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vqc-63mj-rggw", + "modified": "2024-03-20T15:32:46Z", + "published": "2024-03-20T15:32:46Z", + "aliases": [ + "CVE-2024-28581" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28581" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5w5g-r8w6-wjxw/GHSA-5w5g-r8w6-wjxw.json b/advisories/unreviewed/2024/03/GHSA-5w5g-r8w6-wjxw/GHSA-5w5g-r8w6-wjxw.json new file mode 100644 index 00000000000..7aa08ffdb90 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5w5g-r8w6-wjxw/GHSA-5w5g-r8w6-wjxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w5g-r8w6-wjxw", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2024-1811" + ], + "details": "A potential vulnerability has been identified in OpenText ArcSight Platform. The vulnerability could be remotely exploited.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1811" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000027383" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-636r-h4xv-42wh/GHSA-636r-h4xv-42wh.json b/advisories/unreviewed/2024/03/GHSA-636r-h4xv-42wh/GHSA-636r-h4xv-42wh.json new file mode 100644 index 00000000000..aef9154599f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-636r-h4xv-42wh/GHSA-636r-h4xv-42wh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-636r-h4xv-42wh", + "modified": "2024-03-20T15:32:26Z", + "published": "2024-03-20T15:32:26Z", + "aliases": [ + "CVE-2024-1787" + ], + "details": "The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'update_rewards_fuel_api_key' parameter in all versions up to, and including, 2.0.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1787" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3051990%40contests-from-rewards-fuel&new=3051990%40contests-from-rewards-fuel&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9eeec949-e440-4df3-8c26-db92498cada3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-676v-cr2h-h86m/GHSA-676v-cr2h-h86m.json b/advisories/unreviewed/2024/03/GHSA-676v-cr2h-h86m/GHSA-676v-cr2h-h86m.json new file mode 100644 index 00000000000..6aff876dfdb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-676v-cr2h-h86m/GHSA-676v-cr2h-h86m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-676v-cr2h-h86m", + "modified": "2024-03-20T15:32:30Z", + "published": "2024-03-20T15:32:30Z", + "aliases": [ + "CVE-2024-22080" + ], + "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur during XML body parsing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22080" + }, + { + "type": "WEB", + "url": "https://www.elspec-ltd.com/support/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6g94-9vj8-jm74/GHSA-6g94-9vj8-jm74.json b/advisories/unreviewed/2024/03/GHSA-6g94-9vj8-jm74/GHSA-6g94-9vj8-jm74.json new file mode 100644 index 00000000000..86836ba8aa5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6g94-9vj8-jm74/GHSA-6g94-9vj8-jm74.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g94-9vj8-jm74", + "modified": "2024-03-20T15:32:32Z", + "published": "2024-03-20T15:32:32Z", + "aliases": [ + "CVE-2024-2124" + ], + "details": "The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 4.2.5 due to insufficient input sanitization and output escaping on user supplied attributes such as 'className'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2124" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/weglot/trunk/src/actions/class-register-widget-weglot.php#L53" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3051523%40weglot&new=3051523%40weglot&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d87134e8-9d73-4a39-b071-37a5dac033b4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6h7g-9qv9-mrpp/GHSA-6h7g-9qv9-mrpp.json b/advisories/unreviewed/2024/03/GHSA-6h7g-9qv9-mrpp/GHSA-6h7g-9qv9-mrpp.json new file mode 100644 index 00000000000..82469ee9a6a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6h7g-9qv9-mrpp/GHSA-6h7g-9qv9-mrpp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h7g-9qv9-mrpp", + "modified": "2024-03-20T15:32:47Z", + "published": "2024-03-20T15:32:47Z", + "aliases": [ + "CVE-2024-2675" + ], + "details": "A vulnerability, which was classified as critical, has been found in Campcodes Online Job Finder System 1.0. This issue affects some unknown processing of the file /admin/company/index.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257375.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2675" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%208.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257375" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257375" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-76jf-phxv-6m5c/GHSA-76jf-phxv-6m5c.json b/advisories/unreviewed/2024/03/GHSA-76jf-phxv-6m5c/GHSA-76jf-phxv-6m5c.json new file mode 100644 index 00000000000..2e18ef60941 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-76jf-phxv-6m5c/GHSA-76jf-phxv-6m5c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76jf-phxv-6m5c", + "modified": "2024-03-20T15:32:32Z", + "published": "2024-03-20T15:32:32Z", + "aliases": [ + "CVE-2024-22085" + ], + "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22085" + }, + { + "type": "WEB", + "url": "https://www.elspec-ltd.com/support/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-782v-93vg-549q/GHSA-782v-93vg-549q.json b/advisories/unreviewed/2024/03/GHSA-782v-93vg-549q/GHSA-782v-93vg-549q.json new file mode 100644 index 00000000000..09d07612e2b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-782v-93vg-549q/GHSA-782v-93vg-549q.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-782v-93vg-549q", + "modified": "2024-03-20T15:32:27Z", + "published": "2024-03-20T15:32:27Z", + "aliases": [ + "CVE-2024-2668" + ], + "details": "A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/vacancy/controller.php. The manipulation of the argument id/CATEGORY leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257368.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2668" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2010.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257368" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257368" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7cqc-9qrm-q9vh/GHSA-7cqc-9qrm-q9vh.json b/advisories/unreviewed/2024/03/GHSA-7cqc-9qrm-q9vh/GHSA-7cqc-9qrm-q9vh.json new file mode 100644 index 00000000000..68fc21e2fa9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7cqc-9qrm-q9vh/GHSA-7cqc-9qrm-q9vh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cqc-9qrm-q9vh", + "modified": "2024-03-20T15:32:52Z", + "published": "2024-03-20T15:32:52Z", + "aliases": [ + "CVE-2024-2459" + ], + "details": "The UX Flat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2459" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/ux-flat" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1d93db2c-7baf-42d8-9b4a-be91b27221a7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7ph5-37r4-fwh8/GHSA-7ph5-37r4-fwh8.json b/advisories/unreviewed/2024/03/GHSA-7ph5-37r4-fwh8/GHSA-7ph5-37r4-fwh8.json new file mode 100644 index 00000000000..dfdd0ad21eb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7ph5-37r4-fwh8/GHSA-7ph5-37r4-fwh8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ph5-37r4-fwh8", + "modified": "2024-03-20T15:32:29Z", + "published": "2024-03-20T15:32:29Z", + "aliases": [ + "CVE-2024-0337" + ], + "details": "The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0337" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2f17a274-8676-4f4e-989f-436030527890" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7rg9-mm6v-qwrq/GHSA-7rg9-mm6v-qwrq.json b/advisories/unreviewed/2024/03/GHSA-7rg9-mm6v-qwrq/GHSA-7rg9-mm6v-qwrq.json new file mode 100644 index 00000000000..d7ce3a180ec --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7rg9-mm6v-qwrq/GHSA-7rg9-mm6v-qwrq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rg9-mm6v-qwrq", + "modified": "2024-03-20T15:32:43Z", + "published": "2024-03-20T15:32:43Z", + "aliases": [ + "CVE-2024-28567" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImage_CreateICCProfile() function when reading images in TIFF format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28567" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7rm7-qc42-px2v/GHSA-7rm7-qc42-px2v.json b/advisories/unreviewed/2024/03/GHSA-7rm7-qc42-px2v/GHSA-7rm7-qc42-px2v.json new file mode 100644 index 00000000000..e15e833d60f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7rm7-qc42-px2v/GHSA-7rm7-qc42-px2v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rm7-qc42-px2v", + "modified": "2024-03-20T15:32:23Z", + "published": "2024-03-20T15:32:23Z", + "aliases": [ + "CVE-2024-28389" + ], + "details": "SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28389" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2024/03/12/spinwheel.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7x54-8vhv-9frj/GHSA-7x54-8vhv-9frj.json b/advisories/unreviewed/2024/03/GHSA-7x54-8vhv-9frj/GHSA-7x54-8vhv-9frj.json new file mode 100644 index 00000000000..23025fbd322 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7x54-8vhv-9frj/GHSA-7x54-8vhv-9frj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x54-8vhv-9frj", + "modified": "2024-03-20T15:32:30Z", + "published": "2024-03-20T15:32:30Z", + "aliases": [ + "CVE-2024-22078" + ], + "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22078" + }, + { + "type": "WEB", + "url": "https://www.elspec-ltd.com/support/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-858p-q38q-g87r/GHSA-858p-q38q-g87r.json b/advisories/unreviewed/2024/03/GHSA-858p-q38q-g87r/GHSA-858p-q38q-g87r.json new file mode 100644 index 00000000000..43031010581 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-858p-q38q-g87r/GHSA-858p-q38q-g87r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-858p-q38q-g87r", + "modified": "2024-03-20T15:32:56Z", + "published": "2024-03-20T15:32:56Z", + "aliases": [ + "CVE-2023-46840" + ], + "details": "Incorrect placement of a preprocessor directive in source code results\nin logic that doesn't operate as intended when support for HVM guests is\ncompiled out of Xen.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46840" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-450.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8f65-fxmq-vvpx/GHSA-8f65-fxmq-vvpx.json b/advisories/unreviewed/2024/03/GHSA-8f65-fxmq-vvpx/GHSA-8f65-fxmq-vvpx.json new file mode 100644 index 00000000000..5eb1f9ce10d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8f65-fxmq-vvpx/GHSA-8f65-fxmq-vvpx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f65-fxmq-vvpx", + "modified": "2024-03-20T15:32:56Z", + "published": "2024-03-20T15:32:56Z", + "aliases": [ + "CVE-2023-46839" + ], + "details": "PCI devices can make use of a functionality called phantom functions,\nthat when enabled allows the device to generate requests using the IDs\nof functions that are otherwise unpopulated. This allows a device to\nextend the number of outstanding requests.\n\nSuch phantom functions need an IOMMU context setup, but failure to\nsetup the context is not fatal when the device is assigned. Not\nfailing device assignment when such failure happens can lead to the\nprimary device being assigned to a guest, while some of the phantom\nfunctions are assigned to a different domain.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46839" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-449.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8jxj-x793-v7xm/GHSA-8jxj-x793-v7xm.json b/advisories/unreviewed/2024/03/GHSA-8jxj-x793-v7xm/GHSA-8jxj-x793-v7xm.json new file mode 100644 index 00000000000..c1f5d94c912 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8jxj-x793-v7xm/GHSA-8jxj-x793-v7xm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jxj-x793-v7xm", + "modified": "2024-03-20T15:32:45Z", + "published": "2024-03-20T15:32:45Z", + "aliases": [ + "CVE-2024-28577" + ], + "details": "Null Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the jpeg_read_exif_profile_raw() function when reading images in JPEG format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28577" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8pxm-658r-r9j2/GHSA-8pxm-658r-r9j2.json b/advisories/unreviewed/2024/03/GHSA-8pxm-658r-r9j2/GHSA-8pxm-658r-r9j2.json new file mode 100644 index 00000000000..7b9d257271d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8pxm-658r-r9j2/GHSA-8pxm-658r-r9j2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pxm-658r-r9j2", + "modified": "2024-03-20T15:32:30Z", + "published": "2024-03-20T15:32:30Z", + "aliases": [ + "CVE-2024-22081" + ], + "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22081" + }, + { + "type": "WEB", + "url": "https://www.elspec-ltd.com/support/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8x7g-6cjv-9w4w/GHSA-8x7g-6cjv-9w4w.json b/advisories/unreviewed/2024/03/GHSA-8x7g-6cjv-9w4w/GHSA-8x7g-6cjv-9w4w.json new file mode 100644 index 00000000000..56c77403b06 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8x7g-6cjv-9w4w/GHSA-8x7g-6cjv-9w4w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x7g-6cjv-9w4w", + "modified": "2024-03-20T15:32:21Z", + "published": "2024-03-20T15:32:21Z", + "aliases": [ + "CVE-2024-28394" + ], + "details": "An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28394" + }, + { + "type": "WEB", + "url": "https://addons.prestashop.com/en/customer-administration/28379-sales-reports-statistics-custom-fields-export.html" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2024/03/14/reportsstatistics.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9424-h2gv-g6wc/GHSA-9424-h2gv-g6wc.json b/advisories/unreviewed/2024/03/GHSA-9424-h2gv-g6wc/GHSA-9424-h2gv-g6wc.json new file mode 100644 index 00000000000..ab09f432161 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9424-h2gv-g6wc/GHSA-9424-h2gv-g6wc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9424-h2gv-g6wc", + "modified": "2024-03-20T15:32:54Z", + "published": "2024-03-20T15:32:54Z", + "aliases": [ + "CVE-2024-2686" + ], + "details": "A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/applicants/controller.php. The manipulation of the argument JOBREGID leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257386 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2686" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2021.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257386" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-95wg-jpqm-5g5h/GHSA-95wg-jpqm-5g5h.json b/advisories/unreviewed/2024/03/GHSA-95wg-jpqm-5g5h/GHSA-95wg-jpqm-5g5h.json new file mode 100644 index 00000000000..48cfeacabe3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-95wg-jpqm-5g5h/GHSA-95wg-jpqm-5g5h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95wg-jpqm-5g5h", + "modified": "2024-03-20T15:32:49Z", + "published": "2024-03-20T15:32:49Z", + "aliases": [ + "CVE-2024-1477" + ], + "details": "The Easy Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the REST API. This makes it possible for authenticated attackers to obtain post and page content via REST API thus bypassign the protection provided by the plugin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1477" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/easy-maintenance-mode-coming-soon" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1a12f472-0ae1-4c3c-b7e3-85f637fe58c5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9gc2-35h9-mhj5/GHSA-9gc2-35h9-mhj5.json b/advisories/unreviewed/2024/03/GHSA-9gc2-35h9-mhj5/GHSA-9gc2-35h9-mhj5.json new file mode 100644 index 00000000000..eee23a09544 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9gc2-35h9-mhj5/GHSA-9gc2-35h9-mhj5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gc2-35h9-mhj5", + "modified": "2024-03-20T15:32:45Z", + "published": "2024-03-20T15:32:45Z", + "aliases": [ + "CVE-2024-28575" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_read_mct() function when reading images in J2K format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28575" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9h2h-gpqp-6qgg/GHSA-9h2h-gpqp-6qgg.json b/advisories/unreviewed/2024/03/GHSA-9h2h-gpqp-6qgg/GHSA-9h2h-gpqp-6qgg.json new file mode 100644 index 00000000000..f52aa15691a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9h2h-gpqp-6qgg/GHSA-9h2h-gpqp-6qgg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h2h-gpqp-6qgg", + "modified": "2024-03-20T15:32:28Z", + "published": "2024-03-20T15:32:28Z", + "aliases": [ + "CVE-2024-2255" + ], + "details": "The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.5.2 due to insufficient input sanitization and output escaping on user supplied attributes such as listStyle. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2255" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/essential-blocks/tags/4.5.2/blocks/TableOfContents.php#L120" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3053199/essential-blocks/trunk/blocks/TableOfContents.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cfcd59ae-085f-47d2-a4d2-2d1239f035d2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9p5f-8c7x-7c7j/GHSA-9p5f-8c7x-7c7j.json b/advisories/unreviewed/2024/03/GHSA-9p5f-8c7x-7c7j/GHSA-9p5f-8c7x-7c7j.json new file mode 100644 index 00000000000..bad4dafb848 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9p5f-8c7x-7c7j/GHSA-9p5f-8c7x-7c7j.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p5f-8c7x-7c7j", + "modified": "2024-03-20T15:32:56Z", + "published": "2024-03-20T15:32:56Z", + "aliases": [ + "CVE-2024-2690" + ], + "details": "A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been classified as critical. Affected is an unknown function of the file /uupdate.php. The manipulation of the argument ima leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257388.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2690" + }, + { + "type": "WEB", + "url": "https://github.com/wkeyi0x1/vul-report/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257388" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257388" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9v27-xwh4-23q8/GHSA-9v27-xwh4-23q8.json b/advisories/unreviewed/2024/03/GHSA-9v27-xwh4-23q8/GHSA-9v27-xwh4-23q8.json new file mode 100644 index 00000000000..eff2732757d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9v27-xwh4-23q8/GHSA-9v27-xwh4-23q8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v27-xwh4-23q8", + "modified": "2024-03-20T15:32:23Z", + "published": "2024-03-20T15:32:23Z", + "aliases": [ + "CVE-2024-28715" + ], + "details": "Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28715" + }, + { + "type": "WEB", + "url": "https://github.com/Lq0ne/CVE-2024-28715" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c6qx-hfcq-g673/GHSA-c6qx-hfcq-g673.json b/advisories/unreviewed/2024/03/GHSA-c6qx-hfcq-g673/GHSA-c6qx-hfcq-g673.json new file mode 100644 index 00000000000..5281fd75b89 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c6qx-hfcq-g673/GHSA-c6qx-hfcq-g673.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6qx-hfcq-g673", + "modified": "2024-03-20T15:32:47Z", + "published": "2024-03-20T15:32:47Z", + "aliases": [ + "CVE-2024-28584" + ], + "details": "Null Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the J2KImageToFIBITMAP() function when reading images in J2K format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28584" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c7gv-5x7r-f2g7/GHSA-c7gv-5x7r-f2g7.json b/advisories/unreviewed/2024/03/GHSA-c7gv-5x7r-f2g7/GHSA-c7gv-5x7r-f2g7.json new file mode 100644 index 00000000000..6d83d139a5b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c7gv-5x7r-f2g7/GHSA-c7gv-5x7r-f2g7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7gv-5x7r-f2g7", + "modified": "2024-03-20T15:32:43Z", + "published": "2024-03-20T15:32:43Z", + "aliases": [ + "CVE-2024-28568" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the read_iptc_profile() function when reading images in TIFF format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28568" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c94c-g2hm-xg4p/GHSA-c94c-g2hm-xg4p.json b/advisories/unreviewed/2024/03/GHSA-c94c-g2hm-xg4p/GHSA-c94c-g2hm-xg4p.json new file mode 100644 index 00000000000..1c79a15702c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c94c-g2hm-xg4p/GHSA-c94c-g2hm-xg4p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c94c-g2hm-xg4p", + "modified": "2024-03-20T15:32:25Z", + "published": "2024-03-20T15:32:25Z", + "aliases": [ + "CVE-2024-2648" + ], + "details": "A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /nac/naccheck.php. The manipulation of the argument username leads to improper neutralization of data within xpath expressions. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257286 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2648" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-naccheck.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257286" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257286" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-643" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cmpj-67j4-5rq7/GHSA-cmpj-67j4-5rq7.json b/advisories/unreviewed/2024/03/GHSA-cmpj-67j4-5rq7/GHSA-cmpj-67j4-5rq7.json new file mode 100644 index 00000000000..a0a1c000e7e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cmpj-67j4-5rq7/GHSA-cmpj-67j4-5rq7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmpj-67j4-5rq7", + "modified": "2024-03-20T15:32:53Z", + "published": "2024-03-20T15:32:53Z", + "aliases": [ + "CVE-2024-2678" + ], + "details": "A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/applicants/controller.php. The manipulation of the argument JOBREGID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257378 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2678" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2013.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257378" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257378" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cr67-8hmx-xg5c/GHSA-cr67-8hmx-xg5c.json b/advisories/unreviewed/2024/03/GHSA-cr67-8hmx-xg5c/GHSA-cr67-8hmx-xg5c.json new file mode 100644 index 00000000000..8e29aedbef7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cr67-8hmx-xg5c/GHSA-cr67-8hmx-xg5c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr67-8hmx-xg5c", + "modified": "2024-03-20T15:32:28Z", + "published": "2024-03-20T15:32:28Z", + "aliases": [ + "CVE-2024-1799" + ], + "details": "The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to SQL Injection via the 'achievement_types' attribute of the gamipress_earnings shortcode in all versions up to, and including, 6.8.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1799" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3051688%40gamipress&new=3051688%40gamipress&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f357fe2a-aa24-42cd-ac2c-c948e18a4710?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cwwg-grjw-cmp5/GHSA-cwwg-grjw-cmp5.json b/advisories/unreviewed/2024/03/GHSA-cwwg-grjw-cmp5/GHSA-cwwg-grjw-cmp5.json new file mode 100644 index 00000000000..eefe31feae3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cwwg-grjw-cmp5/GHSA-cwwg-grjw-cmp5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwwg-grjw-cmp5", + "modified": "2024-03-20T15:32:29Z", + "published": "2024-03-20T15:32:29Z", + "aliases": [ + "CVE-2024-22077" + ], + "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22077" + }, + { + "type": "WEB", + "url": "https://www.elspec-ltd.com/support/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cxqp-32c8-ch8c/GHSA-cxqp-32c8-ch8c.json b/advisories/unreviewed/2024/03/GHSA-cxqp-32c8-ch8c/GHSA-cxqp-32c8-ch8c.json new file mode 100644 index 00000000000..3837a492958 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cxqp-32c8-ch8c/GHSA-cxqp-32c8-ch8c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxqp-32c8-ch8c", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2024-2721" + ], + "details": "Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2721" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/social-media-builder/wordpress-social-media-share-buttons-plugin-2-1-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f6g6-pjgc-5cj5/GHSA-f6g6-pjgc-5cj5.json b/advisories/unreviewed/2024/03/GHSA-f6g6-pjgc-5cj5/GHSA-f6g6-pjgc-5cj5.json deleted file mode 100644 index ed8b940e854..00000000000 --- a/advisories/unreviewed/2024/03/GHSA-f6g6-pjgc-5cj5/GHSA-f6g6-pjgc-5cj5.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-f6g6-pjgc-5cj5", - "modified": "2024-03-19T09:30:33Z", - "published": "2024-03-19T09:30:33Z", - "aliases": [ - "CVE-2024-24683" - ], - "details": "Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0.\n\nUsers are recommended to upgrade to version 2.8.0, which fixes the issue.\n\nWhen Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly escaped.\nThe variable not properly escaped is the \"id\", which is not directly accessible by users creating pipelines making the risk of exploiting this low.\n\nThis issue only affects users using the Hop Server component and does not directly affect the client.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24683" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread/ts203zssv1n9qth1wdlhk2bhos3vcq6t" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-20" - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-03-19T09:15:06Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fcwm-gx7c-6hgc/GHSA-fcwm-gx7c-6hgc.json b/advisories/unreviewed/2024/03/GHSA-fcwm-gx7c-6hgc/GHSA-fcwm-gx7c-6hgc.json new file mode 100644 index 00000000000..1769bf39f6b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fcwm-gx7c-6hgc/GHSA-fcwm-gx7c-6hgc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcwm-gx7c-6hgc", + "modified": "2024-03-20T15:32:46Z", + "published": "2024-03-20T15:32:46Z", + "aliases": [ + "CVE-2024-28580" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28580" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fhff-594f-mqr9/GHSA-fhff-594f-mqr9.json b/advisories/unreviewed/2024/03/GHSA-fhff-594f-mqr9/GHSA-fhff-594f-mqr9.json new file mode 100644 index 00000000000..d2c8aed78fa --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fhff-594f-mqr9/GHSA-fhff-594f-mqr9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhff-594f-mqr9", + "modified": "2024-03-20T15:32:38Z", + "published": "2024-03-20T15:32:38Z", + "aliases": [ + "CVE-2024-28564" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::CharPtrIO::readChars() function when reading images in EXR format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28564" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fp7w-7c45-949q/GHSA-fp7w-7c45-949q.json b/advisories/unreviewed/2024/03/GHSA-fp7w-7c45-949q/GHSA-fp7w-7c45-949q.json new file mode 100644 index 00000000000..417abb9cafd --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fp7w-7c45-949q/GHSA-fp7w-7c45-949q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp7w-7c45-949q", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2024-28392" + ], + "details": "SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28392" + }, + { + "type": "WEB", + "url": "https://addons.prestashop.com/en/remarketing-shopping-cart-abandonment/16535-abandoned-cart-reminder-pro.html" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2024/03/14/pscartabandonmentpro.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fwx6-53vm-r73w/GHSA-fwx6-53vm-r73w.json b/advisories/unreviewed/2024/03/GHSA-fwx6-53vm-r73w/GHSA-fwx6-53vm-r73w.json new file mode 100644 index 00000000000..c54d3fb1f9b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fwx6-53vm-r73w/GHSA-fwx6-53vm-r73w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwx6-53vm-r73w", + "modified": "2024-03-20T15:32:45Z", + "published": "2024-03-20T15:32:45Z", + "aliases": [ + "CVE-2024-28574" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_copy_default_tcp_and_create_tcd() function when reading images in J2K format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28574" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g5jh-5qmm-vgjw/GHSA-g5jh-5qmm-vgjw.json b/advisories/unreviewed/2024/03/GHSA-g5jh-5qmm-vgjw/GHSA-g5jh-5qmm-vgjw.json new file mode 100644 index 00000000000..e4765ec7607 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g5jh-5qmm-vgjw/GHSA-g5jh-5qmm-vgjw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5jh-5qmm-vgjw", + "modified": "2024-03-20T15:32:47Z", + "published": "2024-03-20T15:32:47Z", + "aliases": [ + "CVE-2024-2674" + ], + "details": "A vulnerability classified as critical was found in Campcodes Online Job Finder System 1.0. This vulnerability affects unknown code of the file /admin/employee/index.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257374 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2674" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%207.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257374" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257374" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g6f3-g3wm-f7p5/GHSA-g6f3-g3wm-f7p5.json b/advisories/unreviewed/2024/03/GHSA-g6f3-g3wm-f7p5/GHSA-g6f3-g3wm-f7p5.json new file mode 100644 index 00000000000..adfabf33caa --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g6f3-g3wm-f7p5/GHSA-g6f3-g3wm-f7p5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6f3-g3wm-f7p5", + "modified": "2024-03-20T15:32:45Z", + "published": "2024-03-20T15:32:45Z", + "aliases": [ + "CVE-2024-28579" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImage_Unload() function when reading images in HDR format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28579" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g6gj-xwhj-g7rm/GHSA-g6gj-xwhj-g7rm.json b/advisories/unreviewed/2024/03/GHSA-g6gj-xwhj-g7rm/GHSA-g6gj-xwhj-g7rm.json new file mode 100644 index 00000000000..4e9f8c3362a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g6gj-xwhj-g7rm/GHSA-g6gj-xwhj-g7rm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6gj-xwhj-g7rm", + "modified": "2024-03-20T15:32:58Z", + "published": "2024-03-20T15:32:58Z", + "aliases": [ + "CVE-2024-29419" + ], + "details": "There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29419" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/X2000R/XSS_6_Wireless_settings/XSS.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/products/id/242/ids/33.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g7jh-36w6-x3c4/GHSA-g7jh-36w6-x3c4.json b/advisories/unreviewed/2024/03/GHSA-g7jh-36w6-x3c4/GHSA-g7jh-36w6-x3c4.json new file mode 100644 index 00000000000..b1ee9bcb25d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g7jh-36w6-x3c4/GHSA-g7jh-36w6-x3c4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7jh-36w6-x3c4", + "modified": "2024-03-20T15:32:53Z", + "published": "2024-03-20T15:32:53Z", + "aliases": [ + "CVE-2024-2680" + ], + "details": "A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/user/index.php. The manipulation of the argument view leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257380.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2680" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2015.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257380" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257380" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gm3p-cxxm-phr6/GHSA-gm3p-cxxm-phr6.json b/advisories/unreviewed/2024/03/GHSA-gm3p-cxxm-phr6/GHSA-gm3p-cxxm-phr6.json new file mode 100644 index 00000000000..3532b866733 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gm3p-cxxm-phr6/GHSA-gm3p-cxxm-phr6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm3p-cxxm-phr6", + "modified": "2024-03-20T15:32:32Z", + "published": "2024-03-20T15:32:32Z", + "aliases": [ + "CVE-2024-22084" + ], + "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed through log files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22084" + }, + { + "type": "WEB", + "url": "https://www.elspec-ltd.com/support/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json b/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json new file mode 100644 index 00000000000..d7bf68d2271 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwcc-j6r9-59p8", + "modified": "2024-03-20T15:32:25Z", + "published": "2024-03-20T15:32:25Z", + "aliases": [ + "CVE-2024-2645" + ], + "details": "A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /vpnweb/resetpwd/resetpwd.php. The manipulation of the argument UserId leads to improper neutralization of data within xpath expressions. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257283. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2645" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-laddfirewall.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257283" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257283" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-643" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gxjr-v6fw-49mr/GHSA-gxjr-v6fw-49mr.json b/advisories/unreviewed/2024/03/GHSA-gxjr-v6fw-49mr/GHSA-gxjr-v6fw-49mr.json new file mode 100644 index 00000000000..ba51b05197b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gxjr-v6fw-49mr/GHSA-gxjr-v6fw-49mr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxjr-v6fw-49mr", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2024-1800" + ], + "details": "\nIn Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1800" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/report-server/knowledge-base/deserialization-vulnerability-cve-2024-1800" + }, + { + "type": "WEB", + "url": "https://www.telerik.com/report-server" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h396-qp5c-h728/GHSA-h396-qp5c-h728.json b/advisories/unreviewed/2024/03/GHSA-h396-qp5c-h728/GHSA-h396-qp5c-h728.json new file mode 100644 index 00000000000..79875f93ca2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h396-qp5c-h728/GHSA-h396-qp5c-h728.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h396-qp5c-h728", + "modified": "2024-03-20T15:32:27Z", + "published": "2024-03-20T15:32:27Z", + "aliases": [ + "CVE-2024-2387" + ], + "details": "The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries and subsequently inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2387" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/trunk/includes/class-adfoin-log-table.php#L227" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/trunk/includes/class-adfoin-log-table.php#L275" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3052201%40advanced-form-integration&new=3052201%40advanced-form-integration&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/45d5a677-9b8b-4258-9cfb-101b0f0e6f6f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h3f7-4pq5-5jqm/GHSA-h3f7-4pq5-5jqm.json b/advisories/unreviewed/2024/03/GHSA-h3f7-4pq5-5jqm/GHSA-h3f7-4pq5-5jqm.json new file mode 100644 index 00000000000..c19ccd2c5e3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h3f7-4pq5-5jqm/GHSA-h3f7-4pq5-5jqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3f7-4pq5-5jqm", + "modified": "2024-03-20T15:32:56Z", + "published": "2024-03-20T15:32:56Z", + "aliases": [ + "CVE-2024-2702" + ], + "details": "Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2702" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/olive-one-click-demo-import/wordpress-olive-one-click-demo-import-plugin-1-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h5fw-99jv-5c89/GHSA-h5fw-99jv-5c89.json b/advisories/unreviewed/2024/03/GHSA-h5fw-99jv-5c89/GHSA-h5fw-99jv-5c89.json new file mode 100644 index 00000000000..96b983b91ed --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h5fw-99jv-5c89/GHSA-h5fw-99jv-5c89.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5fw-99jv-5c89", + "modified": "2024-03-20T15:32:30Z", + "published": "2024-03-20T15:32:30Z", + "aliases": [ + "CVE-2024-22082" + ], + "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated directory listing can occur: the web interface cay be abused be an attacker get a better understanding of the operating system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22082" + }, + { + "type": "WEB", + "url": "https://www.elspec-ltd.com/support/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h8c2-5xf3-fx2x/GHSA-h8c2-5xf3-fx2x.json b/advisories/unreviewed/2024/03/GHSA-h8c2-5xf3-fx2x/GHSA-h8c2-5xf3-fx2x.json new file mode 100644 index 00000000000..a4160235828 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h8c2-5xf3-fx2x/GHSA-h8c2-5xf3-fx2x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8c2-5xf3-fx2x", + "modified": "2024-03-20T15:32:45Z", + "published": "2024-03-20T15:32:45Z", + "aliases": [ + "CVE-2024-28571" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the fill_input_buffer() function when reading images in JPEG format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28571" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h8p2-55fh-ggc4/GHSA-h8p2-55fh-ggc4.json b/advisories/unreviewed/2024/03/GHSA-h8p2-55fh-ggc4/GHSA-h8p2-55fh-ggc4.json new file mode 100644 index 00000000000..94cfc45f800 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h8p2-55fh-ggc4/GHSA-h8p2-55fh-ggc4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8p2-55fh-ggc4", + "modified": "2024-03-20T15:32:54Z", + "published": "2024-03-20T15:32:54Z", + "aliases": [ + "CVE-2024-2682" + ], + "details": "A vulnerability classified as problematic has been found in Campcodes Online Job Finder System 1.0. Affected is an unknown function of the file /admin/employee/controller.php. The manipulation of the argument EMPLOYEEID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257382 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2682" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2017.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257382" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257382" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h8v5-8g7h-c9mq/GHSA-h8v5-8g7h-c9mq.json b/advisories/unreviewed/2024/03/GHSA-h8v5-8g7h-c9mq/GHSA-h8v5-8g7h-c9mq.json new file mode 100644 index 00000000000..c856de2c0df --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h8v5-8g7h-c9mq/GHSA-h8v5-8g7h-c9mq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8v5-8g7h-c9mq", + "modified": "2024-03-20T15:32:23Z", + "published": "2024-03-20T15:32:23Z", + "aliases": [ + "CVE-2024-2641" + ], + "details": "A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been classified as critical. Affected is an unknown function of the file /system/passwdManage.htm of the component Password Handler. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257280. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2641" + }, + { + "type": "WEB", + "url": "https://h0e4a0r1t.github.io/2024/vulns/Unauthorized%20access%20vulnerability%20in%20Ruijie%20RG-NBS2009G-P%20switch.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257280" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257280" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hpmw-vh9j-2pxc/GHSA-hpmw-vh9j-2pxc.json b/advisories/unreviewed/2024/03/GHSA-hpmw-vh9j-2pxc/GHSA-hpmw-vh9j-2pxc.json new file mode 100644 index 00000000000..5ce99fc3c2d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hpmw-vh9j-2pxc/GHSA-hpmw-vh9j-2pxc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpmw-vh9j-2pxc", + "modified": "2024-03-20T15:32:22Z", + "published": "2024-03-20T15:32:22Z", + "aliases": [ + "CVE-2024-28092" + ], + "details": "UBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allows a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via RgFirewallEL.asp, RgDdns.asp, RgTime.asp, RgDiagnostics.asp, or RgParentalBasic.asp. The affected fields are SMTP Server Name, SMTP Username, Host Name, Time Server 1, Time Server 2, Time Server 3, Target, Add Keyword, Add Domain, and Add Allowed Domain.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28092" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Ubee/CVE-2024-28092" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hqf6-9hf3-qr68/GHSA-hqf6-9hf3-qr68.json b/advisories/unreviewed/2024/03/GHSA-hqf6-9hf3-qr68/GHSA-hqf6-9hf3-qr68.json new file mode 100644 index 00000000000..2a86527cd57 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hqf6-9hf3-qr68/GHSA-hqf6-9hf3-qr68.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqf6-9hf3-qr68", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2024-28396" + ], + "details": "An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28396" + }, + { + "type": "WEB", + "url": "https://addons.prestashop.com/en/data-import-export/17596-orders-csv-excel-export-pro.html" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2024/03/14/ordersexport.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hrq6-7x78-h4mh/GHSA-hrq6-7x78-h4mh.json b/advisories/unreviewed/2024/03/GHSA-hrq6-7x78-h4mh/GHSA-hrq6-7x78-h4mh.json new file mode 100644 index 00000000000..608fe088e91 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hrq6-7x78-h4mh/GHSA-hrq6-7x78-h4mh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrq6-7x78-h4mh", + "modified": "2024-03-20T15:32:54Z", + "published": "2024-03-20T15:32:54Z", + "aliases": [ + "CVE-2024-2685" + ], + "details": "A vulnerability, which was classified as problematic, was found in Campcodes Online Job Finder System 1.0. This affects an unknown part of the file /admin/applicants/index.php. The manipulation of the argument view leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257385 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2685" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2020.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257385" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257385" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hvcf-gc35-33ww/GHSA-hvcf-gc35-33ww.json b/advisories/unreviewed/2024/03/GHSA-hvcf-gc35-33ww/GHSA-hvcf-gc35-33ww.json new file mode 100644 index 00000000000..03217e5fe23 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hvcf-gc35-33ww/GHSA-hvcf-gc35-33ww.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvcf-gc35-33ww", + "modified": "2024-03-20T15:32:24Z", + "published": "2024-03-20T15:32:24Z", + "aliases": [ + "CVE-2024-2644" + ], + "details": "A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /protocol/firewall/addfirewall.php. The manipulation of the argument FireWallTableArray leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257282 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2644" + }, + { + "type": "WEB", + "url": "https://github.com/hundanchen69/cve/blob/main/NS-ASG-sql-laddfirewall.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257282" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257282" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j4v2-46x2-2r5q/GHSA-j4v2-46x2-2r5q.json b/advisories/unreviewed/2024/03/GHSA-j4v2-46x2-2r5q/GHSA-j4v2-46x2-2r5q.json new file mode 100644 index 00000000000..14d10d21963 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j4v2-46x2-2r5q/GHSA-j4v2-46x2-2r5q.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4v2-46x2-2r5q", + "modified": "2024-03-20T15:32:25Z", + "published": "2024-03-20T15:32:25Z", + "aliases": [ + "CVE-2024-2647" + ], + "details": "A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3. This issue affects some unknown processing of the file /admin/singlelogin.php. The manipulation of the argument loginId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257285 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2647" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-singlelogin.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257285" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j6j6-pgrh-8gmh/GHSA-j6j6-pgrh-8gmh.json b/advisories/unreviewed/2024/03/GHSA-j6j6-pgrh-8gmh/GHSA-j6j6-pgrh-8gmh.json new file mode 100644 index 00000000000..f2197ada046 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j6j6-pgrh-8gmh/GHSA-j6j6-pgrh-8gmh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6j6-pgrh-8gmh", + "modified": "2024-03-20T15:32:46Z", + "published": "2024-03-20T15:32:46Z", + "aliases": [ + "CVE-2024-28578" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in RAS format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28578" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j6w7-v73w-6pw3/GHSA-j6w7-v73w-6pw3.json b/advisories/unreviewed/2024/03/GHSA-j6w7-v73w-6pw3/GHSA-j6w7-v73w-6pw3.json new file mode 100644 index 00000000000..c1264f97514 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j6w7-v73w-6pw3/GHSA-j6w7-v73w-6pw3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6w7-v73w-6pw3", + "modified": "2024-03-20T15:32:25Z", + "published": "2024-03-20T15:32:25Z", + "aliases": [ + "CVE-2024-1785" + ], + "details": "The Contests by Rewards Fuel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.62. This is due to missing or incorrect nonce validation on the ajax_handler() function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site's user with the edit_posts capability into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1785" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3039978%40contests-from-rewards-fuel&new=3039978%40contests-from-rewards-fuel&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/689f3667-2dda-40a8-8627-d38c6c6816fc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j9jf-hh2m-m3g7/GHSA-j9jf-hh2m-m3g7.json b/advisories/unreviewed/2024/03/GHSA-j9jf-hh2m-m3g7/GHSA-j9jf-hh2m-m3g7.json new file mode 100644 index 00000000000..7c116229a15 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j9jf-hh2m-m3g7/GHSA-j9jf-hh2m-m3g7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9jf-hh2m-m3g7", + "modified": "2024-03-20T15:32:34Z", + "published": "2024-03-20T15:32:34Z", + "aliases": [ + "CVE-2024-2673" + ], + "details": "A vulnerability classified as critical has been found in Campcodes Online Job Finder System 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument user_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257373 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2673" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%206.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257373" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257373" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jh7h-6rpx-g936/GHSA-jh7h-6rpx-g936.json b/advisories/unreviewed/2024/03/GHSA-jh7h-6rpx-g936/GHSA-jh7h-6rpx-g936.json new file mode 100644 index 00000000000..31bfe15c617 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jh7h-6rpx-g936/GHSA-jh7h-6rpx-g936.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh7h-6rpx-g936", + "modified": "2024-03-20T15:32:28Z", + "published": "2024-03-20T15:32:28Z", + "aliases": [ + "CVE-2024-2460" + ], + "details": "The GamiPress – Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gamipress_button' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2460" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3051778%40gamipress-button&new=3051778%40gamipress-button&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/af39e563-5d88-460d-b02d-1aaa111c89dd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jpj7-3cxp-mwxp/GHSA-jpj7-3cxp-mwxp.json b/advisories/unreviewed/2024/03/GHSA-jpj7-3cxp-mwxp/GHSA-jpj7-3cxp-mwxp.json new file mode 100644 index 00000000000..5c9c6f42a86 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jpj7-3cxp-mwxp/GHSA-jpj7-3cxp-mwxp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpj7-3cxp-mwxp", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2024-28395" + ], + "details": "SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28395" + }, + { + "type": "WEB", + "url": "https://addons.prestashop.com/en/pop-up/20208-pop-up-schedule-popup-splash-window.html" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2024/03/14/bestkit_popup.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m2v2-rjrw-p6c5/GHSA-m2v2-rjrw-p6c5.json b/advisories/unreviewed/2024/03/GHSA-m2v2-rjrw-p6c5/GHSA-m2v2-rjrw-p6c5.json new file mode 100644 index 00000000000..53dfd0d40de --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m2v2-rjrw-p6c5/GHSA-m2v2-rjrw-p6c5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2v2-rjrw-p6c5", + "modified": "2024-03-20T15:32:47Z", + "published": "2024-03-20T15:32:47Z", + "aliases": [ + "CVE-2024-2676" + ], + "details": "A vulnerability, which was classified as critical, was found in Campcodes Online Job Finder System 1.0. Affected is an unknown function of the file /admin/company/controller.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257376.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2676" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%209.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257376" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m8qw-mppg-7364/GHSA-m8qw-mppg-7364.json b/advisories/unreviewed/2024/03/GHSA-m8qw-mppg-7364/GHSA-m8qw-mppg-7364.json new file mode 100644 index 00000000000..91d776e7c00 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m8qw-mppg-7364/GHSA-m8qw-mppg-7364.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8qw-mppg-7364", + "modified": "2024-03-20T15:32:29Z", + "published": "2024-03-20T15:32:29Z", + "aliases": [ + "CVE-2024-1983" + ], + "details": "The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1983" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bf3a31de-a227-4db1-bd18-ce6a78dc96fb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mc39-65g2-x85c/GHSA-mc39-65g2-x85c.json b/advisories/unreviewed/2024/03/GHSA-mc39-65g2-x85c/GHSA-mc39-65g2-x85c.json new file mode 100644 index 00000000000..4869bf9bc95 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mc39-65g2-x85c/GHSA-mc39-65g2-x85c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc39-65g2-x85c", + "modified": "2024-03-20T15:32:27Z", + "published": "2024-03-20T15:32:27Z", + "aliases": [ + "CVE-2024-2669" + ], + "details": "A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/employee/controller.php of the component GET Parameter Handler. The manipulation of the argument EMPLOYEEID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257369 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2669" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%202.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257369" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257369" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json b/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json new file mode 100644 index 00000000000..c7652f77846 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxh6-2xpg-m77w", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2023-46841" + ], + "details": "Recent x86 CPUs offer functionality named Control-flow Enforcement\nTechnology (CET). A sub-feature of this are Shadow Stacks (CET-SS).\nCET-SS is a hardware feature designed to protect against Return Oriented\nProgramming attacks. When enabled, traditional stacks holding both data\nand return addresses are accompanied by so called \"shadow stacks\",\nholding little more than return addresses. Shadow stacks aren't\nwritable by normal instructions, and upon function returns their\ncontents are used to check for possible manipulation of a return address\ncoming from the traditional stack.\n\nIn particular certain memory accesses need intercepting by Xen. In\nvarious cases the necessary emulation involves kind of replaying of\nthe instruction. Such replaying typically involves filling and then\ninvoking of a stub. Such a replayed instruction may raise an\nexceptions, which is expected and dealt with accordingly.\n\nUnfortunately the interaction of both of the above wasn't right:\nRecovery involves removal of a call frame from the (traditional) stack.\nThe counterpart of this operation for the shadow stack was missing.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46841" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-451.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p4h9-hj8v-r54m/GHSA-p4h9-hj8v-r54m.json b/advisories/unreviewed/2024/03/GHSA-p4h9-hj8v-r54m/GHSA-p4h9-hj8v-r54m.json new file mode 100644 index 00000000000..5c1a7e0e243 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p4h9-hj8v-r54m/GHSA-p4h9-hj8v-r54m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4h9-hj8v-r54m", + "modified": "2024-03-20T15:32:33Z", + "published": "2024-03-20T15:32:33Z", + "aliases": [ + "CVE-2024-2672" + ], + "details": "A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/user/controller.php. The manipulation of the argument UESRID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257372.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2672" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%205.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257372" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257372" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p94v-hr2q-pvmg/GHSA-p94v-hr2q-pvmg.json b/advisories/unreviewed/2024/03/GHSA-p94v-hr2q-pvmg/GHSA-p94v-hr2q-pvmg.json new file mode 100644 index 00000000000..a4accfa97ab --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p94v-hr2q-pvmg/GHSA-p94v-hr2q-pvmg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p94v-hr2q-pvmg", + "modified": "2024-03-20T15:32:43Z", + "published": "2024-03-20T15:32:43Z", + "aliases": [ + "CVE-2024-28566" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28566" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p97v-hh3c-f8mq/GHSA-p97v-hh3c-f8mq.json b/advisories/unreviewed/2024/03/GHSA-p97v-hh3c-f8mq/GHSA-p97v-hh3c-f8mq.json new file mode 100644 index 00000000000..d089a0b1385 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p97v-hh3c-f8mq/GHSA-p97v-hh3c-f8mq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p97v-hh3c-f8mq", + "modified": "2024-03-20T15:32:23Z", + "published": "2024-03-20T15:32:23Z", + "aliases": [ + "CVE-2023-50811" + ], + "details": "An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. Iterating that parameter, it has been possible to access to the application and take control of many other receptions in addition the assigned one.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50811" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pcj3-p7wg-9c68/GHSA-pcj3-p7wg-9c68.json b/advisories/unreviewed/2024/03/GHSA-pcj3-p7wg-9c68/GHSA-pcj3-p7wg-9c68.json new file mode 100644 index 00000000000..3fcf157e04f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pcj3-p7wg-9c68/GHSA-pcj3-p7wg-9c68.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcj3-p7wg-9c68", + "modified": "2024-03-20T15:32:30Z", + "published": "2024-03-20T15:32:30Z", + "aliases": [ + "CVE-2024-22079" + ], + "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22079" + }, + { + "type": "WEB", + "url": "https://www.elspec-ltd.com/support/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pm3j-v9mg-55rh/GHSA-pm3j-v9mg-55rh.json b/advisories/unreviewed/2024/03/GHSA-pm3j-v9mg-55rh/GHSA-pm3j-v9mg-55rh.json new file mode 100644 index 00000000000..88082e0d46e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pm3j-v9mg-55rh/GHSA-pm3j-v9mg-55rh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm3j-v9mg-55rh", + "modified": "2024-03-20T15:32:54Z", + "published": "2024-03-20T15:32:54Z", + "aliases": [ + "CVE-2024-2683" + ], + "details": "A vulnerability classified as problematic was found in Campcodes Online Job Finder System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/company/index.php. The manipulation of the argument view leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257383.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2683" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2018.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257383" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json b/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json new file mode 100644 index 00000000000..6cdd56e4074 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prfm-p99w-7gm2", + "modified": "2024-03-20T15:32:32Z", + "published": "2024-03-20T15:32:32Z", + "aliases": [ + "CVE-2024-22083" + ], + "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A hardcoded backdoor session ID exists that can be used for further access to the device, including reconfiguration tasks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22083" + }, + { + "type": "WEB", + "url": "https://www.elspec-ltd.com/support/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q3mq-cvp5-qxcr/GHSA-q3mq-cvp5-qxcr.json b/advisories/unreviewed/2024/03/GHSA-q3mq-cvp5-qxcr/GHSA-q3mq-cvp5-qxcr.json new file mode 100644 index 00000000000..db3095f45e1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q3mq-cvp5-qxcr/GHSA-q3mq-cvp5-qxcr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3mq-cvp5-qxcr", + "modified": "2024-03-20T15:32:45Z", + "published": "2024-03-20T15:32:45Z", + "aliases": [ + "CVE-2024-28572" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImage_SetTagValue() function when reading images in JPEG format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28572" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qcc3-2x2p-6v35/GHSA-qcc3-2x2p-6v35.json b/advisories/unreviewed/2024/03/GHSA-qcc3-2x2p-6v35/GHSA-qcc3-2x2p-6v35.json new file mode 100644 index 00000000000..6de00dbcdce --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qcc3-2x2p-6v35/GHSA-qcc3-2x2p-6v35.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcc3-2x2p-6v35", + "modified": "2024-03-20T15:32:21Z", + "published": "2024-03-20T15:32:21Z", + "aliases": [ + "CVE-2024-28595" + ], + "details": "SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28595" + }, + { + "type": "WEB", + "url": "https://github.com/shubham-s-pandey/CVE_POC/blob/main/CVE-2024-28595.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qmw9-5q6h-hjxj/GHSA-qmw9-5q6h-hjxj.json b/advisories/unreviewed/2024/03/GHSA-qmw9-5q6h-hjxj/GHSA-qmw9-5q6h-hjxj.json new file mode 100644 index 00000000000..4173a1c2724 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qmw9-5q6h-hjxj/GHSA-qmw9-5q6h-hjxj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmw9-5q6h-hjxj", + "modified": "2024-03-20T15:32:28Z", + "published": "2024-03-20T15:32:28Z", + "aliases": [ + "CVE-2023-7246" + ], + "details": "The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7246" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7413d5ec-10a7-4cb8-ac1c-4ef554751518" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qq8f-9mh8-5973/GHSA-qq8f-9mh8-5973.json b/advisories/unreviewed/2024/03/GHSA-qq8f-9mh8-5973/GHSA-qq8f-9mh8-5973.json new file mode 100644 index 00000000000..59387c421ee --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qq8f-9mh8-5973/GHSA-qq8f-9mh8-5973.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq8f-9mh8-5973", + "modified": "2024-03-20T15:32:24Z", + "published": "2024-03-20T15:32:24Z", + "aliases": [ + "CVE-2024-2642" + ], + "details": "A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /EXCU_SHELL. The manipulation of the argument Command1 leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257281 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2642" + }, + { + "type": "WEB", + "url": "https://h0e4a0r1t.github.io/2024/vulns/Ruijie%20RG-NBS2009G-P%20switch%20has%20a%20foreground%20CLI%20command%20injection%20vulnerability.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257281" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257281" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r26g-5xh6-pgwp/GHSA-r26g-5xh6-pgwp.json b/advisories/unreviewed/2024/03/GHSA-r26g-5xh6-pgwp/GHSA-r26g-5xh6-pgwp.json new file mode 100644 index 00000000000..ad0f4e4b80e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r26g-5xh6-pgwp/GHSA-r26g-5xh6-pgwp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r26g-5xh6-pgwp", + "modified": "2024-03-20T15:32:48Z", + "published": "2024-03-20T15:32:48Z", + "aliases": [ + "CVE-2024-1205" + ], + "details": "The Management App for WooCommerce – Order notifications, Order management, Lead management, Uptime Monitoring plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the nouvello_upload_csv_file function in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1205" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wemanage-app-worker/trunk/includes/class-nouvello-wemanage-worker-api-wc-ext-controller-functions.php#L982" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wemanage-app-worker/trunk/includes/class-nouvello-wemanage-worker-api-wc-ext-controller.php#L166" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a4219c10-9d2a-429d-9ac7-61efc02bd4cf?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rf45-g4gv-fh4v/GHSA-rf45-g4gv-fh4v.json b/advisories/unreviewed/2024/03/GHSA-rf45-g4gv-fh4v/GHSA-rf45-g4gv-fh4v.json new file mode 100644 index 00000000000..a2c7d12aaaf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rf45-g4gv-fh4v/GHSA-rf45-g4gv-fh4v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf45-g4gv-fh4v", + "modified": "2024-03-20T15:32:48Z", + "published": "2024-03-20T15:32:48Z", + "aliases": [ + "CVE-2024-1181" + ], + "details": "The Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress is vulnerable to maintenance mode bypass in all versions up to, and including, 2.1.2. This is due to the plugin relying on the REQUEST_URI to determine if the page being accesses is an admin area. This makes it possible for unauthenticated attackers to bypass maintenance mode and access the site which may be considered confidential when in maintenance mode.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1181" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/coming-soon-wp/trunk/coming-soon-wp.php#L45" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6dc144cd-7119-477f-9fa1-b00cab215077?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rpqx-wxvq-jh8m/GHSA-rpqx-wxvq-jh8m.json b/advisories/unreviewed/2024/03/GHSA-rpqx-wxvq-jh8m/GHSA-rpqx-wxvq-jh8m.json new file mode 100644 index 00000000000..b030620c0f1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rpqx-wxvq-jh8m/GHSA-rpqx-wxvq-jh8m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpqx-wxvq-jh8m", + "modified": "2024-03-20T15:32:28Z", + "published": "2024-03-20T15:32:28Z", + "aliases": [ + "CVE-2024-2671" + ], + "details": "A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/user/index.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257371.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2671" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%204.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257371" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rrf2-65m6-wmqp/GHSA-rrf2-65m6-wmqp.json b/advisories/unreviewed/2024/03/GHSA-rrf2-65m6-wmqp/GHSA-rrf2-65m6-wmqp.json new file mode 100644 index 00000000000..18410747985 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rrf2-65m6-wmqp/GHSA-rrf2-65m6-wmqp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrf2-65m6-wmqp", + "modified": "2024-03-20T15:32:45Z", + "published": "2024-03-20T15:32:45Z", + "aliases": [ + "CVE-2024-28573" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the jpeg_read_exif_profile() function when reading images in JPEG format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28573" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v82h-9xhx-c8hg/GHSA-v82h-9xhx-c8hg.json b/advisories/unreviewed/2024/03/GHSA-v82h-9xhx-c8hg/GHSA-v82h-9xhx-c8hg.json new file mode 100644 index 00000000000..2f110863375 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v82h-9xhx-c8hg/GHSA-v82h-9xhx-c8hg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v82h-9xhx-c8hg", + "modified": "2024-03-20T15:32:25Z", + "published": "2024-03-20T15:32:25Z", + "aliases": [ + "CVE-2024-2197" + ], + "details": "\nChirp Access improperly stores credentials within its source code, potentially exposing sensitive information to unauthorized access.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2197" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-067-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vcwc-59rg-8254/GHSA-vcwc-59rg-8254.json b/advisories/unreviewed/2024/03/GHSA-vcwc-59rg-8254/GHSA-vcwc-59rg-8254.json new file mode 100644 index 00000000000..9a8546f9886 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vcwc-59rg-8254/GHSA-vcwc-59rg-8254.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcwc-59rg-8254", + "modified": "2024-03-20T15:32:46Z", + "published": "2024-03-20T15:32:46Z", + "aliases": [ + "CVE-2024-28582" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28582" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vh6v-96hr-r3rq/GHSA-vh6v-96hr-r3rq.json b/advisories/unreviewed/2024/03/GHSA-vh6v-96hr-r3rq/GHSA-vh6v-96hr-r3rq.json new file mode 100644 index 00000000000..1f6fcfdc670 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vh6v-96hr-r3rq/GHSA-vh6v-96hr-r3rq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh6v-96hr-r3rq", + "modified": "2024-03-20T15:32:25Z", + "published": "2024-03-20T15:32:25Z", + "aliases": [ + "CVE-2024-2646" + ], + "details": "A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /vpnweb/index.php?para=index. The manipulation of the argument check_VirtualSiteId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257284. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2646" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-index.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257284" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257284" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vhg5-jp6p-2pcw/GHSA-vhg5-jp6p-2pcw.json b/advisories/unreviewed/2024/03/GHSA-vhg5-jp6p-2pcw/GHSA-vhg5-jp6p-2pcw.json new file mode 100644 index 00000000000..acadff93340 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vhg5-jp6p-2pcw/GHSA-vhg5-jp6p-2pcw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhg5-jp6p-2pcw", + "modified": "2024-03-20T15:32:38Z", + "published": "2024-03-20T15:32:38Z", + "aliases": [ + "CVE-2024-28563" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::DwaCompressor::Classifier::Classifier() function when reading images in EXR format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28563" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vjpg-wm6m-cjg7/GHSA-vjpg-wm6m-cjg7.json b/advisories/unreviewed/2024/03/GHSA-vjpg-wm6m-cjg7/GHSA-vjpg-wm6m-cjg7.json new file mode 100644 index 00000000000..42564efe5b6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vjpg-wm6m-cjg7/GHSA-vjpg-wm6m-cjg7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjpg-wm6m-cjg7", + "modified": "2024-03-20T15:32:57Z", + "published": "2024-03-20T15:32:57Z", + "aliases": [ + "CVE-2024-1856" + ], + "details": "\nIn Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1856" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/reporting/knowledge-base/deserialization-vulnerability-cve-2024-1801-cve-2024-1856" + }, + { + "type": "WEB", + "url": "https://www.telerik.com/products/reporting.aspx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vx26-qhj3-h8j2/GHSA-vx26-qhj3-h8j2.json b/advisories/unreviewed/2024/03/GHSA-vx26-qhj3-h8j2/GHSA-vx26-qhj3-h8j2.json new file mode 100644 index 00000000000..2a5d00f1f0c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vx26-qhj3-h8j2/GHSA-vx26-qhj3-h8j2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx26-qhj3-h8j2", + "modified": "2024-03-20T15:32:49Z", + "published": "2024-03-20T15:32:49Z", + "aliases": [ + "CVE-2024-1844" + ], + "details": "The RevivePress – Keep your Old Content Evergreen plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the import_data and copy_data functions in all versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with subscriber-level access or higher, to overwrite plugin settings and view them.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1844" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-auto-republish/trunk/includes/Tools/Database.php#L148" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-auto-republish/trunk/includes/Tools/Database.php#L161" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/63ecb518-50d6-49ad-92e4-c5a7494ced82?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w853-6hc5-89h2/GHSA-w853-6hc5-89h2.json b/advisories/unreviewed/2024/03/GHSA-w853-6hc5-89h2/GHSA-w853-6hc5-89h2.json new file mode 100644 index 00000000000..3ee3e165bf2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w853-6hc5-89h2/GHSA-w853-6hc5-89h2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w853-6hc5-89h2", + "modified": "2024-03-20T15:32:21Z", + "published": "2024-03-20T15:32:21Z", + "aliases": [ + "CVE-2024-24336" + ], + "details": "A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff users to carry out CSRF attacks, including unauthorized changes to usernames and passwords of users visiting the affected page, via the 'Circulation note' and ‘Patrons Restriction’ components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24336" + }, + { + "type": "WEB", + "url": "https://nitipoom-jar.github.io/CVE-2024-24336" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-19T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-whxq-h93c-wvrx/GHSA-whxq-h93c-wvrx.json b/advisories/unreviewed/2024/03/GHSA-whxq-h93c-wvrx/GHSA-whxq-h93c-wvrx.json new file mode 100644 index 00000000000..6991b2bc951 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-whxq-h93c-wvrx/GHSA-whxq-h93c-wvrx.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whxq-h93c-wvrx", + "modified": "2024-03-20T15:32:25Z", + "published": "2024-03-20T15:32:25Z", + "aliases": [ + "CVE-2024-2649" + ], + "details": "A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /protocol/iscdevicestatus/deleteonlineuser.php. The manipulation of the argument messagecontent leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257287. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2649" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-deleteonlineuser.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257287" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257287" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T01:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wprm-8qf4-xrc8/GHSA-wprm-8qf4-xrc8.json b/advisories/unreviewed/2024/03/GHSA-wprm-8qf4-xrc8/GHSA-wprm-8qf4-xrc8.json new file mode 100644 index 00000000000..0b928e74ad7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wprm-8qf4-xrc8/GHSA-wprm-8qf4-xrc8.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wprm-8qf4-xrc8", + "modified": "2024-03-20T15:32:54Z", + "published": "2024-03-20T15:32:54Z", + "aliases": [ + "CVE-2024-2684" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Campcodes Online Job Finder System 1.0. Affected by this issue is some unknown functionality of the file /admin/category/index.php. The manipulation of the argument view leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257384.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2684" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%209.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257384" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257384" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-ww3j-pv6x-2fh2/GHSA-ww3j-pv6x-2fh2.json b/advisories/unreviewed/2024/03/GHSA-ww3j-pv6x-2fh2/GHSA-ww3j-pv6x-2fh2.json new file mode 100644 index 00000000000..de72043c0ab --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-ww3j-pv6x-2fh2/GHSA-ww3j-pv6x-2fh2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww3j-pv6x-2fh2", + "modified": "2024-03-20T15:32:54Z", + "published": "2024-03-20T15:32:53Z", + "aliases": [ + "CVE-2024-2681" + ], + "details": "A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/employee/index.php. The manipulation of the argument view leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257381 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2681" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2016.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257381" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257381" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wwvg-qmhg-chgp/GHSA-wwvg-qmhg-chgp.json b/advisories/unreviewed/2024/03/GHSA-wwvg-qmhg-chgp/GHSA-wwvg-qmhg-chgp.json new file mode 100644 index 00000000000..4039cd57baa --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wwvg-qmhg-chgp/GHSA-wwvg-qmhg-chgp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwvg-qmhg-chgp", + "modified": "2024-03-20T15:32:39Z", + "published": "2024-03-20T15:32:39Z", + "aliases": [ + "CVE-2024-28565" + ], + "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the psdParser::ReadImageData() function when reading images in PSD format.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28565" + }, + { + "type": "WEB", + "url": "https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-x637-x8p3-5p22/GHSA-x637-x8p3-5p22.json b/advisories/unreviewed/2024/03/GHSA-x637-x8p3-5p22/GHSA-x637-x8p3-5p22.json new file mode 100644 index 00000000000..34d8e2b4890 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-x637-x8p3-5p22/GHSA-x637-x8p3-5p22.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x637-x8p3-5p22", + "modified": "2024-03-20T15:32:28Z", + "published": "2024-03-20T15:32:28Z", + "aliases": [ + "CVE-2024-22258" + ], + "details": "Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients.\n\nSpecifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant.\n\nAn application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22258" + }, + { + "type": "WEB", + "url": "https://spring.io/security/cve-2024-22258" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-x99w-3523-r792/GHSA-x99w-3523-r792.json b/advisories/unreviewed/2024/03/GHSA-x99w-3523-r792/GHSA-x99w-3523-r792.json new file mode 100644 index 00000000000..1efae783fb5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-x99w-3523-r792/GHSA-x99w-3523-r792.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x99w-3523-r792", + "modified": "2024-03-20T15:32:49Z", + "published": "2024-03-20T15:32:49Z", + "aliases": [ + "CVE-2024-2129" + ], + "details": "The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's heading widget in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2129" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wpbits-addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/05cd8f96-533a-4036-a01f-6ba1ad2d2b5e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xhh5-7x8q-mcj7/GHSA-xhh5-7x8q-mcj7.json b/advisories/unreviewed/2024/03/GHSA-xhh5-7x8q-mcj7/GHSA-xhh5-7x8q-mcj7.json new file mode 100644 index 00000000000..66c1e8a3171 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xhh5-7x8q-mcj7/GHSA-xhh5-7x8q-mcj7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhh5-7x8q-mcj7", + "modified": "2024-03-20T15:32:53Z", + "published": "2024-03-20T15:32:53Z", + "aliases": [ + "CVE-2024-2679" + ], + "details": "A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/vacancy/index.php. The manipulation of the argument view leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257379.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2679" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Job%20Finder%20System/Online%20Job%20Finder%20System%20-%20vuln%2014.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257379" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257379" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-20T07:15:12Z" + } +} \ No newline at end of file